redact-secret · Report
Organization API key
Organization-scoped secret key, prefixed sk_org_.
Research record
What blocks the research
- Issuance-gatedWhether a live_ or test_ segment follows sk_org_, and the body length and alphabet; needs one organization API key measured (structure only). Product gap redact-secret#1030 is filed.
2 events in the review history: 1 observed, 1 reviewed. Latest: observed on 2026-09-29 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
Shape not recorded.
Format facts
Provider documented ·
dossier-research· current · observed 2026-09-29Legacy dossier research (verdict issuance-gated, tier T1) cited 7 sources; the dossier does not attribute sources to individual properties.
- docs.stripe.com/keysprovider-documentation · last read 2026-10-04 · latest outcome read · supports Cited by the legacy dossier research for this family
- docs.stripe.com/keys/organization-api-keysprovider-documentation · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- baristaze/tadas @ b55571cd85ec5a7fe16bc463537980909f87ee4f: integrations/src/tadas/integrations/settings.pyother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L94-L114
- koki-develop/mask-go @ 1b861d7ac421b392a5bb962207fd1886b28e013e: builtin_stripe_secret_key.gothird-party-writeup · last read 2026-09-30 · latest outcome read · supports Cited by the legacy dossier research for this family · #L100-L113
- lazyluke16-dotcom/richmond-rapid-connect @ 5c057a98ccc24602917441f6c78f3a6aa15dc740: src/lib/stripe.server.tsthird-party-writeup · last read 2026-09-30 · latest outcome read · supports Cited by the legacy dossier research for this family · #L12-L18
- redact-secret/redact-secret @ 378581770a87751d72e27529796c4f790649fd00: docs/audits/evidence/1012/stripe-organization-api-key.mdproject-research-note · last read 2026-09-29 · latest outcome read · supports Final research evidence recorded by the legacy dossier
- stripe/stripe-cli @ 1090068baae4c3d732fd500a9d3dbe4b94bc91a0: pkg/cmd/listen.goother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L193-L196
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- prefix
sk_org_, named on Stripe's key-types page and its organization keys page, which says the keys "support sandboxes and live mode" and have nork_org_sibling. No Stripe page, SDK, mock or peer scanner rule gives a literal key, a body length or an alphabet. Two independent applications branch onsk_org_live_andsk_org_test_, so a mode segment after the prefix is plausible but unconfirmed. - Basis
- - provider docs (T1, prefix): the keys page and the organization API keys page. - provider code (R6, substring only): stripe-cli
listen.gotests for the substringsk_org, no grammar. - independent implementations (one class): mask-go acceptssk_org_live_,sk_org_test_and baresk_org_; richmond-rapid-connect branches onsk_org_test_andsk_org_live_; tadas lists both and alsork_org_, which Stripe says does not exist. - Not evidence: three committedsk_org_live_-shaped values in unrelated repositories, withheld; they are a lead that thelive_segment occurs. - Searched with nothing further: eleven Stripe docs pages, nine Stripe SDK and mock repositories, and the rules of gitleaks, trufflehog, betterleaks, CredSweeper, noseyparker and GitLab. GitHub's partner list has no organization row. - Issuance
- needs a Stripe organization. Create one organization API key in a sandbox (and read a live one if available) and record only the bytes after
sk_org_(test_,live_or none), the body length, whether the body is only[A-Za-z0-9]and the total length; then roll or delete the key. - Contract in core
- core claims
sk_org_+ at least 20[A-Za-z0-9], and since product PR #1101 (mergebfc608cce75f79f6a5cab037d7e558ba629777f6, closing #1030) alsosk_org_live_andsk_org_test_+ at least 20 alphanumerics, as the samestripefinding assk_org_. This is the support-policy floor: it follows the optional mode segment that two independent applications branch on, not a provider-stated grammar, and no issued key has been observed. Fixture framing (decided 2026-09-30, benchmarks#1030): because the body after the segment is not provider-decided, the benchmarks cover the three forms as a policy-floor contract part, never as a provider grammar. Fixtures arepolicy/T3 (never T1 or T2must-redact), the shorter-than-20 and punctuated-body controls score as policy-floor controls, and thestripe-tokencontract rows mark every sk_org_ claim not issuance-evidenced, per decision2026-09-24-stop-asserting-provider-undecided-format-properties. Measured status stays derived. Living spec: detector-families.md.
In this benchmark
- Fixtures
- 28
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
28 fixtures: 10 must stay quiet, 18 record project policy. All at the T3 level, project policy. See every row
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 28 | 18 | 0 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it | 28 | 18 | 0 | 0 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectorsNo detector mapped | 28 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it | 28 | 18 | 0 | 0 |
Benchmark dossier questions
- Blocked by
- Whether a live_ or test_ segment follows sk_org_, and the body length and alphabet; needs one organization API key measured (structure only). Product gap redact-secret#1030 is filed.
- Open caveat
- nothing beyond the
sk_orgprefix is provider-stated; an interim rule is a policy floor, not a grammar.
Looks like it, but isn't
- Collisions
- none worth naming for the prefix, which is unique to Stripe organization keys.
rk_org_does not exist per Stripe and must stay excluded;sk_live_/sk_test_are the account-scoped siblings.
Scanner rules for this family
No peer rule maps to this family
None of the reviewed peer scanners has a rule that can match a credential of this family.
None mapped
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
stripe-token-policy-org-bare-floor-barestripe · documented-format-literal | Project policyT3 · Project policy | Redacted |
stripe-token-policy-org-bare-floor-quotedstripe · documented-format-literal | Project policyT3 · Project policy | Redacted |
stripe-token-policy-org-bare-floor-unicode-crlfstripe · documented-format-literal | Project policyT3 · Project policy | Redacted |
stripe-token-policy-org-live-above-barestripe · documented-format-literal | Project policyT3 · Project policy | Redacted |
stripe-token-policy-org-live-above-quotedstripe · documented-format-literal | Project policyT3 · Project policy | Redacted |
stripe-token-policy-org-live-above-unicode-crlfstripe · documented-format-literal | Project policyT3 · Project policy | Redacted |
stripe-token-policy-org-live-floor-barestripe · documented-format-literal | Project policyT3 · Project policy | Redacted |
stripe-token-policy-org-live-floor-quotedstripe · documented-format-literal | Project policyT3 · Project policy | Redacted |
stripe-token-policy-org-live-floor-unicode-crlfstripe · documented-format-literal | Project policyT3 · Project policy | Redacted |
stripe-token-policy-org-test-above-barestripe · documented-format-literal | Project policyT3 · Project policy | Redacted |
stripe-token-policy-org-test-above-quotedstripe · documented-format-literal | Project policyT3 · Project policy | Redacted |
stripe-token-policy-org-test-above-unicode-crlfstripe · documented-format-literal | Project policyT3 · Project policy | Redacted |
stripe-token-policy-org-test-floor-barestripe · documented-format-literal | Project policyT3 · Project policy | Redacted |
stripe-token-policy-org-test-floor-quotedstripe · documented-format-literal | Project policyT3 · Project policy | Redacted |
stripe-token-policy-org-test-floor-unicode-crlfstripe · documented-format-literal | Project policyT3 · Project policy | Redacted |
stripe-token-shape-5-barestripe · documented-format-literal | Project policyT3 · Project policy | Redacted |
stripe-token-shape-5-quotedstripe · documented-format-literal | Project policyT3 · Project policy | Redacted |
stripe-token-shape-5-unicode-crlfstripe · documented-format-literal | Project policyT3 · Project policy | Redacted |
stripe-token-policy-org-bare-19-controlstripe · benign-lookalike | Must not flagT3 · Project policy | Quiet |
stripe-token-policy-org-live-19-controlstripe · benign-lookalike | Must not flagT3 · Project policy | Quiet |
stripe-token-policy-org-live-embedded-controlstripe · benign-lookalike | Must not flagT3 · Project policy | Quiet |
stripe-token-policy-org-live-no-body-controlstripe · benign-lookalike | Must not flagT3 · Project policy | Quiet |
stripe-token-policy-org-live-underscore-controlstripe · benign-lookalike | Must not flagT3 · Project policy | Quiet |
stripe-token-policy-org-rk-bare-controlstripe · benign-lookalike | Must not flagT3 · Project policy | Quiet |
stripe-token-policy-org-rk-live-controlstripe · benign-lookalike | Must not flagT3 · Project policy | Quiet |
stripe-token-policy-org-test-19-controlstripe · benign-lookalike | Must not flagT3 · Project policy | Quiet |
stripe-token-policy-org-test-hyphen-controlstripe · benign-lookalike | Must not flagT3 · Project policy | Quiet |
stripe-token-policy-org-test-no-body-controlstripe · benign-lookalike | Must not flagT3 · Project policy | Quiet |
Sources
Documentation and code
- benchmarks/lib/assessment.ts (classifyFixture variant guard: "Variant support must not be inferred from a related family name.")
- docs.stripe.com/keys
- docs.stripe.com/keys/organization-api-keys
- github.com/stripe/stripe-cli/blob/1090068baae4c3d732fd500a9d3dbe4b94bc91a0/pkg/cmd/listen.go#L193-L196
- github.com/koki-develop/mask-go/blob/1b861d7ac421b392a5bb962207fd1886b28e013e/builtin_stripe_secret_key.go#L100-L113
- github.com/lazyluke16-dotcom/richmond-rapid-connect/blob/5c057a98ccc24602917441f6c78f3a6aa15dc740/src/lib/stripe.server.ts#L12-L18
- github.com/baristaze/tadas/blob/b55571cd85ec5a7fe16bc463537980909f87ee4f/integrations/src/tadas/integrations/settings.py#L94-L114
Research log
- redact-secret/redact-secret-benchmarks#45Research issue
- redact-secret/redact-secret-benchmarks#127Research issue
- redact-secret/redact-secret#513Research issue
- redact-secret/redact-secret#1012Research issue
- redact-secret/redact-secret#1030Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/378581770a87751d72e27529796c4f790649fd00/docs/audits/evidence/1012/stripe-organization-api-key.md