Skip to content
Benchmarks

redact-secret · Report

Organization API key

Organization-scoped secret key, prefixed sk_org_.

  • Stripe
  • Detectors: none mapped
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictIssuance-gated
  • Dossier evidence levelT1 · Provider-documented
  • Dossier researched2026-09-29
stripe-token's live/test secret-key pattern does not claim sk_org_ values. Since redact-secret#1030 (product #1101) classifyFixture resolves sk_org_, sk_org_live_ and sk_org_test_ followed by at least 20 [A-Za-z0-9] to this one family as policy/T3 rows at core's support-policy floor (not a provider grammar; no organization key issued or observed); other sk_org_ values and whsec_ stay pending.

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · proposed, none current
  • ResearchResearched
  • Researched2026-09-29

What blocks the research

  • Issuance-gatedWhether a live_ or test_ segment follows sk_org_, and the body length and alphabet; needs one organization API key measured (structure only). Product gap redact-secret#1030 is filed.

2 events in the review history: 1 observed, 1 reviewed. Latest: observed on 2026-09-29 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Shape not recorded.

Format facts

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
prefix sk_org_, named on Stripe's key-types page and its organization keys page, which says the keys "support sandboxes and live mode" and have no rk_org_ sibling. No Stripe page, SDK, mock or peer scanner rule gives a literal key, a body length or an alphabet. Two independent applications branch on sk_org_live_ and sk_org_test_, so a mode segment after the prefix is plausible but unconfirmed.
Basis
- provider docs (T1, prefix): the keys page and the organization API keys page. - provider code (R6, substring only): stripe-cli listen.go tests for the substring sk_org, no grammar. - independent implementations (one class): mask-go accepts sk_org_live_, sk_org_test_ and bare sk_org_; richmond-rapid-connect branches on sk_org_test_ and sk_org_live_; tadas lists both and also rk_org_, which Stripe says does not exist. - Not evidence: three committed sk_org_live_-shaped values in unrelated repositories, withheld; they are a lead that the live_ segment occurs. - Searched with nothing further: eleven Stripe docs pages, nine Stripe SDK and mock repositories, and the rules of gitleaks, trufflehog, betterleaks, CredSweeper, noseyparker and GitLab. GitHub's partner list has no organization row.
Issuance
needs a Stripe organization. Create one organization API key in a sandbox (and read a live one if available) and record only the bytes after sk_org_ (test_, live_ or none), the body length, whether the body is only [A-Za-z0-9] and the total length; then roll or delete the key.
Contract in core
core claims sk_org_ + at least 20 [A-Za-z0-9], and since product PR #1101 (merge bfc608cce75f79f6a5cab037d7e558ba629777f6, closing #1030) also sk_org_live_ and sk_org_test_ + at least 20 alphanumerics, as the same stripe finding as sk_org_. This is the support-policy floor: it follows the optional mode segment that two independent applications branch on, not a provider-stated grammar, and no issued key has been observed. Fixture framing (decided 2026-09-30, benchmarks#1030): because the body after the segment is not provider-decided, the benchmarks cover the three forms as a policy-floor contract part, never as a provider grammar. Fixtures are policy/T3 (never T1 or T2 must-redact), the shorter-than-20 and punctuated-body controls score as policy-floor controls, and the stripe-token contract rows mark every sk_org_ claim not issuance-evidenced, per decision 2026-09-24-stop-asserting-provider-undecided-format-properties. Measured status stays derived. Living spec: detector-families.md.

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.
Fixtures
28
Left readable
0
Redacted too much
0
False alarms
0

28 fixtures: 10 must stay quiet, 18 record project policy. All at the T3 level, project policy. See every row

Every scanner on the same fixtures

In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.

Counts per scanner on this family's fixtures
ScannerFixturesLeft readableToo muchFalse alarms
flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it281800
gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it281800
redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectorsNo detector mapped28000
trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it281800

Benchmark dossier questions

Things the sources do not settle. They are listed so nobody reads them as settled.
Blocked by
Whether a live_ or test_ segment follows sk_org_, and the body length and alphabet; needs one organization API key measured (structure only). Product gap redact-secret#1030 is filed.
Open caveat
nothing beyond the sk_org prefix is provider-stated; an interim rule is a policy floor, not a grammar.

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
none worth naming for the prefix, which is unique to Stripe organization keys. rk_org_ does not exist per Stripe and must stay excluded; sk_live_/sk_test_ are the account-scoped siblings.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.

No peer rule maps to this family

None of the reviewed peer scanners has a rule that can match a credential of this family.

None mapped

28 of 28 rows

Fixtures in this family

28 rows, redact-secret's outcome on each. Rows that need a look come first (0), then the rest in corpus order. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Organization API key
FixtureKind and evidenceredact-secret
stripe-token-policy-org-bare-floor-barestripe · documented-format-literalProject policyT3 · Project policyRedacted
stripe-token-policy-org-bare-floor-quotedstripe · documented-format-literalProject policyT3 · Project policyRedacted
stripe-token-policy-org-bare-floor-unicode-crlfstripe · documented-format-literalProject policyT3 · Project policyRedacted
stripe-token-policy-org-live-above-barestripe · documented-format-literalProject policyT3 · Project policyRedacted
stripe-token-policy-org-live-above-quotedstripe · documented-format-literalProject policyT3 · Project policyRedacted
stripe-token-policy-org-live-above-unicode-crlfstripe · documented-format-literalProject policyT3 · Project policyRedacted
stripe-token-policy-org-live-floor-barestripe · documented-format-literalProject policyT3 · Project policyRedacted
stripe-token-policy-org-live-floor-quotedstripe · documented-format-literalProject policyT3 · Project policyRedacted
stripe-token-policy-org-live-floor-unicode-crlfstripe · documented-format-literalProject policyT3 · Project policyRedacted
stripe-token-policy-org-test-above-barestripe · documented-format-literalProject policyT3 · Project policyRedacted
stripe-token-policy-org-test-above-quotedstripe · documented-format-literalProject policyT3 · Project policyRedacted
stripe-token-policy-org-test-above-unicode-crlfstripe · documented-format-literalProject policyT3 · Project policyRedacted
stripe-token-policy-org-test-floor-barestripe · documented-format-literalProject policyT3 · Project policyRedacted
stripe-token-policy-org-test-floor-quotedstripe · documented-format-literalProject policyT3 · Project policyRedacted
stripe-token-policy-org-test-floor-unicode-crlfstripe · documented-format-literalProject policyT3 · Project policyRedacted
stripe-token-shape-5-barestripe · documented-format-literalProject policyT3 · Project policyRedacted
stripe-token-shape-5-quotedstripe · documented-format-literalProject policyT3 · Project policyRedacted
stripe-token-shape-5-unicode-crlfstripe · documented-format-literalProject policyT3 · Project policyRedacted
stripe-token-policy-org-bare-19-controlstripe · benign-lookalikeMust not flagT3 · Project policyQuiet
stripe-token-policy-org-live-19-controlstripe · benign-lookalikeMust not flagT3 · Project policyQuiet
stripe-token-policy-org-live-embedded-controlstripe · benign-lookalikeMust not flagT3 · Project policyQuiet
stripe-token-policy-org-live-no-body-controlstripe · benign-lookalikeMust not flagT3 · Project policyQuiet
stripe-token-policy-org-live-underscore-controlstripe · benign-lookalikeMust not flagT3 · Project policyQuiet
stripe-token-policy-org-rk-bare-controlstripe · benign-lookalikeMust not flagT3 · Project policyQuiet
stripe-token-policy-org-rk-live-controlstripe · benign-lookalikeMust not flagT3 · Project policyQuiet
stripe-token-policy-org-test-19-controlstripe · benign-lookalikeMust not flagT3 · Project policyQuiet
stripe-token-policy-org-test-hyphen-controlstripe · benign-lookalikeMust not flagT3 · Project policyQuiet
stripe-token-policy-org-test-no-body-controlstripe · benign-lookalikeMust not flagT3 · Project policyQuiet

Sources

Researched 2026-09-29.

Documentation and code

Research log

Other Stripe families