redact-secret · Report
Live restricted key
Live-mode restricted-permission key, prefixed rk_live_.
Research record
Format revisions
- Revision 1
stripe:restricted-key-live@1current · draft, not reviewed · superseded by @2 · the family's current revision - Revision 2
stripe:restricted-key-live@2proposed · draft, not reviewed · supersedes @1
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-10-04 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
Shape not recorded.
Format facts
Provider documented ·
provider-source· current · observed 2026-09-17sk_/rk_/pk_ key types: sk_live_/sk_test_/rk_live_/rk_test_ secret and restricted keys, pk_ publishable keys documented as safe to expose, sk_org_ organization keys; 32-character body is tool-corroborated [Legacy contract 'stripe-token' is shared by 4 families; this statement is not specific to one of them.]
- docs.stripe.com/keysprovider-documentation · last read 2026-10-04 · latest outcome read · supports sk_live_/sk_test_/rk_live_/rk_test_ secret and restricted keys, pk_ publishable keys documented as safe to expose, sk_org_ organization keys; 32-character body is tool-corroborated
Tool corroborated ·
tool-corroboration· current · observed 2026-09-17Pinned scanner rules are consistent with the contract grammar (2 artifacts: gitleaks 8.30.1; trufflehog 3.97.4). [Legacy contract 'stripe-token' is shared by 4 families; this statement is not specific to one of them.]
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports gitleaks 8.30.1: gitleaks.toml
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/stripe/stripe.goscanner-rule-source · last read 2026-09-17 · latest outcome read · supports trufflehog 3.97.4: stripe/stripe
Provider documented ·
field-organization-prefix· current · observed 2026-09-29organization-prefix: sk_org_ (organization API key; no rk_org_ sibling) (Prefix only. Not issuance-evidenced: no organization key has been issued or observed.) [Legacy contract 'stripe-token' is shared by 4 families; this statement is not specific to one of them.]
- docs.stripe.com/keys/organization-api-keysprovider-documentation · last read 2026-09-29 · latest outcome read · supports names the organization key type; "support sandboxes and live mode"
Unresolved ·
field-organization-mode-segment· current · observed 2026-09-30organization-mode-segment: optional live_ or test_ directly after sk_org_ (sk_org_live_, sk_org_test_), claimed by core as the same stripe finding as sk_org_ (Two independent applications, one evidence class; no Stripe page, SDK or peer scanner rule states a mode segment. Not issuance-evidenced. The fixtures for these forms are policy/T3 rows on the core support-policy floor and assert no provider grammar.) [Legacy contract 'stripe-token' is shared by 4 families; this statement is not specific to one of them.]
- koki-develop/mask-go @ 1b861d7ac421b392a5bb962207fd1886b28e013e: builtin_stripe_secret_key.gothird-party-writeup · last read 2026-09-30 · latest outcome read · supports accepts sk_org_live_, sk_org_test_ and bare sk_org_ · #L100-L113
- lazyluke16-dotcom/richmond-rapid-connect @ 5c057a98ccc24602917441f6c78f3a6aa15dc740: src/lib/stripe.server.tsthird-party-writeup · last read 2026-09-30 · latest outcome read · supports branches on sk_org_test_ and sk_org_live_ · #L12-L18
- github.com/redact-secret/redact-secret/issues/1030third-party-writeup · last read 2026-09-30 · latest outcome read · supports organization-mode-segment: optional live_ or test_ directly after sk_org_ (sk_org_live_, sk_org_test_), claimed by core as the same stripe finding as sk_org_
Unresolved ·
field-organization-body-floor· current · observed 2026-09-30organization-body-floor: at least 20 [A-Za-z0-9] after sk_org_ or after the mode segment; fewer than 20, or a _ or - inside the run, is not claimed (A project support-policy floor, not a provider statement: no source gives the body length or alphabet. Not issuance-evidenced. No fixture asserts a body at or above the floor as provider-valid; positives score policy/T3 and the shorter-than-20 and punctuated-body controls score as policy-floor controls (T3), never as provider near-misses.) [Legacy contract 'stripe-token' is shared by 4 families; this statement is not specific to one of them.]
- github.com/redact-secret/redact-secret/issues/1030third-party-writeup · last read 2026-09-30 · latest outcome read · supports core support-policy floor, product redact-secret#1101
Provider documented ·
field-rk-org-and-account-keys· current · observed 2026-09-29rk-org-and-account-keys: rk_org_ does not exist per Stripe; sk_live_/sk_test_ are the account-scoped sibling families and are not organization keys (Keeps the three sk_org_ forms apart from stripe:secret-key-live and stripe:secret-key-test.) [Legacy contract 'stripe-token' is shared by 4 families; this statement is not specific to one of them.]
- docs.stripe.com/keys/organization-api-keysprovider-documentation · last read 2026-09-29 · latest outcome read · supports rk-org-and-account-keys: rk_org_ does not exist per Stripe; sk_live_/sk_test_ are the account-scoped sibling families and are not organization keys
Provider documented ·
dossier-research· current · observed 2026-09-20Legacy dossier research (verdict ready, tier T1) cited 1 source; the dossier does not attribute sources to individual properties.
- docs.stripe.com/keysprovider-documentation · last read 2026-10-04 · latest outcome read · supports Cited by the legacy dossier research for this family
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- prefix
rk_live_. - Basis
- T1 on the provider-documented prefix (docs.stripe.com/keys), per the shipped
stripe-tokencontract in the benchmarks assessment (re-checked 2026-09-20, benchmarks#33, closed by PR #34). The page states nothing about body length or alphabet; the 32-character body is tool-corroborated only and stays undecided here.
In this benchmark
- Fixtures
- 5
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
5 fixtures: 4 expect a redaction, 1 must stay quiet. All at the T1 level, provider-documented. See every row
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine1 rule targets it | 5 | 0 | 0 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it | 5 | 0 | 0 | 0 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 5 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled2 rules target it | 5 | 0 | 0 | 0 |
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| flare-redact · rules 1.6.1 | stripe_key | sk_ or rk_ + live or test + 16-64 characters |
| gitleaks · rules 8.30.1 | stripe-access-token | sk_ or rk_ + test, live or prod + 10-99 characters |
| trufflehog · rules 3.97.4 | stripe | sk_live_ or rk_live_ + 20-247 characters |
| trufflehog · rules 3.97.4 | stripepaymentintent | sk_live_ or rk_live_ + 20-247 characters |
No rule maps to this family in openredaction.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
stripe-token-compose-restrictedstripe · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
stripe-token-publishable-prefix-twinstripe · public-sibling-prefix | Must not flagT1 · Provider-documented · twin | Quiet |
stripe-token-shape-4-barestripe · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
stripe-token-shape-4-quotedstripe · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
stripe-token-shape-4-unicode-crlfstripe · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
Sources
Documentation and code
- docs.stripe.com/keys
Research log
- redact-secret/redact-secret-benchmarks#33Research issue