Skip to content
Benchmarks

redact-secret · Report

Webhook signing secret

Webhook endpoint signing secret, prefixed whsec_.

  • Stripe
  • Detectors: stripe-webhook-signing-secret
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictReady
  • Dossier evidence levelT1 · Provider-documented
  • Dossier researched2026-09-27
Same classifyFixture guard as the organization API key covers whsec_ values; stripe-token's pattern does not match them. Measured as the context-gated Beta.8 arrival family stripe-webhook-signing-secret (#211, research #224): Stripe documents the whsec_ prefix only; the body width and alphabet stay provisional (32 alphanumerics is a provider example, not a grammar; Stripe's own scrubber admits + / =). Scored as the arrival family stripe-webhook-signing-secret (#730; docs/decisions/2026-09-24-score-arrival-families-by-finding-type.md): the product types it inside the shared stripe-token detector as stripe_webhook_signing_secret, so its findings carry the arrival id and its status comes from its own contract, profile and ledger rows. stripe-webhook-signing-secret is not a registry detector id.

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · current
  • ResearchResearched
  • Researched2026-09-27

3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-27 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Descriptive pattern
^whsec_[A-Za-z0-9+/]{32,}={0,2}$

Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.

Format facts

  • Provider documented · provider-source · current · observed 2026-09-24

    whsec_ webhook endpoint signing secret: the whsec_ prefix and the per-endpoint configuration context; no body length or alphabet

    • docs.stripe.com/webhooksprovider-documentation · last read 2026-09-27 · latest outcome read · supports the whsec_ prefix and the per-endpoint configuration context; no body length or alphabet
  • Provider documented · field-prefix · current · observed 2026-09-24

    prefix: Webhook signing secrets begin with the literal whsec_ (Dashboard, API and CLI; snapshot and thin destinations alike).

    • docs.stripe.com/webhooks/signatureprovider-documentation · last read 2026-09-27 · latest outcome read · supports Dashboard and CLI secrets both start with whsec_ but differ.
    • docs.stripe.com/webhooksprovider-documentation · last read 2026-09-27 · latest outcome read · supports Dashboard "Reveal secret": a signing secret beginning with whsec_; v2 event destinations return a value that "starts with whsec_".
  • Provider documented · field-context · current · observed 2026-09-24

    context: The secret is configured per webhook endpoint (STRIPE_WEBHOOK_SECRET / endpoint_secret / signing_secret) and passed to the SDK signature verifier. (Context-gated: whsec_ is also issued by Svix/Standard Webhooks (base64, 24–64 bytes), so the prefix alone does not attribute a value to Stripe. Every positive carries a same-line Stripe context; non-Stripe whsec_ values are neither positives nor controls here (#224 left that contract decision open).)

    • docs.stripe.com/keysprovider-documentation · last read 2026-10-04 · latest outcome read · supports "Webhook signing secrets aren't API keys—they're per-webhook secrets."
    • docs.stripe.com/webhooksprovider-documentation · last read 2026-09-27 · latest outcome read · supports Code samples read the endpoint secret into the constructEvent / construct_event verifier.
  • Provider documented · field-body-alphabet · current · observed 2026-09-24

    body-alphabet: The body may be alphanumeric or base64 with + / and = padding. (Stripe's own code disagrees with itself. Positives are alphanumeric (satisfying every candidate); the contract pattern admits + / = so no fixture asserts silence on them.)

  • Provider documented · field-body-length · current · observed 2026-09-24

    body-length: The body is at least 32 characters; 32 and 64 are the widths sources show. (Not exhaustive (#224): an example is not a grammar. The 32 floor only keeps short documentation placeholders out of the pattern; no twin mutates width, and no zero-filled 64-character placeholder is authored as a control because it would satisfy the pattern.)

  • Provider documented · field-mode-marker · current · observed 2026-09-24

    mode-marker: No live/test marker in the value.

    • docs.stripe.com/webhooksprovider-documentation · last read 2026-09-27 · latest outcome read · supports Test and live endpoints have different secrets; the prefix carries no mode segment.
  • Unresolved · field-checksum · current · observed 2026-09-24

    checksum: Whether the body has a checksum or embedded id.

    • docs.stripe.com/webhooksprovider-documentation · last read 2026-09-27 · latest outcome read · supports Nothing stated. SDKs HMAC with the whole string as UTF-8 bytes and never decode it (stripe-go/node/python webhook code).
  • Unresolved · listed-references · current · observed 2026-09-24

    The legacy contract lists 5 references without stating which property each supports.

  • Provider documented · dossier-research · current · observed 2026-09-27

    Legacy dossier research (verdict ready, tier T1) cited 5 sources; the dossier does not attribute sources to individual properties.

  • Provider documented · taxonomy-sources · current · observed 2026-09-27

    The legacy taxonomy lists 1 source for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.

    • docs.stripe.com/webhooksprovider-documentation · last read 2026-09-27 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
prefix whsec_ followed by a body of at least 32 Base64-alphabet characters, optional trailing = padding. Stripe documents only the prefix (in the Dashboard and v2 event destination flows, and for CLI secrets, which are "different" from Dashboard ones) and calls signing secrets "not API keys". The API object example shows 32 mixed-case alphanumerics; a CLI docs placeholder has 14; an SDK example uses 64 zeros. Stripe's own CLI scrubber admits +, / and =, while a second regex in the same repository accepts letters and digits only.
Basis
T1 for the prefix and configuration context (provider docs). Body: provider code and example plus scanner rules, contradictory on alphabet. SDKs use the whole string, prefix included, as the HMAC key and never Base64-decode it.
Issuance
not attempted. Sandbox Dashboard or stripe listen --print-secret is free; checklist in benchmarks#224. There is no live or test segment.
Contract in core
detector-families.md (frozen in the #726 record as context-gated for qualification; the #729 implementation detects the prefix bare, as attribution is a benchmark concept).

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.
Fixtures
29
Left readable
0
Redacted too much
0
False alarms
0

29 fixtures: 3 expect a redaction, 15 must stay quiet, 11 record project policy. See every row

redact-secret fixture counts by evidence level
Evidence levelFixturesLeft readableToo muchFalse alarms
T1Provider-documented1000
T2Tool-corroborated9000
T3Project policy16000
T0Pending review3000

Every scanner on the same fixtures

In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.

Counts per scanner on this family's fixtures
ScannerFixturesLeft readableToo muchFalse alarms
flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine1 rule targets it29000
gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it29501
redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped29000
trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it291100

Benchmark dossier questions

Things the sources do not settle. They are listed so nobody reads them as settled.
Open caveat
T1 on the whsec_ prefix and Stripe context only; body width and alphabet are not provider-stated, and Svix and Standard Webhooks issue whsec_ secrets too.

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
Svix and Standard Webhooks also use whsec_ (Base64 of 24 to 64 bytes, decoded before use), plus asymmetric siblings whsk_/whpk_. Public or non-secret values nearby: we_ endpoint ids, ed_ event destination ids, evt_ ids, Stripe-Signature digests, pk_ keys.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.
Peer scanner rules that target this family
ScannerRuleWhat the rule matches
flare-redact · rules 1.6.1stripe_webhook_secretwhsec_ + 32-64 characters

No rule maps to this family in gitleaks, openredaction, trufflehog.

29 of 29 rows

Fixtures in this family

29 rows, redact-secret's outcome on each. Rows that need a look come first (0), then the rest in corpus order. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Webhook signing secret
FixtureKind and evidenceredact-secret
stripe-webhook-signing-secret-actions-envstripe · documented-format-literalProject policyT3 · Project policyRedacted
stripe-webhook-signing-secret-compose-webhook-secretstripe · documented-format-literalProject policyT3 · Project policyRedacted
stripe-webhook-signing-secret-dotenv-webhook-secretstripe · documented-format-literalProject policyT3 · Project policyRedacted
stripe-webhook-signing-secret-endpoint-create-responsestripe · documented-format-literalProject policyT3 · Project policyRedacted
stripe-webhook-signing-secret-event-destination-create-responsestripe · documented-format-literalProject policyT3 · Project policyRedacted
stripe-webhook-signing-secret-export-webhook-secretstripe · documented-format-literalProject policyT3 · Project policyRedacted
stripe-webhook-signing-secret-node-construct-event-widestripe · documented-format-literalProject policyT3 · Project policyRedacted
stripe-webhook-signing-secret-publishable-key-public-idstripe · public-identifierMust not flagT2 · Tool-corroboratedQuiet
stripe-webhook-signing-secret-python-construct-eventstripe · documented-format-literalProject policyT3 · Project policyRedacted
stripe-webhook-signing-secret-rails-credentials-rollingstripe · documented-format-literalProject policyT3 · Project policyRedacted
stripe-webhook-signing-secret-stripe-listen-readystripe · documented-format-literalProject policyT3 · Project policyRedacted
stripe-webhook-signing-secret-webhook-verifier-logstripe · documented-format-literalProject policyT3 · Project policyRedacted
stripe-token-shape-6-barestripe · unsettled-evidence-inputPending reviewT0 · PendingUnscored
stripe-token-shape-6-quotedstripe · unsettled-evidence-inputPending reviewT0 · PendingUnscored
stripe-token-shape-6-unicode-crlfstripe · unsettled-evidence-inputPending reviewT0 · PendingUnscored
stripe-webhook-signing-secret-docs-sentence-prosestripe · prose-mentionMust not flagT3 · Project policyQuiet
stripe-webhook-signing-secret-dotenv-webhook-secret-public-prefix-twinstripe · public-sibling-prefixMust not flagT1 · Provider-documented · twinQuiet
stripe-webhook-signing-secret-ellipsis-placeholderstripe · documentation-placeholderMust not flagT3 · Project policyQuiet
stripe-webhook-signing-secret-endpoint-create-response-boundary-twinstripe · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
stripe-webhook-signing-secret-endpoint-object-public-idstripe · public-identifierMust not flagT2 · Tool-corroboratedQuiet
stripe-webhook-signing-secret-event-destination-log-public-idstripe · public-identifierMust not flagT2 · Tool-corroboratedQuiet
stripe-webhook-signing-secret-export-webhook-secret-case-twinstripe · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
stripe-webhook-signing-secret-fill-in-placeholderstripe · documentation-placeholderMust not flagT3 · Project policyQuiet
stripe-webhook-signing-secret-masked-placeholderstripe · documentation-placeholderMust not flagT3 · Project policyQuiet
stripe-webhook-signing-secret-prefix-only-near-missstripe · format-near-missMust not flagT2 · Tool-corroboratedQuiet
stripe-webhook-signing-secret-print-secret-substitution-referencestripe · templated-referenceMust not flagT3 · Project policyQuiet
stripe-webhook-signing-secret-python-construct-event-separator-twinstripe · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
stripe-webhook-signing-secret-stripe-signature-header-encoded-valuestripe · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
stripe-webhook-signing-secret-webhook-verifier-log-alphabet-twinstripe · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet

Sources

Researched 2026-09-27.

Other Stripe families