redact-secret · Report
Personal access token
Management-API personal access token, prefixed sbp_/sbp_v0_.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-21 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^sbp_(?:v0_)?[a-z0-9]{40}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Provider documented ·
provider-source· current · observed 2026-09-20sbp_/sbp_v0_ personal access tokens: documents the sbp_ prefix by example (sbp_fc...) and the classic-vs-scoped distinction; states no exact body grammar
- supabase.com/docs/guides/platform/personal-access-tokensprovider-documentation · last read 2026-09-21 · latest outcome read · supports documents the sbp_ prefix by example (sbp_fc...) and the classic-vs-scoped distinction; states no exact body grammar
Unresolved ·
tool-corroboration· current · observed 2026-09-20Pinned scanner rules are consistent with the contract grammar (1 artifact: trufflehog 3.97.4).
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/supabasetoken/supabasetoken.goscanner-rule-source · last read 2026-09-20 · latest outcome read · supports trufflehog 3.97.4: supabasetoken/supabasetoken
Provider documented ·
dossier-research· current · observed 2026-09-21Legacy dossier research (verdict ready, tier T1) cited 1 source; the dossier does not attribute sources to individual properties.
- supabase.com/docs/guides/platform/personal-access-tokensprovider-documentation · last read 2026-09-21 · latest outcome read · supports Cited by the legacy dossier research for this family
Provider documented ·
taxonomy-sources· current · observed 2026-09-21The legacy taxonomy lists 1 source for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- supabase.com/docs/guides/platform/personal-access-tokensprovider-documentation · last read 2026-09-21 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- prefix
sbp_orsbp_v0_, each followed by exactly 40 lowercase letters and digits. The provider page documents thesbp_prefix by example and the classic vs scoped distinction, not the body. The body grammar is TruffleHog's shipped shape forsbp_;sbp_v0_is the same body under a longer prefix. - Basis
- T1 on the prefix, T2 on the body (record in benchmarks#81, from the core decision of 2026-09-20).
- Issuance
- not attempted.
- Contract in core
- detector-families.md.
In this benchmark
- Fixtures
- 26
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
26 fixtures: 12 expect a redaction, 14 must stay quiet. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T1Provider-documented | 12 | 0 | 0 | 0 |
| T2Tool-corroborated | 11 | 0 | 0 | 0 |
| T3Project policy | 3 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine1 rule targets it | 26 | 10 | 1 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it | 26 | 9 | 0 | 0 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 26 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it | 26 | 4 | 0 | 0 |
Benchmark dossier questions
- Open caveat
- T1 on the sbp_ prefix (documented by example) only; the exact 40-character body for sbp_ and sbp_v0_ is tool-corroborated (TruffleHog's shape).
Looks like it, but isn't
- Collisions
- the secret key class above; evidence is kept independent in both directions.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| flare-redact · rules 1.6.1 | supabase_key | sbp_ + 40 hex |
| trufflehog · rules 3.97.4 | supabasetoken | sbp_ + 40 characters |
No rule maps to this family in gitleaks, openredaction.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
supabase-management-token-classic-shape-baresupabase · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
supabase-management-token-classic-shape-quotedsupabase · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
supabase-management-token-classic-shape-unicode-crlfsupabase · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
supabase-management-token-env-access-tokensupabase · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
supabase-management-token-github-actions-db-pushsupabase · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
supabase-management-token-management-api-bearersupabase · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
supabase-management-token-supabase-login-tokensupabase · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
supabase-management-token-terraform-provider-v0supabase · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
supabase-management-token-ts-management-clientsupabase · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
supabase-management-token-versioned-shape-baresupabase · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
supabase-management-token-versioned-shape-quotedsupabase · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
supabase-management-token-versioned-shape-unicode-crlfsupabase · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
supabase-management-token-classic-shape-bare-twinsupabase · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
supabase-management-token-classic-shape-quoted-twinsupabase · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
supabase-management-token-classic-shape-unicode-crlf-twinsupabase · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
supabase-management-token-invalid-alphabetsupabase · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
supabase-management-token-masksupabase · benign-lookalike | Must not flagT3 · Project policy | Quiet |
supabase-management-token-migration-checksum-encoded-valuesupabase · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
supabase-management-token-prefix-onlysupabase · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
supabase-management-token-project-ref-public-idsupabase · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
supabase-management-token-referencesupabase · benign-lookalike | Must not flagT3 · Project policy | Quiet |
supabase-management-token-short-bodysupabase · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
supabase-management-token-token-scope-note-prosesupabase · prose-mention | Must not flagT3 · Project policy | Quiet |
supabase-management-token-versioned-shape-bare-twinsupabase · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
supabase-management-token-versioned-shape-quoted-twinsupabase · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
supabase-management-token-versioned-shape-unicode-crlf-twinsupabase · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
Sources
Documentation and code
- supabase.com/docs/guides/platform/personal-access-tokens
Research log
- redact-secret/redact-secret#515Research issue
- redact-secret/redact-secret-benchmarks#81Research issue