Skip to content
Benchmarks

redact-secret · Report

Personal access token

Management-API personal access token, prefixed sbp_/sbp_v0_.

  • Supabase
  • Detectors: supabase-management-token
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictReady
  • Dossier evidence levelT1 · Provider-documented
  • Dossier researched2026-09-21
#81 backfilled the supabase-management-token detector (redact-secret#535). Deliberately independent of supabase:secret-key's evidence, per https://github.com/redact-secret/redact-secret/blob/de6add470321f40d7b1cb36808d9f4559e6c2e99/docs/decisions/2026-09-20-scope-supabase-management-token-and-secret-key-independence.md.

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · current
  • ResearchResearched
  • Researched2026-09-21

3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-21 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Descriptive pattern
^sbp_(?:v0_)?[a-z0-9]{40}$

Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.

Format facts

  • Provider documented · provider-source · current · observed 2026-09-20

    sbp_/sbp_v0_ personal access tokens: documents the sbp_ prefix by example (sbp_fc...) and the classic-vs-scoped distinction; states no exact body grammar

  • Unresolved · tool-corroboration · current · observed 2026-09-20

    Pinned scanner rules are consistent with the contract grammar (1 artifact: trufflehog 3.97.4).

  • Provider documented · dossier-research · current · observed 2026-09-21

    Legacy dossier research (verdict ready, tier T1) cited 1 source; the dossier does not attribute sources to individual properties.

  • Provider documented · taxonomy-sources · current · observed 2026-09-21

    The legacy taxonomy lists 1 source for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
prefix sbp_ or sbp_v0_, each followed by exactly 40 lowercase letters and digits. The provider page documents the sbp_ prefix by example and the classic vs scoped distinction, not the body. The body grammar is TruffleHog's shipped shape for sbp_; sbp_v0_ is the same body under a longer prefix.
Basis
T1 on the prefix, T2 on the body (record in benchmarks#81, from the core decision of 2026-09-20).
Issuance
not attempted.
Contract in core
detector-families.md.

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.
Fixtures
26
Left readable
0
Redacted too much
0
False alarms
0

26 fixtures: 12 expect a redaction, 14 must stay quiet. See every row

redact-secret fixture counts by evidence level
Evidence levelFixturesLeft readableToo muchFalse alarms
T1Provider-documented12000
T2Tool-corroborated11000
T3Project policy3000

Every scanner on the same fixtures

In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.

Counts per scanner on this family's fixtures
ScannerFixturesLeft readableToo muchFalse alarms
flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine1 rule targets it261010
gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it26900
redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped26000
trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it26400

Benchmark dossier questions

Things the sources do not settle. They are listed so nobody reads them as settled.
Open caveat
T1 on the sbp_ prefix (documented by example) only; the exact 40-character body for sbp_ and sbp_v0_ is tool-corroborated (TruffleHog's shape).

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
the secret key class above; evidence is kept independent in both directions.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.
Peer scanner rules that target this family
ScannerRuleWhat the rule matches
flare-redact · rules 1.6.1supabase_keysbp_ + 40 hex
trufflehog · rules 3.97.4supabasetokensbp_ + 40 characters

No rule maps to this family in gitleaks, openredaction.

26 of 26 rows

Fixtures in this family

26 rows, redact-secret's outcome on each. Rows that need a look come first (0), then the rest in corpus order. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Personal access token
FixtureKind and evidenceredact-secret
supabase-management-token-classic-shape-baresupabase · documented-format-literalMust redactT1 · Provider-documentedRedacted
supabase-management-token-classic-shape-quotedsupabase · documented-format-literalMust redactT1 · Provider-documentedRedacted
supabase-management-token-classic-shape-unicode-crlfsupabase · documented-format-literalMust redactT1 · Provider-documentedRedacted
supabase-management-token-env-access-tokensupabase · documented-format-literalMust redactT1 · Provider-documentedRedacted
supabase-management-token-github-actions-db-pushsupabase · documented-format-literalMust redactT1 · Provider-documentedRedacted
supabase-management-token-management-api-bearersupabase · documented-format-literalMust redactT1 · Provider-documentedRedacted
supabase-management-token-supabase-login-tokensupabase · documented-format-literalMust redactT1 · Provider-documentedRedacted
supabase-management-token-terraform-provider-v0supabase · documented-format-literalMust redactT1 · Provider-documentedRedacted
supabase-management-token-ts-management-clientsupabase · documented-format-literalMust redactT1 · Provider-documentedRedacted
supabase-management-token-versioned-shape-baresupabase · documented-format-literalMust redactT1 · Provider-documentedRedacted
supabase-management-token-versioned-shape-quotedsupabase · documented-format-literalMust redactT1 · Provider-documentedRedacted
supabase-management-token-versioned-shape-unicode-crlfsupabase · documented-format-literalMust redactT1 · Provider-documentedRedacted
supabase-management-token-classic-shape-bare-twinsupabase · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
supabase-management-token-classic-shape-quoted-twinsupabase · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
supabase-management-token-classic-shape-unicode-crlf-twinsupabase · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
supabase-management-token-invalid-alphabetsupabase · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
supabase-management-token-masksupabase · benign-lookalikeMust not flagT3 · Project policyQuiet
supabase-management-token-migration-checksum-encoded-valuesupabase · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
supabase-management-token-prefix-onlysupabase · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
supabase-management-token-project-ref-public-idsupabase · public-identifierMust not flagT2 · Tool-corroboratedQuiet
supabase-management-token-referencesupabase · benign-lookalikeMust not flagT3 · Project policyQuiet
supabase-management-token-short-bodysupabase · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
supabase-management-token-token-scope-note-prosesupabase · prose-mentionMust not flagT3 · Project policyQuiet
supabase-management-token-versioned-shape-bare-twinsupabase · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
supabase-management-token-versioned-shape-quoted-twinsupabase · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
supabase-management-token-versioned-shape-unicode-crlf-twinsupabase · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet

Sources

Researched 2026-09-21.

Documentation and code

Other Supabase families