redact-secret · Report
API key (tvly-)
tvly- with an optional dev- segment and a 32-character alphanumeric body; tvly-prod- and production key widths are unresolved.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-27 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^tvly-(?:dev-)?[A-Za-z0-9]{32}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Tool corroborated ·
tool-corroboration· current · observed 2026-09-26Pinned scanner rules are consistent with the contract grammar (2 artifacts: GitGuardian; noseyparker).
- docs.gitguardian.com/secrets-detection/secrets-detection-engine/detectors/specifics/tavily_api_keyscanner-rule-source · last read 2026-09-26 · latest outcome read · supports GitGuardian: Tavily API Key detector: prefixed, no length stated
- praetorian-inc/noseyparker @ main: crates/noseyparker/data/default/builtin/rules/tavily.ymlscanner-rule-source · last read 2026-09-26 · latest outcome read · supports noseyparker: np.tavily.1: \b(tvly-[a-zA-Z0-9]{32})\b (predates tvly-dev-, so it misses that form)
Provider documented ·
field-prefix· current · observed 2026-09-26prefix: tvly- (A placeholder, not a stated format.)
- docs.tavily.com/documentation/enterprise/key-infoprovider-documentation · last read 2026-09-26 · latest outcome read · supports prefix: tvly-
- docs.tavily.com/documentation/api-reference/introductionprovider-documentation · last read 2026-09-27 · latest outcome read · supports Authorization: Bearer tvly-YOUR_API_KEY (a placeholder)
Provider documented ·
field-dev-segment· current · observed 2026-09-26dev-segment: the optional dev- segment: tvly-dev- + body (Replaced or coexists with the bare form since 2025: undocumented. Positives carry both forms.)
- docs.tavily.com/documentation/enterprise/generate-keysprovider-documentation · last read 2026-09-27 · latest outcome read · supports truncated sample keys tvly-dev-...
Unresolved ·
field-body· current · observed 2026-09-26body: 32 alphanumeric characters after the last hyphen (One scanner rule and n=3 observed bodies; no provider statement.)
- praetorian-inc/noseyparker @ main: crates/noseyparker/data/default/builtin/rules/tavily.ymlscanner-rule-source · last read 2026-09-26 · latest outcome read · supports body: 32 alphanumeric characters after the last hyphen
- github.com/redact-secret/redact-secret/issues/786provider-documentation · last read 2026-09-26 · latest outcome read · supports three full-width samples in 2024-2025, maintainer observation
Unresolved ·
field-production-prefix· current · observed 2026-09-26production-prefix: whether tvly-prod- exists, and the width of production and enterprise expiring keys (No fixture asserts silence on tvly-prod- or on a longer body.)
- docs.tavily.com/documentation/enterprise/generate-keysprovider-documentation · last read 2026-09-27 · latest outcome read · supports the {key_type}-{expiration}-#{index} form is the key name, not the secret
- github.com/redact-secret/redact-secret/issues/786provider-documentation · last read 2026-09-26 · latest outcome read · supports production-prefix: whether tvly-prod- exists, and the width of production and enterprise expiring keys
Provider documented ·
field-transport· current · observed 2026-09-26transport: Authorization: Bearer, the api_key JSON body field, the TAVILY_API_KEY environment variable and the remote-MCP tavilyApiKey query parameter
- docs.tavily.com/documentation/api-reference/introductionprovider-documentation · last read 2026-09-27 · latest outcome read · supports transport: Authorization: Bearer, the api_key JSON body field, the TAVILY_API_KEY environment variable and the remote-MCP tavilyApiKey query parameter
- tavily-ai/tavily-js @ main: src/client.tsprovider-sdk-source · last read 2026-09-26 · latest outcome read · supports transport: Authorization: Bearer, the api_key JSON body field, the TAVILY_API_KEY environment variable and the remote-MCP tavilyApiKey query parameter
Provider documented ·
field-non-secrets· current · observed 2026-09-26non-secrets: the tvly CLI name, the key-name field and search request_id values are not credentials
- docs.tavily.com/documentation/enterprise/generate-keysprovider-documentation · last read 2026-09-27 · latest outcome read · supports non-secrets: the tvly CLI name, the key-name field and search request_id values are not credentials
- github.com/redact-secret/redact-secret/issues/786provider-documentation · last read 2026-09-26 · latest outcome read · supports non-secrets: the tvly CLI name, the key-name field and search request_id values are not credentials
Unresolved ·
listed-references· current · observed 2026-09-26The legacy contract lists 6 references without stating which property each supports.
- docs.tavily.com/documentation/enterprise/key-infoprovider-documentation · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- docs.tavily.com/documentation/enterprise/generate-keysprovider-documentation · last read 2026-09-27 · latest outcome read · supports Listed as a reference by the legacy contract
- docs.tavily.com/documentation/api-reference/introductionprovider-documentation · last read 2026-09-27 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/786provider-documentation · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/867issue-or-discussion · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- tavily-ai/tavily-js @ main: src/client.tsprovider-sdk-source · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
Tool corroborated ·
dossier-research· current · observed 2026-09-27Legacy dossier research (verdict ready, tier T2) cited 3 sources; the dossier does not attribute sources to individual properties.
- docs.tavily.com/documentation/enterprise/generate-keysprovider-documentation · last read 2026-09-27 · latest outcome read · supports Cited by the legacy dossier research for this family
- docs.tavily.com/documentation/api-reference/introductionprovider-documentation · last read 2026-09-27 · latest outcome read · supports Cited by the legacy dossier research for this family
- praetorian-inc/noseyparker @ 17e2b1380cd3fc36968a86295aa4490fd1baab03: crates/noseyparker/data/default/builtin/rules/tavily.ymlother · last read 2026-09-27 · latest outcome read · supports Cited by the legacy dossier research for this family
Unresolved ·
taxonomy-sources· current · observed 2026-09-27The legacy taxonomy lists 2 sources for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- docs.tavily.com/documentation/enterprise/generate-keysprovider-documentation · last read 2026-09-27 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
- docs.tavily.com/documentation/api-reference/introductionprovider-documentation · last read 2026-09-27 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
tvly-, an optionaldev-segment, then 32 alphanumeric characters[A-Za-z0-9]. Pre-2025 samples have nodev-; 2025 samples and the docs' truncated examples do. Whethertvly-prod-exists and the width of production and enterprise key bodies are unresolved (a third-party page says production keys begin plaintvly-).- Basis
- the spec and #867 record prefix T1, body T2 (the tier field above follows the assessment contract, T2, see Open questions). Provider docs show
tvly-only in a placeholder (Bearer tvly-YOUR_API_KEY) andtvly-dev-in truncated samples, with no length or alphabet; the SDKs do no validation. The 32-character body rests on the noseyparker rule, which predatesdev-and so misses it, and three observed samples. GitGuardian confirms "Prefixed" and states no length. No pinned scanner has a Tavily rule. - Issuance
- not attempted. The #786 checklist covers one development key (prefix, body width, charset), a production key if available, and masked display.
- Contract in core
- detector-families.md, section Together AI and Tavily (#867).
tvly-prod-and other widths stay unclaimed.
In this benchmark
- Fixtures
- 45
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
45 fixtures: 18 expect a redaction, 27 must stay quiet. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T2Tool-corroborated | 36 | 0 | 0 | 0 |
| T3Project policy | 9 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 45 | 16 | 2 | 1 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it | 45 | 11 | 0 | 4 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 45 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it | 45 | 18 | 0 | 0 |
Benchmark dossier questions
- Open caveat
- T1 is the tvly- prefix only; the 32-alphanumeric body is T2 (one scanner rule, three observed samples). Needs one issued development key; tvly-prod- and production width open (checklist in #786).
Looks like it, but isn't
- Collisions
- the
tvlycommand-line tool, key names such asdevelopment-...-#1,request_idvalues and the doc placeholder are benign.Bearer tvly-YOUR_API_KEYwas abearer-tokenfalse alarm fixed by #870 (Beta.10 epic #774).
Scanner rules for this family
No peer rule maps to this family
None of the reviewed peer scanners has a rule that can match a credential of this family.
None mapped
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
tavily-api-key-actions-envtavily · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
tavily-api-key-cli-flagtavily · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
tavily-api-key-compose-envtavily · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
tavily-api-key-curl-bearertavily · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
tavily-api-key-docs-bearer-placeholdertavily · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
tavily-api-key-dotenv-devtavily · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
tavily-api-key-export-baretavily · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
tavily-api-key-js-clienttavily · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
tavily-api-key-json-bodytavily · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
tavily-api-key-key-digest-encoded-valuetavily · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
tavily-api-key-key-shape-baretavily · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
tavily-api-key-key-shape-quotedtavily · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
tavily-api-key-key-shape-unicode-crlftavily · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
tavily-api-key-langchain-kwargtavily · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
tavily-api-key-mcp-client-envtavily · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
tavily-api-key-prefix-absent-twintavily · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
tavily-api-key-python-clienttavily · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
tavily-api-key-remote-mcp-querytavily · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
tavily-api-key-search-logtavily · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
tavily-api-key-tool-calltavily · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
tavily-api-key-uppercase-prefix-twintavily · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
tavily-api-key-yaml-configtavily · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
tavily-api-key-base64-etag-encoded-valuetavily · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
tavily-api-key-cli-and-prefix-prosetavily · prose-mention | Must not flagT3 · Project policy | Quiet |
tavily-api-key-cli-login-reference-referencetavily · templated-reference | Must not flagT3 · Project policy | Quiet |
tavily-api-key-dev-ellipsis-placeholdertavily · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
tavily-api-key-dev-word-run-near-misstavily · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
tavily-api-key-docs-url-public-idtavily · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
tavily-api-key-embedded-leading-twintavily · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
tavily-api-key-env-reference-referencetavily · templated-reference | Must not flagT3 · Project policy | Quiet |
tavily-api-key-hyphen-in-body-twintavily · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
tavily-api-key-key-name-public-idtavily · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
tavily-api-key-label-prosetavily · benign-lookalike | Must not flagT3 · Project policy | Quiet |
tavily-api-key-long-body-twintavily · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
tavily-api-key-masktavily · benign-lookalike | Must not flagT3 · Project policy | Quiet |
tavily-api-key-prefix-onlytavily · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
tavily-api-key-prefix-only-near-misstavily · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
tavily-api-key-referencetavily · benign-lookalike | Must not flagT3 · Project policy | Quiet |
tavily-api-key-request-id-public-idtavily · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
tavily-api-key-short-bodytavily · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
tavily-api-key-short-body-near-misstavily · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
tavily-api-key-short-body-twintavily · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
tavily-api-key-underscore-delimiter-twintavily · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
tavily-api-key-underscore-in-body-twintavily · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
tavily-api-key-x-run-placeholdertavily · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
Sources
Documentation and code
- docs.tavily.com/documentation/api-reference/introduction
- docs.tavily.com/documentation/enterprise/generate-keys
- github.com/praetorian-inc/noseyparker/blob/17e2b1380cd3fc36968a86295aa4490fd1baab03/crates/noseyparker/data/default/builtin/rules/tavily.yml
Research log
- redact-secret/redact-secret#786Research issue
- redact-secret/redact-secret#774Research issue
- redact-secret/redact-secret#867Research issue
- redact-secret/redact-secret-benchmarks#384Research issue