redact-secret · Report
Bot token
digits:secret bot token.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-10-03 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^[0-9]{5,}:[A-Za-z0-9_-]{34,}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Provider documented ·
mutable-property-source· current · observed 2026-09-24Documentation for the one property varied in legacy twin fixtures (digits:secret bot token; provider-code delimiter and alphabet, tool-corroborated body length): Un-probeable record lifted 2026-09-24 (#207): twins mutate only the : delimiter and a / inside the secret, both rejected by Telegram's Bot API server acceptance check (tdlib/telegram-bot-api ClientManager.cpp, provider code on github.com), and the secret body below this contract's tool-corroborated 34-character floor. No twin shortens the bot id: provider code accepts 1 to 16 digits.
- github.com/redact-secret/redact-secret/issues/660provider-documentation · last read 2026-09-24 · latest outcome read · supports Un-probeable record lifted 2026-09-24 (#207): twins mutate only the : delimiter and a / inside the secret, both rejected by Telegram's Bot API server acceptance check (tdlib/telegram-bot-api ClientManager.cpp, provider code on github.com), and the secret body below this contract's tool-corroborated 34-character floor. No twin shortens the bot id: provider code accepts 1 to 16 digits.
Unresolved ·
tool-corroboration· current · observed 2026-09-22Pinned scanner rules are consistent with the contract grammar (1 artifact: trufflehog 3.97.4).
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/telegrambottoken/telegrambottoken.goscanner-rule-source · last read 2026-09-22 · latest outcome read · supports trufflehog 3.97.4: telegrambottoken/telegrambottoken
Provider documented ·
field-delimiter· current · observed 2026-09-22delimiter: a single : between the numeric bot id and the secret; the token contains no /
- tdlib/telegram-bot-api @ master: telegram-bot-api/ClientManager.cppprovider-sdk-source · last read 2026-09-22 · latest outcome read · supports Telegram's Bot API server acceptance check (code on github.com, not documentation)
Provider documented ·
field-bot-id· current · observed 2026-09-22bot id: digits, no leading 0, below 2^54; the contract floor is 5 digits and real ids are usually 8–10 (Provider code allows 1–16 digits, so no fixture asserts silence on a short id.)
- tdlib/telegram-bot-api @ master: telegram-bot-api/ClientManager.cppprovider-sdk-source · last read 2026-09-22 · latest outcome read · supports bot id: digits, no leading 0, below 2^54; the contract floor is 5 digits and real ids are usually 8–10
Unresolved ·
field-secret-body· current · observed 2026-09-22secret body: [A-Za-z0-9_-], at least 34 characters: docs examples show 34, community reports and most tools say 35, usually starting AA
- github.com/redact-secret/redact-secret/issues/660provider-documentation · last read 2026-09-24 · latest outcome read · supports secret body: [A-Za-z0-9_-], at least 34 characters: docs examples show 34, community reports and most tools say 35, usually starting AA
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/telegrambottoken/telegrambottoken.goscanner-rule-source · last read 2026-09-22 · latest outcome read · supports secret body: [A-Za-z0-9_-], at least 34 characters: docs examples show 34, community reports and most tools say 35, usually starting AA
Tool corroborated ·
dossier-research· current · observed 2026-09-24Legacy dossier research (verdict ready, tier T2) cited 4 sources; the dossier does not attribute sources to individual properties.
- core.telegram.org/bots/featuresprovider-documentation · last read 2026-09-24 · latest outcome read · supports Cited by the legacy dossier research for this family
- core.telegram.org/bots/apiprovider-documentation · last read 2026-10-03 · latest outcome read · supports Cited by the legacy dossier research for this family
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/660/README.mdproject-research-note · last read 2026-09-24 · latest outcome read · supports Final research evidence recorded by the legacy dossier
- tdlib/telegram-bot-api @ e3e9dd8e5b3d7ab8537cd5a10dc31d5ffa8f82d1: telegram-bot-api/ClientManager.cppother · last read 2026-10-03 · latest outcome read · supports Cited by the legacy dossier research for this family
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- the bot's numeric user id, a literal
:, then a secret from[A-Za-z0-9_-]. The Bot API server rejects a token that lacks:, contains/, is longer than 80 characters, starts with0, or whose id is not in (0, 2^54). Real ids are usually 8 to 10 digits. Secret width is disputed: all three Telegram examples show 34 characters, while most tools and community reports say 35; two of three Telegram examples and most scanner rules show a leadingAAorA, which no source explains. - Basis
- T2.
tdlib/telegram-bot-apiClientManager.cpp(server acceptance code, not documentation), TruffleHog telegrambottoken and detect-secrets (\d{8,10}:[0-9A-Za-z_-]{35}). The TDLib maintainer answered in issue 300 on that repo that "everything can completely change in the future", so Telegram deliberately publishes no format. - Issuance
- not attempted; a fresh BotFather token would settle width and lead.
- Contract in core
- detector-families.md; evidence #660 record.
In this benchmark
- Fixtures
- 40
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
40 fixtures: 14 expect a redaction, 22 must stay quiet, 4 record project policy. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T1Provider-documented | 4 | 0 | 0 | 0 |
| T2Tool-corroborated | 21 | 0 | 0 | 0 |
| T3Project policy | 15 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine1 rule targets it | 40 | 5 | 0 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it | 40 | 16 | 0 | 0 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 40 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it | 40 | 7 | 0 | 0 |
Benchmark dossier questions
- Open caveat
- Telegram documents only example tokens and says the format may change; the secret width (34 in docs, 35 in tools) and the leading AA are unexplained; no fresh token measured.
Looks like it, but isn't
- Collisions
- any short
digits:stringpair; the numeric id part alone is a weak marker, so the secret body carries the discrimination.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| flare-redact · rules 1.6.1 | telegram_bot_token | 8-10 digits + : + 34-46 characters |
| gitleaks · rules 8.30.1 | telegram-bot-api-token | telegr keyword + digits + :A + 34 characters |
| trufflehog · rules 3.97.4 | telegrambottoken | telegram keyword + 8-10 digits + : + 35 characters |
No rule maps to this family in openredaction.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
telegram-bot-token-bomtelegram · multibyte-text-offsets | Must redactT2 · Tool-corroborated | Redacted |
telegram-bot-token-bot-api-urltelegram · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
telegram-bot-token-bot-yamltelegram · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
telegram-bot-token-botfather-replytelegram · documented-format-literal | Project policyT3 · Project policy | Redacted |
telegram-bot-token-compose-envtelegram · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
telegram-bot-token-jsontelegram · structured-text-value | Must redactT2 · Tool-corroborated | Redacted |
telegram-bot-token-markdowntelegram · markdown-and-comment-value | Must redactT2 · Tool-corroborated | Redacted |
telegram-bot-token-no-final-newlinetelegram · value-at-input-edges | Must redactT2 · Tool-corroborated | Redacted |
telegram-bot-token-ptb-buildertelegram · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
telegram-bot-token-pythontelegram · source-code-string-literal | Must redactT2 · Tool-corroborated | Redacted |
telegram-bot-token-shape-1-baretelegram · documented-format-literal | Project policyT3 · Project policy | Redacted |
telegram-bot-token-shape-1-quotedtelegram · documented-format-literal | Project policyT3 · Project policy | Redacted |
telegram-bot-token-shape-1-unicode-crlftelegram · documented-format-literal | Project policyT3 · Project policy | Redacted |
telegram-bot-token-single-quotestelegram · quoted-value-extent | Must redactT2 · Tool-corroborated | Redacted |
telegram-bot-token-tomltelegram · structured-text-value | Must redactT2 · Tool-corroborated | Redacted |
telegram-bot-token-yamltelegram · structured-text-value | Must redactT2 · Tool-corroborated | Redacted |
telegram-bot-token-actions-envtelegram · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
telegram-bot-token-actions-secret-referencetelegram · templated-reference | Must not flagT3 · Project policy | Quiet |
telegram-bot-token-angle-brackets-placeholdertelegram · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
telegram-bot-token-bot-username-public-idtelegram · public-identifier | Must not flagT3 · Project policy | Quiet |
telegram-bot-token-botfather-note-prosetelegram · prose-mention | Must not flagT3 · Project policy | Quiet |
telegram-bot-token-chat-id-public-idtelegram · public-identifier | Must not flagT3 · Project policy | Quiet |
telegram-bot-token-envtelegram · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
telegram-bot-token-label-prosetelegram · benign-lookalike | Must not flagT3 · Project policy | Quiet |
telegram-bot-token-masktelegram · benign-lookalike | Must not flagT3 · Project policy | Quiet |
telegram-bot-token-masked-placeholdertelegram · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
telegram-bot-token-missing-delimiter-twintelegram · boundary-violation | Must not flagT1 · Provider-documented · twin | Quiet |
telegram-bot-token-plus-body-twintelegram · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
telegram-bot-token-prefix-onlytelegram · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
telegram-bot-token-referencetelegram · benign-lookalike | Must not flagT3 · Project policy | Quiet |
telegram-bot-token-short-bodytelegram · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
telegram-bot-token-short-body-docs-width-twintelegram · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
telegram-bot-token-short-body-twintelegram · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
telegram-bot-token-short-body-yaml-twintelegram · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
telegram-bot-token-slash-body-env-twintelegram · wrong-alphabet | Must not flagT1 · Provider-documented · twin | Quiet |
telegram-bot-token-slash-body-twintelegram · wrong-alphabet | Must not flagT1 · Provider-documented · twin | Quiet |
telegram-bot-token-timestamp-colon-near-misstelegram · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
telegram-bot-token-underscore-delimiter-twintelegram · boundary-violation | Must not flagT1 · Provider-documented · twin | Quiet |
telegram-bot-token-update-json-public-idtelegram · public-identifier | Must not flagT3 · Project policy | Quiet |
telegram-bot-token-url-template-placeholdertelegram · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
Sources
Documentation and code
- core.telegram.org/bots/api
- core.telegram.org/bots/features
- github.com/tdlib/telegram-bot-api/blob/e3e9dd8e5b3d7ab8537cd5a10dc31d5ffa8f82d1/telegram-bot-api/ClientManager.cpp
Research log
- redact-secret/redact-secret#660Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/8b6a5fde52ecb4dfce13f09c7a947062d21483c7/docs/audits/evidence/660/README.md