redact-secret · Report
Project API key (tgp_v1_)
tgp_v1_ + 43 base64url characters; a deprecated legacy key population has an undocumented format and is not claimed.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-29 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^tgp_v1_[A-Za-z0-9_-]{43}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Unresolved ·
tool-corroboration· current · observed 2026-09-26Pinned scanner rules are consistent with the contract grammar (1 artifact: betterleaks).
- betterleaks/betterleaks @ main: cmd/generate/config/rules/togetherai.goscanner-rule-source · last read 2026-09-29 · latest outcome read · supports betterleaks: togetherai-api-key: tgp_v1_[A-Za-z0-9_-]{43} (Kingfisher's native rule, tgp_v1_ + 43 since 2025-08-27, predates it and is its own lineage; Kingfisher switched to a betterleaks alias only on 2026-08-21 — corrected by redact-secret#1013)
Tool corroborated ·
field-prefix· current · observed 2026-09-26prefix: tgp_v1_ (No provider source; the versioned prefix is a tool rule plus observation.)
- andrewbaker.ninja/2026/08/20/running-sota-open-ai-models-in-opencode-without-paying-frontier-prices/scanner-rule-source · last read 2026-09-26 · latest outcome read · supports community blog: keys look like tgp_v1_...
- betterleaks/betterleaks @ main: cmd/generate/config/rules/togetherai.goscanner-rule-source · last read 2026-09-29 · latest outcome read · supports prefix: tgp_v1_
- github.com/redact-secret/redact-secret/issues/783scanner-rule-source · last read 2026-09-26 · latest outcome read · supports code-search measurement, maintainer observation
Unresolved ·
field-body· current · observed 2026-09-26body: 43 characters of [A-Za-z0-9_-] (50 in all) (Peer rules only for the width (betterleaks, Kingfisher native since 2025-08-27, CredSweeper since 2026-05-11: three owners, per redact-secret#1013) and n=4 observed bodies; entropy filter 3.0 in betterleaks.)
- betterleaks/betterleaks @ main: cmd/generate/config/rules/togetherai.goscanner-rule-source · last read 2026-09-29 · latest outcome read · supports body: 43 characters of [A-Za-z0-9_-] (50 in all)
- github.com/redact-secret/redact-secret/issues/783scanner-rule-source · last read 2026-09-26 · latest outcome read · supports four full-length samples, first page only
Unresolved ·
field-legacy-keys· current · observed 2026-09-26legacy-keys: deprecated legacy project-less keys with an undocumented format (A common belief of a 64-hex body was searched and found nowhere; it is not assumed.)
- docs.together.ai/docs/api-keys-authenticationprovider-documentation · last read 2026-09-29 · latest outcome read · supports legacy keys are deprecated and cannot be scoped or revoked, only regenerated
Unresolved ·
field-other-versions· current · observed 2026-09-26other-versions: whether tgp_v2_ or another version exists (No fixture asserts silence on a different version.)
- betterleaks/betterleaks @ main: cmd/generate/config/rules/togetherai.goscanner-rule-source · last read 2026-09-29 · latest outcome read · supports tgp_v2_ appears only as a negative test
- github.com/redact-secret/redact-secret/issues/783scanner-rule-source · last read 2026-09-26 · latest outcome read · supports other-versions: whether tgp_v2_ or another version exists
Provider documented ·
field-transport· current · observed 2026-09-26transport: TOGETHER_API_KEY environment variable, the api_key argument, Authorization: Bearer
- docs.together.ai/docs/quickstartprovider-documentation · last read 2026-09-26 · latest outcome read · supports transport: TOGETHER_API_KEY environment variable, the api_key argument, Authorization: Bearer
- togethercomputer/together-python @ main: src/together/client.pyprovider-documentation · last read 2026-09-26 · latest outcome read · supports provider code: api_key, then TOGETHER_API_KEY; optional TOGETHER_BASE_URL
Unresolved ·
field-checksum· current · observed 2026-09-26checksum: no checksum or fixed inner segment is documented or observed
- github.com/redact-secret/redact-secret/issues/783scanner-rule-source · last read 2026-09-26 · latest outcome read · supports checksum: no checksum or fixed inner segment is documented or observed
Unresolved ·
listed-references· current · observed 2026-09-26The legacy contract lists 6 references without stating which property each supports.
- andrewbaker.ninja/2026/08/20/running-sota-open-ai-models-in-opencode-without-paying-frontier-prices/scanner-rule-source · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- docs.together.ai/docs/quickstartprovider-documentation · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- docs.together.ai/docs/api-keys-authenticationprovider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/783scanner-rule-source · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/867issue-or-discussion · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- togethercomputer/together-python @ main: src/together/client.pyprovider-documentation · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
Tool corroborated ·
dossier-research· current · observed 2026-09-29Legacy dossier research (verdict ready, tier T2) cited 6 sources; the dossier does not attribute sources to individual properties.
- docs.together.ai/docs/api-keys-authenticationprovider-documentation · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- betterleaks/betterleaks @ 6cf4f1a29160b68be7c6390599b9b773234e5a43: cmd/generate/config/rules/togetherai.goother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- mongodb/kingfisher @ 82d050530cdef9af070b8f9a75701c9c27a948c3: crates/kingfisher-rules/data/rules/togetherai.ymlother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L8
- redact-secret/redact-secret @ add1188fed9993723c59fbce8c867086b9d2049a: docs/audits/evidence/1013/together-api-key.mdproject-research-note · last read 2026-09-29 · latest outcome read · supports Final research evidence recorded by the legacy dossier
- Samsung/CredSweeper @ f21ab2f2553eea288a72273b9658cd297ab1d11f: credsweeper/rules/config.yamlscanner-rule-source · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L1814-L1827
- togethercomputer/together-py @ 9c9c34e47686344b996eaf19a7c470f72dcdecd6: src/together/lib/cli/_track_cli.pyprovider-sdk-source · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L205
Tool corroborated ·
taxonomy-sources· current · observed 2026-09-29The legacy taxonomy lists 2 sources for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- docs.together.ai/docs/api-keys-authenticationprovider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
- betterleaks/betterleaks @ main: cmd/generate/config/rules/togetherai.goscanner-rule-source · last read 2026-09-29 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- prefix
tgp_v1_followed by 43 characters of[A-Za-z0-9_-](50 in all), lowercase prefix, with identifier boundaries on both sides. Atgp_v2_prefix is only a scanner negative; no source says a v2 exists. Recognised bare or in any context. - Basis
- T2. No provider page or staff statement states the prefix, length or alphabet; the docs establish only issuance, the
TOGETHER_API_KEYvariable and the legacy population. The exact width rests on three peer rules from three owners: betterleaks; Kingfisher's native rule, added 2025-08-27 and replaced by a betterleaks alias only on 2026-08-21, so its own lineage (the earlier "Kingfisher only aliases it" was wrong; corrected by redact-secret#1013); and CredSweeper (2026-05-11). Four full-length samples from a public code search agree (#783). Together's own CLI redactor in together-py (2026-04-27) confirms thetgp_prefix and a[A-Za-z0-9_-]body with no length. No pinned scanner has a Together rule. - Issuance
- not attempted. The #783 checklist covers prefix, total length (expected 50), alphabet, project and expiry variants, and the legacy key.
- Contract in core
- detector-families.md, section Together AI and Tavily (#867). Legacy keys are not claimed.
In this benchmark
- Fixtures
- 56
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
56 fixtures: 22 expect a redaction, 34 must stay quiet. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T2Tool-corroborated | 44 | 0 | 0 | 0 |
| T3Project policy | 12 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 56 | 20 | 2 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it | 56 | 8 | 0 | 3 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 56 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it | 56 | 22 | 0 | 0 |
Benchmark dossier questions
- Open caveat
- No provider source states the length; three peer lineages and four samples back it, provider code backs prefix and alphabet only. Corroboration 4/4/1 against the 3/3/2 needed until Q-TG is ruled; otherwise one issued project key (checklist in #783).
Looks like it, but isn't
- Collisions
tgpappears only in unrelated project names. TheTOGETHER_BASE_URLvariable, model names and 64-hex digests are benign. A pleno-dlp rule for a bare 64-hex Together key is a sibling shape, not a corroboration of this one.
Scanner rules for this family
No peer rule maps to this family
None of the reviewed peer scanners has a rule that can match a credential of this family.
None mapped
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
together-ai-api-key-actions-envtogether · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
together-ai-api-key-chat-backtickstogether · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
together-ai-api-key-cli-flagtogether · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
together-ai-api-key-compose-envtogether · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
together-ai-api-key-curl-bearertogether · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
together-ai-api-key-docs-ellipsis-placeholder-documentation-placeholdertogether · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
together-ai-api-key-dotenvtogether · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
together-ai-api-key-exporttogether · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
together-ai-api-key-files-upload-historytogether · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
together-ai-api-key-js-clienttogether · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
together-ai-api-key-json-configtogether · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
together-ai-api-key-key-shape-baretogether · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
together-ai-api-key-key-shape-quotedtogether · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
together-ai-api-key-key-shape-unicode-crlftogether · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
together-ai-api-key-openai-client-reprtogether · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
together-ai-api-key-openai-sdk-base-urltogether · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
together-ai-api-key-pasted-keytogether · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
together-ai-api-key-plus-in-body-twintogether · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
together-ai-api-key-python-environtogether · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
together-ai-api-key-python-togethertogether · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
together-ai-api-key-router-logtogether · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
together-ai-api-key-tool-calltogether · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
together-ai-api-key-uppercase-prefix-twintogether · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
together-ai-api-key-vercel-ai-sdktogether · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
together-ai-api-key-yaml-configtogether · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
together-ai-api-key-actions-secret-referencetogether · templated-reference | Must not flagT3 · Project policy | Quiet |
together-ai-api-key-base-url-and-model-public-idtogether · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
together-ai-api-key-base-url-readme-prosetogether · prose-mention | Must not flagT3 · Project policy | Quiet |
together-ai-api-key-base64url-blob-encoded-valuetogether · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
together-ai-api-key-docs-ellipsis-placeholdertogether · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
together-ai-api-key-docs-key-placeholdertogether · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
together-ai-api-key-doppler-ref-referencetogether · templated-reference | Must not flagT3 · Project policy | Quiet |
together-ai-api-key-dot-in-body-twintogether · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
together-ai-api-key-embedded-leading-twintogether · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
together-ai-api-key-env-reference-referencetogether · templated-reference | Must not flagT3 · Project policy | Quiet |
together-ai-api-key-finetune-job-listing-public-idtogether · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
together-ai-api-key-hex-digest-encoded-valuetogether · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
together-ai-api-key-hyphen-delimiters-twintogether · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
together-ai-api-key-hyphen-separators-twintogether · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
together-ai-api-key-label-prosetogether · benign-lookalike | Must not flagT3 · Project policy | Quiet |
together-ai-api-key-long-body-twintogether · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
together-ai-api-key-long-body-twin-wrong-lengthtogether · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
together-ai-api-key-masktogether · benign-lookalike | Must not flagT3 · Project policy | Quiet |
together-ai-api-key-masked-display-public-idtogether · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
together-ai-api-key-prefix-guidance-prosetogether · prose-mention | Must not flagT3 · Project policy | Quiet |
together-ai-api-key-prefix-onlytogether · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
together-ai-api-key-prefix-only-near-misstogether · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
together-ai-api-key-referencetogether · benign-lookalike | Must not flagT3 · Project policy | Quiet |
together-ai-api-key-response-object-id-public-idtogether · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
together-ai-api-key-short-bodytogether · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
Sources
Documentation and code
- docs.together.ai/docs/api-keys-authentication
- github.com/betterleaks/betterleaks/blob/main/cmd/generate/config/rules/togetherai.go
- github.com/betterleaks/betterleaks/blob/6cf4f1a29160b68be7c6390599b9b773234e5a43/cmd/generate/config/rules/togetherai.go
- github.com/mongodb/kingfisher/blob/82d050530cdef9af070b8f9a75701c9c27a948c3/crates/kingfisher-rules/data/rules/togetherai.yml#L8
- github.com/Samsung/CredSweeper/blob/f21ab2f2553eea288a72273b9658cd297ab1d11f/credsweeper/rules/config.yaml#L1814-L1827
- github.com/togethercomputer/together-py/blob/9c9c34e47686344b996eaf19a7c470f72dcdecd6/src/together/lib/cli/_track_cli.py#L205
Research log
- redact-secret/redact-secret#783Research issue
- redact-secret/redact-secret#774Research issue
- redact-secret/redact-secret#867Research issue
- redact-secret/redact-secret#1013Research issue
- redact-secret/redact-secret-benchmarks#384Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/add1188fed9993723c59fbce8c867086b9d2049a/docs/audits/evidence/1013/together-api-key.md