redact-secret · Report
API token
22-character alphanumeric API token sent in an Authorization: token header; recognized only beside a same-line travis keyword.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-25 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^(?=[A-Za-z0-9]*[0-9])(?=[A-Za-z0-9]*[A-Za-z])[A-Za-z0-9]{22}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Provider documented ·
mutable-property-source· current · observed 2026-09-24Documentation for the one property varied in legacy twin fixtures (Authorization: token header, token from travis token): the provider documents the API token as generated by the travis CLI (travis token, travis token --pro) and sent in an Authorization: token header to api.travis-ci.org / api.travis-ci.com; the example is masked (xxxxxxxxxxxx) and no length or alphabet is stated. Context twins keep the token and remove the same-line Travis context, or rename the key to a Travis identifier name
- developer.travis-ci.com/authenticationprovider-documentation · last read 2026-09-25 · latest outcome read · supports the provider documents the API token as generated by the travis CLI (travis token, travis token --pro) and sent in an Authorization: token header to api.travis-ci.org / api.travis-ci.com; the example is masked (xxxxxxxxxxxx) and no length or alphabet is stated. Context twins keep the token and remove the same-line Travis context, or rename the key to a Travis identifier name
Tool corroborated ·
tool-corroboration· current · observed 2026-09-24Pinned scanner rules are consistent with the contract grammar (2 artifacts: gitleaks 8.30.1; trufflehog 3.97.4).
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports gitleaks 8.30.1: gitleaks.toml
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/travisci/travisci.goscanner-rule-source · last read 2026-09-24 · latest outcome read · supports trufflehog 3.97.4: travisci/travisci
Provider documented ·
field-transport· current · observed 2026-09-24transport: API token generated by travis token and sent in an Authorization: token header
- developer.travis-ci.com/authenticationprovider-documentation · last read 2026-09-25 · latest outcome read · supports transport: API token generated by travis token and sent in an Authorization: token header
- docs.travis-ci.com/user/triggering-builds/provider-documentation · last read 2026-09-24 · latest outcome read · supports transport: API token generated by travis token and sent in an Authorization: token header
Tool corroborated ·
field-length· current · observed 2026-09-24length: exactly 22 characters
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports travisci-access-token
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/travisci/travisci.goscanner-rule-source · last read 2026-09-24 · latest outcome read · supports length: exactly 22 characters
Tool corroborated ·
field-alphabet· current · observed 2026-09-24alphabet: [A-Za-z0-9], the intersection of gitleaks (?i)[a-z0-9] and trufflehog [a-zA-Z0-9_] (trufflehog also admits _; not claimed.)
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports alphabet: [A-Za-z0-9], the intersection of gitleaks (?i)[a-z0-9] and trufflehog [a-zA-Z0-9_]
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/travisci/travisci.goscanner-rule-source · last read 2026-09-24 · latest outcome read · supports alphabet: [A-Za-z0-9], the intersection of gitleaks (?i)[a-z0-9] and trufflehog [a-zA-Z0-9_]
Unresolved ·
field-mixed-letters-and-digits· current · observed 2026-09-24mixed letters and digits: a token contains at least one letter and one digit (A precision guard, not a provider fact: about 2% of random tokens have no digit.)
- github.com/redact-secret/redact-secret/pull/773other · last read 2026-09-24 · latest outcome read · supports product precision guard (redact-secret#523)
Tool corroborated ·
field-context· current · observed 2026-09-24context: same-line travis keyword
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports context: same-line travis keyword
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/travisci/travisci.goscanner-rule-source · last read 2026-09-24 · latest outcome read · supports context: same-line travis keyword
Unresolved ·
listed-references· current · observed 2026-09-24The legacy contract lists 1 reference without stating which property each supports.
- docs.travis-ci.com/user/triggering-builds/provider-documentation · last read 2026-09-24 · latest outcome read · supports Listed as a reference by the legacy contract
Tool corroborated ·
dossier-research· current · observed 2026-09-25Legacy dossier research (verdict ready, tier T2) cited 3 sources; the dossier does not attribute sources to individual properties.
- developer.travis-ci.com/authenticationprovider-documentation · last read 2026-09-25 · latest outcome read · supports Cited by the legacy dossier research for this family
- docs.travis-ci.com/user/triggering-buildsother · last read 2026-09-25 · latest outcome read · supports Cited by the legacy dossier research for this family
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/523/README.mdproject-research-note · last read 2026-09-25 · latest outcome read · supports Final research evidence recorded by the legacy dossier
Unresolved ·
taxonomy-sources· current · observed 2026-09-25The legacy taxonomy lists 1 source for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- developer.travis-ci.com/authenticationprovider-documentation · last read 2026-09-25 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- 22 alphanumeric characters, recognized only on a line that contains
travis(case-insensitive). The frozen grammar is the intersection of two scanner rules: gitleaks (traviskeyword, then 22 of[a-z0-9]with case-insensitive matching) and trufflehog (travisprefix, then 22 of[a-zA-Z0-9_]). The underscore is left out of positives. The #523 contract adds precision guards: the run must mix letters and digits, must not be one repeated character, and is skipped under an identifier key (_slug,_id,_number,_url). - Basis
- the two provider pages show only a masked twelve-character placeholder in the header and state no length or alphabet, so the tier is T2 (two-tool corroboration). No provider-documented prefix exists.
- Issuance
travis tokenagainst a Travis CI account. Not attempted.- Contract in core
- detector-families.md (
travisci_api_token, confidence-gated); frozen in the #523 evidence.
In this benchmark
- Fixtures
- 48
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
48 fixtures: 29 must stay quiet, 19 record project policy. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T2Tool-corroborated | 11 | 0 | 0 | 0 |
| T3Project policy | 37 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 48 | 19 | 0 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it | 48 | 5 | 0 | 5 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 48 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it | 48 | 1 | 0 | 4 |
Benchmark dossier questions
- Open caveat
- Travis CI states no token length or alphabet; the 22-character shape and the travis keyword gate rest on two scanner rules. No provider-issued token has been observed.
Looks like it, but isn't
- Collisions
- Travis build, job and repository ids are numeric and commit SHAs are 40 hex, so identifiers on Travis lines do not fit the shape. A 22-character mixed-case value under any non-identifier key on a Travis line is reported. About 2 percent of uniformly random 22-byte tokens have no digit and would be missed.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| gitleaks · rules 8.30.1 | travisci-access-token | travis keyword + 22 alphanumerics |
| trufflehog · rules 3.97.4 | travisci | travis keyword + 22 characters |
No rule maps to this family in flare-redact, openredaction.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
travisci-api-token-actions-envtravis-ci · documented-format-literal | Project policyT3 · Project policy | Redacted |
travisci-api-token-context-1-twintravis-ci · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
travisci-api-token-context-2-twintravis-ci · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
travisci-api-token-context-4-twintravis-ci · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
travisci-api-token-context-8-twintravis-ci · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
travisci-api-token-context-base-1travis-ci · documented-format-literal | Project policyT3 · Project policy | Redacted |
travisci-api-token-context-base-2travis-ci · documented-format-literal | Project policyT3 · Project policy | Redacted |
travisci-api-token-context-base-3travis-ci · documented-format-literal | Project policyT3 · Project policy | Redacted |
travisci-api-token-context-base-4travis-ci · documented-format-literal | Project policyT3 · Project policy | Redacted |
travisci-api-token-context-base-5travis-ci · documented-format-literal | Project policyT3 · Project policy | Redacted |
travisci-api-token-context-base-6travis-ci · documented-format-literal | Project policyT3 · Project policy | Redacted |
travisci-api-token-context-base-7travis-ci · documented-format-literal | Project policyT3 · Project policy | Redacted |
travisci-api-token-context-base-8travis-ci · documented-format-literal | Project policyT3 · Project policy | Redacted |
travisci-api-token-curl-authorizationtravis-ci · documented-format-literal | Project policyT3 · Project policy | Redacted |
travisci-api-token-dotenvtravis-ci · documented-format-literal | Project policyT3 · Project policy | Redacted |
travisci-api-token-exporttravis-ci · documented-format-literal | Project policyT3 · Project policy | Redacted |
travisci-api-token-identifier-key-twintravis-ci · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
travisci-api-token-json-configtravis-ci · documented-format-literal | Project policyT3 · Project policy | Redacted |
travisci-api-token-sync-logtravis-ci · documented-format-literal | Project policyT3 · Project policy | Redacted |
travisci-api-token-token-shape-baretravis-ci · documented-format-literal | Project policyT3 · Project policy | Redacted |
travisci-api-token-token-shape-quotedtravis-ci · documented-format-literal | Project policyT3 · Project policy | Redacted |
travisci-api-token-token-shape-unicode-crlftravis-ci · documented-format-literal | Project policyT3 · Project policy | Redacted |
travisci-api-token-travis-whoamitravis-ci · documented-format-literal | Project policyT3 · Project policy | Redacted |
travisci-api-token-travispy-clienttravis-ci · documented-format-literal | Project policyT3 · Project policy | Redacted |
travisci-api-token-underscore-body-twintravis-ci · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
travisci-api-token-actions-secret-referencetravis-ci · templated-reference | Must not flagT3 · Project policy | Quiet |
travisci-api-token-artifact-digest-encoded-valuetravis-ci · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
travisci-api-token-build-env-public-idtravis-ci · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
travisci-api-token-build-url-public-idtravis-ci · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
travisci-api-token-commit-sha-public-idtravis-ci · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
travisci-api-token-context-3-twintravis-ci · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
travisci-api-token-context-5-twintravis-ci · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
travisci-api-token-context-6-twintravis-ci · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
travisci-api-token-context-7-twintravis-ci · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
travisci-api-token-docs-token-placeholdertravis-ci · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
travisci-api-token-env-example-placeholdertravis-ci · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
travisci-api-token-env-reference-referencetravis-ci · templated-reference | Must not flagT3 · Project policy | Quiet |
travisci-api-token-label-prosetravis-ci · benign-lookalike | Must not flagT3 · Project policy | Quiet |
travisci-api-token-letters-only-stage-near-misstravis-ci · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
travisci-api-token-long-token-twintravis-ci · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
travisci-api-token-masktravis-ci · benign-lookalike | Must not flagT3 · Project policy | Quiet |
travisci-api-token-missing-keywordtravis-ci · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
travisci-api-token-no-travis-context-twintravis-ci · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
travisci-api-token-referencetravis-ci · benign-lookalike | Must not flagT3 · Project policy | Quiet |
travisci-api-token-short-in-prose-near-misstravis-ci · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
travisci-api-token-short-token-twintravis-ci · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
travisci-api-token-token-guidance-prosetravis-ci · prose-mention | Must not flagT3 · Project policy | Quiet |
travisci-api-token-travis-secure-encoded-valuetravis-ci · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
Sources
Documentation and code
- developer.travis-ci.com/authentication
- docs.travis-ci.com/user/triggering-builds
Research log
- redact-secret/redact-secret#523Research issue
- redact-secret/redact-secret-benchmarks#259Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/8b6a5fde52ecb4dfce13f09c7a947062d21483c7/docs/audits/evidence/523/README.md