Skip to content
Benchmarks

redact-secret · Report

API token

22-character alphanumeric API token sent in an Authorization: token header; recognized only beside a same-line travis keyword.

  • Travis CI
  • Detectors: travisci-api-token
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictReady
  • Dossier evidence levelT2 · Tool-corroborated
  • Dossier researched2026-09-25
Registry detector travisci-api-token since redact-secret#523 (#773, registry pinned at 3144bb3), authored under #259. Travis CI states no shape; the 22-character grammar is tool-corroborated (gitleaks travisci-access-token, trufflehog travisci).

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · current
  • ResearchResearched
  • Researched2026-09-25

3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-25 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Descriptive pattern
^(?=[A-Za-z0-9]*[0-9])(?=[A-Za-z0-9]*[A-Za-z])[A-Za-z0-9]{22}$

Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.

Format facts

  • Provider documented · mutable-property-source · current · observed 2026-09-24

    Documentation for the one property varied in legacy twin fixtures (Authorization: token header, token from travis token): the provider documents the API token as generated by the travis CLI (travis token, travis token --pro) and sent in an Authorization: token header to api.travis-ci.org / api.travis-ci.com; the example is masked (xxxxxxxxxxxx) and no length or alphabet is stated. Context twins keep the token and remove the same-line Travis context, or rename the key to a Travis identifier name

    • developer.travis-ci.com/authenticationprovider-documentation · last read 2026-09-25 · latest outcome read · supports the provider documents the API token as generated by the travis CLI (travis token, travis token --pro) and sent in an Authorization: token header to api.travis-ci.org / api.travis-ci.com; the example is masked (xxxxxxxxxxxx) and no length or alphabet is stated. Context twins keep the token and remove the same-line Travis context, or rename the key to a Travis identifier name
  • Tool corroborated · tool-corroboration · current · observed 2026-09-24

    Pinned scanner rules are consistent with the contract grammar (2 artifacts: gitleaks 8.30.1; trufflehog 3.97.4).

  • Provider documented · field-transport · current · observed 2026-09-24

    transport: API token generated by travis token and sent in an Authorization: token header

    • developer.travis-ci.com/authenticationprovider-documentation · last read 2026-09-25 · latest outcome read · supports transport: API token generated by travis token and sent in an Authorization: token header
    • docs.travis-ci.com/user/triggering-builds/provider-documentation · last read 2026-09-24 · latest outcome read · supports transport: API token generated by travis token and sent in an Authorization: token header
  • Tool corroborated · field-length · current · observed 2026-09-24

    length: exactly 22 characters

  • Tool corroborated · field-alphabet · current · observed 2026-09-24

    alphabet: [A-Za-z0-9], the intersection of gitleaks (?i)[a-z0-9] and trufflehog [a-zA-Z0-9_] (trufflehog also admits _; not claimed.)

  • Unresolved · field-mixed-letters-and-digits · current · observed 2026-09-24

    mixed letters and digits: a token contains at least one letter and one digit (A precision guard, not a provider fact: about 2% of random tokens have no digit.)

  • Tool corroborated · field-context · current · observed 2026-09-24

    context: same-line travis keyword

  • Unresolved · listed-references · current · observed 2026-09-24

    The legacy contract lists 1 reference without stating which property each supports.

  • Tool corroborated · dossier-research · current · observed 2026-09-25

    Legacy dossier research (verdict ready, tier T2) cited 3 sources; the dossier does not attribute sources to individual properties.

  • Unresolved · taxonomy-sources · current · observed 2026-09-25

    The legacy taxonomy lists 1 source for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
22 alphanumeric characters, recognized only on a line that contains travis (case-insensitive). The frozen grammar is the intersection of two scanner rules: gitleaks (travis keyword, then 22 of [a-z0-9] with case-insensitive matching) and trufflehog (travis prefix, then 22 of [a-zA-Z0-9_]). The underscore is left out of positives. The #523 contract adds precision guards: the run must mix letters and digits, must not be one repeated character, and is skipped under an identifier key (_slug, _id, _number, _url).
Basis
the two provider pages show only a masked twelve-character placeholder in the header and state no length or alphabet, so the tier is T2 (two-tool corroboration). No provider-documented prefix exists.
Issuance
travis token against a Travis CI account. Not attempted.
Contract in core
detector-families.md (travisci_api_token, confidence-gated); frozen in the #523 evidence.

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.
Fixtures
48
Left readable
0
Redacted too much
0
False alarms
0

48 fixtures: 29 must stay quiet, 19 record project policy. See every row

redact-secret fixture counts by evidence level
Evidence levelFixturesLeft readableToo muchFalse alarms
T2Tool-corroborated11000
T3Project policy37000

Every scanner on the same fixtures

In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.

Counts per scanner on this family's fixtures
ScannerFixturesLeft readableToo muchFalse alarms
flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it481900
gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it48505
redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped48000
trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it48104

Benchmark dossier questions

Things the sources do not settle. They are listed so nobody reads them as settled.
Open caveat
Travis CI states no token length or alphabet; the 22-character shape and the travis keyword gate rest on two scanner rules. No provider-issued token has been observed.

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
Travis build, job and repository ids are numeric and commit SHAs are 40 hex, so identifiers on Travis lines do not fit the shape. A 22-character mixed-case value under any non-identifier key on a Travis line is reported. About 2 percent of uniformly random 22-byte tokens have no digit and would be missed.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.
Peer scanner rules that target this family
ScannerRuleWhat the rule matches
gitleaks · rules 8.30.1travisci-access-tokentravis keyword + 22 alphanumerics
trufflehog · rules 3.97.4traviscitravis keyword + 22 characters

No rule maps to this family in flare-redact, openredaction.

48 of 48 rows

Fixtures in this family

48 rows, redact-secret's outcome on each. Rows that need a look come first (0), then the rest in corpus order. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in API token
FixtureKind and evidenceredact-secret
travisci-api-token-actions-envtravis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-context-1-twintravis-ci · missing-context-markerMust not flagT3 · Project policy · twinQuiet
travisci-api-token-context-2-twintravis-ci · missing-context-markerMust not flagT3 · Project policy · twinQuiet
travisci-api-token-context-4-twintravis-ci · missing-context-markerMust not flagT3 · Project policy · twinQuiet
travisci-api-token-context-8-twintravis-ci · missing-context-markerMust not flagT3 · Project policy · twinQuiet
travisci-api-token-context-base-1travis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-context-base-2travis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-context-base-3travis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-context-base-4travis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-context-base-5travis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-context-base-6travis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-context-base-7travis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-context-base-8travis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-curl-authorizationtravis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-dotenvtravis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-exporttravis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-identifier-key-twintravis-ci · missing-context-markerMust not flagT3 · Project policy · twinQuiet
travisci-api-token-json-configtravis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-sync-logtravis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-token-shape-baretravis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-token-shape-quotedtravis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-token-shape-unicode-crlftravis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-travis-whoamitravis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-travispy-clienttravis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-underscore-body-twintravis-ci · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
travisci-api-token-actions-secret-referencetravis-ci · templated-referenceMust not flagT3 · Project policyQuiet
travisci-api-token-artifact-digest-encoded-valuetravis-ci · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
travisci-api-token-build-env-public-idtravis-ci · public-identifierMust not flagT2 · Tool-corroboratedQuiet
travisci-api-token-build-url-public-idtravis-ci · public-identifierMust not flagT2 · Tool-corroboratedQuiet
travisci-api-token-commit-sha-public-idtravis-ci · public-identifierMust not flagT2 · Tool-corroboratedQuiet
travisci-api-token-context-3-twintravis-ci · missing-context-markerMust not flagT3 · Project policy · twinQuiet
travisci-api-token-context-5-twintravis-ci · missing-context-markerMust not flagT3 · Project policy · twinQuiet
travisci-api-token-context-6-twintravis-ci · missing-context-markerMust not flagT3 · Project policy · twinQuiet
travisci-api-token-context-7-twintravis-ci · missing-context-markerMust not flagT3 · Project policy · twinQuiet
travisci-api-token-docs-token-placeholdertravis-ci · documentation-placeholderMust not flagT3 · Project policyQuiet
travisci-api-token-env-example-placeholdertravis-ci · documentation-placeholderMust not flagT3 · Project policyQuiet
travisci-api-token-env-reference-referencetravis-ci · templated-referenceMust not flagT3 · Project policyQuiet
travisci-api-token-label-prosetravis-ci · benign-lookalikeMust not flagT3 · Project policyQuiet
travisci-api-token-letters-only-stage-near-misstravis-ci · format-near-missMust not flagT2 · Tool-corroboratedQuiet
travisci-api-token-long-token-twintravis-ci · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
travisci-api-token-masktravis-ci · benign-lookalikeMust not flagT3 · Project policyQuiet
travisci-api-token-missing-keywordtravis-ci · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
travisci-api-token-no-travis-context-twintravis-ci · missing-context-markerMust not flagT3 · Project policy · twinQuiet
travisci-api-token-referencetravis-ci · benign-lookalikeMust not flagT3 · Project policyQuiet
travisci-api-token-short-in-prose-near-misstravis-ci · format-near-missMust not flagT2 · Tool-corroboratedQuiet
travisci-api-token-short-token-twintravis-ci · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
travisci-api-token-token-guidance-prosetravis-ci · prose-mentionMust not flagT3 · Project policyQuiet
travisci-api-token-travis-secure-encoded-valuetravis-ci · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet

Sources

Researched 2026-09-25.

Documentation and code

Research log