redact-secret · Report
API key secret
32-character API key secret.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-10-03 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
Shape not recorded.
Format facts
Provider documented ·
mutable-property-source· current · observed 2026-09-24Documentation for the one property varied in legacy twin fixtures (context twin: same-line twilio keyword or SK API Key SID removed): Un-probeable record lifted 2026-09-24 (#207): the value is opaque and context-gated (CONTEXT_GATED), so #207 requires context twins and no bare-value claim. Each twin keeps the 32-character value byte-for-byte and removes only the same-line marker the detector contract names (the word twilio or the SK API Key SID, whose SK + 32 hex shape Twilio documents), per the context-twin decision; the twin is policy-tier, like the positive.
- redact-secret/redact-secret-benchmarks @ develop: docs/decisions/2026-09-20-extend-twins-to-assignment-context.mdprovider-documentation · last read 2026-09-24 · latest outcome read · supports Un-probeable record lifted 2026-09-24 (#207): the value is opaque and context-gated (CONTEXT_GATED), so #207 requires context twins and no bare-value claim. Each twin keeps the 32-character value byte-for-byte and removes only the same-line marker the detector contract names (the word twilio or the SK API Key SID, whose SK + 32 hex shape Twilio documents), per the context-twin decision; the twin is policy-tier, like the positive.
Unresolved ·
tool-corroboration· current · observed 2026-09-22Pinned scanner rules are consistent with the contract grammar (1 artifact: trufflehog 3.97.4).
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/twilioapikey/twilioapikey.goscanner-rule-source · last read 2026-09-22 · latest outcome read · supports trufflehog 3.97.4: twilioapikey/twilioapikey
Unresolved ·
field-length-and-alphabet· current · observed 2026-09-22length and alphabet: 32 alphanumeric characters, mixed case, no prefix
- github.com/redact-secret/redact-secret/issues/661scanner-rule-source · last read 2026-09-22 · latest outcome read · supports length and alphabet: 32 alphanumeric characters, mixed case, no prefix
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/twilioapikey/twilioapikey.goscanner-rule-source · last read 2026-09-22 · latest outcome read · supports length and alphabet: 32 alphanumeric characters, mixed case, no prefix
Provider documented ·
field-paired-sid· current · observed 2026-09-22paired SID: the companion API Key SID is SK + 32 hex ([0-9a-fA-F]), 34 characters; the SID is the Basic-auth user and the secret the password
- www.twilio.com/docs/iam/api-keys/key-resource-v1provider-documentation · last read 2026-10-03 · latest outcome read · supports paired SID: the companion API Key SID is SK + 32 hex ([0-9a-fA-F]), 34 characters; the SID is the Basic-auth user and the secret the password
Unresolved ·
field-context-gate· current · observed 2026-09-22context gate: opaque value: recognised only beside a same-line SK SID or the word twilio; no bare-value claim
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/twilioapikey/twilioapikey.goscanner-rule-source · last read 2026-09-22 · latest outcome read · supports context gate: opaque value: recognised only beside a same-line SK SID or the word twilio; no bare-value claim
Tool corroborated ·
dossier-research· current · observed 2026-09-24Legacy dossier research (verdict ready, tier T2) cited 3 sources; the dossier does not attribute sources to individual properties.
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/661/README.mdproject-research-note · last read 2026-09-24 · latest outcome read · supports Final research evidence recorded by the legacy dossier
- twilio/twilio-oai @ 5aa7f31977ce5812f7b7bc1f46a38555ebaa2888: spec/json/twilio_iam_v1.jsonprovider-documentation · last read 2026-09-24 · latest outcome read · supports Cited by the legacy dossier research for this family
- www.twilio.com/docs/iam/api-keys/key-resource-v1provider-documentation · last read 2026-10-03 · latest outcome read · supports Cited by the legacy dossier research for this family
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- 32 alphanumeric characters (
[0-9A-Za-z]), no prefix. The paired key SID isSK+ 32 hex (34 characters) per the provider schema and glossary; core's pairing marker accepts a wider alphabet than the schema. The secret is the basic-auth password paired with the SID and the HMAC key for Access Tokens. - Basis
- T2. No provider source states length or alphabet (
new_key.secretin the OpenAPI spec is an untyped nullable string). 32 rests on TruffleHog'stwilioapikeydetector and 32-character placeholder masks in Twilio sample repositories (a placeholder is not a spec). - Issuance
- not attempted; the secret is shown once.
- Contract in core
- detector-families.md; evidence #661 record.
In this benchmark
- Fixtures
- 50
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
50 fixtures: 2 expect a redaction, 25 must stay quiet, 23 record project policy. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T1Provider-documented | 3 | 0 | 0 | 0 |
| T3Project policy | 47 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 50 | 25 | 0 | 3 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it | 50 | 6 | 1 | 2 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 50 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it | 50 | 25 | 0 | 0 |
Benchmark dossier questions
- Open caveat
- No Twilio source states the secret's length or alphabet; 32 alphanumeric rests on TruffleHog and placeholder masks; only the paired SK SID has a documented grammar.
Looks like it, but isn't
- Collisions
- same as the auth token; the
SKSID within the same line is the context gate.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| trufflehog · rules 3.97.4 | twilioapikey | SK key SID + a 32 character secret |
No rule maps to this family in flare-redact, gitleaks, openredaction.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
twilio-api-key-secret-account-sid-public-idtwilio · public-identifier | Must not flagT3 · Project policy | Quiet |
twilio-api-key-secret-actions-envtwilio · documented-format-literal | Project policyT3 · Project policy | Redacted |
twilio-api-key-secret-api-key-sid-public-idtwilio · public-identifier | Must not flagT3 · Project policy | Quiet |
twilio-api-key-secret-bomtwilio · multibyte-text-offsets | Project policyT3 · Project policy | Redacted |
twilio-api-key-secret-client-sktwilio · documented-format-literal | Project policyT3 · Project policy | Redacted |
twilio-api-key-secret-compose-envtwilio · documented-format-literal | Project policyT3 · Project policy | Redacted |
twilio-api-key-secret-curl-basictwilio · documented-format-literal | Project policyT3 · Project policy | Redacted |
twilio-api-key-secret-envtwilio · documented-format-literal | Project policyT3 · Project policy | Redacted |
twilio-api-key-secret-exporttwilio · documented-format-literal | Project policyT3 · Project policy | Redacted |
twilio-api-key-secret-handoff-notetwilio · documented-format-literal | Project policyT3 · Project policy | Redacted |
twilio-api-key-secret-init-logtwilio · documented-format-literal | Project policyT3 · Project policy | Redacted |
twilio-api-key-secret-js-constanttwilio · documented-format-literal | Project policyT3 · Project policy | Redacted |
twilio-api-key-secret-jsontwilio · documented-format-literal | Project policyT3 · Project policy | Redacted |
twilio-api-key-secret-json-structured-text-valuetwilio · structured-text-value | Project policyT3 · Project policy | Redacted |
twilio-api-key-secret-markdowntwilio · markdown-and-comment-value | Project policyT3 · Project policy | Redacted |
twilio-api-key-secret-no-final-newlinetwilio · value-at-input-edges | Project policyT3 · Project policy | Redacted |
twilio-api-key-secret-paired-api-key-sid-baretwilio · documented-format-literal | Project policyT3 · Project policy | Redacted |
twilio-api-key-secret-paired-api-key-sid-quotedtwilio · documented-format-literal | Project policyT3 · Project policy | Redacted |
twilio-api-key-secret-paired-api-key-sid-unicode-crlftwilio · documented-format-literal | Project policyT3 · Project policy | Redacted |
twilio-api-key-secret-profile-createtwilio · documented-format-literal | Project policyT3 · Project policy | Redacted |
twilio-api-key-secret-pythontwilio · source-code-string-literal | Project policyT3 · Project policy | Redacted |
twilio-api-key-secret-single-quotestwilio · quoted-value-extent | Project policyT3 · Project policy | Redacted |
twilio-api-key-secret-tomltwilio · structured-text-value | Project policyT3 · Project policy | Redacted |
twilio-api-key-secret-wrong-companion-near-misstwilio · format-near-miss | Must not flagT3 · Project policy | Quiet |
twilio-api-key-secret-yamltwilio · documented-format-literal | Project policyT3 · Project policy | Redacted |
twilio-api-key-secret-yaml-structured-text-valuetwilio · structured-text-value | Project policyT3 · Project policy | Redacted |
api-key-secret-before-sidtwilio-compound-credentials-authored · twilio-api-key-sid-and-secret-boundary | Must redactT1 · Provider-documented | Redacted |
api-key-sid-and-secret-envtwilio-compound-credentials-authored · twilio-api-key-sid-and-secret-boundary | Must redactT1 · Provider-documented | Redacted |
twilio-api-key-secret-actions-context-twintwilio · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
twilio-api-key-secret-actions-secret-referencetwilio · templated-reference | Must not flagT3 · Project policy | Quiet |
twilio-api-key-secret-cli-hidden-placeholdertwilio · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
twilio-api-key-secret-client-sk-context-twintwilio · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
twilio-api-key-secret-compose-context-twintwilio · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
twilio-api-key-secret-env-context-twintwilio · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
twilio-api-key-secret-export-context-twintwilio · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
twilio-api-key-secret-handoff-note-context-twintwilio · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
twilio-api-key-secret-init-log-context-twintwilio · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
twilio-api-key-secret-js-constant-context-twintwilio · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
twilio-api-key-secret-json-context-twintwilio · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
twilio-api-key-secret-label-prosetwilio · benign-lookalike | Must not flagT3 · Project policy | Quiet |
twilio-api-key-secret-masktwilio · benign-lookalike | Must not flagT3 · Project policy | Quiet |
twilio-api-key-secret-missing-identifiertwilio · benign-lookalike | Must not flagT3 · Project policy | Quiet |
twilio-api-key-secret-one-time-note-prosetwilio · prose-mention | Must not flagT3 · Project policy | Quiet |
twilio-api-key-secret-process-env-referencetwilio · templated-reference | Must not flagT3 · Project policy | Quiet |
twilio-api-key-secret-referencetwilio · benign-lookalike | Must not flagT3 · Project policy | Quiet |
twilio-api-key-secret-request-signature-encoded-valuetwilio · benign-encoded-value | Must not flagT1 · Provider-documented | Quiet |
twilio-api-key-secret-short-secrettwilio · benign-lookalike | Must not flagT3 · Project policy | Quiet |
twilio-api-key-secret-x-mask-placeholdertwilio · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
twilio-api-key-secret-yaml-context-twintwilio · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
twilio-api-key-secret-your-secret-placeholdertwilio · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
Sources
Documentation and code
- www.twilio.com/docs/iam/api-keys/key-resource-v1
- github.com/twilio/twilio-oai/blob/5aa7f31977ce5812f7b7bc1f46a38555ebaa2888/spec/json/twilio_iam_v1.json
Research log
- redact-secret/redact-secret#661Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/8b6a5fde52ecb4dfce13f09c7a947062d21483c7/docs/audits/evidence/661/README.md