redact-secret · Report
Integration token
Modern integration token identified only by the provider-documented vci stem.
Research record
What blocks the research
- Issuance-gatedNo provider source writes vci_ with the underscore; the 56-character body rests on peer rules only (1 class). Needs ruling Q-VC or one integration token measured (checklist in redact-secret#1013).
2 events in the review history: 1 observed, 1 reviewed. Latest: observed on 2026-09-29 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
Shape not recorded.
Format facts
Provider documented ·
dossier-research· current · observed 2026-09-29Legacy dossier research (verdict issuance-gated, tier T1) cited 7 sources; the dossier does not attribute sources to individual properties.
- github.blog/changelog/2026-03-10-secret-scanning-pattern-updates-march-2026/other · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- betterleaks/betterleaks @ 2a387a5bad4290a84b9a1eb679bffe70611218cc: cmd/generate/config/rules/vercel.goscanner-rule-source · last read 2026-10-06 · latest outcome read · supports Cited by the legacy dossier research for this family · #L81-L114
- mongodb/kingfisher @ 88d3f780fad83960aaddfcf732a690049853ccc9: crates/kingfisher-rules/data/rules/vercel.ymlprovider-documentation · last read 2026-10-06 · latest outcome read · supports Cited by the legacy dossier research for this family · #L92-L132
- redact-secret/redact-secret @ add1188fed9993723c59fbce8c867086b9d2049a: docs/audits/evidence/1013/vercel.mdproject-research-note · last read 2026-09-29 · latest outcome read · supports Final research evidence recorded by the legacy dossier
- secretlint/secretlint @ e8fc91351add9eebfd5eec5bdd7cd0d551d5e42a: packages/@secretlint/secretlint-rule-vercel/src/index.tsother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L27-L58
- vercel.com/changelog/new-token-formats-and-secret-scanningprovider-documentation · last read 2026-10-06 · latest outcome read · supports Cited by the legacy dossier research for this family
- vercel.com/docs/integrations/create-integration/vercel-api-integrationsprovider-documentation · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
Provider documented ·
taxonomy-sources· current · observed 2026-09-29The legacy taxonomy lists 2 sources for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- vercel.com/changelog/new-token-formats-and-secret-scanningprovider-documentation · last read 2026-10-06 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
- vercel.com/docs/integrations/create-integration/vercel-api-integrationsprovider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Issuance
- create an integration and run the OAuth code exchange; record structure only (marker with
_, total length 60, body alphabet, whether the last 6 characters are base62(CRC-32) of the previous 50), then revoke.
In this benchmark
No fixtures in this family yet
Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.
Not measured
Benchmark dossier questions
- Blocked by
- No provider source writes vci_ with the underscore; the 56-character body rests on peer rules only (1 class). Needs ruling Q-VC or one integration token measured (checklist in redact-secret#1013).
Scanner rules for this family
No peer rule maps to this family
None of the reviewed peer scanners has a rule that can match a credential of this family.
None mapped
No fixtures in this family yet
Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.
Not measured
Sources
Documentation and code
- vercel.com/changelog/new-token-formats-and-secret-scanning
- vercel.com/docs/integrations/create-integration/vercel-api-integrations
- github.com/mongodb/kingfisher/blob/88d3f780fad83960aaddfcf732a690049853ccc9/crates/kingfisher-rules/data/rules/vercel.yml#L92-L132
- github.com/betterleaks/betterleaks/blob/2a387a5bad4290a84b9a1eb679bffe70611218cc/cmd/generate/config/rules/vercel.go#L81-L114
- github.com/secretlint/secretlint/blob/e8fc91351add9eebfd5eec5bdd7cd0d551d5e42a/packages/@secretlint/secretlint-rule-vercel/src/index.ts#L27-L58
- github.blog/changelog/2026-03-10-secret-scanning-pattern-updates-march-2026/
Research log
- redact-secret/redact-secret#858Research issue
- redact-secret/redact-secret#516Research issue
- redact-secret/redact-secret-benchmarks#367Research issue
- redact-secret/redact-secret-benchmarks#373Research issue
- redact-secret/redact-secret-benchmarks#473Research issue
- redact-secret/redact-secret#1013Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/add1188fed9993723c59fbce8c867086b9d2049a/docs/audits/evidence/1013/vercel.md