redact-secret · Report
API key (pa- or al-)
Voyage AI platform key (pa-) and MongoDB Atlas model API key (al-, al-eu-, al-us-); a 43-character [A-Za-z0-9_-] body rests on one scanner rule with no cited origin.
Research record
What blocks the research
- Issuance-gatedEvery 43-character body source traces to MongoDB. al- needs ruling Q-VO1 or Q-VO2, pa- needs Q-VO2 or one dashboard key; al-eu- needs one EU-scoped key in any case (checklists in redact-secret#1013).
2 events in the review history: 1 observed, 1 reviewed. Latest: observed on 2026-09-29 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
Shape not recorded.
Format facts
Tool corroborated ·
dossier-research· current · observed 2026-09-29Legacy dossier research (verdict issuance-gated, tier T2) cited 7 sources; the dossier does not attribute sources to individual properties.
- betterleaks/betterleaks @ 2bc07526bd83d8402bed0f7991c4d3e60f345af3: cmd/generate/config/rules/voyageai.goother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- mongodb/docs @ 2fdb2535da7d5595a9974569f1e7b981b797cd45: content/voyageai/source/management/api-keys.txtprovider-documentation · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L119-L121
- mongodb-labs/ai-ml-pipeline-testing @ dce1cd9ec156d602b7af040678bcb022bbbf1159: .evergreen/utils.shprovider-sdk-source · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L134-L146
- mongodb/openapi @ 5e6f651422c9ac9efd2ad21eba8a4256c38af864: openapi/v2.yamlprovider-documentation · last read 2026-10-06 · latest outcome read · supports Cited by the legacy dossier research for this family · #L1781-L1798
- redact-secret/redact-secret @ add1188fed9993723c59fbce8c867086b9d2049a: docs/audits/evidence/1013/voyage-ai-api-key.mdproject-research-note · last read 2026-09-29 · latest outcome read · supports Final research evidence recorded by the legacy dossier
- voyage-ai/voyageai-python @ cf6b295b691f4923946cd13fd8c2efdd9344d74a: voyageai/util.pyprovider-sdk-source · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- www.mongodb.com/docs/voyageai/management/api-keys/provider-documentation · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
Tool corroborated ·
taxonomy-sources· current · observed 2026-09-29The legacy taxonomy lists 3 sources for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- github.com/redact-secret/redact-secret/issues/785issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
- voyage-ai/voyageai-python @ cf6b295b691f4923946cd13fd8c2efdd9344d74a: voyageai/util.pyprovider-sdk-source · last read 2026-09-29 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
- www.mongodb.com/docs/voyageai/management/api-keys/provider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- standalone keys start
pa-; Atlas keys startal-, with region-scoped variants (al-eu-is documented;al-us-is not stated anywhere found). The provider says prefixes "encode the scope". Its "can't exceed 250 characters" is the limit on a key's name (name: maxLength: 250in the Atlas Admin API schema), not on the key; an earlier reading here took it as a key-length ceiling (corrected by redact-secret#1013). The candidate body is 43 characters of[A-Za-z0-9_-](46 in all for the unscoped forms), gated on a Voyage name, host or SDK context. - Basis
- T1 for both prefixes: the Python SDK routes
al-keys tohttps://ai.mongodb.com/v1, and MongoDB's own pipeline tests (2026-09-11) state that dashboard keys beginpa-and Atlas keys beginal-; MongoDB's docs (2026-09-01) stateal-eu-for EU-scoped keys. For the body, redact-secret#1013 found the Atlas Admin API OpenAPI example (AiModelApiKeyResponse, 2026-07-14): one full-lengthal-+ 43 alphanumeric value, withmaskedSecretal-+****+ 4. The betterleaks rule (PR #324, 2026-08-31) and Kingfisher's native rules (pa-2025-12-05,al-2026-05-18) were written by a MongoDB engineer who says so in the PR, so every body source is one MongoDB voice and the corroborated route fails for want of a third independent owner. Third-party code checks thepa-prefix only. - Issuance
- not attempted. The #785 checklist covers one standalone key and one Atlas key: prefix, body length,
_and-, region-scoped variants, masked list view and signup-issued keys. - Contract in core
- none recorded; #785 concluded pending. Named assignment, Bearer, JSON, YAML and tool-call forms were measured as covered by generic paths, and the one-line SDK-call miss is a generic gap. See detector-families.md.
In this benchmark
No fixtures in this family yet
Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.
Not measured
Benchmark dossier questions
- Blocked by
- Every 43-character body source traces to MongoDB. al- needs ruling Q-VO1 or Q-VO2, pa- needs Q-VO2 or one dashboard key; al-eu- needs one EU-scoped key in any case (checklists in redact-secret#1013).
Looks like it, but isn't
- Collisions
pa-andal-are common two-letter prefixes (slugs,al-transliterations), and a 43-character base64url value matches a SHA-256 digest. Placeholders such aspa-your-key-hereand model names likevoyage-3are benign. Key ids and names are public.
Scanner rules for this family
No peer rule maps to this family
None of the reviewed peer scanners has a rule that can match a credential of this family.
None mapped
No fixtures in this family yet
Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.
Not measured
Sources
Documentation and code
- www.mongodb.com/docs/voyageai/management/api-keys/
- github.com/voyage-ai/voyageai-python/blob/cf6b295b691f4923946cd13fd8c2efdd9344d74a/voyageai/util.py
- github.com/redact-secret/redact-secret/issues/785
- github.com/betterleaks/betterleaks/blob/2bc07526bd83d8402bed0f7991c4d3e60f345af3/cmd/generate/config/rules/voyageai.go
- github.com/mongodb/openapi/blob/5e6f651422c9ac9efd2ad21eba8a4256c38af864/openapi/v2.yaml#L1781-L1798
- github.com/mongodb/docs/blob/2fdb2535da7d5595a9974569f1e7b981b797cd45/content/voyageai/source/management/api-keys.txt#L119-L121
- github.com/mongodb-labs/ai-ml-pipeline-testing/blob/dce1cd9ec156d602b7af040678bcb022bbbf1159/.evergreen/utils.sh#L134-L146
Research log
- redact-secret/redact-secret#785Research issue
- redact-secret/redact-secret#774Research issue
- redact-secret/redact-secret#1013Research issue
- redact-secret/redact-secret-benchmarks#384Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/add1188fed9993723c59fbce8c867086b9d2049a/docs/audits/evidence/1013/voyage-ai-api-key.md