Skip to content
Benchmarks

redact-secret · Report

API key (wandb_v1_)

wandb_v1_ + [A-Za-z0-9_] to about 86 characters in all (86 in every provider fixture); the legacy 40-hex key stays with generic context.

  • Weights & Biases
  • Detectors: wandb-api-key
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictReady
  • Dossier evidence levelT1 · Provider-documented
  • Dossier researched2026-09-28
Registry detector wandb-api-key since redact-secret#917 (registry pinned at 1127bf9); graduated from a Beta.11 arrival family (#436), contract in benchmarks/lib/beta8/436f.ts. T1 on the provider test constant (R5) and SDK validator (R1); length measured around 86 with no length asserted. trufflehog 3.97.4 registers only the keyword-gated legacy rule by default.

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · current
  • ResearchResearched
  • Researched2026-09-28

3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-28 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Descriptive pattern
^wandb_v1_[A-Za-z0-9_]{76,78}$

Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.

Format facts

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
prefix wandb_v1_, 86 characters in total (body 77), alphabet [A-Za-z0-9_]. Self-managed keys are <host>-<key>; the host label is outside the key.
Basis
prefix T1 from a W&B-authored test constant (R5). Length T1 by example: the docs say "W&B now issues longer API keys (about 86 characters)", the SDK validator tests (wandb#10688) use 39, 40 and 86, and Weave fixtures use 86. Alphabet T1 from the SDK validator ([\w-]+, dash only for the on-prem host prefix) and its error text (R1). Scanner rules add an internal underscore split (27 then 49), which is T2 and not required by the handoff. Re-checked 2026-09-28.
Issuance
not attempted; recommended because of the "about" in the docs.
Contract in core
detector-families.md. That contract uses a tolerant 64 to 96 band around the documented width by an orchestrator decision on #917, wider than the handoff's exact 86; the handoff verdict here is unchanged.

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.
Fixtures
35
Left readable
0
Redacted too much
0
False alarms
0

35 fixtures: 16 expect a redaction, 19 must stay quiet. See every row

redact-secret fixture counts by evidence level
Evidence levelFixturesLeft readableToo muchFalse alarms
T1Provider-documented16000
T2Tool-corroborated11000
T3Project policy8000

Every scanner on the same fixtures

In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.

Counts per scanner on this family's fixtures
ScannerFixturesLeft readableToo muchFalse alarms
flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it351510
gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it35800
redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped35000
trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it35600

Benchmark dossier questions

Things the sources do not settle. They are listed so nobody reads them as settled.
Open caveat
The docs say "about 86" characters; every provider test uses exactly 86, but a confirming issuance is recommended (does not block the contract).

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
the legacy 40-hex key is SHA-1 and git-SHA shaped with no anchor; generic context already redacts it under WANDB_API_KEY=. Internal client JWTs go to the JWT detector.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.
Peer scanner rules that target this family
ScannerRuleWhat the rule matches
trufflehog · rules 3.97.4weightsandbiases/v2wandb_v1_ + 27 + _ + 49 characters

No rule maps to this family in flare-redact, gitleaks, openredaction.

35 of 35 rows

Fixtures in this family

35 rows, redact-secret's outcome on each. Rows that need a look come first (0), then the rest in corpus order. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in API key (wandb_v1_)
FixtureKind and evidenceredact-secret
wandb-api-key-bare-prosewandb · documented-format-literalMust redactT1 · Provider-documentedRedacted
wandb-api-key-bearer-headerwandb · documented-format-literalMust redactT1 · Provider-documentedRedacted
wandb-api-key-chat-pastewandb · documented-format-literalMust redactT1 · Provider-documentedRedacted
wandb-api-key-dotenvwandb · documented-format-literalMust redactT1 · Provider-documentedRedacted
wandb-api-key-exportwandb · documented-format-literalMust redactT1 · Provider-documentedRedacted
wandb-api-key-json-api-keywandb · documented-format-literalMust redactT1 · Provider-documentedRedacted
wandb-api-key-json-tokenwandb · documented-format-literalMust redactT1 · Provider-documentedRedacted
wandb-api-key-key-shape-barewandb · documented-format-literalMust redactT1 · Provider-documentedRedacted
wandb-api-key-key-shape-quotedwandb · documented-format-literalMust redactT1 · Provider-documentedRedacted
wandb-api-key-key-shape-unicode-crlfwandb · documented-format-literalMust redactT1 · Provider-documentedRedacted
wandb-api-key-mcp-envwandb · documented-format-literalMust redactT1 · Provider-documentedRedacted
wandb-api-key-netrc-passwordwandb · documented-format-literalMust redactT1 · Provider-documentedRedacted
wandb-api-key-on-prem-host-labelwandb · documented-format-literalMust redactT1 · Provider-documentedRedacted
wandb-api-key-sdk-kwargwandb · documented-format-literalMust redactT1 · Provider-documentedRedacted
wandb-api-key-wandb-loginwandb · documented-format-literalMust redactT1 · Provider-documentedRedacted
wandb-api-key-x-api-key-headerwandb · documented-format-literalMust redactT1 · Provider-documentedRedacted
wandb-api-key-actions-secret-referencewandb · templated-referenceMust not flagT3 · Project policyQuiet
wandb-api-key-ellipsis-placeholderwandb · documentation-placeholderMust not flagT3 · Project policyQuiet
wandb-api-key-entity-and-project-public-idwandb · public-identifierMust not flagT2 · Tool-corroboratedQuiet
wandb-api-key-env-reference-referencewandb · templated-referenceMust not flagT3 · Project policyQuiet
wandb-api-key-git-sha-encoded-valuewandb · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
wandb-api-key-hyphen-in-body-twinwandb · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
wandb-api-key-hyphen-prefix-twinwandb · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
wandb-api-key-key-guidance-prosewandb · prose-mentionMust not flagT3 · Project policyQuiet
wandb-api-key-label-prosewandb · benign-lookalikeMust not flagT3 · Project policyQuiet
wandb-api-key-leading-glue-twinwandb · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
wandb-api-key-leading-underscore-twinwandb · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
wandb-api-key-maskwandb · benign-lookalikeMust not flagT3 · Project policyQuiet
wandb-api-key-prefix-onlywandb · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
wandb-api-key-referencewandb · benign-lookalikeMust not flagT3 · Project policyQuiet
wandb-api-key-short-bodywandb · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
wandb-api-key-test-constant-shape-placeholderwandb · documentation-placeholderMust not flagT3 · Project policyQuiet
wandb-api-key-trailing-hyphen-twinwandb · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
wandb-api-key-uppercase-prefix-twinwandb · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
wandb-api-key-version-identifiers-public-idwandb · public-identifierMust not flagT2 · Tool-corroboratedQuiet

Sources

Researched 2026-09-28.

Documentation and code

  • docs.wandb.ai/support/models/articles/why-does-my-api-key-fail-with-must-be-40-characters
  • github.com/wandb/wandb/blob/98f93d636e523bf6e195a2a154f23ba8775623a9/wandb/sdk/lib/wbauth/validation.py#L26-L63
  • github.com/wandb/wandb/pull/10688
  • github.com/wandb/weave-claude-code/blob/8c4111adbafe7abf15312b3188eb69a0b7bf8f79/tests/config-set-masks-secrets.test.ts#L13

Research log