redact-secret · Report
API key (wandb_v1_)
wandb_v1_ + [A-Za-z0-9_] to about 86 characters in all (86 in every provider fixture); the legacy 40-hex key stays with generic context.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-28 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^wandb_v1_[A-Za-z0-9_]{76,78}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Provider documented ·
provider-source· current · observed 2026-09-28wandb SDK validation.py at 98f93d6 ([\w-]+, 40+; "may only contain the letters A-Z, digits and underscores"), the wandb_v1_ weave-claude-code test constant (R5), #10688 test keys of 86, docs "about 86 characters" (re-checked 2026-09-28): wandb_v1_ + [A-Za-z0-9_] to about 86 in all; every provider test fixture of a new key is exactly 86; no separator is required
- wandb/wandb @ 98f93d636e523bf6e195a2a154f23ba8775623a9: wandb/sdk/lib/wbauth/validation.pyprovider-documentation · last read 2026-09-28 · latest outcome read · supports wandb_v1_ + [A-Za-z0-9_] to about 86 in all; every provider test fixture of a new key is exactly 86; no separator is required · #L26-L63
Unresolved ·
tool-corroboration· current · observed 2026-09-28Pinned scanner rules are consistent with the contract grammar (1 artifact: trufflehog 3.97.4).
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/weightsandbiases/v2/weightsandbiases.goscanner-rule-source · last read 2026-09-28 · latest outcome read · supports trufflehog 3.97.4: Weights & Biases v2 (feature-gated, off by default): \b(wandb_v1_[A-Za-z0-9]{27}_[A-Za-z0-9]{49})\b
Provider documented ·
field-prefix· current · observed 2026-09-28prefix: wandb_v1_
- github.com/redact-secret/redact-secret/issues/860issue-or-discussion · last read 2026-09-29 · latest outcome read · supports R5 · #issuecomment-5871306275
- wandb/weave-claude-code @ 8c4111adbafe7abf15312b3188eb69a0b7bf8f79: tests/config-set-masks-secrets.test.tsprovider-sdk-source · last read 2026-09-28 · latest outcome read · supports W&B-authored test constant, 44 characters, placeholder-grade: prefix only · #L13
Provider documented ·
field-alphabet· current · observed 2026-09-28alphabet: [A-Za-z0-9_]; a - is only the on-prem <host>- separator
- github.com/redact-secret/redact-secret/issues/860issue-or-discussion · last read 2026-09-29 · latest outcome read · supports R1 · #issuecomment-5852413851
- wandb/wandb @ 98f93d636e523bf6e195a2a154f23ba8775623a9: wandb/sdk/lib/wbauth/validation.pyprovider-documentation · last read 2026-09-28 · latest outcome read · supports fullmatch [\w-]+ and the letters/digits/underscores error text · #L26-L63
Provider documented ·
field-total-length· current · observed 2026-09-28total-length: about 86; exactly 86 in every provider test fixture of a new key (Positives carry 85, 86 and 87 (86 in most). No length twin is authored: the tolerant range is the product's, and the benchmark cannot prove any length is not a key.)
- docs.wandb.ai/support/models/articles/why-does-my-api-key-fail-with-must-be-40-charactersprovider-documentation · last read 2026-09-28 · latest outcome read · supports "about 86 characters"
- github.com/redact-secret/redact-secret/issues/917provider-documentation · last read 2026-09-28 · latest outcome read · supports orchestrator decision: a bounded tolerant range around 86
- github.com/wandb/wandb/pull/10688provider-documentation · last read 2026-09-28 · latest outcome read · supports validator tests with keys of 39, 40 and 86
Unresolved ·
field-inner-split· current · observed 2026-09-28inner-split: an _ after 27 body characters (the Key ID) (Positives carry both a split body and one with no inner _; neither is asserted as a negative.)
- redact-secret/redact-secret @ 54fe385f718c884d7e3dde6b9756e2d70999ca91: docs/audits/evidence/860/wandb.mdprovider-sdk-source · last read 2026-09-28 · latest outcome read · supports scanner-only, not required
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/weightsandbiases/v2/weightsandbiases.goscanner-rule-source · last read 2026-09-28 · latest outcome read · supports 27/_/49
Provider documented ·
field-host-prefix· current · observed 2026-09-28host-prefix: self-managed keys are <host>-<key>; the host label is public (Authored as an envelope: the secret span is the wandb_v1_ key.)
- redact-secret/redact-secret @ 54fe385f718c884d7e3dde6b9756e2d70999ca91: docs/audits/evidence/860/wandb.mdprovider-sdk-source · last read 2026-09-28 · latest outcome read · supports local- + 86 in the Weave fixtures
- wandb/wandb @ 98f93d636e523bf6e195a2a154f23ba8775623a9: wandb/sdk/lib/wbauth/validation.pyprovider-documentation · last read 2026-09-28 · latest outcome read · supports dashes are allowed only because <host>- is split off · #L26-L63
Unresolved ·
field-other-versions· current · observed 2026-09-28other-versions: whether a wandb_v2_ or another version exists (No fixture asserts silence on another version.)
- redact-secret/redact-secret @ 54fe385f718c884d7e3dde6b9756e2d70999ca91: docs/audits/evidence/860/wandb.mdprovider-sdk-source · last read 2026-09-28 · latest outcome read · supports a future wandb_v2_ is an accepted false negative
Provider documented ·
field-legacy-key· current · observed 2026-09-28legacy-key: the legacy key is 40 lowercase hex (optionally <host>- + 40), with no anchor (Not this family. A bare 40-hex git SHA is a control; a legacy key under WANDB_API_KEY= is not authored either way.)
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/weightsandbiases/v1/weightsandbiases.goprovider-sdk-source · last read 2026-09-28 · latest outcome read · supports keyword-gated [0-9a-f]{40}
- wandb/wandb @ 98f93d636e523bf6e195a2a154f23ba8775623a9: wandb/sdk/lib/wbauth/validation.pyprovider-documentation · last read 2026-09-28 · latest outcome read · supports 40+ · #L26-L63
Provider documented ·
field-transport· current · observed 2026-09-28transport: the WANDB_API_KEY environment variable, ~/.netrc for api.wandb.ai, sent as Basic api:<key>
- docs.wandb.ai/guides/track/environment-variables/provider-documentation · last read 2026-09-28 · latest outcome read · supports transport: the WANDB_API_KEY environment variable, ~/.netrc for api.wandb.ai, sent as Basic api:<key>
Tool corroborated ·
field-peer-lag· current · observed 2026-09-28peer-lag: trufflehog 3.97.4 registers only the keyword-gated legacy v1 rule by default (v2 is feature-gated); gitleaks 8.30.1 has no W&B rule
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports no wandb rule
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/weightsandbiases/v1/weightsandbiases.goprovider-sdk-source · last read 2026-09-28 · latest outcome read · supports peer-lag: trufflehog 3.97.4 registers only the keyword-gated legacy v1 rule by default (v2 is feature-gated); gitleaks 8.30.1 has no W&B rule
Unresolved ·
listed-references· current · observed 2026-09-28The legacy contract lists 12 references without stating which property each supports.
- docs.wandb.ai/support/models/articles/why-does-my-api-key-fail-with-must-be-40-charactersprovider-documentation · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract
- docs.wandb.ai/guides/track/environment-variables/provider-documentation · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract
- redact-secret/redact-secret @ 54fe385f718c884d7e3dde6b9756e2d70999ca91: docs/audits/evidence/860/wandb.mdprovider-sdk-source · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract
- redact-secret/redact-secret @ 54fe385f718c884d7e3dde6b9756e2d70999ca91: docs/audits/evidence/860/tier-b-rerank.mdproject-research-note · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/860issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract · #issuecomment-5852413851
- github.com/redact-secret/redact-secret/issues/860issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract · #issuecomment-5871306275
- github.com/redact-secret/redact-secret/issues/860issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/917provider-documentation · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret-benchmarks/issues/436issue-or-discussion · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract
- wandb/wandb @ 98f93d636e523bf6e195a2a154f23ba8775623a9: wandb/sdk/lib/wbauth/validation.pyprovider-documentation · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract · #L26-L63
- github.com/wandb/wandb/pull/10688provider-documentation · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract
- wandb/weave-claude-code @ 8c4111adbafe7abf15312b3188eb69a0b7bf8f79: tests/config-set-masks-secrets.test.tsprovider-sdk-source · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract · #L13
Provider documented ·
dossier-research· current · observed 2026-09-28Legacy dossier research (verdict ready, tier T1) cited 5 sources; the dossier does not attribute sources to individual properties.
- docs.wandb.ai/support/models/articles/why-does-my-api-key-fail-with-must-be-40-charactersprovider-documentation · last read 2026-09-28 · latest outcome read · supports Cited by the legacy dossier research for this family
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/860/wandb.mdproject-research-note · last read 2026-09-28 · latest outcome read · supports Final research evidence recorded by the legacy dossier
- wandb/wandb @ 98f93d636e523bf6e195a2a154f23ba8775623a9: wandb/sdk/lib/wbauth/validation.pyprovider-documentation · last read 2026-09-28 · latest outcome read · supports Cited by the legacy dossier research for this family · #L26-L63
- github.com/wandb/wandb/pull/10688provider-documentation · last read 2026-09-28 · latest outcome read · supports Cited by the legacy dossier research for this family
- wandb/weave-claude-code @ 8c4111adbafe7abf15312b3188eb69a0b7bf8f79: tests/config-set-masks-secrets.test.tsprovider-sdk-source · last read 2026-09-28 · latest outcome read · supports Cited by the legacy dossier research for this family · #L13
Provider documented ·
taxonomy-sources· current · observed 2026-09-28The legacy taxonomy lists 2 sources for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- docs.wandb.ai/support/models/articles/why-does-my-api-key-fail-with-must-be-40-charactersprovider-documentation · last read 2026-09-28 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
- wandb/wandb @ 98f93d636e523bf6e195a2a154f23ba8775623a9: wandb/sdk/lib/wbauth/validation.pyprovider-documentation · last read 2026-09-28 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy · #L26-L63
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- prefix
wandb_v1_, 86 characters in total (body 77), alphabet[A-Za-z0-9_]. Self-managed keys are<host>-<key>; the host label is outside the key. - Basis
- prefix T1 from a W&B-authored test constant (R5). Length T1 by example: the docs say "W&B now issues longer API keys (about 86 characters)", the SDK validator tests (wandb#10688) use 39, 40 and 86, and Weave fixtures use 86. Alphabet T1 from the SDK validator (
[\w-]+, dash only for the on-prem host prefix) and its error text (R1). Scanner rules add an internal underscore split (27 then 49), which is T2 and not required by the handoff. Re-checked 2026-09-28. - Issuance
- not attempted; recommended because of the "about" in the docs.
- Contract in core
- detector-families.md. That contract uses a tolerant 64 to 96 band around the documented width by an orchestrator decision on #917, wider than the handoff's exact 86; the handoff verdict here is unchanged.
In this benchmark
- Fixtures
- 35
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
35 fixtures: 16 expect a redaction, 19 must stay quiet. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T1Provider-documented | 16 | 0 | 0 | 0 |
| T2Tool-corroborated | 11 | 0 | 0 | 0 |
| T3Project policy | 8 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 35 | 15 | 1 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it | 35 | 8 | 0 | 0 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 35 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it | 35 | 6 | 0 | 0 |
Benchmark dossier questions
- Open caveat
- The docs say "about 86" characters; every provider test uses exactly 86, but a confirming issuance is recommended (does not block the contract).
Looks like it, but isn't
- Collisions
- the legacy 40-hex key is SHA-1 and git-SHA shaped with no anchor; generic context already redacts it under
WANDB_API_KEY=. Internal client JWTs go to the JWT detector.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| trufflehog · rules 3.97.4 | weightsandbiases/v2 | wandb_v1_ + 27 + _ + 49 characters |
No rule maps to this family in flare-redact, gitleaks, openredaction.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
wandb-api-key-bare-prosewandb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
wandb-api-key-bearer-headerwandb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
wandb-api-key-chat-pastewandb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
wandb-api-key-dotenvwandb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
wandb-api-key-exportwandb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
wandb-api-key-json-api-keywandb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
wandb-api-key-json-tokenwandb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
wandb-api-key-key-shape-barewandb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
wandb-api-key-key-shape-quotedwandb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
wandb-api-key-key-shape-unicode-crlfwandb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
wandb-api-key-mcp-envwandb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
wandb-api-key-netrc-passwordwandb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
wandb-api-key-on-prem-host-labelwandb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
wandb-api-key-sdk-kwargwandb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
wandb-api-key-wandb-loginwandb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
wandb-api-key-x-api-key-headerwandb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
wandb-api-key-actions-secret-referencewandb · templated-reference | Must not flagT3 · Project policy | Quiet |
wandb-api-key-ellipsis-placeholderwandb · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
wandb-api-key-entity-and-project-public-idwandb · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
wandb-api-key-env-reference-referencewandb · templated-reference | Must not flagT3 · Project policy | Quiet |
wandb-api-key-git-sha-encoded-valuewandb · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
wandb-api-key-hyphen-in-body-twinwandb · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
wandb-api-key-hyphen-prefix-twinwandb · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
wandb-api-key-key-guidance-prosewandb · prose-mention | Must not flagT3 · Project policy | Quiet |
wandb-api-key-label-prosewandb · benign-lookalike | Must not flagT3 · Project policy | Quiet |
wandb-api-key-leading-glue-twinwandb · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
wandb-api-key-leading-underscore-twinwandb · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
wandb-api-key-maskwandb · benign-lookalike | Must not flagT3 · Project policy | Quiet |
wandb-api-key-prefix-onlywandb · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
wandb-api-key-referencewandb · benign-lookalike | Must not flagT3 · Project policy | Quiet |
wandb-api-key-short-bodywandb · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
wandb-api-key-test-constant-shape-placeholderwandb · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
wandb-api-key-trailing-hyphen-twinwandb · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
wandb-api-key-uppercase-prefix-twinwandb · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
wandb-api-key-version-identifiers-public-idwandb · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
Sources
Documentation and code
- docs.wandb.ai/support/models/articles/why-does-my-api-key-fail-with-must-be-40-characters
- github.com/wandb/wandb/blob/98f93d636e523bf6e195a2a154f23ba8775623a9/wandb/sdk/lib/wbauth/validation.py#L26-L63
- github.com/wandb/wandb/pull/10688
- github.com/wandb/weave-claude-code/blob/8c4111adbafe7abf15312b3188eb69a0b7bf8f79/tests/config-set-masks-secrets.test.ts#L13
Research log
- redact-secret/redact-secret#860Research issue
- redact-secret/redact-secret#917Research issue
- redact-secret/redact-secret-benchmarks#436Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/8b6a5fde52ecb4dfce13f09c7a947062d21483c7/docs/audits/evidence/860/wandb.md