Skip to content
Benchmarks

redact-secret · Report

API key

xai- prefixed API key; the 80-character body is documented only by the provider's example and corroborated by tools.

  • xAI
  • Detectors: xai-api-key
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictReady
  • Dossier evidence levelT2 · Tool-corroborated
  • Dossier researched2026-09-24
Registry detector xai-api-key since redact-secret#727 (registry pinned at dad7868); graduated from a Beta.8 arrival family (#208, research #216), contract in benchmarks/lib/beta8/208.ts. Management keys (tool-reported xai-token- prefix, XAI_MANAGEMENT_KEY) are a separate credential and not members of this family; no taxonomy family is added for them until the provider documents a format.

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · current
  • ResearchResearched
  • Researched2026-09-24

3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-24 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Descriptive pattern
^xai-[A-Za-z0-9_-]{80}$

Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.

Format facts

  • Unresolved · tool-corroboration · current · observed 2026-09-24

    Pinned scanner rules are consistent with the contract grammar (1 artifact: trufflehog 3.97.4).

  • Provider documented · field-prefix · current · observed 2026-09-24

    prefix: xai-

  • Provider documented · field-body-length · current · observed 2026-09-24

    body-length: 80 characters after xai- (Documented by example plus tool corroboration, not a provider-stated grammar; the contract is T2 for that reason.)

  • Provider documented · field-body-alphabet · current · observed 2026-09-24

    body-alphabet: [A-Za-z0-9] in every positive; TruffleHog admits _, betterleaks admits _ and - (The contract pattern admits _ and - so no control asserts silence on them.)

  • Unresolved · field-right-boundary · current · observed 2026-09-24

    right-boundary: Behaviour on an 81st word character: TruffleHog \b rejects, osv-scalibr truncates to 80, Kingfisher anchors exactly

  • Unresolved · field-management-key · current · observed 2026-09-24

    management-key: Management keys (XAI_MANAGEMENT_KEY) are a separate credential; tools report an xai-token- prefix (Not a member of this family and never used as a benign control of it (a real secret).)

  • Unresolved · listed-references · current · observed 2026-09-24

    The legacy contract lists 3 references without stating which property each supports.

  • Unresolved · dossier-research · current · observed 2026-09-24

    Legacy dossier research (verdict ready, tier T2) cited 4 sources; the dossier does not attribute sources to individual properties.

  • Unresolved · taxonomy-sources · current · observed 2026-09-24

    The legacy taxonomy lists 2 sources for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
prefix xai- followed by 80 characters. The provider's API-key response schema shows one example with an 80-character alphanumeric body; the docs never state the length or the alphabet in prose. A third-party masked error (LiteLLM, 2025-03) also shows an 80-character body. The alphabet is contested: TruffleHog admits _, betterleaks admits _ and -, the others accept letters and digits only. No real key with _ or - was seen.
Basis
the family tier follows the assessment contract (T2, #208 record: the prefix is provider-documented, the body is not); the prefix alone is T1. Length is provider-example plus tool rules; alphabet is unresolved. The official Python SDK reads XAI_API_KEY and validates nothing. GitHub lists xAI as a secret-scanning partner (regex not published).
Issuance
not attempted; a free console account can create a key. Checklist in benchmarks#216.
Contract in core
detector-families.md (frozen in the #726 record: 80 characters from the provisional union alphabet).

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.
Fixtures
41
Left readable
0
Redacted too much
0
False alarms
0

41 fixtures: 19 expect a redaction, 22 must stay quiet. See every row

redact-secret fixture counts by evidence level
Evidence levelFixturesLeft readableToo muchFalse alarms
T2Tool-corroborated33000
T3Project policy8000

Every scanner on the same fixtures

In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.

Counts per scanner on this family's fixtures
ScannerFixturesLeft readableToo muchFalse alarms
flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine1 rule targets it41024
gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it41801
redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped41000
trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it41000

Benchmark dossier questions

Things the sources do not settle. They are listed so nobody reads them as settled.
Open caveat
T1 on the prefix only; the 80-character length rests on one provider example plus tools and the body alphabet is unresolved (checklist in benchmarks#216).

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
management keys (XAI_MANAGEMENT_KEY; tools report an xai-token- prefix, provider docs are silent). Public values next to keys: apiKeyId and teamId UUIDs, ACL strings such as api-key:endpoint:chat, xai-org and xai-sdk names, and the redacted form (xai-... plus four characters). A Groq gsk_ value stored under XAI_API_KEY is not an xAI key.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.
Peer scanner rules that target this family
ScannerRuleWhat the rule matches
flare-redact · rules 1.6.1xai_keyxai- + 40-120 characters
trufflehog · rules 3.97.4xaixai- + 80 characters

No rule maps to this family in gitleaks, openredaction.

41 of 41 rows

Fixtures in this family

41 rows, redact-secret's outcome on each. Rows that need a look come first (0), then the rest in corpus order. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in API key
FixtureKind and evidenceredact-secret
xai-api-key-bearer-long-body-twinxai · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
xai-api-key-chat-pastexai · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
xai-api-key-curl-chatxai · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
xai-api-key-env-short-body-twinxai · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
xai-api-key-http-debugxai · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
xai-api-key-key-shape-barexai · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
xai-api-key-key-shape-quotedxai · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
xai-api-key-key-shape-unicode-crlfxai · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
xai-api-key-litellm-half-body-twinxai · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
xai-api-key-openai-compatiblexai · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
xai-api-key-openai-dot-body-twinxai · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
xai-api-key-retry-logxai · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
xai-api-key-short-body-twinxai · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
xai-api-key-vault-readxai · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
xai-api-key-base64-config-encoded-valuexai · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
xai-api-key-bearer-headerxai · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
xai-api-key-docs-prosexai · prose-mentionMust not flagT3 · Project policyQuiet
xai-api-key-envxai · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
xai-api-key-env-grepxai · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
xai-api-key-env-grep-glued-twinxai · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
xai-api-key-env-lookup-referencexai · templated-referenceMust not flagT3 · Project policyQuiet
xai-api-key-env-template-placeholderxai · documentation-placeholderMust not flagT3 · Project policyQuiet
xai-api-key-exportxai · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
xai-api-key-json-profilexai · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
xai-api-key-k8s-secretxai · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
xai-api-key-key-metadata-public-idxai · public-identifierMust not flagT2 · Tool-corroboratedQuiet
xai-api-key-label-prosexai · benign-lookalikeMust not flagT3 · Project policyQuiet
xai-api-key-litellm-configxai · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
xai-api-key-maskxai · benign-lookalikeMust not flagT3 · Project policyQuiet
xai-api-key-masked-error-placeholderxai · documentation-placeholderMust not flagT3 · Project policyQuiet
xai-api-key-packages-and-models-public-idxai · public-identifierMust not flagT2 · Tool-corroboratedQuiet
xai-api-key-prefix-check-near-missxai · format-near-missMust not flagT2 · Tool-corroboratedQuiet
xai-api-key-prefix-letter-twinxai · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
xai-api-key-prefix-onlyxai · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
xai-api-key-redacted-api-placeholderxai · documentation-placeholderMust not flagT3 · Project policyQuiet
xai-api-key-referencexai · benign-lookalikeMust not flagT3 · Project policyQuiet
xai-api-key-short-bodyxai · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
xai-api-key-twin-base-dotenvxai · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
xai-api-key-twin-base-tsxai · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
xai-api-key-vercel-aixai · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
xai-api-key-vercel-underscore-prefix-twinxai · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet

Sources

Researched 2026-09-24.

Documentation and code

Research log