{
  "version": 3,
  "note": "The names of link parameters whose values are secrets: a password-reset or magic-login token, an OAuth code, a session id, a signed URL's signature, a shared document's resource key, a one-time code. A reported link's value under such a name is replaced by [removed] before the report is written, and before any request for the page leaves the case run (worker/src/redact.js; tools/report_files.py redact_secrets; the vectors in tests/vectors/secret-parameters-v2.json). A name matches when any of its words (split on anything but letters and digits, and at a camel-case boundary, after percent-decoding and lower-casing) is one of the words, or when its letters and digits end with one of the suffixes. The same table names the path segments a token may follow: a token-shaped segment (16 characters or more of the token alphabets, letters with digits or both cases, an entropy of 3.0 bits per character or more) is replaced by [removed] when one of the two segments before it matches, as in reset/<token>, magic/<token> or reset/<uid>/<token>, and such a link is not fetched by the case run at all. The list errs toward removing: a value removed by mistake costs the reporter one tick on the report page, a secret kept costs someone their account.",
  "words": [
    "token",
    "key",
    "code",
    "auth",
    "authorization",
    "session",
    "sessionid",
    "sessid",
    "sid",
    "sig",
    "signature",
    "password",
    "passwd",
    "pwd",
    "pass",
    "passphrase",
    "passcode",
    "pin",
    "secret",
    "otp",
    "totp",
    "csrf",
    "xsrf",
    "credential",
    "credentials",
    "jwt",
    "bearer",
    "nonce",
    "ticket",
    "apikey",
    "accesstoken",
    "idtoken",
    "refreshtoken",
    "resourcekey",
    "cvv",
    "cvc",
    "hash",
    "confirm",
    "confirmation",
    "activation",
    "activate",
    "verify",
    "verification",
    "verifier",
    "reset",
    "invite",
    "invitation",
    "unsubscribe",
    "access",
    "magic",
    "login",
    "mfa",
    "2fa",
    "tan",
    "assertion",
    "samlresponse",
    "oauth",
    "signin",
    "recover",
    "recovery",
    "passwordless",
    "autologin",
    "sso"
  ],
  "suffixes": [
    "token",
    "key",
    "secret",
    "password",
    "passwd",
    "signature",
    "session",
    "sessionid",
    "sessid",
    "login",
    "auth"
  ]
}
