Skip to content
KeyDrift
Scan for free
← Support & documentation

Reading a report

Field-by-field tour: label, provider, severity, confidence, mask, fingerprint, chunk path — and what to do next for each.

2 min read

Reports state facts with enough precision to act immediately.

Anatomy of one finding

  • Label/Provider — what rule matched (e.g., Supabase service_role JWT).
  • Severity — critical/high/medium/low/info with rationale below.
  • Confidence — engine certainty; below 0.5 matches are dropped entirely, never caveated.
  • Masked value — first 8 + last 4 characters, never more than half.
  • Fingerprint — salted hash enabling tracking without revealing the value.
  • Chunk path + scanned URL — exactly where it lives.

Severity ladder

Critical: bypass-everything keys (service_role, sk_live_, AKIA pairs, private keys). High: scoped-but-serious (rk_, whsec_, email providers). Medium: test-mode or expired material. Low/info: unknown JWTs, public-by-design formats.

Next step always

Each finding links its fix guide; incident-class findings link runbooks ordered rotate-first.

The bigger picture

Zoom out and the pattern is bigger than one repo. AI-assisted output has outgrown review capacity everywhere at once, which means thousands of teams are making the same reasonable-looking tradeoffs in the same week. Nobody using modern tooling is uniquely exposed. The failure mode documented above is the modal outcome of velocity without verification, not evidence of carelessness.

How KeyDrift reports this exact finding

Report anatomy matters during incidents, so it is worth reading once calmly: masked string (never the live value — it ceases to exist outside the detection engine), salted fingerprint (trackable within your workspace, useless to strangers), chunk path (your starting point for a "git log -S" hunt), disposition (secret versus public-by-design), confidence (matches below 0.5 never reach the page at all).

Manual check, step by step

The full manual drill, for readers who want zero dependence on any tool: open the deployed site in a private window; launch DevTools → Sources; use Search-all-files (Ctrl/Cmd+Shift+F) for keydrift report fields; then repeat for the other marker families — eyJ, sk_live_, sk-proj-, AKIA, postgres, BEGIN PRIVATE KEY. Decode anything JWT-shaped before reacting, and classify public-by-design formats as expected guests rather than intruders.

Close the loop with monitoring

If you take one operational step from this page, make it this: put the URL under continuous monitoring (free tier covers one project daily). The first scan tells you whether you have a problem today; the schedule tells you whether the problem comes back next month after someone re-adds the convenient line.

Where this fits

This document is part of the support knowledge base that mirrors production behaviour exactly: detector counts, plan limits and payload shapes on these pages are computed from the same catalogs that power the product, and tests assert they cannot drift. If anything here contradicts observed behaviour, report it via the false-positive process — calibration improves fastest when reality disagrees loudly.


Run a free scan at keydrift.dev/scan — paste a URL or the bundle source itself, no account. Findings arrive masked, with the exact chunk they live in.

Published by PostHat, KeyDrift’s content pipeline. Every factual claim is grounded in KeyDrift’s product documentation.