# Keychecker Layout Normal input and authority: ```text PostgreSQL keycheck_candidates fenced provider work queue PostgreSQL keycheck_results authoritative history PostgreSQL keycheck_current_state authoritative current classification D:\truf\runtime\proxy.txt optional provider proxy input ``` `found_secrets.jsonl`, `*Results.jsonl`, and `*Checked.txt`/status files are projector-owned compatibility outputs. They may lag and normal providers do not read or write them. Shared helper: ```text D:\truf\app\keycheckers\keycheck_common.py ``` `keycheck_runner.py --input-mode postgres` is the default managed mode. `--input` is accepted only with explicit `--input-mode jsonl` for reviewed offline/import compatibility. Provider completion inserts the result, updates current state, completes the exact candidate lease, releases candidate capacity, and creates its projection job in one PostgreSQL transaction. ## DeepSeek ```powershell python supervisor.py --config config.yaml --cmd "recheck deepseek all --max-keys 100" ``` Output folder: ```text deepseek\deepseekAlive.txt deepseek\deepseekNoBalance.txt deepseek\deepseekDead.txt deepseek\deepseekLimited.txt deepseek\deepseekNetwork.txt deepseek\deepseekUnknown.txt deepseek\deepseekChecked.txt deepseek\deepseekResults.jsonl ``` ## Qwen / DashScope ```powershell python supervisor.py --config config.yaml --cmd "recheck qwen all --max-keys 100" ``` The checker validates `QwenDashScope` findings with `GET /models` against the public DashScope OpenAI-compatible region endpoints. Coding Plan keys (`sk-sp-...`) use `https://coding-intl.dashscope.aliyuncs.com/v1` by default. Workspace-specific endpoints can be added with `--base-url` via `keychecks.service_args.qwen` or `QWEN_BASE_URLS`. Output folder: ```text qwen\qwenAlive.txt qwen\qwenNoBalance.txt qwen\qwenNoContext.txt qwen\qwenDead.txt qwen\qwenLimited.txt qwen\qwenRestricted.txt qwen\qwenNetwork.txt qwen\qwenUnknown.txt qwen\qwenChecked.txt qwen\qwenResults.jsonl ``` ## Kimi / Moonshot AI ```powershell python supervisor.py --config config.yaml --cmd "recheck kimi all --max-keys 100" ``` The explicit `MOONSHOT_API_KEY` / `KIMI_API_KEY` detector is validated without generation by calling `GET /v1/users/me/balance` on the independent global and China Moonshot endpoints. Output folder: ```text kimi\kimiAlive.txt kimi\kimiNoBalance.txt kimi\kimiDead.txt kimi\kimiLimited.txt kimi\kimiRestricted.txt kimi\kimiNetwork.txt kimi\kimiUnknown.txt kimi\kimiChecked.txt kimi\kimiResults.jsonl ``` ## Groq ```powershell python supervisor.py --config config.yaml --cmd "recheck groq all --max-keys 100" ``` The checker validates TruffleHog `Groq` findings with `GET https://api.groq.com/openai/v1/models` and does not run generation probes. Output folder: ```text groq\groqAlive.txt groq\groqDead.txt groq\groqLimited.txt groq\groqRestricted.txt groq\groqNetwork.txt groq\groqUnknown.txt groq\groqChecked.txt groq\groqResults.jsonl ``` ## Replicate / xAI / HuggingFace ```powershell python supervisor.py --config config.yaml --cmd "recheck replicate all --max-keys 100" python supervisor.py --config config.yaml --cmd "recheck xai all --max-keys 100" python supervisor.py --config config.yaml --cmd "recheck huggingface all --max-keys 100" ``` These checkers validate built-in TruffleHog findings through non-generating endpoints: Replicate account lookup, xAI model list, and HuggingFace whoami. ## Anthropic ```powershell python supervisor.py --config config.yaml --cmd "recheck anthropic all --max-keys 100" ``` Output folder: ```text anthropic\anthropicAlive.txt anthropic\anthropicNoQuota.txt anthropic\anthropicDead.txt anthropic\anthropicLimited.txt anthropic\anthropicRestricted.txt anthropic\anthropicNetwork.txt anthropic\anthropicUnknown.txt anthropic\anthropicChecked.txt anthropic\anthropicResults.jsonl ``` ## AWS Default mode only checks STS identity: ```powershell python supervisor.py --config config.yaml --cmd "recheck aws all --max-keys 100" ``` Optional Bedrock probing is configured under `keychecks.service_args.aws`, then run: ```powershell python supervisor.py --config config.yaml --cmd "recheck aws all --max-keys 100" ``` Output folder: ```text aws\awsAlive.txt aws\awsBedrock.txt aws\awsAdmin.txt aws\awsCanary.txt aws\awsQuarantined.txt aws\awsAccessDenied.txt aws\awsDead.txt aws\awsNetwork.txt aws\awsUnknown.txt aws\awsChecked.txt aws\awsResults.jsonl ``` Canary AWS credentials are detected before active AWS probes when TruffleHog provides `ExtraData.is_canary` / canary message. If metadata is absent, STS ARN containing `canarytokens` is also classified as `awsCanary.txt` and IAM/Bedrock probes are skipped. ## Azure ```powershell python supervisor.py --config config.yaml --cmd "recheck azure all --max-keys 100" ``` This checks Azure service-principal findings from `DetectorName=Azure` using `tenantId`, `clientId`, `clientSecret` from `RawV2`. `DetectorName=AzureOpenAI` is placed into `azureOpenAIUnresolved.txt` unless an endpoint/resource name is available. Output folder: ```text azure\azureAlive.txt azure\azureDead.txt azure\azureRestricted.txt azure\azureNetwork.txt azure\azureUnknown.txt azure\azureOpenAIUnresolved.txt azure\azureChecked.txt azure\azureResults.jsonl ``` ## Retry Flags Common flags: ```text --retry-network --retry-limited --retry-unknown --recheck-all --max-keys N ``` Network/proxy failures are committed with the `network` status group and can be selected for a bounded PostgreSQL recheck. `*Network.txt` is only its asynchronous compatibility projection.