Files
2026-09-30 20:30:56 +03:00

5.5 KiB

Keychecker Layout

Normal input and authority:

PostgreSQL keycheck_candidates      fenced provider work queue
PostgreSQL keycheck_results         authoritative history
PostgreSQL keycheck_current_state   authoritative current classification
D:\truf\runtime\proxy.txt           optional provider proxy input

found_secrets.jsonl, *Results.jsonl, and *Checked.txt/status files are projector-owned compatibility outputs. They may lag and normal providers do not read or write them.

Shared helper:

D:\truf\app\keycheckers\keycheck_common.py

keycheck_runner.py --input-mode postgres is the default managed mode. --input is accepted only with explicit --input-mode jsonl for reviewed offline/import compatibility. Provider completion inserts the result, updates current state, completes the exact candidate lease, releases candidate capacity, and creates its projection job in one PostgreSQL transaction.

DeepSeek

python supervisor.py --config config.yaml --cmd "recheck deepseek all --max-keys 100"

Output folder:

deepseek\deepseekAlive.txt
deepseek\deepseekNoBalance.txt
deepseek\deepseekDead.txt
deepseek\deepseekLimited.txt
deepseek\deepseekNetwork.txt
deepseek\deepseekUnknown.txt
deepseek\deepseekChecked.txt
deepseek\deepseekResults.jsonl

Qwen / DashScope

python supervisor.py --config config.yaml --cmd "recheck qwen all --max-keys 100"

The checker validates QwenDashScope findings with GET /models against the public DashScope OpenAI-compatible region endpoints. Coding Plan keys (sk-sp-...) use https://coding-intl.dashscope.aliyuncs.com/v1 by default. Workspace-specific endpoints can be added with --base-url via keychecks.service_args.qwen or QWEN_BASE_URLS.

Output folder:

qwen\qwenAlive.txt
qwen\qwenNoBalance.txt
qwen\qwenNoContext.txt
qwen\qwenDead.txt
qwen\qwenLimited.txt
qwen\qwenRestricted.txt
qwen\qwenNetwork.txt
qwen\qwenUnknown.txt
qwen\qwenChecked.txt
qwen\qwenResults.jsonl

Kimi / Moonshot AI

python supervisor.py --config config.yaml --cmd "recheck kimi all --max-keys 100"

The explicit MOONSHOT_API_KEY / KIMI_API_KEY detector is validated without generation by calling GET /v1/users/me/balance on the independent global and China Moonshot endpoints.

Output folder:

kimi\kimiAlive.txt
kimi\kimiNoBalance.txt
kimi\kimiDead.txt
kimi\kimiLimited.txt
kimi\kimiRestricted.txt
kimi\kimiNetwork.txt
kimi\kimiUnknown.txt
kimi\kimiChecked.txt
kimi\kimiResults.jsonl

Groq

python supervisor.py --config config.yaml --cmd "recheck groq all --max-keys 100"

The checker validates TruffleHog Groq findings with GET https://api.groq.com/openai/v1/models and does not run generation probes.

Output folder:

groq\groqAlive.txt
groq\groqDead.txt
groq\groqLimited.txt
groq\groqRestricted.txt
groq\groqNetwork.txt
groq\groqUnknown.txt
groq\groqChecked.txt
groq\groqResults.jsonl

Replicate / xAI / HuggingFace

python supervisor.py --config config.yaml --cmd "recheck replicate all --max-keys 100"
python supervisor.py --config config.yaml --cmd "recheck xai all --max-keys 100"
python supervisor.py --config config.yaml --cmd "recheck huggingface all --max-keys 100"

These checkers validate built-in TruffleHog findings through non-generating endpoints: Replicate account lookup, xAI model list, and HuggingFace whoami.

Anthropic

python supervisor.py --config config.yaml --cmd "recheck anthropic all --max-keys 100"

Output folder:

anthropic\anthropicAlive.txt
anthropic\anthropicNoQuota.txt
anthropic\anthropicDead.txt
anthropic\anthropicLimited.txt
anthropic\anthropicRestricted.txt
anthropic\anthropicNetwork.txt
anthropic\anthropicUnknown.txt
anthropic\anthropicChecked.txt
anthropic\anthropicResults.jsonl

AWS

Default mode only checks STS identity:

python supervisor.py --config config.yaml --cmd "recheck aws all --max-keys 100"

Optional Bedrock probing is configured under keychecks.service_args.aws, then run:

python supervisor.py --config config.yaml --cmd "recheck aws all --max-keys 100"

Output folder:

aws\awsAlive.txt
aws\awsBedrock.txt
aws\awsAdmin.txt
aws\awsCanary.txt
aws\awsQuarantined.txt
aws\awsAccessDenied.txt
aws\awsDead.txt
aws\awsNetwork.txt
aws\awsUnknown.txt
aws\awsChecked.txt
aws\awsResults.jsonl

Canary AWS credentials are detected before active AWS probes when TruffleHog provides ExtraData.is_canary / canary message. If metadata is absent, STS ARN containing canarytokens is also classified as awsCanary.txt and IAM/Bedrock probes are skipped.

Azure

python supervisor.py --config config.yaml --cmd "recheck azure all --max-keys 100"

This checks Azure service-principal findings from DetectorName=Azure using tenantId, clientId, clientSecret from RawV2.

DetectorName=AzureOpenAI is placed into azureOpenAIUnresolved.txt unless an endpoint/resource name is available.

Output folder:

azure\azureAlive.txt
azure\azureDead.txt
azure\azureRestricted.txt
azure\azureNetwork.txt
azure\azureUnknown.txt
azure\azureOpenAIUnresolved.txt
azure\azureChecked.txt
azure\azureResults.jsonl

Retry Flags

Common flags:

--retry-network
--retry-limited
--retry-unknown
--recheck-all
--max-keys N

Network/proxy failures are committed with the network status group and can be selected for a bounded PostgreSQL recheck. *Network.txt is only its asynchronous compatibility projection.