5.5 KiB
Keychecker Layout
Normal input and authority:
PostgreSQL keycheck_candidates fenced provider work queue
PostgreSQL keycheck_results authoritative history
PostgreSQL keycheck_current_state authoritative current classification
D:\truf\runtime\proxy.txt optional provider proxy input
found_secrets.jsonl, *Results.jsonl, and *Checked.txt/status files are projector-owned compatibility outputs. They may lag and normal providers do not read or write them.
Shared helper:
D:\truf\app\keycheckers\keycheck_common.py
keycheck_runner.py --input-mode postgres is the default managed mode. --input is accepted only with explicit --input-mode jsonl for reviewed offline/import compatibility. Provider completion inserts the result, updates current state, completes the exact candidate lease, releases candidate capacity, and creates its projection job in one PostgreSQL transaction.
DeepSeek
python supervisor.py --config config.yaml --cmd "recheck deepseek all --max-keys 100"
Output folder:
deepseek\deepseekAlive.txt
deepseek\deepseekNoBalance.txt
deepseek\deepseekDead.txt
deepseek\deepseekLimited.txt
deepseek\deepseekNetwork.txt
deepseek\deepseekUnknown.txt
deepseek\deepseekChecked.txt
deepseek\deepseekResults.jsonl
Qwen / DashScope
python supervisor.py --config config.yaml --cmd "recheck qwen all --max-keys 100"
The checker validates QwenDashScope findings with GET /models against the public DashScope OpenAI-compatible region endpoints. Coding Plan keys (sk-sp-...) use https://coding-intl.dashscope.aliyuncs.com/v1 by default. Workspace-specific endpoints can be added with --base-url via keychecks.service_args.qwen or QWEN_BASE_URLS.
Output folder:
qwen\qwenAlive.txt
qwen\qwenNoBalance.txt
qwen\qwenNoContext.txt
qwen\qwenDead.txt
qwen\qwenLimited.txt
qwen\qwenRestricted.txt
qwen\qwenNetwork.txt
qwen\qwenUnknown.txt
qwen\qwenChecked.txt
qwen\qwenResults.jsonl
Kimi / Moonshot AI
python supervisor.py --config config.yaml --cmd "recheck kimi all --max-keys 100"
The explicit MOONSHOT_API_KEY / KIMI_API_KEY detector is validated without generation by calling GET /v1/users/me/balance on the independent global and China Moonshot endpoints.
Output folder:
kimi\kimiAlive.txt
kimi\kimiNoBalance.txt
kimi\kimiDead.txt
kimi\kimiLimited.txt
kimi\kimiRestricted.txt
kimi\kimiNetwork.txt
kimi\kimiUnknown.txt
kimi\kimiChecked.txt
kimi\kimiResults.jsonl
Groq
python supervisor.py --config config.yaml --cmd "recheck groq all --max-keys 100"
The checker validates TruffleHog Groq findings with GET https://api.groq.com/openai/v1/models and does not run generation probes.
Output folder:
groq\groqAlive.txt
groq\groqDead.txt
groq\groqLimited.txt
groq\groqRestricted.txt
groq\groqNetwork.txt
groq\groqUnknown.txt
groq\groqChecked.txt
groq\groqResults.jsonl
Replicate / xAI / HuggingFace
python supervisor.py --config config.yaml --cmd "recheck replicate all --max-keys 100"
python supervisor.py --config config.yaml --cmd "recheck xai all --max-keys 100"
python supervisor.py --config config.yaml --cmd "recheck huggingface all --max-keys 100"
These checkers validate built-in TruffleHog findings through non-generating endpoints: Replicate account lookup, xAI model list, and HuggingFace whoami.
Anthropic
python supervisor.py --config config.yaml --cmd "recheck anthropic all --max-keys 100"
Output folder:
anthropic\anthropicAlive.txt
anthropic\anthropicNoQuota.txt
anthropic\anthropicDead.txt
anthropic\anthropicLimited.txt
anthropic\anthropicRestricted.txt
anthropic\anthropicNetwork.txt
anthropic\anthropicUnknown.txt
anthropic\anthropicChecked.txt
anthropic\anthropicResults.jsonl
AWS
Default mode only checks STS identity:
python supervisor.py --config config.yaml --cmd "recheck aws all --max-keys 100"
Optional Bedrock probing is configured under keychecks.service_args.aws, then run:
python supervisor.py --config config.yaml --cmd "recheck aws all --max-keys 100"
Output folder:
aws\awsAlive.txt
aws\awsBedrock.txt
aws\awsAdmin.txt
aws\awsCanary.txt
aws\awsQuarantined.txt
aws\awsAccessDenied.txt
aws\awsDead.txt
aws\awsNetwork.txt
aws\awsUnknown.txt
aws\awsChecked.txt
aws\awsResults.jsonl
Canary AWS credentials are detected before active AWS probes when TruffleHog provides ExtraData.is_canary / canary message. If metadata is absent, STS ARN containing canarytokens is also classified as awsCanary.txt and IAM/Bedrock probes are skipped.
Azure
python supervisor.py --config config.yaml --cmd "recheck azure all --max-keys 100"
This checks Azure service-principal findings from DetectorName=Azure using tenantId, clientId, clientSecret from RawV2.
DetectorName=AzureOpenAI is placed into azureOpenAIUnresolved.txt unless an endpoint/resource name is available.
Output folder:
azure\azureAlive.txt
azure\azureDead.txt
azure\azureRestricted.txt
azure\azureNetwork.txt
azure\azureUnknown.txt
azure\azureOpenAIUnresolved.txt
azure\azureChecked.txt
azure\azureResults.jsonl
Retry Flags
Common flags:
--retry-network
--retry-limited
--retry-unknown
--recheck-all
--max-keys N
Network/proxy failures are committed with the network status group and can be selected for a bounded PostgreSQL recheck. *Network.txt is only its asynchronous compatibility projection.