PRIVATE_KEY is available in Core 0.4.0 or newer.
PRIVATE_KEY is enabled by default in Rust, Python, Node.js, and browser WASM.
It recognizes complete PEM blocks using these case-sensitive labels:
PRIVATE KEY
RSA PRIVATE KEY
EC PRIVATE KEY
DSA PRIVATE KEY
OPENSSH PRIVATE KEY
ENCRYPTED PRIVATE KEY
The matching -----BEGIN …----- and -----END …----- delimiters must each
occupy an entire line. LF and CRLF line endings are supported. The body must
contain nonempty Base64-shaped lines using ASCII letters, digits, +, /, and
at most two trailing = characters. Its combined length must be divisible by
four. Empty lines, spaces, tabs, and data after padding are rejected.
This is lexical detection: it does not decode, decrypt, or validate the key.
The deliberately synthetic body below demonstrates the shape without providing
a usable key. Public keys, certificates, truncated fragments, indented or inline
delimiters, and legacy Proc-Type / DEK-Info header blocks are outside this
initial detector’s scope.
Scan and redact
Node.js uses the same configuration with scan and scanAndTransform from
@datafog/node. Browser applications import these functions and initialize
@datafog/wasm first. Rust uses scan and scan_and_transform. See the
SDK reference for each runtime’s return types.
Each finding covers the entire block, including both delimiters and every
original internal newline. It excludes the newline following the closing
delimiter and any surrounding text. The finding has entity type PRIVATE_KEY,
detector name datafog-core/private-key, the Core detector version, and no
confidence score.
Byte, Unicode code-point, and JavaScript UTF-16 offsets retain the standard
finding contract. Structured scans inspect each string
value independently; a header and footer in separate fields never form a key.
Redaction replaces the whole block with [PRIVATE_KEY]; masking and removal
also operate on its entire span. Existing entity selection, exact allowlists,
and source-range validation apply. Pseudonymization and reversible tokenization use
the existing providers in Rust, Python, and Node.js. Browser WASM rejects these
provider-dependent strategies as documented in its SDK reference.