{
  "$comment": "Provider shapes for smoke-secret-parity.sh, which proves both secret surfaces block the same set. Each row is SPLIT into a prefix, a filler character and a length, and the gate joins them at run time. No complete credential-shaped string is stored here, so the scanners this file exists to test do not block the file itself - which is exactly what happened when the samples were stored whole and the commit hook refused them. Adding a provider means adding a row here first; the gate then fails until both surfaces catch it.",
  "providers": [
    {
      "id": "github-pat",
      "prefix": "ghp_",
      "fill": "A",
      "len": 36,
      "suffix": ""
    },
    {
      "id": "github-fine-grained",
      "prefix": "github_pat_",
      "fill": "A",
      "len": 66,
      "suffix": ""
    },
    {
      "id": "slack",
      "prefix": "xoxb-",
      "fill": "A",
      "len": 16,
      "suffix": ""
    },
    {
      "id": "aws",
      "prefix": "AKIA",
      "fill": "A",
      "len": 16,
      "suffix": ""
    },
    {
      "id": "google",
      "prefix": "AIza",
      "fill": "A",
      "len": 35,
      "suffix": ""
    },
    {
      "id": "npm",
      "prefix": "npm_",
      "fill": "A",
      "len": 36,
      "suffix": ""
    },
    {
      "id": "gitlab",
      "prefix": "glpat-",
      "fill": "A",
      "len": 20,
      "suffix": ""
    },
    {
      "id": "stripe",
      "prefix": "sk_live_",
      "fill": "A",
      "len": 20,
      "suffix": ""
    },
    {
      "id": "anthropic",
      "prefix": "sk-ant-",
      "fill": "A",
      "len": 36,
      "suffix": ""
    },
    {
      "id": "openai",
      "prefix": "sk-proj-",
      "fill": "A",
      "len": 36,
      "suffix": ""
    },
    {
      "id": "perplexity",
      "prefix": "pplx-",
      "fill": "A",
      "len": 36,
      "suffix": ""
    },
    {
      "id": "huggingface",
      "prefix": "hf_",
      "fill": "A",
      "len": 32,
      "suffix": ""
    },
    {
      "id": "figma-pat",
      "prefix": "figd_",
      "fill": "A",
      "len": 24,
      "suffix": ""
    },
    {
      "id": "figma-mcp",
      "prefix": "figu_",
      "fill": "A",
      "len": 24,
      "suffix": ""
    },
    {
      "id": "service-account",
      "prefix": "\"type\": \"service_",
      "fill": "",
      "len": 0,
      "suffix": "account\""
    },
    {
      "id": "url-with-credentials",
      "prefix": "https://user:",
      "fill": "s",
      "len": 12,
      "suffix": "@example.com/x.git"
    },
    {
      "id": "bearer-header",
      "prefix": "Authorization: Bearer ",
      "fill": "A",
      "len": 24,
      "suffix": ""
    }
  ]
}
