Common annotated security keys (opens in new tab)
GitHub’s improved security-token format demonstrated that fixed signatures and checksums can sharply reduce both false positives and missed secret detections. Microsoft applies these ideas across its services and proposes the open-source Common Annotated Security Standard (CASK), a shared format for identifiable secrets. CASK is intended to make scanning faster, more accurate, and easier to apply across an entire ecosystem without disrupting developers.
Identifiable Secrets and Better Detection
- “Identifiable” keys combine:
- A fixed signature that reliably identifies the format.
- A checksum that validates whether a detected string is a real key.
- These features reduce scanner noise and missed findings.
- Microsoft can hard-block identifiable keys from being stored in source code, work items, and similar locations with high confidence.
- Scanners can detect the common format first and classify the specific service provider later, if needed.
The Common Annotated Security Standard
- CASK defines platform-agnostic requirements for minted security keys.
- It reserves space for individual platforms and providers to encode service-specific metadata.
- Microsoft has defined Azure-specific metadata within this reserved area.
- A shared standard lowers the effort required for security tools to protect multiple service providers.
- Other providers can adopt the same core format.
CASK Key Requirements
Alphanumeric Encoding
- Keys use only the BASE62 alphabet.
- Avoiding special characters allows keys to be transmitted without escaping or additional encoding.
Strong Entropy
- Each key contains 52 randomized encoded characters.
- This provides approximately 310 bits of entropy.
- The design is intended to prevent brute-force attacks, including in a post-quantum environment.
Fixed Signatures
- Every CASK key includes:
- The standard signature
JQQJ. - A provider-specific signature.
- The standard signature
- Microsoft observed
JQQJto be rare in both open-source and internal code, enabling fast and accurate detection. - Azure DevOps uses
AZDOas its provider signature. - These signatures allow tools to detect CASK keys generically while still supporting provider-specific classification.
Metadata and Testing Support
- Keys include their creation month and year.
- Timestamps support incident response and key-rotation enforcement.
- CASK reserves dedicated test keys so developers can test scanners and security controls without exposing real credentials.
- Microsoft plans to provide more details about Azure-specific metadata.
Microsoft recommends that service providers adopt CASK and contribute feedback as the standard evolves.