{
  "action": "block-if-sdd-catches-this",
  "type": "apikey",
  "label": "api key",
  "payload": "API_KEY=sandbox-cfat-XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX",
  "note": "synthetic. shaped like a plausible token but contains no valid material.",
  "sdd": "cloudflare sensitive data detection is configured to BLOCK matches on this path prefix. if you are reading this in your client, sdd did not catch it — check the managed ruleset deployment."
}