01 · How it works
It finds passwords in text, and crosses them out.
The rest of this page is about doing that carefully.
At the boundary
Text in, the same text out
Secrets are allowed on one road only: from your credential manager, through a vault, to the provider. Redact Secret is a filter you install on every other road. Text goes in, the same text comes out, minus anything that looked like a credential.
- Input
- API_KEY=SYNTHETIC_REVOKED_CONTEXT_VALUE
- Output
- API_KEY=<SECRET_1>
The placeholder is only a label. Nothing turns it back into the key. If you need the original back, use the vault, which lives in a separate repository and has to be added on purpose.
The architecture
One brain, four mouths
The hard thinking happens once, in Rust. Every language gets a translator, not its own copy of the rules.
The Rust core
detect → resolve → policy → redact
What is in the box
The feature set
Two sizes
Full knows every provider. Common keeps only the 6 structural detectors, for browsers and small agents: smaller, faster, and it adds no false alarms. The measurements are on the benchmarks site.
Runs in the browser
The same engine compiles to WebAssembly, so a key can be caught before it leaves the laptop. Cloudflare Workers is supported.
A CLI for CI
redact-secret checks files or a staged diff. Exit 0 clean, 1 found, 2 broken, and broken always outranks found.
Fails closed
64 MiB and 50,000 findings by default. Past either, you get an error, never a quietly truncated clean result.
Errors say nothing
Every error message is fixed text with no input in it. Your crash reports cannot leak what your scanner just caught.
Bring your own key format
Declare an in-house credential as a ruleset: plain text the core parses and matches itself, never a callback. The grammar is on the detection page.
Real logging and tracing packages
pino, Python logging and an OpenTelemetry span processor ship as versioned adapters from their own repository.
Personal data, opt in
Email, IBAN, payment card, phone, network address and US SSN families. Off by default on every surface.
The comparison
Most secret scanners guard a different door
Gitleaks, TruffleHog, detect-secrets and GitGuardian watch your code: did a developer commit a key? Redact Secret watches your traffic, at the moment text is about to be logged, stored, or handed to a model.
They are not rivals. Run a repository scanner in CI and this in your request path.
Being honest