Redact Secret documentation
Protect the text your application is about to send
Start with the boundary you control. You do not need to learn every package before making one path safe.
01 · Docs home
What are you trying to protect?
Choose the closest task. Each path leads directly to a minimal example and its honest coverage boundary.
- Application logs — Pino or Python logging
- Traces and telemetry — OpenTelemetry spans and logs
- MCP, LLM, or agent context — MCP or AI Context
- API traffic — the optional Gateway
- Values you must restore later — the optional Vault
- Text you scan directly — JavaScript or Python
02 · Docs home
One detector, several boundaries
Core detects and applies policy. Adapters carry host values to core. Vault adds controlled restoration. Gateway protects a reviewed API subset before forwarding. None of these claims that an empty finding set proves the input is secret-free.