Skip to main content

logveil

logveil removes common credentials and personal data from logs before they are pasted into issues, chats, or support tickets. It runs locally, reads streams line by line, and has no runtime dependencies.

It is designed for developers, support teams, maintainers, and anyone who needs to share diagnostic output without exposing credentials or personal information.

What it redacts

  • Bearer tokens, GitHub tokens, OpenAI-style keys, and AWS access key IDs
  • Private-key headers
  • Password, token, API-key, and secret assignments
  • Email addresses (optional)
  • Sensitive values in nested JSON and JSONL objects
  • Additional JSON keys supplied by the user

Install

python -m pip install logveil-cli

For local development:

python -m pip install -e .

Usage

Pipe a command through logveil:

my-command 2>&1 | logveil --report > safe.log

Sanitize a file:

logveil server.log -o server.safe.log

Preserve JSONL structure and redact a project-specific field:

logveil events.jsonl --jsonl --key session_id -o events.safe.jsonl

By default, malformed lines in JSONL input are treated as plain text so mixed log streams remain usable. Add --strict-jsonl to stop at the first malformed line.

Show a replacement count without mixing it into the sanitized output:

logveil server.log --report > server.safe.log

Keep email addresses when they are required for diagnosis:

logveil server.log --keep-emails

Try the included synthetic sample:

logveil examples/sample.log --report

Design principles

  • Local only: no network requests and no telemetry
  • Stream friendly: memory use does not grow with the input file
  • Conservative: targeted rules avoid rewriting ordinary identifiers
  • Composable: works with pipes, redirected output, and JSONL tooling

See the roadmap for planned improvements and the code of conduct for project participation guidelines.

Limits

Automated redaction reduces accidental disclosure but cannot recognize every secret format. Review sanitized output before publishing it. logveil deliberately avoids attempting to decode, validate, or transmit detected values. It is not a replacement for secret rotation after an exposure.

Contributing

Bug reports and small, focused pull requests are welcome. New detection rules should include tests with synthetic values and avoid matching ordinary identifiers.

Run the test suite with:

python -m unittest discover -s tests

License

MIT

Metadata

Release files for logveil-cli 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for logveil-cli 0.1.1
File Size Uploaded
logveil_cli-0.1.1.tar.gz 8.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for logveil-cli 0.1.1
File Interpreter ABI Platform
logveil_cli-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 14.5 kB

Release files / logveil_cli-0.1.1.tar.gz

Download URL logveil_cli-0.1.1.tar.gz
Size 8.1 kB
Tags Source
SHA-256 checksum
How to use checksums
89b82f3b8b6e30c852541a99939c2e1110674d596e889310c77f07b73732ef98
BLAKE2b-256 checksum
How to use checksums
8738a5b063739b5f827c85152e8752df3e40f8470ba814d9c7d9dbe13b52fddb
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 16, 2026.

Transparency log

Release files / logveil_cli-0.1.1-py3-none-any.whl

Download URL logveil_cli-0.1.1-py3-none-any.whl
Size 6.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
5e330aed7e3b416562ef7c510123075efea5ba1fbc82edf1e9e5fa8c3015cd22
BLAKE2b-256 checksum
How to use checksums
3ca1a9f60d6b2a48278a871972852a58a36f479903d3275a228bbc437cc1373a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 16, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page