logveil
logveil removes common credentials and personal data from logs before they are pasted into issues, chats, or support tickets. It runs locally, reads streams line by line, and has no runtime dependencies.
It is designed for developers, support teams, maintainers, and anyone who needs to share diagnostic output without exposing credentials or personal information.
What it redacts
- Bearer tokens, GitHub tokens, OpenAI-style keys, and AWS access key IDs
- Private-key headers
- Password, token, API-key, and secret assignments
- Email addresses (optional)
- Sensitive values in nested JSON and JSONL objects
- Additional JSON keys supplied by the user
Install
python -m pip install logveil-cli
For local development:
python -m pip install -e .
Usage
Pipe a command through logveil:
my-command 2>&1 | logveil --report > safe.log
Sanitize a file:
logveil server.log -o server.safe.log
Preserve JSONL structure and redact a project-specific field:
logveil events.jsonl --jsonl --key session_id -o events.safe.jsonl
By default, malformed lines in JSONL input are treated as plain text so mixed log streams remain usable. Add --strict-jsonl to stop at the first malformed line.
Show a replacement count without mixing it into the sanitized output:
logveil server.log --report > server.safe.log
Keep email addresses when they are required for diagnosis:
logveil server.log --keep-emails
Try the included synthetic sample:
logveil examples/sample.log --report
Design principles
- Local only: no network requests and no telemetry
- Stream friendly: memory use does not grow with the input file
- Conservative: targeted rules avoid rewriting ordinary identifiers
- Composable: works with pipes, redirected output, and JSONL tooling
See the roadmap for planned improvements and the code of conduct for project participation guidelines.
Limits
Automated redaction reduces accidental disclosure but cannot recognize every secret format. Review sanitized output before publishing it. logveil deliberately avoids attempting to decode, validate, or transmit detected values. It is not a replacement for secret rotation after an exposure.
Contributing
Bug reports and small, focused pull requests are welcome. New detection rules should include tests with synthetic values and avoid matching ordinary identifiers.
Run the test suite with:
python -m unittest discover -s tests
License
MIT
Metadata
Release files for logveil-cli 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| logveil_cli-0.1.1.tar.gz | 8.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| logveil_cli-0.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 14.5 kB
Release files / logveil_cli-0.1.1.tar.gz
| Download URL | logveil_cli-0.1.1.tar.gz |
|---|---|
| Size | 8.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
89b82f3b8b6e30c852541a99939c2e1110674d596e889310c77f07b73732ef98
|
|
BLAKE2b-256 checksum How to use checksums |
8738a5b063739b5f827c85152e8752df3e40f8470ba814d9c7d9dbe13b52fddb
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 16, 2026.
Transparency logRelease files / logveil_cli-0.1.1-py3-none-any.whl
| Download URL | logveil_cli-0.1.1-py3-none-any.whl |
|---|---|
| Size | 6.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
5e330aed7e3b416562ef7c510123075efea5ba1fbc82edf1e9e5fa8c3015cd22
|
|
BLAKE2b-256 checksum How to use checksums |
3ca1a9f60d6b2a48278a871972852a58a36f479903d3275a228bbc437cc1373a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 16, 2026.
Transparency log