redact-secret-adapters
Host integrations for Redact Secret
in Python: value-based redaction for the standard library's logging, plus the
shared fail-closed walker.
pip install redact-secret redact-secret-adapters
logging
import logging
from redact_secret_adapters.logging_filter import RedactSecretFilter
handler = logging.StreamHandler()
handler.addFilter(RedactSecretFilter())
logging.getLogger().addHandler(handler)
The filter formats msg with args before scanning, then clears the
arguments so a downstream formatter cannot rebuild the original. It replaces
exc_info with redacted traceback text, scans cached exc_text and
stack_info, and redacts any extra_fields=[...] you name.
Attach it to each emitting handler: ancestor logger filters do not run for propagated child records.
RedactSecretFilter(scan_and_redact, ...) accepts an injected scanner; with no
argument it uses redact_secret.scan_and_redact.
Masking callbacks (Langfuse and similar)
from redact_secret_adapters.mask_secrets import mask_secrets
langfuse = Langfuse(mask=mask_secrets)
Fail-closed markers
| Marker | When |
|---|---|
[REDACTED:BLOCKED] |
A block finding — the entire leaf is replaced |
[REDACTED:ERROR] |
Any exception from the core. Never the input, never the exception's message |
[REDACTED:LIMIT_EXCEEDED] |
A value past a walk budget; never scanned, never passed through |
[REDACTED:CYCLE] |
A self-referencing object |
DEFAULT_LIMITS: max_depth 8, max_array_length 1000, max_object_keys 200,
max_string_length 200000, max_total_leaves 5000.
OpenTelemetry ([otel] extra)
from opentelemetry.sdk.trace import TracerProvider
from opentelemetry.sdk.trace.export import BatchSpanProcessor
from redact_secret_adapters.otel import create_redacting_span_processor
provider = TracerProvider()
provider.add_span_processor(create_redacting_span_processor(BatchSpanProcessor(otlp_exporter)))
Every string and string-sequence attribute on a span and its events is
redacted before the span reaches the next processor, including OpenInference
and GenAI semantic-convention attributes, without hardcoding either
convention's attribute list. opentelemetry-sdk never hands a processor a
public, mutable view of a span's attributes; the adapter reaches into the
private _attributes field, and past that into its backing _dict to get
past the SDK's own immutability guard on frozen attribute bags. See
redact_secret_adapters.otel for why that's the SDK's own accepted
mechanism, not a version-specific hack.
Supported range: opentelemetry-sdk>=1.16.0,<2 — CI runs
tests/test_otel_host.py, a real TracerProvider/exporter round trip, at
both ends of that range on every run.
Development
pip install -e "./python[otel,test]"
pytest
The fixture tests read the same JSON files in the repository's fixtures/
directory as the TypeScript suite; that shared file is what keeps the two
languages equivalent.
License
MIT
Metadata
Release files for redact-secret-adapters 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| redact_secret_adapters-0.1.0.tar.gz | 10.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| redact_secret_adapters-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 24.7 kB
Release files / redact_secret_adapters-0.1.0.tar.gz
| Download URL | redact_secret_adapters-0.1.0.tar.gz |
|---|---|
| Size | 10.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
fc1ae50a8ae8c959dcf816891ab2b64b8e1e50d472047b337519ef4f76d47404
|
|
BLAKE2b-256 checksum How to use checksums |
a02a3088a5bcf1c429873507b80aaeb6b4da478c3a76757ebc5230ce43c88f7c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.
Transparency logRelease files / redact_secret_adapters-0.1.0-py3-none-any.whl
| Download URL | redact_secret_adapters-0.1.0-py3-none-any.whl |
|---|---|
| Size | 13.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
bc7f26a7ef5d9b535b67deb2457457dd2cf525f2c3f8f49ce425b51fb13c2e47
|
|
BLAKE2b-256 checksum How to use checksums |
46ad07a38358cf01621721ee9cb9a6a1abb8608ecb39502816207ac9d75aced1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.
Transparency log