Skip to main content

redact-secret-adapters

Host integrations for Redact Secret in Python: value-based redaction for the standard library's logging, plus the shared fail-closed walker.

pip install redact-secret redact-secret-adapters

logging

import logging
from redact_secret_adapters.logging_filter import RedactSecretFilter

handler = logging.StreamHandler()
handler.addFilter(RedactSecretFilter())
logging.getLogger().addHandler(handler)

The filter formats msg with args before scanning, then clears the arguments so a downstream formatter cannot rebuild the original. It replaces exc_info with redacted traceback text, scans cached exc_text and stack_info, and redacts any extra_fields=[...] you name.

Attach it to each emitting handler: ancestor logger filters do not run for propagated child records.

RedactSecretFilter(scan_and_redact, ...) accepts an injected scanner; with no argument it uses redact_secret.scan_and_redact.

Masking callbacks (Langfuse and similar)

from redact_secret_adapters.mask_secrets import mask_secrets

langfuse = Langfuse(mask=mask_secrets)

Fail-closed markers

Marker When
[REDACTED:BLOCKED] A block finding — the entire leaf is replaced
[REDACTED:ERROR] Any exception from the core. Never the input, never the exception's message
[REDACTED:LIMIT_EXCEEDED] A value past a walk budget; never scanned, never passed through
[REDACTED:CYCLE] A self-referencing object

DEFAULT_LIMITS: max_depth 8, max_array_length 1000, max_object_keys 200, max_string_length 200000, max_total_leaves 5000.

OpenTelemetry ([otel] extra)

from opentelemetry.sdk.trace import TracerProvider
from opentelemetry.sdk.trace.export import BatchSpanProcessor
from redact_secret_adapters.otel import create_redacting_span_processor

provider = TracerProvider()
provider.add_span_processor(create_redacting_span_processor(BatchSpanProcessor(otlp_exporter)))

Every string and string-sequence attribute on a span and its events is redacted before the span reaches the next processor, including OpenInference and GenAI semantic-convention attributes, without hardcoding either convention's attribute list. opentelemetry-sdk never hands a processor a public, mutable view of a span's attributes; the adapter reaches into the private _attributes field, and past that into its backing _dict to get past the SDK's own immutability guard on frozen attribute bags. See redact_secret_adapters.otel for why that's the SDK's own accepted mechanism, not a version-specific hack.

Supported range: opentelemetry-sdk>=1.16.0,<2 — CI runs tests/test_otel_host.py, a real TracerProvider/exporter round trip, at both ends of that range on every run.

Development

pip install -e "./python[otel,test]"
pytest

The fixture tests read the same JSON files in the repository's fixtures/ directory as the TypeScript suite; that shared file is what keeps the two languages equivalent.

License

MIT

Metadata

Release files for redact-secret-adapters 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for redact-secret-adapters 0.1.0
File Size Uploaded
redact_secret_adapters-0.1.0.tar.gz 10.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for redact-secret-adapters 0.1.0
File Interpreter ABI Platform
redact_secret_adapters-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 24.7 kB

Release files / redact_secret_adapters-0.1.0.tar.gz

Download URL redact_secret_adapters-0.1.0.tar.gz
Size 10.9 kB
Tags Source
SHA-256 checksum
How to use checksums
fc1ae50a8ae8c959dcf816891ab2b64b8e1e50d472047b337519ef4f76d47404
BLAKE2b-256 checksum
How to use checksums
a02a3088a5bcf1c429873507b80aaeb6b4da478c3a76757ebc5230ce43c88f7c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.

Transparency log

Release files / redact_secret_adapters-0.1.0-py3-none-any.whl

Download URL redact_secret_adapters-0.1.0-py3-none-any.whl
Size 13.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
bc7f26a7ef5d9b535b67deb2457457dd2cf525f2c3f8f49ce425b51fb13c2e47
BLAKE2b-256 checksum
How to use checksums
46ad07a38358cf01621721ee9cb9a6a1abb8608ecb39502816207ac9d75aced1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.

Transparency log

Release history Release notifications | RSS feed

0.1.2

2 release files

0.1.1

2 release files

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page