Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

Redact Secret for Python

Deterministic secret detection and redaction for CPython, over the same Rust core that backs the JavaScript, Rust, and CLI surfaces of Redact Secret. Every built-in detector runs in Rust; there is no pure-Python fallback implementation to drift from it.

The distribution is redact-secret and the import name is redact_secret. The product name is Redact Secret everywhere; per PEP 503, redact-secret and redact_secret normalize to the same PyPI project identity, so no registry fallback name is needed — see docs/rust-workspace.md.

No release is authorized by the version currently in the development manifests. Installation applies only after a separately approved release.

This directory is the canonical Python binding decision-release-bindings-in-lockstep requires before the separately created secret-scan-python GitHub repository (empty today) is archived with a redirect to here; that prepared redirect text lives in docs/python-repository-redirect.md.

Install

pip install redact-secret

Wheels are CPython 3.10+ abi3: one wheel per platform serves every supported interpreter, and installing one needs no Rust toolchain and no compiler. See Supported wheels. Where no wheel applies, pip falls back to the source distribution, which does need Rust — see Building from source.

Use

import redact_secret

findings = redact_secret.scan(text)
redacted = redact_secret.redact(text, findings)

# or, to guarantee the findings and the redacted text agree:
result = redact_secret.scan_and_redact(text)
result.text, result.findings

Ranges on every DetectedFinding and Finding are Unicode code point offsets (redact_secret.RANGE_UNIT == "unicode-code-points"), so they index a str the way Python itself does.

For input that arrives in pieces, IncrementalSanitizer sanitizes a bounded session chunk by chunk. Independently scanning chunks is unsafe, because a credential may cross any chunk boundary; a session carries the boundary state that makes it safe. Limits are mandatory and are counted in UTF-8 bytes:

limits = redact_secret.IncrementalLimits(
    max_input_bytes=1_000_000,
    max_buffered_bytes=32_896,
    max_token_bytes=8_192,
    max_multiline_bytes=32_768,
)

with redact_secret.IncrementalSanitizer(limits) as session:
    first = session.append("api_key=SYNTHETIC_REVOKED_")
    second = session.append("INCREMENTAL_VALUE\nordinary text")
    final = session.finalize()

safe_text = first.text + second.text + final.text
# api_key=<SECRET_1>\nordinary text

Leaving the with block aborts a session that was not finalized, so whatever it still retained is discarded. A session's findings carry absolute code point offsets into the logical whole-session input, so they index "".join(chunks) exactly as the synchronous API's findings index the same joined string.

policy and formatter callbacks receive only normalized safe metadata, never the input or a matched value. A callback that raises, or that returns something other than the documented protocol, never propagates its own error: it becomes one of the fixed SecretScanError subclasses. There is no custom detector callback surface.

The package is typed (PEP 561): the wheel ships py.typed and a _native.pyi stub, so type checkers resolve the API without a stub package.

Supported wheels

Platform Architectures Wheel tag
manylinux (glibc 2.17+) x86_64, aarch64 cp310-abi3-manylinux_2_17_*.manylinux2014_*
musllinux (musl 1.2+) x86_64, aarch64 cp310-abi3-musllinux_1_2_*
macOS 11+ x86_64, arm64 cp310-abi3-macosx_*
Windows x64, arm64 cp310-abi3-win_*

Every wheel in that matrix is built and smoke-tested on its own architecture, on CPython 3.10 and 3.14, before a release candidate is accepted; see docs/python-packaging.md.

Building from source

The source distribution needs a Rust toolchain at or above the workspace MSRV (1.88, Rust 2024 edition). With cargo on PATH, pip install builds it like any other source install.

Without one, maturin's build backend downloads a toolchain into a local cache and continues. To refuse that instead and fail immediately with Cargo metadata failed. Do you have cargo in your PATH?, set:

MATURIN_NO_INSTALL_RUST=1 pip install --no-binary redact-secret redact-secret

Set it in any environment that must not fetch a toolchain over the network.

Development

This directory is a mixed Rust/Python maturin project. The crate is redact-secret-python, the native module is redact_secret._native, and the pure Python package lives under python/redact_secret/.

  • src/lib.rs owns CPython conversions, Unicode code point range conversion, and the synchronous scan/redact/scan_and_redact API: immutable finding and result types, sanitized exceptions, and the default policy and formatter helpers (decision-define-runtime-bindings).
  • src/incremental.rs owns the bounded incremental session: IncrementalSanitizer, its mandatory IncrementalLimits, the lifecycle states, and the incremental policy callback. Its CodePointIndex converts the core's absolute UTF-8 byte offsets to the absolute code point offsets a session reports, by recording only where the input's UTF-8 continuation bytes fall, never the characters themselves. Between successful calls it prunes offsets outside max_buffered_bytes; while processing a call it also indexes the incoming chunk, and its allocation can retain that peak capacity until the session ends. Bound host chunk sizes as well as session limits.
  • python/redact_secret/__init__.py re-exports the native module's public surface; python/redact_secret/_native.pyi and py.typed mark the package as typed.
  • tests/ runs against a built extension and exercises the shared conformance/ corpus, Unicode code point conversion, callback failure sanitization, placeholder safety, and determinism. The incremental suites add native-string partition invariance (test_incremental_partitions.py), astral character boundaries (test_incremental_unicode.py), and the canonical lifecycle, limit, callback, and failure-cleanup cases (test_incremental.py). They read the corpus from the repository, so they ship with neither the wheel nor the source distribution.
  • The extension-module Cargo feature is enabled only by maturin, so the crate still links during cargo test --workspace.
cd bindings/python
python3 -m venv .venv && source .venv/bin/activate
pip install '.[test]' maturin pytest
maturin develop
pytest

Rebuild with maturin develop after any change under src/; pytest imports the installed extension, not the Rust sources.

Packaging identity, the abi3 contract, and the wheel matrix are declared in [workspace.metadata.redact-secret] in the root Cargo.toml and enforced by scripts/check-python-package.py. Build and qualify artifacts with scripts/qualify-python-wheel.py; see docs/python-packaging.md.

Release files for redact-secret 0.1.0b2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for redact-secret 0.1.0b2
File Size Uploaded
redact_secret-0.1.0b2.tar.gz 101.7 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for redact-secret 0.1.0b2
File
redact_secret-0.1.0b2-cp310-abi3-win_arm64.whl CPython 3.10 abi3 Windows ARM64 Details
redact_secret-0.1.0b2-cp310-abi3-win_amd64.whl CPython 3.10 abi3 Windows x86-64 Details
redact_secret-0.1.0b2-cp310-abi3-musllinux_1_2_x86_64.whl CPython 3.10 abi3 Linux musl 1.2+ x86-64 Details
redact_secret-0.1.0b2-cp310-abi3-musllinux_1_2_aarch64.whl CPython 3.10 abi3 Linux musl 1.2+ ARM64 Details
redact_secret-0.1.0b2-cp310-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl CPython 3.10 abi3 Linux glibc 2.17+ x86-64 Details
redact_secret-0.1.0b2-cp310-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl CPython 3.10 abi3 Linux glibc 2.17+ ARM64 Details
redact_secret-0.1.0b2-cp310-abi3-macosx_11_0_arm64.whl CPython 3.10 abi3 macOS 11.0+ ARM64 Details
redact_secret-0.1.0b2-cp310-abi3-macosx_10_12_x86_64.whl CPython 3.10 abi3 macOS 10.12+ x86-64 Details

Total release size: 3.2 MB

Release files / redact_secret-0.1.0b2.tar.gz

Download URL redact_secret-0.1.0b2.tar.gz
Size 101.7 kB
Tags Source
SHA-256 checksum
How to use checksums
8a50ae341977916f42cd6cfec82004b9729954a010a9971a2d6b9f2f401c315f
BLAKE2b-256 checksum
How to use checksums
f1583e2a83de836c7b80cdf2e1b73cfbd2a891be105d700a65bf8dd3d23e1ea2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 14, 2026.

Transparency log

Release files / redact_secret-0.1.0b2-cp310-abi3-win_arm64.whl

Download URL redact_secret-0.1.0b2-cp310-abi3-win_arm64.whl
Size 247.2 kB
Tags CPython 3.10 Windows ARM64 abi3
SHA-256 checksum
How to use checksums
417eca4ecdc801f4e909657b3d2cf7895564fbe39c96fd806ebbfd64c0d93461
BLAKE2b-256 checksum
How to use checksums
0f3b4c14de49f3b0428ac4e77f65a02b82c0418a248b4a9e5721c882d3095815
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 14, 2026.

Transparency log

Release files / redact_secret-0.1.0b2-cp310-abi3-win_amd64.whl

Download URL redact_secret-0.1.0b2-cp310-abi3-win_amd64.whl
Size 259.0 kB
Tags CPython 3.10 Windows x86-64 abi3
SHA-256 checksum
How to use checksums
fd03b490c0998502a0773dcd72f0374707036eadb97bcbd172e05b277d515d38
BLAKE2b-256 checksum
How to use checksums
37fcfb7ed873946f38ffcdff1b587310f63f84ea47b209411777870550eb94d5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 14, 2026.

Transparency log

Release files / redact_secret-0.1.0b2-cp310-abi3-musllinux_1_2_x86_64.whl

Download URL redact_secret-0.1.0b2-cp310-abi3-musllinux_1_2_x86_64.whl
Size 591.0 kB
Tags CPython 3.10 Linux musl 1.2+ x86-64 abi3
SHA-256 checksum
How to use checksums
6d85d54da337b054a9a8475000021fe985815e9574cf3d91decbc59a30d5382c
BLAKE2b-256 checksum
How to use checksums
b7ab5ca3d091ed8c2ac0204b01b04ec62b57a0893d536f300c44404b8bc63a63
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 14, 2026.

Transparency log

Release files / redact_secret-0.1.0b2-cp310-abi3-musllinux_1_2_aarch64.whl

Download URL redact_secret-0.1.0b2-cp310-abi3-musllinux_1_2_aarch64.whl
Size 552.2 kB
Tags CPython 3.10 Linux musl 1.2+ ARM64 abi3
SHA-256 checksum
How to use checksums
2812681e44ca29e796a1142820221ea1ec1a56dda9ed51d721246f163c96143e
BLAKE2b-256 checksum
How to use checksums
39b6e3c4d52491d5e8b237f6cf3e8a1f43ae37970e5d3ff803ce0ddee8e681bb
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 14, 2026.

Transparency log

Release files / redact_secret-0.1.0b2-cp310-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL redact_secret-0.1.0b2-cp310-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 379.2 kB
Tags CPython 3.10 Linux glibc 2.17+ x86-64 abi3
SHA-256 checksum
How to use checksums
82ce96aac6ebb510770f5644cd324ff09a19215acc18ecd411f15ef7b89e79dc
BLAKE2b-256 checksum
How to use checksums
52bda458aff4fc6bf58f2513d1c84d055983bb487fe7ab98d2ce7d383a22b088
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 14, 2026.

Transparency log

Release files / redact_secret-0.1.0b2-cp310-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl

Download URL redact_secret-0.1.0b2-cp310-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
Size 372.8 kB
Tags CPython 3.10 Linux glibc 2.17+ ARM64 abi3
SHA-256 checksum
How to use checksums
c485bf85a77c22615ed2d86684807c481e25aa4b6c5befbddb75d527cc44fa14
BLAKE2b-256 checksum
How to use checksums
e9135073c30273f36456f5a5ee66fe6bc65c9dafb5b16072f3dd2712326d3e37
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 14, 2026.

Transparency log

Release files / redact_secret-0.1.0b2-cp310-abi3-macosx_11_0_arm64.whl

Download URL redact_secret-0.1.0b2-cp310-abi3-macosx_11_0_arm64.whl
Size 347.8 kB
Tags CPython 3.10 abi3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
a5be76edb52ea6fc60cd65b8ed6c80e5df1a1ba4011c75cce2cc215819562cf0
BLAKE2b-256 checksum
How to use checksums
a1f44aef2967aaa11800bb475fa3966961de8b5bfe159caa402080334b34760c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 14, 2026.

Transparency log

Release files / redact_secret-0.1.0b2-cp310-abi3-macosx_10_12_x86_64.whl

Download URL redact_secret-0.1.0b2-cp310-abi3-macosx_10_12_x86_64.whl
Size 354.7 kB
Tags CPython 3.10 abi3 macOS 10.12+ x86-64
SHA-256 checksum
How to use checksums
3bf30ec56c2725b9443e053d41bf6b61d4971f1359a6e67607ce75ced60d6d72
BLAKE2b-256 checksum
How to use checksums
61ce09e89f6c3d88f240a20959752105c66bedc26796b6d8f05020e51afbe8ca
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 14, 2026.

Transparency log
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page