Skip to main content

secretHider

Fast secret redaction, log processing, string and JSON tools: one C++20 core, thin bindings for Python and Node.js.

  • Remove secrets from logs in plain text, logfmt and JSON lines: AWS/GitHub/Slack/Stripe/Google keys, JWTs, PEM private keys, Bearer tokens, URL credentials, password=... fields, and optional PII (email, phone, card, SSN, IBAN, IPv4).
  • Tell it what is secret with plain lists: known values, field names and formats (or one secrets.txt file), on top of the built-in patterns.
  • Choose what happens: delete the whole field (drop_field), mask (full, typed, keep first/last N, preserve length, partial email/phone), stable salted hash, realistic fake data via Faker (Python faker, JS @faker-js/faker), or your own function. Partial masks never reveal more than 25% of a secret.
  • Stream it: chunk-safe redaction for files, pipes and sockets (output equals one-shot output at every split point), a secrethider-redact command line, and in-place/.gz file helpers.
  • Fast: about 600 MiB/s per core on clean logs, roughly 38x a hand-written Python re pipeline and comparable to V8's RegExp for a few simple patterns in Node (numbers). Built on simdjson, simdutf, RE2.
  • Also: json_get (JSON Pointer), json_minify, json_valid, UTF-8 helpers.
secrethider-redact --in-place --drop-fields --secrets-file secrets.txt app.log   # a=1 password=x b=2  ->  a=1 b=2
secrethider-redact --pii --mask fake app.jsonl --json-lines                       # fake emails/phones instead of [REDACTED]
import secrethider
from secrethider import Mask, RedactorBuilder

r = (RedactorBuilder()
     .enable("pii")
     .secret_values(["my-known-secret"])       # also: secret_keys([...]), secret_formats([...])
     .mask(Mask.keep_prefix(4))                # or Mask.drop_field(), secrethider.fake_mask(), ...
     .build())

r.redact("login password=hunter2hunter2hunter2 key=AKIAIOSFODNN7EXAMPLE")
# 'login password=hunt**** key=AKIA****'
# (short secrets fall back to a full mask: 4 revealed characters of a 10-character password would exceed 25%)

# logging, files, streams
from secrethider.logging import RedactingFormatter
handler.setFormatter(RedactingFormatter(r, "%(levelname)s %(message)s"))
secrethider.redact_file(open("in.log"), open("out.log", "w"), r)
const fk = require('@noobforal/secrethider');
const r = new fk.RedactorBuilder().mask(fk.Mask.keepPrefix(4)).build();
process.stdin.pipe(fk.createRedactStream(r)).pipe(process.stdout);

Install

pip install secrethider            # Python 3.12+; add `faker` for realistic fake-data masks
npm install @noobforal/secrethider # Node.js 22+

Prebuilt binaries, no compiler needed:

Linux glibc (Debian 10+, Ubuntu 20.04+, RHEL 8+) Linux musl (Alpine) macOS Windows
x64 yes yes yes yes
arm64 yes yes yes (Apple silicon) not yet

The npm package is scoped because npm rejects the unscoped name secrethider as too similar to an existing package.

Layout

core/              C++20 library (no Python/Node headers), tests, benchmarks
bindings/python/   nanobind module + `secrethider` package (built via scikit-build-core, root pyproject.toml)
bindings/node/     Node-API addon (node-addon-api + cmake-js)
cmake/             shared CMake modules (dependencies, warnings)
docs/              architecture: interfaces, log processing, rules and masking, builds, performance, security

Documentation

Start with the guide to removing secrets from logs, or docs/README.md for everything: interfaces, log processing pipeline, rules and masking, build and platforms, performance, security model.

Develop

make fix     # format + auto-fix lint: C++ (clang-format), Python (ruff), JS/TS (prettier)
make test    # build, run all tests (C++, Python, Node), then the benchmarks
make verify  # the full local gate before a push or release: lint, version check, all tests, abi3 wheel on Python 3.12/3.13/3.14
make docker  # build and test on Linux in a container (clean clone of HEAD): C++, Python, Node, abi3
make docker-node VARIANT=linux-x64   # build a Linux Node addon as the release does (glibc 2.28 / Alpine / arm64) and load it on Debian, Ubuntu, Alpine images
make published VERSION=x.y.z   # after a release: install the published packages in clean Debian/Alpine containers and test them
make help    # everything else: lint, check (tests only), bench, bench-full, qa (leak checks + long fuzz), clean

git config core.hooksPath .githooks makes git push run make verify first (bypass once with SKIP_VERIFY=1 git push).

make finds Visual Studio's C++ tools on Windows by itself. Without make, the underlying steps are:

# C++ core: tests + benchmarks (Windows: use the dev-msvc preset from a VS developer prompt)
cmake --preset dev && cmake --build --preset dev && ctest --preset dev
./build/dev/core/secrethider_bench                  # secrethider_bench.exe on Windows

# Python
python -m venv .venv && . .venv/bin/activate    # Windows: .venv\Scripts\activate
pip install . pytest faker && pytest

# Node
cd bindings/node && npm install && npm run build && npm test

-DSECRETHIDER_WITH_RE2=OFF skips RE2/abseil for a much faster build; custom regex() rules are then unavailable.

Cross-platform builds

  • Python wheels: cibuildwheel (Linux manylinux and musllinux on x86_64 and aarch64, macOS x86_64 + arm64, Windows x64), one stable-ABI (abi3) wheel per platform for Python 3.12+, via .github/workflows/release.yml.
  • Node: Node-API is ABI-stable, so one binary per OS/arch (and per libc on Linux); CI builds Linux binaries in manylinux_2_28 and Alpine containers and collects prebuilds/<platform>-<arch>[-musl]/secrethider.node.
  • SIMD is selected at run time by simdjson/simdutf, so no -march=native and one binary runs fast everywhere.

Limits

Redaction is defence in depth, not a guarantee: it finds known formats, sensitive key names and values you register. See the security model.

License

MIT, see LICENSE.

Metadata

Release files for secrethider 0.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for secrethider 0.2.0
File Size Uploaded
secrethider-0.2.0.tar.gz 113.2 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for secrethider 0.2.0
File
secrethider-0.2.0-cp312-abi3-win_amd64.whl CPython 3.12 abi3 Windows x86-64 Details
secrethider-0.2.0-cp312-abi3-musllinux_1_2_x86_64.whl CPython 3.12 abi3 Linux musl 1.2+ x86-64 Details
secrethider-0.2.0-cp312-abi3-musllinux_1_2_aarch64.whl CPython 3.12 abi3 Linux musl 1.2+ ARM64 Details
secrethider-0.2.0-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl CPython 3.12 abi3 Linux glibc 2.17+ x86-64 Details
secrethider-0.2.0-cp312-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl CPython 3.12 abi3 Linux glibc 2.17+ ARM64 Details
secrethider-0.2.0-cp312-abi3-macosx_11_0_x86_64.whl CPython 3.12 abi3 macOS 11.0+ x86-64 Details
secrethider-0.2.0-cp312-abi3-macosx_11_0_arm64.whl CPython 3.12 abi3 macOS 11.0+ ARM64 Details

Total release size: 5.4 MB

Release files / secrethider-0.2.0.tar.gz

Download URL secrethider-0.2.0.tar.gz
Size 113.2 kB
Tags Source
SHA-256 checksum
How to use checksums
9d967652fe07ae7293e3b89b704ffdbb13b59d65977140b16d4d6ebb3c98cbf1
BLAKE2b-256 checksum
How to use checksums
f1b9bd7632b08a538992155399ef516b29774caa68f4bafc10d709f729ce9ba6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.2.0-cp312-abi3-win_amd64.whl

Download URL secrethider-0.2.0-cp312-abi3-win_amd64.whl
Size 521.1 kB
Tags CPython 3.12 Windows x86-64 abi3
SHA-256 checksum
How to use checksums
3233613680bb070a028e9a79029d7232c367de83c6f27106548d22c2ddaf2e54
BLAKE2b-256 checksum
How to use checksums
26179cc809c47b23d451705d5158561ac9531bfc08e28e2a776538d4901451b9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.2.0-cp312-abi3-musllinux_1_2_x86_64.whl

Download URL secrethider-0.2.0-cp312-abi3-musllinux_1_2_x86_64.whl
Size 1.3 MB
Tags CPython 3.12 Linux musl 1.2+ x86-64 abi3
SHA-256 checksum
How to use checksums
9b8d89fb133c80f3f07598fcb3dd5c79c17d3e796efc5ee114044d15bfb2eb91
BLAKE2b-256 checksum
How to use checksums
cf483173591fa0ec83d92862047fd71f0cacd226f129b75a9635d988c795d38f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.2.0-cp312-abi3-musllinux_1_2_aarch64.whl

Download URL secrethider-0.2.0-cp312-abi3-musllinux_1_2_aarch64.whl
Size 1.1 MB
Tags CPython 3.12 Linux musl 1.2+ ARM64 abi3
SHA-256 checksum
How to use checksums
daaaf0d513706dba0bae96f9aaaa1068c70a1b7674da95d224ea052b7f5d999b
BLAKE2b-256 checksum
How to use checksums
7ee16dd19df46790228c72684d106a0d1c85d80e02d10266b639c023412775e1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.2.0-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL secrethider-0.2.0-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 832.2 kB
Tags CPython 3.12 Linux glibc 2.17+ x86-64 abi3
SHA-256 checksum
How to use checksums
68bc926961b6198344f71477ab022e7094d91855ad280ce52dc88031b76ccc61
BLAKE2b-256 checksum
How to use checksums
a6f79bf530e2e93df1185078be4bc7c001cde599b00e7b517b446616c87b3298
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.2.0-cp312-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl

Download URL secrethider-0.2.0-cp312-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
Size 652.1 kB
Tags CPython 3.12 Linux glibc 2.17+ ARM64 abi3
SHA-256 checksum
How to use checksums
48b9d1f86526be89d27aa0eb63a4d146d600f5e4935af743798a97bc35dd7ffe
BLAKE2b-256 checksum
How to use checksums
5086c8d1f776f6cdb78cdbd05fcf1454ae3517c5b5dfdf5adb7763cbc0df1c12
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.2.0-cp312-abi3-macosx_11_0_x86_64.whl

Download URL secrethider-0.2.0-cp312-abi3-macosx_11_0_x86_64.whl
Size 549.1 kB
Tags CPython 3.12 abi3 macOS 11.0+ x86-64
SHA-256 checksum
How to use checksums
2ac3f9ee983f02f44665522dab1ca08a9c71742b96c4ee02d7bd366e288146f6
BLAKE2b-256 checksum
How to use checksums
f2f985e0db0ab1c0f24b90b972417191e2a2dcd145c76293baddf3b0bcb1b71e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.2.0-cp312-abi3-macosx_11_0_arm64.whl

Download URL secrethider-0.2.0-cp312-abi3-macosx_11_0_arm64.whl
Size 394.0 kB
Tags CPython 3.12 abi3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
da40644771ad0c890c1dd8a3e2743febc33d3920496e369850941857a1881855
BLAKE2b-256 checksum
How to use checksums
59c5656965a39051b884a3ece7c250c25b53ba79c22b5252b5063a5e95b82c5f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release history Release notifications | RSS feed

This release

0.2.0 This release

8 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page