Skip to main content

secretHider

Fast secret redaction, log processing, string and JSON tools: one C++20 core, thin bindings for Python and Node.js.

  • Remove secrets from logs in plain text, logfmt and JSON lines: AWS/GitHub/Slack/Stripe/Google keys, JWTs, PEM private keys, Bearer tokens, URL credentials, password=... fields, and optional PII (email, phone, card, SSN, IBAN, IPv4).
  • Tell it what is secret with plain lists: known values, field names and formats (or one secrets.txt file), on top of the built-in patterns.
  • Choose what happens: delete the whole field (drop_field), mask (full, typed, keep first/last N, preserve length, partial email/phone), stable salted hash, realistic fake data via Faker (Python faker, JS @faker-js/faker), or your own function. Partial masks never reveal more than 25% of a secret.
  • Stream it: chunk-safe redaction for files, pipes and sockets (output equals one-shot output at every split point), a secrethider-redact command line, and in-place/.gz file helpers.
  • Fast: about 600 MiB/s per core on clean logs, roughly 38x a hand-written Python re pipeline and comparable to V8's RegExp for a few simple patterns in Node (numbers). Built on simdjson, simdutf, RE2.
  • Also: json_get (JSON Pointer), json_minify, json_valid, UTF-8 helpers.
secrethider-redact --in-place --drop-fields --secrets-file secrets.txt app.log   # a=1 password=x b=2  ->  a=1 b=2
secrethider-redact --pii --mask fake app.jsonl --json-lines                       # fake emails/phones instead of [REDACTED]
import secrethider
from secrethider import Mask, RedactorBuilder

r = (RedactorBuilder()
     .enable("pii")
     .secret_values(["my-known-secret"])       # also: secret_keys([...]), secret_formats([...])
     .mask(Mask.keep_prefix(4))                # or Mask.drop_field(), secrethider.fake_mask(), ...
     .build())

r.redact("login password=hunter2hunter2hunter2 key=AKIAIOSFODNN7EXAMPLE")
# 'login password=hunt**** key=AKIA****'
# (short secrets fall back to a full mask: 4 revealed characters of a 10-character password would exceed 25%)

# logging, files, streams
from secrethider.logging import RedactingFormatter
handler.setFormatter(RedactingFormatter(r, "%(levelname)s %(message)s"))
secrethider.redact_file(open("in.log"), open("out.log", "w"), r)
const fk = require('secrethider');
const r = new fk.RedactorBuilder().mask(fk.Mask.keepPrefix(4)).build();
process.stdin.pipe(fk.createRedactStream(r)).pipe(process.stdout);

Layout

core/              C++20 library (no Python/Node headers), tests, benchmarks
bindings/python/   nanobind module + `secrethider` package (built via scikit-build-core, root pyproject.toml)
bindings/node/     Node-API addon (node-addon-api + cmake-js)
cmake/             shared CMake modules (dependencies, warnings)
docs/              architecture: interfaces, log processing, rules and masking, builds, performance, security

Documentation

Start with the guide to removing secrets from logs, or docs/README.md for everything: interfaces, log processing pipeline, rules and masking, build and platforms, performance, security model.

Develop

make fix     # format + auto-fix lint: C++ (clang-format), Python (ruff), JS/TS (prettier)
make test    # build, run all tests (C++, Python, Node), then the benchmarks
make help    # everything else: lint, check (tests only), bench, bench-full, qa (leak checks + long fuzz), clean

make finds Visual Studio's C++ tools on Windows by itself. Without make, the underlying steps are:

# C++ core: tests + benchmarks (Windows: use the dev-msvc preset from a VS developer prompt)
cmake --preset dev && cmake --build --preset dev && ctest --preset dev
./build/dev/core/secrethider_bench                  # secrethider_bench.exe on Windows

# Python
python -m venv .venv && . .venv/bin/activate    # Windows: .venv\Scripts\activate
pip install . pytest faker && pytest

# Node
cd bindings/node && npm install && npm run build && npm test

-DSECRETHIDER_WITH_RE2=OFF skips RE2/abseil for a much faster build; custom regex() rules are then unavailable.

Cross-platform builds

  • Python wheels: cibuildwheel (Linux manylinux/musllinux, macOS x86_64 + arm64, Windows), stable-ABI (abi3) wheels, via .github/workflows/release.yml.
  • Node: Node-API is ABI-stable, so one binary per OS/arch; CI collects prebuilds/<platform>-<arch>/secrethider.node.
  • SIMD is selected at run time by simdjson/simdutf, so no -march=native and one binary runs fast everywhere.

Limits

Redaction is defence in depth, not a guarantee: it finds known formats, sensitive key names and values you register. See the security model.

License

MIT, see LICENSE.

Metadata

Release files for secrethider 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for secrethider 0.1.0
File Size Uploaded
secrethider-0.1.0.tar.gz 101.3 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for secrethider 0.1.0
File
secrethider-0.1.0-cp312-abi3-win_amd64.whl CPython 3.12 abi3 Windows x86-64 Details
secrethider-0.1.0-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl CPython 3.12 abi3 Linux glibc 2.17+ x86-64 Details
secrethider-0.1.0-cp312-abi3-macosx_11_0_x86_64.whl CPython 3.12 abi3 macOS 11.0+ x86-64 Details
secrethider-0.1.0-cp312-abi3-macosx_11_0_arm64.whl CPython 3.12 abi3 macOS 11.0+ ARM64 Details
secrethider-0.1.0-cp311-cp311-win_amd64.whl CPython 3.11 CPython 3.11 Windows x86-64 Details
secrethider-0.1.0-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl CPython 3.11 CPython 3.11 Linux glibc 2.17+ x86-64 Details
secrethider-0.1.0-cp311-cp311-macosx_11_0_x86_64.whl CPython 3.11 CPython 3.11 macOS 11.0+ x86-64 Details
secrethider-0.1.0-cp311-cp311-macosx_11_0_arm64.whl CPython 3.11 CPython 3.11 macOS 11.0+ ARM64 Details
secrethider-0.1.0-cp310-cp310-win_amd64.whl CPython 3.10 CPython 3.10 Windows x86-64 Details
secrethider-0.1.0-cp310-cp310-manylinux_2_17_x86_64.manylinux2014_x86_64.whl CPython 3.10 CPython 3.10 Linux glibc 2.17+ x86-64 Details
secrethider-0.1.0-cp310-cp310-macosx_11_0_x86_64.whl CPython 3.10 CPython 3.10 macOS 11.0+ x86-64 Details
secrethider-0.1.0-cp310-cp310-macosx_11_0_arm64.whl CPython 3.10 CPython 3.10 macOS 11.0+ ARM64 Details
secrethider-0.1.0-cp39-cp39-win_amd64.whl CPython 3.9 CPython 3.9 Windows x86-64 Details
secrethider-0.1.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl CPython 3.9 CPython 3.9 Linux glibc 2.17+ x86-64 Details
secrethider-0.1.0-cp39-cp39-macosx_11_0_x86_64.whl CPython 3.9 CPython 3.9 macOS 11.0+ x86-64 Details
secrethider-0.1.0-cp39-cp39-macosx_11_0_arm64.whl CPython 3.9 CPython 3.9 macOS 11.0+ ARM64 Details

Total release size: 9.2 MB

Release files / secrethider-0.1.0.tar.gz

Download URL secrethider-0.1.0.tar.gz
Size 101.3 kB
Tags Source
SHA-256 checksum
How to use checksums
cb7643426a1a27f342c7ce4c85d02fb9f2256876f669660c67d68eea736f52e6
BLAKE2b-256 checksum
How to use checksums
6119905d1e3ed9e92ff7488b9a2e1ec46a65ff216384f5398f239877d2d2a5a2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.0-cp312-abi3-win_amd64.whl

Download URL secrethider-0.1.0-cp312-abi3-win_amd64.whl
Size 520.4 kB
Tags CPython 3.12 Windows x86-64 abi3
SHA-256 checksum
How to use checksums
a55077084f2eebfc0795613963d6f343fe3a07c70b873215a1645a1a0b31d93f
BLAKE2b-256 checksum
How to use checksums
83c1c66853205b87da73646d3d435ca2e8aea0576c89f7c73e1943f691ee4326
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.0-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL secrethider-0.1.0-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 834.1 kB
Tags CPython 3.12 Linux glibc 2.17+ x86-64 abi3
SHA-256 checksum
How to use checksums
2cc73bef167bf118b4a255e9b8f40d8a898edd9a83ea8bd628dabc141af5386b
BLAKE2b-256 checksum
How to use checksums
6fba46bc3c9a7052457c7e09dd5159f65d1c062a3399f94e665e3629714001bb
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.0-cp312-abi3-macosx_11_0_x86_64.whl

Download URL secrethider-0.1.0-cp312-abi3-macosx_11_0_x86_64.whl
Size 547.1 kB
Tags CPython 3.12 abi3 macOS 11.0+ x86-64
SHA-256 checksum
How to use checksums
28640ee9f0af3c31ff2b528a091c133962d50b3ac6f5ffcdd5d0b7c02543d712
BLAKE2b-256 checksum
How to use checksums
f5857ac7444b226a5b267d8078a40cf162fd90f4f73bdd97815894bc24df1569
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.0-cp312-abi3-macosx_11_0_arm64.whl

Download URL secrethider-0.1.0-cp312-abi3-macosx_11_0_arm64.whl
Size 394.3 kB
Tags CPython 3.12 abi3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
d6dbc80c67e3ca1377488146af66495b26b2178d748826c1b1345abfff14e002
BLAKE2b-256 checksum
How to use checksums
717f44d6f2e022529640c80855d7094472eadf4c9399c2bf797a2325f5c6e92d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.0-cp311-cp311-win_amd64.whl

Download URL secrethider-0.1.0-cp311-cp311-win_amd64.whl
Size 520.6 kB
Tags CPython 3.11 Windows x86-64
SHA-256 checksum
How to use checksums
ee1fa6238bc718f3a32d9ff49a3e8a62ce8f3dfa7f4f3d75262a5c2b91c4c9a4
BLAKE2b-256 checksum
How to use checksums
dc963fc8d7ead89da596ab462d7c49de007708b3b76cf12ab20cfabd8a6a590e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.0-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL secrethider-0.1.0-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 834.7 kB
Tags CPython 3.11 Linux glibc 2.17+ x86-64
SHA-256 checksum
How to use checksums
cc20d8f51979807ad849ee200effde2f6f6b09e1d84922196c833286f907b341
BLAKE2b-256 checksum
How to use checksums
7d00a6eab9d86a2ee957f77476b08a8d7d7e8e4bd5449f6fb93765623d671282
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.0-cp311-cp311-macosx_11_0_x86_64.whl

Download URL secrethider-0.1.0-cp311-cp311-macosx_11_0_x86_64.whl
Size 547.3 kB
Tags CPython 3.11 macOS 11.0+ x86-64
SHA-256 checksum
How to use checksums
6ee2153ccc9dc630a11caf4736436da7fe978274c6fa0316a91f83ec8ebc2b63
BLAKE2b-256 checksum
How to use checksums
6be0ff7566c6c777320f1a9e2d6075b0632d5e50f8f33da36b5ee87b3db9fe19
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.0-cp311-cp311-macosx_11_0_arm64.whl

Download URL secrethider-0.1.0-cp311-cp311-macosx_11_0_arm64.whl
Size 394.9 kB
Tags CPython 3.11 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
738d4654f980d616042da00fee1210d7c9bf6397f916bf24d7dff7e049323832
BLAKE2b-256 checksum
How to use checksums
abcf27b51e16d12b6fdb160812233c81a2e7f417ce997d945af15cfd84d513b6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.0-cp310-cp310-win_amd64.whl

Download URL secrethider-0.1.0-cp310-cp310-win_amd64.whl
Size 520.2 kB
Tags CPython 3.10 Windows x86-64
SHA-256 checksum
How to use checksums
21a0e7cedae78e76ad071cc8384ce6ec649627df16ba6f28e6e2f5a7c44dd7c4
BLAKE2b-256 checksum
How to use checksums
1219816c81bfc58929a59ebec8b0b260718e0804d3c6963390552302a0cb1df2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.0-cp310-cp310-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL secrethider-0.1.0-cp310-cp310-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 834.9 kB
Tags CPython 3.10 Linux glibc 2.17+ x86-64
SHA-256 checksum
How to use checksums
e5a816d9f0f672b42d60065eaaae0401c6c0d1bad9ced308b7d5c3acde55aae8
BLAKE2b-256 checksum
How to use checksums
f560cdf0aec20cbd265765c4f4df53b73ae18134e1c128d5c6b00dd7cf956814
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.0-cp310-cp310-macosx_11_0_x86_64.whl

Download URL secrethider-0.1.0-cp310-cp310-macosx_11_0_x86_64.whl
Size 547.6 kB
Tags CPython 3.10 macOS 11.0+ x86-64
SHA-256 checksum
How to use checksums
d3174f108c1c8137cc7c35318873740abe31e20ade7ccb79414c3116b78a5f59
BLAKE2b-256 checksum
How to use checksums
a7ab947a4155afaa32eb3a85b0c6fcefa9549f24ad11d8bfccaddc9a89f58f83
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.0-cp310-cp310-macosx_11_0_arm64.whl

Download URL secrethider-0.1.0-cp310-cp310-macosx_11_0_arm64.whl
Size 395.4 kB
Tags CPython 3.10 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
98058d04852bf6749b32d607d0be0bcd5471146fd340e16c2e9d8863a89a487a
BLAKE2b-256 checksum
How to use checksums
6792d7a874645bba26cc2c36c5b18000e17940247dba574be48e1255c91c761c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.0-cp39-cp39-win_amd64.whl

Download URL secrethider-0.1.0-cp39-cp39-win_amd64.whl
Size 494.5 kB
Tags CPython 3.9 Windows x86-64
SHA-256 checksum
How to use checksums
f3aead37a8d777175e4110265d35a8a2a7fd54c621e22b51c5af3b6c638e4b2c
BLAKE2b-256 checksum
How to use checksums
aec97296f9277d8e2bda43cb929c59e2dfd096e55f595d73de03579e16b51c56
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL secrethider-0.1.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 829.1 kB
Tags CPython 3.9 Linux glibc 2.17+ x86-64
SHA-256 checksum
How to use checksums
4dd4362c259dec5222f11aecd022ce9e0b61d526bb5dd58d2a3aa0d33fdaaf99
BLAKE2b-256 checksum
How to use checksums
023ba82b19a74bbcd5ba9f6c2f559d1a6711e0d3f9326c171831b3f9d5e6d750
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.0-cp39-cp39-macosx_11_0_x86_64.whl

Download URL secrethider-0.1.0-cp39-cp39-macosx_11_0_x86_64.whl
Size 537.4 kB
Tags CPython 3.9 macOS 11.0+ x86-64
SHA-256 checksum
How to use checksums
d16338e8e40cc1947acd81758321cf4a575f3f172bd053949aea1f9ddef8187a
BLAKE2b-256 checksum
How to use checksums
1177e923e556eea52132f1cce10ef9fc3d0fe99757dad12e56153374a8b3c78b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.0-cp39-cp39-macosx_11_0_arm64.whl

Download URL secrethider-0.1.0-cp39-cp39-macosx_11_0_arm64.whl
Size 391.1 kB
Tags CPython 3.9 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
46c804dc0a5d586dcfcba41d7e17a3bc01cd9d76873b8ae9eec9564e2623891f
BLAKE2b-256 checksum
How to use checksums
dfbfdc2472681dccfa1b599baf08ddcd9e31388441870ab07c4f9046fe3aac50
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release history Release notifications | RSS feed

0.2.0

8 release files

This release

0.1.0 This release

17 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page