secretHider
Fast secret redaction, log processing, string and JSON tools: one C++20 core, thin bindings for Python and Node.js.
- Remove secrets from logs in plain text, logfmt and JSON lines: AWS/GitHub/Slack/Stripe/Google keys, JWTs, PEM private keys,
Bearertokens, URL credentials,password=...fields, and optional PII (email, phone, card, SSN, IBAN, IPv4). - Tell it what is secret with plain lists: known values, field names and formats (or one
secrets.txtfile), on top of the built-in patterns. - Choose what happens: delete the whole field (
drop_field), mask (full, typed, keep first/last N, preserve length, partial email/phone), stable salted hash, realistic fake data via Faker (Pythonfaker, JS@faker-js/faker), or your own function. Partial masks never reveal more than 25% of a secret. - Stream it: chunk-safe redaction for files, pipes and sockets (output equals one-shot output at every split point), a
secrethider-redactcommand line, and in-place/.gzfile helpers. - Fast: about 600 MiB/s per core on clean logs, roughly 38x a hand-written Python
repipeline and comparable to V8's RegExp for a few simple patterns in Node (numbers). Built on simdjson, simdutf, RE2. - Also:
json_get(JSON Pointer),json_minify,json_valid, UTF-8 helpers.
secrethider-redact --in-place --drop-fields --secrets-file secrets.txt app.log # a=1 password=x b=2 -> a=1 b=2
secrethider-redact --pii --mask fake app.jsonl --json-lines # fake emails/phones instead of [REDACTED]
import secrethider
from secrethider import Mask, RedactorBuilder
r = (RedactorBuilder()
.enable("pii")
.secret_values(["my-known-secret"]) # also: secret_keys([...]), secret_formats([...])
.mask(Mask.keep_prefix(4)) # or Mask.drop_field(), secrethider.fake_mask(), ...
.build())
r.redact("login password=hunter2hunter2hunter2 key=AKIAIOSFODNN7EXAMPLE")
# 'login password=hunt**** key=AKIA****'
# (short secrets fall back to a full mask: 4 revealed characters of a 10-character password would exceed 25%)
# logging, files, streams
from secrethider.logging import RedactingFormatter
handler.setFormatter(RedactingFormatter(r, "%(levelname)s %(message)s"))
secrethider.redact_file(open("in.log"), open("out.log", "w"), r)
const fk = require('secrethider');
const r = new fk.RedactorBuilder().mask(fk.Mask.keepPrefix(4)).build();
process.stdin.pipe(fk.createRedactStream(r)).pipe(process.stdout);
Layout
core/ C++20 library (no Python/Node headers), tests, benchmarks
bindings/python/ nanobind module + `secrethider` package (built via scikit-build-core, root pyproject.toml)
bindings/node/ Node-API addon (node-addon-api + cmake-js)
cmake/ shared CMake modules (dependencies, warnings)
docs/ architecture: interfaces, log processing, rules and masking, builds, performance, security
Documentation
Start with the guide to removing secrets from logs, or docs/README.md for everything: interfaces, log processing pipeline, rules and masking, build and platforms, performance, security model.
Develop
make fix # format + auto-fix lint: C++ (clang-format), Python (ruff), JS/TS (prettier)
make test # build, run all tests (C++, Python, Node), then the benchmarks
make help # everything else: lint, check (tests only), bench, bench-full, qa (leak checks + long fuzz), clean
make finds Visual Studio's C++ tools on Windows by itself. Without make, the underlying steps are:
# C++ core: tests + benchmarks (Windows: use the dev-msvc preset from a VS developer prompt)
cmake --preset dev && cmake --build --preset dev && ctest --preset dev
./build/dev/core/secrethider_bench # secrethider_bench.exe on Windows
# Python
python -m venv .venv && . .venv/bin/activate # Windows: .venv\Scripts\activate
pip install . pytest faker && pytest
# Node
cd bindings/node && npm install && npm run build && npm test
-DSECRETHIDER_WITH_RE2=OFF skips RE2/abseil for a much faster build; custom regex() rules are then unavailable.
Cross-platform builds
- Python wheels:
cibuildwheel(Linux manylinux/musllinux, macOS x86_64 + arm64, Windows), stable-ABI (abi3) wheels, via.github/workflows/release.yml. - Node: Node-API is ABI-stable, so one binary per OS/arch; CI collects
prebuilds/<platform>-<arch>/secrethider.node. - SIMD is selected at run time by simdjson/simdutf, so no
-march=nativeand one binary runs fast everywhere.
Limits
Redaction is defence in depth, not a guarantee: it finds known formats, sensitive key names and values you register. See the security model.
License
MIT, see LICENSE.
Metadata
Release files for secrethider 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| secrethider-0.1.0.tar.gz | 101.3 kB | Details |
Built distributions (wheels)
Total release size: 9.2 MB
Release files / secrethider-0.1.0.tar.gz
| Download URL | secrethider-0.1.0.tar.gz |
|---|---|
| Size | 101.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
cb7643426a1a27f342c7ce4c85d02fb9f2256876f669660c67d68eea736f52e6
|
|
BLAKE2b-256 checksum How to use checksums |
6119905d1e3ed9e92ff7488b9a2e1ec46a65ff216384f5398f239877d2d2a5a2
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.0-cp312-abi3-win_amd64.whl
| Download URL | secrethider-0.1.0-cp312-abi3-win_amd64.whl |
|---|---|
| Size | 520.4 kB |
| Tags | CPython 3.12 Windows x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
a55077084f2eebfc0795613963d6f343fe3a07c70b873215a1645a1a0b31d93f
|
|
BLAKE2b-256 checksum How to use checksums |
83c1c66853205b87da73646d3d435ca2e8aea0576c89f7c73e1943f691ee4326
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.0-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | secrethider-0.1.0-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 834.1 kB |
| Tags | CPython 3.12 Linux glibc 2.17+ x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
2cc73bef167bf118b4a255e9b8f40d8a898edd9a83ea8bd628dabc141af5386b
|
|
BLAKE2b-256 checksum How to use checksums |
6fba46bc3c9a7052457c7e09dd5159f65d1c062a3399f94e665e3629714001bb
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.0-cp312-abi3-macosx_11_0_x86_64.whl
| Download URL | secrethider-0.1.0-cp312-abi3-macosx_11_0_x86_64.whl |
|---|---|
| Size | 547.1 kB |
| Tags | CPython 3.12 abi3 macOS 11.0+ x86-64 |
|
SHA-256 checksum How to use checksums |
28640ee9f0af3c31ff2b528a091c133962d50b3ac6f5ffcdd5d0b7c02543d712
|
|
BLAKE2b-256 checksum How to use checksums |
f5857ac7444b226a5b267d8078a40cf162fd90f4f73bdd97815894bc24df1569
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.0-cp312-abi3-macosx_11_0_arm64.whl
| Download URL | secrethider-0.1.0-cp312-abi3-macosx_11_0_arm64.whl |
|---|---|
| Size | 394.3 kB |
| Tags | CPython 3.12 abi3 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
d6dbc80c67e3ca1377488146af66495b26b2178d748826c1b1345abfff14e002
|
|
BLAKE2b-256 checksum How to use checksums |
717f44d6f2e022529640c80855d7094472eadf4c9399c2bf797a2325f5c6e92d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.0-cp311-cp311-win_amd64.whl
| Download URL | secrethider-0.1.0-cp311-cp311-win_amd64.whl |
|---|---|
| Size | 520.6 kB |
| Tags | CPython 3.11 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
ee1fa6238bc718f3a32d9ff49a3e8a62ce8f3dfa7f4f3d75262a5c2b91c4c9a4
|
|
BLAKE2b-256 checksum How to use checksums |
dc963fc8d7ead89da596ab462d7c49de007708b3b76cf12ab20cfabd8a6a590e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.0-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | secrethider-0.1.0-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 834.7 kB |
| Tags | CPython 3.11 Linux glibc 2.17+ x86-64 |
|
SHA-256 checksum How to use checksums |
cc20d8f51979807ad849ee200effde2f6f6b09e1d84922196c833286f907b341
|
|
BLAKE2b-256 checksum How to use checksums |
7d00a6eab9d86a2ee957f77476b08a8d7d7e8e4bd5449f6fb93765623d671282
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.0-cp311-cp311-macosx_11_0_x86_64.whl
| Download URL | secrethider-0.1.0-cp311-cp311-macosx_11_0_x86_64.whl |
|---|---|
| Size | 547.3 kB |
| Tags | CPython 3.11 macOS 11.0+ x86-64 |
|
SHA-256 checksum How to use checksums |
6ee2153ccc9dc630a11caf4736436da7fe978274c6fa0316a91f83ec8ebc2b63
|
|
BLAKE2b-256 checksum How to use checksums |
6be0ff7566c6c777320f1a9e2d6075b0632d5e50f8f33da36b5ee87b3db9fe19
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.0-cp311-cp311-macosx_11_0_arm64.whl
| Download URL | secrethider-0.1.0-cp311-cp311-macosx_11_0_arm64.whl |
|---|---|
| Size | 394.9 kB |
| Tags | CPython 3.11 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
738d4654f980d616042da00fee1210d7c9bf6397f916bf24d7dff7e049323832
|
|
BLAKE2b-256 checksum How to use checksums |
abcf27b51e16d12b6fdb160812233c81a2e7f417ce997d945af15cfd84d513b6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.0-cp310-cp310-win_amd64.whl
| Download URL | secrethider-0.1.0-cp310-cp310-win_amd64.whl |
|---|---|
| Size | 520.2 kB |
| Tags | CPython 3.10 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
21a0e7cedae78e76ad071cc8384ce6ec649627df16ba6f28e6e2f5a7c44dd7c4
|
|
BLAKE2b-256 checksum How to use checksums |
1219816c81bfc58929a59ebec8b0b260718e0804d3c6963390552302a0cb1df2
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.0-cp310-cp310-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | secrethider-0.1.0-cp310-cp310-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 834.9 kB |
| Tags | CPython 3.10 Linux glibc 2.17+ x86-64 |
|
SHA-256 checksum How to use checksums |
e5a816d9f0f672b42d60065eaaae0401c6c0d1bad9ced308b7d5c3acde55aae8
|
|
BLAKE2b-256 checksum How to use checksums |
f560cdf0aec20cbd265765c4f4df53b73ae18134e1c128d5c6b00dd7cf956814
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.0-cp310-cp310-macosx_11_0_x86_64.whl
| Download URL | secrethider-0.1.0-cp310-cp310-macosx_11_0_x86_64.whl |
|---|---|
| Size | 547.6 kB |
| Tags | CPython 3.10 macOS 11.0+ x86-64 |
|
SHA-256 checksum How to use checksums |
d3174f108c1c8137cc7c35318873740abe31e20ade7ccb79414c3116b78a5f59
|
|
BLAKE2b-256 checksum How to use checksums |
a7ab947a4155afaa32eb3a85b0c6fcefa9549f24ad11d8bfccaddc9a89f58f83
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.0-cp310-cp310-macosx_11_0_arm64.whl
| Download URL | secrethider-0.1.0-cp310-cp310-macosx_11_0_arm64.whl |
|---|---|
| Size | 395.4 kB |
| Tags | CPython 3.10 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
98058d04852bf6749b32d607d0be0bcd5471146fd340e16c2e9d8863a89a487a
|
|
BLAKE2b-256 checksum How to use checksums |
6792d7a874645bba26cc2c36c5b18000e17940247dba574be48e1255c91c761c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.0-cp39-cp39-win_amd64.whl
| Download URL | secrethider-0.1.0-cp39-cp39-win_amd64.whl |
|---|---|
| Size | 494.5 kB |
| Tags | CPython 3.9 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
f3aead37a8d777175e4110265d35a8a2a7fd54c621e22b51c5af3b6c638e4b2c
|
|
BLAKE2b-256 checksum How to use checksums |
aec97296f9277d8e2bda43cb929c59e2dfd096e55f595d73de03579e16b51c56
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | secrethider-0.1.0-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 829.1 kB |
| Tags | CPython 3.9 Linux glibc 2.17+ x86-64 |
|
SHA-256 checksum How to use checksums |
4dd4362c259dec5222f11aecd022ce9e0b61d526bb5dd58d2a3aa0d33fdaaf99
|
|
BLAKE2b-256 checksum How to use checksums |
023ba82b19a74bbcd5ba9f6c2f559d1a6711e0d3f9326c171831b3f9d5e6d750
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.0-cp39-cp39-macosx_11_0_x86_64.whl
| Download URL | secrethider-0.1.0-cp39-cp39-macosx_11_0_x86_64.whl |
|---|---|
| Size | 537.4 kB |
| Tags | CPython 3.9 macOS 11.0+ x86-64 |
|
SHA-256 checksum How to use checksums |
d16338e8e40cc1947acd81758321cf4a575f3f172bd053949aea1f9ddef8187a
|
|
BLAKE2b-256 checksum How to use checksums |
1177e923e556eea52132f1cce10ef9fc3d0fe99757dad12e56153374a8b3c78b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.0-cp39-cp39-macosx_11_0_arm64.whl
| Download URL | secrethider-0.1.0-cp39-cp39-macosx_11_0_arm64.whl |
|---|---|
| Size | 391.1 kB |
| Tags | CPython 3.9 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
46c804dc0a5d586dcfcba41d7e17a3bc01cd9d76873b8ae9eec9564e2623891f
|
|
BLAKE2b-256 checksum How to use checksums |
dfbfdc2472681dccfa1b599baf08ddcd9e31388441870ab07c4f9046fe3aac50
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|