secretHider
Fast secret redaction, log processing, string and JSON tools: one C++20 core, thin bindings for Python and Node.js.
- Remove secrets from logs in plain text, logfmt and JSON lines: AWS/GitHub/Slack/Stripe/Google keys, JWTs, PEM private keys,
Bearertokens, URL credentials,password=...fields, and optional PII (email, phone, card, SSN, IBAN, IPv4). - Tell it what is secret with plain lists: known values, field names and formats (or one
secrets.txtfile), on top of the built-in patterns. - Choose what happens: delete the whole field (
drop_field), mask (full, typed, keep first/last N, preserve length, partial email/phone), stable salted hash, realistic fake data via Faker (Pythonfaker, JS@faker-js/faker), or your own function. Partial masks never reveal more than 25% of a secret. - Stream it: chunk-safe redaction for files, pipes and sockets (output equals one-shot output at every split point), a
secrethider-redactcommand line, and in-place/.gzfile helpers. - Fast: about 600 MiB/s per core on clean logs, roughly 38x a hand-written Python
repipeline and comparable to V8's RegExp for a few simple patterns in Node (numbers). Built on simdjson, simdutf, RE2. - Also:
json_get(JSON Pointer),json_minify,json_valid, UTF-8 helpers.
secrethider-redact --in-place --drop-fields --secrets-file secrets.txt app.log # a=1 password=x b=2 -> a=1 b=2
secrethider-redact --pii --mask fake app.jsonl --json-lines # fake emails/phones instead of [REDACTED]
import secrethider
from secrethider import Mask, RedactorBuilder
r = (RedactorBuilder()
.enable("pii")
.secret_values(["my-known-secret"]) # also: secret_keys([...]), secret_formats([...])
.mask(Mask.keep_prefix(4)) # or Mask.drop_field(), secrethider.fake_mask(), ...
.build())
r.redact("login password=hunter2hunter2hunter2 key=AKIAIOSFODNN7EXAMPLE")
# 'login password=hunt**** key=AKIA****'
# (short secrets fall back to a full mask: 4 revealed characters of a 10-character password would exceed 25%)
# logging, files, streams
from secrethider.logging import RedactingFormatter
handler.setFormatter(RedactingFormatter(r, "%(levelname)s %(message)s"))
secrethider.redact_file(open("in.log"), open("out.log", "w"), r)
const fk = require('@noobforal/secrethider');
const r = new fk.RedactorBuilder().mask(fk.Mask.keepPrefix(4)).build();
process.stdin.pipe(fk.createRedactStream(r)).pipe(process.stdout);
Install
pip install secrethider # Python 3.9+; add `faker` for realistic fake-data masks
npm install @noobforal/secrethider # Node.js 18+ (prebuilt binaries for Linux/macOS/Windows x64 and macOS arm64)
The npm package is scoped because npm rejects the unscoped name secrethider as too similar to an existing package.
Layout
core/ C++20 library (no Python/Node headers), tests, benchmarks
bindings/python/ nanobind module + `secrethider` package (built via scikit-build-core, root pyproject.toml)
bindings/node/ Node-API addon (node-addon-api + cmake-js)
cmake/ shared CMake modules (dependencies, warnings)
docs/ architecture: interfaces, log processing, rules and masking, builds, performance, security
Documentation
Start with the guide to removing secrets from logs, or docs/README.md for everything: interfaces, log processing pipeline, rules and masking, build and platforms, performance, security model.
Develop
make fix # format + auto-fix lint: C++ (clang-format), Python (ruff), JS/TS (prettier)
make test # build, run all tests (C++, Python, Node), then the benchmarks
make help # everything else: lint, check (tests only), bench, bench-full, qa (leak checks + long fuzz), clean
make finds Visual Studio's C++ tools on Windows by itself. Without make, the underlying steps are:
# C++ core: tests + benchmarks (Windows: use the dev-msvc preset from a VS developer prompt)
cmake --preset dev && cmake --build --preset dev && ctest --preset dev
./build/dev/core/secrethider_bench # secrethider_bench.exe on Windows
# Python
python -m venv .venv && . .venv/bin/activate # Windows: .venv\Scripts\activate
pip install . pytest faker && pytest
# Node
cd bindings/node && npm install && npm run build && npm test
-DSECRETHIDER_WITH_RE2=OFF skips RE2/abseil for a much faster build; custom regex() rules are then unavailable.
Cross-platform builds
- Python wheels:
cibuildwheel(Linux manylinux/musllinux, macOS x86_64 + arm64, Windows), stable-ABI (abi3) wheels, via.github/workflows/release.yml. - Node: Node-API is ABI-stable, so one binary per OS/arch; CI collects
prebuilds/<platform>-<arch>/secrethider.node. - SIMD is selected at run time by simdjson/simdutf, so no
-march=nativeand one binary runs fast everywhere.
Limits
Redaction is defence in depth, not a guarantee: it finds known formats, sensitive key names and values you register. See the security model.
License
MIT, see LICENSE.
Metadata
Release files for secrethider 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| secrethider-0.1.1.tar.gz | 101.6 kB | Details |
Built distributions (wheels)
Total release size: 9.2 MB
Release files / secrethider-0.1.1.tar.gz
| Download URL | secrethider-0.1.1.tar.gz |
|---|---|
| Size | 101.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
9fc6fde6d6a8fbbbf30498514b0dece78aa6aaf9433635b0657daf7c5d92fad9
|
|
BLAKE2b-256 checksum How to use checksums |
eefe4e335c94495476d0bee81e6b840ba719c279ed961d1c08bcb1879a4e7374
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.1-cp312-abi3-win_amd64.whl
| Download URL | secrethider-0.1.1-cp312-abi3-win_amd64.whl |
|---|---|
| Size | 520.6 kB |
| Tags | CPython 3.12 Windows x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
738bf0686b2175bed6b1e33d432b34fc5e722d4ae97b2893051b35aa0d4a4531
|
|
BLAKE2b-256 checksum How to use checksums |
ba7b5e589009f08531c1c0215978060bcba95dff257fb0a0a9ff7fe33224c6df
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.1-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | secrethider-0.1.1-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 834.3 kB |
| Tags | CPython 3.12 Linux glibc 2.17+ x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
64db408f9cfee13673412d99d9af7e814acb772a7863ca1b6b642e4f2aae73f6
|
|
BLAKE2b-256 checksum How to use checksums |
372d43ff59cdc3bd5c11febb7dfeea554eb4979ad7a8e4b4f232909de7d78323
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.1-cp312-abi3-macosx_11_0_x86_64.whl
| Download URL | secrethider-0.1.1-cp312-abi3-macosx_11_0_x86_64.whl |
|---|---|
| Size | 547.2 kB |
| Tags | CPython 3.12 abi3 macOS 11.0+ x86-64 |
|
SHA-256 checksum How to use checksums |
dcbb224bb25d90ba5391a175bfa13e174d6222ade4e6ea65f5fe6867adbddbce
|
|
BLAKE2b-256 checksum How to use checksums |
c9fbce2017fc5333e9274afd28637ab99b84775a31b614989fda9ef1e3721ffa
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.1-cp312-abi3-macosx_11_0_arm64.whl
| Download URL | secrethider-0.1.1-cp312-abi3-macosx_11_0_arm64.whl |
|---|---|
| Size | 394.5 kB |
| Tags | CPython 3.12 abi3 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
25a15c577006120542f5e679850ab65d799d0529336930af44e7668a57a7d0ba
|
|
BLAKE2b-256 checksum How to use checksums |
22be31913c67dc87395283953cb3bc850b8e81948de3525cb5653bcc0767798a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.1-cp311-cp311-win_amd64.whl
| Download URL | secrethider-0.1.1-cp311-cp311-win_amd64.whl |
|---|---|
| Size | 520.7 kB |
| Tags | CPython 3.11 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
43caceb191ff9f65727ec8b06f7198cd84d3d60308783987832ef21121b4f8ff
|
|
BLAKE2b-256 checksum How to use checksums |
b03c42e14676160b40f37710059664b896c51c73b029d675a8e0c6c8ef65045c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.1-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | secrethider-0.1.1-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 834.9 kB |
| Tags | CPython 3.11 Linux glibc 2.17+ x86-64 |
|
SHA-256 checksum How to use checksums |
145032304185c9a9303691e00c2569a99a26676e91ba950901cc387673950c03
|
|
BLAKE2b-256 checksum How to use checksums |
38951d1cbf299b41ff818adf9ebf70f95143876bb8f79f35c2f9676579e23db8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.1-cp311-cp311-macosx_11_0_x86_64.whl
| Download URL | secrethider-0.1.1-cp311-cp311-macosx_11_0_x86_64.whl |
|---|---|
| Size | 547.5 kB |
| Tags | CPython 3.11 macOS 11.0+ x86-64 |
|
SHA-256 checksum How to use checksums |
f0e409368fafadbe748673bff51c412e62fc256537c13454c8564b5c11a46ec8
|
|
BLAKE2b-256 checksum How to use checksums |
5da746bd19f4d116b731f48c8c711cfdfb83e95097e7fd4f27592e161baf7d5a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.1-cp311-cp311-macosx_11_0_arm64.whl
| Download URL | secrethider-0.1.1-cp311-cp311-macosx_11_0_arm64.whl |
|---|---|
| Size | 395.0 kB |
| Tags | CPython 3.11 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
1d176487dec6fbf1192aa12c258d50c8e8b284527c15c434bb077910303dce46
|
|
BLAKE2b-256 checksum How to use checksums |
51d4c70d783b2e9f8e2e7c5a891909ff685f5584115d5b97f02cb697299972f4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.1-cp310-cp310-win_amd64.whl
| Download URL | secrethider-0.1.1-cp310-cp310-win_amd64.whl |
|---|---|
| Size | 520.3 kB |
| Tags | CPython 3.10 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
1503427faf956d1c1a440c4f658dd6d4dcc137a5a7c79bfbe28c309f2ddb1c5a
|
|
BLAKE2b-256 checksum How to use checksums |
2aa8be4c36102df0ac42dfb44fef96aeea36e7bec2121f7a509ccf9d1f62e33f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.1-cp310-cp310-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | secrethider-0.1.1-cp310-cp310-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 835.1 kB |
| Tags | CPython 3.10 Linux glibc 2.17+ x86-64 |
|
SHA-256 checksum How to use checksums |
b18f185597e1d0166c64ec121f50de6e26ae99cbc8e831913c5e83728d854910
|
|
BLAKE2b-256 checksum How to use checksums |
3f537f7968b5aea474db7d528be4812ce63812f630963006638d07db800e4618
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.1-cp310-cp310-macosx_11_0_x86_64.whl
| Download URL | secrethider-0.1.1-cp310-cp310-macosx_11_0_x86_64.whl |
|---|---|
| Size | 547.7 kB |
| Tags | CPython 3.10 macOS 11.0+ x86-64 |
|
SHA-256 checksum How to use checksums |
5ba4ca6a771e957d5bac5ea704eb192c8943f76ca572d12dd76738a9681b5dc1
|
|
BLAKE2b-256 checksum How to use checksums |
aac89bdec555d154bcce57e712b3f9913e8f815c377d2e654cf8eccdb3c29162
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.1-cp310-cp310-macosx_11_0_arm64.whl
| Download URL | secrethider-0.1.1-cp310-cp310-macosx_11_0_arm64.whl |
|---|---|
| Size | 395.6 kB |
| Tags | CPython 3.10 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
3ab795301e07978109d0b1638640de44bb8f2859cabea7b8908e86f9b65770e7
|
|
BLAKE2b-256 checksum How to use checksums |
762b09183b579d7e7082aafe2753e8a517d237a3b90199a6d1df3d431eb5faaf
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.1-cp39-cp39-win_amd64.whl
| Download URL | secrethider-0.1.1-cp39-cp39-win_amd64.whl |
|---|---|
| Size | 494.6 kB |
| Tags | CPython 3.9 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
e50952e540e6b6640d5faa5af072a651125ce3ca6b703885aa961dca574d1afe
|
|
BLAKE2b-256 checksum How to use checksums |
90f40f5e403a431c357bbf11ca944c6fd9b00d72efa41bd4bf912283d8a43d09
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.1-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | secrethider-0.1.1-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 829.3 kB |
| Tags | CPython 3.9 Linux glibc 2.17+ x86-64 |
|
SHA-256 checksum How to use checksums |
8ebf67c0eab547ff360ce7d6548ef2c7ff2b38af1b1d3323c2d9d880cb7b87ac
|
|
BLAKE2b-256 checksum How to use checksums |
8d5b5f88d8eadc8a245d335ea76ceabed4e7564069bbd4bb35c60d58f49b2ff8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.1-cp39-cp39-macosx_11_0_x86_64.whl
| Download URL | secrethider-0.1.1-cp39-cp39-macosx_11_0_x86_64.whl |
|---|---|
| Size | 537.5 kB |
| Tags | CPython 3.9 macOS 11.0+ x86-64 |
|
SHA-256 checksum How to use checksums |
ecb6499b4cc9fc54890ed9f6455d09f97f07020c559131763a6df4d2b8d5928a
|
|
BLAKE2b-256 checksum How to use checksums |
5484b44a0608e0ebf15798f7fda7c5a1c71fea4f6c8ae768ee3bccc8fc65bd3e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.1-cp39-cp39-macosx_11_0_arm64.whl
| Download URL | secrethider-0.1.1-cp39-cp39-macosx_11_0_arm64.whl |
|---|---|
| Size | 391.2 kB |
| Tags | CPython 3.9 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
cfd5b08101d483f96f2af909f489832a66d9f4e3a7887d16d57a22745dff5d55
|
|
BLAKE2b-256 checksum How to use checksums |
2be63ce8b95da439168618f3d5aa9902d0d6752a10ef05b78f21ffb8e917ee8c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|