Skip to main content

secretHider

Fast secret redaction, log processing, string and JSON tools: one C++20 core, thin bindings for Python and Node.js.

  • Remove secrets from logs in plain text, logfmt and JSON lines: AWS/GitHub/Slack/Stripe/Google keys, JWTs, PEM private keys, Bearer tokens, URL credentials, password=... fields, and optional PII (email, phone, card, SSN, IBAN, IPv4).
  • Tell it what is secret with plain lists: known values, field names and formats (or one secrets.txt file), on top of the built-in patterns.
  • Choose what happens: delete the whole field (drop_field), mask (full, typed, keep first/last N, preserve length, partial email/phone), stable salted hash, realistic fake data via Faker (Python faker, JS @faker-js/faker), or your own function. Partial masks never reveal more than 25% of a secret.
  • Stream it: chunk-safe redaction for files, pipes and sockets (output equals one-shot output at every split point), a secrethider-redact command line, and in-place/.gz file helpers.
  • Fast: about 600 MiB/s per core on clean logs, roughly 38x a hand-written Python re pipeline and comparable to V8's RegExp for a few simple patterns in Node (numbers). Built on simdjson, simdutf, RE2.
  • Also: json_get (JSON Pointer), json_minify, json_valid, UTF-8 helpers.
secrethider-redact --in-place --drop-fields --secrets-file secrets.txt app.log   # a=1 password=x b=2  ->  a=1 b=2
secrethider-redact --pii --mask fake app.jsonl --json-lines                       # fake emails/phones instead of [REDACTED]
import secrethider
from secrethider import Mask, RedactorBuilder

r = (RedactorBuilder()
     .enable("pii")
     .secret_values(["my-known-secret"])       # also: secret_keys([...]), secret_formats([...])
     .mask(Mask.keep_prefix(4))                # or Mask.drop_field(), secrethider.fake_mask(), ...
     .build())

r.redact("login password=hunter2hunter2hunter2 key=AKIAIOSFODNN7EXAMPLE")
# 'login password=hunt**** key=AKIA****'
# (short secrets fall back to a full mask: 4 revealed characters of a 10-character password would exceed 25%)

# logging, files, streams
from secrethider.logging import RedactingFormatter
handler.setFormatter(RedactingFormatter(r, "%(levelname)s %(message)s"))
secrethider.redact_file(open("in.log"), open("out.log", "w"), r)
const fk = require('@noobforal/secrethider');
const r = new fk.RedactorBuilder().mask(fk.Mask.keepPrefix(4)).build();
process.stdin.pipe(fk.createRedactStream(r)).pipe(process.stdout);

Install

pip install secrethider            # Python 3.9+; add `faker` for realistic fake-data masks
npm install @noobforal/secrethider # Node.js 18+ (prebuilt binaries for Linux/macOS/Windows x64 and macOS arm64)

The npm package is scoped because npm rejects the unscoped name secrethider as too similar to an existing package.

Layout

core/              C++20 library (no Python/Node headers), tests, benchmarks
bindings/python/   nanobind module + `secrethider` package (built via scikit-build-core, root pyproject.toml)
bindings/node/     Node-API addon (node-addon-api + cmake-js)
cmake/             shared CMake modules (dependencies, warnings)
docs/              architecture: interfaces, log processing, rules and masking, builds, performance, security

Documentation

Start with the guide to removing secrets from logs, or docs/README.md for everything: interfaces, log processing pipeline, rules and masking, build and platforms, performance, security model.

Develop

make fix     # format + auto-fix lint: C++ (clang-format), Python (ruff), JS/TS (prettier)
make test    # build, run all tests (C++, Python, Node), then the benchmarks
make help    # everything else: lint, check (tests only), bench, bench-full, qa (leak checks + long fuzz), clean

make finds Visual Studio's C++ tools on Windows by itself. Without make, the underlying steps are:

# C++ core: tests + benchmarks (Windows: use the dev-msvc preset from a VS developer prompt)
cmake --preset dev && cmake --build --preset dev && ctest --preset dev
./build/dev/core/secrethider_bench                  # secrethider_bench.exe on Windows

# Python
python -m venv .venv && . .venv/bin/activate    # Windows: .venv\Scripts\activate
pip install . pytest faker && pytest

# Node
cd bindings/node && npm install && npm run build && npm test

-DSECRETHIDER_WITH_RE2=OFF skips RE2/abseil for a much faster build; custom regex() rules are then unavailable.

Cross-platform builds

  • Python wheels: cibuildwheel (Linux manylinux/musllinux, macOS x86_64 + arm64, Windows), stable-ABI (abi3) wheels, via .github/workflows/release.yml.
  • Node: Node-API is ABI-stable, so one binary per OS/arch; CI collects prebuilds/<platform>-<arch>/secrethider.node.
  • SIMD is selected at run time by simdjson/simdutf, so no -march=native and one binary runs fast everywhere.

Limits

Redaction is defence in depth, not a guarantee: it finds known formats, sensitive key names and values you register. See the security model.

License

MIT, see LICENSE.

Metadata

Release files for secrethider 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for secrethider 0.1.1
File Size Uploaded
secrethider-0.1.1.tar.gz 101.6 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for secrethider 0.1.1
File
secrethider-0.1.1-cp312-abi3-win_amd64.whl CPython 3.12 abi3 Windows x86-64 Details
secrethider-0.1.1-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl CPython 3.12 abi3 Linux glibc 2.17+ x86-64 Details
secrethider-0.1.1-cp312-abi3-macosx_11_0_x86_64.whl CPython 3.12 abi3 macOS 11.0+ x86-64 Details
secrethider-0.1.1-cp312-abi3-macosx_11_0_arm64.whl CPython 3.12 abi3 macOS 11.0+ ARM64 Details
secrethider-0.1.1-cp311-cp311-win_amd64.whl CPython 3.11 CPython 3.11 Windows x86-64 Details
secrethider-0.1.1-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl CPython 3.11 CPython 3.11 Linux glibc 2.17+ x86-64 Details
secrethider-0.1.1-cp311-cp311-macosx_11_0_x86_64.whl CPython 3.11 CPython 3.11 macOS 11.0+ x86-64 Details
secrethider-0.1.1-cp311-cp311-macosx_11_0_arm64.whl CPython 3.11 CPython 3.11 macOS 11.0+ ARM64 Details
secrethider-0.1.1-cp310-cp310-win_amd64.whl CPython 3.10 CPython 3.10 Windows x86-64 Details
secrethider-0.1.1-cp310-cp310-manylinux_2_17_x86_64.manylinux2014_x86_64.whl CPython 3.10 CPython 3.10 Linux glibc 2.17+ x86-64 Details
secrethider-0.1.1-cp310-cp310-macosx_11_0_x86_64.whl CPython 3.10 CPython 3.10 macOS 11.0+ x86-64 Details
secrethider-0.1.1-cp310-cp310-macosx_11_0_arm64.whl CPython 3.10 CPython 3.10 macOS 11.0+ ARM64 Details
secrethider-0.1.1-cp39-cp39-win_amd64.whl CPython 3.9 CPython 3.9 Windows x86-64 Details
secrethider-0.1.1-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl CPython 3.9 CPython 3.9 Linux glibc 2.17+ x86-64 Details
secrethider-0.1.1-cp39-cp39-macosx_11_0_x86_64.whl CPython 3.9 CPython 3.9 macOS 11.0+ x86-64 Details
secrethider-0.1.1-cp39-cp39-macosx_11_0_arm64.whl CPython 3.9 CPython 3.9 macOS 11.0+ ARM64 Details

Total release size: 9.2 MB

Release files / secrethider-0.1.1.tar.gz

Download URL secrethider-0.1.1.tar.gz
Size 101.6 kB
Tags Source
SHA-256 checksum
How to use checksums
9fc6fde6d6a8fbbbf30498514b0dece78aa6aaf9433635b0657daf7c5d92fad9
BLAKE2b-256 checksum
How to use checksums
eefe4e335c94495476d0bee81e6b840ba719c279ed961d1c08bcb1879a4e7374
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.1-cp312-abi3-win_amd64.whl

Download URL secrethider-0.1.1-cp312-abi3-win_amd64.whl
Size 520.6 kB
Tags CPython 3.12 Windows x86-64 abi3
SHA-256 checksum
How to use checksums
738bf0686b2175bed6b1e33d432b34fc5e722d4ae97b2893051b35aa0d4a4531
BLAKE2b-256 checksum
How to use checksums
ba7b5e589009f08531c1c0215978060bcba95dff257fb0a0a9ff7fe33224c6df
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.1-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL secrethider-0.1.1-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 834.3 kB
Tags CPython 3.12 Linux glibc 2.17+ x86-64 abi3
SHA-256 checksum
How to use checksums
64db408f9cfee13673412d99d9af7e814acb772a7863ca1b6b642e4f2aae73f6
BLAKE2b-256 checksum
How to use checksums
372d43ff59cdc3bd5c11febb7dfeea554eb4979ad7a8e4b4f232909de7d78323
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.1-cp312-abi3-macosx_11_0_x86_64.whl

Download URL secrethider-0.1.1-cp312-abi3-macosx_11_0_x86_64.whl
Size 547.2 kB
Tags CPython 3.12 abi3 macOS 11.0+ x86-64
SHA-256 checksum
How to use checksums
dcbb224bb25d90ba5391a175bfa13e174d6222ade4e6ea65f5fe6867adbddbce
BLAKE2b-256 checksum
How to use checksums
c9fbce2017fc5333e9274afd28637ab99b84775a31b614989fda9ef1e3721ffa
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.1-cp312-abi3-macosx_11_0_arm64.whl

Download URL secrethider-0.1.1-cp312-abi3-macosx_11_0_arm64.whl
Size 394.5 kB
Tags CPython 3.12 abi3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
25a15c577006120542f5e679850ab65d799d0529336930af44e7668a57a7d0ba
BLAKE2b-256 checksum
How to use checksums
22be31913c67dc87395283953cb3bc850b8e81948de3525cb5653bcc0767798a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.1-cp311-cp311-win_amd64.whl

Download URL secrethider-0.1.1-cp311-cp311-win_amd64.whl
Size 520.7 kB
Tags CPython 3.11 Windows x86-64
SHA-256 checksum
How to use checksums
43caceb191ff9f65727ec8b06f7198cd84d3d60308783987832ef21121b4f8ff
BLAKE2b-256 checksum
How to use checksums
b03c42e14676160b40f37710059664b896c51c73b029d675a8e0c6c8ef65045c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.1-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL secrethider-0.1.1-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 834.9 kB
Tags CPython 3.11 Linux glibc 2.17+ x86-64
SHA-256 checksum
How to use checksums
145032304185c9a9303691e00c2569a99a26676e91ba950901cc387673950c03
BLAKE2b-256 checksum
How to use checksums
38951d1cbf299b41ff818adf9ebf70f95143876bb8f79f35c2f9676579e23db8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.1-cp311-cp311-macosx_11_0_x86_64.whl

Download URL secrethider-0.1.1-cp311-cp311-macosx_11_0_x86_64.whl
Size 547.5 kB
Tags CPython 3.11 macOS 11.0+ x86-64
SHA-256 checksum
How to use checksums
f0e409368fafadbe748673bff51c412e62fc256537c13454c8564b5c11a46ec8
BLAKE2b-256 checksum
How to use checksums
5da746bd19f4d116b731f48c8c711cfdfb83e95097e7fd4f27592e161baf7d5a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.1-cp311-cp311-macosx_11_0_arm64.whl

Download URL secrethider-0.1.1-cp311-cp311-macosx_11_0_arm64.whl
Size 395.0 kB
Tags CPython 3.11 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
1d176487dec6fbf1192aa12c258d50c8e8b284527c15c434bb077910303dce46
BLAKE2b-256 checksum
How to use checksums
51d4c70d783b2e9f8e2e7c5a891909ff685f5584115d5b97f02cb697299972f4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.1-cp310-cp310-win_amd64.whl

Download URL secrethider-0.1.1-cp310-cp310-win_amd64.whl
Size 520.3 kB
Tags CPython 3.10 Windows x86-64
SHA-256 checksum
How to use checksums
1503427faf956d1c1a440c4f658dd6d4dcc137a5a7c79bfbe28c309f2ddb1c5a
BLAKE2b-256 checksum
How to use checksums
2aa8be4c36102df0ac42dfb44fef96aeea36e7bec2121f7a509ccf9d1f62e33f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.1-cp310-cp310-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL secrethider-0.1.1-cp310-cp310-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 835.1 kB
Tags CPython 3.10 Linux glibc 2.17+ x86-64
SHA-256 checksum
How to use checksums
b18f185597e1d0166c64ec121f50de6e26ae99cbc8e831913c5e83728d854910
BLAKE2b-256 checksum
How to use checksums
3f537f7968b5aea474db7d528be4812ce63812f630963006638d07db800e4618
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.1-cp310-cp310-macosx_11_0_x86_64.whl

Download URL secrethider-0.1.1-cp310-cp310-macosx_11_0_x86_64.whl
Size 547.7 kB
Tags CPython 3.10 macOS 11.0+ x86-64
SHA-256 checksum
How to use checksums
5ba4ca6a771e957d5bac5ea704eb192c8943f76ca572d12dd76738a9681b5dc1
BLAKE2b-256 checksum
How to use checksums
aac89bdec555d154bcce57e712b3f9913e8f815c377d2e654cf8eccdb3c29162
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.1-cp310-cp310-macosx_11_0_arm64.whl

Download URL secrethider-0.1.1-cp310-cp310-macosx_11_0_arm64.whl
Size 395.6 kB
Tags CPython 3.10 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
3ab795301e07978109d0b1638640de44bb8f2859cabea7b8908e86f9b65770e7
BLAKE2b-256 checksum
How to use checksums
762b09183b579d7e7082aafe2753e8a517d237a3b90199a6d1df3d431eb5faaf
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.1-cp39-cp39-win_amd64.whl

Download URL secrethider-0.1.1-cp39-cp39-win_amd64.whl
Size 494.6 kB
Tags CPython 3.9 Windows x86-64
SHA-256 checksum
How to use checksums
e50952e540e6b6640d5faa5af072a651125ce3ca6b703885aa961dca574d1afe
BLAKE2b-256 checksum
How to use checksums
90f40f5e403a431c357bbf11ca944c6fd9b00d72efa41bd4bf912283d8a43d09
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.1-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL secrethider-0.1.1-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 829.3 kB
Tags CPython 3.9 Linux glibc 2.17+ x86-64
SHA-256 checksum
How to use checksums
8ebf67c0eab547ff360ce7d6548ef2c7ff2b38af1b1d3323c2d9d880cb7b87ac
BLAKE2b-256 checksum
How to use checksums
8d5b5f88d8eadc8a245d335ea76ceabed4e7564069bbd4bb35c60d58f49b2ff8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.1-cp39-cp39-macosx_11_0_x86_64.whl

Download URL secrethider-0.1.1-cp39-cp39-macosx_11_0_x86_64.whl
Size 537.5 kB
Tags CPython 3.9 macOS 11.0+ x86-64
SHA-256 checksum
How to use checksums
ecb6499b4cc9fc54890ed9f6455d09f97f07020c559131763a6df4d2b8d5928a
BLAKE2b-256 checksum
How to use checksums
5484b44a0608e0ebf15798f7fda7c5a1c71fea4f6c8ae768ee3bccc8fc65bd3e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.1-cp39-cp39-macosx_11_0_arm64.whl

Download URL secrethider-0.1.1-cp39-cp39-macosx_11_0_arm64.whl
Size 391.2 kB
Tags CPython 3.9 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
cfd5b08101d483f96f2af909f489832a66d9f4e3a7887d16d57a22745dff5d55
BLAKE2b-256 checksum
How to use checksums
2be63ce8b95da439168618f3d5aa9902d0d6752a10ef05b78f21ffb8e917ee8c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release history Release notifications | RSS feed

0.2.0

8 release files

This release

0.1.1 This release

17 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page