Skip to main content

secretHider

Fast secret redaction, log processing, string and JSON tools: one C++20 core, thin bindings for Python and Node.js.

  • Remove secrets from logs in plain text, logfmt and JSON lines: AWS/GitHub/Slack/Stripe/Google keys, JWTs, PEM private keys, Bearer tokens, URL credentials, password=... fields, and optional PII (email, phone, card, SSN, IBAN, IPv4).
  • Tell it what is secret with plain lists: known values, field names and formats (or one secrets.txt file), on top of the built-in patterns.
  • Choose what happens: delete the whole field (drop_field), mask (full, typed, keep first/last N, preserve length, partial email/phone), stable salted hash, realistic fake data via Faker (Python faker, JS @faker-js/faker), or your own function. Partial masks never reveal more than 25% of a secret.
  • Stream it: chunk-safe redaction for files, pipes and sockets (output equals one-shot output at every split point), a secrethider-redact command line, and in-place/.gz file helpers.
  • Fast: about 600 MiB/s per core on clean logs, roughly 38x a hand-written Python re pipeline and comparable to V8's RegExp for a few simple patterns in Node (numbers). Built on simdjson, simdutf, RE2.
  • Also: json_get (JSON Pointer), json_minify, json_valid, UTF-8 helpers.
secrethider-redact --in-place --drop-fields --secrets-file secrets.txt app.log   # a=1 password=x b=2  ->  a=1 b=2
secrethider-redact --pii --mask fake app.jsonl --json-lines                       # fake emails/phones instead of [REDACTED]
import secrethider
from secrethider import Mask, RedactorBuilder

r = (RedactorBuilder()
     .enable("pii")
     .secret_values(["my-known-secret"])       # also: secret_keys([...]), secret_formats([...])
     .mask(Mask.keep_prefix(4))                # or Mask.drop_field(), secrethider.fake_mask(), ...
     .build())

r.redact("login password=hunter2hunter2hunter2 key=AKIAIOSFODNN7EXAMPLE")
# 'login password=hunt**** key=AKIA****'
# (short secrets fall back to a full mask: 4 revealed characters of a 10-character password would exceed 25%)

# logging, files, streams
from secrethider.logging import RedactingFormatter
handler.setFormatter(RedactingFormatter(r, "%(levelname)s %(message)s"))
secrethider.redact_file(open("in.log"), open("out.log", "w"), r)
const fk = require('@noobforal/secrethider');
const r = new fk.RedactorBuilder().mask(fk.Mask.keepPrefix(4)).build();
process.stdin.pipe(fk.createRedactStream(r)).pipe(process.stdout);

Install

pip install secrethider            # Python 3.9+; add `faker` for realistic fake-data masks
npm install @noobforal/secrethider # Node.js 18+ (prebuilt binaries for Linux/macOS/Windows x64 and macOS arm64)

The npm package is scoped because npm rejects the unscoped name secrethider as too similar to an existing package.

Layout

core/              C++20 library (no Python/Node headers), tests, benchmarks
bindings/python/   nanobind module + `secrethider` package (built via scikit-build-core, root pyproject.toml)
bindings/node/     Node-API addon (node-addon-api + cmake-js)
cmake/             shared CMake modules (dependencies, warnings)
docs/              architecture: interfaces, log processing, rules and masking, builds, performance, security

Documentation

Start with the guide to removing secrets from logs, or docs/README.md for everything: interfaces, log processing pipeline, rules and masking, build and platforms, performance, security model.

Develop

make fix     # format + auto-fix lint: C++ (clang-format), Python (ruff), JS/TS (prettier)
make test    # build, run all tests (C++, Python, Node), then the benchmarks
make verify  # the full local gate before a push or release: lint, version check, all tests, abi3 wheel on Python 3.12/3.13/3.14
make docker  # build and test on Linux in a container (clean clone of HEAD): C++, Python, Node, abi3
make help    # everything else: lint, check (tests only), bench, bench-full, qa (leak checks + long fuzz), clean

git config core.hooksPath .githooks makes git push run make verify first (bypass once with SKIP_VERIFY=1 git push).

make finds Visual Studio's C++ tools on Windows by itself. Without make, the underlying steps are:

# C++ core: tests + benchmarks (Windows: use the dev-msvc preset from a VS developer prompt)
cmake --preset dev && cmake --build --preset dev && ctest --preset dev
./build/dev/core/secrethider_bench                  # secrethider_bench.exe on Windows

# Python
python -m venv .venv && . .venv/bin/activate    # Windows: .venv\Scripts\activate
pip install . pytest faker && pytest

# Node
cd bindings/node && npm install && npm run build && npm test

-DSECRETHIDER_WITH_RE2=OFF skips RE2/abseil for a much faster build; custom regex() rules are then unavailable.

Cross-platform builds

  • Python wheels: cibuildwheel (Linux manylinux/musllinux, macOS x86_64 + arm64, Windows), stable-ABI (abi3) wheels, via .github/workflows/release.yml.
  • Node: Node-API is ABI-stable, so one binary per OS/arch; CI collects prebuilds/<platform>-<arch>/secrethider.node.
  • SIMD is selected at run time by simdjson/simdutf, so no -march=native and one binary runs fast everywhere.

Limits

Redaction is defence in depth, not a guarantee: it finds known formats, sensitive key names and values you register. See the security model.

License

MIT, see LICENSE.

Metadata

Release files for secrethider 0.1.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for secrethider 0.1.2
File Size Uploaded
secrethider-0.1.2.tar.gz 106.5 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for secrethider 0.1.2
File
secrethider-0.1.2-cp312-abi3-win_amd64.whl CPython 3.12 abi3 Windows x86-64 Details
secrethider-0.1.2-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl CPython 3.12 abi3 Linux glibc 2.17+ x86-64 Details
secrethider-0.1.2-cp312-abi3-macosx_11_0_x86_64.whl CPython 3.12 abi3 macOS 11.0+ x86-64 Details
secrethider-0.1.2-cp312-abi3-macosx_11_0_arm64.whl CPython 3.12 abi3 macOS 11.0+ ARM64 Details
secrethider-0.1.2-cp311-cp311-win_amd64.whl CPython 3.11 CPython 3.11 Windows x86-64 Details
secrethider-0.1.2-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl CPython 3.11 CPython 3.11 Linux glibc 2.17+ x86-64 Details
secrethider-0.1.2-cp311-cp311-macosx_11_0_x86_64.whl CPython 3.11 CPython 3.11 macOS 11.0+ x86-64 Details
secrethider-0.1.2-cp311-cp311-macosx_11_0_arm64.whl CPython 3.11 CPython 3.11 macOS 11.0+ ARM64 Details
secrethider-0.1.2-cp310-cp310-win_amd64.whl CPython 3.10 CPython 3.10 Windows x86-64 Details
secrethider-0.1.2-cp310-cp310-manylinux_2_17_x86_64.manylinux2014_x86_64.whl CPython 3.10 CPython 3.10 Linux glibc 2.17+ x86-64 Details
secrethider-0.1.2-cp310-cp310-macosx_11_0_x86_64.whl CPython 3.10 CPython 3.10 macOS 11.0+ x86-64 Details
secrethider-0.1.2-cp310-cp310-macosx_11_0_arm64.whl CPython 3.10 CPython 3.10 macOS 11.0+ ARM64 Details
secrethider-0.1.2-cp39-cp39-win_amd64.whl CPython 3.9 CPython 3.9 Windows x86-64 Details
secrethider-0.1.2-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl CPython 3.9 CPython 3.9 Linux glibc 2.17+ x86-64 Details
secrethider-0.1.2-cp39-cp39-macosx_11_0_x86_64.whl CPython 3.9 CPython 3.9 macOS 11.0+ x86-64 Details
secrethider-0.1.2-cp39-cp39-macosx_11_0_arm64.whl CPython 3.9 CPython 3.9 macOS 11.0+ ARM64 Details

Total release size: 9.3 MB

Release files / secrethider-0.1.2.tar.gz

Download URL secrethider-0.1.2.tar.gz
Size 106.5 kB
Tags Source
SHA-256 checksum
How to use checksums
e9c7a7d8dfb3d6d0e461bd03948052c81a0f3a82ecf18074658360be5a0b7f9b
BLAKE2b-256 checksum
How to use checksums
7b3d7c97f7298d1787f26bc5963230e8ffaecc7461d70f0f7f369ae5df8fd04d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.2-cp312-abi3-win_amd64.whl

Download URL secrethider-0.1.2-cp312-abi3-win_amd64.whl
Size 520.8 kB
Tags CPython 3.12 Windows x86-64 abi3
SHA-256 checksum
How to use checksums
62de8a29cb69648de0b0c8353fba8bc158a2c3401a54401bc61e21e94749cf89
BLAKE2b-256 checksum
How to use checksums
a59f71e5dd9b477260228d3ab4e676e328ca7852e25d38dad558286317321104
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.2-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL secrethider-0.1.2-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 831.9 kB
Tags CPython 3.12 Linux glibc 2.17+ x86-64 abi3
SHA-256 checksum
How to use checksums
ff5941d70cc78537db80b9daed0ba6f321f30b2094c3ec3ae1fe3679b73d3e1e
BLAKE2b-256 checksum
How to use checksums
01f98fa62334779e19d99a3a51d4ea2caa1b7fc4c6da826ca9df715e38d7dea6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.2-cp312-abi3-macosx_11_0_x86_64.whl

Download URL secrethider-0.1.2-cp312-abi3-macosx_11_0_x86_64.whl
Size 548.7 kB
Tags CPython 3.12 abi3 macOS 11.0+ x86-64
SHA-256 checksum
How to use checksums
caa4f0b84a8ea00645f562859979d91ee402ef02f40b63fbb0ec030b66a37712
BLAKE2b-256 checksum
How to use checksums
b2b6beddacb6718ff4a23676a2a73541078270945a141b83ba6c24cf7f14d635
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.2-cp312-abi3-macosx_11_0_arm64.whl

Download URL secrethider-0.1.2-cp312-abi3-macosx_11_0_arm64.whl
Size 393.6 kB
Tags CPython 3.12 abi3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
3608113ef1aa08313ccdf6bc51ed5a42e663353e4c18f58613057c58846eac7d
BLAKE2b-256 checksum
How to use checksums
38cae4ffdf358201f6f4706a0973be51dbb8b97e652ae081de0de66dc9956319
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.2-cp311-cp311-win_amd64.whl

Download URL secrethider-0.1.2-cp311-cp311-win_amd64.whl
Size 520.9 kB
Tags CPython 3.11 Windows x86-64
SHA-256 checksum
How to use checksums
4b4fb53feb3ea0445fb05172c0478fa04153800653afc8b78e1531139bc9d6b0
BLAKE2b-256 checksum
How to use checksums
7a5fc1d5c2d5ec770fd483e2536f3e4eb2e7c369d8fa665990ad8f36fa844505
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.2-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL secrethider-0.1.2-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 835.1 kB
Tags CPython 3.11 Linux glibc 2.17+ x86-64
SHA-256 checksum
How to use checksums
8c9452ae2731779337703453192d4b134a5ca938a0b1ea1bc522490903c17d5e
BLAKE2b-256 checksum
How to use checksums
5e578ffecb9597472f5df1f3128e58819e9624cf64c9bf60c074e22fb199337c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.2-cp311-cp311-macosx_11_0_x86_64.whl

Download URL secrethider-0.1.2-cp311-cp311-macosx_11_0_x86_64.whl
Size 547.6 kB
Tags CPython 3.11 macOS 11.0+ x86-64
SHA-256 checksum
How to use checksums
7985fb46589d26f02d62cc28ced34039bf4361f59f5a80c66d98343cfbc6a868
BLAKE2b-256 checksum
How to use checksums
37cc62cfc6581734bffdd7184a0b5ad8bbfab685358b08d1d9dda7f0c42ce321
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.2-cp311-cp311-macosx_11_0_arm64.whl

Download URL secrethider-0.1.2-cp311-cp311-macosx_11_0_arm64.whl
Size 395.2 kB
Tags CPython 3.11 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
08e0f7f168343f2788afd0a98f53030b9f4b1e80591a275324b11456427d270d
BLAKE2b-256 checksum
How to use checksums
76238d5a894cb8e92cf118b40fbf1e1e3e10372eeb57d7833701196ef620a42e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.2-cp310-cp310-win_amd64.whl

Download URL secrethider-0.1.2-cp310-cp310-win_amd64.whl
Size 520.5 kB
Tags CPython 3.10 Windows x86-64
SHA-256 checksum
How to use checksums
2b6d5a4544329e1d61ce60be501e405e96c814763d495fd5fab94c7d9bf7e792
BLAKE2b-256 checksum
How to use checksums
14da9902f96eee550791f6d6cf2853b8fb52713752cad9ae5df5af1b46aac108
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.2-cp310-cp310-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL secrethider-0.1.2-cp310-cp310-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 835.2 kB
Tags CPython 3.10 Linux glibc 2.17+ x86-64
SHA-256 checksum
How to use checksums
20f50ad0fe6ece28eb0093964fe467ca7b985b267b7601f514291b280aee188e
BLAKE2b-256 checksum
How to use checksums
999a41f829c9acce9a6878d8ecf91dc2ccb12d1055510e268af9d7d8389463f5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.2-cp310-cp310-macosx_11_0_x86_64.whl

Download URL secrethider-0.1.2-cp310-cp310-macosx_11_0_x86_64.whl
Size 547.9 kB
Tags CPython 3.10 macOS 11.0+ x86-64
SHA-256 checksum
How to use checksums
c6cdf97e306db720f8e0f3bc5e58bba833e9adb7b877c9cba93d56b052957760
BLAKE2b-256 checksum
How to use checksums
d6035a8a1807516594e122b67eee6ad407c0b663d68f4b225d90c06a3a1980b4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.2-cp310-cp310-macosx_11_0_arm64.whl

Download URL secrethider-0.1.2-cp310-cp310-macosx_11_0_arm64.whl
Size 395.7 kB
Tags CPython 3.10 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
6d95ff251a3def6605920123ec6189c3345c2b5c6a04b0e811e608815e8f38b8
BLAKE2b-256 checksum
How to use checksums
befd33a3da62dc76b004b56b4af4aeda6046c588fd62e3f0a8d4758da1a4a0bb
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.2-cp39-cp39-win_amd64.whl

Download URL secrethider-0.1.2-cp39-cp39-win_amd64.whl
Size 494.8 kB
Tags CPython 3.9 Windows x86-64
SHA-256 checksum
How to use checksums
99663bed9769eed105bdd0f01886bdf8c3561ed833d2cbb2f65793bc700bc3ba
BLAKE2b-256 checksum
How to use checksums
27585876fa88a9a62b9e6756872c51809f4e3e58902d9b2f4fcd495c9eb69f92
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.2-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL secrethider-0.1.2-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 829.5 kB
Tags CPython 3.9 Linux glibc 2.17+ x86-64
SHA-256 checksum
How to use checksums
032855fa2e59c1a514b486f3be43d98b46dae452aa985eaab07b3f1a658d95b0
BLAKE2b-256 checksum
How to use checksums
db4d02aba6b3c0564407465310bdf3d10ae30efd9897f0131854556072fb456c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.2-cp39-cp39-macosx_11_0_x86_64.whl

Download URL secrethider-0.1.2-cp39-cp39-macosx_11_0_x86_64.whl
Size 537.7 kB
Tags CPython 3.9 macOS 11.0+ x86-64
SHA-256 checksum
How to use checksums
584b121fea08e51e757f229ef112f6116aed460afe3b6326b073480b651bc6b9
BLAKE2b-256 checksum
How to use checksums
927d5bd5995e2a47145caa3d3c59fe4b51027a28fa53a605aaac92cf52e5621c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / secrethider-0.1.2-cp39-cp39-macosx_11_0_arm64.whl

Download URL secrethider-0.1.2-cp39-cp39-macosx_11_0_arm64.whl
Size 391.4 kB
Tags CPython 3.9 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
47d739111e2ab54fd3328455ae4ebe1e34dcfc7263f04c861c1656ec534739cf
BLAKE2b-256 checksum
How to use checksums
ec6c5430878c12fbd3a99ed0910dfd2487e2b4ff6ff75b8380282ba93de130c4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release history Release notifications | RSS feed

0.2.0

8 release files

This release

0.1.2 This release

17 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page