secretHider
Fast secret redaction, log processing, string and JSON tools: one C++20 core, thin bindings for Python and Node.js.
- Remove secrets from logs in plain text, logfmt and JSON lines: AWS/GitHub/Slack/Stripe/Google keys, JWTs, PEM private keys,
Bearertokens, URL credentials,password=...fields, and optional PII (email, phone, card, SSN, IBAN, IPv4). - Tell it what is secret with plain lists: known values, field names and formats (or one
secrets.txtfile), on top of the built-in patterns. - Choose what happens: delete the whole field (
drop_field), mask (full, typed, keep first/last N, preserve length, partial email/phone), stable salted hash, realistic fake data via Faker (Pythonfaker, JS@faker-js/faker), or your own function. Partial masks never reveal more than 25% of a secret. - Stream it: chunk-safe redaction for files, pipes and sockets (output equals one-shot output at every split point), a
secrethider-redactcommand line, and in-place/.gzfile helpers. - Fast: about 600 MiB/s per core on clean logs, roughly 38x a hand-written Python
repipeline and comparable to V8's RegExp for a few simple patterns in Node (numbers). Built on simdjson, simdutf, RE2. - Also:
json_get(JSON Pointer),json_minify,json_valid, UTF-8 helpers.
secrethider-redact --in-place --drop-fields --secrets-file secrets.txt app.log # a=1 password=x b=2 -> a=1 b=2
secrethider-redact --pii --mask fake app.jsonl --json-lines # fake emails/phones instead of [REDACTED]
import secrethider
from secrethider import Mask, RedactorBuilder
r = (RedactorBuilder()
.enable("pii")
.secret_values(["my-known-secret"]) # also: secret_keys([...]), secret_formats([...])
.mask(Mask.keep_prefix(4)) # or Mask.drop_field(), secrethider.fake_mask(), ...
.build())
r.redact("login password=hunter2hunter2hunter2 key=AKIAIOSFODNN7EXAMPLE")
# 'login password=hunt**** key=AKIA****'
# (short secrets fall back to a full mask: 4 revealed characters of a 10-character password would exceed 25%)
# logging, files, streams
from secrethider.logging import RedactingFormatter
handler.setFormatter(RedactingFormatter(r, "%(levelname)s %(message)s"))
secrethider.redact_file(open("in.log"), open("out.log", "w"), r)
const fk = require('@noobforal/secrethider');
const r = new fk.RedactorBuilder().mask(fk.Mask.keepPrefix(4)).build();
process.stdin.pipe(fk.createRedactStream(r)).pipe(process.stdout);
Install
pip install secrethider # Python 3.9+; add `faker` for realistic fake-data masks
npm install @noobforal/secrethider # Node.js 18+ (prebuilt binaries for Linux/macOS/Windows x64 and macOS arm64)
The npm package is scoped because npm rejects the unscoped name secrethider as too similar to an existing package.
Layout
core/ C++20 library (no Python/Node headers), tests, benchmarks
bindings/python/ nanobind module + `secrethider` package (built via scikit-build-core, root pyproject.toml)
bindings/node/ Node-API addon (node-addon-api + cmake-js)
cmake/ shared CMake modules (dependencies, warnings)
docs/ architecture: interfaces, log processing, rules and masking, builds, performance, security
Documentation
Start with the guide to removing secrets from logs, or docs/README.md for everything: interfaces, log processing pipeline, rules and masking, build and platforms, performance, security model.
Develop
make fix # format + auto-fix lint: C++ (clang-format), Python (ruff), JS/TS (prettier)
make test # build, run all tests (C++, Python, Node), then the benchmarks
make verify # the full local gate before a push or release: lint, version check, all tests, abi3 wheel on Python 3.12/3.13/3.14
make docker # build and test on Linux in a container (clean clone of HEAD): C++, Python, Node, abi3
make help # everything else: lint, check (tests only), bench, bench-full, qa (leak checks + long fuzz), clean
git config core.hooksPath .githooks makes git push run make verify first (bypass once with SKIP_VERIFY=1 git push).
make finds Visual Studio's C++ tools on Windows by itself. Without make, the underlying steps are:
# C++ core: tests + benchmarks (Windows: use the dev-msvc preset from a VS developer prompt)
cmake --preset dev && cmake --build --preset dev && ctest --preset dev
./build/dev/core/secrethider_bench # secrethider_bench.exe on Windows
# Python
python -m venv .venv && . .venv/bin/activate # Windows: .venv\Scripts\activate
pip install . pytest faker && pytest
# Node
cd bindings/node && npm install && npm run build && npm test
-DSECRETHIDER_WITH_RE2=OFF skips RE2/abseil for a much faster build; custom regex() rules are then unavailable.
Cross-platform builds
- Python wheels:
cibuildwheel(Linux manylinux/musllinux, macOS x86_64 + arm64, Windows), stable-ABI (abi3) wheels, via.github/workflows/release.yml. - Node: Node-API is ABI-stable, so one binary per OS/arch; CI collects
prebuilds/<platform>-<arch>/secrethider.node. - SIMD is selected at run time by simdjson/simdutf, so no
-march=nativeand one binary runs fast everywhere.
Limits
Redaction is defence in depth, not a guarantee: it finds known formats, sensitive key names and values you register. See the security model.
License
MIT, see LICENSE.
Metadata
Release files for secrethider 0.1.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| secrethider-0.1.2.tar.gz | 106.5 kB | Details |
Built distributions (wheels)
Total release size: 9.3 MB
Release files / secrethider-0.1.2.tar.gz
| Download URL | secrethider-0.1.2.tar.gz |
|---|---|
| Size | 106.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
e9c7a7d8dfb3d6d0e461bd03948052c81a0f3a82ecf18074658360be5a0b7f9b
|
|
BLAKE2b-256 checksum How to use checksums |
7b3d7c97f7298d1787f26bc5963230e8ffaecc7461d70f0f7f369ae5df8fd04d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.2-cp312-abi3-win_amd64.whl
| Download URL | secrethider-0.1.2-cp312-abi3-win_amd64.whl |
|---|---|
| Size | 520.8 kB |
| Tags | CPython 3.12 Windows x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
62de8a29cb69648de0b0c8353fba8bc158a2c3401a54401bc61e21e94749cf89
|
|
BLAKE2b-256 checksum How to use checksums |
a59f71e5dd9b477260228d3ab4e676e328ca7852e25d38dad558286317321104
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.2-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | secrethider-0.1.2-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 831.9 kB |
| Tags | CPython 3.12 Linux glibc 2.17+ x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
ff5941d70cc78537db80b9daed0ba6f321f30b2094c3ec3ae1fe3679b73d3e1e
|
|
BLAKE2b-256 checksum How to use checksums |
01f98fa62334779e19d99a3a51d4ea2caa1b7fc4c6da826ca9df715e38d7dea6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.2-cp312-abi3-macosx_11_0_x86_64.whl
| Download URL | secrethider-0.1.2-cp312-abi3-macosx_11_0_x86_64.whl |
|---|---|
| Size | 548.7 kB |
| Tags | CPython 3.12 abi3 macOS 11.0+ x86-64 |
|
SHA-256 checksum How to use checksums |
caa4f0b84a8ea00645f562859979d91ee402ef02f40b63fbb0ec030b66a37712
|
|
BLAKE2b-256 checksum How to use checksums |
b2b6beddacb6718ff4a23676a2a73541078270945a141b83ba6c24cf7f14d635
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.2-cp312-abi3-macosx_11_0_arm64.whl
| Download URL | secrethider-0.1.2-cp312-abi3-macosx_11_0_arm64.whl |
|---|---|
| Size | 393.6 kB |
| Tags | CPython 3.12 abi3 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
3608113ef1aa08313ccdf6bc51ed5a42e663353e4c18f58613057c58846eac7d
|
|
BLAKE2b-256 checksum How to use checksums |
38cae4ffdf358201f6f4706a0973be51dbb8b97e652ae081de0de66dc9956319
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.2-cp311-cp311-win_amd64.whl
| Download URL | secrethider-0.1.2-cp311-cp311-win_amd64.whl |
|---|---|
| Size | 520.9 kB |
| Tags | CPython 3.11 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
4b4fb53feb3ea0445fb05172c0478fa04153800653afc8b78e1531139bc9d6b0
|
|
BLAKE2b-256 checksum How to use checksums |
7a5fc1d5c2d5ec770fd483e2536f3e4eb2e7c369d8fa665990ad8f36fa844505
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.2-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | secrethider-0.1.2-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 835.1 kB |
| Tags | CPython 3.11 Linux glibc 2.17+ x86-64 |
|
SHA-256 checksum How to use checksums |
8c9452ae2731779337703453192d4b134a5ca938a0b1ea1bc522490903c17d5e
|
|
BLAKE2b-256 checksum How to use checksums |
5e578ffecb9597472f5df1f3128e58819e9624cf64c9bf60c074e22fb199337c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.2-cp311-cp311-macosx_11_0_x86_64.whl
| Download URL | secrethider-0.1.2-cp311-cp311-macosx_11_0_x86_64.whl |
|---|---|
| Size | 547.6 kB |
| Tags | CPython 3.11 macOS 11.0+ x86-64 |
|
SHA-256 checksum How to use checksums |
7985fb46589d26f02d62cc28ced34039bf4361f59f5a80c66d98343cfbc6a868
|
|
BLAKE2b-256 checksum How to use checksums |
37cc62cfc6581734bffdd7184a0b5ad8bbfab685358b08d1d9dda7f0c42ce321
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.2-cp311-cp311-macosx_11_0_arm64.whl
| Download URL | secrethider-0.1.2-cp311-cp311-macosx_11_0_arm64.whl |
|---|---|
| Size | 395.2 kB |
| Tags | CPython 3.11 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
08e0f7f168343f2788afd0a98f53030b9f4b1e80591a275324b11456427d270d
|
|
BLAKE2b-256 checksum How to use checksums |
76238d5a894cb8e92cf118b40fbf1e1e3e10372eeb57d7833701196ef620a42e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.2-cp310-cp310-win_amd64.whl
| Download URL | secrethider-0.1.2-cp310-cp310-win_amd64.whl |
|---|---|
| Size | 520.5 kB |
| Tags | CPython 3.10 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
2b6d5a4544329e1d61ce60be501e405e96c814763d495fd5fab94c7d9bf7e792
|
|
BLAKE2b-256 checksum How to use checksums |
14da9902f96eee550791f6d6cf2853b8fb52713752cad9ae5df5af1b46aac108
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.2-cp310-cp310-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | secrethider-0.1.2-cp310-cp310-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 835.2 kB |
| Tags | CPython 3.10 Linux glibc 2.17+ x86-64 |
|
SHA-256 checksum How to use checksums |
20f50ad0fe6ece28eb0093964fe467ca7b985b267b7601f514291b280aee188e
|
|
BLAKE2b-256 checksum How to use checksums |
999a41f829c9acce9a6878d8ecf91dc2ccb12d1055510e268af9d7d8389463f5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.2-cp310-cp310-macosx_11_0_x86_64.whl
| Download URL | secrethider-0.1.2-cp310-cp310-macosx_11_0_x86_64.whl |
|---|---|
| Size | 547.9 kB |
| Tags | CPython 3.10 macOS 11.0+ x86-64 |
|
SHA-256 checksum How to use checksums |
c6cdf97e306db720f8e0f3bc5e58bba833e9adb7b877c9cba93d56b052957760
|
|
BLAKE2b-256 checksum How to use checksums |
d6035a8a1807516594e122b67eee6ad407c0b663d68f4b225d90c06a3a1980b4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.2-cp310-cp310-macosx_11_0_arm64.whl
| Download URL | secrethider-0.1.2-cp310-cp310-macosx_11_0_arm64.whl |
|---|---|
| Size | 395.7 kB |
| Tags | CPython 3.10 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
6d95ff251a3def6605920123ec6189c3345c2b5c6a04b0e811e608815e8f38b8
|
|
BLAKE2b-256 checksum How to use checksums |
befd33a3da62dc76b004b56b4af4aeda6046c588fd62e3f0a8d4758da1a4a0bb
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.2-cp39-cp39-win_amd64.whl
| Download URL | secrethider-0.1.2-cp39-cp39-win_amd64.whl |
|---|---|
| Size | 494.8 kB |
| Tags | CPython 3.9 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
99663bed9769eed105bdd0f01886bdf8c3561ed833d2cbb2f65793bc700bc3ba
|
|
BLAKE2b-256 checksum How to use checksums |
27585876fa88a9a62b9e6756872c51809f4e3e58902d9b2f4fcd495c9eb69f92
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.2-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | secrethider-0.1.2-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 829.5 kB |
| Tags | CPython 3.9 Linux glibc 2.17+ x86-64 |
|
SHA-256 checksum How to use checksums |
032855fa2e59c1a514b486f3be43d98b46dae452aa985eaab07b3f1a658d95b0
|
|
BLAKE2b-256 checksum How to use checksums |
db4d02aba6b3c0564407465310bdf3d10ae30efd9897f0131854556072fb456c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.2-cp39-cp39-macosx_11_0_x86_64.whl
| Download URL | secrethider-0.1.2-cp39-cp39-macosx_11_0_x86_64.whl |
|---|---|
| Size | 537.7 kB |
| Tags | CPython 3.9 macOS 11.0+ x86-64 |
|
SHA-256 checksum How to use checksums |
584b121fea08e51e757f229ef112f6116aed460afe3b6326b073480b651bc6b9
|
|
BLAKE2b-256 checksum How to use checksums |
927d5bd5995e2a47145caa3d3c59fe4b51027a28fa53a605aaac92cf52e5621c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.1.2-cp39-cp39-macosx_11_0_arm64.whl
| Download URL | secrethider-0.1.2-cp39-cp39-macosx_11_0_arm64.whl |
|---|---|
| Size | 391.4 kB |
| Tags | CPython 3.9 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
47d739111e2ab54fd3328455ae4ebe1e34dcfc7263f04c861c1656ec534739cf
|
|
BLAKE2b-256 checksum How to use checksums |
ec6c5430878c12fbd3a99ed0910dfd2487e2b4ff6ff75b8380282ba93de130c4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|