secretHider
Fast secret redaction, log processing, string and JSON tools: one C++20 core, thin bindings for Python and Node.js.
- Remove secrets from logs in plain text, logfmt and JSON lines: AWS/GitHub/Slack/Stripe/Google keys, JWTs, PEM private keys,
Bearertokens, URL credentials,password=...fields, and optional PII (email, phone, card, SSN, IBAN, IPv4). - Tell it what is secret with plain lists: known values, field names and formats (or one
secrets.txtfile), on top of the built-in patterns. - Choose what happens: delete the whole field (
drop_field), mask (full, typed, keep first/last N, preserve length, partial email/phone), stable salted hash, realistic fake data via Faker (Pythonfaker, JS@faker-js/faker), or your own function. Partial masks never reveal more than 25% of a secret. - Stream it: chunk-safe redaction for files, pipes and sockets (output equals one-shot output at every split point), a
secrethider-redactcommand line, and in-place/.gzfile helpers. - Fast: about 600 MiB/s per core on clean logs, roughly 38x a hand-written Python
repipeline and comparable to V8's RegExp for a few simple patterns in Node (numbers). Built on simdjson, simdutf, RE2. - Also:
json_get(JSON Pointer),json_minify,json_valid, UTF-8 helpers.
secrethider-redact --in-place --drop-fields --secrets-file secrets.txt app.log # a=1 password=x b=2 -> a=1 b=2
secrethider-redact --pii --mask fake app.jsonl --json-lines # fake emails/phones instead of [REDACTED]
import secrethider
from secrethider import Mask, RedactorBuilder
r = (RedactorBuilder()
.enable("pii")
.secret_values(["my-known-secret"]) # also: secret_keys([...]), secret_formats([...])
.mask(Mask.keep_prefix(4)) # or Mask.drop_field(), secrethider.fake_mask(), ...
.build())
r.redact("login password=hunter2hunter2hunter2 key=AKIAIOSFODNN7EXAMPLE")
# 'login password=hunt**** key=AKIA****'
# (short secrets fall back to a full mask: 4 revealed characters of a 10-character password would exceed 25%)
# logging, files, streams
from secrethider.logging import RedactingFormatter
handler.setFormatter(RedactingFormatter(r, "%(levelname)s %(message)s"))
secrethider.redact_file(open("in.log"), open("out.log", "w"), r)
const fk = require('@noobforal/secrethider');
const r = new fk.RedactorBuilder().mask(fk.Mask.keepPrefix(4)).build();
process.stdin.pipe(fk.createRedactStream(r)).pipe(process.stdout);
Install
pip install secrethider # Python 3.12+; add `faker` for realistic fake-data masks
npm install @noobforal/secrethider # Node.js 22+
Prebuilt binaries, no compiler needed:
| Linux glibc (Debian 10+, Ubuntu 20.04+, RHEL 8+) | Linux musl (Alpine) | macOS | Windows | |
|---|---|---|---|---|
| x64 | yes | yes | yes | yes |
| arm64 | yes | yes | yes (Apple silicon) | not yet |
The npm package is scoped because npm rejects the unscoped name secrethider as too similar to an existing package.
Layout
core/ C++20 library (no Python/Node headers), tests, benchmarks
bindings/python/ nanobind module + `secrethider` package (built via scikit-build-core, root pyproject.toml)
bindings/node/ Node-API addon (node-addon-api + cmake-js)
cmake/ shared CMake modules (dependencies, warnings)
docs/ architecture: interfaces, log processing, rules and masking, builds, performance, security
Documentation
Start with the guide to removing secrets from logs, or docs/README.md for everything: interfaces, log processing pipeline, rules and masking, build and platforms, performance, security model.
Develop
make fix # format + auto-fix lint: C++ (clang-format), Python (ruff), JS/TS (prettier)
make test # build, run all tests (C++, Python, Node), then the benchmarks
make verify # the full local gate before a push or release: lint, version check, all tests, abi3 wheel on Python 3.12/3.13/3.14
make docker # build and test on Linux in a container (clean clone of HEAD): C++, Python, Node, abi3
make docker-node VARIANT=linux-x64 # build a Linux Node addon as the release does (glibc 2.28 / Alpine / arm64) and load it on Debian, Ubuntu, Alpine images
make published VERSION=x.y.z # after a release: install the published packages in clean Debian/Alpine containers and test them
make help # everything else: lint, check (tests only), bench, bench-full, qa (leak checks + long fuzz), clean
git config core.hooksPath .githooks makes git push run make verify first (bypass once with SKIP_VERIFY=1 git push).
make finds Visual Studio's C++ tools on Windows by itself. Without make, the underlying steps are:
# C++ core: tests + benchmarks (Windows: use the dev-msvc preset from a VS developer prompt)
cmake --preset dev && cmake --build --preset dev && ctest --preset dev
./build/dev/core/secrethider_bench # secrethider_bench.exe on Windows
# Python
python -m venv .venv && . .venv/bin/activate # Windows: .venv\Scripts\activate
pip install . pytest faker && pytest
# Node
cd bindings/node && npm install && npm run build && npm test
-DSECRETHIDER_WITH_RE2=OFF skips RE2/abseil for a much faster build; custom regex() rules are then unavailable.
Cross-platform builds
- Python wheels:
cibuildwheel(Linux manylinux and musllinux on x86_64 and aarch64, macOS x86_64 + arm64, Windows x64), one stable-ABI (abi3) wheel per platform for Python 3.12+, via.github/workflows/release.yml. - Node: Node-API is ABI-stable, so one binary per OS/arch (and per libc on Linux); CI builds Linux binaries in
manylinux_2_28and Alpine containers and collectsprebuilds/<platform>-<arch>[-musl]/secrethider.node. - SIMD is selected at run time by simdjson/simdutf, so no
-march=nativeand one binary runs fast everywhere.
Limits
Redaction is defence in depth, not a guarantee: it finds known formats, sensitive key names and values you register. See the security model.
License
MIT, see LICENSE.
Metadata
Release files for secrethider 0.2.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| secrethider-0.2.0.tar.gz | 113.2 kB | Details |
Built distributions (wheels)
| File | Reset | |||
|---|---|---|---|---|
| secrethider-0.2.0-cp312-abi3-win_amd64.whl | CPython 3.12 | abi3 | Windows x86-64 | Details |
| secrethider-0.2.0-cp312-abi3-musllinux_1_2_x86_64.whl | CPython 3.12 | abi3 | Linux musl 1.2+ x86-64 | Details |
| secrethider-0.2.0-cp312-abi3-musllinux_1_2_aarch64.whl | CPython 3.12 | abi3 | Linux musl 1.2+ ARM64 | Details |
| secrethider-0.2.0-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | CPython 3.12 | abi3 | Linux glibc 2.17+ x86-64 | Details |
| secrethider-0.2.0-cp312-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl | CPython 3.12 | abi3 | Linux glibc 2.17+ ARM64 | Details |
| secrethider-0.2.0-cp312-abi3-macosx_11_0_x86_64.whl | CPython 3.12 | abi3 | macOS 11.0+ x86-64 | Details |
| secrethider-0.2.0-cp312-abi3-macosx_11_0_arm64.whl | CPython 3.12 | abi3 | macOS 11.0+ ARM64 | Details |
Total release size: 5.4 MB
Release files / secrethider-0.2.0.tar.gz
| Download URL | secrethider-0.2.0.tar.gz |
|---|---|
| Size | 113.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
9d967652fe07ae7293e3b89b704ffdbb13b59d65977140b16d4d6ebb3c98cbf1
|
|
BLAKE2b-256 checksum How to use checksums |
f1b9bd7632b08a538992155399ef516b29774caa68f4bafc10d709f729ce9ba6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.2.0-cp312-abi3-win_amd64.whl
| Download URL | secrethider-0.2.0-cp312-abi3-win_amd64.whl |
|---|---|
| Size | 521.1 kB |
| Tags | CPython 3.12 Windows x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
3233613680bb070a028e9a79029d7232c367de83c6f27106548d22c2ddaf2e54
|
|
BLAKE2b-256 checksum How to use checksums |
26179cc809c47b23d451705d5158561ac9531bfc08e28e2a776538d4901451b9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.2.0-cp312-abi3-musllinux_1_2_x86_64.whl
| Download URL | secrethider-0.2.0-cp312-abi3-musllinux_1_2_x86_64.whl |
|---|---|
| Size | 1.3 MB |
| Tags | CPython 3.12 Linux musl 1.2+ x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
9b8d89fb133c80f3f07598fcb3dd5c79c17d3e796efc5ee114044d15bfb2eb91
|
|
BLAKE2b-256 checksum How to use checksums |
cf483173591fa0ec83d92862047fd71f0cacd226f129b75a9635d988c795d38f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.2.0-cp312-abi3-musllinux_1_2_aarch64.whl
| Download URL | secrethider-0.2.0-cp312-abi3-musllinux_1_2_aarch64.whl |
|---|---|
| Size | 1.1 MB |
| Tags | CPython 3.12 Linux musl 1.2+ ARM64 abi3 |
|
SHA-256 checksum How to use checksums |
daaaf0d513706dba0bae96f9aaaa1068c70a1b7674da95d224ea052b7f5d999b
|
|
BLAKE2b-256 checksum How to use checksums |
7ee16dd19df46790228c72684d106a0d1c85d80e02d10266b639c023412775e1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.2.0-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | secrethider-0.2.0-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 832.2 kB |
| Tags | CPython 3.12 Linux glibc 2.17+ x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
68bc926961b6198344f71477ab022e7094d91855ad280ce52dc88031b76ccc61
|
|
BLAKE2b-256 checksum How to use checksums |
a6f79bf530e2e93df1185078be4bc7c001cde599b00e7b517b446616c87b3298
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.2.0-cp312-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
| Download URL | secrethider-0.2.0-cp312-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl |
|---|---|
| Size | 652.1 kB |
| Tags | CPython 3.12 Linux glibc 2.17+ ARM64 abi3 |
|
SHA-256 checksum How to use checksums |
48b9d1f86526be89d27aa0eb63a4d146d600f5e4935af743798a97bc35dd7ffe
|
|
BLAKE2b-256 checksum How to use checksums |
5086c8d1f776f6cdb78cdbd05fcf1454ae3517c5b5dfdf5adb7763cbc0df1c12
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.2.0-cp312-abi3-macosx_11_0_x86_64.whl
| Download URL | secrethider-0.2.0-cp312-abi3-macosx_11_0_x86_64.whl |
|---|---|
| Size | 549.1 kB |
| Tags | CPython 3.12 abi3 macOS 11.0+ x86-64 |
|
SHA-256 checksum How to use checksums |
2ac3f9ee983f02f44665522dab1ca08a9c71742b96c4ee02d7bd366e288146f6
|
|
BLAKE2b-256 checksum How to use checksums |
f2f985e0db0ab1c0f24b90b972417191e2a2dcd145c76293baddf3b0bcb1b71e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / secrethider-0.2.0-cp312-abi3-macosx_11_0_arm64.whl
| Download URL | secrethider-0.2.0-cp312-abi3-macosx_11_0_arm64.whl |
|---|---|
| Size | 394.0 kB |
| Tags | CPython 3.12 abi3 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
da40644771ad0c890c1dd8a3e2743febc33d3920496e369850941857a1881855
|
|
BLAKE2b-256 checksum How to use checksums |
59c5656965a39051b884a3ece7c250c25b53ba79c22b5252b5063a5e95b82c5f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|