Skip to main content

Module sanitizer

Module sanitizer 

Source
Expand description

Secret sanitization utilities for redacting sensitive information.

Provides regex-based secret redaction for:

  • OpenAI API keys (sk-...)
  • AWS Access Key IDs (AKIA...)
  • GitHub App installation tokens (ghs_..., including ~520-char stateless JWTs)
  • Bearer tokens (Bearer ...)
  • Generic secret assignments (api_key=..., password:..., etc.)

Use this module to sanitize text before logging, displaying in UI, or storing in session archives.

GitHub App installation tokens are treated as opaque strings per https://github.blog/changelog/2026-05-15-github-app-installation-tokens-per-request-override-header/ and https://github.blog/changelog/2026-10-02-stateless-github-app-installation-tokens-rolled-out: ghs_-prefixed JWTs (~520 chars, two dots) must not be subject to length assumptions and must be redacted even without a Bearer prefix.

Structs§

StreamingSecretRedactor
Incrementally redact streamed output without retaining the full stream.

Constants§

PROVIDER_DIAGNOSTIC_MAX_BYTES
Maximum serialized size of a provider diagnostic after redaction.

Functions§

redact_secrets
Redact secrets and sensitive keys from a string.
sanitize_provider_diagnostic
Redact secrets and return a bounded, UTF-8-safe provider diagnostic.