Expand description
Secret sanitization utilities for redacting sensitive information.
Provides regex-based secret redaction for:
- OpenAI API keys (
sk-...) - AWS Access Key IDs (
AKIA...) - GitHub App installation tokens (
ghs_..., including ~520-char stateless JWTs) - Bearer tokens (
Bearer ...) - Generic secret assignments (
api_key=...,password:..., etc.)
Use this module to sanitize text before logging, displaying in UI, or storing in session archives.
GitHub App installation tokens are treated as opaque strings per
https://github.blog/changelog/2026-05-15-github-app-installation-tokens-per-request-override-header/
and https://github.blog/changelog/2026-10-02-stateless-github-app-installation-tokens-rolled-out:
ghs_-prefixed JWTs (~520 chars, two dots) must not be subject to length
assumptions and must be redacted even without a Bearer prefix.
Structs§
- Streaming
Secret Redactor - Incrementally redact streamed output without retaining the full stream.
Constants§
- PROVIDER_
DIAGNOSTIC_ MAX_ BYTES - Maximum serialized size of a provider diagnostic after redaction.
Functions§
- redact_
secrets - Redact secrets and sensitive keys from a string.
- sanitize_
provider_ diagnostic - Redact secrets and return a bounded, UTF-8-safe provider diagnostic.