Lesson 13 / 25
Redacting Secrets
Scrub secret-looking text from tool output and logs as a last line of defence.
A safety net, not a wall
A redaction filter scans text on its way into logs, prompts or chat and replaces known secret formats (cloud key IDs, GitHub tokens, password=...) with a placeholder. It catches accidents but cannot recognise every secret, and it can over-match harmless text. Use it in addition to keeping secrets away, never instead.
A redactor, run
I ran this. The key and the password are replaced and ordinary text is untouched. Note that the broad password=... pattern also swallows whatever follows it on the same token.
import re
PATTERNS = [re.compile(r"AKIA[0-9A-Z]{16}"),
re.compile(r"ghp_[A-Za-z0-9]{36}"),
re.compile(r"(?i)(password|secret|token)\s*[=:]\s*\S+")]
def redact(text):
for p in PATTERNS:
text = p.sub("[REDACTED]", text)
return text
print(redact("aws=AKIAABCDEFGHIJKLMNOP password=hunter2 note=ok"))
Output:
aws=[REDACTED] [REDACTED] note=ok
Rotate anything that leaked
Redaction cannot un-send a secret that already reached a model provider or a log. If a real credential appears in output, treat it as exposed and rotate it.
Quick check: What is the right role of a redaction filter?
- A replacement for access control
- A last-line safety net in addition to keeping secrets away
- A way to share secrets safely
- A guarantee that nothing leaks
Answer
A last-line safety net in addition to keeping secrets away — It catches mistakes but is imperfect, so prevention comes first.