Remove secrets from logs before you share them

Paste logs, configs or code. Keys, tokens and passwords are hidden; variable names stay so the context still makes sense.

Loading the tool…

How it works

  1. Step 1

    Paste a log, .env file, config or stack trace.

  2. Step 2

    Keys, tokens, passwords, private keys and IPs are replaced with labels as you type.

  3. Step 3

    Copy the clean version into your issue, chat or AI assistant.

app.log SAFE TO POST

DB_URL=postgres://app: S3cret!pw password @db

STRIPE_KEY= sk_live_4eC39HqLy api_key

GET /login from 203.0.113.42 ip 200

Keys are hidden; variable names stay readable.

Knows the formats

AWS, Stripe, GitHub, GitLab, Slack, OpenAI, Anthropic, Google and other key formats, JWTs, private keys, Authorization headers and passwords in connection strings.

Keeps the context

Only the secret value is replaced, so STRIPE_SECRET_KEY=[API_KEY] still tells the reader what was there.

Safe place to paste secrets

Pasting secrets into a website is exactly what you shouldn’t do, unless it can’t send them anywhere. This page can’t: it runs in your browser under a policy that blocks outside requests.

Questions

Does it catch every secret?

It catches known formats and common patterns. Turn on “Possible secrets” to also flag random-looking strings. Always check before sharing.

I already shared a key. What now?

Rotate it with the provider straight away. Removing it from the message doesn’t revoke copies that were already seen.

Can I hide internal hostnames or project names?

Yes. Add them to “always hide” and they are covered wherever they appear.

Page updated 4 October 2026.