Remove secrets from logs before you share them
Paste logs, configs or code. Keys, tokens and passwords are hidden; variable names stay so the context still makes sense.
How it works
- Step 1
Paste a log, .env file, config or stack trace.
- Step 2
Keys, tokens, passwords, private keys and IPs are replaced with labels as you type.
- Step 3
Copy the clean version into your issue, chat or AI assistant.
DB_URL=postgres://app: S3cret!pw @db
STRIPE_KEY= sk_live_4eC39HqLy
GET /login from 203.0.113.42 200
Knows the formats
AWS, Stripe, GitHub, GitLab, Slack, OpenAI, Anthropic, Google and other key formats, JWTs, private keys, Authorization headers and passwords in connection strings.
Keeps the context
Only the secret value is replaced, so STRIPE_SECRET_KEY=[API_KEY] still tells the reader what was there.
Safe place to paste secrets
Pasting secrets into a website is exactly what you shouldn’t do, unless it can’t send them anywhere. This page can’t: it runs in your browser under a policy that blocks outside requests.
Questions
Does it catch every secret?
It catches known formats and common patterns. Turn on “Possible secrets” to also flag random-looking strings. Always check before sharing.
I already shared a key. What now?
Rotate it with the provider straight away. Removing it from the message doesn’t revoke copies that were already seen.
Can I hide internal hostnames or project names?
Yes. Add them to “always hide” and they are covered wherever they appear.
Related tools
Page updated 4 October 2026.