Skip to content

Redaction

from fastmcp_feedback.instrumentation import Redactor
Redactor(keys=DEFAULT_SECRET_KEYS, patterns=DEFAULT_SECRET_PATTERNS, *,
extra_keys=(), extra_patterns=(), suffixes=DEFAULT_SECRET_SUFFIXES,
replacement="[REDACTED]", max_depth=32)
ParameterDescription
keysDict keys whose values are secrets, matched after lowercasing and turning - into _.
patternsRegular expressions for secret-shaped values, replaced wherever they appear in strings.
extra_keys, extra_patternsAdded to keys and patterns.
suffixesA key ending in one of these is a secret key too.
replacementWhat a secret becomes.
max_depthNesting depth beyond which values become [TRUNCATED].

Methods: redact(value) returns a redacted copy of nested dicts, lists and strings (the input is never modified); redact_text(text) redacts a string; is_secret_key(key).

A secret key’s value is replaced only when it is not None.

r = Redactor(extra_keys=["license"])
assert r.redact({"License": "ABC-123", "user": "ana"}) == {"License": "[REDACTED]", "user": "ana"}
assert r.redact({"X-Api-Key": "k", "db_password": "p"}) == {"X-Api-Key": "[REDACTED]", "db_password": "[REDACTED]"}
assert r.redact_text("login failed: password=hunter2") == "login failed: password=[REDACTED]"

access_token, api_key, apikey, auth_token, authorization, bearer, client_secret, cookie, csrf_token, id_token, passphrase, passwd, password, private_key, proxy_authorization, refresh_token, secret, session_token, set_cookie, token, x_api_key.

Suffixes: _token, _secret, _password, _api_key, _apikey, _private_key.

PatternMatches
\bbmcp_[A-Za-z0-9_-]{8,}blender-mcp personal access tokens
\beyJ[A-Za-z0-9_-]{5,}\.[A-Za-z0-9_-]{5,}\.[A-Za-z0-9_-]{5,}JWTs
(?i)\bbearer\s+[A-Za-z0-9._~+/=-]{8,}Bearer ... credentials
\bsk-[A-Za-z0-9_-]{16,}OpenAI and Anthropic style API keys
\bgh[pousr]_[A-Za-z0-9]{20,}, \bgithub_pat_[A-Za-z0-9_]{20,}GitHub tokens
\bxox[abposr]-[A-Za-z0-9-]{10,}Slack tokens
\bAKIA[0-9A-Z]{16}\bAWS access key ids
\bpypi-[A-Za-z0-9_-]{16,}PyPI tokens

redact_text also replaces the value in password=..., secret: ..., token=..., api_key=... and authorization: ... pairs, keeping the key so the text still says what was removed.

The middleware’s redactor is applied to:

  • tool arguments and results (full mode)
  • exception messages and soft-error messages
  • identity resolver and enricher output
  • event attrs, and record_llm_call errors, prompts and completions
  • text sent to an embedder, which an EmbeddingSink adopts from the middleware

Sizes (args_size, result_size) are measured before redaction.