Configuration Value Sanitizer
Remove values from .env assignments or HTTP headers before you share a diagnostic. Deliberately strict: every recognized value is replaced, not just likely passwords.
Reviewed output
Key and header names remain and can be sensitive. Comments, unparsed lines and HTTP bodies are removed. This tool does not process JSON, YAML, arbitrary logs, archives or binary files.
Runs entirely in your browser. Your input and output are not sent or stored, and are gone when you close the page.
Configuration Sanitizer FAQ
What does strict mode remove?
Every value it can parse, not only values that look like passwords. In .env input each KEY=value becomes KEY="[REDACTED]"; in HTTP input each header value becomes [REDACTED]. Comments, unparsed or continuation lines, the request line and anything after the first blank line (the body) are removed.
Is my input sent anywhere?
No. The tool runs in your browser and makes no network request with your input or output, and nothing is stored when you leave the page. Your clipboard, saved files and browser extensions are outside the page, so treat them accordingly.
Why are key and header names kept?
So the result still shows the structure a support engineer needs. Names can be sensitive too — an internal hostname inside a key name, for example — which is why the output must be reviewed before you copy or save it.
Which formats are supported?
.env assignments (including the export prefix and quoted multi-line values) and raw HTTP headers with an optional request line. It does not process JSON, YAML, arbitrary logs, archives or binary files; text in those formats is not reliably cleaned.
Is this a secret scanner?
No. It is a deliberately blunt redaction step for two structured formats. It cannot prove a text is safe to disclose — that judgement stays with you, which is what the review checkbox records.
What should I send instead of the real value?
Usually nothing: describe the operation, the non-sensitive error, the time and a case reference. If a value genuinely has to reach someone, use an approved protected route rather than the ticket, chat or email thread.
When a value really has to move
Keep it out of the ticket. Send it as an expiring CredenShare link with a view limit, and keep only the case reference in the thread.