Imp.Redaction (Imp v0.5.0)

Copy Markdown View Source

Shared redaction helpers for traces, telemetry, and runtime metadata.

Imp keeps prompts, tool inputs, provider metadata, and optimizer reports inspectable, but credentials and credential-shaped strings must not leak into those artifacts. redact/2 walks ordinary Elixir maps, lists, tuples, and structs, replacing known secret fields and secret-looking string values with "[REDACTED]".

Clients, retrievers and trackers that hold a credential print through a redacting Inspect implementation, which hides every header value and the query, fragment and user info of every URL as well; inspect(term, structs: false), Erlang's ~p, and a credential kept outside those structs (a bare keyword list in a process's state) bypass it.

Summary

Functions

default_keys()

Returns the default key names treated as sensitive.

iex> :api_key in Imp.Redaction.default_keys()
true

iex> :"x-api-key" in Imp.Redaction.default_keys()
true

drop_credentials(value)

Recursively removes credential-bearing entries while preserving semantic data.

This is intended for persistence and cache identity boundaries where restoring a redaction marker as a runtime option would be misleading.

redact(value, keys \\ [:api_key, :authorization, :proxy_authorization, :auth, :bearer, :session, :token, :api_token, :auth_token, :bearer_token, :refresh_token, :id_token, :session_token, :password, :secret, :access_token, :access_key, :access_key_id, :secret_key, :secret_access_key, :client_secret, :private_key, :private_token, :service_account_key, :credential, :credentials, :"x-api-key"])

Redacts sensitive keys and secret-looking string values.

Key matching is intentionally conservative around common credential names: exact keys plus token-delimited or camel-case provider prefixes such as :openai_api_key are redacted.

iex> Imp.Redaction.redact(%{api_key: "sk-test-secret-1234567890", model: "demo"})
%{api_key: "[REDACTED]", model: "demo"}

iex> Imp.Redaction.redact(%{nested: [%{"authorization" => "Bearer abcdefghijklmnop"}]})
%{nested: [%{"authorization" => "[REDACTED]"}]}

iex> Imp.Redaction.redact("sk-test-secret-1234567890")
"[REDACTED]"

iex> Imp.Redaction.redact(%{tenant_id: "public"}, [:tenant_id])
%{tenant_id: "[REDACTED]"}

iex> Imp.Redaction.redact({:error, "Bearer abcdefghijklmnop"})
{:error, "[REDACTED]"}