Skip to main content

Auto-Redaction

claude-mem can automatically detect and redact common secrets before observations and summaries are stored. Unlike the manual <private> tag, this is a deterministic regex pipeline that catches secrets you never typed yourself — for example, an API key printed by a curl response or echoed by a Bash command.

How it works

When enabled, redaction runs at the same single point where <private> tags are stripped, so it covers every capture path at once: tool inputs and outputs, your prompts (including stored prompt history), the assistant’s last message used for summaries, and server-beta events. Content is scanned for a curated set of high-confidence secret patterns, and matches are replaced inline with a self-closing <redacted type='...'/> placeholder, preserving the surrounding context so search and observation quality stay intact.
When a payload contains a marker, the observer prompt tells the model to treat it as a placeholder and not to infer the literal value. Prompts without markers are unchanged, so redaction adds no tokens when it finds nothing.

Enable it

Add to ~/.claude-mem/settings.json:
That is all you need for the 11 built-in patterns to kick in.

Built-in patterns

Disable a single built-in

CSV format. The other built-ins stay active.

Add a custom pattern

name is required and surfaces in the <redacted type='...'/> marker. Custom patterns are evaluated before built-ins, so you can override the built-in detection for a specific token family. If your regex fails to compile or your JSON is malformed, claude-mem logs a warning and skips the broken entry — the rest keep working.

Diagnostic logging

Writes a pattern,count line per invocation to the worker log. The original matched bytes are never logged.

Limits

  • Fails closed on huge fields: a single field over about 1M characters (UTF-16 code units) is replaced whole by <redacted type='oversize'/> rather than stored unscanned, and a warning is logged. There is no cap on the number of matches: every match is redacted.
  • aws_secret_key shape: the lookbehind only anchors KEY=val (shell) and KEY: val (yaml) styles. JSON-style "AWS_SECRET_ACCESS_KEY": "value" is not matched because the lookbehind expects = or : directly after the key name. If you commonly handle JSON config, write a custom pattern for it.
  • Coverage gap: Built-ins do not cover Azure / GCP service-account JSON / IBM Cloud / private IDC tokens — use custom patterns for those.
  • Server-beta scope: in multi-tenant server-beta deployments, the redaction config is currently read from the worker’s local ~/.claude-mem/settings.json rather than from tenant-scoped settings. For team deployments, configure redaction at the worker level. A future change will source tenant-scoped redaction config.
  • Destructive: this is destructive replacement, not encryption. Redacted bytes cannot be recovered. If you need reversible protection, use the <private> tag and keep the secrets out of the conversation entirely.

Comparison with <private> tags

Both can be used together — <private> blocks are removed first, then auto-redaction scans what remains, so a wrapped <private> block has its content removed entirely regardless of what’s inside.