Auto-Redaction
claude-mem can automatically detect and redact common secrets before observations and summaries are stored. Unlike the manual<private> tag, this is a deterministic regex pipeline that catches secrets you never typed yourself — for example, an API key printed by a curl response or echoed by a Bash command.
How it works
When enabled, redaction runs at the same single point where<private> tags are stripped, so it covers every capture path at once: tool inputs and outputs, your prompts (including stored prompt history), the assistant’s last message used for summaries, and server-beta events. Content is scanned for a curated set of high-confidence secret patterns, and matches are replaced inline with a self-closing <redacted type='...'/> placeholder, preserving the surrounding context so search and observation quality stay intact.
Enable it
Add to~/.claude-mem/settings.json:
Built-in patterns
Disable a single built-in
Add a custom pattern
name is required and surfaces in the <redacted type='...'/> marker. Custom patterns are evaluated before built-ins, so you can override the built-in detection for a specific token family.
If your regex fails to compile or your JSON is malformed, claude-mem logs a warning and skips the broken entry — the rest keep working.
Diagnostic logging
pattern,count line per invocation to the worker log. The original matched bytes are never logged.
Limits
- Fails closed on huge fields: a single field over about 1M characters (UTF-16 code units) is replaced whole by
<redacted type='oversize'/>rather than stored unscanned, and a warning is logged. There is no cap on the number of matches: every match is redacted. aws_secret_keyshape: the lookbehind only anchorsKEY=val(shell) andKEY: val(yaml) styles. JSON-style"AWS_SECRET_ACCESS_KEY": "value"is not matched because the lookbehind expects=or:directly after the key name. If you commonly handle JSON config, write a custom pattern for it.- Coverage gap: Built-ins do not cover Azure / GCP service-account JSON / IBM Cloud / private IDC tokens — use custom patterns for those.
- Server-beta scope: in multi-tenant
server-betadeployments, the redaction config is currently read from the worker’s local~/.claude-mem/settings.jsonrather than from tenant-scoped settings. For team deployments, configure redaction at the worker level. A future change will source tenant-scoped redaction config. - Destructive: this is destructive replacement, not encryption. Redacted bytes cannot be recovered. If you need reversible protection, use the
<private>tag and keep the secrets out of the conversation entirely.
Comparison with <private> tags
Both can be used together —
<private> blocks are removed first, then auto-redaction scans what remains, so a wrapped <private> block has its content removed entirely regardless of what’s inside.
