Docs
Jan Agent
Hide Secrets

Hide Secrets

Everything the agent reads is sent to your model provider: file contents, shell output, an environment dump, pasted text. With Hide Secrets on, Jan replaces credentials with placeholders just before a request leaves your machine, and puts the real value back when the model asks a tool to use one.

Hide Secrets is off by default, so existing prompts and provider caches are unchanged.

Turn it on

In /settings, open hide_secrets (Privacy), or set it in ~/.jan/config.toml:


hide_secrets = true

JAN_HIDE_SECRETS=1 (or 0) overrides the file. The setting is read each time a run starts (each prompt, /compact), so a change takes effect on the next prompt, not partway through a model turn.

What is hidden

SourceExample
Values of environment variables whose name has a KEY, SECRET, TOKEN, PASSWORD, PASS, AUTH, CREDENTIAL, PRIVATE or OAUTH part, when the value is 8+ charactersOPENAI_API_KEY
A password inside a URL, whatever the variable is calledpostgres://app:hunter2@db/x
GitHub, GitLab, OpenAI and Anthropic keysghp_…, glpat-…, sk-…, sk-ant-…
AWS access keys, Google API keys, Slack, npm, Stripe, Hugging Face and SendGrid tokensAKIA…, AIza…, xoxb-…
JWTs, Bearer header tokens, PEM private key blockseyJ…, Bearer …

The pass covers message text, tool results, and the arguments of earlier tool calls. Images, tool schemas and ids are left alone. It applies to the main run, subagents and compaction.

How it works


tool output "token=ghp_abc…" -> provider sees "token=$$GITHUBTOKEN_3P8W5JH1TK2Q$$"
model calls bash("curl -H $$GITHUBTOKEN_3P8W5JH1TK2Q$$") -> bash runs with the real token

  • A placeholder is derived from the secret and a random key kept in ~/.jan/secret-placeholder.key (mode 0600, never sent anywhere). A transcript reader cannot hash a placeholder back to its secret, and the same secret always becomes the same placeholder.
  • Saved threads keep the real text, and each request is filtered again, so /resume and fork behave the same.
  • Prompt cache: the same text always yields the same bytes, an earlier message is never rewritten differently on a later request, and nothing is added to the system prompt.

Limits

  • Detection is by name and shape. A secret that has neither (a short or unusual value in a variable with a plain name) is not hidden.
  • Values under 8 characters are left alone, so ordinary words survive.
  • Encrypted or opaque provider replay fields cannot be filtered.
  • Telemetry has its own redaction (see Telemetry).