Privacy Tool

JSON Secret & PII Sanitizer

Instantly detect, mask and replace API keys, JWTs, passwords, emails and PII in any JSON payload — 100% in your browser, zero uploads.

100% In-Browser & Privacy-First

Need to format or generate TypeScript types from this JSON?

Open in full MyJSONPal Studio

Free Online JSON Secret & PII Sanitizer

Sharing JSON before you scrub it is how secrets leak: API keys end up in public GitHub issues, credentials get pasted into ChatGPT prompts, and connection strings surface in stack traces. MyJSONPal's sanitizer catches them before you paste.

🛡️ 100% In-Browser Processing

Web Workers ensure sensitive data never leaves the local browser session. Nothing is uploaded, logged, or stored.

🔍 Entropy & Pattern Scanning

Automatically catches Stripe, OpenAI, AWS, JWTs, hex hashes, and database passwords — plus high-entropy strings that look like keys.

⚙️ Custom Key Rules

Interactively pick domain-specific keys to sanitize and persist custom rules in browser storage for every future session.

How it works

1

Paste JSON

Drop your payload into the editor or drag & drop a .json file. Nothing is uploaded.

2

Auto-Detect & Redact

The engine scans keys and values, then replaces every secret with a safe placeholder value.

3

Download / Copy Clean JSON

Grab the sanitized result from the clipboard or as a .json file — ready to share anywhere.

Built for developers sharing JSON safely

Scrub JSON before feeding LLMs

Pasting API responses into ChatGPT or Claude often leaks real keys. Sanitize first so your prompts and conversations stay clean.

Safe for public GitHub issues

Stack traces and config dumps love to hide credentials. Redact them before attaching reproductions to public bug reports.

Share fixture data without risk

Use realistic mock samples in docs, demos, and test suites without exposing real secrets or customer PII.

Frequently asked questions

Does my JSON ever get sent to a server?

Never. Every scan runs locally in your browser inside a Web Worker. There are no network requests, no uploads, and no analytics beacons — your data never leaves your device.

What keys and token formats are automatically detected?

The engine flags secret-like keys (password, apiKey, token, secret, authorization…), known token formats (JWT, Stripe, OpenAI, AWS, GitHub, Slack, Supabase, Anthropic), connection strings (PostgreSQL, MySQL, MongoDB, Redis, AMQP), hex hashes, emails, phones, credit cards, SSNs, IPs, addresses, and high-entropy strings that look like keys.

How do I sanitize custom sensitive keys not caught automatically?

Click the Keys button in the output toolbar. There you can toggle any parsed key to force-redact it, and add persistent custom rules — plain substrings, *_wildcards, or /regex/ — that are applied across sessions and saved only in your browser.

Can I revert to the original un-sanitized JSON if needed?

Yes. Toggle Auto-Sanitize off at any time, or use the Revert to Raw Paste banner that appears after a sanitization to restore the original values immediately.

Will sanitizing my JSON break its structure or invalidate my JSON schema?

No. Secrets are replaced with same-type mock data — strings become placeholder strings, numbers become 0, booleans stay booleans — so every key, array, and nesting level is preserved and the output remains valid JSON that still matches your schema.

Why should I mask sensitive data in JSON before sharing it on Slack, Teams, or GitHub?

Public channels are crawled by bots that harvest API keys and credentials within minutes. A leaked key in a message, log, or issue can be abused before you notice. Masking first keeps your tokens safe while still sharing the shape of the data.

Can I revert or un-sanitize my JSON back to its original values?

Yes. Flip the Auto-Sanitize toggle in the output toolbar to hide redaction, or click Revert to Raw Paste in the banner that appears after sanitization to instantly bring back the original values.

Can I download or copy the sanitized JSON directly?

Absolutely. The output pane has one-click Copy to Clipboard and Download buttons, so you can grab the clean JSON as a .json file or paste it straight into Slack, Teams, GitHub, or an LLM prompt.

How does the sanitizer handle nested objects and large JSON arrays?

The scan runs recursively in a Web Worker, so deeply nested objects and large arrays are walked without freezing the interface. The engine detects secrets at every level — including inside array items — while keeping the UI responsive.