ctxbleach
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@ctxbleachredact the AWS keys from this log before sending"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
ctxbleach
Local CLI and MCP server that bleaches secrets from logs, files, and diffs before AI agents see them.
🎯 Why?
Trending agent-context projects focus on giving agents more code and memory, while guardrail tools mostly block commands. Developers still need a tiny local middleware that transforms raw logs, env files, and command output into safe, token-budgeted context before it reaches an LLM. Existing secret scanners are CI-oriented and do not provide interactive redaction placeholders, MCP tools, or context budgeting.
Target audience: Developers and platform engineers using Claude Code, Cursor, Codex, or MCP-enabled agents who need to share logs, .env files, stack traces, and CI output without leaking credentials.
Related MCP server: VaultBridge
✨ Features
✨ Regex-based redaction for AWS keys, GitHub/Slack tokens, JWTs, bearer headers, URL passwords, private keys, and generic secret assignments
✨ Stable placeholders and masked scan output so no secret values are echoed back
✨ Token-budgeted truncation with head or tail preservation for large logs
✨ CLI commands for scan, redact, and MCP stdio serving
✨ Zero-dependency Python implementation that can be dropped into agent workflows
🚀 Quick Start
# Install
pip install ctxbleach
# Run
ctxbleach --help📦 Installation
From Source
git clone https://github.com/YOUR_USERNAME/ctxbleach.git
cd ctxbleach# Create virtual environment
python -m venv .venv
source .venv/bin/activate # Windows: .venv\Scripts\activate
# Install in development mode
pip install -e ".[dev]"
# Run tests
pytest -v🎬 Demo
The GIF above was recorded using Charm VHS:
vhs < demo.tape📖 Usage
# Show help
ctxbleach --help
# Common usage examples
ctxbleach --example🏗️ Architecture
graph LR
A[Input] --> B[Core Engine]
B --> C[Output]
B --> D[Plugins]
D --> E[Extensions]🤝 Contributing
Contributions are welcome! Please:
Fork the repo
Create a feature branch (
git checkout -b feature/amazing-feature)Commit your changes (
git commit -m 'Add amazing feature')Push to the branch (
git push origin feature/amazing-feature)Open a Pull Request
📄 License
MIT © 2026 — See LICENSE for details.
If this project helped you, please ⭐ star it!
This server cannot be deployed
Maintenance
Related MCP Connectors
Security & DLP proxy for MCP: tool-poisoning scans, PII redaction on tool args/results. Beta.
Redact PII from text before it reaches a model. Nothing stored, no third-party AI.
Zero-secret MCP gateway for AI agents: risk-scored, audited calls with human-in-the-loop approval.
Security gateway for AI agents: policy, approval, and audited execution, no secrets shared.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceLocal-first CLI and MCP server for redacting sensitive text before sharing logs, configs, and errors with AI tools.MIT
- AlicenseNot gradedqualityDmaintenanceSecret management MCP server for AI coding agents that prevents secrets from entering the LLM context window by returning metadata only and using side-channel injection. Integrates with Bitwarden and offers hooks for auto-capture and leak prevention.1MIT
- AlicenseAqualityAmaintenanceA local-first redacting MCP gateway that strips secrets from file reads and shell output before they reach an AI coding agent's context, the command still runs with the real credential, but the model never sees it.218MIT
- AlicenseAqualityCmaintenanceA redaction engine and MCP server that scrubs sensitive identifiers (AWS keys, IPs, emails, etc.) from AI agent traces, enabling safe storage and sharing of war stories via submit, search, and retrieve tools.3Apache 2.0