Masqo - Secret Redaction
Overview
Detect and redact secrets before pasting into AI chat tools. All processing runs locally - no data leaves your browser.
Masqo intercepts paste events on AI chat interfaces and scans the text for secrets - API keys, JWTs, database connection strings, private keys, and 20+ other patterns - before it reaches the model. Everything runs locally in your browser. No accounts. No servers. No telemetry. The extension never reads your clipboard passively; it only scans text at the exact moment you paste into a supported site. ╋ HOW IT WORKS 1. You paste into a supported AI chat site 2. Masqo's detection engine scans the text using deterministic pattern rules + entropy heuristics 3. A review panel appears showing each detection with type, confidence score, and a preview 4. You accept, reject, or toggle each finding individually 5. Click "Paste clean" - only the redacted version is inserted ╋ WHAT IT DETECTS • Cloud provider access & secret keys • Cloud service account keys • Source control platform tokens • Payment processor & AI provider API keys • Bearer tokens & JWTs • Database connection strings (SQL & NoSQL) • Private keys (RSA, EC, SSH) • HTTP Basic Auth credentials • Cookie headers • .env secret assignments • Messaging & email service API keys • Package registry tokens • Stack traces with embedded tokens • HTTP request headers • Email addresses, phone numbers, SSNs, credit cards, public IPs ╋ POLICIES Pick the policy that matches your workflow: • General (default): Secrets + PII, medium-confidence threshold • Developer: Secrets + logs only, tokenize mode (stable placeholders for AI context) • Default: All detectors, all confidence levels, maximum coverage ╋ REPLACEMENT MODES • Redact: Replace with [REDACTED:type] • Tokenize: Replace with stable [JWT_1] placeholders for AI-readable structure • Partial: Show first/last characters, mask the middle • Warn only: Flag without changing output ╋ SUPPORTED SITES Works on major AI chat interfaces. Full list of supported origins in our GitHub repo. ╋ PRIVACY GUARANTEE Masqo does not: ✗ Send your text to any server ✗ Read your clipboard outside of paste events ✗ Track usage or collect analytics ✗ Load remote code or remote configuration ✗ Require an account or login All detection rules and the redaction engine are bundled into the extension itself. The only network access Chrome grants this extension is for the extension's own update channel managed by the Chrome Web Store. ╋ OPEN SOURCE Source code: https://github.com/hungphamtan/masqo Web demo: https://masqo.dev Privacy policy: https://masqo.dev/privacy Terms: https://masqo.dev/terms Built with TypeScript. MIT licensed. Contributions welcome.
0 out of 5No ratings
Details
- Version0.1.2
- UpdatedJune 24, 2026
- Offered byRyan Pham
- Size942KiB
- LanguagesEnglish
- DeveloperCeladonCity
36 Tan Thang, Son Ky HCMC, Ho Chi Minh City 70000 VNEmail
phamtanhung@gmail.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, visit the developer's support site