
PII & Secret Redactor
io.github.tylerscomic-labv1.0.0Updated Oct 2, 2026
Detect and redact PII and secrets before text reaches an LLM, with reversible placeholders.
Overview
Detects and redacts PII and secrets in text before it reaches an LLM, using reversible placeholders that can be restored afterward.
- What it does
- Provides tools to detect personal data and credentials in text, redact them with stable placeholders, masks, salted hashes, or removal, and restore the originals in a model's response. Detection is checksum-verified for credit cards, IBANs, US routing numbers, and SSNs, and covers emails, phone numbers, dates of birth, US street addresses, IP addresses, and common API keys and private keys. A list_detectors tool reports exactly what is and is not covered.
- When to use it
- Useful when sending text that may contain customer data or credentials to a model, log, or ticket and you want to reduce exposure while keeping the answer readable. It fits workflows where the same value must map back to the same placeholder so responses can be restored.
- Requirements
- Either the hosted remote MCP endpoint over streamable HTTP, which needs an API key from MCPize, or a self-hosted local run using Node.js (npm install, then node server.js, listening on port 8080 with MCP at /mcp).
Installation
In SourceWeft
- Open PII & Secret Redactor in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.
Other MCP clients
Add this to your client's mcpServers config.
{
"mcpServers": {
"pii-redactor-mcp": {
"type": "http",
"url": "https://pii-redactor-mcp.mcpize.run/mcp"
}
}
}README
PII & Secret Redactor
Redact PII and secrets from text before it reaches an LLM. Checksum-verified cards, IBANs and routing numbers, SSN range rules, API keys, and reversible placeholders you can restore after the model responds.
Send the question, not the customer's data
Strip personal data and credentials out of text before it goes to a model, a log or a ticket, then put the originals back in the answer.
What it detects
- Verified, not just matched: credit cards (Luhn, brand identified), IBANs (mod-97), US routing numbers (ABA checksum), SSNs (invalid ranges rejected). Order numbers and random digit strings are left alone.
- Contact and identity: emails, phone numbers (US and international), labelled dates of birth, US street addresses, IPv4 and IPv6.
- Secrets: Anthropic, OpenAI, AWS, GitHub, Stripe, Slack and Google keys, JWTs, private keys, database URLs with credentials.
Tools
detect_pii: findings with type, position and a masked preview. Never echoes full values.redact_text: placeholder (stable tokens like<EMAIL_1>, same value gives the same token), mask, salted hash, or remove.restore_text: swap placeholders back to the originals in the model's response, using the mapping you keep.list_detectors: exactly what is and is not covered.
Be clear about the limits
Pattern and checksum based. It does not detect personal names or free-form addresses in other formats, so it reduces exposure but is not a compliance guarantee for HIPAA, GDPR or PCI. Input is processed in memory and never stored or logged.
Use it
Hosted on MCPize with a free tier (10 calls a day). Remote MCP endpoint (streamable HTTP, API key from MCPize):
Or run it yourself:
MIT licensed.
Source: README.md at commit 530eaf7
Tools
0Version history
1- v1.0.0LatestOct 2, 2026

