Wick redacts secrets and PII from text so it is safe to share — with an LLM, a forum, or a teammate.
Logs, configs, and stack traces routinely contain API keys, internal hostnames, and personal data. Wick strips them out while preserving the surrounding content, so the result is still useful for troubleshooting: kubectl logs before they go into an AI chat, a .env before it lands in a gist, a stack trace before it hits a GitHub issue.
- Detects secrets with bundled Gitleaks-derived rules, plus common PII (emails, IP addresses, US phone numbers, US SSNs)
- Preserves structure for JSON, YAML, and
.envinput - Extensible with custom patterns, allowlists, and blocklists
- Reversible mode: share redacted text, then restore the originals from an encrypted token map
- Exits non-zero when findings are present, so it can gate scripts and CI
Homebrew (macOS, Linux):
brew install krypsis-io/tap/wickGo:
go install github.com/krypsis-io/wick/cmd/wick@latestShell installer (Linux, macOS):
curl -fsSL https://raw.githubusercontent.com/krypsis-io/wick/main/install.sh | shThe script downloads the latest release for your platform, verifies its SHA-256 checksum, and installs to /usr/local/bin (falling back to ~/.local/bin). Set WICK_INSTALL_DIR to change the destination or WICK_VERSION to pin a version.
Prebuilt binary — archives for Linux, macOS, and Windows (amd64/arm64) with checksums are on Releases.
# Redact files
wick app.log
wick .env config.yaml
# Redact anything on stdin
kubectl logs deploy/api | wick
env | wick
# Straight to the clipboard, ready to paste into an LLM
kubectl logs deploy/api | wick | pbcopy
# Save a shareable copy
wick app.log > issue-safe.log
# Redact an entire directory into a safe copy
wick --dir ./configs --out ./safe-configsExit code 1 means Wick found and redacted something; 0 means the input was clean.
wick app.log --format json # sanitized text plus machine-readable findings
wick app.log --summary # count of redactions, printed to stderr
wick app.log --report # per-finding detail (rule ID, location), printed to stderr
wick app.log --style stars # replacement style: redacted (default), stars, hash, custom="..."JSON output contains redacted (the sanitized content), findings (category, rule ID, and location for each match), and summary (counts by rule).
Tokenize mode replaces each finding with a unique token and writes an encrypted map of the originals. Share the redacted text, then rehydrate the response to restore the real values.
# Redact with reversible tokens; the AES-256 key is printed once to stderr
wick --tokenize < app.log > safe.log
# Restore the original values
wick --rehydrate --key <KEY> < safe.logThe token map is written to .wick-tokens.enc by default (--token-file to change it). Both modes read from stdin only.
Wick works with zero configuration. To add project-specific rules, create a .wick.yaml:
style: redacted
format: text
# Custom patterns, in addition to the built-in rules
patterns:
- name: internal-ticket
regex: "ACME-\\d{4}"
- name: internal-hostname
regex: "\\w+\\.internal\\.acme\\.com"
replacement: "[INTERNAL-HOST]" # optional per-pattern replacement
# Known-safe values that should never be redacted
allowlist:
- pattern: "test@example\\.com"
regex: true
reason: "Test fixture email"
# Values that must always be redacted, even if no built-in rule matches
blocklist:
- pattern: "ACME-INTERNAL-[A-Z0-9]+"
category: "custom"
reason: "Internal project codes"
# Extra Gitleaks-compatible rules from a TOML file
rules_file: "./my-rules.toml"
# Disable built-in rules by ID (use --report to see rule IDs)
disable_rules:
- "generic-api-key"Config is loaded from ~/.config/wick/config.yaml (global), then the nearest .wick.yaml walking up from the current directory (project). Project settings override global; CLI flags override both. See .wick.yaml.example for the full reference.
| Code | Meaning |
|---|---|
0 |
No secrets or PII detected |
1 |
Secrets or PII detected, or command error |
Wick is a last-mile filter for text you are about to share. It is not a secrets manager and does not replace proper secret storage, rotation, or leak prevention.
