Repository files navigation

dotmask

mask secrets before they leave your machine.

dotmask runs a local HTTPS proxy for Claude Code, Codex CLI, and similar tools. it replaces real secrets with format-preserving fakes on the way out, then restores them locally on the way back — so the AI sees fake keys while your tools keep working with the real ones.

try it

one session, nothing installed — no daemon, no system cert trust, no settings changes:

npx @ducnmm/dotmask exec -- claude

the proxy starts on a free port, wraps that one command, and disappears when it exits.

works with Codex CLI too (>= 0.129.0, via CODEX_CA_CERTIFICATE):

npx @ducnmm/dotmask exec -- codex

if your Codex uses a custom model provider (model_providers in ~/.codex/config.toml), allow its host first so dotmask masks that traffic:

dotmask allow your-gateway.example.com

Codex streams the model over a WebSocket by default, which is an opaque binary channel dotmask can't mask. So for masked hosts dotmask declines the WebSocket upgrade, and Codex transparently falls back to an HTTP transport whose request body dotmask masks (it also decompresses zstd/gzip/brotli bodies to reach the secrets). If you'd rather tunnel WebSocket traffic through unmasked, set DOTMASK_WS_TUNNEL=1.

install

npm install -g @ducnmm/dotmask
dotmask install

restart Claude Code after install.

use

use Claude Code like normal. dotmask runs automatically after install.

dotmask install also wires up Codex CLI: it adds a small wrapper function to your shell rc (~/.zshrc / ~/.bashrc) that routes codex through the proxy, scoped to that command (no global env changes). Restart your shell — or source ~/.zshrc — after install, then run codex as usual. dotmask uninstall removes it.

supported providers

  • api.anthropic.com - Anthropic (Claude)
  • api.openai.com - OpenAI (GPT)
  • chatgpt.com - Codex CLI (ChatGPT backend)
  • openrouter.ai, api.openrouter.ai - OpenRouter
  • generativelanguage.googleapis.com - Google AI (Gemini)
  • api.deepseek.com - DeepSeek
  • api.groq.com - Groq
  • api.moonshot.ai - Moonshot (Kimi)
  • api.together.ai - Together AI
  • api.fireworks.ai - Fireworks AI
  • api.cerebras.ai - Cerebras
  • api.x.ai - xAI (Grok)
  • api.inference.huggingface.co - Hugging Face
  • api.minimax.io, api.minimax.chat - MiniMax

~/.dotmask/config.json controls the allowed host list.

add a custom host with:

dotmask allow chat.trollllm.xyz

commands

  • dotmask exec -- <command> - run one command behind dotmask (no install)
  • dotmask install - install proxy
  • dotmask install --port 18788 - custom port
  • dotmask allow <host> - add allowed host
  • dotmask disallow <host> - remove host
  • dotmask hosts - list allowed hosts
  • dotmask status - show status
  • dotmask doctor - diagnose issues
  • dotmask uninstall - remove everything

how it works

  1. your prompt with API keys goes to Claude Code
  2. dotmask intercepts and replaces real keys with fakes
  3. fake keys go to the AI API - API thinks its valid
  4. response comes back with fake keys
  5. dotmask swaps fakes back to real keys
  6. Claude Code sees the real response

your secrets never leave your machine.

supported secrets

  • Anthropic keys: sk-ant-api03-...
  • OpenAI keys: sk-proj-..., sk-...
  • Stripe: sk_live_..., sk_test_...
  • AWS: AKIA...
  • Google AI: AIza...
  • GitHub PATs: ghp_..., gho_..., github_pat_...
  • Slack: xoxb-..., xoxp-..., xoxs-..., xapp-1-...
  • JWT tokens
  • Database URLs: postgres://user:pass@...
  • EVM private keys: 0x... (64 chars)
  • GitLab: glpat-..., glrt-...
  • npm: npm_..., PyPI: pypi-...
  • Hugging Face: hf_...
  • SendGrid: SG...., Twilio: SK...
  • DigitalOcean: dop_v1_..., Shopify: shpat_...
  • Telegram bot tokens, Postman: PMAK-...
  • Notion: secret_..., ntn_..., Linear: lin_api_...
  • Databricks: dapi..., Grafana: glc_..., glsa_...
  • HashiCorp Vault: hvs...., Fly.io: fo1_...
  • age keys: AGE-SECRET-KEY-1...

token patterns are curated from the gitleaks default ruleset (MIT) — only strongly-prefixed, low-false-positive rules, since dotmask rewrites matches in place.

debugging

# view logs
tail -f ~/.dotmask/proxy.err.log
# run manually with debug
DOTMASK_DEBUG=1 node dist/proxy/server.js --port 18787

notes

  • macOS only
  • Node.js 18+
  • openssl required
  • secrets stored in macOS Keychain

license

MIT

About

No description, website, or topics provided.

Resources

Contributing

Security policy

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

dotmask

mask secrets before they leave your machine.

dotmask runs a local HTTPS proxy for Claude Code, Codex CLI, and similar tools. it replaces real secrets with format-preserving fakes on the way out, then restores them locally on the way back — so the AI sees fake keys while your tools keep working with the real ones.

try it

one session, nothing installed — no daemon, no system cert trust, no settings changes:

npx @ducnmm/dotmask exec -- claude

the proxy starts on a free port, wraps that one command, and disappears when it exits.

works with Codex CLI too (>= 0.129.0, via CODEX_CA_CERTIFICATE):

npx @ducnmm/dotmask exec -- codex

if your Codex uses a custom model provider (model_providers in ~/.codex/config.toml), allow its host first so dotmask masks that traffic:

dotmask allow your-gateway.example.com

Codex streams the model over a WebSocket by default, which is an opaque binary channel dotmask can't mask. So for masked hosts dotmask declines the WebSocket upgrade, and Codex transparently falls back to an HTTP transport whose request body dotmask masks (it also decompresses zstd/gzip/brotli bodies to reach the secrets). If you'd rather tunnel WebSocket traffic through unmasked, set DOTMASK_WS_TUNNEL=1.

install

npm install -g @ducnmm/dotmask
dotmask install

restart Claude Code after install.

use

use Claude Code like normal. dotmask runs automatically after install.

dotmask install also wires up Codex CLI: it adds a small wrapper function to your shell rc (~/.zshrc / ~/.bashrc) that routes codex through the proxy, scoped to that command (no global env changes). Restart your shell — or source ~/.zshrc — after install, then run codex as usual. dotmask uninstall removes it.

supported providers

  • api.anthropic.com - Anthropic (Claude)
  • api.openai.com - OpenAI (GPT)
  • chatgpt.com - Codex CLI (ChatGPT backend)
  • openrouter.ai, api.openrouter.ai - OpenRouter
  • generativelanguage.googleapis.com - Google AI (Gemini)
  • api.deepseek.com - DeepSeek
  • api.groq.com - Groq
  • api.moonshot.ai - Moonshot (Kimi)
  • api.together.ai - Together AI
  • api.fireworks.ai - Fireworks AI
  • api.cerebras.ai - Cerebras
  • api.x.ai - xAI (Grok)
  • api.inference.huggingface.co - Hugging Face
  • api.minimax.io, api.minimax.chat - MiniMax

~/.dotmask/config.json controls the allowed host list.

add a custom host with:

dotmask allow chat.trollllm.xyz

commands

  • dotmask exec -- <command> - run one command behind dotmask (no install)
  • dotmask install - install proxy
  • dotmask install --port 18788 - custom port
  • dotmask allow <host> - add allowed host
  • dotmask disallow <host> - remove host
  • dotmask hosts - list allowed hosts
  • dotmask status - show status
  • dotmask doctor - diagnose issues
  • dotmask uninstall - remove everything

how it works

  1. your prompt with API keys goes to Claude Code
  2. dotmask intercepts and replaces real keys with fakes
  3. fake keys go to the AI API - API thinks its valid
  4. response comes back with fake keys
  5. dotmask swaps fakes back to real keys
  6. Claude Code sees the real response

your secrets never leave your machine.

supported secrets

  • Anthropic keys: sk-ant-api03-...
  • OpenAI keys: sk-proj-..., sk-...
  • Stripe: sk_live_..., sk_test_...
  • AWS: AKIA...
  • Google AI: AIza...
  • GitHub PATs: ghp_..., gho_..., github_pat_...
  • Slack: xoxb-..., xoxp-..., xoxs-..., xapp-1-...
  • JWT tokens
  • Database URLs: postgres://user:pass@...
  • EVM private keys: 0x... (64 chars)
  • GitLab: glpat-..., glrt-...
  • npm: npm_..., PyPI: pypi-...
  • Hugging Face: hf_...
  • SendGrid: SG...., Twilio: SK...
  • DigitalOcean: dop_v1_..., Shopify: shpat_...
  • Telegram bot tokens, Postman: PMAK-...
  • Notion: secret_..., ntn_..., Linear: lin_api_...
  • Databricks: dapi..., Grafana: glc_..., glsa_...
  • HashiCorp Vault: hvs...., Fly.io: fo1_...
  • age keys: AGE-SECRET-KEY-1...

token patterns are curated from the gitleaks default ruleset (MIT) — only strongly-prefixed, low-false-positive rules, since dotmask rewrites matches in place.

debugging

# view logs
tail -f ~/.dotmask/proxy.err.log
# run manually with debug
DOTMASK_DEBUG=1 node dist/proxy/server.js --port 18787

notes

  • macOS only
  • Node.js 18+
  • openssl required
  • secrets stored in macOS Keychain

license

MIT

About

No description, website, or topics provided.

Resources

Contributing

Security policy

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

dotmask

mask secrets before they leave your machine.

dotmask runs a local HTTPS proxy for Claude Code, Codex CLI, and similar tools. it replaces real secrets with format-preserving fakes on the way out, then restores them locally on the way back — so the AI sees fake keys while your tools keep working with the real ones.

try it

one session, nothing installed — no daemon, no system cert trust, no settings changes:

npx @ducnmm/dotmask exec -- claude

the proxy starts on a free port, wraps that one command, and disappears when it exits.

works with Codex CLI too (>= 0.129.0, via CODEX_CA_CERTIFICATE):

npx @ducnmm/dotmask exec -- codex

if your Codex uses a custom model provider (model_providers in ~/.codex/config.toml), allow its host first so dotmask masks that traffic:

dotmask allow your-gateway.example.com

Codex streams the model over a WebSocket by default, which is an opaque binary channel dotmask can't mask. So for masked hosts dotmask declines the WebSocket upgrade, and Codex transparently falls back to an HTTP transport whose request body dotmask masks (it also decompresses zstd/gzip/brotli bodies to reach the secrets). If you'd rather tunnel WebSocket traffic through unmasked, set DOTMASK_WS_TUNNEL=1.

install

npm install -g @ducnmm/dotmask
dotmask install

restart Claude Code after install.

use

use Claude Code like normal. dotmask runs automatically after install.

dotmask install also wires up Codex CLI: it adds a small wrapper function to your shell rc (~/.zshrc / ~/.bashrc) that routes codex through the proxy, scoped to that command (no global env changes). Restart your shell — or source ~/.zshrc — after install, then run codex as usual. dotmask uninstall removes it.

supported providers

  • api.anthropic.com - Anthropic (Claude)
  • api.openai.com - OpenAI (GPT)
  • chatgpt.com - Codex CLI (ChatGPT backend)
  • openrouter.ai, api.openrouter.ai - OpenRouter
  • generativelanguage.googleapis.com - Google AI (Gemini)
  • api.deepseek.com - DeepSeek
  • api.groq.com - Groq
  • api.moonshot.ai - Moonshot (Kimi)
  • api.together.ai - Together AI
  • api.fireworks.ai - Fireworks AI
  • api.cerebras.ai - Cerebras
  • api.x.ai - xAI (Grok)
  • api.inference.huggingface.co - Hugging Face
  • api.minimax.io, api.minimax.chat - MiniMax

~/.dotmask/config.json controls the allowed host list.

add a custom host with:

dotmask allow chat.trollllm.xyz

commands

  • dotmask exec -- <command> - run one command behind dotmask (no install)
  • dotmask install - install proxy
  • dotmask install --port 18788 - custom port
  • dotmask allow <host> - add allowed host
  • dotmask disallow <host> - remove host
  • dotmask hosts - list allowed hosts
  • dotmask status - show status
  • dotmask doctor - diagnose issues
  • dotmask uninstall - remove everything

how it works

  1. your prompt with API keys goes to Claude Code
  2. dotmask intercepts and replaces real keys with fakes
  3. fake keys go to the AI API - API thinks its valid
  4. response comes back with fake keys
  5. dotmask swaps fakes back to real keys
  6. Claude Code sees the real response

your secrets never leave your machine.

supported secrets

  • Anthropic keys: sk-ant-api03-...
  • OpenAI keys: sk-proj-..., sk-...
  • Stripe: sk_live_..., sk_test_...
  • AWS: AKIA...
  • Google AI: AIza...
  • GitHub PATs: ghp_..., gho_..., github_pat_...
  • Slack: xoxb-..., xoxp-..., xoxs-..., xapp-1-...
  • JWT tokens
  • Database URLs: postgres://user:pass@...
  • EVM private keys: 0x... (64 chars)
  • GitLab: glpat-..., glrt-...
  • npm: npm_..., PyPI: pypi-...
  • Hugging Face: hf_...
  • SendGrid: SG...., Twilio: SK...
  • DigitalOcean: dop_v1_..., Shopify: shpat_...
  • Telegram bot tokens, Postman: PMAK-...
  • Notion: secret_..., ntn_..., Linear: lin_api_...
  • Databricks: dapi..., Grafana: glc_..., glsa_...
  • HashiCorp Vault: hvs...., Fly.io: fo1_...
  • age keys: AGE-SECRET-KEY-1...

token patterns are curated from the gitleaks default ruleset (MIT) — only strongly-prefixed, low-false-positive rules, since dotmask rewrites matches in place.

debugging

# view logs
tail -f ~/.dotmask/proxy.err.log
# run manually with debug
DOTMASK_DEBUG=1 node dist/proxy/server.js --port 18787

notes

  • macOS only
  • Node.js 18+
  • openssl required
  • secrets stored in macOS Keychain

license

MIT

About

No description, website, or topics provided.

Resources

Contributing

Security policy

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

dotmask

mask secrets before they leave your machine.

dotmask runs a local HTTPS proxy for Claude Code, Codex CLI, and similar tools. it replaces real secrets with format-preserving fakes on the way out, then restores them locally on the way back — so the AI sees fake keys while your tools keep working with the real ones.

try it

one session, nothing installed — no daemon, no system cert trust, no settings changes:

npx @ducnmm/dotmask exec -- claude

the proxy starts on a free port, wraps that one command, and disappears when it exits.

works with Codex CLI too (>= 0.129.0, via CODEX_CA_CERTIFICATE):

npx @ducnmm/dotmask exec -- codex

if your Codex uses a custom model provider (model_providers in ~/.codex/config.toml), allow its host first so dotmask masks that traffic:

dotmask allow your-gateway.example.com

Codex streams the model over a WebSocket by default, which is an opaque binary channel dotmask can't mask. So for masked hosts dotmask declines the WebSocket upgrade, and Codex transparently falls back to an HTTP transport whose request body dotmask masks (it also decompresses zstd/gzip/brotli bodies to reach the secrets). If you'd rather tunnel WebSocket traffic through unmasked, set DOTMASK_WS_TUNNEL=1.

install

npm install -g @ducnmm/dotmask
dotmask install

restart Claude Code after install.

use

use Claude Code like normal. dotmask runs automatically after install.

dotmask install also wires up Codex CLI: it adds a small wrapper function to your shell rc (~/.zshrc / ~/.bashrc) that routes codex through the proxy, scoped to that command (no global env changes). Restart your shell — or source ~/.zshrc — after install, then run codex as usual. dotmask uninstall removes it.

supported providers

  • api.anthropic.com - Anthropic (Claude)
  • api.openai.com - OpenAI (GPT)
  • chatgpt.com - Codex CLI (ChatGPT backend)
  • openrouter.ai, api.openrouter.ai - OpenRouter
  • generativelanguage.googleapis.com - Google AI (Gemini)
  • api.deepseek.com - DeepSeek
  • api.groq.com - Groq
  • api.moonshot.ai - Moonshot (Kimi)
  • api.together.ai - Together AI
  • api.fireworks.ai - Fireworks AI
  • api.cerebras.ai - Cerebras
  • api.x.ai - xAI (Grok)
  • api.inference.huggingface.co - Hugging Face
  • api.minimax.io, api.minimax.chat - MiniMax

~/.dotmask/config.json controls the allowed host list.

add a custom host with:

dotmask allow chat.trollllm.xyz

commands

  • dotmask exec -- <command> - run one command behind dotmask (no install)
  • dotmask install - install proxy
  • dotmask install --port 18788 - custom port
  • dotmask allow <host> - add allowed host
  • dotmask disallow <host> - remove host
  • dotmask hosts - list allowed hosts
  • dotmask status - show status
  • dotmask doctor - diagnose issues
  • dotmask uninstall - remove everything

how it works

  1. your prompt with API keys goes to Claude Code
  2. dotmask intercepts and replaces real keys with fakes
  3. fake keys go to the AI API - API thinks its valid
  4. response comes back with fake keys
  5. dotmask swaps fakes back to real keys
  6. Claude Code sees the real response

your secrets never leave your machine.

supported secrets

  • Anthropic keys: sk-ant-api03-...
  • OpenAI keys: sk-proj-..., sk-...
  • Stripe: sk_live_..., sk_test_...
  • AWS: AKIA...
  • Google AI: AIza...
  • GitHub PATs: ghp_..., gho_..., github_pat_...
  • Slack: xoxb-..., xoxp-..., xoxs-..., xapp-1-...
  • JWT tokens
  • Database URLs: postgres://user:pass@...
  • EVM private keys: 0x... (64 chars)
  • GitLab: glpat-..., glrt-...
  • npm: npm_..., PyPI: pypi-...
  • Hugging Face: hf_...
  • SendGrid: SG...., Twilio: SK...
  • DigitalOcean: dop_v1_..., Shopify: shpat_...
  • Telegram bot tokens, Postman: PMAK-...
  • Notion: secret_..., ntn_..., Linear: lin_api_...
  • Databricks: dapi..., Grafana: glc_..., glsa_...
  • HashiCorp Vault: hvs...., Fly.io: fo1_...
  • age keys: AGE-SECRET-KEY-1...

token patterns are curated from the gitleaks default ruleset (MIT) — only strongly-prefixed, low-false-positive rules, since dotmask rewrites matches in place.

debugging

# view logs
tail -f ~/.dotmask/proxy.err.log
# run manually with debug
DOTMASK_DEBUG=1 node dist/proxy/server.js --port 18787

notes

  • macOS only
  • Node.js 18+
  • openssl required
  • secrets stored in macOS Keychain

license

MIT

About

No description, website, or topics provided.

Resources

Contributing

Security policy

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

dotmask

mask secrets before they leave your machine.

dotmask runs a local HTTPS proxy for Claude Code, Codex CLI, and similar tools. it replaces real secrets with format-preserving fakes on the way out, then restores them locally on the way back — so the AI sees fake keys while your tools keep working with the real ones.

try it

one session, nothing installed — no daemon, no system cert trust, no settings changes:

npx @ducnmm/dotmask exec -- claude

the proxy starts on a free port, wraps that one command, and disappears when it exits.

works with Codex CLI too (>= 0.129.0, via CODEX_CA_CERTIFICATE):

npx @ducnmm/dotmask exec -- codex

if your Codex uses a custom model provider (model_providers in ~/.codex/config.toml), allow its host first so dotmask masks that traffic:

dotmask allow your-gateway.example.com

Codex streams the model over a WebSocket by default, which is an opaque binary channel dotmask can't mask. So for masked hosts dotmask declines the WebSocket upgrade, and Codex transparently falls back to an HTTP transport whose request body dotmask masks (it also decompresses zstd/gzip/brotli bodies to reach the secrets). If you'd rather tunnel WebSocket traffic through unmasked, set DOTMASK_WS_TUNNEL=1.

install

npm install -g @ducnmm/dotmask
dotmask install

restart Claude Code after install.

use

use Claude Code like normal. dotmask runs automatically after install.

dotmask install also wires up Codex CLI: it adds a small wrapper function to your shell rc (~/.zshrc / ~/.bashrc) that routes codex through the proxy, scoped to that command (no global env changes). Restart your shell — or source ~/.zshrc — after install, then run codex as usual. dotmask uninstall removes it.

supported providers

  • api.anthropic.com - Anthropic (Claude)
  • api.openai.com - OpenAI (GPT)
  • chatgpt.com - Codex CLI (ChatGPT backend)
  • openrouter.ai, api.openrouter.ai - OpenRouter
  • generativelanguage.googleapis.com - Google AI (Gemini)
  • api.deepseek.com - DeepSeek
  • api.groq.com - Groq
  • api.moonshot.ai - Moonshot (Kimi)
  • api.together.ai - Together AI
  • api.fireworks.ai - Fireworks AI
  • api.cerebras.ai - Cerebras
  • api.x.ai - xAI (Grok)
  • api.inference.huggingface.co - Hugging Face
  • api.minimax.io, api.minimax.chat - MiniMax

~/.dotmask/config.json controls the allowed host list.

add a custom host with:

dotmask allow chat.trollllm.xyz

commands

  • dotmask exec -- <command> - run one command behind dotmask (no install)
  • dotmask install - install proxy
  • dotmask install --port 18788 - custom port
  • dotmask allow <host> - add allowed host
  • dotmask disallow <host> - remove host
  • dotmask hosts - list allowed hosts
  • dotmask status - show status
  • dotmask doctor - diagnose issues
  • dotmask uninstall - remove everything

how it works

  1. your prompt with API keys goes to Claude Code
  2. dotmask intercepts and replaces real keys with fakes
  3. fake keys go to the AI API - API thinks its valid
  4. response comes back with fake keys
  5. dotmask swaps fakes back to real keys
  6. Claude Code sees the real response

your secrets never leave your machine.

supported secrets

  • Anthropic keys: sk-ant-api03-...
  • OpenAI keys: sk-proj-..., sk-...
  • Stripe: sk_live_..., sk_test_...
  • AWS: AKIA...
  • Google AI: AIza...
  • GitHub PATs: ghp_..., gho_..., github_pat_...
  • Slack: xoxb-..., xoxp-..., xoxs-..., xapp-1-...
  • JWT tokens
  • Database URLs: postgres://user:pass@...
  • EVM private keys: 0x... (64 chars)
  • GitLab: glpat-..., glrt-...
  • npm: npm_..., PyPI: pypi-...
  • Hugging Face: hf_...
  • SendGrid: SG...., Twilio: SK...
  • DigitalOcean: dop_v1_..., Shopify: shpat_...
  • Telegram bot tokens, Postman: PMAK-...
  • Notion: secret_..., ntn_..., Linear: lin_api_...
  • Databricks: dapi..., Grafana: glc_..., glsa_...
  • HashiCorp Vault: hvs...., Fly.io: fo1_...
  • age keys: AGE-SECRET-KEY-1...

token patterns are curated from the gitleaks default ruleset (MIT) — only strongly-prefixed, low-false-positive rules, since dotmask rewrites matches in place.

debugging

# view logs
tail -f ~/.dotmask/proxy.err.log
# run manually with debug
DOTMASK_DEBUG=1 node dist/proxy/server.js --port 18787

notes

  • macOS only
  • Node.js 18+
  • openssl required
  • secrets stored in macOS Keychain

license

MIT

About

No description, website, or topics provided.

Resources

Contributing

Security policy

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

dotmask

mask secrets before they leave your machine.

dotmask runs a local HTTPS proxy for Claude Code, Codex CLI, and similar tools. it replaces real secrets with format-preserving fakes on the way out, then restores them locally on the way back — so the AI sees fake keys while your tools keep working with the real ones.

try it

one session, nothing installed — no daemon, no system cert trust, no settings changes:

npx @ducnmm/dotmask exec -- claude

the proxy starts on a free port, wraps that one command, and disappears when it exits.

works with Codex CLI too (>= 0.129.0, via CODEX_CA_CERTIFICATE):

npx @ducnmm/dotmask exec -- codex

if your Codex uses a custom model provider (model_providers in ~/.codex/config.toml), allow its host first so dotmask masks that traffic:

dotmask allow your-gateway.example.com

Codex streams the model over a WebSocket by default, which is an opaque binary channel dotmask can't mask. So for masked hosts dotmask declines the WebSocket upgrade, and Codex transparently falls back to an HTTP transport whose request body dotmask masks (it also decompresses zstd/gzip/brotli bodies to reach the secrets). If you'd rather tunnel WebSocket traffic through unmasked, set DOTMASK_WS_TUNNEL=1.

install

npm install -g @ducnmm/dotmask
dotmask install

restart Claude Code after install.

use

use Claude Code like normal. dotmask runs automatically after install.

dotmask install also wires up Codex CLI: it adds a small wrapper function to your shell rc (~/.zshrc / ~/.bashrc) that routes codex through the proxy, scoped to that command (no global env changes). Restart your shell — or source ~/.zshrc — after install, then run codex as usual. dotmask uninstall removes it.

supported providers

  • api.anthropic.com - Anthropic (Claude)
  • api.openai.com - OpenAI (GPT)
  • chatgpt.com - Codex CLI (ChatGPT backend)
  • openrouter.ai, api.openrouter.ai - OpenRouter
  • generativelanguage.googleapis.com - Google AI (Gemini)
  • api.deepseek.com - DeepSeek
  • api.groq.com - Groq
  • api.moonshot.ai - Moonshot (Kimi)
  • api.together.ai - Together AI
  • api.fireworks.ai - Fireworks AI
  • api.cerebras.ai - Cerebras
  • api.x.ai - xAI (Grok)
  • api.inference.huggingface.co - Hugging Face
  • api.minimax.io, api.minimax.chat - MiniMax

~/.dotmask/config.json controls the allowed host list.

add a custom host with:

dotmask allow chat.trollllm.xyz

commands

  • dotmask exec -- <command> - run one command behind dotmask (no install)
  • dotmask install - install proxy
  • dotmask install --port 18788 - custom port
  • dotmask allow <host> - add allowed host
  • dotmask disallow <host> - remove host
  • dotmask hosts - list allowed hosts
  • dotmask status - show status
  • dotmask doctor - diagnose issues
  • dotmask uninstall - remove everything

how it works

  1. your prompt with API keys goes to Claude Code
  2. dotmask intercepts and replaces real keys with fakes
  3. fake keys go to the AI API - API thinks its valid
  4. response comes back with fake keys
  5. dotmask swaps fakes back to real keys
  6. Claude Code sees the real response

your secrets never leave your machine.

supported secrets

  • Anthropic keys: sk-ant-api03-...
  • OpenAI keys: sk-proj-..., sk-...
  • Stripe: sk_live_..., sk_test_...
  • AWS: AKIA...
  • Google AI: AIza...
  • GitHub PATs: ghp_..., gho_..., github_pat_...
  • Slack: xoxb-..., xoxp-..., xoxs-..., xapp-1-...
  • JWT tokens
  • Database URLs: postgres://user:pass@...
  • EVM private keys: 0x... (64 chars)
  • GitLab: glpat-..., glrt-...
  • npm: npm_..., PyPI: pypi-...
  • Hugging Face: hf_...
  • SendGrid: SG...., Twilio: SK...
  • DigitalOcean: dop_v1_..., Shopify: shpat_...
  • Telegram bot tokens, Postman: PMAK-...
  • Notion: secret_..., ntn_..., Linear: lin_api_...
  • Databricks: dapi..., Grafana: glc_..., glsa_...
  • HashiCorp Vault: hvs...., Fly.io: fo1_...
  • age keys: AGE-SECRET-KEY-1...

token patterns are curated from the gitleaks default ruleset (MIT) — only strongly-prefixed, low-false-positive rules, since dotmask rewrites matches in place.

debugging

# view logs
tail -f ~/.dotmask/proxy.err.log
# run manually with debug
DOTMASK_DEBUG=1 node dist/proxy/server.js --port 18787

notes

  • macOS only
  • Node.js 18+
  • openssl required
  • secrets stored in macOS Keychain

license

MIT

About

No description, website, or topics provided.

Resources

Contributing

Security policy

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

dotmask

mask secrets before they leave your machine.

dotmask runs a local HTTPS proxy for Claude Code, Codex CLI, and similar tools. it replaces real secrets with format-preserving fakes on the way out, then restores them locally on the way back — so the AI sees fake keys while your tools keep working with the real ones.

try it

one session, nothing installed — no daemon, no system cert trust, no settings changes:

npx @ducnmm/dotmask exec -- claude

the proxy starts on a free port, wraps that one command, and disappears when it exits.

works with Codex CLI too (>= 0.129.0, via CODEX_CA_CERTIFICATE):

npx @ducnmm/dotmask exec -- codex

if your Codex uses a custom model provider (model_providers in ~/.codex/config.toml), allow its host first so dotmask masks that traffic:

dotmask allow your-gateway.example.com

Codex streams the model over a WebSocket by default, which is an opaque binary channel dotmask can't mask. So for masked hosts dotmask declines the WebSocket upgrade, and Codex transparently falls back to an HTTP transport whose request body dotmask masks (it also decompresses zstd/gzip/brotli bodies to reach the secrets). If you'd rather tunnel WebSocket traffic through unmasked, set DOTMASK_WS_TUNNEL=1.

install

npm install -g @ducnmm/dotmask
dotmask install

restart Claude Code after install.

use

use Claude Code like normal. dotmask runs automatically after install.

dotmask install also wires up Codex CLI: it adds a small wrapper function to your shell rc (~/.zshrc / ~/.bashrc) that routes codex through the proxy, scoped to that command (no global env changes). Restart your shell — or source ~/.zshrc — after install, then run codex as usual. dotmask uninstall removes it.

supported providers

  • api.anthropic.com - Anthropic (Claude)
  • api.openai.com - OpenAI (GPT)
  • chatgpt.com - Codex CLI (ChatGPT backend)
  • openrouter.ai, api.openrouter.ai - OpenRouter
  • generativelanguage.googleapis.com - Google AI (Gemini)
  • api.deepseek.com - DeepSeek
  • api.groq.com - Groq
  • api.moonshot.ai - Moonshot (Kimi)
  • api.together.ai - Together AI
  • api.fireworks.ai - Fireworks AI
  • api.cerebras.ai - Cerebras
  • api.x.ai - xAI (Grok)
  • api.inference.huggingface.co - Hugging Face
  • api.minimax.io, api.minimax.chat - MiniMax

~/.dotmask/config.json controls the allowed host list.

add a custom host with:

dotmask allow chat.trollllm.xyz

commands

  • dotmask exec -- <command> - run one command behind dotmask (no install)
  • dotmask install - install proxy
  • dotmask install --port 18788 - custom port
  • dotmask allow <host> - add allowed host
  • dotmask disallow <host> - remove host
  • dotmask hosts - list allowed hosts
  • dotmask status - show status
  • dotmask doctor - diagnose issues
  • dotmask uninstall - remove everything

how it works

  1. your prompt with API keys goes to Claude Code
  2. dotmask intercepts and replaces real keys with fakes
  3. fake keys go to the AI API - API thinks its valid
  4. response comes back with fake keys
  5. dotmask swaps fakes back to real keys
  6. Claude Code sees the real response

your secrets never leave your machine.

supported secrets

  • Anthropic keys: sk-ant-api03-...
  • OpenAI keys: sk-proj-..., sk-...
  • Stripe: sk_live_..., sk_test_...
  • AWS: AKIA...
  • Google AI: AIza...
  • GitHub PATs: ghp_..., gho_..., github_pat_...
  • Slack: xoxb-..., xoxp-..., xoxs-..., xapp-1-...
  • JWT tokens
  • Database URLs: postgres://user:pass@...
  • EVM private keys: 0x... (64 chars)
  • GitLab: glpat-..., glrt-...
  • npm: npm_..., PyPI: pypi-...
  • Hugging Face: hf_...
  • SendGrid: SG...., Twilio: SK...
  • DigitalOcean: dop_v1_..., Shopify: shpat_...
  • Telegram bot tokens, Postman: PMAK-...
  • Notion: secret_..., ntn_..., Linear: lin_api_...
  • Databricks: dapi..., Grafana: glc_..., glsa_...
  • HashiCorp Vault: hvs...., Fly.io: fo1_...
  • age keys: AGE-SECRET-KEY-1...

token patterns are curated from the gitleaks default ruleset (MIT) — only strongly-prefixed, low-false-positive rules, since dotmask rewrites matches in place.

debugging

# view logs
tail -f ~/.dotmask/proxy.err.log
# run manually with debug
DOTMASK_DEBUG=1 node dist/proxy/server.js --port 18787

notes

  • macOS only
  • Node.js 18+
  • openssl required
  • secrets stored in macOS Keychain

license

MIT

About

No description, website, or topics provided.

Resources

Contributing

Security policy

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

dotmask

mask secrets before they leave your machine.

dotmask runs a local HTTPS proxy for Claude Code, Codex CLI, and similar tools. it replaces real secrets with format-preserving fakes on the way out, then restores them locally on the way back — so the AI sees fake keys while your tools keep working with the real ones.

try it

one session, nothing installed — no daemon, no system cert trust, no settings changes:

npx @ducnmm/dotmask exec -- claude

the proxy starts on a free port, wraps that one command, and disappears when it exits.

works with Codex CLI too (>= 0.129.0, via CODEX_CA_CERTIFICATE):

npx @ducnmm/dotmask exec -- codex

if your Codex uses a custom model provider (model_providers in ~/.codex/config.toml), allow its host first so dotmask masks that traffic:

dotmask allow your-gateway.example.com

Codex streams the model over a WebSocket by default, which is an opaque binary channel dotmask can't mask. So for masked hosts dotmask declines the WebSocket upgrade, and Codex transparently falls back to an HTTP transport whose request body dotmask masks (it also decompresses zstd/gzip/brotli bodies to reach the secrets). If you'd rather tunnel WebSocket traffic through unmasked, set DOTMASK_WS_TUNNEL=1.

install

npm install -g @ducnmm/dotmask
dotmask install

restart Claude Code after install.

use

use Claude Code like normal. dotmask runs automatically after install.

dotmask install also wires up Codex CLI: it adds a small wrapper function to your shell rc (~/.zshrc / ~/.bashrc) that routes codex through the proxy, scoped to that command (no global env changes). Restart your shell — or source ~/.zshrc — after install, then run codex as usual. dotmask uninstall removes it.

supported providers

  • api.anthropic.com - Anthropic (Claude)
  • api.openai.com - OpenAI (GPT)
  • chatgpt.com - Codex CLI (ChatGPT backend)
  • openrouter.ai, api.openrouter.ai - OpenRouter
  • generativelanguage.googleapis.com - Google AI (Gemini)
  • api.deepseek.com - DeepSeek
  • api.groq.com - Groq
  • api.moonshot.ai - Moonshot (Kimi)
  • api.together.ai - Together AI
  • api.fireworks.ai - Fireworks AI
  • api.cerebras.ai - Cerebras
  • api.x.ai - xAI (Grok)
  • api.inference.huggingface.co - Hugging Face
  • api.minimax.io, api.minimax.chat - MiniMax

~/.dotmask/config.json controls the allowed host list.

add a custom host with:

dotmask allow chat.trollllm.xyz

commands

  • dotmask exec -- <command> - run one command behind dotmask (no install)
  • dotmask install - install proxy
  • dotmask install --port 18788 - custom port
  • dotmask allow <host> - add allowed host
  • dotmask disallow <host> - remove host
  • dotmask hosts - list allowed hosts
  • dotmask status - show status
  • dotmask doctor - diagnose issues
  • dotmask uninstall - remove everything

how it works

  1. your prompt with API keys goes to Claude Code
  2. dotmask intercepts and replaces real keys with fakes
  3. fake keys go to the AI API - API thinks its valid
  4. response comes back with fake keys
  5. dotmask swaps fakes back to real keys
  6. Claude Code sees the real response

your secrets never leave your machine.

supported secrets

  • Anthropic keys: sk-ant-api03-...
  • OpenAI keys: sk-proj-..., sk-...
  • Stripe: sk_live_..., sk_test_...
  • AWS: AKIA...
  • Google AI: AIza...
  • GitHub PATs: ghp_..., gho_..., github_pat_...
  • Slack: xoxb-..., xoxp-..., xoxs-..., xapp-1-...
  • JWT tokens
  • Database URLs: postgres://user:pass@...
  • EVM private keys: 0x... (64 chars)
  • GitLab: glpat-..., glrt-...
  • npm: npm_..., PyPI: pypi-...
  • Hugging Face: hf_...
  • SendGrid: SG...., Twilio: SK...
  • DigitalOcean: dop_v1_..., Shopify: shpat_...
  • Telegram bot tokens, Postman: PMAK-...
  • Notion: secret_..., ntn_..., Linear: lin_api_...
  • Databricks: dapi..., Grafana: glc_..., glsa_...
  • HashiCorp Vault: hvs...., Fly.io: fo1_...
  • age keys: AGE-SECRET-KEY-1...

token patterns are curated from the gitleaks default ruleset (MIT) — only strongly-prefixed, low-false-positive rules, since dotmask rewrites matches in place.

debugging

# view logs
tail -f ~/.dotmask/proxy.err.log
# run manually with debug
DOTMASK_DEBUG=1 node dist/proxy/server.js --port 18787

notes

  • macOS only
  • Node.js 18+
  • openssl required
  • secrets stored in macOS Keychain

license

MIT

About

No description, website, or topics provided.

Resources

Contributing

Security policy

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages