The key stays home.
The model gets a token such as [API_KEY-7a3f9e], [EMAIL-2b8d4c] or [PASSWORD-27d2c4]

sk_live_51H…4Q2 never leaves your machine.

Copies this prompt for Claude Code Or run it yourself Install options

Prefer to run it yourself? See the two commands

claude — ~/shop-api
Left of the handle: your screen, with real values. Right: exactly what the model receives.
How it works

Masked on the way out. Restored on your side.

Four checkpoints sit between your machine and the model. Each one is a plain script that runs locally, so the same input always gets the same result and the model can't talk its way past it.

real valuetoken

Your laptop is the boundary. ZeroH runs on it as a local proxy plus Claude Code hooks. Real values stay on the laptop; only tokens cross the internet to the model provider.

  1. You type “Refund order 1182 for alice@acme.com”. The local proxy masks it, and the model receives [EMAIL-2b8d4c].
  2. Claude answers with a command that uses [API_KEY-7a3f9e]. Just before it runs on your laptop, the PreToolUse hook puts the real key back, only for api.stripe.com. The real key travels to api.stripe.com, its allowed host, and the call succeeds; the same key sent to a host that isn't allowed is blocked on your laptop and never leaves it.
  3. The command's output, STRIPE_KEY=sk_live_51Hx…, is masked on its way back to the model (PostToolUse), so the model sees [API_KEY-7a3f9e].
  4. Claude's answer arrives with tokens, and your screen shows the real values (MessageDisplay).
What it catches

If it would hurt to leak, it becomes a token.

Pick a kind of data. Switch between your file, what the model gets, and the token map that links them, which never leaves your machine.

real valuetokenPremiumleft alone on purpose

About 220 provider formats from the gitleaks rule set, plus every value in your own .env and credential files, matched exactly. Publishable keys, public keys, commit hashes and UUIDs are left alone.

When Claude needs the real value

Most work runs on tokens. When it can't, you decide.

Your sign-up form rejects real customers. The log shows Claude only [EMAIL-3f9c21], so it can't see the apostrophe in anna.o'neil@example.co.uk. Unmask one kind of data, for a while.

Usually

It works it out at home

Claude runs code with tokens. It runs on your machine with the real values, and only the result comes back.

$ node check.mjs [EMAIL-3f9c21]
→ Claude gets validateEmail: rejected
→ you see    anna.o'neil@example.co.uk
When it can't

You unmask one kind of data, for a while

Claude names the kind of data and why. Claude Code asks you, not Claude, how long to show it.

  • Keys are never unmasked. They are put back only inside the command that runs.
  • Limits are yours. 15 minutes, an hour, or until the session ends, within the cap you set per kind. On Enterprise, your DPO sets them.
  • It ends on time, with a record. Say "stop showing emails" and it ends. Each reveal goes on your receipt; what Claude already saw stays until you /clear.
Quickstart

Try it in a minute

Once it's installed: read a secret file, use the key, read the receipt. No Stripe account needed.

Test it step by step 21 steps to copy, each with what you should see
~/shop-api

          
What stays yours

Nothing to hand over. Nothing to trust us with.

Your machine
Your keysfound and swapped here
Token maptoken to real value, in a local folder
Receiptssigned files on your disk
Claude Codeyour login, your model
tokens only
Model provider[API_KEY-7a3f9e]
nothing
Blade LabsNo account, no telemetry. A report only if you send one
Not in the free plugin Images and scanned PDFs claude.ai, ChatGPT, desktop apps Secrets with no known shape
Plans

Start free. Add more when you need it.

Keys are always found on your machine, on every plan.

Free

Available

For anyone using Claude Code who wants keys and personal data out of the chat. Runs on your machine (macOS, Windows or Linux), no account.

Install free

Enterprise

For organisations. A gateway for every request, your DPO's rules, and an audit trail with reports.

Talk to ZeroH
Keeps up with your tools

Your tools ship daily. We test the same day.

All tools
watched daily tested same day on record
Claude Code releases13in the last 14 days
Codex releases5in the last 14 days
OpenCode releases2in the last 14 days
Systems per release4Linux macOS Windows ×2

We don't promise a release never breaks anything. We promise to notice the same day and fix it.

How we test
  • Releases, versions and dates are real, read from each tool's npm channel.
  • Checked every day at 05:17 UTC; at most one live test run per day.
  • Every Claude Code release is tested on Linux, macOS, Windows (Git Bash) and Windows (PowerShell).
  • Test results shown here are illustrative until the public records start at launch.
  • Codex and OpenCode releases are recorded now; their tests start when their plugins ship.

Install it, then keep working the way you do.

No account and no configuration. It runs with the local detection rules and the default policy.

Ask Claude Code

Read the steps on GitHub ↗
Contact

Talk to a person.

Questions, bugs or a plan for your whole team: pick the way that fits.

Email
Questions, Premium and everything else

Write to us and a person answers.

hello@bladelabs.io
GitHub
Bugs and feature requests

Open an issue on the public plugin repository, where fixes ship.

Open an issue ↗
Organisations
For a whole company

A gateway for every request, your DPO's rules and an audit trail, with ZeroH.

Talk to ZeroH ↗

AI can use your files.sk_live_51Hx…⟦API_KEY-7a3f9e⟧It just can't read what's private in them.

Waitlist

Join the waitlist

Pick what you want to try and we'll email you once, when it opens.

Tell me when these open

We keep your email and the products you picked, only to tell you when they open. To be removed, write to hello@bladelabs.io. Privacy

FAQ

Questions to ask before you install

What the model sees, where it works, and what stays on your machine.

Privacy and safety

Does the model ever see my key?

Not a key it recognises. What you type, the files Claude reads and the output of commands reach the model as tokens, for about 220 key formats and every value in your .env and credential files. A key only goes back into a command on your machine, and only to hosts you allow for that key. What it can't catch: a value with no known shape and no secret-like name, images and scanned PDFs. If the local proxy isn't running, what you type is sent as typed, and one line tells you it wasn't protected. The README lists every limit.

What if Claude needs to see a real value?

Usually it doesn't: it writes code with tokens and the code runs on your machine with the real values. When its judgement depends on the value itself, it asks to unmask one kind of data. Claude Code then asks you, not Claude, whether to allow it and for how long. Keys are never unmasked.

What if Claude tries to send a token somewhere else?

Each key is bound to the hosts it may reach, for example a Stripe key only to api.stripe.com. A command that sends it to a host that isn't allowed is stopped, with the one command that would allow it, and the attempt is written to the receipt. A destination ZeroH can't work out in advance, such as a $HOST variable or a script, runs as it would without ZeroH: you see a line saying it wasn't protected, and it goes on the receipt. To stop those too, run /zeroh-disclosure:settings uncertain block.

Does ZeroH ever block my work?

Only in two cases. A secret heading to a host that ZeroH knows isn't allowed for it is stopped, and the message names the one /zeroh-disclosure:allow command that allows it. And Claude can't change ZeroH's own protection: its settings, keys, hooks or local proxy. Everything ZeroH can't check runs as it would without ZeroH, and you're told in one plain line, such as ZeroH Disclosure: this command was not protected (couldn't parse it)., which also goes on the receipt. Blocking those uncertain cases is opt-in: /zeroh-disclosure:settings uncertain block.

What if a secret slips through?

A value with no known shape and no secret-like name, say a token hidden in a URL path, looks like ordinary text. Claude usually notices and flags it. Say “report it”: ZeroH masks it from then on, keeps a note of its shape, never the value, and tells you so in one line. Reports stay on this computer. What Claude already saw can't be recalled, so rotate that key. You can also put the value in your .env to have it matched exactly. In Premium you describe a shape once, for example your company's ID format.

Is anything sent to Blade Labs?

Not on the free plan. A miss report holds a value's shape, never the value. Reports stay on this computer. Your secrets, the token map and the receipts stay on your disk. Premium sends text to our detection service to find names and amounts. Keys and IDs are always found on your machine and never sent.

Can I see what it did?

Yes. The status line under Claude Code's prompt shows whether you're protected and what was masked this session; click receipt ↗ to open the receipt (in terminals that support links). /zeroh-disclosure:mask-show lists the tokens the model saw this session, by type and where each came from. /zeroh-disclosure:mask-receipt shows the signed receipt, and receipt.html shows a short preview of each value on your screen only.

Where it works

Does it work on Windows and macOS?

Yes: macOS, Windows and Linux, with the same install commands. On Windows, Claude Code runs commands in Git Bash or in PowerShell, and Disclosure checks both.

Does it work with my Claude subscription?

Yes. The plugin runs inside Claude Code whichever way you sign in, with a Pro or Max subscription or with an API key.

How do I get plugin updates?

Automatically. Claude Code updates plugins on its own only from Anthropic's marketplaces, so with your first message after the install the plugin turns on auto-update for the zeroh marketplace and says so, however you installed it. You can turn it off in /plugin under Marketplaces. From then on, new versions arrive in the background and Claude Code says Plugin updated: zeroh-disclosure · Run /reload-plugins to apply; your next session uses them. To update right away instead, run claude plugin update zeroh-disclosure@zeroh and restart Claude Code. The local proxy restarts itself with the new version.

What happens when Claude Code updates?

We check Claude Code, Codex and OpenCode for new releases every day. When Claude Code ships one, the full test suite runs against it the same day on macOS, Windows and Linux, and the result is recorded. We can't promise a release never changes something the plugin relies on, but we notice the same day and ship a fix. Update with claude plugin update zeroh-disclosure@zeroh.

Does it work with Codex or OpenCode?

Soon. We ran Codex through a local masking proxy with a ChatGPT login: the model received only tokens, for typed prompts and for a .env file it read. OpenCode's plugin API can mask every request before it goes to any model provider. Both plugins are next.

Does it work in claude.ai, ChatGPT or the desktop apps?

Not as a plugin. Those apps offer no place to run code on your machine before a prompt is sent. Organisations on Claude Enterprise can block prompts with secrets on every Claude surface through ZeroH.

Does it slow Claude Code down?

Each check is a short script that runs on your machine when you send a prompt or Claude Code calls a tool. The call to the model itself is unchanged.

Plans and company

I build an app that calls a model. Can I use this there?

Not with the plugin, which runs inside your coding tools. Premium adds the same masking as an API your own app can call, with the same Blade Labs key. Join the waitlist to hear when it opens.

Is this made by Anthropic?

No. ZeroH Disclosure is an independent plugin made by Blade Labs. It isn't made, sponsored or endorsed by Anthropic, OpenAI or the OpenCode project. Claude and Claude Code are trademarks of Anthropic, and Codex is a trademark of OpenAI.

Pricing

Start free. Add more when you need it.

Keys are always found on your machine, on every plan. Prices for Premium come with its launch.

Free

Available
$0no account, no card

For anyone using Claude Code who wants keys and personal data out of the chat.

  • About 220 key formats, your .env and personal data by pattern
  • Masks prompts, files and command output
  • Real values back only for hosts you allow
  • A signed receipt every turn, on your disk
Install free

Enterprise

Contractfor your organisation

For organisations, with ZeroH.

  • A gateway for every request
  • Your DPO's rules across the tenant
  • An audit trail with reports
  • Your own tenant, or hosted
Talk to ZeroH ↗

Compare plans

✓ Available nowSoon Coming soonPlanned— Not included
FeatureFreePremiumEnterprise
Detect
API keys and tokens by provider formatabout 220 formats, from the gitleaks rule set✓✓✓
Your own .env and credential files, matched exactlyincluding base64, URL and hex forms✓✓✓
Personal data by patternemails, phone numbers, cards, IBANs✓✓✓
Names, organisations, amounts and IDs, recognised in contextany format, not only known patterns; checked by a detection engine, never by an AI model—Planned✓
Scanned PDFs and imagesfree plugin passes them with a noticeNoticePlannedPlanned
Your own detection rulesdescribe a secret or ID shape once and it is caught from then on: for your account in Premium, across your tenant in Enterprise—PlannedPlanned
Keep it from the model
One plain line whenever something wasn't protectedand each one recorded on the receipt✓✓✓
Typed secrets masked automaticallylocal proxy, no copy and paste✓✓✓
File contents and command output masked✓✓✓
SSH keys and credential files read with the key maskedZeroH's own keys are never read✓✓✓
Stop uncertain cases insteadopt-in: /zeroh-disclosure:settings uncertain block✓✓✓
Every request masked by a gatewayfor the whole organisation——Planned
Put real values back
Into commands, only for hosts each key may reach✓✓✓
On your screen, while Claude gets tokens✓✓✓
Timed unmasking with limits you set✓✓DPO sets limits
The same token for the same value on all devices—PlannedPlanned
Prove it
Signed receipt on your disk every turn✓✓✓
Status line: protected, masked, sentone click to the session's receipt✓✓✓
Tamper-evident record of every reveal—PlannedPlanned
Audit service and ProofPack reports—Planned✓
Works with
Claude Code✓✓✓
macOS, Windows and Linuxon Windows, in Git Bash and in PowerShell✓✓✓
Codex and OpenCodeSoonSoonSoon
claude.ai and the Claude appsblocks, does not maskSoonSoonSoon
Account
AccountNoneBlade Labs accountYour organisation
Where it runsYour machineYour machine, plus our detection service for names and IDsYour own tenant, or hosted
How you payFreeCreditsContract