How to hide API keys in screenshots
A failed request is useful context for support. The key used to send it usually is not. Before you upload a screenshot to an AI chat, issue tracker, or forum, cover the credential and check for other copies of it.
Look beyond the field named “API key”
Check request headers, terminal output, configuration files, and browser address bars. The same credential can appear twice: once in a settings field and again in a command or error message.
Look for values beside labels such as Authorization, Bearer, api_key, token, and password. Also check connection strings, URL query parameters, and QR codes. Cover the full value, including wrapped lines.
Keep the error message, status code, and setting names when they help explain the problem. Review project IDs, private hostnames, email addresses, and file paths separately; they may reveal details you did not mean to share.
Cover the credential with a solid mask
In Cloakshot, open Settings → Detection and choose Solid black before opening the screenshot for review. Then import the image with Choose images, or send it from a compatible Share menu.
On iPhone, use Edit in Cloakshot from the Share extension for the full scan and editor. On Android, sharing an image to Cloakshot opens the main app.
Check the suggested edits, then open Edit details. Resize each mask to cover the entire credential. Use Add mask if a value is missing from the suggestions. A scan with no findings does not mean there are no secrets in the image.
Before
POST /v1/example
Status: 401 Unauthorized
Authorization: Bearer
EXAMPLE_TOKEN_NOT_A_REAL_KEYAfter
POST /v1/example
Status: 401 Unauthorized
Authorization: Bearer
Credential coveredInspect the exported file
Tap Export in the main app. Cloakshot writes the selected masks into a separate PNG, verifies the selected edits, and scans the copy for remaining high-risk findings before opening the Share menu.
If you save the file first, open that copy and zoom in. Check the ends of each mask, wrapped lines, and any repeated values elsewhere in the screenshot. Look through the rest of the image for names or account details.
Attach the exported copy to your message. Do not pick the original screenshot from your gallery by mistake. The app's checks help with review but can still miss things.
Scan and edit for free. Export needs an active eligible trial or the one-time Cloakshot Pro Lifetime purchase. See Support for access details.
If you already shared a real key
Redacting a later copy does not change the screenshot you already sent. Revoke the exposed credential through the provider that issued it, create a replacement, and update the applications that use it. Follow that provider's instructions for checking recent usage.
For credentials exposed on GitHub, see GitHub's guidance on removing sensitive data. Removing a post or file alone does not revoke a credential.
