API keys & tokens

How to hide API keys in screenshots

A failed request is useful context for support. The key used to send it usually is not. Before you upload a screenshot to an AI chat, issue tracker, or forum, cover the credential and check for other copies of it.

By Spawn Lau, creator of Cloakshot ·

Look beyond the field named “API key”

Check request headers, terminal output, configuration files, and browser address bars. The same credential can appear twice: once in a settings field and again in a command or error message.

Look for values beside labels such as Authorization, Bearer, api_key, token, and password. Also check connection strings, URL query parameters, and QR codes. Cover the full value, including wrapped lines.

Keep the error message, status code, and setting names when they help explain the problem. Review project IDs, private hostnames, email addresses, and file paths separately; they may reveal details you did not mean to share.

Cover the credential with a solid mask

In Cloakshot, open Settings → Detection and choose Solid black before opening the screenshot for review. Then import the image with Choose images, or send it from a compatible Share menu.

On iPhone, use Edit in Cloakshot from the Share extension for the full scan and editor. On Android, sharing an image to Cloakshot opens the main app.

Check the suggested edits, then open Edit details. Resize each mask to cover the entire credential. Use Add mask if a value is missing from the suggestions. A scan with no findings does not mean there are no secrets in the image.

Before

POST /v1/example
Status: 401 Unauthorized
Authorization: Bearer
EXAMPLE_TOKEN_NOT_A_REAL_KEY

After

POST /v1/example
Status: 401 Unauthorized
Authorization: Bearer
Credential covered

Illustration with a fictional placeholder, not a real key. Cover the credential value; keep the request and error context.

Inspect the exported file

Tap Export in the main app. Cloakshot writes the selected masks into a separate PNG, verifies the selected edits, and scans the copy for remaining high-risk findings before opening the Share menu.

If you save the file first, open that copy and zoom in. Check the ends of each mask, wrapped lines, and any repeated values elsewhere in the screenshot. Look through the rest of the image for names or account details.

Attach the exported copy to your message. Do not pick the original screenshot from your gallery by mistake. The app's checks help with review but can still miss things.

Scan and edit for free. Export needs an active eligible trial or the one-time Cloakshot Pro Lifetime purchase. See Support for access details.

If you already shared a real key

Redacting a later copy does not change the screenshot you already sent. Revoke the exposed credential through the provider that issued it, create a replacement, and update the applications that use it. Follow that provider's instructions for checking recent usage.

For credentials exposed on GitHub, see GitHub's guidance on removing sensitive data. Removing a post or file alone does not revoke a credential.

A Cloakshot API-key example with credential values covered while the surrounding support context remains visible.
Cloakshot can cover credential values while keeping nearby text readable. The example uses fictional data.