# Secret redaction

Mask credentials in tool outputs before they reach the model or the user.

Source: https://usezn.com/docs/zn-gate/redaction/

Tools often return more than they should: API responses with keys, files with tokens, sub-agent output with credentials. zn-gate can mask them before the text goes back into the model context.

## Mask a guarded tool's output

```python
from zn_gate import guard

@guard(mask_secrets=True)
def fetch_credentials():
    return "API response: sk-proj-1234567890abcdef..."

print(fetch_credentials())
# API response: [REDACTED_OPENAI_KEY]
```

## Sanitize any payload

```python
from zn_gate import redact_secrets, sanitize_tool_result

redacted_text, found = redact_secrets(raw_text)
print(redacted_text, len(found), "secrets masked")

clean = sanitize_tool_result("db_query", untrusted_output)
if clean["safe_to_ingest"]:
    llm.invoke(clean["sanitized_content"])
```

`sanitize_tool_result` both masks secrets and checks the output for indirect prompt injection, so a poisoned web page or database row is flagged before the model reads it.
