Last reviewed: August 28, 2026
A terminal, dashboard, commit, or browser screenshot can be useful in a bug report while also exposing an API key, bearer token, password, internal URL, or customer data. The safest option is to rotate an exposed secret first. Before you share the screenshot, PrivaCanvas can help you make a separate redacted PNG locally in your browser.
PrivaCanvas does not currently read text or automatically find keys. Draw the areas to hide yourself, then review the exported image. That keeps the workflow local and prevents an automatic scanner from being mistaken for a security guarantee.
.env values, browser address bars,
request headers, sidebars, notifications, and console output often contain
unrelated secrets.If a live credential was already visible to someone unauthorized, treat it as exposed and rotate or revoke it through the provider. Redacting a later screenshot cannot undo the original exposure.
Blur and pixelation preserve transformed versions of the original pixels. They can be suitable when visual context matters, but not for passwords, API keys, JWTs, private URLs, account numbers, or recovery codes. Blackout replaces the selected output pixels with a solid color, then the final PNG is flattened.
See Blur vs. Pixelate vs. Blackout for a practical comparison of the three methods.
.env filesUse the broader screenshot-redaction guide when the image contains names, addresses, chats, or other private details in addition to developer credentials.
No. The editor opens the image and applies masks in your browser. PrivaCanvas does not provide an image-upload endpoint for this workflow.
No. It has local face detection only; there is no OCR or key scanner. Manual review is intentional and remains necessary for every screenshot.
No. The export is a new, flattened PNG. The blackout, blur, or pixelation is rendered into its pixels rather than saved as an editable overlay.