A public GitHub issue with a sharp stack trace and a live sk_live_ in the address bar is two bug reports: one for the product, and one for whoever scrapes credential patterns out of image attachments. Secret scanning watches text in repos. It does not read the PNG you pasted into Discord, the vendor portal, or a Slack thread that later gets exported.
This page owns the bug-report credential job: opaque bar over every API key, token, cookie, and .env line that appears in the frame, then rotate the credential anyway. Soft blur on a key is still a key. The character shapes survive, the prefix is known, and the length is visible. Treat the screenshot as a second leak channel, not as a substitute for rotation.
Open larger image in a new tabWhat to hide before you file
Walk the frame the way an attacker would scrape it: prefixes first, then chrome, then scrollback. Write reproduction steps in text. Use the image for the layout bug or console error only.
Open larger image in a new tab- API keys, personal access tokens, and cloud access keys:
sk_live_,AKIA,ghp_,xoxb-, and anything else with a recognisable prefix. .envfiles,secrets.json, and config panes with real values, including the “example” ones you never changed.- Authorization headers, cookies, and JWT fragments in the DevTools Network panel. A JWT can decode to a user ID and an expiry with no signing key at all.
- URL query tokens, magic-link paths, and pre-signed storage URLs in the address bar.
- Local paths with your username, internal hostnames, and the customer name that often sits in a tenant subdomain.
- Customer emails or IDs sitting in “dummy” fixture rows that turned out to be production data.
- Terminal scrollback above the error, which frequently includes the command that exported the key in the first place.
Cover the entire address bar when query strings carry tokens, not just the tab title. A partial bar that shows the domain and hides the path still shows length and often a recognisable route pattern.
How to hide an API key before a bug report
Crop to the stack trace or broken UI. Use Black bar on keys, tokens, cookies, and the full address bar. Soft smear is the wrong tool for credentials. Rotate after you send.
In BlurThis
Open the screenshot blur tool. These steps are credential-specific:
- Crop or paste so only the error layout remains. Drop the file into the tab. Editing stays in the browser.
- Select Black bar and Box. Paint an opaque rectangle over every
sk_,AKIA, bearer token, cookie value, and the full address bar. - Optional: run Find text as a first pass, then walk the frame yourself for headers and the taskbar.
- Zoom to full size. If any glyph silhouette remains, widen the bar. Download PNG, attach that file, then rotate the credential in the provider console.
Why blur and star-masks fail on keys
A credential is the worst possible case for blur. It is high-contrast monospace text in a known font, drawn from a small alphabet, with a known prefix and a known length. Averaging neighbouring pixels leaves the silhouette of each glyph. Research on recovering text from blurred and pixelated images has shown high accuracy on exactly this kind of input. Scanners do not even need a perfect recovery: a partial key plus a known prefix narrows a brute-force search enormously.
Star-masking the middle of the key (sk_live_4e…9Xk2) is the same mistake with better manners. It reveals the prefix, the suffix, and the length. Many providers' dashboards show exactly those characters, so a leaked prefix-suffix pair identifies which key it was. Paint an opaque bar over the whole string, or crop the panel out. Why a bar beats every other cover for short secrets is spelled out in blur versus black bar.
DevTools and terminal captures
The Network panel is the most dangerous screenshot a developer takes. One request row expands to show cookies, an Authorization header, the full URL with its query string, and often a response body containing the user's email. Before you capture, click the request you need and collapse the rest. Better still, copy the relevant header names into text and redact values there. If you must screenshot the panel, bar the Headers section in full, not line by line.
Terminal captures leak through scrollback and through the prompt. A prompt that shows user@hostname:~/clients/acme-corp names you, your machine, and your customer before the error even begins. Clear the terminal, re-run the failing command, and capture only that. Container and cloud CLIs echo account IDs and region names constantly. Treat an AWS account ID or a project ID as sensitive in a public issue.
Screen recordings of a bug
A clip leaks everything a screenshot does, on every frame, plus the autocomplete dropdown that surfaced a customer email while you typed. Trim to the failure. Pixelate or bar the address bar for the whole clip if you cannot crop it. Check frame by frame at the start and end of every cover segment. The video workflow, including the support-ticket checklist, is in how to blur part of a video online.
Rotate after any doubtful cover
If a character of the key peeked out, treat it as leaked. OWASP's secrets guidance treats rotation as a core control: a stolen credential should stop working quickly. Create a replacement with least privilege, update every environment that used the old value, then revoke the old key in the provider console. Post the follow-up with a clean snip.
GitHub secret scanning will alert you and, for some providers, revoke the key automatically when a key lands in a public repo. That pipeline does not read images, does not cover Slack thumbnails or email previews, and does not help with a vendor's ticket portal. Rotation is the only step that actually closes the door, and it usually takes a few minutes.
Where to redact without another leak
Do not fix a credential leak by uploading the screenshot to an online “redaction” service that processes files on its server. You have just sent the key to a second stranger. Paint the bar on your own machine: Paint, Preview, or a browser tool that works on a canvas in the tab. BlurThis is the canvas kind. Save as PNG so compression ringing cannot outline the glyphs under a bar. Details on export format sit in JPEG vs PNG for redacted screenshots.
FAQ: The key was already in the repo, does the PNG matter?
Yes. A screenshot is a second channel with previews in email and mobile notifications, and it will be indexed by the issue tracker's search. Rotate either way.
FAQ: Can I star-out the middle of the key?
No. Paint an opaque bar over the whole string, or crop the panel out. Partial masks still leak length and prefixes, and a known prefix plus suffix often identifies the exact key in a dashboard.
FAQ: What about test or sandbox keys?
Bar them too. Test keys still authenticate to a sandbox that may hold realistic data, and the habit of deciding per key is how a live key slips through. Treat every string with a credential prefix the same way.
FAQ: Is it safe to share a screenshot in a private Slack?
Safer than a public issue, not safe. Slack retains messages and thumbnails, exports them on request, and integrations can read channels. Bar the key before it goes anywhere, private or not.





