Skip to content

Repository files navigation

Veil

Hide passwords, tokens, and other secrets when you use large models. Works with the tools already on your machine — one-click install.

You drop .env into the chat so it can fix a bug. It does — and the password is already sitting on someone else's server.

Veil hangs in the doorway of this machine. Secrets go out under an alias. When the answer walks back in, the alias is swapped for the original. You still read plaintext. Outside, the model only ever saw aliases.

Download · 中文说明 · Apache-2.0 · no telemetry


In one glance

You type:

check mysql://root:Pass123@10.1.2.3:3306/app, call 13800138000

The model actually receives:

check {{CONNSTR_01ARZ3NDEKTSV4RRFFQ69G5FAV}}, call {{PHONE_01ARZ3NDEKTSV4RRFFQ69G5FAV}}

It can still reason and advise. By the time the reply hits your screen, the DSN and the number are real again.

The same secret keeps the same alias for the whole conversation. It will not split one person into two.

Do not hand Veil a key. Login and tokens stay in the original app. The curtain covers the body; the ID card (auth headers) walks out as-is.


One line, then you are in

irm https://raw.githubusercontent.com/Mouseww/veil/main/scripts/install.ps1 | iex

When the browser opens http://127.0.0.1:18788 , it is installed. In a new terminal:

veil setup

Pick the apps you use. Veil reads each app's current API address (official or a custom relay), opens a local port for it, and points the app there. Different tools, different upstreams — they do not overwrite each other. Restart those apps and chat as usual. Official Claude login needs no extra key.

You can also click Point this app at Veil on the console Upstream tabs. Same result.

Or grab veil-windows-x64.exe from Releases and double-click.


Not on the list? Point it yourself

Veil is not glued to a handful of agents. Any tool that can set a Base URL (or an env var) can walk through.

Change the tool's API address to one of these. Keep the same key:

What the tool speaks Put this
Anthropic (Claude Code and kin) http://127.0.0.1:18787
OpenAI-compatible (Cursor, Codex, most relays) http://127.0.0.1:18787/v1

The console is for you: http://127.0.0.1:18788

Company relay / LiteLLM: set the relay root on the Upstream page; the key in the tool is the relay's key.


You decide who gets an alias

Open the console → Rules.

Out of the box it catches private keys, API keys, tokens, database URLs, login passwords, mainland mobile numbers, national IDs, and IPs. Email is off — too many false hits.

Flip a switch to pause a rule. Open a row to edit the regex, word list, or priority. Add your own at the bottom: project codenames, internal names become {{CODENAME_…}}.

Allowlist strings are never replaced (localhost is already there). If a body cannot be proven clean, Veil returns 502 and does not forward.


Later

Console: Check for updates. Or veil update.

Double-click to start. veil stop to quit. The mapping table is encrypted on disk. Nothing is phoned home.

UI

Dashboard Rules Upstream

Thanks to everyone on LinuxDo for their support!


Apache-2.0.

About

使用大模型时,隐藏你的密码、token 等敏感信息。适配市面上各种工具,一键安装即可用。 / Hide passwords, tokens and secrets from the model. Works with everyday tools — one-click install.

Topics

Resources

Stars

33 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages