Keys in plain sight
A live API key on a settings screen, a token in the network tab, or a connection string in a config UI is one screenshot away from being public.
For engineers
Blur credentials before they leak. Blurr auto-detects API keys, secrets, connection strings, tokens and customer records so you can demo, screen-share, and file bug reports without exposing production data.
Updated August 2026
Quick answer
Blurr uses smart keyword redaction with 32 presets to automatically detect and blur API keys, tokens, secrets, connection strings, and customer PII wherever they appear on a page, before you demo, record, or file a bug. The blurs you draw run locally and never leave your browser, and they re-apply before the page paints, so a hot reload never flashes a live credential.
The risk
A leaked production key is not a typo you can quietly fix. It means rotation, an incident review, and a scramble to work out what was exposed and for how long. Yet keys, tokens, and real customer data sit in plain view across the tools you demo, pair in, and screenshot every day. Scrubbing each screen by hand is exactly the step people skip when they are moving fast.
A live API key on a settings screen, a token in the network tab, or a connection string in a config UI is one screenshot away from being public.
You scrub through a feature walkthrough and a .env file or a JWT in DevTools sits in frame for the whole clip, forwarded to who-knows-where.
Filing a bug against a production admin panel means a table of real customer names, emails, and IDs rides along in the attachment.
How Blurr helps
Blurr recognizes the shapes of secrets and frosts them automatically, then lets you click-to-blur anything bespoke. Set your presets once and every demo, pairing session, and bug report starts safe by default. The whole engine runs locally in your browser.
Match the shapes of API keys, tokens, card numbers, IBANs, SSNs, and crypto wallet addresses out of the box: no rules to write for the common cases.
The regions you draw are applied with CSS and never leave your browser. Blurr never screenshots, reads, or uploads the page you are working on.
Blurs re-apply before the page paints, so a dev-server rebuild or a single-page-app re-render never flashes a live key in the middle of a demo.
Click a row, a card, or a table to blur it instantly, holding Alt and scrolling to grow the selection to exactly the data you need to cover.
Frost every avatar, image, and ad in an admin panel so a user table full of real people stays anonymous on screen.
Blur anything containing sk_live, a postgres:// connection string, or an internal ID format. Combine terms with AND, OR, and NOT.
Step by step
Configure your presets once; every session after that starts protected.
Turn on the presets for API keys, tokens, and cards, and add custom patterns like sk_live or a postgres:// string once.
Press Ctrl + Shift + Y (Cmd + Shift + Y on Mac) or click the Blurr icon on the dashboard, admin panel, or DevTools view you are about to show.
Every matching credential and identifier is frosted wherever it appears, so you never hunt for each one by hand.
Click a customer row or a config card the presets do not cover to hide it instantly, and dial the intensity up.
Screen-share, capture a Loom, or attach a screenshot knowing production credentials and PII stay covered.
Keep exploring
Blurr adapts to whatever you are about to demo, record, or send.
Blur salaries, customer data and dashboards before you present on Zoom, Meet or Teams. Share a tab to hide the browser frame, and mask your other tab titles while you are at it.
Learn moreRedact names, emails and account numbers before you capture a screenshot for docs, tutorials, support tickets or bug reports.
Learn moreAuto-blur images, videos and ads, and hide your own name, email and address so you never dox yourself live on stream or in a tutorial recording.
Learn moreFAQ
Launching soon on the Chrome Web Store
Be first to know when Blurr lands. Drop your email and we’ll send you the install link the day it goes live.