For engineers

Hide API keys and customer data when you screen share

Blur credentials before they leak. Blurr auto-detects API keys, secrets, connection strings, tokens and customer records so you can demo, screen-share, and file bug reports without exposing production data.

  • 32 secret-detection presets (Pro)
  • Runs locally in your browser
  • Manifest V3 for Chromium

Updated August 2026

Quick answer

Blurr uses smart keyword redaction with 32 presets to automatically detect and blur API keys, tokens, secrets, connection strings, and customer PII wherever they appear on a page, before you demo, record, or file a bug. The blurs you draw run locally and never leave your browser, and they re-apply before the page paints, so a hot reload never flashes a live credential.

The risk

Engineers stare at secrets all day, then hit “share screen”

A leaked production key is not a typo you can quietly fix. It means rotation, an incident review, and a scramble to work out what was exposed and for how long. Yet keys, tokens, and real customer data sit in plain view across the tools you demo, pair in, and screenshot every day. Scrubbing each screen by hand is exactly the step people skip when they are moving fast.

Keys in plain sight

A live API key on a settings screen, a token in the network tab, or a connection string in a config UI is one screenshot away from being public.

A recorded demo or Loom

You scrub through a feature walkthrough and a .env file or a JWT in DevTools sits in frame for the whole clip, forwarded to who-knows-where.

Real PII in the admin panel

Filing a bug against a production admin panel means a table of real customer names, emails, and IDs rides along in the attachment.

How Blurr helps

Blur credentials before they ever leave your screen

Blurr recognizes the shapes of secrets and frosts them automatically, then lets you click-to-blur anything bespoke. Set your presets once and every demo, pairing session, and bug report starts safe by default. The whole engine runs locally in your browser.

32 secret-aware presets

Match the shapes of API keys, tokens, card numbers, IBANs, SSNs, and crypto wallet addresses out of the box: no rules to write for the common cases.

Local-first by design

The regions you draw are applied with CSS and never leave your browser. Blurr never screenshots, reads, or uploads the page you are working on.

Survives hot reloads

Blurs re-apply before the page paints, so a dev-server rebuild or a single-page-app re-render never flashes a live key in the middle of a demo.

Hide whole customer records

Click a row, a card, or a table to blur it instantly, holding Alt and scrolling to grow the selection to exactly the data you need to cover.

Auto-Blur avatars & media

Frost every avatar, image, and ad in an admin panel so a user table full of real people stays anonymous on screen.

Custom patterns, your rules

Blur anything containing sk_live, a postgres:// connection string, or an internal ID format. Combine terms with AND, OR, and NOT.

Step by step

Hide credentials before a demo in five steps

Configure your presets once; every session after that starts protected.

  1. 1

    Add your secret presets and keywords

    Turn on the presets for API keys, tokens, and cards, and add custom patterns like sk_live or a postgres:// string once.

  2. 2

    Open the Blurr toolbar

    Press Ctrl + Shift + Y (Cmd + Shift + Y on Mac) or click the Blurr icon on the dashboard, admin panel, or DevTools view you are about to show.

  3. 3

    Let keyword redaction sweep the page

    Every matching credential and identifier is frosted wherever it appears, so you never hunt for each one by hand.

  4. 4

    Click-to-blur anything it misses

    Click a customer row or a config card the presets do not cover to hide it instantly, and dial the intensity up.

  5. 5

    Demo, record, or file the bug

    Screen-share, capture a Loom, or attach a screenshot knowing production credentials and PII stay covered.

FAQ

Blurring for engineers, answered

Can Blurr automatically detect and blur API keys and secrets?
Yes. Smart keyword redaction ships with 32 presets that match common secret formats (API keys, tokens, card numbers, IBANs, SSNs, and crypto wallet addresses), and you can add your own patterns with AND/OR/NOT logic, such as blurring anything containing sk_live or a postgres:// connection string. Keyword redaction is part of Pro, and every new account starts with a 3-day Pro trial.
Is it safe to use on pages that show production credentials?
The blurs you draw are applied locally with CSS and never leave your browser. Blurr never screenshots, reads, or uploads the page. Your keyword rules do sync across your devices when you sign in for Pro, while the drawn regions and the blur engine itself stay on your machine.
Will a hot reload flash my keys during a demo?
No. Blurr re-applies saved blurs before the page paints, so when your local dev server hot-reloads or a single-page app re-renders, the API keys and secrets stay frosted with no flash of the raw values.
Can I hide customer records and avatars in an admin panel?
Yes. Click any element (a row, a card, or a whole table) to blur it, holding Alt and scrolling to grow the selection, and turn on Auto-Blur to frost every avatar and image. Combined with keyword redaction for emails and IDs, you can demo an admin panel full of real customer data safely.

Launching soon on the Chrome Web Store

Blur it before you share it.

Be first to know when Blurr lands. Drop your email and we’ll send you the install link the day it goes live.

  • Free to use
  • No account for core features
  • Chrome, Edge, Brave & Arc