
Offsend Browser Extension
Mask secrets before they reach ChatGPT, Claude, or Gemini.
FreeAISecurityOpen Source8,274 impressions#1 of its week5 comments
Comments
>log in to comment- yy liao· 3mo ago
This is exactly what the market needs right now. Keep up the great work!
- Zain Sheikh· 3mo ago
A local-first extension that scrubs secrets before they ever hit ChatGPT or Claude is exactly the guardrail most teams are missing right now. Does it let you define custom redaction patterns for internal token formats?
Yes, if you paste a code block into the prompt editor, Offsend scans it as part of the prompt before it is sent. This includes things like configs, stack traces, JSON, .env snippets, API responses, and code blocks. They are treated as plain text. It does not scan uploaded files or attachments in the browser extension. Right now the extension focuses on copy-paste and typed prompts in ChatGPT, Claude, and Gemini. A version that can scan uploaded files is planned. Workflows with files and documents are being considered separately.
- PDFops· 3mo ago
Masking prompts before they reach the model is the right layer for this — server-side DLP always misses the copy-paste path. Two things I'd want to know: (1) how does it decide what's a secret — fixed denylist, regex/entropy heuristics, or user-defined patterns? Entropy alone over-flags base64/UUIDs; a denylist misses the novel key format. (2) Is it one-way redaction, or does it re-map the placeholder back to the real value when the model echoes it? One-way is fine for pasting a config, but anything conversational needs the round-trip. Open-source + local is exactly how a tool like this earns trust — starring it.
- Zain Sheikh· 3mo ago
Local-first scanning with no server-side analysis is exactly the right approach for keeping secrets out of AI chats - does it also cover pasted code blocks?
Offsend is a local-first browser extension that detects and masks secrets in prompts before they reach AI chat services.
- for
- Developers and teams who paste code, logs or data into AI chat tools.
- pricing
- free
- license
- Apache-2.0
Key features
- Local detection — Scans prompts in the browser without sending data to any server.
- Automatic masking — Replaces detected secrets with readable placeholders like {{API_KEY_1}}.
- Restore capability — Keeps encrypted, time-limited mappings to restore original values locally.
- Custom rules — Add JavaScript regex patterns to detect organization-specific secrets.
- Mode selection — Choose Warn, Auto-mask, or Block behavior when secrets are found.
- Built-in detectors — Detect emails, phones, API keys, tokens, private keys, credit cards, IPs, UUIDs and more.
Use cases
- Paste a stack trace containing API keys into ChatGPT without exposing them
- Share a config file snippet with private tokens in Claude while keeping it readable
- Review logs in Gemini and automatically mask any credit-card numbers before sending
Offsend Browser Extension FAQ
Does Offsend upload my prompts or detected secrets?+
No, all detection, masking and restore operations run locally in the browser and never leave the device.
Can I customize what the extension detects?+
Yes, you can add custom JavaScript regex patterns that run alongside the built-in detectors.
What happens if I choose the Block mode?+
The extension stops the prompt from being sent until you mask or remove the detected secrets.
Is an account required to use Offsend?+
No, the extension is free, requires no account and is open source under Apache-2.0.
How long are the encrypted restore mappings kept?+
They are stored locally for a time window you choose and then expire.
Summarized by DevHunt from offsend.io · Sep 27, 2026. Details may change; check the official site.








