Redaction
How the SDK masks sensitive data before anything leaves the browser. Default patterns, per-element overrides, and what's on the roadmap.
Every captured event passes through the redaction pipeline in the browser before being added to the upload buffer. Original sensitive values never leave the browser.
Default patterns
The SDK ships with regex patterns for the most common sensitive fields:
- Email addresses — RFC 5322-ish pattern, masks the local-part.
- Credit card numbers — Luhn-validated 13-19 digit sequences.
- SSNs —
xxx-xx-xxxxand the 9-digit unbroken form. - JWT tokens —
eyJprefix + base64-of-base64. - Bearer tokens —
Authorization: Bearer ...headers in network captures. - API keys — common prefixes:
sk_,pk_,proj_,key_, etc.
Each match is replaced with [redacted] in the captured event. The replacement is deterministic — the same input redacts to the same output, so engineers triaging the replay can see "the user typed an email here" without seeing which one.
Per-element overrides
Tag elements in your DOM to control what's captured at the element level:
data-bugjar-block— the element is excluded entirely from capture. Not even its layout is recorded. Attribute presence is enough (no value needed); rrweb matches it as a CSS attribute selector.data-bugjar-mask— the element's layout is captured but its text/value content is masked. Same presence-only semantics asblock.data-bugjar-capture="true"— opposite of mask: explicitly OK to capture this element verbatim, even if a default pattern would match. The value must be the literal string"true"— the SDK does a strict equality check (a bare boolean attribute resolves to""and won't opt out).
Example:
<input type="text" name="ssn" data-bugjar-mask />
<div data-bugjar-block>
<p>This entire section is not recorded — including layout.</p>
</div>
<code data-bugjar-capture="true">this code block is captured verbatim</code>
Custom regex extensions (coming soon)
Per-project regex patterns will let you mask industry-specific data — PCI tokens, SWIFT codes, internal employee IDs, contract numbers — alongside the 16 built-in categories. The dashboard surface and SDK plumbing are pending; until then the built-in set is the full list, and the data-bugjar-mask / data-bugjar-block annotations above are the recommended path for app-specific masking.