Secret Serialization Review
Find credentials that can leak because a type serializes itself and something upstream serializes whole objects.
A leak usually needs two changes that each look safe alone:
Finds secrets, tokens, passwords, and API keys that can leak through generated serialization: Python dataclass repr and asdict, attrs, pydantic model_dump, NamedTuple, JavaScript JSON.stringify and util.inspect, structured logs, tracing spans, and error reports. Use when asked to "check for secret serialization", "credential in repr", "repr=False audit", "secret in spans", "token in logs", or when a change adds a credential field to a dataclass, model, or config object, or adds code that stringifies whole objects or every kwarg into telemetry.
Permissions
Files
Finds secrets, tokens, passwords, and API keys that can leak through generated serialization: Python dataclass repr and asdict, attrs, pydantic model_dump, NamedTuple, JavaScript JSON.stringify and util.inspect, structured logs, tracing spans, and error reports. Use when asked to "check for secret serialization", "credential in repr", "repr=False audit", "secret in spans", "token in logs", or when a change adds a credential field to a dataclass, model, or config object, or adds code that stringifies whole objects or every kwarg into telemetry.
Find credentials that can leak because a type serializes itself and something upstream serializes whole objects.
A leak usually needs two changes that each look safe alone:
Version history
repr, str, asdict, model_dump, toJSON, or property enumeration.str(value), span.set_data(key, obj), logger.info("%s", obj), JSON.stringify(args)).The two sides are often written months apart by different authors. Report either side on its own. Always search the existing tree for the other side, because it is frequently already on the default branch and absent from the diff.
security-review. Report them here only when they come from a changed wholesale sink..env files are out of scope.| Reference | Read When |
|---|---|
references/python.md | Reviewing Python dataclasses, attrs, pydantic, NamedTuple, msgspec, logging, Sentry SDK, or OpenTelemetry code |
references/javascript-typescript.md | Reviewing JavaScript or TypeScript classes, config objects, JSON.stringify, util.inspect, pino or winston, or Sentry and OpenTelemetry spans |
Treat a field as credential-bearing when its name, type, or source says so:
secret, token, password, passwd, pwd, api_key, apikey, access_key, private_key, signing_key, client_secret, bearer, credential, authorization, auth_header, cookie, session_key, dsn, connection_string, webhook_secret, hmac, or refresh_token.SecretStr, SecretBytes, or wrappers around them.Separate two kinds of path:
__repr__ and __str__, asdict, model_dump, toJSON, and own-enumerable-property walks (JSON.stringify, util.inspect, spread). They are the holder's responsibility.vars(obj), obj.__dict__, pickle, json.dumps(obj, default=vars). Every stored attribute is exposed this way, whatever flags the field has. Treat these only as sinks: report them when a sink in the repository applies one to a credential-bearing instance.A field is fully excluded when every generated path its type has is blocked, whether by one mechanism or several together. A field is partially excluded when at least one generated path still includes it. No field-level mechanism defeats raw attribute access. Only not storing the value does, so fix raw attribute findings at the sink.
| Mechanism | Blocks | Still includes the field |
|---|---|---|
dataclasses.field(repr=False), attrs.field(repr=False) | __repr__, __str__ | asdict, astuple, raw access |
Pydantic Field(repr=False) | __repr__, __str__ | model_dump, model_dump_json, response serialization, raw access |
Pydantic Field(exclude=True) | model_dump, model_dump_json, response serialization | __repr__, __str__, raw access |
Pydantic Field(repr=False, exclude=True) | Every generated path | Raw access |
JavaScript #private field | Every generated path | Nothing outside the class body |
Object.defineProperty(..., { enumerable: false }) | Every generated path | Explicit property reads, Object.getOwnPropertyNames |
Hand-written __repr__, __str__, toJSON, or [util.inspect.custom] that omits the field | Only the path it overrides (a __repr__ also serves str() when there is no __str__) | Every other generated path, raw access |
Redacting wrapper: SecretStr, SecretBytes, a project Redacted[T] | Every generated path | pickle and recursive __dict__ walks such as default=vars, which reach the value stored inside the wrapper |
| Not stored on the object: read inside the method, or held in a closure | Everything | Nothing |
Do not treat underscore naming, TypeScript private, __slots__, type annotations, comments, dataclass(init=False), or a custom __init__ that still assigns the field as blocking any path.
**kwargs, tool call arguments, task payloads, or middleware reach generic sinks.str(value), repr(, asdict(, model_dump(, set_data(, set_attribute(, set_context(, set_extra(, JSON.stringify(, util.inspect(, loggers called with objects, and raw attribute access (vars(, __dict__, pickle.dumps(, default=vars).| Category | Report When |
|---|---|
| Unexcluded credential field | A credential field is added or moved onto a type with generated serialization, and no mechanism blocks any of its generated paths. |
| Partial exclusion | At least one generated path still includes the field, and a sink in the repository uses that path on instances of the type. |
| Raw attribute sink | A sink applies vars, __dict__, pickle, or default=vars to an instance that stores a credential, even if the field is fully excluded or wrapped. |
| Credential moved onto a holder | A refactor moves a credential from a lazy read or closure onto an object field. |
| Wholesale serialization sink | New or changed telemetry, logging, error-context, cache, or response code serializes every kwarg, every attribute, or whole objects without an allowlist or redaction. |
| Sink loses its filter | A change removes or weakens redaction, an allowlist, or object-to-type-name replacement in an existing sink. |
| Object passed to telemetry | A client, config, or settings object is passed to a span, log, or error-context call that stringifies it. |
| Level | Use For |
|---|---|
| high | The credential reaches a sink anywhere in the repository: log line, span attribute, error event, cache entry, persisted row, queue payload, or API response. The other side may predate the diff. Also a new wholesale sink whose existing callers pass credential-bearing objects. |
| medium | An unexcluded credential field whose instances leave the constructing module, after a repository search found no sink. Also a wholesale sink with no allowlist and no traced credential-bearing caller. |
| low | An unexcluded credential field whose instances never leave the constructing scope. |
__dict__ or enumeration sink.Include one concrete fix per finding:
type(value).__name__ instead of str(value) for non-scalar values.sentry_sdk.serializer.serialize, json.dumps(asdict(obj)), JSON.stringify(obj), util.inspect(obj)) and assert the credential string is absent._shared_secret included in RpcClient dataclass repr".In these kits
More from @sentry
Works with
Claude, Codex, Cursor & more