Project
ficta
2026 — present

Secrets that
never leave.

A local secret airlock for coding agents.

ficta intercepts secrets like sk-live-… and ghp_… and swaps them for deterministic placeholders such as <SECRET_01> and <API_KEY> before requests leave your machine. Works with Claude Code, Codex and Pi.

Chapter I
Why

Coding agents are useful precisely because they see your project — but that means your API keys, tokens and connection strings can ride along into a request bound for a model provider. ficta sits between the agent and the provider and makes sure the real values stop at your machine.

It’s deliberately small in scope: personal secret hygiene, not enterprise DLP, not a compliance product, not a sandbox. No telemetry, MIT-licensed, still pre-1.0 beta.

Chapter II
How it works

Swap, then restore.

Four steps, all on your machine.

  • 01DiscoverFind the secrets

    Pulls values from .env / .env.local, Doppler, and secret-like environment variable names — the things that should never be typed into a prompt.

  • 02RedactSwap before it leaves

    Request bodies, query strings and non-auth headers are rewritten, replacing each secret with a deterministic placeholder as traffic passes an ephemeral loopback proxy for the session.

  • 03RestorePut it back locally

    Placeholders in the model’s response are swapped back to the real values on your machine, so the agent keeps working exactly as before.

  • 04Fail closedBlock on leak

    If a protected value would survive redaction in a surface it should have left, ficta blocks the request rather than letting it through.

Chapter III
Honest edges

Works with

Verified against Claude Code, Codex and Pi. IDE clients like Cursor aren’t supported.

Won’t catch

Encoded or split secrets, path-like tokens (unless you opt in), anything sent through tool execution, curl or MCP tools, and binary responses. It protects the request surfaces it can see — no more.

Chapter IV
Try it

Read the source.

Open source on GitHub — install it, or just read how it works.

pnpm add -g @steflsd/ficta