Menu
Masking sensitive data in logs
Hide sensitive fields such as passwords and keys in execution logs with store-level and workflow-specific masking rules.
On this page
What Data Privacy is for
Data Privacy hides sensitive values from your execution logs. You list the fields to mask, for example a password, an API key or a card number, and from then on those values are replaced with a mask when execution details are saved.
Masking is permanent for what it hides. The original value is replaced before the log is stored, so it can't be recovered. It isn't applied to executions that were already saved.
It changes only what is saved in the logs. It doesn't change what your workflow does, passes between steps, or returns to the caller.
Rules belong to the selected store.
Store-level rules
Store-level rules apply to every workflow in the store.
- Under Store-level Rules, enter a field path, for example
$..password, and select Add (or press Enter). - The rule is saved straight away. The count beside the heading shows how many you have.
- Remove a rule with the trash icon. It is removed immediately, without a confirmation.
Workflow-specific rules
Workflow-specific Rules apply to one workflow only.
- Choose a workflow under Select Workflow.
- Enter a field path and select Add.
- Rules are listed under the workflow's name.
Writing a field path
| You write | It masks |
|---|---|
$.password | password at the top level only |
$..password or password | password at any depth, including inside lists |
input.body.password | password at exactly that location |
items[name="Product A"].price | price in the list items whose name is Product A (use double quotes) |
*.password | password inside every top-level object |
Things to know:
- Names without a path (
password) and$..paths ignore upper and lower case. Dotted paths and*match case exactly. - A path that matches nothing is ignored, and doesn't stop other rules from working.
- Letters, numbers and
_ . * [ ] ( ) " ' = $ -are allowed in a path. - Adding a path that is already listed is refused.
The mask value
Mask Value is the text that replaces a hidden value. It defaults to ****** and can be up to 50 characters. Select Update to change it. It applies to all your rules, and you need at least one rule before you can change it.
What gets masked
Masking is applied to the inputs, outputs, data and errors recorded for each step when the execution is saved. Values are masked before the log's previews and sizes are worked out, so those never show the original.
Templates
A template can include masked fields. They are listed on the template page under Data privacy. When you install it, they are added to your store's rules, and your existing rules and mask value are kept. See Templates.
Last updated 9 October 2026