Mask secrets before
you hit send.

Catches secrets in your prompts and masks them locally — before ChatGPT, Claude, or Gemini see them.

Offsend browser extension detecting and masking an email and API key in ChatGPT before send
Free · No account · Open source (Apache-2.0)

Works with

  • ChatGPT
  • Claude
  • Gemini
  • Grok
  • Perplexity
  • DeepSeek

How it works

Scan locally as you type. Review matches, mask what you choose, restore when you need.

Offsend extension review dialog with checkboxes to disable masking for individual sensitive values

Review

See every sensitive match before send and uncheck any value you want to keep.

  • Only checked values are replaced with placeholders.
  • Cancel, send anyway, or mask and send.
Offsend extension detector settings for emails, API keys, tokens, and more

Detectors

Toggle built-in scanners for the data that most often leaks into AI chats.

  • Emails, phones, API keys, tokens, private keys.
  • Credit cards, IP addresses, UUIDs, and more.
Offsend extension mode settings: Warn, Auto-mask, and Block

Mode

Choose how Offsend reacts when sensitive data appears in a prompt.

  • Warn — review before send.
  • Auto-mask — mask and notify.
  • Block — stop until masked.
Offsend extension restore window setting for encrypted masking mappings

Masking

Secrets become placeholders like {{API_KEY_1}} so prompts stay readable.

  • Encrypted mappings stay local for a window you choose.
  • Restore originals until the timer expires.

Custom rules

Built-in detectors cover common leaks, but every team has its own formats. Add JavaScript regex patterns that run alongside them — and toggle Custom rules under Detectors when you want them active.

  • Match internal IDs, ticket prefixes, or proprietary tokens.
  • Enter patterns without /.../ delimiters.
  • Runs locally with the rest of Offsend detection.
Offsend extension custom rules settings for adding JavaScript regex patterns

FAQ

Which AI chat sites does the extension support?

The extension targets major browser AI chats: ChatGPT, Claude, Gemini, Grok, Perplexity, and DeepSeek. It watches prompts and attached files on those surfaces before you send. Repo-side AI context boundaries still belong in .offsend.yml via the CLI, macOS app, or GitHub Action — the extension covers the browser path.

Does it upload prompts or detected values?

No. Detection, masking, and restore run locally in the browser. Offsend does not upload prompts, file bodies, or matched secrets to Offsend servers. That matches the local-first posture of the CLI and macOS app.

How does mask and restore work?

When a detector matches — API keys, tokens, private keys, emails, or similar — the extension can mask the value before send and keep a local restore path so you can recover what you masked when you still need it. Restore is local and time-bounded; treat it as convenience, not a vault.

Extension vs Desktop vs CLI?

Use the extension for secrets in browser AI chats. Use Desktop for files, folders, and Safe Paste on macOS. Use the CLI (and GitHub Action) for repository .offsend.yml policy, ignore rules, and runtime gates in coding agents. Same product family, different AI-context paths.

Is the extension a substitute for .offsend.yml?

No. The extension does not replace repository policy. Coding agents still read workspace files; .offsend.yml plus CLI hooks remain the boundary for that path. Pair the extension with Check or the CLI when you care about both browser prompts and repo context.

Install the extension

Free. No account.
Mask secrets before they reach ChatGPT, Claude, Gemini, and more.

Free · No account · Open source (Apache-2.0)