-
Notifications
You must be signed in to change notification settings - Fork 0
Home
Ahmet Zeybek edited this page Sep 27, 2026
·
9 revisions
Hide sensitive values in configuration files during screen sharing.
camouflage.nvim is a Neovim plugin that draws a mask over secrets in .env, JSON, YAML, TOML, .properties/INI, .netrc, XML, .http, Terraform/HCL and Dockerfile files. The file itself is never changed.

A .env opening masked, other formats, a value masked as it's typed, reveal and follow-cursor, a yank that asks first, picker rows, terminal output, the audit, and presentation mode. It's recorded from the repository's own fixtures with assets/demo-full.tape.
- Masks values as a file opens, in 10 formats, with full key paths for nested values (
database.connection.password), see Supported File Formats - Covers a value you type, put or paste before Neovim draws it
- Lets you reveal a line on purpose, follow the cursor, or copy a value with a prompt and a timed clear
- Keeps values hidden where the file's text shows up elsewhere: Telescope, Snacks, fzf-lua and mini.pick previews and grep rows, quickfix lists, diffs and
git commit -v, and:terminaloutput if you turn it on, see Integrations -
:CamouflagePresentmasks everything and refuses reveals for the length of a demo, and:CamouflageShieldcovers the whole editor until you press a key - Flags weak values offline (
[weak: default]), shows when a JWT expires ([valid 5h],[expires in 30m]), and checks passwords against Have I Been Pwned when you ask it to -
:CamouflageAuditlists every masked key in a project, never the value, with JSON output and an exit code for CI - Reads a per-project
.camouflage.yaml, including data-only rules for what to mask and how - Comes with a lualine component, events and hooks, custom checks, and an API to register parsers for other formats
- Explains itself:
:checkhealth camouflagesays why a file is or isn't masked, without printing a value
-- lazy.nvim
{
'zeybek/camouflage.nvim',
event = { 'BufReadPre', 'BufNewFile' },
opts = {},
keys = {
{ '<leader>mt', '<cmd>CamouflageToggle<cr>', desc = 'Toggle Camouflage' },
{ '<leader>mr', '<cmd>CamouflageReveal<cr>', desc = 'Reveal Line' },
{ '<leader>my', '<cmd>CamouflageYank<cr>', desc = 'Yank Value' },
{ '<leader>mf', '<cmd>CamouflageFollowCursor<cr>', desc = 'Follow Cursor' },
},
}- Getting Started: Installation, basic setup, and first steps
- Commands and Keymaps: All commands and suggested keybindings
- Supported File Formats: Complete list of supported file types
- Security Model: What visual masking does and does not protect
- Presentation Mode: One command for "I am about to share my screen"
- Screen Shield: Cover the whole editor until a key is pressed
- Workspace Audit: Redacted workspace scanning into quickfix or location-list
-
Custom Patterns: Opt-in patterns for unsupported file types such as
*.myconfig - Custom Parsers: Register your own parsers via the public API
- Configuration: Full configuration reference
-
Project Config: Repo-level
.camouflage.yamlconfiguration - Rule Based Policy: Data-only masking policy for ignore and force-mask rules
- Buffer Local Config: Per-buffer overrides
- Weak Secret Check: Offline quality hints for weak or placeholder secrets
- Have I Been Pwned: Password breach checking integration
-
JWT Expiry Hints: Decode JWT
expclaim and show inline expiry badges - Integrations: Pickers, quickfix, diffs, completion and Lualine
- Terminal Masking: Opt-in masking for command output
- TreeSitter: TreeSitter queries and customization
- API: Lua API reference
- Custom Check API: Trusted sync and async Lua checks
- Events and Hooks: Event system for extending functionality
- Architecture: Internal architecture and code flow
- Troubleshooting: Common issues and solutions