Check prompts for secrets and personal data in your own app
The EraseAI API runs the same detection rules as the Chrome extension and the Android app. Send it text before you pass it to a model, and it returns what it found: API keys, passwords, card numbers, emails, phone numbers and other personal data. Or ask it to return the text with those values masked.
Detection is rules-based: patterns plus validators such as the Luhn checksum for card numbers. There is no language model in the loop, so results are consistent, fast and explainable. It will miss secrets it has no pattern for, and it can flag harmless text.
One header
Bearer API key. Keys start with eak_.
Three endpoints
ping, analyze and sanitize. JSON in, JSON out.
Built-in limits
10,000 characters per request and 60 requests a minute per key.
Get a key
API access is included from the Pro plan ($19 a month: 5 keys, 10,000 requests a month) and with Teams/Family (20 keys, 100,000 requests a month, shared). Create an account, choose a plan, then generate a key in your dashboard. Keep it on your server, in an environment variable, never in browser code. See plans and pricing.
Revoke a key at any time; it stops working immediately.
Check the connection
GET /api/dev/ping confirms that the service is up and, with your key, which plan the key belongs to. It does not count as a scan.
curl -H "Authorization: Bearer eak_your_api_key" https://eraseai.ai/api/dev/pingAnalyze text
POST /api/dev/analyze with { "text": "..." } returns a risk score, a level (safe, caution or danger), each issue with its position in the text, and suggested actions. Issues include the matched text, so treat the response as sensitive.
curl -X POST https://eraseai.ai/api/dev/analyze \
-H "Authorization: Bearer eak_your_api_key" \
-H "Content-Type: application/json" \
-d '{"text": "My AWS key is AKIAIOSFODNN7EXAMPLE, email me at jo@example.com"}'{
"riskScore": 40,
"level": "caution",
"issues": [
{
"category": "secret_exposure",
"severity": "high",
"detail": "AWS Access Key: detected in input",
"match": "AKIAIOSFODNN7EXAMPLE",
"start": 14,
"end": 34
},
{
"category": "pii",
"severity": "high",
"detail": "Email address found in prompt",
"match": "jo@example.com",
"start": 48,
"end": 62
}
],
"suggestions": [ { "category": "secret_exposure", "action": "...", "detail": "..." } ],
"summary": "Found 3 issues: 2 secret exposure, 1 pii.",
"meta": { "version": "1.0", "timestamp": "...", "requestId": "..." }
}Sanitize text
POST /api/dev/sanitize takes the same body and returns the text with detected values masked, plus the list of changes. Send the sanitized text to your model instead of the original. Each change lists the original value, so keep the response on your server.
curl -X POST https://eraseai.ai/api/dev/sanitize \
-H "Authorization: Bearer eak_your_api_key" \
-H "Content-Type: application/json" \
-d '{"text": "Reset the password for jo@example.com, key AKIAIOSFODNN7EXAMPLE"}'{
"sanitized": "Reset the password for jo@e******.com, key AKIA************MPLE",
"changes": [
{ "category": "secret_exposure", "original": "jo@example.com",
"replacement": "jo@e******.com", "start": 23, "end": 37 },
{ "category": "secret_exposure", "original": "AKIAIOSFODNN7EXAMPLE",
"replacement": "AKIA************MPLE", "start": 43, "end": 63 }
],
"changeCount": 2,
"meta": { "version": "1.0", "timestamp": "...", "requestId": "..." }
}In your code
// Check a prompt before you send it to any model
async function checkPrompt(text) {
const res = await fetch("https://eraseai.ai/api/dev/analyze", {
method: "POST",
headers: {
Authorization: `Bearer ${process.env.ERASEAI_API_KEY}`,
"Content-Type": "application/json",
},
body: JSON.stringify({ text }),
});
if (!res.ok) throw new Error((await res.json()).code);
return res.json(); // { riskScore, level, issues, ... }
}import os, requests
def check_prompt(text):
r = requests.post(
"https://eraseai.ai/api/dev/analyze",
headers={"Authorization": f"Bearer {os.environ['ERASEAI_API_KEY']}"},
json={"text": text},
timeout=10,
)
r.raise_for_status()
return r.json() # riskScore, level, issues, ...Errors
Errors are JSON with an error message and a stable code. Branch on the code, not the message.
| Status | Code | Meaning |
|---|---|---|
| 400 | INVALID_INPUT | text is missing or is not a string |
| 400 | INPUT_TOO_LONG | text is longer than 10,000 characters |
| 401 | AUTH_REQUIRED / AUTH_INVALID_KEY / AUTH_REVOKED_KEY | missing, unknown or revoked key |
| 429 | RATE_LIMIT_EXCEEDED | free-trial scans used up, or more than 60 requests a minute on one key |
What we keep
Requests are sent over HTTPS. Your scan history stores only the first 500 characters of each request, with keys, tokens and passwords masked, so you can review what was caught. Details are in the privacy policy.