> ## Documentation Index
> Fetch the complete documentation index at: https://envtrap.vercel.app/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Terminal Streams Channel

> How envtrap scans and redacts secrets from stdout and stderr console streams in real time.

# Terminal Streams Channel (`stdout`, `stderr`)

* **Default Mode**: `"warn"`
* **Target**: `process.stdout` and `process.stderr` pipes from the child process.

Logging frameworks, crash reporters, and debug statements frequently dump full request payloads or environment objects to terminal streams. The `stdout` and `stderr` channels inspect these streams and redact active secrets.

***

## Real-Time SHA-256 Redaction

When a secret value appears in standard output or error:

1. `envtrap` replaces the secret value inline with its non-reversible truncated SHA-256 digest:
   ```text theme={null}
   Bearer [REDACTED: SHA256:56018fa5]
   ```
2. The redacted stream is forwarded to the parent terminal.
3. Raw secret values are never printed to the screen or recorded in log files.

***

## Enforcement Modes

<Tabs>
  <Tab title="warn (Default)">
    Redacts secrets from the stream output, logs a leak incident, and allows the application process to continue running normally.
  </Tab>

  <Tab title="block">
    Immediately sends `SIGTERM` to the child process upon the first detected leak, terminating execution before further output can be printed.
  </Tab>

  <Tab title="off">
    Disables stream scanning. Output passes through unredacted.
  </Tab>
</Tabs>

***

## Child-Level Pre-Redaction & Fast-Path

If output originates from a test file or script matching `exclusions.paths`, `hooks.mjs` pre-redacts the string inside the child process to `[REDACTED: PATH_EXCLUDED]`. Because the parent stream scanner receives an already-sanitized string, no alerts or warnings are raised.

### Zero-Overhead Fast-Path (v3.1)

* **Stack Inspection Bypass**: In v3.1, stack frame parsing is completely skipped if no `exclusions.paths` are configured in `envtrap.json`, or if the chunk does not contain any registered secret values. This ensures near-zero CPU and latency overhead on high-throughput console logging.
* **Double-Wrapping Guard**: `process.stdout.write` and `process.stderr.write` hooks include an unwrap guard and recursion flag to prevent multiple wrapping layers or infinite loops when logger libraries wrap streams.

***

## Configuration Example

```json envtrap.json theme={null}
{
  "channels": {
    "stdout": "warn",
    "stderr": "warn"
  }
}
```


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.