# PII Redactor — Mask & Restore Text Before the LLM (`hipersoft/pii-redactor`) Actor

Detect and mask PII (emails, phones, credit cards, SSNs, IPs, IBANs, URLs) in text before it reaches an LLM, with a reversible token map to restore it afterwards.

- **URL**: https://apify.com/hipersoft/pii-redactor.md
- **Developed by:** [hiper soft](https://apify.com/hipersoft) (community)
- **Categories:** Developer tools, Other
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $0.001 / text redacted

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.
Since this Actor supports Apify Store discounts, the price gets lower the higher subscription plan you have.

Learn more: https://docs.apify.com/actors/running/actors-in-store.md#pay-per-event

## What's an Apify Actor?

Actors are web data automations that power AI and operations. They run on the Apify platform to scrape websites, process data, connect APIs, and automate workflows.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.
Actors are written with capital "A".

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.
The best way to integrate Actors is as follows.

- **AI agents and MCP clients** — the [Apify MCP server](https://docs.apify.com/integrations/mcp.md) at `https://mcp.apify.com` (remote, streamable HTTP, OAuth on first use).
- **Agentic workflows and local Actor development** — [Agent Skills](https://apify.com/.well-known/agent-skills/index.json) with the [Apify CLI](https://docs.apify.com/cli/docs.md): `npm install -g apify-cli`, then `apify login`.
- **JavaScript/TypeScript projects** — the official [JS/TS client](https://docs.apify.com/api/client/js/docs.md): `npm install apify-client`.
- **Python projects** — the official [Python client](https://docs.apify.com/api/client/python/docs.md): `pip install apify-client`.
- **Any other language** — the [REST API](https://docs.apify.com/api/v2.md).

For usage examples, see the [API](#api) section below.

For more details, see Apify documentation as [Markdown index](https://docs.apify.com/llms.txt) and [Markdown full-text](https://docs.apify.com/llms-full.txt).

# README

## PII Redactor — Mask Before the LLM (Reversible)

**Strip emails, phone numbers, credit cards and other personal data out of your text before it reaches an AI model — then restore it afterwards with a reversible token map.** GDPR-friendly redaction for AI, automation and analytics pipelines.

### What it does

- **Detects and masks PII** — email addresses, phone numbers, credit card numbers, US SSNs, IP addresses, IBANs and URLs.
- **Reversible tokens** — each value becomes a typed token like `[EMAIL_1]` or `[CREDITCARD_1]`, so the text stays readable and the structure survives.
- **One combined token map** — a single reversible map (token → original value) is written to the run's key-value store, so a later step can put the real values back.
- **Two modes** — `mask` (sequential typed tokens) or `hash` (typed tokens with a stable hash).
- **Privacy by default** — the original text is never stored or logged unless you explicitly opt in.

### Use cases

- **Mask before the LLM** — redact prompts before an AI node (OpenAI, Anthropic, etc.), then restore names, emails and numbers in the model's output. Keep raw PII out of third-party models.
- **n8n / Make / Zapier flows** — drop it in as a step: redact before the AI node, restore after. Great for support-ticket, email and document automations.
- **GDPR-friendly logging & analytics** — scrub personal data out of text before it lands in logs, datasets or a warehouse.
- **Safe sharing** — clean transcripts, tickets and messages before handing them to a vendor or teammate.

### Input

```json
{
  "text": "Contact John at john@acme.com or +1 415 555 0132, card 4111 1111 1111 1111",
  "types": ["email", "phone", "creditcard", "ssn", "ip", "iban", "url"],
  "mode": "mask",
  "includeOriginal": false
}
```

| Field | Type | Description |
|---|---|---|
| `text` | string | A single block of text to redact. |
| `items` | array | An array of strings to redact in bulk (one result row each). |
| `types` | array | Which PII to catch: `email`, `phone`, `creditcard`, `ssn`, `ip`, `iban`, `url`. |
| `mode` | string | `mask` (tokens like `[EMAIL_1]`) or `hash` (tokens with a stable hash). |
| `includeOriginal` | boolean | Include the original text in each row. Off by default. |

Provide `text`, `items`, or both.

### Output

Each row is one redacted input:

```json
{
  "ok": true,
  "redacted": "Contact John at [EMAIL_1] or [PHONE_1], card [CREDITCARD_1]",
  "replacements": [
    { "type": "email", "token": "[EMAIL_1]", "value": "john@acme.com" },
    { "type": "phone", "token": "[PHONE_1]", "value": "+1 415 555 0132" },
    { "type": "creditcard", "token": "[CREDITCARD_1]", "value": "4111 1111 1111 1111" }
  ],
  "counts": { "email": 1, "phone": 1, "creditcard": 1 },
  "totalReplacements": 3
}
```

A combined reversible token map is also saved to the run's default key-value store under **`token-map.json`** (`{ "map": { "[EMAIL_1]": "john@acme.com", ... } }`) so a downstream step can restore the originals.

#### Output schema

| Field | Type | Description |
|---|---|---|
| `redacted` | string | The text with PII replaced by tokens. |
| `replacements` | array | Each masked value: `type`, `token` and original `value`. |
| `counts` | object | Number of matches per PII type. |
| `totalReplacements` | integer | Total number of masked values in this item. |
| `original` | string | The original text (only when `includeOriginal` is on). |

### FAQ

**Does it call an AI model or any external service?** No. Detection is local pattern-matching with light validation (for example a Luhn check on card numbers) — nothing leaves the run.

**How do I restore the original values?** Use the `token-map.json` map (token → value) from the key-value store, or the per-row `replacements`, to swap the tokens back after your AI or automation step.

**Can I automate it?** Yes — via [integrations on the Apify platform](https://apify.com/integrations) (n8n, Make, Zapier and more) and the [Apify API](https://docs.apify.com/api/v2).

### Notes

Original clean-room implementation.

# Actor input Schema

## `text` (type: `string`):

A single block of text to scan and redact. You can use this instead of, or together with, the Items list.

## `items` (type: `array`):

An array of text strings to scan and redact, one result row per item. Use this for batch processing (e.g. many messages, rows or documents).

## `types` (type: `array`):

Which kinds of PII to detect. Allowed values: email, phone, creditcard, ssn, ip, iban, url. Leave as the default to catch all supported types.

## `mode` (type: `string`):

How to replace detected PII. Mask uses sequential typed tokens like \[EMAIL\_1]; Hash uses typed tokens with a stable hash of the value. Both are reversible via the token map.

## `includeOriginal` (type: `boolean`):

If enabled, the original (unredacted) text is included in each output row. Off by default so raw PII never leaves the run.

## Actor input object example

```json
{
  "text": "",
  "items": [],
  "types": [
    "email",
    "phone",
    "creditcard",
    "ssn",
    "ip",
    "iban",
    "url"
  ],
  "mode": "mask",
  "includeOriginal": false
}
```

# Actor output Schema

## `results` (type: `string`):

The redacted results as dataset items.

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {};

// Run the Actor and wait for it to finish
const run = await client.actor("hipersoft/pii-redactor").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = {}

# Run the Actor and wait for it to finish
run = client.actor("hipersoft/pii-redactor").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{}' |
apify call hipersoft/pii-redactor --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,hipersoft/pii-redactor"
        }
    }
}

```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/0KFuDiWRoCIpStMFu/builds/udKyBprKUR5Ve0dKw/openapi.json
