Redact PII
POST /api/redactMask emails, phone numbers, credit-card-like numbers, IPs, and SSNs in text. Send POST /api/redact with the required field text and pay $0.002 per call over x402 or MPP, or call it free by solving a proof-of-work challenge. It returns a JSON object with result and counts.
Returns the redacted text and counts by type.
Parameters
| Name | Type | Required | Description |
|---|---|---|---|
text | string | yes | Also accepted as content, str, string, input, body, data. |
Example request
curl -i -X POST https://agent402.tools/api/redact \
-H "Content-Type: application/json" \
-d '{"text":"reach me at ada@x.com or 555-123-4567"}'
Without payment this returns HTTP 402 Payment Required with the exact price for redact; any x402 v2 or MPP client pays it and retries.
Example response
{
"result": "reach me at [EMAIL] or [PHONE]",
"counts": {
"email": 1,
"phone": 1
}
}
| Field | Type | Always present | In the example |
|---|---|---|---|
result | string | yes | reach me at [EMAIL] or [PHONE] |
counts | object | yes | 2 fields: email, phone |
From an MCP client
catalog.call {
"slug": "redact",
"params": {
"text": "reach me at ada@x.com or 555-123-4567"
}
}
On the hosted connector at https://agent402.tools/mcp, catalog.call runs redact free (rate-limited, no wallet). Local install: npx -y agent402-mcp.
Errors and behavior
textis required. An input the tool rejects returns an HTTP 4xx whose body carrieserror,tool,expected,requiredandexample, so the caller can correct it.- A paid call that ends in any status of 400 or above is not charged over x402, MPP or a prepaid credits key: settlement is cancelled when the tool fails. The exception is a Tempo push credential, a transfer the buyer sent before the call: it settles before the tool runs, so if the tool then fails the payment is recorded as a refund owed to the paying wallet.
- Free tier: no outbound network call leaves the server for this tool, so proof-of-work (16 leading zero bits of sha256) pays for it.
- A
GETorHEADto /api/redact returns the same 402 quote, so the price can be read without a body. - An
Idempotency-Keyheader makes a retried paid call replay the first 200 instead of charging again (an answer larger than 1 MB is not replayed).
Paid call (JavaScript agent)
import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { registerExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";
const client = new x402Client();
client.setSpendControls?.(false); // keep your own spending ceiling in code
registerExactEvmScheme(client, { signer: privateKeyToAccount(KEY) });
const payFetch = wrapFetchWithPayment(fetch, client);
const res = await payFetch("https://agent402.tools/api/redact", {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({
"text": "reach me at ada@x.com or 555-123-4567"
}),
});
No wallet? Pay with compute
Fetch a challenge, solve the sha256 puzzle (16 leading zero bits, a fraction of a second of CPU), and resend with the X-Pow-Solution header:
import { createHash } from "node:crypto";
const lz = (b) => { let t = 0; for (const x of b) { if (!x) { t += 8; continue; } t += Math.clz32(x) - 24; break; } return t; };
const c = await (await fetch("https://agent402.tools/api/pow/challenge?slug=redact")).json();
let n = 0;
while (lz(createHash("sha256").update(c.challenge + ":" + n).digest()) < c.difficulty) n++;
await fetch("https://agent402.tools/api/redact", { method: "POST", headers: { "X-Pow-Solution": c.token + ":" + n, "Content-Type": "application/json" }, body: JSON.stringify({"text":"reach me at ada@x.com or 555-123-4567"}) });
Part of these workflows
Redact PII is one step in these 2 skill packs, each sold as a single call:
- Text hygiene - Turn a wall of dirty text - chat logs, scraped pages, user-generated content, log dumps - into something safe to store, search, and pipe into the next step. Measure first, redact PII before anything else touches the data, then dedupe, sort, extract entities, surface keywords, and grade the readability of what's left.
- Webhook secure intake - The production ingest path for every incoming webhook: verify the provider signature (GitHub / Stripe / Shopify / Slack, constant-time, replay-window enforced), schema-validate the now-trusted body against the provider envelope, fingerprint the raw bytes for redelivery dedup, normalize the event timestamp to UTC + epoch, and redact PII before anything hits a log. Five pure-CPU tools - the accept-or-reject gate, run on every event.
Related tools
Case convert
POST /api/caseConvert text between camelCase, PascalCase, snake_case, kebab-case, CONSTANT_CASE, Title Case, lower, UPPER.
Count
POST /api/countCount characters, words, lines, and (optionally) occurrences of a substring in text.
Dedupe lines
POST /api/dedupe-linesRemove duplicate lines, preserving first-seen order. Returns the deduped text and how many were removed.
Extract entities
POST /api/extract-entitiesPull emails, URLs, IPv4s, @mentions, and #hashtags out of free text. Returns deduped lists.
Keyword extraction
POST /api/keywordsTop keywords and two-word phrases by frequency (stopwords removed). Cheap, deterministic signal for routing, tagging, an…
Edit distance
POST /api/levenshteinLevenshtein edit distance between two strings, plus a 0-1 similarity ratio.