camouflage.nvim
camouflage.nvim hides secrets in config files while you share your screen. It uses Neovim extmarks to draw stars, dots or scrambled text over the values in .env, .json, .yaml, .toml, .properties, .netrc, .xml, .http, Terraform and HCL (.tf, .tfvars, .hcl) and Dockerfiles, and the file itself never changes.
I wrote it after one too many pairing sessions where a .env scrolled past on a shared screen. Masking the file on disk was out of the question, and remembering to close it never worked, so the fix had to be visual and automatic.
What it does
It understands nested keys like database.connection.password in JSON, YAML and XML, and masks strings, numbers and booleans alike. You can reveal a value for a moment, or have the line under the cursor reveal itself as you move. :CamouflageYank copies the real value deliberately, with a confirm prompt and a timed clipboard clear, because yy on a masked line still copies the real text.
A workspace audit lists every supported file in the quickfix window without showing a single value. A small offline check flags weak secrets, placeholders, repeated values and low-entropy tokens, reads the exp claim out of JWTs to tell you "expires in 2h", and, if you opt in, checks passwords against Have I Been Pwned. Parsing goes through TreeSitter where it can, Telescope and Snacks previews are masked too, config reloads live, and there's an API for registering your own parsers and checks.
What it does not do
It's only a visual layer. It protects against shoulder-surfing, screen sharing, screenshots and demos, and nothing else. Grep results, LSP servers, completion sources, AI assistants, :%print, :w and the clipboard registers all see the real text, because it's still there under the mask. Per-repo .camouflage.yaml files are read as data and never executed, and if you don't trust the repos you open, project_config.secure = true puts that file behind Neovim's trust prompt.
Install
With lazy.nvim:
{
"zeybek/camouflage.nvim",
event = { "BufReadPre", "BufNewFile" },
opts = {},
}Open a .env and the values show as stars. :CamouflageToggle turns it off and :CamouflageReveal shows the current line. Everything else (the audit, the checks, the rule-based policy for which paths and keys to mask) is in the README. It needs Neovim 0.9 or newer, and 0.10 for the network checks.