{"_id":"@aws-lambda-powertools/data-masking","_rev":"3-2b9bd096f21c060a74c900f3e8de31ce","name":"@aws-lambda-powertools/data-masking","dist-tags":{"pre":"0.0.0","latest":"2.35.0"},"versions":{"0.0.0":{"name":"@aws-lambda-powertools/data-masking","version":"0.0.0","keywords":["aws","lambda","powertools","handler","nodejs","serverless"],"author":{"url":"https://aws.amazon.com","name":"Amazon Web Services"},"license":"MIT-0","_id":"@aws-lambda-powertools/data-masking@0.0.0","maintainers":[{"name":"dreamorosi","email":"dreamorosi@gmail.com"},{"name":"aws-powertools-bot","email":"aws-powertools+npmjs.com@amazon.com"}],"homepage":"https://github.com/aws-powertools/powertools-lambda-typescript","bugs":{"url":"https://github.com/aws-powertools/powertools-lambda-typescript/issues"},"dist":{"shasum":"835061dc60f9f14dfb19294a3491097bde6f1a1d","tarball":"https://registry.npmjs.org/@aws-lambda-powertools/data-masking/-/data-masking-0.0.0.tgz","fileCount":4,"integrity":"sha512-4ocaPm6L/WqZkg545H4WAhjxyI8EzweBwsJxy0KtHNeZIP6mXfG1s+iwse3hlul7CkV2jEyIFj+pQIyzATz/Xw==","signatures":[{"sig":"MEUCIQC9jz1TvFQUp5MZuPhsPm+MdA+uNX5KUYKaz5834qv8iQIgcDLi+KWlNi1WiVyS5TOuHyVdgTAdh+CUumYzPKR/M4U=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1930},"main":"./lib/index.js","types":"./lib/index.d.ts","_npmUser":{"name":"aws-powertools-bot","email":"aws-powertools+npmjs.com@amazon.com"},"repository":{"url":"git+https://github.com/aws-powertools/powertools-lambda-typescript.git","type":"git"},"_npmVersion":"11.13.0","description":"The data masking package for the Powertools for AWS Lambda (TypeScript) library","directories":{},"_nodeVersion":"24.16.0","dependencies":{},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{},"_npmOperationalInternal":{"tmp":"tmp/data-masking_0.0.0_1783519700929_0.04821765519216359","host":"s3://npm-registry-packages-npm-production"}},"2.34.0":{"name":"@aws-lambda-powertools/data-masking","version":"2.34.0","keywords":["aws","lambda","powertools","data-masking","encryption","pii","sensitive-data","nodejs","serverless"],"author":{"url":"https://aws.amazon.com","name":"Amazon Web Services"},"license":"MIT-0","_id":"@aws-lambda-powertools/data-masking@2.34.0","maintainers":[{"name":"dreamorosi","email":"dreamorosi@gmail.com"},{"name":"aws-powertools-bot","email":"aws-powertools+npmjs.com@amazon.com"}],"homepage":"https://github.com/aws-powertools/powertools-lambda-typescript/tree/main/packages/data-masking#readme","bugs":{"url":"https://github.com/aws-powertools/powertools-lambda-typescript/issues"},"dist":{"shasum":"b7a55b4deb39ce53a109c80dd995601f2679c571","tarball":"https://registry.npmjs.org/@aws-lambda-powertools/data-masking/-/data-masking-2.34.0.tgz","fileCount":52,"integrity":"sha512-pzwAkpWirxR7dLD6dbazj7DUTl/pefXb3ikyiUQ+Q2fSdGHhlgrFI73SgD2wKwX52mlyNC4dIaUURG+HTBuU3w==","signatures":[{"sig":"MEUCICyGRSP6YJzk1q0MgJFonrTPxlsds+sOPwkzFXIEOmFQAiEA9HJhEQOafqBibjzV9vhRLHokjE3A3ezSPJ3HLlP+O6Y=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aws-lambda-powertools%2fdata-masking@2.34.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":70711},"main":"./lib/cjs/index.js","type":"module","types":"./lib/cjs/index.d.ts","exports":{".":{"import":{"types":"./lib/esm/index.d.ts","default":"./lib/esm/index.js"},"require":{"types":"./lib/cjs/index.d.ts","default":"./lib/cjs/index.js"}},"./types":{"import":{"types":"./lib/esm/types.d.ts","default":"./lib/esm/types.js"},"require":{"types":"./lib/cjs/types.d.ts","default":"./lib/cjs/types.js"}},"./errors":{"import":{"types":"./lib/esm/errors.d.ts","default":"./lib/esm/errors.js"},"require":{"types":"./lib/cjs/errors.d.ts","default":"./lib/cjs/errors.js"}},"./providers/kms":{"import":{"types":"./lib/esm/providers/kms/index.d.ts","default":"./lib/esm/providers/kms/index.js"},"require":{"types":"./lib/cjs/providers/kms/index.d.ts","default":"./lib/cjs/providers/kms/index.js"}},"./providers/kms/types":{"import":{"types":"./lib/esm/providers/kms/types.d.ts","default":"./lib/esm/providers/kms/types.js"},"require":{"types":"./lib/cjs/providers/kms/types.d.ts","default":"./lib/cjs/providers/kms/types.js"}}},"gitHead":"e8cff7f39f4a4314e878ae3ddb8b99cc0a1d7c5c","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:0eaa49bd-ce1b-4d2b-a71c-a2756fa9f0cd"}},"repository":{"url":"git+https://github.com/aws-powertools/powertools-lambda-typescript.git","type":"git"},"_npmVersion":"11.16.0","description":"A utility for masking and encrypting sensitive data in AWS Lambda functions","directories":{},"_nodeVersion":"24.18.0","dependencies":{"@aws-lambda-powertools/commons":"2.34.0"},"typesVersions":{"*":{"types":["lib/cjs/types.d.ts","lib/esm/types.d.ts"],"errors":["lib/cjs/errors.d.ts","lib/esm/errors.d.ts"],"providers/kms":["lib/cjs/providers/kms/index.d.ts","lib/esm/providers/kms/index.d.ts"],"providers/kms/types":["lib/cjs/providers/kms/types.d.ts","lib/esm/providers/kms/types.d.ts"]}},"_hasShrinkwrap":false,"peerDependencies":{"@aws-crypto/client-node":">=4.x"},"peerDependenciesMeta":{"@aws-crypto/client-node":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/data-masking_2.34.0_1783686756189_0.6623637004688838","host":"s3://npm-registry-packages-npm-production"}},"2.35.0":{"name":"@aws-lambda-powertools/data-masking","version":"2.35.0","description":"A utility for masking and encrypting sensitive data in AWS Lambda functions","author":{"name":"Amazon Web Services","url":"https://aws.amazon.com"},"license":"MIT-0","homepage":"https://github.com/aws-powertools/powertools-lambda-typescript/tree/main/packages/data-masking#readme","repository":{"type":"git","url":"git+https://github.com/aws-powertools/powertools-lambda-typescript.git"},"bugs":{"url":"https://github.com/aws-powertools/powertools-lambda-typescript/issues"},"keywords":["aws","lambda","powertools","data-masking","encryption","pii","sensitive-data","nodejs","serverless"],"dependencies":{"@aws-lambda-powertools/commons":"2.35.0"},"peerDependencies":{"@aws-crypto/client-node":">=4.x"},"peerDependenciesMeta":{"@aws-crypto/client-node":{"optional":true}},"main":"./lib/cjs/index.js","types":"./lib/cjs/index.d.ts","type":"module","exports":{".":{"require":{"types":"./lib/cjs/index.d.ts","default":"./lib/cjs/index.js"},"import":{"types":"./lib/esm/index.d.ts","default":"./lib/esm/index.js"}},"./types":{"require":{"types":"./lib/cjs/types.d.ts","default":"./lib/cjs/types.js"},"import":{"types":"./lib/esm/types.d.ts","default":"./lib/esm/types.js"}},"./errors":{"require":{"types":"./lib/cjs/errors.d.ts","default":"./lib/cjs/errors.js"},"import":{"types":"./lib/esm/errors.d.ts","default":"./lib/esm/errors.js"}},"./providers/kms":{"require":{"types":"./lib/cjs/providers/kms/index.d.ts","default":"./lib/cjs/providers/kms/index.js"},"import":{"types":"./lib/esm/providers/kms/index.d.ts","default":"./lib/esm/providers/kms/index.js"}},"./providers/kms/types":{"require":{"types":"./lib/cjs/providers/kms/types.d.ts","default":"./lib/cjs/providers/kms/types.js"},"import":{"types":"./lib/esm/providers/kms/types.d.ts","default":"./lib/esm/providers/kms/types.js"}}},"typesVersions":{"*":{"types":["lib/cjs/types.d.ts","lib/esm/types.d.ts"],"errors":["lib/cjs/errors.d.ts","lib/esm/errors.d.ts"],"providers/kms":["lib/cjs/providers/kms/index.d.ts","lib/esm/providers/kms/index.d.ts"],"providers/kms/types":["lib/cjs/providers/kms/types.d.ts","lib/esm/providers/kms/types.d.ts"]}},"gitHead":"7bcc27b1574493f9452688673658f52b80c53847","_id":"@aws-lambda-powertools/data-masking@2.35.0","_nodeVersion":"24.19.0","_npmVersion":"11.17.0","dist":{"integrity":"sha512-Jtd3a02VQ6CX/pMkniyUHi0iyFwFziR2GWbIs5bw9ssdJyESW+yVcAu6JY//gvlxIhIdx/nDaN/9Ux9uMvZfzg==","shasum":"7e92e518f43d0db6da3528ed7126ab59ea9b161e","tarball":"https://registry.npmjs.org/@aws-lambda-powertools/data-masking/-/data-masking-2.35.0.tgz","fileCount":52,"unpackedSize":70757,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aws-lambda-powertools%2fdata-masking@2.35.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCKieRTlUD8FsVOtdsWZUWTCdhKY34tFQe1c6Oz+CEepAIhAKIT16zGnDcywwpVZP9ZVeokD6N6FXML25rgdD3HPneI"}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:0eaa49bd-ce1b-4d2b-a71c-a2756fa9f0cd"}},"directories":{},"maintainers":[{"name":"dreamorosi","email":"dreamorosi@gmail.com"},{"name":"aws-powertools-bot","email":"aws-powertools+npmjs.com@amazon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/data-masking_2.35.0_1787048456610_0.17091641486290587"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-08T14:08:20.704Z","modified":"2026-08-18T10:20:57.434Z","0.0.0":"2026-07-08T14:08:21.071Z","2.34.0":"2026-07-10T12:32:36.337Z","2.35.0":"2026-08-18T10:20:56.761Z"},"bugs":{"url":"https://github.com/aws-powertools/powertools-lambda-typescript/issues"},"author":{"name":"Amazon Web Services","url":"https://aws.amazon.com"},"license":"MIT-0","homepage":"https://github.com/aws-powertools/powertools-lambda-typescript/tree/main/packages/data-masking#readme","keywords":["aws","lambda","powertools","data-masking","encryption","pii","sensitive-data","nodejs","serverless"],"repository":{"type":"git","url":"git+https://github.com/aws-powertools/powertools-lambda-typescript.git"},"description":"A utility for masking and encrypting sensitive data in AWS Lambda functions","maintainers":[{"name":"dreamorosi","email":"dreamorosi@gmail.com"},{"name":"aws-powertools-bot","email":"aws-powertools+npmjs.com@amazon.com"}],"readme":"# Powertools for AWS Lambda (TypeScript) - Data Masking Utility\n\nThe data masking utility can encrypt, decrypt, or irreversibly erase sensitive information to protect data confidentiality.\n\nPowertools for AWS Lambda (TypeScript) is a developer toolkit to implement Serverless [best practices and increase developer velocity](https://docs.aws.amazon.com/powertools/typescript/latest/#features). You can use the library in both TypeScript and JavaScript code bases.\n\nTo get started, install the package by running:\n\n```sh\nnpm i @aws-lambda-powertools/data-masking\n```\n\n## Key features\n\n* Encrypt, decrypt, or irreversibly erase data with ease\n* Erase sensitive information in one or more fields within nested data\n* Seamless integration with [AWS Encryption SDK](https://docs.aws.amazon.com/encryption-sdk/latest/developer-guide/introduction.html) for industry and AWS security best practices\n\n## Usage\n\n### Erasing data\n\nErasing will remove the original data and replace it with `*****`. This means you cannot recover erased data, and the data type will change to `string` for all erased values.\n\nField paths support dot notation and `.*`/`[*]` wildcards to reach nested data.\n\n```typescript\nimport { DataMasking } from '@aws-lambda-powertools/data-masking';\n\nconst masker = new DataMasking();\n\nconst data = {\n  name: 'Jane Doe',\n  customer: { ssn: '123-45-6789', city: 'Anytown' },\n  orders: [{ id: 1, card: '4111-1111-1111-1111' }],\n};\n\nconst masked = masker.erase(data, {\n  fields: ['customer.ssn', 'orders[*].card'],\n});\n// {\n//   name: 'Jane Doe',\n//   customer: { ssn: '*****', city: 'Anytown' },\n//   orders: [{ id: 1, card: '*****' }],\n// }\n```\n\nYou can also use custom masking rules to partially mask data while keeping some of its structure, for example to preserve the domain of an email address or the length of a value:\n\n```typescript\nimport { DataMasking } from '@aws-lambda-powertools/data-masking';\n\nconst masker = new DataMasking();\n\nconst masked = masker.erase(\n  { email: 'jane@example.com', ssn: '123-45-6789' },\n  {\n    maskingRules: {\n      email: { regexPattern: /^(.)([^@]*)(@.*)$/, maskFormat: '$1****$3' },\n      ssn: { dynamicMask: true },\n    },\n  }\n);\n// { email: 'j****@example.com', ssn: '***********' }\n```\n\n### Encrypting and decrypting data\n\nTo encrypt and decrypt data, you need an encryption provider. By default, we use Amazon Key Management Service (KMS) via the AWS Encryption SDK provider, which is available as its own sub-path export so the `@aws-crypto/client-node` peer dependency is only required when you use it:\n\n```sh\nnpm i @aws-crypto/client-node\n```\n\n```typescript\nimport { DataMasking } from '@aws-lambda-powertools/data-masking';\nimport { AWSEncryptionSDKProvider } from '@aws-lambda-powertools/data-masking/providers/kms';\n\nconst masker = new DataMasking({\n  provider: new AWSEncryptionSDKProvider({\n    keys: ['arn:aws:kms:us-east-1:123456789012:key/my-key'],\n  }),\n});\n\nconst encrypted = await masker.encrypt(data, {\n  fields: ['customer.ssn'],\n});\n\nconst decrypted = await masker.decrypt(encrypted, {\n  fields: ['customer.ssn'],\n});\n```\n\nFor more information on how to use this utility, please refer to the [documentation](https://docs.aws.amazon.com/powertools/typescript/latest/features/data-masking).\n\n## Contribute\n\nIf you are interested in contributing to this project, please refer to our [Contributing Guidelines](https://github.com/aws-powertools/powertools-lambda-typescript/blob/main/CONTRIBUTING.md).\n\n## Roadmap\n\nThe roadmap of Powertools for AWS Lambda (TypeScript) is driven by customers’ demand.  \nHelp us prioritize upcoming functionalities or utilities by [upvoting existing RFCs and feature requests](https://github.com/aws-powertools/powertools-lambda-typescript/issues), or [creating new ones](https://github.com/aws-powertools/powertools-lambda-typescript/issues/new/choose), in this GitHub repository.\n\n## Connect\n\n* **Powertools for AWS Lambda on GitHub Discussions**: [Join the conversation](https://github.com/aws-powertools/powertools-lambda-typescript/discussions)\n* **Email**: <aws-lambda-powertools-feedback@amazon.com>\n\n## How to support Powertools for AWS Lambda (TypeScript)?\n\n### Becoming a reference customer\n\nKnowing which companies are using this library is important to help prioritize the project internally. If your company is using Powertools for AWS Lambda (TypeScript), you can request to have your name and logo added to the README file by raising a [Support Powertools for AWS Lambda (TypeScript) (become a reference)](https://s12d.com/become-reference-pt-ts) issue.\n\nThe following companies, among others, use Powertools:\n\n* [Alma Media](https://www.almamedia.fi)\n* [AppYourself](https://appyourself.net)\n* [Bailey Nelson](https://www.baileynelson.com.au)\n* [Banxware](https://www.banxware.com)\n* [Caylent](https://caylent.com/)\n* [Certible](https://www.certible.com/)\n* [Codeac](https://www.codeac.io/)\n* [EF Education First](https://www.ef.com/)\n* [Elva](https://elva-group.com)\n* [Flyweight](https://flyweight.io/)\n* [FraudFalcon](https://fraudfalcon.app)\n* [globaldatanet](https://globaldatanet.com/)\n* [Guild](https://guild.com)\n* [Hashnode](https://hashnode.com/)\n* [Instil](https://instil.co/)\n* [LocalStack](https://localstack.cloud/)\n* [Ours Privacy](https://oursprivacy.com/)\n* [Perfect Post](https://www.perfectpost.fr)\n* [Sennder](https://sennder.com/)\n* [tecRacer GmbH & Co. KG](https://www.tecracer.com/)\n* [Trek10](https://www.trek10.com/)\n* [WeSchool](https://www.weschool.com)\n\n### Sharing your work\n\nShare what you did with Powertools for AWS Lambda (TypeScript) 💞💞. Blog post, workshops, presentation, sample apps and others. Check out what the community has [already shared](https://docs.aws.amazon.com/powertools/typescript/latest/we_made_this) about Powertools for AWS Lambda (TypeScript).\n\n### Using Lambda Layer\n\nThis helps us understand who uses Powertools for AWS Lambda (TypeScript) in a non-intrusive way, and helps us gain future investments for other Powertools for AWS Lambda languages. When [using Layers](https://docs.aws.amazon.com/powertools/typescript/latest/getting-started/lambda-layers/), you can add Powertools as a dev dependency to not impact the development process.\n\n## License\n\nThis library is licensed under the MIT-0 License. See the LICENSE file.\n","readmeFilename":"README.md"}