Debugging “is the API key loaded?” should not paste Script Property values into a shared Log sheet. maskSecret(secret, keepStart, keepEnd) returns an abcd…wxyz-style mask (defaults 4 / 4). Short secrets are fully masked so a 6-char token doesn’t leak in the clear.
When to use
Logger.log/ console lines that mention credentials- Log-sheet rows that record which key/token was used
- Support handoffs where you need to confirm “ends in wxyz” without exposing the value
How to use this snippet
/**
* Mask a secret for logs: keepStart…keepEnd (defaults 4/4).
* Short secrets (len <= keepStart+keepEnd) are fully masked with •.
* null/undefined → ''.
* @param {string} secret
* @param {number=} keepStart
* @param {number=} keepEnd
* @return {string}
*/
function maskSecret(secret, keepStart, keepEnd) {
if (keepStart == null) keepStart = 4;
if (keepEnd == null) keepEnd = 4;
keepStart = Math.max(0, Number(keepStart) || 0);
keepEnd = Math.max(0, Number(keepEnd) || 0);
if (secret == null) return '';
var s = String(secret);
if (!s) return '';
if (s.length <= keepStart + keepEnd) {
return s.replace(/./g, '•');
}
return s.slice(0, keepStart) + '…' + s.slice(s.length - keepEnd);
}
Example
function debugAuthHeaders_() {
var props = PropertiesService.getScriptProperties();
var key = props.getProperty('API_KEY');
Logger.log('API_KEY loaded=%s mask=%s', !!key, maskSecret(key));
// Never: Logger.log(key);
}
function appendTokenAudit_(sheet, label, token) {
sheet.appendRow([new Date(), label, maskSecret(token, 4, 4)]);
}
Tips:
- Masking is for logs, not storage — keep the real value in Script Properties / User Properties only.
- For JWTs, prefer masking over logging claims; the middle still carries data.
- Fully masked short secrets beat a false sense of safety (
ab…cdon a 4-char PIN).
Tip: NitroGAS Co-Pilot can replace raw Property dumps in Log helpers with maskSecret so shared spreadsheets don’t become a credential paste bin.
Happy Coding!
