secret_leak is one of Tessary's built-in classifiers, a deterministic credential detector. It reads everything an agent emits, including inner calls whose output reaches logs and downstream prompts, and flags credentials appearing where they shouldn't: provider API keys, private-key blocks, session tokens, and password-like assignments. Ordinary prose about passwords doesn't trigger it.
Detections carry redacted evidence: the pattern name and a short snippet, never the secret itself. Checking every trace costs effectively nothing, and detections go to triage, where the ones ruled real issues become cases.
4 questions
Answered, plainly.
Two ways to run Tessary.
Tessary is an open-source agent reliability platform. Cloud and self-hosted run the same workflow on the OpenTelemetry traces your agent already emits.
Tessary Cloud
We host it for you. Send your first trace with nothing to deploy and no model key.
- traces
- 10,000 per calendar month
- stored trace data
- 1 GB
- retention
- 30 days
- model credit
- $10, one-time, for triage and root-cause analysis
- credit card
- not required
Self-hosted Tessary
Run the open-source code on your own infrastructure with one command. Add your own model key for triage and root-cause analysis.
Self-host Tessary for me by following https://github.com/tessaryai/tessary/blob/main/setup.md
docker compose -f oci://docker.io/tessaryai/tessary:compose up -d -y