Start Here If
Use this page to:- choose secret scanner engines
- add PII or custom redaction rules
- turn on the OpenAI Privacy Filter
- move inline images out of transcripts
- opt in or out of anonymous CLI analytics
- change checkpoint commit signing
Settings Reference
Every key below lives under.entire/settings.json (shared with the team) or .entire/settings.local.json (yours alone), except where noted.
Secret Scanner Engines
Layer 2 of Entire’s redaction pipeline can run Betterleaks, goredact, or both. Betterleaks runs by default and covers several hundred known secret formats. goredact is off by default and checks a smaller set of provider and contextual token shapes with structural validators such as token length or checksums.CLI 0.10.2 uses Betterleaks and does not support scanner selection.
v0.10.3-nightly.202608210613.680d64782 first exposes the settings below..entire/settings.json
.entire/settings.json. It ignores them in .entire/settings.local.json and logs a warning because scanner selection affects the checkpoint content shared through the repository.
If goredact is the only active scanner and it fails during a scan, Entire stops the checkpoint write. When both scanners run, Entire can complete the write with Betterleaks coverage if goredact fails. See Redaction Layers for the complete pipeline.
PII Redaction
PII redaction is disabled by default. Enable it when checkpoint metadata may include personal information such as email addresses, phone numbers, or addresses.- Project Settings
- Local Settings
- Custom Patterns
Use project settings when PII redaction should apply to everyone working in the repository.
.entire/settings.json
User-Defined Redaction
User-defined redaction lets you redact project-specific strings that Entire’s built-in secret detection may not catch. Patterns use Go RE2 syntax, so lookarounds and backreferences are unavailable.- Inline Rules
- Rule Packs
Use inline rules for a small number of patterns.Put shared rules in
.entire/settings.json
.entire/settings.json. Put private rules in .entire/settings.local.json. Entries merge per key, so a local rule can override one shared key and leave the rest alone.OpenAI Privacy Filter
The OpenAI Privacy Filter is an optional layer that runs a local token-classification model over checkpoints at push time, catching names and other personal data that regex layers miss. It is off by default.Install opf
opf aborts your pushes:
Enable It
OPF needs at least one category. Enabling the filter with no category selected aborts the push with a configuration error rather than tagging commits as scanned..entire/settings.json
Categories
Set a category totrue to detect it. Entire rejects unknown category names when it loads settings, so a typo surfaces immediately instead of silently disabling a category.
Control the Pre-Push Prompt
prompt_default decides whether the pre-push hook asks before running OPF.
Choosing Always at the prompt writes
prompt_default: "always" into .entire/settings.local.json for you.
Override for a Single Push
ENTIRE_OPF beats both the setting and the prompt, for that push only.
ENTIRE_OPF=no when a CI runner pushes without opf installed. Use ENTIRE_OPF=yes to run OPF without a prompt.
Push Caps
Two environment variables bound how much work one push hands to the model. Both accept a number orunlimited.
The command Setting
command points at a specific opf binary. Entire reads it only from .entire/settings.local.json, and only when that file is untracked, because the value becomes a process Entire executes during git push. Entire logs a rejected command and falls back to $PATH.
.entire/settings.local.json
command setting is local-only for why this restriction exists.
Externalized Images
redaction.externalize_images moves inline base64 images out of transcript files and into the checkpoint’s assets/ store, replacing each with a short entire-asset:assets/... placeholder. It is off by default.
.entire/settings.json
ENTIRE_EXTERNALIZE_IMAGES=1 turns it on for one invocation without editing settings.
Turning this on keeps large binary blobs out of full.jsonl and transcript.jsonl, which makes those files cheaper to read and diff. Restore re-injects images byte-exactly whether or not the flag is on.
Telemetry
Telemetry controls anonymous CLI usage analytics. It does not send prompts, transcripts, source code, file paths, repository names, or flag values.- Settings File
- Environment Variable
To opt out in this repository, set:Use
.entire/settings.json
.entire/settings.local.json instead when the telemetry preference should apply only to your machine.Checkpoint Commit Signing
Checkpoint commits are signed by default when your Git signing setup is available. To disable signing for the repository, set:.entire/settings.json
.entire/settings.local.json instead when the signing preference should apply only to your machine.
See Checkpoint commit signing for requirements and best-effort behavior.
Verify Privacy Settings
After changing privacy settings, run:.entire/logs/entire.log instead of stopping the CLI.
To confirm OPF ran, push and then check the checkpoint commit for its trailer: