Permanently redact personal information
Destructively removes personal information from a document or an audio file and returns a new file.
The removal is real, not cosmetic: text is stripped out of the PDF content stream rather than covered with a black box, and audio is beeped or silenced with its transcript rewritten to match.
Routing is by the input’s media type, and the parameters are not interchangeable:
- Documents —
mode:targeted(default, per-entity boxes) orlines(whole lines). - Audio and video —
style:beeporsilence.
Sending the other medium’s parameter is a 400.
Choosing what to remove. categories lists what counts as sensitive; the defaults cover names, government ids, addresses, phone numbers, email addresses and dates of birth. instructions adds free-form guidance on top. The result reports output.entities — a per-category count of what was removed — and output.skipped, the documents that had nothing to redact.
Waiting for the result
Sync by default: the call holds open until the run finishes, up to ?wait= seconds (default 60, max 120, 0 returns immediately).
Learn more: Redaction guide
Authentication
Bearer authentication of the form Bearer <token>, where token is your auth token.
Path parameters
Query parameters
How many seconds to hold the request open waiting for the run to finish.
Finishing inside the window returns 200 with the full run; running past it returns 202 with a statusUrl to poll. Send 0 to skip waiting entirely and always get the 202.
Request
An input file, given one of two ways.
{ "url": "…", "name"?: "…", "processing"?: "…" }— fetched over http(s) for this run and purged with it.{ "id": "…" }— a file you already registered withPOST /v1/files, reusable across runs and never re-parsed.
Arbitrary JSON you attach to the run and get back on every read of it.
Use it to carry your own identifiers — an order number, a customer id — so a webhook or a polled run reconciles without a lookup table. Capped at 10 KB serialized.
Where to deliver this run's events, given one of two ways.
{ "url": "…" }— a one-off https endpoint for this run only.{ "id": "whe_…" }— a saved endpoint fromPOST /v1/webhooks. Runs hold the reference, so pausing or re-pointing that endpoint applies to this run too.
Deliveries are at-least-once and signed — dedupe on eventId and verify against GET /v1/webhooks/jwks.json.
How long, in seconds, to keep this run and its files before purging them automatically.
The maximum is 604800 (7 days). The deadline comes back as expiresAt on every read of the run. Call POST /v1/runs/{id}/keep before then to clear the TTL and move the results into a space permanently.
E-signature runs are exempt — an envelope waits for its signers however long that takes.
Response
Where the run is in its life.
The last four are terminal.
Why the run failed. Present whenever status is failed, and only then.
code is the stable, snake_case reason (input_unavailable, parse_failed, …); message is the human-readable detail. Per-file and per-step failures are also reported in files[].error and, for a pipeline, steps[].error.
The redacted files. Present once status is processed.
files[] holds the new documents — file is an alias of the first for single-file runs — each with a signed download link. entities tallies what was removed per category, and skipped counts documents that contained nothing to redact and so produced no new file.