Session replay without recording passwords

How coview masks inputs in the visitor's browser, before anything is sent — and why that's the only place it works.

coview team · 2 min read
Emailhannah@…Visible
Password••••••••Masked
Card•••• ••••Masked

Session replay is only useful if you can trust what it doesn't record. A tool that captures a password once has captured it for as long as the recording exists, in every system the recording passes through. So coview masks in the one place where a secret has never left the person who typed it: their browser.

Why masking on the server is too late

If a value is masked after it arrives, it has already travelled over the network, been received by a server and possibly logged on the way. “We delete it when it gets here” is a promise about every component on the path. Masking in the browser is a promise about one thing: the value is replaced before the recording is built.

What is always masked

Before a recording leaves the page, coview replaces the values of:

  • Password and hidden fields, and fields whose autocomplete marks a one-time code, a new or current password, or a payment card.
  • Fields that look secret by name. A field whose name, id, placeholder or label mentions a password, PIN, token, card, CVV, IBAN, social security or tax ID is masked whatever its type.
  • Card numbers anywhere. A run of 13 to 19 digits that passes the card checksum is masked, even in a field nobody marked.
  • Anything typed into coview's own widget.

Addresses are cleaned too: query parameters named like token, session, password or email are dropped from recorded URLs, and so is a fragment that carries parameters.

What you add

You know your pages better than any rule. Mark an element with data-coview-mask and coview never sees its text — not in recordings, not when someone watches live:

<div data-coview-mask>Salary: $84,000</div>

You can also mask every input on a site, and keep whole paths out of recordings.

What we keep about the browser

To make replays useful for debugging, coview keeps the errors and warnings the page logged, and the requests that failed or were slow — their address, status and duration. Request bodies and headers are never recorded.

The same rules, live

The masking that protects a recording also protects a live view. When an agent watches a visitor's tab or co-browses with them, masked fields stay masked on the agent's screen (how co-browsing asks first). And during Take over, an agent never types into password, card, bank or tax-number fields.

The safest copy of a password is the one that was never made.

If your privacy policy needs it, recording can wait for consent: coview('consent', { analytics: false }) keeps it off until the visitor agrees. Our privacy page lists everything coview collects.

Masking is on for every workspace from the first session. Start free and add one script tag, or talk to us about a security review.

coview team

We build coview: session replay, co-browsing, chat and calls for support teams. Questions about a post? Ask us from the contact page.

See what your customer sees, today.

Free to start. Your first session shows up as soon as the snippet is on your site.