Acceldata
AIO

Last updated: Oct 06, 2026 15:42 UTC

Hide system prompts and tool definitions

Replace your system prompt and tool definitions with a fingerprint in the data your application sends to AIO. You can still tell prompt versions apart, but the text never leaves your application.

What changes

Each setting is off by default. Only the recorded copy changes. Your model still gets the full request, including the system prompt and tool definitions.

Setting

What AIO receives

hide_system_instructions

The system instructions (gen_ai.system_instructions) are replaced by a fingerprint. Every message with the system role is removed from the recorded input and output messages. These messages are dropped, not blanked, because the fingerprint already records which prompt was used.

hide_tool_definitions

The tool definitions (gen_ai.tool.definitions) are replaced by a fingerprint.

A fingerprint is sha256: followed by the 64-character hex SHA-256 hash of the original value, for 71 characters in total. The hash isn't salted, so the same prompt always produces the same fingerprint. If two traces have the same fingerprint, they used the same prompt. A different fingerprint means the prompt changed.

Prerequisites

  • The Python SDK is installed and your credentials are configured. For more information, see Instrument your code.

Hide them in code

  1. In your application's startup code, pass a policy to aio.init with redaction=aio.redaction_policy(...).
  2. Set hide_system_instructions=True, hide_tool_definitions=True, or both.
  3. Call aio.init once, before you create any HTTP or model clients.
import acceldata_aio_tracer as aio
aio.init(
    redaction=aio.redaction_policy(
        hide_system_instructions=True,
        hide_tool_definitions=True,
    ),
)
# Create your HTTP and model clients after this point.

aio.init returns True when telemetry is running. Only the first call takes effect. A second call returns True but doesn't apply a new policy, so set the policy in the first call.

Hide them with environment variables

  1. Set AIO_HIDE_SYSTEM_INSTRUCTIONS, AIO_HIDE_TOOL_DEFINITIONS, or both to true.
export AIO_HIDE_SYSTEM_INSTRUCTIONS=true
export AIO_HIDE_TOOL_DEFINITIONS=true
  1. Call aio.init without the redaction argument.

Only 1, true, yes, and on turn a setting on. Case doesn't matter, and spaces around the value are ignored. Any other value, including a typo, leaves the setting off.

Important

AIO reads these variables only if you don't pass redaction to aio.init. If you pass a policy in code, AIO ignores these variables completely. It doesn't combine them with your policy.

Check the result in a trace

  1. Open a trace that your application sent after you turned on the setting. For more information, see Explore traces.
  2. In the waterfall, select the step for the LLM call. The step detail pane opens.
  3. Above Input, find the System instructions block. When the prompt is hidden, its header reads 71 characters, which is the length of the fingerprint.
  4. Expand System instructions. The block tells you that only the prompt's fingerprint was exported and that the text wasn't captured. It doesn't show a Copy button.

If the block shows your prompt text and a Copy button instead, the setting wasn't on when the trace was recorded.

Troubleshooting

aio.init raises RedactionUnavailable

If your application sets up OpenTelemetry before it calls aio.init, AIO can't hide the content. So it doesn't start, and it raises RedactionUnavailable with this message:

aio: redaction is configured, but this application already set up an OpenTelemetry TracerProvider. Redaction is applied by the span exporter, which that provider does not use, so span content would be exported unredacted. Call aio.init() before configuring OpenTelemetry.
  • Move the aio.init call so that it runs before your OpenTelemetry setup. For more information, see OpenTelemetry.

The prompt text still appears

  • Check the environment variable values for typos. Any value other than 1, true, yes, or on leaves the setting off.
  • If you pass redaction to aio.init, set the switches in that policy. AIO ignores the environment variables when you pass a policy.
  • Make sure the policy is set in the first call to aio.init. Later calls don't apply a new policy.

Next steps