---
title: Filter sensitive URL content
description: Sanitize sensitive URL content before Session Replay and Heatmaps record it.
product: session-replay
lang: en
token_estimate: 513
---
# Filter sensitive URL content

> For AI agents: a documentation index is available at [/docs/llms.txt](/docs/llms.txt). Append `.md` to any page URL for markdown, or send `Accept: text/markdown`.

Configure `ugcFilterRules` to replace sensitive user-generated content in URLs before the SDK records URLs in replays and heatmaps. Use [web masking settings](https://amplitude.com/docs/session-replay/manage-privacy-settings-for-session-replay) to protect page text and form inputs.

1. Identify URLs that contain sensitive user IDs, company names, query parameters, or dynamic path segments.
2. Choose selectors and descriptive replacement URLs using the [UGC Filter Rules reference](https://amplitude.com/docs/session-replay/ugc-filter-rules).
3. Put specific rules before general rules. The SDK uses the first matching rule.
4. Add the rules to `interactionConfig` during SDK initialization and set `enabled: true`.

## Configure UGC Filter Rules

Configure UGC Filter Rules as part of the `interactionConfig` when initializing the Session Replay SDK:

```javascript
import { sessionReplay } from "@amplitude/session-replay-browser";

sessionReplay.init("YOUR_API_KEY", {
  // ...
  // Other Configs
  // ...
  interactionConfig: {
    enabled: true,
    ugcFilterRules: [
      {
        selector: "https://example.com/user/*/profile",
        replacement: "https://example.com/user/USER_ID/profile",
      },
      {
        selector: "https://example.com/api/token=*",
        replacement: "https://example.com/api/token=REDACTED",
      },
    ],
  },
});
```

## Test patterns in a development environment first

Validate that your glob patterns match expected URLs in a development environment. The following array lists example URLs to include in your checks; it doesn't execute a test:

```javascript
// Test with various URL formats
const testUrls = [
  "https://mycompany.projecttool.com/browse/PROJ-123",
  "https://codehost.com/username/repository/tree/main/src/components",
  "https://myapp.com/user/john.doe@email.com/profile",
];
```

