AddThisFeature

Sensitive Field Reveal

Let users check a password or token without leaving it on screen.

simple Forms & Input

What it adds

A consistent show/hide control for passwords, API keys, and other private values.

What your agent is told to do

5
  1. 1

    Apply one reveal control to every sensitive field in the app rather than styling each form differently.

  2. 2

    Preserve cursor position and any text selection when toggling — losing the caret mid-typing is the reason people abandon these controls.

  3. 3

    Label the button by its action and update the label with the state, and expose the state to assistive technology rather than relying on an icon swap.

  4. 4

    Auto-hide high-value secrets after a short idle period or on blur, and always start hidden after a page load.

  5. 5

    Do NOT offer reveal on values the server only returns masked. A toggle that reveals asterisks is worse than no toggle.

Edge cases it handles

6
  • The revealed value must not be exposed to browser autofill heuristics or password managers as a plain field.
  • Copying a hidden value must copy the real value, not the mask.
  • Revealed state must never persist across navigation or reload.
  • Screenshot and screen-share risk is why timed auto-hide exists — pick the timeout deliberately and document it.
  • The toggle must be reachable by keyboard and must not sit inside the field's tab order in a way that traps the user.
  • A field the user cannot read at all — a write-only secret — needs a clear explanation instead of a disabled eye icon.

Definition of done

8
  • All sensitive fields use the same reveal control.
  • Toggling preserves cursor position and selection.
  • The button's accessible name reflects the current state.
  • Fields start hidden on every load and auto-hide after the documented idle period.
  • Server-masked values do not offer a reveal toggle.
  • The control is fully keyboard operable.
  • The feature matches the existing design system.
  • No existing functionality is broken.

Related features

How it works

  1. 1

    Copy the link

    Grab the Markdown instruction URL for this feature.

  2. 2

    Give it to your AI

    Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.

  3. 3

    It inspects, then implements

    Your agent reads your existing app first, then adds the feature to fit it.

Works with your stack

These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.

Need it tighter than that? Customize the feature and tell it exactly what you're running.