Keys and secrets · 2 of 20

A pasted secret is a burned secret

Hit in our code
Check it
grep -rlE "sk_live_|AKIA[A-Z0-9]{16}|ghp_[A-Za-z0-9]{36}" ~/.claude/projects/ 2>/dev/null | wc -l
Free, no call

Get every Fix AI Slop Code episode

The code it wrote, the code it should have written and a check, for every episode

Free, straight to your inbox. No call, no pitch

What is going on

Chat transcripts persist outside your security boundary. Claude Code stores every session as plaintext JSONL on disk, synced wherever your home folder syncs. Commits co-authored by a coding agent leak secrets at about twice the baseline rate. The window is not private because it feels private.

Where it bit

Four real tokens pasted into an AI chat while debugging, two of them twice. Three were rotatable. One was not: a legacy API app the provider no longer issues, so rotating it means losing the capability for good. The sharper lesson was not "do not paste," it was: know which of your credentials are replaceable before you leak one.

The practice

Refer to secrets by env-var name in chat, never by value. Treat anything pasted as compromised and rotate. Keep an inventory with a column for "re-issuable." Shorten session retention with cleanupPeriodDays and deny .env reads in the agent's permissions.

Free, no call

Get this check as a script you can run tonight

Free, straight to your inbox. No call, no pitch

What to do with this

If this check came back with more than you expected, that is worth a conversation

Book a free 30-minute call