All documentation

Documentation Settings: This Mac

Keeping secrets from models

Which credentials a seat can never read, what is masked before text leaves the Mac, and where that coverage stops.

A key that reaches a model ends up in the provider's logs. The app keeps them back in several layers, and each layer has an edge worth knowing.

Credential reads are refused

The app's own file tools refuse a credential store in every mode: "Refused: … is a credential store, and no seat may read one." A .env file, private key or keystore outside the workspace is refused by name. Both are recorded in the audit log. The same stores are denied to commands by the sandbox, and a command that names one asks even in Auto.

Keys are masked on the way out

Before a turn or a tool result leaves the Mac, anything shaped like an Anthropic, OpenAI, GitHub, xAI, Google, AWS, Slack or Stripe key, a JWT, a private-key block, or the password in a database URL becomes a placeholder such as [key-1]. The same key keeps the same placeholder for the run, so a model can still reason about it. A placeholder is never turned back into the key, and the run ends with a notice saying how many were masked. There is no switch.

The limit: this covers what the app itself sends. A command-line seat reads files with its own tools and talks to its own provider directly, so the mask does not see that traffic. Keep keys out of the workspace, or use a deny read rule, if a CLI seat works there.

Variables are scrubbed

With Remove secret-looking variables on (the default), token-shaped environment variables are taken out before a command or seat starts. A team can name more, and team secrets are passed in by name with their values masked from every transcript.

Personal data (teams)

A team owner can switch on redaction of emails, phone numbers, card numbers and social security numbers in what the room fetches on the Mac. On the server, personal data can be masked before a prompt leaves and put back in the answer. Both are in Governance. A path matched by a classify read rule reaches a seat as a handle with its size and shape, not its content, and the seat can place it into a file without the data entering a model.

When you push

The ship check looks at added lines for keys, at dependency advisories, and at access checks that went the wrong way, when you push or open a pull request. It is shown, not enforced, unless your team makes it a gate. A diff of a secret file stays on the machine running the discussion and is not mirrored to your other devices.

Settings → Workspace → Privacy & Security → Sandbox, the parts list with Remove secret-looking variables and Variables to keep
Settings → Workspace → Privacy & Security → Sandbox, the parts list with Remove secret-looking variables and Variables to keep

Further reading. LLM01:2025 Prompt Injection — OWASP, 2025. OWASP Top 10 for LLM Applications 2025 — OWASP.

See also

Not what you were looking for? The help centre answers one question at a time, and the support page says how to reach a person.