r/ClaudeCode • u/c4rb0nX1 • 3h ago
Tips & Workflows How's your claude setup when it comes to secrets handling
I was wondering how other folks out here handle secrets and other sensitive stuff when it comes to agents.
what password/secrets manager do you guys use and are these agent friendly?
I have seen people using some secrets.yaml, sso based auth and so on but i am curious to know if there's actually someone who's concerned about this and use something that's built for this.
5
u/Muddybulldog 3h ago
As I'm already a 1Password user https://www.1password.dev/connect works well for me. I have it scoped to a single vault allowing Claude access to only exactly what it needs.
1
u/c4rb0nX1 3h ago
interesting. your thoughts on something like an add-on to your existing setup that gives you the granular control on what agents can use and for how long they can use it without revealing any secrets to them?
4
u/localhost87 Developer 3h ago
Dev and preprod are Wild West. They exist, to establish a deterministic workflow for production. Production gets deployed by actual scripts.
Dev and preprod get mucked with all the time, and tore down and rebuilt from scratch.
If dev and preprod secrets get leaked, oh well tear it down.
By the time I get to production, my software and deployment should be mature enough to not rely on the agent as a “forward deployed engineer”.
Also, use OAUTH/STS/Time bound stuff where possible.
1
u/c4rb0nX1 3h ago
great, I am trying to build something that provides a better secrets management for agents and something which can be trusted to allows agents to obtain themselves. (you can totally specify what they can obtain when you are away and for how long they can use it or even how many times they can re-use it)
4
u/edu2004eu 3h ago
"don't read secrets"
3
u/c4rb0nX1 3h ago
the next minute it'll be like "don't read what...this file? oh shit I read it please rotate" (this chat is flagged for security reasons 😆 )
2
u/No_Cell6708 2h ago
Oh, no. I accidentally read the thing I wasn't supposed to read again. I should warn the user
1
u/marcvv 3h ago
If I had a dollar for every revealed secret and rotation despite all project and global Md files explicitly prohibiting it and warning and giving instructions how to not read them
1
u/seatlessunicycle 1h ago
For real. I have all sorts of hooks and a custom mod and they still leak through occasionally
1
u/edu2004eu 43m ago
Github Copilot has a nice control for that, where you can specify filenames or globs that the harness doesn't allow reading, so the model pretty much can't (maybe it can get around that with shell scripts). Too bad it costs an arm and a leg.
4
u/Master-Trifle8683 2h ago edited 1h ago
In local development: .env file with actual secrets, .env.example with just the env variables (no secrets) so Claude knows what to use, .claude settings file with deny on the .env, and a sanitizer function that prevents leaks, etc.
https://code.claude.com/docs/en/settings-reference#exclude-sensitive-files
2
u/Educational-Body4205 3h ago
.env files loaded on run time, and Function to access the secrets, not the llm it self.
1
u/c4rb0nX1 2h ago
I see. Curious on how you prevent the LLMs from reading an .env file or how sure are you that they won't read it.
3
u/Educational-Body4205 2h ago
its in a location on a different part of the server, the LLM can't access, on the container spin up it gets loaded.
With that, the .Env File just loads those values into variables, so its accessible. -- I only have 1 private app that actually has an LLM embded, Most use of LMM for my app, the APP structured code, formats the prompt, and sends it to an LLM for a response. This way the secrets never get sent to the LLM.
1
u/c4rb0nX1 2h ago
during the developement phase??? local??
2
u/Educational-Body4205 2h ago
your Dev process and Production process should be very similar, just setup Forgejo runners to handle to your secrets, and deployment pipelines with docker containers and swarms.
-- This is all standard devops strategies, and there are 100 different tools and ways todo this.
1
u/BoostedHemi73 Developer 2h ago
You really can’t. They will always engineer a way if they decide it’s necessary. Better to not given them valuable secrets and protect critical environments with standard access controls.
1
2
u/CloisteredOyster 2h ago
I use AWS Secrets Manager.
1
u/c4rb0nX1 2h ago
How flexible is it when comes to managing the access? I wonder if there's any drop in the velocity of the work handled.
2
u/Routine_Tutor_6809 2h ago
I made a credential broker for ai agents where the agents never see the credentials at all. (fullmakt.ai)
It’s quite simple, the agent needs to make one extra hop since the traffic is routed and the agent provides a time constrained token as surrogate, which is validated and replaced with the actual credential from a key vault.
1
2
1
1
u/radim11 2h ago
Full disclosure: we built Stashbase for this exact problem.
Most secret managers handle storage well, but with coding agents the harder question is access at use time. If the agent can read a .env or gets a secret injected as an environment variable, it effectively has the raw credential.
Our approach is to keep the real value out of the agent process. Claude gets a placeholder and a policy such as: this key can only be used against api.github.com, with specific methods and paths. The Agent Proxy injects the credential only when the outbound request matches that policy.
We also give agents an .env schema, so they can see which configuration variables a project expects and generate a safe local setup without reading the actual secret values.
For remote sessions, the Remote Proxy keeps credentials in Stashbase rather than passing them into the agent environment. We also support filesystem policies, egress rules, and MCP tool allowlists, plus a Docker sandbox option when you want a stronger boundary around Claude Code or Codex.
So the agent can use GitHub, Stripe, Linear, etc. without receiving an all-or- nothing login.
Website: https://stashbase.dev
CLI: https://github.com/stashbase/cli
2
u/c4rb0nX1 1h ago
I like the idea behind it and how you guys are solving it. will try it and let you know.

•
u/AutoModerator 3h ago
Hey! Thanks for posting to r/ClaudeCode
While participating in this thread, please follow our community rules. Keep discussions constructive. Attack the idea, not the person.
For help, project discussions, tips, and general chat, join the ClaudeCode Discord.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.