You pasted an API key into a coding session. Now what?
Something is failing, you paste the whole config so the agent can see it, and the key is sitting right there in it. It now lives in a transcript on your disk, and in whatever that session synced to.
Where it actually went
Your AI coding tool writes the session to disk as it goes. The paste is in that file the instant you hit send, and it stays there:
- ~/.claude/projects/<project>/<session>.jsonl: Claude Code
- ~/.codex/, ~/.gemini/antigravity-cli/, ~/.config/opencode/: the others, same idea, different shapes
Clearing the conversation in the UI doesn't touch those files. Neither does closing the terminal. If the directory gets backed up, or synced, or sits on a machine someone else can read, the key is now in all of those places too.
What to do, in order
| 1. Rotate it | First, before anything else, no matter how confident you are that nobody saw it. Rotating is cheap; not rotating is a bet. Everything below is about finding the rest, not about whether to rotate this one. |
| 2. Find the others | If you pasted a key once, you've almost certainly pasted one before. The real question isn't whether this key is exposed — it's how many are, and grepping for one string by hand won't answer that. |
| 3. Decide about the files | Deleting a transcript removes the credential, but it takes the work with it. Usually the better call is to rotate the key and keep the history, once you know what's actually in it. |
Finding every single one
A grep for sk- finds one shape of one provider's keys and misses everything else: tokens that are just plain hex, credentials sitting in a pasted .env file, a connection string with the password baked right in. Scanning by pattern per provider is what actually catches all of it:
> do I have any leaked secrets? recall_security_summary: distinct credentials, grouped, with which sessions each one appears in
chat-recall scans as it indexes rather than only when asked, so the answer is already waiting before you even think to ask. Findings are grouped by credential rather than by occurrence: one key pasted into nine sessions is one thing to rotate, not nine separate alerts.
Redaction happens before upload, not after
Worth being precise here, because it's the part that would otherwise make things worse. The scan and the redaction both run on your own machine, inside the CLI, before anything gets sent anywhere. What reaches our server is already redacted. Self-hosting removes the question entirely: see self-hosting.
Not doing this again
Reference the variable, not the value. Say $STRIPE_SECRET_KEY instead, and the agent can reason about your config just fine without the actual secret ever entering the transcript. Nearly every "show me your config" exchange works exactly as well this way.
Worth putting in the project instructions your agent reads, so it becomes a standing rule instead of something you have to remember mid-debug, at the exact moment you're least likely to.
Questions
| I pasted an API key into an AI coding session. Is it still on disk? | Yes. Your tool writes the session to disk as you go, so the key landed in the transcript the moment you sent it. For Claude Code that file is under ~/.claude/projects/, and Codex, Antigravity and OpenCode each keep their own equivalent. |
| Does clearing the conversation delete the key? | No. Clearing the chat in the interface does not touch the transcript, and neither does closing the terminal. If that directory is backed up or synced, the key is in those copies too. |
| What should I do first? | Rotate the key, before anything else and regardless of how sure you are that nobody saw it. Rotating is cheap. Everything after that is about finding the ones you have forgotten. |
| How do I find every credential I have ever pasted? | Grepping for sk- catches one shape from one provider and misses plain hex tokens, pasted .env files and connection strings with the password inside. Scanning per provider pattern across every session is what finds the rest; recall_security_summary groups the results by credential, so one key pasted into nine sessions is one thing to rotate. |
| Should I delete the transcript? | Usually not. Deleting it removes the credential and the work with it. Rotate the key and keep the history once you know what is in it. |
| Does the scan send my keys anywhere? | No. The scan and the redaction both run on your own machine inside the CLI, before anything is sent, so what reaches the server is already redacted. Self-hosting removes the question. |
More notes
| Using several AI coding tools without losing the thread | A practical setup for working across several AI coding tools at once: what breaks when you switch tools, and how to keep one memory across all of them. |
| What claude --continue does not do | claude --continue resumes one session, in one tool, in one directory. What to use when the thing you need is older than that, or was not in Claude Code at all. |
| Where every AI coding tool stores your sessions on disk | Exact paths and formats for every AI coding tool chat-recall reads: and the retention period that quietly deletes them. |