Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
25 changes: 25 additions & 0 deletions adoption/credential-inventory.json
Original file line number Diff line number Diff line change
Expand Up @@ -193,6 +193,31 @@
"rotation": "Run claude setup-token in your own terminal, then tools/credentials/open_credential_terminal.sh claude-oauth-token and type replace at the hidden prompt; revoke the old token in the Claude account settings.",
"notes": "Added 2026-09-30 (docs/decisions/2026-09-29-key-management.md). Until the file exists the token is held only in the kernel keyring as claude-oauth-token and is lost at a kernel restart. Also listed in must_not_be_set: exported in a shell it would override every Claude Code session's native sign-in, so inject it per command only through credential_run.py. Native sign-in remains separate."
},
{
"id": "anthropic-api",
"label": "Anthropic Claude API key for local tools without an identity provider",
"class": "provider_api_key",
"status": "optional",
"lane": "foundation",
"store": {
"kind": "private_env_file",
"path_template": "${XDG_CONFIG_HOME:-$HOME/.config}/native-agent-stack/anthropic-api.env"
},
"variables": [
"ANTHROPIC_API_KEY"
],
"optional_variables": [],
"pointer_variables": [],
"loaders": [
"tools/credentials/credential_run.py anthropic-api -- <command>"
],
"environment_only_consumers": [
"promptfoo anthropic: providers (read ANTHROPIC_API_KEY)",
"Claude Agent SDK workers (anthropics/claude-agent-sdk-python reads ANTHROPIC_API_KEY)"
],
"rotation": "Create a new key at https://platform.claude.com/settings/keys, run tools/credentials/open_credential_terminal.sh anthropic-api and type replace at the hidden prompt, then delete the old key in the Console.",
"notes": "Added 2026-10-08 on the owner's direction: one Console API key, in a dedicated workspace with a spend limit, for local tools that have no identity provider (Anthropic's Console guidance). GitHub Actions use Anthropic workload identity federation through claude-code-action v1's federation inputs instead, so no Anthropic key is stored in GitHub. ANTHROPIC_API_KEY stays in must_not_be_set: exported in a shell it would override every Claude Code session's native sign-in, so it is injected per command only through credential_run.py."
},
{
"id": "grafana-admin",
"label": "Local Grafana admin account and secret key (self-generated)",
Expand Down
8 changes: 4 additions & 4 deletions manifests/evidence.json
Original file line number Diff line number Diff line change
Expand Up @@ -5036,8 +5036,8 @@
},
{
"path": "adoption/credential-inventory.json",
"sha256": "6e1e50f3ad647859915eefa64835ff4c43767bf8abec104b5d30f47895cef097",
"bytes": 24095
"sha256": "2115b56acbcbf6268ae98ef9aef49325d3b9ebdefc67225393e5ccceca708266",
"bytes": 25686
},
{
"path": "adoption/hardware-profiles.json",
Expand Down Expand Up @@ -56047,8 +56047,8 @@
},
{
"path": "tests/test_credential_run.py",
"sha256": "d65c6551a7070b225179ac73316998081857c0f1e256a8e6f39ded12cd587757",
"bytes": 128507
"sha256": "3cb959529bb6b26848e66cbc60de9560820964f78430df44027246b1b54d8338",
"bytes": 128524
},
{
"path": "tests/test_credential_status.py",
Expand Down
2 changes: 1 addition & 1 deletion tests/test_credential_run.py
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@
import set_credential as writer # noqa: E402

INJECTABLE_IDS = {"alpaca-paper", "alpaca-paper-2", "sec-contact", "databento", "typesafe", "omniroute", "tavily",
"claude-oauth-token", "canary-e2e"}
"claude-oauth-token", "canary-e2e", "anthropic-api"}
NOT_INJECTABLE_IDS = ("grafana-admin", "nativestack-generation-key", "openhands-session", "claude-native",
"codex-native", "gh-native", "huggingface-native", "huggingface-native-stored", "ibkr-gateway",
"github-actions")
Expand Down
Loading