Playbooks / Set up a credential vault and secret hygiene

Set up a credential vault and secret hygiene

Set up a credential vault and secret hygiene

Ready now

One gitignored MASTER.md per machine holding every key by service, a UserPromptSubmit hook that captures any pasted secret before it is used, a readback hook, and a git secret scan that blocks commits containing keys.

Kit

No separate kit. The playbook is self-contained.

You need

AccountWhyFree or paidPlan
Claude Code (Anthropic Claude Pro or Max)The AI operator every system runs through. Skills, hooks, memory, MCP servers and the Brain plugin all load inside Claude Code.PaidClaude Pro (20 USD/mo) works for light use; Max (100 USD or 200 USD/mo) for daily multi-hour sessions. Anthropic terms require each user to hold their own subscription; never share a login.

What you bring

  • Your account logins and keys, all of them. The vault is empty until you fill it.

The steps

  1. Create the vault file, gitignored and locked
  2. Fill it, one service at a time
  3. Put the credential rule in CLAUDE.md
  4. Install the capture hook (UserPromptSubmit)
  5. Install the read-back hook (Stop)
  6. Install the git pre-commit secret scan
  7. Move secrets into the systems that need them
  8. Rotate the same way every time

Get the full playbook

Part of: Foundation