Set up a credential vault and secret hygiene
Ready nowOne gitignored MASTER.md per machine holding every key by service, a UserPromptSubmit hook that captures any pasted secret before it is used, a readback hook, and a git secret scan that blocks commits containing keys.
Kit
No separate kit. The playbook is self-contained.
You need
| Account | Why | Free or paid | Plan |
|---|---|---|---|
| Claude Code (Anthropic Claude Pro or Max) | The AI operator every system runs through. Skills, hooks, memory, MCP servers and the Brain plugin all load inside Claude Code. | Paid | Claude Pro (20 USD/mo) works for light use; Max (100 USD or 200 USD/mo) for daily multi-hour sessions. Anthropic terms require each user to hold their own subscription; never share a login. |
What you bring
- Your account logins and keys, all of them. The vault is empty until you fill it.
The steps
- Create the vault file, gitignored and locked
- Fill it, one service at a time
- Put the credential rule in CLAUDE.md
- Install the capture hook (UserPromptSubmit)
- Install the read-back hook (Stop)
- Install the git pre-commit secret scan
- Move secrets into the systems that need them
- Rotate the same way every time
Get the full playbook
Part of: Foundation