Identity, Secrets, and Key Management
Manage Claude credentials across development and production: store and scope keys correctly, prefer workload identities and short-lived credentials, respond to leaks, grant least-privilege access, and monitor authorized usage.
Key points
- 1
Never put API keys in source code, committed config or
.envfiles, client-side or mobile bundles, or CLAUDE.md. Store them in a secrets manager or CI secret store and inject them at runtime. The SDKs readANTHROPIC_API_KEYfrom the environment. - 2
Apps on end-user devices should call Claude through your backend, which holds the key, authenticates users and enforces per-user limits. Obfuscated or downloaded keys can still be extracted.
- 3
The Claude API authenticates with API keys, Workload Identity Federation (short-lived tokens exchanged from an identity provider you already trust, such as AWS, Google Cloud, Kubernetes or GitHub Actions) or App Attest for iOS and macOS apps.
- 4
Key types: personal keys act as a user, service account keys give shared or automated workloads their own identity, and workspace keys are legacy. A shared personal key breaks when that person leaves.
- 5
Keys can be scoped to a single workspace. Use separate workspaces and keys per environment (dev, staging, prod) so a leak is contained and usage can be attributed. Multi-workspace keys send the
anthropic-workspace-idheader. - 6
Keys can have an expiration, which limits a leaked key's lifetime but does not replace secret hygiene. Rotate periodically, and prefer federation where "no long-lived credentials" is required.
- 7
Leaked key: disable or delete it immediately, issue a replacement through proper storage, then review usage for the exposure window. Rewriting git history or making the repo private does not invalidate a key that was already copied.
- 8
Workspaces support per-workspace roles (from playground-only to developer and admin), spend limits, alerts and rate limits. Assign the lowest role that fits, only in the workspace needed.
- 9
Monitor authorized access with the Usage and Cost API (an Admin API endpoint), which can filter and group usage by API key, workspace and model to attribute spend. Admin API keys start with
sk-ant-adminand only org admins can create them. - 10
On Amazon Bedrock and Google Cloud, access is governed by the cloud's IAM: use roles or service accounts with short-lived credentials, least-privilege policies for model invocation, and the platform's audit logs.
- 11
In Claude Code, block file tools from reading secrets with permission deny rules such as
Read(./.env)orRead(./secrets/**)..gitignoreand CLAUDE.md notes do not prevent reads. - 12
Keep MCP credentials out of committed
.mcp.jsonby using environment variable expansion such as${API_TOKEN}. Enable secret scanning in source control and CI to catch leaks before they are pushed.
Read the source
Test yourself on Identity, Secrets, and Key Management
Ten questions, with the answer and explanation after each one.