Playbook · Secrets

Secrets hygiene for AI agents: OpenClaw, Hermes and your API keys

Agents run on keys: model keys, bot tokens, platform keys. Most setups keep them in plain text and hand all of them to every agent. A few habits fix that.

Updated October 2026

In short

Good secrets hygiene for AI agents means keys live in one encrypted vault instead of config files; each agent gets only the keys it needs; every use is logged; keys that sat in plain text are rotated; old copies are verified gone; and email, API keys and business-platform keys are kept in separate lanes so one grant never opens another.

Where agent keys leak

  • Config files such as openclaw.json, readable by any process and any agent in the folder.
  • Environment variables and shell profiles, inherited by child processes and copied with dotfiles.
  • Chat transcripts and logs, when a key is pasted to “just try it”.
  • Backups, sync folders and accidental commits.

One vault, per-agent grants

Move keys into one encrypted vault and let agents resolve them by name. Grant each agent only what its job needs: a coding agent needs a model key, not your payments key. Log every release, so you can see which agent used which key and when.

Rotate, then verify the cleanup

If a key sat in plain text for months, was synced or was ever committed, rotate it after moving it into the vault. Then check the old copies are really gone: agents often keep their own copies or regenerate derived files. For OpenClaw, the authoritative list is what openclaw models auth list reports.

Keep the lanes separate

Email access, API keys and business-platform keys should never unlock each other. A token issued for email shouldn’t grant API keys, and tools that reach your store or payments are better served by a broker that holds the platform key and returns answers, so those keys never reach an agent at all.

Checklist

Agent secrets checklist

  • No API key sits in an agent config file, environment file or shell profile.
  • Each agent has only the keys its job needs.
  • Every key release is logged.
  • Keys that were ever in plain text have been rotated.
  • Email, API keys and platform keys are separate lanes.

How MoltenRock does it

MoltenRock keeps keys in a Secure Enclave vault on your Mac and releases them per agent: OpenClaw and Hermes resolve keys by name, every release is logged, and MoltenRock Connect gives other agents your business tools without any key.

Questions

Do I have to rotate keys after moving them?

If they were only ever on your Mac and never synced or shared, moving them may be enough. If they sat in synced folders, logs or commits, rotate them.

Are environment variables safer than config files?

Slightly, but they are still readable by processes that inherit them and often end up in logs. A vault with per-agent release is safer.

What about Claude Code and Cursor?

They can reach business platforms through MoltenRock Connect over MCP without ever holding a key.

How often should we review access?

A quick look at the log each week is enough for most small teams: remove keys an agent never used.

More guides