Keep passwords and API keys safe

ComputerWeb app3 min readUpdated October 3, 2026

Anything you type to an agent goes to your AI provider and is saved with the conversation. Keep secrets in a file instead, tell the agent where they are, and handle sign-ins yourself.

An API key is a secret code that lets your project use another service, such as a payment or email provider. Treat keys like passwords: whoever has one can act as you.

What agents and providers can see

  • Everything you send. Your messages, attached images, and your project’s instructions go to your AI provider. Enjoy’s privacy policy says “your prompts, files, and other context may be sent to that provider to carry out your request.” Claude Code’s documentation confirms the data it sends “includes all user prompts and model outputs.”
  • Files the agent opens. When you attach a file, the agent gets its location and can open it. If an agent reads any file with a key in it, that key goes to the provider too.
  • Saved conversations. Enjoy keeps each conversation as a plain text file on your computer. Its agent activity also keeps a short preview, up to 200 characters, of each command and step the agent ran. Copies of attached files stay in the project’s storage even after you delete the conversation. Enjoy doesn’t scan messages for secrets or hide them.
  • People you share with. Anyone you share a project with can open its files, even with View only access.

Habits that keep secrets safe

  1. Don’t paste keys or passwords into messages, instructions, docs, or workflows.
  2. Put keys in a .env file yourself. Many projects read keys from a file called .env. In Files, select New file, then Other file. Type .env as the Filename and keep Project folder as the Location. If Folder shows a folder name, clear it so the file goes at the top of your project. Select Create file, then paste the key into the file. Enjoy saves project files on its own.
  3. Tell the agent the key’s name, not its value. “The Stripe key is in .env as STRIPE_SECRET_KEY. Use it from there, and don’t open .env or show its contents.”
  4. Keep .env out of your project’s history. Ask: “Make sure .env is listed in .gitignore and has never been committed.” The .gitignore file tells Git, your project’s version history, which files to leave out. If .env isn’t left out, the key can end up in every saved version of your project, including any you push online.
  5. Sign in to websites yourself. If an agent needs an account, sign in yourself rather than giving it your password. The “Run a web errand” workflow in Enjoy’s workflow Gallery tells the agent to “pause and ask me to handle it instead of entering credentials yourself.”

If you use Claude Code, a permission rule can also stop its file tools from reading .env. Claude Code’s permissions documentation shows how.

An example

You want a newsletter signup to use your email service. Instead of pasting the key into the chat, you create .env in Files, paste NEWSLETTER_API_KEY= followed by the key, and send:

“Connect the signup form to our email service. The key is in .env as NEWSLETTER_API_KEY. Make sure .env is in .gitignore, and never print the key.”

If a secret slips out

Create a new key with the service and delete the old one. Deleting the conversation in Enjoy can’t take the key back from your AI provider, which received it when you sent it.

Good to know

  • When a message comes from your phone, the web app, or a teammate, Enjoy tells the agent to take extra care with requests involving credentials.
  • Enjoy’s own sign-in is stored separately from your projects. See Store your Enjoy sign-in in the system keychain.
Did this help?

Still need a hand?

Email help@enjoy.dev with your computer, your Enjoy version, and what happened. Leave out passwords and sign-in codes. For questions and ideas, join our Slack community .