Quick fixes AG-S001

That paste contains a secret

Shared methods · A shared method; linked tool guides explain the exact steps.

Passwords, API keys and other credentials have no safe form inside a prompt. Redact before pasting — the model never needed the real value.

Quick fix: That paste contains a secret

Instead of Paste the config file as-is, API key and database password included.

Try Paste it with the values swapped: API_KEY=[REDACTED], DB_PASSWORD=[REDACTED].

The model can answer every reasonable question about a config without the real values. It needed the shape, never the secret.

Why this works

A pasted credential is transmitted and sits in a conversation history: copies outside your control of a thing whose entire value was being secret. No answer improves because the key was real: "why does this config fail" works identically with [REDACTED] in place. That asymmetry (zero benefit, real exposure) is why credentials sit in the never category rather than the judgement-call one. If a real secret does slip in, rotate it; deleting the chat is not un-sending it.

When this applies

Anything that grants access is about to enter the conversation: passwords, API keys, tokens, private keys, connection strings, usually riding inside something innocent like a config file, a log, or an error message.

Template

Before pasting a file or log, sweep it once:

Replace every value that grants access with [REDACTED]. Keep the variable names; they are what the answer needs. If one slipped through: rotate that credential now, not later.

Go deeper

The full boundary (what never goes in, regardless of plan or settings) is the absolute list. What happens to conversation data on your plan is training and retention, and the rotate-don't-delete reflex is from incident response.

Improve next

Last verified · Reviewed by Timothy Fehr