I Didn't Revoke My API Keys Because Claude Called Me An Idiot
KnowBe4, March 24,2026
I need to confess something. A few days ago whilst vibe coding at 2am (which can end up burning through tokens like they are going out of fashion) I accidentally pasted my API key directly into a Claude chat instead of the terminal window I had open.
Claude told me off.
It felt like a full, proper, disappointed parent tone; the AI equivalent of 'I'm not angry, just disappointed', except it absolutely was angry. There may have been paragraphs. Multiple paragraphs (at least it felt that way and that is how I'm choosing to recall the episode) about credential hygiene and security best practices and the importance of immediately revoking compromised keys.