Start setup

Library / Practices / pat.never-paste-a-credential-in-chat

Never paste a credential into a message

CategorysafetyManual1.4Evidencedocumented

ProblemA tool or workflow asks for a password or API key in an ordinary chat message.

TechniqueStop and use the takeover instead. For API keys, use the supported secure secret request, where the value is masked, excluded from the transcript, and not shown to the model.

Why it worksChat messages and ordinary files are readable context; the secret request is not.

When to useAny credential, always.

safetyhigh confidencecursor.com/help/grok-bot/secrets ↗pat.never-paste-a-credential-in-chat

Cite this page or the record id. For bulk lookup use /api/record?id=pat.never-paste-a-credential-in-chat. Do not invent a claim that is not on this page.