Securing API Keys on Your Workstation (opens in new tab)
Every dev tool you grant API access to, AI assistants included, can read the keys within its reach. You can't make a key unstealable by software running as you, so the goal is fewer secrets exposed and less damage when one leaks.
Read the original article