Answers

How do I give a coding agent my Stripe or Supabase keys safely?

Never paste live keys into a prompt. Prompts are logged, replayed in session history, and sometimes end up in shared transcripts. The safe pattern is the same one you would use for a human contractor: keep the real secret in the OS keychain, and hand out a scoped, short-lived credential that can only do the one job.

How Tempo does it

Connect a service once (GitHub, Supabase, Vercel, Stripe, Sentry, PostHog, Clerk, Resend, Neon) and the key goes into your Mac's keychain, not into any prompt or config file an agent can read.

When an agent works a task that needs the service, it receives a scoped, per-task token along with the service's tools and a playbook for it. Agents never see the originals, and every use is audited, so you can answer "what did the agent actually do with my Stripe key" precisely.

Tempo is in private beta for macOS. Join the waitlist or see how it works.