# Prevent secrets from leaking

> Use Warp Rules and built-in Secret Redaction to prevent API keys and credentials from leaking in agent output, demos, and shared sessions.

- 网址：https://funcoding.ai/agents/warp/guides/devops/how-to-prevent-secrets-from-leaking/
- 来源：Warp 官方文档原文（英文），MIT 许可，同步于 2026-10-11
- 官方原文：https://docs.warp.dev/guides/devops/how-to-prevent-secrets-from-leaking/

---
Learn how to safeguard credentials and sensitive data using Warp’s Secret Redaction and Rule system.

This tutorial shows how to use Warp’s **Rules** to prevent agents or collaborators from exposing sensitive information while coding or sharing output. Whether you’re pair-programming, streaming, or reviewing code, Warp can automatically redact secrets before they’re ever seen by an agent.

1. #### The problem

   AI assistants often echo API keys, tokens, or credentials in generated code blocks.\
   When collaborating or screen-sharing, that can expose secrets publicly.

2. #### The Rule setup

   Define a simple Rule in Warp that instructs the agent to **never display secrets** in outputs or commands.

   ```
   Rule: Protect Secrets
   Behavior:
   - Never include or reveal secrets when generating code or commands.
   - Automatically redact sensitive strings before showing output.
   ```

<div class="callout callout-note">

Enable Warp’s built-in Secret Redaction:

**Settings** > **Privacy** > **Secret redaction**

This automatically masks sensitive values before the agent or output logs can access them.

</div>

3. #### Benefits

   * Protects API keys and credentials from exposure
   * Keeps live streams and demos safe
   * Works seamlessly with pair-programming or AI debugging
