Credential Rotation Checklist

"# Credential Rotation Checklist\n\nEvery item below was exposed in Git history by agent sessions. All must be rotated at the provider, not just removed from source.\n\n---\n\n## 1. blu-chat — .env.production keys\n- Bead: ESC-1\n- Repo: blu-chat\n- What: Real API keys committed in .env.production\n- Action: Go to each provider dashboard, revoke the old key, generate a new one, store the new reference in 1Password.\n\n---\n\n## 2. agent-router — .env.litellm keys\n- Bead: ESC-2\n- Repo: agent-router (inside agent-docker)\n- What: LiteLLM provider API keys pushed to Git\n- Action: Revoke at each provider (Anthropic / OpenAI / whichever keys were in that file), generate replacements, update 1Password references.\n\n---\n\n## 3. GitLab PAT — bluefly-drupal-agent\n- Bead: bc-31a2\n- What: A GitLab personal access token was embedded in a https://<user>:<token>@gitlab... Git URL in CLI history/logs.\n- Action: GitLab → Settings → Access Tokens → Revoke the bluefly-drupal-agent token → Create replacement → Update 1Password reference.\n\n---\n\n## 4. blu_fleet API token\n- Bead: bc-0pqi\n- Repo: contextcontrol-ai (config/sync)\n- What: blu_fleet API token committed to source.\n- Action: Revoke/regenerate the blu_fleet token at the issuing service, update 1Password reference.\n\n---\n\n## 5. Google API key\n- Bead: bc-4w9a\n- Repo: bluefly-io or contextcontrol-ai (config/sync)\n- What: Google Fonts / Google API key committed to source.\n- Action: Google Cloud Console → APIs & Services → Credentials → Delete the exposed key → Create replacement → Update 1Password reference.\n\n---\n\n## After Each Rotation\n\n1. Verify the NEW credential works (test an API call or git clone).\n2. Verify the OLD credential is rejected.\n3. Update the 1Password item so op:// references resolve to the new value.\n4. Confirm no .env files with resolved values remain in any tracked branch.\n"