Skip to content

Credential Rotation Checklist

Every item below was exposed in Git history by agent sessions. All must be rotated at the provider, not just removed from source.


1. blu-chat — .env.production keys

  • Bead: ESC-1
  • Repo: blu-chat
  • What: Real API keys committed in .env.production
  • Action: Go to each provider dashboard, revoke the old key, generate a new one, store the new reference in 1Password.

2. agent-router — .env.litellm keys

  • Bead: ESC-2
  • Repo: agent-router (inside agent-docker)
  • What: LiteLLM provider API keys pushed to Git
  • Action: Revoke at each provider (Anthropic / OpenAI / whichever keys were in that file), generate replacements, update 1Password references.

3. GitLab PAT — bluefly-drupal-agent

  • Bead: bc-31a2
  • What: A GitLab personal access token was embedded in a https://<user>:<token>@gitlab... Git URL in CLI history/logs.
  • Action: GitLab → Settings → Access Tokens → Revoke the bluefly-drupal-agent token → Create replacement → Update 1Password reference.

4. blu_fleet API token

  • Bead: bc-0pqi
  • Repo: contextcontrol-ai (config/sync)
  • What: blu_fleet API token committed to source.
  • Action: Revoke/regenerate the blu_fleet token at the issuing service, update 1Password reference.

5. Google API key

  • Bead: bc-4w9a
  • Repo: bluefly-io or contextcontrol-ai (config/sync)
  • What: Google Fonts / Google API key committed to source.
  • Action: Google Cloud Console → APIs & Services → Credentials → Delete the exposed key → Create replacement → Update 1Password reference.

After Each Rotation

  1. Verify the NEW credential works (test an API call or git clone).
  2. Verify the OLD credential is rejected.
  3. Update the 1Password item so op:// references resolve to the new value.
  4. Confirm no .env files with resolved values remain in any tracked branch.