Agent skill

Credentials

by alinaqi in alinaqi/maggy

Centralized API key management from Access.txt. An agent skill from alinaqi/maggy.

MITAuto-check: notesSecurity

Install Credentials

skills CLI
$ npx skills add alinaqi/maggy --skill credentials -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alinaqi/maggy credentials --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alinaqi/maggy.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/credentials .claude/skills/credentials && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
credentials
GitHub stars
707
Token cost
~2.4k tokens
SKILL.md length
263 words
Files
1
Skills in repo
71
Repo updated
First seen
Licence
MIT

At a glance

Centralized API key management from Access.txt. An agent skill from alinaqi/maggy.

  • Works in 5 steps: Ask for Credentials File → Read and Parse → Validate Keys → …
  • Tasks that involve Cryptography
  • SKILL.md covers Credentials File Discovery, Supported File Formats, Key Identification Patterns and Parsing Credentials File, plus 5 more sections
  • Calls curl, claude and jq; reaches api.openai.com and api.anthropic.com; needs ANTHROPIC_API_KEY and REDDIT_CLIENT_SECRET

What it does

Credentials is an agent skill from alinaqi/maggy. Centralized API key management from Access.txt

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Cryptography. It works with Reddit, OpenAI, Stripe and Twilio. The repository describes itself as: What started as an opinionated Claude Code setup kit is now an autonomous AI engineering command center. The licence is MIT.

When your agent uses it

  • Tasks that involve Cryptography

Example prompts

  • “/credentials”

Requirements

  • Python 3
  • A credential in RENDER_API_KEY
  • A credential in OPENAI_API_KEY

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Ask for Credentials File
  2. Read and Parse
  3. Validate Keys
  4. Create .env File
  5. Report Missing Keys

What it can do on your machine

Read from SKILL.md and the folder at commit 72a456e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • claude
    • jq
    • supabase

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.openai.com
    • api.anthropic.com
    • api.render.com
    • reddit.com
    • api.replicate.com
    • supabase.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ANTHROPIC_API_KEY
    • REDDIT_CLIENT_SECRET
    • OPENAI_API_KEY
    • RENDER_API_KEY
    • SUPABASE_ANON_KEY
    • REPLICATE_API_TOKEN
    • STRIPE_SECRET_KEY
    • STRIPE_PUBLISHABLE_KEY
    • ELEVEN_LABS_API_KEY
    • GITHUB_TOKEN
    • SUPABASE_SERVICE_ROLE_KEY
    • STRIPE_WEBHOOK_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Credentials loads about 2.4k tokens when it runs. Until then it costs about 15 tokens; SKILL.md has 263 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~15
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:265
    ### Step 4: Create .env File
  • NoteMentions a .env fileSKILL.md:267
    # Write to project .env
  • NoteMentions a .env fileSKILL.md:268
    cat > .env << EOF
  • NoteMentions a .env fileSKILL.md:276
    echo ".env" >> .gitignore
  • NoteMentions a .env fileSKILL.md:319
    - **ALWAYS** add `.env` to `.gitignore`
  • NoteMentions a .env fileSKILL.md:353
    3. Set up your project's .env file

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from alinaqi/maggy at commit 72a456e, republished under its MIT licence (© alinaqi). 263 words, ~2,394 tokens.

Download SKILL.mdSave it as .claude/skills/credentials/SKILL.md (or your agent's skills folder).
name
credentials
description
Centralized API key management from Access.txt
when-to-use
When setting up a new project that needs API keys or environment variables
user-invocable
false
effort
low

Credentials Management Skill

For securely loading API keys from a centralized access file and configuring project environments.


Credentials File Discovery

REQUIRED: When a project needs API keys, ask the user:

I need API credentials for [service]. Do you have a centralized access keys file?

Please provide the path (e.g., ~/Documents/Access.txt) or type 'manual' to enter keys directly.
Default Locations to Check
bash
~/Documents/Access.txt
~/Access.txt
~/.secrets/keys.txt
~/.credentials.txt

Supported File Formats

The credentials file can use any of these formats:

Format 1: Colon-separated
Render API: rnd_xxxxx
OpenAI API: sk-proj-xxxxx
Claude API: sk-ant-xxxxx
Reddit client id: xxxxx
Reddit secret: xxxxx
Format 2: Key=Value
RENDER_API_KEY=rnd_xxxxx
OPENAI_API_KEY=sk-proj-xxxxx
ANTHROPIC_API_KEY=sk-ant-xxxxx
Format 3: Mixed/Informal
Reddit api access:
client id Y1FgKALKmb6f6UxFtyMXfA
and secret is -QLoYdxMqOJkYrgk5KeGPa6Ps6vIiQ

Key Identification Patterns

Use these patterns to identify keys in the file:

ServicePatternEnv Variable
OpenAIsk-proj-* or sk-*OPENAI_API_KEY
Claude/Anthropicsk-ant-*ANTHROPIC_API_KEY
Renderrnd_*RENDER_API_KEY
Eleven Labssk_* (not sk-ant/sk-proj)ELEVEN_LABS_API_KEY
Replicater8_*REPLICATE_API_TOKEN
SupabaseURL + eyJ* (JWT)SUPABASE_URL, SUPABASE_ANON_KEY, SUPABASE_SERVICE_ROLE_KEY
Redditclient_id + secret pairREDDIT_CLIENT_ID, REDDIT_CLIENT_SECRET
GitHubghp_* or github_pat_*GITHUB_TOKEN
Vercel*_* (from vercel.com)VERCEL_TOKEN
Stripe (Test)sk_test_*, pk_test_*STRIPE_SECRET_KEY, STRIPE_PUBLISHABLE_KEY
Stripe (Live)sk_live_*, pk_live_*STRIPE_SECRET_KEY, STRIPE_PUBLISHABLE_KEY
Stripe Webhookwhsec_*STRIPE_WEBHOOK_SECRET
TwilioSK* + Account SIDTWILIO_API_KEY, TWILIO_ACCOUNT_SID
SendGridSG.*SENDGRID_API_KEY
AWSAKIA* + secretAWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY
PostHogphc_*POSTHOG_API_KEY, NEXT_PUBLIC_POSTHOG_KEY

Parsing Credentials File

When reading the user's access file, extract keys using these rules:

python
# Python parsing logic
import re
from pathlib import Path

def parse_credentials_file(file_path: str) -> dict[str, str]:
    """Parse various credential file formats."""
    content = Path(file_path).expanduser().read_text()
    credentials = {}

    # Pattern matching for known key formats
    patterns = {
        'OPENAI_API_KEY': r'sk-proj-[A-Za-z0-9_-]+',
        'ANTHROPIC_API_KEY': r'sk-ant-[A-Za-z0-9_-]+',
        'RENDER_API_KEY': r'rnd_[A-Za-z0-9]+',
        'REPLICATE_API_TOKEN': r'r8_[A-Za-z0-9]+',
        'ELEVEN_LABS_API_KEY': r'sk_[a-f0-9]{40,}',
        'GITHUB_TOKEN': r'ghp_[A-Za-z0-9]+|github_pat_[A-Za-z0-9_]+',
        'STRIPE_SECRET_KEY': r'sk_(live|test)_[A-Za-z0-9]+',
        'STRIPE_PUBLISHABLE_KEY': r'pk_(live|test)_[A-Za-z0-9]+',
        'STRIPE_WEBHOOK_SECRET': r'whsec_[A-Za-z0-9]+',
        'POSTHOG_API_KEY': r'phc_[A-Za-z0-9]+',
    }

    # Supabase requires special handling (URL + JWT tokens)
    supabase_url = re.search(r'https://[a-z0-9]+\.supabase\.co', content)
    anon_key = re.search(r'anon[^:]*:\s*(eyJ[A-Za-z0-9_-]+\.[A-Za-z0-9_-]+\.[A-Za-z0-9_-]+)', content, re.I)
    service_role = re.search(r'service.?role[^:]*:\s*(eyJ[A-Za-z0-9_-]+\.[A-Za-z0-9_-]+\.[A-Za-z0-9_-]+)', content, re.I)

    if supabase_url:
        credentials['SUPABASE_URL'] = supabase_url.group(0)
    if anon_key:
        credentials['SUPABASE_ANON_KEY'] = anon_key.group(1)
    if service_role:
        credentials['SUPABASE_SERVICE_ROLE_KEY'] = service_role.group(1)

    for env_var, pattern in patterns.items():
        match = re.search(pattern, content)
        if match:
            credentials[env_var] = match.group(0)

    # Reddit requires special handling (client_id + secret pair)
    reddit_id = re.search(r'client.?id[:\s]+([A-Za-z0-9_-]+)', content, re.I)
    reddit_secret = re.search(r'secret[:\s]+([A-Za-z0-9_-]+)', content, re.I)
    if reddit_id:
        credentials['REDDIT_CLIENT_ID'] = reddit_id.group(1)
    if reddit_secret:
        credentials['REDDIT_CLIENT_SECRET'] = reddit_secret.group(1)

    return credentials
typescript
// TypeScript parsing logic
function parseCredentialsFile(content: string): Record<string, string> {
  const credentials: Record<string, string> = {};

  const patterns: Record<string, RegExp> = {
    OPENAI_API_KEY: /sk-proj-[A-Za-z0-9_-]+/,
    ANTHROPIC_API_KEY: /sk-ant-[A-Za-z0-9_-]+/,
    RENDER_API_KEY: /rnd_[A-Za-z0-9]+/,
    REPLICATE_API_TOKEN: /r8_[A-Za-z0-9]+/,
    ELEVEN_LABS_API_KEY: /sk_[a-f0-9]{40,}/,
    GITHUB_TOKEN: /ghp_[A-Za-z0-9]+|github_pat_[A-Za-z0-9_]+/,
    STRIPE_SECRET_KEY: /sk_(live|test)_[A-Za-z0-9]+/,
    STRIPE_PUBLISHABLE_KEY: /pk_(live|test)_[A-Za-z0-9]+/,
    STRIPE_WEBHOOK_SECRET: /whsec_[A-Za-z0-9]+/,
    POSTHOG_API_KEY: /phc_[A-Za-z0-9]+/,
  };

  for (const [envVar, pattern] of Object.entries(patterns)) {
    const match = content.match(pattern);
    if (match) credentials[envVar] = match[0];
  }

  // Reddit pair
  const redditId = content.match(/client.?id[:\s]+([A-Za-z0-9_-]+)/i);
  const redditSecret = content.match(/secret[:\s]+([A-Za-z0-9_-]+)/i);
  if (redditId) credentials.REDDIT_CLIENT_ID = redditId[1];
  if (redditSecret) credentials.REDDIT_CLIENT_SECRET = redditSecret[1];

  return credentials;
}

Validation Commands

After extracting keys, validate them:

OpenAI
bash
curl -s -o /dev/null -w "%{http_code}" \
  -H "Authorization: Bearer $OPENAI_API_KEY" \
  https://api.openai.com/v1/models
# 200 = valid
Anthropic/Claude
bash
curl -s -o /dev/null -w "%{http_code}" \
  -H "x-api-key: $ANTHROPIC_API_KEY" \
  -H "anthropic-version: 2023-06-01" \
  https://api.anthropic.com/v1/models
# 200 = valid
Render
bash
curl -s -o /dev/null -w "%{http_code}" \
  -H "Authorization: Bearer $RENDER_API_KEY" \
  https://api.render.com/v1/services
# 200 = valid
Reddit
bash
# Get OAuth token first
TOKEN=$(curl -s -X POST \
  -u "$REDDIT_CLIENT_ID:$REDDIT_CLIENT_SECRET" \
  -d "grant_type=client_credentials" \
  -A "CredentialTest/1.0" \
  https://www.reddit.com/api/v1/access_token | jq -r '.access_token')
# Non-null token = valid
Replicate
bash
curl -s -o /dev/null -w "%{http_code}" \
  -H "Authorization: Token $REPLICATE_API_TOKEN" \
  https://api.replicate.com/v1/models
# 200 = valid

Project Setup Workflow

When initializing a project that needs API keys:

Step 1: Ask for Credentials File
This project needs the following API keys:
- ANTHROPIC_API_KEY (for Claude)
- SUPABASE_URL and SUPABASE_ANON_KEY

Do you have an access keys file? Please provide the path:
Step 2: Read and Parse
python
# Read the file
credentials = parse_credentials_file("~/Documents/Access.txt")

# Show what was found
print("Found credentials:")
for key, value in credentials.items():
    masked = value[:8] + "..." + value[-4:]
    print(f"  {key}: {masked}")
Step 3: Validate Keys
Validating credentials...
✓ ANTHROPIC_API_KEY: Valid
✓ REDDIT_CLIENT_ID: Valid
✗ SUPABASE_URL: Not found in file
Step 4: Create .env File
bash
# Write to project .env
cat > .env << EOF
# Auto-generated from ~/Documents/Access.txt
ANTHROPIC_API_KEY=sk-ant-xxx...
REDDIT_CLIENT_ID=xxx...
REDDIT_CLIENT_SECRET=xxx...
EOF

# Add to .gitignore if not present
echo ".env" >> .gitignore
Step 5: Report Missing Keys
Missing credentials that need manual setup:
- SUPABASE_URL: Get from supabase.com/dashboard/project/[ref]/settings/api
- SUPABASE_ANON_KEY: Same location as above

Would you like me to open these URLs?

Service-Specific Setup Guides

Reddit (from Access.txt)
Found in your access file:
- REDDIT_CLIENT_ID: Y1FgKA...
- REDDIT_CLIENT_SECRET: -QLoYd...

Also needed (add to Access.txt or enter manually):
- REDDIT_USER_AGENT: YourApp/1.0 by YourUsername
Supabase (typically not in file)
Supabase credentials are project-specific. Get them from:
https://supabase.com/dashboard/project/[your-ref]/settings/api

Required:
- SUPABASE_URL
- SUPABASE_ANON_KEY
- SUPABASE_SERVICE_ROLE_KEY (for admin operations)

Security Rules

  • NEVER commit Access.txt or its path to git
  • NEVER log full API keys - always mask middle characters
  • ALWAYS add .env to .gitignore
  • ALWAYS use environment variables, never hardcode keys
  • VALIDATE keys before using them in production setup

Quick Reference

bash
# Check if credentials file exists
ls -la ~/Documents/Access.txt

# Common env var names
OPENAI_API_KEY
ANTHROPIC_API_KEY
RENDER_API_KEY
REDDIT_CLIENT_ID
REDDIT_CLIENT_SECRET
REPLICATE_API_TOKEN
ELEVEN_LABS_API_KEY
SUPABASE_URL
SUPABASE_ANON_KEY
GITHUB_TOKEN
Prompt Template
I need API credentials for this project.

Do you have a centralized access keys file (like ~/Documents/Access.txt)?

If yes, provide the path and I'll:
1. Read and parse your keys
2. Validate they're working
3. Set up your project's .env file
4. Tell you which keys are missing

© alinaqi, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/credentials of alinaqi/maggy.

Open the folder on GitHubat commit 72a456e

Compare with similar skills

Credentials next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Credentials compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Credentials this skillalinaqi/maggy707—~2.4kAutomated safety check: NotesMIT
Stripe Best Practiceskanchengw/cnllm1753 repos~925Automated safety check: PassApache-2.0
Scanning For Hardcoded Secretsjeremylongshore/tons-of-skills-marketplace2.8k—~2.1kAutomated safety check: NotesMIT
Audit Env Variablesqdhenry/Claude-Command-Suite1.3k—~2.8kAutomated safety check: NotesNone
Expo Examplessickn33/agentic-awesome-skills47k1 repos~1.7kAutomated safety check: NotesMIT
Expo Examplesexpo/skills2.7k—~1.7kAutomated safety check: NotesMIT

Similar skills

  • Stripe Best Practices

    kanchengw/cnllm

    Guides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, Treasury financial…

    175 GitHub starsUsed in 3 repos~925 tokens
    Backend & APIsAuto-check passed
  • Scanning For Hardcoded Secrets

    jeremylongshore/tons-of-skills-marketplace

    Scan a source-code tree for hardcoded credentials embedded in source files: AWS access keys, GitHub tokens, Stripe keys, Slack tokens, Anthropic API keys, OpenAI keys, JWT signing secrets, generic…

    2.8k GitHub stars~2.1k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Audit Env Variables

    qdhenry/Claude-Command-Suite

    Analyze environment variables in JavaScript/TypeScript projects.

    1.3k GitHub stars~2.8k tokensUpdated 7 mo ago
    DevOps & CloudAuto-check: notes
  • Expo Examples

    sickn33/agentic-awesome-skills

    Expo's official example projects — the expo/examples repo of ~70 with- integrations (Stripe, Clerk, Supabase, OpenAI, maps, Reanimated, SQLite, Skia, NativeWind, and more).

    47k GitHub starsUsed in 1 repo~1.7k tokens
    MobileAuto-check: notes
  • Expo Examples

    expo/skills

    Official

    Expo's official example projects - the expo/examples repo of ~70 with- integrations (Stripe, Clerk, Supabase, OpenAI, maps, Reanimated, SQLite, Skia, NativeWind, and more).

    2.7k GitHub stars~1.7k tokensUpdated yesterday
    MobileAuto-check: notes
  • Security Secrets

    IgorWarzocha/Opencode-Workflows

    Review secret detection patterns and scanning workflows. An agent skill from IgorWarzocha/Opencode-Workflows.

    122 GitHub stars~1.2k tokensUpdated 8 mo ago
    SecurityAuto-check: notes

More from alinaqi/maggy

All 71 skills in this repo
  • AI Models

    alinaqi/maggy

    Latest AI models reference - Claude, OpenAI, Gemini, Eleven Labs, Replicate

    707 GitHub starsUsed in 1 repo~4.1k tokens
    Auto-check passed
  • Azure Cosmosdb

    alinaqi/maggy

    Azure Cosmos DB partition keys, consistency levels, change feed, SDK patterns

    707 GitHub starsUsed in 1 repo~4.5k tokens
    Auto-check passed
  • LLM Patterns

    alinaqi/maggy

    AI-first application patterns, LLM testing, prompt management

    707 GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Woocommerce

    alinaqi/maggy

    WooCommerce REST API - products, orders, customers, webhooks

    707 GitHub starsUsed in 1 repo~4.4k tokens
    Auto-check: notes
  • Aeo Optimization

    alinaqi/maggy

    AI Engine Optimization - semantic triples, page templates, content clusters for AI citations

    707 GitHub stars~3.7k tokensUpdated 14 days ago
    Auto-check passed
  • Agent Teams

    alinaqi/maggy

    Claude Code Agent Teams - default team-based development with strict TDD pipeline enforcement

    707 GitHub stars~5k tokensUpdated 14 days ago
    Auto-check: notes

Questions about Credentials

What does Credentials do?

Centralized API key management from Access.txt. An agent skill from alinaqi/maggy. Credentials is an agent skill from alinaqi/maggy.

When should I use Credentials?

Credentials fits situations like: tasks that involve Cryptography.

How do I install Credentials in Claude Code?

Run `npx skills add alinaqi/maggy --skill credentials -a claude-code`. Or copy the skill folder (skills/credentials in alinaqi/maggy) into .claude/skills/credentials in your project. Claude Code loads it when a task matches its description.

How do I install Credentials in Codex?

Run `npx skills add alinaqi/maggy --skill credentials -a codex`. Or copy the skill folder (skills/credentials in alinaqi/maggy) into .agents/skills/credentials in your project. Codex loads it when a task matches its description.

Can I use Credentials in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alinaqi/maggy --skill credentials -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/credentials, .gemini/skills/credentials, .github/skills/credentials and .opencode/skills/credentials in your project.

What does Credentials need to run?

Going by SKILL.md and its folder, Credentials needs the command-line tools its instructions call (curl, claude, jq and supabase) and credentials named ANTHROPIC_API_KEY, REDDIT_CLIENT_SECRET, OPENAI_API_KEY and RENDER_API_KEY. Our summary lists: Python 3; A credential in RENDER_API_KEY; A credential in OPENAI_API_KEY.

Does Credentials access the network?

SKILL.md names 6 domains. In commands or code: api.openai.com, api.anthropic.com, api.render.com, reddit.com, api.replicate.com and supabase.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Credentials safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Credentials use?

Credentials is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Credentials use?

About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Credentials?

Skills that share tags, products or a category with Credentials: Stripe Best Practices (kanchengw/cnllm, 175 stars), Scanning For Hardcoded Secrets (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Audit Env Variables (qdhenry/Claude-Command-Suite, 1.3k stars) and Expo Examples (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Credentials?

alinaqi (a GitHub user) maintains it in alinaqi/maggy, which has 707 GitHub stars. The repository holds 71 skills in this directory. The repository was last updated on September 24, 2026.

Source: alinaqi/maggy on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.