Dual-mode API key storage — native file-based or AWS Secrets Manager.

OfficialMIT-0Auto-check passedBackend & APIs

Install API Keys

skills CLI
$ npx skills add aws-samples/sample-host-openclaw-on-amazon-bedrock-agentcore --skill api-keys -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws-samples/sample-host-openclaw-on-amazon-bedrock-agentcore api-keys --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws-samples/sample-host-openclaw-on-amazon-bedrock-agentcore.git skills-src && mkdir -p .claude/skills && cp -r skills-src/bridge/skills/api-keys .claude/skills/api-keys && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-keys
GitHub stars
177
Token cost
~825 tokens
SKILL.md length
280 words
Files
7
Skills in repo
5
Repo updated
First seen
Licence
MIT-0

At a glance

Dual-mode API key storage — native file-based or AWS Secrets Manager.

  • Tasks that involve File uploads and storage
  • SKILL.md covers Important, Native File Storage…, Secrets Manager Storage… and Unified Retrieval (retrieve), plus 3 more sections
  • Runs JavaScript scripts from its folder; calls node

What it does

API Keys is an agent skill from aws-samples/sample-host-openclaw-on-amazon-bedrock-agentcore, published by the product's own GitHub organization. Dual-mode API key storage — native file-based or AWS Secrets Manager. Store, retrieve, list, and delete API keys securely. Use managenative for simple file storage, managesecret for Secrets Manager with audit trail. Use retrieve to look up a key from either backend. Use migrate to move keys between backends.

Its SKILL.md is about 830 tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files (for example `common.js`, `migrate.js` and `migrate.test.js`).

It sits in Backend & APIs, covering File uploads and storage. It works with Amazon Web Services. The licence is MIT-0.

When your agent uses it

  • Tasks that involve File uploads and storage

Example prompts

  • “/api-keys”

Requirements

  • Node.js
  • Pre-approved tools (allowed-tools): Bash(node:*)

What it can do on your machine

Read from SKILL.md and the folder at commit b0c427f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(node:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API Keys loads about 825 tokens when it runs. Until then it costs about 80 tokens; SKILL.md has 280 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~80
When it runs · the whole SKILL.md, loaded when a task matches
~825

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws-samples/sample-host-openclaw-on-amazon-bedrock-agentcore at commit b0c427f, republished under its MIT-0 licence (© aws-samples). 280 words, ~825 tokens.

Download SKILL.mdSave it as .claude/skills/api-keys/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
api-keys
description
Dual-mode API key storage — native file-based or AWS Secrets Manager. Store, retrieve, list, and delete API keys securely. Use manage_native for simple file storage, manage_secret for Secrets Manager with audit trail. Use retrieve to look up a key from either backend. Use migrate to move keys between backends.
allowed-tools
Bash(node:*)

API Key Management

Dual-mode API key storage with native file-based and AWS Secrets Manager backends.

Important

Always use the user_id from the system prompt when calling these tools. Never hardcode or guess a user_id. The system provides it automatically.

Native File Storage (manage_native)

Store API keys in a local JSON file (.openclaw/user-api-keys.json), synced to S3 with KMS encryption at rest.

bash
node {baseDir}/native.js <user_id> <action> [key_name] [key_value]
  • user_id (required): The user's namespace (e.g., telegram_12345)
  • action (required): set, get, list, or delete
  • key_name (required for set/get/delete): Alphanumeric key name
  • key_value (required for set): The API key value to store
Examples
bash
node {baseDir}/native.js telegram_12345 set my_api_key sk-abc123
node {baseDir}/native.js telegram_12345 get my_api_key
node {baseDir}/native.js telegram_12345 list
node {baseDir}/native.js telegram_12345 delete my_api_key

Secrets Manager Storage (manage_secret)

Store API keys in AWS Secrets Manager with KMS encryption, audit trail via CloudTrail, and per-user isolation.

bash
node {baseDir}/secret.js <user_id> <action> [key_name] [key_value]
  • user_id (required): The user's namespace (e.g., telegram_12345)
  • action (required): set, get, list, or delete
  • key_name (required for set/get/delete): Alphanumeric key name
  • key_value (required for set): The secret value to store
Examples
bash
node {baseDir}/secret.js telegram_12345 set my_api_key sk-abc123
node {baseDir}/secret.js telegram_12345 get my_api_key
node {baseDir}/secret.js telegram_12345 list
node {baseDir}/secret.js telegram_12345 delete my_api_key

Unified Retrieval (retrieve)

Look up a key from either backend — checks Secrets Manager first, falls back to native file.

bash
node {baseDir}/retrieve.js <user_id> <key_name>

Migrate Between Backends

Move a key from native to Secrets Manager or vice versa.

bash
node {baseDir}/migrate.js <user_id> <key_name> <direction>
  • direction: native-to-secure or secure-to-native

From Agent Chat

  • "Store my OpenAI key securely" -> manage_secret set
  • "Save this API key" -> manage_native set (simpler)
  • "What API keys do I have?" -> manage_native list + manage_secret list
  • "Get my OpenAI key" -> retrieve (checks both backends)
  • "Move my key to Secrets Manager" -> migrate native-to-secure
  • "Delete my API key" -> manage_native delete or manage_secret delete

Security Notes

  • Native mode: Keys stored in .openclaw/user-api-keys.json, synced to S3 with KMS encryption
  • Secrets Manager mode: Keys stored at openclaw/user/{namespace}/{key_name}, auditable via CloudTrail
  • Per-user isolation via STS session-scoped credentials
  • Max 10 secrets per user in Secrets Manager
  • Key names: alphanumeric, starting with letter, max 64 chars

© aws-samples, MIT-0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files in bridge/skills/api-keys of aws-samples/sample-host-openclaw-on-amazon-bedrock-agentcore.

  • SKILL.md
  • common.js
  • migrate.js
  • migrate.test.js
  • native.js
  • retrieve.js
  • secret.js

Open the folder on GitHubat commit b0c427f

Compare with similar skills

API Keys next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API Keys compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API Keys this skillaws-samples/sample-host-openclaw-on-amazon-bedrock-agentcore177—~825Automated safety check: PassMIT-0
FoundatioFoundatioFx/Foundatio2.1k—~3.9kAutomated safety check: PassApache-2.0
PhidownESA-PhiLab/phidown105—~1kAutomated safety check: PassApache-2.0
Fftiers Opsborisachen/fftiers202—~1.8kAutomated safety check: WarnNone
Processing S3 Uploads With Step Functionsaws/agent-toolkit-for-aws2.8k—~4kAutomated safety check: PassApache-2.0
Django Storages for S3Jeffallan/claude-skills12k—~1.9kAutomated safety check: PassMIT

Similar skills

  • Foundatio

    FoundatioFx/Foundatio

    A skill your agent uses when working with Foundatio infrastructure abstractions for .NET -- caching, queuing, messaging, file storage, distributed locking, or background jobs.

    2.1k GitHub stars~3.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Phidown

    ESA-PhiLab/phidown

    Search, filter, download, and analyze Copernicus Data Space products with the phidown project.

    105 GitHub stars~1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Fftiers Ops

    borisachen/fftiers

    Operate the borischen.co fftiers pipeline — season rollover, run main.R, S3 deploy from Workbench or EC2.

    202 GitHub stars~1.8k tokensUpdated 1 mo ago
    Backend & APIsAuto-check: warnings
  • Official

    Deploy an event-driven workflow that routes S3 uploads to either Lambda or Fargate via Step Functions based on file size.

    2.8k GitHub stars~4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Django Storages for S3

    Jeffallan/claude-skills

    Sets up Django 4.2+ to keep static and media files on AWS S3 through django-storages, with public and private backends, presigned URLs and CloudFront.

    12k GitHub stars~1.9k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • AWS V4 Signing Custom Headers Gcs

    divinevideo/divine-mobile

    Add custom metadata headers (x-amz-meta-) to AWS v4 signed requests for GCS S3-compatible API.

    265 GitHub stars~1k tokensUpdated today
    Backend & APIsAuto-check passed

More from aws-samples/sample-host-openclaw-on-amazon-bedrock-agentcore

  • Agentcore Browser

    aws-samples/sample-host-openclaw-on-amazon-bedrock-agentcore

    Official

    Browse web pages using a headless Chromium browser running inside the AgentCore container.

    177 GitHub stars~688 tokensUpdated 9 days ago
    Auto-check passed
  • Clawhub Manage

    aws-samples/sample-host-openclaw-on-amazon-bedrock-agentcore

    Official

    Install, uninstall, and list ClawHub community skills. An agent skill from aws-samples/sample-host-openclaw-on-amazon-bedrock-agentcore.

    177 GitHub stars~593 tokensUpdated 9 days ago
    Auto-check passed
  • Eventbridge Cron

    aws-samples/sample-host-openclaw-on-amazon-bedrock-agentcore

    Official

    Schedule recurring tasks using Amazon EventBridge Scheduler.

    177 GitHub stars~1.1k tokensUpdated 9 days ago
    Auto-check passed
  • S3 User Files

    aws-samples/sample-host-openclaw-on-amazon-bedrock-agentcore

    Official

    Per-user persistent file storage backed by AWS S3. An agent skill from aws-samples/sample-host-openclaw-on-amazon-bedrock-agentcore.

    177 GitHub stars~779 tokensUpdated 9 days ago
    Auto-check passed

Categories

Questions about API Keys

What does API Keys do?

Dual-mode API key storage — native file-based or AWS Secrets Manager. API Keys is an agent skill from aws-samples/sample-host-openclaw-on-amazon-bedrock-agentcore, published by the product's own GitHub organization. Dual-mode API key storage — native file-based or AWS Secrets Manager.

When should I use API Keys?

API Keys fits situations like: tasks that involve File uploads and storage.

How do I install API Keys in Claude Code?

Run `npx skills add aws-samples/sample-host-openclaw-on-amazon-bedrock-agentcore --skill api-keys -a claude-code`. Or copy the skill folder (bridge/skills/api-keys in aws-samples/sample-host-openclaw-on-amazon-bedrock-agentcore) into .claude/skills/api-keys in your project. Claude Code loads it when a task matches its description.

How do I install API Keys in Codex?

Run `npx skills add aws-samples/sample-host-openclaw-on-amazon-bedrock-agentcore --skill api-keys -a codex`. Or copy the skill folder (bridge/skills/api-keys in aws-samples/sample-host-openclaw-on-amazon-bedrock-agentcore) into .agents/skills/api-keys in your project. Codex loads it when a task matches its description.

Can I use API Keys in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws-samples/sample-host-openclaw-on-amazon-bedrock-agentcore --skill api-keys -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-keys, .gemini/skills/api-keys, .github/skills/api-keys and .opencode/skills/api-keys in your project.

What does API Keys need to run?

Going by SKILL.md and its folder, API Keys needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Bash(node:*).

Does API Keys access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is API Keys safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does API Keys use?

API Keys is published under the MIT-0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does API Keys use?

About 825 tokens (SKILL.md is roughly 3.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to API Keys?

Skills that share tags, products or a category with API Keys: Foundatio (FoundatioFx/Foundatio, 2.1k stars), Phidown (ESA-PhiLab/phidown, 105 stars), Fftiers Ops (borisachen/fftiers, 202 stars) and Processing S3 Uploads With Step Functions (aws/agent-toolkit-for-aws, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API Keys?

aws-samples (a GitHub organization, an official publisher) maintains it in aws-samples/sample-host-openclaw-on-amazon-bedrock-agentcore, which has 177 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on September 28, 2026.

Source: aws-samples/sample-host-openclaw-on-amazon-bedrock-agentcore on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.