Four layers of isolation. Each layer is sufficient on its own. Together, they make leakage structurally impossible.This page is the proof, not just the claim. AI tools running on this workstation cannot read the values behind the locked keychain. They cannot obtain a GitHub write credential without taking a visible lease, and they cannot read the file paths where keys live at rest.
Layer 1—nothing is stored, so there is nothing to steal
There is no GitHub token at rest on the workstation. Every GitHub credential is an ephemeral GitHub App installation token minted at the moment of use and discarded with the process that asked for it.git never holds one of its own: a credential helper answers each request, mints a token scoped to
that request, hands it to git, and forgets it.
The chain starts at a command that needs a credential and ends with nothing persisted. A stolen
shell history, a leaked environment dump, or a recovered disk image yields no usable GitHub
credential, because none was ever written.
Layer 2—three credential tiers, and only one is ambient
The credential an agent can obtain without ceremony is deliberately the least useful one. Escalation is not a matter of reading a different secret; it is a different minting path with a different gate.
This is a stronger boundary than “which secret can you read.” A read credential cannot be widened
into a write credential. The write tier mints from a different endpoint under a policy that
pins the repository parameter server-side. An agent that claims write on one repository still cannot
tap a second one with that token. And the administrator tier has no non-interactive path at all.
There is nothing for an agent to read, unlock, or guess.
The lease is the visibility mechanism: a write claim is recorded, exclusive, and self-expiring.
Two agents cannot silently both hold write on one repository. See GitHub
access for the full model.
Layer 3—the keychain holds nothing an agent needs
There is no AI-readable keychain tier. Every automated read moved to the runtime manager, and what stays on the keychain is human-only break-glass material in a locked database. The detail is in macOS Keychain. The boundary that matters here is that an AI subprocess cannot satisfy the unlock prompt. There is no unlocked database holding a credential it could use instead.Layer 4—explicit allow / deny lists in Claude Code
The Claude Code permission system bakes a deny list into the build. Even if the previous layers were bypassed, the harness refuses the file paths that would yield secret material.
The allow list lets the AI inspect metadata, such as whether a keychain entry with a given service name exists, without ever returning the value.
Layer 5—unattended convergence belongs to one identity
The interactive human account has no password-less escalation. Everysudo it
runs is biometrically gated, convergence included. Unattended convergence runs
instead under a dedicated automation account whose grant covers one exact
declarative command and nothing else. It applies store paths that were already
built, with no ad-hoc shell and no other read access. Which harnesses run under
that account is set out in
harness trust tiers.
The launcher banner (verbatim)
Some launchers relaunchclaude under a scoped credential context, such as an AWS profile.
Each prints this to stderr before calling exec claude. The banner lands in the AI’s tool-output
stream, so the agent knows what it can and cannot do this session:
What AI can and cannot do
Source files
For the literal Nix and shell sources behind each layer, see:nix-darwin/modules/darwin/scripts/openbao-github-creds.sh: the credential helper and the claim/release lease.nix-darwin/hosts/common/claude-launchers.zsh: the scoped launchers and banner.nix-claude-code/data/permissions/allow.nix: read-onlysecurityallow list.nix-claude-code/data/permissions/deny.nix: file-path deny globs.nix-darwin/modules/darwin/security.nix: sudoers path restriction.
See also
- GitHub access: the three credential tiers in detail.
- macOS Keychain: the two-database split.
- Doppler: for AI-readable CI secrets that should be present.
- BWS: programmatic AI-token bridge that respects the same scoping rules.