The latest commit on main is supported.
- Never commit Kimi API keys, OAuth tokens,
.envfiles, DPAPI blobs, or local Kimi state. - Inject
KIMI_MODEL_API_KEYorANTHROPIC_API_KEYat runtime from a trusted secret manager. - Prefer macOS Keychain or Windows DPAPI for local interactive credentials.
- Revoke and rotate any credential that appears in a commit, issue, log, screenshot, or chat.
- After rotating a local key, rerun the platform
configure-kimi-k3-keyscript. - Do not commit Claude Code settings that contain API credentials.
Use GitHub's private vulnerability reporting for security-sensitive findings. Do not include a live credential in the report.