Get started

Protect provider credentials

Understand how Kition 0.1.41 stores provider secrets and reduce the impact of device or key compromise.

Updated

By Kition Docs

Verified against Kition 0.1.41 (d3e1b931) on 2026-08-29

Current storage model

In Kition 0.1.41, provider keys and account tokens are stored as local files inside Kition’s application data directory. Kition does not encrypt these files and does not use the operating-system keychain for them in this release.

The files are outside the workspace, so copying or committing a workspace does not copy provider credentials. Their protection depends on your operating-system account permissions, device security, and disk encryption.

Heads up

Anyone or any malware that can read your Kition application data under your user account may be able to read stored provider credentials.

Reduce exposure

  • Use provider project keys instead of an organization-wide key
  • Set provider spend limits, alerts, and the smallest available permissions
  • Keep work and personal provider keys separate
  • Use full-disk encryption and lock the operating-system account when unattended
  • Do not include Kition application data in shared or public backups
  • Do not paste credentials into documents, Agent prompts, screenshots, issue reports, or logs

Workspace backups do not contain the key

Workspace-owned data may contain provider references or Agent history, but secret values are intentionally stored outside the workspace. After moving or cloning a workspace, reconnect providers and external accounts on the new device.

Disable and rotate

In Kition 0.1.41, the external-provider Disconnect action disables the provider but does not reliably invoke the secret-deletion path. Do not use the disconnected status as proof that the plaintext secret file is gone.

Revoke or rotate the key in the provider console to stop remote use. If verified local erasure is required, close Kition and follow support or operating-system application-data removal guidance rather than guessing at files while the app is running.

  • Rotate immediately after accidental disclosure or unexpected usage
  • Review provider audit/usage records before issuing a replacement
  • Update every device that used the old key
  • Confirm the revoked key can no longer make requests

Heads up

The Disconnect dialog text and the 0.1.41 persistence call do not match. Treat remote revocation as the reliable containment step.

Be careful with diagnostics

Debug mode can retain more model-request and turn detail than normal operation. Review logs and screenshots before sharing them, and keep workspace content, prompts, tokens, and private URLs out of public issue attachments.

Implementation sources

Related pages

Ready when you are.

Kition is a desktop AI workspace for connected documents, structured tables, editable designs, whiteboards, visual workflows, and reviewable AI agents.