• Sources: primary, discussion
  • Summary: The report checks Claude Code 2.1.257 and finds ~/.claude/.credentials.json holding a top-level mcpOAuth object with access tokens, at file mode 0600. This is not a discrepancy with Anthropic's credential-management documentation, which the author quotes as stating that macOS uses the Keychain with that file as fallback, that Linux uses the file at mode 0600, and that Windows uses the profile directory's access controls. The gap the post identifies is between that documentation and the MCP documentation's phrase stored securely, and it notes that Codex documents auto, file and keyring backends for the same data. The author publishes SecretSpec and the post's proposed remedy is SecretSpec's own SDK and provider integrations, so the remedy is self-interested while the observation is checkable against Anthropic's own pages.
  • Why it matters: MCP server credentials on Linux and Windows sit behind file permissions rather than an OS keyring, so any process running as the user reads them.
  • Follow-up: Track whether Anthropic adds a keyring backend for MCP OAuth tokens or reconciles the two documentation pages.

send feedback on this story