mirror of
https://github.com/openclaw/openclaw.git
synced 2026-05-29 17:45:15 +00:00
1.0 KiB
1.0 KiB
summary, read_when, title
| summary | read_when | title | ||
|---|---|---|---|---|
| Secret-scanner-safe placeholder conventions for docs and examples |
|
Secret Placeholder Conventions |
Secret placeholder conventions
Use placeholders that are human-readable but do not resemble real secrets.
Recommended style
- Prefer descriptive values like
example-openai-key-not-realorexample-discord-bot-token. - For shell snippets, prefer
${OPENAI_API_KEY}over inline token-like strings. - Keep examples obviously fake and scoped to purpose (provider, channel, auth type).
Avoid these patterns in docs
- Literal PEM private-key header or footer text.
- Prefixes that resemble live credentials, for example
sk-...,xoxb-...,AKIA.... - Realistic-looking bearer tokens copied from runtime logs.
Example
# Good
export OPENAI_API_KEY="example-openai-key-not-real"
# Better (when the doc is about env wiring)
export OPENAI_API_KEY="${OPENAI_API_KEY}"