WEBSITESfor Normal People2026

Part I: Setup (the boring bit that makes it work)04

Chapter 04Step 3

Step 3: Make one place for every key

3 min read, 1 cheat sheet, 2 things to tick

Wait, where do I paste the key? Here. Only here.

This is the chapter that makes everything else work.

Most people who try building with AI hit the same wall. The agent says "go to Cloudflare, create a token, paste it here." You paste it into the chat. Next session, it's gone. You paste it again. Then you paste the wrong one. Then you've got keys scattered across chat history, sticky notes and a file called keys-FINAL-2.txt on your desktop.

The fix: one vault. The agent reads keys from it when it needs them and writes new ones into it when it creates them. You almost never touch it. Nothing sits in a chat, nothing sits in your code.

What to use

Bitwarden Secrets Manager. Free plan: unlimited secrets, 3 projects, 3 "machine accounts" (the login your agent uses). Built exactly for this.

Already pay for 1Password? That works too. See the end of this chapter.

Set it up (the only clicking in this chapter)

This part has to be you, because it's the account the agent logs in with. Five minutes.

  1. Go to bitwarden.com and create an account (or log in).
  2. Create an organization. Bitwarden needs one even if it's just you. Free.
  3. Switch to Secrets Manager with the product switcher (top left).
  4. Create a project called websites.
  5. Create a machine account called claude. Give it Can read, write access to the websites project.
    • Read and write, because the agent is going to create most of your keys itself and needs somewhere to put them.
  6. In the machine account → Access tokens → Create access token. Copy it.
Watch itBitwarden sign-up → organization → switch to Secrets Manager → project → machine account (read, write) → access token.

Personal details are blurred. Press play, it's silent and loops.

Put the master token in your computer's keychain

That access token unlocks the vault, so it's the one key that doesn't go in the vault. It goes in your computer's own keychain, where your passwords already live.

Mac: open Terminal, paste this, press Enter. It asks for the token: paste it and press Enter. Nothing shows while you paste. That's normal.

TerminalCheat sheet 011 lines
security add-generic-password -a "$USER" -s bitwarden-secrets-token -w
Watch itKeychain command in Terminal.

Personal details are blurred. Press play, it's silent and loops.

Windows: Start → Credential Manager → Windows Credentials → Add a generic credential. Internet or network address: bitwarden-secrets-token. User name: anything. Password: the token.

How the agent uses it

Bitwarden has a small command-line tool called bws. The agent installs it and wraps it in a helper called withkeys. When the agent needs to deploy, it runs the command through withkeys, which pulls the keys out of the vault and hands them to that one command. They never get printed, never saved to a file in your project, never land in the chat.

What ends up in the vault

You'll put in one key yourself (chapter 5). The agent adds everything else as it goes.

SecretWho puts it thereUsed for
CLOUDFLARE_BOOTSTRAP_TOKENYouLets the agent create its own Cloudflare token
CLOUDFLARE_API_TOKENAgentDeploys, DNS, database, storage, email, forms
CLOUDFLARE_DEPLOY_TOKENAgentDeploy-only token, the only one GitHub ever sees
CLOUDFLARE_ACCOUNT_IDAgentTells Cloudflare which account
TURNSTILE_SECRET_KEYAgentSpam protection on your forms
PAYLOAD_SECRETAgentThe CMS (Path B)
STRIPE_SECRET_KEYYouPayments (Path C)
STRIPE_WEBHOOK_SECRETAgentConfirms payments actually happened (Path C)
GOOGLE_SERVICE_ACCOUNT_JSONAgentAnalytics and Search Console

If you'd rather use 1Password

1Password's command-line tool, op, does the same job and hooks into the desktop app, so the agent triggers a Touch ID or Windows Hello prompt when it needs a key. Some people love that. Some people find it annoying on the 40th deploy.

  1. Create a vault called websites.
  2. 1Password app → Settings → Developer → turn on Integrate with 1Password CLI.
  3. Use the 1Password line in the chapter 6 prompt.

Checklist

On a phone, swipe left and right to turn pages.