Hmbown/CodeWhale · error

The key was created, but saving it to the local secret store

Error message

The key was created, but saving it to the local secret store ({slot}) failed: {error}. Copy the secret above into {MACHINE_KEY_ENV} instead.

What it means

After successfully creating an API key on the service, the CLI tries to persist the secret into the local secret store slot for the Codewhale provider. If the store write fails, it wraps the store error and tells the user the key still exists — copy it manually into MACHINE_KEY_ENV.

Solutions

  1. Copy the secret printed above the error into MACHINE_KEY_ENV and export it — the key was created successfully.
  2. Install/unlock a secret service (e.g. gnome-keyring + libsecret) so the keyring write can succeed, then re-set the key.
  3. On headless systems, use the file-based or env-var secret configuration the CLI supports instead of the OS keyring.

Example fix

// after seeing the error
export MACHINE_KEY_ENV="<secret printed by the create command>"
Defensive patterns

Strategy: fallback

Validate before calling

let key = std::env::var("MACHINE_KEY_ENV").unwrap_or_default();
if key.trim().is_empty() {
    // keyring write failed earlier — use the manually copied secret
}

Prevention

When it happens

Trigger: `secrets.set(slot, secret)` fails after `MachineKey::parse` validated the secret — e.g. no keychain/keyring available, keyring locked, disk/permission issues on the secret store.

Common situations: Headless Linux without a secret-service (gnome-keyring/kwallet) daemon; locked keyring prompting for a password that cannot be answered; read-only or full disk; CI containers with no keyring.

Understand the failure class

Background: "failed to write file", "Could not save figure", "Error saving remote file" — file write failed: causes and fixes across languages and libraries — this error's family across 38 libraries.

Related errors


AI-assisted analysis of Hmbown/CodeWhale@73e0f67d83 (2026-09-22). Data as JSON: /api/errors/16052c66f2181ec2. Report an issue: GitHub.

Appendix: source

Thrown at crates/cli/src/cloud/machine.rs:1029

}

/// Save a freshly minted key as this machine's local `codewhale` credential.
///
/// `--use` is the one place a Codewhale API key is written to disk by this
/// surface, and it writes only locally: the same secret store `codewhale auth`
/// uses, under the `codewhale` provider's own slot. Nothing is uploaded, and
/// no other provider's credential is touched.
fn save_key_as_local_codewhale_credential<W: Write>(
    secrets: &codewhale_secrets::Secrets,
    secret: &str,
    out: &mut W,
) -> Result<()> {
    // Refuse to store a value this CLI would not accept as a key: a truncated
    // response is better caught here than as a 401 on the next model call.
    let key = MachineKey::parse(secret)?;
    let slot = ProviderKind::Codewhale.secret_store_slot();
    secrets.set(slot, secret).map_err(|error| {
        anyhow!(
            "The key was created, but saving it to the local secret store ({slot}) failed: {error}. Copy the secret above into {MACHINE_KEY_ENV} instead."
        )
    })?;
    writeln!(out)?;
    writeln!(
        out,
        "Saved {} as this machine's local `codewhale` provider credential.",
        key.head()
    )?;
    writeln!(
        out,
        "Select it with `codewhale config set provider codewhale`; models come from the account's own connected providers."
    )?;
    Ok(())
}

fn write_key_listing<W: Write>(out: &mut W, keys: &[ApiKeyMetadata]) -> Result<()> {
    if keys.is_empty() {

View on GitHub (pinned to 73e0f67d83)