Hmbown/CodeWhale · error
The key was created, but saving it to the local secret store
Error message
The key was created, but saving it to the local secret store ({slot}) failed: {error}. Copy the secret above into {MACHINE_KEY_ENV} instead. What it means
After successfully creating an API key on the service, the CLI tries to persist the secret into the local secret store slot for the Codewhale provider. If the store write fails, it wraps the store error and tells the user the key still exists — copy it manually into MACHINE_KEY_ENV.
Solutions
- Copy the secret printed above the error into MACHINE_KEY_ENV and export it — the key was created successfully.
- Install/unlock a secret service (e.g. gnome-keyring + libsecret) so the keyring write can succeed, then re-set the key.
- On headless systems, use the file-based or env-var secret configuration the CLI supports instead of the OS keyring.
Example fix
// after seeing the error export MACHINE_KEY_ENV="<secret printed by the create command>"
Defensive patterns
Strategy: fallback
Validate before calling
let key = std::env::var("MACHINE_KEY_ENV").unwrap_or_default();
if key.trim().is_empty() {
// keyring write failed earlier — use the manually copied secret
} Prevention
- Ensure a secret service (gnome-keyring/kwallet) is installed and unlocked on Linux.
- Capture and export the printed secret immediately when keyring writes are known to fail.
- In CI/headless, always provision MACHINE_KEY_ENV instead of relying on the OS keyring.
When it happens
Trigger: `secrets.set(slot, secret)` fails after `MachineKey::parse` validated the secret — e.g. no keychain/keyring available, keyring locked, disk/permission issues on the secret store.
Common situations: Headless Linux without a secret-service (gnome-keyring/kwallet) daemon; locked keyring prompting for a password that cannot be answered; read-only or full disk; CI containers with no keyring.
Understand the failure class
Background: "failed to write file", "Could not save figure", "Error saving remote file" — file write failed: causes and fixes across languages and libraries — this error's family across 38 libraries.
Related errors
- Codewhale account login requires an OS credential manager…
- could not clear the Codewhale-owned legacy
- could not snapshot the Codewhale-owned legacy
- doctor configuration validation failed; details omitted…
- ; additionally failed to restore prior secret-store state…
AI-assisted analysis of Hmbown/CodeWhale@73e0f67d83 (2026-09-22).
Data as JSON: /api/errors/16052c66f2181ec2.
Report an issue: GitHub.
Appendix: source
Thrown at crates/cli/src/cloud/machine.rs:1029
}
/// Save a freshly minted key as this machine's local `codewhale` credential.
///
/// `--use` is the one place a Codewhale API key is written to disk by this
/// surface, and it writes only locally: the same secret store `codewhale auth`
/// uses, under the `codewhale` provider's own slot. Nothing is uploaded, and
/// no other provider's credential is touched.
fn save_key_as_local_codewhale_credential<W: Write>(
secrets: &codewhale_secrets::Secrets,
secret: &str,
out: &mut W,
) -> Result<()> {
// Refuse to store a value this CLI would not accept as a key: a truncated
// response is better caught here than as a 401 on the next model call.
let key = MachineKey::parse(secret)?;
let slot = ProviderKind::Codewhale.secret_store_slot();
secrets.set(slot, secret).map_err(|error| {
anyhow!(
"The key was created, but saving it to the local secret store ({slot}) failed: {error}. Copy the secret above into {MACHINE_KEY_ENV} instead."
)
})?;
writeln!(out)?;
writeln!(
out,
"Saved {} as this machine's local `codewhale` provider credential.",
key.head()
)?;
writeln!(
out,
"Select it with `codewhale config set provider codewhale`; models come from the account's own connected providers."
)?;
Ok(())
}
fn write_key_listing<W: Write>(out: &mut W, keys: &[ApiKeyMetadata]) -> Result<()> {
if keys.is_empty() {View on GitHub (pinned to 73e0f67d83)