{"record":{"id":"16052c66f2181ec2","repo":"Hmbown/CodeWhale","slug":"the-key-was-created-but-saving-it-to-the-local-secret-store","errorCode":null,"errorMessage":"The key was created, but saving it to the local secret store ({slot}) failed: {error}. Copy the secret above into {MACHINE_KEY_ENV} instead.","messagePattern":"The key was created, but saving it to the local secret store \\((.+?)\\) failed: (.+?)\\. Copy the secret above into (.+?) instead\\.","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"crates/cli/src/cloud/machine.rs","lineNumber":1029,"sourceCode":"}\n\n/// Save a freshly minted key as this machine's local `codewhale` credential.\n///\n/// `--use` is the one place a Codewhale API key is written to disk by this\n/// surface, and it writes only locally: the same secret store `codewhale auth`\n/// uses, under the `codewhale` provider's own slot. Nothing is uploaded, and\n/// no other provider's credential is touched.\nfn save_key_as_local_codewhale_credential<W: Write>(\n    secrets: &codewhale_secrets::Secrets,\n    secret: &str,\n    out: &mut W,\n) -> Result<()> {\n    // Refuse to store a value this CLI would not accept as a key: a truncated\n    // response is better caught here than as a 401 on the next model call.\n    let key = MachineKey::parse(secret)?;\n    let slot = ProviderKind::Codewhale.secret_store_slot();\n    secrets.set(slot, secret).map_err(|error| {\n        anyhow!(\n            \"The key was created, but saving it to the local secret store ({slot}) failed: {error}. Copy the secret above into {MACHINE_KEY_ENV} instead.\"\n        )\n    })?;\n    writeln!(out)?;\n    writeln!(\n        out,\n        \"Saved {} as this machine's local `codewhale` provider credential.\",\n        key.head()\n    )?;\n    writeln!(\n        out,\n        \"Select it with `codewhale config set provider codewhale`; models come from the account's own connected providers.\"\n    )?;\n    Ok(())\n}\n\nfn write_key_listing<W: Write>(out: &mut W, keys: &[ApiKeyMetadata]) -> Result<()> {\n    if keys.is_empty() {","sourceCodeStart":1011,"sourceCodeEnd":1047,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/73e0f67d83c59909b571efdfc88c4bc28c309cb1/crates/cli/src/cloud/machine.rs#L1011-L1047","documentation":"After successfully creating an API key on the service, the CLI tries to persist the secret into the local secret store slot for the Codewhale provider. If the store write fails, it wraps the store error and tells the user the key still exists — copy it manually into MACHINE_KEY_ENV.","triggerScenarios":"`secrets.set(slot, secret)` fails after `MachineKey::parse` validated the secret — e.g. no keychain/keyring available, keyring locked, disk/permission issues on the secret store.","commonSituations":"Headless Linux without a secret-service (gnome-keyring/kwallet) daemon; locked keyring prompting for a password that cannot be answered; read-only or full disk; CI containers with no keyring.","solutions":["Copy the secret printed above the error into MACHINE_KEY_ENV and export it — the key was created successfully.","Install/unlock a secret service (e.g. gnome-keyring + libsecret) so the keyring write can succeed, then re-set the key.","On headless systems, use the file-based or env-var secret configuration the CLI supports instead of the OS keyring."],"exampleFix":"// after seeing the error\nexport MACHINE_KEY_ENV=\"<secret printed by the create command>\"","handlingStrategy":"fallback","validationCode":"let key = std::env::var(\"MACHINE_KEY_ENV\").unwrap_or_default();\nif key.trim().is_empty() {\n    // keyring write failed earlier — use the manually copied secret\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Ensure a secret service (gnome-keyring/kwallet) is installed and unlocked on Linux.","Capture and export the printed secret immediately when keyring writes are known to fail.","In CI/headless, always provision MACHINE_KEY_ENV instead of relying on the OS keyring."],"tags":["secrets","keyring","storage","cli"],"backgroundTag":"file-write-failed","analyzedSha":"73e0f67d83c59909b571efdfc88c4bc28c309cb1","analyzedAt":"2026-09-22T01:30:00.501Z","contentChangedAt":"2026-09-22T01:30:00.501Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}