{"record":{"id":"91bc320a377be65a","repo":"Hmbown/CodeWhale","slug":"secret-storage-snapshot-failed-for-slot-error-refusing-to","errorCode":null,"errorMessage":"Secret storage snapshot failed for {slot}: {error}. Refusing to write the API key in plaintext to {}. Fix the configured secret backend and retry; Codewhale did not change that file.","messagePattern":"Secret storage snapshot failed for (.+?): (.+?)\\. Refusing to write the API key in plaintext to (.+?)\\. Fix the configured secret backend and retry; Codewhale did not change that file\\.","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"crates/config/src/credentials.rs","lineNumber":120,"sourceCode":"    // cannot provide that snapshot, fail before changing the config file.\n    let prior_secret = secrets.get(slot);\n    let secret_store_saved = match prior_secret.as_ref().map_err(|error| error.to_string()) {\n        Ok(_) => match secrets.set(slot, api_key) {\n            Ok(()) => {\n                clear_provider_api_key_from_config(store, provider);\n                true\n            }\n            Err(err) => {\n                store.config = original_config;\n                return Err(anyhow::anyhow!(\n                    \"Secret storage write failed for {slot}: {err}. Refusing to write the API key in plaintext to {}. Fix the configured secret backend and retry; Codewhale did not change that file.\",\n                    crate::quote_os_path(store.path())\n                ));\n            }\n        },\n        Err(error) => {\n            store.config = original_config;\n            return Err(anyhow::anyhow!(\n                \"Secret storage snapshot failed for {slot}: {error}. Refusing to write the API key in plaintext to {}. Fix the configured secret backend and retry; Codewhale did not change that file.\",\n                crate::quote_os_path(store.path())\n            ));\n        }\n    };\n    if let Err(error) = store.save() {\n        store.config = original_config;\n        if secret_store_saved {\n            let current = secrets\n                .get(slot)\n                .map_err(|rollback| anyhow::anyhow!(\n                    \"{error}; additionally could not verify secret-store rollback for {slot}: {rollback}\"\n                ))?;\n            if current.as_deref() == Some(api_key) {\n                match prior_secret.expect(\"snapshot succeeded before secret write\") {\n                    Some(previous) => secrets.set(slot, &previous),\n                    None => secrets.delete(slot),\n                }","sourceCodeStart":102,"sourceCodeEnd":138,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/73e0f67d83c59909b571efdfc88c4bc28c309cb1/crates/config/src/credentials.rs#L102-L138","documentation":"Before mutating the secret store, `set_provider_api_key_unlocked` snapshots the slot's prior value. If the snapshot read itself fails, it rolls back the in-memory config and returns this error rather than proceeding without a known prior state — the API key is never written in plaintext to the config file.","triggerScenarios":"Calling `set_provider_api_key` when the secret backend's initial `get(slot)` (snapshot) fails, before any secret write occurs.","commonSituations":"Keychain/session unavailable, backend permissions denied on read, or secret service crashed between operations.","solutions":["Fix backend availability (unlock keychain / start the secret service) and retry.","Check read permissions on the secret backend for the current user.","The config file is unchanged; simply re-run the command once the backend responds."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"match set_provider_api_key(provider, key) {\n    Err(e) if e.to_string().starts_with(\"Secret storage snapshot failed\") => {\n        eprintln!(\"Secret backend unreadable; unlock it and retry. Nothing was changed.\");\n    }\n    other => other?,\n}","preventionTips":["Verify the secret backend answers reads (e.g. list an existing entry) before auth commands","Keep keychain sessions alive during scripted auth operations","Check backend permissions for the current user"],"tags":["secret-storage","keychain","api-key","credentials"],"backgroundTag":"secret-storage-write-failed","analyzedSha":"73e0f67d83c59909b571efdfc88c4bc28c309cb1","analyzedAt":"2026-09-22T01:30:00.501Z","contentChangedAt":"2026-09-22T01:30:00.501Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}