Guide

Keeping API Keys Safe at an AI Agent Workshop

A hands-on session changes the risk around a key in ways that have nothing to do with the key itself. The fix is mostly about timing, not cleverness.

Quick Answer

There is no single product called an AI agent workshop. The phrase describes a real situation: a training session, hackathon, or pairing class where several people run coding agents, often on shared screens, borrowed laptops, or one projected demo, sometimes against a key everyone was handed for the day. That setting leaks keys more easily than your own desk, because the screen is often public or recorded, the repository often gets pushed somewhere public before the session ends, and a key handed to a group outlives the person who wrote it down. The fix is to issue a scoped, low-limit key per participant instead of one shared key, keep every key out of anything shown on screen, and rotate every workshop key the moment the session ends.

What people mean by an AI agent workshop

An AI agent workshop is not a product. It is a format: a room, a class, a hackathon table, or a pairing session where more than one person runs a coding agent at the same time, often on hardware or a network they do not fully control.

Two different searches tend to land here. One is about the event itself: how do you stop a key from leaking during a hands-on session. The other is about Google Workspace specifically, because Gemini now shows up inside Gmail, Docs and Sheets, and people assume there is an API key involved somewhere. There usually is not, and the two situations need different answers, covered in the next two sections.

Gemini in Google Workspace does not hand you an API key

If your search was about Google Workspace specifically: Gemini built into Gmail, Docs, Sheets, Slides, Drive and Meet is included for Workspace customers on eligible plans, and it works the same way any other built-in feature does. You do not create, paste or manage an API key to summarize an email or draft a slide. There is nothing to safeguard, because nothing is exposed.

The part that does use an API key is a separate product: the Gemini API, available through Google AI Studio or Vertex AI, built for developers writing their own applications or agents against Google's models. That key behaves like any other provider key, and the advice in the rest of this guide applies to it directly.

So the first useful step is working out which of the two you are actually running. A room full of people clicking Gemini inside Docs has no keys to protect. A room full of people calling the Gemini API from their own scripts does.

  • Gemini inside Gmail, Docs, Sheets, Slides, Drive and Meet: no API key, nothing to leak.
  • The Gemini API, via Google AI Studio or Vertex AI: a real key, with real exposure if it is mishandled.

What a 2026 cowork agent workshop actually needs

Claude Cowork is a real product, not a developer tool: Anthropic built it for non-technical knowledge work, and it runs on a paid Claude.ai plan rather than a developer API key. If your workshop is teaching people to hand research or document work to Cowork, there is no API key for a participant to protect, for the same reason as the Workspace case above: the key does not exist at that layer.

Keys show up once a workshop moves from using an agent product to building with one, wiring up Claude Code, Codex, or a script that calls a model API directly. That is the point where the rest of this page applies.

Why a workshop leaks keys that your own desk would not

A shared session changes the risk in ways that have nothing to do with the key itself. The screen is often projected or recorded, so anything printed to a terminal, including an echoed environment variable, is visible to the whole room and sometimes to a video that outlives the event.

The repository is often pushed somewhere public before the session ends, for grading, for a demo, or because that is just how the class is run. A .env file or a hardcoded key that would stay private on your own machine can end up in a commit within minutes.

And the key itself is often shared on purpose. A workshop organizer hands out one API key for the room so nobody has to sign up for their own account first. That key now outlives the session in group chats, shared documents and screenshots, long after the people who had it have forgotten it exists.

  • Projected or recorded screens turn a printed secret into a public one.
  • A repo pushed for grading or a demo can carry a .env file with it.
  • One shared key for the room keeps circulating after the room empties.

What actually holds up during the session

GitHub scans public repositories for recognizable secret formats automatically and for free, which catches some leaks after the fact. That is a safety net, not a plan. By the time it fires, the key has already been visible to anyone who had the commit.

The better fix is timing: issue a separate, scoped key to each participant for the day, not one key for the room. A key scoped to a single provider, with a low spending limit, costs little if it leaks and is easy to trace back to whoever caused it.

Keep every key out of anything the group can see. That means the Keychain or a secrets manager, not a value typed into a terminal on the projector, and not a value printed by a debug command. Rotate every key the moment the workshop ends, whether or not you think it leaked.

  • One scoped, low-limit key per participant, not one shared key for the room.
  • Keep keys in the Keychain or a secrets manager, never typed where a recording can catch it.
  • Rotate every workshop key at the end, as routine, not as incident response.

How Forkbench handles the single-machine version of this

Forkbench's Vault keeps a key in your Mac's Keychain and lets a command use it by name, so running a workshop exercise does not mean typing the value into a terminal someone else can see over your shoulder or on a shared screen.

If you are pairing or sharing a Thread with someone at a workshop, an invited person gets that one Thread and nothing else. They do not get a copy of your Vault, your other repositories, or your other Threads.

The limit worth knowing: an unpinned Vault key can still be read by the program it was run with. Vault stops the value from appearing in the prompt, the command line, or the transcript. It does not stop a command that was handed the key from doing something careless with it once it is running.

  • A key is used by name, never typed or shown on screen.
  • An invited collaborator gets one Thread, not your whole Vault.
  • An unpinned key is still readable by whatever program it was handed to.

A checklist for the morning of

Most of this is cheap to do before anyone sits down, and expensive to clean up after the fact.

  • Decide whether participants need any API key at all, or just a seat on a product plan like Gemini in Workspace or a Claude.ai plan.
  • Issue one scoped, low-limit key per participant, not one key for the room.
  • Add .env and credential files to the ignore file in any repo used for the session.
  • Keep keys out of anything typed on a projected or recorded screen.
  • Rotate every workshop key once the session ends.

Related: What Claude Cowork is, and how to watch it work, Stop coding agents reading your .env file, An agent read my API keys, what now, How Forkbench handles your data

Frequently asked

  • Do I need an API key to use Gemini in Google Workspace apps?

    No. Gemini inside Gmail, Docs, Sheets, Slides, Drive and Meet is included for eligible Workspace plans and needs no API key from the user. A separate product, the Gemini API through Google AI Studio or Vertex AI, is what developers use, and that one does need a key.

  • Is it safe to share one API key with everyone in a workshop?

    It works, but it is the riskiest option. One shared key outlives the session in chats and screenshots, and a leak cannot be traced to one person. A scoped, low-limit key per participant costs little if it leaks and is easy to attribute.

  • Does Claude Cowork need an API key for a workshop?

    No, for an individual participant. Cowork runs through a paid Claude.ai plan, not a developer API key, so there is nothing at that layer to safeguard.

  • What should I do if a key was shown on a projected screen?

    Treat it as leaked immediately and rotate it. It does not matter whether anyone in the room was paying attention or whether a recording exists; assume both are true.

  • Can Forkbench stop a workshop partner from seeing my key?

    Forkbench's Vault lets a command use a key by name, so it is never typed or shown in the transcript, and an invited collaborator only ever gets the one Thread you shared, not your Vault. A key that was handed to a running program can still be read by that program.

Keep reading