Never install a Platform key in an agent. A Connection key cannot administer the workspace or select another target by changing the request body. A secret is returned when created; list views expose metadata, not a retrievable copy of that secret.
Use the generated configuration
The CLI writes one value to the repository’s git-ignored.env:
rippletide connect removes superseded discrete Rippletide variables, including RIPPLETIDE_PROXY_URL. Do not re-add it.
The app/manual path supplies:
~/.rippletide/codex.env, not the repository’s .env. Its setup command claims the Connection key on the machine that runs Codex. The app’s single-use session token is a setup token, not a runtime key.
Rotation and revocation
- Agent/MCP Connection key: replace it from the connection’s page and update the runtime configuration. The previous key is revoked when replaced. For a CLI-managed repository, rerun
connectto refresh its configuration. - Direct API integration keys: replacement keys can overlap. Revoke the old key explicitly after switching the integration.
- Platform keys: creating a new one does not revoke older keys. Revoke obsolete keys in Settings after switching your scripts.
- CLI login: a repeated
loginreuses a valid stored key. Uselogoutthenloginto replace it or change accounts. Logout revokes the key before clearing local credentials; failed revocation preserves the local login for retry. CLI-issued keys expire after 90 days.
workspaces use changes the CLI’s authorized workspace through browser approval, independently of the workspace open in the app.
Local files and removal
To disconnect a repository, remove instrumentation, remove the project binding and Rippletide runtime variables, and revoke its Connection key. Keep unrelated
.env values. Account logout is a separate operation. For Codex use its uninstall command.