---
title: "Keep long-lived API keys off your developer laptop"
description: "Learn how Cloudsmith CLI credential helpers swap long-lived API keys on developer workstations for short-lived SAML tokens in Docker, pnpm, Cargo, and Terraform."
canonical_url: "https://cloudsmith.com/blog/oidc-removed-long-lived-credentials-from-your-pipelines-what-about-your-laptop"
last_updated: "2026-10-09T12:00:00.000Z"
---
# Keep long-lived API keys off your developer laptop

Using long-lived credentials in CI/CD and embedding static API keys in pipeline secrets are security risks. The CI platform authenticates a build job’s identity and context, and using short-lived tokens that expire on their own reduces exposure from a credential leak.

Previous discussions of OIDC covered using it to [connect Cloudsmith to your CI/CD](https://cloudsmith.com/blog/securely-connect-cloudsmith-to-your-cicd-using-oidc-authentication), [Dependabot](https://cloudsmith.com/blog/dependabot-with-cloudsmith-using-oidc), and [Kubernetes](https://cloudsmith.com/blog/goodbye-image-pull-secrets-hello-kubernetes-credential-providers), to build [zero trust pipelines with GitHub Actions](https://cloudsmith.com/blog/zero-trust-pipelines-with-oidc-cloudsmith-and-github-actions), and to authenticate workloads using your [AWS](https://cloudsmith.com/blog/authenticate-to-cloudsmith-with-your-aws-identity) or [Google Cloud](https://cloudsmith.com/blog/authenticate-to-cloudsmith-with-your-google-cloud-identity) identities.

For any developer, the common denominator with using these tools is your individual workstation, which likely contains long-lived credentials.

## **The API keys in your dotfiles**

At least one of these files on your local workstation likely contains long-lived API keys:

- `~/.docker/config.json`
- `~/.npmrc`
- `~/.cargo/credentials.toml`
- `~/.terraformrc`
- `pip.conf`, `.netrc`, or an index URL in your shell profile

Each tool has its own login command and config file, which contains a copy of the API key in plain text. It’s the owner’s job to manually rotate these keys.

The [**Shai-Hulud**](https://cloudsmith.com/blog/evolution-of-shai-hulud-worms) npm worm targeted files that contained tokens on developer machines, like `.npmrc`, and used them to access maintainer accounts and workflows.

You can sign into the Cloudsmith CLI with SAML via your company's identity provider. This creates a short-lived token that expires and rotates frequently. Credential helpers enable package managers like Docker and pnpm to borrow this authentication context from the Cloudsmith CLI, avoiding long-lived API keys being stored on disk.

## **Step 1: Sign into Cloudsmith with SAML**

Install the [Cloudsmith CLI](https://docs.cloudsmith.com/developer-tools/cli), then sign in with SAML:

```json
{
  "_key": "d3791f8be17c",
  "_type": "code",
  "code": "cloudsmith auth -w my-workspace",
  "filename": null,
  "language": "shell",
  "markDefs": null
}
```

The result is a short-lived access token, issued from your SAML sign-in. The CLI stores the token in your system keyring, and it expires on its own. The CLI renews it with a refresh token, so you are not sent back to the browser each time it expires. If you run `cloudsmith auth` again while your session can still be renewed, the CLI simply renews it.

Confirm who you are:

```json
{
  "_key": "877beb7bb8c7",
  "_type": "code",
  "code": "cloudsmith whoami",
  "filename": null,
  "language": "shell",
  "markDefs": null
}
```



You now have a short-lived, SAML-backed session. The next step is to share that session with your package managers.

## **Step 2: Set up Cloudsmith credential helpers**

Most package managers already know how to ask an external program for a credential. Docker has **credential helpers**. pnpm has **`tokenHelper`**. Cargo has **credential providers**. Terraform has **`credentials_helper`**. Python has **`keyring`**. Each one is a small, standard hook for a single question: _"Who can give me a credential for this host?"_

The Cloudsmith CLI now answers that question for all of them.

A credential helper does not log you in. It hands your active session to your package manager(s).

When a package manager needs a credential, it calls the helper. The helper asks the CLI for the current access token, and the CLI renews that token if it is close to expiry. Nothing is written into the package manager’s config file.



Here is how to set up each one.

### **Docker**

```json
{
  "_key": "c4100467cdae",
  "_type": "code",
  "code": "cloudsmith credential-helper install docker\ndocker pull docker.cloudsmith.io/my-workspace/my-repo/my-image:latest",
  "filename": null,
  "language": "shell",
  "markDefs": null
}
```



The installer registers `docker-credential-cloudsmith` in `~/.docker/config.json`. You will never need to run `docker login` against Cloudsmith again.

### **pnpm**

```json
{
  "_key": "cbf9f8547187",
  "_type": "code",
  "code": "cloudsmith credential-helper install pnpm\npnpm install",
  "filename": null,
  "language": "shell",
  "markDefs": null
}
```



The installer adds a `tokenHelper` entry to your **user-level** `~/.npmrc`, not the project file, so the helper config never ends up in source control. If you already have an `_authToken` for the same registry, the installer leaves it alone.

### **Cargo**

```json
{
  "_key": "bdfc7f7c9f78",
  "_type": "code",
  "code": "cloudsmith credential-helper install cargo\ncargo fetch",
  "filename": null,
  "language": "shell",
  "markDefs": null
}
```



The provider answers only for Cloudsmith registries, doesn’t require `cargo login`, and writes nothing to `credentials.toml`. For crates.io and anything else, the credential helper steps aside and lets Cargo try the next provider.

### **Terraform**

```json
{
  "_key": "904e3e9d1c1a",
  "_type": "code",
  "code": "cloudsmith credential-helper install terraform -w my-workspace --repo my-repo\nterraform init",
  "filename": null,
  "language": "shell",
  "markDefs": null
}
```



Terraform does not tell a credential helper which repository it wants, so the installer writes your Workspace and repository into `~/.terraformrc` for you. Terraform allows only one credential helper. If you already have one, the installer tells you and does not overwrite it.

### **Python: pip and uv**

[cloudsmith-keyring](https://github.com/cloudsmith-labs/cloudsmith-keyring) gives pip and uv a keyring backend that gets its credential from the Cloudsmith CLI:

```json
{
  "_key": "a191ed0012b3",
  "_type": "code",
  "code": "uv tool install keyring --with cloudsmith-keyring",
  "filename": null,
  "language": "shell",
  "markDefs": null
}
```



```json
{
  "_key": "f206cf138a31",
  "_type": "code",
  "code": "[tool.uv]\nkeyring-provider = \"subprocess\"",
  "filename": null,
  "language": "shell",
  "markDefs": null
}
```

```json
{
  "_key": "a457489761ff",
  "_type": "code",
  "code": "[[tool.uv.index]]\nname = \"cloudsmith\"\nurl = \"https://token@dl.cloudsmith.io/basic/my-workspace/my-repo/python/simple/\"",
  "filename": null,
  "language": "shell",
  "markDefs": null
}
```

The `token` in that URL is not a secret. It is the literal username that Cloudsmith expects for token authentication. Your `pyproject.toml` names the repository, but it contains no credential at all.

### **Everything else**

For tools with no helper mechanism, the **generic helper** prints the current credential as JSON, ready for a wrapper script:

```json
{
  "_key": "e6a364572da8",
  "_type": "code",
  "code": "cloudsmith credential-helper generic | jq -r .password",
  "filename": null,
  "language": "shell",
  "markDefs": null
}
```

## **Missing your favorite package manager?**

We are working on helpers for more package managers. The goal is to make the API key **the exception, not the default**.

Tell us which one you want next! [Open an issue on the Cloudsmith CLI GitHub repository](https://github.com/cloudsmith-io/cloudsmith-cli/issues/new) and let us know which tool you use. Your requests help us decide which helper to build next.

## **Get started in five commands**

```json
{
  "_key": "6122600edf2a",
  "_type": "code",
  "code": "cloudsmith auth -w my-workspace\ncloudsmith credential-helper install docker\ncloudsmith credential-helper install pnpm\ncloudsmith credential-helper install cargo\ncloudsmith credential-helper install terraform -w my-workspace --repo my-repo",
  "filename": null,
  "language": "shell",
  "markDefs": null
}
```



Then use your tools exactly as you do today. One SSO sign-in. One short-lived session. Zero keys in your dotfiles.

OIDC took long-lived credentials out of your pipelines. Credential helpers take them off your laptop. Together, they move every part of your workflow toward short-lived, identity-based access.

Ready to try it? Update to the latest [Cloudsmith CLI](https://docs.cloudsmith.com/developer-tools/cli) and run `cloudsmith auth`.
