Claude Operator: Prompt to Autonomy · 16 min · 120 XP
Credentials, reads before writes, and clean removal
Three habits that keep a connection from becoming a liability.
Secrets don't go in files you commit. Use the provider's supported flow — OAuth through /mcp, or an environment variable referenced by the config rather than pasted into it. Then check: run a diff before committing and make sure no token entered a tracked file. A leaked key in git history outlives the commit that removed it.
Test a read before you trust a write. Ask for one specific record you can check in the service itself, and compare. This catches the boring failures that would otherwise show up later as confident nonsense: the connection is scoped to the wrong workspace, or it's reading a stale cache, or "the March invoice" means something different to the API than to you.
Removal is part of the lifecycle. claude mcp remove <name> disconnects it, but for anything OAuth-based that's only half — the authorisation still exists in the service until you revoke it there too. A connector you stopped using and never revoked is an access grant nobody is watching.
Practice. Configure credentials through the provider's supported secure flow and confirm with a clean diff that no token reached a tracked file. Run one harmless read and verify the returned record against the source service by eye. Then disconnect the practice server, confirm a tool call no longer works, and revoke the authorisation in the service where that applies.
Loading your workspace…