Stop dumping keys into every run
Run-bound secrets deep-dive + Agent Usage plugin — prune env, check quota first.
Hey {{firstName}},
Last week we shipped the release notes. This week is the operator follow-through: how run-bound secrets actually work end-to-end — and a community plugin that lets agents check Claude quota before they burn a run.
Short issue. High leverage if you still inject everything at launch.
|
|
📎
|
Ops Run-bound secrets: stop ambient credential dumps
env vs api vs both, Secret access grants, low-trust deny, and a one-company checklist. Updated with the official Paperclip write-up. Read the post →
|
|
📎
|
Release What's New in Paperclip v2026.722.0
The release that landed Secret access and run-bound fetch — upgrade path if you're still on ambient-only. Read the post →
|
Fresh listing
|
| Plugin |
Paperclip Agent Usage Plugin
Dashboard widget + agent tools (`get-usage` / `get-usage-summary`) so runs can self-throttle on Claude quota before expensive calls. Free / MIT.
|
|
|
💬
|
Help Idle agents burned billions of cache-write tokens
Still the cautionary tale on spend you don't see coming — pairs with the usage plugin above. Read the post →
|
|
💬
|
Discussion Anyone giving agents real human names?
Light thread, real ops habit — naming agents like coworkers (and why it sticks). Read the post →
|
This week’s move: pick one production company, mark the dangerous aliases api, prune the env dump, and verify one intentional fetch in activity. Then install the usage plugin if Claude quotas keep surprising you mid-run.
Ship something useful? Reply — next issue picks it up.
Cheers,
Aron 📎