subagentpermissions

.com permission policy catalog

← all invocation controls

credential revocation equivalent destructive

Write-only secret storage (Cloudflare Worker secrets)

applies to

Every *_WRITE_SECRET value across the family, once set via wrangler secret put

mechanism

Cloudflare Worker secrets have no read-back API — a secret can be overwritten or deleted, never displayed again after it's set

notes

This is the same write-only property security-and-data.md documents for claude-tag's own credential store ("A saved credential is not displayed again. The setup screens are write-only.") — already cited on subagentidentities.com's security-and-data-handling page. It is not reversible in the sense of "recover the old value," matching restrict-access.md's own note that deleting a bundle "revokes its credentials everywhere it was attached."

grounded in

admins/restrict-access.md, "Quiet or remove Claude Tag", step 5 ("Delete the bundle"); concepts/security-and-data.md, "Credential storage"

created 2026-07-02 14:20:40