Turret Download

All help topics

Explanation

Why Turret holds no credential

Claude and Codex sessions run on the CLI's own login; Gemini is the one exception, held encrypted.

A Claude session runs on whatever claude login already exists on the machine. Turret spawns the CLI and never asks it to hand over a token, a key or a session file. Signing in runs the CLI's own claude auth login on that machine and shows its prompt, not a form of Turret's. Every session after it inherits the same login.

Turret closing or being reinstalled leaves that login untouched, because Turret never held it.

A Codex session runs the same way, against whatever codex login already produced. Turret gives each session its own copy of the login file, so sessions cannot see each other's state. It is not a credential Turret created. Reinstalling Turret changes nothing about a Codex login, since the CLI outside it still holds the answer.

A reader who has seen both engines work this way might expect the others to as well. They do not. Gemini and DeepSeek are the exceptions. Turret stores each engine's API key itself, encrypted with the operating system's own encryption, in a file of its own under Turret's application data.

Turret decrypts a key once, each time it starts a Gemini or DeepSeek process, and places it only in that process's environment. It never logs the key, never writes it into a saved configuration, and never sends it to a window or a phone.

The Settings screen that manages each key reflects the same restraint. It can set a key, replace the key already stored, clear it, or report whether a key is present. It cannot show the key back, on the machine that holds it or on a phone reaching it remotely. Seeing a key again means keeping a copy of it outside Turret.

See Settings for the API key fields on the Gemini and DeepSeek tabs.

The difference comes from how each engine is built. Claude Code and Codex are complete command-line tools with their own sign-in flow, built to run standalone before Turret spawns either. Gemini and DeepSeek run on a background process with no sign-in flow of its own. It expects a key handed to it in its environment, so something has to supply and hold that key.

Turret is that something. Encryption, and a key that is never read back, is how it carries the two credentials it does hold as narrowly as it can.