curl -K config file: keep your Sume API key out of ps output

A key passed with -H shows in ps args and shell history. curl -K reads headers from a chmod 600 file instead. Tested on curl 8.7.1 against a stub.

3 min readSume
All posts

Any process on the machine can list your running commands, and curl -H "x-api-key: sk_..." puts the key in that list for as long as the request runs. On a slow download or a hung connection that can be minutes. It also lands in shell history. curl -K file (long form --config) reads options from a file, so the command line carries no secret.

Checked on curl 8.7.1 against a local listener that never answered: ps -o args= printed curl -s --max-time 3 -H x-api-key: SECRETKEY123 http://127.0.0.1:8895/ for the -H form and curl -s --max-time 3 -K sume.curlrc http://127.0.0.1:8896/ for the config form.

Create the file with tight permissions

Sume's dashboard shows the full key once, at creation. Paste it into the file straight from there. umask 077 makes the file readable only by you (-rw-------).

umask 077
cat > sume.curlrc <<EOF
header = "x-api-key: $SUME_API_KEY"
header = "content-type: application/json"
EOF

Use it

The config adds the headers; the rest of the command stays readable and safe to paste into a ticket. The submit below returned 202 from a stub.

curl -s -K sume.curlrc -H 'Idempotency-Key: kite-k-1' \
  -d '{"model":"wan-3.0","prompt":"a red kite","duration":5,"resolution":"480p"}' \
  https://api.sume.com/v1/videos

Limits of the trick

The key is now in a file, so treat the file like the key: never commit it, delete it on shared machines, and rotate if it leaks. Environment variables are not safer from ps on every platform. Prefer your CI's secret store and write the file at job start. Use one header only; sending both x-api-key and Authorization: Bearer returns 401.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume