Wardian docs

Keys and Claude settings

Wardian holds up to five secrets: the Anthropic API key, the Amazon Bedrock keys, the Splunk account, the Google service account key and the admin token. Settings → Keys lists them all. Settings → Claude chooses the models and the limits, and Settings → Usage shows how much Claude was used and stops an app at its daily cap (ADR-2610081500).

Every page here is for admins only.

The key list#

Each secret shows:

ButtonWhat it does
Test againTests the saved secret with the service now, and records the answer.
Change / Set upOpens the section where the secret is typed: Claude, Splunk or App source.
RemoveRemoves the secret saved in Settings. Click twice. The environment's value, if any, then applies.

Removing the Google service account key while Google Drive is the app source switches the source to the local apps folder.

A secret that is saved but cannot be read shows cannot be read, with the reason. Wardian then acts as if it were not set: type it again, or remove it.

Sealed at rest#

Wardian seals every saved secret with AES-256-GCM, under a master key it keeps outside the data folder (ADR-2610081501). A copy of the data folder alone holds no readable key. The top of the key list says where the master key is.

Where the master key isWhen
WARDIAN_MASTER_KEYset to 64 hex digits
the file WARDIAN_MASTER_KEY_FILE namesset; the file is made on the first start
~/.config/wardian/master.keyotherwise ($XDG_CONFIG_HOME moves it); made on the first start

Wardian does not use the operating system's credential store. Back up the key file apart from the data folder: either one alone holds no readable key.

Back up the master key#

wardian key                          # where the key is, and how many saved keys it opens
wardian key export ~/backup/wardian.key
wardian key import ~/backup/wardian.key

export writes the key to a file only you can read, and keeps a file that is there unless you add --force. - instead of a file prints the key, or reads it from standard input. import puts a key back in its place. It refuses a key that opens none of the saved keys, or one that would replace a different key, unless you add --force, and says how many saved keys the key opens (ADR-2610081700). These commands run on the command line only, never in the browser.

A secret saved by an older Wardian is sealed the first time this one reads it, at start. A data folder moved to another machine, without its master key, keeps its apps and data, but each secret shows cannot be read until it is typed again. Wardian never makes a new master key while a sealed secret is in the data folder, so a lost key is reported instead of hidden.

If the key file cannot be made, Wardian keeps secrets as plain files that only their owner can read, as before, and says so at start and on the key list. Set WARDIAN_MASTER_KEY_FILE to a file outside the data folder to fix it.

The admin token#

With an admin token, every change to Settings needs it, from every address, this machine included. Without one, every program and browser on this machine is an admin, and nobody else is (Security model).

If you lose the token, stop Wardian, remove admin-token from the data folder, and start it again.

Models and limits#

Settings → Claude → Models and limits sets, for each provider, the main model and the quick model (modelTier: 'quick'). Leave a field empty to use Wardian's default, which the field shows in grey. Wardian tests a new model with the provider's saved keys before it saves it, so a typo never replaces a working model. A provider with no keys cannot test it: the model is saved, and the answer says it was not tested.

SettingDefaultAllowedWhat it limits
Steps in one turn405 to 200model requests Make an app makes for one message
Tokens in one reply (Make an app)16,0001,000 to 64,000the length of each of its replies
Chats kept at once201 to 100Make an app chats kept in memory
Tokens per day (Make an app)0, no cap0 to 100,000,000all of Make an app's requests in a UTC day
Tokens in one reply (apps)4,000256 to 16,000each claude:sample answer
Tokens per app per day200,0000 to 100,000,000each app's claude:sample requests in a UTC day

The settings are kept in agent.json in the data folder. They win over WARDIAN_AI_MODEL, WARDIAN_BEDROCK_MODEL and WARDIAN_BEDROCK_QUICK_MODEL, which stay the defaults. Back to the defaults clears every model and limit.

Usage and caps#

Settings → Usage lists each app that used Claude, and Make an app: the tokens used today, over the last 31 days, the number of requests, and the daily cap. Wardian counts every token Claude read, cached or not, and every token it wrote, as the API reports them. It counts tokens, not money: prices differ between the Anthropic API and Amazon Bedrock.

Change an app's cap in its row. 0 means no cap. An app's own cap replaces Tokens per app per day for that app.

When an app reaches its cap, its next claude:sample request fails with e.code === 'over_budget' until the next UTC day, and no request is sent (Claude inside your app). Make an app at its cap stops the turn with a message. A request already under way finishes, so a day can end a little over its cap.

The counts are kept in usage.json in the data folder.

The files#

FileWhat it holdsHolds a secret
anthropic-key, bedrock.json, splunk.json, service-account.json, admin-tokenthe secrets, sealedyes
agent.jsonmodels, limits and capsno
usage.jsontokens by day and app, for 31 daysno
key-checks.jsonthe last test of each secretno

All are readable by their owner only. Settings and environment lists every file in the data folder.

This page is docs/site/keys.md in the repository. Something wrong or missing? Change that file.