Copying an API key into a config file takes a second. Forgetting it on the clipboard can last all day.
Why it matters
- Any app can read the clipboard. On macOS, apps can read what you copied without asking. macOS shows a notice when an app pastes from another device, but not for ordinary reads.
- Universal Clipboard sends what you copy to your other Apple devices nearby.
- Clipboard managers save it. If you use one, the key may now be stored in its history.
- Screen sharing. One accidental ⌘ V into a chat or a call’s shared screen and it’s out.
How to clear it
Copy something harmless, like a space. Or in Terminal:
pbcopy < /dev/null
Stop secrets landing there
- Use your password manager’s autofill instead of copying. Most also clear the clipboard after a short time when you do copy.
- Exclude password managers from your clipboard manager.
- Use a clipboard tool that spots secrets. NotchMind, which I make, has Secret Guard: when you copy something that looks like a key, token or password, the notch offers Clear Clipboard, and it’s never saved in clipboard history. It ignores 1Password, Bitwarden, KeePassXC, LastPass, Dashlane, Passwords and Keychain Access entirely. See Secret Guard.
If a key did leak
Rotate it: create a new one and revoke the old one in the service’s dashboard. Clearing the clipboard doesn’t undo a paste.
NotchMind