What Secret Guard does when you copy a password or API key

Secret Guard spots copied API keys, tokens and passwords, keeps them out of clipboard history and lets you clear the clipboard in one click.

Checked against the app on

Copied secrets linger on the clipboard, where any app can read them. Secret Guard watches for them and helps you clear them.

What it looks for

Secret Guard checks copied text, on your Mac, for patterns such as:

  • GitHub, Stripe, OpenAI and Anthropic keys
  • AWS access keys and secret keys
  • Private keys (PEM)
  • JWTs and bearer tokens
  • Labelled credentials, like password = … or api_key: …
  • Long random tokens that look like a key

When it finds one

The notch shows a red Possible secret copied card:

  • Clear Clipboard empties the clipboard straight away.
  • Keep Once leaves it on the clipboard this time, for when you’re about to paste it.
  • Ignore This Pattern stops warning about this kind of secret. NotchMind asks you to confirm, because it turns that check off until you undo it: Clear Clipboard History in Settings → General → Support turns every check back on.

Whatever you choose, a suspected secret is never saved in clipboard history, and with Smart Mode on it’s never sent for classification.

It isn’t a guarantee

Secret Guard checks for known patterns. It can miss something sensitive, or flag something harmless. Treat it as a helpful warning, not a password manager. Copying from a password manager is safest: NotchMind ignores 1Password, Bitwarden, KeePassXC, LastPass, Dashlane, Passwords and Keychain Access entirely.

Still stuck?

Email support@notchmind.com with your NotchMind build and macOS version, or see Support for what to include. All help articles