Security in DEVUP Code

Sign in by allowing access on devupai.com, without copying an API key. Files that may hold secrets can't be attached, and in Restricted Mode DEVUP AI doesn't write to your files.

Account

Sign in without copying a key

In DEVUP AI, choose Sign in with DEVUP, then click Allow access on devupai.com. The editor completes the sign-in, and there is no API key to copy or paste.

Once you are signed in, the editor keeps that sign-in in secure storage on this device, apart from your settings and your files.

You can also sign in by pasting a DEVUP API key. Remote and web windows use that option.

Account

Sign out and revoke access

To sign out, run DEVUP AI: Sign Out from the Command Palette, or use the Account page of DEVUP AI Settings.

Signing out revokes the key this editor received.

Every editor sign-in gets a key of its own. On the API keys page these keys are marked Editor sign-in, and you can revoke any of them whenever you want.

How your data is handled

How DEVUP AI handles your data is described in the privacy policy.

Files

Files that may hold secrets

Some files may hold secrets: .env files, private keys, certificates, and SSH and Git folders. DEVUP AI leaves them out of file search, refuses to attach them and never changes them.

To protect more files, add never-send patterns of your own. They extend the built-in protection and can never take anything away from it.

Files

Your workspace and file search

File search leaves out what your project excludes, such as the entries in .gitignore.

A repository's own settings can't change DEVUP AI's settings. The one thing a workspace may add is never-send patterns, and those only add protection.

The docs explain which files from your workspace can be attached.

Workspace trust

Restricted Mode

When a workspace is in Restricted Mode, DEVUP AI can still chat with you and read what you attach. It does not write to your files, and it does not read project rules.

Walkthrough

How it works in practice: exploring a repository you have not reviewed

You clone an open-source project to evaluate it, and you want help reading it before you trust anything inside.

  1. Open the folder and keep the workspace in Restricted Mode while you look around.
  2. Attach the entry point with + → current file and ask how the project starts up. Chat and reading attachments work as usual.
  3. Any AGENTS.md or .devupai/rules.md the repository ships is left unread for now, and DEVUP AI writes to none of its files.
  4. The workspace settings it ships cannot change how DEVUP AI behaves; at most they add never-send patterns.
  5. Whatever the repository contains, its .env files, keys and certificates stay out of file search and cannot be attached.
  6. Once you decide to trust the workspace, project rules and file writes are available, and every change made with Apply still waits for your Accept.

At a glance

What each safeguard covers

The safeguards in DEVUP Code, what each one covers, and where you control it
SafeguardWhat it coversWhere you control it
Built-in secret-file protection.env files, private keys, certificates, and SSH and Git folders: kept out of search, not attachable, never changed.Always on. Your own patterns cannot remove it.
Never-send patternsAny other files you name with a pattern.The devupai.context.neverSend setting.
Restricted ModeNo writes to files and no project rules; chat and attachments keep working.Your editor's workspace trust.
Diff before writingEvery change proposed through Apply.Accept or Reject on the diff.
Editor sign-in keysA separate key for each editor sign-in, marked Editor sign-in.The API keys page.
Link confirmationLinks that appear inside replies.You confirm each address before it opens.

Use cases

Security situations and what to do

An editor you no longer use. A laptop has been handed back, or an old installation is gone. Find its key marked Editor sign-in on the API keys page and revoke it there.

Coding over SSH or in the browser. In a remote or web window, pasting a DEVUP API key is the sign-in option to use.

Asking support for help. Copy the diagnostic info, which contains no keys and no chats, and add the request ID that an error lets you copy.

Secrets stored under unusual names. If tokens live in a folder such as secrets/, add a never-send pattern for it. The built-in list keeps covering .env files and private keys alongside your pattern.

For sign-in steps and fixes to common issues, see sign-in and account and troubleshooting in the docs.

Diagnostic info for support

If you contact support, you can copy diagnostic info from DEVUP AI. It holds no keys and no chats.

No usage analytics or telemetry

The extension contains no usage analytics or telemetry.

FAQ

Questions and answers

No. Choose Sign in with DEVUP and approve access on devupai.com; the sign-in then completes with no key to copy. If you prefer, paste a DEVUP API key instead; that is the option remote and web windows use.

When you sign out, the key this editor received is revoked. Every editor sign-in also shows on the API keys page, marked Editor sign-in, and you can revoke it there whenever you like.

Open the API keys page in your DEVUP AI dashboard, find the key marked Editor sign-in for that editor, and revoke it.

It keeps them out of file search, refuses to attach them and never changes them. That covers .env files, private keys, certificates, and SSH and Git folders, plus any files your own never-send patterns name.

No. A repository's settings can only add never-send patterns, which add protection. Every other DEVUP AI setting comes from your own settings.

You can chat, and DEVUP AI reads the files you attach. It doesn't write to files or read project rules while the workspace is restricted.

No. The extension contains no usage analytics or telemetry.

Start coding with DEVUP Code

Create your DEVUP AI account, then sign in from the editor.