Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
alsk1992 avatar

Credentials

  • 14 installs
  • 610 repo stars
  • Updated June 26, 2026
  • alsk1992/cloddsbot

Credentials is a skill that securely stores and manages trading-platform API keys using AES-256-GCM encryption with per-user isolation and failure cooldowns.

About

Credentials is a skill for securely storing and managing API keys for trading platforms with AES-256-GCM encryption. A developer adds, lists, tests and removes credentials per platform, and the skill applies cooldowns after failed auth attempts. It matters as the shared secrets layer for the other trading skills in this toolkit.

  • Securely store trading-platform API credentials with AES-256-GCM encryption
  • Add, test and remove creds for Polymarket, Kalshi, Binance, Bybit and more
  • Per-user isolation, failure cooldowns and no secret logging

Credentials by the numbers

  • 14 all-time installs (skills.sh)
  • Ranked #1,623 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
At a glance

credentials capabilities & compatibility

Capabilities
binance futures · bybit futures · crypto hft
Works with
postgres
Use cases
security audit
Pricing
Bring your own API key
From the docs

What credentials says it does

Securely store and manage API credentials for trading platforms with AES-256-GCM encryption.
SKILL.md
**AES-256-GCM** | Military-grade encryption at rest
SKILL.md
npx skills add https://github.com/alsk1992/cloddsbot --skill credentials

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs14
repo stars610
Last updatedJune 26, 2026
Repositoryalsk1992/cloddsbot

What it does

Encrypt, store, test and rotate API credentials for multiple trading platforms with per-user isolation.

Who is it for?

Encrypting and rotating API keys for the trading skills in this toolkit

When should I use this skill?

You need to store, test or rotate trading-platform API credentials securely

By the numbers

  • 8 supported platforms
  • AES-256-GCM encryption
  • default 15-minute cooldown after 3 failures

Files

SKILL.mdMarkdownGitHub ↗

Credentials - Complete API Reference

Securely store and manage API credentials for trading platforms with AES-256-GCM encryption.

---

Chat Commands

Add Credentials

/creds add polymarket                       Interactive setup
/creds add kalshi --key abc --secret xyz    Direct setup
/creds add binance                          Add Binance API
/creds add hyperliquid                      Add wallet key

View Credentials

/creds list                                 List configured platforms
/creds status                               Encryption system status
/creds test polymarket                      Test API connection
/creds check polymarket                     Verify credentials work

Remove Credentials

/creds remove polymarket                    Remove platform creds
/creds clear                                Clear all (careful!)

Auth Status

/auth status                                Overall auth status
/auth refresh kalshi                        Refresh tokens
/auth cooldown                              View cooldown status

---

TypeScript API Reference

Create Credentials Manager

import { createCredentialsManager } from 'clodds/credentials';

const creds = createCredentialsManager({
  // Encryption key (required)
  encryptionKey: process.env.CREDENTIALS_KEY,

  // Storage backend
  storage: 'sqlite',  // 'sqlite' | 'postgres'
  dbPath: './credentials.db',

  // Cooldown settings
  cooldownMinutes: 15,
  maxFailures: 3,
});

Set Credentials

// Polymarket (API + signing key)
await creds.setCredentials({
  userId: 'user-123',
  platform: 'polymarket',
  credentials: {
    apiKey: 'pk_...',
    apiSecret: 'sk_...',
    privateKey: '0x...',  // For order signing
    funderAddress: '0x...',
  },
});

// Kalshi (API key)
await creds.setCredentials({
  userId: 'user-123',
  platform: 'kalshi',
  credentials: {
    email: 'user@example.com',
    apiKey: 'key_...',
  },
});

// Binance Futures
await creds.setCredentials({
  userId: 'user-123',
  platform: 'binance',
  credentials: {
    apiKey: 'abc...',
    apiSecret: 'xyz...',
  },
});

// Hyperliquid (wallet)
await creds.setCredentials({
  userId: 'user-123',
  platform: 'hyperliquid',
  credentials: {
    privateKey: '0x...',
    walletAddress: '0x...',
  },
});

Get Credentials

// Get for specific platform
const polymarketCreds = await creds.getCredentials({
  userId: 'user-123',
  platform: 'polymarket',
});

if (polymarketCreds) {
  console.log(`API Key: ${polymarketCreds.apiKey}`);
  // Credentials are decrypted on retrieval
}

// List user's configured platforms
const platforms = await creds.listUserPlatforms('user-123');
console.log(`Configured: ${platforms.join(', ')}`);

Delete Credentials

// Remove single platform
await creds.deleteCredentials({
  userId: 'user-123',
  platform: 'kalshi',
});

// Remove all for user
await creds.deleteAllCredentials('user-123');

Test Credentials

// Test API connection
const result = await creds.testCredentials({
  userId: 'user-123',
  platform: 'polymarket',
});

if (result.success) {
  console.log(`✓ Connected to ${result.platform}`);
  console.log(`  Balance: $${result.balance}`);
} else {
  console.log(`✗ Failed: ${result.error}`);
}

Cooldown Management

// Mark failed auth attempt
await creds.markFailure({
  userId: 'user-123',
  platform: 'kalshi',
  error: 'Invalid API key',
});

// Check if in cooldown
const inCooldown = await creds.isInCooldown({
  userId: 'user-123',
  platform: 'kalshi',
});

if (inCooldown) {
  const remaining = await creds.getCooldownRemaining({
    userId: 'user-123',
    platform: 'kalshi',
  });
  console.log(`Cooldown: ${remaining} minutes remaining`);
}

// Mark successful auth (resets failures)
await creds.markSuccess({
  userId: 'user-123',
  platform: 'kalshi',
});

Build Trading Context

// Get ready-to-use trading context
const context = await creds.buildTradingContext({
  userId: 'user-123',
  platform: 'polymarket',
});

// Context includes authenticated client
await context.client.getBalance();
await context.client.placeOrder({ ... });

---

Supported Platforms

PlatformCredentials Required
PolymarketAPI key, secret, private key, funder address
KalshiEmail, API key
BetfairApp key, session token
SmarketsAPI key
BinanceAPI key, secret
BybitAPI key, secret
HyperliquidPrivate key, wallet address
MEXCAPI key, secret

---

Security Features

FeatureDescription
AES-256-GCMMilitary-grade encryption at rest
Per-user keysIsolated credential storage
CooldownRate limits on failed attempts
No loggingSecrets never logged
Memory wipeCredentials cleared from memory after use

---

Environment Variables

# Required encryption key (generate with: openssl rand -hex 32)
CREDENTIALS_KEY=your-64-char-hex-key

# Optional: per-platform keys
POLYMARKET_API_KEY=pk_...
POLYMARKET_API_SECRET=sk_...
POLYMARKET_PRIVATE_KEY=0x...
KALSHI_EMAIL=user@example.com
KALSHI_API_KEY=key_...

---

Best Practices

1. Strong encryption key — Use openssl rand -hex 32 2. Rotate keys regularly — Update API keys periodically 3. Test after adding — Always verify credentials work 4. Minimal permissions — Use read-only keys when possible 5. Backup securely — Keep encrypted backups offline

Related skills

Securitysecretsappsec

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.