> ## Documentation Index
> Fetch the complete documentation index at: https://docs.usepitboard.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and privacy

> pitboard keeps parked logins on your machine, sends them only to the service that issued them, and has no telemetry.

pitboard handles the OAuth refresh tokens of Claude Code and OpenAI's Codex CLI, which grant full access to a paid account. For the full policy, see [SECURITY.md](https://github.com/datlechin/pitboard/blob/main/SECURITY.md).

## Where parked logins are kept

On macOS, parked logins are keychain items whose names start with `pitboard-park-`. pitboard reads and writes them, and Claude Code's own item, only through `/usr/bin/security`, the one program that item trusts. Writing an item through the Security framework would slow every later read of it from 0.01 seconds to about a second, for good.

A Claude Code parked login holds the account's OAuth block, plus any `organizationUuid`, `trustedDeviceToken`, `enterpriseGateway` or `designOauth` stored beside it. Whether restoring a device token spares a re-verification has not been measured. A Codex parked login is Codex's whole login file, `~/.codex/auth.json`.

On Linux, parked logins are files in `~/.pitboard/vault/`, at mode 0600 in a 0700 directory. Claude Code keeps its login in a plaintext `~/.claude/.credentials.json`. `pitboard doctor` fails if anyone else can read that file or the vault. On both systems, it warns if anyone else can read Codex's `auth.json`.

pitboard's other files hold no token, though some hold your email address and project paths; see [Files and environment variables](/reference/files#the-pitboard-directory).

## What leaves your machine

pitboard makes only these requests. It has no server of its own and no telemetry.

| Request                                  | Carries                                                                    | Used for                                                                                                                                                                                                                                                                      |
| ---------------------------------------- | -------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `api.anthropic.com/api/oauth/profile`    | An access token                                                            | Which account a Claude Code login belongs to                                                                                                                                                                                                                                  |
| `api.anthropic.com/api/oauth/usage`      | An access token                                                            | What a Claude Code account has left                                                                                                                                                                                                                                           |
| `platform.claude.com/v1/oauth/token`     | A refresh token and the login's client id, or Claude Code's if it has none | Renewing a Claude Code parked login                                                                                                                                                                                                                                           |
| `chatgpt.com/backend-api/wham/usage`     | An access token and the ChatGPT account id                                 | What a Codex account has left, and whether OpenAI still accepts a login pitboard is about to switch to. It counts against no limit.                                                                                                                                           |
| `auth.openai.com/oauth/token`            | A refresh token and Codex's public client id                               | Renewing a Codex parked login                                                                                                                                                                                                                                                 |
| `github.com/datlechin/pitboard/releases` | Nothing of yours                                                           | The app's update check (`appcast.xml`) and update downloads, only in a copy of the app from a release. It checks once a day while **Check for updates automatically** is on, and when you choose **Check for Updates** or click **Check Now**. The command line never checks. |

pitboard never renews a login a tool is using. Until you enrol a Codex account, pitboard sends OpenAI nothing.

Every request verifies TLS against your system's trust store. Requests to Anthropic and OpenAI time out after 5 seconds.

## Large logins on macOS

pitboard hands a login to `security` in hex on standard input, where `ps` cannot see it. pitboard keeps that input within 4032 bytes, Claude Code's own ceiling, so about 2 KB of login fits.

MCP server tokens can push a Claude Code login past that. Every Codex parked login is past it.

Past the ceiling, pitboard passes the login as an argument, which another process running as you could read while the call lasts. Claude Code writes its own large logins the same way.

A switch or `--sign-in` enrolment that does this says so; a renewal does not.

`PITBOARD_NO_ARGV=1` makes pitboard refuse such a write, so on macOS it cannot park a Codex account. It also leaves such a parked login unrenewed, since the renewed login could not be stored. pitboard refuses before asking the service, so the parked login stays as it was.

The command line reads the variable from your shell. The app reads it from its own environment, which does not include your shell's when the app opens from Finder or at login; `open -a Pitboard` from a shell that sets it passes it on. A daily renewal schedule installed while it is set keeps it.

## What pitboard protects against

* pitboard identifies each login before moving it, so accounts do not get mixed up.
* The next command that changes something finishes or undoes an interrupted switch. If it cannot tell which, it changes nothing; see [Interrupted switches](/concepts/switching#interrupted-switches).
* pitboard records a parked login's name before storing it and retries a failed delete, so no copy goes untracked.
* A locked keychain is reported as unreadable, never as empty.
* pitboard keeps no copy of a login in use.
* pitboard refuses to keep its files in a synced folder, because a parked login belongs to one machine.
* Every release is attested; see [Verify a download](/install/verify).
* The app installs only updates signed with the key it shipped with.

pitboard keeps renewing an unused account's parked login, so its token stays live. `pitboard doctor` warns about an account last switched to 30 days ago or more, and `pitboard forget` deletes its login.

Deleting a parked login does not revoke it, and pitboard revokes no login. Its refresh token stays valid until it expires.

## What pitboard does not protect against

* Another process running as you.
* Another user with administrator access to your computer.
* A compromised Claude Code or Codex, or a compromised library that pitboard uses. CI checks those libraries against known advisories, and each release lists them in a bill of materials.
* `/logout` in a `codex` session started before a switch, which revokes the login pitboard has parked; see [Switch accounts](/guides/switch#what-happens-to-open-sessions).
* Anyone who can already read your files.

## Report a vulnerability

Use [pitboard's private report form](https://github.com/datlechin/pitboard/security/advisories/new), not a public issue.

One person maintains pitboard. Anything that could expose a token comes before other work.
