Catalog/Claude Code

Config & secrets · Transcripts

Claude Code

One directory per project holding the verbatim JSONL history of your Claude Code sessions — every prompt, file read, command, and output — plus subagent and workflow logs.

Anthropic Linux · macOS · Windows JSONL · JSON

Exposure

High
Stores found
2
Holds
API keys · personal data · source code
Confidence
verified

Where it writes

2 stores in the current signature database. Paths shown for a typical macOS install.

Transcripts high

JSONL may hold API keys · personal data · source code

  • all OSes ~/.claude/projects/*dir

One directory per project holding the verbatim JSONL history of your Claude Code sessions — every prompt, file read, command, and output — plus subagent and workflow logs.

  • Set cleanupPeriodDays in your Claude Code settings to limit local retention.
  • Keep ~/.claude out of cloud-synced folders and git repositories.

Source: code.claude.com

Config & secrets high

JSON may hold API keys

  • all OSes ~/.claude.json

Claude Code configuration, which can include account and credential-adjacent material.

  • Ensure this file is not world-readable.
  • Keep it out of synced folders and repositories.

What to do about it

PromptDust flags these stores and leaves them in place; cleanup is your call. If a store holds a live secret, rotate the secret first, since deleting the file won’t un-leak a key that already sat in plain text.

For ongoing work, keep sensitive material out of sessions where you can, and prune old transcripts and caches now and then.

This describes where Claude Code stores data. Metadata only, never your content. Confidence: verified. Spot a mistake? Tell us.

See if this one’s on your machine.

One pass finds every store, for this tool and the other 51.