SSD Nodes Learn Hosting plans →
Guides Matt ConnorBy Matt Connor

What a Claude session key gives away

A Claude session key logs a stranger into your whole account. What they can read and spend, why an API key is safer, and how to make a leaked key stop working.

What a Claude session key is

A Claude session key is the browser cookie that keeps you logged in to claude.ai, and handing it to a third party hands over the whole account. The cookie is named sessionKey, it is set on the claude.ai domain, and its value begins with sk-ant-sid01- on older accounts or sk-ant-sid02- on newer ones. Whoever presents that string to Anthropic's servers is you.

That prefix is where the confusion starts. Anthropic API keys also begin with sk-ant-, so a session key looks like a developer credential that was meant to be pasted into a config box. It is not one. An API (application programming interface) key is something you created on purpose, for one job, with its own bill and its own delete button. A session key is only the proof that you already passed the login.

Anthropic's help center states that web sessions last 28 days and refresh hourly with activity. A key you paste today keeps working for weeks, and it keeps refreshing itself while the holder uses it.

Why the key authenticates as the account and not as an app

When the claude.ai web app loads your conversations, it calls endpoints on claude.ai and sends that cookie. The cookie is the only thing proving who is asking. It carries no scope field, no list of allowed actions, and no name for the tool using it. Nothing in the format can say "read chats but do not send messages", or "this is the extension, not the person", because those limits were never part of the design. A browser session means one person in one browser.

So a tool holding your session key is not connected to your account. It is logged in to it. Every request it sends is indistinguishable from a request you made yourself, in your own browser, at your own desk.

What the holder of a Claude session key can read and spend

Assume that anything you can see in the web app, they can see, and anything you can click, they can click. In practice that means:

  • Every conversation in your history, including the old ones where you pasted a config file, a log with real hostnames, or a password.
  • Your Projects, and the files in project knowledge, which is usually where the sensitive documents actually live.
  • Your account settings, your name and email address, your plan, and your billing page.
  • Your connected apps and integrations, which may reach further into a drive or a code host than Claude itself does.
  • Your usage allowance. Messages sent on your key draw from your own five hour session limit and your weekly limit, so the first symptom is often a session limit warning you did not earn.

Some sensitive actions may ask for your password again. Treat that as luck, not as a boundary, because reading never asks. And a copied key can be copied again by whoever holds it, so "we only keep it in your browser" is a promise about one copy, made by the party who took it.

How this differs from an API key

An API key is the credential a tool should be asking for, and the differences are the whole point.

  • Identity: an API key belongs to an organisation and a workspace in Claude Console. It cannot read your chat history, because your chat history is not part of the API.
  • Billing: API usage is billed to the key's own account, while subscription usage comes out of your plan's limits, which you cannot split per tool. That gap is the difference between paying per token and paying a monthly plan.
  • Revocation: you delete one API key at platform.claude.com/settings/keys and everything else keeps running. Killing a leaked session key means logging every one of your own devices out.
  • Leak handling: Anthropic works with GitHub's secret scanning program, so an API key committed to a public repository is detected and deactivated. Nobody scans the internet for your cookie.

Console shows a new API key once, at creation, and never again. That is deliberate, because a credential you can re-read is a credential that leaks quietly. For how those keys travel on a request, see how Claude API authentication actually works. If the tool is a coding agent, signing in with your subscription instead of an API key is a separate decision with real trade-offs, and it happens inside Anthropic's own login flow rather than in a text box in someone's extension.

Signals that a tool should not be asking for this at all

  • It tells you to open developer tools, find sessionKey under Application, then Cookies, and copy the value. A product that needs a browser cookie has no supported way in.
  • It advertises free Claude, or Claude without a subscription. Your subscription is the thing paying for it.
  • It takes the key in a web form, a chat message, or a bot command. The key is now in a database, a log file, and probably a backup.
  • It wants the key so it can show you your usage. Your usage is already on your own page at claude.ai/settings/usage, and reading it does not require giving anyone your login.
  • It is a browser extension that asks for the key in its own interface while also holding permission to read data on claude.ai.

That last one deserves its own check. Before installing any extension that works near claude.ai, read the permission list. Permission to read and change your data on claude.ai includes every cookie set on that domain, so an extension with it does not need you to paste anything. The paste box is the honest version of a capability it already has.

What the account terms say about letting a tool drive your subscription

As of September 2026, Anthropic's Consumer Terms of Service say: "You may not share your Account login information, Anthropic API key, or Account credentials with anyone else." The same clause adds "You also may not make your Account available to anyone else", and that you are responsible for all activity occurring under your account.

Claude Code's legal and compliance page is more specific about the tools themselves. OAuth (open authorization) sign-in is intended for Anthropic's own applications. Third-party developers may not offer claude.ai login inside their products, and may not "route requests through Free, Pro, or Max plan credentials on behalf of their users". The page also states that developers "may not collect, store, or intermediate Claude.ai credentials or session tokens", and that sign-in must complete through Anthropic's own flow. Anthropic reserves the right to enforce this without prior notice.

The consequence lands in an uncomfortable place. The rule binds the developer, but the account is yours. Traffic that breaks the usage policy is traffic from your login, and an enforcement action applies to your login rather than to the wrapper that sent it. That is the part people skip past when a tool explains that there is no risk because it is only using your own subscription.

I already pasted my session key. What now?

Work through this in order. The first two steps exist to make the copied string stop working.

  1. Open claude.ai in a browser, go to Settings, then Account, and find the Active sessions section. Each row shows the device and browser, an approximate location from the IP address, and when that session was last used. Use the three dot menu to terminate anything you do not recognise.
  2. In the same Settings and Account section, press the Log Out button. It signs you out on every device at once, which is what invalidates the session the tool is holding. Expect to log in again on your phone, your desktop app and your other browsers. The control is on the web only, so it is not in the iOS or Android apps.
  3. Open claude.ai/settings/usage and read the current session bar and the weekly total. Consumption you cannot account for is the clearest evidence that something ran on your key. If you are now near a ceiling because of it, what to do when you have hit a Claude limit is a separate question; right now you only need to know whether the usage was yours.
  4. Read your conversation list from the top. Requests made with your key create chats in your own history, so look for conversations you did not start and titles you do not recognise.
  5. Check Settings for changes you did not make: connected apps, integrations, your email address, and your plan.
  6. Rotate any secret that ever appeared in a chat or a project file. Assume it was read. A token or password in a conversation stays exposed until you change it, and changing it is the only fix available to you.
  7. If you find activity that was not yours, email support@anthropic.com. The terms ask you to report unauthorised access immediately, and that record matters if usage or billing has to be sorted out later.

Logging out everywhere ends the access. It does not undo the reading. That is why the decision sitting in front of you now, before anything is pasted, is the only cheap one in this whole sequence.

What to hand a tool instead

For anything automated, create an API key in Claude Console and give the tool that. It carries its own bill, its own limits, and a delete button that costs you nothing else. If a tool cannot work that way, the plain reading is that it was built to drive a subscription it does not pay for.

Whichever credential you settle on, keep it out of prompts, chat messages and repositories. The habits that keep secrets out of an AI agent's reach apply to the credential as much as to the data behind it: one key per tool, held in a secrets manager or an environment file, and never typed into a page that posts it to a server you do not run.

FAQ

Is a Claude session key the same as an API key?

No. They look alike because both start with sk-ant-. A session key is the sessionKey cookie from claude.ai, and it authenticates your entire logged in account: chat history, Projects, settings and billing page. An API key is created in Claude Console, is billed to that organisation, cannot read your claude.ai conversations, and can be deleted on its own without logging you out of anything.

How do I make a leaked Claude session key stop working?

Go to claude.ai, open Settings, then Account, and press the Log Out button. That signs you out across every device and invalidates the existing sessions, so the copied cookie no longer authenticates. If you want to see what was connected first, look at the Active sessions list and terminate rows individually. Do this on the web, because the control is not available in the mobile apps.

Can someone read my old conversations with my session key?

Yes. The cookie authenticates the same web session you use, so your full conversation history, your Projects and the files in project knowledge are all readable. This is the part that no logout can reverse, which is why any password, token or key that once appeared in a chat should be treated as exposed and rotated.

Can a third-party tool legitimately use my Pro or Max subscription?

Not by holding your credentials. As of September 2026, Anthropic's documentation states that OAuth sign-in is for its own applications, that developers may not route requests through Free, Pro or Max plan credentials on behalf of their users, and that they may not collect, store or intermediate claude.ai session tokens. The permitted pattern is you signing in through Anthropic's own flow in Anthropic's own unmodified client. Anything else should be asking for an API key you created yourself.

#claude#security#accounts#browser-extensions#api-keys