Pseudonymized by design

R.Code for Claude Code keeps real names and paths out of the framework itself. Real project names, machine paths and personal identifiers live only in a local vault. Every write, every commit and every publish is checked: 0 real values in any tracked file.

The vault

Real values live only on your machine, in a local vault (gitignored, never committed). The framework’s own tracked files refer to them through tokens instead of the real value.

Several spellings of the same real thing — a short name, a long name, another casing, a path alias — can share one group, so the same real entity stays recognizable as one entity after replacement, instead of splintering into unconnected tokens.

Tokens, not placeholders

A token is an HMAC-SHA256 prefix keyed with a local secret, not a plain hash. Project and account names have too little entropy — a plain hash would be reversible by dictionary lookup; an HMAC keyed with a secret is not. On the same machine a token stays stable across sessions, so a record built over many sessions stays legible together. On a different machine, the same real value produces a different token — two developers’ vaults are never linkable against each other.

Three gates, one matcher

A real value is refused at three independent points, all sourced from the same matcher so no second, independently written check can drift from the first:

  • A PreToolUse hook refuses an Edit or Write that would land a real value in a versioned file.
  • A git pre-commit hook checks staged content for writers outside Claude Code itself.
  • A public CI check checks the published clone, so a gap on one machine still gets caught before the public repo sees it.

Structural patterns — user/volume paths, email addresses, UUIDs, session and trigger identifiers — don’t need a vault entry to be caught, so the same three gates work even in a fresh public clone that has never had a vault.

Contributing without your private data

Working with R.Code for Claude Code naturally produces local findings — observations your own routine writes into your personal, local improvement ledger. Real project names, paths, and account identifiers may legitimately appear there; they belong on your machine, never in the published framework. To share a finding upstream without any of that leaving your machine:

  1. Create your local vault once (idempotent): bash scripts/vault/vault.sh init. Register your own recurring private terms with vault.sh add.
  2. Get a submission form: copy the submission template and fill it in by hand, or pre-fill it from a local ledger entry — every value taken from the ledger is tokenized before it is written.
  3. Have it checked: a clean run prints ready-to-paste issue/PR text on stdout; a finding blocks and names only the kind and token, never the real value.
  4. Open the printed text as a GitHub issue or PR.