Option B follows standard secrets-management practice and Anthropic's explicit guidance for API credentials. API keys are authentication secrets and should not be embedded in source code or committed to repositories. Anthropic's authentication documentation explicitly recommends storing API keys in a secrets manager, rotating them periodically, and revoking credentials suspected of compromise. Anthropic SDKs can load Claude credentials from environment variables such as ANTHROPIC_API_KEY, allowing the secret to be injected at runtime instead of compiled into the application.
The same principle applies to external service credentials used by a Claude application. Development, staging, and production should normally receive independently scoped credentials through the deployment environment or secret-management infrastructure.
A creates a high-probability credential leak because repository history can retain secrets even after a later deletion. C violates isolation and least privilege by sharing credentials across services and users. D uses email as an uncontrolled secret-distribution channel and creates inconsistent manual configuration.
Therefore, B supplies credentials only at runtime while keeping them outside source control and enabling rotation and environment-specific access. Relevant Study Guide topics: API-key management, secrets managers, environment configuration, credential rotation, least privilege, and secure configuration.
===============