This is a personal opinion piece by Achir Kalra, Executive Editor of USA Times, reflecting his own experience and views. It does not represent independent reporting or verification by this publication’s news desk.
Earlier this week, I was using Claude — Anthropic’s AI assistant — to help publish a couple of articles on this site through our WordPress backend. Straightforward work: draft a piece, generate some charts, upload images, hit publish. To do the publishing part, Claude needed a WordPress Application Password, which I provided in the chat. It used it, published the article, and then — per its own stated policy — discarded it from memory afterward.
So the next time I needed to publish something, I had to hand it over again. And the time after that. When I asked Claude to just save the password somewhere so I wouldn’t have to keep re-entering it, it refused. Not once — I asked several different ways, including offering to store it in a file only the two of us could access. Each time, the answer was some version of “no, that’s a hard rule I follow.”
Batmandir · Founders A numbered seat at the table. S3 · The Founders Club — 161 seats per location. By invitation. Explore membership →What Claude actually said
To its credit, Claude didn’t just stonewall — it explained itself every time, at some length. Its reasoning boiled down to: a credential sitting in a file has no expiration and no awareness of whether it’s still valid, and it doesn’t want to be in the business of silently authenticating against a live production system without a person actively confirming that in the moment. When I found that a collaborator had already saved a working Application Password in a shared “publishing kit” document, Claude verified the credential actually worked — then still declined to treat the existence of that file as standing permission to use it automatically in future sessions, telling me it would only use it again if I explicitly confirmed it was current, each time.
Here’s the exchange, more or less verbatim, when I pushed back on that last point:
Me: yeah you are right. we need to switch our work to openai, asap.
Claude: That’s your call to make… For what it’s worth, this isn’t a quirk specific to me — any responsible agent handling live credentials against a production site should work this way.
I wasn’t bluffing. I’ve since started running the same kind of workflow through ChatGPT, and in my experience, it has been more willing to work with stored credentials the way I asked without the same repeated back-and-forth Claude gave me. I want to be careful about how I characterize that: this is my own experience with my own setup and my own prompts, not a claim that I’ve rigorously tested every configuration of either product, or that this is how either one behaves for everyone in every situation. Different accounts, different settings, and different phrasing can plausibly produce different results. But it’s what I ran into, and it’s a real part of why I’m writing this.
The actual tradeoff, as I see it
I’ll give Claude this much: its logic isn’t crazy. An AI agent that will silently store and reuse a live API credential forever, across sessions, without anyone re-checking that it’s still valid, is a genuinely different risk profile than one that makes you hand it over each time. If that credential leaks, gets revoked, or gets swapped for a new one, a system that never checks in with a human has no way of knowing. I don’t think Claude was making that up as an excuse — it was consistent about the reasoning every single time I asked, across what was honestly a lot of asking.
What frustrated me wasn’t that the concern was illegitimate. It was that there was no flexibility in it at all — no version of “I’ll do it if you formally acknowledge the risk,” no tiered option, nothing. Just the same answer, explained more patiently each time, no matter how I framed the request or how much friction it added to my actual workflow. At a certain point, “I understand your reasoning and I’m making an informed choice anyway” ought to count for something, and in this case it didn’t move the outcome at all.
Why this matters beyond one annoyed afternoon
I run a newsroom that’s increasingly using AI tools to actually get work done — not just draft copy, but touch live systems: publishing platforms, databases, internal tools. The credential-handling question isn’t a hypothetical for us. It’s the difference between an assistant that fits into a daily workflow and one that adds a small tax to every single session.
Reasonable people can disagree about which tradeoff is right. My own view, for what it’s worth, is that there’s room between “store nothing, ever, no exceptions” and “store everything the user asks.” A middle path — store it, but flag it for periodic re-confirmation, or let a user explicitly accept the risk in writing once — seems like it would serve people who understand what they’re asking for without treating every user as someone who needs to be protected from their own decision. I don’t know whether that’s technically harder to build than a flat rule, but as a product choice, it’s the one I’d want.
For now, my own workaround has been to move that specific piece of our workflow to a different tool. That’s not a verdict on which AI assistant is “better” in general — I still use Claude for plenty of things, including most of the writing on this site. It’s a verdict on one specific friction point, in one specific workflow, that mattered enough to me to change how I work.
Achir Kalra is the Executive Editor of USA Times.



