Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

No. Bash history is useful for ordinary commands, but saving every command is not safe if you type passwords, API tokens, private keys, or other secrets directly at the prompt. Bash can retain the command text in its history list and write it to ~/.bash_history. Use an application’s supported credential prompt or another appropriate secrets workflow instead of putting a secret in a command.

What Bash history saves

Bash adds commands to its history list before parameter and variable expansion, subject to history controls. By default, it uses ~/.bash_history as the history file: Bash reads the configured file when it starts and ordinarily writes history when the shell exits. With histappend enabled, it appends entries; otherwise, it overwrites the file with saved entries. The HISTFILESIZE setting limits the file’s size. See the GNU Bash Reference Manual.

This behavior makes history convenient for reviewing and reusing commands, but it also means literal sensitive text in a command may be retained. OWASP advises that secrets must not be stored in command-history files such as ~/.bash-history (OWASP CI/CD Security Cheat Sheet). History is not the only exposure: access to an unsecured shell session or utilities that can see command parameters can also reveal information (AWS Secrets Manager best practices).

How Bash history filters work—and where they fall short

Bash provides settings that can omit some commands, but they are convenience filters, not a reliable way to handle secrets. Their behavior depends on configuration, and they do not prevent other forms of command-parameter exposure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Setting Effect
HISTCONTROL=ignorespace Omits a command line that begins with a space.
HISTCONTROL=ignoredups Omits a line identical to the immediately previous history entry.
HISTCONTROL=ignoreboth Combines ignorespace and ignoredups.
HISTCONTROL=erasedups Removes earlier matching entries before saving the new entry.
HISTIGNORE Uses patterns to match whole command lines for omission.

The Bash manual notes that history-control order matters and that later lines of a multi-line compound command may still be saved even when its first line was saved. A leading space only helps when ignorespace is configured, and it is easy to forget. Do not rely on it to protect a credential. See Bash’s history-facility documentation.

Safer ways to handle sensitive commands

  • For routine commands: Keep history if it helps your workflow, while protecting the account and device that hold the history file.
  • For passwords and tokens: Do not put the literal secret in the command you enter. Prefer the application’s supported interactive prompt, credential store, or another suitable secrets-management workflow. The right method depends on the application; no single mechanism is appropriate for every tool.
  • For a session where Bash history should not persist: Bash documents that an unset or null HISTFILE prevents the shell from saving history when it exits. This affects Bash history persistence only; it does not prevent unrelated logging or access to command parameters. See the GNU Bash Reference Manual’s variable documentation.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Should you keep history enabled?

For ordinary commands, history can make work easier to inspect and repeat. Disabling persistence for a particular shell session trades that convenience and recoverability for less retention in Bash’s history file. Handle credentials separately: choosing how an application receives a secret is more important than relying on a history filter to hide a command after you have entered it.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.