Overview
keygrant is a secrets manager for AI coding agents such as Claude Code. It lets an agent use your API keys without ever seeing them.
The idea
Anything in a model’s context can leak: through a reply, generated code, a URL in a tool call, request logs, or a prompt-injected instruction hidden in an issue or web page. So keygrant keeps values out of context entirely:
model context: STRIPE_KEY the name, harmless
child process: sk-live-... the value, injected at exec time
output to model: [STRIPE_KEY:REDACTED]
The model writes curl -H "Authorization: Bearer $STRIPE_KEY" ... and never
learns what $STRIPE_KEY expands to.
The four pieces
- Storage in the OS keystore. DPAPI on Windows, the login Keychain on macOS, Secret Service on Linux. Values go in through stdin, never through a command-line argument or a chat message.
- Two MCP tools.
list_secretsreturns names and descriptions only.exec_with_secretsruns one command with the named secrets injected into that child process. There is deliberately no tool to store a secret. - Approval per command. A native dialog shows the full command before any secret is released. See Approvals and grants.
- Output redaction. Output is scrubbed of the secret values (plaintext, base64, hex, URL-encoded) before it returns to the model. It’s a second line of defense; see Redaction.
Where to go next
- New here: the Quickstart takes about three minutes.
- Using another MCP client, or want it in every project: Claude Code and other clients.
- Several machines, or approving from your phone: Cloud sync (preview).
- Every command and flag: CLI reference.
- What it does and doesn’t protect against: the threat model.