Overview

keygrant is a secrets manager for AI coding agents such as Claude Code. It lets an agent use your API keys without ever seeing them.

The idea

Anything in a model’s context can leak: through a reply, generated code, a URL in a tool call, request logs, or a prompt-injected instruction hidden in an issue or web page. So keygrant keeps values out of context entirely:

model context:     STRIPE_KEY        the name, harmless
child process:     sk-live-...       the value, injected at exec time
output to model:   [STRIPE_KEY:REDACTED]

The model writes curl -H "Authorization: Bearer $STRIPE_KEY" ... and never learns what $STRIPE_KEY expands to.

The four pieces

Where to go next