Storage and platforms
Values always live in the operating system’s own credential store. keygrant’s own files hold metadata only, plus, on Windows, values encrypted to your user account.
| Platform | Values | Files |
|---|---|---|
| Windows | DPAPI, encrypted to your Windows user | %APPDATA%\keygrant\ |
| macOS | login Keychain (service keygrant) | ~/.config/keygrant/ |
| Linux | Secret Service keyring via secret-tool | ~/.config/keygrant/ |
On macOS and Linux the folder follows $XDG_CONFIG_HOME if it’s set.
Files
| File | Contents |
|---|---|
vault.json | one entry per secret: description, created, use count, last used; on Windows also the DPAPI-encrypted value |
revocations.json | revocation times written by keygrant revoke |
cloud.json | cloud account state, only if you use cloud sync; key material in it is itself stored through the OS keystore |
vault.json is safe to back up on macOS and Linux (no values). On Windows the
values in it can only be decrypted by your Windows account on that machine.
Platform notes
Windows. Nothing to install. The approval dialog is a standard
MessageBox, so its buttons follow your system language (Yes/No, 是/否).
macOS. The first time keygrant reads a value, macOS asks whether to let
security access the Keychain item. That prompt is an extra OS-level gate;
“Always Allow” stops it for that item.
Linux. You need secret-tool and a running keyring daemon (GNOME Keyring
or KWallet’s Secret Service), and zenity for approval dialogs:
sudo apt install libsecret-tools zenity # Debian, Ubuntu
sudo dnf install libsecret zenity # Fedora
sudo pacman -S libsecret zenity # Arch
On a headless box without zenity there’s no local dialog: requests go to your
phone approver if you have one, and are denied
otherwise.
Local malware
Anything running as your OS user can ask the keystore for your secrets. keygrant limits what agents can touch; it doesn’t defend against malware already running as you.