Storage and platforms

Values always live in the operating system’s own credential store. keygrant’s own files hold metadata only, plus, on Windows, values encrypted to your user account.

PlatformValuesFiles
WindowsDPAPI, encrypted to your Windows user%APPDATA%\keygrant\
macOSlogin Keychain (service keygrant)~/.config/keygrant/
LinuxSecret Service keyring via secret-tool~/.config/keygrant/

On macOS and Linux the folder follows $XDG_CONFIG_HOME if it’s set.

Files

FileContents
vault.jsonone entry per secret: description, created, use count, last used; on Windows also the DPAPI-encrypted value
revocations.jsonrevocation times written by keygrant revoke
cloud.jsoncloud account state, only if you use cloud sync; key material in it is itself stored through the OS keystore

vault.json is safe to back up on macOS and Linux (no values). On Windows the values in it can only be decrypted by your Windows account on that machine.

Platform notes

Windows. Nothing to install. The approval dialog is a standard MessageBox, so its buttons follow your system language (Yes/No, 是/否).

macOS. The first time keygrant reads a value, macOS asks whether to let security access the Keychain item. That prompt is an extra OS-level gate; “Always Allow” stops it for that item.

Linux. You need secret-tool and a running keyring daemon (GNOME Keyring or KWallet’s Secret Service), and zenity for approval dialogs:

sudo apt install libsecret-tools zenity      # Debian, Ubuntu
sudo dnf install libsecret zenity            # Fedora
sudo pacman -S libsecret zenity              # Arch

On a headless box without zenity there’s no local dialog: requests go to your phone approver if you have one, and are denied otherwise.

Local malware

Anything running as your OS user can ask the keystore for your secrets. keygrant limits what agents can touch; it doesn’t defend against malware already running as you.