KeyValet lets Claude Code, Cursor and other AI agents use your API keys and OAuth accounts without ever seeing them. You approve each credential with Touch ID, KeyValet makes the call, and every use is written down. KeyValet 让 Claude Code、Cursor 等 AI agent 使用你的 API key 和 OAuth 账号,却看不到它们。每个凭证由你用 Touch ID 批准,由 KeyValet 代为调用,每次使用都有记录。
Open source (Apache-2.0). Runs entirely on your Mac. Works with any MCP client. 开源(Apache-2.0)。完全在你的 Mac 上运行。支持任何 MCP 客户端。
openai/mainThe key stays with the valet. The agent gets the answer. 钥匙留在 KeyValet 手里,agent 只拿到结果。
Four steps, and the secret never leaves the root-only vault.四步完成,秘密始终留在只有 root 能读的凭证库里。
Over MCP, naming the credential and saying why it needs it.通过 MCP 说明要用哪个凭证、为了什么。
Touch ID shows the credential and the purpose. One touch, one credential.Touch ID 弹窗写明凭证和目的。按一次,只授权这一个。
A root helper injects the key, only toward hosts you allowed, and redacts anything that echoes it back.root 进程注入 key,只发往你允许的域名,并抹掉响应里回显的秘密。
Response in, purpose and result logged. The grant ends with the session.返回响应,记录目的和结果。会话结束,授权随之失效。
Putting keys in .env or pasting them into chat hands over the master key.把 key 写进 .env 或贴进对话,等于交出了万能钥匙。
| Master key: .env, pasted keys万能钥匙:.env、贴进对话的 key | Valet key: KeyValet代客钥匙:KeyValet | |
|---|---|---|
| What the agent seesagent 看到什么 | The plaintext key, in its context and logs明文 key,留在上下文和日志里 | Only the response. Long-term secrets never leave root.只有响应。长期秘密不出 root 进程。 |
| Who decides谁来决定 | Nobody, once the file is readable没人,文件能读就能用 | You, per credential, with Touch ID你,逐个凭证,用 Touch ID |
| Where it can go能发往哪里 | Anywhere the agent sends itagent 发到哪就是哪 | Only the hosts you allowed, no redirects只能发往你允许的域名,不跟随跳转 |
| What you can check later事后能查到什么 | Nothing什么都查不到 | Every use, with session, purpose and result每次使用的会话、目的和结果 |
| Where it lives存在哪里 | Plaintext files, or someone else’s cloud明文文件,或别人的云上 | An encrypted vault on your Mac that only root can read你 Mac 上只有 root 能读的加密凭证库 |
Agents receive short-lived tokens or proxied responses. Refresh tokens, private keys and seeds stay in the vault.agent 拿到的是短期 token 或代理后的响应。refresh token、私钥和种子都留在凭证库里。
A credential tool should be precise about its limits. The full model is in SECURITY.md.凭证工具应该讲清楚自己的边界。完整的安全模型见 SECURITY.md。
credential_get are in the agent’s context.用 credential_get 取出的值会进入 agent 的上下文。One command. It checks the requirements, asks for your password once, and sets up Claude Code for you. Run it again to upgrade.一条命令。它会检查运行环境,要你输一次密码,并自动配置好 Claude Code。重跑即可升级。
curl -fsSL https://keyvalet.dev/install.sh | sh
Needs macOS, Node.js 20+ from nodejs.org or nvm, and the Xcode Command Line Tools.需要 macOS、来自 nodejs.org 或 nvm 的 Node.js 20+,以及 Xcode 命令行工具。
Then just ask your agent:然后直接对 agent 说:
“Store my OpenAI key in KeyValet with the openai template.”
“Use KeyValet to list my OpenAI models.”“用 KeyValet 的 openai 模板保存我的 OpenAI key。”
“用 KeyValet 列出我的 OpenAI 模型。”
You type the key into a native dialog, and approve its use with Touch ID. The agent never sees it.key 由你在原生对话框里输入,使用时由你用 Touch ID 批准。agent 始终看不到它。