It says it needs one
The agent finds the provider's template, opens the key page for you, and says which permission to pick. It never logs in, passes 2FA or pays.
Built for vibe coders
They fetch, store, verify and use keys on your Mac. You approve; they never see the value.
v0.3.5 · Free · Apple Silicon · macOS 14+ · No account
The agent finds the provider's template, opens the key page for you, and says which permission to pick. It never logs in, passes 2FA or pays.
KeyKeeper checks the value looks like a Stripe key before writing, stores it in the Keychain, and verifies it with a read-only request the agent never sees.
The key goes into the command's environment through keykeeper run, and only there. Approve once, for this run, or for good — and revoke any time.
keykeeper import ./.envAlready have a .env? One command moves it in — secrets to the Keychain, settings beside them, the file left for you to delete.
KeyKeeper has 98 provider integrations built in: where the key is made, what to choose, what a real key looks like, how to verify it. You or your agent copy once, and it lands under the right name, checked with the provider.
Install it, then say "use KeyKeeper for API keys". The next time the agent needs one, this is what happens.
v0.3.5 · Free · Apple Silicon · macOS 14+ · No account
Build from source ↗