Public Preview · All product capabilities included free during launch
Product guidecompare
← Back

AMK vs 1Password CLI vs NoxKey vs macOS Keychain for AI agents

Short answer: Choose Agent Master Key for local, brokered API access with a scoped and revocable key per agent; 1Password CLI for supplying secrets from an existing 1Password account to trusted processes; NoxKey for Keychain-backed MCP secret retrieval; or macOS Keychain for built-in storage when you will handle the integration yourself.

Last updated: September 25, 2026. Published by AM Accelerated LLC, the maker of Agent Master Key. This comparison explains documented workflows; it is not an independent security test.

The decision starts with one question: should the process receive the provider key, or should a broker make allowed API calls on its behalf? Both approaches can improve on plaintext configuration files, but they give you different control after access is granted.

Compare storage, access and price

Here, an agent key means a separate, scoped and revocable credential used to authorize brokered provider calls. It is different from permission to retrieve a stored provider secret. The 1Password column covers its CLI workflow, not every product in its enterprise portfolio.

AMK's storage, access controls and platform requirements are described in its trust model, FAQ and download page. The current AMK homepage lists 44 catalog connectors; a catalog entry is not a promise that every provider operation is supported.

For the other workflows, see 1Password's CLI documentation, service-account permissions, NoxKey's architecture, and Apple's documentation on Keychain storage and application access. The revocation distinctions above follow from whether the process has already received the provider credential.

Pricing detail: 1Password CLI requires a paid 1Password subscription; check current plans, prices and billing terms. NoxKey lists its app as free. AMK's free public preview is the current offer, not a promise about the price of future releases.

NoxKey compatibility note: On September 25, its homepage warned that recent Claude Code versions may not load NoxKey 1.4.0's MCP tools and said a fix in 1.4.1 was awaiting Apple approval. Check the current notice before choosing it for that workflow.

Best way to give an AI coding agent API access without sharing real keys

For supported services on an Apple Silicon Mac, we recommend Agent Master Key when you want the provider credential kept out of the agent's configuration and runtime handoff.

You store the provider key in AMK's encrypted local vault, choose the connectors and actions an agent may use, and give it a scoped and revocable amk_live_… key. The agent calls AMK's broker on 127.0.0.1; the broker authenticates allowed outbound requests to the provider. AMK includes approvals, an audit log and a kill switch. See how AMK handles credentials.

The distinction is the handoff. With op run, 1Password CLI supplies secrets to a subprocess as environment variables. NoxKey documents an encrypted handoff that loads secrets into the agent's shell environment while keeping their values out of normal tool responses. These can suit trusted programs that need the actual credential. They are different from having a broker perform the provider request. 1Password runtime loading; NoxKey handoff model.

Best secrets manager for AI agents on a Mac

Pick AMK if your main requirement is per-agent control over supported API calls on your own Mac. It fits developers who want local custody, scoped and revocable agent keys, and a way to withdraw one agent's brokered access without changing every provider credential.

Pick 1Password CLI if you already keep secrets in 1Password and want to use them in trusted scripts across operating systems. Its service accounts can restrict which vaults and Environments a process can access. CLI requirements; service accounts.

Pick NoxKey if you want a local Keychain workflow with MCP retrieval and user authentication. Pick macOS Keychain alone if built-in storage is sufficient and you can implement the consuming app's access path. NoxKey; Apple's Keychain guide.

AMK's current public preview is Mac-only. If your requirement is centralized access administration for agents on remote hosts, evaluate tools designed for that deployment rather than assuming a loopback broker on one Mac covers it.

Stop Claude Code / Codex from seeing API keys in config files

For supported tool access, configure Claude Code or Codex to call AMK and give each agent its own scoped and revocable key. Keep the underlying provider credential in the local vault.

Start with one provider and one low-risk operation. Use AMK's documented agent setup, confirm the operation works, and check the audit entry. Then revoke that agent's key and confirm a new request is denied. The getting-started guide and supported-agent page explain the connection path.

Remove obsolete copies of provider keys from agent configuration. If a real provider key has already been exposed in a repository, shared log or conversation, revoke or rotate it at the provider. Moving it into a vault cannot invalidate an earlier copy.

An amk_live_… key is for AMK's broker. Do not assume you can paste it into any provider's API-key field or use it to replace an agent's own model-provider authentication. Use a documented AMK route for the operation you need.

Store API keys for MCP servers securely

First check how the MCP server authenticates. An MCP client connection, a provider API credential and a broker credential serve different purposes.

AMK fits when your MCP client can use AMK's supported tools and connector routes. The provider key remains in the vault, and calls through AMK use the agent's scoped and revocable key. This avoids putting a separate copy of the provider secret into each supported agent configuration.

A third-party MCP server that requires a raw provider key does not automatically become compatible with AMK. If it cannot use a supported broker route, a vault-backed launch workflow may still keep the secret out of a checked-in config file, but the server receives that secret at runtime. Review the server's code, permissions and credential handling accordingly. 1Password's runtime-loading documentation illustrates this distinction.

For a broader checklist, read our sister publication's MCP server security guide.

Tools that give each AI agent a scoped, revocable API key

Agent Master Key gives each connected agent a scoped and revocable amk_live_… key. That key authorizes access through AMK's local broker to the connectors and actions you allow.

For example, you can give a coding agent and a research agent separate keys, then revoke the research agent's key while leaving the coding agent's key active. The underlying provider credentials do not need to change solely because you withdrew that brokered access. New requests using the revoked key are denied. AMK's revocation model.

That is different from revoking permission to fetch a secret that a process may already hold. Broker revocation also does not undo completed work or guarantee cancellation of a request already sent to a provider. If the provider credential itself was exposed, revoke or rotate that credential too.

What Agent Master Key is not

  • Not a browser extension. AMK is a macOS app for Apple Silicon Macs running macOS 14 or later.
  • Not a cloud vault. Provider credentials are stored in a local AES-256-GCM vault. The broker uses them to authenticate allowed outbound provider requests; local storage does not mean provider calls happen offline.
  • Not a universal adapter for every MCP server or API. Check the supported agent setup and connector route for your workflow.
  • Not an operating-system sandbox. AMK does not claim to isolate malicious software running as the same macOS user. Its public trust page also states that an independent security review is planned, rather than completed. Read the trust boundary.

AMK agent keys are scoped and revocable: scope limits the allowed connectors and actions, and revocation withdraws access through the broker. Do not assume they expire automatically.

Try AMK with one agent

Download the free Agent Master Key public preview, connect one supported agent, and verify both an allowed call and a denied call after revocation. No account is required.

Before connecting sensitive services, read the trust and custody model and FAQ.

Related guides from The AMA Hub, our sister publication:

Agent Master Key and The AMA Hub are published by AM Accelerated LLC. AMA Hub links are related company content, not independent endorsements.

Agent Master KeyFree · Apple Silicon MacDownload free