AMK vs the alternatives
There are several good ways to keep AI agents away from your raw credentials, and Agent Master Key is not the right one for everybody. This page compares the main options as plainly as we can. Where a competitor's offering varies by plan, deployment, or setup, we say "varies" rather than guess. Corrections welcome: support@agentmasterkey.com.
At a glance
| Agent Master Key | Infisical Agent Vault (free OSS) | ToolHive (free OSS) | 1Password (enterprise agent access) | Cloud brokers (Composio-style) | |
|---|---|---|---|---|---|
| Who it's for | Individuals on a Mac who want AI agents to use their accounts without handing over raw keys — no infrastructure to run. | Developers and teams who use (or want to self-host) Infisical's secret-management platform and extend it to agents. | Developers running MCP servers who are comfortable with containers and developer tooling. | Organizations on 1Password business/enterprise plans extending managed credential access to agents. | Teams that want hosted, managed integrations and are comfortable with a cloud service in the loop. |
| Access model | Free for a limited time — version 0.0.16 includes all product capabilities. Any future commercial terms will be announced on the blog at least seven days before they apply; this preview build will not be remotely downgraded. | Free open source to self-host; paid cloud and enterprise plans exist (varies). | Free open source. | Subscription; agent-access features are positioned for business/enterprise plans (varies). | Typically subscription or usage-based (varies by vendor). |
| Local-first (keys stay on your machine)? | Yes — encrypted vault and policy broker run on your Mac (127.0.0.1); provider secrets are not uploaded to us. | Varies — self-hosting keeps secrets on your own infrastructure; the hosted cloud stores them in Infisical's service. | Largely yes when run on your own machine (varies by setup). | No — vaults sync through 1Password's cloud (end-to-end encrypted). | No — credentials are typically held or proxied by the vendor's cloud (varies). |
| Docker/terminal required? | No — native Mac app, no terminal required. | Self-hosting generally involves Docker/CLI; the hosted cloud reduces this (varies). | Container runtime required; provides CLI and UI tooling (varies by workflow). | No for end users; admin setup runs through the console, and developer tooling uses a CLI (varies). | No — typically a web dashboard plus SDK/API. |
| One-click agent connect? | Yes for supported connectors — you bring an API key, AMK issues the agent a scoped key. | Configuration-driven; designed for developer workflows (varies). | Positions as a streamlined way to run MCP servers (varies). | Managed through admin policies and integrations (varies). | Often yes, via hosted OAuth flows (varies by vendor). |
| Kill switch + audit trail | Yes — per-key revocation that refuses new requests immediately, a kill switch that pauses every agent, and a local redacted audit trail. | Audit logging and access revocation available; depth varies by plan and deployment. | Container isolation and permission controls; audit features vary. | Enterprise audit and reporting available (varies by plan). | Vendor-side logs and revocation (varies). |
| Open source? | No. | Yes — the core platform is open source. | Yes. | No. | Varies by vendor. |
Competitor descriptions are based on public materials as of July 2026 and are intentionally conservative. All product names are trademarks of their respective owners; none of these projects or companies is affiliated with Agent Master Key.
Frequently asked
"Why not just run Docker's free MCP gateway?"
Docker's MCP Gateway is a solid developer tool for running MCP servers in containers. It answers a different question than AMK. The gateway standardizes how MCP servers run; AMK answers who can see your credentials. With AMK your provider keys never leave an encrypted vault on your Mac — there is no container to configure, no Docker Desktop dependency, and no per-server images to trust. Agents get scoped, revocable keys with per-connector audit, and you can kill one agent without touching the rest. If you already live in Docker and want free open source plumbing, the gateway is a reasonable choice; if you want a native Mac app where custody — not plumbing — is the product, that is AMK's lane.
"Why local custody after the Composio breach?"
In May 2026, a widely used cloud MCP broker disclosed a breach. The failure mode is structural: any broker that holds or proxies your provider keys in its cloud is a single point of compromise for every customer at once. AMK's answer is architectural, not cosmetic — provider keys are stored only in an encrypted vault on your own Mac and are never uploaded to us. There is no AMK cloud credential store to breach. An attacker would have to compromise your individual machine, not one vendor's infrastructure. That is the whole reason AMK is local-first: it removes the class of incident, not just the likelihood.
"We already have 1Password — isn't that enough?"
1Password is excellent at what it is: a team vault with admin policies. Its agent-access features extend that to agents on business and enterprise plans (varies by plan). Two honest differences: 1Password vaults sync through 1Password's cloud (end-to-end encrypted — a trust choice, not a flaw), and its model is organization-centric. AMK is for the individual Mac user who wants keys that never leave the machine at all, plus per-agent scoped keys, a kill switch, and a local audit trail without an enterprise admin console. If your company standardizes on 1Password, use it. If you want local-only custody for your own accounts, that is AMK.
What AMK is NOT
- Not cross-platform. AMK runs on macOS 14 (Sonoma) or later on Apple Silicon (M1 or newer). No Windows or Linux build.
- Not a universal OAuth broker. Connectors are API-key-first: you bring a scoped token or API key for each provider you connect.
- Local enforcement is best-effort by design. AMK defends your keys against being uploaded to the cloud, scattered across agent configs, or read directly by agents. It does not claim to stop malware already running on your Mac as you — no local application can honestly promise that. See Trust & custody for the full threat model.
- Not open source. AMK is a commercial, closed-source app — free for a limited time during the launch window.
Honest guidance
If you are a developer who is happy running containers and wants free open source, Infisical or ToolHive may fit you better. If your company already standardizes on 1Password's enterprise plans, its agent-access features may be the natural path. If you want hosted integrations managed for you and don't mind a cloud service holding or proxying credentials, a cloud broker is the convenient option.
AMK's lane is narrower on purpose: a native Mac app for individuals, free for a limited time during the launch window, and your provider keys staying in an encrypted vault on your own machine while agents get scoped keys you can watch and revoke. If that is what you want, download it free — the security overview and getting-started guide cover the rest.
Agent Master Key