Give your agents access.
Never your keys.
Agent Master Key keeps your API keys and accounts on your Mac and hands each AI agent one scoped, revocable key — routed through local approvals and an audit trail. Your secrets stay in your Mac's Keychain — not on our servers.
Private beta. macOS 14+ on Apple Silicon. Developer ID direct-download beta first; Mac App Store/TestFlight is a separate proof lane.
Built so a leaked agent can't leak your accounts
The whole point is custody. Your provider secrets stay in your Mac's Keychain; agents only ever get a scoped Master Key they can use through a local policy broker.
Local-first custody
API keys and OAuth live in your macOS Keychain. They are never sent to our servers — we don't have servers in the loop.
Scoped agent keys
Each agent gets one amk_live_… key limited to the connectors and actions you allow — not your raw secrets.
Approvals & audit
Risky writes wait for your approval. Every action is recorded in a redacted, local audit trail.
Instant revoke
Kill one agent's key — or flip the Kill Switch to pause every agent — the moment something looks wrong.
Read the full custody & trust details. An independent security review is part of our path to general availability.
From key to safe agent in a few clicks
No terminal. The app walks you through it.
Connect an app
Start with GitHub OAuth or a scoped API key. (Google — Gmail, Calendar, Drive — joins the beta once Google's app review is approved.) Provider credentials go straight into your Mac's Keychain.
Create one agent key
Generate a single scoped Master Key for your AI agent — you choose what it can reach.
Hand it to your agent
Copy the setup into your agent. It discovers only the tools you granted.
Stay in control
Safe reads just work; risky writes ask first; unscoped access is denied; revoke anytime.
Connectors
The private beta stays intentionally narrow: GitHub first (no provider review needed), Google next (live once Google's verification is approved), the Codex subscription handoff, and scoped API-key paths. A connector is listed as working only after it passes a live end-to-end test.
Beta launches with
Joining the beta — in progress
Parked until proven
Pricing
$129 one-time lifetime license
$99 early-bird for the first users — limited time (the exact cap is announced when checkout opens).
No subscription. Each license activates up to 3 Macs. Backed by a 30-day refund guarantee — see our refund policy.
Checkout opens only after payment, legal, support, and release gates are ready. Refund policy · Terms.
Be an early Agent Master Key operator
We're onboarding the private beta in small groups so every first run is smooth. Tell us you're interested and we'll invite you when your spot and the release gates are ready.
Request beta accessOr email [email protected]. macOS 14+ · Apple Silicon.
Questions
Do you ever see my API keys or account passwords?
No. Your provider secrets are stored in your Mac's Keychain and used by a broker that runs on your own machine. They are not uploaded to us.
What does my AI agent actually get?
One scoped key (amk_live_…) that can reach only the connectors and actions you allow — never your underlying secrets. You can revoke it instantly.
Why isn't it on the Mac App Store?
The immediate beta lane is Developer ID direct download. Mac App Store and TestFlight are a separate proof-gated path that requires sandboxing, App Store signing, App Store Connect upload, privacy labels, and Apple review.
What are the system requirements?
macOS 14 or later on Apple Silicon (M1 or newer). We will only send beta builds after the direct-download lane passes signing, notarization, stapling, Gatekeeper, packaged launch, and clean-install proof.
Can I remove everything later?
Yes. Uninstalling removes the app, and a one-command full clean removes every Agent Master Key item from your Keychain and local state.
Agent Master Key