API key manager for Claude Code and AI agents

Your AI agent
uses the key.
Never sees it.

STRIPE_SECRET_KEY=hidden from the agent

Open-source CLI that keeps API keys in your OS keychain. Claude runs commands with them by name — the value never reaches the chat.

$npx @tscodex/skey ui
Agent skill ↗ GitHub npm MIT · open source
Without skeyleaked
here's the token: sk_live_51HfQk2pX…
This key is now exposed in our chat. Please rotate it before we continue.
With skeysafe
› skey run --only STRIPE_SECRET_KEY -- npm run sync
key=***MASKED*** · 200 OK
Done. I used STRIPE_SECRET_KEY by name.

Where keys leak

01
In the chat
Tokens pasted into chatskey run
“Paste your key here”skey request
Tools echoing secrets***MASKED***
.env, CI, hostingskey dotenv
Between people
Keys sent over Telegram--share
Trusting the relayend-to-end
No servers allowed--offline
Answer from a terminalskey fill
On disk
.env files in gitkeychain
What keys do I have?skey ui
Leftover keysskey clean
Agent reading valuesdeny rules

Request a key, not a paste

02

1Agent asks

› skey request
waiting for 2 keys · k7f2qa

2You fill

An assistant needs 2 keys

SMTP loginStored
SMTP password
Save

3It continues

✓ stored SMTP_USER, SMTP_PASS
› skey run --only SMTP_PASS -- …
250 OK

Set up Claude Code

03
// ~/.claude/settings.json
{
  "permissions": {
    "allow": ["Bash(skey run:*)", "Bash(skey list:*)"],
    "deny":  ["Bash(skey export:*)", "Bash(skey set:*)"]
  }
}

skey

part of tscodex · by unbywyd Node 18+ · macOS · Windows · Linux