Keys: your API keys and app logins, for your agents, without handing them over.

Sign in

How each thing works

Getting in
  1. Anyone opens Keys and taps Create an account: a name and an email, the 6-digit code Keys emails them, then Face ID or Touch ID. They get an empty space of their own. One account per email.
    no key is seen
  2. Lost your passkey? A code to the same email adds a new passkey to the account, and Keys emails you that it happened. The keys stay as they are.
    no key is seen
  3. Nobody sees another person's keys, apps, agents or history in Keys. Home has a link to send to someone else.
    no key is seen
  4. Without a passkey, Keys shows the sign-in page and nothing else. A test server limits new accounts per address and in total, and can be set to invite only.
    no key is seen
Starting from Composio
  1. Home asks you to connect Composio if you use it: you paste your Composio key on its page.
    you see the key
  2. The Apps page lists the apps you connected in Composio and as which account (GitHub: your login, Gmail: your address).
    no key is seen
  3. Your agents use those apps through Keys, as you, after a yes per app.
    only Keys sees the key
  4. Next to each app, "Connect directly" adds that app's own key. Agents can then call its API directly through Keys; its ready-made tools still come from Composio for now.
    you see the key

Keys cannot take your logins out of Composio; Composio does not give them out.

Connecting an agent
  1. On the Agents page, copy the short message and send it to the agent. It downloads the Keys command from your Keys and asks to connect.
    no key is seen
  2. You open the link it shows and type the code it shows, choose the project, and tap Connect. A link alone connects nothing.
    no key is seen
  3. The agent receives its agent key and adds Keys to its tools: Claude Code, Codex or Cursor, whichever it finds on that machine. It starts with access to nothing.
    no key is seen

The project is yours to name when you connect. "Always for this project" covers every agent you connected to it, and no other.

Adding a key
  1. An agent that needs a key asks for it by service name. You get a page, never a chat message.
    no key is seen
  2. On that page: the service's own guide and a field to paste the key, or, once Composio is connected, a pick list from your 1Password. A pasted link, or something that does not look like a known service's key, is refused.
    you see the key
  3. On the same page you say how the asking agent may use it.
    no key is seen
  4. An agent that creates a key itself can send it straight in and gets a short fingerprint back.
    only Keys sees the key
Using a key or an app
  1. An agent asks Keys to call an API with a key by name, or to use one of your apps.
    no key is seen
  2. The first time, you answer: in the chat as buttons, otherwise on a page linked from Home and from the agent.
    no key is seen
  3. Keys checks the address belongs to the key and is a public one, adds the key in its own header, and sends the request.
    the service gets the key
  4. Keys removes every one of your keys from the answer before the agent reads it.
    no key is seen

Apps through Composio are allowed per app (GitHub, Gmail...), not per action. Your Composio key cannot be used or read by any agent; only Keys uses it.

A deployed app, such as a test server
  1. On the Agents page you add the app and get its token, shown once. The platform keeps two variables: the Keys address and that token.
    you see the key
  2. At each start the app loads the keys it needs (with varlock: KEY=exec(`node keys.ts reveal KEY`)). The first time you answer once.
    your app gets the key
  3. Replace a key on the Keys page; the next start has it. The platform is not touched.
    only Keys sees the key
Taking things back
  1. Revoke a permission on the Keys page; the next use asks again.
    no key is seen
  2. Disconnect an agent on the Agents page; it stops at once, including anything it was waiting for.
    no key is seen
  3. Look at a value yourself: Keys checks your passkey first if you have not used it in the last 5 minutes.
    you see the key
  4. Replace a key: it keeps where it may be sent. A known service's key (OpenAI, GitHub...) always goes to that service, whoever stored it. For other keys, the Keys page and every request show where they go.
    only Keys sees the key

Can an agent store a key but never read one?

Yes. A value leaves Keys only:

Answers are cleaned of your keys in their usual forms (as is, base64, hex, URL-encoded, any case). Answers are unpacked before cleaning, so asking for a compressed answer does not get around it. Files (audio, images) go and come back as bytes; a file that holds one of your keys is not handed over. A service that shows only a piece of a key ("ending in 3456") is not cleaned. Keys only goes to public addresses, never to internal ones.

Some services can make a new key (OpenRouter, Vercel, Railway, GitHub, PostHog, Sentry). Those calls ask you first, each time, even when the key itself is allowed, and your yes covers the one call the page shows. Their answer stays in Keys: the new key is kept under a new name, and the agent reads only that name. In any other answer, values shaped like keys are hidden. This is a net, not a wall: a service Keys does not know, returning a new key with no known shape, gets through.

What this does not stop: an agent you allowed can do anything that key can do, and spend your credits, through an allowed service, and a service you allowed is trusted with what you send it. Password managers reached through Composio (1Password...) are never offered to agents: their values come in through your own page.

If you know Composio or 1Password

Compared with Composio

  • Today Keys sits in front of it. Your agents reach your Composio apps through Keys, as you, after your yes.
  • Composio has the catalog. Ready tools for 1,000+ apps and one-click sign-ins. Keys has neither: direct connections are API keys, and the agent writes the API call.
  • Composio keeps your app logins. A direct key adds a second way in; it does not move the login.

Compared with 1Password

  • Use instead of read. A 1Password service account hands values to whoever holds it. Keys makes the call for the agent.
  • Rights when needed. Not fixed vault permissions: each agent asks per key, and you answer once.
  • Much less. No team vaults, no apps, no browser filling, no outside security audit. For anything your colleagues need, 1Password stays.

Not yet