Native macOS app / local-first / version 1.7

Let your AI use a credential. Never show it the value.

Codex, Claude Code or OpenCode asks KeyCourier for a saved credential and destination. You approve on your Mac or through Telegram. KeyCourier delivers it directly and returns a receipt with no secret inside.

01
Touch ID or Telegram
02
Approved destination
03
Secret-free receipt
Protected hand-offAsk · approve · deliver · verify

01 / How it works

The AI asks. You decide where the credential goes.

KeyCourier shows a friendly credential name, destination, requesting app and reason. Internal secret, consumer and target IDs stay under Advanced. Every delivery is limited to a destination you registered in advance.

The hand-off

Ask, approve, deliver, verify.

The agent sends a request without the credential value. KeyCourier handles the protected value and tells the agent only whether the approved destination received it.

Credentials without the clutter

Simple screens. Strict delivery rules.

Projects, environments, owners and rotation dates make credentials easier to manage. The rules underneath still prevent agents from choosing arbitrary paths, commands or destinations.

01

No plaintext hand-back

The CLI and installable skills exchange request details and receipts. Secret material stays in the owner-controlled path.

02

Approved destinations only

You register where each credential may go. Requests cannot add arbitrary paths, variables, commands or services.

03

Encrypted recovery

Multi-recipient age backups support offline recovery and rekeying without adding a hosted vault.

04

Failures stay visible

A missing destination, expired request or offline machine produces a clear failure instead of a misleading success.

Three guided destinations / fixed consumers

This Mac stays local. Mac Mini and VPS use encrypted delivery.

This Mac installs into a private KeyCourier-managed consumer after approval. Mac Mini and VPS each have their own age recipient, reviewed owner-only helper and fixed canary consumer.

Dummy ciphertext delivery passed on both remote hosts. The checks covered exact-package replay rejection, mode-600 consumer verification and recovery decryption without printing the value.

Production credentials remain off until the final app-mediated canary receives owner approval and the recovery identity moves to owner-controlled offline media. This is an explicit release gate, not a hidden failure.

This MacLocal consumer registered
Mac MiniHost delivery canary passed
VPSHost delivery canary passed
Recovery identityOffline move pending
Owner approvalFinal app-mediated canary pending

Security boundary

Your credential never needs to become an AI response.

KeyCourier uses the macOS data-protection Keychain with user-presence access control. Telegram approval is optional per credential, paired to one private chat and user, and protected by expiring single-use buttons. Telegram messages are not end-to-end encrypted, so they contain friendly request details but never credential values or internal routing IDs.

Stored
Friendly metadata in the app; value in Keychain
Requested
Credential, destination, requesting app and reason
Returned
Content-free status and receipt code
Not included
Hosted vault, arbitrary shell, secret-bearing flags or Telegram values

Works with the tools you already use

Codex, Claude Code and OpenCode share one approval path.

The KeyCourier CLI and installable skills give each tool the same narrow request contract. A model can request delivery and check its receipt without reading the credential.