The AI names the saved credential, destination and reason. It cannot provide a value or arbitrary path.
Native macOS app / local-first / version 1.7
Let your AI use a credential. Never show it the value.
Codex, Claude Code or OpenCode asks KeyCourier for a saved credential and destination. You approve on your Mac or through Telegram. KeyCourier delivers it directly and returns a receipt with no secret inside.
- 01
- Touch ID or Telegram
- 02
- Approved destination
- 03
- Secret-free receipt
01 / How it works
The AI asks. You decide where the credential goes.
KeyCourier shows a friendly credential name, destination, requesting app and reason. Internal secret, consumer and target IDs stay under Advanced. Every delivery is limited to a destination you registered in advance.
The hand-off
Ask, approve, deliver, verify.
The agent sends a request without the credential value. KeyCourier handles the protected value and tells the agent only whether the approved destination received it.
Approve locally with macOS authentication or use an explicitly paired Telegram bot.
KeyCourier installs into the registered Keychain, dotenv or service destination.
The AI receives the result and a code. It never receives plaintext or secret-bearing logs.
Credentials without the clutter
Simple screens. Strict delivery rules.
Projects, environments, owners and rotation dates make credentials easier to manage. The rules underneath still prevent agents from choosing arbitrary paths, commands or destinations.
No plaintext hand-back
The CLI and installable skills exchange request details and receipts. Secret material stays in the owner-controlled path.
Approved destinations only
You register where each credential may go. Requests cannot add arbitrary paths, variables, commands or services.
Encrypted recovery
Multi-recipient age backups support offline recovery and rekeying without adding a hosted vault.
Failures stay visible
A missing destination, expired request or offline machine produces a clear failure instead of a misleading success.
Three guided destinations / fixed consumers
This Mac stays local. Mac Mini and VPS use encrypted delivery.
This Mac installs into a private KeyCourier-managed consumer after approval. Mac Mini and VPS each have their own age recipient, reviewed owner-only helper and fixed canary consumer.
Dummy ciphertext delivery passed on both remote hosts. The checks covered exact-package replay rejection, mode-600 consumer verification and recovery decryption without printing the value.
Production credentials remain off until the final app-mediated canary receives owner approval and the recovery identity moves to owner-controlled offline media. This is an explicit release gate, not a hidden failure.
Security boundary
Your credential never needs to become an AI response.
KeyCourier uses the macOS data-protection Keychain with user-presence access control. Telegram approval is optional per credential, paired to one private chat and user, and protected by expiring single-use buttons. Telegram messages are not end-to-end encrypted, so they contain friendly request details but never credential values or internal routing IDs.
- Stored
- Friendly metadata in the app; value in Keychain
- Requested
- Credential, destination, requesting app and reason
- Returned
- Content-free status and receipt code
- Not included
- Hosted vault, arbitrary shell, secret-bearing flags or Telegram values
Works with the tools you already use
Codex, Claude Code and OpenCode share one approval path.
The KeyCourier CLI and installable skills give each tool the same narrow request contract. A model can request delivery and check its receipt without reading the credential.