Agent Master Key Agent Master Key
Local-first · macOS

One click to connect any agent.
With a key you can kill.

Stop hand-editing config files to give agents your real API keys. Agent Master Key writes the MCP setup into Claude Desktop, Cursor, and Codex for you - and hands each agent one scoped, revocable amk_live_ key - routed through local approvals, a kill switch, and an audit trail.

AI Appreciation Day · Free launch FREE FOR A LIMITED TIME
$129 $99 Free for a limited time

List prices for context only. Premium is free for a limited time — no checkout during this window.

Premium free for a limited time · all product capabilities included.

Give your agent access, not your keys — kill it in one step.

Download Read the launch post

Any change to the free window will be announced in advance on the blog.

See how it works
On your Mac

Your real secrets

Provider keys you already own - encrypted in AMK's local vault by default.

GitHub PAT (redacted) OpenAI key (redacted)
used by
Local broker

Agent Master Key

Loopback only. Checks policy, holds risky writes for approval, logs every call.

Policy & scopes Approvals & audit
hands out
Your AI agent

One Master Key

Claude, Codex, or any MCP agent. Reaches only what you allowed — nothing more.

amk_live_8f2c…2b Revoke anytime
The real secret never leaves your Mac and never reaches us.
The problem

Right now, your agent holds your real keys.

Paste a provider token into an AI agent and it holds the actual secret — full account access, everywhere that key works, for as long as it lives. One leaked log, one prompt injection, one rogue tool call, and it isn't the agent that's exposed. It's your repos, your cloud bill, your data.

Without AMK Full access
GitHub PAT (redacted)

The raw key, copied out. Can't scope it, can't watch it, can't take it back without rotating everywhere.

With Agent Master Key Scoped
amk_live_8f2c41a9b7e0…05e2b

A scoped key you can watch and revoke from the dashboard — new requests are refused immediately. The real secret stays on your Mac.

See it in action

Proof, not promises

Real app-window captures from an isolated demo profile — connect a key, mint a scoped key, reject a fake credential, and pull the kill switch. No real secrets shown.

Turn on the local service

First-run starts the private local helper and hands off to vault setup.

Connect an agent

AMK configures a scoped local profile without terminal copy-paste.

Reject a fake key

A false connector credential stays masked and receives a clear denial.

Pause every agent

The kill switch stops scoped agent calls without deleting connector credentials.

Why it's safe

Built so a leaked agent key
can't unlock your accounts

Local-first custody

Bring scoped API keys first. Provider secrets are never uploaded to Agent Master Key servers.

Scoped agent keys

Each agent gets one amk_live_… key limited to the connectors and actions you allow.

Approvals & audit

Risky writes wait for your approval. Every action lands in a redacted, local audit trail.

Revoke & kill switch

Kill one agent's key — or flip the kill switch to pause every agent — the moment something looks wrong.

Setup

From key to safe agent in a few clicks

No terminal. The app walks you through it.

01

Connect an app

Start with a GitHub Personal Access Token or another scoped API key. Provider credentials stay local.

02

Create one agent key

Generate a single scoped Master Key for your AI agent — you choose what it can reach.

03

Hand it to your agent

Copy the setup into your agent. It discovers only the tools you granted.

04

Stay in control

Safe reads just work; risky writes ask first; unscoped access is denied; revoke anytime.

Connectors

Hard-wired connectors for the tools you already use

Every connector runs through the scoped local broker — the provider secret stays in your encrypted vault on your Mac, and each agent only ever sees a scoped, revocable key. Don't see yours? Bring your own key and build it — included free during the launch window.

MCP agent handoff (any agent) and Codex / ChatGPT subscription handoff stay inside the same scoped AMK broker model.

1Password
Apple Notarization
AWS
Azure
Calendly
Claude
Cloudflare
Context7
Deepgram
DeepSeek
Discord
Docker
ElevenLabs
Firecrawl
GitHub
GitHub Copilot
GitLab
Google AI Studio
Google Cloud
Groq
HubSpot
Hugging Face
Jira
Linear
Mistral AI
New Relic
Notion
Obsidian
Omi
OpenAI
OpenRouter
Perplexity
Pinecone
PostHog
Render
Sentry
Simple Analytics
Slack
Stripe
Supabase
Telegram
Twilio
Twitter / X
Vercel
xAI
Build your own connector Need something beyond the catalog? Wire any provider with your own API key — included free during the launch window. The secret lives in AMK's encrypted local vault, and your agent only ever sees a scoped key.
Free during launch
Launch window

Launch access. All features included.

Free for a limited time
Free download and use every product capability

We're launching free to build the next phase with real users. Any change to the free window will be announced in advance on the blog.

Unlimited agents and unlimited connectors.
Bring-your-own-key custom providers included.
Scoped keys, approvals, kill switch, and audit trail — always on.

macOS 14+ · Apple Silicon.

Questions

The things people ask first

Do you ever see my API keys or passwords?+

No. AMK's encrypted local vault is the default. Keychain can return later as an optional Mac unlock backend. Your provider secrets stay local and are not uploaded to us.

What does my AI agent actually get?+

One scoped key (amk_live_...) that can reach only the connectors and actions you allow - never your underlying secrets. You can revoke it from the dashboard at any time — new requests are refused immediately.

Do my keys ever get shared with a server?+

No. The local broker runs on your Mac, keeps the real provider secret local, and logs what each scoped agent key can do.

What is included?+

This free launch includes launch access to every product capability. This preview build will not be remotely downgraded. Material terms for later releases will be announced on the blog at least seven days in advance.

What if I replace or reinstall my Mac?+

Reinstall or redownload whenever you need to. Your vault lives on your Mac, so a new machine starts with a fresh vault and you reconnect your providers there.

Stop handing agents
your real keys.

Give your agent access, not your keys — kill it in one step. This free launch includes launch access to all features.

Download

Unlimited agents, unlimited connectors, and bring-your-own-key custom providers — all included free during the launch window. We're launching free to build the next phase with real users.