← Back

Blog

Plain words from the team building Agent Master Key. Material access changes are announced here first.

Agent Master Key 0.0.17 is live — and here's where we're headed

July 22, 2026

The new build is out, and it's the easiest Agent Master Key has ever been to start. If you've been meaning to stop pasting your real API keys into agent config files, this is the one to grab.

What Agent Master Key does, in one line

You keep your provider keys in an encrypted vault on your Mac. Each AI agent gets a scoped, revocable amk_live_ key that only works through a local broker — with an approval prompt on risky actions, a full audit trail, and a one-click kill switch. Off your machine, the agent's key is useless. Your real keys never leave your Mac.

What's new in 0.0.17

Connecting an agent used to mean hand-editing config files. Now Agent Master Key writes the MCP setup for you — for Claude Desktop, Cursor, and Codex — and hands the agent its scoped key in one step. Download, open, connect. No account, no email, no terminal.

It's free for a limited time, with every connector and agent workflow included. We're building the next phase with real users, so if something breaks or feels rough, tell us on the community page — that's what this window is for.

Where we're headed: your Keys

Agent Master Key started with one job — get your API keys out of agent config files. The same idea applies to much more of your life than credentials. In the age of AI agents, you shouldn't have to re-type who you are into every chat, and you shouldn't have to hand your personal history to a cloud service to get help from an agent. Your life stays on your machine; agents get keys, not copies.

We're designing the next Keys now, and you can preview them:

These are in design, not part of the shipped app yet, and we're not promising dates. See the Keys and tell us which one you want first — the order we build them in depends on what people ask for.

The honest boundary

Agent Master Key mediates every agent's use of your keys on your macOS login: real keys stay in the local vault, each agent gets a scoped revocable key, and every use is attributed and reversible. The security page states plainly what that protects and what sits outside its boundary — worth a read before you rely on it.

Download Agent Master Key · Preview the Keys

Use Kimi K3 through your agent — without exposing your OpenRouter key

July 17, 2026

Kimi K3 launched this week, and the fastest way for most agents to reach it is an OpenRouter API key. Which raises the usual question: do you really want to paste that key into another agent config file?

You don't have to put that provider key in the agent's config. Agent Master Key's connector catalog covers the tools most agents reach for, and the Add Your Own Key path wires any provider beyond the catalog through the same scoped local vault and broker boundary. OpenRouter is one such bring-your-own-key workflow. Here is the setup boundary:

1. Add your OpenRouter key

Use Agent Master Key's Add Your Own Key flow to configure the OpenRouter credential on your Mac. Agent Master Key encrypts the credential with AES-256-GCM and stores it locally — it is not uploaded to us, and it does not need to sit in the agent's config file. Because this is a custom provider workflow, verify the request shape against your current build before relying on it.

2. Hand your agent a stand-in key

Connect your agent (Claude Desktop, Codex, or any MCP-compatible agent — Agent Master Key writes the MCP setup for you). The agent receives a scoped amk_live_ key that only works through the broker on your Mac. Off your machine, it's useless.

3. Point it at Kimi K3

Your agent calls OpenRouter through the broker with a Kimi K3 model id (for example moonshotai/kimi-k3). The broker injects your real key into the outbound request itself, scrubs credential-shaped values from responses, and records the call in your local audit trail. Done with the experiment? Revoke that one agent key — your OpenRouter key never needs rotating, because the agent never had it.

The honest footnote

Every connector in the catalog works through the same scoped local vault and broker boundary — your provider credential stays encrypted on your Mac, and the agent only ever holds a scoped, revocable key. For anything beyond the catalog, the Add Your Own Key path brokers your own provider key through that same boundary; OpenRouter is one example. The security page states exactly where that boundary sits. During the launch window, Add Your Own Key access is free for a limited time.

Deeper dive on The AMA Hub, our sister publication: use Kimi K3 without exposing your OpenRouter key.

Agent Master Key is live — and Premium is free for a limited time

July 16, 2026 · AI Appreciation Day

Today, on AI Appreciation Day, Agent Master Key goes live — and Premium is free for a limited time. Agents are doing real work now — writing code, triaging email, and operating across your accounts — and raw credentials do not belong in their config files. Agent Master Key is built to give agents scoped, revocable access without placing raw provider credentials in the agent's hands.

What it is

Agent Master Key is a Mac app with one promise: give your agent access, not your keys — kill it in one step.

Provider credentials are stored in an AES-256-GCM encrypted local vault and used by the loopback broker to make approved provider requests. Each agent receives a scoped, revocable stand-in key rather than the raw provider credential. Broker decisions land in a local, redacted audit trail, and any grant can be undone: revoke one key, or use the kill switch to pause scoped agent calls. Safe reads proceed inside the granted scope; risky writes wait for your explicit approval.

No security product should make you guess, so the security page states plainly where the boundary sits and what sits outside it. We'd rather you read the honest version there than hear a stronger claim from us anywhere else.

New to the pattern? The AMA Hub's plain-language primer on what a credential broker for AI agents is explains why this design exists.

The launch decision

This free launch includes launch access to all product capabilities. This preview build will keep that access. We are opening it broadly so real users can test the product, report issues, and help shape what comes next.

How launch claims are proved

Connector and distribution claims are bound to the exact sealed release candidate. The public download is promoted only after physical QA and a public re-download match the release receipt. Bring-your-own-key providers are included in launch access, while each provider workflow remains subject to its own current-build verification.

What happens later

This free-launch build will not be remotely downgraded. If later releases introduce different commercial terms, we will announce them here at least seven days before they apply.

How to help

Download it. Break it. Tell us. The most valuable thing you can do is run Agent Master Key against your real agents and report what you find — what broke, what confused you, and what's missing. The community page routes public discussion, private support, and confidential security reports.

Today, on AI Appreciation Day, give your agents access — and keep your keys.

— The AMK team · AM Accelerated LLC