Turn on the local service
First-run starts the private local helper and hands off to vault setup.
Stop hand-editing config files to give agents your real API keys. Agent Master Key writes the MCP setup into Claude Desktop, Cursor, and Codex for you - and hands each agent one scoped, revocable amk_live_ key - routed through local approvals, a kill switch, and an audit trail.
List prices for context only. Premium is free for a limited time — no checkout during this window.
Premium free for a limited time · all product capabilities included.
Give your agent access, not your keys — kill it in one step.
Download Read the launch postAny change to the free window will be announced in advance on the blog.
See how it worksProvider keys you already own - encrypted in AMK's local vault by default.
Loopback only. Checks policy, holds risky writes for approval, logs every call.
Claude, Codex, or any MCP agent. Reaches only what you allowed — nothing more.
Paste a provider token into an AI agent and it holds the actual secret — full account access, everywhere that key works, for as long as it lives. One leaked log, one prompt injection, one rogue tool call, and it isn't the agent that's exposed. It's your repos, your cloud bill, your data.
GitHub PAT (redacted)
The raw key, copied out. Can't scope it, can't watch it, can't take it back without rotating everywhere.
amk_live_8f2c41a9b7e0…05e2b
A scoped key you can watch and revoke from the dashboard — new requests are refused immediately. The real secret stays on your Mac.
Real app-window captures from an isolated demo profile — connect a key, mint a scoped key, reject a fake credential, and pull the kill switch. No real secrets shown.
Bring scoped API keys first. Provider secrets are never uploaded to Agent Master Key servers.
Each agent gets one amk_live_… key limited to the connectors and actions you allow.
Risky writes wait for your approval. Every action lands in a redacted, local audit trail.
Kill one agent's key — or flip the kill switch to pause every agent — the moment something looks wrong.
No terminal. The app walks you through it.
Start with a GitHub Personal Access Token or another scoped API key. Provider credentials stay local.
Generate a single scoped Master Key for your AI agent — you choose what it can reach.
Copy the setup into your agent. It discovers only the tools you granted.
Safe reads just work; risky writes ask first; unscoped access is denied; revoke anytime.
Every connector runs through the scoped local broker — the provider secret stays in your encrypted vault on your Mac, and each agent only ever sees a scoped, revocable key. Don't see yours? Bring your own key and build it — included free during the launch window.
MCP agent handoff (any agent) and Codex / ChatGPT subscription handoff stay inside the same scoped AMK broker model.
We're launching free to build the next phase with real users. Any change to the free window will be announced in advance on the blog.
macOS 14+ · Apple Silicon.
No. AMK's encrypted local vault is the default. Keychain can return later as an optional Mac unlock backend. Your provider secrets stay local and are not uploaded to us.
One scoped key (amk_live_...) that can reach only the connectors and actions you allow - never your underlying secrets. You can revoke it from the dashboard at any time — new requests are refused immediately.
No. The local broker runs on your Mac, keeps the real provider secret local, and logs what each scoped agent key can do.
This free launch includes launch access to every product capability. This preview build will not be remotely downgraded. Material terms for later releases will be announced on the blog at least seven days in advance.
Reinstall or redownload whenever you need to. Your vault lives on your Mac, so a new machine starts with a fresh vault and you reconnect your providers there.
Give your agent access, not your keys — kill it in one step. This free launch includes launch access to all features.
Unlimited agents, unlimited connectors, and bring-your-own-key custom providers — all included free during the launch window. We're launching free to build the next phase with real users.