Your agent needs access. It doesn't need your keys.
Pasting a raw provider token into an agent gives it the real secret, wherever that key is stored and everywhere it works. AMK puts a local policy layer in the middle.
A leaked log can expose the underlying account key
WITH AMK
One scoped key. Control stays with you.
AMKamk_live_••••••••••••
Provider secrets stay encrypted on your Mac
Each agent sees only the connectors and actions you allow
Approvals, audit history, revocation, and a kill switch
Your agent. Your services. Your choice.
One place to manage access for the agents on your Mac.
01
Mac-first agent users
Running Codex, Claude, Cursor, Hermes, or another MCP client against real tools.
02
Choose the services
Keep the provider credentials you use in one local vault, outside your agent configuration.
03
Set the scope
Choose which connectors and actions each agent may use.
04
Stay in control
Review access, inspect the audit trail and revoke an agent when you need to.
Try an access example
Allow a request. Take access back.
See the boundary change, one action at a time.
◇ Browser simulation · dummy data · no connection to your Mac
EXAMPLE AGENTCodex
→
EXAMPLE ACCESSNot allowed
→
EXAMPLE SERVICEFirecrawl
Search for “Mac automation documentation”
The interactive controls need JavaScript. Read the complete example below, or continue to a setup guide.
No example access. Try a request, or allow example access first.
The provider key is not shown to the agent in this illustration. No keys, accounts or services are used here.
01You choose access.
Allow this example before its request can succeed.
02A request gets a result.
The allowed example returns dummy data, not a real provider response.
03The next request is denied.
Revoke the example and try again. Revocation does not undo completed work.
This explains a permission boundary. It does not demonstrate your Mac's current state, stop an in-flight request, or verify behavior across restarts. Watch the recorded app →
Real app. Real flows.
Proof, not promises.
These short previews use the actual Agent Master Key macOS app with isolated demo data—no customer secrets and no concept UI.
01
Turn on your local vault
AMK runs the broker on your Mac. Your provider credentials stay in an AES-256-GCM encrypted local vault.
02
Connect your agent
Give Codex, Claude, Cursor, Hermes, or another MCP agent one scoped Master Key instead of every provider secret.
03
Bad credentials stop here
Invalid credentials stay masked and get a clear denial. The real key is never copied into the agent.
04
One switch stops every agent
Pause scoped calls immediately without deleting the provider credentials stored in your vault.
Local-first by design
The secret never needs to leave your Mac.
The local broker uses your real provider credential only for an allowed outbound request. The agent gets a scoped amk_live_…key, not the underlying secret.
YOUR PROVIDERSGitHub · OpenAI · AWSreal scoped credentials
encrypted
ON YOUR MACAMK Local VaultAES-256-GCM · 127.0.0.1
scoped
YOUR AGENTSCodex · Claude · Cursorone revocable key each
01
Local custody
No Agent Master Key cloud vault sits in the loop. Provider secrets remain on your machine.
02
Least privilege
Grant an agent only the connectors and actions it needs. Unscoped calls are denied.
03
Human approvals
Risky actions can stop for your decision. Notifications and audit entries are redaction-aware.
04
Instant control
Revoke one agent or pause them all without rotating every provider credential.
Bring the tools you already use
One control plane. A whole stack of possibilities.
Start with the 44-connector catalog, or bring your own scoped key for a custom provider. Every route still passes through the same local broker and policy layer.
Apple Developer — Notarization
AWS
Microsoft Azure
Calendly
Claude
Cloudflare
Context7
Deepgram
DeepSeek
Discord
Docker
ElevenLabs
Firecrawl
Google AI Studio
GitHub
GitHub Copilot
GitLab
Google Cloud
Groq — fast LLM inference
HubSpot
Hugging Face
Jira
Linear
Mistral AI
New Relic
Notion
Obsidian
Omi
OpenAI
OpenRouter
Perplexity
Pinecone
PostHog
Render
Sentry
Simple Analytics
Slack
Stripe
Supabase
Telegram
Twilio
Twitter / X
Vercel
xAI
44 catalog connectors and your own
No fine-print theater
Questions people ask first.
What does my AI agent actually get?+
One scoped, revocable amk_live_… key that works through the local broker. It can reach only the connectors and actions you allowed—not your underlying provider credentials.
Does Agent Master Key upload my provider keys?+
No. The provider credentials live in an AES-256-GCM encrypted vault on your Mac and are used by the broker running on 127.0.0.1.
Is the Public Preview really free?+
Yes. During the current launch window, all product capabilities are included and no account or email is required. Future material changes are announced by Agent Master Key.
What security boundary should I understand?+
AMK limits what a scoped key can do, keeps real provider secrets out of agent configs, and gives you approvals, audit, revocation, and a kill switch. It does not claim to isolate malicious programs already running as the same macOS user. For hard OS-level separation, use separate macOS user accounts.
What Mac do I need?+
The current Public Preview supports Apple Silicon Macs running macOS 14 or later. Download the DMG, drag Agent Master Key to Applications, and connect your first agent.
AMK
Access, not secrets.
Stop handing AI agents your real keys.
Download the full Agent Master Key Public Preview and take back control of every connection.