Software
aikeys
A small command line tool that stores API keys in a local encrypted vault or the native keychain, and hands them to AI coding agents by stable names instead of by file location.
What it is
aikeys is a single-file Node.js CLI, installed as both aikeys and apikeys. Each secret is addressed as section/key with an optional version, for example openai/api_key@prod. An agent only needs to know that name; it never has to learn where the value lives.
| Command | What it does |
|---|---|
setup | Creates ~/.apikeys/config.json and vault.json, and picks the default store |
set | Stores a secret, read from a hidden prompt, stdin or AIKEYS_SECRET |
get | Prints one secret to stdout |
render | Fills {{aikeys:...}} placeholders in a template and writes the result |
scan | Finds likely secrets in a file tree, prints them masked, and can import them |
where | Prints the home, config and vault paths |
Who it is for
- Developers who work with AI coding agents and want keys out of chat history, prompts and committed files.
- Anyone who keeps .env files for several projects and wants them generated from one encrypted store.
- Teams that want a written rule agents can follow: use aikeys get or aikeys render, never read the vault.
How it works
There are two stores, chosen at setup and overridable per secret:
| Store | Where the value lives |
|---|---|
| file (default) | vault.json, encrypted per entry with AES-256-GCM under a key derived from your vault password with scrypt |
| keychain | macOS Keychain through the security command, or the Linux Secret Service through secret-tool. vault.json keeps only a pointer. |
Templates carry placeholders instead of values, so a project can commit .env.template and generate .env just in time:
.env.template
OPENAI_API_KEY={{aikeys:openai/api_key@prod}}
ANTHROPIC_API_KEY={{aikeys:anthropic/api_key}}The vault refuses entries whose recorded algorithm or KDF differs from AES-256-GCM and scrypt, and rejects wrong lengths for the salt, IV or tag before decrypting. A wrong password, a flipped ciphertext bit or a forged tag all fail with a non-zero exit and nothing on stdout. Rendered files, vault.json and config.json are always written atomically at mode 0600.
Install
The repository is public under the MIT license. aikeys is not published to the npm registry, so install it from GitHub; it has no runtime dependencies.
npm install -g github:afterdarksys/aikeys # puts aikeys and apikeys on your PATH aikeys setup # or: aikeys setup --store keychain
Or from a checkout:
git clone https://github.com/afterdarksys/aikeys.git cd aikeys npm install npm link # puts aikeys and apikeys on your PATH aikeys setup # or: aikeys setup --store keychain
You can also run it without linking: node bin/aikeys.js help.
Platform support
| Platform | Status |
|---|---|
| Node.js | 18 or newer |
| macOS | File vault and Keychain (security command; keychain secrets up to about 1,900 bytes) |
| Linux | File vault, and Secret Service when secret-tool is installed |
| Windows | File vault only. Asking for the keychain store is an error; there is no fallback. |