Documentation menu

Software

aikeys

A small command line tool that stores API keys in a local encrypted vault or the native keychain, and hands them to AI coding agents by stable names instead of by file location.

What it is

aikeys is a single-file Node.js CLI, installed as both aikeys and apikeys. Each secret is addressed as section/key with an optional version, for example openai/api_key@prod. An agent only needs to know that name; it never has to learn where the value lives.

CommandWhat it does
setupCreates ~/.apikeys/config.json and vault.json, and picks the default store
setStores a secret, read from a hidden prompt, stdin or AIKEYS_SECRET
getPrints one secret to stdout
renderFills {{aikeys:...}} placeholders in a template and writes the result
scanFinds likely secrets in a file tree, prints them masked, and can import them
wherePrints the home, config and vault paths
aikeys runs entirely on your machine. It does not connect to SecretServer and needs no account or API key.

Who it is for

  • Developers who work with AI coding agents and want keys out of chat history, prompts and committed files.
  • Anyone who keeps .env files for several projects and wants them generated from one encrypted store.
  • Teams that want a written rule agents can follow: use aikeys get or aikeys render, never read the vault.

How it works

There are two stores, chosen at setup and overridable per secret:

StoreWhere the value lives
file (default)vault.json, encrypted per entry with AES-256-GCM under a key derived from your vault password with scrypt
keychainmacOS Keychain through the security command, or the Linux Secret Service through secret-tool. vault.json keeps only a pointer.

Templates carry placeholders instead of values, so a project can commit .env.template and generate .env just in time:

.env.template

OPENAI_API_KEY={{aikeys:openai/api_key@prod}}
ANTHROPIC_API_KEY={{aikeys:anthropic/api_key}}

The vault refuses entries whose recorded algorithm or KDF differs from AES-256-GCM and scrypt, and rejects wrong lengths for the salt, IV or tag before decrypting. A wrong password, a flipped ciphertext bit or a forged tag all fail with a non-zero exit and nothing on stdout. Rendered files, vault.json and config.json are always written atomically at mode 0600.

Install

The repository is public under the MIT license. aikeys is not published to the npm registry, so install it from GitHub; it has no runtime dependencies.

npm install -g github:afterdarksys/aikeys   # puts aikeys and apikeys on your PATH
aikeys setup                                # or: aikeys setup --store keychain

Or from a checkout:

git clone https://github.com/afterdarksys/aikeys.git
cd aikeys
npm install
npm link            # puts aikeys and apikeys on your PATH

aikeys setup        # or: aikeys setup --store keychain

You can also run it without linking: node bin/aikeys.js help.

Platform support

PlatformStatus
Node.js18 or newer
macOSFile vault and Keychain (security command; keychain secrets up to about 1,900 bytes)
LinuxFile vault, and Secret Service when secret-tool is installed
WindowsFile vault only. Asking for the keychain store is an error; there is no fallback.