software · open source · secrets vault

vaultos

Keep your API keys in one place on your Mac. Give coding agents the access they need, without pasting your keys into chat.

View on GitHub

Set up VaultOS with your agent.

Paste this into your coding agent. You’ll unlock the vault and approve access yourself. If the clipboard isn’t available, select the text and copy it.

  • macOS 13+
  • free and open source
  • unsigned preview

the idea

another project, less setup

Every new project needs the same keys in another .env file. VaultOS keeps your keys organised and lets your agent write the ones you approve into the right project.

How a handoff goes

  1. MCP

    your coding agent

    asks to inject API_KEY into example-app

  2. on your Mac

    VaultOS

    checks your rules for this agent

  3. local

    your project

    API_KEY written to .env.local, ready to build

An illustrated handoff. The tool response contains names and counts, no secret values.

the app

what it looks like

Find a key, check its details and manage agent access from one desktop app.

The VaultOS Mac app showing a project called Example App with one stored key, and buttons to hide, copy, edit or delete it.
The real app, with made-up example data. Apple Silicon and Intel · macOS 13+ · unsigned preview.

your rules

give each agent the access it needs

  1. find the key you need.

    Group keys by project, search by name or provider, and check expiry dates in one place.

    projects · search · expiry
  2. choose what each agent can use.

    Give each agent its own access. Choose the projects it can use, the folders it can write to, and the actions it can take through VaultOS.

    per-agent permissions
  3. skip the copy and paste.

    Let your agent write approved keys into an environment file through MCP. Choose dotenv, JSON, or shell format. The tool response reports what was written without including the values.

    scoped secret injection
  4. keep the final say.

    An agent needs your permission to edit credentials you own. If it adds a new key, you approve that key before it can write it into a project.

    human approval
  5. keep your vault on your Mac.

    Your vault is encrypted and stored locally. There is no account to create, no telemetry, and no automatic cloud upload. You can choose to remember your password in Keychain.

    local storage · opt-in keychain
  6. back it up.

    Make encrypted backups, export a PDF, change your vault password, or review and undo supported changes. Optional encrypted Git sync lets you connect another machine when you need to.

    backups · recovery · optional sync

security

what it protects, and what it can't

VaultOS keeps secret values out of injection responses. The files it writes still contain plaintext secrets, and an agent with filesystem access can read them.

Think of it as a way to organise your keys and control how agents use the vault. It cannot isolate an agent from files on your Mac.

from download to first project

three steps to set it up

  1. install the preview.

    Download the preview for your Mac. Verify its checksum, open it, and create a vault with a passphrase you’ll remember.

  2. choose the access.

    Add a project. Enrol your agent. Choose its permissions and the folders it can write to. Save its token in a private file.

  3. let your agent help.

    Give it the setup prompt. It can prepare the MCP bridge and verify a test injection. You handle passwords and approvals.

    Set up VaultOS with your agent.

    Paste this into your coding agent. You’ll unlock the vault and approve access yourself. If the clipboard isn’t available, select the text and copy it.

questions

before you hand over a key

Why use this instead of just an .env file?

An .env file works well for configuring an app. VaultOS helps when you have several projects and want one place to manage their keys. Your agent can write approved keys into the right file, so you do not have to find and paste them each time. That file still contains plaintext secrets.

Can an agent still read my secrets?

Yes, if it has filesystem or shell access to a file containing them. VaultOS keeps values out of the injection tool response, but it cannot stop an agent from reading a file it can already access. Asking VaultOS to reveal a value is a separate permission, turned off by default.

Which coding agents can use it?

You can connect a coding client that supports local MCP servers over stdio. The setup prompt helps your agent follow the right instructions for your client. The MCP bridge needs Node.js 22 or later and a checkout of the repository. The desktop app includes its own runtime.

Is the macOS preview signed and notarized?

No. The current preview is unsigned and has not been notarized by Apple. Download the Apple Silicon or Intel build for your Mac, verify its checksum, and follow the opening instructions on GitHub. Start with test credentials and keep separate backups. VaultOS has not had an independent security audit.

What happens when I lock or close the app?

Lock stops the desktop API and blocks remembered background unlock until a human unlocks again. While the desktop is running, sleep, screen lock, and 15 minutes without a privileged desktop action also lock it. Closing stops its API, but an explicitly enabled background helper can restart a separate backend. That headless backend does not monitor screen lock.

Is it free? Does it require a cloud account?

Yes, it is free and open source under the MIT license. You can use the local vault without a cloud account. Sync is optional and needs a separate Git repository. There is no password reset service, so keep your passphrase and backups somewhere safe.

try it

start with one project and a test key

View on GitHub

Set up VaultOS with your agent.

Paste this into your coding agent. You’ll unlock the vault and approve access yourself. If the clipboard isn’t available, select the text and copy it.