NoxKey
API keys & secrets for agents
Only for Mac
Free
Hand AI the kingdom. Keep the keys. API keys stay in the macOS Keychain — AI agents ask through MCP and get env vars. No .env, no copy-paste, no secrets in chat.
Hand AI the kingdom. Keep the keys.
Your API keys stay in the macOS Keychain. AI agents ask for them through MCP and get the values loaded as environment variables — no copy-paste, no .env files, no secrets in the conversation window.
— BUILT FOR AI AGENTS FIRST —
NoxKey ships with a Model Context Protocol server. Claude Code, Cursor, Codex, Windsurf — any MCP-aware agent — can request a secret and get it, without the raw value ever touching its chat context. The value lands in your shell as an environment variable; the agent only sees the variable name.
— TOUCH ID PROTECTED —
Protected reads use macOS system authentication. Strict secrets require fresh approval, while optional short sessions can reuse a recent unlock. Values stay in the macOS Keychain, and the clipboard clears automatically.
— ZERO OUTBOUND CONNECTIONS —
NoxKey is sandboxed without network access. macOS blocks outbound traffic at the kernel level. No telemetry, no analytics, no cloud sync. Your secrets never leave your Mac.
— MCP SERVER BUILT IN —
• Focused tools: discover, load, save, scan, and native import review
• Single-use encrypted handoff files — values never enter conversation history
• Works with Claude Code, Cursor, Codex, Windsurf, and any MCP client
— QUICK ACCESS —
A global hotkey opens a command-palette panel. Type a few letters, Touch ID unlocks, value is copied. Clipboard clears automatically.
— ORGANIZED BY PROJECT —
Secrets live under org/project paths like noboxdev/gitpulse/DATABASE_URL. Fast to browse, impossible to confuse staging with production.
— CREDENTIAL TYPES & EXPIRY TRACKING —
API keys, passwords, tokens, SSH keys, recovery codes. Mark expiry dates and get reminded before things rotate out from under you.
— REPLACES .ENV FILES —
Stop checking .env.example into git. Stop pasting tokens into PRs. Stop worrying about which dotfile leaked your Stripe key. Move every credential to NoxKey and reference it by name.
PERFECT FOR:
• Developers using AI coding agents (Claude Code, Cursor, Codex, Windsurf)
• Engineers managing API keys, tokens, database credentials
• Anyone tired of heavyweight secret managers
• Teams who want zero-trust local credential storage
REQUIRES:
• macOS 14 (Sonoma) or later
• Touch ID recommended; macOS system-authentication fallback is supported
more A cleaner vault and more reliable browser shortcuts.
• The vault now uses one streamlined row for Recent, Secrets, Logins, Recovery and SSH Keys.
• Organization and project filters now live together in the main header for faster navigation.
• Git signing identities now appear with SSH keys and can be edited, organized and scoped to an organization and project.
• Quick Password always copies a password, even when a website cannot be filled automatically.
• Blank organization, project and environment choices now resolve consistently to useful General or Any environment catch-alls.
• Removed unfinished Passkey and Secure Note categories so the vault only shows supported credential types.
1.7.3 Sep 2
A smoother, more resilient NoxKey.
• Appearance now follows your Mac by default, with persistent Always Light and Always Dark options that update the entire interface immediately.
• Settings, Audit Log, Keyboard Shortcuts and Updates now live in one compact branded menu; Updates opens the Mac App Store directly.
• Add, edit and share drafts are preserved when you click outside NoxKey, so reopening the menu-bar window returns you to exactly where you left off.
• AI agent connections can now refresh their own signed MCP helper after an update without restarting NoxKey or disturbing other connected agents.
• Safari and Chrome login workflows have more consistent project metadata, field handling and save confirmations across the app and MCP.
• Blank project, organization and environment fields now resolve predictably to General or Any environment, giving every saved item a useful catch-all scope.
• The utilities menu now stays above banners and vault content throughout the menu-bar window.
• Login cards now show the website domain followed by the account email, including useful fallbacks for older hostless records.
• The Updates action now opens the published NoxKey listing in the Mac App Store.
1.7.2 Aug 31
A cleaner, faster NoxKey built around your vault.
• A completely redesigned light interface keeps search, organizations and credential types stable at the top while every view scrolls naturally underneath.
• Switch organizations without leaving your current workflow, then browse Recent, Secrets, Logins and specialist credential types from one consistent layout.
• Projects, logins and secrets now use clearer cards, aligned project columns and type badges, with progressive loading for large vaults.
• Logins are identified by their website and username, with searchable project selection wherever a credential is created or edited.
• Copy actions always confirm success, destructive actions require confirmation, and recovery codes are consistently identified as Recovery.
• The quick-access window now sits cleanly beneath the menu bar, stays stable while changing tabs and closes when you click away.
• Large vaults scroll and navigate more smoothly through lazy rendering, cached grouping and fewer Keychain/configuration reads.
• Refreshed NoxKey branding, app icon and accent system align the app with the wider Nox family while preserving a calm, readable light theme.
• Command-Shift-A once again opens Create Login, and Git signing handles additional SSH signature formats safely.
1.7.0 Aug 30
Faster browser setup, clearer agents, and safer Git signing.
• A shorter, fully skippable setup now explains NoxKey, helps enable its bundled Safari extension, and optionally saves your name, email, organization, role, and phone for signup autofill.
• Safari can fill saved logins and signup details, generate private email aliases and strong passwords, and save a new login only after the website is submitted.
• Browser filling handles more modern form labels, password confirmation controls, and birthday formats.
• See verified NoxKey MCP integrations and inspect each live agent connection, including its client, verified host, connection age, and helper version.
• Connect an AI coding agent through a concise guided flow without changing shared project configuration.
• Use a separate Secure Enclave Git signing identity for each organization. Approval prompts show the commit subject, repository, and branch, bound to the exact payload being signed.
• Quick Password keeps one predictable meaning and never silently reads a saved login password.
1.6.1 Aug 24
Clearer agent connections and safer Git signing.
• See verified NoxKey MCP integrations and whether Codex or Claude Code is active right now.
• Expand an integration to inspect each live MCP connection, including its client, verified host, connection age, and NoxKey helper version.
• Set up NoxKey as an MCP server through a dedicated guided flow without changing shared project configuration.
• Git signing prompts now show the commit subject, repository, and branch so Touch ID approvals are easier to recognize.
• Commit context is bound to the exact payload being signed and sanitized before it reaches the system authentication prompt.
• Agents receive clearer, safer instructions for completing protected NoxKey operations without exposing secret values.
1.6.0 Aug 6
A better home for every login and clearer secret rotation.
• Browse all saved logins in one dedicated screen, grouped by organization and project.
• Search logins, filter by environment, and sort by recently added, last used, or name.
• Login rows keep email and password together, with quick access to edit or open the associated site.
• Mark secrets with a rotation deadline such as 90d or a calendar date. NoxKey shows when rotation is approaching or overdue without blocking access.
• Recent and pinned sections now treat a login as one credential instead of separate username and password entries.
• Search, shortcuts, empty states, and login editing have been polished throughout the app.
• The MCP server understands rotation deadlines and returns clearer login details to connected AI agents.
1.5.0 Aug 4
Reliability release focused on git commit signing and login storage.
• Git commit signature verification works again. The signatures themselves were always valid, but the signing helper wasn't passing the commit through to be checked, so "git log --show-signature" reported an error.
• Signing now works from any terminal or editor, even when another SSH agent is set up on your Mac.
• When your Mac is locked, NoxKey now says so instead of reporting a missing or broken signing key — and it never suggests recreating the key, which would invalidate every commit you had already signed.
• "Test signing" in Settings now runs the real signing path from end to end and shows you the result, replacing an internal check that passed even while signing was broken.
• Logins saved before 1.4.3 are migrated to the current format on launch, so every login opens and edits the same way.
• Create Login gains keyboard shortcuts: ⌘⇧A opens the panel, ⌘⇧E copies the email, ⌘⇧D copies the password.
• The audit log no longer records NoxKey's own health check as a rejected connection, so real events are easier to spot.
1.4.4 Jul 28
Project-aware logins plus major reliability hardening.
• New Create Login panel: detects the site or local project you're on, picks the right org/project, generates a unique email alias and strong password, and saves both in one step.
• Vault now tells you when it is temporarily unreadable instead of showing an empty list — no more "my keys are gone" scares.
• Git commit signing survives app updates and reinstalls: signing is served from a stable location that no longer breaks when the app moves.
• Clearer agent diagnostics when an MCP connection is rejected, so AI agents get accurate instructions instead of a misleading version-skew error.
• Fixes a case where hotkey customizations could be lost or reassigned after an update.
1.4.3 Jul 26
Compatibility hotfix for Claude Code.
• Restores MCP tool discovery in recent Claude Code releases.
• Keeps the six-tool NoxKey MCP interface unchanged.
• Adds a release check preventing incompatible tool-schema roots from shipping again.
1.4.1 Jul 23
More reliable, private AI-agent connections.
• A streamlined MCP toolset for discovering, loading, saving, scanning, and importing secrets.
• One clear Touch ID or passcode approval performs each protected mutation—without duplicate confirmation screens.
• NoxKey verifies its bundled MCP and signed caller identity before protected requests.
• Stronger cancellation, timeout, restart, update, and stale-process recovery.
• Secret discovery and scan results never expose stored values or value prefixes.
• Safer paginated search plus validated, replay-protected `.env` imports.
• A new Welcome tour and clearer Vault, Organization, and Personal Vault navigation.
1.4.0 Jul 22
A simpler, more private way to connect AI agents.
• One prompt connects any agent. Copy NoxKey's install prompt into your AI
assistant and it sets itself up — no per-agent steps, and it works with any
MCP-capable agent.
• NoxKey no longer needs access to your home folder or your agents' config
files. Your agent writes its own setup; NoxKey just guards your secrets.
• New in Settings: an "AI agent connection" section to install or reconnect an
agent in one step if its NoxKey tools ever stop showing up.
1.3.0 Jun 8
Native MCP for AI coding agents:
• NoxKey now ships its own MCP server built in — no Node.js install, no manual config files. Open Settings, hit "Install MCP," and Claude Code, Cursor, Windsurf, and Claude Desktop pick it up automatically.
• Self-healing when the app and the MCP server drift out of sync — the MCP detects the mismatch and re-installs itself.
• Clearer feedback when an AI agent triggers a Touch ID prompt: instead of a cryptic error, the agent is told the prompt is waiting on you and to pause until you respond.
• Reliability fixes around MCP bundle packaging and Release signing.
1.2.0 May 21
Built-in MCP installer for AI coding agents:
• One-click install: connect NoxKey to Claude Code, Cursor, and other MCP-compatible agents from a new Settings panel — no terminal, no config files.
• Faster, leaner MCP server: rewritten in Swift and bundled inside the app, so there's nothing extra to install and no Node runtime required.
• Self-healing setup: if you move NoxKey or use multiple Claude homes, the integration repairs itself automatically the next time an agent reconnects.
• Clearer error messages when agents talk to NoxKey, so AI assistants give you better next steps when something needs your attention.
1.1.0 May 17
Quick-access panel rebuild and Share Secrets:
• New full-window quick-access panel replaces the menu-bar dropdown — search secrets, organizations, and actions in one place.
• Share Secrets: hand a credential to another NoxKey user with an encrypted .noxkey file. End-to-end encrypted, file-only — no servers, no accounts, no network.
• Faster vault search and a more responsive interface across the app.
• Reliability fixes around credential search and the recents list.
1.0.6 May 14
Quick-access panel rebuild and Share Secrets:
• New full-window quick-access panel replaces the menu-bar dropdown — search secrets, organizations, and actions in one place.
• Share Secrets: hand a credential to another NoxKey user with an encrypted .noxkey file. End-to-end encrypted, file-only — no servers, no accounts, no network.
• Faster vault search and a more responsive interface across the app.
• Reliability fixes around credential search and the recents list.
1.0.4 May 11
Quick-access panel rebuild and Share Secrets:
• New full-window quick-access panel replaces the menu-bar dropdown — search secrets, organizations, and actions in one place.
• Share Secrets: hand a credential to another NoxKey user with an encrypted .noxkey file. End-to-end encrypted, file-only — no servers, no accounts, no network.
• Faster vault search and a more responsive interface across the app.
• Reliability fixes around credential search and the recents list.
1.0.3 May 9
Polish and reliability improvements:
• Vault search now persists when you close and reopen the panel, so returning to a filtered view no longer starts over.
• Refreshed app icon and brand system across the app and website.
• Smaller copy, layout, and readability improvements throughout.
1.0.2 Apr 24
A cleaner vault and more reliable browser shortcuts.
• The vault now uses one streamlined row for Recent, Secrets, Logins, Recovery and SSH Keys.
• Organization and project filters now live together in the main header for faster navigation.
• Git signing identities now appear with SSH keys and can be edited, organized and scoped to an organization and project.
• Quick Password always copies a password, even when a website cannot be filled automatically.
• Blank organization, project and environment choices now resolve consistently to useful General or Any environment catch-alls.
• Removed unfinished Passkey and Secure Note categories so the vault only shows supported credential types.
more Version 1.7.3 Sep 2
Data Not Collected The developer does not collect any data from this app.