Solo
£4.99/mo
One machine, a few scoped projects.
- ✓ 1 device
- ✓ 1 vault
- ✓ Up to 3 scoped projects
- ✓ Local audit log
- ✓ CLI + daemon
- ✓ Agent approval prompts
Local vault for passwords and API keys. Connect agents without handing them secrets.
Works with Cursor, Claude Code, MCP tools · keys stay on your machine
Your secrets
+ addOPENAI_API_KEY
sk-••••••••k4Fj
DATABASE_URL
postgres://••••5432
STRIPE_SECRET
rk_live_••••test
# agent request
agent mcp:coding-agent
asks OPENAI_API_KEY
reason: run eval suite in ./tools
Waiting for agent…
Built for people shipping agents
Complete control
Set the gate once. Instant approvals in the app or CLI. Encrypted vault. Audit trail that never leaks values.
Agents request by name. Latchkey injects into the child process — the model never sees plaintext.
Every CLI or MCP ask pauses for approve or deny. Same calm loop as a modern IDE.
libsodium secretbox. OS keychain via keytar. Argon2id passphrase fallback.
.latchkey.toml allowlists secret names per repo. Values never land in git.
Append-only metadata: who, what name, when. Secret values are never written.
Offline heuristics + rotation steps. One-off scan from £2.99 — nothing uploaded.
How it works
Encrypt passwords and API keys into the local vault.
Allowlist names in .latchkey.toml for that project only.
An agent asks for a key by name — never by reading .env.
You decide. Deny means no plaintext leaves the vault.
Try the gate
Switch audiences. Same rule: nothing injects until you say yes.
# agent request · simulated
agent mcp:cursor-agent
asks ANTHROPIC_API_KEY
reason: MCP tool latchkey_get_secret
Waiting for your decision…
Product tour
Scroll the real path. Checkout mock until secrets are live.
latchkey.com/pricing
£4.99/mo
Solo · 1/7
Get Solo →Works alongside — not a replacement for your cloud IAM. Latchkey gates what leaves the laptop.
| Topic | .env files | Latchkey |
|---|---|---|
| Where secrets live | Plaintext on disk | Ciphertext in local vault |
| Agent access | Process reads the file | Request → approve / deny |
| Project scope | Whole file or nothing | .latchkey.toml allowlist |
| Audit trail | Usually none | Append-only access log |
In build
Waitlist openLatchkey CLI and approve gate ship today. Join a list for what's next — we only email about the product you pick.
Guide cloud → full agent
Works alongside Cursor, Claude, ChatGPT, and other AI chats — Latch explains Latchkey vault, approvals, and MCP without replacing your IDE assistant. Waitlist for a deeper agent tied to your workspace.
Join Latch Agent waitlistSecurity pass for agents & repos
Scans for risky tool configs, secret-shaped strings, and MCP scope issues — complements the approve gate (the OpenAI / Hugging Face class of mistakes).
Join Latch Check waitlistAI-written code review
Static passes and dependency nudges before merge — separate SKU from Latch Check, same waitlist plumbing.
Join VibeCheck waitlistAlready live: Compare · Trust pack · Ask Latch (FAQ) · Full roadmap
Why trust Latchkey
We do not show testimonials or invented user counts. Trust comes from crypto choices, local-first storage, and a clear list of what never leaves your device.
libsodium secretbox on your machine. OS keychain or Argon2id passphrase — not a cloud vault sync product.
CLI and MCP pause before injection. Deny means no plaintext leaves the vault; audit stores names, not values.
Vault plaintext, passphrases, or secret values in logs. Hosted side: billing, licence metadata, optional scan entitlement.
From the team
Keys and AI agents
Why agent workflows need an approval gate between the model and your secrets.
Rotating a leaked key
A practical sequence when a token appears in a repo, paste, or chat log.
.env file risks
What plaintext env files get wrong for local agent tooling — and what to do instead.
Community posts
Fellows — In buildVerified UGC and fellow write-ups ship after launch. No sponsored quotes or fake creators on this page.
Fellows apply →Plans
No free tier. Most daily-driver setups land on Pro; Solo is one machine, Team when limits grow. Unbuilt features stay Coming soon.
£4.99/mo
One machine, a few scoped projects.
£15/mo
Daily flow across repos and agents.
£60/mo
Higher limits for a small group. Shared workspace & invites are in build — licence capacity ships today.
£124/mo
Higher local capacity and hardened policy.
£2.99 one-off
One local repo or paste scan for exposed keys, with rotation guidance.
Roadmap (not sold until shipped): Team sharing & invites · SSO (SAML) · Org-wide policy templates · Hosted audit export
Fast local vault. Ironclad approvals. Full oversight for every ask.