vs .env on disk
| Topic | .env files | Latchkey |
|---|
| Where secrets live | Plaintext on disk | Ciphertext in local vault |
| Agent access | Process reads the file | Request → approve / deny |
| Project scope | Whole file or nothing | .latchkey.toml allowlist |
| Audit trail | Usually none | Append-only access log |
| Model sees values | Often yes (in context) | No — inject into child only |
| Cloud vault sync | N/A | Not our model — device-local |
vs other approaches
| Topic | Typical alternative | Latchkey |
|---|
| Cloud secret managers | Central store, IAM, rotation APIs | Developer laptop + agent gate; keys never hosted by us |
| Password managers | Human unlock, browser fill | CLI/MCP inject with per-request approve |
Plan limits (GBP / month)
| Feature | Solo£4.99 | Pro£15 | Team£60 | Business£124 |
|---|
| Devices | 1 | 3 | 10 | 25 |
| Vaults | 1 | 2 | 5 | 10 |
| Scoped projects | 3 scoped projects | 15 scoped projects | Unlimited | Unlimited |
| MCP approve mode | — | Yes | Yes | Yes |
| Team workspace (preview) | Solo/Pro | Solo/Pro | Yes | Yes |
Enterprise is custom — contact. Leak scan is £2.99 one-off on pricing.