Docs
Install, CLI reference, MCP setup, and project scopes.
Install (fast path)
npm install -g @latchkey/cli latchkey login <your-licence-key> latchkey init LATCHKEY_VALUE=sk-… latchkey add MY_API_KEY
After Stripe checkout, your key is on the success page and in email. From source: npm run build -w @latchkey/cli then npx latchkey.
CLI reference
latchkey init— create vault + master key (keychain or--passphrase)latchkey add NAME— store a secret (value viaLATCHKEY_VALUE)latchkey get / list / rm— manage nameslatchkey run -- cmd— inject scoped env after approvallatchkey scan— offline leak scanlatchkey login <token>— activate licencelatchkey lock— clear unlocked material from memory
MCP setup
Point your MCP client at the Latchkey stdio server. Set LATCHKEY_MCP_APPROVE=1 in the environment that launches the server so requests can prompt for approval. The tool name is latchkey_get_secret.
{
"mcpServers": {
"latchkey": {
"command": "npx",
"args": ["latchkey", "mcp"],
"env": { "LATCHKEY_MCP_APPROVE": "1" }
}
}
}Agent sandbox (planned)
Approve/deny ships today. Preview: latchkey run --sandbox -- … (warns only; see /agent-sandbox. Do not enable sandbox flags until announced in changelog.
.latchkey.toml
# Commit this file. Never put secret values here. [scope] allowed = ["OPENAI_API_KEY", "ANTHROPIC_API_KEY"]
Threat model: /security. Questions: Yusuf@yusuf-choudhury.com.