Five steps from empty vault to an approved agent run.
01
Install the CLI, run latchkey init, and choose keychain or passphrase wrap for the master key.
02
latchkey add NAME stores ciphertext in the local vault. Values are never written to project files.
03
Commit .latchkey.toml with the env names this repo may request.
04
latchkey run -- your-agent injects only scoped names after approval. MCP tools use the same gate.
05
Each approve or deny appends metadata to the local audit log. Export from the app when signed in.
npm install -g @latchkey/cli # or npx latchkey init latchkey add OPENAI_API_KEY # edit .latchkey.toml latchkey run -- node agent.jsFull docs