Protect API keys from OpenClaw agent access using Linux user isolation
-
Updated
Feb 8, 2026 - Shell
Protect API keys from OpenClaw agent access using Linux user isolation
Agent-native macOS Keychain CLI for dev secrets. Never in .env files, shell history, or chat.
Claude Code skill for 1Password secrets management — store, read, and inject API keys and credentials using the op CLI
Hand API keys to your AI coding assistant without pasting them into the chat. Hidden-input dialog -> .env + encrypted .env.enc (SOPS + age). Apache-2.0.
A lightning-fast, Bash-based web security analysis tool. SpyWeb crawls and scans remote URLs or local files to detect leaked API keys, cloud tokens, passwords, and sensitive information using highly optimized regex patterns.
Save a secret: a small window opens that Claude cannot see, you paste there, it lands in 1Password. Read it back: any item in your vault loads into Claude with one fingerprint check, names only, never the values. Keys you paste in the chat are deleted before Claude reads them. Mac, Windows, Linux. MIT.
Easy API Key switcher for Claude Switching between Z.AI and Kimi
Zero-config credential DLP for Claude Code — auto-intercepts API keys, stores to macOS Keychain, blocks before Anthropic
Bulk-rotate a leaked API-key env var across every .env and .mcp.json, safely. Dry-run by default, never prints the secret; agent- and CI-safe.
Prevent committing sensitive keys to repos
macOS Keychain-based secrets manager for exporting project .env files without storing API keys in plaintext.
Keep API keys out of your Claude Code transcripts: GUI capture into DPAPI, plus a PreToolUse hook that blocks the commands which print secrets back into the session log.
Zero-dependency, offline pre-commit credential firewall.
Git secret scanner and protection tool - prevent API keys, passwords, and credentials from being committed (Dual Licensed: GPL v3 / Commercial)
This simple repository offers a set of guards to mitigate secret leakage into application source codes. It can prevent the disclosure of sensitive API keys, web hooks and cloud tokens by setting three guards. Pre-commit, Pre-Push and on PR. If secret somehow escapes into the PR, it fails it and opens an issue.
🔑 Stop pasting API keys into Claude Code & Cursor. keypop pops a native dialog to collect a secret your agent never sees — value goes to a local file, never the model's context. 60 lines of shell, no infra.
Universal environment variable manager for macOS & Linux GUI/CLI apps · public mirror
To associate your repository with the api-keys topic, visit your repo's landing page and select "manage topics."