Skip to content

Agent Keychain

Use your credentials across devices and agent sessions.

Store API keys, approve your agent, and connect through MCP. Keychain runs on Lit, so you can work across devices and sessions without deploying or maintaining a secrets server.

One keychain. Access from the agents you approve. MCP
LaptopApproved agent
WorkstationApproved agent
New sessionSame agent setup
Lit Agent KeychainYour encrypted credentials
Access you approve
Permission checked inside Lit
No credential server to host. Set up each device once; reuse its agent configuration across sessions.

Get started with MCP

Sign in and connect your agent.

Give your agent the setup guide. You approve access; Keychain handles credential storage and delivery through Lit.

Agent setup guide
  1. Store your credentials.

    Sign in with Google, a passkey, or a wallet. Your browser encrypts credentials before they are stored in Keychain.

  2. Approve your agent.

    Your agent creates an identity on its device. In Keychain, choose which credentials it can use and when access expires.

  3. Connect through MCP.

    Download the agent configuration and add Keychain to your MCP client. Reuse that setup across sessions while your approval remains valid.

Works with your tools

Use Keychain from your agent.

Connect through MCP in Claude Code, Cursor, or another compatible client. The SDK and CLI are there for your own integrations.

Fetch it for a local tool.

Deliver a stored secret to an approved agent or command when it needs it. The credential is decrypted in that environment.

SDK, CLI & MCP guide

Use it inside Lit.

For supported services, Lit can use the key and return the result. An agent can check a Stripe balance, for example, without receiving the Stripe key.

Explore supported actions

How Lit powers Keychain

Convenient to use. Open to inspection.

Open-source.

Inspect the credential-handling actions in Keychain’s public library, including the operations and destinations each action allows.

Read the source

Cryptographically verifiable.

The client checks hardware attestation and approved runtime measurements. Lit verifies your signed permission on each request.

How verification works

Confidential.

Credentials are stored encrypted. Lit checks access inside confidential hardware, then uses the credential or encrypts it for delivery to the approved agent.

Read the security model

Common questions.

What does Keychain cost?

Keychain is free for 5 secrets, or $10/month for up to 1,000.

What carries across devices and sessions?

Your stored credentials and approved access. Each device needs a configured client and an approved agent identity. Later sessions can reuse that setup while permission remains valid. Keychain does not sync conversations, agent memory, or private identity files.

Do I need to run a server?

You don’t need to host a credential server or database. Install the Keychain client on the machine running your tools. For MCP, the local connector runs alongside your agent and connects to the hosted Keychain and Lit services.

What do I still trust?

Your client, sign-in provider, and Lit runtime remain part of the security model. Keychain’s storage service supplies the current signed permission record; an operator can replay an older valid approval until it expires. These records are separate from ChainSecured wallet permissions. Revoke the provider key too if compromise is suspected. Full security model ↗

How do I recover access?

Add and test a second owner credential, and keep an encrypted backup. Connected-service credentials cannot be exported, so retain the original keys separately. Read the recovery guide ↗

Lit Agent Keychain

Set up your keychain.

Open Keychain