A local-first, zero-knowledge secrets workspace and configuration manager for developers and AI coding agents.
KeyHarbor gives developers a safe, encrypted space to manage application credentials, validate .env requirements, and inject secrets into CLI commands or AI workflows. Every secret read or write through external tools requires deliberate, interactive approval—keeping credentials off the cloud, out of prompt logs, and protected from silent exfiltration.
Real screenshots of the desktop app on macOS, using a temporary demo vault with fictional projects and credentials. Secret values remain masked.
Your projects, together in one local vault.

Separate environments, masked secrets, and useful metadata.

Compare an environment against its required keys. This demo deliberately omits SENTRY_DSN, so the checklist marks it as missing.

External secret requests open a desktop prompt showing the vault, project, environment, and requested key. You choose whether to approve or deny access.
Vault → Project → Environment → Secrets). Maintain independent dev, staging, and prod configurations without accidental value bleed or fallback..env.example templates. Instantly see whether required variables are Ready, Missing, Empty, or Expired..env files up to 1 MiB / 5,000 assignments with masked visual reviews and explicit conflict resolution. Export keys-only templates, secret references, or encrypted backups.flowchart TD
subgraph UI ["Desktop App (Electron + React)"]
Dashboard["Vault & Project Dashboard"]
EnvManager["Environment & Secrets Table"]
ApprovalPrompt["Interactive Approval Gate"]
end
subgraph External ["External Callers"]
CLI["KeyHarbor CLI\n(keyharbor run / get / set)"]
MCP["MCP Server (v2)\n(Coding Agents: Claude, Cursor, Codex)"]
HTTP["Local HTTP Bridge"]
end
subgraph Storage ["Encrypted Storage (~/.keyharbor)"]
VaultFile[("Encrypted Vault\nAES-256-GCM")]
Logs[("Encrypted Audit Logs")]
end
CLI -->|Request Access| ApprovalPrompt
MCP -->|Request Access| ApprovalPrompt
HTTP -->|Request Access| ApprovalPrompt
ApprovalPrompt -->|User Confirms| VaultFile
Dashboard --> EnvManager
EnvManager --> VaultFile
VaultFile --> Logs
20.19+ or >= 22.1210+# Clone repository
git clone https://github.com/varunyn/KeyHarbor.git
cd KeyHarbor
# Install dependencies
npm install
# Start the application
npm start
To produce standalone installers:
# macOS (.dmg)
npm run build:mac
# Windows (.exe / NSIS)
npm run build:win
# Linux (.AppImage)
npm run build:linux
The KeyHarbor CLI allows you to read, write, and inject credentials into terminal commands. The desktop app must be running and unlocked; commands will trigger an interactive approval dialog before executing.
# List all accessible projects
keyharbor list
# Retrieve a specific secret (returns JSON with value and expiration)
keyharbor get myapp DATABASE_URL --env=prod
# Set or update a secret (requires write approval)
keyharbor set myapp STRIPE_KEY "sk_live_123456789" --env=prod
# Run a process with secrets injected directly into its environment
keyharbor run --project=myapp --env=dev -- npm run dev
# Omitting --env defaults to the project's designated default environment
keyharbor run --project=myapp -- docker compose up
KeyHarbor ships with a Model Context Protocol (MCP v2) server over stdio. AI coding agents can inspect configuration requirements and read or set secrets under strict user approval.
In the KeyHarbor desktop app, open Settings and ensure the CLI helper is installed, or build the backend locally with npm run build:backend.
~/.codex/config.toml)[mcp_servers.keyharbor]
command = "keyharbor"
args = ["mcp"]
default_tools_approval_mode = "writes"
tool_timeout_sec = 60
claude_desktop_config.json){
"mcpServers": {
"keyharbor": {
"command": "keyharbor",
"args": ["mcp"]
}
}
}
Settings → Features → MCP)keyharborcommandkeyharbor mcpkeyharbor_status: Check daemon status and vault unlock state.list_projects: Discover available projects and environments.create_project: Create a new project workspace.list_secret_keys: Enumerate key names in a project environment (metadata-only, requires read approval).get_secret / get_secrets: Fetch one or more secret values (prompts desktop approval).set_secrets: Store or update one or multiple secrets in batch (prompts desktop approval).default, dev, staging, prod, etc.), which hold Secrets.prod will never silently fall back to dev.--env flag target this default rather than whichever environment is active in the desktop GUI..env.example file or uploading a template..env Import & Exportexport prefixes..env.example (keys-only baseline)keyharbor://project/KEY?environment=dev).lkvb)~/.keyharbor. Installations migrated from previous versions will seamlessly read existing data from ~/.localkeys without moving files or invalidating backups.├── cli/ # Stdio CLI and MCP v2 server implementations
├── src/
│ ├── main.ts # Electron main process entry point
│ ├── preload.ts # Typed contextBridge IPC interface
│ ├── modules/ # Vault crypto, storage, HTTP server, and logger
│ ├── dashboard/ # React views for Vault and Project management
│ ├── project/ # React views for Secrets table, imports, & checks
│ ├── renderer/ # Shared React components, Radix UI, & i18n
│ └── styles/ # Tailwind CSS and theme tokens
├── test/ # Unit and integration test suites
| Command | Description |
|---|---|
npm start | Builds renderer & backend, then launches Electron |
npm run test | Executes unit tests via Node test runner |
npm run check | Runs Ultracite read-only code quality & style checks |
npm run check:backend | Validates TypeScript types and backend linting |
npm run fix -- <path> | Formats a specific file using Oxfmt |
npm run build:backend | Compiles backend TypeScript to backend-build/ |
npm run build:renderer | Compiles React views and assets via Vite |
This project is licensed under the MIT License.
A local-first, zero-knowledge secrets workspace and configuration manager for developers and AI coding agents.
KeyHarbor gives developers a safe, encrypted space to manage application credentials, validate .env requirements, and inject secrets into CLI commands or AI workflows. Every secret read or write through external tools requires deliberate, interactive approval—keeping credentials off the cloud, out of prompt logs, and protected from silent exfiltration.
Real screenshots of the desktop app on macOS, using a temporary demo vault with fictional projects and credentials. Secret values remain masked.
Your projects, together in one local vault.

Separate environments, masked secrets, and useful metadata.

Compare an environment against its required keys. This demo deliberately omits SENTRY_DSN, so the checklist marks it as missing.

External secret requests open a desktop prompt showing the vault, project, environment, and requested key. You choose whether to approve or deny access.
Vault → Project → Environment → Secrets). Maintain independent dev, staging, and prod configurations without accidental value bleed or fallback..env.example templates. Instantly see whether required variables are Ready, Missing, Empty, or Expired..env files up to 1 MiB / 5,000 assignments with masked visual reviews and explicit conflict resolution. Export keys-only templates, secret references, or encrypted backups.flowchart TD
subgraph UI ["Desktop App (Electron + React)"]
Dashboard["Vault & Project Dashboard"]
EnvManager["Environment & Secrets Table"]
ApprovalPrompt["Interactive Approval Gate"]
end
subgraph External ["External Callers"]
CLI["KeyHarbor CLI\n(keyharbor run / get / set)"]
MCP["MCP Server (v2)\n(Coding Agents: Claude, Cursor, Codex)"]
HTTP["Local HTTP Bridge"]
end
subgraph Storage ["Encrypted Storage (~/.keyharbor)"]
VaultFile[("Encrypted Vault\nAES-256-GCM")]
Logs[("Encrypted Audit Logs")]
end
CLI -->|Request Access| ApprovalPrompt
MCP -->|Request Access| ApprovalPrompt
HTTP -->|Request Access| ApprovalPrompt
ApprovalPrompt -->|User Confirms| VaultFile
Dashboard --> EnvManager
EnvManager --> VaultFile
VaultFile --> Logs
20.19+ or >= 22.1210+# Clone repository
git clone https://github.com/varunyn/KeyHarbor.git
cd KeyHarbor
# Install dependencies
npm install
# Start the application
npm start
To produce standalone installers:
# macOS (.dmg)
npm run build:mac
# Windows (.exe / NSIS)
npm run build:win
# Linux (.AppImage)
npm run build:linux
The KeyHarbor CLI allows you to read, write, and inject credentials into terminal commands. The desktop app must be running and unlocked; commands will trigger an interactive approval dialog before executing.
# List all accessible projects
keyharbor list
# Retrieve a specific secret (returns JSON with value and expiration)
keyharbor get myapp DATABASE_URL --env=prod
# Set or update a secret (requires write approval)
keyharbor set myapp STRIPE_KEY "sk_live_123456789" --env=prod
# Run a process with secrets injected directly into its environment
keyharbor run --project=myapp --env=dev -- npm run dev
# Omitting --env defaults to the project's designated default environment
keyharbor run --project=myapp -- docker compose up
KeyHarbor ships with a Model Context Protocol (MCP v2) server over stdio. AI coding agents can inspect configuration requirements and read or set secrets under strict user approval.
In the KeyHarbor desktop app, open Settings and ensure the CLI helper is installed, or build the backend locally with npm run build:backend.
~/.codex/config.toml)[mcp_servers.keyharbor]
command = "keyharbor"
args = ["mcp"]
default_tools_approval_mode = "writes"
tool_timeout_sec = 60
claude_desktop_config.json){
"mcpServers": {
"keyharbor": {
"command": "keyharbor",
"args": ["mcp"]
}
}
}
Settings → Features → MCP)keyharborcommandkeyharbor mcpkeyharbor_status: Check daemon status and vault unlock state.list_projects: Discover available projects and environments.create_project: Create a new project workspace.list_secret_keys: Enumerate key names in a project environment (metadata-only, requires read approval).get_secret / get_secrets: Fetch one or more secret values (prompts desktop approval).set_secrets: Store or update one or multiple secrets in batch (prompts desktop approval).default, dev, staging, prod, etc.), which hold Secrets.prod will never silently fall back to dev.--env flag target this default rather than whichever environment is active in the desktop GUI..env.example file or uploading a template..env Import & Exportexport prefixes..env.example (keys-only baseline)keyharbor://project/KEY?environment=dev).lkvb)~/.keyharbor. Installations migrated from previous versions will seamlessly read existing data from ~/.localkeys without moving files or invalidating backups.├── cli/ # Stdio CLI and MCP v2 server implementations
├── src/
│ ├── main.ts # Electron main process entry point
│ ├── preload.ts # Typed contextBridge IPC interface
│ ├── modules/ # Vault crypto, storage, HTTP server, and logger
│ ├── dashboard/ # React views for Vault and Project management
│ ├── project/ # React views for Secrets table, imports, & checks
│ ├── renderer/ # Shared React components, Radix UI, & i18n
│ └── styles/ # Tailwind CSS and theme tokens
├── test/ # Unit and integration test suites
| Command | Description |
|---|---|
npm start | Builds renderer & backend, then launches Electron |
npm run test | Executes unit tests via Node test runner |
npm run check | Runs Ultracite read-only code quality & style checks |
npm run check:backend | Validates TypeScript types and backend linting |
npm run fix -- <path> | Formats a specific file using Oxfmt |
npm run build:backend | Compiles backend TypeScript to backend-build/ |
npm run build:renderer | Compiles React views and assets via Vite |
This project is licensed under the MIT License.