Stop pasting API keys into chats, notes, and .env files.
ScopeHold gives every key one home. Grant it to your coding agents per project, see everything they touched, revoke in one click. Designed for builders shipping real products with Claude Code, Cursor, and Codex.
No credit card. Free tier available. Secrets are encrypted before database write.
Agent Secrets demo (try it)
Repository automation token
Shared PR context
Read-only issue token
Research context
Launch notes bot login
Draft releases
How it works
Quick to save, safe to share.
Start with the Stripe, OpenAI, Supabase, or GitHub key your agent needs. Store it once, connect the right agent, and let the work run without exposing the raw value.
The workflow stays light enough for an individual builder and structured enough for a team.
Store
Store a live credential once. Values are encrypted before they are saved.
Connect
Connect Claude, Codex, Cursor, or another AI agent with its own scoped identity.
Grant
Grant the agent only the secrets it needs, with expiry set when needed.
Run
Run commands with secrets injected at runtime. Each retrieval is logged without exposing the raw value in chat or project files.
Access model
Access for people and agents
You can reveal a password when you need it. Your agent can run a command with a key injected at runtime. Both paths use the same grants and audit trail.
One place to manage access, without turning every agent task or team handoff into a DevOps project.
Human access
Dashboard reveal
Humans reveal only granted secrets, with optional MFA before sensitive fields are shown.
Mia Jackson
Member access
Agent access
CLI / API retrieval
Agents retrieve only granted secrets, run with runtime injection, and keep each retrieval visible in the audit trail.
$ scopehold run -- deploy
injected: STRIPE_SECRET_KEY
value not printed by ScopeHold
Practical outcomes
Keep secrets out of chat and get clear visibility into access.
ScopeHold removes raw secrets from everyday agent work while recording human reveals, agent retrievals, denials, grants, and revokes.
Review when each secret is accessed without exposing the raw value.
Let agents do the work without handing them every secret.
Store a real credential, grant it to the right agent or team, and keep the raw value out of prompts, files, and logs.