Stop pasting API keys into chats, notes, and .env files.

ScopeHold gives every key one home. Grant it to your coding agents per project, see everything they touched, revoke in one click. Designed for builders shipping real products with Claude Code, Cursor, and Codex.

No credit card. Free tier available. Secrets are encrypted before database write.

Agent Secrets demo (try it)

Repository automation token

API key

Read-only issue token

API key

Launch notes bot login

Login

How it works

Quick to save, safe to share.

Start with the Stripe, OpenAI, Supabase, or GitHub key your agent needs. Store it once, connect the right agent, and let the work run without exposing the raw value.

The workflow stays light enough for an individual builder and structured enough for a team.

1

Store

Store a live credential once. Values are encrypted before they are saved.

2

Connect

Connect Claude, Codex, Cursor, or another AI agent with its own scoped identity.

3

Grant

Grant the agent only the secrets it needs, with expiry set when needed.

4

Run

Run commands with secrets injected at runtime. Each retrieval is logged without exposing the raw value in chat or project files.

Access model

Access for people and agents

You can reveal a password when you need it. Your agent can run a command with a key injected at runtime. Both paths use the same grants and audit trail.

One place to manage access, without turning every agent task or team handoff into a DevOps project.

Human access

Dashboard reveal

Humans reveal only granted secrets, with optional MFA before sensitive fields are shown.

Mia Jackson

Member access

ActionSecret revealed
SecretTesting account login
TimeToday, 10:24
MFAconfirmed
optional MFAcopy fieldsaudit log
A freelancer shares two staging logins for a client review. The member reveals only what was granted, and the access event lands in the audit log.

Agent access

CLI / API retrieval

Agents retrieve only granted secrets, run with runtime injection, and keep each retrieval visible in the audit trail.

agent runtime

$ scopehold run -- deploy

injected: STRIPE_SECRET_KEY

value not printed by ScopeHold

APICLIruntime injection
Mia asks her Codex agent to fix a Stripe bug. ScopeHold injects the Stripe key at runtime, logs the retrieval, and keeps the raw value out of the prompt, chat, and project files.

Practical outcomes

Keep secrets out of chat and get clear visibility into access.

ScopeHold removes raw secrets from everyday agent work while recording human reveals, agent retrievals, denials, grants, and revokes.

Review when each secret is accessed without exposing the raw value.

Without ScopeHold
With ScopeHold
Agent chats
Keys pasted into chat
Resolved at runtime
Local files
.env full of raw keys
Names in config, values in ScopeHold
Client work
Keys copied between projects
Access scoped per agent
Audit trail
No record of access
Reveals and retrievals logged

Let agents do the work without handing them every secret.

Store a real credential, grant it to the right agent or team, and keep the raw value out of prompts, files, and logs.