Zero-knowledge · for AI coding agents
Scilo encrypts your secrets on your own device. Claude Code and Codex fetch them at runtime through a safe MCP wrapper — the plaintext never lands in a transcript, a log, or a prompt.
Prefer the CLI? It runs on macOS, Linux, and Windows too — see all downloads.
$ scilo add stripe --revealable Value for stripe: sk_live_9fK2m… Stored stripe $ claude mcp add --transport stdio scilo -- scilo mcp Claude: Running deploy script… → run_with_secrets(env=["STRIPE_KEY=stripe"], cmd=["./deploy.sh"]) ✓ exited 0
The agent asked Scilo to run the command with the secret injected — it never saw the value.
The problem
A .env file, a pasted API key, a shell variable an agent can cat — every one of these puts the plaintext somewhere a transcript, a log, or a prompt-injected instruction can read it back. Scilo isn't another password manager competing for your attention; it's the thing that replaces the copy-paste.
How it works
Your master password derives a key that wraps a random, per-vault VaultKey. A device you enroll gets its own wrap too — so unlocking on a machine you've already trusted never needs the password again. Either way, the VaultKey itself never touches Scilo's servers.
Built for AI agents
Once scilo mcp is connected, Claude Code, Claude Desktop, and Codex can call three tools — and by default, none of them can see a raw value:
list_secretsNames and metadata only — category, description, which API a key is for. Never a value.
run_with_secretsInjects a secret into a subprocess's environment. The agent triggers the run — it never reads the value back.
reveal_secretOnly works if you stored the secret with --revealable. Nothing is revealable by default.
Beyond the basics
The sync server only ever stores ciphertext and salts. There's no code path on it that can decrypt a secret — not a policy, a structural fact.
Losing a device rotates and re-encrypts the whole vault — not a permissions flag a cached key can ignore.
An org's VaultKey wraps per-member — removing someone rotates the key for real, the same guarantee as a lost device.