Zero-knowledge · for AI coding agents

Your API keys stay invisible to your AI agent.

Scilo encrypts your secrets on your own device. Claude Code and Codex fetch them at runtime through a safe MCP wrapper — the plaintext never lands in a transcript, a log, or a prompt.

Download for macOS See how the encryption works

Prefer the CLI? It runs on macOS, Linux, and Windows too — see all downloads.

$ scilo add stripe --revealable
Value for stripe: sk_live_9fK2m…
Stored stripe

$ claude mcp add --transport stdio scilo -- scilo mcp

Claude:  Running deploy script…
   →  run_with_secrets(env=["STRIPE_KEY=stripe"], cmd=["./deploy.sh"])
   ✓  exited 0

The agent asked Scilo to run the command with the secret injected — it never saw the value.

The problem

You're already copy-pasting secrets into an agent's context

A .env file, a pasted API key, a shell variable an agent can cat — every one of these puts the plaintext somewhere a transcript, a log, or a prompt-injected instruction can read it back. Scilo isn't another password manager competing for your attention; it's the thing that replaces the copy-paste.

How it works

One key, wrapped two ways, never leaves your device

Your master password derives a key that wraps a random, per-vault VaultKey. A device you enroll gets its own wrap too — so unlocking on a machine you've already trusted never needs the password again. Either way, the VaultKey itself never touches Scilo's servers.

Master password Device identity Vault Key encrypts every secret

Read the full breakdown — every primitive, named →

Built for AI agents

The MCP server is the whole point

Once scilo mcp is connected, Claude Code, Claude Desktop, and Codex can call three tools — and by default, none of them can see a raw value:

list_secrets

Names and metadata only — category, description, which API a key is for. Never a value.

run_with_secrets

Injects a secret into a subprocess's environment. The agent triggers the run — it never reads the value back.

reveal_secret

Only works if you stored the secret with --revealable. Nothing is revealable by default.

Beyond the basics

The details that matter when a device is lost

Zero-knowledge, actually

The sync server only ever stores ciphertext and salts. There's no code path on it that can decrypt a secret — not a policy, a structural fact.

Real revocation

Losing a device rotates and re-encrypts the whole vault — not a permissions flag a cached key can ignore.

Share with a team

An org's VaultKey wraps per-member — removing someone rotates the key for real, the same guarantee as a lost device.

Store it once. Never paste it again.