keyrelay

Pass the key.
Keep it out
of chat.

Your coding agent needs a token.
Your conversation doesn’t.

Keyrelay gives you a private link to review a command and send its credential once. The agent gets on with the work. No account or API key is needed to install Keyrelay.

npx keyrelay --help

Runs locally. No Tailscale required. Node.js + Python 3.9+.

A credential’s journey EXAMPLE
Agent requests accessCLI
$ npx keyrelay run \
  --env API_KEY -- your-command
One-time linkexpires in 5 min
You review the commandPRIVATE
your-command
•••• •••• •••• ••••
Send once
Delivered to the command
Plain-text secret echoes redacted.

Example syntax: replace your-command with your tool. This site collects no credentials.

A small detour.
A better handoff.

For the moment your agent says,
“I need an API key.”

  1. 1

    Ask for a credential.

    The agent wraps its command with Keyrelay. A temporary local broker starts; the runner prints a link and waits.

  2. 2

    See what will run.

    Open the local link on the same computer. Review the command and enter the token in your browser.

  3. 3

    Send it once.

    The runner claims the credential, passes it through an environment variable or stdin, and runs the command.

Your computer.
Your trust boundary.

Run one command. Keyrelay starts a temporary broker on your computer and shuts it down afterward. Tailscale is optional if you want to enter keys from another device.

Read the security model
In memory
Requests expire after five minutes. Successful claims delete the entry; expired entries are cleared on the next request.
In your control
Bound to localhost. No database or HTTP request logging. Other programs on your computer share the same trust boundary.
Built on trust
Keyrelay keeps the handoff out of chat. A command still receives the real secret and can store or transmit it. Review what you run.

The next time it asks for a key,
give it a relay.

Get started on GitHub