Local vault
Secrets are encrypted at rest in the local vault. You unlock with your master password; Cloud receives ciphertext only when you choose encrypted sync.
Optional cloud companion to WispKey
WispKey is a local-first credential firewall for AI agents: credentials live encrypted on your machine, agents use opaque wisp tokens, and a local proxy swaps tokens for real secrets at the network boundary. WispKey Cloud adds encrypted sync and team/org groundwork without receiving your master key or plaintext secrets.
The open-source CLI keeps control on your hardware: a local encrypted vault, HTTP/HTTPS proxy modes, MCP tooling, policies, audit logs, and wisp tokens so agents never see raw API keys.
Secrets are encrypted at rest in the local vault. You unlock with your master password; Cloud receives ciphertext only when you choose encrypted sync.
Point tools at the WispKey proxy. Requests carry wisp tokens; the proxy resolves policy-checked credentials so agents stay productive without direct secret access.
Backend services for encrypted sync, billing, and team/org groundwork, built on Cloudflare with ciphertext in object storage and non-sensitive metadata in D1.
Partition blobs stay encrypted end-to-end. Cloud stores opaque ciphertext and sync indexes—not your master key or plaintext vault.
Project, partition, and single-credential share metadata routes store ciphertext and grants. Recipient acceptance flows are still being built.
Clerk-backed user, plan, org, and member primitives support Enterprise workflows without adding plaintext secret access to Cloud.
Operational visibility into sync and partition lifecycle metadata without exposing secret values.
Start free with the open-source core. Add Cloud when you need encrypted sync and managed team/org infrastructure.
$0 forever
$1.99 / mo
Contact us
The credential firewall your agents use every day stays public and auditable.
Open source core. WispKey CLI, proxy, MCP server, policy engine, and audit log live in the public repository. WispKey Cloud is the optional managed backend that pairs with what you already run locally.
github.com/rankupgames/wispkey