Optional cloud companion to WispKey

Your AI agents work. Your secrets stay home.

WispKey is a local-first credential firewall for AI agents: credentials live encrypted on your machine, agents use opaque wisp tokens, and a local proxy swaps tokens for real secrets at the network boundary. WispKey Cloud adds encrypted sync and team/org groundwork without receiving your master key or plaintext secrets.

How WispKey works

The open-source CLI keeps control on your hardware: a local encrypted vault, HTTP/HTTPS proxy modes, MCP tooling, policies, audit logs, and wisp tokens so agents never see raw API keys.

Local vault

Secrets are encrypted at rest in the local vault. You unlock with your master password; Cloud receives ciphertext only when you choose encrypted sync.

Proxy and wisp tokens

Point tools at the WispKey proxy. Requests carry wisp tokens; the proxy resolves policy-checked credentials so agents stay productive without direct secret access.

WispKey Cloud

Backend services for encrypted sync, billing, and team/org groundwork, built on Cloudflare with ciphertext in object storage and non-sensitive metadata in D1.

Encrypted sync

Partition blobs stay encrypted end-to-end. Cloud stores opaque ciphertext and sync indexes—not your master key or plaintext vault.

Encrypted share APIs

Project, partition, and single-credential share metadata routes store ciphertext and grants. Recipient acceptance flows are still being built.

Org groundwork

Clerk-backed user, plan, org, and member primitives support Enterprise workflows without adding plaintext secret access to Cloud.

Sync activity records

Operational visibility into sync and partition lifecycle metadata without exposing secret values.

Pricing

Start free with the open-source core. Add Cloud when you need encrypted sync and managed team/org infrastructure.

Personal

$0 forever

  • Local vault, proxy, MCP, plugin
  • Unlimited local credentials
  • Policy engine and audit log
  • No cloud account required

Enterprise

Contact us

  • Everything in Cloud
  • Unlimited partitions
  • Org management and SSO
  • Dedicated support

Open source

Open source core. WispKey CLI, proxy, MCP server, policy engine, and audit log live in the public repository. WispKey Cloud is the optional managed backend that pairs with what you already run locally.

github.com/rankupgames/wispkey