FREE & OPEN SOURCE
Keychain-first credential management.
Secure, systematic environment bootstrapping for multi-channel DTC brands. Every API key stored in Apple Keychain, validated with smoke tests, protected by pre-commit hooks. 30+ services supported.
30+ services. One workflow.
Every credential your project needs — acquired, validated, and secured in a single session.
GitHub · Vercel · Supabase · Cloudflare · GoDaddy
Shopify (full admin: products, orders, customers, themes, content)
Stripe · Omise (Opn) · PayPal · Shopify Payments
Meta (Facebook + Instagram + Ads) · Google Ads
GA4 · Klaviyo
Gmail · Google Drive · Gorgias · Twilio
OpenAI · Anthropic · xAI (Grok) · Gemini
Figma · Canva · FreePik · Milanote · Notion · Sentry · QuickBooks
Five steps. Zero guesswork.
Service Inventory
Select which services your project needs from a visual checklist.
Keychain Namespace
Create a project-scoped namespace in Apple Keychain — encrypted at rest, biometric unlock.
Credential Acquisition
Walk through each service: dashboard URL → key generation → format validation → Keychain storage.
Smoke Tests
Verify every connection works with per-service health checks before moving on.
Security Hardening
Pre-commit secret scanning, credential lifecycle tracking, AI context rules.
Four security tiers.
NEXT_PUBLIC_SHOPIFY_STORE_DOMAINSafe to exposeVERCEL_ORG_IDServer-side onlyOPENAI_API_KEYAPI key — billableSTRIPE_SECRET_KEY — can spend real moneyCan spend real moneyThree commands. Five minutes.
Clone, open the workflow, and let your AI agent walk you through it.
The workflow runs interactively. Your agent will prompt you service by service, help you acquire credentials, store them in Keychain, and validate each connection.
Stop managing .env files. Start managing secrets properly.
Clone the repo. Run the workflow. Every API key encrypted in Apple Keychain in minutes.
How it works.
macOS · Apple Keychain · Node ≥ 18 · Any AI assistant · MIT License