← All articles

How to give Claude Code and MCP servers secrets without handing them the keys

Agent Keychain lets an agent use a credential without seeing it. Here is how it works, how to set it up in Claude Code, and what it does not protect against.

Lit Protocol

The safest way to give an agent access to a secret is to never give it the secret. Agent Keychain is an open-source app built on Lit Protocol that does this. You store a credential, encrypted in your browser. You approve an agent to use it. When the agent needs it, one of two things happens. Either the credential is decrypted on the agent's machine and handed to a process, or Lit uses the credential inside a secure enclave and hands the agent only the result. In the second case the agent never sees the key at all.

Here is the problem this solves. Agents log everything. Their transcripts get saved, summarized, and sometimes shared. If a Stripe key or a database password ends up in the agent's context, it can end up in all of those places too. A normal secrets manager keeps the key out of your repo, which is good, but when the agent runs a command that needs the key, the key is still in that process. For a live payment key, you want the agent to be able to check a balance without ever holding the key.

The two modes

The first mode is called stored secrets. The credential is encrypted in your browser before Keychain stores it. An approved agent fetches the encrypted value, decrypts it on its own machine, and passes it to a child process as an environment variable or a temporary file. Use this when a tool truly needs the raw value.

The second mode is called connected services. The agent calls an action, such as stripe_balance or github_read_file. Each action comes from a public catalog and is pinned to an exact version. Its manifest says which hosts it may contact and what shape of result it may return. Lit runs the action inside the enclave with your credential and returns the result. The agent gets the balance. It does not get the key. There is no way for the agent to export the credential or make the action do something else.

Setting it up in Claude Code

First, the agent creates its own identity on its machine. Only the public key ever leaves that machine.

npx @lit-protocol/keychain@2.2.0 init agent-identity.json

Next, sign in at keychain.litprotocol.com. You can use Google, a passkey, or a wallet. Add your secrets. Then approve the agent's public key for the secrets and actions you want it to use, and set an expiry. Thirty days is the default.

Then add Keychain to Claude Code as an MCP server.

claude mcp add lit-keychain -- npx -y @lit-protocol/keychain@2.2.0 mcp /absolute/path/agent-identity.json

That is the whole setup. The agent now has tools called list_secrets, get_secret, and list_actions, plus one tool for each connected service you approved. The same identity file works in Cursor or any other MCP client. It works across sessions and across your devices, and you do not have to host anything. If you change an approval, it takes effect on the agent's next request.

If you want to use a secret in a script instead of an agent, the CLI can pass it to a command without printing it.

npx @lit-protocol/keychain@2.2.0 run --secret STRIPE_KEY -- ./deploy.sh

What Keychain's operator can and cannot do

Keychain's storage service holds encrypted values and permission records that you signed. It cannot decrypt a secret, because it does not have your key. It cannot approve an agent or extend an approval, because you sign those. It cannot change what a connected-service action returns, because the enclave signs the response. Before every request, the client checks the hardware attestation and the on-chain list of approved runtime versions.

There are things the operator can do. It can refuse service. It can keep serving an older approval until that approval expires. And when you revoke an agent, that takes effect on the next request. Anything the agent already received stays with the agent.

What it does not protect against

If a stored secret is delivered to a child process, it is plaintext on that machine, and the child process can log it. Connected services send your credential to the upstream provider over TLS, so you are trusting the provider with it, same as always. Contract wallets cannot be owner credentials yet.

Get started

Keychain is free for five secrets and $10 a month for up to a thousand. The setup guide is written so you can paste it to your agent. The security model has the full details.

This is part 2 of a five-part series on building with Lit. Part 3 comes out on Friday, October 2, and is about signing from your backend without exposing the private key.