MoltenRock keeps your API keys encrypted on your Mac and out of plaintext configs, served only to the local AI agents you approve, with per-agent, per-key permissions and access logged. Keys are released securely to signature-verified apps only: OpenClaw works out of the box (secrets resolver + read-only email bridge). No account, no cloud, no telemetry - the vault runs fully offline. Requires a Mac with Secure Enclave (Apple Silicon or T2). Free tier
Framer AI AgentsDesign and publish professional sites with AI
Promoted
Maker
š
Hey Product Hunt š
We built MoltenRock because of a bad habit we kept seeing: developers pasting API keys into .env files and plaintext configs to wire up their AI agents. The moment you do that, every plugin and script running inside your agent can read them.
MoltenRock is a secure vault for your AI agent's API keys:
š Keys are encrypted on your Mac - hardware-backed by the Secure Enclave, never stored in plaintext on disk
š¤ Agents get scoped access - you approve which app gets which key, and can revoke anytime
š Every access is logged - you always know which agent used which key, and when
āļø OpenClaw works out of the box: a secrets resolver plus a read-only email bridge (agents can read & draft email - never send or delete)
Straight talk on privacy, since you'll ask anyway:
⢠No account, no telemetry
⢠The vault, key serving, and agent bridges run entirely offline
⢠The only network connection MoltenRock ever makes is the optional in-app upgrade/license check
⢠When an approved app needs a key, it's decrypted in memory for that session only - plaintext never touches disk, config files, or env vars
Part of a suite with MoltenMail (agent-safe email, on the Mac App Store) and MoltenView (agent canvas).
Requires a Mac with Secure Enclave (Apple Silicon or T2). Free to use; Pro from $9.99/mo for unlimited keys & mailboxes.
Swiss-built šØš Ask me anything - happy to go deep on the security model.