Connected Apps

Connected Apps

Local connections. Your keys stay in the vault.

MoltenRock connects to apps on your Mac over a private, local link. Passwords and API keys stay in the Secure Enclave vault. Each app gets only what you allow, and you can revoke access any time.

Two connections today: MoltenRock ↔ MoltenMail and MoltenRock ↔ MoltenRock Connect

MoltenRock holds your email credentials. MoltenMail reads and drafts mail without storing your password. You connect once from MoltenMail; MoltenRock stays in control.

MoltenRock also holds the platform keys for MoltenRock Connect, which serves your AI agent business data through them, and sends the changes you approve in its Human Queue. You pair once from MoltenRock Connect.

Three things to know

MoltenRock is the vault

Credentials and API keys live in an encrypted vault on your Mac, protected by the Secure Enclave.

Connected apps never get your password

They request access from MoltenRock. You choose which apps are allowed in MoltenRock → Settings → Local Agent → Agent Access.

Everything stays local

Connections run on your Mac only. No cloud relay. No account required.

MoltenRock ↔ MoltenMail

MoltenRockMoltenMail
RoleHolds your IMAP password securelyRead-only email for you and your AI
Install orderFirstSecond
Connect from—MoltenMail → Connect MoltenRock (onboarding or Settings)
Password in MoltenMail?NeverNever (for MoltenRock-managed accounts)

Typical setup (about 2 minutes)

  1. Install and open MoltenRock. Complete setup and unlock the vault.
  2. Install and open MoltenMail.
  3. On the welcome screen, tap Connect MoltenRock instead (no password) — or use Settings later.
  4. In MoltenRock, confirm MoltenMail is allowed under Settings → Local Agent → Agent Access.
  5. Back in MoltenMail, choose an account to add.

MoltenMail can read mail and create drafts. It cannot send, delete, move, or mark messages.

Related guide: For connecting an AI assistant to MoltenMail (separate from MoltenRock pairing), see the MoltenMail guide and its agent help.

MoltenRock ↔ MoltenRock Connect

MoltenRockMoltenRock Connect
RoleHolds the platform keys in the Secure-Enclave vaultServes your AI agent business data through them, and sends the changes you approve
Install orderFirstSecond — in your Applications folder, opened from there
Connect from—MoltenRock Connect → Settings → MoltenRock → Pair
Key stored in Connect?—Never for a vault-served platform — fetched from MoltenRock per request and dropped. Platforms you keep on the Keychain still work without MoltenRock.
NeedsMoltenRock Pro (the vault lane)macOS 14.6 or later

Typical setup (about 2 minutes)

  1. Install and open MoltenRock. Complete setup and unlock the vault.
  2. Install MoltenRock Connect in your Applications folder and open it from there.
  3. In MoltenRock Connect, Settings → MoltenRock → Pair. MoltenRock shows the pairing on its MoltenConnect screen.
  4. In MoltenRock, Secrets → “+” → MoltenConnect Key, pick the platform and paste its key (read-only; for Stripe’s Human Queue, a secret or restricted key). Connect now serves that platform from the vault.
  5. Back in Connect, Settings → Agent Setup: pick the app your agent runs in and follow its steps.

Keys added for Connect are never shared with OpenClaw or Hermes. Connect makes read calls only.

Related guide: the full MoltenRock Connect guide on the support page, and its connection help below.

Want your app connected?

We are opening Connected Apps to Mac developers who need safe, local key management — API keys, email credentials, or other secrets served to trusted local agents without plain-text config files.

What you get
  • Per-app, per-secret permissions with a full activity log
  • Local-only connections (no cloud)
  • User-controlled grant, block, and revoke
Get in touch

Email support email with:

  • Your app name and bundle ID
  • What secrets or capabilities you need
  • How your users would connect (one-click vs manual)

We will reply with integration requirements and timing.

Help & troubleshooting

Connection help & troubleshooting

If MoltenMail shows Can’t reach MoltenRock, MoltenRock is busy, or MoltenRock is reconnecting, use the section below that matches what you see in the app. MoltenRock Connect has its own blocks after the MoltenMail ones.

MoltenRock isn’t installed

In MoltenMail you see: MoltenRock isn’t installed

  1. Download and install MoltenRock on this Mac from the MoltenRock download.
  2. Open MoltenRock from your Applications folder and complete first-time setup.
  3. Return to MoltenMail and tap Re-check (or Connect MoltenRock again).

Can’t reach MoltenRock

In MoltenMail you see: Can’t reach MoltenRock. Make sure MoltenRock is running and that MoltenMail is allowed under MoltenRock → Settings → Local Agent → Agent Access.

MoltenMail cannot tell whether MoltenRock is quit or whether access was blocked — both look the same. Check both:

  1. Quit and reopen both MoltenMail and MoltenRock.
  2. Make sure MoltenRock is in your Applications folder, and open it from there (not from Xcode or a download folder).
  3. In MoltenRock → Settings → Local Agent → Agent Access, confirm MoltenMail is allowed and the accounts you need are shared.
  4. In MoltenMail, tap Re-check (or Try again).

Version pairing: MoltenMail and MoltenRock should be updated together — use matching builds from the same release (both from the App Store, or both Direct download from the MoltenRock homepage and the MoltenMail page).

MoltenRock is busy or reconnecting

In MoltenMail you see: MoltenRock is busy, or MoltenRock is reconnecting…

  1. Give MoltenRock a few seconds — it may be finishing a task.
  2. If it keeps happening, quit and reopen both apps.
  3. In MoltenMail, tap Try again.

Unlock MoltenRock

In MoltenMail you see: Unlock MoltenRock to load this account.

  1. Open MoltenRock and unlock the vault (Touch ID, password, or recovery phrase).
  2. Return to MoltenMail and tap Re-check or Try again.

No accounts shared with MoltenMail

In MoltenMail you see: MoltenRock is connected, but no accounts are shared with MoltenMail yet (or similar).

  1. Open MoltenRock → Settings → Local Agent → Agent Access.
  2. Turn on access for MoltenMail.
  3. Select which email accounts MoltenMail may use.
  4. Return to MoltenMail and tap Re-check.

Access was limited or account removed

In MoltenMail you see: MoltenMail’s access was limited in MoltenRock → Settings → Local Agent — or — This account is no longer available from MoltenRock.

  1. Open MoltenRock → Settings → Local Agent → Agent Access.
  2. Confirm MoltenMail is still allowed and the account is still shared.
  3. If you turned access off on purpose, turn it back on — or remove the account from MoltenMail and add it again.

MoltenRock Connect

MoltenRock isn’t available

In MoltenRock Connect you see: MoltenRock isn’t available for MoltenRock Connect — or — vault mode needs MoltenRock Pro

  1. Open MoltenRock and unlock the vault.
  2. Check MoltenRock → Settings → Plan: serving Connect from the vault needs MoltenRock Pro.
  3. Make sure MoltenRock Connect runs from your Applications folder (next block).

Connect isn’t running from Applications

In MoltenRock Connect you see: Move MoltenRock Connect to Applications

MoltenRock verifies Connect by reading its signed app bundle, and it can only read apps in the Applications folder.

  1. Quit MoltenRock Connect.
  2. Move it into your Applications folder (not Downloads, not the disk image).
  3. Open it from there.

A platform bound to MoltenRock is refused

In MoltenRock Connect you see: MoltenRock is locked or not running

MoltenRock-only mode is on for that platform: it is served only from MoltenRock, never from a Keychain copy.

  1. Open and unlock MoltenRock — or, in Connect, switch that platform back to the Keychain.

The platform list is unavailable

In MoltenRock you see: The Add-key sheet (Secrets → + → MoltenConnect Key) says the platform list is unavailable

Connect is not running from Applications, or it is a Connect build without a platform list. The sheet says which; the fix for the first is the block above.

Refused connections are counted

In MoltenRock you see: A refused-connection count on the MoltenConnect screen

Something reached MoltenRock’s door and could not be verified, so it was refused before any request was read. If Connect runs from Applications, that was not Connect; nothing was served.

Still stuck?

Email support email and include:

  • macOS version
  • Whether you use App Store or Direct download for MoltenRock and MoltenMail
  • The exact message MoltenMail or MoltenRock Connect shows
  • What you already tried from this page