MoltenRock for developers

Keys out of your config files. Tokens out of your agent’s reach.

MoltenRock seals your API keys behind your Mac’s Secure Enclave and releases them only to the agents you approve, starting with OpenClaw and Hermes. MoltenRock Connect gives Claude Code, Claude Desktop, Cursor and Codex your GitHub, Sentry, Vercel, Cloudflare and more over MCP, without ever handing over a token.

Notarized by Apple · no account · no cloud · no telemetry

Activity · a working afternoonlocal only
  • OpenClawOPENAI_API_KEYreleased
  • Claude CodeGitHub · open pull requestsread
  • CursorSentry · new issuesread
  • CodexVercel · deploymentsread
  • unknown processANTHROPIC_API_KEYblocked

Illustration, example data: what the Activity log could show on a day like this.

The problem

Every agent you try wants another copy of your keys.

  • .env files full of live keys
    Plain-text keys in project folders and agent configs, readable by any process that looks.
  • Copies everywhere
    Each new agent, CLI and tool gets its own copy of the same token, and you forget which ones you rotated.
  • No idea who used what
    When something odd happens there is no record of which agent read which key, or when.

What changes

One vault, scoped access, a record of everything.

  • Sealed by the Secure Enclave
    Paste a key once. It’s encrypted at rest with hardware-backed keys, with a recovery phrase you keep.
  • Per-agent, per-key
    OpenClaw can have your OpenAI key without ever seeing your Stripe key. Grant, block or revoke anytime.
  • Your dev tools over MCP
    MoltenRock Connect reads GitHub, GitLab, Sentry, Vercel, Cloudflare, Linear, Jira, PostHog, Datadog, Resend and more for your agent.
  • Every access in the log
    Which agent, which key or platform, when, and whether it was allowed. On your Mac.

One command

Add MoltenRock Connect to Claude Code

With Connect in Applications, one command. Claude Desktop and Cursor have their own steps in Connect → Settings → Agent Setup.

Terminal
claude mcp add --scope user moltenconnect -- '/Applications/MoltenConnect.app/Contents/MacOS/MoltenConnect' mcp

Then ask: “Check MoltenRock Connect’s status, then list my platforms.” Your agent fetches its instructions from Connect before each task, so there’s nothing to paste again when you add a platform. Full setup guide →

A day with it

From scattered keys to one vault

  1. 01
    Move your keys in
    Paste each key into MoltenRock once. It’s sealed in the Secure Enclave, out of your config files.
  2. 02
    Pair your agents
    OpenClaw and Hermes resolve keys from the vault by name. Each pairing is its own grant.
  3. 03
    Add Connect over MCP
    Claude Code, Claude Desktop and Cursor get your dev tools through Connect; the tokens stay with Connect.
  4. 04
    Watch the log
    Every release, read and refusal is recorded. Revoke one agent in one switch.

What you need

The apps for this

  • MoltenRock

    The Secure-Enclave vault for your API keys and mail credentials, with per-agent grants and the Activity log.

    See MoltenRock →
  • MoltenRock Connect

    31 platforms for your agent over MCP or a local socket; changes only through the Human Queue (Stripe today, Cloudflare next).

    Cloudflare and Connect →
  • MoltenView

    A local canvas where your agent renders dashboards and views, with a built-in helper for Claude Code.

    See MoltenView →

Questions

What people ask first

Does it work with Claude Code, Cursor and Codex?

Yes. Claude Code, Claude Desktop and Cursor add MoltenRock Connect over MCP; Codex and OpenClaw use a local socket with a short note. OpenClaw and Hermes resolve API keys from MoltenRock’s vault directly.

Where are my keys stored?

In an encrypted vault on your Mac, protected by the Secure Enclave, with a recovery phrase you keep. There is no MoltenRock account and no MoltenRock cloud.

Can I stop one agent without breaking the others?

Yes. Grants are per agent and per key: block or revoke one agent and the rest keep working. Every access is in the Activity log.

Does my agent ever see my GitHub or Cloudflare token?

Not through MoltenRock Connect: Connect holds the token and makes the call; your agent gets the data. Changes go only through the Human Queue, live for Stripe and coming next for Cloudflare.

Is it free?

MoltenRock is free for 3 API keys, 1 mailbox and 1 paired agent. MoltenRock Pro removes the limits and covers up to five Macs per licence.

Stop pasting keys. Start granting them.

Free for Mac. Notarized by Apple, or from the Mac App Store.