MoltenRock for developers
Keys out of your config files. Tokens out of your agent’s reach.
MoltenRock seals your API keys behind your Mac’s Secure Enclave and releases them only to the agents you approve, starting with OpenClaw and Hermes. MoltenRock Connect gives Claude Code, Claude Desktop, Cursor and Codex your GitHub, Sentry, Vercel, Cloudflare and more over MCP, without ever handing over a token.
Notarized by Apple · no account · no cloud · no telemetry
- OpenClawOPENAI_API_KEYreleased
- Claude CodeGitHub · open pull requestsread
- CursorSentry · new issuesread
- CodexVercel · deploymentsread
- unknown processANTHROPIC_API_KEYblocked
Illustration, example data: what the Activity log could show on a day like this.
The problem
Every agent you try wants another copy of your keys.
- .env files full of live keysPlain-text keys in project folders and agent configs, readable by any process that looks.
- Copies everywhereEach new agent, CLI and tool gets its own copy of the same token, and you forget which ones you rotated.
- No idea who used whatWhen something odd happens there is no record of which agent read which key, or when.
What changes
One vault, scoped access, a record of everything.
- Sealed by the Secure EnclavePaste a key once. It’s encrypted at rest with hardware-backed keys, with a recovery phrase you keep.
- Per-agent, per-keyOpenClaw can have your OpenAI key without ever seeing your Stripe key. Grant, block or revoke anytime.
- Your dev tools over MCPMoltenRock Connect reads GitHub, GitLab, Sentry, Vercel, Cloudflare, Linear, Jira, PostHog, Datadog, Resend and more for your agent.
- Every access in the logWhich agent, which key or platform, when, and whether it was allowed. On your Mac.
One command
Add MoltenRock Connect to Claude Code
With Connect in Applications, one command. Claude Desktop and Cursor have their own steps in Connect → Settings → Agent Setup.
claude mcp add --scope user moltenconnect -- '/Applications/MoltenConnect.app/Contents/MacOS/MoltenConnect' mcpThen ask: “Check MoltenRock Connect’s status, then list my platforms.” Your agent fetches its instructions from Connect before each task, so there’s nothing to paste again when you add a platform. Full setup guide →
A day with it
From scattered keys to one vault
- 01Move your keys inPaste each key into MoltenRock once. It’s sealed in the Secure Enclave, out of your config files.
- 02Pair your agentsOpenClaw and Hermes resolve keys from the vault by name. Each pairing is its own grant.
- 03Add Connect over MCPClaude Code, Claude Desktop and Cursor get your dev tools through Connect; the tokens stay with Connect.
- 04Watch the logEvery release, read and refusal is recorded. Revoke one agent in one switch.
What you need
The apps for this
- MoltenRock
The Secure-Enclave vault for your API keys and mail credentials, with per-agent grants and the Activity log.
See MoltenRock → - MoltenRock Connect
31 platforms for your agent over MCP or a local socket; changes only through the Human Queue (Stripe today, Cloudflare next).
Cloudflare and Connect → - MoltenView
A local canvas where your agent renders dashboards and views, with a built-in helper for Claude Code.
See MoltenView →
Questions
What people ask first
Does it work with Claude Code, Cursor and Codex?
Yes. Claude Code, Claude Desktop and Cursor add MoltenRock Connect over MCP; Codex and OpenClaw use a local socket with a short note. OpenClaw and Hermes resolve API keys from MoltenRock’s vault directly.
Where are my keys stored?
In an encrypted vault on your Mac, protected by the Secure Enclave, with a recovery phrase you keep. There is no MoltenRock account and no MoltenRock cloud.
Can I stop one agent without breaking the others?
Yes. Grants are per agent and per key: block or revoke one agent and the rest keep working. Every access is in the Activity log.
Does my agent ever see my GitHub or Cloudflare token?
Not through MoltenRock Connect: Connect holds the token and makes the call; your agent gets the data. Changes go only through the Human Queue, live for Stripe and coming next for Cloudflare.
Is it free?
MoltenRock is free for 3 API keys, 1 mailbox and 1 paired agent. MoltenRock Pro removes the limits and covers up to five Macs per licence.
Stop pasting keys. Start granting them.
Free for Mac. Notarized by Apple, or from the Mac App Store.
Not quite you?
MoltenRock for other kinds of work
- Online storesShopify, WooCommerce and Stripe: agents answer order questions and propose refunds you approve.See how
- Solo founders & startupsNo IT team needed: one vault on your Mac, every agent scoped, nothing changes without you.See how
- Law, accounting & agenciesClient email and keys stay on your Macs; agents read and draft, and never send on their own.See how
- Teams & enterpriseRolling MoltenRock out across a team, and the team Human Queue on our roadmap. Talk to us.See how