Start here

What MoltenRock is

It lives in the menu bar

MoltenRock has no Dock icon. Click its flame/keyhole icon in the macOS menu bar (top-right) → Show MoltenRock. Settings open from there, or with ⌘,.

Hardware-backed vault

Your secrets are encrypted with your Mac’s Secure Enclave and only released to tools you approve — every access is audited.

Secure Enclave required

Needs Apple Silicon, or an Intel Mac with the T2 chip (2018+). On unsupported hardware it shows “Hardware Not Supported.”

First run

Getting started

  1. 1

    Welcome

    Click Get Started — or Restore Vault if you’re moving from another Mac with a backup file + recovery phrase.

  2. 2

    Security Setup

    MoltenRock checks Touch ID, the Secure Enclave and Keychain and generates your master key. Continue unlocks once all four checks are green.

  3. 3

    Recovery Phrase

    The single most important step — reveal your 12 words and write them on paper. They are never shown again.

  4. 4

    Connect AI Agent

    Optional — set up an agent now, or Skip for Now.

  5. 5

    You’re All Set

    Add your first key, or Skip for Now.

Write down your 12-word recovery phrase

MoltenRock does not store this phrase and will not show it again after setup. Write it on paper, confirm the words it asks for, and keep it separate from your backup file. To restore a vault on a new Mac you need both your exported backup file and your 12-word phrase — one without the other is not enough.

Your vault

Vault & security

Lock Vault (⌘L)

A managed lock — locks the window and Settings but keeps the key loaded, so connected apps and agents keep working. Auto-lock uses this mode (Settings → General → Auto-lock after).

Lock & Seal (⌘⇧L)

A hard lock — drops the key from memory; all email and API-key access stops until you unlock. Use it when you want nothing to be able to read your secrets.

Backup & restore

Export: Settings → Vault → Export Vault Backup… Restore: Settings → Vault → Restore from Backup… (replaces all current contents, so it confirms first).

Rotate or reset

Settings → Advanced → Rotate Recovery Phrase… makes a new phrase (secrets unaffected). Reset Vault… permanently deletes everything and confirms twice.

Secrets screen

API keys

Add a key: Secrets → “+” (⌘N) → API Key. Choose the secret type, pick your provider for model-provider keys, paste your key (a green Captured badge confirms it), add an optional display name, then Save Key.

Status dots: 🟢 Green = active and healthy · 🟠 Amber = needs attention (an inline fix button appears on the row).

A stored key is encrypted with Secure Enclave hardware and can only be used or replaced, never viewed, copied, or shown to the AI model.

🔑 API keys for the CLI

OpenClaw integration

OpenClaw is a developer command-line tool. When you “protect” a key, MoltenRock moves the plaintext out of OpenClaw’sopenclaw.jsoninto its encrypted vault and leaves a pointer. Only the one agent you pair can fetch keys back, and every access is audited. This is entirely separate from the Email/IMAP bridge below.

Step 1

Pair

OpenClaw → Add OpenClaw agent → name it → Pair. Names the one agent allowed to resolve your keys.

Step 2

Migrate keys

Migrate existing keys → tick the keys to protect → Migrate. Then run the one cleanup command it shows you.

Step 3

Reload secrets

Copy reload command (openclaw secrets reload) and run it — MoltenRock can’t see the gateway, so this step is yours.

The mental model that prevents most confusion

OpenClaw’s key lookup order is its own key database → environment → vault. A key you migrated can still look present until OpenClaw’s own database row is removed and the gateway restarted. The durable check after any cleanup isopenclaw models auth list— the key must be gone from that list. Never trust an assistant’s ✅ alone.

🪶 Secrets for Hermes

Hermes integration

MoltenRock can be the secrets source for Hermes 0.21.1 and later: Hermes asks MoltenRock for a key by name over a private pairing token, and the key never sits in Hermes’s config — the only thing MoltenRock writes there is its own block. This is entirely separate from OpenClaw pairing and from the Email bridge.

Step 1

Pair Hermes

Hermes screen → Pair Hermes. MoltenRock writes its secrets.command block, with a private pairing token, into Hermes’s config.yaml.

Step 2

Give Hermes its keys

On the Hermes screen: Add key for a new key, or Grant an existing secret. Hermes can fetch only the keys listed there; Remove takes one away.

Step 3

Restart Hermes

The Hermes desktop app runs its own backend: restart the app itself, not only hermes gateway restart. Keep MoltenRock running and unlocked before Hermes starts.

The rule that prevents most confusion

Hermes reads its keys when it starts. If MoltenRock is locked or not running at that moment, Hermes starts without your MoltenRock keys and the Hermes screen says so. Unlock MoltenRock, then restart Hermes.

✉️ Read-only mailbox bridge

Email / IMAP integration

A read-only email bridge: local AI agents can read your mail and save draft replies — never send, delete, move, or empty anything — without your email password ever leaving MoltenRock. This is entirely separate from the OpenClaw API-key integration above.

1 · Add a mailbox

Secrets → “+” → IMAP Account. Enter server (e.g. imap.gmail.com), port 993, your full address and password; leave SSL/TLS on. Save Account.

2 · The bridge starts itself

There is no on/off switch — it activates once the vault is unlocked and at least one IMAP account exists. Check Settings → Local Agent → IMAP Bridge (green dot = live).

3 · Give the agent its address

Settings → Local Agent → IMAP Bridge → Copy the socket path (or Copy Shell Export).

4 · Give the agent a token

Email → Add Connection → name it → Generate token. Copy it immediately — it’s shown only once — and paste it into the agent’s config.

Control what each agent can do

On the Email screen, expand a connection to toggle Read and Write per mailbox (newly added mailboxes start with no access), regenerate or block its token, and flag new agents. Privacy filters — Strip URLs, Strip attachments and Sanitize draft content — are on by default.

Error-code quick key

1000
Malformed request
1003
Account not found / out-of-scope
1008
Vault locked
1101
Action not permitted

Companion apps

Permissions & connected apps

The Permissions screen is a read-only overview of every grant across the Email, Apps and OpenClaw lanes. Connected Apps manages companions like MoltenMail — open its row to toggle Read/Write per mailbox, Block, or Reconnect. (MoltenRock Drive and App keys show “Coming soon.”)

Trouble pairing the two apps? See the full MoltenMail ↔ MoltenRock connection troubleshooting guide.

🔌 Connectors for agents · the Human Queue

MoltenRock Connect

MoltenRock Connect is a small Mac app that sits between your business tools and your AI agent. The agent asks Connect; Connect calls the platform with a key you gave it once; the answer comes back with customer names and addresses replaced by tokens. Agents only read — to change anything on Stripe they propose it in the Human Queue and you approve it. Every request audited, and a kill switch that refuses everything the moment you flip it. Keys stay in your Mac’s Keychain — or in MoltenRock’s Secure-Enclave vault when the two are paired — and are never shown to the agent. This lane is entirely separate from OpenClaw and Email: a key added for Connect is never shared with either.

What you need

A Mac on macOS 14.6 or later. MoltenRock Connect installed in Applications and opened from there — MoltenRock verifies Connect by its signed app bundle and can only read apps in Applications.

One agent

An MCP app — Claude Code, Claude Desktop, Cursor — or any agent that can run a command on your Mac, such as Codex or OpenClaw. An MCP app runs Connect itself once it’s added; any other agent talks to Connect over a local socket. Nothing to install on the agent side.

Keys

One read-only key per platform — except Stripe for the Human Queue: a secret key (sk_…) or restricted key (rk_…), and you decide what it allows. Each platform card in Connect says which key type it expects and where to create it. Shopify, WooCommerce, Stripe, AfterShip, ShipStation, Sentry, Vercel, Resend, Airtable, PostHog, Slack, Linear, Plausible, Notion, ChartMogul, GitLab, Datadog, Pipedrive, GitHub, Jira, Confluence, Discord, Intercom, Cloudflare, Mixpanel, Twilio, SendGrid, Mailchimp, Asana, Zendesk and ClickUp ship today — 31 platforms.

Step 1

Add a platform

Connect → Add Platform → pick it, paste its key (read-only; for Stripe’s Human Queue, a secret or restricted key), Test, Save. New platforms start disabled; switch each on in Settings → Platforms. Using MoltenRock? Add the key there instead: Secrets → “+” → MoltenConnect Key → pick the platform. Connect then fetches it through MoltenRock per request and never stores it.

Step 2

Connect your agent

In Connect → Settings → Agent Setup, pick the app your agent runs in (Claude Code; Claude Desktop, Cursor; or another agent) and follow its steps; a Step by step walkthrough spells out every click. However it connects, the agent fetches its instructions from Connect before each task — your platforms and their actions, generated from your Mac — so there’s nothing to copy again when you add a platform or change agent access. Nothing the agent receives contains a key or a token.

Claude Code, in Terminal (Connect in Applications):

claude mcp add --scope user moltenconnect -- '/Applications/MoltenConnect.app/Contents/MacOS/MoltenConnect' mcp
Step 3

Ask your first question

With Connect open, say: “Check MoltenRock Connect’s status, then list my platforms.” Then something real using any platform and action from the agent’s instructions — “Show me my latest Stripe charges”, say, if Stripe is listed. The agent appears in Settings → Agents; every call lands in Settings → Audit log.

The Human Queue (Stripe) Live

Your agent can propose changes on Stripe: refunds, dispute evidence, fraud reviews, customers, subscriptions, invoices, credit notes, payment links, payment captures, coupons and promotion codes. Nothing changes until you approve. The agent never holds a write key — Connect sends what you approve, itself. Every other platform stays read-only.

  1. Add Stripe with a secret key (sk_…) or restricted key (rk_…). You decide what the key allows; anything it can’t do is simply unavailable. Test Connection reads your charges, so the key needs at least Read on Charges and Refunds. Every Stripe card shows live or test mode.
  2. Connect your agent (step 2 above) and ask it for something real — “refund the duplicate charge from this morning”, say.
  3. The agent files a proposal: a one-line summary, why, and what it read — and the message that prompted it, quoted, if there was one.
  4. It appears as a card in Connect’s Human Queue. Customer names stay tokens until you approve. If the key lacks a permission, the card names it in Stripe’s words.
  5. Approve with Touch ID, or deny with a note — the agent can amend and propose again. Unanswered proposals expire after 72 hours.
  6. On approval, Connect sends the change to Stripe and records it; the agent sees the result. Approving needs MoltenRock Pro.

Who gets served

By default any agent that connects is served straight away and listed in Settings → Agents by the name it declares — switch one off to stop serving it. Turn on “Only allow agents I’ve listed” and the reverse applies: a new agent is refused until you switch it on. Names are self-declared, so treat the list as a courtesy control, not a security wall; verified per-agent identity is on the roadmap.

What an agent is told (example — yours will list your own platforms)

MoltenRock Connect is running on this Mac and exposes my business tools READ-ONLY over a local Unix socket. Talk to it directly — no MCP server is needed. Socket: /Users/you/.moltenconnect/connect.sock … Identify yourself with "agentToken" on every request except "status" … My platforms and the read actions each accepts: – stripe:main (stripe): get_customer, get_charges, get_refunds, get_invoices – woocommerce:shop (woocommerce): get_orders, get_stock, get_tracking … Everything is read-only; customer names and addresses arrive as tokens — that is expected.

Need the raw socket path? Settings → General shows it with a Copy button, and the app menu has Copy Socket Path (⌘⇧C).

With MoltenRock

Pair from Connect → Settings → MoltenRock; MoltenRock shows the pairing on its MoltenConnect screen. Keys added for Connect on MoltenRock’s Secrets screen are served to Connect per request and never stored in Connect. MoltenRock-only mode refuses a bound platform while MoltenRock is locked — the strictest posture; leave it off if you want the Keychain fallback. Requires MoltenRock Pro.

How it stays private

  • Local only — the agent talks to Connect on your Mac; Connect talks to the platform. No MoltenRock server in the path.
  • Keys stay put — Keychain or MoltenRock’s vault. The agent never receives a key; its instructions contain none.
  • PII is tokenised — names and addresses reach the agent as tokens; a real value only for drafting a specific reply, each disclosure audited.
  • Every request is audited — Settings → Audit log, one row per call: ok, denied, rate_limited, credential_error.
  • Kill switch — closes the socket; every request is refused until you turn it back on.
  • Who is asking — every agent that has connected is listed by the name it declared; switch any off. A courtesy control, not a security wall.

Troubleshooting

You seeCauseDo this
The agent says it can’t connect / connection refusedConnect is quit, or the kill switch is onOpen Connect; Settings → turn the kill switch off
“MoltenRock Connect is not running. Open it and try again.”Connect is quit, or its kill switch is onOpen Connect; or Settings → General → Enable Connections
An MCP app shows no MoltenRock Connect toolsConnect hasn’t been added to that app, or Connect was moved after it was added (the command names this copy of the app)Settings → Agent Setup → pick your app and add it again
permission_denied naming your agent“Only allow agents I’ve listed” is on and this agent isn’t switched on yetSettings → Agents → switch it on, then ask the agent to try again
permission_denied — “Action … is not permitted”the agent used a verb that platform doesn’t allowit should use an action from the platform’s list in its instructions
denied in the audit logplatform disabled, or the agent switched offSettings → Platforms (enable) or Agents (allow)
credential_errorthe key expired, was revoked, lacks read scope — or that platform has no key saved yetopen the platform card, paste a fresh key (read-only; for Stripe’s Human Queue a secret or restricted key), Test
not_found — “Unknown platform”the agent used an id that isn’t one of your platformsask the agent to fetch its instructions again; ids are exact
rate_limitedtoo many calls in a short time — the platform’s limit, not Connect’swait and retry
The agent shows as “unidentified” in Settings → Agentsit isn’t sending its name (agentToken) on requestspaste the “Tell your agent” note again; it tells the agent how to identify itself (an MCP app is named automatically)
A Human Queue card says the key is missing a permissionthe Stripe key you gave Connect doesn’t allow that actionthe card names the permission in Stripe’s words; add it to a restricted key in Stripe, or deny the proposal
“MoltenRock is locked or not running”MoltenRock-only mode is on and MoltenRock is locked or quitunlock or open MoltenRock, or switch that platform back to the Keychain
“MoltenRock isn’t available for MoltenRock Connect” / “vault mode needs MoltenRock Pro”not on MoltenRock Pro, or MoltenRock cannot verify ConnectSettings → Plan in MoltenRock; run Connect from Applications
“Move MoltenRock Connect to Applications”Connect was opened from Downloads, the disk image or a build folderQuit Connect, move it to Applications, reopen it
MoltenRock’s Add-key sheet says the platform list is unavailableConnect not in Applications, or a Connect build without a platform listsame fix — MoltenRock’s sheet names the cause
MoltenRock’s MoltenConnect screen counts refused connectionsa process reached MoltenRock’s door and could not be verifiedif Connect runs from Applications, that was not Connect; nothing was served
The agent sees tokens instead of a customer’s namePII tokenisation working as designedask the agent to draft the reply; it may request the real value for that draft, audited

Unlock unlimited connectors (MoltenRock Connect Pro). The free plan covers a couple of connectors. Choose Unlock Unlimited in the app — it opens Stripe checkout in your browser; after paying, your licence key (mc_pro_…) is emailed to you. Back in the app, choose Unlock Unlimited, paste the key, and click Activate. One payment, no subscription; usable on up to five devices.

Paid but no key within ~10 minutes? Check spam, or email moltenrock@moltenmail.com with your Stripe receipt.

Peace of mind

Privacy & safety

  • Your keys are never shown to anyone — not on screen, not to the clipboard, not to the AI model.
  • Your email password never leaves MoltenRock — agents receive filtered results, never the credential.
  • Email is read-only + draft-append — never send, delete, move, copy, or empty; agents poll, there is no live push.
  • Everything is audited — every secret access is logged on the Activity screen.
  • Hardware-backed — secrets are encrypted with your Mac’s Secure Enclave; code-signature and socket-security checks are always on.

Still stuck?

Export diagnostics from Settings → Advanced → Diagnostics → Export Diagnostics… (enable debug logging first to capture more), then get in touch.