Cross-platform secrets workflow for macOS, Windows, and Linux. The keys CLI routes values to explicit local sinks without returning plaintext in normal agent tool output. This reduces accidental transcript exposure; it is not an isolation boundary against arbitrary code running as the same OS user.
Securely save, retrieve, or reference API keys, SSH keys, server credentials, and domain info via the keys CLI using workflows that avoid returning plaintext in normal tool output. Use when the user mentions saving, getting, injecting, or referencing secrets, API keys, tokens, SSH keys, server addresses, or domain…
Storage CLI is keys (run which keys / Get-Command keys to find the install path; typically wherever pipx installed it). Run keys --help for the full surface.