# Keys

> Secure API key management with broker. Keys never exposed to agent context.

- Skill: `dvcrn/keys` (Agent Skill, multi-file: 4 files)
- Install (CLI): `npx skillmds@latest add dvcrn/keys`
- Raw SKILL.md: https://api.skillmd.com/api/skills/dvcrn/keys/raw
- Safety review: pending (external: skill-scanner PASS, skillspector CAUTION)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: AI & ML
- Author: dvcrn (https://skillmd.com/u/dvcrn)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/dvcrn/keys

---


## Usage

Make authenticated API calls without seeing the key:

```bash
keys-broker call '{"action":"call","service":"openai","url":"https://api.openai.com/v1/chat/completions","method":"POST","body":{"model":"gpt-4","messages":[{"role":"user","content":"Hello"}]}}'
```

Response:
```json
{"ok": true, "status": 200, "body": {...}}
```

## Supported Services

Only preconfigured services work (security: prevents key exfiltration):
- `openai` → api.openai.com
- `anthropic` → api.anthropic.com  
- `stripe` → api.stripe.com
- `github` → api.github.com

To add services, edit `ALLOWED_URLS` in `keys-broker.sh`.

## Rules

1. **Never retrieve keys directly** — always use `keys-broker call`
2. **Never ask user to paste keys in chat** — guide them to keychain commands

## Other Tasks

- First time setup → see `setup.md` (install `keys-broker.sh`)
- Add/remove/rotate keys → see `manage.md`

## Limitations

Does NOT work in: Docker containers, WSL, headless Linux servers (no keychain access).

