Keys Manager
A skill for managing API keys and secrets locally using the keys CLI tool.
Installation
The keys CLI must be installed first:
brew install stym06/tap/keys
Or with Go:
go install github.com/stym06/keys@latest
Commands
Store a key
keys add <name> <value>
If the key already exists, the user is prompted to overwrite, edit, or cancel.
Retrieve a key
keys get <name> # print value directly
keys get # interactive typeahead picker
Browse keys interactively
keys see
Opens a TUI with fuzzy search, checkboxes, clipboard copy, and age indicators.
space— toggle selectiontab— copy selected asKEY=VALctrl+y— copy selected asexport KEY=VALctrl+e— export selected to.envfileenter— add a new key (when no matches found)esc— quit
Masked view
keys peek
Same as see but values are hidden as ***. Press r to reveal individual keys. Useful for screen-sharing.
Edit a key
keys edit <name>
Opens a TUI editor. tab switches fields, enter saves, esc cancels.
Delete a key
keys rm <name>
Export keys
keys env # interactive selector, writes .env file
keys expose # print export statements to stdout
Import from .env
keys import <file>
Parses .env files — handles comments, quotes, and export prefixes. Reports new vs updated counts.
Profiles
Isolate keys by project or environment:
keys profile use <name> # switch profile
keys profile list # list all profiles (* = active)
All add, get, rm, see, and other commands operate within the active profile.
Delete all keys
keys nuke
Requires typing nuke to confirm. Only affects the active profile.
Version
keys version
Authentication
On macOS, keys prompts for Touch ID before any command that accesses keys. Authentication is cached per terminal session — the first command triggers Touch ID, subsequent commands in the same shell skip the prompt.
Commands that skip authentication: profile, completion, version, help.
On non-macOS systems or when biometrics are unavailable, access is allowed without prompting.
Examples
Typical workflow
keys add OPENAI_KEY sk-proj-abc123
keys add STRIPE_KEY sk_test_4eC3
keys get OPENAI_KEY
keys see # browse and copy
keys env # generate .env for a project
Multi-project setup
keys profile use projectA
keys import .env
keys profile use projectB
keys add DB_HOST prod-db.example.com
keys profile list
Quick export to shell
eval $(keys expose)
Guidelines
- Always use
keys get <name>when the user knows the exact key name - Use
keys get(no args) when the user wants to search/pick interactively - Use
keys peekinstead ofkeys seewhen the user is screen-sharing or wants masked output - Use
keys profileto separate keys across different projects or environments - Use
keys importfor bulk loading from existing.envfiles - Suggest
keys envwhen the user needs to generate a.envfile for a specific project