Short-lived access for AI agents

Keep your secretsholstered.

Env Holster access grantIssued
AgentCodex
ScopeStaging deploy
Access ends When you lock
eh_live_7K4••••••R9

Master credential remains sealed

Stop your AI coding tools from leaking your API keys.

Env Holster moves permanent credentials out of plaintext .env files and into an encrypted vault. Your agent works through Env Holster instead of holding your key.

  • Vault instead of .env
  • Access instead of keys
  • Grants die when you lock

Two ways credentials escape

Plaintext env files were leaky before agents. Now every tool call and transcript is another place a permanent key can land.

Track 01

Plaintext .env

One read from disk or git history puts every secret in play — for humans, malware, and anything with filesystem access.

Track 02

Agent gets a permanent key

Once a long-lived credential enters the model, it can show up in prompts, chat history, tool output, and MCP configs.

Close both tracks

Your permanent secrets live in an encrypted vault. Your AI agents get temporary, scoped access — never the key itself.

For environments

Replace .env

Vault holds long-lived secrets. A plaintext config manifest describes what each environment needs — without putting raw keys on disk.

For agents

Short-lived access for agents

When an agent needs a credential, Env Holster hands it a scoped, short-lived grant instead — so the model never holds the permanent key.

The Env Holster Mac app
The Env Holster Mac app

How your keys stay safe

Keys stay holstered

Agents ask Env Holster for what they need, and work through it instead of holding your key.

Access is temporary

It dies when you lock the vault or the job ends.

Grants are scoped

Each grant covers one provider and one purpose — nothing more.

Serious tools under the hood

Local-first by design: your vault is an encrypted file on your own disk, and on the Solo plan nothing leaves your machine.

Rust core

The vault and credential engine are written in Rust — the same language trusted for security-critical infrastructure across the industry.

Native Mac app

A clean SwiftUI interface handles setup, approvals, and imports — most setups never touch a config file. Unlock with your Mac’s Secure Enclave or a YubiKey.

An experienced team

Env Holster is built by Millennial Apps, whose apps have been downloaded more than 2 million times.

Free for individuals.$15/seat for teams.

One developer keeps the vault local and free. Teams share the same vault — no secrets left in plaintext or DMs.

Solo

[Individual Developer]
Free

Just you. The vault stays on your machine.

  • Local-first encrypted vault for one developer
  • Replace plaintext .env, give agents short-lived access
  • No shared unlock, no team seats

Free for local use. No shared unlock, no team seats.

Request Solo access

Posse

[For the Team]

$15/seat/mo

billed annually · $180/seat/yr · save ~21%

One shared vault the whole team unlocks.

  • Shared vault unlock for every teammate
  • Same vault across the whole team
  • Agents & CI included — no machine seats
Request Posse access

Private beta · Waitlist open

Holster your secrets in the private beta.

Join the waitlist to move long-lived credentials out of plaintext files and give your AI coding agents scoped, short-lived access instead.

Hands-on by design. Invites go out in rounds — we’ll email yours when the next one starts, plus product notes and direct support as you put Env Holster to work.