
ValetFS
Secrets your agent can't keep
0 ratings
Free
Rating summary
About
AI agents and build tools need your API keys. Handing them over usually means
writing them into a dotfile, an environment variable or a config directory —
where they sit forever, readable by anything on the machine, long after the job
is done.
ValetFS is the other way round. Your secrets live on your iPhone, in the
Keychain, behind Face ID. When a tool on your computer needs one, ValetFS lends
it — into memory, never to disk — and takes it back when you are finished.
HOW IT WORKS
• Install the ValetFS daemon on your computer and start it. It prints a QR code.
• Scan the code with the app. The two are now paired.
• Push a secret from your phone. It appears on the computer as an ordinary file
that any tool can read — but it exists only in memory.
• Close the app, and a grace timer starts. When it expires the daemon unmounts
and wipes itself. Nothing is left behind on disk.
END-TO-END ENCRYPTED
Secrets are encrypted on your phone for one specific daemon, using X25519 key
agreement and ChaCha20-Poly1305. The relay that carries them sees only
ciphertext. We cannot read your secrets, and neither can anyone operating the
infrastructure in between.
BUILT FOR AGENTS
Provision a session from the app and hand an AI agent a single connection key.
The agent installs the daemon and joins — and you keep the authority to revoke
it. One tap forgets the session, and a still-running daemon locks itself,
unmounts, and wipes its memory.
NO ACCOUNT, NO TRACKING
There is no sign-up and no login. No analytics SDK, no advertising, no
behavioural tracking. The app is a client for infrastructure you can inspect —
the daemon and the relay are both open source.
REQUIRES A COMPUTER
ValetFS is a companion to the ValetFS daemon, which runs on macOS or Linux and
is a free open-source download. The app on its own has nothing to pair with.
Daemon and source: https://github.com/WinM2M/valet-fs
Show more
What's New in ValetFS
1.1.2
September 10, 2026
Sessions between this app and your daemon are now mutually authenticated. The daemon learns which vault is talking to it and accepts only the identity you authorised, so nothing else can take its place — and the connection key you hand to an agent names that identity, which removes the window where a first connection had to be taken on trust. Pairing is gated by a secret carried in the QR code rather than by the session ID, which is printed to terminals and ends up in logs. Also: reconnecting no longer reports a handshake in progress as an error, and a vault that loses signal can get back in.
More



