The best secrets managers for Mac developers in 2026
By Maria Otworowska,
We build fidelius, so read this with that in mind. We've tried to be fair: every fact below comes from the product's own website, App Store listing or GitHub repository, checked on October 4, 2026, and we say where another tool is the better choice. Prices change, so check before you buy.
At a glance
| Tool | Stores keys in | Syncs between Macs | Runs a command with keys | AI agent features | Price |
|---|---|---|---|---|---|
| fidelius | iCloud Keychain | Yes | accio | Agent setup, masking | Free shared project, Pro $24 once |
| 1Password CLI | 1Password cloud | Yes | op run | MCP server, plugins (beta) | $3.99/mo billed annually ($2.99 first year for new customers) |
| NoxKey | Local Keychain | No | Through MCP | MCP, agent detection | Free |
| Keycard | Own vault | Planned | keycard run | None | Free core; Pro offered at $9 early bird, $15 regular, once |
| SecretKit | Own vault | Optional iCloud | Companion CLI | None | Free |
| KeyStack | Local Keychain | No | Writes a temporary .env | None | $9.99 once |
| PassStore | Own vault | Via a synced folder | No | None | Free, MIT |
| Axo Pass | Own vault, Secure Enclave key | No | ap exec (in source) | None | Free, MIT |
| enveigh | Local Keychain | No | enveigh run | MCP, redaction, audit log | Free beta |
| Claude Keychain | Local Keychain | Not documented | Through MCP | Claude Code only | Free |
| envchain | Login keychain | No | envchain | None | Free, MIT |
| psst | Local database | Only via AWS | psst run | Redaction by default | Free, MIT |
If you already pay for 1Password: 1Password CLI
op run runs a command with secrets from your vault, loaded "only for the duration of the subprocess", and conceals them in output by default. You keep references like op://vault/item/field in your environment or an env file. 1Password Environments adds project variables, a .env that's mounted through a named pipe instead of written to disk (Mac and Linux), and an MCP server that never returns secret values. The Claude Code and Cursor plugins are in beta.
Choose it if you already use 1Password, need Windows or Linux too, or share secrets with a team. Skip it if you don't want a subscription: there's no free tier. Individual is $3.99 a month billed annually ($2.99 for the first year for new customers) or $4.99 billed monthly.
Free and built for agents: NoxKey
NoxKey is a free menu bar app on the Mac App Store that keeps keys in your local Keychain. Agents get keys through its MCP server, which hands back an encrypted script instead of the raw value. It detects Claude, Cursor and Codex by their process and blocks the commands that would print a raw value. No sync and no outbound connections, by design.
Choose it if you work on one Mac and want a free app with an MCP server, agent detection and blocks on commands that print raw values. Note: the site says it's AGPL-3.0 open source, but the linked GitHub repository returned a 404 when we checked.
Grouped by project, synced, set up for your agents: fidelius
fidelius keeps keys by project in your iCloud Keychain, so they reach every Mac signed in to your Apple ID with Apple's end-to-end encryption. accio myapp npm test runs a command with that project's keys, and a shared project holds keys every project uses. One menu item writes setup instructions into Claude Code, Codex and Gemini CLI, and when Claude Code or Codex runs accio, key values in the output come back concealed. Key files like .p8 arrive as a temporary file that's deleted afterwards. There's also Recently Deleted and encrypted backups.
Choose it if you use more than one Mac or more than one agent and want a native app. Skip it if you need sharing with a team, Windows or Linux, or an MCP server. Masking is best effort and doesn't stop an agent that sets out to read a value. Free for the shared project, and Pro is $24 once for every project. macOS 15 or later.
Simple run command, free core: Keycard
Keycard keeps keys in its own encrypted vault and runs a command with a profile: keycard run --profile dev -- npm start. The site says the core is free and MIT licensed, though we couldn't find its public repository. Pro is offered at $9 early bird ($15 regular), one-time with a year of updates, and lists multi-device sync, which its FAQ says is coming soon. We couldn't confirm whether Pro has launched. No agent-specific features.
Free vault with optional iCloud sync: SecretKit
SecretKit is a free App Store app with an encrypted local vault, optional end-to-end encrypted iCloud sync, and a companion CLI for injecting secrets into commands. Donations are optional. It requires macOS 15. No agent features are mentioned.
If your tools need a .env file: KeyStack
KeyStack ($9.99 on the App Store) keeps keys in the Keychain and writes a temporary .env when you activate a project, then deletes it on a timer, when the Mac sleeps or when it locks. That suits tools that only read a file. While the file exists, anything in the project can read it, agents included. One Mac only.
Open source vaults: PassStore and Axo Pass
PassStore is a free, MIT-licensed app for API keys,.env groups and server logins, with import and write-back of .env files. To use it on another Mac, put its vault file in a folder you already sync. It needs macOS 26. There's no run command.
Axo Pass is a free, MIT-licensed Touch ID manager for SSH keys, GPG keys and API tokens, with the vault key held in the Secure Enclave. Its source includes an ap exec -- <cmd> command for axo:// references, though we couldn't confirm it's in the current release. iCloud sync is on its roadmap.
Worth watching: enveigh and Claude Keychain
enveigh is a native vault for agents with enveigh run, an MCP server, output redaction and a local audit log. It's a free private beta and needs macOS 26. Claude Keychain is a free menu bar app whose MCP server runs commands with your keys for Claude Code, and only Claude Code.
Command-line only: envchain and psst
envchain sets variables from named Keychain sets for one command: envchain aws terraform plan. It's free and MIT licensed, but it has had one release since 2016 (v1.1.0, April 2024), and its items sit in the local login keychain, so they don't sync. psst is a free, MIT-licensed CLI built for agents that redacts values in output by default and also runs on Linux and Windows.
Related: fidelius vs 1Password CLI and envchain alternatives for the macOS Keychain.