0.3.0
Agent key access, from notes/2026-09-06-agent-key-access.md. Verified live
on 2026-09-06: grant from a Terminal and from a Codex sandbox (the prompt
comes from the menubar site), cancel gives exit 3, screen lock revokes, and
keys test lists 68 Ramp Router models.
- Grants:
keys grant,keys grants,keys revokeand a Grant action in the
dashboard. One Touch ID per task; the token is used as the API key; bound to
key, host, methods, path prefixes, expiry, optional request and USD caps.
Revoked on screen lock, gateway off, key edit or delete, and site restart. - The gateway now requires a grant token. A request without one gets
401 grant_required; out-of-scope requests get a named 403 or 429. The
old open-once-enabled behaviour is gone. - Checks:
keys test,keys models [--cached] [--grep]and a Check action
with a filter box. Read-only, provider-specific, never a generation call;
result stored per key and reused without a second unlock. - Errors: presence failures split into cancelled, failed and unavailable
(with the reason); provider 401 and 403 reported differently; provider
message and request id kept, key scrubbed from every message. - Keys list and
keys envshow the provider and the host a key is bound to. - README now says what the per-launch token is (browser cross-site defence),
not local-process authentication. - Menubar dropdown: a tab strip (Overview, then one tab per subscription)
over bars with "% left" and reset times; the tab is remembered. Rows below:
Plan Usage, Status Page submenu, Refresh (was Ingest), About. - providers.json: Ramp Router API host is
api.router.com; a check that
gets a web page back says so.
All notable changes to Keysreallysafe. Each entry is a GitHub release.