Skip to content

Releases: thu-lawyer/keystash

v0.3.3

Choose a tag to compare

@thu-lawyer thu-lawyer released this 07 Oct 14:45

keystash 0.3.3

Documentation/metadata release. No code changes.

What this unblocks

The official MCP registry verifies PyPI ownership by looking for an mcp-name: io.github.thu-lawyer/keystash token in the package description on PyPI — which comes from README.md at build time. That token is on main, but the published 0.3.2 metadata predates it, so the registry ownership check could not pass. This release republishes so the token reaches PyPI.

Changes

  • README.md carries the <!-- mcp-name: io.github.thu-lawyer/keystash --> ownership token.
  • server.json bumped to 0.3.3 (top-level and the pypi package entry) so the registry publish step targets a version that exists on PyPI.
  • pyproject.toml version bumped to 0.3.3.

Install

uvx keystash mcp
# or
pip install keystash

Touch ID unlock is macOS-only; the vault is encrypted locally and secret values are never returned to the model.

v0.3.2 — MCP Touch ID prompts only when secrets are actually needed

Choose a tag to compare

@thu-lawyer thu-lawyer released this 04 Oct 15:35

The MCP server previously resolved the vault password at startup, so every new agent session triggered a Touch ID prompt even if the conversation never touched the vault. Password resolution is now lazy: the prompt appears on the first tool call that needs the vault (at most once per session); initialize and tools/list touch nothing.

v0.3.1 — bilingual README (English + 中文)

Choose a tag to compare

@thu-lawyer thu-lawyer released this 04 Oct 07:25

Documentation-only release: the README is now bilingual (English + 中文) covering Touch ID unlock, keystash doctor, and the zero-plaintext MCP server. No code changes.

v0.3.0 — keystash mcp: AI agents, zero plaintext

Choose a tag to compare

@thu-lawyer thu-lawyer released this 04 Oct 06:57

Run keystash as an MCP server so AI agents (Claude Desktop, ZCode, Cursor…) can orchestrate secrets without ever seeing their values.

{ "mcpServers": { "keystash": { "command": "keystash", "args": ["mcp"] } } }
  • list_entries / status — metadata only
  • run_command — env-var injection with automatic secret scrubbing of all tool output; dumpers (printenv, env, /proc/*/environ) refused; subprocess stdout always captured (never leaks into the MCP channel)
  • copy_secret — clipboard only, 30 s auto-clear, value never in the reply
  • generate_and_store — strong secret created and stored, never revealed to the AI
  • add_secret — documented exception for values the human already pasted
  • update_entry / delete_entry — metadata edits, deletion needs confirm

Unlock first with keystash unlock so the server finds the password in the keychain. Zero new dependencies — the MCP stdio transport is hand-rolled JSON-RPC. 65 tests.

v0.2.0 — Touch ID unlock & keystash doctor

Choose a tag to compare

@thu-lawyer thu-lawyer released this 04 Oct 06:31

Touch ID unlock

keystash unlock stores the master password in the macOS login keychain; every read is gated by the system authentication prompt (Touch ID → Apple Watch → device passcode). keystash lock undoes it, --no-keychain / KEYSTASH_PASSWORD bypass it for scripts.

keystash doctor — hunt scattered plaintext secrets

keystash doctor scans the current project and your shell dotfiles for keys living outside the vault (OpenAI/Anthropic/GitHub/AWS/Google/Slack/Stripe/HF token shapes, PEM keys, JWTs, entropy-checked API_KEY= sweep), marks the ones already stored, and can ingest + redact:

keystash doctor --import-all --shred --yes

Pure-ctypes Security/LocalAuthentication bindings — no new dependencies. 50 tests, CI green on py3.9–3.13 × Linux/macOS/Windows.