Repository navigation
Releases: thu-lawyer/keystash
Release list
v0.3.3
keystash 0.3.3
Documentation/metadata release. No code changes.
What this unblocks
The official MCP registry verifies PyPI ownership by looking for an mcp-name: io.github.thu-lawyer/keystash token in the package description on PyPI — which comes from README.md at build time. That token is on main, but the published 0.3.2 metadata predates it, so the registry ownership check could not pass. This release republishes so the token reaches PyPI.
Changes
README.mdcarries the<!-- mcp-name: io.github.thu-lawyer/keystash -->ownership token.server.jsonbumped to 0.3.3 (top-level and thepypipackage entry) so the registry publish step targets a version that exists on PyPI.pyproject.tomlversion bumped to 0.3.3.
Install
uvx keystash mcp
# or
pip install keystash
Touch ID unlock is macOS-only; the vault is encrypted locally and secret values are never returned to the model.
v0.3.2 — MCP Touch ID prompts only when secrets are actually needed
The MCP server previously resolved the vault password at startup, so every new agent session triggered a Touch ID prompt even if the conversation never touched the vault. Password resolution is now lazy: the prompt appears on the first tool call that needs the vault (at most once per session); initialize and tools/list touch nothing.
v0.3.1 — bilingual README (English + 中文)
Documentation-only release: the README is now bilingual (English + 中文) covering Touch ID unlock, keystash doctor, and the zero-plaintext MCP server. No code changes.
v0.3.0 — keystash mcp: AI agents, zero plaintext
Run keystash as an MCP server so AI agents (Claude Desktop, ZCode, Cursor…) can orchestrate secrets without ever seeing their values.
{ "mcpServers": { "keystash": { "command": "keystash", "args": ["mcp"] } } }list_entries/status— metadata onlyrun_command— env-var injection with automatic secret scrubbing of all tool output; dumpers (printenv,env,/proc/*/environ) refused; subprocess stdout always captured (never leaks into the MCP channel)copy_secret— clipboard only, 30 s auto-clear, value never in the replygenerate_and_store— strong secret created and stored, never revealed to the AIadd_secret— documented exception for values the human already pastedupdate_entry/delete_entry— metadata edits, deletion needs confirm
Unlock first with keystash unlock so the server finds the password in the keychain. Zero new dependencies — the MCP stdio transport is hand-rolled JSON-RPC. 65 tests.
v0.2.0 — Touch ID unlock & keystash doctor
Touch ID unlock
keystash unlock stores the master password in the macOS login keychain; every read is gated by the system authentication prompt (Touch ID → Apple Watch → device passcode). keystash lock undoes it, --no-keychain / KEYSTASH_PASSWORD bypass it for scripts.
keystash doctor — hunt scattered plaintext secrets
keystash doctor scans the current project and your shell dotfiles for keys living outside the vault (OpenAI/Anthropic/GitHub/AWS/Google/Slack/Stripe/HF token shapes, PEM keys, JWTs, entropy-checked API_KEY= sweep), marks the ones already stored, and can ingest + redact:
keystash doctor --import-all --shred --yesPure-ctypes Security/LocalAuthentication bindings — no new dependencies. 50 tests, CI green on py3.9–3.13 × Linux/macOS/Windows.