About this project

JitPass is a macOS (Apple Silicon, macOS 14+) application that scans your Mac for plaintext API keys, tokens, cloud credentials, private keys, and database URLs, then moves them into a local vault protected by Touch ID and the Secure Enclave. It leaves decoy values in the original files so tools such as aws, gh, docker, terraform, kubectl, and shell scripts continue to work, while real secrets are only released after per-program approval. The app includes a read-only scan that recognizes 100+ token formats, one-click migration with encrypted backups, per-process consent prompts that name the requesting program and its parent, time-limited grants for unattended work, and a full audit trail of uses, unlocks, refusals, and decoy reads. It can also wrap CLIs, keep typed secrets out of zsh history, and redact secrets from AI agent transcripts and MCP configs. AI-specific features include AI Jobs, which run an approved command and return only its output with secret values hidden, and integration with Claude Desktop, Cursor, Claude Code, Codex, Gemini, Copilot, Cline, OpenCode, and Kiro through a local MCP server. The project is source-available, free for personal and internal company use, with no account, no telemetry, and no cloud dependency.