pthwyconnect

KeyHand · Built by Pathway Connection Solutions

Client credentials, without the plaintext.

KeyHand is a credential dropbox for agencies and teams that run AI tooling. Clients hand off API keys through one magic link. Your tools use them through injected calls. Nobody's secrets sit in a chat transcript.

Status: in development. The MCP bridge is open source today.

How it works

Three steps, zero exposed secrets

Send one link

Your client gets a magic-link form and types their keys once. No email chains, no vault exports, no pasting secrets into chat.

Locked at rest

Values land in an encrypted store with a per-client audit trail. Every access is recorded, and the client can revoke at any time.

Agent-blind use

The open-source MCP bridge injects secrets into outbound calls at request time. The AI never sees plaintext, so keys cannot leak into transcripts, logs, or prompts.

The problem

Prompt injection reads chat history. Keys should not be in it.

Pasting client credentials into AI coding tools puts them one bad prompt away from a transcript, a log line, or a leak. Guardrails police the symptom. KeyHand removes the exposure class: plaintext that never enters the model's context cannot come out of it.

Early access

Tell us what your team hands off today.

One email: who sends you credentials, how they arrive now, and which tools need them. We will show you what KeyHand replaces.

A Pathway Connection Solutions product Open-source bridge: keyhand-mcp pthwyconnect.com