# Keychain

How credentials are stored in the OS keychain and read by tools.

Credentials (provider API keys, OAuth tokens) are stored through `go-pkg/filesystem/keychain` under service `agenvoy`:

| Platform | Backend |
|---|---|
| macOS | `security` CLI |
| Linux / other | `secret-tool` (libsecret), falling back to a plain `KEY=value` file `~/.config/agenvoy/.secrets` |

When no stored value is found, an environment variable of the same name is used. The service name `"agenvoy"` is fixed and must not change.

The `GET /v1/key?key=<name>` lookup endpoint (loopback-only), which script tools used to fetch a stored value over HTTP, was removed in v1.0.23. A script tool now reads the keychain in-process, in the same order: `security find-generic-password -s agenvoy -a <KEY> -w` on macOS, `secret-tool lookup service agenvoy account <KEY>` then `~/.config/agenvoy/.secrets` on Linux, then the environment variable. `DELETE /v1/key`, `GET /v1/keys` and `POST /v1/keys` remain, behind `localhostOnly()`.
