Documentation v1.1.1

Keychain

·

How credentials are stored in the OS keychain and read by tools.

Credentials (provider API keys, OAuth tokens) are stored through go-pkg/filesystem/keychain under service agenvoy:

Platform Backend
macOS security CLI
Linux / other secret-tool (libsecret), falling back to a plain KEY=value file ~/.config/agenvoy/.secrets

When no stored value is found, an environment variable of the same name is used. The service name "agenvoy" is fixed and must not change.

The GET /v1/key?key=<name> lookup endpoint (loopback-only), which script tools used to fetch a stored value over HTTP, was removed in v1.0.23. A script tool now reads the keychain in-process, in the same order: security find-generic-password -s agenvoy -a <KEY> -w on macOS, secret-tool lookup service agenvoy account <KEY> then ~/.config/agenvoy/.secrets on Linux, then the environment variable. DELETE /v1/key, GET /v1/keys and POST /v1/keys remain, behind localhostOnly().

中文