Keyway

B
B tier on Secrets Management ToolsScore 7.2 · #1 of 39
Android app
Not listed
Free plan
Yes
Paid plans from
€9/mo
Runs on
api, Linux, Mac, self-hosted, Web, Windows
keyway.sh
The Keyway homepage

Summary

Keyway is an open-source secrets manager for injecting environment variables into a running process rather than keeping them in a project .env file. Its `keyway run` command makes secrets available to the process only while it is running. Keyway says this approach keeps those injected secrets out of reach of AI agents that read files from disk. Access follows GitHub repository permissions, so removing a person's repository access also removes their Keyway access. Secrets use AES-256-GCM encryption with a unique random IV for each secret; an isolated crypto service holds the encryption key, and connections among the CLI, API, crypto service, and database use TLS 1.3. An audit trail records access details. Provider workflows are documented for Vercel, Netlify, and Railway. The CLI supports macOS, Linux, and Windows, while the full stack can be self-hosted with Docker Compose. Plans include a free tier and paid plans, with Pro listed at 9.00 EUR per month.

Who it is for

Keyway suits developers or teams who want secrets injected into processes instead of stored in project files, with access tied to GitHub repositories. It offers CLI binaries for macOS, Linux, and Windows, plus a self-hosting option.

What is good

  • Secrets disappear when the process stops.
  • Access follows GitHub repository permissions.
  • Records who accessed secrets, when, and where.
  • Supports Vercel, Netlify, and Railway workflows.
  • Full stack can be self-hosted with Docker Compose.

What to know first

  • Does not protect against compromised developer machines.
  • Application code and dependencies can read process environments.
  • Dynamic secrets, PKI, and database credential rotation are out of scope.
  • Secret rotation is not available.

Everything Xiaomi review

Keyway: the full review

Keyway focuses on process-scoped secret injection, with repository-based access, encryption, and audit logging. Its stated threat model excludes compromised machines and code that can read the process environment; dynamic secrets and credential rotation are also outside its scope.

Overview

Keyway is an open-source secrets manager for teams that want credentials injected into running processes instead of stored in project files. It suits developers whose access control already centers on GitHub repositories. Its focused approach can reduce file-based exposure, but it is not a defense against compromised machines or code that can read process environments.

Key features

The keyway run command injects secrets into a process and removes them when that process stops. This keeps them out of project .env files, and Keyway says AI agents that read files from disk cannot see secrets injected this way. It does not prevent application code or dependencies in the process from reading them, so this is a narrower safeguard than protection from runtime access.

Secret access follows GitHub repository permissions: removing someone's repository access also revokes their Keyway access. That is a practical fit for teams that manage membership through GitHub, but it couples secret access to repository access.

Keyway encrypts secrets with AES-256-GCM, using a unique random IV for each secret. The encryption key is held by an isolated crypto service rather than the API server or database, and Keyway states that connections among its CLI, API, crypto service, and database use TLS 1.3. Its audit trail records who accessed which secrets, when, and from where, giving teams a record to review.

Provider workflows sync secrets with Vercel, Netlify, and Railway. Keyway also supports CI/CD injection and Kubernetes integration, extending its use beyond local development. Teams needing dynamic secrets, PKI, or database credential rotation should look elsewhere: those capabilities are outside its stated scope, and secret rotation is not supported.

The full stack can be self-hosted with Docker Compose, a useful option for teams that want to operate the service themselves. The CLI installation guide covers macOS, Linux, and Windows; the service also lists API and web platforms.

Pricing

Keyway has a free plan and a 14-day trial. The Free plan is billed at 0€/month and includes unlimited public repositories, one private repository, three environments per repository, two provider integrations, and unlimited collaborators. It suits evaluation or small projects, but the single private repository and environment cap constrain broader private use.

Pro costs 9.00 EUR per month, billed 9€/month, for 10 private repositories, unlimited environments, and unlimited collaborators. It removes the Free plan's private-repository and environment ceilings, but does not include the audit logs or member management listed for Team.

Team costs 19.00 EUR per month, billed 19€/month, and includes 20 private repositories, unlimited environments, audit logs, and member management. It fits teams that need access oversight and administration. Business costs 39.00 EUR per month, billed 39€/month, for 50 private repositories, unlimited collaborators, exposure reports, and priority support; it is the tier for teams that need those reporting and support provisions. The legal notice describes Keyway as a personal project in the process of legal structuring.

Platforms

Keyway spans API, Linux, macOS, self-hosted, web, and Windows. The CLI binaries cover the three desktop operating systems, while Docker Compose self-hosting gives teams a way to run the full stack themselves.

Who it's for

Keyway is a strong candidate for development teams that want process-scoped secret injection, repository-based access, and audit logs, especially when they deploy through Vercel, Netlify, or Railway. It is a less suitable choice for teams that require rotating credentials, dynamic secrets, PKI, or protection from hostile code on a developer machine.

Pros and cons

  • Pro: Secrets are injected for a process lifetime rather than kept in project files, reducing file-based exposure.
  • Pro: GitHub repository permissions govern access, and removing repository access revokes Keyway access.
  • Pro: AES-256-GCM encryption, an isolated crypto service, TLS 1.3 connections, and access logs provide several distinct security and review controls.
  • Pro: Self-hosting, CI/CD injection, Kubernetes integration, and three documented deployment-provider workflows serve varied development setups.
  • Con: Secrets remain readable to code in the process environment, and a compromised developer machine is outside the threat model.
  • Con: No dynamic secrets, PKI, or credential rotation makes it a poor fit for teams that need those lifecycle controls.
  • Con: The Free plan limits private use to one repository and three environments per repository.

Alternatives

For a broader comparison, browse Secrets Management Tools.

  • Infisical is worth considering if its free tier's five identities, unlimited projects, and 100+ integrations suit your needs.
  • Kubermatic Kubernetes Platform offers an open-source Community Edition under Apache License 2.0.
  • Phase is another option for teams comparing freemium secrets-management tools.
  • SikkerKey is another freemium option for teams evaluating secrets-management tools.
  • KeyEnv is another freemium option for teams seeking secrets management with self-hosting.
  • AWS Secrets Manager is a paid option with an AWS Free Tier that includes up to $200 in credits, available for six months after account creation; the credits expire within 12 months of account creation.
  • Oracle Cloud Infrastructure Secret Management is a free option with 5,000 secrets per tenancy and up to 30 active versions per secret.
  • Akeyless is a freemium alternative whose free plan includes dynamic and rotated secrets.

Verdict

Choose Keyway if your team wants secrets injected only for a process's lifetime and can use GitHub repository permissions as its access boundary. Its audit trail, self-hosting option, and focused deployment integrations strengthen that case. Look elsewhere if you need dynamic secrets or credential rotation, or if secrets must be protected from code running inside the process.

Keyway plans and pricing

All plans
Pro €9/mo 9€/month 10 private repos · Unlimited environments · Unlimited collaborators keyway.sh · 3 Oct 2026
Team €19/mo 19€/month 20 private repos · Unlimited environments · Audit logs · Member management keyway.sh · 3 Oct 2026
Business €39/mo 39€/month 50 private repos · Unlimited collaborators · Exposure reports · Priority support keyway.sh · 3 Oct 2026
Free Not published 0€/month Unlimited public repos · 1 private repo · 3 environments per repo · 2 provider integrations · Unlimited collaborators keyway.sh · 3 Oct 2026

Compared on secrets management tools

Free plan
Yeskeyway.sh
Secret rotation
Nokeyway.sh
Dynamic secrets
Nokeyway.sh
CI/CD injection
Yeskeyway.sh
Kubernetes integration
Yeskeyway.sh
Deployment model
bothkeyway.sh
Audit logs
Yeskeyway.sh

Facts

Purpose
Keyway is an open-source secrets manager that injects environment variables into process memory so they are not stored in a project .env file.keyway.sh · 3 Oct 2026
CLI
The keyway run command injects secrets into a process, and the secrets disappear when that process stops.keyway.sh · 3 Oct 2026
AI assistant access
Keyway says secrets injected by keyway run are not visible to AI agents reading files from disk.keyway.sh · 3 Oct 2026
GitHub access
Keyway uses GitHub repository permissions for secret access, and removing a person's repository access revokes their Keyway access.keyway.sh · 3 Oct 2026
Encryption
Secrets are encrypted with AES-256-GCM, using a unique random IV for each secret.keyway.sh · 3 Oct 2026
Key isolation
The encryption key is held by an isolated crypto service and does not touch the API server or database.keyway.sh · 3 Oct 2026
Transport security
Keyway states that connections between its CLI, API, crypto service, and database use TLS 1.3.keyway.sh · 3 Oct 2026
Audit trail
Keyway logs who accessed which secrets, when, and from where.keyway.sh · 3 Oct 2026
Integrations
The documented available provider integrations are Vercel, Netlify, and Railway, with workflows to sync secrets.docs.keyway.sh · 3 Oct 2026
Installation platforms
The CLI installation guide lists macOS, Linux, and Windows binaries.docs.keyway.sh · 3 Oct 2026
Self-hosting
Keyway says its full stack can be self-hosted with Docker Compose.keyway.sh · 3 Oct 2026
Threat model
Keyway says it does not protect secrets from a compromised developer machine or from application code and dependencies that can read the process environment.keyway.sh · 3 Oct 2026
Out of scope
The stated threat model excludes dynamic secrets, PKI, and database credential rotation.keyway.sh · 3 Oct 2026
Support
The Business plan includes priority support, and Keyway lists [email protected] as its contact email.keyway.sh · 3 Oct 2026
Company status
Keyway's legal notice describes it as a personal project in the process of legal structuring.keyway.sh · 3 Oct 2026

Best Keyway alternatives

See all 12

Where it ranks on Everything Xiaomi

Is Keyway yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources