On-device & encrypted
AES-GCM at rest, key in the data-protection Keychain, this-device-only. Never synced, never backed up to anyone's cloud.
Local secrets vault · macOS
Rook keeps API keys, tokens, TOTP codes and .env bundles encrypted on-device with AES-GCM, unlocked with Touch ID. No account. No cloud. No sync. A vault built for developers — and for the AI agents working alongside them.
§ Capabilities
Everything you'd expect from a modern secrets manager — without an account to sign into or a server to trust.
AES-GCM at rest, key in the data-protection Keychain, this-device-only. Never synced, never backed up to anyone's cloud.
Paste an otpauth:// URI and Rook shows a ticking 2FA code with a countdown — your authenticator, in the vault.
Lives in the menu bar. Star your favorites and copy any field straight from the tray — copies auto-clear after 30 seconds.
Generate passwords, hex tokens and base64url secrets with a system CSPRNG — right where you're editing a field.
Locks on idle, sleep and screen-lock. Deletes go to a recoverable Trash — restore until you empty it for good.
Export the whole vault as a passphrase-encrypted file and carry it to another Mac. Standard crypto, no lock-in.
§ The deal
The most private secrets manager is the one that has nothing to leak. Rook collects nothing because Rook sends nothing.
§ Editions
The same on-device vault. Choose the App Store build, or the direct build that an AI agent can drive from your shell.
$4.99 · one-time
one-time · direct download
vault CLI for your shell