Move credentials out of plaintext files
Automic Vault moves supported credentials into the macOS Keychain as protected Secrets. It applies them to an authorized tool operation when needed.
Max Howell
Automic Vault complements macOS security for supported CLI tools: protected credentials, operation-level authorization, and your usual commands.
Last updated: October 3, 2026
Why we built it
I created Homebrew in 2009 to make developer tools easier to install. In the years since, Apple has built excellent layers of protection around Mac apps. Gatekeeper, notarization, malware checks, and privacy permissions help you control the software you run and the data it can access.
Command-line tools still often leave credentials in files or helpers that other code running as you can read. An agent or dependency can inherit the power to publish a release or change your cloud infrastructure without asking you.
Automic Vault builds on macOS code signing, Hardened Runtime, and the Keychain to protect developer credentials and authorize supported command-line operations. We harden tools where you install and configure them, then check protected operations when they run.
Automic Vault moves supported credentials into the macOS Keychain as protected Secrets. It applies them to an authorized tool operation when needed.
Automic Vault checks the executable, command, arguments, working directory, and requested Secrets. It also verifies the app or executable that launched the operation: the Verified Launcher.
The public GitHub repository shows how Automic Vault implements local control.
Automic Vault enforces policy on the Mac where the Tool operation runs.
What Automic Vault does
For GitHub, av harden gh installs our signed, patched CLI and moves its credentials into Automic Vault custody. You still run gh. Its Authorization Gate checks whether an operation may proceed: your policy can allow issue reads while requiring your approval for writes or token disclosure.
Homebrew hardening gates supported package-management operations and protects its installation against modification by other code running as you. Read & Update access allows recognized reads and updates; installing a new package requires approval. See supported tools and their protection.
Automic Vault is for developers on macOS who use command-line tools from terminals, editors, or coding agents.
If you let an agent work with GitHub or manage packages, you can choose which supported operations it may perform and which need your approval. You can also protect supported CLI credentials during your own terminal work.
I’m Max Howell. I created Homebrew in 2009 to make installing developer tools easier.
With Automic Vault, I’m working on the credentials and authority those tools bring with them, especially when a coding agent runs them on your behalf. You should be able to keep your commands and choose what they’re allowed to do.
| Product | Automic Vault |
|---|---|
| Creator | Max Howell, creator of Homebrew |
| Platform | macOS |
| Core offering | Hardening supported CLI tools, protecting developer credentials, and authorizing their use |
| Source and license | Open source on GitHub, Apache-2.0 |
| Documentation | Setup, supported tools, and security boundaries |
You keep using your usual commands after hardening a supported tool. Depending on the tool, Automic Vault changes its configuration, installs a wrapper, or installs a patched version so protected operations request authorization.
No. Coverage depends on the supported tool and operation. Check the hardener documentation for what each integration protects.
No. Automic Vault controls protected credentials and supported operations; it does not intercept every command or prevent arbitrary local destruction. An authorized executable can still expose a credential after receiving it. Read the security boundaries before choosing its access.