jit - Just-in-time secrets for your Mac

Show HN: Laptop is the last place your secrets are still in plaintext

jit - Just-in-time secrets for your Mac

jit is a macOS tool that finds plaintext secrets on your Mac—like API keys in .env files, AWS credentials, and shell exports—and moves them into a local encrypted vault protected by Touch ID. It rewrites configuration files so your existing tools keep working, injecting real credentials only into the specific processes that request them, after a biometric prompt. This protects against malicious scripts, sketchy npm installs, and AI agents running with your permissions. With jit, you unlock once, approve each tool's access, and leave decoy files on disk. It supports AWS, GCP, Docker, shell exports, and more, and includes an audit trail to track every access.

Your secrets live in plaintext all over your machine: .env files, ~/.aws/credentials, ~/.zshrc exports, .npmrc tokens, MCP configs. Anything running as you can read them.

More from this day

2026-08-16