Passtrami: an MCP server for Apple Passwords that never leaks plaintext into agent transcripts
zats · x · 2026-09-10
Developer zats released Passtrami, a macOS app that gives Apple Passwords (iCloud Keychain) a local MCP interface. Coding agents like Codex, Claude Code, and Cursor can use it, but password values never appear in MCP tool responses — preventing leaks into agent session transcripts. The design borrows from 1Password's Environments MCP: send passwords to the program that needs them without exposing them to the agent. Every retrieval requires Touch ID approval, keeping the user in control. It ships as a menu bar app plus an optional CLI, built on the open-source apw project, requiring Apple Silicon and macOS 26.2+.
Related event: Passtrami Open-Sources MCP Bridge to Apple Passwords for AI Agents(3 posts)→
More from coding & agent
- Open-source CVE MCP server turns Claude into a security analyst with 28 tools across 21 APIs — tom_doerr · 2026-09-10
- OpenClaw Dashboards Turn Prompts into Mini-Apps, Replacing Custom Team Tooling — steipete · 2026-09-10
- Five Years of AI Coding in One Joke: From Fancy Autocomplete to Doing Your Entire Job — shauseth · 2026-09-10
- Vesence launches an agent-native Unix-like desktop in the browser with approval gates — ycombinator · 2026-09-10
- A three-step prompt pattern for AI code review: solve it yourself first, then compare with the PR — dotey · 2026-09-10
- OpenAI case study: GPT-6 Astra builds a house in Blender from one prompt, then moves it into UE5 — xiaohu · 2026-09-10