Connect once
Encrypted before it leaves your browser.
Click to connect GitHub, Vercel, Cloudflare, and Resend at caddi.build. Pasted keys are encrypted in your browser before they leave it. Our servers only ever store ciphertext.
The place to organize everything your agents need (access, keys, skills) and hand it to them the moment they need it. Any agent, any machine, with everything end-to-end encrypted so even we can’t read it.
Free. Your keys stay yours.
How it works
Encrypted before it leaves your browser.
Click to connect GitHub, Vercel, Cloudflare, and Resend at caddi.build. Pasted keys are encrypted in your browser before they leave it. Our servers only ever store ciphertext.
No .env files, no copy-paste.
One command registers a single MCP server in every agent you use. No per-project config, no tokens in .env files, no copy-pasting keys into chats.
Scoped, logged, never raw.
Deploys, DNS, email: your agent gets them as tools, never raw keys. Every call is scoped and logged. Your skills ride along to every machine.
Security
Your account has a vault. The public half encrypts; the private half exists only on machines you’ve approved, in the OS keychain. Keys you paste are sealed in your browser. OAuth tokens are sealed the moment they arrive: where a provider supports device-flow OAuth, they never touch our servers at all.
If our database leaked, an attacker would get ciphertext they cannot decrypt. That’s the whole design.
What’s included
A good caddie doesn’t just carry the bag: they hand you the right club before you ask. Caddi keeps your agents’ supplies organized in one place and delivers them mid-round.
GitHub, Vercel, Cloudflare, Resend at launch, more on the way. Connected once, available to every agent.
Your skills library, synced to ~/.claude/skills on every machine you use with Claude Code today. Other agents are coming. Add one from a git repo or your own private stash. Pinned to a commit until you re-sync.
Every tool call your agents make, in one feed: what ran, from which project, on which machine. Names only, never your data.
Questions
The place where you organize everything your coding agents need, the way a golf caddie organizes the bag. You connect your services once at caddi.build, install the caddi CLI, and any MCP-speaking agent (Claude Code, Cursor, Codex, whatever you use) gets those services as tools when it needs them. Your skills library also syncs to every machine you use, to ~/.claude/skills for Claude Code today, with other agents coming.
No. Keys are encrypted to your vault’s public key; the private key only exists on your approved devices. Every connection today is a pasted token, sealed client-side (in your browser, or on your device with the CLI) before it ever reaches our servers. There’s no OAuth flow and no plaintext token ever transits our infrastructure. We say this precisely because the honest version is the whole point.
A secrets manager hands out secrets. Caddi mostly doesn’t: your agent calls tools ("deploy this", "send that email") and Caddi executes them with keys the agent never sees. When a running app genuinely needs a key, caddi env pull delivers it, per-project and logged.
Anything that speaks MCP: Claude Code, Cursor, Codex, Windsurf, and whatever ships next. One server entry, all your connections.
Nothing. Caddi is free.
Your recovery code restores the vault on a new machine. Lose both and your stored keys are unrecoverable by design, so you just reconnect your services. We can’t reset what we can’t read.
Caddi v2 is live, free. Connect your services, install the CLI, and your agents are equipped.
Get started →Free. Your keys stay yours.
Prefer email updates? Join the list.