How StateSync handles your API keys
We never receive your API keys. Bring your own key and use it exactly as you would with the provider directly, in any agent that accepts one. StateSync passes it to the agent on your computer and keeps no copy of its own.
Where a key goes
A key you enter in the app goes straight from the screen into the agent's own storage on your computer. It is not sent to StateSync, and it is not kept in a StateSync file or database. Where it lands depends on the agent.
- Pi keys go in your operating system's secure store: DPAPI on Windows, the login Keychain on macOS, the Secret Service on Linux. They are passed to the Pi process when it starts and to no other process.
- OpenCode keys are written into OpenCode's own auth.json, next to any credentials you already keep there, so OpenCode behaves the same when you run it outside StateSync.
- Droid keys are written into Factory Droid's own settings.json, which is where Droid reads them.
For Pi, if your system has no secure store, StateSync refuses to save the key rather than write it in plain text. On Linux without a Secret Service there is an opt-in encrypted file instead. Anyone who can read your home directory can decrypt it, which is why it is off unless you turn it on.
No key proxy
Your agent sends requests from your computer to your provider's API. StateSync does not run a server that relays them, so there is no StateSync server between you and your provider, and no StateSync server holds a copy of your key.
What StateSync does see
Inside the app, the list of saved keys is only a yes or no for each provider. The screen that shows your keys never receives the keys.
The billing and fault-tracking information the app sends is numbers only: models and providers used, token counts and costs, how often each tool ran. It never includes a key or a credential. The full list is in the privacy policy.