PwKV.com reads the way a developer writes it in a config file: pw for password, KV for key-value store. Secrets have lived in key-value stores for years (HashiCorp Vault, the standard secrets tool for a decade, keeps them in an engine called KV), so the name lands instantly with the people who’d use the product.
The product behind it solves a problem that barely existed two years ago. AI coding agents read everything in a project folder, including the .env file where the API keys sit. A key an agent has read can end up in a log, a prompt, a commit or a pasted transcript. Teams are learning this the hard way.
How the swap works
PwKV keeps the real keys in one encrypted file. The app, and any agent working on it, only ever holds placeholders. A small local proxy watches outgoing requests and swaps the real key in on the way out, but only for hosts on an approved list. A leaked placeholder is worthless. An agent that tries to send a key somewhere it shouldn’t gets refused.
The same trick works for people. A contractor or a new hire can run the project without ever seeing a production key. It’s an idea a homepage can explain with one diagram, and it fits how developers already work: nothing in the app changes except the value in the .env file.
A paid category with a new front
Secrets management has been a paying business for a long time. Vault, Doppler, 1Password’s developer tools and every cloud provider’s secrets service all sell into it. Agent security is the new front in that market, and the companies moving into it will need names. PwKV is four letters on a .com, and it says what’s inside.
Agents won’t stop reading files. The keys just have to stop being there.