Sep 21 edition/Reporting & analysis
AgentsCodingSafetyInfrastructure

AgentsAutonomy & tool use

llm-keys-ui 0.1 offers a short-lived web UI for LLM API keys, but ships without authentication

Simon Willison’s llm-keys-ui 0.1 addresses a remote coding-agent workflow: entering API keys on a host machine without pasting secrets into chat. Its value is convenience; its central risk is an unauthenticated local web server.

Illustration from Simon Willison’s Weblog: llm-keys-ui 0.1 offers a short-lived web UI for LLM API keys, but ships without authentication
Image: Simon Willison’s Weblog — Original article ↗
THE CORE IDEAS3 TAKEAWAYS
01

The tool is aimed at phone- or remote-controlled coding setups where developers need to place API keys on the host machine while avoiding exposure in an agent or chat context. [1] [2] [3]

02

llm-keys-ui appears to be a front end for the existing LLM CLI key mechanism rather than a new secrets-management system. [1] [4] [5]

03

The practical security tradeoff is clear: the interface can help avoid leaking keys into prompts, but the reviewed sources describe no authentication, so it should be treated as a temporary bootstrap tool. [1]

WHY IT MATTERS

Evidence shows a small utility for setting LLM CLI keys in remote-agent workflows. The implication for teams is operational: it may reduce prompt-level secret leakage, but it does not replace access controls, secret managers, or network hardening.

Executive brief

The most consequential detail is security tradeoff, not functionality: llm-keys-ui 0.1 creates an unauthenticated local web interface for writing LLM API keys, and its own README says to stop the server after use. The tool targets a real agentic-coding pain point: setting API keys on a remote machine controlled from a phone without pasting secrets into an agent/chat context. It is small, open source, Apache-2.0, Python >=3.10, published to PyPI on September 20, 2026, and backed mainly by author materials plus package metadata—not independent evaluation.

What changed and event timeline

  1. Codex remote mobile preview

    OpenAI said Codex in the ChatGPT mobile app could connect to machines running Codex, with files and credentials staying on the host machine.

  2. llm-keys-ui 0.1 appears on PyPI

    PyPI lists version 0.1, Python >=3.10, Apache-2.0, one maintainer, and release files totaling 24.3 kB.

  3. GitHub Actions provenance recorded

    PyPI says both the sdist and wheel were uploaded using Trusted Publishing and signed by GitHub Actions, tied to simonw/llm-keys-ui commit 6415948….

  4. Willison announces the plugin

    Simon Willison described using it with Codex Remote by running uvx --with llm-keys-ui llm keys-ui --all, then saving keys through URLs printed for local/Tailscale interfaces.

Capabilities and access

  • Exact release: llm-keys-ui 0.1.
  • Installs as an LLM plugin: llm install llm-keys-ui.
  • Adds llm keys-ui, defaulting to 127.0.0.1:8010; -p/--port changes port; -h/--host changes interface; --all binds 0.0.0.0 and prints IPv4 URLs. GitHub README
Read the full section
  • Exact release: llm-keys-ui 0.1.
  • Installs as an LLM plugin: llm install llm-keys-ui.
  • Adds llm keys-ui, defaulting to 127.0.0.1:8010; -p/--port changes port; -h/--host changes interface; --all binds 0.0.0.0 and prints IPv4 URLs. GitHub README
  • Purpose: set keys used by Simon Willison’s llm CLI without exposing existing values in the UI. llm-keys-ui · PyPI

Technical analysis for researchers and developers

Documented implementation is a Starlette app served by Uvicorn, registered through LLM’s plugin entry point. The app writes to llm.user_dir()/keys.json, validates key names, discovers installed model key names via LLM model metadata, and writes updates atomically through a temporary file, fsync, os.replace, and 0600 permissions.

Read the full section

Documented implementation is a Starlette app served by Uvicorn, registered through LLM’s plugin entry point. Dependencies are llm, psutil, starlette, and uvicorn. The app writes to llm.user_dir()/keys.json, validates key names, discovers installed model key names via LLM model metadata, and writes updates atomically through a temporary file, fsync, os.replace, and 0600 permissions. It adds CSRF tokens, no-store, CSP, referrer, and nosniff headers, but no authentication. source file, pyproject.toml

Claims and evidence

  • Vendor/author-reported: The plugin is intended for remote coding-agent machines where users want to set API keys without pasting them into agent context.
  • Package-metadata supported: Release 0.1 was published September 20, 2026, with Trusted Publishing attestations from GitHub Actions. PyPI
  • Code-supported: Existing key values are not displayed; POSTs require a CSRF token; the server has no authentication. source file
Read the full section
  • Vendor/author-reported: The plugin is intended for remote coding-agent machines where users want to set API keys without pasting them into agent context. Simon Willison post, PyPI
  • Package-metadata supported: Release 0.1 was published September 20, 2026, with Trusted Publishing attestations from GitHub Actions. PyPI
  • Code-supported: Existing key values are not displayed; POSTs require a CSRF token; the server has no authentication. source file
  • Independent corroboration: no independent review, audit, exploit analysis, or adoption study specific to llm-keys-ui 0.1 appears in the reviewed sources.

Context and prior work

llm-keys-ui sits on top of LLM’s existing key system: llm keys set, llm keys, llm keys path, and keys.json storage. LLM plugins can retrieve secrets with llm.get_key(alias=...), with optional environment-variable fallback.

Read the full section

llm-keys-ui sits on top of LLM’s existing key system: llm keys set, llm keys, llm keys path, and keys.json storage. LLM plugins can retrieve secrets with llm.get_key(alias=...), with optional environment-variable fallback. The new contribution is not a new secret store; it is a short-lived web front end for the existing local store, motivated by phone-controlled coding agents and remote hosts. LLM setup docs, LLM plugin utilities

Limitations, safety and contested findings

The main documented risk is explicit: the interface “does not implement authentication,” so the README advises stopping the server after setting keys. Binding to 0.0.0.0 via --all is useful for LAN/Tailscale access but increases exposure. The UI cannot read existing key values, which limits disclosure through the web page, but it can write or overwrite keys.

Read the full section

The main documented risk is explicit: the interface “does not implement authentication,” so the README advises stopping the server after setting keys. Binding to 0.0.0.0 via --all is useful for LAN/Tailscale access but increases exposure. The UI cannot read existing key values, which limits disclosure through the web page, but it can write or overwrite keys. No independent security audit is cited in the reviewed sources. GitHub README, source file

Business and practitioner implications

For teams experimenting with mobile-supervised coding agents, the pattern is pragmatic: keep API keys off chat transcripts and agent prompts, but still inject them onto the host where work runs. Treat it as a temporary bootstrap tool, not an enterprise secrets manager.

Read the full section

For teams experimenting with mobile-supervised coding agents, the pattern is pragmatic: keep API keys off chat transcripts and agent prompts, but still inject them onto the host where work runs. Treat it as a temporary bootstrap tool, not an enterprise secrets manager. Practical controls: run on loopback when possible, prefer private overlays such as Tailscale only when needed, stop immediately after use, rotate keys if exposed, and avoid using it on shared or untrusted networks.

Sources

Read the full section
FOLLOW THE EVIDENCE

The source trail.

Sources (5)
A LITTLE LESS NOISE. A LOT MORE CONTEXT.

Stay curious.
Follow the evidence.

Independent perspectives, the original sources, and room for the questions that don't have easy answers.

How we build the brief