AgentsAutonomy & tool use
llm-keys-ui 0.1 offers a short-lived web UI for LLM API keys, but ships without authentication
Simon Willison’s llm-keys-ui 0.1 addresses a remote coding-agent workflow: entering API keys on a host machine without pasting secrets into chat. Its value is convenience; its central risk is an unauthenticated local web server.

The tool is aimed at phone- or remote-controlled coding setups where developers need to place API keys on the host machine while avoiding exposure in an agent or chat context. [1] [2] [3]
llm-keys-ui appears to be a front end for the existing LLM CLI key mechanism rather than a new secrets-management system. [1] [4] [5]
The practical security tradeoff is clear: the interface can help avoid leaking keys into prompts, but the reviewed sources describe no authentication, so it should be treated as a temporary bootstrap tool. [1]
Evidence shows a small utility for setting LLM CLI keys in remote-agent workflows. The implication for teams is operational: it may reduce prompt-level secret leakage, but it does not replace access controls, secret managers, or network hardening.
Executive brief
The most consequential detail is security tradeoff, not functionality: llm-keys-ui 0.1 creates an unauthenticated local web interface for writing LLM API keys, and its own README says to stop the server after use. The tool targets a real agentic-coding pain point: setting API keys on a remote machine controlled from a phone without pasting secrets into an agent/chat context. It is small, open source, Apache-2.0, Python >=3.10, published to PyPI on September 20, 2026, and backed mainly by author materials plus package metadata—not independent evaluation.
What changed and event timeline
Codex remote mobile preview
OpenAI said Codex in the ChatGPT mobile app could connect to machines running Codex, with files and credentials staying on the host machine.
llm-keys-ui 0.1appears on PyPIPyPI lists version
0.1, Python>=3.10, Apache-2.0, one maintainer, and release files totaling 24.3 kB.GitHub Actions provenance recorded
PyPI says both the sdist and wheel were uploaded using Trusted Publishing and signed by GitHub Actions, tied to
simonw/llm-keys-uicommit6415948….Willison announces the plugin
Simon Willison described using it with Codex Remote by running
uvx --with llm-keys-ui llm keys-ui --all, then saving keys through URLs printed for local/Tailscale interfaces.
Capabilities and access
- Exact release:
llm-keys-ui 0.1. - Installs as an LLM plugin:
llm install llm-keys-ui. - Adds
llm keys-ui, defaulting to127.0.0.1:8010;-p/--portchanges port;-h/--hostchanges interface;--allbinds0.0.0.0and prints IPv4 URLs. GitHub README
Read the full section
- Exact release:
llm-keys-ui 0.1. - Installs as an LLM plugin:
llm install llm-keys-ui. - Adds
llm keys-ui, defaulting to127.0.0.1:8010;-p/--portchanges port;-h/--hostchanges interface;--allbinds0.0.0.0and prints IPv4 URLs. GitHub README - Purpose: set keys used by Simon Willison’s
llmCLI without exposing existing values in the UI. llm-keys-ui · PyPI
Technical analysis for researchers and developers
Documented implementation is a Starlette app served by Uvicorn, registered through LLM’s plugin entry point. The app writes to llm.user_dir()/keys.json, validates key names, discovers installed model key names via LLM model metadata, and writes updates atomically through a temporary file, fsync, os.replace, and 0600 permissions.
Read the full section
Documented implementation is a Starlette app served by Uvicorn, registered through LLM’s plugin entry point. Dependencies are llm, psutil, starlette, and uvicorn. The app writes to llm.user_dir()/keys.json, validates key names, discovers installed model key names via LLM model metadata, and writes updates atomically through a temporary file, fsync, os.replace, and 0600 permissions. It adds CSRF tokens, no-store, CSP, referrer, and nosniff headers, but no authentication. source file, pyproject.toml
Claims and evidence
- Vendor/author-reported: The plugin is intended for remote coding-agent machines where users want to set API keys without pasting them into agent context.
- Package-metadata supported: Release
0.1was published September 20, 2026, with Trusted Publishing attestations from GitHub Actions. PyPI - Code-supported: Existing key values are not displayed; POSTs require a CSRF token; the server has no authentication. source file
Read the full section
- Vendor/author-reported: The plugin is intended for remote coding-agent machines where users want to set API keys without pasting them into agent context. Simon Willison post, PyPI
- Package-metadata supported: Release
0.1was published September 20, 2026, with Trusted Publishing attestations from GitHub Actions. PyPI - Code-supported: Existing key values are not displayed; POSTs require a CSRF token; the server has no authentication. source file
- Independent corroboration: no independent review, audit, exploit analysis, or adoption study specific to
llm-keys-ui 0.1appears in the reviewed sources.
Context and prior work
llm-keys-ui sits on top of LLM’s existing key system: llm keys set, llm keys, llm keys path, and keys.json storage. LLM plugins can retrieve secrets with llm.get_key(alias=...), with optional environment-variable fallback.
Read the full section
llm-keys-ui sits on top of LLM’s existing key system: llm keys set, llm keys, llm keys path, and keys.json storage. LLM plugins can retrieve secrets with llm.get_key(alias=...), with optional environment-variable fallback. The new contribution is not a new secret store; it is a short-lived web front end for the existing local store, motivated by phone-controlled coding agents and remote hosts. LLM setup docs, LLM plugin utilities
Limitations, safety and contested findings
The main documented risk is explicit: the interface “does not implement authentication,” so the README advises stopping the server after setting keys. Binding to 0.0.0.0 via --all is useful for LAN/Tailscale access but increases exposure. The UI cannot read existing key values, which limits disclosure through the web page, but it can write or overwrite keys.
Read the full section
The main documented risk is explicit: the interface “does not implement authentication,” so the README advises stopping the server after setting keys. Binding to 0.0.0.0 via --all is useful for LAN/Tailscale access but increases exposure. The UI cannot read existing key values, which limits disclosure through the web page, but it can write or overwrite keys. No independent security audit is cited in the reviewed sources. GitHub README, source file
Business and practitioner implications
For teams experimenting with mobile-supervised coding agents, the pattern is pragmatic: keep API keys off chat transcripts and agent prompts, but still inject them onto the host where work runs. Treat it as a temporary bootstrap tool, not an enterprise secrets manager.
Read the full section
For teams experimenting with mobile-supervised coding agents, the pattern is pragmatic: keep API keys off chat transcripts and agent prompts, but still inject them onto the host where work runs. Treat it as a temporary bootstrap tool, not an enterprise secrets manager. Practical controls: run on loopback when possible, prefer private overlays such as Tailscale only when needed, stop immediately after use, rotate keys if exposed, and avoid using it on shared or untrusted networks.