Get started
OperationsLive · in the productSettings

KeyRing

Your own keys and connections, sealed and verifiable.

Get KeyRingOpen the appAvailable nowHow pricing works →

What it is

Bring your own accounts — your model provider, your Resend domain, your payment gateway, your WhatsApp number, your own Supabase project — and the platform uses them instead of ours. Each key is sealed under a data key that is itself sealed under the deployment master key, and bound to your organisation so a copied row opens nowhere else. Stored keys are checked against the provider on the spot, so a wrong key is wrong at the moment you paste it rather than at 2am.

Who uses it
Built for: Every specialty
Reads
Nothing — it holds credentials, not records
Writes
Sealed credentials, verification outcomes
Never
It never shows a key back.
Access
Only people whose role includes it — the clinic owner decides who
Your data
No PHI. Hosted in Boston, United States. On uninstall: Revoked keys stop being used immediately; the rows stay so an incident can still ask which key was in force last month.

How it works

  1. Open KeysThe screen is grouped by what a key is for: AI model provider, email, WhatsApp, payments, your own database, Google Sheets & Drive, reviews, GST e-invoicing and the image archive. If no vault master key is configured on the server the screen says so and refuses to store anything.
  2. Connect a providerPress Connect, pick the provider from the list this build knows how to talk to, paste the key and fill the fields it needs, such as the from address for Resend or the phone number id for WhatsApp.
  3. Store and checkThe key is sealed on save and, where a verifier exists for that provider, checked against it on the spot. The row then reads verified, invalid with the provider’s error, or unverified where nothing checked.
  4. Never read it backA stored key is shown only as a masked hint. Check re-runs the verification; Revoke stops the platform using the key while the record of it stays.

Rules it keeps

What it does not do, by design. A listing with only benefits is an advertisement.

It never shows a key back.
Once stored, a secret is only ever a masked hint — not to you, not to us, not to support.
There is no reveal endpoint to be talked into.

AI in KeyRing

AskQuestions about what is on screen — “What needs attention in KeyRing today?” — answered with the records it read.
DraftSummaries and notes for the team, marked as drafts until a person signs.
Every answer shows its sources. Nothing AI writes is saved until a person accepts it.

See it on screen

Live product
01Keys — Your own API keys and connections, sealedCaptured from the running demo clinic
KeyRing — Keys — Your own API keys and connections, sealed
1 of 1

Questions clinics ask

What does KeyRing do?
Your own keys and connections, sealed and verifiable. Bring your own accounts — your model provider, your Resend domain, your payment gateway, your WhatsApp number, your own Supabase project — and the platform uses them instead of ours. Each key is sealed under a data key that is itself sealed under the deployment master key, and bound to your organisation so a copied row opens nowhere else. Stored keys are checked against the provider on the spot, so a wrong key is wrong at the moment you paste it rather than at 2am.
What data does KeyRing read and write?
KeyRing reads nothing — it holds credentials, not records and writes sealed credentials, verification outcomes. Its data class is No PHI. Every app works on the same patient record — nothing is copied into a silo.
What does KeyRing deliberately not do?
It never shows a key back. Once stored, a secret is only ever a masked hint — not to you, not to us, not to support. There is no reveal endpoint to be talked into.
What happens to our data if we uninstall KeyRing?
Revoked keys stop being used immediately; the rows stay so an incident can still ask which key was in force last month.
Is KeyRing available today?
Yes — KeyRing is live in clinics today. Set up your practice on MedAppz and install it from your dashboard.

Want to see KeyRing running on your own patients?

Tell us what you run and we will show you this app inside a practice shaped like yours — or answer the question the page above did not.

We use your name, phone number and clinic name for one thing: to answer this enquiry about MedAppz. It is stored on our own server, in the single region our trust centre names, and it is not sold or passed to anyone else.

Email us

You can withdraw either at any time: write to hello@medappz.com, or tell whoever calls you, and we will delete what you gave us.

More in Operations

All 129 →