An API key is easy to lose in a scratch file or old message. OGAD (Off Grid AI Desktop) gives it a dedicated API Key entry in an encrypted local Vault. Keep the token with a clear label, find it when needed, and copy it into the tool you intend to use.
Download OGAD for Mac or Windows

What would you like to do with Off Grid AI?
Have a feature or use case you would like us to support? Tell us what you want to do and which device you use.
Write to support@offgridmobileai.co, join our Slack community, or talk to us on Reddit.
Vault is a Pro feature on the shipped Mac and Windows desktop builds. It does not need an AI model to store a key, and the local storage workflow does not require a cloud vault service. Complete installation and Pro setup before relying on it offline.
Give each key a name you will understand later
The useful result is more than hiding a token. You want to know which account, environment, and purpose it belongs to before you use it. OGAD’s API Key entry separates the secret from the title and label you browse.
A simple naming scheme can be enough:
| Field | Example content |
|---|---|
| Title | Personal project — test API |
| Label / Name | Development |
| Key / Token | The actual secret value |
| Notes | Purpose, creation date, and where to rotate it |
Keep the token in Key / Token, not in the title or label. Notes can explain the entry without repeating the secret. This helps you distinguish a development key from another account’s key when you return months later.
The entry types and local encrypted storage are available in OGAD 0.0.51, including its shipped Windows package.
What protection does the vault provide?
OGAD stores the database locally in encrypted KDBX form. Opening it uses your master password and a device-derived key. The key values are revealed when you ask for them, rather than displayed as plain text throughout the entry list.
This protects the saved vault. Once you copy a token, the text enters the system clipboard and can reach clipboard-history software or the app where you paste it. Pause clipboard capture when you do not want a secret recorded there, and check separate clipboard sync settings too.
A vault also does not change the permission or expiry of an API key. Those remain with the service that issued it. Keep narrowly scoped keys where the service supports them, and rotate a key through that service when needed.
Getting started
Create the vault and test one non-secret entry before storing an important token. Then use the dedicated API Key type for the real value.
- Open Vault in OGAD with Pro active.
- Create a master password and store the recovery phrase safely outside the vault.
- Select New entry → API Key.
- Add a Title, Label / Name, and Key / Token.
- Add a short purpose note and select Save.
- Lock the vault, unlock it again, and find the entry.
You can use a dummy value such as example-token-not-a-real-key for the first save-and-unlock check. Never put a real token in a tutorial screenshot or a chat request merely to test the process.
Search uses visible identifying fields such as the title and label. You do not need to reveal every token to locate the right one.
Use the token deliberately
Open the matching entry, reveal the value if needed, and copy it to the intended destination. Check the destination app and environment before pasting. A good label prevents an avoidable mix-up between a test project and a live one.
Vault is a local storage tool. Saving a token there does not automatically inject it into shell commands, development environments, CI jobs, or application settings. You choose where to use it.
After a rotation, update the stored entry to match the newly issued key. Do not assume that editing the vault entry revokes the old token. That action must happen at the service that owns it.
Keep context without keeping extra copies
A short note can tell you enough to use the key later: what it is for, which account owns it, and where to manage it. Avoid pasting the secret into several note fields or keeping an extra unencrypted “backup” beside the project.
If you already have a configuration file, the File entry type can store a small encrypted copy. That does not remove the original configuration file from disk. Treat the working copy and the vault copy separately.
Lock the vault when finished. The app provides Lock vault for this purpose; do not assume that closing an entry alone locks the database.
Prepare for loss as well as access
Keep the recovery phrase private and outside the vault. Retain an appropriate backup of the vault data and required recovery material. The phrase cannot recreate missing entries from nothing.
Device binding also means that moving only the database file to another computer is not equivalent to unlocking it on the original machine. Use the recovery workflow when necessary, with the files and phrase it requires.
Store one key you can identify with confidence
Download OGAD and create an API Key entry with a clear purpose and environment label. Check the lock-and-unlock flow, then keep the real token in its protected field. You get a local place to retrieve it without a required cloud vault.