# AgentKey: One Installer to Give Your AI Agent Web, Social and On-chain Data

> AgentKey is a shell and skill package from chainbase-labs that wires web search, social media scraping and crypto data into 40+ coding agents through a single curl or PowerShell command. The trade-off is that the data path runs through AgentKey's own service and subscription.

**chainbase-labs/Agentkey** — Connect your AI agent to the world — Web search, Social media, Crypto & On-chain data. One plugin, zero extra config.

- Repository: https://github.com/chainbase-labs/Agentkey
- Website: https://agentkey.app
- Stars: 652 · Forks: 69
- Language: Shell
- License: Apache-2.0
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/chainbase-labs-agentkey

## The credential sprawl AgentKey is built to remove

The README frames the problem as arithmetic: ten tasks need ten API keys and ten separate bills, so the agent stalls whenever it hits a platform it has no credentials for. Tweets are blocked, Instagram wants a login, Reddit returns 403, LinkedIn returns 403 again, and a plain webpage comes back as a wall of raw HTML. AgentKey's answer is a single subscription that the agent calls instead of the individual providers. The audience is narrow and specific: people running an agent that already supports skills or MCP, on macOS, Linux or Windows, who want the agent to answer questions about social platforms, video transcripts, GitHub repositories and wallet activity without a human pasting keys into a JSON file. The README's use case table is the clearest statement of scope. It is not a general web framework. It is a data-access layer for agents that otherwise cannot reach these platforms at all.

## How the installer detects agents and what the DSH integration actually writes

The install path is a shell script or a PowerShell script, and the README says it auto-detects every supported agent on the machine, naming Claude Code, Codex, Gemini CLI and Cursor CLI as common cases, with a link to a list of 40+ agents. Detection is followed by a browser tab for login. The repository layout confirms the breadth of that integration surface: there are separate plugin directories for Claude, Codex, Cursor and Kimi, plus gemini-extension.json, mcp_config.json, plugin.json and a skills directory. The DeepSeek Harness case is the one the README documents in detail, and it is worth reading closely because it is not a native plugin install. The installer places a skill at ~/.agents/skills/agentkey, authenticates, and adds one managed Loader block to ${DSH_HOME:-~/.dsh}/cordis.patch.yml. That block uses Loader id agentkey, module @deepseek-ai/dsh-mcp-client and MCP serverName agentkey, composed over current and future profiles. The README states plainly that DSH 0.1.0-rc.7 does not provide an OAuth authProvider to its MCP SDK client, so a header-free server entry cannot complete 401 discovery or open a browser. That is why DSH has to use a device-code login instead. Tool allow and deny policy still decides whether a given preset, session or subagent can see the tools, so installing AgentKey does not automatically expose it everywhere.

## Installing AgentKey and running a first query

The README gives one command per platform. On macOS or Linux, the installer is piped from agentkey.app into bash, and the README says a browser tab opens for login before configuration finishes.

```bash
curl -fsSL https://agentkey.app/install.sh | bash
```

On Windows the equivalent runs through PowerShell. Both scripts do the same work: detect agents, install the skill, authenticate, and configure each detected agent.

```powershell
irm https://agentkey.app/install.ps1 | iex
```

After the installer finishes, restart your agent and ask it something that needs the internet. The README's own example is a question about recent tweets, and the expected result is that the agent pulls the relevant posts and summarizes them rather than reporting a block or a 403.

If you only want DeepSeek Harness configured, the README gives a two-step manual path instead of the one-liner. The first command installs the skill globally and the second performs the device-code login scoped to dsh. The README notes the CLI stores the API key only in the local home patch, and that no key belongs in Git.

```bash
npx -y skills add chainbase-labs/agentkey -g -a universal -s agentkey -y
npx -y @agentkey/cli --auth-login --only dsh
```

Re-running that second command rotates the key and replaces the managed block. No existing profile is required.

## The migration behaviour is the part most installers get wrong

Installer scripts that edit user configuration are usually the least documented part of a project, and here the README is unusually explicit. During migration the CLI removes only top-level, column-1 AgentKey managed blocks from per-profile patches, and it renames a legacy .agent-presets/agentkey directory to a timestamped backup, printing that backup path. The conservative case is more interesting: if it structurally detects an older unmarked AgentKey Loader row, it stops without changing any patch and asks you to remove that top-level insert child by hand. That is a deliberate refusal to guess. It also means an upgrade can halt and wait for a human, which is the right call for a file that other tooling may have edited, but it is a real operational cost if you were expecting a fully unattended install across a fleet. The README's text on symlinked profile paths is truncated in the available README, so how symlinks are handled is not something this article can state.

## Where AgentKey is the wrong tool

The dependency is the limitation. Every query the agent makes for social, web or on-chain data goes through AgentKey's service, which is why the project can promise no per-provider registrations, and also why a network-isolated or air-gapped environment cannot use it. If your agent runs on a build server with no outbound access to agentkey.app, the installer itself will fail before any data question is asked. The second constraint is the subscription. The README describes one subscription replacing many bills, and it points to console.agentkey.app for managing that subscription and tracking usage. What the free tier, if any, covers is not stated in the README. Third, the DSH path is explicitly a CLI-managed MCP integration rather than a native plugin, and the README ties the device-code workaround to a specific DSH version, 0.1.0-rc.7, and to a missing OAuth authProvider in its MCP SDK client. If that upstream gap closes, the documented workaround may no longer be the recommended path, and the README does not say what happens then. Finally, the project is Shell-first with a private package.json named agentkey-skill, so anyone expecting to import it as a library into a Node or Python application will not find that shape here.

## AgentKey versus wiring the APIs yourself

The honest alternative is not a competing product but the manual route the README describes as the status quo: register with each provider, hold the keys, and let the agent call them directly. That approach gives you control over rate limits, data retention and which account is billed, and it keeps every request inside your own infrastructure. It costs you the setup time for each platform and the ongoing work of chasing API changes. AgentKey trades that control for a single credential and one bill, and it adds a layer that can normalize platforms your agent would otherwise fail on, such as pages that return 403 or videos without subtitles. The difference is architectural, not cosmetic: manual wiring puts the integration in your codebase, while AgentKey puts a managed MCP or skill layer between the agent and the providers. If your data sources are one or two well-documented APIs, manual wiring is probably less machinery. If the list runs to social platforms, video transcripts, GitHub repositories and wallet activity, the managed layer starts to look like the cheaper option.

## Maintenance, releases and the Apache-2.0 licence

The repository is not archived, and the last push was on 2026-08-24. Release cadence is visible in the release history: v1.13.0 on 2026-08-05, v1.13.1 on 2026-08-07, and v1.14.0 on 2026-08-22. The repository carries release-please-config.json and .release-please-manifest.json, so versioning and changelog generation are automated, and CHANGELOG.md is present at the top level. For upgrade cost, the README's own warning is the relevant fact: re-running the auth command rotates the API key and replaces the managed block. That is fine when you control the machine and awkward when a shared environment depends on the key. The licence is Apache-2.0, with a NOTICE file and a LICENSE file at the root. Apache-2.0 permits commercial use and modification and includes an explicit patent grant, but it also carries notice and attribution obligations, and the trademark question is separate from the copyright licence. Whether the AgentKey service, as opposed to the repository, is governed by the same terms is not something the README addresses. This is a description of the licence text, not legal advice; read LICENSE and NOTICE yourself before redistributing.

## Conclusion

AgentKey is worth trying if you already run Claude Code, Codex, Gemini CLI or another supported agent and you are tired of registering a separate API key for every data source. Skip it if your agent must run fully offline, if you cannot send queries through a third-party service, or if you need a self-hosted data pipeline you control end to end. Before you adopt it, open console.agentkey.app and confirm what the subscription covers, then run the installer on one machine and check that the managed block it writes to ${DSH_HOME:-~/.dsh}/cordis.patch.yml is one you are willing to keep in version control or exclude from it.

## FAQ

### How do I install AgentKey on macOS or Linux?

The README gives a single command, curl -fsSL https://agentkey.app/install.sh | bash. It says the installer auto-detects supported agents on the machine and opens a browser tab for login, after which you restart your agent.

### Does AgentKey work with Claude Code, Codex and Gemini CLI?

The README names Claude Code, Codex, Gemini CLI and Cursor CLI as common examples among 40+ supported agents, and the repository contains separate plugin directories for Claude, Codex, Cursor and Kimi plus a gemini-extension.json file.

### Is AgentKey a native DeepSeek Harness plugin?

No. The README states it is a CLI-managed DSH MCP integration, not a native installable DSH plugin, and it adds a managed Loader block to ${DSH_HOME:-~/.dsh}/cordis.patch.yml using module @deepseek-ai/dsh-mcp-client.

### What happens to my existing AgentKey configuration when I re-run the login command?

The README says re-running the command rotates the key and replaces the managed block. During migration it removes only top-level, column-1 managed blocks from per-profile patches and renames a legacy .agent-presets/agentkey directory to a timestamped backup.

### Why does DeepSeek Harness need a device-code login instead of a browser login?

The README states that DSH 0.1.0-rc.7 does not provide an OAuth authProvider to its MCP SDK client, so a header-free server entry cannot complete 401/RFC 9728 discovery or open a browser, and the CLI must write a local Bearer key instead.

### What licence does AgentKey use?

The repository is licensed under Apache-2.0 and includes both a LICENSE and a NOTICE file at the top level. The README does not state whether the hosted service is covered by the same terms.

## Sources

- [chainbase-labs/Agentkey on GitHub](https://github.com/chainbase-labs/Agentkey)
- [License: Apache-2.0](https://github.com/chainbase-labs/Agentkey/blob/main/LICENSE)
- [Project website](https://agentkey.app)
- [README](https://github.com/chainbase-labs/Agentkey/blob/main/README.md)
- [Releases](https://github.com/chainbase-labs/Agentkey/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/chainbase-labs-agentkey
