XEntropy
Turn credential chaos into order.
XEntropy
Turn credential chaos into order.
XEntropy is a native Mac workbench for discovering exposed credentials, understanding API-key history, and planning safer cleanup. It brings local scanning, a structured credential inventory, and tools for developers into one place while keeping the metadata catalog separate from your chosen credential store.
Understand what you have
Passwords, API keys, and authentication records accumulate across development folders, configuration files, exports, and password managers. XEntropy helps you review their sources, versions, and evidence before deciding what to keep or change. Its core approach is local-first, deterministic, and read-only by default.
Key features
Shannon-entropy secret scanner
Find candidate secrets using Shannon entropy and recognizable credential patterns. Choose folders, use your home folder when no target is selected, set include/exclude globs, adjust the entropy threshold, and enable the detector families you need. Saved settings persist between launches. Start or stop a scan, inspect coverage and partial results, filter and sort findings, and export metadata for review. A finding is evidence for review, not proof that a credential works.
API Key Table
Review key names, providers, status, version history, locations, and exposure evidence in a searchable table. The registry helps distinguish current, previous, and unmanaged observations. Secret values remain outside the metadata catalog; owner-controlled local access is a separate permission boundary.
CLI and MCP integration
Use xentropyctl and a local stateless MCP server for scoped catalog, discovery, service, and planning workflows. A conventional local JSON API is also implemented. Optional network listeners are disabled by default and require authenticated caller profiles.
Password-manager federation foundation
The universal password-manager front end includes a federation workbench and deterministic ranking by recency and entropy, with provenance and conflict indicators. Values-free export parsers and consolidation planning provide a foundation for comparing records.
Planned: live manager connections and complete cross-manager deduplication. The current federation adapters use synthetic fixtures or report that a user-selected export is required; the workbench must not be presented as live access to every password manager. The choice of consolidation destination remains undecided.
Permissions guidance
The merged Permissions interface explains Full Disk Access and Apple Notes Automation and provides actions that open the appropriate system settings. Denied-state guidance has been verified. Planned: completion of the human-assisted granted-state acceptance check.
Platforms and requirements
- Current platform: macOS desktop app and command-line tool.
- Declared minimum: macOS 15.0 in the current package and bundle build configuration. This is a declared requirement, not a claim that every supported operating-system release has been tested.
- Architectures: universal2 app and CLI, with Apple Silicon (
arm64) and Intel (x86_64) slices verified in the latest merge report. - Permissions: protected sources require the applicable macOS permission and explicit user authorization. Unsupported or inaccessible sources must remain visibly incomplete.
- Planned: iPhone/iPad review companion and private sync of non-secret metadata.
Status and availability
XEntropy is under active development. Current repository build metadata is 0.3.3, build 6. That version has documented internal deployment; the latest interface and icon changes have been merged and passed a canary launch check. Those newer changes are not documented as deployed to every installation.
Planned: public distribution and App Store availability. No public download is established by the current release evidence.
Product links
- XEntropy — designated product domain.
- XEntropy developer documentation — designated technical-documentation domain.
The domains are recorded in the product requirements; this content pack does not verify their current served content.