AutoBrief LogoAutoBrief
Back to news

Show HN: OneCLI – OSS credential gateway that keeps secrets out of AI agents

Hacker News2 min read263 words
Share:

**Open-Source Vault for AI Agents Seeks to Combat Security Risks**

In a bid to address the security risks associated with AI agents, developers Jonathan and Guy, creators of OneCLI, have released an open-source vault designed specifically for these agents. Traditional vaults store secrets and provide them to users in a secure manner, relying on the user to keep them safe. However, in the context of AI agents, this approach is not feasible as the agent's behavior and actions are unpredictable. OneCLI aims to bridge this gap by serving as a network gateway that sits between AI agents and the services they interact with.

The OneCLI vault matches requests from AI agents by host and path, verifies their access, swaps placeholder credentials with real ones, and forwards the requests. It also supports encrypted storage of secrets, with the option to fetch them in real-time from password managers like Bitwarden or 1Password. The developers have demonstrated the effectiveness of OneCLI in a YouTube video, showcasing its ability to control AI agent behavior and prevent potential security risks. OneCLI is designed to work with various agent frameworks, including Claude Code, Codex, and OpenClaw, and is built using Rust and Next.js.

The creators of OneCLI have emphasized the importance of deterministic rules in controlling AI agent behavior, citing the need to trust neither the model nor the agent to behave securely. They encourage users to scope policies tightly to prevent agents from misusing access they have. The OneCLI project has garnered interest from the developer community, with 21 points and 11 comments on Y Combinator's news platform.

🤖 AI-generated content — This article was automatically summarised from public RSS feeds by AutoBrief. Verify important information with the original source.