OneCLI is an open-source credential gateway that shields secrets from AI agents
Developers Jonathan and Guy have launched OneCLI, an open-source network gateway designed to prevent AI agents from directly accessing sensitive credentials. Unlike traditional vaults that hand over secrets to the requester, OneCLI sits between AI agents and the services they call, substituting placeholder tokens with real credentials only at the network layer. The tool supports integration with existing password managers like Bitwarden and 1Password, and stores secrets using AES-256-GCM encryption at rest. It also supports human-in-the-loop approval for sensitive operations, ensuring that even a manipulated or misbehaving agent cannot exfiltrate credentials or exceed its permitted scope. OneCLI is compatible with any agent framework that supports an HTTPS proxy, and the entire stack runs inside a Docker container.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in