Self-hosted execution layer for AI agents: connect any agent to real APIs, scope exactly what it can touch, and keep credentials out of the agent's hands.
-
Updated
Oct 4, 2026 - Python
Self-hosted execution layer for AI agents: connect any agent to real APIs, scope exactly what it can touch, and keep credentials out of the agent's hands.
Turn a fresh LXC into an AI homelab command center. One command installs Claude Code + a web UI, preloaded with skills, and a credential broker so Claude operates your TrueNAS/Proxmox/Linux over SSH without ever seeing a secret.
Give your agent access to your GitHub, Hugging Face and other accounts safely
Credential Broker CLI for AI agents: zero-knowledge secret injection (pass/bitwarden), subprocess run injection, integrated DLP with pattern rules, OAuth refresh, structured audit logs. Zero-dependency single binary.
Secrets manager for AI agents: let LLM agents use API keys & DB passwords without ever seeing the plaintext. Master-password vault, OS-isolated credential-injecting broker/proxy, per-secret usage policies, PostgreSQL connector. Stops prompt-injection key leaks.
Local SSH credential broker and MCP server
Approval-gated credential brokerage and actor-scoped connectors for OpenClaw.
Secretless, identity-aware credential broker for agents & automations (non-human identities) — acts on behalf of a verified caller against any service, including the un-API'd web.
SecretBroker is a local macOS credential broker for scoped, user-approved AI agent operations without exposing stored credentials.
Multi-cluster deployment placement oracle and short-lived credential broker
Secrets for coding agents — both seekrit MCP servers plus the skills that keep API keys out of your agent transcript. One install.
Secretless credential broker: AI agents use real API keys & SSH keys via proxy tokens — plaintext never reaches the agent's process, env, logs, or model context.
Agent-safe credential capability broker and public MCP client for secret-backed tools.
Terminal-first AI IDE where the agent builds, runs and debugs your app without you ever handing it a credential.
Security-first Python agent runtime with capability-enforced authorization, broker-controlled credential use, trusted execution boundaries, and adversarial security tests.
Scoped, TTL-boxed credentials and a signed action-audit trail for autonomous AI agents on Kubernetes — agents hold no long-lived secrets
Egress proxy that swaps {{seekrit:NAME}} placeholders in outbound requests for real credentials, so an AI agent never holds an API key. Default-deny allowlist, operation-level rules, decryption on your own machine.
Local-first credential broker for AI agents — secrets your agents can use but never see. 66 testable security constraints. Rust.
Stdio MCP bridge for KeyHand — credential dropbox with agent-blind injection. Clients hand off API keys via magic-link form; AI agents use them via HTTP calls without ever seeing the plaintext.
Credential broker for AI coding tools and MCP clients. Keep raw tokens out of prompts, .env files, and agent output.
To associate your repository with the credential-broker topic, visit your repo's landing page and select "manage topics."