Latchkey
inject credentials into agents' curl calls
Details
- External ID
- 46876636
- Source
- HN
- Company
- —
- Product
- Latchkey
- Website domain
- github.com
- Launched
- Feb. 3, 2026
- Cohort
- —
- Upvotes
- 12
- Upvotes percentile
- 0.5970350404312669
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:26 p.m.
- Updated at
- Sept. 7, 2026, 9:26 p.m.
Description
Hi HN,At Imbue, we’ve been following the rapid developments in the agent landscape and noticed that the way agents interact with third-party services on users’ behalf often leaves a lot to be desired. Integrations are ad hoc, complicated, context-heavy, and either unfriendly to non-technical users or tied to a lock-in of some sort.We‘re experimenting with a command-line tool, Latchkey, that could be used by local agents targeted at non-technical users while avoiding remote intermediaries. As far as we know, this is the only existing approach at the intersection of these two goals.Core idea: Agents access APIs of third-party services by prepending ordinary `curl` calls with the `latchkey` command, like this: latchkey curl -X POST 'https://slack.com/api/conversations.create' \ -H 'Content-Type: application/json' \ -d '{"name":"something-urgent"}' Latchkey then transparently injects credentials into these calls, prompting the user to log in via a browser pop-up when needed. Browser automation is used to extract an API token from the browser session once logged in.Benefits:* A single skill to integrate with all services.* Direct communication between the agent and the third-party service (no OAuth intermediary app needed).* Agents usable by non-technical users.* Secrets do not leak to logs or chat transcripts.We believe this aligns with a vision of a decentralized future in which people don’t need to ask corporations for permission to use their own data. We imagine a lively ecosystem of local agents that people use freely, supported by a community helping each other keep these tools useful and functional.We’re aware that this approach comes with some downsides, too, and would love your feedback.P.S. Here’s also a link to Passepartout, a toy demo AI assistant app built using Latchkey: https://github.com/imbue-ai/passepartout
Enrichment
- Theme
- self-hosted infrastructure and security tools
- Vertical
- Horizontal
- Function
- Agent / copilot
- Audience
- Developer
- AI stance
- AI feature
- Project type
- Commercial product
- Normalized one-liner
- credential injection for ai agents
- Manually corrected
- False
Could you build this?
Yes Latchkey is a credential injection proxy or CLI wrapper that intercepts outgoing HTTP/cURL requests from LLM agents to inject auth headers on the fly.
Discussion
No comments on this launch.
Competitors
Other products that read as similar to this one — 216 launches clear the similarity bar, closest 8 shown.
Attention rank: #92 of 217 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 94 days after the earliest competitor.
- Agent Vault · hn · 2026-04-22 · 156 upvotes · similarity 0.53
- My agents are building a secure fork of OpenClaw · hn · 2026-02-13 · 9 upvotes · similarity 0.52
- Latch · hn · 2026-02-06 · 5 upvotes · similarity 0.52
- OneCLI · hn · 2026-03-12 · 161 upvotes · similarity 0.48
- Clay Seal Identity · hn · 2026-07-13 · 5 upvotes · similarity 0.47
- Open Passkey · hn · 2026-04-19 · 10 upvotes · similarity 0.47
- Kontext.dev · hn · 2026-03-16 · 6 upvotes · similarity 0.46
- Vestauth · hn · 2026-02-17 · 11 upvotes · similarity 0.46
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a agent / copilot tool for Agriculture yet.