Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

OneCLI

Vault for AI Agents in Rust

Details

External ID
47353558
Source
HN
Company
—
Product
OneCLI
Website domain
github.com
Launched
March 12, 2026
Cohort
—
Upvotes
161
Upvotes percentile
0.9532595325953259
Tags
—
Fetched at
Sept. 7, 2026, 9:26 p.m.
Updated at
Sept. 7, 2026, 9:26 p.m.

Description

We built OneCLI because AI agents are being given raw API keys. And it's going about as well as you'd expect. We figured the answer isn't "don't give agents access," it's "give them access without giving them secrets."OneCLI is an open-source gateway that sits between your AI agents and the services they call. You store your real credentials once in OneCLI's encrypted vault, and give your agents placeholder keys. When an agent makes an HTTP call through the proxy, OneCLI matches the request by host/path, verifies the agent should have access, swaps the placeholder for the real credential, and forwards the request. The agent never touches the actual secret. It just uses CLI or MCP tools as normal.Try it in one line: docker run --pull always -p 10254:10254 -p 10255:10255 -v onecli-data:/app/data ghcr.io/onecli/onecliThe proxy is written in Rust, the dashboard is Next.js, and secrets are AES-256-GCM encrypted at rest. Everything runs in a single Docker container with an embedded Postgres (PGlite), no external dependencies. Works with any agent framework (OpenClaw, NanoClaw, IronClaw, or anything that can set an HTTPS_PROXY).We started with what felt most urgent: agents shouldn't be holding raw credentials. The next layer is access policies and audit, defining what each agent can call, logging everything, and requiring human approval before sensitive actions go through.It's Apache-2.0 licensed. We'd love feedback on the approach, and we're especially curious how people are handling agent auth today.GitHub: https://github.com/onecli/onecli Site: https://onecli.sh

Enrichment

Theme
self-hosted infrastructure and security tools
Vertical
Security
Function
Dev tools
Audience
Developer
AI stance
Not AI
Project type
Commercial product
Normalized one-liner
vault for ai agents in rust
Manually corrected
False

Could you build this?

Yes This is a reverse-proxy gateway written in Rust (using Axum or Actix) that intercepts agent outbound requests, authenticates them, injects stored secrets into headers, and forwards them to target APIs.

Discussion

20 comments analyzed.

Competitors mentioned: IronClaw (hardened open-source agent security), Vault (HashiCorp credential management), AWS Secrets Manager, AWS STS (temporary time-bound credentials), 1Password adapters

Concerns raised: Prompt injection attacks can still exfiltrate sensitive data through legitimate endpoint responses, Design fails open to MITM if tools misconfigured to use HTTP instead of proxy, Doesn't solve underlying problem of agents accessing services; just moves credential risk, Prompt-injected agents can abuse proxied access for attacker's benefit even without key exposure

Feature requests: 1Password adapter integration, Dynamic access policies for temporary elevated agent permissions, Agent-level audit logging and request tracking, Integration with existing IAM systems

Competitors

Other products that read as similar to this one — 326 launches clear the similarity bar, closest 8 shown.

Attention rank: #20 of 327 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 118 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a dev tools tool for Sales yet.