Kontext CLI
Credential broker for AI coding agents in Go
Details
- External ID
- 47765374
- Source
- HN
- Company
- —
- Product
- Kontext CLI
- Website domain
- github.com
- Launched
- April 14, 2026
- Cohort
- —
- Upvotes
- 70
- Upvotes percentile
- 0.8669665809768637
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:26 p.m.
- Updated at
- Sept. 7, 2026, 9:26 p.m.
Description
We built the Kontext CLI because AI coding agents need access to GitHub, Stripe, databases, and dozens of other services — and right now most teams handle this by copy-pasting long-lived API keys into .env files, or the actual chat interface, whilst hoping for the best.The problem isn't just secret sprawl. It's that there's no lineage of access. You don't know which developer launched which agent, what it accessed, or whether it should have been allowed to. The moment you hand raw credentials to a process, you've lost the ability to enforce policy, audit access, or rotate without pain. The credential is the authorization, and that's fundamentally broken when autonomous agents are making hundreds of API calls per session.Kontext takes a different approach. You declare what credentials a project needs in a .env.kontext file: GITHUB_TOKEN={{kontext:github}} STRIPE_KEY={{kontext:stripe}} LINEAR_TOKEN={{kontext:linear}} Then run `kontext start --agent claude`. The CLI authenticates you via OIDC, and for each placeholder: if the service supports OAuth, it exchanges the placeholder for a short-lived access token via RFC 8693 token exchange; for static API keys, the backend injects the credential directly into the agent's runtime environment. Either way, secrets exist only in memory during the session — never written to disk on your machine. Every tool call is streamed for audit as the agent runs.The closest analogy is a Security Token Service (STS): you authenticate once, and the backend mints short-lived, scoped credentials on-the-fly — except unlike a classical STS, we hold the upstream secrets, so nothing long-lived ever reaches the agent. The backend holds your OAuth refresh tokens and API keys; the CLI never sees them. It gets back short-lived access tokens scoped to the session.What the CLI captures for every tool call: what the agent tried to do, what happened, whether it was allowed, and who did it — attributed to a user, session, and org.Install with one command: `brew install kontext-dev/tap/kontext`The CLI is written in Go (~5ms hook overhead per tool call), uses ConnectRPC for backend communication, and stores auth in the system keyring. Works with Claude Code today, Codex support coming soon.We're working on server-side policy enforcement next — the infrastructure for allow/deny decisions on every tool call is already wired, we just need to close the loop so tool calls can also be rejected.We'd love feedback on the approach. Especially curious: how are teams handling credential management for AI agents today? Are you just pasting env vars into the agent chat, or have you found something better?GitHub: https://github.com/kontext-dev/kontext-cli Site: https://kontext.security
Enrichment
- Theme
- AI agent frameworks and developer tools
- Vertical
- Horizontal
- Function
- Dev tools
- Audience
- Developer
- AI stance
- AI feature
- Project type
- Commercial product
- Normalized one-liner
- credential management for ai coding agents
- Manually corrected
- False
Could you build this?
Yes It is a command-line interface written in Go that acts as a secure local credential broker or proxy for development secrets. A solo developer can vibe-code this using standard Go CLI libraries, local encrypted storage (or OS keyring integration), and basic token generation.
Discussion
17 comments analyzed.
Competitors mentioned: Bitwarden (self-hosted password management), Tailscale Aperture (contextual authorization), OneCLI (credential management), System keyrings (macOS, Linux, Windows)
Concerns raised: Server-side secret storage makes it DOA for many users, Agent could persist or leak API keys from environment, Memory inspection vulnerability if agent runs as same user, Unclear custody model and credential storage location, Support for non-OIDC services unclear
Feature requests: Self-hosted deployment option, Support for services without OIDC, Work with direct HTTP calls (curl) not just scripts, eBPF-based approach to inject tokens without abstraction layer, Integration with coding/AI agents
Competitors
Other products that read as similar to this one — 367 launches clear the similarity bar, closest 8 shown.
Attention rank: #59 of 368 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 164 days after the earliest competitor.
- Kontext.dev · hn · 2026-03-16 · 6 upvotes · similarity 0.78
- Agent Vault · hn · 2026-04-22 · 156 upvotes · similarity 0.56
- OneCLI · hn · 2026-07-23 · 110 upvotes · similarity 0.51
- Agents, run any coding agent on your subscription not API costs · hn · 2026-05-31 · 6 upvotes · similarity 0.49
- OneCLI · hn · 2026-03-12 · 161 upvotes · similarity 0.48
- AI Code Review CLI · hn · 2026-03-04 · 5 upvotes · similarity 0.47
- I built an open source multi-agent harness in Go · hn · 2026-04-08 · 6 upvotes · similarity 0.47
- I built an open-source alternative to Claude Cowork · hn · 2026-07-02 · 39 upvotes · similarity 0.46
Other launches for this product
Same idea, different domain
Nobody's really built a dev tools tool for Sales yet.