<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Agent Credential Gateway on RockB</title><link>https://baeseokjae.github.io/tags/agent-credential-gateway/</link><description>Recent content in Agent Credential Gateway on RockB</description><image><title>RockB</title><url>https://baeseokjae.github.io/images/og-default.png</url><link>https://baeseokjae.github.io/images/og-default.png</link></image><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 30 Sep 2026 15:46:24 +0000</lastBuildDate><atom:link href="https://baeseokjae.github.io/tags/agent-credential-gateway/index.xml" rel="self" type="application/rss+xml"/><item><title>OneCLI Review: The Sandboxed Agent Harness for Teams (YC S26)</title><link>https://baeseokjae.github.io/posts/onecli-sandboxed-agent-harness-teams/</link><pubDate>Wed, 30 Sep 2026 15:46:24 +0000</pubDate><guid>https://baeseokjae.github.io/posts/onecli-sandboxed-agent-harness-teams/</guid><description>OneCLI gives every employee a sandboxed agent whose requests pass a Rust gateway that injects credentials the agent never holds. Hands-on review.</description><content:encoded><![CDATA[<p>A sandboxed agent harness is the layer that gives each AI agent its own isolated computer, routes every outbound request through a policy gateway, and injects credentials at the network boundary so the agent never holds a real key. OneCLI (YC Summer 2026, built by ChartDB Inc.) ships exactly that: one sandboxed agent per employee, all egress forced through a Rust gateway that enforces organization policy before a secret is ever decrypted.</p>
<p>That single sentence also contains the honest problem with reviewing this product in late 2026. The credential boundary it is built around stopped being rare sometime around the middle of the year. Anthropic shipped the same architecture inside Claude Tag, Infisical shipped Agent Vault, and a queue of smaller projects shipped proxy-based lookalikes. OneCLI&rsquo;s own comparison page says so in writing. So the useful question is not &ldquo;does it keep the key out of the agent&rdquo; — several tools now do — but &ldquo;what does OneCLI do that the others structurally cannot.&rdquo;</p>
<p>This review answers that question with the parts that hold up, the parts that do not, and the three failure modes the company itself concedes.</p>
<h2 id="what-is-onecli-and-why-did-it-pivot-from-a-credential-vault-to-an-agent-harness">What Is OneCLI, and Why Did It Pivot From a Credential Vault to an Agent Harness?</h2>
<p>OneCLI is an open-source platform that runs each employee&rsquo;s AI agent inside its own sandbox and forces every outbound network request through a policy-enforcing Rust gateway that injects credentials on the agent&rsquo;s behalf. The project began in March 2026 as a Rust credential vault for AI agents and pivoted in August 2026 into a full agent harness for teams.</p>
<p>The pivot is visible in the launch history. The first Show HN on 2026-03-12 was titled &ldquo;OneCLI – Vault for AI Agents in Rust&rdquo; and reached 161 points. A second Show HN on 2026-07-23 was still framed as a credential gateway. Only the third launch, on 2026-08-19, was the &ldquo;OSS sandboxed agent harness for teams&rdquo; announcement — 88 points and 37 comments, a smaller reception than the original vault launch, which tells you something about how much harder the harness category is to differentiate in.</p>
<p>The company behind it is not a first-time repo owner. ChartDB Inc. previously built ChartDB, an open-source database diagramming tool with more than 20,000 GitHub stars, and the founders bring security-company backgrounds: CEO Jonathan Fishner worked on zero-trust network access at Axis Security (acquired by HPE) and previously in Israeli Military Intelligence.</p>
<p>What OneCLI means by &ldquo;agent&rdquo; is worth stating precisely, because it is not a prompt and not a chat session. An agent is a durable object with its own isolated sandbox containing a filesystem and a shell — a micro-VM on OneCLI Cloud since August 2026 — plus a durable workspace volume that survives park and wake cycles, its own persistent memory and skills, and an identity bound to exactly one employee. The only path out of that sandbox is the gateway. That last constraint is the entire architecture in one line.</p>
<h2 id="the-architecture-component-by-component-dashboard-api-server-rust-gateway-runner-sandbox-supervisor">The Architecture, Component by Component: Dashboard, API Server, Rust Gateway, Runner, Sandbox Supervisor</h2>
<p>The repository layout is nine apps and six packages, and the split is more informative than most architecture diagrams because it shows where trust boundaries sit.</p>
<table>
  <thead>
      <tr>
          <th>Component</th>
          <th>Language / Port</th>
          <th>What it does</th>
          <th>Trust property</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Web dashboard</td>
          <td>Next.js, port 10254</td>
          <td>Create agents, chat, edit memory and skills, manage connections, secrets, grants</td>
          <td>Human control plane</td>
      </tr>
      <tr>
          <td>API server</td>
          <td>Node.js (Hono)</td>
          <td>Owns the database, conversation plane, and the work queue the runner polls</td>
          <td>Control plane</td>
      </tr>
      <tr>
          <td>Gateway</td>
          <td>Rust, port 10255</td>
          <td>Intercepts outbound requests including HTTPS via MITM, enforces policy, injects credentials</td>
          <td>The only egress path</td>
      </tr>
      <tr>
          <td>Runner</td>
          <td>—</td>
          <td>Starts, parks and reaps sandboxes; outbound-only and never touches the database</td>
          <td>Cannot read secrets or data</td>
      </tr>
      <tr>
          <td>Sandbox supervisor</td>
          <td>Inside each sandbox</td>
          <td>Speaks a vendor-neutral harness interface so the runtime is swappable</td>
          <td>Untrusted</td>
      </tr>
      <tr>
          <td>Channel adapter</td>
          <td>Slack daemon</td>
          <td>Posts answers, mirrors, and approval cards</td>
          <td>Notification surface</td>
      </tr>
      <tr>
          <td>Secret store</td>
          <td>—</td>
          <td>AES-256-GCM encrypted at rest, decrypted only at request time, matched by host and path pattern</td>
          <td>Decrypted after policy</td>
      </tr>
      <tr>
          <td>Database</td>
          <td>PostgreSQL</td>
          <td>Control-plane state</td>
          <td>Never reachable from a sandbox</td>
      </tr>
  </tbody>
</table>
<p>Three design decisions in that table are load-bearing.</p>
<p>First, the gateway is the only way out. There is no second egress path, so a policy that blocks <code>api.stripe.com</code> is not a suggestion the agent can route around by using <code>curl</code> instead of a tool call. This is the direct answer to the vendor&rsquo;s own argument that an MCP gateway sees only a slice of agent traffic: an agent with a shell reaches APIs four ways — MCP tool calls, CLIs like <code>gh</code>/<code>aws</code>/<code>stripe</code>, raw <code>curl</code>, and code it writes itself — and a gate on one of those is a gate with three doors beside it.</p>
<p>Second, the runner is deliberately crippled. It starts, parks and reaps sandboxes but never touches the database. That means the component with the most direct control over sandbox lifecycle holds no secrets and no customer data, which is a meaningful reduction in what a compromise of that service buys an attacker.</p>
<p>Third, the sandbox supervisor speaks a vendor-neutral harness interface. The agent runtime is swappable by design, which is how <code>onecli run -- claude</code> works and why the product is not locked to one model vendor.</p>
<p>There are 40+ managed integrations with OAuth or API-key injection: Gmail, Google Calendar/Drive/Docs/Sheets and the rest of Workspace, Outlook Mail and Calendar, GitHub and GitHub App, Notion, Jira, Confluence, Slack, AWS with automatic SigV4 request signing, Cloudflare, Salesforce, HubSpot, Attio, Apollo.io, Clay, Datadog, Sentry, PostHog, Supabase, MongoDB Atlas, Dropbox, Zoom, LinkedIn, Monday.com, Todoist, Fly.io, Resend, Vertex AI, and the Anthropic and OpenAI APIs. External vaults are supported too: 1Password via service accounts and <code>op://</code> references, and Bitwarden through its Agent Access SDK. OneCLI was listed on the 1Password Marketplace on 2026-07-20.</p>
<h2 id="how-a-single-request-gets-decided-policy-before-credentials-approval-as-a-held-request">How a Single Request Gets Decided: Policy Before Credentials, Approval as a Held Request</h2>
<p>The request flow is where this product earns or loses its claim, so it is worth walking through one call end to end.</p>
<p>An agent issues a normal HTTP request — say <code>GET https://www.googleapis.com/calendar/v3/events</code>. The gateway evaluates policy across two layers, top-down, first match wins: organization rules first (a ceiling that no project can loosen), then project-level access compiled automatically from that agent&rsquo;s grants. Each layer ends in a Default Rule of Allow or Block, and a request is permitted only when both layers permit it. Blocked returns 403 and rate-limited returns 429 immediately.</p>
<p>Approval-gated requests pause for a human decision. A card appears in Slack or the dashboard, and expiry denies rather than allowing. If the request survives policy, the gateway matches the target host and path against the credentials granted to that specific agent, decrypts the match, and injects it as a header or URL query parameter. A credential the agent has no grant for is never considered at all. The request forwards with credentials attached, and the response passes back unchanged.</p>
<p>The critical property is the ordering: <strong>policy is evaluated before credential injection</strong>, so a blocked request never decrypts or touches a secret. That is a genuinely better failure mode than a system that authenticates first and then checks permissions.</p>
<p>The policy engine has four details that matter in practice.</p>
<ul>
<li><strong>Approval is deterministic, not model-mediated.</strong> The held request binds to the exact proposed request — method, URL and body — and the parsed payload is rendered in the approval card, so the human approves a specific action rather than a described intention.</li>
<li><strong>Organization rule edits are staged.</strong> Changes go into a draft and enforce only on publish; the gateway keeps enforcing the last published set throughout. Agent grants, by contrast, take effect immediately. That asymmetry is the right way round: broad policy changes are reviewable, narrow ones are fast.</li>
<li><strong>Per-tool access is tri-state.</strong> Connection grants can be full access or custom with Allow, Ask, or Never per tool, and any tool not named is blocked. Secret grants are all-or-nothing with no tool lists, which is a real granularity gap.</li>
<li><strong>New agents start with nothing.</strong> No grants, no injected credentials, and no credential stubs in the container config.</li>
</ul>
<p>That last point is the strongest quantitative argument in the whole product, and the industry data backs it. The Cloud Security Alliance survey published 2026-04-21 — 418 IT and security professionals, commissioned by Token Security — found that only <strong>11% of organizations automatically block an agent action that exceeds its scope</strong>. A further 38% require human approval and 24% require it be logged. &ldquo;A prompt is a suggestion; a gateway is a guarantee&rdquo; is a defensible architectural claim rather than marketing, and it is the one claim in this review that survived every counterexample I could construct.</p>
<h2 id="what-onecli-actually-does-differently-per-employee-identity-an-org-policy-ceiling-and-self-hosting">What OneCLI Actually Does Differently: Per-Employee Identity, an Org Policy Ceiling, and Self-Hosting</h2>
<p>Strip away the parts of the credential story that are now commodity and three things remain.</p>
<p><strong>1. Access follows the person, not a channel or a bot.</strong> Anthropic&rsquo;s Claude Tag binds service accounts to a Slack channel, and Anthropic is explicit that a channel member without direct repository access can ask Claude to read that repository if the channel&rsquo;s profile grants it. OneCLI&rsquo;s unit of access is the employee, scoped to what that person already has. Joining a channel widens nothing, because the agent&rsquo;s grants are bound to the human identity behind it. That is a meaningfully different security model, not a repackaging of the same one.</p>
<p><strong>2. The organization policy ceiling cannot be loosened from below.</strong> Because org rules evaluate before project-level grants and a request needs both layers to allow it, a well-meaning team lead cannot grant an agent access that the security function forbade. Most credential proxies give you per-agent or per-project policy and leave the global ceiling as an operational convention. Making it structural is the difference between a rule and an invariant.</p>
<p><strong>3. It self-hosts, and it self-hosts the important parts.</strong> The repository is Apache-2.0 with one carve-out: three paths (<code>apps/web/src/ee/</code>, <code>packages/api/src/ee/</code>, <code>apps/gateway/crates/ee/</code>) fall under the OneCLI Enterprise License, free for development, testing and evaluation, with production use requiring a subscription. The license file states that everything outside those paths is Apache-2.0 and self-hostable in production with no commercial license. The self-hosted Community edition is a single Docker container plus PostgreSQL.</p>
<p>For teams whose objection to a hosted agent platform is data residency or vendor dependency, point three is the deciding factor — and it is the one Claude Tag will never match.</p>
<p>The fourth, weaker advantage is distribution. NanoClaw — 30,863 stars, MIT, and arguably the leading container-isolated agent runtime — adopted OneCLI&rsquo;s agent vault as its <strong>default</strong> credential and proxying layer on 2026-03-24, replacing a credential proxy it had written itself. That adoption predates the YC announcement by five months, and it also explains the star count skepticism on launch day. When a commenter asked how the repository could have 3,200 stars when the demo video had 38 views, the honest answer was that the repo dates to March 2026 and had been the default credential layer for a 30K-star project for two quarters. That is distribution earned, not bought.</p>
<h2 id="what-is-not-a-differentiator-anymore-claude-tag-infisical-agent-vault-and-the-2026-credential-boundary">What Is Not a Differentiator Anymore: Claude Tag, Infisical Agent Vault, and the 2026 Credential Boundary</h2>
<p>In 2026 the credential boundary is table stakes. Four direct comparisons make the point, and OneCLI&rsquo;s own documentation concedes most of it.</p>
<table>
  <thead>
      <tr>
          <th>Product</th>
          <th>Credential boundary</th>
          <th>Unit of access</th>
          <th>Approval model</th>
          <th>Self-host</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><strong>OneCLI</strong></td>
          <td>MITM gateway, outbound-only Runner, policy before decryption</td>
          <td>Employee</td>
          <td>Held request with parsed payload card; expiry denies</td>
          <td>Yes, Apache-2.0 outside <code>ee/</code></td>
      </tr>
      <tr>
          <td><strong>Claude Tag</strong></td>
          <td>Stored independently, injected at the network boundary, egress default-deny</td>
          <td>Slack channel / service account</td>
          <td>Spend limits and host allowlists; per-action grants listed as &ldquo;what&rsquo;s next&rdquo;</td>
          <td>No</td>
      </tr>
      <tr>
          <td><strong>Infisical Agent Vault</strong></td>
          <td>HTTP credential proxy; dummy values like <code>__anthropic_api_key__</code> swapped on the way out</td>
          <td>Project / agent</td>
          <td>Policy plus egress filtering</td>
          <td>Yes, MIT with <code>ee/</code> carve-out</td>
      </tr>
      <tr>
          <td><strong>TrueFoundry TrueForge</strong></td>
          <td>Scoped credentials in a sandbox</td>
          <td>Tool call, gated centrally</td>
          <td>Central human-in-the-loop approvals</td>
          <td>Yes, MIT</td>
      </tr>
      <tr>
          <td><strong>OpenClaw</strong></td>
          <td>None — real API keys in plaintext config on the host</td>
          <td>Single person, single machine</td>
          <td>In-loop command approval prompts and DM pairing</td>
          <td>Yes, but per-person installs</td>
      </tr>
  </tbody>
</table>
<p>Anthropic&rsquo;s agent identity post describes the credential as stored independently, mapped to the channel&rsquo;s identity, and injected at the network boundary at request time, with unlisted hosts blocked and egress default-deny. OneCLI&rsquo;s comparison page concedes in writing that this is the architecture it argues for. Against Claude Tag, credential injection is agreement, not differentiation — the difference is the identity model and the approval timing.</p>
<p>Infisical Agent Vault is the closest architectural twin. It substitutes dummy header values for real ones on outbound requests and is deliberately interface-agnostic, bootstrapping agents to use <code>HTTPS_PROXY</code> so MCP calls, CLIs, SDKs and plain API calls all route through it. It is published by an established secrets vendor with 29,528 stars on its main repository, and it has one capability OneCLI does not match natively: pluggable credential stores, so the vault can be backed by Infisical or HashiCorp Vault, including dynamic secrets, instead of a local encrypted store.</p>
<p>It also has one default worth flagging in the opposite direction. Infisical&rsquo;s vault defaults to <strong>pass-through</strong> for unmatched hosts; strict deny mode requires explicitly setting <code>unmatched_host_policy=deny</code>. A fail-open default in a security boundary is the kind of thing that looks fine in a demo and matters in an incident. Infisical&rsquo;s own README labels the product Preview with an API subject to change, which is honest but relevant.</p>
<p>TrueFoundry TrueForge attacks the harness axis rather than the credential axis: an MIT-licensed, vendor-neutral harness where models, MCP servers and sandbox are all bring-your-own. It overlaps OneCLI v2 substantially — scoped credentials, human-in-the-loop approvals, a versioned <code>SKILL.md</code> skills registry with RBAC mounted into the sandbox on demand, every tool call logged and policy-checked. Its approvals are tool-call scoped, which is exactly the coverage gap OneCLI&rsquo;s &ldquo;your MCP gateway cannot see most of what your agent does&rdquo; argument targets. TrueForge comes from an existing commercial infrastructure vendor, so it brings enterprise go-to-market that a seed-stage team does not.</p>
<p>And OpenClaw — 390,873 stars, the most-starred repository on GitHub — is the incumbent OneCLI defines itself against. OneCLI&rsquo;s comparison page opens with credit rather than attack, noting that OpenClaw went from weekend project to most-starred repo in under five months and that nearly everything in the category, including OneCLI, exists downstream of it. The substantive critique is about the fortieth install, not the first: forty unmanaged machines, forty copies of credentials in config files, nobody able to answer which agent touched the billing API last Tuesday, and offboarding that means finding a machine and rotating every key on it.</p>
<h2 id="does-policy-enforcement-solve-prompt-injection-no--here-is-the-provenance-blind-spot">Does Policy Enforcement Solve Prompt Injection? No — Here Is the Provenance Blind Spot</h2>
<p>This is the strongest technical criticism of the product, and it deserves its own section because it is not fixed by better engineering.</p>
<p>A gateway matching on method, path and host cannot tell what entered the context window three steps earlier. <code>GET /customers?limit=5000</code> looks identical whether the operator asked for it or a retrieved document did. The gateway is a confused-deputy boundary that is blind to provenance: it sees a well-formed, correctly authenticated request from an agent that legitimately holds a grant for that endpoint.</p>
<p>OneCLI&rsquo;s mitigations are real but partial. Approval binds to the exact proposed request, and the parsed payload is rendered in the card so the human sees what will actually be sent. Granularity reaches sub-endpoint level — <code>GET /calendar/v3/*</code> can be allowed freely while <code>POST</code> requires approval. And the design eliminates one entire class of outcome: the agent cannot leak a credential it never holds.</p>
<p>But there is a boundary case nobody in this category has solved. &ldquo;Summarize this document and email it to Bob&rdquo; legitimately originates in untrusted content, so pure provenance tracing cannot distinguish the intended task from an injection that emails everything to an attacker. The company says as much in its own writing: not holding the secrets does not make the agent harmless. When I asked whether OneCLI stops prompt injection, the correct answer is no, and the vendor does not claim otherwise.</p>
<p>The evidence supports that framing. Tachyon&rsquo;s analysis &ldquo;Sandboxes Won&rsquo;t Save You From OpenClaw&rdquo; (2026-02-25, 112 points and 103 comments on HN) found that in every major reported OpenClaw incident, the failure involved a third-party service the user had explicitly connected — not a sandbox escape. The most common real-world damage from a prompt-injected agent is misuse of access that was deliberately granted. A gateway that controls reach is directly relevant to that threat; a sandbox alone is not.</p>
<p>The broader data says most organizations are not even at the starting line. The CSA/Token Security survey found that <strong>65% of organizations experienced at least one AI agent-related security incident in the past 12 months</strong>, with consequences including data exposure (61%), operational disruption (43%) and financial cost (35%) — and no respondent reported zero material business impact. <strong>82% discovered at least one agent or autonomous workflow created without the knowledge of their security, IT or governance teams</strong>, and 41% said it happened multiple times. The detail that should unsettle anyone relying on self-assessment: <strong>68% of those same organizations believed they had strong visibility into their agents</strong>.</p>
<h2 id="credential-isolation-is-not-blast-radius-control--stack-it-with-a-sandbox">Credential Isolation Is Not Blast-Radius Control — Stack It With a Sandbox</h2>
<p>A placeholder key stops an agent from carrying a secret out. It does nothing about an agent misusing a service it was legitimately granted, and it does nothing about an agent wrecking its own filesystem. Those are different controls.</p>
<p>The cleanest way to hold the three apart is to name what each one bounds. Sandboxing bounds local damage. A gateway bounds reach. Identity binds action to a person who can be offboarded. NanoClaw&rsquo;s own framing after adopting OneCLI&rsquo;s vault draws the line precisely: NanoClaw solves runtime isolation, OneCLI solves credential isolation and policy enforcement. That is the honest answer to &ldquo;do I need OneCLI if I already containerize my agents.&rdquo;</p>
<p>The isolation half is not solved either. Sandbox bypasses recur in the agent tooling itself — CVE-2026-39861 was a Claude Code sandbox escape via symlink following that allowed arbitrary file write outside the workspace, reported 2026-05-08 with CVSS v4 severity high, network attack vector and low attack complexity. OSV.dev lists a cluster of related Claude Code symlink and permission-deny-bypass advisories, including CVE-2025-59829 (fixed in 1.0.120) and CVE-2026-25724 (fixed in 2.1.7). The tool you trust to enforce permissions is itself a moving target.</p>
<p>There is also a trust shift that gets under-discussed. Injection only works by terminating TLS, which means installing a CA certificate into the agent&rsquo;s trust store. Some runtimes ignore <code>HTTP_PROXY</code> — Node historically did, though Node 24+ honours it with <code>NODE_USE_ENV_PROXY=1</code>. And AWS access keys cannot be handled by simple token substitution: the request must be re-signed with SigV4, which OneCLI does explicitly, and which is a real engineering detail rather than a checkbox. If a tool you depend on ignores proxy environment variables and has no CA installed, it escapes the boundary silently. Test that, do not assume it.</p>
<p>The scale of what is being protected puts the boundary question in context. GitGuardian&rsquo;s State of Secrets Sprawl 2026 counted <strong>28,649,024 new secrets detected in public GitHub commits in 2025, up 34% year over year</strong> — the largest single-year jump on record. Secret sprawl is not shrinking; the agent layer is being bolted on top of a problem that was already growing.</p>
<h2 id="pricing-and-editions-what-the-free-community-self-host-does-not-include">Pricing and Editions: What the Free Community Self-Host Does Not Include</h2>
<p>Published pricing is unusual in a crowded category: there is a real free tier and it is not a trial.</p>
<table>
  <thead>
      <tr>
          <th>Plan</th>
          <th>Price</th>
          <th>Seats</th>
          <th>Agents</th>
          <th>Notes</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Free</td>
          <td>$0</td>
          <td>3</td>
          <td>3</td>
          <td>Free forever, no credit card; $5 AI credits, 500 integration calls/mo, 7-day audit logs</td>
      </tr>
      <tr>
          <td>Team</td>
          <td>$499/mo</td>
          <td>5</td>
          <td>10</td>
          <td>$149/mo if you bring your own Anthropic/OpenAI key; 30-day audit logs</td>
      </tr>
      <tr>
          <td>Scale</td>
          <td>$1,999/mo</td>
          <td>10</td>
          <td>20</td>
          <td>$499/mo with your own LLM key; 90-day audit logs</td>
      </tr>
      <tr>
          <td>Extra seats</td>
          <td>$199 or $49/user/mo</td>
          <td>—</td>
          <td>—</td>
          <td>$199 with hosted models, $49 bring-your-own</td>
      </tr>
      <tr>
          <td>Enterprise</td>
          <td>Custom</td>
          <td>Custom</td>
          <td>Custom</td>
          <td>Self-hosted in your cloud, VPC or on-prem</td>
      </tr>
  </tbody>
</table>
<p>Two details in that table are more generous than the headline numbers suggest: humans never count as agents, and all integrations are included on every plan with no metering on integration calls. Audit log retention is metered instead, which is a rarer and arguably fairer axis.</p>
<p>The self-hosted editions are where buyers need to read carefully, because the free Community edition omits the features the product&rsquo;s own marketing treats as the reason to pick it over a coding-agent wrapper.</p>
<table>
  <thead>
      <tr>
          <th>Capability</th>
          <th>Community (free, self-host)</th>
          <th>Enterprise (self-host)</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Per-agent access: grants, per-tool allow/block</td>
          <td>Yes</td>
          <td>Yes</td>
      </tr>
      <tr>
          <td>Manual approval on grants and rules</td>
          <td><strong>No</strong></td>
          <td>Yes</td>
      </tr>
      <tr>
          <td>Organization policy console</td>
          <td><strong>No</strong></td>
          <td>Yes</td>
      </tr>
      <tr>
          <td>Premium app integrations</td>
          <td>No</td>
          <td>Yes</td>
      </tr>
      <tr>
          <td>Organization API key for headless provisioning</td>
          <td>No</td>
          <td>Yes</td>
      </tr>
      <tr>
          <td>Deployment</td>
          <td><code>ghcr.io/onecli/onecli</code>, one container + PostgreSQL</td>
          <td><code>onecli/slim</code> all-in-one image, under contract</td>
      </tr>
  </tbody>
</table>
<p>Teams evaluating the free edition should read the edition matrix before assuming parity, because the two missing features are precisely the ones that make this a teams product rather than a credential proxy. A self-hosted free deployment of OneCLI Community with approvals disabled is closer to Infisical Agent Vault than to the product described on the marketing page. A connector deployment — cloud dashboard plus an in-network gateway and database — is announced as coming, which will be the deployment shape many regulated buyers actually want.</p>
<h2 id="where-onecli-fits-in-a-real-stack-and-when-to-pick-something-else">Where OneCLI Fits in a Real Stack, and When To Pick Something Else</h2>
<p>The category keeps collapsing three distinct controls into one purchase decision, and that is why evaluations go sideways.</p>
<p><strong>Buy OneCLI if</strong> you have more than a handful of people running agents, the credentials are the thing keeping you up at night, you need an org-level ceiling that individual teams cannot weaken, and self-hosting is a requirement rather than a preference. The per-employee identity binding is the part no competitor currently matches at the same depth, and offboarding — revoke the person and the agent stops resolving credentials on the next request — maps directly onto the retirement-debt problem. Only <strong>21% of organizations have a formal AI agent decommissioning process</strong>, and only 19% are highly confident that agents are fully retired when no longer needed, per the CSA survey.</p>
<p><strong>Do not buy OneCLI</strong> expecting it to make prompt injection harmless, expecting the free Community edition to cover your approvals workflow, or expecting credential isolation to replace a sandbox. Each of those expectations is wrong for a different reason covered above.</p>
<p><strong>Consider the alternatives</strong> on these triggers: pick Infisical Agent Vault if you already run Infisical or HashiCorp Vault and want dynamic secrets with a pluggable backend — but set <code>unmatched_host_policy=deny</code> on day one. Pick Claude Tag if your agents live in Slack, your team is too small to run infrastructure, and channel-scoped access is an acceptable model. Pick TrueForge if the harness and skills registry matter more than the credential boundary, or if you want an established vendor&rsquo;s support contract. Pick plain container isolation with no gateway only if your agents hold no credentials — which, if you have read this far, they probably do.</p>
<h2 id="frequently-asked-questions">Frequently Asked Questions</h2>
<h3 id="is-onecli-really-open-source">Is OneCLI really open source?</h3>
<p>Mostly, with a carve-out worth reading before you plan a deployment. The repository is Apache-2.0 except for three paths — <code>apps/web/src/ee/</code>, <code>packages/api/src/ee/</code> and <code>apps/gateway/crates/ee/</code> — which carry the OneCLI Enterprise License: free for development, testing and evaluation, with production use requiring a subscription. The license file states that everything outside those paths is Apache-2.0 and self-hostable in production with no commercial license. The <code>ee/</code> folder is not visible at the repository root, which is why a commenter on the Launch HN thread asked where it was.</p>
<h3 id="does-onecli-stop-prompt-injection">Does OneCLI stop prompt injection?</h3>
<p>No, and the company does not claim it does. It removes one consequence — the agent cannot leak a credential it never holds — and it gives you a deterministic place to block or approve individual requests. A prompt-injected agent can still misuse a service you legitimately granted it, and a gateway matching on host, method, path and body cannot tell whether the instruction behind a request came from you or from a retrieved document. Treat OneCLI as blast-radius and reach control, not as injection defense.</p>
<h3 id="do-i-still-need-a-sandbox-if-i-use-onecli">Do I still need a sandbox if I use OneCLI?</h3>
<p>Yes. OneCLI does run each agent in its own sandbox — a micro-VM on OneCLI Cloud — but the sandbox and the gateway solve different problems. The sandbox bounds what the agent can break locally; the gateway bounds what it can reach externally. NanoClaw&rsquo;s own framing after adopting OneCLI is exactly this split: NanoClaw solves runtime isolation, OneCLI solves credential isolation and policy enforcement. Run both, and remember that sandbox escapes recur in the tooling itself, as CVE-2026-39861 in Claude Code showed.</p>
<h3 id="what-does-onecli-cost">What does OneCLI cost?</h3>
<p>Cloud pricing is $0 free forever with 3 seats, 3 agents, $5 in AI credits and 500 integration calls per month; Team at $499/mo for 5 users and 10 agents, dropping to $149/mo if you bring your own Anthropic or OpenAI key; Scale at $1,999/mo for 10 users and 20 agents, or $499/mo with your own key. Extra seats run $199/user/mo with hosted models or $49/user/mo bring-your-own. The self-hosted Community edition is free and Enterprise is by contract. Audit log retention is the metered axis: 7 days free, 30 days Team, 90 days Scale.</p>
<h3 id="how-is-onecli-different-from-a-secrets-manager-like-vault-or-1password">How is OneCLI different from a secrets manager like Vault or 1Password?</h3>
<p>A vault protects the secret at rest but hands the real value to whatever fetches it, so once the agent holds the key the vault is out of the picture entirely. OneCLI keeps the credential out of the agent and injects it into the outbound request only after policy allows it — with policy evaluated before decryption, so a blocked request never touches a secret. It also connects to 1Password and Bitwarden as external vaults, so the two categories complement rather than compete. The structural difference to remember: a vault answers &ldquo;who can read this secret,&rdquo; a gateway answers &ldquo;what can this agent do with it.&rdquo;</p>
<h2 id="the-verdict">The Verdict</h2>
<p>OneCLI is a well-engineered product that arrived at a credential-boundary architecture the market had already converged on, and it is honest about that convergence in its own comparison pages. What survives the comparison is narrower than the launch post suggests but more durable than a feature list: one agent per employee with access bound to the person, an organization policy ceiling that no project grant can loosen, deterministic approval evaluated before any secret is decrypted, and a genuinely self-hostable production deployment. Against Claude Tag, that is a different security model rather than a better implementation of the same one. Against Infisical, it is a stricter default. Against TrueForge, it is a deeper credential story and a shallower harness story.</p>
<p>Three cautions stand. Credential isolation is not blast-radius control, and the provenance blindness of any request-matching gateway is unsolved across the entire category. The free Community self-host omits manual approvals and the org policy console — the two features that make this a teams product — so evaluate the paid tier or Enterprise before concluding it fits. And the market is crowded enough that the top-voted question on the Launch HN thread was literally how the company wins in this space, with a co-founder answer that amounted to &ldquo;we are not sure yet, we believe it lands with security-minded buyers.&rdquo; That is a more useful datapoint than any feature grid, and it should sit in your evaluation next to the 3,532 stars.</p>
<p>If the credential boundary is your blocker and you run agents for a team rather than for yourself, OneCLI is worth a self-hosted pilot this quarter. If your agents hold no credentials, or you need the sandbox rather than the gateway, spend the effort elsewhere. For the surrounding layers, see our guides on <a href="/posts/kontext-credential-broker-guide-2026/">agent credential brokers</a>, <a href="/posts/ai-agent-identity-framework-guide-2026/">AI agent identity frameworks</a>, <a href="/posts/ai-agent-hacked-own-permissions/">agent permission boundaries</a>, <a href="/posts/1password-unified-access-ai-agents-2026/">unified access for AI agents</a>, and <a href="/posts/peta-ai-agent-credential-guide-2026/">agentic credential management</a>.</p>
]]></content:encoded></item></channel></rss>