Show HN: OneCLI – OSS Credential Gateway That Keeps Secrets Out Of AI Agents
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

FOR BUSINESS

Open a free Amazon Business account

Business pricing, bulk buying and tax-exempt orders.

Create a free account

As an affiliate, we earn on qualifying purchases.

OneCLI is an open source credential gateway designed to prevent secrets from being embedded in AI agents. It aims to improve security by acting as a centralized vault for credentials. The project was announced on Hacker News by its creators, Jonathan and Guy.

Developers Jonathan and Guy announced the launch of OneCLI, an open source credential gateway designed to prevent secrets from being stored directly within AI agents. The project aims to address security concerns related to exposing sensitive credentials in AI workflows, offering a centralized vault that manages secrets securely outside of the AI environment.

OneCLI is an open source tool that acts as a credential gateway, enabling AI agents to access secrets without storing them locally or embedding them directly into code. The creators describe it as a solution to improve security and privacy, especially as AI systems increasingly handle sensitive data. The project is hosted on GitHub and was shared via a posting on Hacker News by the developers, who emphasized its open source nature and potential for community collaboration.

The tool functions as a vault that securely manages credentials, allowing AI agents to fetch secrets dynamically at runtime without exposing them in code or logs. According to the creators, this approach mitigates risks associated with secret leakage, which is a common concern in AI deployment pipelines. The announcement includes a link to the project repository (https://onecli.sh), inviting developers to try and contribute to the project.

At a glance
announcementWhen: announced on Hacker News, recent public…
The developmentThe developers of OneCLI announced an open source credential gateway that enhances security for AI agents by keeping secrets out of them.

Potential Impact on AI Security and Privacy

OneCLI addresses a critical security challenge in AI development: preventing sensitive secrets from being embedded or exposed in AI agents. As AI systems become more integrated into business and personal workflows, the risk of credential leakage increases. By providing a centralized, open source vault, OneCLI could significantly reduce these risks, fostering more secure AI deployments. Its open source nature also encourages community-driven improvements, which could lead to broader adoption and integration into existing AI pipelines.

Amazon

hardware security key for developers

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Security Challenges in AI Credential Management

Recent years have seen increasing concerns about security vulnerabilities in AI workflows, especially regarding secret management. Developers often embed API keys, tokens, and other credentials directly into code or logs, leading to potential leaks. Traditional vault solutions exist but can be complex or proprietary. The rise of open source projects like OneCLI reflects a growing desire for transparent, customizable security tools tailored for AI environments. The announcement on Hacker News signals community interest in addressing these issues collaboratively.

“Our goal is to make secret management more accessible for developers working with AI, without sacrificing security.”

— Guy, co-creator of OneCLI

Amazon

secure credential vault software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Extent of Adoption and Integration Challenges

It is not yet clear how widely adopted OneCLI will become within the AI developer community or how easily it will integrate with existing tools and workflows. As an open source project, its success depends on community engagement, contributions, and real-world testing. Additionally, the security effectiveness of the tool in various deployment environments remains to be validated through broader use and feedback.

Amazon

API key management tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Next Steps for Community Engagement and Development

Developers and organizations interested in improving AI security are expected to evaluate OneCLI through testing and integration into their workflows. The project maintainers plan to gather feedback, improve functionality, and potentially add features based on community input. Further updates and version releases are anticipated as the project matures, with ongoing efforts to promote adoption and address any emerging security concerns.

Amazon

secret management hardware

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

How does OneCLI improve security for AI agents?

It acts as a centralized vault, allowing AI agents to fetch secrets dynamically without storing them locally or embedding them in code, reducing the risk of leakage.

Is OneCLI open source?

Yes, it is fully open source and hosted on GitHub, inviting community contributions and customization.

Can OneCLI integrate with existing AI tools?

The project aims to be flexible, but integration ease depends on the specific tools and workflows. Community feedback will shape future compatibility.

What security guarantees does OneCLI provide?

While designed to keep secrets out of AI agents, the actual security depends on proper implementation and environment setup. Broader testing is ongoing.

What are the main challenges for adopting OneCLI?

Potential challenges include integration complexity, community adoption, and ensuring security effectiveness across diverse deployment scenarios.

Source: hn

LABOR DAY SALES

Labor Day sales Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

Exploiting System Management Mode With A Very Long Interrupt

Researchers reveal a vulnerability allowing attackers to exploit System Management Mode via very long interrupts, raising concerns over hardware security.

Paged Out #9 [Pdf]

The ninth issue of Paged Out has been officially released as a PDF, making it accessible to readers worldwide. Details on content and distribution confirmed.

Critical CVE Issued For Hallucinated SQLite Vulnerability

A critical CVE has been issued for a newly identified SQLite vulnerability related to hallucinated data, raising security concerns worldwide.

Biggest Breaches of 2025: What We’ve Learned (or Not)

The biggest breaches of 2025 reveal troubling gaps in security, leaving us to wonder what lessons are still being overlooked and how to prevent future attacks.