A coding agent wiped a production database in 9 seconds →

Your agents get tokens.
You keep the keys.

LEASH sits between your AI agents and your APIs. Agents never see a real key, and anything they can't take back waits for one tap of your passkey.

Start free
leash.gautamkhosla.com/app

Activity

Live
Heldclaude-code · laptopjust now
POST backboard.railway.app volumeDelete("vol_prod")

Deletes a volume and its backups. This cannot be undone.

Approve with passkeyDeny
    LEASHnow
    Claude Code wants to delete vol_prod
    Held. Tap to review.

    Knows what can't be undone on

    GitHubCloudflareRailwayStripeSupabase

    How it works

    Three rules, enforced outside the model.

    Prompts can be ignored. A proxy can't. LEASH is the only thing holding your real keys, so the rules hold even when the agent goes off script.

    Agents never hold a real key

    Your keys live in an envelope-encrypted vault. Agents get lsh_ tokens: scoped, expiring, revocable. Leak one and you leaked nothing.

    Irreversible means held

    LEASH knows which calls can't be undone on each API. Those wait for your passkey. One approval covers that exact request, once, for ten minutes.

    Everything is on the record

    Every call, hold and decision goes into an append-only log where each entry commits to the one before. Edit a row and the chain breaks.

    25 April 2026 · PocketOS

    Nine seconds. Same agent, same token.

    A coding agent fixing staging found an unrelated token in the repo. That token could also delete volumes. It did, and took every volume backup with it.

    Without LEASH0.0s
    
          
    With LEASH0.0s
    
          

    Try it

    Your agent asks. You decide.

    Pick what the agent tries. Then approve or deny on the phone, exactly like the real thing.

    Simulated in your browser. Nothing is sent, stored, or scanned. Privacy

    claude code
    9:41
    All clearNo calls waiting

    The irreversible map

    Every call you can't take back.

    Versioned, per provider, each rule tied to the incident or doc that earned it a place. This is what LEASH holds by default.

    Setup

    Sixty seconds to leash Claude Code.

    1

    Sign in

    Approve the code on your phone with a passkey.

    npx leashcli login
    2

    Vault a key

    Paste it once. It is encrypted and never written to disk.

    npx leashcli add github
    3

    Connect your agent

    Claude Code now calls GitHub through LEASH.

    claude mcp add leash \
      -e LEASH_TOKENS=github=lsh_... \
      -- npx -y leashcli mcp

    Security

    Built like it guards production. Because it does.

    Passkeys only

    No passwords to phish. The same tap that signs you in approves held calls.

    The CLI can't approve

    An agent on your laptop can read the CLI's files, so a CLI session can never approve a hold.

    Envelope encryption

    A key per secret, wrapped by a master key, bound to its row. Never logged, never returned by any API.

    Locked-down web

    Strict CSP with Trusted Types, HSTS preload, SameSite=Strict cookies, CSRF headers, no CORS.

    Abuse limits

    Rate limits per token and per IP (IPv6 by /64). Upstream redirects are never followed.

    Open standard

    Shaped after the IETF draft for agent credential brokers, with optional public receipts.

    Pricing

    Cheaper than one bad Tuesday.

    Free

    $0

    For one developer.

    • 2 providers
    • 10k calls a month
    • 30 days of audit
    Start free

    Pro

    Popular
    $12/mo

    For people shipping with agents daily.

    • All providers
    • 1M calls a month
    • A year of audit
    • Custom hold rules
    Go Pro

    Team

    $300/mo

    Up to 25 people.

    • Two-person approval
    • SSO
    • Audit export
    Talk to us

    Ship with agents.
    Keep production.

    Start free