Agents never hold a real key
Your keys live in an envelope-encrypted vault. Agents get lsh_ tokens: scoped, expiring, revocable. Leak one and you leaked nothing.
LEASH sits between your AI agents and your APIs. Agents never see a real key, and anything they can't take back waits for one tap of your passkey.
Deletes a volume and its backups. This cannot be undone.
Knows what can't be undone on
How it works
Prompts can be ignored. A proxy can't. LEASH is the only thing holding your real keys, so the rules hold even when the agent goes off script.
Your keys live in an envelope-encrypted vault. Agents get lsh_ tokens: scoped, expiring, revocable. Leak one and you leaked nothing.
LEASH knows which calls can't be undone on each API. Those wait for your passkey. One approval covers that exact request, once, for ten minutes.
Every call, hold and decision goes into an append-only log where each entry commits to the one before. Edit a row and the chain breaks.
25 April 2026 · PocketOS
A coding agent fixing staging found an unrelated token in the repo. That token could also delete volumes. It did, and took every volume backup with it.
Try it
Pick what the agent tries. Then approve or deny on the phone, exactly like the real thing.
Simulated in your browser. Nothing is sent, stored, or scanned. Privacy
The irreversible map
Versioned, per provider, each rule tied to the incident or doc that earned it a place. This is what LEASH holds by default.
Setup
Approve the code on your phone with a passkey.
npx leashcli login
Paste it once. It is encrypted and never written to disk.
npx leashcli add github
Claude Code now calls GitHub through LEASH.
claude mcp add leash \ -e LEASH_TOKENS=github=lsh_... \ -- npx -y leashcli mcp
Security
No passwords to phish. The same tap that signs you in approves held calls.
An agent on your laptop can read the CLI's files, so a CLI session can never approve a hold.
A key per secret, wrapped by a master key, bound to its row. Never logged, never returned by any API.
Strict CSP with Trusted Types, HSTS preload, SameSite=Strict cookies, CSRF headers, no CORS.
Rate limits per token and per IP (IPv6 by /64). Upstream redirects are never followed.
Shaped after the IETF draft for agent credential brokers, with optional public receipts.
Pricing
For people shipping with agents daily.