frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Keychains – Prevent LLM/OpenClaw agents from leaking API credentials

https://keychains.dev/
1•severin•1h ago
Hi HN — I’m a heavy OpenClaw user and, like many others, I’ve been thinking about how to give these new “unleashed” agents secure access to my accounts.

Agents need API access to be useful. But API keys are long-lived secrets. And agents are not secure environments.

So I built something for myself that quickly turned into a product: keychains.dev.

The idea is simple: agents never see raw credentials.

With Keychains.dev:

• Agents make API calls via a drop-in replacement for curl or JavaScript’s fetch() • They use template variable names instead of embedding credentials • The request is proxied through keychains.dev • The proxy analyzes the target endpoint and determines the minimal OAuth scopes required • It attempts to fulfill the request using credentials stored server-side • If credentials are missing — or the agent isn’t approved for that action — it returns an approval link • The agent forwards that link to its human for authorization

This creates a user-in-the-loop escalation model instead of blind credential injection.

Security-wise:

• Agents can make requests without ever touching credentials (protects against prompt-injection exfiltration) • Credentials cannot be replayed to arbitrary endpoints — they’re bound to the issuing provider • Each agent machine is authenticated via SSH keypair + stateful fingerprinting (keys can’t be reused elsewhere, instant revocation) • Agents can delegate scoped credentials to sandboxed sub-agents if needed • Users approve new permissions via FaceID/TouchID in the browser • Full audit trail of every request, with granular revocation at the agent, sub-agent, or scope level

Even if a private key is stolen, permissions can be revoked immediately and tokens are short-lived.

I currently support delegation across 6,754 APIs, but the core idea isn’t the number — it’s controlled delegation with human approval on escalation (+ any API you can reach with curl is compatible).

WDYT?

I’d really appreciate feedback on: – Whether this matches your threat model for agents – If user-in-the-loop escalation feels practical – How you're handling credential security today

Happy to answer technical questions.

The latest design problem? Getting a job

https://carly.substack.com/p/the-latest-design-problem-getting
1•herbertl•42s ago•0 comments

Stephen Colbert going down swinging

https://www.nytimes.com/2026/02/18/arts/television/stephen-colbert-cbs-statement.html
2•-0•2m ago•0 comments

The Ricoh Printing Experience

https://eidel.io/the-ricoh-printing-experience/
2•olieidel•6m ago•0 comments

Show HN: Agentpriv – Sudo for AI Agents

https://github.com/nichkej/agentpriv
1•nichkej•6m ago•0 comments

The Ozempic Effect: How McDonald's Is Reinventing Fast Food

https://ariatatrezvalthazar.blogspot.com/2026/02/the-ozempic-effect-how-mcdonalds-is.html
1•Traumen•7m ago•0 comments

I've Disallowed LLMs

https://ylan.segal-family.com/blog/2026/02/17/ive-disallowed-llms/
1•speckx•9m ago•0 comments

Open sourcing the Liveblocks sync engine and dev server

https://liveblocks.io/blog/open-sourcing-the-liveblocks-sync-engine-and-dev-server
4•ctnicholas•9m ago•1 comments

Show HN: Turn any OpenAPI spec into agent-callable skills

https://neutree.ai/projects/openapi-to-skills
1•yz-yu•10m ago•0 comments

Show HN: A pay-per-request API to search social media posts

https://apidirect.io/
1•joshwaller7•10m ago•0 comments

Show HN: VectorNest responsive web-based SVG editor

https://ekrsulov.github.io/vectornest/
2•ekrsulov•12m ago•0 comments

Reddit and Discord users forced to use biometric ID system backed by Palantir

https://www.openrightsgroup.org/press-releases/roblox-reddit-and-discord-users-compelled-to-use-b...
2•robtherobber•13m ago•0 comments

Detection of Spoilage-Associated Acetic Acid Levels Using a Whole-Cell Biosensor

https://enviromicro-journals.onlinelibrary.wiley.com/doi/10.1111/1751-7915.70267
1•PaulHoule•14m ago•0 comments

What Cooking Tells Us About AI

https://nik.art/what-cooking-tells-us-about-ai/
2•herbertl•14m ago•1 comments

Extracting Financial Data Using LLMs Without Reading Every Email

https://github.com/brainless/dwata/blob/feature/reverse-template-based-financial-data-extraction/...
1•brainless•15m ago•0 comments

FDA No Longer Warns Against Ineffective Autism Treatments Like Chlorine Dioxide

https://www.propublica.org/article/rfk-jr-fda-removes-autism-treatments-warning
3•hn_acker•16m ago•1 comments

Show HN: Free Windows shell extension for quick .NET assembly inspection

https://github.com/tebjan/AssemblyInformation
1•tebjan•16m ago•0 comments

After Microsoft's AI overreach, Gentoo begins its march away from GitHub

https://www.pcgamer.com/software/linux/after-microsoft-couldnt-keep-its-ai-hands-to-itself-a-noto...
4•stalfosknight•18m ago•0 comments

Experiential Reinforcement Learning

https://arxiv.org/abs/2602.13949
2•geophile•20m ago•0 comments

If you're always listening to an audiobook, you're not alone

https://www.washingtonpost.com/books/2026/02/11/audiobook-listening-trends/
1•randycupertino•21m ago•1 comments

Show HN: Mock any HTTP request from DevTools, with AI-generation and zero setup

https://mockstudio.app
1•denyherianto•22m ago•0 comments

Show HN: Poncho, a general agent harness built for the web

https://github.com/cesr/poncho-ai
2•heycesr•23m ago•0 comments

What determines whether a post gets visibility on Hacker News

1•beratbozkurt0•23m ago•1 comments

Breccia: Single-file, append-only, blob storage with efficient random access

https://github.com/petertodd/breccia/blob/master/DESIGN.md
1•StingyJelly•25m ago•0 comments

Perpetual Calendar

https://www.ochsundjunior.swiss/watches/perpetual-calendar/
2•OJFord•28m ago•0 comments

Show HN: Air – Open-source black box for AI agents (tamper-evident audit trails)

https://github.com/nostalgicskinco/air-blackbox-gateway
2•shotwellj•28m ago•1 comments

What's a "gig work minimum wage"

https://pluralistic.net/2026/02/17/no-piecework/
2•hn_acker•29m ago•0 comments

'No meat on its bones': Federal judge dismisses lawsuit over boneless wings

https://stocks.apple.com/Ax-EAJBvGSy21LBCzYJ7eDA
2•RickJWagner•29m ago•0 comments

Show HN: Aspara – Open-source ML metrics tracker that stays fast at scale

https://github.com/prednext/aspara
2•tkng•29m ago•0 comments

EFF to Wisconsin Legislature: VPN Bans Are Still a Terrible Idea

https://www.eff.org/deeplinks/2026/02/eff-wisconsin-legislature-vpn-bans-are-still-terrible-idea
5•hn_acker•30m ago•0 comments

Show HN: Lite open-source Python tool for network discovery and port auditing

https://github.com/mennylevinski/network_scanner
1•mennylevinski•30m ago•0 comments