frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Keypo – Secure Enclave encrypted secrets for AI coding agents

https://github.com/keypo-us/keypo-cli
5•dhblumenfeld1•1h ago

Comments

dhblumenfeld1•1h ago
Every developer using Claude Code, Codex or Cursor has the same problem: your agent runs your code but it can also read your .env files. API keys, database credentials, anything on disk is visible to the agent.

I built keypo-signer, an open-source CLI that encrypts secrets in a vault backed by your Mac's Secure Enclave. The key command is vault exec: it decrypts secrets via Touch ID, injects them as environment variables into a child process, and the agent gets back stdout and an exit code. It never sees the secret values. They never touch disk, shell history, or the agent's context window.

See it in action: https://youtu.be/rOSyWQ3gw70

It's open source and self-custody: no cloud provider, no accounts to maintain.

There are three vault tiers: open (no auth), passcode and biometric (Touch ID).

Two demos showing what you can build on top of this:

1. Secure Agent Checkout (https://github.com/keypo-us/keypo-cli/tree/main/demo/checkou...): Tell your agent "buy me a hat" and it completes a real Shopify checkout with your actual credit card. Card details live in the biometric vault. The agent calls a wrapper script, Touch ID pops up on your Mac, and a headless browser fills the payment form inside a child process the agent can't inspect. You get an order confirmation email. The agent never sees your card number.

2. Agent Wallet (https://github.com/keypo-us/keypo-cli/tree/main/demo/hermes-...): A hardware wallet for your agent. Uses EIP-7702 smart accounts with the Mac Secure Enclave so your agent can send on-chain transactions but the private key never leaves the hardware. Touch ID gates every signature.

macOS/Apple Silicon only (Secure Enclave is the point). Swift + Rust. brew install keypo-us/tap/keypo-signer

https://github.com/keypo-us/keypo-cli

Hithium to invest €400M in Spanish mega battery factory

https://www.ess-news.com/2026/03/11/hithium-to-invest-e400-million-in-spanish-mega-battery-factory/
1•toomuchtodo•33s ago•0 comments

Thariq's Lessons from Building Claude Code: How We Use Skills

https://twitter.com/trq212/status/2033949937936085378
1•nadis•33s ago•0 comments

Trump's plan to shut down weather and climate center triggers lawsuit

https://arstechnica.com/science/2026/03/university-group-sues-trump-administration-over-shutdown-...
1•voxadam•40s ago•0 comments

Overseas 'content farms' creating political deepfakes uncovered

https://www.bbc.com/news/articles/c07jj7d72yzo
1•robtherobber•2m ago•0 comments

Show HN: StackStats – Analytics tool for Substack writers, runs 100% locally

1•rishikeshs•3m ago•0 comments

Et tu, S&P 500? The SpaceX IPO gamesmanship is going to be epic

https://www.ft.com/content/59adbe42-ca30-47f3-9cda-5415945e9368
1•petethomas•4m ago•0 comments

You're Not Thinking About Your Network the Way You Should

https://packetpushers.net/podcasts/heavy-strategy/hs127-youre-not-thinking-about-your-network-the...
1•oavioklein•4m ago•0 comments

Did Cinema Get Narrower?

https://www.kopanko.com/notes/did-cinema-get-narrower
1•pcktm•4m ago•0 comments

Turning raw logs into feature vectors without manual labeling

https://www.securesql.info/2025/04/05/etl-playbooks/
1•projectnexus•5m ago•1 comments

Show HN: Starting Five – NBA Lineup Building Challenges

https://draftdawg.app
1•perhapsAnLLM•5m ago•0 comments

SecOps without manual schemas: Using EBMs and automated ETL for detection

https://www.securesql.info/2025/04/04/loop-architecture/
1•projectnexus•7m ago•1 comments

Ban Bots Not Human Directed Tool Use

1•morpheos137•7m ago•1 comments

Show HN: Horizon – GPU-accelerated infinite-canvas terminal in Rust

https://github.com/peters/horizon
1•petersunde•7m ago•0 comments

Fair Source Software in the AI Age

https://blog.sentry.io/fair-source-software-in-the-ai-age/
1•ezekg•7m ago•0 comments

AI Agents and the New SaaS

https://www.gouthamve.dev/on-ai-agents-and-the-new-saas/
2•gouthamve•9m ago•0 comments

YouTube is experimenting with ads visible even after users skip

https://searchengineland.com/youtube-tests-sticky-banner-after-ad-skip-471902
3•speckx•9m ago•0 comments

Stop training your security ML on labeled attack data

https://www.securesql.info/2025/04/03/energy-based-models-anomaly-detection/
1•projectnexus•9m ago•1 comments

Why does it feel uncomfortable to think about how much you use your phone?

https://dogdogfish.com/blog/2026/03/17/psychological-discomfort/
1•matthewsharpe3•10m ago•0 comments

Stripe.com/6oU7sL9Pwg6Xa9kBest AI Agent Certi1iK1gs0s

1•OpenClawAura•11m ago•0 comments

Spectra – detect API contract drift from real runtime traffic

https://github.com/rmalik1-hash/spectra_windows_public
1•Spectra73•11m ago•1 comments

What was DOGE? How Elon Musk tried to gamify government

https://www.theguardian.com/news/ng-interactive/2026/mar/17/elon-musk-gamify-government
5•billybuckwheat•12m ago•0 comments

Why Claude Code Can't Find Your Tools

https://layer5.io/blog/engineering/why-claude-code-cant-find-your-tools/
2•lcalcote•12m ago•0 comments

India's outsourcing industry is worth $300B. Can it survive AI?

https://www.bbc.com/news/articles/c5yrq1090p8o
3•devonnull•13m ago•0 comments

Can You Train a Computer?

https://dimitrisp.substack.com/p/can-you-train-a-computer
2•marojejian•13m ago•0 comments

Zero ZGC4: A Better Graphing Calculator for School and Beyond

https://www.zerocalculators.com/features
1•uticus•14m ago•0 comments

Kexec handover and the live update orchestrator

https://lwn.net/Articles/1033364/
1•tosti•15m ago•0 comments

Researchers disclose vulnerabilities in IP KVMs from four manufacturers

https://arstechnica.com/security/2026/03/researchers-disclose-vulnerabilities-in-ip-kvms-from-4-m...
2•joozio•16m ago•0 comments

Illinois Introducing Operating System Account Age Bill

https://www.ilga.gov/Legislation/BillStatus?DocTypeID=HB&DocNum=5511
22•terminalbraid•16m ago•3 comments

Putting Thought into Things (2014)

https://ia.net/topics/putting-thought-into-things
1•levmiseri•16m ago•1 comments

Operating Systems: Three Easy Pieces

https://pages.cs.wisc.edu/~remzi/OSTEP/
1•vinhnx•16m ago•0 comments