Observed arrival · 2026-09-07
unsudo Keeps AI-Agent Credentials Out of Reach
An open-source credential and capability broker in development that lets AI agents use APIs, command-line tools, databases, SSH, and logged-in browsers without exposing the underlying keys.
Field notes
The proposed security boundary uses two Linux users: the agent performs work, while an operator-side service holds credentials and enforces access through API proxies, CLI or SSH brokers, and a protected browser profile. The page names example services ranging from OpenRouter and GitHub to Stripe and Supabase, and describes workflows that return results without exposing provider keys. The source, installation instructions, and non-Linux support are presented as forthcoming rather than available now.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue