Observed arrival · 2026-09-10
Slifer Key Locker Keeps the Real API Key Away from the Agent
A local-first broker gives apps and coding agents scoped stand-in tokens while holding provider credentials inside an encrypted vault.
Field notes
Slifer separates the less-trusted client from the upstream credential by issuing scoped skl_tok_v1 tokens and keeping the provider key in encrypted local vault data. Its policy model names the provider, secret alias, HTTP methods, paths, headers, egress host, rate ceiling, concurrency cap, and expiry, with deny-by-default behavior. The page says unlocking requires both a passphrase and a generated Vault Secret Key, while acknowledging that the project remains private, pre-release, and currently limited to an OpenAI brokered path.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue