Skip to content

docs(ideas): credential broker - #392

Draft
wagoodman wants to merge 1 commit into
simion:mainfrom
wagoodman:feature/credential-broker
Draft

wagoodman wants to merge 1 commit into
simion:mainfrom
wagoodman:feature/credential-broker

Conversation

@wagoodman

@wagoodman wagoodman commented Oct 11, 2026 •

Copy link
Copy Markdown
Contributor

Idea doc for letting a caged agent use a credential without being able to see it. The agent and its tools only ever hold a placeholder, and Termic swaps in the real secret from the Keychain only for the hosts that secret is bound to. No change to the user's system trust store.

Screenshot 2026-10-10 at 9 28 16 PM

Overall the proposed idea encompass:

  • three transports cover most tools: MITM through the existing proxy, base-URL override, and gh's http_unix_socket
  • spikes for gh, git, oras and AWS SigV4 (including terraform, s5cmd, rclone), stubbed, nothing went upstream
  • role-based UX: secrets grouped into roles, one role per task, no cage means no secrets
  • security rules for the broker, Keychain read risks, Docker mode, prior art, open questions

Idea doc for letting a caged agent use a credential without seeing it:
the agent and its tools hold a placeholder, and Termic swaps in the
real secret from the Keychain only for the hosts it is bound to, with
no change to system trust.

Covers the transports (MITM, base URL, gh's http_unix_socket), spikes
for gh, git, oras and AWS SigV4, the security rules, a role-based UX
model, Docker mode, prior art and open questions.

Signed-off-by: Alex Goodman <wagoodman@users.noreply.github.com>
@wagoodman

Copy link
Copy Markdown
Contributor Author

Here is a UI mock up to motivate how a user might configure and interact with this feature... consider this purely speculative to help get the idea across (nothing is finalized and coded up yet).

Add secret names and map them to keychain entries:

Screenshot 2026-10-10 at 9 14 36 PM

Assign secrets to roles and add additional per-host path rules which map directly to capabilities we want to suppress for each credential depending on the role:

Screenshot 2026-10-10 at 9 14 45 PM

Project can hold the default preference for which roles can be used when making new tasks:

Screenshot 2026-10-10 at 9 14 52 PM

When making a new task you get to select the role, and all claude sessions under this task adhere to this role:

Screenshot 2026-10-10 at 9 15 01 PM

One of the great features about Termic sandbox is its immediate feedback on what things are being blocked when in sandbox mode. I think the same thing should apply for secrets and roles we should have some clarity as to what is attempting to use secrets and which role I have selected:

Screenshot 2026-10-10 at 9 15 20 PM

Call this a stretch goal, but this would give Termic a unique position to be able to detect suspicious activity regarding secrets:

Screenshot 2026-10-10 at 9 24 48 PM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant