KeyLeash

Guardrail and audit trail, not a guarantee

What is true, and what is not

What is true

  • A grant names an agent, a service, scopes, and an expiry. It can also name max uses and conditions. The CLI signs it. You can revoke it.
  • keyleash run injects the real credential into one child process. That mode does not limit which endpoints the child calls.
  • keyleash proxy checks the endpoint scope before it forwards.
  • Receipts are append-only and hash-chained. Changing one saved line fails verification.
  • The hosted ingest rejects a batch that does not continue the stored chain.
  • Services in this build are openai, github, and generic http.
  • An approval can be decided once, by an admin or an approver. Approval issues a signed grant.
  • This server can record expiry and denied-burst alerts for the signed-in organization.
  • CSV export includes every stored receipt for this organization that matches the filter, not only the rows on screen.
  • A new verified email creates its own organization.
  • A hosted policy is a ceiling. Later edits can only remove scopes, shorten the max ttl, or lower max uses.

What is not true

  • This is not a guarantee. An agent that bypasses the broker bypasses KeyLeash.
  • If the agent can read the real credential from somewhere else, nothing here stops the call.
  • Someone who can rewrite the whole receipt file can build a new chain. Shipping the file off the machine is what makes that visible.
  • Local credentials are a mode 0600 file, not an encrypted vault.
  • A hosted grant row does not prove the credential is gone from an agent machine. A local revoke shows up as a receipt.
  • Email verification shows control of that inbox. It does not join an organization because the domain matches.
  • Billing is not enabled. A paid plan and a 14-day trial are not implemented. Stripe is not part of this build. Nothing on this page charges a card.
  • This page is not an npm publish. This page is not a marketplace listing.
  • Bot protection runs only when Turnstile is configured. Otherwise sign-in stays closed.
  • Row level security applies only when the server connects as the non-owner role. A superuser or the table owner bypasses it.
  • This page does not prove that keyleash.dev is deployed, and it does not prove that mail or Turnstile are live for a given server.
  • A policy does not bind a grant issued by keyleash grant without --url.
  • The API returns members, policies, grants, and receipts for the signed-in organization. Policies, grants, receipts, requests, and alerts also have a row policy. The users, sessions, and token tables do not. A database role that can query those tables directly can see every organization.

Sign in

Use an email code. The code proves control of that inbox. A new address gets a new organization. A shared company domain does not open someone else's grants.