Backed byY Combinator

The credential gateway
for AI agents

Route every request through OneCLI.
Enforce policies, inject credentials. Keys never leave the vault.

.envproxied by onecli

OPENAI_API_KEY=sk-proj-Xh4mQ2████████f8Kwonecli-managed ✓

STRIPE_SECRET_KEY=sk_live_51Hx8m████████Rq2vonecli-managed ✓

GITHUB_TOKEN=ghp_uV4nR7Tk████████p3Xzonecli-managed ✓

AWS_SECRET_ACCESS_KEY=aK9dPmXw████████L7Rqonecli-managed ✓

DATABASE_URL=postgres://acme:pg4s█████@db.acme.ioonecli-managed ✓

SLACK_BOT_TOKEN=xoxb-8214-Ju7wK████████m2Nponecli-managed ✓

ANTHROPIC_API_KEY=sk-ant-api03-R5kT████████v8Nqonecli-managed ✓

7keys exposed to agents

Want this for your environment?

Get Started

Trusted by

  • Docker
  • MindsDB
  • Zoho
  • Coralogix
  • Kakao Entertainment
  • Cleo
  • Optibus
  • Reply.io
  • Kaiko
  • Percent
  • Pillar Security
  • Phase
  • Medallion
  • Glilot Capital

Every agent. One gateway.

Scoped credentials injected per request. Agents never hold a real secret.

OneCLI secures them all

OneCLI enforces at the network layer, covering every path your agent takes:
MCP tool calls, CLI commands, curl, and the code it writes.

An MCP gateway governs 1 of 4 agent paths. OneCLI governs all 4: MCP tool calls, CLI commands, curl, and the code agents write

Why an MCP gateway isn't enough →

“CLIs are super exciting precisely because they are a ‘legacy’ technology, which means AI agents can natively and easily use them.”

Andrej KarpathyAndrej KarpathyAI researcher · 1.9M views on X

Rules agents can't break

Prompts are suggestions. OneCLI policies are enforced at the network layer, outside the agent, outside the LLM. No matter what the model decides, the proxy enforces your rules deterministically.

Block endpoints

Prevent agents from calling specific APIs (DELETE /repos, POST /payments, or any path you define). Enforced at the proxy, not a suggestion.

Rate limit per agent

Cap how many requests an agent can make per minute, hour, or day. Stop runaway loops before they cause damage.

Require approval

Flag sensitive operations for human review before they go through. Agents wait, you decide.

Scope per project

Each agent only accesses the credentials and services assigned to its project. No cross-project leakage.

See how it works

Get started

Start securing your agents today

Free forever for up to 2 agents. No credit card required.