Private beta Credential approvals for AI agents

Your agents ask. You decide.

alicit puts your decision in front of every credential an agent uses. You see the exact operation on your phone, and Face ID or your fingerprint signs your answer.

Try it yourself
How it works

One command. One decision.

The agent does not hold a standing token. It asks for the smallest profile it needs, for a short time, and it says why.

The agent asks

It runs alicit run with a profile, a time limit and a justification. Nothing else changes in its workflow.

Your phone shows the request

You see the operation, its exact inputs and the reason. You approve it or decline it, and your phone signs your answer.

The credential stays sealed

The command gets a local proxy, not the real token. When the command stops, alicit revokes the token.

Try it

Your turn.

Show the session on
Approval requestednow
Open alicit to review.
Approve
Decline
Read
GitHub · alicit-ai
Hostbuild-mac
Repositoryalicit-ai/alicit
AgentClaude Code · 3f2a9c1e
Processgh
Path/v1/github/alicit-ai/token/issues

List the exact repository issues for the current implementation task

jev · clear
Reason fits 91% · Scope fits 80%
2m 0s
All caught up
A new request appears here when an Agent asks for a credential.
Sign out of alicit?
alicit
Your credentials. Your decision.
Swipe right to approve
Swipe left to decline
Face ID signs every decision

A simulation made from the real alicit iOS app and CLI text. The Android phone shows the design of the Android app, which is not released yet. The simulation does not connect to a Vault.

Principles

Small, short and signed.

The smallest profile

An agent asks for one server-owned profile, such as read access to one repository. It does not get a broad key that works everywhere.

The shortest time

Tokens last minutes, not months. Each time the agent needs a new credential, it asks again.

A key only your phone holds

The approval key lives in the Secure Enclave of your iPhone or the Android Keystore of your Android phone. The server checks the signature before it issues anything.

Built on OpenBao

alicit runs in front of an OpenBao vault that you control. Policy decides what an agent can request. You decide what it gets.

Let your agents work. Keep the keys.

alicit is in private beta. Ask us for an invitation.