TL;DR

Developers introduced OneCLI, an open-source credential gateway that prevents secrets from being embedded in AI agents. This aims to improve security in AI applications.

OneCLI, an open-source credential gateway designed to keep secrets out of AI agents, has been launched and publicly announced on Show HN by its creators, Jonathan and Guy. This development addresses growing concerns about credential security in AI workflows and aims to provide a secure, transparent alternative to proprietary solutions.

OneCLI functions as an open-source vault that manages credentials separately from AI agents, reducing the risk of secrets exposure during AI operations. The tool is hosted on its website (https://onecli.sh) and is intended for developers seeking a transparent, community-supported security solution.

According to the creators, Jonathan and Guy, OneCLI is designed to integrate easily with existing AI workflows, providing a secure gateway for credentials without embedding secrets directly into AI models or codebases. They emphasize its open-source nature, allowing for community review and customization.

At a glance
announcementWhen: announced on Show HN, date unspecified…
The developmentThe creators of OneCLI announced its availability on Show HN as an open-source tool for secure credential management in AI workflows.

Impact on AI Security and Credential Management

This development is significant because it offers a transparent, community-supported approach to credential security in AI workflows, addressing widespread concerns about secrets exposure. By keeping secrets out of AI models and code, OneCLI could reduce security vulnerabilities and improve trust in AI deployments, especially in sensitive or regulated environments.

ESP32-CAM Programming Guide for Beginners: Practical Steps for Building Intelligent Image-Based Microcontroller Projects (Complete Programming, … Development for Beginners and Developers)

ESP32-CAM Programming Guide for Beginners: Practical Steps for Building Intelligent Image-Based Microcontroller Projects (Complete Programming, ... Development for Beginners and Developers)

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Growing Concerns Over Credential Exposure in AI

Recent years have seen increased scrutiny of how credentials and secrets are managed in AI applications. Many AI models and workflows have inadvertently exposed secrets, leading to security breaches and data leaks. Proprietary solutions are often closed-source, limiting transparency and community oversight. The launch of open-source tools like OneCLI responds to calls for more transparent, secure credential management options.

Prior efforts have focused on proprietary vaults or embedding secrets directly into code, which can be insecure. The open-source movement aims to provide more auditable and flexible solutions, with OneCLI being a notable recent example.

Unclear Aspects of OneCLI’s Adoption and Security

It is not yet clear how widely adopted OneCLI will become or how it compares in security effectiveness to proprietary solutions. Details on its integration complexity, performance impact, and real-world security testing remain undisclosed or are still under evaluation.

Additionally, the long-term community support and development trajectory are uncertain, as with many open-source projects.

Next Steps for Community Adoption and Security Testing

Developers and organizations interested in credential security will likely evaluate OneCLI’s integration ease and security robustness. Further testing, community feedback, and potential feature updates are expected to follow. The creators may also seek to build a broader ecosystem around the tool, encouraging collaboration and security audits.

Key Questions

How does OneCLI improve credential security in AI workflows?

It acts as an open-source vault that manages secrets separately from AI models, preventing secrets from being embedded directly into AI code or data, thereby reducing exposure risks.

Is OneCLI compatible with existing AI tools and frameworks?

According to its creators, OneCLI is designed for easy integration with current AI workflows, but specific compatibility details are still emerging.

Can anyone contribute to or review OneCLI’s code?

Yes, as an open-source project hosted at https://onecli.sh, it is open for community review, contributions, and customization.

What are the potential limitations of using OneCLI?

Potential limitations include untested security performance in large-scale deployments and the need for community support to maintain and improve the project.

When will OneCLI be widely adopted in industry?

It is unclear at this stage; adoption will depend on community engagement, security evaluations, and integration success in real-world applications.

Source: hn

You May Also Like

A hotel check-in system left a million passports and driver’s licenses open for anyone to see

A security lapse in a hotel check-in system led to the exposure of over one million passports, driver’s licenses, and photos, now secured after alert.

400 domains used for illegal 2026 World Cup streams seized by US Justice Department — operation is five times the scale of the previous crackdown

US authorities have seized nearly 400 domains illegally streaming the 2026 FIFA World Cup, aiming to curb piracy and malware risks.

Exploit Brokers Pay $500K For WordPress RCEs. I Found One With GPT5.6 And $25

Exploit brokers are reportedly paying up to $500,000 for remote code execution vulnerabilities in WordPress, with claims of a new GPT5.6 version costing only $25.

Kill-Switch-Proof: How To Build So Washington Can’t Take Your AI Stack Down

A guide to making AI stacks resistant to government shutdowns through architecture and dependency management, based on recent US government actions in 2026.