Secure developer workflows with Authsia
Keep secrets in your Mac Keychain. Let terminals, Git, MCP, and coding agents request scoped access only when you approve.
Get started
Install once, then pick the surface you need: app, CLI, or a workflow guide.
Developer quickstart
Install Authsia, add vault items, initialize a workspace, and run a command through the CLI.
Start hereUse the Mac app
First run, vault folders, Workspace Center, Access Center, and agent-safe habits.
Open app guidesAuthsia CLI
Workspace env refs, guarded terminals, MCP, agent JIT, SSH signing, and audit.
Open CLI guidesDevelop locally
Store secrets in the vault, commit references, and resolve them only in approved child processes.
Secure local development
Compare workspace run, guarded terminal, and exec so plaintext stays out of the parent shell.
Workflow guideWorkspace CLI
Init commit-safe refs, select one environment, and run npm, tests, or scripts through Authsia.
Guarded terminal
PATH shims for npm, docker, aws, and kubectl. Humans get resolution; agents do not inherit secrets implicitly.
Vault boundaries
Folders and per-item CLI toggles decide what can ever leave the app.
Secure agentic workflows
Give coding agents scoped, time-boxed access without putting credentials in prompts, config files, or LLM context.
Secure AI agents
Start here for Codex, Claude Code, Cursor, and other local agents. JIT grants, MCP tools, and workspace rules.
Workflow guideLocal MCP server
Six fixed tools and no secret-return path. The client launches Authsia; approvals stay in Access Center.
MCP Manager
Use the local portal for existing STDIO protection and authenticated localhost Streamable HTTP.
Agent JIT approvals
Approve folder, capability, and TTL from Access Center or a paired iPhone, then revoke anytime.
Access Center
Agent grants, human sessions, and investigation flags — without editing project files.
Authenticate with SSH & Git
Keep private keys in the vault. Git and SSH sign through the local Authsia agent.
Security and verification
Offline-first by default. Confirm a release before you trust a download.
Security model
How CLI, agents, SSH, and Chrome autofill enter through local boundaries before human approval.
Verify a release
Check DMG hash, signing, notarization, Gatekeeper, and the bundled CLI.
AI-readable docs
Point coding agents at llms.txt so they can search these guides without scraping HTML.