The agent asks
It runs alicit run with a profile, a time limit and a justification. Nothing else changes in its workflow.
alicit puts your decision in front of every credential an agent uses. You see the exact operation on your phone, and Face ID or your fingerprint signs your answer.
Try it yourselfThe agent does not hold a standing token. It asks for the smallest profile it needs, for a short time, and it says why.
It runs alicit run with a profile, a time limit and a justification. Nothing else changes in its workflow.
You see the operation, its exact inputs and the reason. You approve it or decline it, and your phone signs your answer.
The command gets a local proxy, not the real token. When the command stops, alicit revokes the token.
A simulation made from a recorded run of the real alicit CLI and Vault, and from the real alicit iOS and Android apps. The Android app is not released yet. The simulation does not connect to a Vault.
An agent asks for one server-owned profile, such as read access to one repository. It does not get a broad key that works everywhere.
Tokens last minutes, not months. Each time the agent needs a new credential, it asks again.
The approval key lives in the Secure Enclave of your iPhone or the Android Keystore of your Android phone. The server checks the signature before it issues anything.
alicit runs in front of an OpenBao vault that you control. Policy decides what an agent can request. You decide what it gets.
alicit is in private beta. Ask us for an invitation.