Rendered at 00:15:59 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
ericmaciver 1 hours ago [-]
The "policy in one place, enforced across every agent" part is the piece I would have underrated a year ago.
I went looking for that in my own codebase and found six independent secret-redaction denylists, no two of which agreed. Measured against 17 real credential shapes, the list I thought was canonical caught 10. The seven it missed included a GitLab PAT, a Supabase key, a Cloudflare token and a literal password= . The widest list was a fork, not the canonical one, and only the union of all six covered everything. Nobody wrote six on purpose. Each was locally reasonable when it was added and there was no single place to put the rule.
So the question I would ask about the team layer: when a policy changes, is there exactly one artifact every agent reads, and can I diff what an agent was actually allowed to touch at run time against what the policy said? Enforcement I can audit afterward is worth a lot more to me than enforcement I have to trust.
ezzy-1630 2 days ago [-]
Keeping the real credential out of model context is a meaningful improvement, but the gateway still becomes a confused-deputy boundary. How granular are policies below the endpoint level? An agent allowed to call a CRM API may still be tricked into exporting the wrong customer or changing a field it should only read. I'd be interested in whether policies can constrain method, path, request fields, resource ownership, and response volume, and how those rules are tested against prompt injection.
coder-pm 5 hours ago [-]
OneCLI controls what the agent can reach. It doesnt control where it runs. Block a leaked key and the process is still on your host, so a bad rm or a prompt injected "clean up this repo" still hits real files. So I would stack them, not pick one. Sandbox the agent so it can't touch anything you care about, then route egress through a policy layer like this. Reach and blast radius are different problems:)
hugorus87 15 hours ago [-]
Sandbox choice matters more than most agent harnesses admit. Docker-in-Docker vs firecracker vs unshared namespaces each break in different ways once you start bind-mounting the user's repo. Curious which tradeoff you picked and why.
aliasxneo 2 days ago [-]
How do you even win in this space? I feel like every day I see either a paid or fully OSS version of this product being posted here. As an end user I've become so overwhelmed that I've just started to mostly ignore them at this point. I can't be the only potential customer feeling this way?
guyb3 2 days ago [-]
Honestly, we're not sure yet how we win this space. We both come from security backgrounds, and that's probably what led us to where we are today. basically we built the gateway first because we were afraid of using openclaw the way it came out of the box. we didn't even connect our gmail out of fear. then after a while working with agents behind the gateway, we just started building our own agent that integrates better with it, for me and my partner. So maybe it lands with the same kind of people as us, who worry about the security side and want that safe feeling. Still figuring out how many of us are out there.
rukshn 2 days ago [-]
This I fully agree. I think I was few who never wanted to try Open Claw or wanted to connect my accounts because I saw someone at Meta getting their emails deleted.
Then after I listened to Garry’s talk on Gbrain last week I thought why not give it a try.
So connected my email and calendar to a simple agent I built via MCP and I get a summery of important emails and also delete all non important ones.
You're not alone, I don't get it either and this market is extremely crowded with many agent tools popping up everyday.
Some closed source, lots that are open source, hundreds of thousands and many which are completely vibecoded.
I feel that YC just invests in anything these days.
I mean, I don't see a moat here.
Like, why this over Grok Bot or anything that Anthropic or OpenAI would make for their 900M+ users?
Or is that the goal all along? Get acquired by a lab?
nrmitchi 2 days ago [-]
> I feel that YC just invests in anything these days.
When there is a popular gold rush, YC invests in many companies that do the same thing with the expectation that 1) a rising tide lifts all ships, and 2) if there is a clear winner, they have eggs in every basket.
guyb3 2 days ago [-]
It’s definitely a crowded space, totally agree about it.
honestly for us we didn't want to commit to a specific provider, whether that's grok or openai. So we decided to go with a harness that lets us switch models easily when one is down, or when another provider comes out with a new improved model
robbomacrae 2 days ago [-]
Yep. OrcaBot has all these features. Free on desktop.
It's been out for 6 months.
taoh 2 days ago [-]
The important detail is whether approval binds to the exact proposed action, including the recipient, repository, issue, or data being sent, rather than just “allow Gmail” or “allow this endpoint.” How granular are the gateway policies for APIs where read and write actions share the same host?
Jonathanfishner 2 days ago [-]
jonathan from OneCLI here, yes - approval binds to the exact req by opening it (method, URL, body) when there’s a matching policy defined. then the gateway holds the call and the card shows the parsed payload.
just to clarify how it works - on same host, rules match based on method + path + body, not only the host. for example, GET /calendar/v3/* can be allowed while POST needs approval.
GiganticCupcake 2 days ago [-]
In a similar vein, I've been playing with Nemesis8. It provides the same sandbox and network constraint as this repo but adds orchestration and observability. You can control and communicate a fleet of agent containers that persist sessions, configure MCP tooling, and schedule events. That appears to just be the surface, I'm still digging into it. Now that I've experienced this single-pane-of-glass interface, I don't think I'm going back. If this is a trend, I hope it sticks. Check it out:
https://github.com/DeepBlueDynamics/nemesis8
madmecodes 18 hours ago [-]
If every agent action maps to a real user, with clear limits and logs, agents become much easier to trust.
snthpy 2 days ago [-]
Looks good , but I don't understand the licensing. The bottom of the read me says it's Apache 2.0, except for the /ee folder, but I don't see the /ee folder in the repo, at least not at the top-level. I also don't see anything about what the enterprise features are on the actual web page.
FailMore 2 days ago [-]
I think it's pretty interesting - I can see why companies would want to go for this instead of build everything themselves...
Curious about how your customers are responding to pricing. 20 agents for $499/month without API costs included feels steep... but perhaps within the range of "worth it if we don't have to think about this".
Honest question, how does this project already has over 3,200 stars on GitHub?
Their video demo was posted 13 hours ago, and it only has 38 views as of the time of this post.
The post on HN is 4 hours ago.
brabel 1 days ago [-]
I’ve known them for months, the product was available for at least that much time. I guess this is just a funding announcement, not a launch from nothing.
pitzips 2 days ago [-]
I started using OneCLI when Nanoclaw (came out just after Open Claw) announced them as the way to handle credentials. I think that may have been their first boost?
frangonf 2 days ago [-]
I had the project already starred, I lurk around the sandbox space from time to time, and the project it's a few months old and was already discoverable and in a usable state before today.
brunoborges 2 days ago [-]
Still, over 3,000 stars so quick? It's just weird.
soltanov 2 days ago [-]
The earliest repository commits and initial public announcements show this date: March 17, 2026.
grugnog 2 days ago [-]
How do credentials work to access user data with the right permissions? Is there a way to integrate OAuth flows via Slack, for instance?
Cameri 2 days ago [-]
How is OneCLI different from Databrick's Omnigent?
eli_berman 2 days ago [-]
Interesting, gonna take a closer look at this. But nice repo!
Axsuul 2 days ago [-]
How does this compare to YC's qm?
guyb3 2 days ago [-]
fair question and there are lots of overlap, here some diffs we found important for us -
1) the agent never holds your keys and all its traffic goes to onecli gateway. which adds the secret at the moment of the request.
2) our approval mechanism for risky actions like sending an email or deleting data need human approval.
3) each agent gets its own Slack app with a name, and its own avatar. QM uses one shared workspace bot for everyone, in onecli it will be three agents that look like three people in Slack, not one bot.
I went looking for that in my own codebase and found six independent secret-redaction denylists, no two of which agreed. Measured against 17 real credential shapes, the list I thought was canonical caught 10. The seven it missed included a GitLab PAT, a Supabase key, a Cloudflare token and a literal password= . The widest list was a fork, not the canonical one, and only the union of all six covered everything. Nobody wrote six on purpose. Each was locally reasonable when it was added and there was no single place to put the rule.
So the question I would ask about the team layer: when a policy changes, is there exactly one artifact every agent reads, and can I diff what an agent was actually allowed to touch at run time against what the policy said? Enforcement I can audit afterward is worth a lot more to me than enforcement I have to trust.
Then after I listened to Garry’s talk on Gbrain last week I thought why not give it a try.
So connected my email and calendar to a simple agent I built via MCP and I get a summery of important emails and also delete all non important ones.
Still a WIP: https://github.com/rukshn/zen
But I agree the space is very much crowded
Some closed source, lots that are open source, hundreds of thousands and many which are completely vibecoded.
I feel that YC just invests in anything these days.
I mean, I don't see a moat here.
Like, why this over Grok Bot or anything that Anthropic or OpenAI would make for their 900M+ users?
Or is that the goal all along? Get acquired by a lab?
When there is a popular gold rush, YC invests in many companies that do the same thing with the expectation that 1) a rising tide lifts all ships, and 2) if there is a clear winner, they have eggs in every basket.
It's been out for 6 months.
just to clarify how it works - on same host, rules match based on method + path + body, not only the host. for example, GET /calendar/v3/* can be allowed while POST needs approval.
Curious about how your customers are responding to pricing. 20 agents for $499/month without API costs included feels steep... but perhaps within the range of "worth it if we don't have to think about this".
Their video demo was posted 13 hours ago, and it only has 38 views as of the time of this post.
The post on HN is 4 hours ago.