{"repo":"OlegSotnikov/sallyport","free":true,"listed":false,"github":"https://github.com/OlegSotnikov/sallyport","clone":"git clone https://github.com/OlegSotnikov/sallyport.git","description":"A Mac vault that runs authenticated actions for AI agents over MCP. The agent gets the operation, never the key: no command reveals a stored credential, and there is no export route.","language":"Swift","stars":244,"topics":["ai-agents","credentials","developer-tools","macos","mcp","secrets-management","security","swift"],"license":"Apache-2.0","category":"ai-agents","readme_excerpt":"Sallyport Let your agent touch prod. Keep the keys. Sallyport is a free Mac app that holds API and SSH credentials in an encrypted local vault and executes authenticated actions for AI agents. The agent asks for an operation over MCP; Sallyport runs it, records it in a signed journal, and the key never appears in the agent's environment. There is no command that reveals a stored credential, and no export or recovery route either. Website: sallyport.dev Why Coding agents read .env files, shell variables, and config files, and so does every package they pull in. Recent npm supply-chain attacks harvested credentials from exactly those places, and a prompt-injected agent can leak a token without any malware at all. Traditional secret managers still deliver the secret to the workload. That model breaks when the workload itself is untrusted. Sallyport inverts it: the workload gets an action, the vault keeps the secret. The exact security boundary, including what Sallyport does not stop, is written down in docs/14-trust-model.md and docs/08-security-model.md. Executor responses are returned as received, so a target that echoes sensitive data is outside the credential-isolation guarantee. Repository This public repository contains one source snapshot per Sallyport release. Pull requests are not accepted here. Report bugs and security issues as described in CONTRIBUTING.md. Install Install the signed and notarized DMG from sallyport.dev, Releases, or Homebrew: Launch the app, create t","default_branch":null,"files":null,"tree":[],"storefront":"/r/OlegSotnikov","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/OlegSotnikov/sallyport/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}