Credential isolation for AI agents. Inject secrets at the network boundary.
io.github.getaegis/aegis MCP Server
io.github.getaegis/aegis is an MCP server related to Aegis, described as “Credential isolation for AI agents” that “Inject[s] secrets at the network boundary.” The server’s purpose, based on the provided description and excerpt, is to act as a local-first credential isolation proxy for AI agents, preventing API keys from being accessible to agents. Topics include ai-agent, ai-security, cli, credential-management, devtools, mcp, mcp-server, proxy, secrets-management, security, and typescript.
🛠️ Key Features
Credential isolation for AI agents
Local-first credential isolation proxy
Injects secrets at the network boundary
🚀 Use Cases
Securing agent access to secrets
Running agent workloads while limiting where API keys are exposed
⚡ Developer Benefits
Supports mcp / mcp-server integration patterns
CLI and TypeScript-oriented tooling context (cli, typescript, devtools)
⚠️ Limitations
Provided data does not specify available MCP tools (toolCount) or concrete tool behaviors.
Stop putting API keys where AI agents can read them.
Aegis is a local-first credential isolation proxy for AI agents. It sits between your agent and the APIs it calls — injecting secrets at the network boundary so the agent never sees, stores, or transmits real credentials.
Aegis demo
How It Works
Why?
AI agents (Claude, GPT, Cursor, custom bots) increasingly call real APIs — Slack, GitHub, Stripe, databases. The current pattern is dangerous:
Agents see raw API keys — one prompt injection exfiltrates them
No domain guard — a compromised agent can send your Slack token to evil.com
No audit trail — you can't see what an agent did with your credentials
No access control — every agent can use every credential
Aegis solves all four. Your agent makes HTTP calls through a local proxy. Aegis handles authentication, enforces domain restrictions, and logs everything.
Quick Start
bash
# Install
npm install -g @getaegis/cli
# Initialize (stores master key in OS keychain by default)
aegis init
# Add a credential
aegis vault add \
--name slack-bot \
--service slack \
--secret "xoxb-your-token-here" \
--domains slack.com
# Start the proxy
aegis gate --no-agent-auth
# Test it — Aegis injects the token, forwards to Slack, logs the request# X-Target-Host tells Gate which upstream server to forward to (optional if credential has one domain)
curl http://localhost:3100/slack/api/auth.test \
-H "X-Target-Host: slack.com"
Production Setup (with agent auth)
bash
# Create an agent identity
aegis agent add --name "my-agent"# Save the printed token — it's shown once only# Grant it access to specific credentials
aegis agent grant --agent "my-agent" --credential "slack-bot"# Start Gate (agent auth is on by default)
aegis gate
# Agent must include its token
curl http://localhost:3100/slack/api/auth.test \
-H "X-Target-Host: slack.com" \
-H "X-Aegis-Agent: aegis_a1b2c3d4..."
MCP Integration
Aegis is a first-class MCP server. Any MCP-compatible AI agent can use it natively — no HTTP calls needed.