Local credential control for AI coding agents.
Local credential control for coding agents. Approve bounded actions locally. Keep raw credentials out of model context and tool output.
Demo · Downloads · Quick start · Documentation · Security · Contributing
Stop handing raw credentials to coding agents. s-gw gives agents typed handles, asks you to approve bounded local actions, resolves the credential inside a constrained process on your machine, and returns sanitized output instead of secret values.
[!IMPORTANT] s-gw is an early preview. Storage formats and interfaces may change, Windows support is still experimental, and the project has not completed an independent security audit. Do not treat it as a replacement for endpoint security or a hardened enterprise secrets platform yet.
- Agent sees: s-gw:credential:prod-readonly - You approve: agent, command, handle, environment binding, working directory, and target - s-gw runs: the command locally with the credential injected only into that child process - Agent receives: sanitized output, audit evidence, and no raw secret
If s-gw helps your agent workflow, star the project. It makes the preview easier for other developers to find.
The local console shows the approval queue, credential inventory, policy state, usage flow, and activity history without exposing secret values.
Govern Approve Execute Audit --- --- --- --- Turn secrets into typed local handles that agents can reference safely. Review the requesting agent, handle, command, environment binding, working directory, and target before access is granted. Inject the credential only into the approved child proces
From the project README.
Add the radar badge to your README — it shows your project was picked up by MCP Radar and links to this page:
[](https://mcp.liqiwa.com/s/sgateway--s-gw.html)
Local-first MCP password and credential manager for AI agents. Use passwords, API keys, SSH identities, and TOTP without exposing hidden plaintext to the model.
alexanderradahl/mac-developer-bridgeGive ChatGPT a real terminal on your Mac. Open-source MCP bridge for shell, files, PTY sessions, jobs, and Codex history.
herry2059/project-os-for-codexOpen-source control plane for Codex projects: Git-backed context, visible agent progress, scoped MCP access, resumable work, and safe handoffs.
pranee54/AgentDoctorLocal CLI that audits coding-agent configuration for security, instructions, context, and MCP — no API key or code upload by default.
luckeyfaraday/frontier-orchestratorMulti-agent orchestration for Claude Code: MCP server + skill that keeps Claude as lead engineer while delegating backend work to OpenAI Codex and frontend/design work to Kimi
leynier/exeoraSecure execution for AI agents, on any machine. Connect any MCP client to the development environment on any machine you can run a command on (even your own laptop) - no open ports, no tunnels, and yo
The top new MCP servers of the week, every Monday. No spam, unsubscribe anytime.