Public betaCredential isolation for autonomous agents

Your agentscall any API.
They neversee your keys.

Agents write {{TEMPLATE_VARIABLES}} instead of secrets. Blinds resolves them against the vault, binds the destination, forwards the request, and strips credentials from the response. The secret never enters agent runtime.

Rust coreApache-2.0Self-hostable4 SDKs
scroll
How it worksAgent makes a request with a template variable
Agent runtime
AuthorizationBearer {{GITHUB_TOKEN}}
X-API-Key{{STRIPE_KEY}}
AuthorizationBearer {{OPENAI_KEY}}
Blinds proxy
resolve
Destination API
AuthorizationBearer ghp_R3aL...
X-API-Keysk_live_9xB7...
AuthorizationBearer sk-proj...
Template parserDestination bindingSSRF guardResponse sanitizerEd25519 audit chain
01Store a credential

Your secrets go into the vault. Destination-bound. Ed25519-signed.

blinds · terminal~
02Make a request

The agent writes a template. Blinds resolves it server-side. The credential never enters the runtime.

blinds · terminal~
03Delegate scoped access

Parent agents delegate subsets. Scopes only narrow. Revocation cascades.

blinds · terminal~
04Check the chain

Every request appends to a BLAKE3 fingerprint chain. Break the chain, Blinds sees it.

blinds · terminal~
Install

Running in
thirty seconds.

One command installs the CLI. One more generates your keypair and starts the fingerprint chain. After that, every outbound request routes through the proxy automatically.

Rust core · Axum · Tokio
SDKs: Rust, TypeScript, Python, Go
Self-hostable · Apache 2.0
Built on Arsenal
# install
$ curl -sSL https://blinds.sh/install | sh
✓ installed to /usr/local/bin/blinds
# initialize
$ blinds init
✓ Generated Ed25519 keypair
✓ Registered machine mach_a1b2c3d4
✓ Initialized fingerprint chain
# use it
$ blinds curl https://api.github.com/user \
-H "Authorization: Bearer {{GITHUB_TOKEN}}"
← 200 OK · 42 repos

Every agent deserves
blinds.

Stop shipping secrets into agent context windows. Start the migration with one command.