Back to updates
New releaseJul 25, 2026

aquaman v0.14.0

🔱 The only independent credential proxy for AI agents: bring-your-own-vault isolation & least-privilege request policies. Your keys stay where you already keep them, never in the agent's memory. Compatible with 1Password, keychain, keepassxc and many others.

Share

🔱 Aquaman

CI codecov npm version npm downloads Security: process isolation TypeScript License: MIT

🔱 The only independent credential proxy for AI agents: bring-your-own-vault isolation & least-privilege request policies. Your keys stay where you already keep them, never in the agent's memory. Compatible with 1Password, keychain, keepassxc and many others.

You set up Claude Code, Codex, OpenClaw, Hermes, or Docker Sandboxes, and now you're staring at .env files with your precious API keys sitting there in plaintext. You read the articles. You know what happens when an agent gets prompt-injected. We get it.

Aquaman fixes this with three layers of defense:

  1. Process isolation: API keys live in a separate proxy process that injects them at egress. The agent holds a marker, never a key, so even RCE in the agent can't read one. Coding agents get only the refs you declare, one command at a time.
  2. Request policies: Per-service rules control which endpoints an agent can call. Block admin APIs, prevent deletions, allow drafts but deny sends. Denied requests never get real credentials.
  3. Tamper-evident audit: Every credential use is logged with SHA-256 hash chains. You can prove what was accessed and detect tampering after the fact.

Pick your path

Aquaman ships as four coordinated packages, sharing one vault + one daemon. Install only what you need:

PackageWhat it doesWhen to install
aquaman-proxyCore: vault, daemon, audit, policy, CLI. The piece everyone needs.Always.
aquaman-pluginOpenClaw Gateway adapter. Spawns the proxy on Gateway startup; routes model and Telegram traffic through it; 25 builtin services across 5 auth modes.If you run an OpenClaw Gateway. Also available at https://clawhub.ai/plugins/aquaman-plugin
aquaman-coderAI coding-agent adapter. Project-scoped aquaman://service/key references resolved per Bash tool call.If you use Claude Code or Codex.
aquaman-hermesHermes agent-host plugin (Python, on PyPI). Points Hermes at an opt-in, token-gated loopback listener via its native ANTHROPIC_BASE_URL/OPENAI_BASE_URL; adds an in-session /aquaman-status command, tool, and health probe. Isolation is proxy-side; the plugin holds no credentials.If you run the Hermes agent host. pip install aquaman-hermes
Docker SandboxesNot a package: a separate path that needs only aquaman-proxy. Docker's own proxy injects the secrets; aquaman get supplies them from your vault, with the allow-list and audit log.If you run agents in Docker Sandboxes. See Quick Start 5.

A single aquaman CLI surfaces all four: top-level commands for vault and audit, aquaman openclaw ... for the OpenClaw integration, aquaman coder ... for the coding-agent integration (delegates to aquaman-coder under the hood) as well as aquaman hermes ... for the Hermes Python package.

Quick Start

aquaman help, aquaman doctor are your friends.

1. Vault only (just the proxy + your secrets)

npm install -g aquaman-proxy
aquaman setup                                # backend wizard + store keys
aquaman daemon &                             # start the proxy
aquaman credentials list                     # verify

The proxy listens on ~/.aquaman/proxy.sock (UDS, chmod 0o600). Point any tool at http://aquaman.local/<service>/<path> and the proxy injects auth headers for that service from your chosen vault backend.

2. OpenClaw Gateway

openclaw plugins install aquaman-plugin           # 1. install plugin + proxy
openclaw aquaman setup                            # 2. backend + keys + plugin wire-up
openclaw                                          # 3. done - proxy starts automatically

Troubleshooting: openclaw aquaman doctor.

Using npm directly? npm install -g aquaman-proxy && aquaman openclaw setup does the same - installs the proxy CLI, stores your keys, installs the plugin into ~/.openclaw/extensions/aquaman-plugin/, and wires the credentials (SecretRef refs on OpenClaw ≥ 2026.6.5, the auth-profiles.json placeholder on older versions).

aquaman openclaw setup points models.providers.<svc>.baseUrl and channels.telegram.apiRoot at the proxy's loopback listener, because OpenClaw's model transport and its channels each build their own HTTP client and bypass the fetch interceptor. Channels other than Telegram expose no endpoint override, so their tokens are stored and migrated but not injected at egress (see packages/plugin/README.md). Add channels under the plugin config in openclaw.json; supported ones include Slack, Discord, Telegram, MS Teams, Matrix, LINE, Twitch, Twilio, BlueBubbles, Mattermost, Nostr, Tlon, Feishu, Google Chat, ElevenLabs, xAI, Cloudflare AI Gateway, Mistral, Hugging Face, and more (25 total).

3. AI coding agents (Claude Code, Codex)

npm install -g aquaman-proxy aquaman-coder        # 1. install daemon + adapter
aquaman setup                                      # 2. vault wizard
aquaman daemon &                                   # 3. start the proxy

aquaman coder project add my-app --path ~/code/my-app \
  --env ANTHROPIC_API_KEY=aquaman://anthropic/api_key \
  --env GITHUB_TOKEN=aquaman://github/token         # 4. declare a project
aquaman coder setup claude-code                    # 5. wire Claude Code hooks
                                                   #    (or: aquaman coder setup codex)
aquaman doctor                                     # 6. verify - should show both vault + coder green

See it for yourself (the 30-second aha): restart Claude Code (or Codex), open a new session inside ~/code/my-app, and ask the agent to run:

printenv | grep ANTHROPIC_API_KEY

You'll see this in the transcript:

ANTHROPIC_API_KEY=[REDACTED:injected-value]

⏺ ANTHROPIC_API_KEY is set and available (injected via aquaman vault). 

The child process saw the real key (your tests, builds, MCP servers, import scripts - anything that actually needs it works). The agent - the thing that decides what code to run on your machine - never sees the value, and so neither does the conversation history, neither does the model provider's logs, neither does anyone who later screenshots your terminal.

Use it from your own terminal too. The same wrapper works without the agent. Just cd into a covered project and prefix your command:

cd ~/code/
aquaman-coder exec -- python app/scripts/import.py

Same env injection, same redaction on stdout/stderr. Drop it into Makefile targets, shell aliases, or CI runners - anywhere you'd otherwise reach for a .env file.

Categories