अपडेट पर वापस जाएँ
New releaseJul 25, 2026

aquaman v0.14.0

🔱 AI एजेंटों के लिए एकमात्र स्वतंत्र क्रेडेंशियल प्रॉक्सी: अपना स्वयं का वॉल्ट पृथक्करण और न्यूनतम विशेषाधिकार अनुरोध नीतियां। आपकी चाबियाँ वहीं रहती हैं जहाँ आप पहले से रखते हैं, एजेंट की मेमोरी में कभी नहीं। 1Password, keychain, keepassxc और कई अन्य के साथ संगत।

साझा करें

🔱 Aquaman

CI codecov npm version npm downloads Security: process isolation TypeScript License: MIT

🔱 AI एजेंट्स के लिए एकमात्र स्वतंत्र क्रेडेंशियल प्रॉक्सी: bring-your-own-vault आइसोलेशन और least-privilege अनुरोध नीतियाँ। आपकी कुंजियाँ वहीं रहती हैं जहाँ आप उन्हें पहले से रखते हैं, कभी भी एजेंट की मेमोरी में नहीं। 1Password, keychain, keepassxc और कई अन्य के साथ संगत।

आपने Claude Code, OpenClaw, या Hermes सेट अप किया, और अब आप .env फ़ाइलों को देख रहे हैं जिनमें आपकी कीमती API कुंजियाँ सादे टेक्स्ट में पड़ी हैं। आपने लेख पढ़े हैं। आप जानते हैं कि जब किसी एजेंट को prompt-injected किया जाता है तो क्या होता है। हम समझते हैं।

Aquaman इसे तीन सुरक्षा परतों के साथ ठीक करता है:

  1. Process isolation: API कुंजियाँ एक अलग प्रॉक्सी प्रक्रिया में रहती हैं जो उन्हें egress पर इंजेक्ट करती है। एजेंट एक मार्कर रखता है, कभी कुंजी नहीं, इसलिए एजेंट में RCE होने पर भी कोई कुंजी नहीं पढ़ सकता। कोडिंग एजेंट्स को केवल वही refs मिलते हैं जो आप घोषित करते हैं, एक बार में एक कमांड।
  2. Request policies: प्रति-सेवा नियम नियंत्रित करते हैं कि एजेंट कौन से endpoints कॉल कर सकता है। Admin APIs ब्लॉक करें, deletions रोकें, drafts की अनुमति दें लेकिन sends अस्वीकार करें। अस्वीकृत अनुरोधों को कभी वास्तविक क्रेडेंशियल नहीं मिलते।
  3. Tamper-evident audit: प्रत्येक क्रेडेंशियल उपयोग SHA-256 hash chains के साथ लॉग किया जाता है। आप साबित कर सकते हैं कि क्या एक्सेस किया गया और बाद में छेड़छाड़ का पता लगा सकते हैं।

अपना रास्ता चुनें

Aquaman चार समन्वित पैकेजों के रूप में आता है, जो एक vault + एक daemon साझा करते हैं। केवल वही इंस्टॉल करें जो आपको चाहिए:

PackageWhat it doesWhen to install
aquaman-proxyCore: vault, daemon, audit, policy, CLI. The piece everyone needs.Always.
aquaman-pluginOpenClaw Gateway adapter. Spawns the proxy on Gateway startup; routes model and Telegram traffic through it; 25 builtin services across 5 auth modes.If you run an OpenClaw Gateway. Also available at https://clawhub.ai/plugins/aquaman-plugin
aquaman-coderAI coding-agent adapter. Project-scoped aquaman://service/key references resolved per Bash tool call.If you use Claude Code (today) - Codex / OpenCode / Cursor planned.
aquaman-hermesHermes agent-host plugin (Python, on PyPI). Points Hermes at an opt-in, token-gated loopback listener via its native ANTHROPIC_BASE_URL/OPENAI_BASE_URL; adds an in-session /aquaman-status command, tool, and health probe. Isolation is proxy-side; the plugin holds no credentials.If you run the Hermes agent host. pip install aquaman-hermes

एक ही aquaman CLI चारों को सामने लाता है: vault और audit के लिए top-level कमांड, OpenClaw इंटीग्रेशन के लिए aquaman openclaw ..., कोडिंग-एजेंट इंटीग्रेशन के लिए aquaman coder ... (अंदर से aquaman-coder को डेलिगेट करता है) तथा Hermes Python पैकेज के लिए aquaman hermes ...।

Quick Start

aquaman help, aquaman doctor आपके मित्र हैं।

1. केवल Vault (बस प्रॉक्सी + आपके secrets)```bash

npm install -g aquaman-proxy aquaman setup # backend wizard + store keys aquaman daemon & # start the proxy aquaman credentials list # verify

प्रॉक्सी `~/.aquaman/proxy.sock` (UDS, `chmod 0o600`) पर सुनता है। किसी भी टूल को `http://aquaman.local/<service>/<path>` पर पॉइंट करें और प्रॉक्सी आपके चुने हुए vault बैकएंड से उस सेवा के लिए auth हेडर इंजेक्ट कर देता है।

### 2. OpenClaw Gateway```bash
openclaw plugins install aquaman-plugin           # 1. install plugin + proxy
openclaw aquaman setup                            # 2. backend + keys + plugin wire-up
openclaw                                          # 3. done - proxy starts automatically

समस्या निवारण: openclaw aquaman doctor।

सीधे npm का उपयोग कर रहे हैं? npm install -g aquaman-proxy && aquaman openclaw setup वही करता है - प्रॉक्सी CLI इंस्टॉल करता है, आपकी कुंजियाँ संग्रहीत करता है, प्लगइन को ~/.openclaw/extensions/aquaman-plugin/ में इंस्टॉल करता है, और क्रेडेंशियल्स को वायर करता है (OpenClaw ≥ 2026.6.5 पर SecretRef refs, पुराने संस्करणों पर auth-profiles.json प्लेसहोल्डर)।

aquaman openclaw setup models.providers.<svc>.baseUrl और channels.telegram.apiRoot को प्रॉक्सी के लूपबैक लिसनर पर इंगित करता है, क्योंकि OpenClaw का मॉडल ट्रांसपोर्ट और उसके चैनल प्रत्येक अपना HTTP क्लाइंट बनाते हैं और fetch इंटरसेप्टर को बायपास करते हैं। Telegram के अलावा अन्य चैनल कोई एंडपॉइंट ओवरराइड उजागर नहीं करते, इसलिए उनके टोकन संग्रहीत और माइग्रेट किए जाते हैं लेकिन egress पर इंजेक्ट नहीं किए जाते (देखें packages/plugin/README.md)। openclaw.json में प्लगइन कॉन्फ़िग के अंतर्गत चैनल जोड़ें; समर्थित चैनलों में Slack, Discord, Telegram, MS Teams, Matrix, LINE, Twitch, Twilio, BlueBubbles, Mattermost, Nostr, Tlon, Feishu, Google Chat, ElevenLabs, xAI, Cloudflare AI Gateway, Mistral, Hugging Face, और अन्य शामिल हैं (कुल 25)।

3. AI कोडिंग एजेंट (आज Claude Code)```bash

npm install -g aquaman-proxy aquaman-coder # 1. install daemon + adapter aquaman setup # 2. vault wizard aquaman daemon & # 3. start the proxy

aquaman coder project add my-app --path ~/code/my-app
--env ANTHROPIC_API_KEY=aquaman://anthropic/api_key
--env GITHUB_TOKEN=aquaman://github/token # 4. declare a project aquaman coder setup claude-code # 5. wire Claude Code hooks aquaman doctor # 6. verify - should show both vault + coder green

**इसे स्वयं देखें (30-सेकंड का अहा):** Claude Code को पुनः आरंभ करें, `~/code/my-app` के अंदर एक नया सत्र खोलें, और एजेंट से चलाने के लिए कहें:```
printenv | grep ANTHROPIC_API_KEY

आप इसे ट्रांसक्रिप्ट में देखेंगे:``` ANTHROPIC_API_KEY=[REDACTED:injected-value]

⏺ ANTHROPIC_API_KEY is set and available (injected via aquaman vault).

*child* प्रक्रिया ने असली key देखी (आपके tests, builds, MCP servers, import scripts - जो कुछ भी वास्तव में इसे चाहता है वह काम करता है)। *agent* - वह चीज़ जो तय करती है कि आपकी मशीन पर कौन सा code चलाना है - कभी भी value नहीं देखती, और इसलिए न तो conversation history देखती है, न ही model provider के logs, न ही कोई और जो बाद में आपके terminal का screenshot लेता है।

**इसे अपने खुद के terminal से भी उपयोग करें।** वही wrapper agent के बिना भी काम करता है। बस किसी covered project में `cd` करें और अपने command के आगे prefix लगाएं:```bash
cd ~/code/
aquaman-coder exec -- python app/scripts/import.py

Same env injection, same redaction on stdout/stderr. Drop it into Makefile targets, shell aliases, or CI runners - anywhere you'd otherwise reach for a .env file.

When Claude Code runs a Bash tool in ~/code/my-app, aquaman's hook rewrites the command via updatedInput.command to wrap it under aquaman-coder exec. That wrapper:

श्रेणियाँ