
🔱 The only independent credential proxy for AI agents: bring-your-own-vault isolation & least-privilege request policies. Your keys stay where you already keep them, never in the agent's memory. Compatible with 1Password, keychain, keepassxc and many others.
🔱 The only independent credential proxy for AI agents: bring-your-own-vault isolation & least-privilege request policies. Your keys stay where you already keep them, never in the agent's memory. Compatible with 1Password, keychain, keepassxc and many others.
You set up Claude Code, Codex, OpenClaw, Hermes, or Docker Sandboxes, and now you're staring at .env files with your precious API keys sitting there in plaintext. You read the articles. You know what happens when an agent gets prompt-injected. We get it.
Aquaman fixes this with three layers of defense:
Aquaman ships as four coordinated packages, sharing one vault + one daemon. Install only what you need:
| Package | What it does | When to install |
|---|---|---|
aquaman-proxy | Core: vault, daemon, audit, policy, CLI. The piece everyone needs. | Always. |
aquaman-plugin | OpenClaw Gateway adapter. Spawns the proxy on Gateway startup; routes model and Telegram traffic through it; 25 builtin services across 5 auth modes. | If you run an OpenClaw Gateway. Also available at https://clawhub.ai/plugins/aquaman-plugin |
aquaman-coder | AI coding-agent adapter. Project-scoped aquaman://service/key references resolved per Bash tool call. | If you use Claude Code or Codex. |
aquaman-hermes | Hermes agent-host plugin (Python, on PyPI). Points Hermes at an opt-in, token-gated loopback listener via its native ANTHROPIC_BASE_URL/OPENAI_BASE_URL; adds an in-session /aquaman-status command, tool, and health probe. Isolation is proxy-side; the plugin holds no credentials. | If you run the Hermes agent host. pip install aquaman-hermes |
| Docker Sandboxes | Not a package: a separate path that needs only aquaman-proxy. Docker's own proxy injects the secrets; aquaman get supplies them from your vault, with the allow-list and audit log. | If you run agents in Docker Sandboxes. See Quick Start 5. |
A single aquaman CLI surfaces all four: top-level commands for vault and audit, aquaman openclaw ... for the OpenClaw integration, aquaman coder ... for the coding-agent integration (delegates to aquaman-coder under the hood) as well as aquaman hermes ... for the Hermes Python package.
aquaman help, aquaman doctor are your friends.
npm install -g aquaman-proxy
aquaman setup # backend wizard + store keys
aquaman daemon & # start the proxy
aquaman credentials list # verify
The proxy listens on ~/.aquaman/proxy.sock (UDS, chmod 0o600). Point any tool at http://aquaman.local/<service>/<path> and the proxy injects auth headers for that service from your chosen vault backend.
openclaw plugins install aquaman-plugin # 1. install plugin + proxy
openclaw aquaman setup # 2. backend + keys + plugin wire-up
openclaw # 3. done - proxy starts automatically
Troubleshooting: openclaw aquaman doctor.
Using npm directly? npm install -g aquaman-proxy && aquaman openclaw setup does the same - installs the proxy CLI, stores your keys, installs the plugin into ~/.openclaw/extensions/aquaman-plugin/, and wires the credentials (SecretRef refs on OpenClaw ≥ 2026.6.5, the auth-profiles.json placeholder on older versions).
aquaman openclaw setup points models.providers.<svc>.baseUrl and channels.telegram.apiRoot at the proxy's loopback listener, because OpenClaw's model transport and its channels each build their own HTTP client and bypass the fetch interceptor. Channels other than Telegram expose no endpoint override, so their tokens are stored and migrated but not injected at egress (see packages/plugin/README.md). Add channels under the plugin config in openclaw.json; supported ones include Slack, Discord, Telegram, MS Teams, Matrix, LINE, Twitch, Twilio, BlueBubbles, Mattermost, Nostr, Tlon, Feishu, Google Chat, ElevenLabs, xAI, Cloudflare AI Gateway, Mistral, Hugging Face, and more (25 total).
npm install -g aquaman-proxy aquaman-coder # 1. install daemon + adapter
aquaman setup # 2. vault wizard
aquaman daemon & # 3. start the proxy
aquaman coder project add my-app --path ~/code/my-app \
--env ANTHROPIC_API_KEY=aquaman://anthropic/api_key \
--env GITHUB_TOKEN=aquaman://github/token # 4. declare a project
aquaman coder setup claude-code # 5. wire Claude Code hooks
# (or: aquaman coder setup codex)
aquaman doctor # 6. verify - should show both vault + coder green
See it for yourself (the 30-second aha): restart Claude Code (or Codex), open a new session inside ~/code/my-app, and ask the agent to run:
printenv | grep ANTHROPIC_API_KEY
You'll see this in the transcript:
ANTHROPIC_API_KEY=[REDACTED:injected-value]
⏺ ANTHROPIC_API_KEY is set and available (injected via aquaman vault).
The child process saw the real key (your tests, builds, MCP servers, import scripts - anything that actually needs it works). The agent - the thing that decides what code to run on your machine - never sees the value, and so neither does the conversation history, neither does the model provider's logs, neither does anyone who later screenshots your terminal.
Use it from your own terminal too. The same wrapper works without the agent. Just cd into a covered project and prefix your command:
cd ~/code/
aquaman-coder exec -- python app/scripts/import.py
Same env injection, same redaction on stdout/stderr. Drop it into Makefile targets, shell aliases, or CI runners - anywhere you'd otherwise reach for a .env file.