Backed byY Combinator
Firewall for any agent
Built for engineering teams
Stop babysitting your coding agents.
OneCLI gates and blocks risky actions, and keeps keys in the vault.
$ onecli run -- claudecodexcursor
permissions: guarded by onecli
>
✻ Baked for 3s
⏺ Bash(psql -c "DELETE FROM orders;")
└ ✗ rejected by onecli · DELETE without WHERE is not allowed
↳ nothing reached the database · orders intact
SAFE ✓
Trusted by
- Docker
- MindsDB
- Zoho
- Coralogix
- Kakao Entertainment
- Cleo
- Optibus
- Reply.io
- Kaiko
- Percent
- Pillar Security
- Phase
- Medallion
- Glilot Capital
Every agent. One gateway.
Scoped credentials injected per request. Agents never hold a real secret.
OneCLI secures them all
OneCLI enforces at the network layer, covering every path your agent takes:
MCP tool calls, CLI commands, curl, and the code it writes.
“CLIs are super exciting precisely because they are a ‘legacy’ technology, which means AI agents can natively and easily use them.”
It happened to her.
It won't happen to you.
META's head of AI safety and alignment gets her emails nuked by OpenClaw
>be director of AI Safety and Alignment at Meta
>install OpenClaw
>give it unrestricted access to personal emails
>it starts nuking emails
>"Do not do that"
>*keeps going*
>"Stop don't do anything"
>*gets all remaining old stuff and nukes it aswell*
>"STOP OPENCLAW"
>"I asked you to not do that"
>"do you remember that?"
>"Yes I remember. And I violated it."
>"You're right to be upset"



With OneCLI, agents call APIs through a gateway that injects credentials at the network layer. They never see a key, and you control exactly what they can access.
Rules agents can't break
Prompts are suggestions. OneCLI policies are enforced at the network layer, outside the agent, outside the LLM. No matter what the model decides, the proxy enforces your rules deterministically.
Block endpoints
Prevent agents from calling specific APIs (DELETE /repos, POST /payments, or any path you define). Enforced at the proxy, not a suggestion.
Rate limit per agent
Cap how many requests an agent can make per minute, hour, or day. Stop runaway loops before they cause damage.
Require approval
Flag sensitive operations for human review before they go through. Agents wait, you decide.
Scope per project
Each agent only accesses the credentials and services assigned to its project. No cross-project leakage.
Get started
Start securing your agents today
Free forever for up to 2 agents. No credit card required.



