Skip to content

Give agents access.
Keep the decision.

Local access control for named AI agents. Define what an agent may use, for which task, under which limits.

Open beta programme · Apple-silicon Macs
Current availability and requirements are listed at vardra.dev.

An example grant / illustration

Named agentOne task.
Defined access.
Capability
Test API credential
Policy
Ask-first
Duration
15 minutes
Use limit
One use

A local decision before execution.

A saved password
is only the start.

An agent needs access to do useful work. The next question is which identity may use a credential, what it may do, how long access lasts and how you can stop the next use.

  • Separate the agent identity from a shared standing token.
  • Make scope, expiry and approval part of the grant.
  • Keep an attributable record after the task.

One grant.
Four clear steps.

  1. 01

    Name the agent

    Give each connected coding agent its own identity, grants and attributable decisions.

  2. 02

    Set the grant

    Choose the secret field, action, expiry, lease duration and use limit. Scope the access to the task.

  3. 03

    Decide before execution

    Use Auto-allow for permitted routine work or Ask-first when a local approval is required.

  4. 04

    Review and revoke

    Read the local audit and revoke a grant or agent to deny its next broker use.

Control close to
the work.

The vault, grants, approval inbox and access audit belong to a local workflow on your Mac.

Named agent access

Connect coding agents such as Codex, Claude Code and Cursor through identifiable access.

Scoped, time-boxed grants

Define the capability and its limits rather than leaving a credential in standing agent context.

Local approval and audit

Keep the decision and record on your Mac, with a clear path to review and revoke.

Recovery you control

Save the one-time Emergency Kit when creating the vault. Recovery depends on material you retain.

Know what the
control covers.

The trusted child process holds the credential while it runs. Vardra withholds arbitrary child output and returns exit metadata.

This is an access policy boundary, not a process sandbox or an exfiltration defense. Same-user processes remain within the operating-system account's trust boundary. The readable vault opens on your device.

Keep your Emergency Kit safe. Vardra cannot reset the master password for you; recovery comes from material you control.

Read the current product information

Start at the
official source.

Find the current Mac download, setup requirements, beta terms and product information on Vardra's own website.

App support: [email protected]