Local credential control for AI coding agents.
Local credential control for coding agents. Approve bounded actions locally. Keep raw credentials out of model context and tool output.
Demo · Downloads · Quick start · Documentation · Security · Contributing
Stop handing raw credentials to coding agents. s-gw gives agents typed handles, asks you to approve bounded local actions, resolves the credential inside a constrained process on your machine, and returns sanitized output instead of secret values.
[!IMPORTANT] s-gw is an early preview. Storage formats and interfaces may change, Windows support is still experimental, and the project has not completed an independent security audit. Do not treat it as a replacement for endpoint security or a hardened enterprise secrets platform yet.
- Agent sees: s-gw:credential:prod-readonly - You approve: agent, command, handle, environment binding, working directory, and target - s-gw runs: the command locally with the credential injected only into that child process - Agent receives: sanitized output, audit evidence, and no raw secret
If s-gw helps your agent workflow, star the project. It makes the preview easier for other developers to find.
The local console shows the approval queue, credential inventory, policy state, usage flow, and activity history without exposing secret values.
Govern Approve Execute Audit --- --- --- --- Turn secrets into typed local handles that agents can reference safely. Review the requesting agent, handle, command, environment binding, working directory, and target before access is granted. Inject the credential only into the approved child proces
From the project README.
Add the radar badge to your README — it shows your project was picked up by MCP Radar and links to this page:
[](https://mcp.liqiwa.com/s/sgateway--s-gw.html)
Open-source control plane for Codex projects: Git-backed context, visible agent progress, scoped MCP access, resumable work, and safe handoffs.
pranee54/AgentDoctorLocal CLI that audits coding-agent configuration for security, instructions, context, and MCP — no API key or code upload by default.
luckeyfaraday/frontier-orchestratorMulti-agent orchestration for Claude Code: MCP server + skill that keeps Claude as lead engineer while delegating backend work to OpenAI Codex and frontend/design work to Kimi
nisargpatel1906/Aethos_MemoryUniversal, cross-tool persistent memory bank for AI assistants (Claude Code, Cursor, Windsurf, OpenCode, Codex) powered by FastMCP, Gemini embeddings & Supabase pgvector.
menot-you/n-memoryMemory your agent can trust — every answer carries its source; when it doesn't know, it says so. Hermetic, local, MCP.
Kaseban/batonConvert AI coding sessions between Claude Code, Codex, OpenCode, Zed, Aider, Gemini CLI, Cursor, Cline & more — lossless, round-trip tested. MCP server + CLI.
The top new MCP servers of the week, every Monday. No spam, unsubscribe anytime.