Local agent access control

The control room between agents and credentials.

Connect named agents, author exact grants, decide Ask-first requests, inspect every access event, and revoke authority from one native macOS surface.

Account API checking Desktop version pending
Vardra Desktop
Codex · Vardra workspace Connected agent - 2 exact grants
Active
Claude Code · Client delivery Connected agent - 1 Ask-first grant
Review
Cursor · Local sandbox Connected agent - No grants
Blocked
Release automation Local workflow - Lease expired
Revoked

Exact agent grant

Billing health check

Codex · Vardra workspace
Billing test · API key
Reveal through executor
Ask-first
15 minutes · one use
Approve once Deny Revoke grant

Backend connected

The page reads release state from the account API.

Desktop Checking
CLI Checking

Desktop UX map

Every desktop action keeps the trust boundary visible.

01

Connect a named agent

Create an expiring local identity for Codex, Claude Code, Cursor, or another MCP-capable agent.

02

Grant one capability

Bind an exact secret field, action, TTL, use cap, and Auto-allow or Ask-first policy tier.

03

Decide higher-risk work

Approve or deny Ask-first requests on the same Mac while routine bounded work continues automatically.

04

Audit and revoke

Trace every request to a named agent and invalidate a grant or active lease before the next use.

Supported desktop

Vardra is focused on Apple-silicon macOS.

v0.1 desktop target

macOS

  • Apple Silicon package
  • OS keychain daily unlock
  • Menu bar lock state
View macOS download

Launch path

Start on desktop, then pair every other surface.