Every access decision, under local control.
Vardra connects named coding agents to exact, time-boxed capabilities without returning raw credentials to the model. Here is the complete local policy path.
Local policy, not a hosted control plane
Agent identities, grants, approvals, leases, audit, and revocation stay on the operator’s Mac. Routine work does not depend on a remote policy service.
Raw values stay outside the model
The trusted local executor may use an approved credential, but model-facing MCP output contains state and redacted task output—not the secret or a reusable bearer capability.
Human input only when risk calls for it
Auto-allow keeps routine work moving inside a bounded lease. Ask-first pauses higher-risk requests for an explicit same-Mac approval or denial.
Agent identity
Named software identities
Connect each coding agent as its own attributable identity instead of inheriting the operator’s access.
Expiring connection credentials
Agent connections are scoped and time-bound, with no implicit owner or administrator authority.
Deny by default
A connected agent receives no secret capability until an exact grant authorizes it.
Immediate agent revocation
Invalidate an agent and every active lease tied to it before the next attempted use.
Exact grants
Secret-and-field scope
Authorize one exact secret field instead of exposing a whole vault, file, or environment.
Action scope
Separate metadata reads from reveal-through-executor actions so low-risk discovery grants no credential use.
TTL and use caps
Set grant expiry, maximum lease duration, and total uses to bound the blast radius.
Auto-allow or Ask-first
Choose the risk tier explicitly for every grant; there is no ambiguous global approval mode.
Brokered execution
Trusted local executor
Approved credentials reach a Vardra-controlled local execution boundary, not the model-facing response.
No raw-secret MCP output
Agent tools receive request state, non-authorizing IDs, and redacted results rather than plaintext values.
Same-Mac approval inbox
Ask-first requests appear in the native app and menu bar without phone push or a hosted approval service.
Fail-closed leases
Vault lock, daemon restart, expiry, denial, or revocation prevents further credential use.
Audit and control
Local access audit
Filter requests and decisions by agent and secret reference without recording the secret value.
Grant and lease revocation
Stop one capability, one active lease, or every lease for an agent immediately.
CLI and MCP workflows
Use the same local access policy from native macOS, retained command-line, and MCP-capable coding agents.
Encrypted vault foundation
Credentials remain sealed locally with optional blind sync; the broker adds controlled use on top.
Platform coverage
Want the cryptographic detail?
Every claim on this page is backed by the same Rust crypto core that ships in our clients. Read the exact key derivation, encryption, and recovery model.
Broker your first agent task free.
Start free for 14 daysAgent Access CA$29/mo CAD. Cancel anytime.