Let agents run production. Keep your keys.
Claude Code, Codex, and Cursor use Railway, Vercel, GitHub, and Stripe through Passport. Destructive actions wait for you.
npx passport-bridge@latest scan
See which keys your agents can reach. Runs locally. No account.
Set up in two minutes.
Two commands, then nothing new to learn. Needs Node.js 20 or newer, and you can skip any step.
- 1
npx passport-bridge@latest scanLists the keys your agents can read on this computer and what each one can do. No account, and nothing leaves your machine. - 2
npx passport-bridge@latest initSigns you in, connects the apps it found, adds Passport to your agents, and turns on the guard and production safety. Each step asks first. - 3Work as usualYour agents reach those apps through Passport. Reads and routine writes go through, and destructive actions wait for you. Rotate your old keys once your agents don't need them.
Production safety.
One setting covers Railway, Vercel, Supabase, Cloudflare, GitHub, and Stripe. Choose Off, Ask first, or Block. While it's on, secrets, domains, raw SQL, rollbacks, and refunds count as destructive too.
It only tightens. A stricter choice of yours or a workspace rule still wins.
A guard in
the terminal.
Agents also run CLIs directly. With the guard on, Claude Code and Cursor ask before destructive commands Passport recognizes, like railway volume delete or git push --force. In Codex it can block, but can't ask yet.
It's a guardrail, not a security boundary. It can't see inside scripts, aliases, or make targets.
See what your
agents did.
Every call through Passport lands in Activity, with the agent, the tool, and the result. So do the commands the hook reports. Passport records the action, never the prompt or the data.
Free for one person.
Unlimited apps and agents, approvals, and Activity. No card required. Bring your team on Pro when you're ready.