Passkeys protect your authority
Signing in uses your device's passkey. Adding lasting access requires a fresh confirmation. A recovery key lets you replace lost passkeys.
Security comes from the boundaries enforced around an agent, as well as the model you choose.
Signing in uses your device's passkey. Adding lasting access requires a fresh confirmation. A recovery key lets you replace lost passkeys.
Each credential is encrypted separately and bound to one service origin. Agents receive a result, not an API for retrieving the secret.
A mission names the permitted actions, sites, resources, budget and expiry. Deterministic checks enforce that scope on each action.
Device and agent credentials are revocable. Browser sessions use redacted observations; screenshots are withheld after secret entry.
Production requires an isolated customer identity and database. Hosted vaults also require customer-bound KMS. Operators must isolate the actual machines, cloud permissions and backups; a configuration flag is not that infrastructure.
Commands fail closed until local execution isolation is configured. Container mode mounts only a selected workspace and defaults to no network. Explicit unsandboxed compatibility mode is not suitable for a master-key device.
The cloud vault decrypts credentials to use them; it is not zero knowledge. Give agents restricted automation keys. The Mac preview has a separate device-only Keychain safe with local authentication, no agent API and no cloud recovery.
This is a security preview, not approval for unrestricted master-key or customer production use. Independent penetration testing, real cloud-isolation tests, container escape tests and physical-device acceptance remain required.
Security controls reduce risk; they do not make every website, integration or approved command safe. Provider permissions and the authority you grant still apply.