AI tools ask
Codex, Claude, Cursor, Hermes, OpenWork, terminals, scripts, and deploy tools request access when real work needs real credentials.
SSH and Git approvals
Reveiew sensitive requests on a trusted device. You decide what to authorize.
Starting with SSH and Git signing on iPhone.
SSH SIGNING REQUEST
A paired Mac is asking to use your SSH signing key.
Example approval screen
The goal is not to block agents. The goal is to let them keep working while sensitive authority stays visible, scoped, and approved somewhere more trustworthy than the ordinary coding environment.
Codex, Claude, Cursor, Hermes, OpenWork, terminals, scripts, and deploy tools request access when real work needs real credentials.
Early access starts with a lite container on iPhone or Android, with dedicated Hito hardware planned for higher-value use.
You see the sensitive action on a trusted device and approve the scoped result, not a blanket credential handoff.
HoldKey starts with developer access because that is testable: Git, SSH, deploys, API credentials, and agent workflows across tools like Codex, Claude, Cursor, Hermes, and OpenWork. Payment credentials, card data, crypto keys, passkeys, passwords, and documents belong to the broader authority-vault direction, but every class needs its own typed approval model.
Early access is for builders who want to help shape trusted-device approvals around their own workflows.
The lite container makes the workflow reachable. Dedicated Hito hardware is the advanced path for users who want a smaller attack surface and stronger ceremony.
Git signing, API-key use, card-use approval, crypto signing, passkeys, and passwords should be separate typed requests with clear scope, expiry, and audit behavior.
If this is the exact discomfort you are feeling with AI coding tools, send a note. The best early feedback is specific: which tool you use, what credentials it can touch, and what would make you comfortable.