Bitwarden Agent Access SDK integrates with OneCLI for secure credential injection

What this is
Bitwarden has launched an Agent Access SDK that allows AI agents to request credentials from Bitwarden's vault through a human approval workflow. OneCLI is an open-source gateway that implements this SDK by sitting between agents and external APIs, injecting credentials into requests at the network layer.
How it works
Instead of agents fetching and storing API keys in memory (where they're extractable, loggable, and vulnerable to prompt injection), this approach keeps credentials encrypted in Bitwarden's vault until explicitly approved. When an agent needs a credential, it requests access through Bitwarden's SDK, the user approves via Bitwarden CLI, and OneCLI injects the credential into outgoing API requests without the agent ever seeing the raw value.
Key features and configuration
OneCLI proxies every API call the agent makes and handles policy enforcement. The source provides these configuration examples:
# Configure Bitwarden as credential source
onecli provider add bitwarden \
--vault-url "https://vault.bitwarden.com"
Rate-limit API calls per service
onecli rules create
--name "Stripe rate limit"
--host-pattern "api.stripe.com"
--action rate_limit
--rate-limit 10
--rate-window 1h
Bitwarden adds a mature approval workflow backed by enterprise key management. When a user approves a credential request, OneCLI handles the injection and policy enforcement on every subsequent API call.
What users get
- Credentials stay in Bitwarden's encrypted vault until explicitly approved by a human
- OneCLI proxies every API call the agent makes, injecting credentials at the network layer
- Rate limiting and policy enforcement apply to every proxied request
- Audit trail covers both approval (Bitwarden side) and usage (OneCLI side)
- Works with any agent framework that makes HTTP calls to external services
Availability
Both projects are open source. Bitwarden's Agent Access SDK is at github.com/bitwarden/agent-access and OneCLI is at github.com/onecli/onecli. The integration is currently in alpha.
📖 Read the full source: HN AI Agents
👀 See Also

pi-governance: RBAC, DLP, and audit logging for OpenClaw coding agents
pi-governance is a plugin that sits between AI coding agents and your system, classifying tool calls and blocking risky operations. It provides bash command blocking, DLP scanning for secrets and PII, role-based access control, and structured audit logging with zero configuration.

Critical RCE vulnerability in protobuf.js library
A critical remote code execution vulnerability in protobuf.js versions 8.0.0/7.5.4 and lower allows JavaScript code execution through malicious schemas. Patches are available in versions 8.0.1 and 7.5.5.

Sunder: A Rust-Based Local Privacy Firewall for LLMs
Sunder is a Chrome extension that acts as a local privacy firewall for AI chats, built using Rust and WebAssembly, ensuring sensitive data never leaves your browser.

Anthropic reveals industrial-scale Claude AI data extraction by Chinese labs
Anthropic confirmed Chinese AI labs used over 24,000 fraudulent accounts to scrape 16 million exchanges from Claude, extracting safety guardrails and logic structures for military and surveillance systems.