Project · Linux · Source release in preparation
unsudo
Let your agent work. Keep your keys.
I built unsudo after a leaked API key cost me about $100. The agent gets a local endpoint and a placeholder key. A separate gateway holds the provider key and checks each request against the rules I set.
Get the release emailHow I use it
The agent and gateway run under separate Linux accounts. I can restrict API routes, cap requests and spend where the provider supports it, and give the agent scoped access to PostgreSQL and SSH. Browser sessions stay with a protected service.
The gateway controls the operations routed through it. The setup still needs OS isolation and network rules so the agent cannot bypass it. It does not inspect the agent’s reasoning or promise that every action is safe.
Follow the project
- Website
- unsudo.dev
- Documentation
- Architecture and current scope
- Repository
- I’m preparing the source for a public release. The repository link will appear here when it is available.
- The story
- Your AI agent won’t pay your bill
Linux first. macOS and Windows support is planned. Join the release list on unsudo.dev to hear when the source is available.