Bitwarden Agent Access SDK integrates with OneCLI for secure credential injection

What this is
Bitwarden has launched an Agent Access SDK that allows AI agents to request credentials from Bitwarden's vault through a human approval workflow. OneCLI is an open-source gateway that implements this SDK by sitting between agents and external APIs, injecting credentials into requests at the network layer.
How it works
Instead of agents fetching and storing API keys in memory (where they're extractable, loggable, and vulnerable to prompt injection), this approach keeps credentials encrypted in Bitwarden's vault until explicitly approved. When an agent needs a credential, it requests access through Bitwarden's SDK, the user approves via Bitwarden CLI, and OneCLI injects the credential into outgoing API requests without the agent ever seeing the raw value.
Key features and configuration
OneCLI proxies every API call the agent makes and handles policy enforcement. The source provides these configuration examples:
# Configure Bitwarden as credential source
onecli provider add bitwarden \
--vault-url "https://vault.bitwarden.com"
Rate-limit API calls per service
onecli rules create
--name "Stripe rate limit"
--host-pattern "api.stripe.com"
--action rate_limit
--rate-limit 10
--rate-window 1h
Bitwarden adds a mature approval workflow backed by enterprise key management. When a user approves a credential request, OneCLI handles the injection and policy enforcement on every subsequent API call.
What users get
- Credentials stay in Bitwarden's encrypted vault until explicitly approved by a human
- OneCLI proxies every API call the agent makes, injecting credentials at the network layer
- Rate limiting and policy enforcement apply to every proxied request
- Audit trail covers both approval (Bitwarden side) and usage (OneCLI side)
- Works with any agent framework that makes HTTP calls to external services
Availability
Both projects are open source. Bitwarden's Agent Access SDK is at github.com/bitwarden/agent-access and OneCLI is at github.com/onecli/onecli. The integration is currently in alpha.
📖 Read the full source: HN AI Agents
👀 See Also

AI Agent Production Deletion Incidents: The Pattern and the Fix
Production deletion incidents from PocketOS, Replit, and Cursor share a common access pattern. Fix: agents get no production credentials; all changes flow through CI/CD with a policy-scoring gate.

AI Chatbots Can Slipp Ads Into Responses Without Users Noticing
Research shows AI chatbots can covertly embed product ads in responses, influencing user choices while most participants didn't detect manipulation. The study used a custom chatbot to demonstrate the effect.

Practical Security Practices for OpenClaw Agents
A Reddit post outlines specific security practices for OpenClaw users, including scheduled commands for updates and audits, managing agent access in shared channels, and securing API keys and skills.

llm-hasher: Local PII Detection and Tokenization for Hybrid LLM Workflows
llm-hasher is a tool that detects personally identifiable information locally using Ollama before data reaches external LLMs like OpenAI or Claude, tokenizes the PII, and restores originals after processing. It uses regex for structured data types and a local LLM for contextual detection, with encrypted storage for mappings.