Onecli

OneCLI is an open-source credential gateway and identity layer for AI agents. Agents connect to Gmail, GitHub, Slack, AWS, Jira and 50+ other services through a network-layer proxy that injects real API keys and OAuth tokens at request time, so the agent only ever sees placeholder credential stubs and a compromised or misbehaving agent can never leak secrets. Teams get per-agent access control, policy rules (allow, block, rate-limit, manual approval), a built-in encrypted secrets vault, and full audit logs. The REST API manages agents, secrets, policy rules, and app connections programmatically; OneCLI runs as hosted Cloud or as a self-hosted (Docker) community edition. Founded by ex-Argon Security / Aqua Security engineers and backed by Y Combinator; licensed Apache-2.0.

Onecli publishes 24 APIs on the APIs.io network, including Agent Setup API, Agents API, Approvals API, and 21 more. Tagged areas include Company, Security, Identity, AI Agents, and Secrets Management.

Onecli’s developer surface includes authentication, documentation, API reference, getting-started guide, pricing, signup flow, engineering blog, and 19 more developer resources.

51.4/100 developing ▬ flat Agent 65/100 agent native Full breakdown ↓
scored 2026-07-23 · rubric v0.5
AccessSelf serve
24 APIs 1 MCP Servers
CompanySecurityIdentityAI AgentsSecrets ManagementCredentialsGatewayOAuthDeveloper ToolsMCPVault

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-23 · rubric v0.5
Composite quality — 51.4/100 · developing
Contract Quality 13.7 / 25
Developer Ergonomics 16.1 / 20
Commercial Clarity 8.9 / 20
Operational Transparency 2.7 / 13
Governance 0.0 / 12
Discoverability 10.0 / 10
Agent readiness — 65/100 · agent native
Machine-Readable Contract 18 / 18
Agentic Access Contract 15 / 15
MCP Server 12 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 8 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 0 / 6
Agent Skills 5 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/onecli: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 24

Individual APIs this provider publishes, each with its own machine-readable definition.

Onecli Agent Setup API

Endpoints agents and orchestrators use to bootstrap gateway access (container config, credential stubs, gateway skill).

Onecli Agents API

Manage agents and their access tokens, secrets, and configuration.

Onecli Approvals API

Long-poll for pending manual-approval requests and submit approve/deny decisions.

Onecli Apps API

Manage app connections (OAuth and direct credentials), BYOC configuration, permission catalogs, and blocklists.

Onecli Connections API

App connections as a top-level resource.

Onecli Migration API

Migrate data from a self-hosted instance to OneCLI Cloud.

Onecli Organization App Config API

Connect apps (OAuth and direct credentials) and manage BYOC app configuration at the organization level. Available on OneCLI Cloud and self-hosted Enterprise.

Onecli Organization Approvals API

Long-poll for manual-approval requests across every project in the organization. Available on OneCLI Cloud and self-hosted Enterprise.

Onecli Organization Connections API

Manage app connections at the organization level. Available on OneCLI Cloud and self-hosted Enterprise.

Onecli Organization Partner API

Inspect and detach an organization's partner relationship. Cloud only.

Onecli Organization Rules API

Manage policy rules at the organization level. Organization rules apply across all projects. Available on OneCLI Cloud and self-hosted Enterprise.

Onecli Organization Secrets API

Manage secrets at the organization level. Organization secrets apply across all projects. Available on OneCLI Cloud and self-hosted Enterprise.

Onecli Organization Settings API

Organization-wide policy settings. Available on OneCLI Cloud and self-hosted Enterprise.

Onecli Partner Budgets API

Cap how much an organization can spend on a partner LLM key. Owner or admin only. Cloud only.

Onecli Partner Members API

Manage who can sign in to your partner portal. Owner or admin only. Cloud only.

Onecli Partner Organizations API

Create and manage customer organizations as a partner. Requires a Partner API key. Cloud only.

Onecli Partner Projects API

Manage projects within an unclaimed partner organization. Cloud only.

Onecli Partner Secrets API

Manage partner-level secrets inherited by every organization you manage. Cloud only.

Onecli Projects API

Manage projects within your organization. Requires admin role for create/update and owner role for delete. Cloud only.

Onecli Rules API

Manage policy rules that control how agents interact with external services.

Onecli Secrets API

Manage credentials that the gateway injects into outbound requests.

Onecli Team API

Provision team members programmatically. Requires admin role. Cloud only.

Onecli User API

Manage your user profile and API keys.

Onecli Utility API

Health check and project resource summaries.

Scroll for all 24

MCP Servers 1

Model Context Protocol servers that expose these APIs to AI agents.

onecli-mcp.yml

MCP SERVER

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Onecli Authentication

http · 1 scheme

SECURITY

Onecli Domain Security

TLSv1.3 · HSTS · DNSSEC · DMARC

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Onecli Agentic Access

116 operations · 64 acting

116 operations · 64 acting

AGENTIC

Resources

Get Started 3

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 4

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 5

Pagination, idempotency, versioning, errors, and events

Build 4

SDKs, sample code, and the tooling you integrate with

Access & Security 2

Authentication, authorization, and security posture

Operate 2

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 1

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: onecli
name: Onecli
description: OneCLI is an open-source credential gateway and identity layer for AI agents. Agents connect to Gmail, GitHub,
  Slack, AWS, Jira and 50+ other services through a network-layer proxy that injects real API keys and OAuth tokens at request
  time, so the agent only ever sees placeholder credential stubs and a compromised or misbehaving agent can never leak secrets.
  Teams get per-agent access control, policy rules (allow, block, rate-limit, manual approval), a built-in encrypted secrets
  vault, and full audit logs. The REST API manages agents, secrets, policy rules, and app connections programmatically; OneCLI
  runs as hosted Cloud or as a self-hosted (Docker) community edition. Founded by ex-Argon Security / Aqua Security engineers
  and backed by Y Combinator; licensed Apache-2.0.
accessModel:
  pricing: unknown
  onboarding: self-serve
  trial: false
  try_now: false
  public: false
  label: Self-serve signup
  confidence: medium
  source:
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://onecli.sh/og.png
url: https://raw.githubusercontent.com/api-evangelist/onecli/refs/heads/main/apis.yml
x-type: company
x-source: vc-portfolio
x-backed-by:
- y-combinator
x-tier: stub
x-tier-reason: portfolio-lead
specificationVersion: '0.20'
created: '2026-07-17'
modified: '2026-07-20'
tags:
- Company
- Security
- Identity
- AI Agents
- Secrets Management
- Credentials
- Gateway
- OAuth
- Developer Tools
- MCP
- Vault
apis:
- aid: onecli:onecli-agent-setup-api
  name: Onecli Agent Setup API
  description: Endpoints agents and orchestrators use to bootstrap gateway access (container config, credential stubs, gateway
    skill).
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Agent Setup
  properties:
  - type: OpenAPI
    url: openapi/onecli-agent-setup-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-agents-api
  name: Onecli Agents API
  description: Manage agents and their access tokens, secrets, and configuration.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Agents
  properties:
  - type: OpenAPI
    url: openapi/onecli-agents-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-approvals-api
  name: Onecli Approvals API
  description: Long-poll for pending manual-approval requests and submit approve/deny decisions.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Approvals
  properties:
  - type: OpenAPI
    url: openapi/onecli-approvals-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-apps-api
  name: Onecli Apps API
  description: Manage app connections (OAuth and direct credentials), BYOC configuration, permission catalogs, and blocklists.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Apps
  properties:
  - type: OpenAPI
    url: openapi/onecli-apps-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-connections-api
  name: Onecli Connections API
  description: App connections as a top-level resource.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Connections
  properties:
  - type: OpenAPI
    url: openapi/onecli-connections-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-migration-api
  name: Onecli Migration API
  description: Migrate data from a self-hosted instance to OneCLI Cloud.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Migration
  properties:
  - type: OpenAPI
    url: openapi/onecli-migration-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-organization-app-config-api
  name: Onecli Organization App Config API
  description: Connect apps (OAuth and direct credentials) and manage BYOC app configuration at the organization level. Available
    on OneCLI Cloud and self-hosted Enterprise.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Organization App Config
  properties:
  - type: OpenAPI
    url: openapi/onecli-organization-app-config-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-organization-approvals-api
  name: Onecli Organization Approvals API
  description: Long-poll for manual-approval requests across every project in the organization. Available on OneCLI Cloud
    and self-hosted Enterprise.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Organization Approvals
  properties:
  - type: OpenAPI
    url: openapi/onecli-organization-approvals-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-organization-connections-api
  name: Onecli Organization Connections API
  description: Manage app connections at the organization level. Available on OneCLI Cloud and self-hosted Enterprise.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Organization Connections
  properties:
  - type: OpenAPI
    url: openapi/onecli-organization-connections-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-organization-partner-api
  name: Onecli Organization Partner API
  description: Inspect and detach an organization's partner relationship. Cloud only.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Organization Partner
  properties:
  - type: OpenAPI
    url: openapi/onecli-organization-partner-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-organization-rules-api
  name: Onecli Organization Rules API
  description: Manage policy rules at the organization level. Organization rules apply across all projects. Available on OneCLI
    Cloud and self-hosted Enterprise.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Organization Rules
  properties:
  - type: OpenAPI
    url: openapi/onecli-organization-rules-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-organization-secrets-api
  name: Onecli Organization Secrets API
  description: Manage secrets at the organization level. Organization secrets apply across all projects. Available on OneCLI
    Cloud and self-hosted Enterprise.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Organization Secrets
  properties:
  - type: OpenAPI
    url: openapi/onecli-organization-secrets-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-organization-settings-api
  name: Onecli Organization Settings API
  description: Organization-wide policy settings. Available on OneCLI Cloud and self-hosted Enterprise.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Organization Settings
  properties:
  - type: OpenAPI
    url: openapi/onecli-organization-settings-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-partner-budgets-api
  name: Onecli Partner Budgets API
  description: Cap how much an organization can spend on a partner LLM key. Owner or admin only. Cloud only.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Partner Budgets
  properties:
  - type: OpenAPI
    url: openapi/onecli-partner-budgets-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-partner-members-api
  name: Onecli Partner Members API
  description: Manage who can sign in to your partner portal. Owner or admin only. Cloud only.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Partner Members
  properties:
  - type: OpenAPI
    url: openapi/onecli-partner-members-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-partner-organizations-api
  name: Onecli Partner Organizations API
  description: Create and manage customer organizations as a partner. Requires a Partner API key. Cloud only.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Partner Organizations
  properties:
  - type: OpenAPI
    url: openapi/onecli-partner-organizations-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-partner-projects-api
  name: Onecli Partner Projects API
  description: Manage projects within an unclaimed partner organization. Cloud only.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Partner Projects
  properties:
  - type: OpenAPI
    url: openapi/onecli-partner-projects-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-partner-secrets-api
  name: Onecli Partner Secrets API
  description: Manage partner-level secrets inherited by every organization you manage. Cloud only.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Partner Secrets
  properties:
  - type: OpenAPI
    url: openapi/onecli-partner-secrets-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-projects-api
  name: Onecli Projects API
  description: Manage projects within your organization. Requires admin role for create/update and owner role for delete.
    Cloud only.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Projects
  properties:
  - type: OpenAPI
    url: openapi/onecli-projects-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-rules-api
  name: Onecli Rules API
  description: Manage policy rules that control how agents interact with external services.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Rules
  properties:
  - type: OpenAPI
    url: openapi/onecli-rules-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-secrets-api
  name: Onecli Secrets API
  description: Manage credentials that the gateway injects into outbound requests.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Secrets
  properties:
  - type: OpenAPI
    url: openapi/onecli-secrets-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-team-api
  name: Onecli Team API
  description: Provision team members programmatically. Requires admin role. Cloud only.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Team
  properties:
  - type: OpenAPI
    url: openapi/onecli-team-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-user-api
  name: Onecli User API
  description: Manage your user profile and API keys.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - User
  properties:
  - type: OpenAPI
    url: openapi/onecli-user-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-utility-api
  name: Onecli Utility API
  description: Health check and project resource summaries.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Utility
  properties:
  - type: OpenAPI
    url: openapi/onecli-utility-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
common:
- type: DomainSecurity
  url: security/onecli-domain-security.yml
- type: AgenticAccess
  url: agentic-access/onecli-agentic-access.yml
- type: Authentication
  url: authentication/onecli-authentication.yml
- url: https://onecli.sh
  type: DeveloperPortal
- url: https://onecli.sh/docs
  type: Documentation
- url: https://onecli.sh/docs/api-reference
  type: APIReference
- url: https://onecli.sh/docs/quickstart
  type: GettingStarted
- url: https://onecli.sh/pricing
  type: Pricing
- url: https://app.onecli.sh
  type: SignUp
- url: https://onecli.sh/terms
  type: TermsOfService
- url: https://onecli.sh/privacy
  type: PrivacyPolicy
- url: https://onecli.sh/blog
  type: Blog
- url: https://github.com/onecli
  type: GitHubOrganization
- url: https://discord.gg/PSztzsQB3g
  type: Support
- type: Packages
  url: packages/onecli-packages.yml
- type: SDKs
  url: packages/onecli-packages.yml
- type: CLI
  url: cli/onecli-cli.yml
- type: MCPServer
  url: mcp/onecli-mcp.yml
- type: LLMsTxt
  url: llms/onecli-llms.txt
- type: Conventions
  url: conventions/onecli-conventions.yml
- type: ErrorCatalog
  url: errors/onecli-error-codes.yml
- type: Lifecycle
  url: lifecycle/onecli-lifecycle.yml
- type: ChangeLog
  url: changelog/onecli-changelog.yml
- type: Conformance
  url: conformance/onecli-conformance.yml
- type: DataModel
  url: data-model/onecli-data-model.yml
- type: AgentSkill
  url: skills/_index.yml
x-enrichment:
  date: '2026-07-20'
  status: enriched
  artifacts_added: 20
  pass: local-v1