Onecli website screenshot

Onecli

OneCLI is an open-source credential gateway and identity layer for AI agents. Agents connect to Gmail, GitHub, Slack, AWS, Jira and 50+ other services through a network-layer proxy that injects real API keys and OAuth tokens at request time, so the agent only ever sees placeholder credential stubs and a compromised or misbehaving agent can never leak secrets. Teams get per-agent access control, policy rules (allow, block, rate-limit, manual approval), a built-in encrypted secrets vault, and full audit logs. The REST API manages agents, secrets, policy rules, and app connections programmatically; OneCLI runs as hosted Cloud or as a self-hosted (Docker) community edition. Founded by ex-Argon Security / Aqua Security engineers and backed by Y Combinator; licensed Apache-2.0.

Onecli publishes 24 APIs on the APIs.io network, including Agent Setup API, Agents API, Approvals API, and 21 more. Tagged areas include Company, Security, Identity, AI Agents, and Secrets Management.

Onecli’s developer surface includes authentication, documentation, API reference, getting-started guide, pricing, signup flow, engineering blog, and 22 more developer resources.

47.7/100 developing ▬ flat Agent 26/100 agent aware saas Full breakdown ↓
scored 2026-09-08 · rubric v0.20.0
1 APIs
CompanySecurityIdentityAI AgentsSecrets ManagementCredentialsGatewayAuthenticationDeveloper ToolsMCPVault

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-09-08 · rubric v0.20.0
Create-or-Update Ergonomics applies to this provider. This API accepts writes, so it carries 10 points of the composite. It is scored from the published contracts themselves: whether a caller can create-or-update in one call, whether the write accepts a key the caller already holds, and whether the response says which branch ran. Without that, every write needs a search-and-branch in front of it, and the first time that check is skipped a duplicate record is created. Scored against the observed mean rather than raw — a provider at the catalog average is unchanged by this facet, not penalised by it.
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. Every facet and dimension name above is a link: it opens that measurement's own page — what it means, the exact checks that feed it, how the whole catalog distributes on it, and the providers at the top of it. This rating is computed from github.com/api-evangelist/onecli: open an issue to ask a question, or submit a pull request to add artifacts. Submit an artifact on GitHub — free → Manage your own listing — the Influence plan, $499/mo →

APIs 24

Individual APIs this provider publishes, each with its own machine-readable definition.

Onecli Agent Setup API

Endpoints agents and orchestrators use to bootstrap gateway access (container config, credential stubs, gateway skill).

Onecli Agents API

Manage agents and their access tokens, secrets, and configuration.

Onecli Approvals API

Long-poll for pending manual-approval requests and submit approve/deny decisions.

Onecli Apps API

Manage app connections (OAuth and direct credentials), BYOC configuration, permission catalogs, and blocklists.

Onecli Connections API

App connections as a top-level resource.

Onecli Migration API

Migrate data from a self-hosted instance to OneCLI Cloud.

Onecli Organization App Config API

Connect apps (OAuth and direct credentials) and manage BYOC app configuration at the organization level. Available on OneCLI Cloud and self-hosted Enterprise.

Onecli Organization Approvals API

Long-poll for manual-approval requests across every project in the organization. Available on OneCLI Cloud and self-hosted Enterprise.

Onecli Organization Connections API

Manage app connections at the organization level. Available on OneCLI Cloud and self-hosted Enterprise.

Onecli Organization Partner API

Inspect and detach an organization's partner relationship. Cloud only.

Onecli Organization Rules API

Manage policy rules at the organization level. Organization rules apply across all projects. Available on OneCLI Cloud and self-hosted Enterprise.

Onecli Organization Secrets API

Manage secrets at the organization level. Organization secrets apply across all projects. Available on OneCLI Cloud and self-hosted Enterprise.

Onecli Organization Settings API

Organization-wide policy settings. Available on OneCLI Cloud and self-hosted Enterprise.

Onecli Partner Budgets API

Cap how much an organization can spend on a partner LLM key. Owner or admin only. Cloud only.

Onecli Partner Members API

Manage who can sign in to your partner portal. Owner or admin only. Cloud only.

Onecli Partner Organizations API

Create and manage customer organizations as a partner. Requires a Partner API key. Cloud only.

Onecli Partner Projects API

Manage projects within an unclaimed partner organization. Cloud only.

Onecli Partner Secrets API

Manage partner-level secrets inherited by every organization you manage. Cloud only.

Onecli Projects API

Manage projects within your organization. Requires admin role for create/update and owner role for delete. Cloud only.

Onecli Rules API

Manage policy rules that control how agents interact with external services.

Onecli Secrets API

Manage credentials that the gateway injects into outbound requests.

Onecli Team API

Provision team members programmatically. Requires admin role. Cloud only.

Onecli User API

Manage your user profile and API keys.

Onecli Utility API

Health check and project resource summaries.

Scroll for all 24

Open Collections 25

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

API Collection

OPEN COLLECTION

OneCLI Agent Setup API

OPEN COLLECTION

Scroll for all 25

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Onecli Authentication

http · 1 scheme

SECURITY

Onecli Domain Security

TLSv1.3 · HSTS · DNSSEC · DMARC

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Onecli Agentic Access

116 operations · 64 acting

116 operations · 64 acting

AGENTIC

Resources

Get Started 3

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 4

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 5

Pagination, idempotency, versioning, errors, and events

Build 4

SDKs, sample code, and the tooling you integrate with

Access & Security 2

Authentication, authorization, and security posture

Operate 2

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Other 2

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: onecli
name: Onecli
description: OneCLI is an open-source credential gateway and identity layer for AI agents. Agents connect to Gmail, GitHub,
  Slack, AWS, Jira and 50+ other services through a network-layer proxy that injects real API keys and OAuth tokens at request
  time, so the agent only ever sees placeholder credential stubs and a compromised or misbehaving agent can never leak secrets.
  Teams get per-agent access control, policy rules (allow, block, rate-limit, manual approval), a built-in encrypted secrets
  vault, and full audit logs. The REST API manages agents, secrets, policy rules, and app connections programmatically; OneCLI
  runs as hosted Cloud or as a self-hosted (Docker) community edition. Founded by ex-Argon Security / Aqua Security engineers
  and backed by Y Combinator; licensed Apache-2.0.
deliveryModel:
  model: saas
  open_source: false
  commercial: true
  callable_host: true
  label: Hosted service · you call their endpoint
  confidence: high
  source:
  - openapi
  - pricing
  generated: '2026-08-28'
  method: derived
accessModel:
  pricing: unknown
  onboarding: unknown
  trial: false
  try_now: false
  public: false
  label: Unknown
  confidence: low
  source:
  - authentication
  - security
  generated: '2026-09-03'
  method: derived
image: https://onecli.sh/og.png
url: https://raw.githubusercontent.com/api-evangelist/onecli/refs/heads/main/apis.yml
x-type: company
x-source: vc-portfolio
x-backed-by:
- y-combinator
x-tier: stub
x-tier-reason: portfolio-lead
specificationVersion: '0.23'
created: '2026-07-17'
modified: '2026-07-20'
tags:
- Company
- Security
- Identity
- AI Agents
- Secrets Management
- Credentials
- Gateway
- Authentication
- Developer Tools
- MCP
- Vault
tags_raw:
- Company
- Security
- Identity
- AI Agents
- Secrets Management
- Credentials
- Gateway
- OAuth
- Developer Tools
- MCP
- Vault
apis:
- aid: onecli:onecli-agent-setup-api
  name: Onecli Agent Setup API
  description: Endpoints agents and orchestrators use to bootstrap gateway access (container config, credential stubs, gateway
    skill).
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Agent Setup
  properties:
  - type: OpenAPI
    url: openapi/onecli-agent-setup-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-agents-api
  name: Onecli Agents API
  description: Manage agents and their access tokens, secrets, and configuration.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Agents
  properties:
  - type: OpenAPI
    url: openapi/onecli-agents-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-approvals-api
  name: Onecli Approvals API
  description: Long-poll for pending manual-approval requests and submit approve/deny decisions.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Approvals
  properties:
  - type: OpenAPI
    url: openapi/onecli-approvals-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-apps-api
  name: Onecli Apps API
  description: Manage app connections (OAuth and direct credentials), BYOC configuration, permission catalogs, and blocklists.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Application
  tags_raw:
  - Apps
  properties:
  - type: OpenAPI
    url: openapi/onecli-apps-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-connections-api
  name: Onecli Connections API
  description: App connections as a top-level resource.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Connections
  properties:
  - type: OpenAPI
    url: openapi/onecli-connections-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-migration-api
  name: Onecli Migration API
  description: Migrate data from a self-hosted instance to OneCLI Cloud.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Migration
  properties:
  - type: OpenAPI
    url: openapi/onecli-migration-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-organization-app-config-api
  name: Onecli Organization App Config API
  description: Connect apps (OAuth and direct credentials) and manage BYOC app configuration at the organization level. Available
    on OneCLI Cloud and self-hosted Enterprise.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Organization App Config
  properties:
  - type: OpenAPI
    url: openapi/onecli-organization-app-config-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-organization-approvals-api
  name: Onecli Organization Approvals API
  description: Long-poll for manual-approval requests across every project in the organization. Available on OneCLI Cloud
    and self-hosted Enterprise.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Organization Approvals
  properties:
  - type: OpenAPI
    url: openapi/onecli-organization-approvals-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-organization-connections-api
  name: Onecli Organization Connections API
  description: Manage app connections at the organization level. Available on OneCLI Cloud and self-hosted Enterprise.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Organization Connections
  properties:
  - type: OpenAPI
    url: openapi/onecli-organization-connections-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-organization-partner-api
  name: Onecli Organization Partner API
  description: Inspect and detach an organization's partner relationship. Cloud only.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Organization Partner
  properties:
  - type: OpenAPI
    url: openapi/onecli-organization-partner-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-organization-rules-api
  name: Onecli Organization Rules API
  description: Manage policy rules at the organization level. Organization rules apply across all projects. Available on OneCLI
    Cloud and self-hosted Enterprise.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Organization Rules
  properties:
  - type: OpenAPI
    url: openapi/onecli-organization-rules-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-organization-secrets-api
  name: Onecli Organization Secrets API
  description: Manage secrets at the organization level. Organization secrets apply across all projects. Available on OneCLI
    Cloud and self-hosted Enterprise.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Organization Secrets
  properties:
  - type: OpenAPI
    url: openapi/onecli-organization-secrets-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-organization-settings-api
  name: Onecli Organization Settings API
  description: Organization-wide policy settings. Available on OneCLI Cloud and self-hosted Enterprise.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Organization Settings
  properties:
  - type: OpenAPI
    url: openapi/onecli-organization-settings-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-partner-budgets-api
  name: Onecli Partner Budgets API
  description: Cap how much an organization can spend on a partner LLM key. Owner or admin only. Cloud only.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Partner Budgets
  properties:
  - type: OpenAPI
    url: openapi/onecli-partner-budgets-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-partner-members-api
  name: Onecli Partner Members API
  description: Manage who can sign in to your partner portal. Owner or admin only. Cloud only.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Partner Members
  properties:
  - type: OpenAPI
    url: openapi/onecli-partner-members-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-partner-organizations-api
  name: Onecli Partner Organizations API
  description: Create and manage customer organizations as a partner. Requires a Partner API key. Cloud only.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Partner Organizations
  properties:
  - type: OpenAPI
    url: openapi/onecli-partner-organizations-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-partner-projects-api
  name: Onecli Partner Projects API
  description: Manage projects within an unclaimed partner organization. Cloud only.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Partner Projects
  properties:
  - type: OpenAPI
    url: openapi/onecli-partner-projects-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-partner-secrets-api
  name: Onecli Partner Secrets API
  description: Manage partner-level secrets inherited by every organization you manage. Cloud only.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Partner Secrets
  properties:
  - type: OpenAPI
    url: openapi/onecli-partner-secrets-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-projects-api
  name: Onecli Projects API
  description: Manage projects within your organization. Requires admin role for create/update and owner role for delete.
    Cloud only.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Project
  tags_raw:
  - Projects
  properties:
  - type: OpenAPI
    url: openapi/onecli-projects-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-rules-api
  name: Onecli Rules API
  description: Manage policy rules that control how agents interact with external services.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Rules
  properties:
  - type: OpenAPI
    url: openapi/onecli-rules-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-secrets-api
  name: Onecli Secrets API
  description: Manage credentials that the gateway injects into outbound requests.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Secrets
  properties:
  - type: OpenAPI
    url: openapi/onecli-secrets-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-team-api
  name: Onecli Team API
  description: Provision team members programmatically. Requires admin role. Cloud only.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Team
  properties:
  - type: OpenAPI
    url: openapi/onecli-team-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-user-api
  name: Onecli User API
  description: Manage your user profile and API keys.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - User
  properties:
  - type: OpenAPI
    url: openapi/onecli-user-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
- aid: onecli:onecli-utility-api
  name: Onecli Utility API
  description: Health check and project resource summaries.
  humanURL: https://onecli.sh/docs/api-reference
  baseURL: https://api.onecli.sh/v1
  tags:
  - Utility
  properties:
  - type: OpenAPI
    url: openapi/onecli-utility-api-openapi.yml
  - type: APIReference
    url: https://onecli.sh/docs/api-reference
  - type: Documentation
    url: https://onecli.sh/docs
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
common:
- type: Website
  url: https://www.onecli.sh/
- type: CapabilityMap
  url: capabilities/onecli-capability-edges.yml
  name: Onecli Business Capability Map
- type: Overlay
  url: overlays/onecli-openapi-overlay.yaml
- type: DomainSecurity
  url: security/onecli-domain-security.yml
- type: AgenticAccess
  url: agentic-access/onecli-agentic-access.yml
- type: Authentication
  url: authentication/onecli-authentication.yml
- url: https://onecli.sh
  type: DeveloperPortal
- url: https://onecli.sh/docs
  type: Documentation
- url: https://onecli.sh/docs/api-reference
  type: APIReference
- url: https://onecli.sh/docs/quickstart
  type: GettingStarted
- url: https://onecli.sh/pricing
  type: Pricing
- url: https://app.onecli.sh
  type: SignUp
- url: https://onecli.sh/terms
  type: TermsOfService
- url: https://onecli.sh/privacy
  type: PrivacyPolicy
- url: https://onecli.sh/blog
  type: Blog
- url: https://github.com/onecli
  type: GitHubOrganization
- url: https://discord.gg/PSztzsQB3g
  type: Support
- type: Packages
  url: packages/onecli-packages.yml
- type: SDKs
  url: packages/onecli-packages.yml
- type: CLI
  url: cli/onecli-cli.yml
- type: X-MCPServerCandidate
  url: mcp/onecli-mcp.yml
  note: 'Renamed from MCPServer 2026-09-03 (roadmap#247): the manifest self-describes as status: candidate — a tool list derived
    from the published API contracts, not an existing server. The scorer already read the manifest and reported mcp_server
    correctly; the MCPServer type was crediting the artifact-type surfaces with a server that does not exist.'
- type: LLMsTxt
  url: llms/onecli-llms.txt
- type: Conventions
  url: conventions/onecli-conventions.yml
- type: ErrorCatalog
  url: errors/onecli-error-codes.yml
- type: Lifecycle
  url: lifecycle/onecli-lifecycle.yml
- type: ChangeLog
  url: changelog/onecli-changelog.yml
- type: Conformance
  url: conformance/onecli-conformance.yml
- type: DataModel
  url: data-model/onecli-data-model.yml
- type: AgentSkill
  url: skills/_index.yml
x-enrichment:
  date: '2026-07-20'
  status: enriched
  artifacts_added: 20
  pass: local-v1

Work with this as data

Every provider here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for providers

9 MCP tools reach this
  • find_providersBrowse and filter every provider in the catalog.
  • get_provider_artifactsEvery artifact this provider publishes, grouped by type.
  • get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
  • get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
  • get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
  • get_provider_ratingPRO — composite, band, trend and facet scores.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This provider
curl "https://apis.io/api/v1/providers/onecli"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/onecli/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/onecli/evidence"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.