# Onecli

**Canonical:** https://apis.io/providers/onecli/  
**Website:** https://onecli.sh  
**APIs profiled:** 24

OneCLI is an open-source credential gateway and identity layer for AI agents. Agents connect to Gmail, GitHub, Slack, AWS, Jira and 50+ other services through a network-layer proxy that injects real API keys and OAuth tokens at request time, so the agent only ever sees placeholder credential stubs and a compromised or misbehaving agent can never leak secrets. Teams get per-agent access control, policy rules (allow, block, rate-limit, manual approval), a built-in encrypted secrets vault, and full audit logs. The REST API manages agents, secrets, policy rules, and app connections programmatically; OneCLI runs as hosted Cloud or as a self-hosted (Docker) community edition. Founded by ex-Argon Security / Aqua Security engineers and backed by Y Combinator; licensed Apache-2.0.

## Kin Score — 50.8 / 100 (developing)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 50.8).

| Facet | Score |
|---|---|
| Discoverability | 81.5 |
| Contract Quality | 57.3 |
| Governance | 16.7 |
| Contract Governance | 16.7 |
| Operational Transparency | 21.1 |
| Developer Ergonomics | 73.2 |
| Commercial Clarity | 44.7 |
| Access Clarity | 44.7 |

## Agent readiness — 37.0 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | verified |
| OpenAPI Examples | partial |
| Rate Limit Signal | no |
| Event Surface Described | no |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (24)

- **Onecli Agent Setup API** — Endpoints agents and orchestrators use to bootstrap gateway access (container config, credential stubs, gateway skill).
- **Onecli Agents API** — Manage agents and their access tokens, secrets, and configuration.
- **Onecli Approvals API** — Long-poll for pending manual-approval requests and submit approve/deny decisions.
- **Onecli Apps API** — Manage app connections (OAuth and direct credentials), BYOC configuration, permission catalogs, and blocklists.
- **Onecli Connections API** — App connections as a top-level resource.
- **Onecli Migration API** — Migrate data from a self-hosted instance to OneCLI Cloud.
- **Onecli Organization App Config API** — Connect apps (OAuth and direct credentials) and manage BYOC app configuration at the organization level. Available on OneCLI Cloud and self-hosted Enterprise.
- **Onecli Organization Approvals API** — Long-poll for manual-approval requests across every project in the organization. Available on OneCLI Cloud and self-hosted Enterprise.
- **Onecli Organization Connections API** — Manage app connections at the organization level. Available on OneCLI Cloud and self-hosted Enterprise.
- **Onecli Organization Partner API** — Inspect and detach an organization's partner relationship. Cloud only.
- **Onecli Organization Rules API** — Manage policy rules at the organization level. Organization rules apply across all projects. Available on OneCLI Cloud and self-hosted Enterprise.
- **Onecli Organization Secrets API** — Manage secrets at the organization level. Organization secrets apply across all projects. Available on OneCLI Cloud and self-hosted Enterprise.
- **Onecli Organization Settings API** — Organization-wide policy settings. Available on OneCLI Cloud and self-hosted Enterprise.
- **Onecli Partner Budgets API** — Cap how much an organization can spend on a partner LLM key. Owner or admin only. Cloud only.
- **Onecli Partner Members API** — Manage who can sign in to your partner portal. Owner or admin only. Cloud only.
- **Onecli Partner Organizations API** — Create and manage customer organizations as a partner. Requires a Partner API key. Cloud only.
- **Onecli Partner Projects API** — Manage projects within an unclaimed partner organization. Cloud only.
- **Onecli Partner Secrets API** — Manage partner-level secrets inherited by every organization you manage. Cloud only.
- **Onecli Projects API** — Manage projects within your organization. Requires admin role for create/update and owner role for delete. Cloud only.
- **Onecli Rules API** — Manage policy rules that control how agents interact with external services.
- **Onecli Secrets API** — Manage credentials that the gateway injects into outbound requests.
- **Onecli Team API** — Provision team members programmatically. Requires admin role. Cloud only.
- **Onecli User API** — Manage your user profile and API keys.
- **Onecli Utility API** — Health check and project resource summaries.

## MCP servers (1)

- **Onecli MCP Server**

## Agentic access (1)

- **Onecli Agentic Access** — 116 operations · 64 acting

## Security (2)

- **Onecli Authentication** — http · 1 scheme
- **Onecli Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC

## Tags

Company, Security, Identity, AI Agents, Secrets Management, Credentials, Gateway, Authentication, Developer Tools, MCP, Vault

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/onecli/). Scores are computed from the provider's own public artifacts under a published rubric.
