v1.1.1
AgentSecrets v1.1.1
What's New
Agent Identity
AI agents running in your workspace can now have named identities. Every credential call made through the proxy is logged against the agent that made it, and you can issue, rotate, or revoke access tokens per agent without affecting anything else in the workspace.
agentsecrets agent list
agentsecrets agent token issue "billing-agent"
agentsecrets agent token revoke <id> --agent="<name>"Three identity levels are supported. Anonymous calls continue to work as before and are logged with an anonymous marker. Declared identity lets an agent assert a name without verification. Issued identity uses a signed token the proxy verifies on every call.
Richer Audit Logs
The audit log now captures more than what happened, it captures the state under which it happened. We moved from a jsonl file to an sqlite db
Every log entry now includes the agent identity that made the call, the domain allowlist as it existed at the moment of the call, and the workspace role of the caller. This means if something goes wrong, the log tells you exactly which agent was involved, what it was permitted to do, and whether those permissions have changed since.
New log commands:
agentsecrets log list [--tail] # stream global backend logs
agentsecrets log summary # aggregate statistics for the workspace
agentsecrets log export --format csv # export to CSV or JSON
agentsecrets log detail <id> # full record for a specific requestFilter by agent identity:
agentsecrets log list --agent billing-agent
agentsecrets log list --identity anonymous # find calls with no identity setThe log schema has no value field. That has not changed.
Bug Fix
Fixed: exec provider failing when called from a non-home working directory
When OpenClaw's exec secret provider called the AgentSecrets binary, it did so from an arbitrary working directory without setting the HOME environment variable. This caused two independent failures: the project config lookup failed because it searched relative to the current directory rather than walking up to find the project root, and keychain access failed because HOME was not set.
Both are now resolved. The exec provider falls back to the globally selected project ID stored in ~/.agentsecrets/config.json when no local project config is found in the current directory. HOME resolution is also handled correctly in environments where it is not set by the caller.
This fix was contributed by Joshua Ensley — thank you for the precise diagnosis and the clean implementation.
Upgrade
brew upgrade The-17/tap/agentsecrets
# or
npx @the-17/agentsecrets@latest[GitHub](https://github.com/The-17/agentsecrets) · [Website](https://agentsecrets.theseventeen.co) · [Docs](https://engineering.theseventeen.co/series/building-agentsecrets)
Changelog
- ea88856 Merge pull request #3 from joshua-ensley/fix/exec-provider-docker-home-1
- 1b41ef3 Merge pull request #4 from joshua-ensley/fix/exec-provider-docker-home-2
- da21b87 Update README.md
- 9b40177 Update projects.go
- 7a74e61 chore: rename pypi package to agentsecrets-cli and update READMEs
- 1cefac8 feat: Agent Identity and Richer Proxy Logs. - Introduced Agent Identity CLI & core resolution - Added Proxy Live Sync, Status Reporting, and PID tracking - Added Global Log Export, Summary Breakdowns, and Streaming - Overhauled OpenClaw integrations to support native exec - Incremented PyPI and NPM versions to 1.1.1 - Overhauled Documentation and AI workflow schemas
- be32ae2 feat: agent identity, richer logs
- d9e08cd feat: agent identity, richer logs
- 3578d91 fix: fall back to global project ID in exec command when no local config found