Across homes, teams & vendors

Your control center for every AI device

Like phone permissions plus cloud memory: every AI device asks before it remembers, accesses, or acts — and your memory and rules follow you across homes, teams, and vendors.

9:41● ● ▮
Devices
🤖
Pip
Kids' toy · Active
1
Devices
4
Allowed
0
Blocked
🛡️Pip can use 2 of 4 memories, control the living room.
Allow Pip to access
PPersonalRead & update
FFamilyRead & update
WWorkDon't Allow
TTravelRead only
SSpendingDon't Allow

Three things you're always in charge of

Control · the gate
Nothing happens without your say-so.

It can't spend, read the family calendar, or call out unless you allow it. Revoke any permission in one tap.

Memory · the hook
Your AI remembers you — and you own the memory.

Import what it should know on day one. The memory lives with you, not the device maker.

Portability · no lock-in
Switch devices. Keep your memory.

Your memory and rules follow you across devices, homes, teams, and vendors. No lock-in.

See it live

The actual app, right here

This is the real Agent Terrier app — tap through it. Switch the theme or language up top and it re-skins instantly.

9:41
Devices
Agent Terrier
Hi Alex · all under your control
1
Devices
4
Permissions on
1
Blocked today
How it works

Pairing a device starts with a quick scan

Four steps. You confirm safe defaults — you don't configure.

Tap a step, or use the arrows
Scan to pair
Pip

Open the app and scan the QR code on the new device — it introduces itself to your control center.

🛡️

Honest about enforcement: online revocation is immediate; offline or cached capabilities expire on a short timer — never “instant everywhere.” Sensitive actions are blocked when the device is offline.

For families

Permissions in plain language

Set per device — a kids' toy is nothing like a work assistant.

P
Pip
Permission profile
Kids' toy
Personal
Diary entries, preferences, profile
Read & update
Family
Shared schedules, lists, routines
Read & update
Work
Projects, calendars, documents
Don't Allow
Travel
Places, bookings, trip plans
Read only
SpendingHIGH
Pay for small things you approve
Don't Allow
EmailHIGH
Send and receive mail
Don't Allow
Smart home
Lights, locks and plugs
Allow

You confirm; you don't configure — the AI recommends safe defaults, you approve with a tap. Tap any permission to see and change it in the app.

Developers / Open source

Agent IAM + memory control plane

The technical layer behind the consumer experience. Bring your own cloud; we provide only the control plane.

Read the docsView on GitHub
Broker, not proxy.
We hand your agent a key and get out of the way.
Open by default.
Every line in the trust boundary is open. MIT OR Apache-2.0.
Bring your own cloud.
Run the substrate in your own account; we provide identity, gate, memory policy, audit & revocation.

One place to audit everything

Permissions and memory together are your AI's context — see, question, and revoke all of it from one control center.

Permissions and memory, audited in one place

Every grant, every memory read, every revoke lands in one tamper-evident timeline — across every device you've paired. Nothing your AI does is off the books.

PermissionsMemoryActivity log
Granted Travel memory · Read
2:14 PM
Memory read Pip opened travel memory
2:14 PM
Blocked Tried to call out · no permission
2:09 PM
Revoked Spending turned off
1:50 PM
Sealed Work memory · never read
Revocation

Online revocation is immediate; offline or cached capabilities expire on a short timer — never “instant everywhere.”

Audit

A real-time activity feed in the app, plus a ~2-minute on-chain anchor for tamper-evidence.

Isolation

Every device is sandboxed on its own — one device can never reach another's memory.

Sovereign by design

Your keys. Your rules — on a chain no one controls.

Your agents' permissions live on a public chain that only your passkey can change — not in our database. We run the plumbing; we can't grant access you didn't sign for.

Sovereign

Every permission is granted by your own passkey and written on-chain. We can't grant your agents access you didn't sign for — we don't hold a key that can.

Trustless

Don't take the broker's word for it. Every data request is re-checked against your on-chain grant by an independent worker — no single server can over-reach.

Neutral

The infrastructure is stateless and replaceable — it reads your policy from the chain, never a database we own. A new node is correct the moment it starts.

One key writes. Everything else only reads.
Enterprise-grade · user-sovereign

Built in the language security teams already trust

AgentKeys maps cleanly to enterprise identity standards — then adds the part a platform-local IAM system cannot promise: user-owned authority across partners, clouds, and devices.

Enterprise-grade standards
Workload identity

Agent identities map to the same mental model as SPIFFE-style workload identity: every AI runtime has a verifiable actor.

OIDC federation + STS

Short-lived cloud credentials replace long-lived keys, with resource access scoped by attributes instead of shared secrets.

PDP / PEP enforcement

Policy is decided by a deterministic gate and enforced at the action boundary, not left to the model to remember.

Audit + revocation

Every grant, read, denial, and revoke becomes operational evidence, with tamper-evident anchoring for proof.

AgentKeys edge
User-signed authority

Permissions are granted by the owner, not silently expanded from a vendor admin console.

Device-bound presence

Sensitive changes require a device key plus biometric user presence, giving agents a real hardware boundary.

Cross-partner memory

Memory and rules can follow the user across devices and brands instead of staying trapped in one product.

Neutral trust layer

We do not replace the partner app, agent, or MCP. We make those surfaces safe to authorize and easy to revoke.

Partners keep the app, device, agent, and MCP surface. AgentKeys supplies the consent, scoped memory, tool authorization, audit, and revocation layer behind them.
Security · keys

Security is our top priority

The keys that control your AI never sit in one place. We split trust across independent boundaries, so no single break can take it all.

01
Your device
Your keys live here. Your face authorizes any change.
02
The gatekeeper
Hands out time-limited permissions. Holds no master secret.
03
The sealed vault
The master secret never leaves secure hardware.
04
The workers
Each does one job, and holds nothing at rest.
05
The ledger
A tamper-evident record every action is checked against.
Five independent locks. Breaking one never opens the rest.
Sealed in hardware
The master secret stays inside secure hardware — not even we can read it.
Your face is the key
Sensitive changes need a hardware biometric — a stolen laptop can't grant itself power.
Cryptographically anchored
Every action is signed and checked against a tamper-evident ledger.
Open source, open to audit.
Every line inside the trust boundary is public — security researchers and anyone else can verify exactly how your keys are handled, not just take our word for it.
View the code on GitHub

Bring every AI device under one roof

Request early access — we'll reach out as we open up.

No spam. One email when your invite is ready.