UnYOLO: Agent credential broker and policy engine for your GitHub account
unYOLO is a security framework that acts as a credential broker for AI agents, preventing them from holding full account tokens. It allows users to set fine-grained, time-limited policies for agent actions on platforms like GitHub.
Why it matters
It addresses the security risks of granting AI agents broad access to sensitive developer accounts and repositories.
unYOLO Docs Concepts Guides Brokers Reference Search ⌘K YOLO safely with your agents unYOLO is a framework for building credential brokers and proxies for services like GitHub, Hugging Face, or Google Workspace. Your agent talks to the broker and never holds the real credential.
unYOLO lets you keep fine-grained policies in a local file. No permission screens to click through and no separate account to create for the agent. When the agent needs more permissions, you can give it timed grants that expire on their own.
$ gh-broker operation submit pull_request.create op_9c2f succeeded pull request #482 opened $ gh-broker operation submit pull_request.merge op_1d55 pending policy requires operator approval op_1d55 approved by operator, single use op_1d55 succeeded pull request #482 merged ‹ u unYOLO bot unYOLO
agent-a wants to merge #482 in acme/api .
1x Install unYOLO Run the guided installer on macOS or Linux.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in