rsdouglas

Janee — AI skill for Claude Code

AI community

Secrets management for AI agents via MCP • @janeesecure.

How to install Janee

This entry records only its repository, not the path inside it, so there is no exact command to give. Open rsdouglas/janee and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Janee does

Secrets management for AI agents via MCP • @janeesecure.

Alternatives in AI

  • Claude Task Master — by eyaltoledano - A task management system for AI-driven development with Claude, designed to work seamlessly 26k ★
  • AI Dev Tasks — A simple task management system for managing AI dev agents 7.8k ★
  • OpenSpace — "OpenSpace: The Skill Management Layer for AI Agents" -- https://open-space.cloud/ 7.5k ★

README

Janee 🔐

**Secrets management for AI agents via MCP**

[![npm version](https://img.shields.io/npm/v/@true-and-useful/janee.svg)](https://www.npmjs.com/package/@true-and-useful/janee) [![npm downloads](https://img.shields.io/npm/dw/@true-and-useful/janee.svg)](https://www.npmjs.com/package/@true-and-useful/janee) [![License: MIT](https://img.shields.io/badge/License-MIT-blue.svg)](https://opensource.org/licenses/MIT) [![GitHub stars](https://img.shields.io/github/stars/rsdouglas/janee.svg?style=social)](https://github.com/rsdouglas/janee)

Your AI agents need API access to be useful. But they shouldn't have your raw API keys. Janee sits between your agents and your APIs — injecting credentials, enforcing policies, and logging everything.

✨ Features

🔒 Zero-knowledge agents Agents call APIs without ever seeing keys
📋 Full audit trail Every request logged with timestamp, method, path, status
🛡️ Request policies Allow/deny rules per capability (e.g., read-only Stripe)
⏱️ Session TTLs Time-limited access with instant revocation
🔌 Works with any MCP client Claude Desktop, Cursor, OpenClaw, and more
🏠 Local-first Keys encrypted on your machine, never sent to a cloud
🖥️ Exec mode Run CLI tools with injected credentials — agents never see the keys
🤖 GitHub App auth Short-lived tokens for autonomous agents — no static PATs
🐦 Twitter/X OAuth 1.0a Per-request OAuth signing — 4 secrets stay encrypted
☁️ AWS SigV4 Sign AWS API requests server-side — SES, S3, and more
🔧 Automatic git auth git push/pull just works when credentials include GitHub tokens

The Problem

AI agents need API access to be useful. The current approach is to give them your keys and hope they behave.

  • 🔓 Agents have full access to Stripe, Gmail, databases
  • 📊 No audit trail of what was accessed or why
  • 🚫 No kill switch when things go wrong
  • 💉 One