
Today, many agents read keys and sensitive info from dotenv files, configs, or memory. One bad prompt or compromised tool can drain your wallet, API bill, or private data. DCP makes agents safe for real work: your wallets and API keys stay encrypted on your own machine. Give each agent only the scopes it needs; it asks, you approve from Telegram or App. Daily budgets, logs, and instant revoke keep you in control. Open source, non-custodial, and works with Claude, Cursor, OpenClaw, and Hermes.
DCP provides a secure method for AI agents to access encrypted permissions and keys, ensuring sensitive information remains protected on the user's machine. It offers features like scoped access, daily budgets, and instant revocation, while being open source and compatible with various AI models.
The comments reflect a mix of curiosity and concern about AI security and decision-making.
Would you give your private keys to your AI agents? What if an agent makes the wrong decision?
<p>Hey PH! I’m Iftakhar, building DCP.</p><p></p><p>AI agents are moving from answering questions to executing real work: signing transactions, using API keys, making payments, and calling tools across apps.</p><p></p><p>But there’s a problem: agents should not hold private keys, raw credentials, or sensitive information.</p><p></p><p>DCP is my attempt to solve that. It is a local permission vault for AI agents.</p><p></p><p>The flow is simple:</p><p></p><p>agent asks </p><p>you approve on Telegram or in the app </p><p>DCP signs locally </p><p>secret never enters the model context</p><p></p><p>What works today:</p><p></p><p>- desktop app</p><p>- local encrypted vault</p><p>- Telegram approvals</p><p>- Solana wallet signing</p><p>- API credential storage</p><p>- budgets and approval limits</p><p>- MCP-compatible agent flow</p><p>- open source repo</p><p></p><p>I built this because I think the next bottleneck for agents is not intelligence. It is permission.</p><p></p><p>If agents are going to act for us, they need a safe way to use wallets, credentials, and sensitive tools without taking custody.</p><p></p><p>Would love feedback from people building agents, wallets, MCP tools, x402 apps, or anything around agent commerce.</p><p></p><p>Website: <a href="https://dcpagent.com" target="_blank" rel="nofollow noopener noreferrer">https://dcpagent.com</a> </p><p>Docs: <a href="https://dcpagent.com/docs" target="_blank" rel="nofollow noopener noreferrer">https://dcpagent.com/docs</a> </p><p>Download: <a href="https://dcpagent.com/#download" target="_blank" rel="nofollow noopener noreferrer">https://dcpagent.com/#download</a> </p><p>GitHub: <a href="https://github.com/1lystore/dcp" target="_blank" rel="nofollow noopener noreferrer">https://github.com/1lystore/dcp</a></p>
<p>Congrats on the launch! One question, if we hit the daily cap does it pause and wait for next day or does it notify you?</p>
<p>the harder question underneath this product is whether detecting AI use in a technical interview is actually the right goal. a senior engineer who knows how to use AI tools effectively might be more valuable than one who can whiteboard without them. curious if there's a way to configure what counts as unauthorized versus what's just how people actually work now</p>