COUNTERSEAL

Hold the keys.
Let agents work.

Sign in with a passkey. Your phone, laptop or security key is your login, and the same tap approves held calls.

You are offline. Counterseal needs a connection to sign in, show held requests and approve them; nothing is kept on this device.

Sign in to approve or deny a command line sign-in. You will type the code from your terminal next.

You are invited to

Invited by
Your role
For
Works until

Join only if you expected this invite from . Counterseal never sends invites by itself. The passkey you make here is yours alone and belongs to this team.

Joining signs this browser in as you, on this team. If this browser was signed in to another Counterseal account, it is signed out of it.

New to Counterseal?

Two steps: type your name, then confirm with Face ID, Touch ID, Windows Hello, your phone or a security key. No password, no email. Your passkey never leaves your device. New accounts start with public receipts on: each decision on a write is sealed in the public log as the method, the provider host, the decision and hashes, never a path, body, key, name or IP. You can turn it off in Receipts. What is public

Not affiliated with GitHub, Cloudflare, Railway, Stripe, Supabase, Vercel, Neon, Fly.io, Resend or Shopify.

Heldcoding-agent
DELETE /repos/acme/app

Deletes the repository. This cannot be undone.

Approve with passkeyDeny
GET /pullsallowed
POST /issuesallowed
GET /actions/runsallowed
COUNTERSEAL
Held0 Vault Agent tokens Deploy gates Agent keys Receipts Audit log Team1 Account Privacy
?
Agents are runningOne tap stops every agent token. Only your passkey starts them again.

Protection will be lowered

Break glass is open

Sign in a command line

Type the code shown in the terminal where you ran counterseal login.

This link tried to fill in a sign-in code for you. Counterseal never puts sign-in codes in links, emails or chats. If someone sent you this link or a code, stop here.

A command line wants access to your Counterseal account

Code
Started
From
You are

For 7 days it can see your vault's key names, held requests and audit log; create agent tokens that use your vaulted keys for any call that is not held; add keys to your vault; make agent keys and receipts keys; make guard keys that ask you to approve commands; deny held calls; and revoke tokens, receipts keys and guard keys.

It can never approve a held call, pre-approve irreversible calls, read a key, delete a vaulted key, revoke an agent key, turn receipts off or delete your account. On a team it signs in as you, with your role: a viewer's command line can only read and deny.

Did you just run counterseal login yourself, on a computer you control? If someone sent you this code or a link to this page, deny it: approving gives them your account.

A command line was signed in to your account

If this was not you, revoke it now: it is signed out at once, and every token, agent key, receipts key and guard key it made is revoked.

Held

Irreversible calls and commands your agents tried. Nothing happens until you decide.

Get started

  1. Make your passkeyDone: it signs you in and approves held calls.
  2. Try a held callA pretend agent asks to delete a pretend repository. You approve it with your passkey, like a real one. Nothing real is called, nothing is made public.
  3. Install the app and turn on alertsSo a held call reaches you on your phone or computer, with no website to open.
  4. Put a real API key in the vaultGitHub, Cloudflare, Stripe and 7 more. Encrypted; no agent ever sees it.
  5. Give your agent a token insteadIt works only through Counterseal, so irreversible calls wait for you.
  6. Your agent's first protected callPaste the token into your agent (the app shows the config). The first call that goes through Counterseal ticks this.

Install Counterseal

An installed Counterseal opens from your dock, taskbar, Start menu or Home Screen like any app, shows how many requests are waiting on its icon where your system supports it, and alerts you when an agent is stopped. It is the same app as this page: nothing else is downloaded.

counterseal...

Your browser can install Counterseal in one step.

If no button appears: in Chrome, click the install icon at the right of the address bar (or the menu, then Cast, save and share, then Install page as app). In Edge, open the menu, then Apps, then Install this site as an app.

FileNew WindowAdd to Dock...
  1. In Safari's menu bar, choose File, then Add to Dock. (Or click the Share button in the toolbar, then Add to Dock.)
  2. Keep the name Counterseal and click Add. It opens from the Dock and Launchpad like an app.
  3. Open it from the Dock, sign in, and turn on alerts inside the app: the Dock icon then shows how many requests are waiting.

Needs macOS Sonoma 14 or later. Your passkey from Safari works in the app.

1. Share2. Add toHome Screen3. Add
  1. Open this page in Safari. Tap the Share button (the square with an arrow).
  2. Scroll down and tap Add to Home Screen, then Add.
  3. Open Counterseal from your Home Screen, sign in with your passkey, and tap Turn on alerts. Only the Home Screen app can get alerts and show a badge on its icon.

Alerts and the icon badge need iOS or iPadOS 16.4 or later. Some other browsers on iPhone also offer Add to Home Screen in their Share menu; if yours does not, use Safari.

  1. Tap Install below, or open your browser's menu and tap Install app (or Add to Home screen).
  2. Open Counterseal from your Home Screen, sign in, and tap Turn on alerts.
counterseal...

On Windows, Firefox 143 or later can pin Counterseal to your taskbar: click Add tab to taskbar at the right of the address bar. (Not in Firefox installed from the Microsoft Store.)

Alerts work in Firefox without installing anything: turn them on below, and they arrive while Firefox is running, even with this tab closed.

Firefox on macOS and Linux does not install web apps. If you want a dock icon there, use Safari (macOS) or a Chromium browser.

Counterseal is installed and running as an app. Turn on alerts on this device if you have not yet.

Where the app works
WhereInstallAlertsBadge on the icon
Chrome, Edge (Windows, macOS, ChromeOS, Linux)Yes, one clickYesWindows, macOS and ChromeOS
Chrome, Edge, Samsung Internet (Android)Yes, Install appYesNo number; your launcher may show a notification dot
Safari (macOS Sonoma 14 or later)File, Add to DockYesYes, when alerts are allowed in the app
Safari (iPhone, iPad)Share, Add to Home ScreeniOS and iPadOS 16.4 or later, from the Home Screen app only16.4 or later, with alerts allowed
Firefox (Windows)143 or later: Add tab to taskbarYes, in the browserNo
Firefox (macOS, Linux)NoYes, in the browserNo

Approving always needs your passkey inside the app. An alert only opens the request; it never approves it.

Get alerted on this device

When an agent is stopped, this phone or computer buzzes and the notification opens the request. The alert itself carries nothing: details load from Counterseal only after you tap.

All clear

When an agent tries something it can't take back, it waits here. Turn on alerts to hear about it on your phone.

Vault

Your real API keys. Encrypted, never shown again, never given to an agent.

No keys yet.

Add a key

Agent tokens

What your agents hold instead of keys. Scoped, expiring, revocable.

No tokens yet.

New token

Brakes (optional)

Past a limit the token trips: its writes wait until you reset it with your passkey, and reads still pass. A write is any request that is not a GET or HEAD. The repeat limit trips on the request after that many identical ones (2 to 100).

Only Stripe refunds and payouts, in that one currency. Transfers, charges and the rest stay held.

Pre-approvals and money caps are paused while your team requires two seals or someone other than the maker: no one person can approve in advance.

Deploy gates

Hold a GitHub Actions job until you approve it with a passkey. The approval is bound to the repository, workflow, commit and run in the token GitHub signs for the job.

No gates yet.

New gate

A gate accepts only what you list here: one repository, its workflow files and the branches or tags it deploys from. Nothing is accepted by default, and a gate cannot be edited (make a new one and revoke the old). Making one asks for your passkey, because it decides which repository may ask you to approve deploys. A gate does not use GitHub's required reviewers (GitHub offers those only for public repositories on the Free, Pro and Team plans); it checks the token GitHub signs for the job.

Hand out a key (optional: no approval, no key)

Pick a key from your vault and the job gets no deploy key until you approve. On approval it receives a Counterseal token for that key, valid 15 minutes and limited by the policy below; the real key never leaves the vault. A policy that pre-approves irreversible calls is allowed here only because making the gate takes your passkey.


          

Agent keys

Prove who. Each agent holds its own Ed25519 key and signs every request with it, so a stolen token alone is useless.

No agent keys yet.

New agent key

Made in this browser. The private key is downloaded to you as a file and never sent anywhere; only the public key and a proof that you hold it reach the server. Put the file on the agent's machine and set LEASH_AGENT_KEY to its path. From the agent's machine, npx counterseal agent-key (0.3.0) does the same.

Receipts

If it was recorded, you can prove it. Decisions sealed in the public log, as hashes and labels. Verify a receipt

Public receipts

No receipts yet.

Receipts API keys

For agents that record their own actions with POST /v1/receipts. Everything they send is public: send hashes, not content.

No receipts keys yet.

New receipts key

Audit log

Append-only. Each entry commits to the one before it.

Evidence pack

Every decision in a date range with the audit chain, the public receipts' numbers, and the public log's latest signed checkpoint and key, checked here in your browser: it recomputes every hash itself, so you do not have to take our word for it. Download it as JSON, and the decisions as CSV for a spreadsheet.


        
How this lines up with the EU AI Act and SOC 2 (our interpretation)

Team

Everyone signs in with their own passkey. With two seals, an irreversible action needs two different people.

One seal

Change it

Raising takes effect now, for actions already waiting too. Lowering it, or letting the person who asked count, waits 24 hours, wakes every member's devices, and any approver can cancel it in that time.

People

Invite someone

The link works once, for the person you name, and shows them this account, your name and the role before they make their passkey. Send it privately.

Open invites

No open invites.

Break glass

For the night the second approver cannot be reached. An owner or approver opens a window of 5 to 60 minutes with a passkey; while it is open, what Counterseal would hold for the tokens and guard keys you pick goes through, every call it lets through is on the record and in its public receipt as a break-glass call, and every member and channel is told at once. It cannot be extended, three a day at most. It never lifts a freeze, a tripped breaker or a money cap, and never applies to deploy gates.

Alert channels

Slack, Discord or Google Chat also get told when something is held, partly sealed, or the team changes. They are only told: nobody can approve from a channel, approving always needs a passkey in this app. A message says who asked, the rule, how many seals and the link; never the path, command, body, amount, a name or a reason. The webhook address is kept encrypted and is not shown again.

No channels yet.

Roles

Owner
Everything: the team, the seals needed, the vault, deleting the account. Seals held actions.
Approver
Seals held actions with their passkey. Makes tokens and keys for their agents.
Member
Makes tokens, guard keys and keys for their agents. Cannot seal.
Viewer
Reads everything, and can deny a held action or freeze the account. Nothing else.

Anyone can deny: one no ends a held action. A passkey proves who is there; what they may do is checked by Counterseal on every request.

Account

Your data, and how to take it all away.

What Counterseal keeps about you

Your name, your passkey's public key, your encrypted vault, token, receipts key and guard key hashes, agent public keys, holds (for a coding agent's command: the command, its folder name and your deny reason), your audit log, the limits and money caps you set on a token, what each token's money caps have let through today (kept 35 days), its breaker's counts for the current hour and 5 minutes, whether your account is frozen, your receipts counters and openings, the country and network name each command line sign-in started from and, if you turn on alerts, each device's push address. On a team, also each person's name, role and the label the owner gave them, who invited whom, open invites (as hashes), and who sealed each held action, with which passkey (a short fingerprint) and when. Also five first-time dates (your first token, first protected call, first demo, first installed use, first alerts) for the Get started list and our totals, and any demo held calls you try. Never your face, fingerprint, readable keys or private keys. Privacy policy. Download all of it or choose how long held requests are kept under Privacy.

Passkeys

Command line sign-ins

Each counterseal login of the last 7 days, where it started, and whether it is still signed in (7 days at most). Revoking one signs that command line out and revokes every token, agent key, receipts key and guard key it made, even after it signed out.

No command line sign-ins in the last 7 days.

Guard keys

For the guard on a coding agent's machine (counterseal guard): it holds commands such as terraform destroy until you approve them here with your passkey. A guard key can ask for an approval and read your answer; it can never approve. A key made by the CLI ends with that command line sign-in; a key made here lasts until you revoke it.

No guard keys yet.

Delete account

Erases your account, passkeys, vault, tokens, agent keys, receipts keys, guard keys, holds, sessions and audit log immediately, and unlinks your public receipts (they stay in the log, but nothing on our side says they were yours). On a team, everyone's access, passkeys and seals go with it. Agents using your tokens stop working. This cannot be undone.

Privacy

What Counterseal keeps, for how long, who processes it, and how to take all of it with you.

Download all my data

One JSON file with everything Counterseal keeps about this account: settings, people and roles, passkeys (as fingerprints), sessions, vault entries (names and dates, never a key or any part of one), tokens and their policies, keys (labels and dates, never the key), every held request and command still kept, seals, invites, which push services your devices use (never the push address), counters and the whole audit log. Your passkey confirms it; 3 times an hour; it is written to the audit log.

Only an owner of this account can download all of it. Ask an owner, or write to privacy@gautamkhosla.com.

How long it is kept

Closed means approved and used, denied or expired. Waiting ones are never deleted early. The audit log keeps a fingerprint of each one.

Who processes it

Counterseal runs on Cloudflare (Workers, D1 and a Durable Object), our only processor. If you turn on alerts, your browser's push service (Apple, Google, Mozilla or Microsoft) carries an empty wake-up and nothing else. No analytics, no ads, no third-party scripts. Subprocessors

For your data protection officer

  • Records of processing (summary): purposes, data, legal bases and retention.
  • Data processing agreement: a template covering GDPR Art. 28 and PIPEDA; not legal advice, have your lawyer review it.
  • Security standards self-assessment: OWASP ASVS 5.0 and four OWASP Top 10 lists. Self-assessed, not certified.
  • Evidence of every decision: Audit log, Evidence pack (verified in your browser).
  • Erasure: Account, Delete account (an owner, with a passkey). Public log entries stay, unlinked from you.