Held
Irreversible calls and commands your agents tried. Nothing happens until you decide.
Get started
- Make your passkeyDone: it signs you in and approves held calls.
- Try a held callA pretend agent asks to delete a pretend repository. You approve it with your passkey, like a real one. Nothing real is called, nothing is made public.
- Install the app and turn on alertsSo a held call reaches you on your phone or computer, with no website to open.
- Put a real API key in the vaultGitHub, Cloudflare, Stripe and 7 more. Encrypted; no agent ever sees it.
- Give your agent a token insteadIt works only through Counterseal, so irreversible calls wait for you.
- Your agent's first protected callPaste the token into your agent (the app shows the config). The first call that goes through Counterseal ticks this.
Install Counterseal
An installed Counterseal opens from your dock, taskbar, Start menu or Home Screen like any app, shows how many requests are waiting on its icon where your system supports it, and alerts you when an agent is stopped. It is the same app as this page: nothing else is downloaded.
Your browser can install Counterseal in one step.
If no button appears: in Chrome, click the install icon at the right of the address bar (or the menu, then Cast, save and share, then Install page as app). In Edge, open the menu, then Apps, then Install this site as an app.
- In Safari's menu bar, choose File, then Add to Dock. (Or click the Share button in the toolbar, then Add to Dock.)
- Keep the name Counterseal and click Add. It opens from the Dock and Launchpad like an app.
- Open it from the Dock, sign in, and turn on alerts inside the app: the Dock icon then shows how many requests are waiting.
Needs macOS Sonoma 14 or later. Your passkey from Safari works in the app.
- Open this page in Safari. Tap the Share button (the square with an arrow).
- Scroll down and tap Add to Home Screen, then Add.
- Open Counterseal from your Home Screen, sign in with your passkey, and tap Turn on alerts. Only the Home Screen app can get alerts and show a badge on its icon.
Alerts and the icon badge need iOS or iPadOS 16.4 or later. Some other browsers on iPhone also offer Add to Home Screen in their Share menu; if yours does not, use Safari.
- Tap Install below, or open your browser's menu and tap Install app (or Add to Home screen).
- Open Counterseal from your Home Screen, sign in, and tap Turn on alerts.
On Windows, Firefox 143 or later can pin Counterseal to your taskbar: click Add tab to taskbar at the right of the address bar. (Not in Firefox installed from the Microsoft Store.)
Alerts work in Firefox without installing anything: turn them on below, and they arrive while Firefox is running, even with this tab closed.
Firefox on macOS and Linux does not install web apps. If you want a dock icon there, use Safari (macOS) or a Chromium browser.
Counterseal is installed and running as an app. Turn on alerts on this device if you have not yet.
Where the app works
| Where | Install | Alerts | Badge on the icon |
|---|---|---|---|
| Chrome, Edge (Windows, macOS, ChromeOS, Linux) | Yes, one click | Yes | Windows, macOS and ChromeOS |
| Chrome, Edge, Samsung Internet (Android) | Yes, Install app | Yes | No number; your launcher may show a notification dot |
| Safari (macOS Sonoma 14 or later) | File, Add to Dock | Yes | Yes, when alerts are allowed in the app |
| Safari (iPhone, iPad) | Share, Add to Home Screen | iOS and iPadOS 16.4 or later, from the Home Screen app only | 16.4 or later, with alerts allowed |
| Firefox (Windows) | 143 or later: Add tab to taskbar | Yes, in the browser | No |
| Firefox (macOS, Linux) | No | Yes, in the browser | No |
Approving always needs your passkey inside the app. An alert only opens the request; it never approves it.
All clear
When an agent tries something it can't take back, it waits here. Turn on alerts to hear about it on your phone.
Vault
Your real API keys. Encrypted, never shown again, never given to an agent.
No keys yet.
Add a key
Agent tokens
What your agents hold instead of keys. Scoped, expiring, revocable.
No tokens yet.
New token
Brakes (optional)
Past a limit the token trips: its writes wait until you reset it with your passkey, and reads still pass. A write is any request that is not a GET or HEAD. The repeat limit trips on the request after that many identical ones (2 to 100).
Only Stripe refunds and payouts, in that one currency. Transfers, charges and the rest stay held.
Pre-approvals and money caps are paused while your team requires two seals or someone other than the maker: no one person can approve in advance.
Deploy gates
Hold a GitHub Actions job until you approve it with a passkey. The approval is bound to the repository, workflow, commit and run in the token GitHub signs for the job.
No gates yet.
New gate
A gate accepts only what you list here: one repository, its workflow files and the branches or tags it deploys from. Nothing is accepted by default, and a gate cannot be edited (make a new one and revoke the old). Making one asks for your passkey, because it decides which repository may ask you to approve deploys. A gate does not use GitHub's required reviewers (GitHub offers those only for public repositories on the Free, Pro and Team plans); it checks the token GitHub signs for the job.
Hand out a key (optional: no approval, no key)
Pick a key from your vault and the job gets no deploy key until you approve. On approval it receives a Counterseal token for that key, valid 15 minutes and limited by the policy below; the real key never leaves the vault. A policy that pre-approves irreversible calls is allowed here only because making the gate takes your passkey.
Agent keys
Prove who. Each agent holds its own Ed25519 key and signs every request with it, so a stolen token alone is useless.
No agent keys yet.
New agent key
Made in this browser. The private key is downloaded to you as a file and never sent anywhere; only the public key and a proof that you hold it reach the server. Put the file on the agent's machine and set LEASH_AGENT_KEY to its path. From the agent's machine, npx counterseal agent-key (0.3.0) does the same.
Receipts
If it was recorded, you can prove it. Decisions sealed in the public log, as hashes and labels. Verify a receipt
No receipts yet.
Receipts API keys
For agents that record their own actions with POST /v1/receipts. Everything they send is public: send hashes, not content.
No receipts keys yet.
New receipts key
Audit log
Append-only. Each entry commits to the one before it.
Evidence pack
Every decision in a date range with the audit chain, the public receipts' numbers, and the public log's latest signed checkpoint and key, checked here in your browser: it recomputes every hash itself, so you do not have to take our word for it. Download it as JSON, and the decisions as CSV for a spreadsheet.
How this lines up with the EU AI Act and SOC 2 (our interpretation)
Team
Everyone signs in with their own passkey. With two seals, an irreversible action needs two different people.
One seal
Change it
Raising takes effect now, for actions already waiting too. Lowering it, or letting the person who asked count, waits 24 hours, wakes every member's devices, and any approver can cancel it in that time.
People
Invite someone
The link works once, for the person you name, and shows them this account, your name and the role before they make their passkey. Send it privately.
Open invites
No open invites.
Break glass
For the night the second approver cannot be reached. An owner or approver opens a window of 5 to 60 minutes with a passkey; while it is open, what Counterseal would hold for the tokens and guard keys you pick goes through, every call it lets through is on the record and in its public receipt as a break-glass call, and every member and channel is told at once. It cannot be extended, three a day at most. It never lifts a freeze, a tripped breaker or a money cap, and never applies to deploy gates.
Alert channels
Slack, Discord or Google Chat also get told when something is held, partly sealed, or the team changes. They are only told: nobody can approve from a channel, approving always needs a passkey in this app. A message says who asked, the rule, how many seals and the link; never the path, command, body, amount, a name or a reason. The webhook address is kept encrypted and is not shown again.
No channels yet.
Roles
- Owner
- Everything: the team, the seals needed, the vault, deleting the account. Seals held actions.
- Approver
- Seals held actions with their passkey. Makes tokens and keys for their agents.
- Member
- Makes tokens, guard keys and keys for their agents. Cannot seal.
- Viewer
- Reads everything, and can deny a held action or freeze the account. Nothing else.
Anyone can deny: one no ends a held action. A passkey proves who is there; what they may do is checked by Counterseal on every request.
Account
Your data, and how to take it all away.
What Counterseal keeps about you
Your name, your passkey's public key, your encrypted vault, token, receipts key and guard key hashes, agent public keys, holds (for a coding agent's command: the command, its folder name and your deny reason), your audit log, the limits and money caps you set on a token, what each token's money caps have let through today (kept 35 days), its breaker's counts for the current hour and 5 minutes, whether your account is frozen, your receipts counters and openings, the country and network name each command line sign-in started from and, if you turn on alerts, each device's push address. On a team, also each person's name, role and the label the owner gave them, who invited whom, open invites (as hashes), and who sealed each held action, with which passkey (a short fingerprint) and when. Also five first-time dates (your first token, first protected call, first demo, first installed use, first alerts) for the Get started list and our totals, and any demo held calls you try. Never your face, fingerprint, readable keys or private keys. Privacy policy. Download all of it or choose how long held requests are kept under Privacy.
Passkeys
Command line sign-ins
Each counterseal login of the last 7 days, where it started, and whether it is still signed in (7 days at most). Revoking one signs that command line out and revokes every token, agent key, receipts key and guard key it made, even after it signed out.
No command line sign-ins in the last 7 days.
Guard keys
For the guard on a coding agent's machine (counterseal guard): it holds commands such as terraform destroy until you approve them here with your passkey. A guard key can ask for an approval and read your answer; it can never approve. A key made by the CLI ends with that command line sign-in; a key made here lasts until you revoke it.
No guard keys yet.
Delete account
Erases your account, passkeys, vault, tokens, agent keys, receipts keys, guard keys, holds, sessions and audit log immediately, and unlinks your public receipts (they stay in the log, but nothing on our side says they were yours). On a team, everyone's access, passkeys and seals go with it. Agents using your tokens stop working. This cannot be undone.
Privacy
What Counterseal keeps, for how long, who processes it, and how to take all of it with you.
Download all my data
One JSON file with everything Counterseal keeps about this account: settings, people and roles, passkeys (as fingerprints), sessions, vault entries (names and dates, never a key or any part of one), tokens and their policies, keys (labels and dates, never the key), every held request and command still kept, seals, invites, which push services your devices use (never the push address), counters and the whole audit log. Your passkey confirms it; 3 times an hour; it is written to the audit log.
Only an owner of this account can download all of it. Ask an owner, or write to privacy@gautamkhosla.com.
How long it is kept
Closed means approved and used, denied or expired. Waiting ones are never deleted early. The audit log keeps a fingerprint of each one.
Who processes it
Counterseal runs on Cloudflare (Workers, D1 and a Durable Object), our only processor. If you turn on alerts, your browser's push service (Apple, Google, Mozilla or Microsoft) carries an empty wake-up and nothing else. No analytics, no ads, no third-party scripts. Subprocessors
For your data protection officer
- Records of processing (summary): purposes, data, legal bases and retention.
- Data processing agreement: a template covering GDPR Art. 28 and PIPEDA; not legal advice, have your lawyer review it.
- Security standards self-assessment: OWASP ASVS 5.0 and four OWASP Top 10 lists. Self-assessed, not certified.
- Evidence of every decision: Audit log, Evidence pack (verified in your browser).
- Erasure: Account, Delete account (an owner, with a passkey). Public log entries stay, unlinked from you.