Support
The homepage points to CLI documentation hosted on GitHub. No dedicated support channel is described.
Open-source CLI that keeps secrets out of AI coding agents

Offsend CLI is an open-source, local-first tool that defines what AI coding agents can see through one .offsend.yml file, tokenizing secrets, syncing ignore files, gating prompts and tools, and checking policy in CI.
Offsend CLI is an open-source, local-first boundary layer that sits between a developer's projects and the AI coding agents that read them. A single policy file, .offsend.yml, committed to git, describes what the agent may see. Once installed, secrets are swapped for tokens, so the agent continues to work on the code while the plaintext values stay out of its context. The tool is aimed at developers and teams who use Cursor, Claude Code, Windsurf or Codex and want a practical guardrail against leaking keys, credentials and sensitive files into prompts. Installation is a single shell command (also available through Homebrew on macOS and Linux), which runs the setup step automatically. That step creates a seal key and installs user-level Cursor and Claude hooks that work in any folder, with no YAML needed. In a repository the team owns, init writes the policy file, protect adds exposed paths, and sync generates AI ignore files plus git and editor hooks. A GitHub Action runs the same check in CI and can fail a build on secrets or ignore drift. Runtime gates inspect prompts, file reads, writes, shell commands and MCP arguments on editors that expose those hooks. Cursor and Claude Code can also seal secrets inside MCP responses, and sealed values can be restored from an agent reply with the unseal command through clipboard, file or pipe. Without the key, secret-bearing MCP output is withheld rather than passed through. Local transcripts can be audited and scrubbed afterward, and all checks run locally without uploading code. Offsend is candid about its limits. It is defense-in-depth rather than a guarantee, coverage varies by editor (Codex is prompt-only, Windsurf lacks MCP response sealing), and cloud agent sessions bypass local hooks. It includes content scanning but is not a replacement for history-focused scanners such as Gitleaks, TruffleHog or GitGuardian, and is best used alongside them. Companion pieces include a macOS desktop app, a browser extension, an online repository check and a research feed called Radar.



The homepage points to CLI documentation hosted on GitHub. No dedicated support channel is described.
Works with Cursor, Claude Code, Windsurf and Codex through hooks, generates ignore files for Copilot, Continue, Gemini, Aider, Cline, Roo, Zed and Cody, and ships a GitHub Action. Related products include a macOS desktop app and browser extension.
Learn moreSingle .offsend.yml policy, seal key and secret tokenization, AI ignore file sync, runtime gates for prompts, reads, writes, shell and MCP, MCP response sealing on Cursor and Claude Code, unseal restore, content scanning, transcript audit, git hooks and a CI check.





