Venya
AI agent infrastructure access platform that lets LLMs execute commands on remote systems using stored credentials without ever exposing plaintext secrets, secured by FIDO2 hardware key authentication.
At a Glance
Source-available under Business Source License 1.1. Free to use, modify, and deploy in production for organizations with total consolidated revenue below US $10M/year and non-competing use cases.
Engagement
Available On
Alternatives
Listed Oct 2026
About Venya
Venya is a privileged access management platform built specifically for AI agents, developed by Tabith LLC. It enables AI coding assistants like Claude Code and Cursor to execute commands on remote infrastructure — SSH, databases, APIs — without ever receiving plaintext credentials. The project is currently in alpha (v0.1.0alpha15 as of September 2026) and is source-available under the Business Source License (BSL) 1.1.
What It Is
Venya sits between an AI agent and the infrastructure it needs to operate. When an agent needs to run a command that requires a credential, Venya's server decrypts the secret, wraps it with cryptographic sentinel markers, relays it over mutual TLS to an executor daemon, and unwraps it only inside a sandboxed microVM. The agent sees the command output — filtered by a Rust-based redaction layer — but never the credential value itself. Tabith LLC describes this as a "zero-knowledge injection model" that has no direct equivalent in traditional secrets managers like HashiCorp Vault or CyberArk, which hand plaintext to whatever process holds a valid token.
Architecture and Trust Model
Venya's design separates components by trust level:
- Core server — the trust anchor; holds the CA keys, encrypted secret store (AES-256 envelope encryption), and append-only audit log. Must run on its own protected host.
- Executor daemon — runs on a host treated as potentially compromised by design. Commands execute inside sbx microVMs with deny-by-default egress networking and a Rust output filter that replaces any leaked secret values with
[REDACTED:<id>]markers. - Workstation CLI — the
venyacommand used by human operators for administration, enrollment, and session management. - MCP server — exposes Venya's tools to LLM clients via the Model Context Protocol, supporting Claude Code, Cursor, and any MCP-compatible client.
The server and executor communicate exclusively over mutual TLS. A revoked executor certificate is rejected before any secret is transmitted.
FIDO2 Session Authorization
Every Venya session begins with a physical FIDO2 hardware key press (YubiKey, SoloKeys, etc.). AI agents cannot initiate sessions on their own — only a human authenticating with a registered security key can authorize access. Sessions carry a hard 4-hour cap with a 15-minute idle window; past the cap, the agent receives an actionable error prompting re-authentication. Disclosure of a secret value is a separate, deliberate, FIDO2-elevated, single-use, audited act — never part of normal operation.
MCP Protocol Integration
Venya speaks the Model Context Protocol natively, exposing tools that let agents discover available executors and secrets (metadata only, never values), construct and submit commands, and query the audit log. The MCP server runs as a stdio transport, compatible with Claude Code and Cursor out of the box. Tabith LLC reports verified MCP client compatibility with opencode and local LLMs via omlx.ai.
Deployment and Prerequisites
Installation targets Ubuntu 24.04 LTS for the core server and executor daemon. The workstation CLI additionally supports Debian 13, macOS (arm64 verified), and Windows (CLI only; core and executor are Linux-only). Key prerequisites include:
- PostgreSQL 16 (installed automatically by the core installer)
- Python 3.14 (pinned, provisioned via uv)
- A FIDO2 security key for every operator
- Docker account and hardware virtualization (
/dev/kvm) on executor hosts — sbx microVMs require KVM access, so VM deployments need nested virtualization enabled - Separate physical or virtual hosts for core and executor (co-location voids the isolation model)
Update: v0.1.0alpha15
The latest release, v0.1.0alpha15, was published on September 26, 2026. The project was created on September 15, 2026, making this an early-stage alpha with rapid iteration. The roadmap includes SSO with LDAP and WebAuthn hybrid authentication, FIDO2 hardware attestation, high-availability core deployment, TPM credential sealing, SIEM/audit export integration, offline and air-gapped deployment modes, and a pure auditor role. The license is BSL 1.1 with a Change Date of four years from first public distribution, at which point each version converts to MPL 2.0 — the same model used by HashiCorp for Vault and Terraform.
Community Discussions
Be the first to start a conversation about Venya
Share your experience with Venya, ask questions, or help others learn from your insights.
Pricing
Free (BSL)
Source-available under Business Source License 1.1. Free to use, modify, and deploy in production for organizations with total consolidated revenue below US $10M/year and non-competing use cases.
- Full platform access for organizations under $10M annual revenue
- Use, modify, and create derivative works
- Production use permitted within license terms
- Converts to MPL 2.0 four years after each version's first public distribution
Commercial License
Required for organizations at or above US $10M total consolidated annual revenue, or for competing hosted/embedded offerings. Contact Tabith LLC for terms.
- Commercial use above $10M annual revenue threshold
- Competing hosted or embedded deployments
- Enterprise licensing terms
Capabilities
Key Features
- Zero-knowledge secret injection — AI agents never receive plaintext credentials
- FIDO2 hardware key binding for session authorization
- Sandboxed microVM execution via Docker sbx
- Rust-based output redaction filter replacing leaked values with [REDACTED] markers
- Mutual TLS between core server and executor daemons
- Deny-by-default egress allowlisting in sandbox
- AES-256 envelope encryption for secrets at rest
- Append-only audit log with user, executor, command, timestamp, and secret IDs
- Model Context Protocol (MCP) native integration
- 4-hour hard session cap with 15-minute idle window
- Certificate revocation enforcement at executor level
- CLI for administration, enrollment, and session management
- Support for env injection, askpass, sudo-stdin, and sshpass secret shapes
- Compatible with Claude Code, Cursor, and any MCP client
