# Venya

> AI agent infrastructure access platform that lets LLMs execute commands on remote systems using stored credentials without ever exposing plaintext secrets, secured by FIDO2 hardware key authentication.

Venya is a privileged access management platform built specifically for AI agents, developed by Tabith LLC. It enables AI coding assistants like Claude Code and Cursor to execute commands on remote infrastructure — SSH, databases, APIs — without ever receiving plaintext credentials. The project is currently in alpha (v0.1.0alpha15 as of September 2026) and is source-available under the Business Source License (BSL) 1.1.

## What It Is

Venya sits between an AI agent and the infrastructure it needs to operate. When an agent needs to run a command that requires a credential, Venya's server decrypts the secret, wraps it with cryptographic sentinel markers, relays it over mutual TLS to an executor daemon, and unwraps it only inside a sandboxed microVM. The agent sees the command output — filtered by a Rust-based redaction layer — but never the credential value itself. Tabith LLC describes this as a "zero-knowledge injection model" that has no direct equivalent in traditional secrets managers like HashiCorp Vault or CyberArk, which hand plaintext to whatever process holds a valid token.

## Architecture and Trust Model

Venya's design separates components by trust level:

- **Core server** — the trust anchor; holds the CA keys, encrypted secret store (AES-256 envelope encryption), and append-only audit log. Must run on its own protected host.
- **Executor daemon** — runs on a host treated as potentially compromised by design. Commands execute inside sbx microVMs with deny-by-default egress networking and a Rust output filter that replaces any leaked secret values with `[REDACTED:<id>]` markers.
- **Workstation CLI** — the `venya` command used by human operators for administration, enrollment, and session management.
- **MCP server** — exposes Venya's tools to LLM clients via the Model Context Protocol, supporting Claude Code, Cursor, and any MCP-compatible client.

The server and executor communicate exclusively over mutual TLS. A revoked executor certificate is rejected before any secret is transmitted.

## FIDO2 Session Authorization

Every Venya session begins with a physical FIDO2 hardware key press (YubiKey, SoloKeys, etc.). AI agents cannot initiate sessions on their own — only a human authenticating with a registered security key can authorize access. Sessions carry a hard 4-hour cap with a 15-minute idle window; past the cap, the agent receives an actionable error prompting re-authentication. Disclosure of a secret value is a separate, deliberate, FIDO2-elevated, single-use, audited act — never part of normal operation.

## MCP Protocol Integration

Venya speaks the Model Context Protocol natively, exposing tools that let agents discover available executors and secrets (metadata only, never values), construct and submit commands, and query the audit log. The MCP server runs as a stdio transport, compatible with Claude Code and Cursor out of the box. Tabith LLC reports verified MCP client compatibility with opencode and local LLMs via omlx.ai.

## Deployment and Prerequisites

Installation targets Ubuntu 24.04 LTS for the core server and executor daemon. The workstation CLI additionally supports Debian 13, macOS (arm64 verified), and Windows (CLI only; core and executor are Linux-only). Key prerequisites include:

- PostgreSQL 16 (installed automatically by the core installer)
- Python 3.14 (pinned, provisioned via uv)
- A FIDO2 security key for every operator
- Docker account and hardware virtualization (`/dev/kvm`) on executor hosts — sbx microVMs require KVM access, so VM deployments need nested virtualization enabled
- Separate physical or virtual hosts for core and executor (co-location voids the isolation model)

## Update: v0.1.0alpha15

The latest release, v0.1.0alpha15, was published on September 26, 2026. The project was created on September 15, 2026, making this an early-stage alpha with rapid iteration. The roadmap includes SSO with LDAP and WebAuthn hybrid authentication, FIDO2 hardware attestation, high-availability core deployment, TPM credential sealing, SIEM/audit export integration, offline and air-gapped deployment modes, and a pure auditor role. The license is BSL 1.1 with a Change Date of four years from first public distribution, at which point each version converts to MPL 2.0 — the same model used by HashiCorp for Vault and Terraform.

## Features
- Zero-knowledge secret injection — AI agents never receive plaintext credentials
- FIDO2 hardware key binding for session authorization
- Sandboxed microVM execution via Docker sbx
- Rust-based output redaction filter replacing leaked values with [REDACTED] markers
- Mutual TLS between core server and executor daemons
- Deny-by-default egress allowlisting in sandbox
- AES-256 envelope encryption for secrets at rest
- Append-only audit log with user, executor, command, timestamp, and secret IDs
- Model Context Protocol (MCP) native integration
- 4-hour hard session cap with 15-minute idle window
- Certificate revocation enforcement at executor level
- CLI for administration, enrollment, and session management
- Support for env injection, askpass, sudo-stdin, and sshpass secret shapes
- Compatible with Claude Code, Cursor, and any MCP client

## Integrations
Claude Code, Cursor, opencode, omlx.ai (local LLMs), Model Context Protocol (MCP), Docker Sandboxes (sbx), PostgreSQL, YubiKey, SoloKeys, SSH, FIDO2/WebAuthn

## Platforms
LINUX, MACOS, WINDOWS, CLI, API

## Pricing
Freemium — Free tier available with paid upgrades

## Version
v0.1.0alpha15

## Links
- Website: https://github.com/tabith-llc/venya
- Documentation: https://github.com/tabith-llc/venya/blob/main/docs/installation.md
- Repository: https://github.com/tabith-llc/venya
- EveryDev.ai: https://www.everydev.ai/tools/venya
