
PassControl
Identity, budgets and kill switches for AI agents
I made PassControl public today.
The self-hosted version is live, the repo is public, the hosted version exists, and after months of building, testing, fixing bugs and tightening the security model, I finally stopped holding it back.
And almost immediately I ran into the next problem:
Nobody automatically cares just because the product exists.
That sounds obvious, but building makes it very easy to forget.
For months, progress was measurable.
A bug existed, then it didn’t.
A test failed, then it passed.
A security issue existed, then it was patched.
A feature didn’t exist, then I built it.
Today I started distribution, and it feels completely different.
You can post something you spent hours preparing and get almost nothing back. You can launch somewhere you thought was perfect and get buried. You can explain the product badly and nobody understands why it matters.
And then one person randomly asks:
“what ur building?”
Right now, that question is more valuable to me than a huge number of passive impressions.
Because I don’t need a massive audience yet.
I need the first few people who will actually use PassControl.
The idea is pretty simple:
AI agents are getting more autonomy, but we still often give them access by handing over provider API keys with way more authority than they actually need.
PassControl sits between the agent and those provider credentials.
Each agent can have its own identity, scopes, budgets and revocable access. The provider keys stay behind the gateway, and you can see what the agent is doing and kill its access when needed.
Basically, I think autonomous agents need an actual control layer around them.
But there’s a much more important question now:
Does anyone besides me actually want this?
I’ve spent months staring at PassControl.
Of course I understand it.
Of course I know why every part exists.
That means my opinion is now the least useful one.
What I need is somebody who has never seen it before to install it, connect an agent, use it for something real and tell me:
- what is confusing
- what feels unnecessary
- what breaks
- what is missing
- whether they would actually keep using it
That’s also why I released a free self-hosted version.
I don’t want the first conversation to be about pricing.
I want people to break it.
So as of today, my goal isn’t 1,000 users or some impressive MRR screenshot.
It’s much simpler:
find the first real beta testers.
Today was the day I stopped hiding behind the product.
Now I get to find out whether I built something people actually want.
After months of building, testing and tightening the security model, I finally made PassControl public today.
The self-hosted version is live, the repo is public, and the first distribution push has started.
PassControl gives AI agents their own identity, scopes, budgets and revocable access while keeping provider API keys inside the gateway.
Now comes the part I’ve been avoiding for way too long: getting it in front of people and seeing whether anyone actually wants it.
2 Likes
Comment
About
PassControl exists because AI agents are gaining autonomy faster than their security model is evolving. They shouldn’t hold raw provider keys or broad permissions; they need identity, limits, and revocable access.

5 Comments
The security thesis is clear, but the real test seems to be whether agent builders actually change their credential workflow because of it. Have any beta users connected a real production agent yet, and what prompted them to use PassControl instead of managing provider keys directly?
That’s exactly the test I’m starting now. I launched PassControl today, so I don’t have a production beta user yet. I’m trying to get the first one now.
That first production-agent test is the key one. If you’re open to it, what’s the best email to reach you on?
Absolutely - kristiyan.iwanov@proton_dot_me.
Would love to set it up with you.
Used dot as a “.” Because website doesnt allow me to post links yet
Thanks! I’ve just sent it over.
Looking forward to hearing your thoughts whenever you have a chance.