Solutions · AI coding agents

Let coding agents work on infrastructure without the keys

Coding agents are good at infrastructure chores: noticing a missing webhook, writing the config change and the code that goes with it. The risk is giving them the credentials to do it. With Ahena, an agent gets enough access to understand and propose, and the changes that matter need a person.

Why the obvious approach is risky

The simplest way to let an agent help is to let it use whatever you use:

  • An agent in your terminal can read any file you can, including stored provider keys and CLI tokens.
  • A confirmation prompt in a terminal proves nothing: the agent can answer it.
  • If the credential that lets it look also lets it change production, the only control left is the agent's judgement.

How Ahena splits looking from changing

  1. Coding agent
  2. Ahena MCP
  3. Ahena policy and approvals
  4. Provider management API
  1. Its own session

    ahena mcp creates an agent session from your CLI login. Ahena's servers know a request came from an agent, and the activity log says so.

  2. No credentials in either direction

    No MCP tool returns a provider credential or a secret value, and none accepts one: connecting a provider gives the agent the command for you to run.

  3. Intent, not raw API calls

    Agents change ahena.config.ts and ask Ahena to plan. They can't send arbitrary requests to a provider through Ahena.

  4. People approve what matters

    Read-only by default. With --allow-write, safe changes apply, other changes need you, and production, billable and destructive changes are approved only in the signed-in dashboard.

  5. Refused outright

    Ahena's API refuses agent sessions for approving changes, revealing secrets, managing members or billing, and creating tokens, whatever your role.

What an agent can do

ChangeDevelopment or stagingProduction
Read, Doctor, planYesYes
SAFE changes (with --allow-write)AppliedApplied
Confirmation-required changesYou approve in the MCP clientYou approve in the dashboard
Billable or destructive changesYou approve in the dashboardYou approve in the dashboard
Manual stepsNever applied by AhenaNever applied by Ahena

Connecting an MCP client

$ ahena login
$ ahena mcp # read-only
$ ahena mcp --allow-write # also lets the agent propose and apply approved changes

The honest limits

  • An agent that controls your browser, or knows your password, can act as you. Two-factor sign-in raises the bar for the password case.
  • Outside production, an agent with shell access to your CLI login can approve reversible, non-billable confirmation-required changes.
  • Your app's runtime traffic never goes through Ahena or the agent: the code it generates calls providers directly.

Questions

How can I safely let Claude or another coding agent manage infrastructure?

Run ahena mcp as the agent's MCP server. The agent gets its own session that can read the stack, run Doctor and plan changes, never sees provider credentials or secret values, and can't approve its own changes: production, billable and destructive changes are approved only by you in the signed-in dashboard.

Does the agent ever see my API keys?

Not through Ahena. No MCP tool returns or accepts a credential or secret value, and the API refuses secret reveals for agent sessions. An agent with access to your own shell can still read files on your machine, so keep keys out of your project files.