Claude Code, Cursor, and Codex work with real repos and systems — give them brokered, revocable access instead of raw keys.
The problem
Raw keys pasted from ~/.env and dotfiles
No inventory of agents or what they reach
Production touched from personal machines
No switch to flip when something goes wrong
How a laptop agent gets brokered
Claude Code, Cursor, and Codex are enabled per organization — nothing connects uninvited.
A device flow ties the session to a real person. No keys pasted anywhere.
Credentials inject server-side at call time; dotfiles stay empty.
Disable the agent org-wide and its next call fails closed.
See it
Capabilities
The payoff
The agent on the laptop is still your agent — broker it, watch it, revoke it.
Questions
Related solutions