This product was not featured by Product Hunt yet.
It will not be visible on their landing page and won't be ranked (cannot win product of the day regardless of upvotes).

Product Thumbnail

Chancery

The identity provider for AI agents

Open Source
Artificial Intelligence
GitHub
Security
Visit WebsiteSee on Product HuntGithubVercel

Hunted byAneesh GuptaAneesh Gupta

Orchestrators create agents at runtime, and tool servers hand them every key you own. Chancery gives each agent its own identity, access that can only narrow, safe runtime spawning, verified tool servers, instant revocation, and a provable audit trail.

Top comment

Hey Product Hunt 👋 Agents stopped being single scripts and became fleets. Orchestrators create sub-agents at runtime, each alive for minutes, each wired into real systems. Almost nothing governs them. One API key shared by everything, all-or-nothing tool access, server code downloaded fresh on every launch, and the only record of what happened written by the agent itself. Chancery is the identity layer for that. Following one agent's life: Identity. Registered, owned by a named human, and fingerprinted (prompt, config, tool list), so "did this change since review?" becomes a comparison rather than a meeting. The agent, its version, and each running copy are separately revocable. Access that only narrows. Permissions are signed and delegated downward, and a child can only hold a subset. Revoke any link and everything beneath it dies on its next action. Widening simply cannot be expressed. Safe runtime spawning. This is the multi-agent piece most stacks skip. A human approves a template once, capping capability and lifetime. Orchestrators then create workers on the fly with no admin credentials: each gets its own identity, a narrower slice of the parent's access, the parent's owner attached so accountability can't be laundered, and an expiry that shuts it out automatically. Both directions secured. Requests are checked live, and anything an agent can't do is hidden from the model rather than refused. The tool server is fingerprinted and re-verified before every run. Change one file in its dependencies and it won't start. You can also install servers frozen instead of pulling them fresh, restrict them to named destinations, make their filesystem read-only, and run them as a separate user. Secrets agents never hold. Encrypted at rest and handed only to the tool server as it starts, so a prompt injection can't leak what was never in context. Rotation is one update with no agent changes. Browser agents work the same way: a human's session is custodied on their behalf, and every page the agent visits is checked against what it's allowed to reach. Revocation that lands. Cut access and the next action fails, mid-session. Servers that opt in can check with Chancery right before committing, so a revocation arriving mid-flight prevents the action instead of documenting it afterwards. That part needs the server to cooperate, and the docs say so. Evidence, not logs. Tamper-evident, so any edit or reorder is detectable, and physically unable to hold prompts or payloads. There's also a read-only dashboard with a live timeline and the delegation chain drawn as a tree. Adoption is a one-line change to how you already launch tool servers. It governs non-MCP agents too (LangGraph, CrewAI, cron jobs) through the same decision API. All 17 known limitations are published with owners and timelines. Last week someone on Reddit showed that one of our credential-isolation claims was weaker than stated. He was right. It's now a numbered gap with his handle on it, and the fix shipped the next day. Apache-2.0, self-hosted, no cloud, no telemetry. brew install chanceryhq/tap/chancery More useful than an upvote: tell me where it breaks. 🔗 chanceryai.vercel.app ⭐ github.com/chanceryhq/chancery

Comment highlights

Identity is becoming a much bigger problem for AI agents than for traditional apps. Curious what part of that problem you believe is still most underestimated.

A sandbox mode for testing agents before they get real credentials would be huge, especially for evaluating how narrowly they scope access in practice. Maybe a one click "dry run" that simulates the full identity and tool flow but uses throwaway keys, so you can audit behavior safely before going live.

A nice dashboard showing each agent's real-time permissions tree would be super helpful. Something where you can see what tools an agent currently has access to and visually tighten or revoke scopes with one click. Right now the audit trail sounds great after the fact, but I'd love a live view to catch drift before it becomes a problem.

About Chancery on Product Hunt

The identity provider for AI agents

Chancery was submitted on Product Hunt and earned 13 upvotes and 12 comments, placing #65 on the daily leaderboard. Orchestrators create agents at runtime, and tool servers hand them every key you own. Chancery gives each agent its own identity, access that can only narrow, safe runtime spawning, verified tool servers, instant revocation, and a provable audit trail.

Chancery was featured in Open Source (68.6k followers), Artificial Intelligence (474.3k followers), GitHub (41.3k followers) and Security (2.8k followers) on Product Hunt. Together, these topics include over 153.3k products, making this a competitive space to launch in.

Who hunted Chancery?

Chancery was hunted by Aneesh Gupta. A “hunter” on Product Hunt is the community member who submits a product to the platform — uploading the images, the link, and tagging the makers behind it. Hunters typically write the first comment explaining why a product is worth attention, and their followers are notified the moment they post. Around 79% of featured launches on Product Hunt are self-hunted by their makers, but a well-known hunter still acts as a signal of quality to the rest of the community. See the full all-time top hunters leaderboard to discover who is shaping the Product Hunt ecosystem.

Want to see how Chancery stacked up against nearby launches in real time? Check out the live launch dashboard for upvote speed charts, proximity comparisons, and more analytics.