鞍馬 Kurama

鞍馬

KURAMA

Credentials and APIs for you and your coding agents

Let an agent use your AWS roles, APIs and data without ever handing it a secret.

brew install ynishimura/tap/kurama
AWSAssumeRole + MFA AWSConsole SigV4API Gateway · Lambda URLs · OpenSearch OAuthPKCE · device code · client credentials GitHubGoogleLinear OpenAISlackJira ZendeskBacklogElevenLabs DataCSV · JSONL · Parquet on S3 DBSQLite · PostgreSQL · MySQL · Aurora DSQL Secrets1Password · Secrets Manager · SSM SpecsOpenAPI · Swagger · Discovery · GraphQL MCPkurama mcp

Built for coding agents

機Ask in plain words. Kurama does the rest.

Your agent runs one kurama command. Kurama fetches the MFA code from 1Password, assumes the role, reads the key, signs the request, and hands back only the result.

You
agent@kurama: ~/app

        

The credential layer

鍵Secrets flow in. Only results flow out.

The secret never enters the prompt, the transcript or the disk. It stays in your secret stores, and kurama is the only thing it reaches.

NO SECRET CROSSES Coding agent Claude Code · Codex · Cursor You shell · TUI 鞍馬 KURAMA AWS roles APIs Files on S3 Databases 1Password · Keychain · Secrets Manager
a commanda secret, into kurama onlya result
0

secrets in the prompt or the transcript

0

files with role credentials or tokens on disk

1

error[CODE] line and a hint an agent can act on

3

is the exit code that means: stop and ask a person

Features

技One tool for every credential you juggle

The same commands work for a person at a terminal, and every source has a screen of its own. Every option is in the command reference.

AWS roles and MFA

Switch roles in zsh, run one command with exec, attach ReadOnlyAccess or open the console. MFA codes come from 1Password, and one session serves every role behind it.

OAuth and API keys

Authorization code with PKCE, device code or client credentials, refreshed automatically. API keys are read on every call and never stored.

An OpenAPI explorer

Browse operations, fill in a form, send the request, filter the result with jq, and copy the command that repeats the call.

Presets for common APIs

kurama preset add writes the config for GitHub, Google, Linear, OpenAI, Slack, Jira, Zendesk, Backlog and more, spelled out in full.

Files and databases

kurama data runs read-only SQL over CSV, JSONL and Parquet on S3 with embedded DuckDB; kurama db reads SQLite, PostgreSQL, MySQL and Aurora DSQL.

Guardrails and an audit log

An agent run is held to the [agent] policy: a write needs a person's --confirm, and every call goes to an audit log with no secret in it.

For people, too

景A terminal home, dressed for the night

Tabs for every source, Ctrl-K to jump anywhere, and an explorer for each API, database and bucket.

A recording of the selected kurama screen

The home screen: the AWS, Auth, API, DB and Data tabs, then Ctrl-K into the database explorer.

Quick start

始Three steps to your first switch

Kurama targets macOS and zsh. It also runs on Linux (x86_64 and arm64, glibc), without the keychain cache.

Install

$ brew install ynishimura/tap/kurama

Without Homebrew: curl --proto '=https' --tlsv1.2 -LsSf https://github.com/ynishimura/kurama/releases/latest/download/kurama-installer.sh | sh. To build from source, see the README.

Enable the shell integration

eval "$(kurama init zsh)"

Add it to ~/.zshrc, after compinit: the wrapper that exports into your shell, and tab completion.

Switch, or hand it to your agent

$ kurama env dev          # temporary credentials in this shell
$ kurama agent install    # Agent Skills for kurama and each API
Kurama logo: a white fox, mountains, a red sun and a torii gate

Why “Kurama”

志Named after a mountain

Kurama (鞍馬) is a mountain north of Kyoto. The logo brings together a fox, mountains, a red sun and a torii gate, and the terminal and this page are dressed in the blues of a night there: ruri, tsuyukusa and asagi.

The goal is a terminal home for developer and cloud workflows, with AWS as the first integration.

Give your agent the keys, not the secrets.

Open source under the MIT License.