AI coding accelerates leakage risk
Teams are adding agents, MCP servers, temporary tokens, and assisted commits faster than traditional access reviews can track.
Private alpha for small teams
Developer key and identity inventory for the machines where SSH keys, signing keys, passkeys, MCP configs, and stale credentials quietly spread out.
Why now
Teams are adding agents, MCP servers, temporary tokens, and assisted commits faster than traditional access reviews can track.
Account security is improving, but teams still need an operational inventory of who owns which auth surfaces and recovery paths.
SSH keys, Git signing settings, local repos, and tool configs often live outside central IAM dashboards.
Workflow
Run PubKeySpace on a developer machine to inventory key material, public fingerprints, Git posture, MCP configs, and passkey review notes.
Open the dashboard to sort stale keys, weak permissions, unsigned repositories, unapproved MCP servers, and accepted risk.
Create team enrollment profiles so developers can submit signed reports without exposing private key contents or token values.
Use team summaries, audit events, collector health, and baseline checks to spot machines that stop reporting or accumulate risky auth surfaces.
Trust model
Reports include metadata, public fingerprints, file paths, ages, permissions, and finding details.
Reports do not include private key contents, token values, MCP environment values, or secret values.
Cloud and team sync flows are opt-in, and the CLI remains the auditable source of truth for alpha users.
Current alpha
Generate HTML reports or run the local API at 127.0.0.1 for rescans and summaries.
Track approved MCP servers, passkey attestation notes, suppressions, owners, tags, and expirations in policy.
Upload signed bundles into a hosted-style team service with organization tokens and audit events.
Run repeat collection and identify enrolled clients that stop reporting.
Private alpha
Accepted alpha teams get CLI access, setup help, and a direct line into the team dashboard roadmap. The goal is to learn with serious operators before opening the repo or publishing installers.
Roadmap
Private alpha, local dashboard, team ingestion, enrollment, collector daemon, and direct design-partner onboarding.
Packaged desktop sidecar, guided remediation, better onboarding, and hosted team access controls.
Signed and notarized macOS release, Windows installer, organization accounts, SSO, and production RBAC.