Skip to content

Give your agent the infrastructure, not the keys.

infrapad is the system of record for your infrastructure, secrets and agent access. Agents draft plans and work with masked values. Anything real waits for a person, the way this command does.

~/billing
❯ infrapad run --env prod -- bun scripts/seed-owner.ts→ This token sees masked values in billing/prod. A person can let this one command read real ones.  Approve it in your browser to run: bun scripts/seed-owner.ts
    https://your-infrapad/cli/approve/cla_7hq2…
  The page shows the code BXKR-TNWP. Approve only if it matches.
▍
your-infrapad/cli/approve/cla_7hq2

Let this command read real values?

Project
billing
Environment
prodProtected
Command
bun scripts/seed-owner.ts
Machine
dev-laptop
Code
BXKR-TNWP

The command receives the values in its environment.

Provision, hand over, back up. One record.

Today that loop is four tools: something to provision with, a secrets manager, a backup script, and a paste into .env. infrapad keeps all of it in one place, and writes down who did what.

An agent drafts the plan. You read the diff.

Ask your coding agent for a database and it writes a plan: what would be created, with which provider, and which variables it would write. Nothing exists until someone with the right role approves it.

Plan pl_8fx2 for billing/dev

Waiting for approval
  • billing-db PostgresNeonDATABASE_URL, DATABASE_URL_APP
  • billing-cache RedisUpstashREDIS_URL
  • billing-web WorkerCloudflareSecrets set on the Worker itself

Drafted by Claude Code over MCP. There is no setting that lets a plan apply itself.

Connection strings land on their own

Every resource writes its variables into the environment it belongs to. Nobody pastes one.

  • DATABASE_URL••••••••••from billing-db
  • DATABASE_URL_APP••••••••••from billing-db
  • REDIS_URL••••••••••from billing-cache

The repository says what each app needs

infrapad check exits 2 when a required variable has no value, so a deploy gate is one line.

infrapad.yaml

apps:
  api:
    path: apps/api
    env:
      - DATABASE_URL: { type: postgres_url, required: true }
      - STRIPE_WEBHOOK_SECRET: { type: string, required: true }
❯ infrapad check --app api --env dev
  ✓ DATABASE_URL           set by billing-db
  ✗ STRIPE_WEBHOOK_SECRET  required, no value

Schema, without a credential

The role that reads it is created for the request and dropped before the answer comes back.

❯ infrapad db schema billing-db --env prod
payments   id uuid, amount_cents int4, status text
customers  id uuid, email text, created_at timestamptz
invoices   id uuid, customer_id uuid, due_on date
refunds    id uuid, payment_id uuid, reason text
4 tables. No connection string left this server.
  1. Role created
  2. Schema read
  3. Role dropped

Backups nobody set up

Every provisioned database is backed up and encrypted, and a sample is restored to prove it can be.

  • Today, 03:00412 MB, encryptedRestore tested
  • Yesterday, 03:00409 MB, encrypted
  • Sunday, 03:00407 MB, encrypted

One view of the estate

What exists, on which provider, and where it has drifted from what was approved.

  • Cloudflare4 resourcesDrifted
  • Neon2 databases
  • Upstash1 cache

An audit trail without values

Every provision, approval and secret read, with who and when. The values never are.

  • secret.readbilling/prod, approved by you2m
  • plan.approvedpl_8fx2 in billing/dev1h
  • backup.verifiedbilling-db9h
Provisions and adopts on
  • Cloudflare
  • Neon
  • Supabase
  • Upstash
  • Coolify
  • Resend
  • Expo
  • Apple
  • Polar

What a token can do, and what it never can.

An agent connects over MCP or the CLI with a token that expires. Each environment also has its own agent-access setting, and both have to allow a read. A leaked token reads nothing from an environment set to blocked.

With a token, an agent can

  • List which variables exist, with their names and types.
  • Read masked values where the environment allows it.
  • Inspect a database's tables and columns through a role that is dropped after 15 minutes.
  • Draft a plan for new infrastructure or a missing secret.
  • See which restore points exist for a database.

Only a signed-in person can

  • Approve a plan, so that anything is created at all.
  • Let one command read real values: five minutes, three reads, then the grant is gone.
  • Approve a read from production, with a fresh two-factor code.
  • Start a restore. It spends money and picks a point in time.
  • Change what agents may see in an environment.

Start in dev. Production stays locked until you say so.

Sign-up is by invitation. Ask whoever runs your infrapad for a link.

  1. Install the CLI

    A small Bun bundle, served by your own deployment so it always matches the server.

    ❯ curl -fsSL https://infrapad.glixstudio.cloud/install.sh | sh
  2. Log in from the browser

    Approve the code it prints. A masked, 30-day token lands in your keychain.

    ❯ infrapad login
  3. Connect your agent

    Writes the MCP configuration for Claude Code, Codex or Cursor from that token.

    ❯ infrapad mcp install