- Your sign-ins stay here
- Ghostget stores sign-ins on this machine, including any linked-device store you choose to use. Your agent gets a named action and its result, never cookies, tokens, or a browser it can steer.
- Import a token without showing it
- For X,
ghostget vault import-x accepts a 1Password field reference instead of a pasted secret; Ghostget verifies the X user and stores the token privately on your machine. It is a token importer for one provider, not a general password manager.
- Only the traffic you asked for
- Reads and actions contact their selected sources. Provider sign-in and explicitly started messaging sync also use the network. The CLI and SDK send no website analytics.
- Reads you can open later
- Provider-read snapshots are encrypted on your machine; owner messaging keeps a separate private local history and journal. A failed refresh does not erase the last verified state.
- Writes need a preview and a confirmation
- Anything that changes an account needs a preview and an explicit confirmation of that exact preview, or a limited grant you set up for owner messaging. If a write went out and its result is unknown, Ghostget won’t send it again. It stays marked unsettled until separate evidence shows what happened.
- When a service changes
- If a service changes how it responds, the affected action stays off until it is reviewed again. Ghostget never quietly falls back to a browser.
- Bring your own agent
- Ghostget supplies the local tools and a macOS menu-bar companion for outputs and CLI guidance. Your agent owns the model and planning.
- No bypassing access controls
- Media archiving is limited to one finite item you are allowed to access that is not protected by DRM. Ghostget does not bypass payment, sign-in, access controls, or DRM.