Building Decoy: scoped identities instead of handing agents your real inbox and credentials
jmppmj · reddit · 2026-10-06
- Problem: making agents like Claude Code actually useful usually means granting standing access to your Gmail, calendar, or credentials. The author cites a case where an agent combed through someone's inbox just to find a Cursor 2FA code — exposing years of receipts, bank alerts, and password resets for one email is clearly backwards.
- Decoy (decoys.me) proposes an alternative:
- Give agents scoped, task-specific identities (disposable inboxes for signups, 2FA codes, confirmations) that can be revoked or burned when the task ends — no standing access to the primary account;
- Credentials and memory stay user-owned, encrypted client-side with a key tied to the user's device rather than siloed inside each agent provider;
- Connected agents share context through a knowledge graph the user owns (preferences, project context, credentials), avoiding per-agent memory silos.
- You install the Decoy app first (the device acts as the end-to-end encryption key), then agents connect via a single prompt at decoys.me/agents.
- The author is soliciting feedback from other agent builders.
More from coding & agent
- DeepSeek-style agent infrastructure ran 1.3B sandboxes in 4 weeks, peaking at 170K concurrent — teortaxesTex · 2026-10-06
- DIY agentic memory with an nginx proxy: surviving 35 compactions — cryowastakenbycryo · 2026-10-06
- Burkov: no one will need to fix AI code — just prompt it to fix itself — burkov · 2026-10-06
- "A single Claude Code session won't replace your software": a reality check on the one-shot AI narrative — seatedro · 2026-10-06
- Your evals are your product spec: the most common mistake AI product teams make — realmadhuguru · 2026-10-06
- Dev's Ultrafast review: 6x token cost, $500 plan hits weekly limits every 1-2 days — holdenmatt · 2026-10-06