curl
A curl drop-in that substitutes credentials at call time, so the agent never holds a key.
npx interagentic curl <url> [curl options]Takes the flags you already know — -X, -H, -d, --data-raw, -F, -i,
-o, -L, -u, --compressed and the rest. The difference is what you put
where a secret would go.
Credential placeholders
npx interagentic curl https://api.github.com/user/repos \
-H "Authorization: Bearer {{OAUTH2_ACCESS_TOKEN}}"{{UPPER_CASE}} is resolved by the proxy, after a human has connected the
provider. The value is substituted as the request leaves and never travels back
toward your process.
Placeholders work in headers, the query string and the body:
npx interagentic curl \
"https://maps.googleapis.com/maps/api/geocode/json?address=Paris&key={{GOOGLE_MAPS_API_KEY}}"Use a header or a query parameter rather than -u: curl encodes Basic
credentials before the request leaves your machine, so the proxy would never see
the placeholder.
When nothing is connected
403 permission_denied — github.com::repo
Ask your human to connect GitHub:
https://id.interagentic.dev/link/9f2c…Hand that link over. Once approved, re-run the identical command.
| Flag | Effect |
|---|---|
--scopes <list> | State the scopes instead of letting them be inferred |
--account <label> | Choose between several connected accounts |
--wait | Block until a human approves, then retry automatically |
--wait is for interactive sessions. In a scheduled job, prefer exiting 3 and
letting your supervisor decide.
Talking to compatible services
If the target already speaks the identity protocol, curl skips the proxy and
signs the request directly. You do not have to know which case you are in.