Private beta: the source and binaries are not public yet, so the install commands do not work yet.
aisync

Security model

What aisync protects, and what it doesn't.

What it protects

Situation Outcome
Your GitHub repo leaks Tokens are ciphertext only and can't be opened without the passphrase
A config file (.claude.json) is backed up or shared It holds references, so no token goes with it
Another website targets the admin UI 127.0.0.1 only, a fresh token per run, Host and Origin checks
You paste a token into a file by mistake The upload stops at the check

What it doesn't

GitHub access

aisync gets a token from gh auth token each time and never stores it. gh tokens usually reach all your repos, so keep your gh login safe.

Unattended machines

If macOS shows a keychain permission dialog, aisync waits up to 20 seconds, then stops and says why. On a machine nobody sits at, run aisync keystore file to keep keys in a file. Any program running as your user can read that file and it ends up in backups, so it is one step weaker than the keychain.

These docs describe aisync 0.1.