A gate that fails closed
A Claude Code hook sends force pushes, deploys, deletes and anything matching your rules to your phone. No answer in time means no: the hook denies before Claude Code’s own timeout, so it never fails open.
For developers
Coding agents run commands and need your tokens. Vando puts your phone in the loop: risky commands and secrets wait for a tap, secrets go into the command instead of the chat, and every decision leaves a receipt signed on your phone.
> push my branch over main, CI is flaky anyway ● I'll force-push the rebased branch. ● Bash(git push --force origin main) ⏳ Vando: this needs your phone (force push to main)… ✗ Denied on Tom’s phone · “never force-push main” ● Understood. I’ll open a pull request instead.
> publish 2.4.0 to npm ● Bash(npm publish) ⏳ Vando: wants “npm token” for this command… ✓ Approved · token passed to this command only + @storefront/checkout@2.4.0 ● Published. (The token never appeared here, so it isn’t in my context or your logs.)
$ npx vando connect Connect Claude Code to Vando Code K7QM-4XTB Words amber · kettle · orbit · 4F2A Check your phone shows the same words… ✓ Connected as “Claude Code · MacBook” Reading is allowed. Sending, deleting, paying and secrets ask your phone first.
> why is checkout slow in production? ● I need to read the API logs in AWS. ⏳ Vando: asking for read-only log access (20 min)… ✓ Temporary key issued · expires 14:32 ● aws logs filter-log-events --log-group api-checkout p99 latency 2.4 s since 09:10 deploy… (Your AWS keys never left Vando.)
git push --force origin main
Goes into this one command. It won’t appear in the chat or the AI company’s logs.
Only connect if these words match your terminal:
amber · kettle · orbit · 4F2A
Your phone remembers this agent’s key, so nothing else can pretend to be it later.
A Claude Code hook sends force pushes, deploys, deletes and anything matching your rules to your phone. No answer in time means no: the hook denies before Claude Code’s own timeout, so it never fails open.
Approve a token on your phone and Vando hands it to that one command. It never lands in the model’s context, its logs or the provider’s servers.
Reading is allowed; sending, deleting, paying and secrets ask you. Loosening a rule waits a day or needs your security key, so a compromised laptop can’t quietly relax it.
Pause an agent and its open asks are cancelled at once. Disconnect it and anything sent but not collected is destroyed. You see every secret it ever received, so you know what to rotate.
Claude Code first; Cursor, Claude Desktop and other MCP clients follow. Not open yet. Security design →