DEV Community

Bees
Bees

Posted on Originally published at bees.bot

Your keys and logins stay on your computer

This post first appeared on the Bees blog.

An AI agent that does real work needs real access. It needs an AI key to think with, your Google account to read your mail or Drive, and a logged-in browser for the sites that have no API.

Most hosted agent products keep all of that on their servers. You paste your key into their web page. You click "Connect Google" and the refresh token (the long-lived pass that lets an app back into your account) goes into their database. Their browser runs in their cloud, holding your cookies.

That works, but it means one company holds a copy of every key and session its users have. One breach, one careless log line or one curious employee reaches all of them at once.

Bees does it the other way. The agents run on your computer, so the keys and logins can stay there too. Here is where each one lives, and what our server sees.

Your AI keys, Google sign-ins, browser cookies, files and agents stay on your computer. Prompts go straight to an AI company only if you pick a cloud model. Google calls use your own tokens. Bees Cloud is optional and gets names, titles and run summaries, never keys, tokens, cookies or file contents.

AI keys

When you add a key for OpenAI, Anthropic, OpenRouter or Google, Bees first sends one small test request straight to that provider to check the key works. Only then does it save the key on your computer.

After that, your prompts go straight from your computer to the provider. No Bees server sits in the middle, so we never see the key or the prompts. Google keys go in a request header rather than the web address, because addresses end up in logs far more often than headers do.

The default model runs on your own computer. With it, your prompts are not sent to any AI company.

Google: Gmail, Calendar and Drive

Connecting a Google account happens on your computer. Bees opens Google's consent page in your browser. Google then sends you back to a small listener on your own machine (127.0.0.1), which shuts itself down after a few minutes.

The tokens Google hands back are saved on your computer. The Gmail, Calendar and Drive add-ons read them from there and call Google directly. Our server never receives them.

Signing in to Bees itself with Google is different, and we want to be clear about it. Our server learns your name and email so it can create your Bees account. It does not get access to your mail, calendar or files.

Browser logins

Some work only happens in a browser: a site with no API, or a dashboard behind a login. A hosted agent runs that browser in its own cloud, so your cookies, the things that keep you logged in, live on its machines.

Bees drives the Google Chrome already installed on your Mac, with a separate profile that belongs to Bees. Your everyday Chrome profile is not touched. You log in to a site once inside the Bees profile, and those cookies stay in that profile's folder on your disk. Bees also saves a copy of them to a local file, so you stay logged in after a restart. None of that code talks to our server.

We use your real Chrome instead of a bundled test browser for a practical reason: Google refuses sign-ins from browsers that announce they are automated. For now the agent's browser works on Mac only.

Where the keys are kept

AI keys, Google tokens, add-on keys and your Bees session all go into one credentials file in the Bees folder under your home directory. On Mac and Linux, Bees creates that file so only your user account can read it, and refuses to start if someone loosens that.

The screen where you manage AI keys is only told whether a key is set, never the key itself. When a run's history shows a tool call, values with names like token, password or API key are shown as hidden.

What our server does see

Bees Cloud is optional. It exists so a team can see each other's work. When you use it, the app sends seven kinds of records, each with a fixed list of fields:

  • the names and settings of your processes, agents and schedules
  • work item titles, status and who owns them
  • file names and paths relative to a shared folder, never full paths from your disk and never file contents
  • a summary of each run, capped at 20,000 characters

It never sends keys, tokens, cookies or file contents. One honest caveat: a run summary is the agent's own words about what it did, so it can mention things from your files.

The app sends no usage analytics and no crash reports. It starts its agent engine with telemetry switched off, and there is no analytics code in it. It does ask our server for its sign-in settings when it starts, even if you never sign in. That request carries no account token and no usage data, but like any request it shows us your IP address. It also asks GitHub whether a new version is out, when it starts and every six hours. That request goes to GitHub, not us. It names only the update tool Bees uses, not you or your Bees version, and your computer compares the versions itself.

What this does not protect you from

  • A cloud model sees what you send it. If you pick a cloud AI model, the text an agent works on goes to that AI company under its own terms. Use the local model when that matters.
  • The credentials file is not encrypted. It is protected the way your SSH keys are, by file permissions. That stops other users on the same computer. It does not stop malware running as you.
  • A run folder is not a full sandbox. Bees gives each run its own folder with only the files it needs. That narrows what an agent can touch, but it is not a wall against hostile code.
  • Your computer has to be on. Agents run on your computer, so they only work while it is awake.

We think this is the right trade for a desktop app that handles work files and real accounts. If a hosted tool fits you better, that is a fair choice too. Just ask it where your refresh tokens live.

If you want to try Bees on your own machine, download it here.

Top comments (0)