Agent access without the credentials.

Agents route their calls through a proxy that attaches the real credential on the way out. Scope what each one can reach, time-bound it, and revoke it mid-run.

Trusted by the best teams in the world

The problem

A credential an agent can read is a credential it can leak.

Prompt injection is only one way out. An agent can print a key into its own monologue and ship it to the model provider, install a package whose post-install hook forwards it, or work from a .env someone created just to get their coding agent running. You often find out on the rotation, not the leak.

Agents get the access. Infisical keeps the credential.

Agent Vault connects AI agents to the APIs, MCP servers, and internal services they need to do work, without exposing any underlying credential to the agent, its environment, or the model behind it.

.env
# what the agent sees
STRIPE_API_KEY=_stripe_dummy_key_
GITHUB_TOKEN=_github_dummy_token_
DATABASE_URL=_database_dummy_url_
# real values attach at the proxy
Broker

Real credentials attach at the network boundary

The proxy applies the real credential as the request leaves, attaching an auth header the agent never sent or substituting a real value where it used a placeholder. Nothing in the agent's context, environment, or transcript holds a real value.

Placeholder valuesNo code changesHTTPS_PROXY
Agent
GitHub
Stripe
AWS
claude-code
codex
ci-agent
hermes
Scope

Scope access to the job an agent is doing

Group the services one kind of agent needs into a reusable bundle: GitHub and Slack for code review, Twilio and Google Docs for marketing. Reuse it across every session that does that job.

Reusable bundlesPer-bundle grantsEgress policy
Access bundle
Expires
State
code-review
6d 04h
Active
marketing
22m
Active
customer-feedback
--
Revoked
code-review
--
Expired
Grant

Time-bound sessions you can revoke mid-run

Every session is scoped to one bundle and expires on a schedule you set. Revoke it early and the proxy stops attaching credentials within one poll, with nothing on the agent's machine to restart.

Set a TTLRevoke early60-second propagation
Claude Code
Codex
Hermes
OpenClaw
Agent
Vault
APIs
MCPs
OAuth
Run

Works with any agent or harness

Anything that honors HTTPS_PROXY runs behind Agent Vault: Claude Code, Codex, OpenClaw, Hermes, or a harness you wrote yourself. Nothing about the agent itself has to change.

Claude CodeCodexCustom harnesses
Time
Agent
Host
Status
14:02:11
claude-code
api.stripe.com
14:02:13
codex
api.github.com
14:02:15
hermes
mcp.linear.app
14:02:18
codex
evil-exfil.io
Denied
Audit

Every brokered request gets recorded

See what each agent called, when, and whether it was allowed. Requests to hosts outside the bundle are denied rather than quietly forwarded, and expired sessions stay readable for 30 days.

Per-request logsEgress denialsIdentity attribution

How it works

Set it up once, then mint sessions.

Define the services an agent is allowed to reach, run a proxy where your agents' traffic leaves, and mint sessions against an access bundle whenever an agent needs to work.

Build an access bundlepreview coming
Run a proxypreview coming
Mint a sessionpreview coming

Everything you get with Agent Vault.

  • Access bundlesReusable, job-shaped lists of the services an agent can reach during a session.
  • Time-bound sessionsSet a TTL, revoke early, and keep expired and revoked sessions readable for 30 days.
  • Service templatesOpenAI, Anthropic, Slack, GitHub, and Google Workspace, or a custom host and header.
  • Bearer, Basic, and pass-through authChoose how the credential is applied per service, or forward a request untouched.
  • Custom headers and substitutionsInject a credential into a URL path, query string, or request body when a header won't do.
  • Interface-agnosticAny agent or runtime that honors HTTPS_PROXY, without a code change.
  • A proxy you runEnroll over CLI, Docker, or systemd, on its own host or next to a single agent.
  • Traffic policyDecide what happens to hosts you haven't configured, and block everything else.
  • Two-level access controlProduct membership plus per-bundle grants for users, groups, and machine identities.
  • Changes land in 60 secondsRevoke a grant or a session and running agents lose it within one proxy poll.
  • Machine identity attributionGive an agent its own identity and every session it opens is attributed to it.
  • Full audit loggingEvery brokered request recorded, denials included.

Your first agent, running credential-free.

  1. Bundle

    Group the services your agent needs and add a credential to each.

  2. Proxy

    Enroll a proxy where your agents' traffic leaves your network.

  3. Run

    Mint a session and start the agent behind it.

Frequently asked questions

Everything you need to know. Can't find an answer? Talk to our team.

The agent's HTTP clients are pointed at a forward proxy through the standard HTTPS_PROXY variable. On the way out, the proxy applies the real credential to any request bound for a service you have configured. Depending on how that service is set up, it attaches an auth header the agent never sent, replaces one the agent did send, or substitutes a real value where the agent used a placeholder. Either way the credential stays in Infisical and is never written into the agent's environment, filesystem, or context.