Agent access without the credentials.
Agents route their calls through a proxy that attaches the real credential on the way out. Scope what each one can reach, time-bound it, and revoke it mid-run.

The problem
A credential an agent can read is a credential it can leak.
Prompt injection is only one way out. An agent can print a key into its own monologue and ship it to the model provider, install a package whose post-install hook forwards it, or work from a .env someone created just to get their coding agent running. You often find out on the rotation, not the leak.
Agents get the access. Infisical keeps the credential.
Agent Vault connects AI agents to the APIs, MCP servers, and internal services they need to do work, without exposing any underlying credential to the agent, its environment, or the model behind it.
Real credentials attach at the network boundary
The proxy applies the real credential as the request leaves, attaching an auth header the agent never sent or substituting a real value where it used a placeholder. Nothing in the agent's context, environment, or transcript holds a real value.
Scope access to the job an agent is doing
Group the services one kind of agent needs into a reusable bundle: GitHub and Slack for code review, Twilio and Google Docs for marketing. Reuse it across every session that does that job.
Time-bound sessions you can revoke mid-run
Every session is scoped to one bundle and expires on a schedule you set. Revoke it early and the proxy stops attaching credentials within one poll, with nothing on the agent's machine to restart.
Works with any agent or harness
Anything that honors HTTPS_PROXY runs behind Agent Vault: Claude Code, Codex, OpenClaw, Hermes, or a harness you wrote yourself. Nothing about the agent itself has to change.
Every brokered request gets recorded
See what each agent called, when, and whether it was allowed. Requests to hosts outside the bundle are denied rather than quietly forwarded, and expired sessions stay readable for 30 days.
How it works
Set it up once, then mint sessions.
Define the services an agent is allowed to reach, run a proxy where your agents' traffic leaves, and mint sessions against an access bundle whenever an agent needs to work.
Everything you get with Agent Vault.
- Access bundlesReusable, job-shaped lists of the services an agent can reach during a session.
- Time-bound sessionsSet a TTL, revoke early, and keep expired and revoked sessions readable for 30 days.
- Service templatesOpenAI, Anthropic, Slack, GitHub, and Google Workspace, or a custom host and header.
- Bearer, Basic, and pass-through authChoose how the credential is applied per service, or forward a request untouched.
- Custom headers and substitutionsInject a credential into a URL path, query string, or request body when a header won't do.
- Interface-agnosticAny agent or runtime that honors HTTPS_PROXY, without a code change.
- A proxy you runEnroll over CLI, Docker, or systemd, on its own host or next to a single agent.
- Traffic policyDecide what happens to hosts you haven't configured, and block everything else.
- Two-level access controlProduct membership plus per-bundle grants for users, groups, and machine identities.
- Changes land in 60 secondsRevoke a grant or a session and running agents lose it within one proxy poll.
- Machine identity attributionGive an agent its own identity and every session it opens is attributed to it.
- Full audit loggingEvery brokered request recorded, denials included.
Some of our (human) customers.
Frequently asked questions
Everything you need to know. Can't find an answer? Talk to our team.

