Self-hosted credential store and API proxy for AI agents. One Bearer token, all your services. Handles OAuth refresh, encrypted storage, audit logging, and per-agent permissioning.
Enables AI agents to securely access authenticated services (HTTP, SSH, SMTP) without exposing secrets, by acting as a server-side proxy that injects authentication.
Permission gateway that hands an AI agent a scoped MCP endpoint instead of an OAuth token: connect 27 services (Gmail, Google Calendar/Drive/Ads/Search Console, Slack, Notion, GitHub, Jira, Salesforce, HubSpot, Stripe, LinkedIn, X, Meta Ads and more), grant per-action permissions finer than native OAuth scopes, audit every call and revoke a key in one click. Self-hostable, MIT.
Credential isolation proxy for AI agents. Injects API keys at the network boundary so your agent never sees the raw credential. Supports domain allowlists, agent auth, policy enforcement, and audit logging.
Enables AI agents to securely perform privileged actions like creating GitHub issues by minting short-lived, single-purpose tokens on demand, with policy enforcement and audit logging.
Local credential broker that enables AI agents to securely run CLI tools like SSH and MySQL without exposing passwords to the AI context, environment variables, or process listings.