ioLiteLabs, Inc.

Free and open source · a gift to the community

agent-vault

Your coding agent never holds a credential.

A local credential proxy for coding agents. The agent sends a placeholder; the vault swaps in the real secret only where that credential belongs, only for a destination you allowed, and scrubs it from every response.

  • Apache 2.0
  • Free
  • Linux and macOS
  • Node 20.10+
  • No dependencies

$ node demo/demo.js

4. The agent calls the API with the placeholder

status200

upstream receivedAuthorization: Bearer ghp_DEMOSECRET…

what the agent sees"token_used": "av1.embg57k08r4g…"

5. Prompt injection: the agent is told to post its token into an issue comment

status403 AV_BAD_LOCATION

upstream sawnothing - the request never reached the wire

6. The same injection, base64-encoded to hide it

status403 AV_BAD_LOCATION

7. The agent tries to send the placeholder somewhere else entirely

status403 AV_NO_GRANT

Summary

reached the agentnever

reached the audit lognever

From node demo/demo.js, shortened

How it works

Placeholders in, secrets never out.

Your agent

A placeholder and a session. Nothing else.

sends

Authorization: Bearer av1.7f2x…c4d9tz

gets back

{"token_used": "av1.7f2x…"}

agent-vault

  1. 01Checks the session, the grant, the destination and the budget
  2. 02Spends one use before the first byte leaves
  3. 03Swaps in the secret, only at the declared place
  4. 04Scrubs every secret from the response

The service

receives

Authorization: Bearer ghp_real…

returns

{"token_used": "ghp_real…"}

Even when the service echoes the token back, the agent only ever sees the placeholder.

What makes it safe

Built for an agent that has been told to leak.

Placeholders, not secrets

The agent only ever sees a placeholder. The real credential is substituted at the one place it may be injected, for a destination the grant allows, while the placeholder has uses left.

Built for prompt injection

A placeholder found anywhere else, even percent-, unicode- or base64-encoded, is refused before any upstream connection exists.

Responses scrubbed

Every injected secret and every other stored credential is scrubbed from what comes back, in the encodings it is likely to appear in, across streaming chunks.

The agent asks, a person grants

An agent can request a session; only a human can approve it, and can narrow it first.

A log you can check

A hash-chained audit log with an anchored end, so removing the latest records is detected. No credential value ever enters it.

Works with your agent

MCP for Claude Code, Cursor, Gemini and Codex, an HTTP endpoint, or environment variables for anything that makes an HTTP request. It can route the model's own API key too.

Try it

From zero to a refused prompt injection in a minute.

Get the code from GitHub first. Node 20.10 or newer; there is nothing else to install. Get it on GitHub

  1. 01

    Watch it work

    Starts a real daemon and walks through an injection, an encoded smuggling attempt, an approval and the audit chain.

    $ node demo/demo.js
  2. 02

    Install it

    Shows the plan, then runs the installer. Run with --dry-run first to see every change.

    $ agent-vault setup
  3. 03

    Store a credential

    The value is read from your terminal, never from the command line.

    $ agent-vault cred add gh --kind github
  4. 04

    Connect your agent

    Writes itself into the agent's own config, keeping a backup. Also cursor, gemini and codex.

    $ agent-vault mcp install --agent claude-code

Works with

  • Claude Code
  • Cursor
  • Gemini
  • Codex
  • Anything that speaks HTTP

It can route the model's own API key too: the OpenAI, Anthropic and Gemini SDKs read their base URL from the environment, so no code changes.

Honest status

The working core, tested the way an attacker would test it.

  • CI runs the suite on Linux and macOS, on Node 20.10 through 24.
  • A security suite that encodes each attack and its refusal, and property tests that generate their own inputs.
  • A mutation suite that removes each critical protection in turn and proves the tests notice.
  • Four independent adversarial reviews, and every finding fixed with a test behind it.

It is the working core, not the finished v1. The privileged installer has only been run for real on macOS. Read the honest limits

Why we built it

Agents work with your keys. A prompt injection shouldn't be able to walk off with them.

The same idea runs through everything we build: don't rely on an AI behaving well, put a check where it matters. agent-vault puts that check between the agent and the secret, and we're giving it away.

Take it. It's free.

Apache 2.0. Use it, fork it, and tell us what you find.