Free and open source · a gift to the community
agent-vault
Your coding agent never holds a credential.
A local credential proxy for coding agents. The agent sends a placeholder; the vault swaps in the real secret only where that credential belongs, only for a destination you allowed, and scrubs it from every response.
- Apache 2.0
- Free
- Linux and macOS
- Node 20.10+
- No dependencies
$ node demo/demo.js
4. The agent calls the API with the placeholder
status200
upstream receivedAuthorization: Bearer ghp_DEMOSECRET…
what the agent sees"token_used": "av1.embg57k08r4g…"
5. Prompt injection: the agent is told to post its token into an issue comment
status403 AV_BAD_LOCATION
upstream sawnothing - the request never reached the wire
6. The same injection, base64-encoded to hide it
status403 AV_BAD_LOCATION
7. The agent tries to send the placeholder somewhere else entirely
status403 AV_NO_GRANT
Summary
reached the agentnever
reached the audit lognever
How it works
Placeholders in, secrets never out.
Your agent
A placeholder and a session. Nothing else.
sends
Authorization: Bearer av1.7f2x…c4d9tzgets back
{"token_used": "av1.7f2x…"}agent-vault
- 01Checks the session, the grant, the destination and the budget
- 02Spends one use before the first byte leaves
- 03Swaps in the secret, only at the declared place
- 04Scrubs every secret from the response
The service
receives
Authorization: Bearer ghp_real…returns
{"token_used": "ghp_real…"}Even when the service echoes the token back, the agent only ever sees the placeholder.
What makes it safe
Built for an agent that has been told to leak.
Placeholders, not secrets
The agent only ever sees a placeholder. The real credential is substituted at the one place it may be injected, for a destination the grant allows, while the placeholder has uses left.
Built for prompt injection
A placeholder found anywhere else, even percent-, unicode- or base64-encoded, is refused before any upstream connection exists.
Responses scrubbed
Every injected secret and every other stored credential is scrubbed from what comes back, in the encodings it is likely to appear in, across streaming chunks.
The agent asks, a person grants
An agent can request a session; only a human can approve it, and can narrow it first.
A log you can check
A hash-chained audit log with an anchored end, so removing the latest records is detected. No credential value ever enters it.
Works with your agent
MCP for Claude Code, Cursor, Gemini and Codex, an HTTP endpoint, or environment variables for anything that makes an HTTP request. It can route the model's own API key too.
Try it
From zero to a refused prompt injection in a minute.
Get the code from GitHub first. Node 20.10 or newer; there is nothing else to install. Get it on GitHub
01
Watch it work
Starts a real daemon and walks through an injection, an encoded smuggling attempt, an approval and the audit chain.
$ node demo/demo.js02
Install it
Shows the plan, then runs the installer. Run with --dry-run first to see every change.
$ agent-vault setup03
Store a credential
The value is read from your terminal, never from the command line.
$ agent-vault cred add gh --kind github04
Connect your agent
Writes itself into the agent's own config, keeping a backup. Also cursor, gemini and codex.
$ agent-vault mcp install --agent claude-code
Works with
- Claude Code
- Cursor
- Gemini
- Codex
- Anything that speaks HTTP
It can route the model's own API key too: the OpenAI, Anthropic and Gemini SDKs read their base URL from the environment, so no code changes.
Honest status
The working core, tested the way an attacker would test it.
- CI runs the suite on Linux and macOS, on Node 20.10 through 24.
- A security suite that encodes each attack and its refusal, and property tests that generate their own inputs.
- A mutation suite that removes each critical protection in turn and proves the tests notice.
- Four independent adversarial reviews, and every finding fixed with a test behind it.
It is the working core, not the finished v1. The privileged installer has only been run for real on macOS. Read the honest limits
Why we built it
Agents work with your keys. A prompt injection shouldn't be able to walk off with them.
The same idea runs through everything we build: don't rely on an AI behaving well, put a check where it matters. agent-vault puts that check between the agent and the secret, and we're giving it away.
Take it. It's free.
Apache 2.0. Use it, fork it, and tell us what you find.