
A HTTP credential proxy and vault for AI agents like Claude Code, OpenClaw, Hermes, custom agents + harnesses, and more.
HTTP credential proxy and vault
An open-source credential broker by Infisical that sits between your agents and the APIs they call.
Agents should not possess credentials. Agent Vault eliminates credential exfiltration risk with brokered access.
New here? The launch blog post has the full story behind Agent Vault.
Documentation | Installation | Tutorial | Video Demo | Slack
Traditional secrets management involves returning credentials back to you applications and services. This breaks down with AI agents which can be tricked via prompt injection into leaking secrets. This is the problem of credential exfiltration.
Agent Vault was created to solve credential exfiltration for all AI agents. Instead of giving AI agents credentals directly, you store them in Agent Vault (e.g. ANTHROPIC_API_KEY, GITHUB_PAT, etc.) and force your agents to route HTTP requests through it. Agent Vault intercepts every request and attaches credentials onto it before forwarding the request to the target outbound API.
Features:
__anthropic_api_key__ with real credentials or replacing auth headers entirely on outbound requests through it.HTTPS_PROXY and be compatible with Agent Vault's MITM architecture.mitmproxy or squid require modification to perform credential brokering and integrate well with agents. Agent Vault is purpose-built to work with the ergonomics of all types of agent use-cases with a dedicated CLI, multi-tenancy, and agent-specific roadmap backed by Infisical.By default, requests not matching any service forward as plain proxy traffic; flip a vault into strict deny mode (unmatched_host_policy=deny) to reject them with 403 instead.
Read the full backstory behind Agent Vault here.
Agent Vault works with all kinds of AI Agent use-cases including secure remote coding agents, all-purpose agents, custom agents + harnesses, secure ephemeral sandboxes and more.
ANTHROPIC_API_KEY and GITHUB_PAT in Agent Vault, allowing Claude Code to interact with the Anthropic and GitHub API to code, raise PRs, and more. The same principle applies to other coding agents.Agent Vault is both a vault and proxy service and ships as a single binary that acts as both a server and CLI client. It stores credentials and brokers them to your AI agents using a MITM proxy architecture. By design, Agent Vault is meant to be deployed on a separate machine from your AI agents to provide the security guarantee needed so your AI agents cannot directly access the credentials within Agent Vault.
┌─────────────────────────────────────────────────────────────────┐
│ Public internet │
│ │
│ api.anthropic.com api.github.com api.stripe.com ... │
│ ▲ ▲ ▲ │
└──────────┼───────────────────┼──────────────────┼───────────────┘
│ │ │
└───────────────────┼──────────────────┘
│ outbound HTTPS, Agent Vault
│ injects credentials on the way out
┌──────────────────────────────┼──────────────────────────────────┐
│ Private network │ │
│ │ │
│ ┌───────────────────────────┴────┐ ┌────────────────────┐ │
│ │ Agent Vault │ │ AI agent │ │
│ │ :14321 management UI / API │◀────│ HTTPS_PROXY= │ │
│ │ :14322 MITM proxy │ │ agent-vault:14322 │ │
│ └────────────────▲───────────────┘ └────────────────────┘ │
│ │ │
└───────────────────┼─────────────────────────────────────────────┘
│ operator access: keep private, or front
│ with TLS + auth (SSO reverse proxy, IP
│ allowlist, or VPN) if you need remote admin
│
Operator
You can configure Agent Vault to broker credentials for an AI agents in just a few steps:
curl --proto '=https' --proto-redir '=https' --tlsv1.2 -fsSL https://get.agent-vault.dev | sh
Start the Agent Vault server and set a master password for it (store it somewhere safe); the password is used as part of its data encryption mechanism and is unset from the process after the initial read.
export AGENT_VAULT_MASTER_PASSWORD=your-password
agent-vault server -d