Skip to content

Repository files navigation

Awesome Agent Vault Awesome

The category map for giving agents credentials safely. Products, integrations, per-service recipes, patterns, threat models. Neutral, curated, no CTAs.

This list is a directory, not a product. agent-vault is also the name of a product shipped by Infisical, listed below alongside every other entry in this space. See CATEGORY-MAP.md for how this list stays neutral.

Last verified: 2026-05-27.

Contents

The category map

Five reader-intent buckets. Every entry belongs to exactly one bucket.

                  Awesome Agent Vault
                          |
   +--------+----------+--+----+----------+-------------+
   |        |          |      |          |             |
Products  Integr-   Services  Patterns  Threat models  Web
          ations    (recipes) (the IP)  (security)     (matrix)
  • Products are the things you install or call: vaults, proxies, identity layers, credential gateways.
  • Integrations are the agent platforms that consume those products: Claude Code, Codex, Cursor, LangChain, etc.
  • Services are per-third-party-API recipes: Stripe, GitHub, Slack. Each names the credential type to mint and the scopes to refuse.
  • Patterns are named recipes for recurring problems, each citing the project that demonstrably handles it best.
  • Threat models are documented attack surfaces with mitigations and references.

Compatibility matrix

Rows are products. Columns are agent platforms.

Product Claude Code Codex CLI Cursor Aider Windsurf LangChain OpenAI Agents SDK Mastra Vercel AI SDK Continue.dev
1Password CLI 1 🟡 🟡
Authsome 🟡 🟡 🟡 🟡
AWS Secrets Manager 🟡 🟡 🟡 🟡 🟡 🟡
Bitwarden Agent Access 🟡 🟡 - - 🟡 🟡 - - -
Botiverse agent-vault 🟡 - - - - 🟡 - - - -
Doppler
HashiCorp Vault 🟡 🟡 🟡 🟡 🟡 🟡
Infisical Agent Vault 🟡 🟡 🟡 🟡 🟡 🟡 🟡 🟡 🟡
Keeper Agent Kit - - - - - - -
Kontext CLI 🟡 🟡 - - - - 🟡
LiteLLM Agent Platform 🟡 🟡 🟡 🟡 🟡 🟡
onecli 🟡 🟡 🟡 🟡 🟡 🟡 🟡
Pulumi ESC
SOPS 🟡 🟡 🟡 🟡 🟡 🟡 🟡 🟡 🟡 🟡
Wirken 🟡 🟡 - - - - - - - -

Cell meanings: ✅ maintained adapter or first-party docs. 🟡 can be wired in, requires custom glue. - no public path. ? maintainer has not been asked.

Products added during the 2026-05-27 gap research (AgentGuard, AWS Secrets Manager Agent, Composio, DeepSecure, earl, faramesh-core, hasp, jentic-mini, mcp-governance-sdk, mcp-secrets-plugin, psst, sigcli, zeroid) are pending matrix verification with their maintainers and not yet rendered above.

Products

Vaults, proxies, identity layers, and credential gateways. Alphabetical. Entry name links to the upstream project; (details) opens our notes.

  • 1Password CLI · op run substitutes op:// secret references into a process environment at startup. Closed source, Go binary. (details)
  • agentgateway · Rust agentic proxy for AI agents and MCP servers with credential injection at the proxy layer. (details)
  • AgentGuard · Runtime guardrail layer for agents: data loss path blocking, secret scrubbing, skill trust registry. (details)
  • Arcade.dev · MCP server framework plus commercial OAuth-for-agents platform. Per-user OAuth tokens for many third-party APIs. (details)
  • archestra · Enterprise AI platform with guardrails plus MCP registry, gateway, and orchestrator. (details)
  • Authsome · Local OAuth2 and API-key vault. The agent never sees raw credentials. MIT, Python. (details)
  • AWS Secrets Manager · IAM-scoped managed secret store with rotation. Proprietary. (details)
  • AWS Secrets Manager Agent · Official AWS sidecar exposing Secrets Manager over loopback. Apache 2.0, Rust. (details)
  • Bitwarden Agent Access · Open protocol for per-request human approval against a Bitwarden vault. Apache 2.0, Rust. (details)
  • Botiverse agent-vault · Local proxy that keeps secrets out of chat-agent context. Apache 2.0, TypeScript. (details)
  • Casdoor · Open-source agent-first IAM/LLM MCP gateway and auth server. OAuth/OIDC/SAML/SCIM for agents. (details)
  • Composio · Toolkit platform with 1000+ integrations and managed OAuth for agent frameworks. Apache 2.0. (details)
  • DeepSecure · Identity, credential, and access management for AI agents and MCP servers. (details)
  • Docker MCP Gateway · Official Docker CLI plugin and gateway for MCP. Manages secret and env injection into MCP servers. (details)
  • Doppler · CLI that injects a project's secrets into a wrapped process. Apache 2.0, Go. (details)
  • earl · Rust CLI proxy with HCL operation templates, OS keychain secrets, MCP integration. (details)
  • faramesh-core · Governance-as-Code library for agent credential brokering. (details)
  • hasp · Local-first broker for managed secrets in agent workflows. Go. (details)
  • HashiCorp Vault · General secrets platform with Vault Agent sidecars and an AI-agent-identity validated pattern. BUSL 1.1, Go. (details)
  • Infisical Agent Vault · HTTPS proxy that swaps placeholder tokens for real credentials at the network layer. Source-available, Go. (details)
  • jentic-mini · Self-hosted API execution layer that injects credentials between agent and external APIs. (details)
  • Keeper Agent Kit · Skill bundle wrapping Keeper Secrets Manager for coding agents. Apache 2.0, Shell. (details)
  • Kong AI Gateway · API gateway with LLM/MCP gateway features. Production-grade rate limiting, observability, auth plugins. Apache 2.0. (details)
  • Kontext CLI · Wraps coding agents with RFC 8693 token-exchanged short-lived credentials. MIT, Go. (details)
  • LiteLLM Agent Platform · Self-hosted platform running coding agents in isolated sandboxes with a vault proxy. MIT, TypeScript. (details)
  • mcp-governance-sdk · Enterprise governance layer (identity, RBAC, credentials, audit) for the MCP SDK. (details)
  • mcp-secrets-plugin · OS-keychain credential management for MCP servers. (details)
  • metamcp · MCP aggregator, orchestrator, middleware, and gateway in one container. Handles per-server authentication. (details)
  • Microsoft Agent Governance Toolkit · Policy enforcement, zero-trust identity, and sandboxing scaffolding for agent credential brokers. MIT. (details)
  • Nango · OAuth-token broker positioned for agents and MCP. Handles auth lifecycle for hundreds of third-party APIs. (details)
  • onecli · Single-binary credential gateway with a built-in vault for AI agents. Apache 2.0, TypeScript. (details)
  • psst · AI-native secrets manager using the OS keychain and a token-substitution model. (details)
  • Pulumi ESC · Environments, secrets, and configuration service that composes secrets from many backends. Apache 2.0, Go. (details)
  • sigcli · Auth CLI and proxy for AI agents: "give agents access, not your credentials." (details)
  • snyk agent-scan · Security scanner for AI agents, MCP servers, and agent skills. Detects credential disclosure surfaces. (details)
  • SOPS · Encrypts files in place with KMS, age, or PGP. MPL 2.0, Go. (details)
  • Wirken · Single-binary switchboard with encrypted vault, per-channel isolation, and hash-chained audit log. MIT, Rust. (details)
  • zeroid · Autonomous Agent Identity Management System using RFC 8693 token exchange and SPIFFE. (details)

Integrations

How each agent platform consumes credentials today. Alphabetical. Entry name links to the upstream project; (details) opens our notes.

  • Aider · .env and .aider.conf.yml. Ad hoc, env vars only. (details)
  • AutoGen · Model client config plus tool env vars; conductor pattern inherits credentials across spawned agents. (details)
  • browser-use · Top open-source browser agent framework. Ships sensitive_data primitives and allowed-domain controls. (details)
  • Claude Code · settings.json env, MCP env per server, pre/post-tool-use hooks, skills. (details)
  • Cline · VS Code extension settings, MCP config, inherited env. No first-party broker. (details)
  • Codex CLI · ~/.codex/config.toml, per-provider env_key, optional OS keyring. (details)
  • Continue.dev · config.yaml with ${{ secrets.NAME }} resolved from .env, workspace .env, or Mission Control hub. (details)
  • CrewAI · Tool constructors accept credentials at init time. Common pairing with Composio. (details)
  • Crush · Charm's TUI coding agent (successor to opencode-ai/opencode). Provider config in .crush.json plus env vars. (details)
  • Cursor · ~/.cursor/mcp.json with ${env:VAR} interpolation. Remote-header interpolation broken. (details)
  • Goose · ~/.config/goose/config.yaml plus per-extension env vars. (details)
  • LangChain · secret_from_env returns SecretStr for log scrubbing. (details)
  • LangGraph · RunnableConfig["configurable"] plus the Auth handler for per-request secret resolution. (details)
  • LlamaIndex · Data framework for LLM apps. Data loaders carry credentials; no built-in broker. Common pairing with Composio. (details)
  • Mastra · mastra server env import (mode 0600); pluggable auth providers. (details)
  • OpenAI Agents SDK · Lazy-read OPENAI_API_KEY, set_default_openai_key. Third-party tool creds are ad hoc. (details)
  • OpenCode · Terminal coding agent. opencode auth login <provider> persists tokens; provider env vars at startup. (details)
  • OpenHands · Sandboxed container runtime; egress proxy is a natural injection point. (details)
  • Plandex · Open-source terminal coding agent. Provider keys from env vars. Same credential model as Aider and Crush. (details)
  • Pydantic AI · Provider env vars; Pydantic SecretStr scrubs logs. (details)
  • Stagehand · Browser-agent SDK by Browserbase. Pairs naturally with Browserbase managed sessions. (details)
  • Vercel AI SDK · process.env inside tool({ execute }), Sensitive env vars, AI Gateway OIDC. (details)
  • Windsurf · mcp_config.json with ${env:VAR} interpolation across command/args/env/headers/url. (details)

Services

Per-third-party-API credential recipes. Alphabetical. Entry name links to the canonical credential docs; (recipe) opens our agent-specific notes.

  • Anthropic · Workspace-scoped keys, admin keys held separately. (recipe)
  • Apollo · API keys per user. No per-resource scoping; treat as full-account. (recipe)
  • Atlassian · OAuth 2.0 3LO for Jira and Confluence under user delegation. (recipe)
  • Buffer · OAuth 2.0 with refresh tokens. Scopes per social channel. (recipe)
  • Cal.com · OAuth client + managed-user access tokens (60m) and refresh (1y). (recipe)
  • Calendly · OAuth 2.0 with scoped grants; PATs as a fallback. (recipe)
  • Cloudflare · API tokens with permission group, resource, IP, and TTL filters. (recipe)
  • Discord · Bot tokens (long-lived, coarse) vs OAuth 2.0 access tokens (scoped). (recipe)
  • GitHub · GitHub App installation tokens (1h, repo-scoped). (recipe)
  • GitLab · Personal/group/project access tokens with expiry and scope. OAuth for delegated actions. (recipe)
  • Google Workspace · OAuth 2.0 with per-scope grants; service accounts with domain-wide delegation. (recipe)
  • HubSpot · Private apps with minimum CRM scopes. (recipe)
  • Intercom · OAuth for marketplace apps; long-lived access tokens for internal apps. (recipe)
  • Klaviyo · OAuth for marketplace integrations, private API keys for first-party. (recipe)
  • Linear · OAuth with actor authorization for revocable, attributed writes. (recipe)
  • Mailchimp · API keys with data center prefix. No native scoping; rotate aggressively. (recipe)
  • Mailgun · Domain sending keys bound to one verified domain. (recipe)
  • Microsoft Graph · OAuth 2.0 with Entra ID. Application and delegated permissions. (recipe)
  • Notion · Public OAuth integration with rotating refresh tokens. (recipe)
  • OpenAI · Project-scoped service account keys with Restricted permissions. (recipe)
  • Pinecone · Project-scoped API keys (granular roles require Standard+). (recipe)
  • Plaid · Per-user Item access tokens; rotate via /item/access_token/invalidate. (recipe)
  • Postmark · Server tokens scoped to one Postmark Server (sending domain). (recipe)
  • Resend · Sending-access key bound to one verified domain. (recipe)
  • Salesforce · JWT Bearer flow with per-agent certificate and minimum scopes. (recipe)
  • SendGrid · Custom (Restricted) access key with only mail.send. (recipe)
  • Shopify · Custom-app Admin API token, read-only where possible. (recipe)
  • Slack · Bot tokens with granular scopes and 12h rotation. (recipe)
  • Stripe · Restricted API keys (RAKs) with per-resource Read/Write. (recipe)
  • Supabase · Secret key on the server, never the service_role JWT in agent reach. (recipe)
  • Twilio · Per-agent Subaccount + Restricted API key. (recipe)
  • Typeform · OAuth 2.0 with explicit scopes for forms, results, accounts. (recipe)
  • Vercel · Team-scoped PATs with explicit expiry. (recipe)
  • X (Twitter) · OAuth 2.0 with PKCE. Per-scope grants for read/write/DM. (recipe)
  • Zapier · OAuth flows for embedded integrations; team-scoped API keys for internal Zaps. (recipe)

Patterns

Named recipes. Each cites the project that best implements it.

Threat models

Contributing

PRs welcome. Read CONTRIBUTING.md and CATEGORY-MAP.md first. Every entry follows the same frontmatter and word-count shape. Direct competitors of the maintainer get accepted on equal terms.

License

CC0 1.0 Universal. Public domain dedication.


Curated by Authsome · agent identity for third-party APIs. Authsome is one of the products listed above. See CATEGORY-MAP.md for how that is handled.

Footnotes

  1. 1Password Environments MCP server shipped a Codex-first integration in May 2026.

About

The category map for agent credential management. Products, integrations, recipes, patterns, threat models. Curated by Authsome.

Topics

Resources

Contributing

Stars

13 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors