The category map for giving agents credentials safely. Products, integrations, per-service recipes, patterns, threat models. Neutral, curated, no CTAs.
This list is a directory, not a product. agent-vault is also the name of a product shipped by Infisical, listed below alongside every other entry in this space. See CATEGORY-MAP.md for how this list stays neutral.
Last verified: 2026-05-27.
- The category map
- Compatibility matrix
- Products
- Integrations
- Services
- Patterns
- Threat models
- Contributing
- License
Five reader-intent buckets. Every entry belongs to exactly one bucket.
Awesome Agent Vault
|
+--------+----------+--+----+----------+-------------+
| | | | | |
Products Integr- Services Patterns Threat models Web
ations (recipes) (the IP) (security) (matrix)
- Products are the things you install or call: vaults, proxies, identity layers, credential gateways.
- Integrations are the agent platforms that consume those products: Claude Code, Codex, Cursor, LangChain, etc.
- Services are per-third-party-API recipes: Stripe, GitHub, Slack. Each names the credential type to mint and the scopes to refuse.
- Patterns are named recipes for recurring problems, each citing the project that demonstrably handles it best.
- Threat models are documented attack surfaces with mitigations and references.
Rows are products. Columns are agent platforms.
| Product | Claude Code | Codex CLI | Cursor | Aider | Windsurf | LangChain | OpenAI Agents SDK | Mastra | Vercel AI SDK | Continue.dev |
|---|---|---|---|---|---|---|---|---|---|---|
| 1Password CLI | ✅ | ✅ 1 | 🟡 | ✅ | 🟡 | ✅ | ✅ | ✅ | ✅ | ✅ |
| Authsome | ✅ | ✅ | ✅ | ✅ | ✅ | 🟡 | 🟡 | 🟡 | 🟡 | ✅ |
| AWS Secrets Manager | 🟡 | 🟡 | 🟡 | 🟡 | 🟡 | ✅ | ✅ | ✅ | ✅ | 🟡 |
| Bitwarden Agent Access | ✅ | 🟡 | 🟡 | - | - | 🟡 | 🟡 | - | - | - |
| Botiverse agent-vault | 🟡 | - | - | - | - | 🟡 | - | - | - | - |
| Doppler | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ |
| HashiCorp Vault | 🟡 | 🟡 | 🟡 | 🟡 | 🟡 | ✅ | ✅ | ✅ | ✅ | 🟡 |
| Infisical Agent Vault | ✅ | 🟡 | 🟡 | 🟡 | 🟡 | 🟡 | 🟡 | 🟡 | 🟡 | 🟡 |
| Keeper Agent Kit | ✅ | ✅ | ✅ | - | - | - | - | - | - | - |
| Kontext CLI | ✅ | ✅ | ✅ | 🟡 | 🟡 | - | - | - | - | 🟡 |
| LiteLLM Agent Platform | ✅ | ✅ | 🟡 | 🟡 | 🟡 | ✅ | ✅ | 🟡 | 🟡 | 🟡 |
| onecli | ✅ | ✅ | ✅ | 🟡 | 🟡 | 🟡 | 🟡 | 🟡 | 🟡 | 🟡 |
| Pulumi ESC | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ |
| SOPS | 🟡 | 🟡 | 🟡 | 🟡 | 🟡 | 🟡 | 🟡 | 🟡 | 🟡 | 🟡 |
| Wirken | 🟡 | 🟡 | - | - | - | - | - | - | - | - |
Cell meanings: ✅ maintained adapter or first-party docs. 🟡 can be wired in, requires custom glue. - no public path. ? maintainer has not been asked.
Products added during the 2026-05-27 gap research (AgentGuard, AWS Secrets Manager Agent, Composio, DeepSecure, earl, faramesh-core, hasp, jentic-mini, mcp-governance-sdk, mcp-secrets-plugin, psst, sigcli, zeroid) are pending matrix verification with their maintainers and not yet rendered above.
Vaults, proxies, identity layers, and credential gateways. Alphabetical. Entry name links to the upstream project; (details) opens our notes.
- 1Password CLI ·
op runsubstitutesop://secret references into a process environment at startup. Closed source, Go binary. (details) - agentgateway · Rust agentic proxy for AI agents and MCP servers with credential injection at the proxy layer. (details)
- AgentGuard · Runtime guardrail layer for agents: data loss path blocking, secret scrubbing, skill trust registry. (details)
- Arcade.dev · MCP server framework plus commercial OAuth-for-agents platform. Per-user OAuth tokens for many third-party APIs. (details)
- archestra · Enterprise AI platform with guardrails plus MCP registry, gateway, and orchestrator. (details)
- Authsome · Local OAuth2 and API-key vault. The agent never sees raw credentials. MIT, Python. (details)
- AWS Secrets Manager · IAM-scoped managed secret store with rotation. Proprietary. (details)
- AWS Secrets Manager Agent · Official AWS sidecar exposing Secrets Manager over loopback. Apache 2.0, Rust. (details)
- Bitwarden Agent Access · Open protocol for per-request human approval against a Bitwarden vault. Apache 2.0, Rust. (details)
- Botiverse agent-vault · Local proxy that keeps secrets out of chat-agent context. Apache 2.0, TypeScript. (details)
- Casdoor · Open-source agent-first IAM/LLM MCP gateway and auth server. OAuth/OIDC/SAML/SCIM for agents. (details)
- Composio · Toolkit platform with 1000+ integrations and managed OAuth for agent frameworks. Apache 2.0. (details)
- DeepSecure · Identity, credential, and access management for AI agents and MCP servers. (details)
- Docker MCP Gateway · Official Docker CLI plugin and gateway for MCP. Manages secret and env injection into MCP servers. (details)
- Doppler · CLI that injects a project's secrets into a wrapped process. Apache 2.0, Go. (details)
- earl · Rust CLI proxy with HCL operation templates, OS keychain secrets, MCP integration. (details)
- faramesh-core · Governance-as-Code library for agent credential brokering. (details)
- hasp · Local-first broker for managed secrets in agent workflows. Go. (details)
- HashiCorp Vault · General secrets platform with Vault Agent sidecars and an AI-agent-identity validated pattern. BUSL 1.1, Go. (details)
- Infisical Agent Vault · HTTPS proxy that swaps placeholder tokens for real credentials at the network layer. Source-available, Go. (details)
- jentic-mini · Self-hosted API execution layer that injects credentials between agent and external APIs. (details)
- Keeper Agent Kit · Skill bundle wrapping Keeper Secrets Manager for coding agents. Apache 2.0, Shell. (details)
- Kong AI Gateway · API gateway with LLM/MCP gateway features. Production-grade rate limiting, observability, auth plugins. Apache 2.0. (details)
- Kontext CLI · Wraps coding agents with RFC 8693 token-exchanged short-lived credentials. MIT, Go. (details)
- LiteLLM Agent Platform · Self-hosted platform running coding agents in isolated sandboxes with a vault proxy. MIT, TypeScript. (details)
- mcp-governance-sdk · Enterprise governance layer (identity, RBAC, credentials, audit) for the MCP SDK. (details)
- mcp-secrets-plugin · OS-keychain credential management for MCP servers. (details)
- metamcp · MCP aggregator, orchestrator, middleware, and gateway in one container. Handles per-server authentication. (details)
- Microsoft Agent Governance Toolkit · Policy enforcement, zero-trust identity, and sandboxing scaffolding for agent credential brokers. MIT. (details)
- Nango · OAuth-token broker positioned for agents and MCP. Handles auth lifecycle for hundreds of third-party APIs. (details)
- onecli · Single-binary credential gateway with a built-in vault for AI agents. Apache 2.0, TypeScript. (details)
- psst · AI-native secrets manager using the OS keychain and a token-substitution model. (details)
- Pulumi ESC · Environments, secrets, and configuration service that composes secrets from many backends. Apache 2.0, Go. (details)
- sigcli · Auth CLI and proxy for AI agents: "give agents access, not your credentials." (details)
- snyk agent-scan · Security scanner for AI agents, MCP servers, and agent skills. Detects credential disclosure surfaces. (details)
- SOPS · Encrypts files in place with KMS, age, or PGP. MPL 2.0, Go. (details)
- Wirken · Single-binary switchboard with encrypted vault, per-channel isolation, and hash-chained audit log. MIT, Rust. (details)
- zeroid · Autonomous Agent Identity Management System using RFC 8693 token exchange and SPIFFE. (details)
How each agent platform consumes credentials today. Alphabetical. Entry name links to the upstream project; (details) opens our notes.
- Aider ·
.envand.aider.conf.yml. Ad hoc, env vars only. (details) - AutoGen · Model client config plus tool env vars; conductor pattern inherits credentials across spawned agents. (details)
- browser-use · Top open-source browser agent framework. Ships
sensitive_dataprimitives and allowed-domain controls. (details) - Claude Code ·
settings.jsonenv, MCPenvper server, pre/post-tool-use hooks, skills. (details) - Cline · VS Code extension settings, MCP config, inherited env. No first-party broker. (details)
- Codex CLI ·
~/.codex/config.toml, per-providerenv_key, optional OS keyring. (details) - Continue.dev ·
config.yamlwith${{ secrets.NAME }}resolved from.env, workspace.env, or Mission Control hub. (details) - CrewAI · Tool constructors accept credentials at init time. Common pairing with Composio. (details)
- Crush · Charm's TUI coding agent (successor to opencode-ai/opencode). Provider config in
.crush.jsonplus env vars. (details) - Cursor ·
~/.cursor/mcp.jsonwith${env:VAR}interpolation. Remote-header interpolation broken. (details) - Goose ·
~/.config/goose/config.yamlplus per-extension env vars. (details) - LangChain ·
secret_from_envreturnsSecretStrfor log scrubbing. (details) - LangGraph ·
RunnableConfig["configurable"]plus theAuthhandler for per-request secret resolution. (details) - LlamaIndex · Data framework for LLM apps. Data loaders carry credentials; no built-in broker. Common pairing with Composio. (details)
- Mastra ·
mastra server env import(mode 0600); pluggable auth providers. (details) - OpenAI Agents SDK · Lazy-read
OPENAI_API_KEY,set_default_openai_key. Third-party tool creds are ad hoc. (details) - OpenCode · Terminal coding agent.
opencode auth login <provider>persists tokens; provider env vars at startup. (details) - OpenHands · Sandboxed container runtime; egress proxy is a natural injection point. (details)
- Plandex · Open-source terminal coding agent. Provider keys from env vars. Same credential model as Aider and Crush. (details)
- Pydantic AI · Provider env vars; Pydantic
SecretStrscrubs logs. (details) - Stagehand · Browser-agent SDK by Browserbase. Pairs naturally with Browserbase managed sessions. (details)
- Vercel AI SDK ·
process.envinsidetool({ execute }), Sensitive env vars, AI Gateway OIDC. (details) - Windsurf ·
mcp_config.jsonwith${env:VAR}interpolation acrosscommand/args/env/headers/url. (details)
Per-third-party-API credential recipes. Alphabetical. Entry name links to the canonical credential docs; (recipe) opens our agent-specific notes.
- Anthropic · Workspace-scoped keys, admin keys held separately. (recipe)
- Apollo · API keys per user. No per-resource scoping; treat as full-account. (recipe)
- Atlassian · OAuth 2.0 3LO for Jira and Confluence under user delegation. (recipe)
- Buffer · OAuth 2.0 with refresh tokens. Scopes per social channel. (recipe)
- Cal.com · OAuth client + managed-user access tokens (60m) and refresh (1y). (recipe)
- Calendly · OAuth 2.0 with scoped grants; PATs as a fallback. (recipe)
- Cloudflare · API tokens with permission group, resource, IP, and TTL filters. (recipe)
- Discord · Bot tokens (long-lived, coarse) vs OAuth 2.0 access tokens (scoped). (recipe)
- GitHub · GitHub App installation tokens (1h, repo-scoped). (recipe)
- GitLab · Personal/group/project access tokens with expiry and scope. OAuth for delegated actions. (recipe)
- Google Workspace · OAuth 2.0 with per-scope grants; service accounts with domain-wide delegation. (recipe)
- HubSpot · Private apps with minimum CRM scopes. (recipe)
- Intercom · OAuth for marketplace apps; long-lived access tokens for internal apps. (recipe)
- Klaviyo · OAuth for marketplace integrations, private API keys for first-party. (recipe)
- Linear · OAuth with actor authorization for revocable, attributed writes. (recipe)
- Mailchimp · API keys with data center prefix. No native scoping; rotate aggressively. (recipe)
- Mailgun · Domain sending keys bound to one verified domain. (recipe)
- Microsoft Graph · OAuth 2.0 with Entra ID. Application and delegated permissions. (recipe)
- Notion · Public OAuth integration with rotating refresh tokens. (recipe)
- OpenAI · Project-scoped service account keys with Restricted permissions. (recipe)
- Pinecone · Project-scoped API keys (granular roles require Standard+). (recipe)
- Plaid · Per-user Item access tokens; rotate via
/item/access_token/invalidate. (recipe) - Postmark · Server tokens scoped to one Postmark Server (sending domain). (recipe)
- Resend · Sending-access key bound to one verified domain. (recipe)
- Salesforce · JWT Bearer flow with per-agent certificate and minimum scopes. (recipe)
- SendGrid · Custom (Restricted) access key with only
mail.send. (recipe) - Shopify · Custom-app Admin API token, read-only where possible. (recipe)
- Slack · Bot tokens with granular scopes and 12h rotation. (recipe)
- Stripe · Restricted API keys (RAKs) with per-resource Read/Write. (recipe)
- Supabase · Secret key on the server, never the
service_roleJWT in agent reach. (recipe) - Twilio · Per-agent Subaccount + Restricted API key. (recipe)
- Typeform · OAuth 2.0 with explicit scopes for forms, results, accounts. (recipe)
- Vercel · Team-scoped PATs with explicit expiry. (recipe)
- X (Twitter) · OAuth 2.0 with PKCE. Per-scope grants for read/write/DM. (recipe)
- Zapier · OAuth flows for embedded integrations; team-scoped API keys for internal Zaps. (recipe)
Named recipes. Each cites the project that best implements it.
- Agents Rule of Two · Hold at most two of {untrusted input, sensitive data, state change}.
- Audit trails and SIEM integration · Per-agent identity, credential reference IDs (never values), pipe to SIEM.
- Confused deputy across subagents · Authenticate the requesting agent, do not implicitly trust the caller.
- Headless OAuth via device-code flow · RFC 8628 grant for agents on headless hosts (CI, SSH, cron).
- Hook-based injection · Resolve placeholders at the tool boundary, not in prompt context.
- Just-in-time credential injection · Credentials supplied at the moment of the call, valid for minutes.
- Lethal trifecta · Break at least one leg of {private data, untrusted input, outbound channel}.
- Multiple named connections per provider · Address accounts by name (work vs personal GitHub, dev vs prod Stripe).
- Non-Human Identity (RFC 8693, SPIFFE) · Treat the agent as a principal, not a key holder.
- Per-task credential scoping · One narrow credential per task; revoke on completion.
- Sandboxed egress for the agent process · Domain allowlist, JWT-authenticated proxy, network-level firewall.
- Scoped delegation tokens · Narrowest principal that works: GitHub App tokens, Stripe RAKs.
- Secret redaction in prompts and logs · Placeholders in prompts, sanitisers on stdout.
- Short-lived tokens with rotation · ~1h access tokens with rotated refresh tokens.
- Subagent credential non-inheritance · Spawned subagents start with the least privilege their role requires.
- Token substitution proxy · Agent operates on opaque placeholders end to end; substitution is symmetric.
- Browser-agent takeover · Agentic browser inheriting user sessions, password manager auto-unlock.
- Indirect injection through shared data · Untrusted instructions in shared documents, tickets, spreadsheets.
- Logging-pipeline secret leakage · Credentials echoed to stdout, structured logs, observability backends.
- Long-running agent rotation gaps · Multi-day agents outliving their tokens, 401s mid-task.
- Offline disk-image theft · Stolen laptops and unencrypted backups yield any unencrypted vault.
- Over-scoped write credential · One credential carrying delete on both production and backups.
- Process enumeration disclosure · Other processes reading agent env via
/proc/<pid>/environorps. - Prompt-injection credential disclosure · Untrusted text directing the agent to surface secrets via tool calls.
- Shared-session leakage · Multi-tenant agents bleeding secrets across users.
- Shell history exposure · Inline secrets typed at the shell land in
.bash_history/.zsh_history. - Skill and tool supply-chain · Third-party skills inheriting the agent's credential surface.
- Subagent credential inheritance · Spawned subagents inheriting more privilege than their role needs.
- Tool-use credential confusion · Agent invoking a tool with the wrong principal's credentials.
PRs welcome. Read CONTRIBUTING.md and CATEGORY-MAP.md first. Every entry follows the same frontmatter and word-count shape. Direct competitors of the maintainer get accepted on equal terms.
CC0 1.0 Universal. Public domain dedication.
Curated by Authsome · agent identity for third-party APIs. Authsome is one of the products listed above. See CATEGORY-MAP.md for how that is handled.
Footnotes
-
1Password Environments MCP server shipped a Codex-first integration in May 2026. ↩