Your API key is everywhere.
Your OpenAI key is in Cursor, Claude, OpenClaw, all reading from .env. When it leaks, you need to rotate keys in every agent. creds gives each agent its own scoped access. Revoke any agent without breaking the others. Rotate your real keys in one place.
3 keys. 8 agents. Full access to everything.
Your OpenAI key can burn $1,000 in credits overnight. Your GitHub token can delete every repo you own. Your Stripe key can charge $50,000. You pasted these into agents you connected last week. When one leaks or just acts up, you're editing config files while your team waits.
You can't freeze just Cursor without also breaking Copilot, Replit, and every other agent sharing that same key. creds gives each agent its own access. Revoke one. Your real keys stay where they are.
$ grep -r "KEY\|TOKEN\|SECRET" ~/ --include="*.env" --include="*.json" ~/.cursor/settings.json:12:OPENAI_API_KEY=sk-proj-p7FmK2xN9bQ4wR8vL3jY6cT1h ~/.claude/.env:3:OPENAI_API_KEY=sk-proj-p7FmK2xN9bQ4wR8vL3jY6cT1h ~/n8n/.env:5:GITHUB_TOKEN=ghp_a8k2Mf9nB3qR7sL1wX6vJ4cZy ~/.copilot/config:2:GITHUB_TOKEN=ghp_a8k2Mf9nB3qR7sL1wX6vJ4cZy ~/.openclaw/.env:6:OPENAI_API_KEY=sk-proj-p7FmK2xN9bQ4wR8vL3jY6cT1h ~/n8n/.env:8:STRIPE_API_KEY=sk_live_4eC39HqLyjWDarjtT1zdp7dc ~/.zapier/credentials.json:4:STRIPE_API_KEY=sk_live_4eC39HqLyjWDarjtT1zdp7dc 3 keys shared across 8 agents
Each agent gets its own access
Give Cursor a creds key instead of your real OpenAI key. Point it at the proxy. The proxy injects the right credential on each request. Your real keys never leave your sight. If an agent acts up, revoke its access. The others are unaffected.
What you get
Revoke one agent without affecting the others
When n8n acts up, freeze n8n. Cursor keeps coding. Copilot keeps accessing repos. You never shared your real keys with any of them.
Each agent does only what you allowed.
Cursor calls OpenAI. n8n hits Stripe. That's it. No agent does more than you permitted. Cursor can't accidentally charge your Stripe account.
See every API call, per agent.
How many times did Cursor call OpenAI yesterday? Which repos did Copilot touch? Spot the workflow hitting Stripe 1,000 times an hour and freeze it from the dashboard.
Rotate your real key without reconfiguring agents
Update your OpenAI key once in the creds dashboard. Every agent picks it up on its next request. No config changes needed.
Kernel-level sandboxing per agent
creds sandboxes each agent process at the kernel level. The agent reads and writes only in the project directory you gave it. It connects only to the proxy. It cannot touch your SSH keys, your .aws folder, or anything outside its workspace. Set hard limits on memory, CPU, file size, and wall-clock time. A runaway agent hits the cap and gets killed. A compromised agent has nowhere to send data and nothing to take.
Your real keys never touch the agent's disk
creds mounts a FUSE overlay over the project directory. When the agent reads its .env file, it sees a scoped creds token, not your real key. creds never writes your real key to disk. The original files stay untouched. Unmount the overlay and the directory looks exactly as you left it.
Launch integrations
More coming.
$49 once. Less than one key leak.
Individual is a one-time purchase. No subscription. One incident costs more than a lifetime of creds.
- Revoke any agent without breaking the rest
- Each agent scoped to only what it needs
- Rotate your real keys without touching agent configs
- See every API call, per agent
- Freeze any agent in one click
- Kernel-level sandboxing with resource limits
- FUSE credential overlay keeps real keys off disk
- Dashboard and all providers
- Everything in Individual
- Shared credential contexts
- SSO / SAML authentication
- 12-month audit log retention
- Custom integrations
- Priority support
- Everything in Team
- Self-hosted deployment
- Unlimited agents
- Unlimited audit log retention
Frequently asked questions
openai:POST:/v1/chat/completions means that agent can only call that specific OpenAI endpoint. It cannot access embeddings, files, or any other provider.