For developers using AI agents

Your API key is everywhere.

Your OpenAI key is in Cursor, Claude, OpenClaw, all reading from .env. When it leaks, you need to rotate keys in every agent. creds gives each agent its own scoped access. Revoke any agent without breaking the others. Rotate your real keys in one place.

See the damage
app.creds.md/agents/openclaw
openclaw
cursor
copilot
claude
n8n
zapier
openclaw
active 3 scopes
Scopes
openai:POST:/v1/chat/completionscompletions
anthropic:POST:/v1/messagesmessages
github:GET:/repos/*repos:read
API calls (7d)

3 keys. 8 agents. Full access to everything.

Your OpenAI key can burn $1,000 in credits overnight. Your GitHub token can delete every repo you own. Your Stripe key can charge $50,000. You pasted these into agents you connected last week. When one leaks or just acts up, you're editing config files while your team waits.

You can't freeze just Cursor without also breaking Copilot, Replit, and every other agent sharing that same key. creds gives each agent its own access. Revoke one. Your real keys stay where they are.

bash -- ~/
$ grep -r "KEY\|TOKEN\|SECRET" ~/ --include="*.env" --include="*.json"
~/.cursor/settings.json:12:OPENAI_API_KEY=sk-proj-p7FmK2xN9bQ4wR8vL3jY6cT1h
~/.claude/.env:3:OPENAI_API_KEY=sk-proj-p7FmK2xN9bQ4wR8vL3jY6cT1h
~/n8n/.env:5:GITHUB_TOKEN=ghp_a8k2Mf9nB3qR7sL1wX6vJ4cZy
~/.copilot/config:2:GITHUB_TOKEN=ghp_a8k2Mf9nB3qR7sL1wX6vJ4cZy
~/.openclaw/.env:6:OPENAI_API_KEY=sk-proj-p7FmK2xN9bQ4wR8vL3jY6cT1h
~/n8n/.env:8:STRIPE_API_KEY=sk_live_4eC39HqLyjWDarjtT1zdp7dc
~/.zapier/credentials.json:4:STRIPE_API_KEY=sk_live_4eC39HqLyjWDarjtT1zdp7dc
3 keys shared across 8 agents

Each agent gets its own access

Give Cursor a creds key instead of your real OpenAI key. Point it at the proxy. The proxy injects the right credential on each request. Your real keys never leave your sight. If an agent acts up, revoke its access. The others are unaffected.


What you get

Isolation

Revoke one agent without affecting the others

When n8n acts up, freeze n8n. Cursor keeps coding. Copilot keeps accessing repos. You never shared your real keys with any of them.

Boundaries

Each agent does only what you allowed.

Cursor calls OpenAI. n8n hits Stripe. That's it. No agent does more than you permitted. Cursor can't accidentally charge your Stripe account.

Visibility

See every API call, per agent.

How many times did Cursor call OpenAI yesterday? Which repos did Copilot touch? Spot the workflow hitting Stripe 1,000 times an hour and freeze it from the dashboard.

Sanity

Rotate your real key without reconfiguring agents

Update your OpenAI key once in the creds dashboard. Every agent picks it up on its next request. No config changes needed.

Containment

Kernel-level sandboxing per agent

creds sandboxes each agent process at the kernel level. The agent reads and writes only in the project directory you gave it. It connects only to the proxy. It cannot touch your SSH keys, your .aws folder, or anything outside its workspace. Set hard limits on memory, CPU, file size, and wall-clock time. A runaway agent hits the cap and gets killed. A compromised agent has nowhere to send data and nothing to take.

Credential overlay

Your real keys never touch the agent's disk

creds mounts a FUSE overlay over the project directory. When the agent reads its .env file, it sees a scoped creds token, not your real key. creds never writes your real key to disk. The original files stay untouched. Unmount the overlay and the directory looks exactly as you left it.


Launch integrations

More coming.

OpenAI
Anthropic
Zapier
Make
n8n

$49 once. Less than one key leak.

Individual is a one-time purchase. No subscription. One incident costs more than a lifetime of creds.

Launch pricing
Individual
$49
One-time purchase. Locked in for early adopters.
  • Revoke any agent without breaking the rest
  • Each agent scoped to only what it needs
  • Rotate your real keys without touching agent configs
  • See every API call, per agent
  • Freeze any agent in one click
  • Kernel-level sandboxing with resource limits
  • FUSE credential overlay keeps real keys off disk
  • Dashboard and all providers
Team
$200/mo
Shared contexts, SSO, and longer retention for teams.
  • Everything in Individual
  • Shared credential contexts
  • SSO / SAML authentication
  • 12-month audit log retention
  • Custom integrations
  • Priority support
Enterprise
Custom
Self-hosted. Includes setup and ongoing support.
  • Everything in Team
  • Self-hosted deployment
  • Unlimited agents
  • Unlimited audit log retention

Frequently asked questions

creds is a self-hosted credential proxy for AI agents. Instead of pasting your real API keys into every agent, you give each agent a scoped token that points at the creds proxy. The proxy injects the right credential on each request. You can revoke any agent's access without affecting the others.
Secrets managers like Vault store secrets securely, but every agent still gets the same full-access key. creds sits between your agents and the APIs, giving each agent its own scoped token. Cursor gets openai-only access. n8n gets stripe+slack. Revoke any agent without rotating the underlying key. It runs on your machine. No infrastructure overhead.
Each agent gets a token that defines exactly which providers and endpoints it can reach. For example, a scope of openai:POST:/v1/chat/completions means that agent can only call that specific OpenAI endpoint. It cannot access embeddings, files, or any other provider.
No. creds sandboxes each agent at the kernel level. The agent reads and writes only in the project directory you gave it. It connects only to the proxy. It cannot touch your SSH keys, your .aws folder, or anything outside its workspace. A compromised agent has nowhere to send data and nothing to take.
Freeze the agent in one click from the creds dashboard. Its scoped token is invalidated. Other agents are unaffected. You can see exactly how many API calls each agent has made in the audit logs to spot abuse before it becomes expensive.
creds is self-hosted. It runs on your machine. Your real API keys never leave your infrastructure. The proxy intercepts requests locally and injects credentials before forwarding them to the API provider.
Yes. Update your real key once in the creds dashboard. Every agent picks up the new key automatically on its next request. No config file changes, no downtime, no agents left broken while you track down every .env file.
creds works with any agent that reads API keys from environment variables or config files: Cursor, Claude, Copilot, n8n, Zapier, Make, custom scripts, and more. On the provider side, it supports OpenAI, Anthropic, GitHub, Stripe, Slack, and any HTTP-based API.
Individual is $49 one-time with no subscription. Early adopter pricing is locked in. If you need team features like shared contexts or SSO, contact us for a team trial.