Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
59 commits
Select commit Hold shift + click to select a range
d03c1e3
feat: add agent delete, revoke, and token rotation to UI (#257)
saifsmailbox98 Jun 13, 2026
543bb06
feat(web): move vault settings editing into a side drawer (#259)
dangtony98 Jun 13, 2026
5e340cd
feat: switch a vault's credential store in place (#260)
dangtony98 Jun 13, 2026
f269ab2
deps: bump github.com/infisical/go-sdk from 0.7.1 to 0.8.0 (#243)
dependabot[bot] Jun 13, 2026
f28b88d
deps: bump @tanstack/react-router from 1.170.8 to 1.170.10 in /web (#…
dependabot[bot] Jun 13, 2026
feb6b5c
deps: bump node from `7c6af15` to `144769e` (#241)
dependabot[bot] Jun 13, 2026
0d5f068
deps: bump node from `e89172f` to `79723b4` in /internal/isolation/as…
dependabot[bot] Jun 13, 2026
ae07bba
ci: bump docker/setup-qemu-action from 4.0.0 to 4.1.0 (#242)
dependabot[bot] Jun 13, 2026
bca1e6a
deps: bump modernc.org/sqlite from 1.50.1 to 1.52.0 (#245)
dependabot[bot] Jun 13, 2026
d96286c
deps: bump vite from 8.0.15 to 8.0.16 in /web (#247)
dependabot[bot] Jun 13, 2026
39ccfdf
deps: bump react and @types/react in /web (#246)
dependabot[bot] Jun 13, 2026
54c529d
deps: bump golang from 1.26.3-alpine to 1.26.4-alpine (#240)
dependabot[bot] Jun 13, 2026
e159203
deps: bump react-dom from 19.2.6 to 19.2.7 in /web (#244)
dependabot[bot] Jun 13, 2026
6dc2b79
feat(infisical): support dynamic secrets as leased credentials (#268)
dangtony98 Jun 14, 2026
ed9840c
docs(readme): tighten Pluggable Credential Stores blurb
dangtony98 Jun 14, 2026
79c7df9
ci: bump actions/checkout from 6.0.2 to 6.0.3 (#262)
dependabot[bot] Jun 14, 2026
f5540d3
deps: bump node from `144769e` to `3ad34ca` (#264)
dependabot[bot] Jun 14, 2026
8f0d57f
deps: bump @tanstack/react-router from 1.170.10 to 1.170.15 in /web (…
dependabot[bot] Jun 14, 2026
a842f9d
deps: bump github.com/jedib0t/go-pretty/v6 from 6.7.10 to 6.8.0 (#266)
dependabot[bot] Jun 14, 2026
f38292b
deps: bump alpine from 3.23.4 to 3.24.0 (#263)
dependabot[bot] Jun 14, 2026
972d435
deps: bump node from `79723b4` to `3fe807a` in /internal/isolation/as…
dependabot[bot] Jun 14, 2026
735d53f
deps: bump golang.org/x/sync from 0.20.0 to 0.21.0 (#267)
dependabot[bot] Jun 14, 2026
30ff25c
fix(broker): resolve dynamic secrets through the MITM proxy (#269)
dangtony98 Jun 14, 2026
c17d1a1
feat: add anonymous usage telemetry (#270)
saifsmailbox98 Jun 16, 2026
1e147e4
docs: add enterprise demo banners to key documentation pages (#271)
devin-ai-integration[bot] Jun 16, 2026
1a44036
fix: include substitution keys in credential-usage checks (#272)
saifsmailbox98 Jun 16, 2026
cedd958
docs(slack-template): add slack agent template example (#275)
jakehulberg Jun 19, 2026
26b68d5
feat: add PostgreSQL database support for production deployments (#273)
saifsmailbox98 Jun 19, 2026
102206d
feat: add database_backend to server-start telemetry (#276)
saifsmailbox98 Jun 19, 2026
99d7129
docs: move password rotation steps to CLI reference (#277)
saifsmailbox98 Jun 19, 2026
f07170a
docs: add enterprise CTA banners to PostgreSQL self-hosting page (#288)
devin-ai-integration[bot] Jun 21, 2026
3e4f57d
feat: allow users to remove themselves from a vault (#290)
saifsmailbox98 Jun 22, 2026
fc0443d
feat: resolve actor names in request log details (#292)
devin-ai-integration[bot] Jun 23, 2026
750ef0c
feat: HashiCorp Vault as a read-only external credential store
preetbhinder Jun 13, 2026
3bd0c1e
feat: add Pi, Devin, Windsurf, Cline, and Roo Code to knownAgents (#295)
devin-ai-integration[bot] Jun 24, 2026
6dd9247
Merge branch 'main' into hashicorp-pr
preetbhinder Jun 25, 2026
0df6d5d
docs(youtubevideo): adding agent vault general YT video to docs (#297)
jakehulberg Jun 26, 2026
46dfbd2
Merge branch 'main' into hashicorp-pr
preetbhinder Jun 26, 2026
1b39a14
deps: bump github.com/posthog/posthog-go from 1.15.0 to 1.16.1 (#301)
dependabot[bot] Jul 19, 2026
32735cd
deps: bump gorm.io/gorm from 1.31.1 to 1.31.2 (#302)
dependabot[bot] Jul 19, 2026
8257636
ci: bump actions/attest-build-provenance from 4.1.0 to 4.1.1 (#307)
dependabot[bot] Jul 19, 2026
43465fd
deps: bump golang from 1.26.4-alpine to 1.26.5-alpine (#325)
dependabot[bot] Jul 19, 2026
9e3a52a
deps: bump node from `3ad34ca` to `e88a35b` (#280)
dependabot[bot] Jul 19, 2026
479a77b
deps: bump golang.org/x/crypto from 0.52.0 to 0.54.0 (#282)
dependabot[bot] Jul 19, 2026
da76ad4
deps: bump alpine from 3.24.0 to 3.24.1 (#283)
dependabot[bot] Jul 19, 2026
47f95fd
deps: bump github.com/jedib0t/go-pretty/v6 from 6.8.0 to 6.8.2 (#286)
dependabot[bot] Jul 19, 2026
48be6f8
deps: bump @vitejs/plugin-react from 6.0.2 to 6.0.3 in /web (#314)
dependabot[bot] Jul 20, 2026
d95712e
deps: bump @tanstack/react-router from 1.170.15 to 1.170.16 in /web (…
dependabot[bot] Jul 20, 2026
715feb4
deps: bump vite from 8.0.16 to 8.1.0 in /web (#311)
dependabot[bot] Jul 20, 2026
bbb441d
deps: bump @tailwindcss/vite from 4.3.0 to 4.3.2 in /web (#309)
dependabot[bot] Jul 20, 2026
008fea6
ci: bump goreleaser/goreleaser-action from 7.2.2 to 7.2.3 (#312)
dependabot[bot] Jul 20, 2026
c1bd9a4
ci: bump docker/setup-qemu-action from 4.1.0 to 4.2.0 (#318)
dependabot[bot] Jul 20, 2026
8ba2789
ci: bump actions/setup-go from 6.4.0 to 6.5.0 (#308)
dependabot[bot] Jul 20, 2026
8e4325f
Merge branch 'main' into hashicorp-pr
preetbhinder Jul 22, 2026
b6faa37
docs: point to Infisical Agent Proxy from readme and docs (#355)
saifsmailbox98 Jul 30, 2026
f9ecddf
Merge branch 'main' into hashicorp-pr
preetbhinder Jul 31, 2026
795e19a
Fix punctuation in master password documentation (#357)
saifsmailbox98 Jul 31, 2026
1074383
feat(catalog): add 13 service templates and fix four incorrect ones (…
saifsmailbox98 Aug 3, 2026
0dc9cc7
Merge branch 'main' into hashicorp-pr
preetbhinder Aug 6, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
32 changes: 32 additions & 0 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,16 @@
# Server listen port (respected by PaaS platforms like Fly.io, Cloud Run, Heroku)
# PORT=14321

# PostgreSQL connection URL for production deployments. When set, Agent Vault
# uses Postgres instead of the built-in SQLite database. All instances must
# share the same DATABASE_URL. Supports sslmode parameter (e.g. ?sslmode=require).
# DATABASE_URL=postgres://user:password@host:5432/agentvault

# Postgres connection pool tuning (only used when DATABASE_URL is set)
# DB_MAX_OPEN_CONNS=25 # max open connections per instance
# DB_MAX_IDLE_CONNS=10 # max idle connections in the pool
# DB_CONN_MAX_LIFETIME=5m # max lifetime before a connection is recycled (Go duration)

# Master password — derives a KEK that wraps the data encryption key (DEK).
# If omitted, the DEK is stored unwrapped (passwordless mode).
# AGENT_VAULT_MASTER_PASSWORD=
Expand Down Expand Up @@ -69,6 +79,22 @@
# INFISICAL_LDAP_AUTH_USERNAME=
# INFISICAL_LDAP_AUTH_PASSWORD=

# HashiCorp Vault credential store (optional). Enables read-only vaults whose
# credentials are pulled from a HashiCorp Vault KV mount instead of stored
# locally. VAULT_ADDR enables the feature; set one auth-method group (AppRole
# wins over Token when both are present). VAULT_CACERT, VAULT_SKIP_VERIFY, and
# VAULT_NAMESPACE are read from the standard Vault environment too.
# VAULT_ADDR=http://127.0.0.1:8200
# Token Auth:
# VAULT_TOKEN=
# AppRole Auth (both required):
# VAULT_ROLE_ID=
# VAULT_SECRET_ID=
# VAULT_APPROLE_MOUNT=approle # override if AppRole is mounted at a non-default path
# VAULT_NAMESPACE=
# Note: the AppRole-issued token is not auto-renewed; on expiry, syncs fail
# (last_sync_status=error) until the server restarts and re-authenticates.

# MITM proxy body-size limits (optional)
# AGENT_VAULT_MAX_RESPONSE_BYTES=0 # max response body bytes streamed to agents (default 0 = unlimited)
# AGENT_VAULT_MAX_REQUEST_BYTES=1073741824 # max request body bytes forwarded to upstreams (default 1073741824 = 1 GiB)
Expand All @@ -92,6 +118,12 @@
# and KNOB ∈ RATE | BURST | WINDOW | MAX | CONCURRENCY. Example:
# AGENT_VAULT_RATELIMIT_PROXY_BURST=50

# Telemetry (optional)
# Agent Vault reports anonymous usage events (command invocations, feature usage)
# to PostHog. No credential values or request payloads are ever included.
# Set to "false" to disable. Also overridable with --telemetry=false on the CLI.
# AGENT_VAULT_TELEMETRY=true

# Installer (install.sh only — not read by the server or CLI binary).
# Set to any non-empty value to disable the anonymous install/upgrade beacon.
# Must be passed to `sh`, not `curl`:
Expand Down
18 changes: 9 additions & 9 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@ jobs:
sdk_ts: ${{ steps.filter.outputs.sdk_ts }}
steps:
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false

Expand Down Expand Up @@ -58,7 +58,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false

Expand All @@ -80,12 +80,12 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false

- name: Set up Go
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
with:
go-version-file: go.mod

Expand All @@ -104,12 +104,12 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false

- name: Set up Go
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
with:
go-version-file: go.mod

Expand All @@ -131,12 +131,12 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false

- name: Set up Go
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
with:
go-version-file: go.mod

Expand All @@ -152,7 +152,7 @@ jobs:
working-directory: sdks/sdk-typescript
steps:
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/release-node-sdk.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ jobs:
runs-on: ubuntu-22.04
steps:
- name: Checkout repo
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false

Expand Down
11 changes: 6 additions & 5 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,13 +19,13 @@ jobs:
# Pin all actions to full commit SHAs to prevent supply-chain attacks.

- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
fetch-depth: 0 # GoReleaser needs full history for changelog
persist-credentials: false

- name: Set up Go
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
with:
go-version-file: go.mod

Expand All @@ -35,7 +35,7 @@ jobs:
node-version: 22

- name: Set up QEMU
uses: docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a # v4.0.0
uses: docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v4.2.0

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4.1.0
Expand All @@ -53,16 +53,17 @@ jobs:
uses: anchore/sbom-action/download-syft@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0

- name: Run GoReleaser
uses: goreleaser/goreleaser-action@5daf1e915a5f0af01ddbcd89a43b8061ff4f1a89 # v7.2.2
uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7.2.3
with:
version: "~> v2"
args: release --clean
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
HOMEBREW_TAP_TOKEN: ${{ secrets.GO_RELEASER_GITHUB_TOKEN }}
POSTHOG_API_KEY: ${{ secrets.POSTHOG_API_KEY }}

- name: Generate build provenance attestations
uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0
uses: actions/attest-build-provenance@0f67c3f4856b2e3261c31976d6725780e5e4c373 # v4.1.1
with:
subject-path: |
dist/*.tar.gz
Expand Down
1 change: 1 addition & 0 deletions .goreleaser.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@ builds:
- -X github.com/Infisical/agent-vault/cmd.version={{.Version}}
- -X github.com/Infisical/agent-vault/cmd.commit={{.ShortCommit}}
- -X github.com/Infisical/agent-vault/cmd.date={{.Date}}
- -X github.com/Infisical/agent-vault/cmd.posthogAPIKey={{ .Env.POSTHOG_API_KEY }}
goos:
- linux
- darwin
Expand Down
1 change: 1 addition & 0 deletions CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,7 @@ make docker # Multi-stage Docker image; data persisted at /data/.agent-vau
- Vault role: `proxy` < `member` < `admin`. Proxy can use the proxy and raise proposals; member can manage credentials/services; admin can invite humans.
- **KEK/DEK key wrapping**: A random DEK (Data Encryption Key) encrypts credentials and the CA key at rest (AES-256-GCM). If a master password is set, Argon2id derives a KEK (Key Encryption Key) that wraps the DEK; changing the password re-wraps the DEK without re-encrypting credentials. If no password is set (passwordless mode), the DEK is stored in plaintext — suitable for PaaS deploys where volume security is the trust boundary. Login uses email+password. The first user to register becomes the instance owner and is auto-granted vault admin on `default`.
- **Agent skill is the agent-facing contract.** [cmd/skill_cli.md](cmd/skill_cli.md) is embedded into the binary, installed by `vault run`, and served publicly at `/v1/skills/cli`. It teaches agents how to create proposals when API access is needed.
- **Dual database backend (SQLite / Postgres)**: By default, all state lives in a single SQLite file (`~/.agent-vault/agent-vault.db` or `/data/.agent-vault/agent-vault.db` in Docker). Setting `DATABASE_URL` (or `--database-url`) switches the backend to PostgreSQL for production deployments or running multiple instances. The `store.Dialect` interface abstracts SQL differences; SQLite and Postgres implementations live in `internal/store/`. Schema migrations are Go files in `internal/store/` (e.g. `001_init.go`, `20260617143022_postgres_baseline.go`) that self-register via `init()` and `RegisterGORMMigration`. Each migration contains both dialect blocks in one file. The CA private key is stored in the database (not on disk) in Postgres mode so all instances share it. `agent-vault migrate-db` copies data from SQLite to Postgres for existing deployments. `master-password` CLI commands are blocked when `DATABASE_URL` is set (use `--force` after stopping all instances).
- **Two isolation modes for `vault run`** (selected via `--isolation` or `AGENT_VAULT_ISOLATION`): `host` (default, cooperative — fork+exec on the host with `HTTPS_PROXY`/`HTTP_PROXY` envvars) and `container` (non-cooperative — Docker container with iptables egress locked to the Agent Vault proxy). Container mode lives in [internal/isolation/](internal/isolation/) with an embedded Dockerfile + init-firewall.sh + entrypoint.sh, built on first use and cached by content hash.

## Where to look for details
Expand Down
10 changes: 6 additions & 4 deletions Dockerfile
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# ---- Frontend build ----
FROM node:26-alpine@sha256:7c6af15abe4e3de859690e7db171d0d711bf37d27528eddfe625b2fe89e097f8 AS frontend
FROM node:26-alpine@sha256:e88a35be04478413b7c71c455cd9865de9b9360e1f43456be5951032d7ac1a66 AS frontend

WORKDIR /app
COPY web/package.json web/package-lock.json ./
Expand All @@ -8,11 +8,12 @@ COPY web/ .
RUN npm run build

# ---- Go build stage ----
FROM golang:1.26.3-alpine@sha256:91eda9776261207ea25fd06b5b7fed8d397dd2c0a283e77f2ab6e91bfa71079d AS builder
FROM golang:1.26.5-alpine@sha256:0178a641fbb4858c5f1b48e34bdaabe0350a330a1b1149aabd498d0699ff5fb2 AS builder

ARG VERSION=dev
ARG COMMIT=unknown
ARG BUILD_DATE=unknown
ARG POSTHOG_API_KEY=

WORKDIR /src
COPY go.mod go.sum ./
Expand All @@ -22,11 +23,12 @@ COPY --from=frontend /internal/server/webdist /src/internal/server/webdist
RUN CGO_ENABLED=0 go build -trimpath -ldflags="-s -w \
-X github.com/Infisical/agent-vault/cmd.version=${VERSION} \
-X github.com/Infisical/agent-vault/cmd.commit=${COMMIT} \
-X github.com/Infisical/agent-vault/cmd.date=${BUILD_DATE}" \
-X github.com/Infisical/agent-vault/cmd.date=${BUILD_DATE} \
-X github.com/Infisical/agent-vault/cmd.posthogAPIKey=${POSTHOG_API_KEY}" \
-o /agent-vault .

# ---- Runtime stage ----
FROM alpine:3.23.4@sha256:5b10f432ef3da1b8d4c7eb6c487f2f5a8f096bc91145e68878dd4a5019afde11
FROM alpine:3.24.1@sha256:28bd5fe8b56d1bd048e5babf5b10710ebe0bae67db86916198a6eec434943f8b

RUN apk add --no-cache ca-certificates \
&& addgroup -S agentvault && adduser -S -G agentvault -u 65532 agentvault \
Expand Down
2 changes: 1 addition & 1 deletion Dockerfile.goreleaser
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# Minimal runtime image for GoReleaser — the binary is pre-built.
FROM alpine:3.23.4@sha256:5b10f432ef3da1b8d4c7eb6c487f2f5a8f096bc91145e68878dd4a5019afde11
FROM alpine:3.24.1@sha256:28bd5fe8b56d1bd048e5babf5b10710ebe0bae67db86916198a6eec434943f8b

RUN apk add --no-cache ca-certificates \
&& addgroup -S agentvault && adduser -S -G agentvault -u 65532 agentvault \
Expand Down
3 changes: 2 additions & 1 deletion Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,8 @@ DATE := $(shell date -u +%Y-%m-%dT%H:%M:%SZ)
LDFLAGS := -s -w \
-X github.com/Infisical/agent-vault/cmd.version=$(VERSION) \
-X github.com/Infisical/agent-vault/cmd.commit=$(COMMIT) \
-X github.com/Infisical/agent-vault/cmd.date=$(DATE)
-X github.com/Infisical/agent-vault/cmd.date=$(DATE) \
-X github.com/Infisical/agent-vault/cmd.posthogAPIKey=$(POSTHOG_API_KEY)

.PHONY: build dev test lint coverage test-all clean docker web web-dev sdk-ts sdk-ts-test

Expand Down
27 changes: 21 additions & 6 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ Agents should not possess credentials. Agent Vault eliminates credential exfiltr
</p>

<p align="center">
<a href="https://docs.agent-vault.dev">Documentation</a> | <a href="https://docs.agent-vault.dev/installation">Installation</a> | <a href="https://docs.agent-vault.dev/tutorial">Tutorial</a> | <a href="https://youtu.be/6dERVjLk0-Q">Video Demo</a> | <a href="https://infisical.com/slack">Slack</a>
<a href="https://docs.agent-vault.dev">Documentation</a> | <a href="https://docs.agent-vault.dev/installation">Installation</a> | <a href="https://docs.agent-vault.dev/tutorial">Tutorial</a> | <a href="https://youtu.be/AkyMmDSX8b4">Video Demo</a> | <a href="https://infisical.com/slack">Slack</a>
</p>

<p align="center">
Expand All @@ -30,7 +30,7 @@ Agent Vault was created to solve credential exfiltration for all AI agents. Inst
Features:

- **Credential Brokering**: Broker AI agents access target services like LLM providers and GitHub without them holding any real credentials. Agent Vault is able to broker that access by substituting dummy values in headers like `__anthropic_api_key__` with real credentials or replacing auth headers entirely on outbound requests through it.
- **Pluggable Credential Stores**: Back a vault with an external system like [Infisical](https://infisical.com) instead of the local encrypted store. Set `INFISICAL_URL` and create vaults with `--credential-store=infisical`. See [docs/learn/credential-stores](docs/learn/credential-stores.mdx).
- **[Pluggable Credential Stores](docs/learn/credential-stores.mdx)**: Back a vault with an external secrets store like [Infisical](https://infisical.com) or [HashiCorp Vault](https://developer.hashicorp.com/vault) instead of the local encrypted store. Set `INFISICAL_URL` and create vaults with `--credential-store=infisical` (which extends Agent Vault with features like [dynamic secrets](https://infisical.com/docs/documentation/platform/dynamic-secrets/overview) from Infisical), or set `VAULT_ADDR` and use `--credential-store=hashicorp`.
- **Transparent Integration**: Let AI agents use existing tools like MCP, CLI, SDK, API with all underlying requests automatically routed through Agent Vault. Agent Vault takes an interface-agnostic, non-invasive approach to credential brokering by bootstrapping your agents' environment to use `HTTPS_PROXY` and be compatible with Agent Vault's MITM architecture.
- **Purpose-Built Design**: Existing forward proxies like `mitmproxy` or `squid` require modification to perform credential brokering and integrate well with agents. Agent Vault is purpose-built to work with the ergonomics of all types of agent use-cases with a dedicated CLI, multi-tenancy, and agent-specific roadmap backed by [Infisical](https://github.com/Infisical/infisical).
- **Egress Filtering**: Control which agents should have access to which services and API endpoints on them since authenticated requests flow through Agent Vault.
Expand All @@ -40,6 +40,15 @@ By default, requests not matching any service forward as plain proxy traffic; fl

Read the full backstory behind Agent Vault [here](https://infisical.com/blog/agent-vault-the-open-source-credential-proxy-and-vault-for-agents).

## Agent Vault and Infisical Agent Proxy

[Infisical](https://infisical.com) offers two ways to broker credentials to agents.

- **Agent Vault** is the simpler, self-contained option: a single open-source binary that stores credentials itself and runs entirely on infrastructure you control, with no dependency on any other system.
- **[Infisical Agent Proxy](https://infisical.com/blog/agent-proxy)** is the commercial-grade option, built directly into Infisical. Your secrets, the services they are brokered to, and access control all live in one place, and it comes with everything Infisical supports around secrets management, including dynamic secrets, secret rotation, versioning, and more.

For production and enterprise use cases we recommend Agent Proxy. It is part of Infisical Secrets Management and available on every plan, including the free one.

## Use Cases

Agent Vault works with all kinds of AI Agent use-cases including secure remote coding agents, all-purpose agents, custom agents + harnesses, secure ephemeral sandboxes and more.
Expand Down Expand Up @@ -160,15 +169,15 @@ There are many ways to deploy Agent Vault and integrate your AI agents with it.

## See it in Action

A full end-to-end walkthrough: running Hermes Agent on a remote VPS while Agent Vault brokers every outbound API call from a second box. Real credentials never touch the agent host.
Watch how Agent Vault brokers credentials for AI agents: store your keys once, route every outbound request through the proxy, and let agents call real APIs without ever seeing a secret.

<p align="center">
<a href="https://youtu.be/6dERVjLk0-Q">
<img src="assets/hermes-vps-video-thumbnail.png" alt="Watch: Run Hermes on a VPS without leaking your API keys" />
<a href="https://youtu.be/AkyMmDSX8b4">
<img src="assets/agent-vault-video-thumbnail.png" alt="Watch: agents shouldn't see your secrets" />
</a>
</p>

Step-by-step companion guide: [Run Hermes on a VPS](https://docs.agent-vault.dev/guides/hermes-on-vps).
Want a full deployment walkthrough? See [Run Hermes on a VPS](https://docs.agent-vault.dev/guides/hermes-on-vps) for an end-to-end example with a brokered agent on a separate box.

## Best Practices

Expand All @@ -181,6 +190,12 @@ Step-by-step companion guide: [Run Hermes on a VPS](https://docs.agent-vault.dev

3. Tokens: You should create an [agent](https://docs.agent-vault.dev/agents/overview) in Agent Vault to represent a long-lived agent. For ephemeral sandboxes, you may prefer to mint short-lived, vault-scoped tokens for sandboxed agents to use to proxy requests through Agent Vault.

## PostgreSQL (Production)

By default Agent Vault stores all state in a local SQLite database, which requires no setup. For production deployments, or when running multiple instances, set the `DATABASE_URL` environment variable (or `--database-url` flag) to a PostgreSQL connection string and Agent Vault switches to Postgres as its backend. All instances share the same database, so state is consistent across replicas.

Migrate existing data with `agent-vault migrate-db --to postgres://...` before switching. See the [PostgreSQL guide](https://docs.agent-vault.dev/self-hosting/postgres) for deployment examples (Kubernetes, Docker Compose), architecture notes, and operational details.

## SDK

Agent Vault offers a TypeScript SDK in the event you'd like an orchestrator to mint a short-lived token and pass proxy config into a sandboxed agent to have it proxy requests through Agent Vault that way.
Expand Down
Binary file added assets/agent-vault-video-thumbnail.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading