You authenticate
Passwords, passkeys, CAPTCHA, MFA and hardware-key prompts stay human-controlled. API Vault never asks the AI to type your password.
Authorize ChatGPT, Claude and other capable agents to actually do things for you across the services you choose. API Vault brokers APIs, OAuth accounts and signed-in browser sessions while keeping passwords, provider keys and session credentials behind the vault boundary.
API Vault exposes a vendor-neutral MCP + OAuth surface. You decide which services and action classes each AI may exercise; underlying credentials remain inside API Vault.
https://api-vault-gpp.vercel.app/mcp
Run the API Vault browser worker on a computer you control. You sign in personally in a visible browser, then explicitly hand the authenticated session to an authorized AI.
Passwords, passkeys, CAPTCHA, MFA and hardware-key prompts stay human-controlled. API Vault never asks the AI to type your password.
Cookies, browser storage and the persistent Chromium profile remain on your worker machine rather than being exported to the AI.
Choose the AI, allowed sites, authority mode, uploads/downloads and whether financial, security, destructive or external-communication actions are permitted.
Put a profile back into human-login mode or revoke the browser session. New AI work is blocked until a signed-in profile is explicitly marked ready.
The AI receives revocable capabilities and authorized results, not the provider credentials that make those actions possible.
API keys and OAuth credentials remain server-side. Browser authentication material remains on the user-controlled worker.
Use granular, provider-wide or explicitly acknowledged owner-equivalent authority while retaining financial, security, destructive and communication switches.
Public connectors use PKCE, one-time authorization codes, short-lived child capabilities and rotating refresh tokens.
Connector identity, operation and result metadata can be audited without logging raw authorization headers or secret values. Authority can be revoked independently.
These checks read only non-secret OAuth and MCP discovery metadata.
Checking…
Checking…
API Vault intentionally exposes no tool for retrieving raw stored credentials.