Privacy

Credential privacy is the boundary.

What API Vault handles

API Vault stores or brokers credentials and delegated authorization only for services the user explicitly connects. Connector-facing access is represented by revocable capabilities rather than raw provider credentials.

What AI clients receive

AI clients may receive connection metadata, authorized tool results, usage metadata and action results. API Vault does not expose a tool that returns stored API keys, OAuth refresh credentials, passwords, browser cookies or session storage.

OAuth and connector records

Authorization codes are short lived. Connector access tokens are short-lived child capabilities. Refresh tokens are rotatable and revocable. API Vault records the minimum metadata required to authorize, audit and revoke connector access.

Auditing

Operational audit data may include timestamp, connector identity, requested capability, outcome, risk classification and correlation identifiers. Raw authorization headers and plaintext secrets are not intended audit fields.

Revocation

Users can revoke gateway identities, connector capabilities, provider grants and connected accounts. Revoking the parent authority invalidates dependent access according to API Vault policy.

Third parties

When a user authorizes an action, data needed for that action can be sent to the selected provider. Those providers process data under their own terms and privacy policies.

This page describes the connector privacy model for API Vault. Product-specific legal notices and store disclosures may supplement it.