What API Vault handles
API Vault stores or brokers credentials and delegated authorization only for services the user explicitly connects. Connector-facing access is represented by revocable capabilities rather than raw provider credentials.
API Vault stores or brokers credentials and delegated authorization only for services the user explicitly connects. Connector-facing access is represented by revocable capabilities rather than raw provider credentials.
AI clients may receive connection metadata, authorized tool results, usage metadata and action results. API Vault does not expose a tool that returns stored API keys, OAuth refresh credentials, passwords, browser cookies or session storage.
Authorization codes are short lived. Connector access tokens are short-lived child capabilities. Refresh tokens are rotatable and revocable. API Vault records the minimum metadata required to authorize, audit and revoke connector access.
Operational audit data may include timestamp, connector identity, requested capability, outcome, risk classification and correlation identifiers. Raw authorization headers and plaintext secrets are not intended audit fields.
Users can revoke gateway identities, connector capabilities, provider grants and connected accounts. Revoking the parent authority invalidates dependent access according to API Vault policy.
When a user authorizes an action, data needed for that action can be sent to the selected provider. Those providers process data under their own terms and privacy policies.
This page describes the connector privacy model for API Vault. Product-specific legal notices and store disclosures may supplement it.