Your AI asks for access
The AI keeps working normally. If a service needs browser access, API Vault creates a site-bounded protected session instead of asking you to configure workers, profiles or browser machinery.
API Vault lets ChatGPT, Claude and other capable AI clients act across the services you choose without giving them your passwords, provider tokens, API keys or signed-in browser sessions. Connect once, assign abilities, revoke anytime. The web app works on its own; Android adds a hardware-backed local vault companion.
Choose a service and sign in normally. API Vault keeps the authorization behind its security boundary, then you choose which AI may use it and what that AI is allowed to do. Technical connector details stay under Advanced.
https://vault.goldenphysics.org/mcp
API Vault can fall back to a protected managed browser automatically. You stay in your AI app; the browser appears only when you need to sign in, approve something, watch it, or take control.
The AI keeps working normally. If a service needs browser access, API Vault creates a site-bounded protected session instead of asking you to configure workers, profiles or browser machinery.
A secure login view appears only when necessary. Enter passwords, use Google or GitHub sign-in, passkeys, CAPTCHA, MFA or hardware keys directly on the real service. The AI never receives those secrets.
After sign-in, API Vault preserves the protected authenticated session and returns you to ChatGPT, Claude or your other AI. The agent can continue without you watching the browser.
Open Live View whenever you want, take control for a human-only step, lock the session, or revoke it. A private/local browser worker remains available under Advanced for users who want execution on their own hardware.
The AI receives revocable authority to perform approved operations, not the provider credentials or authenticated session material that make those operations possible.
API keys and OAuth credentials remain server-side. Managed browser state is isolated and protected; private/local mode can keep browser state entirely on user-controlled hardware.
Start with understandable presets such as read only, ask before changes or broad autonomy, then expand exact provider, browser and risk-class controls only when you want them.
Public connectors use PKCE, one-time authorization codes, short-lived child capabilities and rotating refresh tokens. The owner can suspend all AI authority without disconnecting personal accounts.
API Vault records who acted, what operation was attempted, where it ran and whether it succeeded without logging raw authorization headers, passwords, provider tokens or browser credentials.
Every plan keeps the same core safety model. Pro is for the individual who wants the full product without the Android fallback-vault cap. Founders Lifetime is a one-time early-adopter price and will increase as API Vault matures.
Connect services and websites, assign AI access, use the emergency pause, and keep up to five fallback vault credentials on Android.
Start freeIndividual Pro. Same security controls, with the paid individual entitlement and no Android fallback-vault cap.
Choose monthlyThe same individual Pro entitlement, billed every three months.
Choose quarterlyThe same individual Pro entitlement at the annual rate.
Choose annualIndividual Pro without a recurring subscription. This founders price is temporary and may increase as the product matures.
Get Lifetime ProTeam is coming later and is not for sale until collaboration, shared-vault administration, and role controls are complete.
These checks read only non-secret OAuth and MCP discovery metadata from vault.goldenphysics.org.
Checking…
Checking…
API Vault intentionally exposes no tool for retrieving raw stored credentials.