Ag

Agent Vault – Open-source credential proxy and vault for agents

Hacker News

Agent Vault – Open-source credential proxy and vault for agents

Hey HN! Today we're launching Agent Vault - an open source HTTP credential proxy and vault for AI agents. Repo is at https://github.com/Infisical/agent-vault , and there's an in-depth description at https://infisical.com/blog/agent-vault-the-open-source-crede... . We built Agent Vault in response to a question that been plaguing the industry: How do we give agents secure access to services without them reading any secrets? Most teams building agents have run into this exact problem: They build an agent or agentic system and come to realize at some point that it needs credentials in order to access any services. The issue is that agents, unlike traditional workloads, are non-deterministic, highly-prone to prompt injection, and thus can easily be manipulated to leaking the credentials that they need to operate. This is the problem of credential exfiltration (not to be confused with data exfiltration). In response to this, some teams we've seen have implemented basic guardrails and security controls to mitigate this risk in their agentic environments including using short-lived access tokens. The more advanced teams have started to converge toward a pattern: credential brokering, the idea being to separate agents from their credentials through some form of egress proxy. In this model, the agent makes a request to a proxy that attaches a credential onto it and brokers it through to the target service. This proxy approach is actually used in Anthropic's Managed Agents architecture blog with it being that "the harness is never made aware of the credentials." We've seen similar credential brokering schemes come out from Vercel and in Cloudflare's latest Outbound Workers. Seeing all this made us think: What if we could create a portable credential brokering service plugged seamlessly into agents' existing workflows in an interface agnostic way, meaning that agents could continue to work with APIs, CLIs, SDKs, MCPs without interference and get the security of credential brokering. This led to Agent Vault - an open source HTTP credential proxy and vault that we're building for AI agents. You can deploy this as a dedicated service and set up your agent's environment to proxy requests through it. Note that in a full deployment, you do need to lock down the network so that all outbound traffic is forced through Agent Vault The Agent Vault (AV) implementation has a few interesting design decisions: - Local Forward Proxy: AV chooses an interface agnostic approach to credential brokering by following a MITM architecture using HTTPS_PROXY as an environment variable set in the agent's environment to redirect traffic through it; this also means that it runs its own CA whose certificate must be configured on the client's trust store. - MITM architecture: Since AV terminates TLS in order to do credential brokering its able to inspect traffic and apply rules to it before establishing a new TLS connection upstream. This makes it a great to be able to extend AV to incorporate firewall-like features to be applied at this proxy layer. - Portable: AV itself is a single Go binary that bundles a server and the CLI; it can be deployed as a Docker container as well. In practice, this means that you can self-host AV on your own infrastructure and it should work more universally than provider specific approaches like that of Vercel and Cloudflare. While the preliminary design of Agent Vault is a bit clunky to work with and we’d wished to have more time to smoothen the developer experience around it, particularly around the configuration setup for agents to start proxying requests through it, we figured it would be best to open source the technology and work with the community to make gradual improvements for it to work seamlessly across all agentic use cases since each has its own nuances. All in all, we believe credential brokering is the right next step for how secrets management should be done for agents and would love to hear your views, questions, feedback!

Share card

Actual performance

156points
55comments
Made the leaderboard

Launch Intel predictions

Analyze your own launch →
Product HuntOn track for Day 1 leaderboard · Strong signals: agents, agent, model · Missing: mac, macos, cursor
98%98% predicted probability of success on Product Hunt, based on ML models trained on real launch data.
best fitHighest predicted score across all platforms for this description.
Indie HackersFits the IH revenue-focused audience · Strong signals: started, para, including · Missing: supports, reddit linkedin, podcasting
92%92% predicted probability of success on Indie Hackers, based on ML models trained on real launch data.
Hacker NewsStrong engagement from HN community · Strong signals: exist, open source, existing · Missing: https docs, excited, just released
53%53% predicted probability of success on Hacker News, based on ML models trained on real launch data.
nativeThis product was originally launched on this platform.
TrustMRRLess likely to generate early MRR · Strong signals: way, para · Missing: mobile apps, ios, personal
37%37% predicted probability of success on TrustMRR, based on ML models trained on real launch data.
AppSumoMay struggle as an AppSumo deal · Strong signals: host, interface · Missing: plus, platform, intuitive
28%28% predicted probability of success on AppSumo, based on ML models trained on real launch data.
Acquire.comPre-revenue stage for this audience · Missing: arr, mrr, revenue
14%14% predicted probability of success on Acquire.com, based on ML models trained on real launch data.
BetaListMay not resonate with beta-testers · Missing: web3, chat, crypto
0%0% predicted probability of success on BetaList, based on ML models trained on real launch data.

Correct prediction on native model

Similar products

Ag
AgentState – Open-source resilience and caching proxy for AI agents41%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

AgentState – Open-source resilience and caching proxy for AI agents

Hacker News2
Sw
Switchboard is an open-source easy-to-configure Envoy proxy66%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Switchboard is an open-source easy-to-configure Envoy proxy

Hacker News4
el
elipsis.io (open source password vault)67%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

elipsis.io (open source password vault)

Hacker News2
Ha
Harp Proxy – open-source API Proxy for reliability and observability63%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Harp Proxy – open-source API Proxy for reliability and observability

Hacker News10
CrabTalk
CrabTalk95%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

The agent daemon that hides nothing. 5MB. Open Source

Product Hunt+192Developer Tools
Ro
Roids – Open Source Steroids for your Agents61%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Roids – Open Source Steroids for your Agents

Hacker News2
Mi
Mitmproxy 3.0 released, an open-source console-based proxy60%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Mitmproxy 3.0 released, an open-source console-based proxy

Hacker News242
AgentGate
AgentGate35%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Open-source Just-in-Time security proxy for Al agents.

Indie Hackerscommitment-side-project
ST
STSproxy – An open-source AWS STS proxy solution60%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

STSproxy – An open-source AWS STS proxy solution

Hacker News1
Na
Naisys: An open source command shell proxy for LLM agents59%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Naisys: An open source command shell proxy for LLM agents

Hacker News4