What is CallVault?
CallVault is an agent credential broker. Your operators connect SaaS accounts (for example GitHub) through OAuth. Your backend holds bk_test_* / bk_live_* control API keys. Agent runtimes receive only short-lived broker JWTs and call tools through a single hero endpoint: POST /v1/tools/execute.
Agents never hold long-lived SaaS secrets. Usage is metered on tool executions (not OAuth connects). The broker enforces tenant policy, optional human approval for high-risk tools, and audit logging.
Production hosts
- API: https://api.callvault.dev
- Operator dashboard: https://app.callvault.dev
- This site: https://docs.callvault.dev
Where to go next
- Quickstart — mint a broker JWT and execute a tool with
@broker/sdk-ts - Auth model — Auth0 operators vs control keys vs broker JWTs
- Core endpoints — summarized routes (not a full OpenAPI dump)
- Pricing — locked tiers and plan-match labels
OpenAPI
In production, public GET /openapi.json is disabled. Authenticated operators can fetch the full schema at GET /v1/ops/openapi.json with an Auth0 access token and X-Broker-Tenant-Id. Local development may expose /openapi.json when NODE_ENV is not production.
TypeScript SDK and monorepo source: packages/sdk-ts.