What is CallVault?

CallVault is an agent credential broker. Your operators connect SaaS accounts (for example GitHub) through OAuth. Your backend holds bk_test_* / bk_live_* control API keys. Agent runtimes receive only short-lived broker JWTs and call tools through a single hero endpoint: POST /v1/tools/execute.

Agents never hold long-lived SaaS secrets. Usage is metered on tool executions (not OAuth connects). The broker enforces tenant policy, optional human approval for high-risk tools, and audit logging.

Production hosts

Where to go next

  • Quickstart — mint a broker JWT and execute a tool with @broker/sdk-ts
  • Auth model — Auth0 operators vs control keys vs broker JWTs
  • Core endpoints — summarized routes (not a full OpenAPI dump)
  • Pricing — locked tiers and plan-match labels

OpenAPI

In production, public GET /openapi.json is disabled. Authenticated operators can fetch the full schema at GET /v1/ops/openapi.json with an Auth0 access token and X-Broker-Tenant-Id. Local development may expose /openapi.json when NODE_ENV is not production.

TypeScript SDK and monorepo source: packages/sdk-ts.