AgentValet sits between your agents and the platforms they call. Each agent gets its own cryptographic identity, scoped to exactly what it needs. You approve the risky calls. Every action leaves an audit receipt. One revoke ends it instantly.
Free tier available. Live in under 5 minutes, or we'll wire your first agent with you on a call. 30-day money-back on paid plans.
A while back Dharmesh Shah described a valet key for AI agents. A key that starts the car but won't open the boot, the glovebox, or the front gate at home. I commented that I might build it. Then I did.
I'm Edwin. I build and run AI systems for government, legal, and enterprise teams out of Brisbane, and I'd watched too many agents handed the full keyring when all they needed was to start the car. AgentValet is that valet key, shipped.
I'm not reselling someone else's platform. I write the code and run it in production. I've spent fifteen years in regulated Australian environments where a leaked credential is a genuinely bad day. AgentValet is the thing I wanted and couldn't buy: every agent with its own identity, scoped to exactly what it needs, a human on the risky calls, and a trail you can hand an auditor without apologising for it.
CLAUDE.md and .mcp.json automatically.
It's one proxy in front of everything your agents touch, so there's a single audit trail and a single place to pull the plug.
The assumption underlying most secrets management is that if nobody can read the secret file, you're fine. That assumption breaks the moment an agent runs with inherited API keys and no scope enforcement, because now a compromised agent, a rogue prompt injection, or a careless scope grant becomes a master key.
AgentValet starts from a different position. Each credential gets its own AES-256 data encryption key. That key is itself encrypted by a master key held in a Key Vault HSM we don't control at the database layer. When a call comes in, the proxy decrypts the credential in-memory for that single request, then discards it. It never lands in a log, a response body, or a debug trace.
Scope enforcement runs before decryption. An agent without the right grant never triggers a decrypt at all. Risky actions (writes, deletes, financial operations) pause the request and wait for a human to approve from their phone or browser. If the approval doesn't come, the call doesn't run. Every decision, approved or denied, lands in the append-only audit log so you can reconstruct exactly what happened and when. Revoke an agent and the effect is immediate: its public key is removed from the registry, all scope grants are invalidated, and any in-flight requests are rejected.
Not a reseller. Not a rebranded platform I'm badging and pitching. The proxy, the vault integration, the audit logic: I built it and I'm the person maintaining it. That matters when something goes wrong, because the person you're talking to is the person who can fix it.
The audit trail and approval flows are the point. If your security team would call them security theatre on a review, I want to know before you pay me for it. The goal is something that survives a real security review, not something that merely passes a checkbox.
Bring-your-own-key (BYOK) is in development. OpenClaw integration is coming soon. A few parts of the roadmap aren't shipped. I'd rather you know that than find out after signing up. The things that are live are live, and I'll say which ones those are.
Fifteen years in regulated Australian environments means I've seen what happens when a secret gets out. I didn't build AgentValet for the theoretical threat. I built it because watching agents inherit full keyrings made me genuinely uncomfortable, and I couldn't find something to buy that fixed it properly.
Undefined scope, free thinking, "we'll sort out the IP later": none of that. My thinking here is commercial and clear-eyed, which means if you want something AgentValet doesn't do, I'll tell you plainly rather than promise a roadmap I don't have. The product exists because I needed it. It keeps existing because other people need it too.
One MCP endpoint. Connect it to your host in minutes, or register directly with npx @agentvalet/register. Every agent gets cryptographic identity, scoped credentials, and a full audit trail regardless of which tool is running it.
.cursor/mcp.json. Agent-mode tools governed from day one.npx @agentvalet/register wires the MCP config and CLAUDE.md automatically.agentvalet server entry into claude_desktop_config.json.codex mcp add or drop into .codex/config.toml.hermes mcp add.droid mcp add or .factory/mcp.json.Things you can actually verify, not things I'm asking you to take my word for.
Published on npm. Works today. Free tier, no card required.
It's still beta, and I'll tell you what isn't built yet rather than paper over it. If the audit trail and approval flow don't satisfy your team, walk away. The free tier is there to let you check before you trust me.
Bring-your-own-key is in development (sign up below to get notified). A handful of integrations are in testing, not yet live. If you need something specific, ask me directly.
AgentValet is in beta. Early-adopter pricing goes up at GA, and any plan you start now is locked in for as long as you stay subscribed.
A separate scoped identity per client, instant offboarding when an engagement ends, and an isolation trail each client's auditor will accept. Everything in Team, scaled to your whole book of clients.
Calls beyond your included amount are tracked and billed at your plan's overage rate at the end of the month. You'll see the running total in your dashboard and we'll email you before your bill grows significantly. No surprises. Pay for what you use.
Your agents never stop mid-run. If you use more calls than your plan includes, we track the extra calls and add them to your next invoice at your plan's overage rate. No surprises. No cutoffs. Pay for what you use.
npx @agentvalet/register automatically injects the correct CLAUDE.md configuration. Any agent that can make HTTP requests can use the proxy.Start on the free tier and run your first agent through it. You'll know within an hour whether it does what you need. If the audit trail and approval flow don't satisfy your team, walk away. I'd rather you find out for free than pay for something that doesn't fit.
No card for the free tier. 30-day money-back on paid plans. · Want to hold your own key? Get notified when BYOK ships →