AgentValet sits between your AI agents and every SaaS platform. Cryptographic identity. Granular permissions. Human approval when it matters.
Three steps to deploy a fully governed agent that your whole team can audit.
A clean separation of identity, governance, and integration — each independently auditable.
Every request passes through a layered gauntlet. No credential ever touches a log.
AgentValet scales with you — one config file to hundreds of governed agents across teams.
Every tier includes the core security model. Upgrade for more agents, seats, and support.
Run AgentValet anywhere — or let us handle the ops while you build.
Paperclip orchestrates who does the work. AgentValet controls what they're allowed to touch — and proves it. Every platform call is credentialed, scoped, rate-limited, and logged. One revoke to stop any agent, instantly, across your whole company.
AgentValet sits between your Paperclip agents and every SaaS platform they touch. Agents never hold real credentials — they hold a scoped valet key that AgentValet controls.
stripe:charge, mail:send — as requiring your approval. AgentValet holds the call and only proceeds when you say so.| Paperclip alone | Paperclip + AgentValet | |
|---|---|---|
| Agent orchestration | ✓ | ✓ |
| Budget controls | ✓ | ✓ |
| Credential vault | ✗ | ✓ |
| Per-agent scope enforcement | ✗ | ✓ |
| Human approval for sensitive calls | ✗ | ✓ |
| Per-call audit log | ✗ | ✓ |
| One-click agent revoke | Suspends future runs | Revokes credentials now |
| IETF AIMS compliant identity | ✗ | ✓ |
"Paperclip is the company. AgentValet is the security desk at the door."
"The agent does the work. AgentValet holds the keys."
npm install @agentvalet/paperclip-adapter
AGENTVALET_PROXY_URL=https://api.agentvalet.ai AGENTVALET_OWNER_ID=your-owner-id AGENTVALET_COMPANY_KEY=your-rs256-key
No per-agent config. No credential juggling. One setup, every agent in your Paperclip company covered.
"I've been running 12 Paperclip agents across 3 companies. Before AgentValet I had API keys in 12 different config files. Now I have one dashboard and one revoke button."
Start free. Connect in minutes. Approve your first agent before your next heartbeat fires.
agentvalet-register automatically injects the correct CLAUDE.md configuration and hooks. Any agent that can make HTTP requests can use the proxy.Deploy in 5 minutes. No credit card required. Self-host forever free.