What is AgentSecrets?
The Zero-Knowledge Difference
How AgentSecrets Works
Installation
Quick Start
Migrating from .env Files
Migrating from Vault / AWS
Migrating from dotenv-vault
Production Checklist
Credential Exposure
What Zero-Knowledge Means
The Proxy Model
The Three-Layer Model
Environments
Agent Identity
Storage Modes
The No get() Principle
Secret-Level Policies
Cloud Overview & Architecture
The Dual-Engine Model
Cloud Resolver Data Plane
Workload & Agent Tokens
Egress Allowlists & Audit Streams
Cloud REST API Reference
Account (init / login)
Server & Self-Hosting (server)
Docs
Shell Autocompletion
Keychain Auth
Secrets
Environments
Credential Proxy
env Injection
Workspaces & Teams
Projects
Agent Identity
Audit & Governance
Integrations Overview
Claude Desktop
Cursor
OpenClaw
HTTP Proxy (Any)
LangChain (Soon)
CrewAI (Soon)
CI/CD Pipeline
SDK Overview
Python SDK
Python API Reference
Python SDK Manual Testing
JavaScript SDK (Soon)
Ecosystem Overview
Zero-Knowledge MCP Server
Server Overview
5-Layer Architecture
Self-Hosting Guide
Authentication & Keys
Workspaces & Teams
Projects & Scope
Environments
Secrets & Sync Protocol
Agent Identity Resolution
Telemetry & Metrics Engine
Audit Log Sync
API Endpoint Reference
Security Overview
Anti-Impersonation & Process Verification
Encryption Model
Zero-Knowledge Sync
Proxy Security Layers
Threat Model
OWASP Top 10 Mitigation
Security FAQ
Third-Party Audit
Reporting Vulnerabilities
Guides Overview
Building on the SDK
Stripe Integration
OpenAI Integration
Multi-Agent Setup
Onboarding Team
CI/CD Pipeline
Publishing ZK MCP
Rotating Credentials
Auditing Team Activity
Dev to Production
Kubernetes Deployment
Monorepo Setup
Production Proxy Hardening
vs .env Files
vs HashiCorp Vault
vs AWS Secrets Manager
vs dotenv-vault
vs Infisical
When Not to Use
Proxy Not Starting
Proxy Not Resolving
Domain Blocked
Sync Conflicts
MCP Not Connecting
Session Token Errors
Proxy Session Authorization
Keychain Storage & Backends
SSRF & Destination Rules
Installation Issues
Error Codes Reference
Frequently Asked Questions
v3.1.x
v3.0.0
v2.1.0
v2.0.0
v1.4.0
v1.3.x
v1.2.0
v1.1.x
v1.0.x
IntegrationsIntegrations Overview

Integrations Overview

AgentSecrets is designed to act as the universal credential infrastructure for the AI era. Because it operates at the process boundary and transport layer, it can integrate with virtually any application, framework, or AI agent without requiring you to rewrite your codebase.


Supported Integration Methods

You can integrate AgentSecrets into your workflow using any of the following methods, depending on your architecture and security requirements:

1HTTP Proxy (Zero-Knowledge)

The most secure method for autonomous AI agents. AgentSecrets runs a local proxy daemon on port 8765. Your application routes standard API calls through the proxy using X-AS-Inject-Bearer or related headers. The proxy resolves the credential from the OS Keychain, injects it, and forwards the request.

  • Best for: LangChain, CrewAI, AutoGen, and custom agents.
  • Security: Complete. Credentials never touch your process memory.
  • Read the HTTP Proxy Guide

2Environment Injection (Process Spawning)

The highest compatibility method. You run your normal command prefixed with agentsecrets env --. AgentSecrets resolves your keys from the keychain and injects them as standard environment variables directly into the child process at launch time.

  • Best for: Legacy tools, standard web applications (Next.js, Django, Spring), CI/CD pipelines, and local test suites.
  • Security: Moderate. Credentials never touch your disk, but they are accessible in process RAM.
  • Read the Environment Injection Guide

3AI Framework Integrations (LangChain & CrewAI)

Integrate AgentSecrets with popular AI frameworks (like LangChain and CrewAI) by routing the HTTP clients inside your custom agent tools through the local proxy.

  • Best for: Developers building agent toolkits where tools need to make authenticated API calls.
  • Security: Complete. Credentials never touch your agent's process memory or context window.
  • Read the LangChain Guide
  • Read the CrewAI Guide

4Model Context Protocol (MCP) Servers

A zero-knowledge integration for AI desktop tools (like Cursor, Claude Desktop, and Windsurf). The AgentSecrets MCP server exposes a local API call tool to the assistant over stdio, allowing the AI to query external APIs without ever holding the API keys in its context window.

Was this helpful?
Thanks for your feedback!
Your feedback helps us improve the platform.