Vault · Early access
One door to every MCP tool. Every call checked and recorded.
People plug MCP servers into Claude, ChatGPT, Cursor and their own agents, each with its own tokens and no oversight. Vault gives your company one governed MCP endpoint: admins connect servers once, people sign in with the company account, and every tool call is checked against the groups and rules you set.
- 01MCP tokens live on every laptopEach person connects servers with their own keys, so access can't be reviewed or revoked in one place.
- 02Anyone can call any toolThere is no way to say which team may use which server, let alone which individual tool or what it may be asked to do.
- 03Shared secrets get pasted aroundAPI keys and passwords travel through chats and files, with no record of who can use them.
Example goal
Every MCP tool call governed
of calls through Vault, target 100%. Illustrative numbers.
How it works
Connect once. Govern every call.
Connect servers once
An admin connects an MCP server with OAuth or a custom setup and approves its tool definitions. Connecting a server gives nobody access.
Grant by group
Access is deny by default. Give a group individual tools or whole servers, and add rules on a tool's inputs, with exact values or patterns.
Share secrets without showing them
Let a group use a shared secret without anyone seeing its value.
Everything is recorded
Each call is checked again against the current groups and rules, and logged with the person and the AI client that made it.
What it includes
Built for your security review. From day one.
Vault is in early access. Book a call to see it and shape what comes next.
- One MCP endpoint for Claude, ChatGPT, Cursor and AgentWorks agents
- Sign-in with your company account, and each AI client's access can be revoked
- Deny-by-default grants per group, server or single tool
- Rules on tool inputs: exact values or full-string patterns
- New or changed tool definitions are held for review
- Shared secrets granted to groups without revealing their value
- An audit log of every call, with the person and AI client
- A chat assistant that sets up access and explains each change
Built for your security review
Runs in your cloud. Every action on the record.
Self-hosted
Deployed in your cloud account or data center. Evidence stays in your environment.
Approvals
Anything that changes production or reaches people waits for approval by default.
Audit trail
Every run, tool call, decision and cost is recorded per workflow.
Your models
Your enterprise Claude, ChatGPT or Gemini agreements, or private endpoints.
Scoped access
Tools, folders and secrets are granted per workflow, and every command agents run is OS-sandboxed.
SSO and roles
Sign-in through your identity provider, with roles and per-workflow access.
FAQ
Questions, answered.
Is Vault available?
It is in early access. Book a call and we will set it up with you.
Which MCP clients work with it?
Any client that can connect to a remote MCP server, such as Claude, ChatGPT, Cursor and AgentWorks agents. People sign in with the company account, and a client can be disconnected at any time.
Does connecting a server give people access?
No. Access is deny by default. A server's tools reach people only through the groups an admin grants them, and new or changed tool definitions wait for review.
Can a rule limit what a tool is asked to do?
Yes, for the values a tool exposes as inputs, using exact values or full-string patterns. For things like free-form queries or opaque IDs, also use a narrowly scoped credential upstream.
Where does it run?
On your AgentWorks server, in your own cloud or data center.
Also in AgentWorks
The rest of the platform.
Govern MCP before it sprawls. Join the early access.
Tell us which MCP servers and AI clients your teams use, and we will set up Vault with you.