Vault · Encrypted credential storage
No more .env files.
Encrypted credential storage for AI agents. Store API keys, OAuth tokens, and login credentials with scoped access, automatic rotation, and audit trails.
AES-256-GCM
Encryption
Per-identity
Scoped access
Auto
OAuth refresh
One-click migration
Drop your .env. Walk away.
Drag a .env file into the console. Loomal auto-detects secret types — API keys, database URLs, OAuth tokens — categorizes them, and stores each one encrypted with AES-256-GCM. Delete the .env from your repo forever.
.env detected · 4 secrets
STRIPE_KEYAPI_KEYDATABASE_URLCUSTOMGITHUB_TOKENOAUTHADMIN_PASSWORDLOGIN
stored · encrypted · scoped
Encrypted at every layer.
Per-credential data encryption keys, each wrapped by org-level KMS keys. Even if the database is fully compromised, encrypted values are useless without the KMS key hierarchy. Not security theater.
Envelope encryption
Org KMS key
Wraps · DEK per credential
AES-256-GCM ciphertext
Revoke once. Cascades everywhere.
Every credential access traces through Human → Org → Identity → Credential. Pull one node and everything downstream stops instantly. No orphaned secrets. No cleanup scripts. No grep'ing through .env files.
The capabilities
Built for autonomous credential management.
- Scoped access per identity: Every credential is bound to a specific agent identity. Sub-agents receive attenuated access. Every read, write, and delete is audit-logged.
- OAuth auto-refresh: Store access and refresh tokens together. Loomal refreshes access tokens before they expire. Your agent never sees a 401.
- Zero-downtime rotation: Overwrite a credential and the next API read returns the new value instantly. No config files, no deployments, no downtime.
- Delegation chain: Every access traces through Human > Org > Identity > Credential. Revoke an identity and every credential it owns becomes instantly inaccessible.
- Typed credentials: Store credentials with semantic types — API_KEY, OAUTH, LOGIN, CUSTOM. Each has structured fields so your agent knows what it's working with.
- Native MCP integration: Access vault credentials directly from Claude Desktop, Cursor, or any MCP client via vault.store / get / list / delete tools.
In production
Where Vault saves the most time.
- Third-party API access: Stores and retrieves API keys for Stripe, Twilio, HubSpot, or any third-party service. Encrypted at rest, scoped per identity.
- Autonomous service login: Stores usernames, passwords, and TOTP seeds. Agents complete full login flows including 2FA — no human paste-in.
- Database connection strings: Store DB URLs, connection strings, and certificates securely. Agents retrieve at runtime — no hardcoded creds, no .env in git.
- Payment processing: Retrieves Stripe or payment processor API keys to create charges, generate invoices, or send payment links. Audit-logged.
- OAuth workflow automation: Stores OAuth tokens for Google Workspace, Microsoft 365, HubSpot. Tokens auto-refresh so the agent maintains persistent access.
- Multi-agent credential sharing: Parent agents delegate attenuated access to sub-agents. Lead-gen agent shares read-only CRM access without exposing the full token.
Stop hardcoding secrets.
Migrate from .env files in one click. Store, rotate, and audit every credential your agents use.
We’re live on Product Hunt
Loomal gives AI agents an identity — email, credentials, 2FA — all via MCP. An upvote today would mean the world.