Loopback HTTPS proxy that fetches API credentials from Bitwarden Secrets Manager just-in-time and injects them into outbound requests, so the calling process never holds the real credential bytes in its address space.
Project description
agent-vault-proxy
Just-in-time API keys for AI agents and any other process you route through it: the caller only ever sees a placeholder.
AVP protects you from credential stealers (Shai-Hulud and similar) and prompt-injected agents leaking your secrets. It's a local proxy that injects real secrets into requests in-flight, so a compromised or prompt-injected agent has nothing to steal.
Under the hood: a loopback HTTPS proxy that fetches credentials from Bitwarden Secrets Manager — cloud or self-hosted — just-in-time and injects them into outbound requests, so the calling process never holds the real credential bytes in its address space.
Try it. 10 seconds.
$ pipx install agent-vault-proxy # pipx puts `avp` on $PATH for sudo
$ sudo avp setup --static
$ sudo avp secret add STRIPE_API_KEY # prompts; no echo
✓ added secret 'STRIPE_API_KEY'
next: run `avp env` to refresh ~/.config/avp/env
$ avp env
$ avp run claude # auto-loads ~/.config/avp/env, sets proxy, exec
avp run reads the placeholder env file itself, so the real key never enters your shell — not even as a placeholder. Add more secrets later by repeating secret add + avp env.
No Bitwarden account? --static keeps secrets in a local YAML file owned by the service user. Upgrade later by editing backend: in /etc/agent-vault-proxy/bindings.yaml (setup never overwrites an existing config).
On Mac: brew install inflightsec/avp/agent-vault-proxy
See it in action
Add a secret with your AI agent — no config editing
Onboarding a new brokered credential shouldn't mean hand-writing binding YAML. The bundled avp-bindings skill lets an AI assistant (Claude Code, or any agent that loads skills) walk you through it: you say "route the Acme API through AVP," it asks the auth shape and host, then tells you exactly what to add — the secret name plus the annotation to paste into the Bitwarden Secrets Manager Notes field (or the Google Secret Manager avp-binding annotation, or a future backend's per-secret metadata). No AVP config edit, no redeploy — and the assistant never sees or stores the secret; it proposes, you apply.
Install the skill
Claude Code (recommended) — install it as a plugin, so it's available in every project and updates with /plugin marketplace update:
/plugin marketplace add inflightsec/agent-vault-proxy
/plugin install avp@agent-vault-proxy
Invoke it as /avp:avp-bindings, or just say "route the Acme API through AVP" and it triggers on its own.
Manual (any agent that loads Anthropic-format skills) — copy or symlink skills/avp-bindings/ into your agent's skills directory; Claude Code reads ~/.claude/skills/. A symlink keeps it current on git pull:
ln -s "$PWD/skills/avp-bindings" ~/.claude/skills/avp-bindings
Docs
- Is AVP for you? — what it does, what it deliberately does not do, why, and when to reach for it (start here if you're evaluating)
- Quickstart — 10-minute first run ending in a visible substitution
- Concepts — placeholder, binding, the CA, fail-closed — in plain terms
- Prerequisites — Bitwarden Secrets Manager setup (do this first)
- Linux install · Docker · macOS
- Usage — pointing your agent at the proxy
- Linux isolation — composing AVP with
bubblewrapfor filesystem sandboxing - bindings.example.yaml — full config schema
- avp-bindings skill — let an AI assistant author your notes/annotation bindings (propose-only, no config edit, no redeploy)
- Architecture — threat model, G1–G9 invariants, hardening, residual risks
- Adapter architecture — vault backends (Bitwarden + Google Secret Manager ship today,
staticfor dev) and how to add another - Google Secret Manager — keep secrets in GSM: setup, keyless auth, and end-to-end testing
- Comparison — vs. Vault Agent, Doppler,
op run,superfly/tokenizer - CHANGELOG · SECURITY · CONTRIBUTING · CREDITS
The proxy never phones home. The only outbound connections it makes are to the BWS endpoint you configure and the upstream APIs your agent is calling. No telemetry. The audit log under /var/log/agent-vault-proxy/audit.jsonl is local-only by default; optional off-box shipping forwards it — from a separate sidecar, never the proxy — only to a collector you run and control.
License
MIT — see LICENSE. Prior art acknowledged in CREDITS.md.
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file agent_vault_proxy-0.8.0.tar.gz.
File metadata
- Download URL: agent_vault_proxy-0.8.0.tar.gz
- Upload date:
- Size: 670.2 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
cc0a01ec6dc6d955d39e60e8f08491094b46586fc2e0e35c591105d9f961202f
|
|
| MD5 |
9290fe39dcef25169e8eb6fad3929e24
|
|
| BLAKE2b-256 |
e03638bf0574338061cd1f59143fec38ac03740f5322a52a6f8ae635a7bf3145
|
Provenance
The following attestation bundles were made for agent_vault_proxy-0.8.0.tar.gz:
Publisher:
release.yml on inflightsec/agent-vault-proxy
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
agent_vault_proxy-0.8.0.tar.gz -
Subject digest:
cc0a01ec6dc6d955d39e60e8f08491094b46586fc2e0e35c591105d9f961202f - Sigstore transparency entry: 2195131837
- Sigstore integration time:
-
Permalink:
inflightsec/agent-vault-proxy@57dbecb555385e0324643318b7f74560d8004cf7 -
Branch / Tag:
refs/tags/v0.8.0 - Owner: https://github.com/inflightsec
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@57dbecb555385e0324643318b7f74560d8004cf7 -
Trigger Event:
push
-
Statement type:
File details
Details for the file agent_vault_proxy-0.8.0-py3-none-any.whl.
File metadata
- Download URL: agent_vault_proxy-0.8.0-py3-none-any.whl
- Upload date:
- Size: 165.2 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
1a193e73ad4d3235b7a7e66794394afc9aa7368c7523f011b10479d888237e95
|
|
| MD5 |
842da5f30a3e9899aab6347b25b75496
|
|
| BLAKE2b-256 |
f65c7d8b9c4d4fb2cb4b6d61492e9bc6dc2f5c8a51f2844742cd8d79cd754035
|
Provenance
The following attestation bundles were made for agent_vault_proxy-0.8.0-py3-none-any.whl:
Publisher:
release.yml on inflightsec/agent-vault-proxy
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
agent_vault_proxy-0.8.0-py3-none-any.whl -
Subject digest:
1a193e73ad4d3235b7a7e66794394afc9aa7368c7523f011b10479d888237e95 - Sigstore transparency entry: 2195131842
- Sigstore integration time:
-
Permalink:
inflightsec/agent-vault-proxy@57dbecb555385e0324643318b7f74560d8004cf7 -
Branch / Tag:
refs/tags/v0.8.0 - Owner: https://github.com/inflightsec
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@57dbecb555385e0324643318b7f74560d8004cf7 -
Trigger Event:
push
-
Statement type: