Cointime

Download App
iOS & Android

Infisical Launches Open Source Agent Vault: Agents Never Handle Keys, Unified Interception at HTTPS Layer

According to monitoring by Dongcha Beating, Tony Dang, co-founder of key management company Infisical (YC incubated, processing billions of keys monthly), announced the open-source release of Agent Vault, an HTTP forward proxy and key vault specifically designed for AI agents, currently in research preview. The core idea is that agents are untrusted and should not directly hold any keys; instead, the proxy layer injects them during outbound requests. Traditional key management directly distributes keys to workloads, which works fine for programs with fixed execution paths, but agents are non-deterministic and can be induced by prompt injections to leak keys from the environment. Attackers can use poisoned documents, malicious web pages, and other methods to make agents send keys to endpoints controlled by the attacker. Even with protections in place, there is no guarantee that the agent won't be manipulated. The approach of Agent Vault is to insert a forward proxy between the agent and external services. The agent only needs to set the HTTPS_PROXY environment variable and trust the CA certificate of Agent Vault; all outbound requests are automatically routed through the proxy. Agent Vault terminates TLS, intercepts requests, retrieves the corresponding key from encrypted storage to inject into the request headers, and then establishes a new TLS connection with the real upstream for forwarding. The agent never comes into contact with the keys and does not require workflow modifications. The design is interface-agnostic: whether the agent calls external services via API, CLI, SDK, or MCP, all outbound connections ultimately go through HTTPS, where interception occurs uniformly. Similar ideas have independently emerged in several companies: Anthropic's Managed Agents architecture uses proxy services to inject keys, while Vercel and Cloudflare have launched their own credential brokering solutions tied to their platforms. Agent Vault is the first open-source, platform-agnostic implementation in this direction.

Comments

All Comments

Recommended for you

  • Arthur Hayes: More Concerned About Fed Nominee Waller's Comments on Balance Sheet Than Short-Term Interest Rates

    On April 28, BitMEX founder Arthur Hayes spoke about the Federal Reserve at the Bitcoin 2026 conference, stating, "When Kevin Waller was nominated as the Fed's SEC chairman, everyone started to panic because during his tenure as a Fed governor— I believe from the 2008 financial crisis until the current president— he has been very critical of the Fed's massive balance sheet. He has publicly stated that he believes the Fed's balance sheet is too large and that he needs to find ways to shrink it while also being able to lower interest rates. Now, if you have read my articles, you know that I am a firm advocate of the idea that the quantity of money is more important than its price. Therefore, I am more concerned about his comments on the balance sheet than the direction of short-term interest rates. So, if the market believes that due to Waller's actions at the Fed, the liquidity of dollars circulating in the system will decrease, then they will be bearish on Bitcoin and other risk assets. This is the discussion we see in the media about a hawkish Fed emerging after Waller takes over in May. Now, I don't think so. I believe that essentially the Fed will replace reserves, treasury bonds, and repos and put them into the commercial banking system, and they will do this with the help of new regulations concerning how banks hold assets on their balance sheets and how much capital they need to hold against those assets. Finally, I think the most important point to understand about what Waller will or will not do at the Fed is that he has a very substantial hard constraint, which is that he needs to work with Treasury's Scott Bessen to ensure that any actions he takes regarding the Fed's balance sheet do not impair Bessen's ability to sell billions and trillions of dollars in bonds.
  • SEC Chair: Reg GG Crypto to Allow Private Sector Token Sales Soon

    On April 28, U.S. SEC Chair Gary Gensler stated in an interview at the Bitcoin 2026 conference that the agency will continue to advance other exciting initiatives, such as truly allowing companies to conduct on-chain experiments, build tokenized securities, and trade on-chain within the United States. We plan to release innovative exemption regulations in the coming weeks. Additionally, we will permit the private sector to raise funds through on-chain token sales, which we refer to as 'Reg GG Crypto.' These initiatives are in preparation and will be launched soon. Currently, there is a bill titled the 'Clarity Act' under consideration in Congress. We do need Congress to provide regulations in this area. We are ready, willing, and able to explain their regulations and translate them into rules that people can rely on and pursue their innovative ideas. It is important to emphasize that this is happening domestically in the U.S., so they do not have to go overseas. This is the core idea that truly matters here.
  • SEC Chair Discusses Clarity Act: Codified Law Provides Greater Assurance for the Future

    On April 28, during the Bitcoin 2026 Conference, SEC Chair Gary Gensler spoke about the Clarity Act, stating that the U.S. Securities and Exchange Commission has considerable operational flexibility under the regulations. However, we are constrained by existing authorities, which, despite some amendments over the years, fundamentally remain rooted in the framework established in the 1930s. This is why having a piece of legislation is so important; it can shield future developments from adverse impacts, allowing us to leverage new authorities and the flexibility provided by the Act. We can collaborate with the Commodity Futures Trading Commission to coordinate and clarify definitions, and further develop from there. But again, nothing provides greater assurance for the future than codified law, coupled with sound judicial opinions that engrave the provisions of the law in stone through the mechanisms of the entire court system. Therefore, all of this is very important, but we are focused on efforts to simplify processes, enhance efficiency, and assist innovators in their endeavors, enabling them to operate with certainty rather than being stifled by those who jealously guard the existing ways of doing things. However, we must ensure that we remain at the forefront of innovation in the United States.
  • Meta Prepares to Withdraw Acquisition of Manus; Investors Including Tencent Plan to Cooperate

    On April 28, the Wall Street Journal reported, citing informed sources, that after the Office of Foreign Investment Security Review under China's National Development and Reform Commission made a legal decision to prohibit foreign investment in the Manus project, Meta is preparing to withdraw from the acquisition deal. According to sources, if Meta proceeds with the withdrawal process, several former Asian investors in Manus, including Tencent, Sequoia China, and ZhenFund, have planned to cooperate.
  • US Spot Bitcoin ETF Sees Net Outflow of $263.2 Million Yesterday

    On April 28, according to monitoring data from Farside Investors, the US spot Bitcoin ETF experienced a net outflow of $263.2 million yesterday.
  • US Spot Ethereum ETF Sees $50.4 Million Net Outflow

    On April 28, according to monitoring data from Farside Investors, the US spot Ethereum ETF experienced a net outflow of $50.4 million yesterday.
  • Bank of Japan Maintains Interest Rate, Meeting Expectations

    On April 28, the Bank of Japan kept its target interest rate unchanged at 0.75% for the third consecutive meeting, in line with market expectations.
  • DeFi United Raises Over 132,000 ETH to Fully Cover Kelp DAO Attack Losses

    As of April 28, the latest data shows that DeFi United, initiated by Aave in response to the Kelp DAO hacking incident, has raised over $300 million in 132,000 ETH, fully covering the $292 million loss from the issuance of rsETH due to the attack on Kelp DAO. The main contributors to this rescue effort include: Arbitrum DAO with 30,765 ETH recovered; Consensys and founder Joseph Lubin providing 30,000 ETH; Mantle contributing 30,000 ETH; Aave DAO with 25,000 ETH; Aave founder Stani Kulechov with 5,000 ETH; Ether.Fi with 5,000 ETH; Lido with 2,500 ETH; Kelp with 2,000 ETH; Golem Foundation with 1,000 ETH; Aave engineering senior vice president Emilio Frangella with 500 ETH; and BGD Labs and co-founder Ernesto with 350 ETH.
  • Iran Allegedly Begins Using Abandoned Oil Tanks for Storage

    On April 28, according to The Wall Street Journal, Iran is urgently seeking new methods for oil storage to avoid devastating production shutdowns due to the U.S. Navy's blockade and stalled negotiations. As oil accumulates domestically, Iran is restarting abandoned sites known as 'garbage storage,' utilizing makeshift containers and attempting to continue exports via rail. These unconventional measures aim to delay the onset of an infrastructure crisis and weaken the U.S. leverage in the standoff in the Strait of Hormuz.