Observed arrival · 2026-09-10
Botpasses Keeps Agent API Keys Out of the Chat
An MCP-compatible credential vault lets AI agents call services such as Stripe, Slack, and GitHub without exposing the underlying API key to the model.
Field notes
The workflow separates the model-visible request from the API-facing request: the agent supplies a URL and task description, while the vault applies a credential only after operator approval and a host check. The example uses an eight-digit approval code and restricts a Stripe credential to api.stripe.com. The page documents three operating modes—hosted, local SQLite, and self-hosted with Postgres—and says the project is MIT-licensed and free during beta.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue