Skip to content

Connect your tools once. Agents act with the keys. Credentials live encrypted in the org vault, teammates run workflows without ever seeing a key, and you bring your own model keys or use ModuleX's.

credential vault · orgencrypted
  • SlackOAuth or Bearer tokenstored once
  • StripeAPI keystored once
  • HubSpotOAuth or Bearer tokenstored once
  • NotionOAuth or Bearer tokenstored once
keys encrypted in the org vault, used without being seen

Every account, one vault. Connect each Gmail account once, the work address, the personal one, or the team inbox, and workflows reference exactly the one they need.

Each connection is scoped and named. Rotate or revoke one account without touching the others, and no workflow ever sees a key.

One vault for the whole organization. Connect a tool once and every workflow can use it.

Credentials for the tools your team runs on, OAuth grants and API keys alike, are stored once in the organization's credential vault and masked everywhere they appear. A workflow references a connection, never a raw secret, so the same Slack or HubSpot account can power a dozen workflows without the key being copied into any of them.

Role permissions decide who can connect a new credential, who can edit a workflow, and who can run one. Sensitive actions can sit behind an approval step, so a run that moves money or deletes data waits for a second person.

guarantees
  • OAuth and API keys stored once, masked everywhere.
  • Workflows reference a connection, not a copied secret.
  • Role permissions and approval steps gate who can connect, edit, and run.

Agents act with your credentials. They never get to see them.

When an agent calls a tool, ModuleX makes the request with the stored credential and hands the agent the result, not the key. Nothing about the secret, its value, or its scope is exposed to the model or to the teammate who triggered the run.

Every execution lands in a per-run audit ledger: who ran it, which credential it used, which actions it called, and what it cost. Attribution is by user and by credential, so you can answer 'who did what, with which key' after the fact.

guarantees
  • The model sees tool results, never the credential.
  • Every run is attributed in the audit ledger, per user and per credential.

Your model keys, or ours. Your data either way.

Start on ModuleX-managed models with zero setup and pay for usage in credits. Or connect your own provider accounts, Anthropic and OpenAI among them, and pay those providers directly with no markup on that usage. Either way the model keys sit in the same vault, encrypted and masked, and your data stays yours.

Switching is a setting, not a migration: point a workflow at a managed model today and your own key tomorrow without rebuilding anything.

guarantees
  • Managed models, billed in credits, with nothing to set up.
  • Bring your own provider keys and pay providers directly, no markup.
  • Model keys live in the same encrypted org vault.

Every kind of key, counted from the registry. The vault holds the credentials behind all 179 integrations.

API key credentials91 integrations
OAuth credentials60 integrations
Custom credentials23 integrations
Bearer token credentials16 integrations
ModuleX-managed key credentials5 integrations
Integrations in the vault179
Actions they expose1,784
Last updatedJul 2026

Credential vault FAQ

  • In your organization's credential vault, encrypted at rest. OAuth grants and API keys are stored once and masked everywhere they appear in the product.

Connect your tools. Keep your keys.

Free plan. No credit card.