CallVault

Howlin Wolf Applications

Agents never hold long-lived SaaS secrets.

Your tools run through a broker that injects credentials at the boundary — with audit, revoke, and no keys in the model.

Built for the default mess: keys pasted into agent configs and prompts — not a dig at other brokers.

API: https://api.callvault.dev

CallVault

How it works

Operator session (Auth0), server control plane (bk_*), and agent runtime (broker JWT).

1

Connect SaaS accounts

Operators sign in with Auth0 and connect GitHub via OAuth. Tokens stay encrypted in CallVault; agents get connection handles only.

2

Mint broker JWTs server-side

Your backend uses a bk_test_* or bk_live_* control key to call POST /v1/broker/token and passes only the short-lived JWT to the agent runtime.

3

Execute tools

Agents call POST /v1/tools/execute with the broker JWT and a connected_account_id. Results return — secrets do not.

Product proof

Credentials at the boundary

OAuth tokens and control keys stay in CallVault and your server. Agents receive short-lived broker JWTs scoped to tenant, agent app, and environment.

Policy + approvals

Low-risk tools run automatically. High-risk calls pause for operator approval before the broker continues the invocation.

Audit and revoke

Tool executions are metered and logged per invocation — built for teams that need visibility without pasting keys into prompts.

Transparent tiers

Usage is billed on tool executions (not OAuth connects). Plans from Free through Scale, with front-of-house plan match when usage crosses the next tier.

Pricing

Metered on tool executions. Free tier includes 5k calls per month.

+10% included calls · same price
TierPriceIncluded callsOverage
Free$05k—
Starter$4955k$0.0006
Growth$89110k$0.0005
Pro$139275k$0.0004
Scale$239550k$0.00035
EnterpriseContact salescustom (1.1M+)no public $

Plan match FAQ

What if my usage crosses the next plan?
If usage crosses the next plan, we may apply a one-time plan match (bill the next plan’s price that month). Once per account per plan. After that: standard plan billing (base + overage) and we show Upgrade savings available.

Start with the dashboard

Connect GitHub, mint broker tokens from your server, and run your first tool execution.