Let agents use credentials without reading them.
Putting an API key in an environment variable hands it to every process on the machine, including a confused or compromised agent. Vault Gateway keeps the secret outside the guest and brokers its use.
- Use without reading
- The agent can call an approved destination with the credential attached, but never receives the long-lived secret itself.
- Scoped to destination and action
- Each grant names where the credential can be used and for what, instead of opening everything the key can reach.
- Environments define what enters
- Environments are versioned policy bundles that control which secrets and settings reach a dock at all.
- Every use is recorded
- Brokered calls appear in Flight Recorder next to the run and command that triggered them.
Questions
Can I still put plain environment variables on a dock?
Yes. Environments can define what enters a dock. Vault Gateway is for the narrower cases where an agent should use a credential without holding it.
Use cases that fit
Coding agents
Run coding agents like Claude Code, Codex, and OpenCode in isolated, repository-aware Linux machines with Docker, previews, and cheap branches.
Learn moreBrowser and computer use agents
Keep Chrome profiles, logins, and session state on a persistent dock, with a live desktop for human takeover when the workflow needs judgment.
Learn moreQA and preview environments
Build branches, run services, expose private preview URLs, and keep screenshots, logs, and artifacts on a persistent dock per change.
Learn moreInternal agent platforms
Connect agents to internal tools and private systems with deny-by-default egress, brokered credentials, approvals, and a full audit trail.
Learn moreAgent evaluations
Branch one snapshot into many identical docks to run agents, prompts, or models side by side and compare results fairly.
Learn more
Tell us what your agents need to run.
Private beta is open. Describe your workload and we will reply about access.