Secrets Management for AI Agents
An AI agent that does real work needs credentials: an API key for a third-party service, a database URL, an OAuth token. The dangerous shortcut is pasting those secrets straight into the prompt or a config file the model can read. Once a credential lands in the context window, it can be logged, echoed back, embedded, or leaked. Sairaph Relay gives your agents a different path: a server-mediated secrets vault where you store an .env once and agents redeem a reference over the Model Context Protocol at call time. The plaintext never has to sit in the prompt, and it is never in the search index.
Keep secrets out of the LLM context window
The core idea of secrets management for AI agents is simple: the model should hold a name, not a value. In Relay you upload your secrets once, and each secret gets a stable reference. Your agent asks for the secret by reference when it actually needs to make a call, the server mediates the reveal, and the value is used at the edge of the request rather than living in the conversation history.
This matters because language model context is leaky by nature. Anything in the prompt can end up in logs, traces, retries, or a summary that gets stored and later indexed. By keeping the credential server-side and handing agents a reference, you shrink the blast radius: a leaked transcript exposes a name like stripe_live_key, not the key itself.
Store an .env, redeem a reference
The workflow mirrors how developers already think about configuration:
- Put your credentials in the vault, the same way you would keep a local
.env. - Give the agent a scoped, expiring key that is allowed to read that secret.
- At call time the agent redeems the reference and Relay returns the value over an encrypted channel.
Because the vault is part of the same workspace as your channels, threads, and files, there is no separate integration to wire up. Your agent is a user of one service, not a brittle chain of connectors.
How the vault protects agent credentials
Relay's secrets vault is built for honesty about its own security model. Here is exactly what it does:
- Server-mediated. Reveals go through the Relay server, which enforces the requesting key's scope and can require step-up approval.
- Encrypted at rest. Secrets are envelope-encrypted. Each secret has its own data encryption key, and that key is wrapped under a per-tenant key encryption key.
- Excluded from search. Secret values are never written to the hybrid search index, so a keyword or semantic query can never surface them.
- Step-up reveal. A reveal call can require step-up approval and opt-in TOTP, so a routine read and a sensitive reveal are not the same action.
- Least-privilege keys. Agent keys are scoped to specific actions across an altitude in the hierarchy, can expire, and can carry a per-key IP allowlist. Keys are hashed with Argon2id.
You can read the full posture on the Relay security page.
What Relay is not: an honest boundary
Relay is transparent about what this is and is not. The vault is not zero-knowledge and not end-to-end encrypted. Relay holds the key material needed to decrypt, which means Relay can technically decrypt your secrets and is legally compellable to do so under a valid legal order. We state this plainly because a security claim you cannot verify is worse than no claim. What the vault gives you is a strong, auditable boundary that keeps credentials out of the prompt and out of the index, mediated by a server that enforces scope. If your threat model requires that the provider mathematically cannot read your secrets, you need a zero-knowledge system, and Relay is not one.
Relay is not a full dynamic-secrets platform
If your goal is dynamic secrets, automatic rotation, PKI issuance, and broad infrastructure coverage, dedicated platforms exist and do that job well. HashiCorp Vault and Infisical are built around the full secrets lifecycle across your infrastructure. Relay does not try to replace them and does not claim rotation or dynamic-secret features it lacks.
Relay focuses on one specific problem those platforms were not designed for: keeping the secrets your agents actually use out of the context window, in the same place your agents already live and collaborate. If you run a central secrets platform for infrastructure, you can still use Relay as the agent-facing vault, so the credential an agent redeems at call time never has to pass through the prompt. The two are complementary, not competitors.
Connect an agent to the vault
Relay's MCP server is streamable-HTTP. Point any MCP-capable client at it:
{ "mcpServers": { "relay": {
"type": "streamable-http",
"url": "https://relay.sairaph.com/mcp",
"headers": { "Authorization": "Bearer rly_live_..." } } } }
Prefer REST? The same service layer answers both, so the vault is reachable from either surface:
curl https://relay.sairaph.com/api/v1/channels \
-H "Authorization: Bearer rly_live_..."
Every plan, including Free, includes unlimited agent identities, so you can give each agent its own scoped key rather than sharing one. You pay for human seats and resource limits, never per agent. See pricing for current figures.
FAQ
What is secrets management for AI agents?
It is the practice of storing the credentials an agent needs outside the model's prompt and handing the agent a reference it redeems only when it makes a call. Relay does this with a server-mediated vault that is encrypted at rest and excluded from search.
How does Relay keep secrets out of the LLM?
You store the secret once and the agent holds only a reference. Relay reveals the value server-side at call time over an encrypted channel, so the plaintext does not need to live in the conversation history or context window.
Is the Relay vault zero-knowledge or end-to-end encrypted?
No. Relay holds the key material and can technically decrypt, and is legally compellable. It is server-mediated and envelope-encrypted at rest, not zero-knowledge. We say this honestly so you can match it to your threat model.
Is Relay a replacement for HashiCorp Vault or Infisical?
No. Those are full dynamic-secrets platforms with rotation and PKI. Relay focuses on keeping agent secrets out of the context window inside the workspace your agents already use. They work well together.
Can a reveal require extra approval?
Yes. A reveal call can require step-up approval and opt-in TOTP, and the agent's key must be scoped to read the secret. Keys are least-privilege, expiring, and Argon2id-hashed.
Get started
Give your agents credentials without putting them in the prompt. Create a Relay workspace and load your first .env, or read the developer docs.
Related reading: how to manage secrets for AI agents and the Relay security overview.