Temporary credentials for AI agents. Without giving them your secrets.
Let agents use APIs without exposing permanent credentials.
The key never leaves the server
Agents get a lease ID, not your API key. The proxy injects the credential and scrubs any echo of it from responses.
Policy first
One agent, one secret, exact hosts, methods and path prefixes, a maximum lease length and a request budget.
Short-lived by design
Leases expire on their own and can be revoked instantly. Deleting a secret stops every lease at once.
Audited
Every lease, request, denial and payment is recorded — host, method, path, status, duration — never the secret.
How an agent uses it
# 1. The agent asks for a 5-minute lease on a policy the owner created
curl -X POST https://agentsecretlease.online/api/v1/leases \
-H "Authorization: Bearer asl_agent_…" -H "Idempotency-Key: $(uuidgen)" \
-H "Content-Type: application/json" \
-d '{"policy_id":"pol_…","duration_seconds":300,"max_requests":10}'
# 2. It calls the API through the lease — the credential is added server-side
curl -X POST https://agentsecretlease.online/api/v1/leases/lease_…/execute \
-H "Authorization: Bearer asl_agent_…" -H "Content-Type: application/json" \
-d '{"method":"GET","url":"https://api.example.com/v1/search?q=x"}'Agents can integrate without reading this page: llms.txt, OpenAPI and an MCP endpoint. Free monthly lease allowance; then 0.01 USDC per lease via x402 on Base.