# Agent Secret Lease > Let AI agents use an API credential without ever receiving it. The owner stores the credential and a policy (agent, hosts, methods, path prefixes, lease length, request limits). The agent requests a short-lived lease and sends HTTPS requests through the proxy, which injects the credential server-side. The credential is never returned by any endpoint. ## Get access - The owner signs in at https://agentsecretlease.online/login, creates an agent and gives the agent its token (asl_agent_…, shown once). - Send it on every call: Authorization: Bearer asl_agent_… ## Use a credential 1. GET https://agentsecretlease.online/api/v1/capabilities → policies you may lease (policy_id, allowed hosts/methods/paths, limits) and the price of the next lease. 2. POST https://agentsecretlease.online/api/v1/leases with Idempotency-Key and {"policy_id":"pol_…","duration_seconds":300,"max_requests":10} → 201 {lease:{id,expires_at,remaining_requests}}. 3. POST https://agentsecretlease.online/api/v1/leases/{id}/execute with {"method":"GET","url":"https://api.example.com/v1/resource","headers":{"Accept":"application/json"}} → {upstream:{status,headers,body,body_encoding}}. 4. POST https://agentsecretlease.online/api/v1/leases/{id}/revoke when done (or let it expire). ## Pay - Leases are free within the owner's monthly allowance. Beyond it, one lease costs 0.01 USDC via x402 v2 (exact scheme, USDC on Base mainnet, eip155:8453). - Unpaid request → 402 with the requirement in the body (x402) and the PAYMENT-REQUIRED header. Resend the same body and Idempotency-Key with PAYMENT-SIGNATURE. Rejected requests are never charged; one authorization pays for one lease. ## Rules - https only, port 443, DNS hostnames on the policy allowlist; private, loopback, link-local and metadata addresses are refused; redirects are not followed. - Authorization, Cookie, Host, Proxy-*, X-Forwarded-* and the credential header cannot be set by the agent. Any echo of the credential in a response is replaced by [REDACTED]. - Errors: {"error":{"code","message","retryable"}} with stable codes (LEASE_EXPIRED, HOST_NOT_ALLOWED, PAYMENT_REQUIRED, …). ## Links - OpenAPI: https://agentsecretlease.online/openapi.json - Docs: https://agentsecretlease.online/docs - MCP (Streamable HTTP, stateless): https://agentsecretlease.online/api/mcp — tools: list_capabilities, request_lease, get_lease, execute_with_lease, revoke_lease - Pricing: https://agentsecretlease.online/api/v1/pricing - Security model: https://agentsecretlease.online/security