CAIN-42 · Protect identities, keys & data
Credential broker
Agents use your API keys without ever seeing them, so a hijacked agent cannot steal them.
Last reviewed 2026-10-01
Live Core platform · Platform feature
What it is
Agents call third-party APIs through CAIN without ever holding the API key; the key stays in the broker and every call is decided first.
Where it fits
Part of Protect identities, keys & data: Who the agent is, what it may touch, and what it must never leak. Every CAIN-42 product runs behind the same rule: an AI agent's action is checked before it runs (identity, authority, policy, risk), decided as allow, hold for a human, or block, and recorded as signed evidence. Unknown or error never becomes allow.
Use it
- Documentation
https://cainstudio.online/docs/broker
Live now
Checked from your browser when this page opened, not from a cached list.
Fire a real decision
Send an action through the live CAIN-42 pipeline from this page, with no account, and watch every stage decide. This is the same pipeline every product here sits behind; it runs for a throwaway demo tenant and is rate limited.
For AI engineers
Every product sits behind one decision path: your agent proposes an action with the exact arguments, CAIN runs it through identity, authority, policy, risk, trust and quorum consensus, and answers ALLOW, REQUIRE_APPROVAL or DENY with an Ed25519-signed record. A timeout, outage or unknown verdict never becomes ALLOW. A brand-new agent has no trust history, so its first actions usually come back REQUIRE_APPROVAL.
Python (zero dependencies)
pip install https://cainstudio.online/cainstudio-0.3.0-py3-none-any.whl
export CAIN_API_KEY=... # free key: https://cainstudio.online/signup
import cainstudio
@cainstudio.guard()
def transfer(amount_usd: float, to: str) -> str:
... # runs only if CAIN allows this call, with these arguments
try:
transfer(5000, "acme")
except cainstudio.ApprovalRequired as e:
print("held for a human:", e.approval_id)
except cainstudio.ActionBlocked as e:
print("refused:", e.decision.reasons)
except cainstudio.CainUnavailable:
print("CAIN unreachable: not run") # fail-closedSee a real decision with no account
cainstudio try # live pipeline, stage by stage
cainstudio try --list # the other attack scenariosMCP clients (Claude Code, Cursor)
claude mcp add --transport http cain https://cainstudio.online/mcpMore: Python SDK · TypeScript SDK · framework integrations · AI quickstart · decision signing key
Tested guarantees in this area
Every rule in these niches has its own page with its recorded result.
- Memory, data & privacy: 92 tested invariants — What agents remember and what must never leak.
- Identity, authority & delegation: 964 tested invariants — Who an agent is, what it may do, and who allowed it.
Related
- CAIN Context — Controls what information an agent sees before it decides.
- CAIN Identity — Gives every agent and person a verifiable identity, so CAIN always knows who is acting.
- CAIN Memory — Long-term memory for agents that cannot be poisoned or quietly rewritten.
- CAIN Private — A private space for your agents with governed memory, tools and MCP connections.
- LeakGuard — Stops passwords, keys and personal data from leaving in text sent to an AI tool.
Full documentation
The complete reference, also at /docs/broker.
Credential broker#
Your agents need to call GitHub, Stripe, your CRM or an internal API, but you do not want the API key inside the agent: in its prompt, its memory, its logs, or the hands of whoever injects instructions into it. With the broker, the key lives in CAIN. The agent asks CAIN to make the call, and CAIN decides first.
Store a credential (owner or admin key)#
curl -s https://cainstudio.online/fabric/broker/credentials -H "X-API-Key: $CAIN_API_KEY" \
-H 'content-type: application/json' \
-d '{"name":"github", "kind":"bearer", "secret":"ghp_...",
"allowed_hosts":["api.github.com"], "allowed_methods":["GET","POST"]}'
kind is bearer, header (with header_name, for example X-API-Key), basic (user:password) or query (with header_name as the parameter name). Hosts can be exact or *.example.com. The secret is encrypted at rest and no endpoint ever returns it. Agent keys can use credentials but cannot store, change or revoke them.
Call through CAIN (any workspace key, including agent keys)#
curl -s https://cainstudio.online/fabric/broker/call -H "X-API-Key: $AGENT_KEY" \
-H 'content-type: application/json' \
-d '{"credential":"github", "method":"POST", "url":"https://api.github.com/repos/acme/app/issues",
"json":{"title":"Flaky test"}, "agent_id":"triage-bot"}'
1. The URL and method must be inside the credential's scope. Otherwise the answer is 403, and no decision is made and no request is sent. 2. CAIN decides on the call as the tool http_<method> (here http_post), with the credential name, URL and body as arguments. Your tool rules, the risk model, the agent's trust and approvals all apply. The decision is recorded like any other. 3. Allowed means CAIN sends the request with the credential added and returns {"executed": true, "response": {"status", "headers", "body"}}. Held returns 202 with an approval_id; ask again after a person approves. Refused returns 403, and nothing is sent.
From Python (cainstudio 0.3.0 and later):
resp = cain.broker_call("github", "https://api.github.com/repos/acme/app/issues", method="POST",
json_body={"title": "Flaky test"}, wait_for_approval=120)
What protects the key#
- It is only ever sent to the credential's own hosts and methods. Redirects are not followed, so a
302
cannot carry it elsewhere.
- Requests go only to public addresses (the same checks as webhooks), and the connection is made to the
address that was checked.
- An
Authorizationheader the agent supplies is dropped. If the upstream echoes the key back, it is
replaced with [REDACTED:brokered-credential] before the response reaches the agent.
- Revoking (
DELETE /fabric/broker/credentials/<name>) takes effect on the next call.
Limits#
- The stored credential is long-lived. CAIN does not mint short-lived per-call tokens with each provider
(OAuth token exchange).
- Responses are capped at 1 MB, and each call times out after 20 seconds.
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem