Infisical’s follow-up post on 8 October 2026 says Agent Vault “is in preview now, on Infisical Cloud or self-hosted.” That is not a first-release date. The Infisical/agent-vault repository was created on 27 March 2026. A blog post dated 22 April 2026 announced “an open source project in research preview.” A note at the top says Agent Vault “started as a research preview and is now a product in Infisical” and that “this post covers the research preview.” The README still says: “Preview. Agent Vault is in active development and the API is subject to change.” Tag v0.40.0 was published on 1 October 2026.
A proxy that holds the secret
A credential proxy keeps the real secret and attaches it to a request the agent sends, so the process that can be prompt-injected never holds the key. The README says agents are given placeholders such as __anthropic_api_key__. The tutorial uses __github_token__ in a header and says the agent and the GitHub CLI only ever see that placeholder. Clients are pointed at the proxy with HTTPS_PROXY. The README says the server uses port 14321 for the management API and UI, and port 14322 for the proxy.
A normal forward proxy only sees the CONNECT destination, not HTTPS headers. To swap a header, Agent Vault terminates TLS: it presents a certificate from a locally trusted certificate authority, replaces the placeholder, and opens a new TLS connection to the real host. The security page says that proxy authorization “travels in cleartext between agent and broker,” so the proxy belongs on a trusted or private network.
What “preapproved” covers
The first 8 October post says “A prompt-injected agent can only reach preapproved HTTP services, down to exact methods and paths,” and that sessions expire on a schedule you set and every request is logged. Those are Infisical’s claims. The open-source services page matches a host pattern, optionally with a path glob, and says “the matcher does not run regex, does not match on method/headers/query/body.” If no service matches, the request is forwarded unless an admin sets strict deny mode (unmatched_host_policy=deny), which rejects it. The April blog says HTTPS_PROXY alone does not force traffic, because the agent can unset the variable. The lockdown it describes is at the network: cut off every other outbound path so only Agent Vault is reachable. The project is an HTTP and HTTPS proxy. Traffic that is not HTTP does not go through it.
Licence, the cloud product, and a demo date
The LICENSE file says content outside any ee/ directory is under the MIT Expat licence, and that ee/ content, if present, is under ee/LICENSE. GitHub’s licence API reports the file as “Other” (SPDX NOASSERTION).
The README’s platform path groups services into access bundles and uses time-bound sessions. The overview calls access bundles lists of services for a session, sessions “time-bound grants,” and session logs “a record of every request an AI agent makes, stored encrypted in your own Amazon S3 bucket.”
The webinar page titles the live demo “Agent Vault in Action” and lists 21 October, 1 p.m. Eastern, 30 minutes. It does not print a year.
Run the open-source binary with deny mode and no egress except the proxy, and treat the method-level line as Infisical’s claim.

The Campfire
No commentsNobody has pulled up a log by this one yet. Be the first to say what you make of it.
Held for the desk. It appears after a look.