Secure, user-controlled API key delegation
Every app asks you to paste your API key. Keys end up scattered across dozens of apps with no visibility or control.
Your keys stay in one vault. Apps request scoped tokens. Revoke any app instantly without rotating your key.
# App requests access from user's vault from okap import OkapClient client = OkapClient("https://vault.okap.dev") token = client.request_access(provider="openai", models=["gpt-4"]) # Use with OpenAI SDK — key never leaves the vault ai = OpenAI(api_key=token.token, base_url=token.base_url)
Apps request scoped access: provider, models, limits, expiration.
Vault proxies requests, injecting keys and enforcing limits.
Users revoke any token instantly without rotating keys.
Yes. The more apps adopt it, the more useful it becomes. Start with your own projects.
Yes! Use the reference server or Cloudflare Worker.