proxy_request
Make an API request through the locker proxy. The real API key is injected automatically — the agent never sees the raw secret. Use this when you need to call an external API (OpenAI, Stripe, etc.) using a stored credential.
store_key
Store a new api_key credential in the vault. The secret is encrypted with AES-GCM before being stored. Use store_oauth_credential for multi-field OAuth credentials. Requires master token auth.
store_oauth_credential
Store a new OAuth multi-field credential (client_id, client_secret, refresh_token, etc.). For OAuth providers like Google, GitHub, Slack, Microsoft, Notion, Spotify, Twitter, LinkedIn, Discord, Zoom, Dropbox, Salesforce, HubSpot. Requires master token auth.
rotate_key
Replace a credential's value in place with a new one. The credential's name, provider, and all metadata stay the same. Scoped tokens that reference the key continue to work. Requires master token auth.
rename_key
Rename a credential alias. The old name is remembered as a legacy alias forever, so existing references to the old name continue to work transparently. Requires master token auth.
pause_key
Pause proxy access for a credential without deleting it. Reveal/run/get/env operations still work on paused credentials. The proxy returns HTTP 423 for paused keys until they are resumed. Requires master token auth.
resume_key
Resume proxy access for a paused credential. Requires master token auth.
delete_key
Permanently delete a credential. The encrypted blob is removed from KV and the metadata row is removed from D1. This cannot be undone. Requires master token auth.
list_tokens
List scoped access tokens for the user's account. Each token authorizes proxy/MCP access to a specific subset of credentials. Requires master token auth.
create_token
Create a new scoped access token. Returns the access token and (for rotating tokens) the refresh token. Requires master token auth.
pause_token
Pause a scoped token. Paused tokens cannot be used until resumed. Requires master token auth.
resume_token
Resume a paused scoped token. Requires master token auth.
revoke_token
Permanently revoke (delete) a scoped token. Cannot be undone. Requires master token auth.
list_devices
List all devices registered to the user's account. Requires master token auth.
revoke_device
Revoke a registered device. The device's master token immediately stops working. Requires master token auth.