Scoped AI access with a hard boundary

Your keys work till they don’t.

Give every AI agent enough access to finish the job—and a clear stop when the job is done. Set a ceiling for requests, tokens, estimated spend, time, and source across 12 supported providers.

Controlled beta Manually onboarded Free plan available

Example boundary — not live account data

Till pass // 043 Active

Research sprint

One agent · one operating envelope

Provider requests
17 / 50
Est. spend
$1.84 / $5
Token ceiling
100K
Expires
Fri · 6 PM
Request capacity33 remain
12supported AI providers
1required request ceiling
5ways to bound each key
Nowrevoke access anytime
The short answer

What is Till?

Till is a hosted control layer for AI provider credentials. It gives each AI agent or automation a disposable Till key with a required request ceiling and optional token, estimated-spend, expiration, and IP controls.

A master key is too much power for one task.

Agents, automations, contractors, and demos are temporary. A shared provider credential can keep working after the task ends.

Till makes access match the work. Each workload gets its own boundary without revealing the provider credential behind it.

See where Till fits alongside secret managers →

Provider key
Broad, reusable accessOne credential can outlive the task it was shared for.
Till pass
One workload. Explicit limits.Bound it, watch capacity, revoke it, replace it.
01

Agent runs

Put a request ceiling around loops, retries, research runs, and experiments before they begin.

02

Contractor access

Give a project disposable access with its own budget, source policy, and end date.

03

Product demos

Let prospects try AI features inside a pre-set operating envelope instead of an open tab.

04

Team experiments

Separate credentials and counters by project so remaining capacity is easier to understand.

Three moves between open access and controlled work.

Keep the provider accounts your team already uses. Till adds the per-workload boundary in front of them.

  1. 01 / CONNECT

    Connect once.

    Add the provider accounts your team already uses. Connections are encrypted at rest and are not returned after save.

  2. 02 / BOUND

    Set the line.

    Choose the required request ceiling, then add token, estimated-spend, expiry, or IP controls when the work needs them.

  3. 03 / HAND OFF

    Let it work.

    The agent uses its Till key. Till selects a configured connection, checks the boundary, and returns capacity signals.

For builders: what changes in the request?

The same scoped key works across provider-native request schemas. Point a supported client at Till and use the Till key as the bearer. Automatic routing across 12 providers uses configured connections and route, model, or default signals.

# Example Anthropic-native header
anthropic-version: 2023-06-01
authorization: Bearer till_sk_…

# OpenAI-compatible clients can set
base_url = "https://api.till.ac"

A key that knows its limits.

Start with the simplest boundary that makes the workload safe to hand off. Add tighter AI API spend controls when you need them.

L.01 Requests Required 50 attempts Cap the provider requests Till may dispatch for this key.
L.02 Tokens Optional 100,000 Reserve a conservative bound before generation, then settle to reported usage.
L.03 Spend Optional $5.00 est. Use known model pricing and provider-reported usage. Estimates may differ from provider invoices.
L.04 Expiry Optional Friday · 6 PM Give temporary work an explicit end time instead of a calendar reminder.
L.05 Source IP Optional IP / CIDR Restrict where the bearer can be used with an approved address or network.
L.06 Revocation Any time Pull one workload’s access without rotating every provider connection.

One pass. Twelve provider doors.

Connect the providers you use. Till selects among those configured connections from the request route, model, or account default.

  • 01OpenAI
  • 02Anthropic
  • 03Google
  • 04OpenRouter
  • 05Mistral
  • 06Groq
  • 07Together AI
  • 08Fireworks AI
  • 09Perplexity
  • 10DeepSeek
  • 11xAI
  • 12Cohere

Reduce the blast radius. Keep the truth visible.

A Till key is still a bearer secret. The difference is that it can be limited, revoked, and replaced without revealing the provider credentials behind it.

T.01

Encrypted connections

Provider credentials are stored as AES-256-GCM ciphertext with separate application key material.

T.02

No credential return path

After a provider credential is saved, admin APIs expose connection metadata—not the plaintext or ciphertext.

T.03

Fail-closed budgets

Unknown pricing or a missing output cap cannot silently turn a budgeted generation request into an unbounded one.

T.04

Capacity the agent can read

Machine-readable headers and validation responses expose remaining limits, warnings, and provider context.

What Till does not pretend to be.

Till is not a zero-knowledge system, prompt firewall, general secrets manager, compliance certification, or replacement for provider billing controls. Read the complete security model and check the independent service status.

Start with a bounded workload, not a platform migration.

Use your own provider accounts. Till charges a fixed platform subscription; provider inference remains billed separately.

Subscriptions cover Till’s hosted control layer, not provider usage, uptime guarantees, compliance certifications, SSO, or dedicated support. Prices shown apply to new subscriptions. Eligible paid beta subscriptions keep their founding price under Till’s founding-customer policy. Existing account holders can authenticate to upgrade. Compare full plan details →

Questions before you hand over the key.

What is Till?

Till is a hosted control layer for AI provider credentials. It gives each AI agent or automation a disposable Till key with a required request ceiling and optional token, estimated-spend, expiration, and IP controls.

What limits can I set on a Till scoped key?

Every Till scoped key requires an activation ceiling. You can also add token and estimated-spend budgets, an expiration time, and an IP or network allowlist. Any key can be revoked immediately.

Which AI providers does Till support?

Till supports 12 providers: OpenAI, Anthropic, Google, OpenRouter, Mistral, Groq, Together AI, Fireworks AI, Perplexity, DeepSeek, xAI, and Cohere. Automatic keys route among the provider connections configured for your account.

Does Till store my AI provider credentials?

Till stores provider connections as AES-256-GCM encrypted ciphertext and does not return provider credentials after they are saved. The proxy decrypts the selected credential in service memory when forwarding a request, so Till is not a zero-knowledge system.

How do I get access during the beta?

Till is in a controlled beta. New accounts are approved and provisioned manually; public anonymous signup is not available. Request beta access to start the onboarding conversation.

Need a deeper answer? Visit the full FAQ, explore use cases, or read the API documentation.

Give it enough. Not everything.

Till is accepting a small number of manually onboarded beta customers. Tell us what you want to put behind the Till line.