Hand the Agent a Key That Stops
The buyer for scoped AI credentials is not the agent. It is the person who decides what the agent is allowed to spend, call, and keep after the task ends.
That decision usually happens in a hurry. A research sprint, a contractor handoff, a weekend experiment. Someone opens the provider dashboard, copies a key, and pastes it into an agent config. The job finishes. The key does not.
This is not a secrets-manager failure. Vaults store the credential. They do not bound the work.
The job is temporary. The key usually isn't.
An agent run has a natural end: the documents are processed, the contractor's week is over, the demo is done. A provider API key typically does not. It remains a bearer secret with standing access to whatever the upstream credential can do.
OWASP's API Security Top 10 treats both broken authentication and unrestricted resource consumption as first-class risks. A leaked or over-used API key is both: anyone holding it can authenticate as the workload, and nothing in the key itself stops retries, loops, or an overnight run.
NIST's Zero Trust Architecture argues against standing, implicit trust. Least privilege is supposed to be per-session and per-task. A shared provider key handed to an agent is the opposite: one credential, many tasks, no stop.
OpenAI's own API key safety guidance tells teams not to share keys and to revoke them if they leak. That is correct, and it still leaves a gap: revocation is a reaction. The agent needed a ceiling before the first call.
What a key that stops actually means
A useful stop is defined before the agent starts, not in the incident channel afterwards.
For a single workload, that usually means:
- A request ceiling. Count the attempts the job is allowed to make. OWASP's resource-consumption guidance calls for operation limits alongside rate limits and spending limits. A lifetime call ceiling is the operation limit for one agent run.
- Optional spend, token, and time bounds. A request ceiling does not cap how expensive one generation is, or how long a forgotten key remains valid. Pair it with those controls when they matter.
- A revocation path that does not rotate every provider connection. If this agent misbehaves, you should be able to pull its access without touching the rest of the team.
Till is a hosted control layer in front of the provider accounts you already use. You connect those accounts once. Each agent gets a disposable Till key with a required request ceiling and optional token, estimated-spend, expiry, and IP controls. The provider credential stays behind Till. The Till key is still a bearer secret. The difference is that it can be limited, watched, revoked, and replaced without revealing the upstream key.
Till is not a zero-knowledge vault, a prompt firewall, a compliance certification, or a replacement for provider billing alerts and IAM. Provider inference is still billed by the provider. Till charges a platform subscription.
The Pro line for a team that hands out agent keys
If you are that team, you do not need a platform migration. You need enough keys to cover the agents you actually run this month, with a stop on each one.
Till is in a controlled beta. Public anonymous signup is closed. New accounts are approved and provisioned manually.
Pro is the plan built for that handoff:
- $59 / month
- 25 scoped keys
- 25,000 monthly activations
- full limit controls (request ceiling required; token, estimated spend, expiry, and source IP optional)
Those numbers are plan limits, not usage claims. Free ($0, 3 keys, 1,000 monthly activations) exists for a first bounded workload. Scale ($249, 100 keys, 250,000 monthly activations) exists when the fleet is larger. Existing eligible paid beta subscriptions keep their founding price under Till's founding-customer policy.
Request Pro beta access
Tell us the workload you want behind a stop: the agent, the ceiling you would set, and which providers you already use.
Subject the mail Till Pro beta access. We onboard a small number of teams by hand.
If you want the design notes behind call ceilings before you write, read Call Ceilings for AI Workloads.
Request access to the Till beta
New accounts are approved and provisioned manually. Public signup is closed.
Request beta access