A key that stops
You are about to give an agent, a contractor, or a demo an API key. A provider key keeps working after the job ends. A Till key is a separate token with a required request ceiling, so the access you handed out can end on its own.
The provider key stays. The Till key can end.
-
01
A scoped token, not the provider credential
You connect the provider accounts you already pay. Till stores those credentials encrypted and does not return them after save. The workload gets a Till key. Leaking that key does not reveal the upstream credential.
-
02
A stop you set before the first call
Every Till key requires an activation ceiling: how many upstream attempts it may make. You can also cap tokens, cap estimated spend, set an expiry, and limit source IPs. When one of those is hit, that key stops.
-
03
One key, one revoke
If the key leaks or the job goes wrong, revoke that key. The provider connections behind it stay in place. The Till key is still a bearer secret until it stops or you revoke it.
The stops Till can actually enforce.
-
01
Request ceiling, required
A positive activation count. Till counts each attempt it dispatches upstream, including a failed provider or transport response. A request Till rejects locally is refunded. This is a lifetime operation limit for that key. It is not a per-minute rate limit.
-
02
Token budget, optional
A positive token cap, or none. A generation request that uses a token or spend limit also needs an explicit output cap, so Till can reserve capacity before it sends the call.
-
03
Estimated spend, optional
A positive cap in cents, or none. Till enforces it only when it has a price for the model. It reserves a conservative amount, then settles to reported usage. The provider still bills your provider account. This estimate is not the provider invoice, and it does not replace provider billing alerts.
-
04
Expiry, optional
A future time. After it, the key is expired and stops accepting requests. Leave it unset and the key does not expire on its own.
-
05
IP allowlist, optional
IP addresses or CIDR ranges. Requests from other addresses are rejected. The key itself can still be used from an address you allowed. This is available on every plan, not a paid add-on.
-
06
Revoke
You can revoke a key immediately. Revoked stays revoked. Raising a limit or clearing an expiry can bring an exhausted or expired key back; it does not bring a revoked key back.
Till does not set a per-key rate limit, and it does not allowlist individual API paths. A loop can still use the whole ceiling quickly. Till is a hosted control layer for AI provider credentials. It is not a zero-knowledge vault, prompt firewall, secrets-manager replacement, compliance certification, or a replacement for provider billing or IAM. Provider inference is billed by the provider. Till charges a platform subscription.
Four steps. Then the key can stop.
-
01
Connect the providers you already use
Add the provider accounts once. Automatic keys route among the connections on the account, including ones you add later. The workload never receives those credentials.
-
02
Issue one Till key for the job
Set the required activation ceiling. Add a token budget, an estimated-spend cap, an expiry, or an IP allowlist when the job needs a tighter bound.
-
03
Point the workload at Till
The agent, contractor, or demo sends requests with the Till key. Till checks the key, then forwards the call to a configured provider.
-
04
The key stops, or you revoke it
It stops when the activation, token, or estimated-spend limit is reached, or when it expires. You can also revoke it. The provider connections stay where they are.
These are plan limits, not usage claims.
Pro
Scale
Public signup is closed. New accounts are approved and provisioned manually. Existing customers can open the dashboard. Compare the full ledger on pricing. The same limit controls are on every plan: a required request ceiling, and optional token, estimated-spend, expiry, and IP controls. The monthly activation number is the account quota, separate from the ceiling on each key. Provider inference is billed by the provider.
Give it enough. Not everything.
Request Pro beta access. Till is a controlled beta. Accounts are onboarded manually. Public signup is closed.