Skip to main content
Token Vault

Last updated: June 2026

Terms of Service

Acceptance of Terms

By accessing or using Token Vault, you agree to be bound by these Terms of Service. If you do not agree, do not use the service.

Description of Service

Token Vault is a credential management platform for AI agents. The service provides:

  • A webhook-sovereign credential brokering layer: your credentials are stored on your own infrastructure, not on Token Vault's servers
  • An MCP proxy for secure agent connections with credential injection
  • Scoped, time-limited credential grants for AI agents
  • A webhook kill switch for instant credential revocation

Token Vault is zero-knowledge by architecture: Token Vault does not store, hold encryption keys for, or have the ability to decrypt your credentials. Credentials are stored on a webhook server you deploy and control. Token Vault stores only operational metadata (vault item names, grant scopes, timestamps).

Account Registration and Security

You may create an account using Google authentication via Firebase. You are responsible for:

  • Maintaining the security of your account and any associated authentication credentials
  • All activity that occurs under your account
  • Safeguarding any vault keys, agent API keys, and webhook pairing codes generated through the service
  • Notifying us promptly at [email protected] if you become aware of any unauthorised access to your account

You must not share your account credentials or agent API keys with unauthorised parties.

Acceptable Use Policy

You agree to use Token Vault only for lawful purposes. You must not:

  • Store credentials obtained through unauthorised means
  • Use the service to facilitate unauthorised access to third-party systems
  • Attempt to reverse-engineer, decompile, or circumvent the encryption or security mechanisms of the service
  • Use the service in any way that could damage, disable, or impair its operation
  • Probe, scan, or test the vulnerability of the service without prior written consent
  • Exceed any rate limits or usage quotas applied to your account
  • Use the service to store content unrelated to API credentials or authentication tokens (such as general file storage)

Credential Storage and Shared Responsibility

Credentials are stored on your own webhook infrastructure. You are solely responsible for the security, availability, backup, and encryption of your self-hosted credential store. Token Vault's role is limited to brokering authenticated, policy-checked requests between agents and your webhook endpoint.

You acknowledge that:

  • You are responsible for the security of your webhook server and the credentials stored on it
  • You are responsible for managing which agents have access to your credentials via grant scopes
  • The webhook kill switch (taking your webhook offline) provides instant credential revocation, but its effectiveness depends on the availability of your infrastructure
  • Token Vault is not responsible for credential exposure caused by compromise of your webhook server

Agent grants are scoped and time-limited by design. You are responsible for reviewing and revoking grants as appropriate.

Limitation of Liability

To the maximum extent permitted by law:

  • Token Vault is provided on an “as is” and “as available” basis without warranties of any kind, whether express or implied.
  • We do not warrant that the service will be uninterrupted, error-free, or completely secure.
  • We are not liable for any indirect, incidental, special, consequential, or punitive damages arising from your use of the service.
  • Our total liability for any claim arising from these terms or the service shall not exceed GBP 10.
  • We are not liable for any loss or damage resulting from unauthorised access to your credentials where such access was caused by your failure to maintain account security.
  • We are not liable for the actions, availability, or security of any third-party services accessed using credentials stored in Token Vault.

Nothing in these terms excludes or limits liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any other liability that cannot be excluded or limited by law.

Data Handling and Encryption

Token Vault does not store credentials or hold encryption keys. Credentials are stored on your webhook infrastructure, optionally encrypted by your webhook (recommended; reference implementations use AES-256-GCM). Token Vault stores only operational metadata. All data in transit between your browser, agents, and Token Vault's servers is protected by TLS 1.3. For full details of how we handle your data, see our Privacy Policy.

Service Availability and Uptime

We aim to maintain high availability but do not guarantee any specific uptime percentage. The service may be temporarily unavailable due to:

  • Scheduled maintenance (we will make reasonable efforts to provide advance notice)
  • Unplanned outages on our infrastructure providers (Google Cloud Platform, Cloudflare)
  • Security incidents requiring immediate remediation

Credential retrieval depends on the availability of your self-hosted webhook endpoint. Token Vault is not responsible for downtime caused by your infrastructure.

Termination

You may delete your account at any time. Upon account deletion:

  • Your account data and operational metadata will be removed within 30 days
  • Credentials on your webhook infrastructure are unaffected and remain under your control

We may suspend or terminate your account if you violate these terms, with reasonable notice where possible. In cases of serious or repeated violations, we may terminate access immediately without notice.

We recommend exporting or backing up any critical credentials before deleting your account.

Intellectual Property

Token Vault, including its design, code, documentation, and branding, is the intellectual property of Conor Grant. You retain ownership of all credentials and data you store using the service.

Changes to Terms

We may update these terms from time to time. We will notify you of material changes by updating the “Last updated” date at the top of this page. For significant changes, we will make reasonable efforts to notify you via email. Continued use of the service after changes constitutes acceptance of the updated terms. If you do not agree with the changes, you should stop using the service and delete your account.

Governing Law

These terms are governed by and construed in accordance with the laws of Northern Ireland and the United Kingdom. Any disputes arising from these terms or your use of the service shall be subject to the exclusive jurisdiction of the courts of Northern Ireland.

Contact Information

For questions about these terms, contact us at [email protected].