Secrets vault for AI agents

Your AI asks for a secret. You approve it on your phone.

AI hub keeps your credentials in an end-to-end encrypted vault. When Claude or another agent needs one, it asks over MCP with a reason, you approve on your phone, and the value is delivered sealed to that one session, for as long as you allow. Nothing gets pasted into the chat.

Free for up to 25 vault items. No card needed.

  • End-to-end encrypted with age
  • A person approves every request
  • Every read on the record

Three steps, and you decide at each one

The agent never holds your vault. It holds one answer to one request.

  1. Connect your AI tool

    Add AI hub as a connector in Claude, or run claude mcp add in Claude Code. Sign in once and approve the connection.

  2. The agent asks

    When a task needs a credential, the agent calls secret_request with the name and a reason you can read, plus its own age public key. It gets nothing yet.

  3. You approve on your phone

    You see who asks, for what and why. Pick the lifetime and approve: your device seals the value to that session's key, and the agent reads it with secret_get.

For the credentials your agents keep asking for

Deploy keys for Claude Code

Let Claude Code deploy or run a migration without a .env file left on disk. Through the local agent the value can be written to a file the session uses, so it never enters the model's context.

API keys for agents

Agents that call your cloud, payment or model APIs ask for the key when they need it, for 15 minutes or a single read, instead of keeping it in a prompt or a config file.

TOTP codes without sharing the seed

Keep the two-factor seed in the vault. An approval gives the agent the six-digit codes for the next five minutes; the seed itself never leaves the vault.

Secrets the AI creates, into your vault

When an agent creates a password or an API key during a setup, it seals it to your inbox key (secret_inbox_key) and proposes it with secret_propose. You accept all, some or none on your phone.

Claude, Claude Code and any MCP client

One remote MCP endpoint with OAuth. Nothing to install: the client registers itself, you sign in and approve the connection, and you can revoke it later.

Claude (claude.ai and desktop)

Settings, Connectors, Add custom connector. Paste this URL and connect:

https://ai-hub.rc.center/mcp

Claude Code

Run this, then /mcp inside Claude Code to sign in:

claude mcp add --transport http ai-hub https://ai-hub.rc.center/mcp

Other MCP clients

Cursor, VS Code and any client with remote MCP over streamable HTTP and OAuth. In Cursor, add this to ~/.cursor/mcp.json:

{"mcpServers": {"ai-hub": {"url": "https://ai-hub.rc.center/mcp"}}}

Local agent (hardened)

rc-agent runs on Linux, macOS and Windows. It pairs the machine with your account, runs your Claude Code and Codex CLI sessions, and gives each one its own secrets MCP server that can deliver a value straight to a file.

Set up the local agent

MCP tools

The same tools on every client. Names only in listings; values only after an approval.

  • secret_request
  • secret_get
  • secret_ls
  • secret_inbox_key
  • secret_propose
  • secret_proposal_status

Built so that nobody but you can open the vault

Approvals in your pocket

The AI hub app for Android notifies you of each request and lets you approve, deny or revoke in a few seconds.

Google Play listing coming soon. No phone at hand? Approve in the web panel.

Start free. Upgrade when the vault grows.

Machines, approvals and grants are free on every plan. Pro removes the vault limit.

Free

US$ 0

No card needed.

  • Vault with up to 25 items
  • Machines and access grants
  • Android app and web panel
  • MCP connector and local agent
Get started

rc.center Pro

Promotional price

US$ 9/month

R$ 49/month in Brazil.

  • Unlimited vault items
  • Machines and access grants
  • Everything in Free
  • Also includes OTPBox
Subscribe to Pro

Billed by rc.center. Subscribers are told before any price change.

Questions

Can AI hub read my secrets?

No. Vault items are encrypted on your device with a key derived from your master password, which is never sent. With end-to-end delivery the value is sealed to the requesting session's key. The hub does see metadata such as secret names, reasons, clients and times.

Does the secret end up in the model's context?

Not with the local agent's file delivery: the value is written to a file the session uses. The remote tools tell the agent to decrypt straight into a file or an environment variable and never print the value.

Which AI tools work with it?

Claude as a custom connector, Claude Code, Cursor, VS Code and other MCP clients that support remote servers with OAuth. The local agent also runs Claude Code and Codex CLI sessions on your machines.

Do I need the Android app?

No. You can approve requests in the web panel. The app adds push notifications and fingerprint or face unlock.

What if I lose my master password?

The vault cannot be recovered. The hub has no copy of the key, so keep the master password somewhere safe.

How much does it cost?

Free for up to 25 vault items. rc.center Pro removes the limit for US$ 9/month (R$ 49/month in Brazil), a promotional price, and also includes OTPBox.

Is the Android app on Google Play?

Not yet. You can download the APK from this site today; the Google Play listing is coming.

Stop pasting secrets into the chat

Create an account, connect your AI tool and approve the first request in a few minutes.

Get started