KeyRunner is a security platform that converts enterprise APIs into governed AI tools, enabling AI agents to execute approved actions with policy enforcement, runtime credential isolation, and complete audit trails. It sits between AI agents and internal systems, ensuring that agents never receive raw credentials. Instead, secrets are injected at runtime within the enterprise infrastructure, and every tool call is checked, controlled, and logged. KeyRunner offers a free local-first API client for developers, as well as an enterprise governance layer for agentic workflows. The platform includes features such as policy enforcement, secret injection, approval gates, response redaction, rate limiting, and full auditability. It integrates with major secret stores like HashiCorp Vault, AWS Secrets Manager, and Azure Key Vault, and supports AI frameworks like LangChain, CrewAI, and MCP. AiDOOS enhances deployment and adoption by providing a seamless integration environment, enabling organizations to deploy KeyRunner faster and scale it across teams with minimal effort.
Challenges It Solves
AI agents frequently leak credentials through logs, prompts, and tool outputs when given raw API keys.
Post-execution logs only show what happened, but do not prevent risky API calls.
Every new agent requires rebuilding the same API actions, leading to integration drift and security risk.
Direct API integrations lack pre-execution policy checks, allowing agents to make unauthorized calls.
Screenshots
Use Cases
Secure Enterprise Agent Deployments
Deploy AI agents in regulated environments with policy enforcement and audit trails.
API Testing and Development
Use the free API client for local development, testing, and mocking without signup.
Governed Agentic Workflows
Convert existing APIs into governed AI tools that agents can call safely.
Compliance and Audit Readiness
Maintain complete audit trails and comply with SOC 2, HIPAA, and GDPR requirements.
Pricing
Custom pricing — built for your team
KeyRunner pricing is tailored to your organisation's size, integrations, and requirements. AiDOOS generates your proposal instantly — scoped & ready in seconds.
💡 Pricing insight from reviewers: KeyRunner offers a free tier for individual developers, with paid plans starting at $49 per user per month for teams.
Key Features
Policy Enforcement
Validate and enforce governance contracts on every agent API call before execution.
Runtime Credential Isolation
Secrets are injected at runtime from vaults and never exposed to agents.
Approval Gates
Hold high-impact write operations for human review before execution.
Response Redaction
Strip PII, PHI, and PCI data from API responses before agents see them.
Audit Trails
Immutable audit trail on every agent API call with full visibility.
Vault Integration
Integrates with HashiCorp Vault, 1Password, and other secret stores.
What Reviewers Say
What works well
Provides strong governance for AI agent API access, preventing credential leakage.
Offers a free local-first API client with no signup required.
Supports integration with major secret stores and CI/CD pipelines.
Ensures compliance readiness with SOC 2 Type II, HIPAA, and GDPR alignment.
Common concerns
Limited customer reviews or social proof available publicly.
Pricing for advanced features (AI Tools Add-on) is custom, potentially costly for small teams.
Reviews
💬
No reviews yet for KeyRunner
AiDOOS-verified review data is collected after deployment. Deploy this product and be among the first to share your experience.
Enterprise Readiness
SOC 2 Type II
HIPAA
GDPR
Identity & Access
SSO✓ SAML, OIDC, Okta, Azure AD
RBAC✓ Fine-grained roles and permissions per tool, agent, and environment.
Audit Logs✓ 90-day retention
Data Security
At restAES-256
In transitTLS 1.2+
Key mgmtVendor-managed
SLA & Availability
Uptime SLA99.9%
RPO—
RTO—
Pen test—
Compliance & Portability
Data residencyUS, EU
Data export✓ JSON, CSV
Right to erasure✓ Supported
Integrations
29 total apps
HV
HashiCorp Vault
Pull dynamic secrets from Vault at runtime for agent API calls.
Native< 1 hour⚡ AiDOOS Pre-wired
AS
AWS Secrets Manager
Retrieve AWS-managed secrets on demand with IAM role authentication.
Native< 1 hour⚡ AiDOOS Pre-wired
AK
Azure Key Vault
Certificate and secret resolution for Microsoft-hosted workloads.
Native< 1 hour
1P
1Password Secrets Automation
Service account-based secret injection without exposing credentials.
Native< 1 hour⚡ AiDOOS Pre-wired
CA
Claude (Anthropic MCP)
Expose KeyRunner tool definitions over the Model Context Protocol.
Native< 1 hour⚡ AiDOOS Pre-wired
OG
OpenAI / GPT
Register KeyRunner as a tool provider for GPT-4 function calling.
Native< 1 hour⚡ AiDOOS Pre-wired
LC
LangChain
Wrap KeyRunner MCP tools as LangChain tools for agent chains.
Native1-2 hours⚡ AiDOOS Pre-wired
GA
GitHub Actions
Use KeyRunner CLI step in Actions workflows to enforce API policies in deployments and integration tests.
Native< 1 hour
SL
Slack
Receive notifications and approval requests via Slack integration.
Third_Party< 1 hour
DD
Datadog
Send OpenTelemetry-compatible telemetry and execution logs to Datadog.
Native< 1 hour
Governance & Compliance
EU AI Act
No data available
Data Processing Agreement
No data available
Sub-processors
No data available
Right to Erasure
No data available
Change Notifications
No data available
NIST AI RMF
No data available
AiDOOS Managed Deployment
Deploy KeyRunner in 72 hours
AiDOOS handles setup, CRM integration, SSO config, and user provisioning. Your team goes live — not your IT department.
12
Deployments
94%
Adoption rate
4.8/5
Post-deploy sat.
2-4 weeks
Time to value
Prerequisites
Sign up for KeyRunner account
Provide OpenAPI spec for APIs to expose
Configure secret store credentials (e.g., Vault, AWS Secrets Manager)
Set up AI agent framework connectivity
Configuration Options
Configure policy rules (rate limiting, time boxing, redaction)
Define approval gates for high-impact operations
Set up audit log export to SIEM tools
Integrate with SSO and RBAC for team access
How KeyRunner Compares
Product
AI & Analytics
Ease of Use
Enterprise Features
Pricing
Integrations
Mobile Experience
Quick Setup
Customer Support
Rating
Price/mo
K
KeyRunner This product
Good
Excellent
Excellent
Excellent
Good
Poor
Excellent
Good
—
$49/user
PO
Postman
Good
Excellent
Good
Fair
Excellent
Fair
Excellent
Good
—
$Custom/user
IN
Insomnia
Fair
Good
Fair
Excellent
Good
Poor
Excellent
Fair
—
$Custom/user
KG
Kong Gateway
Good
Fair
Excellent
Fair
Excellent
Poor
Fair
Good
—
$Custom/user
Virtual Delivery Center · A new delivery category
A Virtual Delivery Center for
KeyRunner
Pre-vetted experts and AI agents in the loop, assembled as a delivery
pod. Pay in Delivery Units — universal pricing across roles,
seniority, and tech stacks. No hiring, no contracting, no procurement
cycle.
Plans from $2,000 — Starter Pack, 10 Delivery Units, 90 days
Refundable on unused Delivery Units, anytime — no questions asked
Re-delivery guarantee on acceptance miss
Pre-flight delivery sizing — you see the plan before you commit
How does KeyRunner ensure agents never see secrets?
KeyRunner acts as a secure runtime that intercepts agent API calls, retrieves credentials from secret stores at runtime, and performs the call on behalf of the agent. The agent only receives the response, never the secret itself.
Can KeyRunner work with existing secret managers like Vault or 1Password?
Yes, KeyRunner natively integrates with HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, and 1Password, allowing you to use your existing secret infrastructure without exposing credentials to agents.
Is KeyRunner compliant with SOC 2, HIPAA, and GDPR?
KeyRunner is SOC 2 Type II compliant, HIPAA aligned, and GDPR ready, making it suitable for regulated industries.
What is the pricing model for KeyRunner?
KeyRunner offers a free Local-Lite plan for individuals. The Explorer plan is $49 per user per month, with an AI Tools add-on available at custom pricing and an Enterprise plan with advanced features.
Can I deploy KeyRunner inside my own infrastructure?
Yes, KeyRunner offers private deployment options for enterprise customers, allowing you to run it within your own VPC or data center.
How quickly can KeyRunner be deployed?
KeyRunner can be deployed quickly, typically within a few hours, and with AiDOOS, most integrations are pre-wired and can be live in 72 hours.