credential vault

A credential vault built for agency-to-client handoff.

AES-256-GCM credentials, scoped per client and workflow. Clients add their own keys via a 7-day link; you never see plaintext.

n8n stays where it is. Autom8 sits in front.

AES-256GCM encryption
7-dayshare link expiry
100-viewper-link limit
0plaintext in DB
security model

Every safeguard a client would audit, without asking you to ship compliance docs.

AES-256-GCM at rest

Every credential encrypted with its own random IV before it touches the database. Keys never hit disk in plaintext, never appear in logs, never leak into error traces.

Time-limited share links

Generate a 7-day, 100-view link for your client. They submit credentials through a branded form. The link auto-expires. Revoke any time.

Global vs. workflow-scoped

Shared credentials at the client level for services used everywhere (e.g. a Gmail account), or workflow-specific secrets for one-off integrations.

SSRF-protected n8n calls

The client library blocks outbound requests to internal IP ranges by default. Your customer’s n8n instance stays on the safe side of the firewall.

Zero plaintext in the database

Even with full DB access, an attacker sees ciphertext. The encryption key is a separate env secret, rotatable without data migration.

Full audit trail

Every credential creation, update, rotation, and deletion is logged with timestamp, user ID, and resource scope. The trail your future auditor will want.

Frequently asked questions

pricing

Pick the plan that fits your roster

Yearly billing · 17% off vs monthly · No free trial · Cancel from dashboard.

Starter

1-10 clients · solo

83/mo

Billed 990€/year

  • 10 clients
  • 5 templates
  • Credential vault
Pro

10-20 clients · 2-3 team

166/mo

Billed 1990€/year

  • 20 clients
  • Bulk deploy & clone
  • Execution analytics
Agency

20+ clients · multi-operator

374/mo

Billed 4490€/year

  • Unlimited clients
  • 90-day activity logs
  • Direct support

Ship credentials without the Slack DM.