Enter the 6-digit code from your authenticator app to finish signing in.
MyApi is a personal API gateway that sits between AI agents and your accounts. Agents hold scoped tokens instead of your passwords; the real credentials for 228 connected services stay encrypted in the vault, and every call is monitored, rate-limited, and audit-logged.
Agents get scoped tokens. Your real credentials stay sealed in the vault — never seen, never shared.
“Access to your private data — one of the most common purposes of tools in the first place! … Exposure to untrusted content … The ability to externally communicate in a way that could be used to steal your data.”
“An LLM-based system is often granted a degree of agency by its developer — the ability to call functions or interface with other systems … to undertake actions in response to a prompt.” The risk stems from excessive functionality, excessive permissions, or excessive autonomy.
“The principle that a security architecture is designed so that each entity is granted the minimum system resources and authorizations that the entity needs to perform its function.”
220+ services. MyApi holds the OAuth and the keys — agents never see them.
Build a persona once — skills, knowledge, and a scope ceiling — and assign it to any agent. Or skip it: a plain scoped token works on its own.
Token, persona ceiling, service grant — the narrowest wins. Out-of-scope calls never reach the service.
Live metrics per agent and per service. Set rate limits, get alerted on unusual volume, and pause or revoke any agent in one click.
Credentials are encrypted with AES-256-GCM before they touch the database; scoped tokens are stored hashed; every API action lands in the audit log with agent attribution.
Snapshot everything that makes your setup yours — and restore it anytime, or move it between workspaces without losing a thing.
Point any MCP client at your gateway. Every service surfaces as tools, already scoped.
No. Credentials are encrypted with AES-256-GCM and never leave the vault. Agents get scoped tokens; MyApi proxies and signs each call — no password, token, or secret is ever exposed. See the full security practices.
A reusable AI profile — scope, role & tone in one. It bundles skills, knowledge, and a scope ceiling. Assign it to many agents, or none: a plain scoped token works on its own.
Each call is checked against the token, the persona ceiling (when attached), and the service grant. The narrowest wins; denied calls never reach the service.
Yes. Every call is metered per agent and per service. Set rate limits, get alerts on unusual volume, and pause or revoke any agent in one click.
Yes. Snapshot personas, skills, knowledge base, and memory, then restore anytime or move them between workspaces — nothing is locked in.
Yes — MCP-native and plain REST. Claude Code, Claude Desktop, Cursor, OpenClaw, Hermes, custom agents — anything that can hold a bearer token or speak MCP. Setup guide in the docs.
Nothing — open beta, no credit card. Bring your own model keys for free, or use platform credits.
Human docs live at /docs — auth flows, token lifecycle, REST examples, MCP setup. Machine-readable: /openapi.json (OpenAPI 3), /llms.txt (agent instructions), /auth.md (agent registration).
228 services today — Gmail, GitHub, Slack, Notion, Stripe, Jira, and more — connected by OAuth, API key, or instance URL. Browse the full catalog.
Credentials are AES-256-GCM encrypted at rest with PBKDF2 (600k iterations) key derivation; scoped tokens are stored bcrypt-hashed; every API action is audit-logged with agent attribution; inbound content is scanned for prompt injection. Full details at /security.
Yes. Workspaces partition services, tokens, and audit history; invite members with role-based permissions, and move personas or knowledge between workspaces. SSO, SCIM, and seat billing exist for organizations — pricing is finalized after beta.
Every capability is unlocked during the open beta. Commercial packaging will be set once real usage teaches us what matters — no fake certainty before then.
Your plan while MyApi is in open beta.
Use the full control layer before packaging is finalized.
Packaging set once beta usage teaches us what matters.
During the open beta, every capability is unlocked on your account. Commercial plans — including team and enterprise options — will be announced after beta.
Open beta. First service connected in two minutes.