Use Case
Collect API Keys & Credentials for AI Automation Agencies
Collect the OpenAI keys, SaaS tokens, and database secrets you need to build client automations — through an end-to-end encrypted intake, not a Slack DM. Secure credential collection built for AI and automation agencies.
Collect Client Keys SecurelyThe Problem
Clients paste API keys into Slack and Loom
To get the build moving, a client drops their OpenAI key or CRM token into a chat message or a Loom comment. It sits there in plaintext, in a thread anyone on the channel can scroll back to.
You're holding live keys to the client's whole business
An OpenAI key is a metered credit card. A CRM or database token is every customer record. Collect a dozen of these per project and your inbox becomes the single richest target the client has.
No structure across projects and platforms
Every automation needs a different mix of keys: LLM, CRM, email, webhooks. Chasing each one across DMs and docs slows the build and leaves you unsure what you've actually received.
Offboarding leaves keys everywhere
When a project ends, those keys are still sitting in old messages, docs, and inboxes, with no record of what you held or when it should be rotated.
How it works
Build a reusable credential request
Create one intake asking for exactly the keys the automation needs (LLM API keys, SaaS tokens, database and webhook secrets) with clear labels so a non-technical client knows what to paste where.
Send the branded link
The client opens a page with your agency's name. No account to create, no tool to learn. They paste each key into the right field.
Keys are submitted encrypted
Every value is encrypted in the client's browser before it reaches our servers. We store ciphertext; you're notified the moment the keys land.
Isolate, use, and rotate on offboarding
Each client's keys live in their own project. You decrypt what you need, when you need it, and the audit trail is your checklist of exactly what to rotate when the engagement ends.
Benefits
- —LLM and SaaS keys never sit in Slack, Loom, or email
- —One reusable request covers every key an automation needs
- —Each client's credentials isolated in their own project
- —Clear labels let non-technical clients submit the right key
- —Audit trail of every key received and accessed — your rotation checklist at offboarding
- —No account required — the client just opens the link
Every automation you build starts by asking the client for their keys. Most of them arrive in a Slack DM.
You sign a client to build an automation or an AI agent. Before you can wire anything up, you need access: their OpenAI or Anthropic key, their HubSpot or Airtable token, a database connection string, maybe a webhook secret and an ad-platform token. So you ask, and the client, usually non-technical, does the fastest thing: they paste the keys into a Slack message, a shared doc, or a Loom comment.
Now the keys to the client's business are sitting in plaintext across your tools. That OpenAI key bills a real credit card on every call. That CRM token reads every customer record. Multiply it by every key an automation needs, and every client on your roster, and you're quietly holding the richest target each of those businesses has, with no expiration and no record of who's seen it. There's a structured, encrypted way to collect all of it in one pass.
What you'll collect
One reusable credential request replaces the scattered DMs. Everything the client submits is encrypted end-to-end in their browser before it's sent:
- LLM API keys (OpenAI, Anthropic, and others)
- SaaS API tokens (HubSpot, Airtable, Notion, Slack, and the rest of their stack)
- Ad-platform tokens (Google, Meta, LinkedIn)
- Database connection strings and webhook secrets
- No-code platform connections (Zapier, Make, n8n)
- Service-account credentials for anything else the build touches
How the intake flow works
When a client signs: Create a project for them and send your standard credential request. It opens as a branded page carrying your agency's name, not a generic form or a chat thread.
They hand over the keys — safely: Clear labels tell a non-technical client exactly which key goes where, so you get the right values the first time. Each one is encrypted on their device before it's sent. We store ciphertext.
You build: Open the submission in that client's project, decrypt only what you need, and wire up the automation. Every access is timestamped.
What your client experiences
A link, a form, a few paste-ins, submit. No account, no app, no confusion about where to send a secret. For a client who's nervous about handing over the key that bills their OpenAI account, watching the form encrypt it on their own device is what turns hesitation into a completed submission.
Isolation and clean offboarding
Client A's keys live in Client A's project, never mixed with Client B's, never left in a shared channel. When a project wraps or a contractor rotates off, the project's audit trail is your exact checklist of which keys to rotate or hand back. That's how you run ten automation clients without one leaked key becoming an incident.
This page is the AI-agency view of a broader workflow — for the general playbook, see Receive Client Credentials. For the underlying practices, see our guides on why sending API keys over email is risky and how agencies collect client credentials securely, or explore Secure Requests and Workspaces & Projects.
Handle sensitive client information securely — from onboarding to handoff. Try any workspace free for 3 days — no credit card required.
Collect Client Keys Securely