Generate, revoke, and monitor API keys with per-key analytics. Know exactly who is calling your API and when.
Why APIVault
Group keys by project. Revoke an entire project in one click without touching others.
Request counts, last-seen timestamps, and usage trends per key — not just aggregate totals.
Compromised key? Revoke it instantly. No propagation delay. No downtime for other keys.
Keys are stored as bcrypt hashes. Even a database breach exposes nothing usable.
Human-readable key prefixes (sk_live_, sk_test_) so you always know which key is which.
Your infrastructure, your data. Deploy to any Postgres-backed host in minutes.
Pricing
Self-Hosted
MIT license. Forever.
Hosted
We handle the ops.