Token Vault
Manage

Stop all access

The kill switch — refuse every agent, proxy, and MCP request at once, and how to resume.

"Stop all access" is the kill switch: one click refuses every agent, proxy, and MCP request across your whole account. Use it the moment you suspect a key is compromised, or whenever you want everything paused while you investigate, without deleting or reconfiguring anything.

What it does

Clicking it sets a single flag on your account (isLocked). While set:

  • Every agent credential fetch, MCP proxy call, MCP tool call, and tv_session-backed request is refused — REST callers get 423 VAULT_LOCKED, MCP tool calls get the JSON-RPC equivalent.
  • Scheduled token refresh is also refused (503) while locked.
  • New webhook binds and re-binds are blocked too.

This is a request-level switch, not a way to invalidate bytes already handed out

A signed ticket already issued to an agent can still be redeemed for up to 60 seconds, and a credential an agent already fetched keeps working until you rotate it with the provider. If you suspect a specific credential is compromised, rotate it there — the kill switch stops new requests, it doesn't reach into an agent's memory.

While locked, you can still reduce access

Locking doesn't freeze the console. You can still:

  • Suspend or rename an agent or MCP proxy
  • Turn off MCP for an agent

You can't do anything that increases access — resuming a suspended agent, changing what a proxy points at, or binding a new webhook all still require unlocking first.

Resuming access

Resuming needs a recent sign-in — within the last 5 minutes. If your session is older than that, the console asks you to sign in again before it lets you resume; a stolen but still-valid session token isn't enough on its own to restore access to everything at once. Engaging the kill switch in the first place has no such requirement, so stopping access is always a single click.

Where it lives

The button (VaultLockButton) and the "All agent access is stopped" banner (VaultLockBanner) are shared components mounted in the dashboard header, the Console, and Settings → Vault. Both read the same lock state, so every place you see it agrees on whether you're locked and whether a lock/unlock request is already in flight.

From the CLI

tvault vault lock      # stop all access
tvault vault unlock    # resume (needs a recent tvault login)
tvault vault status    # show the current lock state

vault unlock needs a fresh tvault login — the same 5-minute recent-sign-in rule the console UI enforces. See the tvault CLI reference for full syntax.

The stronger stop: take your webhook offline

The kill switch is a Token Vault–side flag — it stops TV from routing new requests. Your credentials themselves live on your webhook, which TV has no keys to. If you want the strongest possible stop, take your webhook offline: with no webhook reachable, Token Vault has no credential path of any kind, locked or not.

On this page