WiKey Gateway · For AI Agents

Your agents use the key.
They never hold it.

The WiKey Gateway lets an AI agent connect to any MCP server or REST API through a wallet passkey — no API keys, no client secrets, no bearer tokens living inside the agent. The real secret stays server-side and is injected per request. Every call is tied to a human owner and authorized on-chain.

✓ Wallet-passkey enrollment ✓ Works with MCP & REST APIs Live at gateway.wikey.io
Wallet Passkey
MCP & REST
Key Injected Server-Side

Today, an agent’s reach is a pile of stored secrets

To call an MCP server or a SaaS API, agents carry API keys, client secrets and bearer tokens. A stored secret is an extractable secret — and nothing ties the call back to a person.

The Risk

The agent holds the secret

  • Agents store API keys, client secrets and bearer tokens to reach every MCP server and SaaS API.
  • A stored secret is an extractable secret — prompt injection or a rogue dependency lifts it, backups included.
  • Keys are shared and unscoped — one leak exposes every tool the agent can touch.
  • No action traces to a real person; revoking means rotating secrets everywhere.
The Answer

The WiKey Gateway holds it

  • The agent authenticates with a wallet passkey — no password, no client secret, nothing to share.
  • The third-party key lives server-side in the gateway and is injected per request — the agent never sees it.
  • Every action runs under a scoped, revocable sub-identity that descends from a human owner.
  • Authorization is gated on-chain on the WiKey safe — recovery-proof, no help-desk reset.

Enroll with a passkey. Call through the gateway.

The agent enrolls itself from an invite, then makes authenticated calls — without ever possessing the underlying key.

1

Invited by a link

The agent enrolls from a one-time invite link. No password is ever set — the invite code is the only secret, and it’s single-use.

2

Passkey enrollment

A WiKey wallet passkey is created via standard OAuth (Authorization Code + PKCE). Public client — no client secret to store or leak.

3

Call through the gateway

The agent calls the MCP server or REST API. The gateway injects the real key server-side and proxies the request — the agent never holds it.

4

Authorized & traceable

A per-resource rule — sub-user → resource → method → Allow — gates every call, anchored on-chain to a human-owned safe.

The agent asks. The boundary decides.

The agent never possesses the third-party secret. It authenticates with a wallet passkey; the gateway injects the key server-side and proxies the request — so a compromised agent has nothing to leak.

Nothing to steal. Nothing to phish. Nothing to reset.

One identity for every tool your agents touch

The Gateway is where WiKey's three pillars — Keys, Data & PII, and Recovery — come together: keyless attested login, every instruction vetted, secrets injected server-side, and one-click revoke.

🔌

MCP and plain REST

Proven for both Model Context Protocol servers and ordinary REST APIs (e.g. OpenRouter). One gateway, any tool the agent needs to reach.

🔑

No secret in the agent

API keys and bearer tokens stay server-side. The agent presents a wallet passkey — there’s nothing standing to phish, leak, or back up.

🧩

Drop-in OAuth / OIDC

Standard Authorization Code + PKCE. The gateway presents as an identity provider, so existing tools accept it at the door — no rip-and-replace.

On-chain, recovery-proof

Authorization is gated on the WiKey safe on-chain. Access survives recovery and can’t be granted by a help-desk reset.

Give your agents reach without giving them keys

The WiKey Gateway is live. If you’re building agents that touch MCP servers, internal tools or third-party APIs, we should talk.

Visit gateway.wikey.io Get in Touch
info@wikey.io