Anthropic added Vaults to Claude Managed Agents beta and priced the layer at $0.08 per session-hour. I think that matters more than the safety framing suggests. This is Anthropic trying to own the agent control plane, not just shipping another nice security feature.
The mechanics in the post are simple and well chosen. Each end user gets a vault_id. Credentials are bound to an MCP server address. A session gets created with that vault_id, and Anthropic injects credentials only when the tool call needs them. The architecture detail that actually counts is the isolation boundary: secrets never enter Claude’s context window, code runs in a sandbox, auth goes through a dedicated proxy, and the harness never touches the secret material. For prompt-injection-heavy agent workflows, that is the right default. A lot of failures in production are not “the model made a bad plan.” They are “the model had too much ambient authority.” Anthropic is at least removing one ugly path where the model could ever see the secret and be tricked into leaking it.
I’ve felt for a while that most of the 2025 agent market chased the wrong wow factor. Everyone demoed agents operating GitHub, Linear, Notion, Salesforce. Far fewer teams solved the boring part cleanly: per-user credential storage, OAuth refresh handling, token scoping, audit trails, session isolation, and a sane execution boundary between model and tools. That stuff is where production systems break. Anthropic is packaging exactly that pain and charging a small runtime tax for it.
There’s useful context here. OpenAI spent the last year pushing more hosted tool use through Responses, built-in tools, and agentic workflows, but I haven’t seen a clearer public statement from them on secrets being kept fully outside model context in this specific pattern. Google’s advantage sits more with first-party identity and Workspace access. Anthropic is aiming at the cross-SaaS developer problem: one agent, many end users, many third-party systems, and a lot of liability if you get the boundary wrong. That’s a more grounded wedge than another benchmark slide.
I do have some pushback. The article does not disclose the audit model, and that is a big omission. In production, isolation is table stakes. The real trust test is whether a team can answer: which credential was used, by which session, against which MCP endpoint, for what operation, and with what policy. If Vaults cannot expose that at fine granularity, security teams will stall this fast. The article also does not disclose how narrow permissions can get. Binding a credential to an MCP server address is not the same as least privilege. If one MCP server fronts many actions, the agent can still receive more authority than the task requires.
The pricing also deserves a harder look. $0.08 per session-hour sounds cheap when you compare it to a team building secret storage, auth proxies, and sandbox plumbing themselves. It looks less trivial at scale. A service with 1,000 concurrent sessions running eight hours racks up $640 per day before token spend. That is fine for internal ops or premium enterprise workflows. It is not automatically fine for thin-margin SaaS products.
The broader pattern is the interesting part. Model APIs are getting easier to swap. The sticky layer is moving upward into runtime infrastructure: secret custody, session state, tool mediation, sandboxes, policy enforcement. Once a company stores every end user’s third-party credentials behind Anthropic-managed vault_ids, migrating away is no longer just “point at a new model.” The operational coupling gets much tighter.
So I buy the product direction. I don’t buy the idea that the story is complete yet. What I still need to see is enterprise-grade control surface: token rotation, short-lived credentials, detailed audit logs, policy hooks, HSM or BYOK options, and proof that MCP mediation can enforce narrow scopes instead of broad trust. Without that, Vaults is a very sensible convenience layer. With it, Anthropic starts looking less like a model vendor and more like agent infrastructure people won’t want to unwind later.