{"name":"XGuard Secretless Egress","version":"1.0.0","role":"credential broker and egress choke point for AI agents","guarantee":"Agents receive scoped XGuard capabilities, never reusable upstream API credentials. XGuard injects the credential only after scope and Usage Credit checks, then forwards one public HTTPS request without following redirects.","credentials":"POST https://api.xguardgate.com/v1/egress/credentials","list_credentials":"GET https://api.xguardgate.com/v1/egress/credentials","capabilities":"POST https://api.xguardgate.com/v1/egress/capabilities","fetch":"POST https://api.xguardgate.com/v1/egress/fetch","providers":"GET https://api.xguardgate.com/v1/egress/providers","public_key":"https://api.xguardgate.com/.well-known/xguard-egress-key.json","credits_per_authorized_egress_attempt":1,"providers_supported":["openai","anthropic","github","stripe","slack","notion","cloudflare","gemini","custom"],"controls":["secret never returned to the agent","credential encrypted at rest with per-record AES-GCM key wrapped by XGuard RSA-OAEP authority","short-lived scoped capability","exact HTTPS host allowlist","path-prefix allowlist","HTTP method allowlist","billing before credential release and network egress","manual redirect handling prevents credential forwarding to another host","private/local targets blocked","automatic Idempotency-Key for unsafe methods","no automatic retry after network ambiguity"],"boundary":"Once an operator keeps upstream credentials only in XGuard and gives agents XGuard capabilities instead, secret-backed calls must pass through the egress gateway unless the operator deliberately re-distributes those credentials elsewhere."}