Too much permission
A provider key can keep spending and calling long after the job should be done.
The control layer for agentic work
Give every AI agent a key with a finish line—before it starts working.
Not your provider credential.
Not open-ended permission.
The uncomfortable default
A provider key can keep spending and calling long after the job should be done.
The credential cannot tell a prototype, contractor, production agent, or one-off task apart.
When something goes wrong, teams rotate the shared secret and disrupt everything attached to it.
A smaller permission surface
Don’t hand the agent your master key.
Hand it permission to finish one job.
Broad · shared · open-ended
Bounded · disposable · revocable
The shortest path to control
Save your existing AI provider credentials as encrypted connections.
Issue a Till key with the exact limits the work deserves.
Point the workload at Till. Requests route to your configured provider.
Later requests are rejected before another provider call is dispatched.
The finish line is yours
Every key has a required request ceiling. Add the other boundaries the work calls for.
A fixed number of provider calls.
Designed for a smaller blast radius
Bring the providers you already use
Automatic keys can route among the connections configured for your account. Till tracks activations and provider-reported usage through one surface.
250+ priced provider/model identifiers for estimated-spend enforcement. Provider usage remains billed by your provider.
Straightforward beta pricing
Provider usage is billed separately through your own provider accounts. Till is currently onboarding approved beta customers.
Prove the workflow.
Run active agent workflows.
Standardize across more work.
Founding customers who joined before July 18, 2026 retain documented price protection. See full pricing terms.
The job has an end. Its permission should too.