← Fort Tools

Fort Card

Let your AI and your apps use your credentials — post, send, pay — without ever holding the actual key. Cards, not keys.

The problem it solves

Every tool and every AI assistant wants you to paste in an API key or a password so it can act for you. That's exactly how keys leak — copied into configs, prompts, screenshots, a dozen apps you forgot about. Fort Card means you never hand the key over in the first place.

What it is

Your credentials live in a wallet you own. When an agent needs one, it doesn't get the key — it spends a card. The wallet injects the real key on its own side, makes the call, and hands back only the result. The agent never sees the secret.

Key never exposedYou approve from your phoneScoped to one hostCharge-cappedFreezable in a tap

How it works

  1. Store a key once in your wallet. It never leaves.
  2. An agent asks to use it — you approve (or deny) from your phone. It can never issue itself a card.
  3. The card spends the key server-side — locked to one host, capped, freezable any time. The agent only gets the result, never the key.
The whole idea in one line: permission flows one way — from you.