The end of credential sprawl for agents
Vercel Connect gives agents runtime-minted, task-scoped credentials instead of stored provider tokens, adding per-user identity, revocation, audit logs, and usage visibility.
Vercel Connect is now **generally available**, with **100+ preset connectors**. Deployments authenticate through OIDC, request short-lived credentials at runtime, and can scope access to a task, application, or named user.
Replace standing agent secrets with per-request credentials where provider support is granular enough. RBAC, audit logs, usage visibility, per-environment attachment, and one-command revocation make access easier to constrain and inspect.
Vercel Connect is now **generally available**, with **100+ preset connectors**. Deployments authenticate through OIDC, request short-lived credentials at runtime, and can scope access to a task, application, or named user. Replace standing agent secrets with per-request credentials where provider support is granular enough. RBAC, audit logs, usage visibility, per-environment attachment, and one-command revocation make access easier to constrain and inspect. Scope precision still depends on each provider. Pricing is request-based: Hobby includes **500 token requests and 1,000 triggers** monthly; revised beta-user billing begins **September 25, 2026**.
Connect moves agent access from stored, standing secrets toward short-lived, runtime-issued credentials with centralized attachment, observation, and revocation. Compared with adjacent controls, it strengthens credential lifecycle and attribution rather than execution isolation or data residency. Its least-privilege benefit remains provider-dependent, and request-based pricing makes credential issuance itself an operational cost to monitor.