Obol

Automation & AgentsAI AgentsContact for Pricing
0Popularity
Obol featured image

About Obol

Obol provides a single API and control plane for agent execution that authenticates, scopes, authorizes, and logs every model and tool call. It replaces scattered vendor credentials with a single Obol key that agents hold, while vaulting actual provider keys and injecting them only on the outbound request. The system enforces Cedar policies that can restrict actions by principal, resource, environment, and argument values, and writes detailed receipts for each call. Obol supports OpenAI-compatible chat completions and streamable MCP over HTTP, allowing existing applications to point to a single gateway URL without code changes. Usage is metered and budgets can fail closed across both model and tool spend. The gateway caches policy decisions and revokes credentials within 60 seconds, while streaming responses back to the client without database writes on the hot path.

Key features

  • OpenAI-compatible chat completions endpoint
  • Streamable MCP over HTTP
  • Cedar policy engine for authorization
  • Virtual key system with 60-second revocation
  • Budget and rate limit enforcement
  • Receipt logging for all calls
  • In-process credential injection
  • Workspace-based policy and configuration

Use cases

  • Enforcing spending limits for support agents
  • Restricting destructive actions to approved users
  • Centralizing audit trails for agent tool calls

Pros

  • Single API endpoint for multiple model and tool providers
  • Vaulted credentials injected only on outbound requests
  • Fine-grained Cedar policy enforcement including argument-level checks
  • Unified metering and budget controls across model and tool spend
  • Receipts written for every call with decision details

Cons

  • Requires design-partner or paid access
  • No pricing information publicly available
  • Policy authoring requires Cedar language knowledge

Frequently asked questions about Obol

What does Obol do?

Obol provides a single API and control plane for agent execution that authenticates, scopes, authorizes, and logs every model and tool call. It centralizes credential management by replacing scattered vendor keys with a single Obol key, while vaulting actual provider credentials and injecting them only during outbound requests.

Who is Obol designed for?

Obol is designed for teams and applications using AI agents that interact with multiple vendors such as Stripe, GitHub, OpenAI, or Anthropic. It suits organizations needing centralized policy enforcement, auditability, and credential security for agent workflows.

How does Obol handle pricing and billing?

Obol meters usage for both model and tool spend, with budgets that can fail closed across both categories. The vendor bills remain with the respective providers, while Obol provides a unified usage record and policy enforcement layer.

What integrations does Obol support?

Obol supports OpenAI-compatible chat completions and streamable MCP over HTTP. It integrates with vendors like Stripe, GitHub, OpenAI, and Anthropic, as well as any MCP-compatible tool or service.

Can Obol be self-hosted?

Yes, Obol offers a self-hosting option via Docker Compose, allowing organizations to deploy the control plane and gateway on their own infrastructure for enhanced control and data residency.

How do I get started with Obol?

To get started, request access via the Obol website, then configure your application to point to the Obol gateway URL instead of direct vendor endpoints. The agent uses an Obol key for authentication, while vendor credentials remain vaulted and injected only on outbound requests.

Obol compared

Reviews