The consent layer for the password era

Lend access, not passwords.

Tesska keeps every secret in the vault and hands out short-lived, scoped, revocable tokens instead — to teammates, contractors, scripts, and AI agents.

Zero-knowledge optionalSOC 2 in progress
CONSENT BROKERLive
Stripe · Production
never leaves the vault
brokers consent ↓
Billing Bot AI agent
tsk_live_3f9a · ttl 6h
charges:readrefunds:create+ revoke anytime
Built forAI agentsMSPs & agenciesDev platformsShared-account teamsContractors
HOW IT WORKS

Three steps. The password never moves.

01

Store the credential

Drop in a password or key. The server only ever holds ciphertext — envelope encryption, or zero-knowledge so even we can’t read it.

02

Grant scoped access

Authorize a project, person, or agent. Narrow the scope, set a TTL, flip “callable” on. They get a token — never the secret.

03

Approve & revoke

Sensitive calls ping your phone for approval. Every call is logged. Kill any grant in one click — instantly, everywhere.

WHO IT'S FOR

Lend access where passwords used to leak.

THE BIGGEST OPENING

Give AI agents access — not your real passwords.

Let an assistant log in and act as the user with a scoped, approvable, revocable token. The secret stays in the vault; every call is logged.

scopedapprovablerevocable

MSPs & agencies

Manage a wall of client accounts. Grant per-project, revoke on offboarding, audit who did what.

Dev platforms

Let users safely connect third-party accounts without handing you raw keys.

Shared-account teams

Stop pasting the team password in chat. Broker consent and see every use.

Contractors & temps

Time-boxed, scope-limited access that expires on its own. No “please remove me” later.

Everything that ships with Tesska

Every capability below is in the product — no add-on tiers, no hidden modules.

  • Envelope-encrypted managed credentials (A-mode)
  • Zero-knowledge vault — unlocked only in your browser (B-mode)
  • Per-call owner approval with end-to-end encrypted delivery
  • Mobile approvals: installable app with push notifications
  • M-of-N multi-sig & seed-phrase protection (coming soon)
  • Scoped short-lived tokens with TTL caps & rate limits
  • Six OAuth adapters: GitHub, Google, Apple, Microsoft, GitLab, Slack
  • Password credentials for any website
  • Full audit log with anomaly reports & push alerts
  • AI copilot: conversational grants & security checkup
  • Connect Tesska OAuth for platforms + developer portal
  • One-click freeze, revoke & connection recall
SECURITY MODEL

The consent layer for the password era.

Stop sharing accounts by sending the password. Grant consent instead — who can use it, for how long, to do exactly what.

Zero leak

The secret never leaves the vault. Optional zero-knowledge means the server can’t read plaintext — ever.

Revoke + audit

One-click kill switch on every grant, and a full trail of who called which credential, when.

Mobile approval

Sensitive operations push to the owner’s phone. Unlock locally, approve or reject in a tap.

M-of-N multi-sig

Shamir secret sharing splits the key into N shares — any M reconstruct it, and the server never holds the complete key. Built for seed phrases; shipping soon.

Least privilege

Every grant is scoped: token TTL caps, per-minute rate limits and platform allowlists shrink the blast radius of any single key.

AI copilot

Ask it to review grants, run a security checkup or freeze a credential — every change goes through a confirmation card first.

Embed “Connect Tesska”

OAuth-style: your users authorize in one click and your platform gets a revocable, scope-limited per-user token — no key-pasting.

Connect Tesska
PRICING

Start free. Pay as you delegate.

Starter
$0/mo
Start free
Up to 25 credentials
5 active grants
Envelope encryption
7-day audit log
TeamPopular
$49/mo
Start 14-day trial
Unlimited credentials
Zero-knowledge vault
Mobile approvals + Stuck queue
Self-serve token center
Roles & SSO
Scale
Custom
Talk to us
Connect Tesska (OAuth) embeds
AI-agent access at scale
Pluggable backends · 1Password / Bitwarden
SLA + dedicated support

Turn “who can use my account” into a switch.

Lend access, not passwords — you never hand over your real password.