Keys in plain text
API and MCP keys end up in config files on laptops, in chat history, and in notes apps. Unencrypted, and invisible to IT.
Toolshed makes AI adoption safe for organisations of 10–100 people — and for public-sector teams held to even higher standards. Your team works with Claude, Codex, or Cursor on real work data, always within their own roles and permissions, without ever seeing an API key.
https://toolshed.aqqo.io/mcp
78%
of AI users bring their own AI tools to work — 80% at smaller organisations
Microsoft & LinkedIn Work Trend Index
28.65M
keys and secrets leaked publicly on GitHub in 2025, with AI-service leaks up 81%
GitGuardian, State of Secrets Sprawl 2026
±70%
of leaked credentials are still valid years later — nobody revokes them
GitGuardian, State of Secrets Sprawl 2026
The problem
Employees don't wait for policy. The most resourceful ones connect AI tools to mail, files, and databases themselves — and this is what “I'll just set it up myself” actually looks like.
API and MCP keys end up in config files on laptops, in chat history, and in notes apps. Unencrypted, and invisible to IT.
The key belongs to a person, not to the organisation. Nobody else can see it, rotate it, or revoke it.
An admin token “because then it works”. The AI tool can suddenly do more than the employee was ever allowed to.
Offboarding checklists cover accounts, not stray keys. The backdoor stays open indefinitely.
Banning AI doesn't work — usage goes underground and the risk grows. The real question is not whether your team connects AI to your systems, but whether you decide how.
How it works
Employees sign in with their existing work account and reach every approved system through the same MCP URL.
Team MCP access
Choose which integrations this team can use.
Sirportly
6 tools
MariaDB
3 tools
Docs
2 tools
Every request routes through Toolshed, where organisation and team rules decide what each user can reach.
Codex
Use the same approved tools
Claude
Use the same approved tools
Cursor
Use the same approved tools
Codex, Claude, Cursor, and other MCP-compatible apps all use the same governed toolset.
Why Toolshed
1
2
3
Identity & access
AI access should follow your directory — not live next to it in a separate admin.
SSO through your existing tenant via OpenID Connect. Your MFA and Conditional Access policies apply automatically to every sign-in.
Map team access to the Microsoft Entra security groups your Conditional Access policies already govern — so AI permissions follow your directory. A must-have we hear from government IT.
Google SSO with Google Groups as the access-group equivalent, for organisations outside the Microsoft stack.
The most tangible proof
Every AI connection runs through your identity provider and user-bound tokens. The offboarding step you already have — disabling the account — now closes every AI connection too. One action, nothing left behind.
Without Toolshed
Stray keys on personal accounts survive every offboarding checklist. Nobody knows they exist, so nobody revokes them. An ex-employee's access never expires.
With Toolshed
Disable the SSO account and every AI connection closes instantly — keys stay in the encrypted vault, tokens are user-bound, and the usage dashboard proves it.
See in 30 minutes how your team works safely with Claude, Codex, or Cursor on real work data — within the roles and permissions you already manage.
Aqqo is ISO 27001 certified