The Model Context Protocol lets an agent call tools, and those tools usually need provider credentials: a GitHub token to open a pull request, a Cloudflare token to change DNS, a database URL to run a query. The common pattern puts those secrets in the MCP server's environment, which means they sit one prompt injection away from the model.
Where MCP leaks credentials
- Tokens in the MCP server's environment. Most MCP servers read a provider key from an env var and use it directly. Anything that can drive the tool can drive the key's full scope.
- Injection reaches the tools. An agent that reads untrusted content can be told to call a tool with attacker-chosen arguments. If the tool wraps a broadly scoped token, the attacker now has that reach.
- Error surfaces and logs. MCP servers log tool calls and errors. A misconfigured or verbose server can echo a token into logs or back to the model.
Broker the operation, keep the secret out of MCP
The fix is the same principle PastKeys applies everywhere: the tool should request an authorized operation, not hold the credential. PastKeys ships an MCP server (broker mcp) that exposes pastkeys_authorize and pastkeys_execute as tools. The agent calls them with an operation to perform; the broker checks a default-deny policy, performs the operation with a credential it holds, and returns the result.
With that in place:
- The MCP layer carries no provider token the model can leak, only the broker endpoint and the agent's own identity.
- Provider tokens stay sealed inside the broker you run, which the hosted control plane cannot decrypt.
- An injected tool call can only trigger operations the policy already allows, and each one is audited.
Practical shape
Run the broker where your MCP server runs, seal the provider tokens to it, and write a policy naming the agent and the operations it may perform. Point the agent at the PastKeys MCP server. The agent asks to "open a pull request on repo X" or "read these DNS records," and the broker does it without ever exposing the token.
See getting started for setup, and why agents should not hold long-lived secrets for the reasoning.