Credential security for AI agents
How to keep API keys, cloud credentials, and database passwords out of autonomous agents, MCP servers, and CI, without slowing them down.
Secrets management for AI agents: a practical guide
AI agents break the assumptions secret managers were built on. A practical guide to keeping API keys, database passwords, and cloud credentials out of autonomous agents built with LangChain, CrewAI, MCP, and others.
Read →How to give an AI agent AWS access without long-lived keys
Don't put AWS access keys in your agent. Use workload identity (OIDC) so the agent proves who it is and the broker assumes a role with short-lived STS credentials, scoped to one operation.
Read →How prompt injection steals API keys, and how to stop it
Prompt injection turns untrusted content into instructions your agent follows. If a provider key is in the agent's reach, injection can exfiltrate or misuse it. The durable fix is to keep the key out of the agent entirely.
Read →Are API keys in environment variables safe for AI agents?
Environment variables are fine for ordinary services but a poor fit for AI agents: once the agent process can read the key, prompt injection, logs, and memory can all reach it. What to do instead.
Read →Why AI agents should never hold long-lived secrets
Long-lived API keys in an AI agent's context are a standing liability: prompt injection, logs, and model memory all leak them. Scoped, short-lived credentials through a broker shrink the blast radius.
Read →Zero-access custody, explained
Zero-access means the vendor is architecturally incapable of decrypting your credentials, not merely promising not to. Here is how sealed-box encryption and a customer-held key make that true.
Read →Securing MCP servers' credentials
MCP servers hold the provider tokens your agent's tools use, which puts secrets one injection away from the model. Broker the operations instead, so the MCP layer carries no decryptable credential.
Read →Scoped, short-lived credentials for AWS, GitHub, and Postgres
Instead of a standing API key, mint a credential scoped to one operation that expires in minutes. How PastKeys brokers short-lived access to AWS, GitHub, and Postgres for AI agents.
Read →Stop handing agents long-lived secrets.Free for 3 agents. No card required.
Start freeRead the docs