Gemini Credentials API deep dive: zero plaintext secrets and egress-proxy exfiltration blocking

_philschmid · x · 2026-09-18

Phil Schmid details the new Gemini Credentials API: register secrets once via credentials.create() (bearertoken, environmentvariable, or oauth2 with auto-refresh/rotation). Zero plaintext exposure — secrets never enter model context, stdout, or memory; agents only see placeholders like GEMINICREDslack-bot-token. An egress proxy swaps in real tokens only for allowlisted trusteddomains, returning 403 to any other host to block exfiltration. Credentials can bind directly to remote mcpserver tools or sandbox env vars.

Related event: Gemini Managed Agents Cut Costs 30%, Add Files and Credentials APIs(5 posts)→

Original post →

More from coding & agent

coding & agent channel →