Gemini Credentials API deep dive: zero plaintext secrets and egress-proxy exfiltration blocking
_philschmid · x · 2026-09-18
Phil Schmid details the new Gemini Credentials API: register secrets once via credentials.create() (bearertoken, environmentvariable, or oauth2 with auto-refresh/rotation). Zero plaintext exposure — secrets never enter model context, stdout, or memory; agents only see placeholders like GEMINICREDslack-bot-token. An egress proxy swaps in real tokens only for allowlisted trusteddomains, returning 403 to any other host to block exfiltration. Credentials can bind directly to remote mcpserver tools or sandbox env vars.
Related event: Gemini Managed Agents Cut Costs 30%, Add Files and Credentials APIs(5 posts)→
More from coding & agent
- Sim Search lets agents build a knowledge graph across 1,000+ tool integrations — JafarNajafov · 2026-09-18
- Ethan Mollick rebuilds Umberto Eco's 33,000-book library in 3D with Claude Projects — emollick · 2026-09-18
- Cua and typesafeai launch jev-use dev preview, claiming fast computer use is solved — TianbaoX · 2026-09-18
- Developer demos auto-navigating slides driven by the Jev computer-use model — threepointone · 2026-09-18
- DeepSeek Harness ships v0.1.6-alpha.2 pre-release as the app takes shape — teortaxesTex · 2026-09-18
- Self-Proclaimed ChatGPT Co-Inventor Launches Jev, Claims 200x Speed at 1/400 Cost — iamrobotbear · 2026-09-18