Google launches Credentials API to keep agent sandbox secrets off-limits

_philschmid · x · 2026-09-28

Phil Schmid highlights a common agent security risk: API keys passed as regular env vars can be read — and leaked — by any dependency inside an agent's sandbox.

The new Credentials API for Gemini Managed Agents keeps secrets secure and injects them on the wire only for trusted domains, so sandboxed code never touches raw tokens. It works for environment variables, CLIs, and MCP servers.

Original post →

More from coding & agent

coding & agent channel →