Google launches Credentials API to keep agent sandbox secrets off-limits
_philschmid · x · 2026-09-28
Phil Schmid highlights a common agent security risk: API keys passed as regular env vars can be read — and leaked — by any dependency inside an agent's sandbox.
The new Credentials API for Gemini Managed Agents keeps secrets secure and injects them on the wire only for trusted domains, so sandboxed code never touches raw tokens. It works for environment variables, CLIs, and MCP servers.
More from coding & agent
- Agentic commerce is still in its VHS/Betamax phase — builders are openly collaborating — jeff_weinstein · 2026-09-28
- Codex Computer Use 'Neutered' by Guardrails; Opus 5.5 Does the Job on First Try — iannuttall · 2026-09-28
- Local AI lemon inspection on a MacBook catches 4 defects out of 44 — iamrobotbear · 2026-09-28
- OpenAI co-founder Alex Atallah: a single chief-of-staff agent sacrifices your understanding everywhere — jeff_weinstein · 2026-09-28
- System 1 vs System 2 agent harnesses: bounded judgment vs open-ended planning, explained — blaizedsouza · 2026-09-28
- Stanford puts all 9 lectures of CS329A: Self-Improving AI Agents online for free — ghumare64 · 2026-09-28