Skip to content
View original post on X: Philipp Schmid· 36/100AI score36/100

Gemini Managed Agents' Credentials API keeps secrets out of sandboxed code

AISummary

Google's Credentials API for Gemini Managed Agents injects secrets on the wire only for trusted domains, so sandboxed code cannot read raw tokens. It supports environment variables, CLIs, and MCP servers. Passing API keys as plain environment variables lets any sandboxed dependency read and potentially leak them.

Post on XView on X
@_philschmid

Passing API keys or secrets as normal env lets any dependency in your agent's sandbox read and potentially leak them.

The Credentials API for Gemini Managed Agents keeps secrets secure and injects them on the wire only for trusted domains, so sandboxed code can't access raw tokens. Works for environment variables, CLIs and MCP Server.

Learn more 👇

Philipp Schmid@_philschmid
https://x.com/i/article/2104585345740210176
View quoted post on X

Source: Philipp Schmid · x.comPublished · added here