Blog
Notes on credential brokering, zero-knowledge encryption, and keeping secrets away from the agents that use them.
Your agent acts as your users. Their credentials shouldn't live in your database.
Every agent platform that connects a user's Gmail or Resend account ends up holding that user's credentials. Vault is the drop-in that lets you stop: captured on a hosted page, encrypted to an executor in your own Cloudflare account, applied at the moment of use, never seen by your backend, your agent, or seekrit.
read →VaultTwo breaches and still no credential: how Vault's custody works
A breach of seekrit yields ciphertext nobody can open. A breach of your backend yields a key that cannot release anything. Why both hold, where each guarantee comes from, and the design rule every boundary follows.
read →VaultThe hard part of "connect your Gmail" is the refresh token
The consent screen takes an afternoon. Keeping a user's OAuth grant alive for a year — refresh races, single-use refresh tokens, a Worker that dies mid-exchange — is where agent platforms lose months. How the Vault executor handles it, and why your code never sees a token.
read →VaultWhen the site has no API, the signed-in session is the credential
Half of what a personal agent needs to do happens on sites with no API. Vault treats the signed-in browser session as a credential: captured when the person signs in on their own phone, encrypted to your executor, restored into a fenced browser your agent drives, and saved back when it is done.
read →VaultWhat you would have to build to hold your users' credentials yourself
An inventory of the system behind 'Connect your account' on an agent platform: capture, consent, key custody, OAuth lifecycle, revocation, end-user controls, webhooks, audit, and the guardrails that keep a prompt-injected agent from walking off with a token. Then the five-step version.
read →IntegrationsOne token for your Cloudflare Python Worker's secrets
Python Workers are generally available. Resolve a Seekrit environment from one token binding with native async fetch, decrypt inside the Worker, and read rotated credentials without an application redeploy.
read →IncidentsCrowdSec's stolen token: when source code becomes a credential inventory
CrowdSec's September disclosure traces a May repository theft to a compromised developer token. What keeping secrets out of Git, separating machine identities, and verifying revocation can contain — and what still depends on GitHub access controls.
read →IncidentsGrok Build's repository uploads: keep credentials out of what agents can copy
A July wire-level investigation found repository history and test secrets leaving a coding agent through separate upload paths. How to keep real credentials outside the workspace, and where runtime injection needs a stronger boundary.
read →IncidentsClinejection: keep the issue triager away from release credentials
An AI triage workflow, shared CI caches, and an exposed publishing token made a dangerous combination. Lessons from the February disclosure and unauthorized Cline CLI release, with a scoped Seekrit broker for the agent's own API key.
read →AgentsSecuring AI agents on Cloudflare Workers
An Agents SDK agent reads its keys from env, one wrangler secret put at a time, and every tool's key sits beside the model key. Four ways to give it credentials: sync into bindings, resolve from one token, hold a placeholder, or keep the key outside the sandbox with an outbound handler.
read →AgentsSecuring AI agents on Vercel
A Vercel Function has no process to wrap and reads its environment from Vercel's copy. How to run an agent with one credential in the project instead of every key, keep tool keys out of traces, let the browser hold a placeholder, and run agent-generated code in a sandbox that never sees a key.
read →FrameworksManaging secrets in LangChain agents
LangChain 1.x agents in Python and JavaScript read provider keys from the environment, and LangSmith adds a second one. Four shapes for getting credentials into create_agent and createAgent, from wrapping the process to middleware that lets one tool spend a key the others cannot.
read →How-toSecuring n8n AI agent workflows
Self-hosted n8n holds every credential your workflows use, encrypted with one key, and an AI Agent node acts on whatever it reads. How to run n8n with no secrets in the compose file, keep the encryption key off the host, and give the agent's tools placeholders instead of keys.
read →How-toSecuring Open WebUI and Ollama deployments
Open WebUI is where a self-hosted chat stack collects its keys: OpenAI-compatible providers, web search, tool servers, the JWT signing secret. How to run it with one credential in the compose file, put a proxy between it and every paid API, and stop admin-panel edits from bypassing that proxy.
read →FrameworksManaging secrets in Google ADK agents
ADK puts GOOGLE_API_KEY in a .env beside agent.py, and every tool's key ends up in the same file. How to wrap adk web, resolve in code, deploy to Cloud Run with one variable, and give tools placeholders instead of keys.
read →How-toSecrets in durable agent workflows: Inngest and Trigger.dev
Durable execution stores step outputs and payloads so a run can resume, which means anything a step returns is written to the platform, including a resolved secret. How to give Inngest and Trigger.dev agents credentials that never appear in a payload, an output, or a checkpoint.
read →How-toSecuring an AI agent in Supabase Edge Functions
Every Edge Function gets the service role key injected by default, and an agent in one holds it alongside every provider key set with supabase secrets set. How to run an agent on Supabase with one secret, placeholders for tool keys, and the database reached as the user rather than as the service role.
read →How-toSecuring self-hosted agent builders: Dify, Langflow, and Flowise
Visual agent builders hold every provider key their flows use, encrypted with one key from the compose file, and an exposed Langflow was enough for unauthenticated remote code execution. How to run them with no secrets in the compose file and route provider calls through a proxy that holds the keys instead.
read →AgentsDeploying AI agents without a secrets plan is how keys leak
Agent launch plans cover the model, the tools, the evals, and the cost. Credentials go in a .env file during the prototype and stay there. How an agent differs from a service, five ways standing keys go wrong, and how to deploy one that never holds a credential.
read →ArchitectureSecrets at the edge: why a decrypting server can't scale the way a ciphertext-only one does
Every workload fetches its secrets at boot. If the server decrypts them, that response can't be cached and always travels to one region. If the server holds only ciphertext, the hot path can run at the edge. How that decision sets the ceiling for Infisical, Doppler, and seekrit, and what the zero-knowledge version is like to use.
read →PatternsEvery place a secret ends up, and what each one costs you
Nobody decides to have a password in eleven places; it happens one reasonable step at a time. An inventory of where plaintext comes to rest, from .env files to Terraform state to an agent's context window, what each exposes, and the one pattern underneath all of it.
read →FrameworksManaging secrets in Ruby on Rails without dotenv or credentials.yml.enc
Rails gives you encrypted credentials and RAILS_MASTER_KEY, most teams add dotenv-rails on top, and the two drift. How to load ENV for Puma, Sidekiq, rake tasks, and Kamal from one encrypted store, with a Railtie or a wrapper command.
read →FrameworksVite environment variables: keeping API keys out of the bundle
Vite compiles every VITE_-prefixed variable into the JavaScript it serves. Why a .env file is the wrong place to draw that line, and how to load secrets into vite.config.ts, SSR, and Vitest without one.
read →How-toDocker Compose secrets without a .env file
Where Compose puts the values from env_file and environment, why docker compose config and docker inspect print them, and three ways to give containers their credentials at start time with no plaintext file on the host.
read →How-toKeeping secrets out of Terraform state
Terraform writes every attribute it manages into terraform.tfstate, sensitive or not. How write-only arguments and ephemeral resources (Terraform 1.11+) keep database passwords and API keys out of state and plan files.
read →How-toSyncing secrets into Kubernetes with External Secrets Operator
A step-by-step External Secrets Operator tutorial: install ESO, point a SecretStore at a secrets manager, write an ExternalSecret, and consume the resulting Secret with envFrom. Plus etcd, refresh timing, and outages.
read →How-toManaging secrets in a Python app without a .env file
Where python-dotenv and pydantic-settings fall short, and how to load API keys and database URLs into a Python process at startup from an encrypted store. Covers scripts, FastAPI, Django, pytest, Docker, and notebooks.
read →How-toSyncing environment variables to Vercel from one source of truth
Vercel injects env vars from its own copy at build and run time, so a secrets manager has to push to it. How to connect a project, bind an environment per deployment target, handle preview branches, and what Vercel can see.
read →FrameworksManaging secrets in Spin applications
Three ways to get credentials into a Spin app, what each one costs, and the WASI version mismatch that makes the obvious approach fail at startup with an error that names neither Spin nor seekrit.
read →PatternsManaging secrets in wasmCloud
wasmCloud has a pluggable secrets API, which makes it the rare WebAssembly host where the platform can refuse to spread a plaintext. What that buys you, what the nkeys trust model actually proves, and the two setup steps that fail silently.
read →SecurityNeocloud security is now an API key problem
A summer of neocloud security research found cross-tenant RCE, container escapes, and a monitoring stack that leaked every tenant at once. If you rent GPUs, the question is no longer whether you handled your keys well — it's what happens to them when the provider's isolation fails.
read →PatternsYour agent moved to OpenAI. Your keys don't have to.
The Agents API runs the loop for you. OpenAI vaults can keep keys out of hosted sandbox code; a seekrit proxy can also keep the real values on infrastructure you control.
read →PatternsA checkpoint is a backup of your API keys
Sandboxes taught us that secrets inside them are disposable, because the sandbox was. Fly.io Sprites keep their filesystem and snapshot it — so a rotated key comes back on restore, and a Sprite you provisioned in January never hears about February's rotation.
read →PatternsYour GPU node lives for an hour. Your API key lives for a year.
Renting compute by the hour inverts the usual lifetimes: the machine is disposable and the credential isn't. The only thing you can put on an SF Compute node before it boots is a cloud-init script the provider keeps — so make it carry one credential, not twenty.
read →SecurityYour stolen API key is someone else's compute budget
Anthropic's September 2026 threat report describes attackers stealing AI credentials to run their attacks on the victim's bill, under the victim's name. Every one of those keys was reusable plaintext sitting somewhere a process could read it.
read →SecurityAttackers test every key they steal. Give them one that pages you.
Three separate groups in Anthropic's September 2026 threat report validate harvested credentials in bulk before using them. That validation step is the one moment they touch your infrastructure from the outside — and the only free detection you get.
read →PatternsThree hours from one developer token to full cloud admin
Anthropic's September 2026 threat report measures modern intrusions in hours. Most credential lifetimes are still measured in quarters. Rotating faster doesn't close that gap — not issuing long-lived credentials does.
read →AgentsHow an AI agent can set up its own secrets manager
Written for the agent doing the work. Connect to mcp.seekrit.dev with no credential, call signup once, store credentials, run commands with them injected, and hand the org to a human before you stop.
read →SecuritySecrets in GitHub Actions when an agent writes your workflows
Coding agents write workflow YAML from examples, and the common examples expose secrets to pull requests. The two mistakes to check for, and a setup where the runner decrypts a scoped set and nothing else holds it.
read →FrameworksManaging secrets in the OpenAI Agents SDK
Run an OpenAI Agents SDK agent on injected secrets or behind a credential proxy with no code change, and why traces disappear the moment you add the proxy.
read →FrameworksManaging secrets in Pydantic AI agents
Pydantic AI's deps_type and RunContext are a per-run credential seam. How to resolve a tenant's secrets per run, hold a placeholder instead of a key, and let one tool use a Stripe key while the others cannot.
read →FrameworksManaging secrets in Mastra agents
Five ways to get credentials into a Mastra agent: wrap mastra dev, resolve in code, hold a placeholder, resolve a different key per tenant from requestContext, and scope a Stripe key to one createTool executor.
read →FrameworksManaging secrets in CrewAI crews
How to get API keys into a CrewAI crew without a .env file, and how to stop every agent in the crew from being able to use every tool's credential. Three setups, one command each.
read →SecurityShould your coding agent be able to read your .env?
Claude Code, Cursor, and Copilot all work in a directory that probably holds production credentials in plaintext. How to block the reads, why blocking isn't enough, and the setup where there's nothing to block.
read →How-toPassing secrets into a sandbox without baking them into the image
Every credential baked into an image outlives the build. Injecting at start time in Docker, E2B, Modal, Daytona, and Vercel Sandbox — and keeping the key out of the sandbox entirely when the code inside is the threat.
read →FrameworksManaging secrets in LangGraph agents
Four shapes for getting credentials into a LangGraph agent, from wrapping the process to scoping a Stripe key to a single tool call — and why CVE-2025-68664 argues for the stronger two.
read →How-toHow to give an AI agent an API key without giving it the API key
Five levels of keeping a credential away from an agent — from spawn-time injection to a full egress proxy with the sandbox inside it — and a table for picking the one your setup needs.
read →SecurityYour MCP config is a plaintext secrets file
claude_desktop_config.json, .mcp.json, and most server READMEs tell you to paste API keys into an env block — a file your agent reads and your team commits. Make it name credentials instead of holding them.
read →WorkflowGetting secrets into a Jupyter notebook without leaking them
Every common way of getting a credential into a notebook either writes it into the .ipynb or only works on one platform. One call that works the same in JupyterLab, papermill, Voilà, and a container.
read →SecurityYour coding agent will hand over your API key if asked nicely
An instruction in a pull-request title was enough to make three major coding agents post their own credentials to the thread. The fix isn't a better agent — it's not giving the agent a credential at all.
read →PatternsCredential brokering for AI agents, without running a vault
What a credential broker is, the four properties that separate one from an open proxy, and the question most comparisons skip: after the broker, who can still read the key?
read →TrustWhat happens to your secrets if seekrit disappears
Every secrets manager is a single point of failure for everything you deploy. Exactly what you keep if we shut down — the signed archive, the offline decryptor, the custodian quorum — and where the answer stops.
read →