seekrit
▓▒░ writing

Blog

Notes on credential brokering, zero-knowledge encryption, and keeping secrets away from the agents that use them.

Vault

Your agent acts as your users. Their credentials shouldn't live in your database.

Every agent platform that connects a user's Gmail or Resend account ends up holding that user's credentials. Vault is the drop-in that lets you stop: captured on a hosted page, encrypted to an executor in your own Cloudflare account, applied at the moment of use, never seen by your backend, your agent, or seekrit.

read →
Vault

Two breaches and still no credential: how Vault's custody works

A breach of seekrit yields ciphertext nobody can open. A breach of your backend yields a key that cannot release anything. Why both hold, where each guarantee comes from, and the design rule every boundary follows.

read →
Vault

The hard part of "connect your Gmail" is the refresh token

The consent screen takes an afternoon. Keeping a user's OAuth grant alive for a year — refresh races, single-use refresh tokens, a Worker that dies mid-exchange — is where agent platforms lose months. How the Vault executor handles it, and why your code never sees a token.

read →
Vault

When the site has no API, the signed-in session is the credential

Half of what a personal agent needs to do happens on sites with no API. Vault treats the signed-in browser session as a credential: captured when the person signs in on their own phone, encrypted to your executor, restored into a fenced browser your agent drives, and saved back when it is done.

read →
Vault

What you would have to build to hold your users' credentials yourself

An inventory of the system behind 'Connect your account' on an agent platform: capture, consent, key custody, OAuth lifecycle, revocation, end-user controls, webhooks, audit, and the guardrails that keep a prompt-injected agent from walking off with a token. Then the five-step version.

read →
Integrations

One token for your Cloudflare Python Worker's secrets

Python Workers are generally available. Resolve a Seekrit environment from one token binding with native async fetch, decrypt inside the Worker, and read rotated credentials without an application redeploy.

read →
Incidents

CrowdSec's stolen token: when source code becomes a credential inventory

CrowdSec's September disclosure traces a May repository theft to a compromised developer token. What keeping secrets out of Git, separating machine identities, and verifying revocation can contain — and what still depends on GitHub access controls.

read →
Incidents

Grok Build's repository uploads: keep credentials out of what agents can copy

A July wire-level investigation found repository history and test secrets leaving a coding agent through separate upload paths. How to keep real credentials outside the workspace, and where runtime injection needs a stronger boundary.

read →
Incidents

Clinejection: keep the issue triager away from release credentials

An AI triage workflow, shared CI caches, and an exposed publishing token made a dangerous combination. Lessons from the February disclosure and unauthorized Cline CLI release, with a scoped Seekrit broker for the agent's own API key.

read →
Agents

Securing AI agents on Cloudflare Workers

An Agents SDK agent reads its keys from env, one wrangler secret put at a time, and every tool's key sits beside the model key. Four ways to give it credentials: sync into bindings, resolve from one token, hold a placeholder, or keep the key outside the sandbox with an outbound handler.

read →
Agents

Securing AI agents on Vercel

A Vercel Function has no process to wrap and reads its environment from Vercel's copy. How to run an agent with one credential in the project instead of every key, keep tool keys out of traces, let the browser hold a placeholder, and run agent-generated code in a sandbox that never sees a key.

read →
Frameworks

Managing secrets in LangChain agents

LangChain 1.x agents in Python and JavaScript read provider keys from the environment, and LangSmith adds a second one. Four shapes for getting credentials into create_agent and createAgent, from wrapping the process to middleware that lets one tool spend a key the others cannot.

read →
How-to

Securing n8n AI agent workflows

Self-hosted n8n holds every credential your workflows use, encrypted with one key, and an AI Agent node acts on whatever it reads. How to run n8n with no secrets in the compose file, keep the encryption key off the host, and give the agent's tools placeholders instead of keys.

read →
How-to

Securing Open WebUI and Ollama deployments

Open WebUI is where a self-hosted chat stack collects its keys: OpenAI-compatible providers, web search, tool servers, the JWT signing secret. How to run it with one credential in the compose file, put a proxy between it and every paid API, and stop admin-panel edits from bypassing that proxy.

read →
Frameworks

Managing secrets in Google ADK agents

ADK puts GOOGLE_API_KEY in a .env beside agent.py, and every tool's key ends up in the same file. How to wrap adk web, resolve in code, deploy to Cloud Run with one variable, and give tools placeholders instead of keys.

read →
How-to

Secrets in durable agent workflows: Inngest and Trigger.dev

Durable execution stores step outputs and payloads so a run can resume, which means anything a step returns is written to the platform, including a resolved secret. How to give Inngest and Trigger.dev agents credentials that never appear in a payload, an output, or a checkpoint.

read →
How-to

Securing an AI agent in Supabase Edge Functions

Every Edge Function gets the service role key injected by default, and an agent in one holds it alongside every provider key set with supabase secrets set. How to run an agent on Supabase with one secret, placeholders for tool keys, and the database reached as the user rather than as the service role.

read →
How-to

Securing self-hosted agent builders: Dify, Langflow, and Flowise

Visual agent builders hold every provider key their flows use, encrypted with one key from the compose file, and an exposed Langflow was enough for unauthenticated remote code execution. How to run them with no secrets in the compose file and route provider calls through a proxy that holds the keys instead.

read →
Agents

Deploying AI agents without a secrets plan is how keys leak

Agent launch plans cover the model, the tools, the evals, and the cost. Credentials go in a .env file during the prototype and stay there. How an agent differs from a service, five ways standing keys go wrong, and how to deploy one that never holds a credential.

read →
Architecture

Secrets at the edge: why a decrypting server can't scale the way a ciphertext-only one does

Every workload fetches its secrets at boot. If the server decrypts them, that response can't be cached and always travels to one region. If the server holds only ciphertext, the hot path can run at the edge. How that decision sets the ceiling for Infisical, Doppler, and seekrit, and what the zero-knowledge version is like to use.

read →
Patterns

Every place a secret ends up, and what each one costs you

Nobody decides to have a password in eleven places; it happens one reasonable step at a time. An inventory of where plaintext comes to rest, from .env files to Terraform state to an agent's context window, what each exposes, and the one pattern underneath all of it.

read →
Frameworks

Managing secrets in Ruby on Rails without dotenv or credentials.yml.enc

Rails gives you encrypted credentials and RAILS_MASTER_KEY, most teams add dotenv-rails on top, and the two drift. How to load ENV for Puma, Sidekiq, rake tasks, and Kamal from one encrypted store, with a Railtie or a wrapper command.

read →
Frameworks

Vite environment variables: keeping API keys out of the bundle

Vite compiles every VITE_-prefixed variable into the JavaScript it serves. Why a .env file is the wrong place to draw that line, and how to load secrets into vite.config.ts, SSR, and Vitest without one.

read →
How-to

Docker Compose secrets without a .env file

Where Compose puts the values from env_file and environment, why docker compose config and docker inspect print them, and three ways to give containers their credentials at start time with no plaintext file on the host.

read →
How-to

Keeping secrets out of Terraform state

Terraform writes every attribute it manages into terraform.tfstate, sensitive or not. How write-only arguments and ephemeral resources (Terraform 1.11+) keep database passwords and API keys out of state and plan files.

read →
How-to

Syncing secrets into Kubernetes with External Secrets Operator

A step-by-step External Secrets Operator tutorial: install ESO, point a SecretStore at a secrets manager, write an ExternalSecret, and consume the resulting Secret with envFrom. Plus etcd, refresh timing, and outages.

read →
How-to

Managing secrets in a Python app without a .env file

Where python-dotenv and pydantic-settings fall short, and how to load API keys and database URLs into a Python process at startup from an encrypted store. Covers scripts, FastAPI, Django, pytest, Docker, and notebooks.

read →
How-to

Syncing environment variables to Vercel from one source of truth

Vercel injects env vars from its own copy at build and run time, so a secrets manager has to push to it. How to connect a project, bind an environment per deployment target, handle preview branches, and what Vercel can see.

read →
Frameworks

Managing secrets in Spin applications

Three ways to get credentials into a Spin app, what each one costs, and the WASI version mismatch that makes the obvious approach fail at startup with an error that names neither Spin nor seekrit.

read →
Patterns

Managing secrets in wasmCloud

wasmCloud has a pluggable secrets API, which makes it the rare WebAssembly host where the platform can refuse to spread a plaintext. What that buys you, what the nkeys trust model actually proves, and the two setup steps that fail silently.

read →
Security

Neocloud security is now an API key problem

A summer of neocloud security research found cross-tenant RCE, container escapes, and a monitoring stack that leaked every tenant at once. If you rent GPUs, the question is no longer whether you handled your keys well — it's what happens to them when the provider's isolation fails.

read →
Patterns

Your agent moved to OpenAI. Your keys don't have to.

The Agents API runs the loop for you. OpenAI vaults can keep keys out of hosted sandbox code; a seekrit proxy can also keep the real values on infrastructure you control.

read →
Patterns

A checkpoint is a backup of your API keys

Sandboxes taught us that secrets inside them are disposable, because the sandbox was. Fly.io Sprites keep their filesystem and snapshot it — so a rotated key comes back on restore, and a Sprite you provisioned in January never hears about February's rotation.

read →
Patterns

Your GPU node lives for an hour. Your API key lives for a year.

Renting compute by the hour inverts the usual lifetimes: the machine is disposable and the credential isn't. The only thing you can put on an SF Compute node before it boots is a cloud-init script the provider keeps — so make it carry one credential, not twenty.

read →
Security

Your stolen API key is someone else's compute budget

Anthropic's September 2026 threat report describes attackers stealing AI credentials to run their attacks on the victim's bill, under the victim's name. Every one of those keys was reusable plaintext sitting somewhere a process could read it.

read →
Security

Attackers test every key they steal. Give them one that pages you.

Three separate groups in Anthropic's September 2026 threat report validate harvested credentials in bulk before using them. That validation step is the one moment they touch your infrastructure from the outside — and the only free detection you get.

read →
Patterns

Three hours from one developer token to full cloud admin

Anthropic's September 2026 threat report measures modern intrusions in hours. Most credential lifetimes are still measured in quarters. Rotating faster doesn't close that gap — not issuing long-lived credentials does.

read →
Agents

How an AI agent can set up its own secrets manager

Written for the agent doing the work. Connect to mcp.seekrit.dev with no credential, call signup once, store credentials, run commands with them injected, and hand the org to a human before you stop.

read →
Security

Secrets in GitHub Actions when an agent writes your workflows

Coding agents write workflow YAML from examples, and the common examples expose secrets to pull requests. The two mistakes to check for, and a setup where the runner decrypts a scoped set and nothing else holds it.

read →
Frameworks

Managing secrets in the OpenAI Agents SDK

Run an OpenAI Agents SDK agent on injected secrets or behind a credential proxy with no code change, and why traces disappear the moment you add the proxy.

read →
Frameworks

Managing secrets in Pydantic AI agents

Pydantic AI's deps_type and RunContext are a per-run credential seam. How to resolve a tenant's secrets per run, hold a placeholder instead of a key, and let one tool use a Stripe key while the others cannot.

read →
Frameworks

Managing secrets in Mastra agents

Five ways to get credentials into a Mastra agent: wrap mastra dev, resolve in code, hold a placeholder, resolve a different key per tenant from requestContext, and scope a Stripe key to one createTool executor.

read →
Frameworks

Managing secrets in CrewAI crews

How to get API keys into a CrewAI crew without a .env file, and how to stop every agent in the crew from being able to use every tool's credential. Three setups, one command each.

read →
Security

Should your coding agent be able to read your .env?

Claude Code, Cursor, and Copilot all work in a directory that probably holds production credentials in plaintext. How to block the reads, why blocking isn't enough, and the setup where there's nothing to block.

read →
How-to

Passing secrets into a sandbox without baking them into the image

Every credential baked into an image outlives the build. Injecting at start time in Docker, E2B, Modal, Daytona, and Vercel Sandbox — and keeping the key out of the sandbox entirely when the code inside is the threat.

read →
Frameworks

Managing secrets in LangGraph agents

Four shapes for getting credentials into a LangGraph agent, from wrapping the process to scoping a Stripe key to a single tool call — and why CVE-2025-68664 argues for the stronger two.

read →
How-to

How to give an AI agent an API key without giving it the API key

Five levels of keeping a credential away from an agent — from spawn-time injection to a full egress proxy with the sandbox inside it — and a table for picking the one your setup needs.

read →
Security

Your MCP config is a plaintext secrets file

claude_desktop_config.json, .mcp.json, and most server READMEs tell you to paste API keys into an env block — a file your agent reads and your team commits. Make it name credentials instead of holding them.

read →
Workflow

Getting secrets into a Jupyter notebook without leaking them

Every common way of getting a credential into a notebook either writes it into the .ipynb or only works on one platform. One call that works the same in JupyterLab, papermill, Voilà, and a container.

read →
Security

Your coding agent will hand over your API key if asked nicely

An instruction in a pull-request title was enough to make three major coding agents post their own credentials to the thread. The fix isn't a better agent — it's not giving the agent a credential at all.

read →
Patterns

Credential brokering for AI agents, without running a vault

What a credential broker is, the four properties that separate one from an open proxy, and the question most comparisons skip: after the broker, who can still read the key?

read →
Trust

What happens to your secrets if seekrit disappears

Every secrets manager is a single point of failure for everything you deploy. Exactly what you keep if we shut down — the signed archive, the offline decryptor, the custodian quorum — and where the answer stops.

read →