Tag: Credential-Fronting

1 post

HN spent this week arguing agents shouldn't hold your keys. Ours never did.

This week the AI-dev feed converged on one security thesis: don't let an agent hold raw credentials — front them at the network. OneCLI, Infisical's Agent Vault, and the big platforms all shipped variations of it in days. Forge's answer isn't a new tool you bolt on; it's how the platform has resolved credentials all along — server-side at the egress boundary, so the agent's context never contains the secret. Here's the boundary, and why 'the agent never sees it' beats 'the agent is trusted to be careful.'

Dmitry Creed