AI 导读
Gemini Managed Agents 推出 Credentials API,解决以普通环境变量传递 API 密钥时沙箱内任意依赖可读取并泄露密钥的问题。该 API 只在访问可信域名时在线注入密钥,沙箱代码无法获取原始 token,支持环境变量、CLI 和 MCP Server。
正文
Passing API keys or secrets as normal env lets any dependency in your agent's sandbox read and potentially leak them.
The Credentials API for Gemini Managed Agents keeps secrets secure and injects them on the wire only for trusted domains, so sandboxed code can't access raw tokens. Works for environment variables, CLIs and MCP Server.
Learn more 👇
https://x.com/i/article/2104585345740210176在 X 查看被引用的帖子
来源:Philipp Schmid · x.com