PASTKEYS
ARTICLE Agent security

Why AI agents should never hold long-lived secrets

PastKeys · October 2026

An AI agent with a long-lived API key is a credential waiting to leak. The agent reads untrusted input, writes to logs, and keeps context across turns, and each of those is a path for the key to escape. The fix is not a better prompt. It is to stop giving the agent the secret at all.

Why a long-lived key is the wrong thing to hand an agent

The alternative: authorize the operation, not the agent's wallet

Put a broker between the agent and the provider. The agent asks the broker to perform a specific operation. The broker authenticates the agent, checks a default-deny policy, and performs the operation itself using a credential the agent never receives. Where the provider supports it, that credential is minted for this one call and expires in minutes.

This changes what a leak is worth:

Least privilege, shortest lifetime. The point is not to hide the key better. It is to make the thing the agent holds worthless to steal.

What this looks like in practice

With PastKeys, provider tokens stay inside a broker you run, sealed so the hosted control plane cannot decrypt them. The agent holds only its own identity token and sends operations like "read these DNS records" or "open a read-only database session." The broker does the rest and writes an audit record for each call.

See getting started for the five-step setup, or the zero-access custody explainer for how the vendor is kept unable to read your secrets.

Stop handing agents long-lived secrets.

Create an account Read the whitepaper