On this page
- Where Do Your AI Agents' Credentials Actually Live?
- What Does a Credential Gateway Do on Every Call?
- Which Two Default Settings Leak Credentials on Day One?
- Do You Need an Enterprise Platform or Is Open Source Enough?
- How Do You Harden an Agent Stack in One Afternoon?
- What Is the Blast Radius When a Key Leaks?
- Frequently Asked Questions
- Where should AI agents store their API keys?
- What is an AI agent gateway?
- How do I stop an AI agent from leaking credentials?
- Do I need an enterprise product to secure AI agents?
- What happens if an AI agent's API key is leaked?
Last Updated: October 7, 2026
Key takeaways
- Most agent stacks copy model keys and MCP credentials into config files on every laptop, CI runner and server, so one stolen file hands over working credentials.
- A credential gateway keeps real keys in one encrypted store: the agent presents a gateway key and profile on every call, and the real credential is attached only after the call is approved.
- Tuskira's open-source AI Agent Gateway, published October 1, 2026 under Apache 2.0, runs on your own hardware with per-agent profiles, tool trimming, and token and cost logs for every call.
- Fix two shipped defaults on day one: bind every key to its profile, and turn off request-body storage in production.
- RSA Agent ID, announced September 2026, adds the enterprise layer: every agent and MCP server gets a named owner, a risk classification and a lifecycle state.
- Delinea's 2026 research found 87 percent of IT leaders say an AI tool or agent accessed sensitive data beyond its intended scope in the past year, so least-privilege agent credentials are a baseline control now, not a nice-to-have.
Your AI agents keep their passwords in the worst possible place: a copy of the config file on every machine that runs them. The fix is a pattern the security market finally shipped this month, the credential gateway, and it works for a two-person agency as well as it does for a bank. Tuskira published an open-source AI Agent Gateway on October 1, 2026, RSA launched the enterprise Agent ID platform in late September, and Delinea's 2026 AI Policy Enforcement Report explains why it matters: 87 percent of IT leaders say an AI tool or agent accessed sensitive data beyond its intended scope in the past year. This post explains where agent credentials actually live, how a gateway call works, which two defaults to fix, and how to harden a self-hosted stack in one afternoon.
Where Do Your AI Agents' Credentials Actually Live?
In a typical team running Claude Code, Cursor and a homegrown ticket bot, model keys and MCP credentials are copied into each agent's config file on every laptop and CI runner. According to Help Net Security's October 7, 2026 write-up of Tuskira's AI Agent Gateway, anyone who gets hold of one of those files gets the credentials inside it, and nothing checks the agent's permissions at the moment it acts. Every copy is a separate leak waiting for a pushed repository, a shared dotfile backup, or a departed employee's laptop.
In our own dual DGX Spark deployment, a five-minute audit found the same model provider key in a .env file, an agent config, and two cron job scripts, with bot tokens sitting in each integration config alongside them. Four kinds of file, four separate rotations after any incident. Multiply that across every machine in a fleet and credential sprawl becomes the default state of every self-hosted agent stack.

What Does a Credential Gateway Do on Every Call?
The agent registers the gateway as its MCP server and presents a gateway key plus a profile name with every request. The gateway checks the key against a tenant and a role, confirms that profile may use the requested tool, and either denies the call, returning an error and logging it without the backend ever seeing it, or attaches the real credential from an encrypted store on the way out. According to Help Net Security, the agent never holds the GitHub token: it holds a short gateway key that is worth nothing on its own.
Two more controls ride along. The gateway trims the tool list each agent sees, so an agent talked into calling a tool it was never shown still gets refused, and the check runs at the moment of the call, not at deploy time. Model traffic can pass through the same gateway by changing an SDK's base URL, covering Anthropic directly and through AWS Bedrock plus OpenAI and Gemini, with tokens and an estimated cost recorded for every call. The project itself is written in Go, licensed Apache 2.0, and picked up 67 GitHub stars in its first week after publication on October 1, 2026, according to the GitHub API. It runs on macOS and Linux, with worked examples for Claude Code, Cursor, VS Code, Codex CLI, a Python agent and Kubernetes.

Which Two Default Settings Leak Credentials on Day One?
Two shipped defaults need changing before real use. First, profiles bind only when you bind them: a key with no profile attached lets the caller name its own profile in a request header, so a leaked unbound key can ask for any profile it wants. Bind every key to exactly one profile and a leaked CI key reaches only what that profile allows, which in Tuskira's sample is a single tool. Second, the demo stack stores LLM request and response bodies, capped at 1 MiB each, so the console can display them, and those bodies hold whatever your agents actually sent. One setting turns storage off in production.
The network guardrails are worth copying even outside the gateway. Out of the box it refuses connections to private and loopback addresses and always blocks the cloud metadata address, while the shipped Docker Compose file allows outbound connections to the host and loopback range for local testing. Help Net Security's guidance is to remove both exceptions on anything shared. The discipline matches what Delinea's CEO Art Gilliland told the 2026 AI Policy Enforcement Report: "Written policy is only as good as your ability to enforce it at the moment an AI agent acts," adding that leaders "have the AI policies in place, but they can't see or report on what their agents actually do." A gateway is enforcement at the moment the agent acts, with the report to prove it.

Do You Need an Enterprise Platform or Is Open Source Enough?
Open source covers the core controls for most teams: an encrypted credential store, per-call authorization, tool trimming and audit logs, all on hardware you own. Enterprise platforms add organization-wide governance. According to RSA's launch release, RSA Agent ID, announced at The AI Conference in San Francisco in September 2026, discovers, secures and governs AI agents and MCP servers as first-class identities, each with a named owner, a risk classification and a lifecycle state. "For government, financial services, and critical infrastructure, getting agentic security wrong is not inconvenient, it is catastrophic," says RSA CEO Greg Nelson. "Hope won't control agents, but RSA Agent ID will."
| Dimension | Tuskira AI Agent Gateway | RSA Agent ID |
|---|---|---|
| What it is | Open-source credential gateway for agent tool calls and model traffic | Agentic identity platform for regulated industries |
| License and cost | Apache 2.0, free, self-hosted | Commercial, enterprise pricing |
| Identity model | Gateway keys tied to tenant, role and profile | Named owner, risk classification and lifecycle state per agent and MCP server |
| Control point | Per call: approves or denies each tool call | Lifecycle: discovery, registration, proof of authority |
| Model coverage | Anthropic direct and Bedrock, OpenAI, Gemini | Vendor-neutral across agents and MCP servers |
| Best fit | SMB and mid-market self-hosted stacks | Government, financial services, critical infrastructure |
"RSA Agent ID brings agents under the same identity discipline RSA has applied to human access for decades," Nelson says. Our take for the businesses we advise: the gateway layer is the one you can ship this week, and the identity layer is the one your auditor will ask for next year. They are not competitors, they are floors of the same building.
How Do You Harden an Agent Stack in One Afternoon?
The whole move is five steps, and none of them need new hardware beyond a server you already trust. According to the project's documentation, the Tuskira gateway ships worked examples for Claude Code, Cursor, VS Code, Codex CLI, a Python agent and Kubernetes, so most stacks have a same-day path to the gateway pattern.
- Inventory every credential your agents hold. Search agent configs, .env files, cron job scripts and CI workflows for model keys, MCP credentials and bot tokens, and list every file and machine holding a copy. This list is your current blast radius.
- Stand up the gateway on your own hardware. Run it with Docker Compose on a server you control, and remove the host and loopback test exceptions from the shipped compose file before anything shared touches it.
- Bind every key to a least-privilege profile. One profile per agent role, only the tools that role needs, following Tuskira's sample CI profile that allows a single tool, and every key bound to exactly one profile.
- Point agents and SDKs at the gateway. Register the gateway as each agent's MCP server, and change the model SDK base URL so model traffic passes through the same check point and gets token and cost accounting for free.
- Turn off request-body storage and keep the audit logs. Disable LLM body storage for production, keep the per-call authorization, token and cost logs, and revoke-test one key to confirm the blast radius is one log entry instead of one procurement exercise.

What Is the Blast Radius When a Key Leaks?
The math changes with the pattern. A leaked config-file key means finding every copy and rotating all of them, on every laptop and runner, before you can say the incident is contained. A leaked gateway key is one revocation, and the call log shows exactly what that key touched. Delinea's 2026 AI Policy Enforcement Report quantifies the status quo it replaces: 99.7 percent of organizations now have a formal policy governing what data AI tools and agents can access, yet only about half check access against policy in real time, and 55 percent take a full day or longer to detect an agent going beyond its scope.
Running the agents on your own hardware shrinks the exposure further. A local model on a DGX Spark or an on-prem server has no per-token cloud key to steal at all, and the credentials that do exist stay inside your walls. For Australian businesses, that distinction carries legal weight: stolen cloud credentials can trigger obligations under the Privacy Act's notifiable data breaches scheme, while a credential store that never left your hardware is a much smaller conversation with counsel. Help Net Security's companion piece this week makes the human side explicit: sorting out whether automation, AI agents or people handle each security finding, and the gateway logs are what give the human triager something to read.

One leaked API key can cost more than every hour of hardening on this list, and the setup is one afternoon on hardware you already own. That trade does not need a committee.
Frequently Asked Questions
Where should AI agents store their API keys?
In one encrypted store behind a credential gateway, not in each agent's config file. The agent presents a gateway key and profile on every call, and the real credential is attached only after the call is approved, so the agent process never holds the GitHub token or model API key.
What is an AI agent gateway?
A service that sits between your agents and everything they call: MCP tool servers such as GitHub or Jira, and model providers such as Anthropic, OpenAI and Gemini. Tuskira's open-source AI Agent Gateway checks a per-agent key and profile on every call, trims tool lists, denies and logs unauthorized calls, and records tokens and cost.
How do I stop an AI agent from leaking credentials?
Stop copying keys into configs, stand up a gateway on your own hardware, bind every key to a least-privilege profile, turn off request-body storage in production, and remove test-time network exceptions. A leak then costs one key revocation, not a fleet-wide rotation.
Do I need an enterprise product to secure AI agents?
Not for the core controls: an open-source gateway on your own hardware covers encrypted storage, per-call authorization, tool trimming and audit logs. Enterprise platforms such as RSA Agent ID add agent discovery, named ownership and lifecycle governance, which regulated industries typically layer on top.
What happens if an AI agent's API key is leaked?
A config-file key gives an attacker everything it could reach until you find and rotate every copy, and Delinea's 2026 report found 55 percent of organizations take a full day or longer to detect an agent going out of scope. A gateway key is tied to one tenant, role and profile, so revocation is one action and the log shows exactly what it touched.
One email a month, no noise
Practical AI notes for Australian businesses. Unsubscribe anytime.