Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use workload identity or federation instead of a persistent key whenever the platform and API support it. For credentials that must be stored, keep them in a secret-management system, grant each agent only the access it needs, and keep secret values out of prompts, model context, logs, traces, and broad process environments. A vault helps control retrieval; it does not stop an agent from misusing a credential it is authorized to access.

Start by identifying what each agent actually uses

“API key” is often used loosely, but an agent’s dependencies may include API keys, OAuth client credentials, refresh tokens, service-account keys, database passwords, certificates, and signing keys. Their privileges, expiration rules, and revocation methods can differ. Inventory each credential the agent uses directly or indirectly before choosing how to protect it.

For every credential, record its issuer, purpose, owning team, consumers, granted permissions, expiration or rotation process, and the way to revoke it. Classify it by the likely impact if exposed. OWASP’s Secrets Management Cheat Sheet treats management as a lifecycle that includes creation, rotation, revocation, and expiration; centralized provisioning and audit can help identify which principal or application uses a credential.

Prefer workload identity to a persistent key

When the agent runs on a platform that can provide an identity, use that identity to obtain access instead of downloading and storing a long-lived credential. Depending on the platform, this may be an attached runtime identity, metadata-provided credentials, or federation from an external workload. Google Cloud recommends metadata-provided credentials for supported Google-hosted workloads and workload identity federation for supported external platforms as alternatives to exporting a service-account credential.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
OnlyKey FIDO2 / U2F Security Key and Hardware Password Manager | Universal Two Factor Authentication | Portable Professional Grade Encryption | PGP/SSH/Yubikey OTP | Windows/Linux/Mac OS/Android
  • ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
  • ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
  • ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
  • ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
  • ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!

There is an important bootstrap boundary: if a workload already has an identity that Google Cloud recognizes, Google advises using that identity rather than storing a service-account key in Secret Manager or another cloud secret store. The workload would otherwise need an identity to retrieve the key that grants the identity access.

For an API that requires an issued secret, check whether its issuer supports a narrower credential, short-lived tokens, or audience restrictions. Bind credentials to one workload or agent where possible. Token capabilities vary by provider, so confirm the available controls in that API’s current documentation rather than assuming all tokens support them.

Choose an approach that fits the workload

Identity-based access and stored-secret systems solve different problems. Use the identity route when the target service can trust the workload directly; use a secret manager when the application must retrieve an issued secret. A dedicated secrets platform and a cloud-native secret manager are both possible categories, but their suitability depends on the team’s identity integration, operations, availability, and portability needs.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Approach Best fit Key consideration
Workload identity or federation The runtime or external platform can be authenticated directly by the service being called. Can avoid storing an additional exported service-account credential. Verify that the specific platform and API support the required identity flow.
Cloud-native secret manager The agent must retrieve an API key, password, or other application secret. Bind access to the workload identity and, where supported, to the individual secret. Secret storage does not limit what an authorized agent can do with the retrieved value.
Dedicated secrets platform The organization needs a separately operated secrets system or wants to assess portability across environments. Evaluate who operates and patches it, how policies are standardized, and the migration and availability implications. OWASP names HashiCorp Vault as one example of this category.

OWASP highlights availability, centralization, fine-grained access control, automation, and portability as factors in choosing a secrets-management approach. Google Cloud’s guidance also emphasizes IAM, audit access, replication, and controlled rollout. Compare options on those dimensions, as well as delivery method and regional requirements, rather than assuming that a product category alone determines security.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Give each agent a narrow identity and narrow permissions

Separate credentials or principals by agent, environment, and meaningful trust boundary. Avoid sharing one production key among unrelated agents or between staging and production. At the secret store, allow each principal to retrieve only the required secrets; at the API or service, limit each credential to the operations the task needs. Permission to retrieve a secret is not a substitute for limiting the secret’s downstream privileges.

Apply least privilege to the agent’s tools as well as its credentials. Limit the available tools and the operations each tool may perform, separate tool sets for different trust levels, and require explicit authorization for sensitive actions. OWASP’s guidance on agentic AI identifies excessive tool permissions and credentials in agent context or logs as concerns. An agent that can legitimately retrieve a powerful credential may still use it in an unsafe way.

Rank #3
Thetis Pro For Business - FIDO2 Security Key L1 MFA & NFC Passkey Access For School ERP, Employee Online Account, Compatible with Coinbase Google Workspace Apple ID Window Salesforce,Dual USB A +USB C
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Universal Connectivity (USB-C, USB-A, & NFC): Designed for PCs, Macs, iPhones, and Android. For mobile use, simply unfold the key, align it with your phone’s NFC antenna, and hold for a few seconds to authenticate.
  • Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.

Store and deliver secrets without exposing them

Do not commit credentials to source control, put them in agent instructions, or paste them into prompts. Use a platform identity or designated secret manager instead of plaintext configuration. OWASP lists cloud secret stores and dedicated systems such as Vault among possible approaches.

Where practical, have the application retrieve the secret through the secret manager’s API. Google Cloud recommends direct Secret Manager API access where possible and cautions that other delivery methods introduce exposure paths:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Mounted files: A filesystem or directory-traversal vulnerability can expose a secret made available as a file.
  • Environment variables: Debug endpoints or dependencies that log the process environment may reveal values.
  • Synced copies: Copying a secret into another datastore can expand who can access it or weaken auditability. Review that store’s access controls, audit coverage, encryption, and regional handling.

Some integrations support or require file- or environment-based delivery. If you use one, tightly restrict access to the process and host, and make sure diagnostic output redacts values. Environment variables are a risk to assess, not a universally impossible delivery method.

Rank #4
Sale
Kensington VeriMark NFC+ USB‑C Security Key, FIDO2/WebAuthn Hardware Authenticator for Passwordless Login, Works with Windows, macOS & Chrome OS, K64739WW
  • USB-C or tap via NFC for easy authentication on any compatible device. No drivers needed; optional Kensington software available for advanced management features.
  • Works across Windows, macOS, iOS, Android, ChromeOS, and supports Passkeys and Apple ID.
  • Slim, keychain-ready form for easy carry and on-the-go authentication
  • IP68-rated for dependable performance
  • FIDO CTAP 2.1 for enhanced security features (e.g. resident credentials, Passkey support) and backwards compatibility with CTAP 2. FIDO2 L2 certified security for phishing resistant protection against identity theft and unauthorized access.

Never put credential values in model context, tool outputs, telemetry, traces, error messages, or logs. Redact secrets at the point data is captured, then test the redaction path with dummy credentials. OWASP specifically identifies credentials inadvertently included in agent context or logs as a sensitive-data exposure risk.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Rotate credentials with a staged rollout

Automate lifecycle operations when the issuer and consumers support them. A safe rotation changes the credential in stages so you can verify the replacement before removing the old value:

  1. Create: Issue a replacement credential with the intended scope and target service.
  2. Deploy: Make the new credential available to the intended consumers, using versioning or a controlled rollout where supported.
  3. Test: Confirm the consumers authenticate and perform the required operation with the replacement.
  4. Disable and monitor: Disable the old credential and watch for remaining use or failures before deleting it.
  5. Delete: Remove the old credential after validation and monitoring show that it is no longer needed.

OWASP’s rotation guidance separates creation, setting, testing, and completion, and emphasizes checking that a pending credential targets the intended service before promotion. The exact mechanics depend on the credential issuer and application.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

Google Cloud service-account key guidance

Google recommends rotating Google Cloud service-account keys at least every 90 days. This interval is specific to those keys, not a universal schedule for API keys or every other credential. Google’s documented process is to identify keys, create replacements, update applications, disable replaced keys while monitoring, and delete them after validation. Its guidance also warns that expiration can cause production outages if workloads are not rotated correctly. For suspected compromise, rotate immediately rather than waiting for a routine interval.

Prepare to revoke a credential quickly

Maintain an incident path that lets the responsible team revoke a leaked credential at its issuer, find affected consumers, replace dependent credentials if necessary, and inspect relevant access logs. Deleting a leaked value from a repository does not make an already exposed credential safe; revoke or rotate it.

Make sure the people responding can identify the credential’s owner and downstream dependencies without relying on the secret value itself. For Google Cloud service accounts, Google also documents service-account insights that can identify accounts not used in the past 90 days; this is a product-specific monitoring capability, not a general measure of key age or a universal rotation rule.

Audit access and review the whole agent path

Enable secret-access audit logging and alert on unexpected principals, locations, frequency, or access patterns. Google recommends enabling Secret Manager data access logs and monitoring access requests. Keep records useful for investigation by recording principal and event details, not secret material.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Review who can change the agent’s tool configuration, alter its workload identity, grant secret access, and inspect its runtime. Consider whether the runtime can exfiltrate values and whether logs or debug endpoints could expose them. Test with dummy secrets, inspect logs and traces for leakage, and rehearse revocation. These checks apply the least-privilege, agent-tool, and audit principles described by OWASP and Google Cloud; they are not a single vendor-prescribed test suite.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.