Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Keep long-lived proxy credentials outside the agent’s readable environment. Have a trusted application, secrets manager, or egress proxy add authentication only to approved outbound requests, then return the agent a small result rather than credential-bearing request details. A proxy alone does not protect every log: traces, tool servers, exception handlers, proxy logs, and observability systems each need their own controls.

Choose a boundary the agent cannot read

The key distinction is where the real credential exists when the request is made. A secret stored securely and then injected into an environment readable by agent-generated code is exposed to that code. OpenAI’s sandbox guidance explicitly warns that a secret manager does not prevent exposure after a secret is injected into the environment: OpenAI secure environment guidance.

Prefer a boundary that keeps the credential out of the agent’s context and runtime. The agent can request an allowed operation, while a trusted application function or proxy attaches authentication and returns only the result needed for the next step. For OpenAI-hosted sandbox requests, a documented proxy pattern gives sandbox code a placeholder and substitutes the real secret for approved hosts. This hosted feature does not provide credentials to self-hosted environments or application-run function tools; those need their own trusted server or proxy.

Compare the common patterns

Pattern Can agent-generated code read the real credential? Where authentication happens Important boundary
Secret injected into an agent-readable environment Yes, code in that environment can read it. Inside the environment using the injected value. Do not treat an environment variable as secret from code that can inspect the environment. OpenAI secure environment guidance
OpenAI-hosted sandbox with vault-backed environment credential The sandbox receives a placeholder, not the real value, in the documented supported request pattern. OpenAI’s network proxy substitutes the value for an approved HTTPS destination. Host allowlists, supported ports, and unchanged placeholder requirements apply. OpenAI secure environment guidance
Application-run function tool No, if the application keeps the credential outside the agent runtime. The trusted application performs the authenticated operation. Return a minimal result; the hosted sandbox credential feature does not supply credentials to application-run tools. OpenAI secure environment guidance
MCP HTTP session credential Depends on connection mode and where the MCP client runs. Session transport configuration, or a matching vault credential for connections from OpenAI. Environment-origin HTTP calls for inline authentication or a trusted proxy in the documented setup. OpenAI MCP guide
MCP stdio environment credential Yes, code running in that environment can read the value. Environment value available to the process. A poor fit when the agent-generated code itself must not see the credential. OpenAI MCP guide

Build the request path so secrets are not returned to the agent

  1. Store the credential outside prompts and agent assets. Use a secrets manager or controlled application-side store. Do not put raw credentials in prompts, source files, reusable agent definitions, plugin archives, or diagnostic output.
  2. Expose a narrow operation. Let the agent ask for a specific permitted task rather than freely constructing credential-bearing requests. A trusted function, server, or proxy should attach authentication after validating the operation.
  3. Constrain destinations and credential use separately. Limit which tools can be called and which network destinations are reachable. Independently restrict where the proxy may inject a credential; network access to a host does not by itself mean that host should receive the secret.
  4. Return only what the next step needs. Prefer a compact result object over raw authenticated request and response material. Avoid returning headers, full bodies, or exception details that might contain credentials.
  5. Redact before data is persisted. Exclude authorization headers, proxy authorization fields, credential-bearing URLs, full request or response bodies, and exceptions that may embed those values from logs and traces.
  6. Review every persistence boundary. Inspect agent traces, framework callbacks, tool-server and proxy access logs, exception reporting, and observability exports. A proxy is not automatically a logging control for the rest of the system.

Configure OpenAI-hosted sandbox credentials narrowly

OpenAI documents an environment_variable credential for API requests from an OpenAI-hosted sandbox. The sandbox code receives a placeholder; the network proxy substitutes the real secret for approved hosts. This is not a general mechanism for self-hosted environments, local computation, or application-run function tools. See the secure environment guide for current configuration details.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
OnlyKey FIDO2 / U2F Security Key and Hardware Password Manager | Universal Two Factor Authentication | Portable Professional Grade Encryption | PGP/SSH/Yubikey OTP | Windows/Linux/Mac OS/Android
  • ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
  • ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
  • ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
  • ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
  • ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!

Keep the two host controls distinct

  • allowed_domains controls where the sandbox may connect.
  • Credential allowed_hosts controls where the proxy may inject the secret. Specify exact host names without a scheme, path, port, or wildcard.

The documented proxy supplies credentials only to HTTPS destinations on port 443 or 8443. If network access is restricted, the credential host must also be reachable under the sandbox network policy. A destination allowlist and a credential-injection allowlist solve different problems; configure both.

Use the placeholder only for supported requests

The placeholder must be passed unchanged in a supported HTTPS request for proxy substitution to work. The documented pattern cannot provide the real value for local computation such as request signing. For an operation that requires local access to the secret, keep the credential in the application and expose the operation through a function tool instead.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Choose MCP authentication by connection mode

OpenAI’s MCP guide describes different credential paths for HTTP and stdio connections. The connection mode determines which component can read the value.

HTTP connections

  • For a session, credentials can be supplied in session transport configuration; OpenAI says they are encrypted and omitted from the returned session resource.
  • For connections from OpenAI, reusable HTTP credentials can be stored in a vault and matched to the connection.
  • For environment-origin HTTP in the documented setup, vault credentials are not used; use inline authentication or a trusted proxy.

Stdio connections

Stdio credentials are environment values. Code running in that environment can read process variables, so this approach does not keep the real value from agent-generated code that can inspect the environment. Keep secrets out of reusable agent definitions, plugin archives, and logs regardless of transport.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Thetis Pro For Business - FIDO2 Security Key L1 MFA & NFC Passkey Access For School ERP, Employee Online Account, Compatible with Coinbase Google Workspace Apple ID Window Salesforce,Dual USB A +USB C
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Universal Connectivity (USB-C, USB-A, & NFC): Designed for PCs, Macs, iPhones, and Android. For mobile use, simply unfold the key, align it with your phone’s NFC antenna, and hold for a few seconds to authenticate.
  • Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.

Keep sensitive model and tool payloads out of logs

The OpenAI Agents JS SDK configuration guide says, “Model and tool data, including related error objects and details, is not included in logs by default.” It also documents sensitive-data logging as an explicit opt-in and advises enabling it only where logs are handled securely. Programmatic configuration controls model and tool data and takes precedence over the relevant environment variables; unset or unrecognized variables leave the default redaction behavior in place, while setting them to 0 or false opts into logging. See the Agents JS SDK configuration guide.

Confirm the behavior against the SDK version installed in your application: the guide does not state a package version. Also verify logging behavior outside that SDK. A safe SDK default cannot prevent a framework callback, proxy, tool server, exception tracker, or downstream system from persisting sensitive data.

Rank #4
Sale
Kensington VeriMark NFC+ USB‑C Security Key, FIDO2/WebAuthn Hardware Authenticator for Passwordless Login, Works with Windows, macOS & Chrome OS, K64739WW
  • USB-C or tap via NFC for easy authentication on any compatible device. No drivers needed; optional Kensington software available for advanced management features.
  • Works across Windows, macOS, iOS, Android, ChromeOS, and supports Passkeys and Apple ID.
  • Slim, keychain-ready form for easy carry and on-the-go authentication
  • IP68-rated for dependable performance
  • FIDO CTAP 2.1 for enhanced security features (e.g. resident credentials, Passkey support) and backwards compatibility with CTAP 2. FIDO2 L2 certified security for phishing resistant protection against identity theft and unauthorized access.

If debugging requires payload logging

  • Enable it only in a controlled diagnostic setting with restricted log access.
  • Limit retention and avoid exporting payloads to broadly accessible observability systems.
  • Disable sensitive logging again when the investigation is complete.
  • Check persisted traces and logs for prior exposure; redaction applied later cannot remove data already copied elsewhere.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Apply defense in depth and respond to exposure

Credential isolation is one layer, not a complete agent security design. OWASP’s Securing Agentic Applications Guide 1.0 recommends isolated execution, restricted filesystem and network access, dedicated secret-management systems, credential rotation, and checks that secrets are not written to logs.

  • Grant only the tools and destinations needed for the task.
  • Scope credentials and their permitted hosts as narrowly as the platform allows; implement method and lifetime limits where supported.
  • Rotate credentials regularly and revoke them promptly if disclosure is suspected.
  • Audit stored logs and traces after a suspected leak, then address the source of persistence as well as replacing the credential.

These sources provide platform guidance and security recommendations, not a measured cross-platform leakage rate or effectiveness percentage.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.