Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A secret manager stores credentials and controls access to them; an AI agent credential gateway mediates agent-to-tool requests and enforces how those calls are authenticated and authorized. Some gateways can also inject credentials at the outbound boundary, keeping raw secrets out of an agent’s runtime. The two functions can complement each other: a gateway may retrieve credentials from a secret manager.

What each component does

Secret manager: custody and credential lifecycle

A secret manager is primarily a controlled place to store credentials and manage access to them. Depending on the system, it may also broker authentication flows or manage OAuth credentials and tokens. Google Cloud describes its Agent Identity auth manager as a centralized credential vault and broker for API keys, OAuth client credentials, and delegated user tokens (Google Cloud auth manager overview).

But storing a secret centrally does not automatically keep it away from the agent. If agent code retrieves a key and attaches it to a request, the key enters that runtime’s call path—even if it was never placed in a prompt.

Credential gateway: mediation and enforcement

A credential gateway sits in the request path between an agent and tools or downstream services. It can authenticate the caller, authorize the requested action, inspect or govern traffic, and—in some configurations—apply credentials to outbound requests. AWS describes AgentCore Gateway as a way to centralize tool access and manage inbound authentication and outbound authorization (AWS Prescriptive Guidance, Capability 5). Google describes Agent Gateway as enforcing access policies and inspecting traffic (Google Cloud Agent Identity overview).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
OnlyKey FIDO2 / U2F Security Key and Hardware Password Manager | Universal Two Factor Authentication | Portable Professional Grade Encryption | PGP/SSH/Yubikey OTP | Windows/Linux/Mac OS/Android
  • ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
  • ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
  • ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
  • ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
  • ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!

“Gateway” and “secret manager” name functions, not mutually exclusive product categories. A gateway can use a secret manager as its credential source, while the secret manager continues to handle custody and lifecycle.

Why the credential’s runtime path matters

The decisive security question is which component can see the plaintext credential. A secret can be encrypted at rest and still be exposed after retrieval. Trace the complete flow: whether the model sees a value, whether the agent process receives it in memory or an environment variable, whether a trusted adapter receives it, or whether a gateway injects it without disclosing it to the agent.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Documented Google configurations illustrate why the exact integration matters. In an auth-manager example, credentials are retrieved and attached to headers before dispatch, which places them in the agent-side request path. In a separate Agent Gateway and Gemini Enterprise arrangement, end-user credentials are decrypted at the gateway so the agent does not access the raw credential. Gemini managed-agent documentation also describes a server-managed egress proxy that injects credentials at request time, keeping the secret out of the agent environment (Credentials in managed agents). These are distinct configurations, not a universal guarantee for every gateway or integration.

Compare systems by the controls they actually enforce

Question What to verify
Plaintext boundary Can a credential enter the model context, agent memory, tool arguments, traces, or logs? Can the gateway inject it without exposing it to the agent?
Identity granularity Does each agent have a distinct cryptographic or workload identity, or do agents share a service account or secret? Google documents per-agent SPIFFE-based identity; AWS recommends least-privilege IAM roles.
Authority model Does the agent act under its own machine identity, or on behalf of a user through delegated OAuth? Google documents both agent authority patterns and user-delegated OAuth.
Enforcement point Is access checked when a secret is read, when a tool is invoked, at the gateway, or by the downstream API? Determine which checks are server-side and cannot be bypassed by agent code.
Credential lifecycle Who handles consent, token exchange and refresh, rotation, revocation, and short-lived credentials? Confirm the selected system supports the lifecycle you need.
Audit attribution Can records identify both the calling agent and, for delegated access, the user? Google documents attribution to both identities; HashiCorp documents audit metadata for its agentic IAM flow.
Operational fit Check cloud and IAM integration, supported runtimes, deployment model, and licensing. HashiCorp’s cited agentic IAM capability is a Vault Enterprise feature.

Identity and authorization remain important even if a gateway keeps a raw credential hidden. AWS recommends narrowly scoped roles and tool access. Google documents per-agent identities and audit attribution, while HashiCorp describes checking agent registration and authorization constraints in its agentic IAM flow.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Thetis Pro For Business - FIDO2 Security Key L1 MFA & NFC Passkey Access For School ERP, Employee Online Account, Compatible with Coinbase Google Workspace Apple ID Window Salesforce,Dual USB A +USB C
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Universal Connectivity (USB-C, USB-A, & NFC): Designed for PCs, Macs, iPhones, and Android. For mobile use, simply unfold the key, align it with your phone’s NFC antenna, and hold for a few seconds to authenticate.
  • Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.

How the documented product examples differ

Example Documented function Important qualification
Google Cloud Agent Identity Provides per-agent identity and integrates with the auth manager and Agent Gateway. The gateway enforces policies and inspects traffic. Check the documented supported environments and authentication models against your runtime and deployment.
Google Cloud Agent Identity auth manager Acts as a centralized credential vault and authentication broker. Its described ADK flow retrieves credentials and attaches headers before dispatch. A brokered credential can still enter the agent-side call path; this is not the same as gateway-side decryption and injection.
Google Agent Gateway with Gemini Enterprise In the documented arrangement, the gateway decrypts end-user credentials and the agent does not access the raw credential. Do not assume the same boundary applies to other integrations.
Gemini managed-agent egress proxy Resolves server-managed write-only secrets and injects them at request time. Documented credential types include bearer tokens, OAuth2, and environment-variable substitution. The feature is described for managed agents; check current availability and the exact network rules.
AWS AgentCore Gateway with AWS Secrets Manager The gateway centralizes agent-tool access; AWS recommends storing client IDs and secrets in Secrets Manager and using least-privilege roles and scopes. AWS guidance names multiple authentication choices. Use a supported option and restrict its permissions to the required tools and actions.
HashiCorp Vault Enterprise agentic IAM Validates OAuth JWTs, resolves client identity, checks agent registry status, and applies authorization constraints. HashiCorp identifies the cited capability as available in Vault Enterprise 2.1.0 and later; verify current version and license details.

For the Google identity and gateway capabilities, see the Agent Identity overview. For the auth manager, see its overview. AWS’s recommendations are in Capability 5; HashiCorp’s Vault information is in Vault + agentic AI; managed-agent credential behavior is documented in Google AI for Developers’ Credentials in managed agents.

Can an AI agent access secrets in a secret manager?

Yes, if its identity and permissions allow it to retrieve them. That can be appropriate when the agent must use the credential directly, but it means the credential is available to the agent process after retrieval. Keeping a key out of the prompt is not the same as keeping it out of the runtime.

Rank #4
Sale
Kensington VeriMark NFC+ USB‑C Security Key, FIDO2/WebAuthn Hardware Authenticator for Passwordless Login, Works with Windows, macOS & Chrome OS, K64739WW
  • USB-C or tap via NFC for easy authentication on any compatible device. No drivers needed; optional Kensington software available for advanced management features.
  • Works across Windows, macOS, iOS, Android, ChromeOS, and supports Passkeys and Apple ID.
  • Slim, keychain-ready form for easy carry and on-the-go authentication
  • IP68-rated for dependable performance
  • FIDO CTAP 2.1 for enhanced security features (e.g. resident credentials, Passkey support) and backwards compatibility with CTAP 2. FIDO2 L2 certified security for phishing resistant protection against identity theft and unauthorized access.

If the security requirement is that the agent must never receive raw credentials, look for an integration that enforces request-time injection outside the agent process. Confirm the boundary for the specific tool, authentication method, and deployment rather than relying on a product label such as “vault” or “gateway.”

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Questions to answer before choosing an architecture

  • Does the model receive a secret value, or only an opaque credential or tool identifier?
  • Does the runtime receive the credential in memory or through an environment variable, even when it is absent from prompts?
  • Can the gateway restrict destinations, HTTP methods, scopes, and individual tools, with those restrictions enforced server-side?
  • How are delegated user permissions consented to, refreshed, attributed in logs, and revoked?
  • Do request logs, traces, tool arguments, and error messages omit credentials and sensitive headers?
  • If an agent is compromised, can its credentials be revoked independently and its access separated from other agents?

These checks follow from the credential flows and controls described in the vendor documentation; they are questions to validate in the actual deployment, not claims that every named product passes every check.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.