Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Keep raw API keys out of agent-readable configuration, prompts, source code, reusable plugin packages, and logs. Put only non-secret settings in files you share or commit. If the agent process can read a key—whether it comes from an environment variable or a vault injection—assume code running in that process can expose it. When the agent must use a credential without seeing it, have a trusted backend or proxy attach it to approved requests.

Why API keys do not belong in agent configuration

Agent definitions and tool-connection files are easy to copy, commit, package, or include in logs. A credential placed inline can travel with them. OpenAI’s MCP connections guidance says to keep secrets out of reusable agent definitions, plugin archives, and logs.

Use configuration files for settings that are safe to share, such as a service name or a non-secret endpoint. Do not include a raw key in a prompt, code sample, MCP authorization field, plugin archive, or debugging output. A reference to a secret is safer than its value only when the target runtime supports that reference and resolves it securely.

Choose the right place for the credential

Pattern What it protects Limitation Best fit
Environment variable Keeps the literal key out of source code and checked-in configuration. The process and code able to read its environment can read the key. Local development or a trusted process where process-level access is acceptable.
Platform vault or secret store Stores the real credential outside reusable agent configuration and can supply it through a supported integration. Availability and isolation depend on the platform, credential type, and injection mechanism. Direct injection into an agent-readable environment still exposes the value to that process. Hosted agent and MCP integrations that document vault support.
Trusted backend or proxy Keeps the raw key outside agent-generated code; the trusted service authenticates approved outbound requests. Requires operating and securing an intermediary, including constraints on its destinations and capabilities. Untrusted agent execution or stronger separation between agent code and credentials.

OpenAI’s sandbox security guidance puts the environment-variable limitation plainly: “Injecting a stored secret into the environment still exposes it to agent-generated code.” Environment variables improve configuration hygiene, but they are not an isolation boundary.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Keep MCP credentials out of reusable configuration

MCP setups may specify authorization inline or use a matching vault credential, depending on the platform. Prefer the documented vault mechanism when the runtime supports it; do not assume a placeholder syntax from one SDK or platform works elsewhere. OpenAI documents vault credentials for MCP and sandbox use, including a placeholder environment variable for cases where the real secret stays outside an OpenAI-hosted sandbox.

For details, follow the platform’s documentation for MCP connections and vaults. If the credential must remain inaccessible to agent-generated code, a trusted proxy or server should hold it and add it only to approved requests.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Restrict which tools an agent can discover and call. In OpenAI’s MCP connection setup, allowed_tools can limit tool access. That reduces available actions, but it does not protect a key already readable by the process.

Set up an environment variable without exposing its value

  1. Remove the literal key from the config and source. Replace it with a non-secret setting or a runtime-supported secret reference. Check that the key is not in prompts, plugin packages, or example files either.
  2. Supply the key through the trusted runtime. For local development, use an environment variable that is not committed to source control. For a hosted agent, use its documented secret-store integration if available.
  3. Check presence without printing the secret. Verify that the required variable is set using a presence-only check or the platform’s secret-status indicator. Do not echo the value to a terminal, log, or agent transcript.
  4. Review what can read it. Determine whether the agent process, generated code, tools, or subprocesses can inspect the environment. If they can, the variable does not keep the key secret from them; use a proxy or other documented isolation boundary instead.
  5. Keep logs and traces free of credential values. Avoid logging authorization headers, environment contents, or full request data that may contain secrets.

OpenAI recommends environment variables as an API-key safety measure in its API key safety guidance. That protects against accidental inclusion in source control; it does not make a key inaccessible to software running with permission to read it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Limit what an exposed credential can do

Storage is only one part of the security boundary. Assess each setup by asking:

  • Can the agent or its generated code read the raw credential?
  • Where does the real secret reside, and which component injects or uses it?
  • Which hosts and actions can the credential authorize?
  • Can you scope, revoke, or replace it independently of the agent configuration?
  • Could logs, traces, or error reports capture the secret?

Grant only the tool access and credential scope the task needs. OWASP’s MCP01:2025 guidance on token mismanagement and secret exposure identifies hard-coded MCP credentials and poor token handling as exposure risks, and recommends using secret-storage controls.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

If a key may have been exposed

  1. Revoke or rotate the credential. Do not wait to confirm whether someone used it if exposure is credible.
  2. Remove it from active configuration and source. Replace it with a supported secret reference or move credential use behind a trusted service.
  3. Check relevant repositories, logs, and traces. Look for copies of the value or requests that may have included it; do not reproduce the secret in remediation notes.
  4. Review access and usage. Check the provider’s available activity records for unexpected use, and narrow the credential’s permissions if needed.

OpenAI’s sandbox security guidance advises rotation or revocation when exposure is suspected.

Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.