Use workload identity or federation instead of a persistent key whenever the platform and API support it. For credentials that must be stored, keep them in a secret-management system, grant each agent only the access it needs, and keep secret values out of prompts, model context, logs, traces, and broad process environments. A vault helps control retrieval; it does not stop an agent from misusing a credential it is authorized to access.
Start by identifying what each agent actually uses
“API key” is often used loosely, but an agent’s dependencies may include API keys, OAuth client credentials, refresh tokens, service-account keys, database passwords, certificates, and signing keys. Their privileges, expiration rules, and revocation methods can differ. Inventory each credential the agent uses directly or indirectly before choosing how to protect it.
For every credential, record its issuer, purpose, owning team, consumers, granted permissions, expiration or rotation process, and the way to revoke it. Classify it by the likely impact if exposed. OWASP’s Secrets Management Cheat Sheet treats management as a lifecycle that includes creation, rotation, revocation, and expiration; centralized provisioning and audit can help identify which principal or application uses a credential.
Prefer workload identity to a persistent key
When the agent runs on a platform that can provide an identity, use that identity to obtain access instead of downloading and storing a long-lived credential. Depending on the platform, this may be an attached runtime identity, metadata-provided credentials, or federation from an external workload. Google Cloud recommends metadata-provided credentials for supported Google-hosted workloads and workload identity federation for supported external platforms as alternatives to exporting a service-account credential.
Recommended Free Tools
#1 Best Overall
- ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
- ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
- ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
- ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
- ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!
There is an important bootstrap boundary: if a workload already has an identity that Google Cloud recognizes, Google advises using that identity rather than storing a service-account key in Secret Manager or another cloud secret store. The workload would otherwise need an identity to retrieve the key that grants the identity access.
For an API that requires an issued secret, check whether its issuer supports a narrower credential, short-lived tokens, or audience restrictions. Bind credentials to one workload or agent where possible. Token capabilities vary by provider, so confirm the available controls in that API’s current documentation rather than assuming all tokens support them.
Choose an approach that fits the workload
Identity-based access and stored-secret systems solve different problems. Use the identity route when the target service can trust the workload directly; use a secret manager when the application must retrieve an issued secret. A dedicated secrets platform and a cloud-native secret manager are both possible categories, but their suitability depends on the team’s identity integration, operations, availability, and portability needs.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
| Approach | Best fit | Key consideration |
|---|---|---|
| Workload identity or federation | The runtime or external platform can be authenticated directly by the service being called. | Can avoid storing an additional exported service-account credential. Verify that the specific platform and API support the required identity flow. |
| Cloud-native secret manager | The agent must retrieve an API key, password, or other application secret. | Bind access to the workload identity and, where supported, to the individual secret. Secret storage does not limit what an authorized agent can do with the retrieved value. |
| Dedicated secrets platform | The organization needs a separately operated secrets system or wants to assess portability across environments. | Evaluate who operates and patches it, how policies are standardized, and the migration and availability implications. OWASP names HashiCorp Vault as one example of this category. |
OWASP highlights availability, centralization, fine-grained access control, automation, and portability as factors in choosing a secrets-management approach. Google Cloud’s guidance also emphasizes IAM, audit access, replication, and controlled rollout. Compare options on those dimensions, as well as delivery method and regional requirements, rather than assuming that a product category alone determines security.
Give each agent a narrow identity and narrow permissions
Separate credentials or principals by agent, environment, and meaningful trust boundary. Avoid sharing one production key among unrelated agents or between staging and production. At the secret store, allow each principal to retrieve only the required secrets; at the API or service, limit each credential to the operations the task needs. Permission to retrieve a secret is not a substitute for limiting the secret’s downstream privileges.
Apply least privilege to the agent’s tools as well as its credentials. Limit the available tools and the operations each tool may perform, separate tool sets for different trust levels, and require explicit authorization for sensitive actions. OWASP’s guidance on agentic AI identifies excessive tool permissions and credentials in agent context or logs as concerns. An agent that can legitimately retrieve a powerful credential may still use it in an unsafe way.
Rank #3
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Universal Connectivity (USB-C, USB-A, & NFC): Designed for PCs, Macs, iPhones, and Android. For mobile use, simply unfold the key, align it with your phone’s NFC antenna, and hold for a few seconds to authenticate.
- Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.
Store and deliver secrets without exposing them
Do not commit credentials to source control, put them in agent instructions, or paste them into prompts. Use a platform identity or designated secret manager instead of plaintext configuration. OWASP lists cloud secret stores and dedicated systems such as Vault among possible approaches.
Where practical, have the application retrieve the secret through the secret manager’s API. Google Cloud recommends direct Secret Manager API access where possible and cautions that other delivery methods introduce exposure paths:
- Mounted files: A filesystem or directory-traversal vulnerability can expose a secret made available as a file.
- Environment variables: Debug endpoints or dependencies that log the process environment may reveal values.
- Synced copies: Copying a secret into another datastore can expand who can access it or weaken auditability. Review that store’s access controls, audit coverage, encryption, and regional handling.
Some integrations support or require file- or environment-based delivery. If you use one, tightly restrict access to the process and host, and make sure diagnostic output redacts values. Environment variables are a risk to assess, not a universally impossible delivery method.
Rank #4
- USB-C or tap via NFC for easy authentication on any compatible device. No drivers needed; optional Kensington software available for advanced management features.
- Works across Windows, macOS, iOS, Android, ChromeOS, and supports Passkeys and Apple ID.
- Slim, keychain-ready form for easy carry and on-the-go authentication
- IP68-rated for dependable performance
- FIDO CTAP 2.1 for enhanced security features (e.g. resident credentials, Passkey support) and backwards compatibility with CTAP 2. FIDO2 L2 certified security for phishing resistant protection against identity theft and unauthorized access.
Never put credential values in model context, tool outputs, telemetry, traces, error messages, or logs. Redact secrets at the point data is captured, then test the redaction path with dummy credentials. OWASP specifically identifies credentials inadvertently included in agent context or logs as a sensitive-data exposure risk.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Rotate credentials with a staged rollout
Automate lifecycle operations when the issuer and consumers support them. A safe rotation changes the credential in stages so you can verify the replacement before removing the old value:
- Create: Issue a replacement credential with the intended scope and target service.
- Deploy: Make the new credential available to the intended consumers, using versioning or a controlled rollout where supported.
- Test: Confirm the consumers authenticate and perform the required operation with the replacement.
- Disable and monitor: Disable the old credential and watch for remaining use or failures before deleting it.
- Delete: Remove the old credential after validation and monitoring show that it is no longer needed.
OWASP’s rotation guidance separates creation, setting, testing, and completion, and emphasizes checking that a pending credential targets the intended service before promotion. The exact mechanics depend on the credential issuer and application.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Best Value
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
Google Cloud service-account key guidance
Google recommends rotating Google Cloud service-account keys at least every 90 days. This interval is specific to those keys, not a universal schedule for API keys or every other credential. Google’s documented process is to identify keys, create replacements, update applications, disable replaced keys while monitoring, and delete them after validation. Its guidance also warns that expiration can cause production outages if workloads are not rotated correctly. For suspected compromise, rotate immediately rather than waiting for a routine interval.
Prepare to revoke a credential quickly
Maintain an incident path that lets the responsible team revoke a leaked credential at its issuer, find affected consumers, replace dependent credentials if necessary, and inspect relevant access logs. Deleting a leaked value from a repository does not make an already exposed credential safe; revoke or rotate it.
Make sure the people responding can identify the credential’s owner and downstream dependencies without relying on the secret value itself. For Google Cloud service accounts, Google also documents service-account insights that can identify accounts not used in the past 90 days; this is a product-specific monitoring capability, not a general measure of key age or a universal rotation rule.
Audit access and review the whole agent path
Enable secret-access audit logging and alert on unexpected principals, locations, frequency, or access patterns. Google recommends enabling Secret Manager data access logs and monitoring access requests. Keep records useful for investigation by recording principal and event details, not secret material.
Free tools Windows power users keep installed
One-click scans. No signup required.
Review who can change the agent’s tool configuration, alter its workload identity, grant secret access, and inspect its runtime. Consider whether the runtime can exfiltrate values and whether logs or debug endpoints could expose them. Test with dummy secrets, inspect logs and traces for leakage, and rehearse revocation. These checks apply the least-privilege, agent-tool, and audit principles described by OWASP and Google Cloud; they are not a single vendor-prescribed test suite.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

