api-keys

Tag

Cards List
#api-keys

@_philschmid: Passing API keys or secrets as normal env lets any dependency in your agent's sandbox read and potentially leak them. T…

X AI KOLs Timeline ↗ · 2d ago Cached

The article highlights the security risks of passing API keys as environment variables in sandboxed agents and introduces the Credentials API for Gemini Managed Agents, which secures secrets by injecting them only for trusted domains.

0 favorites 0 likes
#api-keys

How do you guys give your models web browsing capabilities?

Reddit r/LocalLLaMA ↗ · 3d ago

The user is seeking reliable methods to give their AI model, specifically using Deepseek Harness, web browsing and search capabilities, noting issues with paid APIs and unreliable free options like SearXNG.

0 favorites 0 likes
#api-keys

Your agent just found an API key in your repo. What happens next?

Reddit r/AI_Agents ↗ · 2026-09-22

A coding agent unexpectedly used an available API key from a repository, leading to higher costs, which underscores the importance of credential scoping in AI agent deployments to prevent unauthorized access and cost overruns.

0 favorites 0 likes
#api-keys

@LangChain: LangSmith LLM Gateway lets you govern model access across your org. Lock a key to permitted models, and every other mod…

X AI KOLs Timeline ↗ · 2026-09-14 Cached

LangSmith LLM Gateway enables organizations to control model access by restricting API keys to specific models and automatically blocking unauthorized calls, demonstrated with Opus 5 and Sonnet 5.

0 favorites 0 likes
#api-keys

@ant_av7: Take a look at our latest research on DockerHub secrets exposure! This time, we focused on high-value targets and we fo…

X AI KOLs Timeline ↗ · 2026-09-03 Cached

Binarly's research on DockerHub uncovers widespread exposure of secrets and credentials that could compromise major enterprises, and shows how fine-tuned LLMs can be used for cost-effective automated triage.

0 favorites 0 likes
#api-keys

@XQOPTRX: [AGENT IDENTITY] — DESCOPE LAUNCHES CROSS-APP ACCESS TO REPLACE STATIC API KEYS WITH SHORT-LIVED IDENTITY ASSERTIONS FO…

X AI KOLs Following ↗ · 2026-09-01 Cached

Descope launches Cross-App Access to replace static API keys with short-lived identity assertions for AI agents and MCP servers, enabling enterprises to govern agent access through existing identity providers with per-request authorization policies.

0 favorites 0 likes
#api-keys

I scanned AI-generated code for exposed API keys — the patterns repeat, so I built a tool for it

Reddit r/AI_Agents ↗ · 2026-08-23

The author scanned AI-generated code projects and found repeated patterns of exposed API keys, leading them to build NeuralScan, a tool that scans code for secrets and dangerous patterns, explaining fixes in plain English.

0 favorites 0 likes
#api-keys

Protect Your Relays

Hacker News Top ↗ · 2026-08-10 Cached

Iroh's managed relays are now authenticated by default, requiring API-key-issued capability tokens so only authorized endpoints can use them, preventing relay abuse and traffic hijacking.

0 favorites 0 likes
#api-keys

@patio11: There are many forms of security through obscurity, technical and otherwise, and many of them are going to come under s…

X AI KOLs Following ↗ · 2026-08-06 Cached

Patrick McKenzie argues that many forms of security through obscurity will face severe pressure once adversaries can leverage AI models equivalent to 10,000 research analysts, urging users to remove exposed API keys and credentials from the open internet.

0 favorites 0 likes
#api-keys

@tszzl: needless to say but if you have any API keys, eth wallet keys, user credentials, etc hanging out on the open internet i…

X AI KOLs Following ↗ · 2026-08-06

A tweet warns developers to remove exposed API keys, wallet keys, and credentials from public repositories before AI models find and exploit them.

0 favorites 0 likes
#api-keys

Why do AI coding tools charge a subscription when users already have API keys?

Reddit r/AI_Agents ↗ · 2026-07-25

The article discusses the subscription pricing model of AI coding tools and introduces CleanSlate's alternative: free usage with your own API key, with an optional managed plan. It questions whether developers prefer bringing their own API key or paying a fixed monthly fee.

0 favorites 0 likes
#api-keys

We gave our agents production API keys which I'm starting to think was a mistake

Reddit r/AI_Agents ↗ · 2026-07-22

A cautionary tale about the risks of granting AI agents production API keys, highlighting potential unintended consequences.

0 favorites 0 likes
#api-keys

Your AI agent's history is quietly storing the API keys you pasted into it

Reddit r/AI_Agents ↗ · 2026-07-15

A developer highlights that AI agent history files store API keys pasted into prompts, and introduces an open-source CLI tool to scan and redact those secrets locally.

0 favorites 0 likes
#api-keys

If you're new to coding agents: they keep a diary, and your API keys are in it

Reddit r/AI_Agents ↗ · 2026-07-13

Coding agents like Claude Code, Cursor, and Codex save session logs locally, potentially exposing sensitive data like API keys and environment variables. A developer named Ishan created an offline tool to scan and redact secrets from these logs, addressing a common security blind spot.

0 favorites 0 likes
#api-keys

Why We Don't Trust the Database with Authentication

Hacker News Top ↗ · 2026-07-07 Cached

This article explains the dangers of trusting the database as the sole source of truth for API authentication, using a SQL injection scenario, and presents Sturdy Statistics' approach of using HMAC-SHA512 with a cryptographic pepper for defense in depth.

0 favorites 0 likes
#api-keys

@KanikaBK: I am a beta tester for ClinePass & honestly it's amazing! Average developer in 2026 juggles 5+ API keys across 3 provid…

X AI KOLs Following ↗ · 2026-07-01 Cached

ClinePass launches a $9.99/month subscription giving discounted access to top open-weight models like GLM-5.2, DeepSeek V4 Pro, and Kimi K2.7, integrated into Cline CLI and IDE. A beta tester praises it as a solution for developers juggling multiple API keys.

0 favorites 0 likes
#api-keys

i completely misunderstood what clients actually pay for

Reddit r/AI_Agents ↗ · 2026-06-30

A developer reflects that the hardest part of building AI automations for businesses is not the workflow design but managing integrations, permissions, and building client trust around system access.

0 favorites 0 likes
#api-keys

Run Codex and Claude with any model including GLM 5.2. No settings file headaches.

Reddit r/ArtificialInteligence ↗ · 2026-06-25

A CLI tool called relay-ai acts as a proxy for Codex Desktop and Claude Code, enabling users to route requests to any model (including GLM 5.2) using their own API keys or OAuth subscriptions, with features to prevent crashes and manage context overflow.

0 favorites 0 likes
#api-keys

We’re getting hit by AI sticker shock. How are you guys catching and stopping this stuff?

Reddit r/AI_Agents ↗ · 2026-06-17

A discussion about unexpected high AI API costs due to bad loops, unauthorized key usage, and lack of monitoring; seeking advice on detection and prevention.

0 favorites 0 likes
#api-keys

Anyone else tired of juggling API keys + billing for every tool your agent touches?

Reddit r/AI_Agents ↗ · 2026-06-12

Discusses the hassle of managing separate API keys and billing for multiple tools in agent workflows. Highlights Orthogonal (YC W26), an MCP server/SDK offering unified pay-per-call access to various APIs.

0 favorites 0 likes
Next →
← Back to home

Submit Feedback