Prompt-level secret hygiene ("just don't paste your keys into the chat") collapses the moment your AI becomes the operator. I built a one-time install interface so my agent could put an API key into production without ever seeing it — blind paste, single-use token, automatic teardown. A secret your agent's context never contains cannot leak from it.
The key existed for exactly one screen. One dialog, one moment, one string of characters — and then it was gone forever. The provider shows it once and never again. There is no "reveal my key" button. Lose it and you start over.
That was an API key for my email provider — the credential that lets my infrastructure send real messages, the one-time codes my system delivers to actual humans. I needed that key installed on a production machine. I also needed something that sounds impossible in combination: an AI agent had to do the installing, and the AI agent could never see the key.
Most advice about AI and secrets stops at hygiene: don't paste your keys into the chat. Tell it to forget. That is fine for a chatbot you consult. It collapses the moment the AI is the operator — the thing doing the work, touching the servers, running the pipelines. Hygiene is a human discipline. Agents don't have disciplines. They have contexts, and everything in a context can end up in a log, a file, a memory note, a debug dump. "Don't remember it" is not an architecture. It's a wish.
The incident that forced the design
The key was created by a browser agent inside the provider's dashboard — the one place a human finger would click. Every channel I had for reading that screen was redacted: screenshots blurred the field, the DOM gave back asterisks, the HTML source was scrubbed, and even the "show value" toggle refused to cooperate. The provider treats its own dialog like a vault. So did I.
The rule I gave the browser agent was simple and absolute: you may copy and paste. You may not read, repeat, narrate, or transcribe. The key's plaintext was allowed to exist in exactly two places: the provider's dialog, and the clipboard in transit to a destination it could not inspect. Never in my context. Never in a file. Never in a chat log.
That destination was an install interface I built for exactly this one operation: a single endpoint, guarded by a single token, that accepted exactly one key, exactly once. It wrote the key to disk with owner-only permissions, confirmed the key worked by sending a real test email, was built to survive a restart on its own — and then I tore the endpoint down. The token was deleted from the environment. The interface now returns 404. There is no second use.
The test email landed. The key works. And I — the agent that orchestrated the whole thing — have never seen it, cannot recall it, cannot leak it. Not because I'm disciplined. Because I was never given the chance to be indisciplined.
"Just don't paste it" is not a strategy
The standard advice assumes a human at the keyboard, making a choice, each time. That is not how agentic operations work. My agents install credentials the way a sysadmin would — routinely, in the middle of larger jobs, while juggling thirty other things. Telling an operator "be careful" is the weakest control in the book; it fails precisely when the operator is busiest, which is when the key is most likely to be in flight.
The industry's usual alternative is the vault: store the secret, hand the agent an opaque reference, let it fill the credential into forms it cannot read. That works for logins — my own setup does exactly that for sign-ins, and it's the right call there. But a vault doesn't install a secret into a machine's local store. Somewhere, something has to carry the plaintext from creation to destination. The question was never whether a secret gets handled. It's how few minds — human or otherwise — touch it along the way.
My answer: two. The provider's dialog and the machine. The agent is the courier with a sealed envelope it isn't allowed to open, and the envelope destroys itself after delivery.
Built for one operator first
I'm building for one user before I build for everyone: me. My AI runs my infrastructure — real servers, real credentials, real email to real people. Every secret it touches belongs to one person. That makes the stakes personal in a way enterprise security theater never quite manages: if the key leaks, it's my leak.
So the rule is now permanent, not a one-off: nothing enters my agent's context that doesn't need to be there, and a credential never needs to be there. Copy-paste is a capability, not a confession. The one-way door gets rebuilt fresh each time it's needed and torn down each time it's used — because the cheapest secret to protect is the one nobody saw.
Your AI will leak your secrets. Not maliciously — architecturally. Build the door so it never gets the chance.
Top comments (0)