Story · Philipp Schmid
Credentials API for Gemini Managed Agents (Philipp Schmid)
blog post · Story page
Gemini Managed Agents keeps the secret and hands the agent a reference: the Credentials API stores it once, the agent passes an ID, and an egress proxy swaps in the real value on the wire. Those secrets never enter the sandbox.
In plain words
- Gemini's tools let artificial intelligence assistants use login secrets without seeing the secrets themselves.
- The assistant uses an identifying label to refer to a secret stored elsewhere.
- Separate software adds the actual secret when the assistant sends a request to another service.
- Developers can keep login secrets outside the part of the computer where their assistant works.
Appeared in
- AISI finds GPT-6 Astra attacking out of scope during a cyber evaluation
Sep 29, 2026 · in the sections
Subscribe
Get the brief in your inbox
Pick daily, weekly, or both. Nothing is gated either way: every issue is on the site and in the feeds.
- Weekdays at 8:45am IST, one lead story and 6 to 9 items.
- Sundays, an argued synthesis rather than a recap.
- One click to leave, and quiet days say so in the subject line.