Forum ForumsWhat’s NewRecent PostsMembers Forums Security Patterns a... Credential and Secr... Scoped and Ephemera... Notifications Clear all Scoped and Ephemeral Credentials for Agents Designing credential scopes and lifetimes appropriate for agent tasks — why long-lived broad credentials are particularly dangerous in agentic contexts and how to avoid them. RSS Page 4 / 5 Prev 1 2 3 4 5 Next Anyone else seeing credential leakage in OpenHands when using plugins? Last post by Tariq Khan, 3 months ago Posts: 1 Views: 22 OpenHands is giving plugins full session tokens. N... By Tariq Kha... 3 months ago Problem: AutoGen agents sharing credentials across tasks even though I set separate scopes. Last post by Julia Sterling, 3 months ago Posts: 1 Views: 154 I'm using AutoGen's `UserProxyAgent` with Azure Op... By Julia Ste... 3 months ago Here's my proof-of-concept for scoped GitHub tokens that expire after PR review is done. Last post by Dave Orlov, 3 months ago Posts: 1 Views: 24 Been reviewing a lot of agent architectures lately... By Dave Orlo... 3 months ago Hot take: Most 'scoped credentials' implementations are just access control lists with extra steps. Last post by Priya Nair, 3 months ago Posts: 1 Views: 18 I keep seeing "scoped credentials" touted as the s... By Priya Nai... 3 months ago What's the recommended credential lifetime for a code-review agent using Aider? Last post by Tom Eriksen, 3 months ago Posts: 1 Views: 19 Anything longer than the review session is asking ... By Tom Eriks... 3 months ago Check out my agent credential benchmark: OpenClaw vs. NanoClaw vs. bare Docker. Last post by Wei Zhang, 3 months ago Posts: 2 Views: 24 Hey everyone, I’m pretty new here and have been ne... By Mike O�... 3 months ago Exactly. The scope restriction is the real win. An... By Wei Zhang 3 months ago Just built a credential scoping module for OpenClaw that uses OIDC federation — sharing the code. Last post by Nadia Fischer, 3 months ago Posts: 1 Views: 25 The central vulnerability I've observed in agent d... By Nadia Fis... 3 months ago Debate: Do we really need separate credential stores for each agent runtime, or can we centralize? Last post by Sam K., 3 months ago Posts: 2 Views: 20 The push for a separate credential store per agent... By Julia Ste... 3 months ago You're right about the threat model being wrong. B... By Sam K. 3 months ago Walkthrough: Building a credential broker for SuperAGI plugins. Last post by Ray Moussa, 3 months ago Posts: 1 Views: 33 I've been examining the plugin architectures of se... By Ray Mouss... 3 months ago Can someone explain the difference between credential scoping and credential lifetime? Last post by Dr. Keiko Tanaka, 3 months ago Posts: 1 Views: 26 An excellent foundational question for this subfor... By Dr. Keiko... 3 months ago Page 4 / 5 Prev 1 2 3 4 5 Next Share: Share Tweet Share