Video yükleniyor...
Video Yüklenemedi
Composio CTO Karan Vaidya says giving an AI agent your API key is basically making it public once prompt injection enters the picture: "Even if you use [MCP], across all your apps you have to go and authenticate one after the other. If you use Codex, if you switch... show more
16,328 görüntüleme • 15 gün önce •via X (Twitter)
10 Yorum

@KaranVaidya6 U dont have to give api keys to agents. Nobody does that anymore!! U just pass short lived tokens to agents (via a gateway) which in turn hide the real api keys of the services in use.

@KaranVaidya6 the re-auth dance is painful. i keep a separate low-priv dev key for agent runs and still have to rotate it after an invented curl call shows up in the diff.

@KaranVaidya6 Keep the credential out of model context, and scope the broker too. A hidden key can still fund a very visible mistake.

@KaranVaidya6 the real switching cost is reauthorizing your whole life every time the interface changes.

@KaranVaidya6 I bounce off tools that make me reauth every model switch.

@KaranVaidya6 Prompt injection doesn't invent keys. It steals whatever the agent already holds. MCP login loops aren't custody. Scoped keys that never enter the agent are.

Third option they skip: don't give the agent a credential at all. WebMCP (a browser proposal, not a standard yet) does this — the page registers the tools, and they run inside the session the user is already logged into. The server checks that user's permission on every call. No key to leak: an injection gets exactly what the logged-in human already had, and nothing more. The limit is real though — it needs a human session. Is headless what Shared Connections is actually for?

@KaranVaidya6 the auth handoff is the part that still breaks the illusion. every new connector needs its own consent, and agents rarely show which credential or scope they are about to use.

@KaranVaidya6 Handing an agent a live API key is a different threat model than a chat app. Prompt injection turns "authenticated once" into "public forever" real fast.

@KaranVaidya6 The per-app auth sprawl is the real tax here. Even with MCP, each server holds its own token, so a single injected instruction can walk the whole chain of credentials. Scoping keys per tool and rotating on session end helps more than one shared agent identity.
Benzer Videolar
Sensitive content
It’s much easier to build an AI agent, if all you have to do is prompt it! The backend, code execution and deployment are all handled automatically. Even non-techies can build AI agents
Bindu Reddy
51,180 görüntüleme • 1 yıl önce
