Agent credentials
Your GitHub or Slack, used by an agent that never holds the secret.
Distinct from provider keys, which buy model tokens, and from opsen API keys, which authenticate you. These are your own accounts elsewhere, lent to a run.
How it works
The secret stays with opsen. On the way out of the sandbox, opsen attaches it — and only for the hosts listed against that credential. An agent talked into calling somewhere else is refused before the request leaves.
The host list is the protection, not a convenience. Without it, lending a credential would be a way to launder your key to any address an injected prompt names.
Adding and lending
Add one on the credentials page, then lend it by name when you start a run. The loan ends when the run ends.
A credential is never written into the sandbox
environment. The agent makes an ordinary request; opsen fills in the
authorization on the way past.