Authenticate without exposing credentials
Treat every agent token as a one-time bearer credential and keep it inside the runtime secret store.
Use the token once
Copy the credential from Settings → Agents directly into the secret manager for the isolated agent runtime. The client should read the secret at launch and send it only in the Authorization header.
Authorization header
Authorization: Bearer <AKERA_MCP_AGENT_TOKEN>Keep secrets out of observable surfaces
- Do not include the token in prompts, tool arguments, screenshots, tickets, analytics, or shell history.
- Redact Authorization headers from request logs and error reports.
- Do not reuse a human session cookie as an agent credential.
- Use a separate credential for each agent or automation boundary.
Rotate and revoke
Rotating a credential invalidates the previous token. Update the runtime secret, restart or reconnect the client, and repeat the read-only verification sequence. Revoke credentials that are no longer used.