Skip to content

Credentials

The gate’s credential broker keeps real keys out of the sandbox. The agent works with a placeholder; the gate swaps in the real key only on the way out, after the rules and any approval.

Terminal window
export ANTHROPIC_API_KEY=…
noset run --credential ANTHROPIC_API_KEY -- claude
  • The key comes from the gate’s environment, the one you start noset run in. The sandbox never sees the host environment.
  • Inside the sandbox the variable of the same name holds a random placeholder. The agent and its tools use it as if it were the key.
  • When a request leaves the sandbox, the gate checks it against the rules first. Only then, and only if the request goes to one of the key’s hosts over HTTPS, does the gate replace the placeholder with the real key.
  • The key is masked in everything the gate prints or records.

These keys know their host:

Variable Host
ANTHROPIC_API_KEY api.anthropic.com
OPENAI_API_KEY api.openai.com
GEMINI_API_KEY, GOOGLE_API_KEY generativelanguage.googleapis.com

For any other key, name its hosts:

Terminal window
noset run --credential BILLING_TOKEN@api.example.com -- my-agent
noset run --credential BILLING_TOKEN@api.example.com,billing.example.com -- my-agent

--credential can be given several times, once per key.

The gate puts the real key only into these request headers: Authorization (for example Bearer …), x-api-key, x-goog-api-key and api-key. Everything else keeps the placeholder:

  • requests to any other host;
  • plain HTTP;
  • other headers, the URL and the body.

So a server that echoes an unexpected value back cannot hand the real key to the agent.

  • Only keys sent in one of those headers are brokered. A key that goes in the URL (?key=…), Basic auth or a request signature (AWS) is not supported yet.
  • Keep real keys out of the workspace: a .env file in your project folder is visible to the agent like any other file.