Credentials
The gate’s credential broker keeps real keys out of the sandbox. The agent works with a placeholder; the gate swaps in the real key only on the way out, after the rules and any approval.
export ANTHROPIC_API_KEY=…noset run --credential ANTHROPIC_API_KEY -- claudeHow it works
Section titled “How it works”- The key comes from the gate’s environment, the one you start
noset runin. The sandbox never sees the host environment. - Inside the sandbox the variable of the same name holds a random placeholder. The agent and its tools use it as if it were the key.
- When a request leaves the sandbox, the gate checks it against the rules first. Only then, and only if the request goes to one of the key’s hosts over HTTPS, does the gate replace the placeholder with the real key.
- The key is masked in everything the gate prints or records.
Which hosts get the key
Section titled “Which hosts get the key”These keys know their host:
| Variable | Host |
|---|---|
ANTHROPIC_API_KEY |
api.anthropic.com |
OPENAI_API_KEY |
api.openai.com |
GEMINI_API_KEY, GOOGLE_API_KEY |
generativelanguage.googleapis.com |
For any other key, name its hosts:
noset run --credential BILLING_TOKEN@api.example.com -- my-agentnoset run --credential BILLING_TOKEN@api.example.com,billing.example.com -- my-agent--credential can be given several times, once per key.
Where the key goes, and where it does not
Section titled “Where the key goes, and where it does not”The gate puts the real key only into these request headers: Authorization (for example Bearer …), x-api-key, x-goog-api-key and api-key. Everything else keeps the placeholder:
- requests to any other host;
- plain HTTP;
- other headers, the URL and the body.
So a server that echoes an unexpected value back cannot hand the real key to the agent.
Limits
Section titled “Limits”- Only keys sent in one of those headers are brokered. A key that goes in the URL (
?key=…), Basic auth or a request signature (AWS) is not supported yet. - Keep real keys out of the workspace: a
.envfile in your project folder is visible to the agent like any other file.