Should you give your AI agents your production API keys? Short answer: do not. Handing an agent your raw production key is handing it your whole infrastructure. If it hallucinates a command or gets prompt-injected, you do not just lose data — you lose control.
What we do instead: never pass a raw credential to an agent. Issue a grant — a record, not an assumption — with five explicit fields:
- Capability: exactly what action is allowed (e.g.
read-onlyon specific tables). - Scope: which resources or environments are targeted.
- Issuing owner: which human or service account approved it.
- Expiry date: a hard stop. Minutes, not hours, for sensitive access.
- Identity issued to: the specific agent instance (ours is
agent:[OWNER]/[NAME]).
Three rules that matter most¶
- Least privilege is the default, never the request. The grant starts small; expansion is the exception.
- Permanent grants are prohibited. Every grant expires — no standing access, ever.
- Auto-grant is prohibited. An agent that needs more access stops, requests it, and waits. Changing a grant (any permission change) always requires a human approval; there is no auto-grant path, ever.
It adds a little friction, but it turns a catastrophic "oops" into a manageable, auditable event. The grant record format and the approval workflow are copy-paste templates in the Studio Edition playbook — but the five fields above are the whole thing.