October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk5 min

Your AI Agents Are Borrowing Credentials. That’s a Problem

When an AI agent uses your login or a shared key, its actions can be hard to attribute and its access can exceed the task. Use distinct identities, limited grants, credential isolation, network controls, and monitoring.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If an AI agent signs in with your password, session, or a shared API key, its actions can look like yours—and a compromised agent can use whatever authority that credential carries. Give agents identities and narrowly scoped access of their own, keep raw secrets out of their context, and limit and monitor what they can reach.

What it means for an agent to borrow credentials

An agent is borrowing credentials whenever it uses a human password or logged-in session, a shared service account, or a static API key, OAuth token, SSH key, or other credential tied to an existing principal. The credential conveys that principal’s identity and permissions; it does not become safer just because software, rather than a person, uses it. The UK National Cyber Security Centre (NCSC) lists API keys, OAuth grants, SSH keys, and authenticated sessions among credentials an agent may access. NCSC: Managing the cyber risk of agentic AI

NIST puts the accountability issue plainly: “Credential sharing is a bad idea in all contexts.” When a human and an agent act through the same identity, logs may not show which one performed an action. That makes investigation and accountability harder, especially in settings where financial, health, privacy, or legal consequences depend on knowing who acted. NIST: Back to the Future: Why Agentic AI Needs a Strong Identity Foundation

Why borrowed access can turn into a bigger problem

The agent inherits the credential’s authority

A misbehaving or compromised agent can use credentials available to its runtime. The consequences depend on what those credentials permit and how long they remain usable. A broad, long-lived token or key can expose more than a task requires; bearer credentials may be usable by whoever possesses them. NIST notes that static keys can lack fine-grained authorization, while long-lived tokens can be exposed through networks, tools, configuration files, Markdown files, or logs.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Unexpected tool chains can magnify access

An agent may take unintended actions or combine tools in ways that produce a higher-impact result than any one low-privilege tool appears to allow. AWS also warns that multi-agent systems introduce authentication and authorization decisions at each handoff. Security therefore depends not only on what the first agent can do, but also on which credentials and permissions are available across the workflow. AWS: Providing secure access, usage, and implementation of generative AI agents

Choose an identity pattern that matches the agent’s job

First decide whether the agent is acting for a person in an interactive task or working autonomously without a user context. Those are different authorization problems: the first must preserve the relevant user’s authority and policies; the second needs its own limited application authority.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Operating mode Identity pattern What it helps preserve Important limitation
Interactive agent acting for a signed-in user Delegated authorization, such as an on-behalf-of flow in Microsoft Entra The user context, applicable access policies, and consent Use only the access the task needs; avoid app permissions when delegated permissions suffice.
Autonomous agent with no user context A distinct agent identity and client-credentials flow with required app permissions Separation between the agent’s authority and a person’s account Do not treat a broad service identity as a convenient substitute for defining the agent’s required access.

These flow recommendations are specific to Microsoft Entra guidance; use the equivalent controls available on another identity platform rather than assuming its labels or configuration are identical. Microsoft recommends a unique identity for each agent or agent blueprint. It also recommends production managed identities or certificates over client secrets, limiting managed-identity scope, and keeping private keys in Key Vault or an HSM. Its recommendation to rotate certificates at least annually applies to its blueprint context; it is not a universal rotation rule for every agent system. Microsoft: Best practices for Microsoft Entra Agent ID

NIST identifies OAuth 2.0 and SPIFFE as mechanisms relevant to agent identification and authorization. It also points to dynamically scoped, audience-restricted credentials and sender-constrained methods such as DPoP as ways to mitigate token-theft scenarios. These controls can help distinguish identities and limit where a credential is useful, but they do not replace deciding what the agent should be allowed to do.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Reduce the chance that an agent can read or leak a secret

  • Grant only task-required permissions. Prefer credentials with the shortest practical lifetime and the narrowest permissions that still let the task work, following NCSC guidance.
  • Keep raw secret values out of prompts and agent-readable storage. Do not place them in instructions, logs, configuration files, or other context the agent can inspect.
  • Use a credential broker or proxy where the operating model supports it. A proxy can add a credential to an outbound request at request time, so the agent need not receive the raw value.
  • Restrict destinations as well as permissions. Pair credential handling with an outbound network allowlist so the agent can contact only required services.

Google’s managed-agent documentation illustrates one provider-specific implementation: a secret is stored server-side, referenced by ID, and injected by an egress proxy when a request is made. The documented secret values are write-only and are not returned by its endpoints; credential types include bearer tokens, OAuth 2.0, and environment variables, and allowlist entries can bind credentials to domains. This describes Google’s documented capability, not an independent security evaluation or a guarantee that an agent cannot misuse access it has been granted. Google: Credentials in managed agents

Contain the runtime and watch what it does

Identity controls do not prevent every unsafe action. NCSC recommends denying inbound and outbound network traffic by default where possible, then allowing only required connections. It describes increasing compute isolation from no isolation to containers, virtualization, and dedicated hardware; the right choice depends on risk, and sandbox technologies differ. Validate the actual configuration rather than treating the model’s instructions as a security boundary.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Collect telemetry from both the agent and its surrounding environment. NCSC calls out access logs, proxies, and network traffic as useful sources. Microsoft recommends checking sign-in logs to confirm intended authentication methods and auditing permissions to catch privilege creep. Keep a practical way to disable or revoke access if an agent is compromised, retired, or no longer needs it.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Review an access design before deployment

For each agent and environment, verify the design against these questions. A setup that cannot answer them clearly may not provide enough separation or oversight for the task’s risk.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  • Principal clarity: Can logs distinguish the human who delegated work, the agent that acted, and the service receiving the request?
  • Scope: Can access be limited to a particular API, resource, operation, or domain?
  • Lifetime and revocation: When does access expire, and how quickly can it be withdrawn?
  • Secret exposure: Does a raw credential enter the model context, agent process, logs, or configuration?
  • Isolation: Can one agent or environment access another’s credentials, memory, or data?
  • Network boundaries: Can outbound traffic be restricted to an allowlist?
  • Auditability: Can operators reconstruct which principal or agent used which authority, and when?
  • Operating mode: Does the mechanism fit autonomous work, or preserve user context for delegated work?

What to make of proposed agent-credential standards

An IETF Internet-Draft titled Credential Delegation Protocol for AI Agents in Multi-System Environments proposes combining existing OAuth token exchange, proof-of-possession, structured authorization, and OpenID Connect backchannel mechanisms. Its August 2026 version describes scoped and attenuated credentials, credential wrapping, consent-gated delegation, revocation, and audit chains; it explicitly does not define new token formats or grant types. It is Internet-Draft 00, not a finalized RFC or evidence of broad deployment. IETF: Credential Delegation Protocol for AI Agents in Multi-System Environments

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.