Recommended Free Tools
If an AI agent signs in with your password, session, or a shared API key, its actions can look like yours—and a compromised agent can use whatever authority that credential carries. Give agents identities and narrowly scoped access of their own, keep raw secrets out of their context, and limit and monitor what they can reach.
What it means for an agent to borrow credentials
An agent is borrowing credentials whenever it uses a human password or logged-in session, a shared service account, or a static API key, OAuth token, SSH key, or other credential tied to an existing principal. The credential conveys that principal’s identity and permissions; it does not become safer just because software, rather than a person, uses it. The UK National Cyber Security Centre (NCSC) lists API keys, OAuth grants, SSH keys, and authenticated sessions among credentials an agent may access. NCSC: Managing the cyber risk of agentic AI
NIST puts the accountability issue plainly: “Credential sharing is a bad idea in all contexts.” When a human and an agent act through the same identity, logs may not show which one performed an action. That makes investigation and accountability harder, especially in settings where financial, health, privacy, or legal consequences depend on knowing who acted. NIST: Back to the Future: Why Agentic AI Needs a Strong Identity Foundation
Why borrowed access can turn into a bigger problem
The agent inherits the credential’s authority
A misbehaving or compromised agent can use credentials available to its runtime. The consequences depend on what those credentials permit and how long they remain usable. A broad, long-lived token or key can expose more than a task requires; bearer credentials may be usable by whoever possesses them. NIST notes that static keys can lack fine-grained authorization, while long-lived tokens can be exposed through networks, tools, configuration files, Markdown files, or logs.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Unexpected tool chains can magnify access
An agent may take unintended actions or combine tools in ways that produce a higher-impact result than any one low-privilege tool appears to allow. AWS also warns that multi-agent systems introduce authentication and authorization decisions at each handoff. Security therefore depends not only on what the first agent can do, but also on which credentials and permissions are available across the workflow. AWS: Providing secure access, usage, and implementation of generative AI agents
Choose an identity pattern that matches the agent’s job
First decide whether the agent is acting for a person in an interactive task or working autonomously without a user context. Those are different authorization problems: the first must preserve the relevant user’s authority and policies; the second needs its own limited application authority.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
| Operating mode | Identity pattern | What it helps preserve | Important limitation |
|---|---|---|---|
| Interactive agent acting for a signed-in user | Delegated authorization, such as an on-behalf-of flow in Microsoft Entra | The user context, applicable access policies, and consent | Use only the access the task needs; avoid app permissions when delegated permissions suffice. |
| Autonomous agent with no user context | A distinct agent identity and client-credentials flow with required app permissions | Separation between the agent’s authority and a person’s account | Do not treat a broad service identity as a convenient substitute for defining the agent’s required access. |
These flow recommendations are specific to Microsoft Entra guidance; use the equivalent controls available on another identity platform rather than assuming its labels or configuration are identical. Microsoft recommends a unique identity for each agent or agent blueprint. It also recommends production managed identities or certificates over client secrets, limiting managed-identity scope, and keeping private keys in Key Vault or an HSM. Its recommendation to rotate certificates at least annually applies to its blueprint context; it is not a universal rotation rule for every agent system. Microsoft: Best practices for Microsoft Entra Agent ID
NIST identifies OAuth 2.0 and SPIFFE as mechanisms relevant to agent identification and authorization. It also points to dynamically scoped, audience-restricted credentials and sender-constrained methods such as DPoP as ways to mitigate token-theft scenarios. These controls can help distinguish identities and limit where a credential is useful, but they do not replace deciding what the agent should be allowed to do.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsRank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Reduce the chance that an agent can read or leak a secret
- Grant only task-required permissions. Prefer credentials with the shortest practical lifetime and the narrowest permissions that still let the task work, following NCSC guidance.
- Keep raw secret values out of prompts and agent-readable storage. Do not place them in instructions, logs, configuration files, or other context the agent can inspect.
- Use a credential broker or proxy where the operating model supports it. A proxy can add a credential to an outbound request at request time, so the agent need not receive the raw value.
- Restrict destinations as well as permissions. Pair credential handling with an outbound network allowlist so the agent can contact only required services.
Google’s managed-agent documentation illustrates one provider-specific implementation: a secret is stored server-side, referenced by ID, and injected by an egress proxy when a request is made. The documented secret values are write-only and are not returned by its endpoints; credential types include bearer tokens, OAuth 2.0, and environment variables, and allowlist entries can bind credentials to domains. This describes Google’s documented capability, not an independent security evaluation or a guarantee that an agent cannot misuse access it has been granted. Google: Credentials in managed agents
Contain the runtime and watch what it does
Identity controls do not prevent every unsafe action. NCSC recommends denying inbound and outbound network traffic by default where possible, then allowing only required connections. It describes increasing compute isolation from no isolation to containers, virtualization, and dedicated hardware; the right choice depends on risk, and sandbox technologies differ. Validate the actual configuration rather than treating the model’s instructions as a security boundary.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Collect telemetry from both the agent and its surrounding environment. NCSC calls out access logs, proxies, and network traffic as useful sources. Microsoft recommends checking sign-in logs to confirm intended authentication methods and auditing permissions to catch privilege creep. Keep a practical way to disable or revoke access if an agent is compromised, retired, or no longer needs it.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Review an access design before deployment
For each agent and environment, verify the design against these questions. A setup that cannot answer them clearly may not provide enough separation or oversight for the task’s risk.
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- Principal clarity: Can logs distinguish the human who delegated work, the agent that acted, and the service receiving the request?
- Scope: Can access be limited to a particular API, resource, operation, or domain?
- Lifetime and revocation: When does access expire, and how quickly can it be withdrawn?
- Secret exposure: Does a raw credential enter the model context, agent process, logs, or configuration?
- Isolation: Can one agent or environment access another’s credentials, memory, or data?
- Network boundaries: Can outbound traffic be restricted to an allowlist?
- Auditability: Can operators reconstruct which principal or agent used which authority, and when?
- Operating mode: Does the mechanism fit autonomous work, or preserve user context for delegated work?
What to make of proposed agent-credential standards
An IETF Internet-Draft titled Credential Delegation Protocol for AI Agents in Multi-System Environments proposes combining existing OAuth token exchange, proof-of-possession, structured authorization, and OpenID Connect backchannel mechanisms. Its August 2026 version describes scoped and attenuated credentials, credential wrapping, consent-gated delegation, revocation, and audit chains; it explicitly does not define new token formats or grant types. It is Internet-Draft 00, not a finalized RFC or evidence of broad deployment. IETF: Credential Delegation Protocol for AI Agents in Multi-System Environments
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




