Skip to content

Question of the day

Google's new Credentials API for Gemini managed agents stores secrets and injects them at request time, so the agent uses a token it never reads. Do you treat an agent like that as an identity in its own right, with its own access reviews, or does it still sit under whoever set it up?

No replies yet

Anyone can read the thread. Replying is for AISAT members. Sign in to join in, or apply if you have not already. It is free, and approval usually takes a day or two.