Protecting Keys, Passwords, and Private Data
Agents need credentials to do useful things: passwords, API keys and login tokens. How you handle them decides whether a slip stays small.
Do not paste passwords or keys into a chat, and do not leave them in files an agent can read. Anything in the agent’s working folder may be sent to the AI company as part of a request, and could also be exposed if the agent is tricked. Keep credentials in a proper password manager or in the app’s own secure settings, and give the agent access through that route where the tool supports it.
Use separate keys for separate jobs, with the lowest permissions and, where possible, a spending limit. If a key leaks, you revoke that one key and the damage is contained. A single master key used everywhere turns one mistake into a disaster.
Think about other people’s data too. Client files, customer lists and private messages carry obligations, and an agent that reads them may be sending them to a third party. If you would not email the file to a stranger, do not point an agent at it without checking the tool’s terms.
Finally, know how to rotate a key. If you suspect a leak, do not wait. Create a new key, delete the old one, and check the service’s activity log.
Takeaway: keep credentials out of chats and out of agent-readable folders, use separate low-permission keys, and be ready to revoke one quickly.
Tools, prices and features in this area change quickly. Last reviewed September 2026.