Custody boundary
Credential custody covers where an agent credential is created, stored, selected, presented, refreshed, rotated, revoked, logged, and destroyed. Agent systems can hold user-delegated access tokens, refresh tokens, service credentials, API keys, client secrets, certificates, and local session handles.
Keep each credential bound to its issuer, subject, client, tenant, audience, resource, tool, and task context. A credential cache is an authorization boundary.
Broker use
Prefer a broker that selects and uses a credential without exposing it to the model, prompt, tool arguments, logs, or general agent process. Isolate records by user and route. Use short-lived access tokens and protect longer-lived refresh or client credentials in a narrower service. Validate audience and sender context at every use.
Record safe metadata and a fingerprint. Define logout, disconnect, consent withdrawal, user disable, tool removal, token replay, and compromise response. Test cache eviction and revocation propagation.
Failure and residual risk
A model can reveal a credential that entered context. One user's token can leak through a shared cache. Token passthrough can send a credential to a server or audience that was never intended to receive it. Environment variables, command lines, traces, support bundles, and memory dumps can expose secrets.
A broker reduces exposure and becomes a high-value deputy. Compromise can use credentials without extracting them. Enforce action policy at the broker and downstream service.
Pomerium boundary
Pomerium documents per-user, per-route upstream OAuth connection management for MCP routes. Pomerium can acquire, cache, refresh, and inject upstream access tokens for that flow. Operators own provider registration, allowed metadata domains, route policy, disconnect behavior, and downstream authorization. Other credentials in the agent host remain outside this custody boundary.
Evaluation checklist
- Are credentials inaccessible to model context and ordinary tool arguments?
- Is every cache key isolated by user, tenant, route, issuer, and audience?
- Can the broker enforce action and resource policy without exposing the credential?
- Do disconnect, logout, disable, replay, and compromise revoke future use?
- Are logs, traces, dumps, command lines, prompts, and support artifacts credential-free?
