Give tools access. Keep keys out of prompts.
Supply configured credentials to tool processes at runtime so an agent can request a capability without needing the credential in its prompt.
Separate the request from the credential
The agent requests a tool action. The runtime supplies configured credentials to the tool process. Restrict credentials to the permissions that integration needs.
Scan governed traffic
Configured secret detection checks supported patterns on governed paths. Detection is a defense against accidental exposure, not a guarantee that every encoding or unknown credential can be recognized.
Review the tool boundary
A tool process that receives a credential can use it. Review trusted tool code, constrain network access and host permissions, and monitor outputs as part of your deployment.
Bring your deployment questions.
Discuss your clients, tools, and security requirements with the team building SystemPrompt.