frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: Do you trust AI agents with API keys / private keys?

5•devendra116•1h ago
are you ok sharing secrets or api keys to you ai agent via .env?

or is there any other tool or mechanism that one use to safegaurd from potential exploit or leaks

Comments

10keane•1h ago
nope. too dangerous - i'm personally working for an agent project and i know from personal experience they do collect your session log - especially in china lol. one approach i use for my own agent is that to use keyring to store all secrets. agent will call a tool to request for it, and it will be something like <secret:gmail.password>. the substitution happens at tool execution time so the llm never sees or logs the actual value.
devendra116•27m ago
keyring is one of solution but even substituting values at excution does not gaurantee the security as agents can read the process itself.

im building a safe agent execution layer, A runtime where agents can act, but cannot access secrets. kinda sidecar that is callable by agent for using api keys, secrets, private keys, etc and plus one can add policy on how and what a agent can do.

does this seems good?

jvqv•41m ago
As a precaution I would probably never pass secrets directly to the agent at all. Something like a placeholder format where the actual substitution happens at execution time so the LLM never sees the real value. Keeps things cleaner if something ever goes wrong.
devendra116•27m ago
is there any tool that can do this ?
para_parolu•15m ago
I use mitmproxy outside of agent vm

A Deep Dive into Tinygrad AI Compiler

https://tinyblog-phi.vercel.app/tinygrad
1•ppadjin123•4m ago•0 comments

Strait of Hormuz Gameplay Demo [video]

https://www.youtube.com/watch?v=XVY7WAT4OdE
1•us321•4m ago•0 comments

Lawsuit over who owns top ranked coding bootcamp Codesmith

https://michaelnovati.substack.com/p/codesmith-in-court-the-hard-parts
1•michaelnovati•9m ago•0 comments

Apple Stops Accepting Orders for Some Mac Mini and Mac Studio Models

https://www.macrumors.com/2026/04/11/some-mac-mini-mac-studio-currently-unavailable/
1•Brajeshwar•11m ago•0 comments

Salesforce and ServiceNow are squaring off in the battle for the helpdesk

https://www.theregister.com/2026/04/11/salesforce_vs_servicenow_itsm_battle/
1•Brajeshwar•12m ago•0 comments

Show HN: Bullseye2D – A Dart library for cross-platform 2D games

https://github.com/bullseye2d/bullseye2d
1•joemanaco•12m ago•0 comments

Apple update looks like Czech mate for locked-out iPhone user

https://www.theregister.com/2026/04/12/ios_passcode_bug/
3•OuterVale•13m ago•0 comments

Phyphox – Physical Experiments Using a Smartphone

https://phyphox.org/
2•_Microft•14m ago•1 comments

Asha Bhosle: The sound of Bollywood dies aged 92

https://www.bbc.com/news/articles/c6ppd0qdp1do
1•Brajeshwar•18m ago•1 comments

Joborigo – Job application tracker with ghost detection and employer API

https://www.joborigo.com/
1•sasanin•18m ago•1 comments

On Division by Three

https://leahneukirchen.org/blog/archive/2023/11.html
1•jruohonen•19m ago•0 comments

Show HN: Food Decoder

https://github.com/adityaprasad-sudo/FoodDecoder
1•PotatoAditya•20m ago•0 comments

Angular Compiler in Rust – Experimental and 10x faster

https://voidzero.dev/posts/oxc-angular-compiler
1•AbuAssar•22m ago•0 comments

Podman Kube Generator – Web UI to Generate Kubernetes YAML and Quadlet Configs

https://github.com/Garfieldttt/podman-kube-generator
2•Garfieldttt•25m ago•0 comments

System Integrity Protection: The misunderstood (macos) setting

https://khronokernel.com/macos/2022/12/09/SIP.html
1•gurjeet•25m ago•0 comments

Can AI Think?

https://medium.com/@henry.ponco/can-ai-ever-truly-think-92d62e509862
1•ponco•27m ago•2 comments

Is Math Big or Small?

https://chessapig.github.io/talks/Big-Small
1•robinhouston•27m ago•0 comments

Show HN: Attempting to Design a Minimalistic Website

https://soham-saha.github.io/
1•omegacombinator•27m ago•0 comments

Sorting with Singeli

https://github.com/mlochbaum/SingeliSort
1•tosh•30m ago•0 comments

How to Read Headphone Measurements (2020)

https://crinacle.com/2020/04/08/graphs-101-how-to-read-headphone-measurements/
1•tosh•30m ago•0 comments

Ask HN: How do you retain what you learn from podcasts?

2•LifeOfKP•34m ago•2 comments

A/B/U Review System

https://openresearchinstitute.org/onboarding/A_B_U.html
1•patcon•36m ago•0 comments

ORAC-NT – A 3D Tactical Bridge for NASA Kepler/Tess Star Stability

https://orac-nt.streamlit.app/
2•DREDREG•36m ago•1 comments

How the "AI Loser" may end up winning

https://adlrocha.substack.com/p/adlrocha-how-the-ai-loser-may-end
1•adlrocha•37m ago•0 comments

The big math changes to small math by same change and solve in Matlab BVP4C

https://www.nature.com/articles/s41598-025-18302-5
1•internet_points•41m ago•0 comments

Build nice terminal UI with Bubble Tea

https://www.prskavec.net/post/bubbletea/
2•swq115•42m ago•0 comments

Ask HN: How is everyone dealing with the increase of code reviews?

2•Lethalman•46m ago•0 comments

The API Key Is Dead: A Blueprint for Agent Identity in the Age of MCP

https://kontext.security/content/oauth-for-mcp-agents
1•mc-serious•47m ago•0 comments

Show HN: OpenPolicy Plus – Cloud platform for managing your privacy policies

https://plus.openpolicy.sh/
2•jamie_davenport•48m ago•0 comments

DSPi – A powerful, open-source DSP

https://www.audiosciencereview.com/forum/index.php?threads/introducing-dspi-a-powerful-user-frien...
2•djsedaw•54m ago•1 comments