Credential Airlock vs. environment variables
Environment variables are the easy default, but anything the agent's process can read it can log or be tricked into repeating. A credential firewall gives the agent only dummy keys and runs a local deny-by-default proxy that injects real credentials at the network boundary for allow-listed hosts, logging every request it handles — that's Credential Airlock.
- Can the agent read the real key?
- No — it only ever sees dummy values
- Yes — it's in the process environment Credential Airlock
- Prompt-injection blast radius
- Capped: nothing real to leak; unknown hosts denied
- Full key compromise is possible Credential Airlock
- Destination control
- Deny-by-default allow-list per host
- None — the key works anywhere Credential Airlock
- Audit trail
- Every request through the proxy logged
- None by default Credential Airlock
- Setup cost
- Install and route agent traffic through the local proxy
- Zero Environment variables
Facts checked Sep 27, 2026. Environment variables’s own site has its current details.
- Your agent browses, reads untrusted content, or runs semi-autonomously
- A leaked key would actually hurt (billing, data, production)
- You want an audit trail of every credentialed request
- Short-lived, throwaway keys in a sandbox where a leak costs nothing
Common questions.
Is Credential Airlock a complete security boundary?
It is a credential boundary for cooperative agents, not an isolation boundary against untrusted processes running as the same OS user. Containing those needs OS-level isolation layered on top.
What about OS keychains — don't they solve this?
OS keychains protect keys at rest, but once the agent retrieves the key it holds the real value again. The firewall pattern keeps that value out of the agent entirely, and Airlock uses OS protections like DPAPI to seal its own storage.
- OWASP Secrets Management Cheat Sheet — environment variables are generally accessible to all processes and may land in logs
- OWASP Top 10 for LLM Applications — LLM01 prompt injection, including disclosure of sensitive information
- Linux manual — environ(7): a child process inherits a copy of its parent's environment
- Apple Developer — Keychain Services