CLASSEVE
RouteCompare
Compare

Credential Airlock vs. environment variables

Environment variables are the easy default, but anything the agent's process can read it can log or be tricked into repeating. A credential firewall gives the agent only dummy keys and runs a local deny-by-default proxy that injects real credentials at the network boundary for allow-listed hosts, logging every request it handles — that's Credential Airlock.

Can the agent read the real key?
No — it only ever sees dummy values
Yes — it's in the process environment
Credential Airlock
Prompt-injection blast radius
Capped: nothing real to leak; unknown hosts denied
Full key compromise is possible
Credential Airlock
Destination control
Deny-by-default allow-list per host
None — the key works anywhere
Credential Airlock
Audit trail
Every request through the proxy logged
None by default
Credential Airlock
Setup cost
Install and route agent traffic through the local proxy
Zero
Environment variables

Facts checked Sep 27, 2026. Environment variables’s own site has its current details.

Choose Credential Airlock if
  • Your agent browses, reads untrusted content, or runs semi-autonomously
  • A leaked key would actually hurt (billing, data, production)
  • You want an audit trail of every credentialed request
Choose Environment variables if
  • Short-lived, throwaway keys in a sandbox where a leak costs nothing
FAQ

Common questions.

Is Credential Airlock a complete security boundary?
It is a credential boundary for cooperative agents, not an isolation boundary against untrusted processes running as the same OS user. Containing those needs OS-level isolation layered on top.
What about OS keychains — don't they solve this?
OS keychains protect keys at rest, but once the agent retrieves the key it holds the real value again. The firewall pattern keeps that value out of the agent entirely, and Airlock uses OS protections like DPAPI to seal its own storage.