Leaked AI Agent API Key? Why Rotation Is a Five-Minute Job With a Credential Broker and a Week-Long Hunt Without One
6 min read Fullmakt Team
- business-case
- credentials
- governance
- traceability
- observability
- authentication
- agents
- mcp
Sooner or later a key an AI agent used ends up somewhere it shouldn’t be: in a transcript pasted into a ticket, in a debug log, in a repository, or echoed back by a model that was asked politely. Whether the cause is a prompt injection, a credential-bearing log line or plain carelessness, the first instruction is always the same: rotate it.
The key isn’t the hard part. The hard part is that nobody can say how many places it lives.
The failure: one leaked key, eleven copies
Here is a composite of a pattern teams describe often. A support agent calls a billing API. The API key was created once and then, over a few months, copied:
- Into the agent’s environment variables in production.
- Into the same variable in staging, “just to test”.
- Into a second agent’s config, because it needed billing read access too.
- Into an MCP server’s settings on a developer laptop.
- Into a CI secret used by an evaluation job.
- Into a notebook, to reproduce a bug.
When the key leaks, rotating it at the billing provider is one click. Everything that used it breaks at the same moment, and the team spends the next day finding out what “everything” was. Worse, the order of operations is a trap. Rotate first and agents fail in production with no explanation. Hunt first and the leaked key stays live while you search.
Underneath is a governance gap: the key identifies a system, not an agent. The provider’s logs show that the key was used. They can’t say which agent used it, for which task, or whether the leaked copy was used at all. Without that, you can’t tell an incident from a near miss, which is why agent forensics starts with identity.
Why rotation is slow for agents specifically
Rotation is routine for human-operated systems. Agents make it worse in three ways.
- Copies multiply. Every new agent, tool or MCP server tends to get its own pasted secret, the fan-out problem in slow motion.
- Secrets travel through places humans don’t. Prompts, tool arguments, model context and traces all carry text, and text gets stored.
- Nobody owns the credential. Agents are non-human identities that rarely appear in an offboarding or rotation checklist, so keys outlive the people and projects that created them, a theme in agent offboarding.
Rotation as a design property
The fix is not a better rotation schedule. It is arranging things so there is one copy to rotate and the agent never holds it.
In a credential broker model, the agent calls the broker, the broker attaches the credential on the server side, and the secret never enters the prompt, the tool arguments or the agent’s environment. An agent that never saw the key can’t leak it. This is the core of scoped credentials for AI agents.
That changes the incident runbook:
- Contain. Disable or revoke the specific agent’s access in the broker. The upstream key is untouched, and other agents keep working.
- Scope. Query the audit trail for that agent’s calls during the exposure window. You are answering “was it used?” with data, not guesses.
- Rotate. Create the new key at the provider and update the single reference the broker resolves. Agents, MCP clients and A2A peers need no change because they never held the old value.
- Verify. Watch the next calls succeed and confirm nothing still uses the old key.
- Report. Hand the timeline to whoever asked, auditor or customer.
One honest caveat: brokers cache resolved credentials briefly for performance, so a rotated value can take a short time to be picked up. Fullmakt’s default cache lifetime is 60 seconds and it is configurable, which is worth knowing before you plan a rotation window.
The business case: what this saves
Fullmakt is a credential broker for AI agents. Mapped to the runbook above:
- One reference, not eleven copies. Credentials are held as references to a local encrypted vault, an environment variable or an external vault such as HashiCorp Vault, and resolved server-side only at execution time.
- Agent-level revocation. Each agent has its own identity and scoped access to a collection of endpoints, so you can cut one agent off without touching the upstream key or its siblings.
- Evidence for scoping. Every call is recorded in an audit trail tied to the agent identity, and the record notes which credential references were used, never their values. “Was the leaked key used, and by whom?” becomes a query. That is the traceability auditors ask for.
- Less to leak in the first place. Responses can be sanitized before they return to the model, and sensitive actions can require human approval.
- Works with the clients you already use. MCP and A2A are first-class surfaces, so Claude, ChatGPT or an in-house agent connect without a custom OAuth server, as described in MCP OAuth for AI agents.
- Pay for what runs. Pricing is usage-based, with no plans or minimums, and a no-card sandbox lets you rehearse a rotation against your own agents before you need one.
The result is a smaller incident: fewer people paged, no multi-system hunt, and a timeline you can hand over. Teams comparing this with maintaining their own proxy should read build vs buy for the agent credential proxy.
A rotation readiness checklist
- Can you list every place each agent credential is stored today?
- Can you revoke one agent without rotating the shared upstream key?
- Can you show which agent called which API during a given hour?
- Do agents hold secrets in prompts, env vars or config, or only references?
- Have you rehearsed a rotation, including cache expiry and rollback?
If two or more answers are “no”, a leaked key will cost you days, not minutes.
FAQ
What should I do first when an AI agent leaks an API key? Contain before you hunt: cut off the affected agent’s access, then work out whether the key was used, then rotate the upstream key and update where it is stored.
How do I rotate an API key used by an AI agent? Create the new key at the provider and update the one stored reference the agent’s calls resolve through. If agents hold the key directly, you must update every copy, which is why keeping secrets out of agents helps.
Why shouldn’t AI agents hold API keys directly? Anything in a prompt, tool argument or environment can be logged, echoed or exfiltrated through prompt injection. A broker keeps the secret server-side so the agent has nothing to leak.
How do I find out whether a leaked key was used? Only if calls are logged with an agent identity. Provider logs show the key was used, not by which agent. A broker audit trail ties each call to an agent, endpoint and time.
Does a credential broker make rotation instant? It reduces rotation to one place. Resolved credentials may be cached briefly; Fullmakt’s default is 60 seconds, configurable.
What does Fullmakt cost? Usage-based pricing per operation, with no plans or minimums, plus a no-card sandbox for testing.