How to Keep API Keys Out of a Coding Agent's Context With a Credential Gateway
Scoping a token does not stop a prompt-injected agent from leaking it. Moving the token out of the agent's process does. Three working setups: a 50-line gateway any agent can call, Claude Code 2.1.199+ sandbox masking with injectHosts, and Claude Managed Agents vaults, plus the measured leak that host-level injection still allows.