Safety & Security · Software component
Just-in-Time Credential Broker
Software componentSafety & SecuritySafety, Security & Governancearc:JustInTimeCredentialBroker
A security service that obtains fresh, short-lived, task-scoped credentials for each agent task or sandbox session instead of standing credentials.
Responsibility. Provisions ephemeral scoped credentials per task so compromised credentials expire within minutes.
Also known as: JIT access manager, Secret injection service
Relationships
invokes dependency
reads dependency
sends data to dynamic
- Agent Controller abstract Ch9.2
- Execution Sandbox abstract Ch9.3
Design guidance
- SHOULD request fresh short-lived credentials for each task rather than persisting credentials across invocations.
- MUST NOT place secrets in sandbox environment variables; inject scoped credentials that expire when the sandbox terminates.
Classification
- Patterns
- Just-in-Time (JIT) access provisioningSecret injectionDefense-in-depth Layer 5
- Risks mitigated
- Credential theftLong-lived credential misuseSecrets exposed in sandbox environment variables
Sources
- Ch9.2: T. Nguyen, "Action Constraints and Permission Models," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.2. ISBN: 9798244538229.
- Ch9.3: T. Nguyen, "Sandboxing and Transparency Foundations," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.3. ISBN: 9798244538229.