Safety & Security · Software component

Just-in-Time Credential Broker

Software componentSafety & SecuritySafety, Security & Governancearc:JustInTimeCredentialBroker

A security service that obtains fresh, short-lived, task-scoped credentials for each agent task or sandbox session instead of standing credentials.

Responsibility. Provisions ephemeral scoped credentials per task so compromised credentials expire within minutes.

Also known as: JIT access manager, Secret injection service

sends data tosends data toinvokesreadsAgent Controller: sends data toAgent ControllerExecution Sandbox: sends data toExecution SandboxIdentity Provider: invokesIdentity ProviderSecrets Vault: readsSecrets Vault
Direct neighbourhood (hover for relationship types)

Relationships

invokes dependency

reads dependency

sends data to dynamic

Design guidance

Classification

Patterns
Just-in-Time (JIT) access provisioningSecret injectionDefense-in-depth Layer 5
Risks mitigated
Credential theftLong-lived credential misuseSecrets exposed in sandbox environment variables

Sources

  1. Ch9.2: T. Nguyen, "Action Constraints and Permission Models," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.2. ISBN: 9798244538229.
  2. Ch9.3: T. Nguyen, "Sandboxing and Transparency Foundations," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.3. ISBN: 9798244538229.