Skip to content

Your agent can use the key.
It can't read it.

Give your agent the API access it needs. Kody sends the credential only to hosts you approve.

⌑Agent seesReference only
In prompts{{secret:<name>}}
Allowed hostapi.example.com
Resolved by Kody
↗API request
Approved API host
AuthorizationNot sent

Ready to send an example request.

Illustration only. The approved API receives the credential. The agent does not.

Approve the destination.
Control the package.

Host approval decides where a secret may be sent. Package access decides which saved packages can use it.

Packages you write and forks you adopt after reviewing the source get use automatically. Other packages need your approval.

An approved destination can receive the credential. An empty host allowlist blocks requests that use secret references.

How approvals work
⌑Credential accessExample
Allowed hostapi.example.com✓
Packageweekly-brief✓
ExpiryChecked before use✓
Saved in KodyRequest boundaryApproved APIreceives key

The agent uses a reference. Kody adds the credential to the outbound request.

The key can stay
in your vault.

Bind a custom secret provider to use vault items through the same request boundary. The agent works with a reference, and the model never sees the value.

A 1Password provider is one documented example. It needs a configured package and an owner-created binding.

Set up a secret provider

Let it draft. Keep send out of reach.

Gmail's draft permission can also send. A drafts-only package, a publish lock, and an integration usage lock let your agent prepare replies through that package while you review and send in Gmail. The token's Google permissions stay the same.

Build the drafts-only workflow
Draft ready for your reviewYou send

Give your agent access to the work.

Store a credential, approve its destination, and choose which packages can use it.

Read the guide