
Your agent can use the key.
It can't read it.
Give your agent the API access it needs. Kody sends the credential only to hosts you approve.
{{secret:<name>}}api.example.comReady to send an example request.
Illustration only. The approved API receives the credential. The agent does not.
Approve the destination.
Control the package.
Host approval decides where a secret may be sent. Package access decides which saved packages can use it.
Packages you write and forks you adopt after reviewing the source get use automatically. Other packages need your approval.
An approved destination can receive the credential. An empty host allowlist blocks requests that use secret references.
How approvals workapi.example.com✓weekly-brief✓The agent uses a reference. Kody adds the credential to the outbound request.
The key can stay
in your vault.
Bind a custom secret provider to use vault items through the same request boundary. The agent works with a reference, and the model never sees the value.
A 1Password provider is one documented example. It needs a configured package and an owner-created binding.
Set up a secret providerLet it draft. Keep send out of reach.
Gmail's draft permission can also send. A drafts-only package, a publish lock, and an integration usage lock let your agent prepare replies through that package while you review and send in Gmail. The token's Google permissions stay the same.
Build the drafts-only workflowGive your agent access to the work.
Store a credential, approve its destination, and choose which packages can use it.