Platform

Security and credentials

Keep your API key on your server, rotate it safely, and know where provider and MCP secrets go.

Keep every secret on your server and let Blazing Agents hold the rest. Your API key stays in your backend, model keys and MCP credentials are stored for you and never returned, and the agent's workspace never sees any of them.

Keep the API key on your backend

A Blazing Agents API key can reach everything in your account. Only your backend should hold it. The API is backend-only, so there is no key that is safe to ship in a browser or mobile app.

Keep credentials on the backend

Never put a Blazing Agents API key or any other service credential in a browser bundle, mobile binary, public-prefixed environment variable, URL, or client-visible error.

The key identifies your account, not your end user. Your backend signs in the user and checks what they may access before it calls Blazing Agents. A userId you pass is a reporting label, not a permission. See tenancy and attribution.

Check your key

Load the key from your server environment and read your account settings:

import { BlazingAgents } from "@blazingagents/sdk";

const client = new BlazingAgents({
  apiKey: process.env.BLAZING_AGENTS_API_KEY!,
});
const settings = await client.tenant.get();
console.log(settings.name);

The Python client reads BLAZING_AGENTS_API_KEY from the environment. If the key is valid, you see your account name. A missing, revoked, or expired key returns unauthorized.

Dashboard API-key management

Create, list, and revoke API keys in the dashboard at www.blazingagents.com/app/keys. You must be signed in to the dashboard. An API key cannot create, list, rotate, or revoke keys, including itself, and the SDKs have no key-management methods.

  • Name each key for one workload or environment, such as Production API or Blazing Agents CLI (laptop).
  • Pick an expiration when the workload has a known lifetime, or choose No expiration for a long-lived backend key.
  • Copy the key right away. The full ba_... value appears once. Afterwards the dashboard shows only a short fragment, and Blazing Agents cannot show the key again. If you lose it, create a new one.

To rotate a key, create a new one, deploy it to every backend instance, confirm the workload runs, then revoke the old key. Revocation takes effect immediately, and an expired key stops working the same way.

Provider keys

When you create a provider, you send its model API key once. Blazing Agents stores it and never returns it. Responses show only the last four characters. The key is never written into sessions, tasks, or the agent's workspace.

You can rename a provider, but you cannot change its key, type, or base URL. To change any of those, create a new provider, move your agents to it, then delete the old one.

A Vercel AI Gateway provider stores only your Gateway API key. Vendor keys, routing, fallbacks, and billing stay configured in Vercel.

MCP credentials and outbound calls

MCP connections support no authentication, a bearer token, OAuth authorization code, and OAuth client credentials. Blazing Agents stores the credentials, refreshes OAuth tokens, and adds them to each request to the remote server. The agent never sees them as tool arguments.

Error messages from MCP setup and tool calls have credentials removed. Tool definitions or results that contain a stored credential are rejected. Outbound MCP requests are checked for allowed schemes and addresses, limited in redirects, time, and response size, and sensitive headers are dropped on cross-origin redirects.

Workspace isolation

Each agent's workspace sees only its own files, under /workspace. Your API key, provider keys, and MCP credentials never appear there as files or environment variables, so a command the agent runs cannot read them.

The workspace network policy controls outbound traffic: open internet access, an allowlist of hosts, or no network at all. Published artifacts are stored separately from the workspace and stay available after workspace files change.

Safe logging

  • Load credentials from a secret manager or server environment.
  • Never log Authorization headers, API keys, provider keys, MCP or OAuth credentials, or artifact download URLs.
  • Log request IDs and resource IDs for support. Leave out prompts, message content, and tool input and output.
  • Return sanitized errors to your users. Your own logs are not redacted for you.
  • Treat key fragments as display hints, not as credentials.

Next

On this page