logoalt Hacker News

mjg59today at 5:30 PM1 replyview on HN

No they don't - you're still giving the agent a static token that can be exfiltrated and used elsewhere.


Replies

hmokiguesstoday at 7:16 PM

doesn't the token has an expiry window though? if you're using oidc/sso with aws for example it is short lived and can be revoked

show 1 reply