If you're running an AI agent that interacts with services requiring authentication, you face a dilemma: how do you give your agent access to credentials without exposing them in chat logs, code, or c