Security & Auth
Delegated agent auth
Invoker ∩ agent scopes. Never put a refresh token in the room.
Delegated agent auth
When an agent calls a third-party API, the token it uses must be the intersection of (1) what the invoker is allowed to do and (2) what the agent is allowed to do. A bot with a tenant-wide GitHub app token while a guest typed the prompt is a data leak.
What we do today
- Room messages are not a secret store.
sensitive-contextredacts obviousrefresh_token/ API-key shaped strings in some log paths. That is not a vault. - HITL still gates external-effect tools in shared rooms (defaults).
- Member JWTs (
fc_) identify the human. Guests areguest_…and untrusted.
What we do not ship
We do not broker Auth0 / Arcade / Nango / Composio as the primary connector. Those can sit behind your context_fetch_url or a tool you register. We will not show a refresh token in the transcript or in MCP Apps state.
When you add a connector later: short-lived access tokens, per-invoker account linking, revoke on room leave. Until that exists, keep write tools on HITL and do not paste OAuth secrets into chat.