HabrSeptember 11, 2026🇷🇺Translated from Russian

ProxyKey MCP: Securing API Access for AI Agents Without Exposing Credentials

ProxyKey has launched an MCP server that lets AI agents such as Claude Code and Cursor control access to third-party APIs without ever receiving the actual credential. The project builds on the earlier observation that any credential visible inside an agent’s context must be treated as compromised because model outputs are logged, traced, and potentially exfiltrated through prompt injection.

The architecture separates three roles. The real provider key (secret) is submitted once through a web panel and stored encrypted with AES-256-GCM envelope encryption. A virtual token called a pass (prefixed vlt_) is bound to that secret and carries its own IP restrictions, rate limits, TTL, and request log. The proxy itself accepts the pass, decrypts the secret only for the duration of a single outbound request, and forwards the call transparently.

API calls change only the host and authorization header; path, body, and streaming behavior remain identical. Example:

  • Original: curl https://api.openai.com/v1/chat/completions -H "Authorization: Bearer sk-…"
  • Proxied: curl https://api.proxykey.org/p/openai/v1/chat/completions -H "Authorization: Bearer vlt_openai_…"

Telegram bots keep their familiar URL format: /p/telegram-bot/<pass>/getMe.

Agents connect to the MCP server over Streamable HTTP using a separate mcp_ token. Thirteen tools are exposed, none of which accept or return secret values. The catalog tools list providers and stored secrets (metadata only). Pass-management tools create, rotate, update, revoke, and monitor passes. Observability tools return request logs and statistics without exposing authorization headers or keys.

A key use case is the pending-secret flow. An agent can call create_pending_pass to obtain a pass immediately, embed it in configuration, and later hand a setup link to a human. Once the real token is entered through the web panel, the pass activates automatically without any further agent action. Throughout the entire lifecycle the secret never enters the model’s context.

The hosted proxy cannot be zero-knowledge because it must decrypt the secret in memory to forward the request. ProxyKey publishes its crypto module (proxykey-crypto) with tests and design notes covering nonce handling and key-wrapping choices. The service is positioned for environments where agents autonomously deploy services and bots; it is not intended for single, fully controlled keys or for workloads with strict sub-millisecond latency requirements.

Related articles

HabrAI Security

Agent-Ops 0.4.0 Released: Methodology for Secure Human-AI Collaboration in IT Operations

Sergey Zhitinsky, founder of Git in Sky, has published the public normative candidate for Agent-Ops 0.4.0, an open industry methodology governing how engineers and AI agents jointly handle IT infrastructure tasks. The framework keeps humans firmly in the decision-making loop while using deterministic programs for data collection and approved changes. It addresses risks such as prompt injection through processed data, unverified model outputs, and unclear accountability when AI recommendations lead to incidents. The methodology divides work across eight explicit steps and three separate planes: data, governance, and independent verification performed by a Guardian role. Two additional companies have joined as maintainers following agreements at the IT Elements 2026 conference, turning the project into a multi-organization effort. Contributors are invited to help refine contracts, schemas, and operational scenarios through GitHub and GitVerse.

HabrAI Security

Shadow AI in CI/CD: Why AI Agents Must Be Modeled as Security Threats

A new analysis from the CNCF highlights the growing risks of Shadow AI within continuous integration and continuous deployment pipelines. The report argues that AI agents should be treated as potential threats rather than simple productivity tools. Starting from a developer's laptop and extending to Kubernetes clusters, these agents can introduce unauthorized access paths and data exposure risks. Security teams are urged to incorporate AI agent behavior into formal threat modeling exercises. The discussion emphasizes the need for visibility and control over autonomous AI components operating in production environments.

HabrAI Security

Detecting Lateral Movement with Neural Networks Trained Solely on Synthetic Data

A researcher generated entire corporate network histories using a 135-line configuration file to create synthetic authentication logs containing lateral movement attacks. Neural networks trained exclusively on these artificial datasets were then evaluated against 1.65 billion real authentication events from Los Alamos National Laboratory, including 749 red team events across 301 compromised machines. The best ensemble of six models flagged 3.6 million hourly machine windows and placed 16 genuine attacks among the top 23 highest-scoring entries, producing only seven false positives. In comparison, a simple threshold counter required 161,000 false alarms to reach the same detection level. The approach also demonstrated an iterative feedback loop where detector errors directly informed refinements to the synthetic world generator. The work shows that synthetic data can reach AUC performance comparable to models trained on real labeled attacks while providing full control over the underlying attack definitions.

BoletimSecAI Security

US Accuses Chinese AI Companies of Industrial-Scale Model Distillation Targeting Claude, GPT, Gemini and Grok

US agencies have accused six Chinese artificial intelligence firms of conducting large-scale unauthorized distillation operations to replicate advanced capabilities from leading models including Claude, GPT, Gemini, and Grok. The activity is reported to have begun at least by late 2024 and involved DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. Billions of tokens were extracted through millions of automated API requests routed via cloud providers, aggregators, and proxies to conceal origins and evade detection. The targeted capabilities included chain-of-thought reasoning, programming, software engineering, autonomous agent functions, and multimodal processing. Shared premium accounts and bulk subscriptions were used to lower costs while automated route-switching systems helped maintain access after blocks. Authorities assess that the sophistication and volume indicate distillation has become a core development method for these companies and likely occurred with Chinese government awareness. China has rejected the claims, stating its AI progress stems from independent innovation and calling the allegations unfounded.