What you will build
A credential-capability map and a redacted verification record. The first version is a paper exercise; a live extension requires a dedicated low-privilege test credential and permission to use its provider account.
- Agent sends placeholder
- Policy checks destination
- Host proxy injects secret
- Provider executes authorized action
Conceptual flow. Follow the lesson for prerequisites, exact commands and verification limits.
Read the mechanism
Proxy injection can keep a raw API credential outside the VM. The agent uses a placeholder, the request crosses the boundary, and the host proxy substitutes the real value for the intended service. This reduces direct key exposure, but the resulting request still acts with the credential’s authority.
A useful analogy is a clerk who stamps approved letters with a seal you never hold. Not possessing the seal does not make your stamped letters harmless. A read-only test token and a production administrator token create very different risks even when both are hidden behind the same proxy.
Plain environment variables are another path. A secret passed through --env, an environment file or a copied configuration file is readable within the guest. It may be captured in logs, generated artifacts or a saved template. Do not treat those paths as equivalent to proxy-managed secrets.
Worked example · review the capability first
Create this synthetic inventory without any secret values:
{
"credentialLabel": "documentation-test-reader",
"service": "approved-test-provider",
"allowedOperations": ["read test metadata"],
"forbiddenOperations": ["write", "delete", "billing changes"],
"destinations": ["provider host from official integration docs"],
"rawValueLocation": "host-managed secret store",
"owner": "lab operator",
"expiry": "short-lived test credential"
}
For a supported OpenAI test account, Docker documents sbx secret set openai as the host-side prompted setup. This changes a stored credential and may enable billed model use; it is optional here. Never put the key in a command example or print it to prove that storage worked.
Design two observations: a harmless authenticated read at the intended provider and an unrelated destination that must not receive that credential. In the live extension, inspect only a boolean “configured” result or documented placeholder behavior, not full environment dumps, verbose authorization headers or token values.
Expected observations
Your record should explain where substitution occurs and which API action was permitted. A valid response demonstrates that an authenticated operation occurred; it does not prove that every exfiltration path is blocked. A successful placeholder check is narrower still.
On systems without a working OS keychain, Docker documents alternative credential storage behavior. Record the actual installation’s storage mode and permissions without copying its contents into evidence.
Troubleshooting
Separate provider authorization failures from denied egress and absent secret configuration. Do not broaden a token or disable TLS verification as a first fix. If diagnostic output accidentally contains a credential, treat it as exposed, remove it from shareable evidence and follow the provider’s rotation procedure.
For templates and snapshots, review files written inside the guest. Runtime proxy injection cannot remove a credential that you manually copied there earlier.
Interview practice
Can an agent cause harm without learning the API key?
Yes. It can submit authenticated operations through the proxy within the token’s permissions. Restrict actions, destinations, duration and account scope as well as raw-value access.
Why is logging all environment variables a poor authentication test?
It can reveal unrelated secrets and configuration. Test a narrow property or a harmless authorized operation, and retain only redacted evidence.
Completion check
Draw raw-value location and usable authority separately. Explain why a proxy is one control in a credential design, and identify which outputs must be excluded from logs.
Sources and version notes
Checked 6 October 2026; current baseline: sbx v0.46.0. Manage credentials · Architecture
Make the understanding yours.
Use the completion check above. Mark this chapter when you can explain the mechanism and its limits.
Self-assessed reading progress. This does not certify that a lab ran or a system is secure.