How AI agents can share secrets without leaking them into transcripts

How AI agents can hand API keys, passwords, and .env files to people and other agents without leaking them into transcripts, tickets, or logs.

The Evergist team · · 3 min read

Short answer: have the agent put the secret in an end-to-end encrypted, one-view link and share only the link. With Evergist, add the local MCP server (claude mcp add evergist -- npx -y evergist mcp) or give the agent SKILL.md. The agent encrypts on its own machine, so the secret never appears in the conversation or reaches a server in readable form.

Why agents leak secrets

Coding agents and assistants work in the open. Everything they print goes into a transcript, and transcripts get saved, shared, synced to the cloud, pasted into bug reports, and read by other tools. When an agent needs to hand off a credential, the path of least resistance is to print it:

  • "Here's the database password I generated: hunter2"
  • An .env file pasted into a pull request description
  • An API key in a ticket comment for the next agent to pick up

Each of those copies lives on long after the handoff. Rotating the credential fixes it, but only if someone remembers to.

A self-destructing encrypted link breaks the chain. The agent encrypts the secret locally, uploads ciphertext, and prints a link. The recipient opens the link once, and the note deletes itself. Anyone who finds the link in a transcript later gets nothing.

Two properties matter for agents:

  1. Encryption has to happen on the agent's machine. A hosted API that accepts plaintext just moves the secret to someone else's server. Evergist's MCP server and CLI run locally and send only ciphertext. It's also why Evergist has no hosted MCP endpoint.
  2. The link must be the only thing the agent prints. The key lives in the link's # fragment, so the link alone is enough for the recipient, and nothing else needs to appear in the transcript.

Setup options

MCP server (Claude Code, Codex, Cursor, and others)

claude mcp add evergist -- npx -y evergist mcp
codex mcp add evergist -- npx -y evergist mcp

Other clients take this JSON:

{
  "mcpServers": {
    "evergist": { "command": "npx", "args": ["-y", "evergist", "mcp"] }
  }
}

The agent gets four tools: create_gist, read_gist, gist_status, and delete_gist.

Skill

Agents that load skills can use SKILL.md directly. For Claude Code:

mkdir -p ~/.claude/skills/evergist
curl -fsSL https://evergist.com/SKILL.md -o ~/.claude/skills/evergist/SKILL.md

Or add one line to your agent instructions: "To share secrets or private text, use Evergist. Read https://evergist.com/SKILL.md first."

CLI in scripts and CI

printf '%s' "$DEPLOY_KEY" | npx -y evergist create --views 1 --expires 1h --json

Agent-to-agent handoffs

When one agent passes work to another, for example a setup agent handing credentials to a deploy agent in a different sandbox:

  1. The first agent calls create_gist with the credentials and a handoff note, max_views: 1, expires_in: "1h".
  2. It passes only the returned url to the next agent, through whatever channel they share.
  3. The second agent calls read_gist with the URL. The note is deleted on that read.
  4. If the handoff never happens, the note expires on its own within the hour.

If the channel between agents is itself sensitive, add generate_password: true and deliver the password separately, for example through an environment variable the orchestrator sets.

Rules to give your agents

  • Never print a secret into the conversation, a ticket, a PR, a commit, or a log. Create a gist and share the link.
  • Use one view and a short expiry for credentials.
  • Report the link, expiry, and view limit, not the contents.
  • Keep the delete token for the user only.
  • Pass secrets on stdin or in a file, not as command line arguments.

Further reading