Security Model¶
An agent reaches only the hosts you allow and the AgentZ services it needs. Secrets, model keys and MCP credentials stay in AgentZ and are added to requests outside the agent.
Network Access Is Closed by Default¶
Each agent has its own network policy. The policy allows only these destinations:
- The allowed hosts in the agent's sandbox.
- The AgentZ gateways for models and MCP tools.
- The secret-injection proxy and the telemetry endpoint of AgentZ.
Every other destination is denied. To open a host, add it to Allowed hosts in the sandbox. See Sandboxes.
Secrets Reach an Agent as Placeholders¶
You save a secret with a name, the hosts it may be sent to, and a value. After you save it, the value is write-only.
The agent sees an environment variable with the secret name. Its value is a placeholder. For a secret named SERVICE_API_TOKEN, the value is agentz:resolve:env:SERVICE_API_TOKEN. When the agent calls a listed host over HTTPS, a proxy outside the agent swaps in the real value. The agent holds only the placeholder.
See Secrets for the parts of a request that the proxy rewrites.
Model Keys Stay in AgentZ¶
Model calls go through the AgentZ inference gateway. Your provider key stays in AgentZ and is not passed to the agent. The provider host needs no entry in Allowed hosts.
MCP Credentials Stay Outside the Agent¶
AgentZ stores MCP tokens outside the agent. A separate service adds them to each MCP call. That service also checks that the calling sandbox includes the connection.
Lens Shows Allowed and Blocked Events¶
Lens is the workspace page that shows what your agents did. Open Lens → Runtime telemetry → Network to see the network events of your agents. The Action column shows Allowed or Blocked. You need the Lens read permission to open it. See Roles and teams.