AI Agents That Don’t Leak Secrets: Safer Tool-Calling With SecretRef

SecretRef handling changes tool calling so AI agents never receive real API keys. Resolve secrets only at execution time and test prompts and traces for leaks.