What should stay on our server rather than in a browser or AI agent?
3 min readKeep service credentials and privileged integration decisions in a trusted environment. An AI proposal should be evaluated within an approved identity and policy context, not receive a private key or the ability to substitute arbitrary authority identifiers.
Give each environment only what it needs
A browser is where users interact; an agent interprets information and proposes actions; a trusted server can hold appropriate service credentials and enforce integration checks. These roles should not automatically share the same access. Keep privileged credentials out of public client code and agent prompts. Treat values supplied by a browser or model as requests to validate, not as proof that the caller owns the named wallet or may use its authority.
Keep customer authorization separate
Moving a service credential to a server does not mean moving the customer’s password, passkey, or private signing material there. Follow the specific authorized protocol for those elements. The server should establish the permitted identity, resource relationship, and operation scope rather than accepting arbitrary authority identifiers from an untrusted proposal. A useful AI integration lets the agent describe what it wants while the trusted workflow determines what is actually allowed.
Test information leaks and unauthorized substitution
Review logs, error messages, screenshots, and request bodies for secrets or unnecessary personal information. Test whether a caller can substitute another resource identifier and obtain a result it should not see. Keep decision-only evaluation separate from execution even when they appear in one user journey. Name the owner of credential rotation and incident response. Clear trust boundaries make the application safer to operate and give developers a concrete checklist beyond the general instruction to “secure the API.”
Illustrative example
A server checks the workload binding and permitted scope before forwarding a proposal for decision-only evaluation.
Conditions & limitations
This does not mean moving customer passwords, passkeys, or signing material to your application server. Their handling must follow the specific authorized wallet protocol.
What to do next
Review credential storage, scope checks, customer authorization, and untrusted inputs as separate integration boundaries.