The Hallway Track
Engineering Insights

How Many Credentials Should Your AI Agent Have? Zero. — Jim Clark, Docker

AI Engineer · Oct 06, 2026 · Engineering Insights

AI agents should operate with zero credentials, secured via sandboxes and MCP gateways

“Agents do a lot more than I thought...than I expected them to do.”

Docker engineer Jim Clark argues that as AI agents take on longer autonomous tasks with less human supervision, credential management becomes a critical security concern — his answer is zero standing credentials for agents. The talk covers agent harnesses, sandboxes, and MCP gateways as the architectural pattern to constrain what resources an unsupervised agent can access. This is an early but concrete industry signal of zero-trust principles being applied specifically to agentic AI workloads.

ai-agents security docker mcp sandboxing credentials zero-trust

Watch / read the original source →