1 minute readSecurityAgent-ready
Saved function credentials are never shown again
The credential a function sends to its endpoint is now write-only. No API response, key or dashboard view returns it; responses say whether one is saved.
When you register a pricing function that calls your own endpoint, you can save the credential it sends there, such as a bearer token or an API key. That credential is now write-only:
- No response returns it. Listing your functions, reading one, registering one and updating one all leave it out, whether you use the dashboard, an API key or the
list_functionsMCP tool. - Each of your own functions carries an
authsummary instead: whether a credential is saved, its type, and for an API key the header it is sent in. - To change it, send a new one. To keep it, leave it out of the update. To remove it, send
auth_config: null. Anything other than an object or null is refused.
Before this change, an API key that could read your workspace's functions could also read these credentials. If you saved one, we recommend replacing it with a new one from your endpoint's provider.