Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
mjg59
40 days ago
|
parent
|
context
|
favorite
| on:
Show HN: OneCLI – OSS credential gateway that keep...
No they don't - you're still giving the agent a static token that can be exfiltrated and used elsewhere.
hmokiguess
40 days ago
[–]
doesn't the token has an expiry window though? if you're using oidc/sso with aws for example it is short lived and can be revoked
mjg59
40 days ago
|
parent
[–]
The refresh token is often going to be good for a week, even if the access token isn't.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: