Skip to main content
bash TV

How Many Credentials Should Your AI Agent Have? Zero. — Jim Clark, Docker

AI Engineer

1.9K views6 Oct 2026

YouTube

Agents now run long enough that you stop watching them. So what are they allowed to touch? Jim Clark, principal software engineer at Docker, uses MCP gateways as a way into agent safety. Harnesses are simple loops. Safety comes from what context and tools flow into them, so the boundary to manage is the sandbox. Through two examples, a newsroom split into researcher, fact-checker and publisher sandboxes, and a coding agent that only gets signing keys when it's committing, he shows how to model each sandbox on the task's intent. He explains how a single MCP gateway endpoint per sandbox gives you a control point and makes harnesses interchangeable, why the right number of credentials in a sandbox is zero, and how Cross App Access (XAA) with Okta lets agents use your existing SSO. In this talk: • Why safety comes from limiting tools and context, not from the harness • Splitting one workflow into sandboxes that never mix untrusted input with dangerous tools • An MCP gateway as the single control point for tools, resources and prompts • Agent identity and authorization grants with Cross App Access (XAA) SPEAKER Jim Clark, Principal Software Engineer, Docker LinkedIn: https://www.linkedin.com/in/james-clark-b78649/ GitHub: https://github.com/slimslenderslacks LINKS Docker MCP Gateway (GitHub): https://github.com/docker/mcp-gateway Docker Sandboxes docs: https://docs.docker.com/ai/sandboxes/ sbx CLI reference: https://docs.docker.com/reference/cli/sbx/ Okta Cross App Access: https://www.okta.com/solutions/cross-app-access/ CHAPTERS 0:00 Intro 0:18 Hi from Docker 0:52 This is really about AI safety 1:17 Agents run longer, unsupervised 2:02 Harnesses, sandboxes and MCP 2:32 What a harness is 3:37 What MCPs add 4:37 What a sandbox is 5:56 Example: the newsroom 8:41 Example: a coding agent's signing keys 10:06 One gateway endpoint per sandbox 10:56 A control point, and swappable harnesses 12:05 Zero credentials in the sandbox 12:30 Cross App Access (XAA) with Okta 14:25 Progressive disclosure for tools 15:05 Orchestrators that build the sandbox 16:14 Recap: role separation and intent 17:04 Try it: brew install sbx Recorded at the AI Engineer World's Fair 2026 in San Francisco. Subscribe for more talks from the engineers building with AI. AI Engineer: https://ai.engineer YouTube: https://www.youtube.com/@aiDotEngineer X: https://x.com/aiDotEngineer LinkedIn: https://www.linkedin.com/company/aidotengineer/ #MCP #AISecurity #AIEngineer

Join the discussion

Sign in to join the discussion

Sign in