AI Workshop
Episode 2 of 10Upcoming

Connecting and authorizing

Keys, OAuth, MCP servers, secrets and permissions — wiring an agent to services without leaking anything.

Wednesday 14 October at 19:00 Moscow time· 90 min

The link arrives by email an hour before the stream

Sign up — a day before we'll send a reminder with the episode plan, and an hour before the start the stream link. The player appears on this page 15 minutes before the start.

What we'll show

  1. Subscription sign-in vs. API key: the difference, where each is stored, how to revoke
  2. Connecting an MCP server (GitHub, a database, a browser) and OAuth sign-in from inside the agent
  3. Secrets: .env.local, a password manager, CI variables — and why a key never goes into a prompt
  4. Permissions: allowlists for commands and tools, permission modes, what to allow forever vs. once
  5. What to do when a key shows up on screen or in a commit: revoke and reissue in five minutes

What you take away

Connected MCP servers and a secrets setup you'd happily show a security engineer.

Safe connection checklist

  • Да: Keys live in .env.local or a secrets manager, .env* is in .gitignore
  • Да: One key per service, least privilege, a clear name
  • Да: Only the MCP servers the project needs are connected; for each you know what it can reach
  • Да: The agent settings have a command allowlist; dangerous ones (rm -rf, git push --force, deploy) need confirmation
  • Да: The agent has no production access; production goes through CI with environment secrets
  • Да: There's a leak plan: where to revoke, who reissues, what to check in the logs

Harness in this episode

Permissions and secrets are the harness perimeter: the agent can make mistakes, but can't step outside what it was given.

The full harness episode