AI Workshop
Episode 2 of 10Upcoming
Connecting and authorizing
Keys, OAuth, MCP servers, secrets and permissions — wiring an agent to services without leaking anything.
The link arrives by email an hour before the stream
Sign up — a day before we'll send a reminder with the episode plan, and an hour before the start the stream link. The player appears on this page 15 minutes before the start.
What we'll show
- Subscription sign-in vs. API key: the difference, where each is stored, how to revoke
- Connecting an MCP server (GitHub, a database, a browser) and OAuth sign-in from inside the agent
- Secrets: .env.local, a password manager, CI variables — and why a key never goes into a prompt
- Permissions: allowlists for commands and tools, permission modes, what to allow forever vs. once
- What to do when a key shows up on screen or in a commit: revoke and reissue in five minutes
What you take away
Connected MCP servers and a secrets setup you'd happily show a security engineer.
Safe connection checklist
- Keys live in .env.local or a secrets manager, .env* is in .gitignore
- One key per service, least privilege, a clear name
- Only the MCP servers the project needs are connected; for each you know what it can reach
- The agent settings have a command allowlist; dangerous ones (rm -rf, git push --force, deploy) need confirmation
- The agent has no production access; production goes through CI with environment secrets
- There's a leak plan: where to revoke, who reissues, what to check in the logs
Harness in this episode
Permissions and secrets are the harness perimeter: the agent can make mistakes, but can't step outside what it was given.
The full harness episodeWhat to have ready
- The setup from episode one
- A GitHub account
- A password manager (1Password, Bitwarden or similar)
