All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
Bluesky
Twitter
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

Vercel Connect launches to replace long-lived API tokens with scoped, short-lived access for agents and apps

By

Hedi Zandi

3d ago· 13 min readen

Summary

Vercel Connect is a new service that allows apps and agents to access third-party services like Slack and GitHub without storing long-lived, dangerous provider tokens in environment variables. Instead, users register a connector once and request scoped, short-lived tokens at runtime. The article argues that current approaches using long-lived tokens shared across users are insecure, and that a vault doesn't solve the fundamental risk. Vercel Connect is now in Public Beta.

Source

bskyVercel Connect launches to replace long-lived API tokens with scoped, short-lived access for agents and appsvercel.com

Key quotes

· 4 pulled
Giving your agents access to your tools, data, and services is what makes them useful.
Today, agent access is usually granted through long-lived provider tokens stored in your environment variables, provisioned for everything your agent might need.
These tokens are shared across every user, never expire, and give your agent full reach across every task, no matter how small the job.
A vault makes that token harder to steal. It doesn't make it less dangerous.
Snippet from the RSS feed
Vercel Connect lets your apps and agents access Slack, GitHub, and other services without storing long-lived secrets. Register a connector once and request scoped, short-lived tokens at runtime. Now in Public Beta.

You might also wanna read