API Keys Are Hidden from Agent Sandboxes
We improved security in Agenta. An agent can no longer see your API keys when it runs in a cloud sandbox. This covers both your model provider keys and the credentials on your MCP servers.
Ask an agent to print its own environment variables now, and you get a useless placeholder instead of a key.
This is on by default in Agenta Cloud, and there is nothing for you to do.
If you self-host, it applies to agents running in a Daytona sandbox, and your Daytona API key now needs permission to manage Secrets. Read the upgrade note below before you upgrade.