Most AI agents today run on standing credentials. That means an API key or service account password that works until someone rotates it by hand. Often nobody does. The key sits in a config file for months, with far more access than any one task needs.
How short-lived credentials work
The agent proves who it is once. Then, for each task or call, it asks a trusted service for a fresh token. The token is narrow and runs out fast. When it does, the agent has to ask again, and the service can say no.
Where teams get it wrong
They shorten the token's life but keep its scope wide. A ten-minute token that can read everything is still too much.
They issue short tokens but leave the old long-lived key in place. Apps keep using the old key, and nothing changes.
They skip the log. Each fresh token should name the agent, so every call traces back to it.
They treat it as a one-time setup. Someone has to keep watching for calls that still use a standing key.
A concrete example
Compare two setups. In the first, an agent holds one API key for a model provider, saved on disk. If that key leaks, it works for anyone until somebody notices. In the second, the gateway mints a token for each call. It lasts a few minutes and never touches a disk. A leaked token from the second setup is dead before it's useful.