| ▲ | mjg59 6 hours ago | |||||||
No they don't - you're still giving the agent a static token that can be exfiltrated and used elsewhere. | ||||||||
| ▲ | hmokiguess 4 hours ago | parent [-] | |||||||
doesn't the token has an expiry window though? if you're using oidc/sso with aws for example it is short lived and can be revoked | ||||||||
| ||||||||