Are you an LLM? You can read better optimized documentation at /docs/agent-guard/running-agents/pass-credentials.md for this page in Markdown format
Pass credentials into the microVM
By default the microVM receives only these from your host:
- what the agent needs to authenticate: its API key variable if set, or its cached OAuth token (see Run an agent);
- proxy settings (
HTTP_PROXY,HTTPS_PROXY,NO_PROXY) and terminal identification (TERM_PROGRAM,LC_TERMINAL, and their versions); - your SSH keys (
~/.ssh/id_*),known_hosts, and SSHconfig, sogitover SSH works; - the values an agent definition declares in
spec.needs.
Pass any other credential explicitly: --pass-env for arbitrary environment variables, and --pass-cloud-creds for cloud-provider credentials that often involve files as well as variables. Neither reaches a custom runtime's container; declare those values in the definition's spec.needs instead (see Declare a runtime in an agent definition).
Environment variables are delivered to the microVM in memory over vsock and are never written to disk on the host. Credential files are copied to a staging directory under ~/.agentguard for the length of the run and removed when it ends. Inside the microVM, both live on a memory-backed filesystem: they are never persisted in the environment's overlay and are discarded when the microVM stops.
Pass an environment variable
--pass-env <KEY> passes a single host environment variable into the microVM. The flag is repeatable. A variable that is not set on the host is skipped without an error.
To give the agent GitHub CLI access:
bash
export GH_TOKEN=$(gh auth token)
agentguard run claude-code --pass-env GH_TOKEN --workspace ~/projects/myappInside the microVM, gh picks up GH_TOKEN automatically and can open issues and pull requests on your behalf.
For private package registries:
bash
agentguard run claude-code \
--pass-env NPM_TOKEN \
--pass-env PIP_INDEX_URL \
--pass-env PIP_EXTRA_INDEX_URL \
--workspace ~/projects/myappPass cloud provider credentials
--pass-cloud-creds <provider> passes only the variables and files that the named provider uses. The flag is repeatable and accepts comma-separated values.
Valid providers: aws, gcp, azure, vault, kubernetes, all.
AWS
bash
agentguard run claude-code --pass-cloud-creds aws --workspace ~/projects/myappPasses AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, AWS_PROFILE, AWS_REGION, and AWS_DEFAULT_REGION. If AWS_SHARED_CREDENTIALS_FILE is an absolute path to a file, the file is copied into the microVM and the variable is rewritten to point at the copy. ~/.aws/credentials and ~/.aws/config are not copied on their own: to pass a credentials file, name it in AWS_SHARED_CREDENTIALS_FILE.
GCP
bash
export GOOGLE_APPLICATION_CREDENTIALS=~/.config/gcloud/svc-account.json
agentguard run claude-code --pass-cloud-creds gcp --workspace ~/projects/myappThe service account key file is copied into the microVM and GOOGLE_APPLICATION_CREDENTIALS is rewritten to point at the copy. GOOGLE_CLOUD_PROJECT and GCLOUD_PROJECT are also passed when set. CLOUDSDK_CONFIG is passed as its host value, but the gcloud configuration directory it names is not copied.
Azure
bash
export AZURE_CLIENT_ID=... AZURE_CLIENT_SECRET=... AZURE_TENANT_ID=...
agentguard run claude-code --pass-cloud-creds azure --workspace ~/projects/myappPasses AZURE_CLIENT_ID, AZURE_CLIENT_SECRET, AZURE_TENANT_ID, and AZURE_SUBSCRIPTION_ID.
Vault
bash
export VAULT_ADDR=https://vault.internal:8200
export VAULT_TOKEN=hvs.xxxxx
agentguard run claude-code --pass-cloud-creds vault --workspace ~/projects/myappPasses VAULT_ADDR, VAULT_TOKEN, and VAULT_NAMESPACE.
Kubernetes
bash
agentguard run claude-code --pass-cloud-creds kubernetes --workspace ~/projects/myappIf KUBECONFIG is an absolute path to a single file, the file is copied into the microVM and the variable is rewritten to point at the copy. A KUBECONFIG listing several files, or a relative path, is passed as its host value without copying.
Combine providers
Use comma-separated values for multiple providers in one flag:
bash
agentguard run claude-code --pass-cloud-creds aws,gcp --workspace ~/projects/myappOr repeat the flag:
bash
agentguard run claude-code \
--pass-cloud-creds aws \
--pass-cloud-creds gcp \
--workspace ~/projects/myappPass every supported provider at once with all. Prefer naming providers, because all passes every provider's credentials that are set on the host:
bash
agentguard run claude-code --pass-cloud-creds all --workspace ~/projects/myappCombine with --pass-env
--pass-env and --pass-cloud-creds work together:
bash
export GH_TOKEN=$(gh auth token)
agentguard run claude-code \
--pass-cloud-creds aws \
--pass-env GH_TOKEN \
--pass-env CUSTOM_API_KEY \
--workspace ~/projects/myappOne-time credentials
For a credential needed only for a single run, set it inline rather than exporting it in your shell:
bash
GH_TOKEN=$(gh auth token) agentguard run claude-code --pass-env GH_TOKEN --workspace ~/projects/myappThe variable exists only in the environment of that one agentguard process and is not left in your shell.
