TL;DR: AI agent stacks centralised through MCP can move credentials out of developer laptops and into the platform database, creating a new secrets sprawl and auditability problem as enterprises connect hundreds or thousands of upstream services, according to 1Password. Runtime resolution keeps secrets in the vault until needed, but governance now hinges on the control point, not the agent alone.
Editorial analysis by NHI Mgmt Group, based on content published by 1Password: “Secure MCP credentials with 1Password and Runlayer”.
Key questions
Q: What breaks when MCP gateways store raw credentials instead of vault references?
A: The gateway stops being a policy layer and becomes an unmanaged secrets store.
Q: Why does runtime secret resolution reduce risk in AI agent access flows?
A: Runtime resolution removes durable credential copies from the platform and limits exposure to the request window.
Q: How do teams know whether an MCP control plane is actually governing secrets?
A: Look for evidence that the platform stores references, not raw values, and that every fetch and rotation is logged with traceability.
Practitioner guidance
- Keep the vault authoritative for MCP credentials Store only a secret reference in the gateway and resolve the live value at request time so the platform never becomes a second secrets store.
- Audit every secret fetch and rotation Log fetch events and rotation events with hash-based traceability so security teams can prove change without exposing the credential itself.
- Limit secret persistence to memory only Ensure the credential exists only for the duration of the upstream request and is never written to disk, cached in the database, or reused across sessions.
Bottom line: MCP gateways can improve control over AI tool access while simultaneously creating a new secrets sprawl layer if raw credentials are stored in the platform.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
MCP gateways create an identity control-point problem, not just an integration problem. Once the gateway becomes the place where credentials are entered, resolved, and logged, it inherits the governance burden that used to sit in the vault. The field should stop describing this as simple platform consolidation, because the real issue is whether the control point preserves ownership and revocation semantics. Practitioners need to treat the gateway as part of the credential lifecycle, not a neutral transit layer.
A few things that frame the scale:
- 88% of organisations have embedded AI agents in their workflows, according to KPMG's 2026 report.
A question worth separating out:
Q: How should security teams handle secrets in MCP gateways for AI agents?
A: Security teams should keep the raw secret in the vault and let the MCP gateway resolve only a reference at runtime. That reduces persistence, limits blast radius, and preserves the vault as the source of truth. The gateway should log fetch and rotation events, but never store or expose the credential value itself.
👉 Read our full editorial: MCP gateways create a new secrets sprawl problem for AI agents