Learning paths / Vibe coding to production / Ship it with an agent

Least-privilege tokens

Reading · 6 min · Module 8, lesson 1 of 452 min left in this module

Module 8 · Ship it with an agentLesson 1 of 4

Goal: Create a project-scoped, expiring ComputeSphere token for an agent, hand it over without pasting it into a chat, and revoke it.

Key idea

When an agent deploys, it acts with a token. Give it the smallest one that does the job: limited to one project, expiring in days, handed over outside the chat, and revoked when the work is done. Then a mistake, or a leak, stops at that project and that week.

Why agents change the sums

You'd trust yourself with a token that reaches everything. An agent is different:

  • It runs many commands, and you skim most of them.
  • Anything it runs can read the environment it runs in, token included.
  • Text it reads, in a README, an issue or a web page, can steer what it does next.
  • Whatever goes into its chat is sent to the model provider, and transcripts get saved and shared.

None of that means don't use agents. It means limit what a token can reach, and for how long.

Pick the scope

ComputeSphere tokens start with csph_, so secret scanners recognise a leaked one.

ScopeReachesUse it for
Full accessEverything your user can reachAlmost never with an agent
Account accessEvery project in the accounts you pickTools that manage a whole account
Project accessOnly the projects you pickAn agent or pipeline that deploys one app

Every token has an expiry. After that moment, ComputeSphere refuses it. The console suggests 30 days; for an agent session, pick 7 days or less.

Create one in the console

Go to Settings, then User tokens, and choose New token. Name it for the job, such as agent_deploy. Choose Project access and pick the one project. Under expiration choose 7 days, then Create token. It's shown once: copy it straight to where it's going.

A user token acts as you, and stops working if you lose access to the project. For a pipeline that must outlive your membership, use an account token instead (lesson 5.8.4).

Creating it with csph
csph auth token create --name agent_deploy --scope project \
  --restrictions <project-id> --expiry "2026-10-05 23:59:59"

It prints the token once. csph projects list shows the project ID. --expiry is required: set it a week from today, in UTC.

Hand it over outside the chat

csph reads a token from the COMPUTESPHERE_API_TOKEN environment variable, and prefers it to your own sign-in. Set it in the terminal your agent runs in, without it showing on screen:

read -rs COMPUTESPHERE_API_TOKEN && export COMPUTESPHERE_API_TOKEN

Paste it and press Enter; it isn't shown. The agent's commands can use it without it ever entering the chat. They could also print it, which is why the scope and expiry do the real protecting.

Revoke it

In Settings, User tokens, hover over the token and choose the delete icon, or run csph auth token delete <token-id>. Revoke when the work is done, and straight away if the token was pasted anywhere it shouldn't be.

Check yourself

You accidentally paste a project token into your agent's chat. What now?
Your agent will redeploy one service for the next few days. Which token?

In the docs