Diagrid
Back to all questions
Agent Identity & Security

Why can't I just use a static API key for my agent in a development environment?

Static API keys in development create a security gap because they often leak into code, config files, or logs, and may be accidentally promoted to production. They also prevent you from testing authentication and authorization logic early. Catalyst lets you use workload identities in development too—identities are scoped to a development environment and short-lived, so you can validate agent security before deployment. This catches misconfigurations early without risking production keys.

Was this article helpful?

Your feedback helps improve Diagrid's FAQ experience.

Keep reading

More Diagrid FAQ articles

View all