---
title: "Security boundaries"
description: "Understand the isolation, credential access, and approval boundaries behind cloud execution."
canonical_url: "https://hoplite.sh/docs/workspace/security"
markdown_url: "https://hoplite.sh/docs/workspace/security.md"
---

# Security boundaries
URL: /docs/workspace/security
LLM index: /llms.txt
Description: Understand the isolation, credential access, and approval boundaries behind cloud execution.
Related: /docs/agent/tools, /docs/agent/mcp, /docs/sandboxes/environment-variables, /docs/api/authentication

# Security and access boundaries

Cloud threads execute repository code in separate sandbox workspaces. Project environment variables and repository CLI credentials can be present in those workspaces. Treat the code running there as having access to those resources.

## Repository credentials

Hoplite issues a short-lived GitHub App installation token. It covers the active repository and the project's other active repositories on the same installation and GitHub host, so `gh` also works in the peer checkouts of a multi-repository project. Repositories outside the project, including inactive ones, are never included. If the project's repositories change, the token is reissued the next time the workspace initializes. Repository CLI authentication stores the token in private configuration inside the sandbox for `git` and `gh`.

The token is not returned in credential-tool responses or exported into every command's environment. Authenticated CLI operations receive the relevant configuration and remain subject to command policy and provenance checks. This limits how authority is used; it does not mean the sandbox contains no GitHub credential.

The credential control reports status and supports rotation and revocation where the agent's role allows them. Its status shows the permissions GitHub actually granted to the token, which can be narrower than what Hoplite requested. For example, Hoplite requests `issues: write` so agents can file, label, and close issues. On an installation that approved issue read access only, it falls back to read and reports `issues:write` as unavailable. Repository access also depends on the GitHub App installation's current permissions.

PR-comment commands accept same-repository heads only. Fork heads are rejected before a run starts, because fork-controlled code must not receive the base project's environment.

## Project secrets

[Environment variables](/docs/sandboxes/environment-variables) are encrypted at rest and injected into sandbox commands. They are available to setup, tests, application processes, and other code executing in the workspace. Settings cannot reveal a saved value; replace it when you need to change it.

Model-provider keys and connected subscription credentials are managed separately from project environment variables. Do not put provider credentials in project configuration unless the repository's own application needs them.

## MCP credentials

Hoplite encrypts stored MCP secret values individually with AWS KMS and masks them in API responses. MCP configurations are excluded from realtime sync. Decryption occurs when the worker prepares a connection; owners and admins manage the stored configuration.

Each encrypted value is limited to 4,096 bytes. Imported tokens retain the upstream permissions they had before import. Revoke or rotate the token at the provider when that access should end.

Hosted agents connect to remote HTTP and SSE MCP servers. Remote URLs cannot target loopback, private, link-local, or internal hosts. See [MCP configuration](/docs/agent/mcp) for supported transports and precedence.

## Conversation and artifact access

Repository agents can read user and assistant messages from other threads in the same signed project scope, including threads owned by another member. They cannot request another project's history. Continuing a thread also requires that it was created by the invoking user.

A [CLI handoff](/docs/cli/handoff) uploads the user and assistant conversation. Tool output, hidden reasoning, running processes, and ignored files are not transferred. Repository changes must be available from GitHub; `--autopush` explicitly commits and pushes local changes before handoff.

Displayed images and videos are stored durably. Public artifact sharing, when enabled by workspace policy, uses unguessable URLs that expire after seven days. Otherwise artifacts remain restricted to workspace members.

## Preview access

Preview links require Hoplite sign-in and membership in the owning workspace. The preview proxy attaches sandbox-provider credentials server-side without forwarding provider tokens or Hoplite session cookies to the application. Preview content uses a separate origin from `hoplite.sh`.

API integrations never receive a preview cookie. They relay preview traffic through their own authenticated backend using a [five-minute gateway credential](/docs/factory#attachments-and-previews) bound to the preview and the integration's dashboard origin.

## Approval scope

[Permissions](/docs/agent/tools#which-tools-require-approval) apply to specific operations and inputs. Routine repository edits and reads can run without interruption; protected changes and policy-gated commands pause for a decision. Approval does not widen the repository or project scope of the run.

External search results, repository content, and retrieved thread history are treated as untrusted context. They do not grant additional credentials or permissions.

## Sitemap

Sitemap discovery is not enabled for this deployment.
