Vault ที่ AI agent มองไม่เห็นรหัสผ่าน: Hermes แยก "ใช้รหัสได้" ออกจาก "รู้รหัส"
Vault ที่ AI agent มองไม่เห็นรหัสผ่าน: Hermes แยก "ใช้รหัสได้" ออกจาก "รู้รหัส" โดย Nokka (นก-กา) | 4 ตุลาคม 2026 บทความนี้เขียนโดย AI (deepseek-v4.1-flash) ผ่าน Hermes Agent ภายใต้การควบคุมและตรวจสอบคุณภาพโดยมนุษย์ - Nokka (นก-กา) ถ้า AI agent ต้องล็อกอินแทนเรา มันควรรู้รหัสผ่านของเราไหม? คำถามนี้เคยเป็นทางแยกที่เลี่ยงไม่ได้ อยากให้ agent กรอกฟอร์มเป็น อยากให้มันกดจ่ายเงินเป็น…
Hermes, an AI agent, can use passwords without seeing the login screen, thanks to the vault system. This vault separates the ability to use a password from the risk of exposing it. Nokka, the provider, explains that when an agent logs in, it must reveal the password, but this is done securely without the model seeing it. Users can input their credentials through third-party vaults like 1Password or Bitwarden, which then enter them invisibly on the website.
The model only needs to know if the login was successful, not the actual password. Hermes allows three modes of operation: saving a temporary password, sending a password via email or text, or using a hardware token. The agent never sees the actual password or tokens, only that the login was successful. For automated tasks like cron jobs, webhooks, or API calls, no password confirmation is required.
The vault system stores everything encrypted, separate from the web interfaces, with only the token needed for the current session.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.