Skip to content
Courses/Agents and automation/MCP without giving away your keys

MCP without giving away your keys

MCP makes an agent useful because it connects it to GitHub, databases, browsers, and internal services. That same power expands the attack surface.

  • Understand what risk each MCP server adds.
  • Separate credentials, permissions, and sandbox environments.
  • Design allowlists and usage rules for teams.
Terminal
{
  "mcpServers": {
    "github-readonly": {
      "command": "npx",
      "args": ["-y", "@modelcontextprotocol/server-github"],
      "env": {
        "GITHUB_PERSONAL_ACCESS_TOKEN": "${GITHUB_READONLY_TOKEN}"
      }
    }
  }
}

Best practices

  • Use read-only tokens when the workflow does not need to write.
  • Separate development, preview, and production tokens.
  • Do not put secrets in repositories, prompts, or screenshots.
  • Review what tools each MCP exposes before approving it.
  • Limit allowed servers for teams through managed settings if you have them.
Complete Aulafy mapSee how this lesson fits without leaving your path.

Complete Aulafy map

How all courses connect

This is not a checklist. Start with the foundation, choose an outcome, and go deeper only when your project needs more control.

  1. 1Understand
  2. 2Apply or build
  3. 3Operate with confidence
01

Choose an application

Turn the foundation into a visible outcome: a website, a business improvement, media, or an interactive experience.

Continue into the technical branch when you need to maintain code, data, or infrastructure.

02

Build with code

Prepare your environment, work with coding agents, and run models while keeping control of your projects.

This branch prepares you to design and operate reliable AI systems.

03

Take systems to production

Combine retrieval, agents, evaluation, security, deployment, and model adaptation when the problem requires it.

You do not need every course: choose the component your system needs and return as it grows.

View full catalogue