To secure credentials in AI agents, start by giving each agent a unique identity for the task. Limit access to only the systems and actions required, make that access short-lived, and apply intent-based access controls at runtime. Keep credentials and policy enforcement outside the agent, then revoke access as soon as the task is complete.