# Your agent shouldn't be you, with extra steps.

Short pieces on why handing your Gmail, your Stripe key, or your phone to an AI agent eventually ends badly — and what to do instead.

## Stop being the 2FA device
If your agent pings you for a 6-digit code every time it logs in, you've rebuilt the bottleneck the agent was supposed to remove. Give the agent its own TOTP.

[Read →](/content/stop-sharing/phone-2fa/index.html)

## Stop giving AI agents
A live secret key in the process that runs an autonomous LLM is the most boring breach that will ever happen to you. Here's the alternative.

[Read →](/content/stop-sharing/stripe-keys/index.html)

## Stop putting AI agent
.env works for one developer and one process. It stops working the moment you have five agents, two environments, and a teammate who pasted the file into Slack by accident.

[Read →](/content/stop-sharing/env-api-keys/index.html)

## Stop sharing OAuth tokens
An agent holding OAuth tokens minted in your name is an agent that cannot be revoked without also revoking you. Scope agents to their own identities instead.

[Read →](/content/stop-sharing/oauth-tokens/index.html)

## Stop sharing your calendar
A scheduling agent with write access to your primary calendar is the fastest way to end up with meetings you don't remember agreeing to. Give it its own.

[Read →](/content/stop-sharing/calendar/index.html)

## Stop sharing your Gmail
The OAuth button is right there and your agent 'just needs' the inbox. It's the single decision that causes the most long-term regret.

[Read →](/content/stop-sharing/gmail/index.html)
