# Keycard Workshop @ AI Engineer World's Fair
**Date de l'événement :** 01/07/2026
* Publié le 01/07/2026

### Date
01/07/2026

### Galerie d'image
![1.png](https://firebasestorage.googleapis.com/v0/b/memory-ai.appspot.com/o/prod%2FrKxsdSTpqCfzIFY8Y2hg%2FprojectsMedias%2FawLQvGfVA1MT8SWjJziQ%2Fthumbs%2F1_1600x900.png?alt=media&token=887b8a10-8242-4aea-908d-0e667a32c904) 

### Ville
`#San Francisco` 

## Description
Your agents are reaching for real tools and real data. The risk isn't the capable agent, it's the standing secret it holds. One long-lived API key sitting in an agent's environment is one prompt injection or Shai-Hulud away from being read out. At AI Engineer World's Fair, Keycard is running a hands-on workshop where you build the answer on your own machine. We'll serve lunch and then you'll build a custom support-escalation MCP server in TypeScript (Express, Streamable HTTP), and lock down both the server and everything it touches with Keycard, end to end. You'll leave having built a server with three tools: Read support tickets, where the user's identity is swapped for a read-only credential so no standing key ever sits in your server Escalate to engineering, where an LLM scrubs the PII before posting a clean issue to Linear using a write-scoped credential Delete an escalation, which asks for a scope your policy refuses to grant What you'll learn: Why standing secrets are the real risk in agentic systems, and how to build them so your server never holds one How to give each tool exactly the access it needs, and nothing more How to trace every hop of an agent delegation chain in a complete audit trail How to set policy that blocks an over-permissioned action Bring a laptop with Node and npm, a GitHub account, and your local coding agent (Claude Code, Cursor, Codex, or Copilot). TypeScript familiarity is strongly preferred. You'll walk out with a governed escalation server you built, and a clear pattern for securing every agent you ship next. Join us if you're building MCP servers or agentic systems and want to learn how to control access to your server and the resources behind it.

**Lien de l'évènement :** [https://luma.com/a9cu3jjx](https://luma.com/a9cu3jjx)

### Pays
`#United States` 

### Continent
`#North America` 

**Médias associés :**
[Média 1](https://80954c1d.sibforms.com/serve/MUIFABojU8UBbDiX_TdcGa7Wv5VMoVB_nBZ92mkLkGlS1pJLpP7s-pVJusyN-7cG9KPrSuv3fv7TmXwuw_AoyNUShR8jZhmNDgUbZPJO2V5xYXlNz4YXOTjSb8X7Lj7PRIPzgzEWlLbA4f4uw_F8RM51EUsjSfQQko0qaby98GHMdYJVWLIXd5JzzaXBGmqN2CcYOFuqnbnaYEnw) 

## event_id
evt-AjJ1lKUpKH29weA@events.lu.ma

### Outils
`#Keycard` 



---
### Navigation pour IA
- [Index de tous les contenus](https://ai-memory.io/llms.txt)
- [Plan du site (Sitemap)](https://ai-memory.io/sitemap.xml)
- [Retour à l'accueil](https://ai-memory.io/)
