Security configuration covers caller identity, tool permissions, and data handling. VeADK provides authentication middleware, Agent Identity integration, content moderation callbacks, and Trusted MCP connections. Select the capabilities required by your application
Capabilities
Inbound and outbound authentication
Inbound authentication establishes who calls the application; the application must still authorize access to sessions and resources. Outbound authentication supplies credentials for third-party calls; the service and credential scope determine permission. Setting Runner.user_id does not perform either task
Content safety
Moderation depends on configured policies and service responses. The current guardrail can continue execution when requests time out or HTTP errors occur. It should not be the only mandatory blocking control; see Content safety
Trusted execution
Trusted MCP protects tool communication configured to use that connection. Model endpoints, other tools, logs, and storage require separate controls; enabling Trusted MCP does not automatically protect the entire application
See the Agent Identity documentation for activation and permissions. Volcengine examples use resources in the selected region. BytePlus deployments need their own identity configuration and credentials, not Volcengine user pools or callback addresses Last modified on September 19, 2026