Skip to main content
Security configuration covers caller identity, tool permissions, and data handling. VeADK provides authentication middleware, Agent Identity integration, content moderation callbacks, and Trusted MCP connections. Select the capabilities required by your application

Capabilities

Inbound and outbound authentication

Inbound authentication establishes who calls the application; the application must still authorize access to sessions and resources. Outbound authentication supplies credentials for third-party calls; the service and credential scope determine permission. Setting Runner.user_id does not perform either task

Content safety

Moderation depends on configured policies and service responses. The current guardrail can continue execution when requests time out or HTTP errors occur. It should not be the only mandatory blocking control; see Content safety

Trusted execution

Trusted MCP protects tool communication configured to use that connection. Model endpoints, other tools, logs, and storage require separate controls; enabling Trusted MCP does not automatically protect the entire application See the Agent Identity documentation for activation and permissions. Volcengine examples use resources in the selected region. BytePlus deployments need their own identity configuration and credentials, not Volcengine user pools or callback addresses
Last modified on September 19, 2026