No. The handoff should reference approved protected resources without embedding API keys, authorization headers, environment secrets, or other credentials in the payload.
No. The handoff should reference approved protected resources without embedding API keys, authorization headers, environment secrets, or other credentials in the payload.