End-to-end encrypted secret delivery for LLM agents. The agent asks for a secret **by name**. The server returns a one-time URL to an **age-encrypted blob** (X25519). Only the agent's private key can decrypt it. The server never sees the plaintext in the wire response. When an LLM agent needs a password / API key / token, the worst thing is