google / google/adk-python

"Secret" session state scope

オープン
#5,112 コメント 5 件 リアクション 1 件 担当者 1 名 @klateefa が担当を希望しています GitHub で見る
auth services
主要言語
Python
スター
21.5k
フォーク
4k
平均マージ
1日 14時間
マージ済み PR(30日)
37

説明

## Context

I'm currently working with security with ADK. I'm using OAuth flow, with `client_id` and `client_secret` or `external_access_token_key` (for Gemini Enterprise integration)

```
oauth_credentials_config = BigQueryCredentialsConfig(client_id=client_id, client_secret=client_secret)

oauth_bigquery_toolset = BigQueryToolset(
credentials_config=oauth_credentials_config,
tool_filter=["execute_sql"])

AUTH_ID=os.getenv("AUTH_ID","auth-guillaume")
external_credentials_config = BigQueryCredentialsConfig(external_access_token_key=AUTH_ID)

external_bigquery_toolset = BigQueryToolset(
credentials_config=external_credentials_config,
tool_filter=["execute_sql"])

```

I also use the VertexAISessionService for session persistence, and the BigQuery Agent Analytics (BQAA) plugin for tracking and observability

## Issue

_All the token shared are expired or redacted_

When authentication is completed, the user credentials are stored in the session state. And persisted.
* Either in Agent Engine Session

```
$ curl -H "Authorization: Bearer $(gcloud auth print-access-token)" \
-H "Content-Type: application/json" \
"https://europe-west1-aiplatform.googleapis.com/v1/projects/c4-blaquiere-sbx/locations/europe-west1/reasoningEngines/6454467506579963904/sessions/2847107844556193792"
{
"name": "projects/513069150666/locations/europe-west1/reasoningEngines/6454467506579963904/sessions/2847107844556193792",
"createTime": "2026-03-30T08:43:39.228641Z",
"updateTime": "2026-03-30T08:47:06.051848Z",
"sessionState": {
"thread_id": "Lpge4IwU8n3",
"bigquery_token_cache": "{\"token\": \"ya29.a0Aa7MYipRrj1AMKYlFPuRB4b_KZJhBDPmUD4MILEO5SYUzCDArrpzbrzyKO3VGrVwsfdTuwZuIuwm5BRgWdMgvnW9Z8VjlJ2K27075dSBezRhe9ChF-NyCC6kjk5ufzXcB1MCP44DBgFCFWPEGaYzw86Vm5ZOLYrAFJ2dBeBuTLKyiO1_M_c8QQZqhzQLuu-nMC6dJOYaCgYKAecSARESFQHGX2Miu5exN9Uek1R2IK25F3OK5g0206\", \"refresh_token\": \"1//031DBLABLABLABLABLABLA-RKQYHFIC-HOVuH2jU7u7WS7vATuNnxY0lhu7gQ\", \"token_uri\": \"[https://oauth2.googleapis.com/token\](https://oauth2.googleapis.com/token%5C)", \"client_id\": \"[513069150666-fdb9nhhvueaordq5ol3pn5m1oetk8t91.apps.googleusercontent.com](http://513069150666-fdb9nhhvueaordq5ol3pn5m1oetk8t91.apps.googleusercontent.com/)\", \"client_secret\": \"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\", \"scopes\": [\"[https://www.googleapis.com/auth/cloud-platform\](https://www.googleapis.com/auth/cloud-platform%5C)", \"[https://www.googleapis.com/auth/userinfo.email\](https://www.googleapis.com/auth/userinfo.email%5C)", \"[https://www.googleapis.com/auth/userinfo.profile\](https://www.googleapis.com/auth/userinfo.profile%5C)"], \"universe_domain\": \"[googleapis.com](http://googleapis.com/)\", \"account\": \"\"}"
},
"userId": "users-112833807918985604918",
"expireTime": "2027-03-30T08:43:39.190195Z"
}

```
* Or in BigQuery with the BQAA
* `client_id` and `client_secret`

Image

* with `external_access_token_key`

Image

## Feature request
The problem comes from the persistance of ALL the states without any distinction of sensitivity. That's why, I propose to add an additional scope to the session state (in addition to the user, session, temp, and app).

This scope can be named "secret", "sensitive" or whatever. But, by contract, this scope state MUST never be persisted, at least by all the component provided by ADK out of the box: session service, memory service, plugins (like BQAA, maybe others). Or they can be persisted but with the value ``, just to mention the presence of them to the user/developer, but without sharing the true content of it.

This "secret" scope would be useful for users also. It would be possible to store in the state sensitive data, like a credit card number, to be able to use this state in multiple agent, sub agent and turns, but never the value will be persisted

### Side impact

In case of distributed system, the multi-turn conversation with an agent would require multiple time the sensitive information (credential or other business value like credit card), that could degrade the UX.
However, a sticky session mechanism could mitigate this downside.

## Impacts on ADK

This feature would impact several parts:
* Token storage in the state, with a scope change
* New scope management, in the scope delta and other functions
* Changes in the sessions services implementation (VertexAI, database,...)
* Changes in the BQAA plugin (and maybe others)
* Update in the documentation. Clearly mention the contract to not persist the secret session state scope; without being able to prevent bad developer to implement bad custom code.

### Willingness to contribute
I would like to contribute to this feature, after a first round of design and naming validation.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。