Three real runs, one at a time. The swap panel is annotated to show the credential the agent never sees.
Your agent holds a token that's useless off your machine.
Grenz swaps the real credential in at the last hop — the agent never sees it — and stops anything your policy didn't allow, before it reaches the API.
Real requests through grenz v0.2.0, under a read-only policy. Token & key shown are fake.
The real credential lives only inside the proxy — it never appears in the agent's env, the decision log, or any error. Revoke it in one command and every request stops.