generated: '2026-09-14' method: searched source: >- https://github.com/boozallen/strands-base-agent/blob/develop/docs/foundry/configuration/environment-variables.md, .../docs/foundry/guides/http-api.md, .../security/README.md and https://raw.githubusercontent.com/boozallen/palm/main/openapi-specification.yaml — read 2026-09-14 summary: >- There is no authentication to document for a Booz Allen API, because there is no Booz Allen API to call. Both published contracts in the estate are for self-hosted software: the PALM openapi-specification.yaml declares no components.securitySchemes at all, and the Agent Foundry strands-base-agent baseline mounts its REST and A2A routes with no authn/authz layer, leaving both to the adopter's deployment. This file records that measured absence — it is deliberately NOT wired as an `Authentication` pointer in apis.yml, because crediting a documented auth model here would assert a posture neither product has. schemes: [] derived_from_spec: file: openapi/booz-allen-hamilton-palm-openapi.yaml security_schemes: 0 note: PALM's published spec has no securitySchemes and no security requirement on its one operation. runtime_posture: product: Agent Foundry — Strands Base Agent built_in_authentication: none responsibility: adopter (the fork/deployment) transport_security: tls: configurable in the runtime (TLS config module shipped in strands_base_agent) cors: env: - {name: STRANDS_CORS_ORIGINS, default: localhost dev ports} - {name: STRANDS_CORS_ALLOW_CREDENTIALS, default: 'false'} - {name: STRANDS_CORS_ALLOW_METHODS, default: 'GET,POST,PUT,DELETE,OPTIONS,HEAD'} - {name: STRANDS_CORS_ALLOW_HEADERS, default: 'Accept,Content-Type,Authorization,…'} outbound_credentials: - surface: MCP servers the agent calls mechanism: per-server `headers` in config.yaml with ${VAR} substitution (e.g. Authorization Bearer) note: these authenticate the agent TO third-party services; they do not protect the agent's own endpoints - surface: AWS Bedrock mechanism: AWS_PROFILE / AWS_DEFAULT_REGION and the standard AWS credential chain secrets_guidance: >- "Secrets (API keys, tokens, AWS credentials) should stay in .env files and never in config.yaml." evidence: stig_checklist: https://github.com/boozallen/strands-base-agent/blob/develop/security/stig_checklist.json note: >- The shipped DISA ASD STIG assessment covers the auth and authz domains explicitly; of 286 findings, 38 are marked `delivery` responsibility and 21 `shared`, which is where the adopter's authentication work lands.