It’s injected into an outbound api call, not into an env var the agent can read.
There's also an ability to create kits where you can setup credential injection into other services as well.
The main reason a "proxy-managed" env var is set is because most CLI tools assume if the env var is set, auth is set. If the env var is unset, it will assume auth needs to occur. Fortunately, most don't do a pattern matching on what the value actually is.