Skip to content

Machine admin

Register an agent from a blueprint

POST/v1/admin/agents

agents:write. Everything an agent needs on day one, all or nothing, so the hundredth agent is onboarded as code. The person it acts for is named by email and must be a member. The agent starts at the workspace’s starting tier; a token cannot set a tier, cannot name a sponsor or kill owner (people do that in the console), and attaches mandates from templates only.

#Authentication

Service token

A scoped machine token (ims_...) made by an owner or admin under Settings, sent as Authorization: Bearer. Each route needs one scope; tokens expire within 90 days and can be pinned to address ranges. A token can stop agents but never start them, and never decides an approval.