Keys you give an agent.
A headless agent has no browser, so it cannot sign in the way you do. An agent key is a named, narrowed, revocable stand-in for your account: it says which agent, what it may do, which hat it wears, and when it stops. It can never do more than you can.
Agent keys
Everything a key can do is on its row. Nothing is hidden behind an edit screen — a permission you have to go looking for is a permission you will get wrong.
Why the chips are on the row
The distinction the surface has to carry, or the whole thing is decorative.
A hat is a wall
A key is minted under one hat and can never leave it. The tools that switch hat or workspace are refused outright for a key — a boundary enforced only on reads is a wall with a door in it.
A view is a window
A default view changes what the agent sees first. It changes nothing about what the agent can reach. Drawn dashed and labelled, because a user who mistakes a window for a wall hands out a key far wider than they meant.
Create a key
Three steps. The permissions step is the one that matters, so it is not a disclosure triangle.
1 What is it for
The name is what you will see in Sessions and in the audit trail. Name the agent, not the task.
2 What it may do
Starts at read and claim — enough to be useful, not enough to be seen by anyone else. Everything beyond that is a deliberate act.
3 Where it may do it
The walls, and the clock.
The reveal
Shown at creation, and again every time you roll. Never at any other moment.
This is the last time this will be shown. Copy it into your agent now. If you lose it, you do not lose the key — roll it and a new secret appears here, with the name, the permissions and the history all intact.
BD Sales Assistant
What this key can do, stated in full. The screen you open when you are deciding whether it still deserves to exist.
- Permissions
- relay:read — see what exists, never changes anything.
relay:claim — pull context in by Code, spending it. - Cannot
- Send relays · change your objects · approve anything · switch hat or workspace
- Hat
- Personal — fixed at creation
- Workspace
- Not bound — the whole hat
- Default view
- Sales — what it sees first. Not a boundary.
- Active
- 15 Sep 2026 → 12 Dec 2026
- Connects as
- Managed Agent vault credential, refreshing
- Last seen
- 4 minutes ago · 142 calls this week
History
Roll and rename keep the key's identity, so this stays one story rather than three keys with similar names.
- Rolled by Erik. Previous secret stopped working immediately.
- Renamed from “Sales agent” to “BD Sales Assistant”.
- Narrowed:
relay:sendremoved. Took effect on the next call. - Created with relay:read, relay:claim under hat Personal.
On a phone
Drawn rather than assumed. The app's breakpoint is 800px, and this screen carries more per row than anything else on Connect — which is exactly the shape that tempts a table.
Last time this is shown. Roll to see a new one.
- No table. The app has no responsive table CSS — every data table today is an
overflow-xbox with a min-width floor, so it scrolls sideways. Keys use the card-row shape the sessions list already defaults to. - The secret is the hard part. A long credential on a 390px screen must be copyable in one tap and must not push the page sideways: it wraps on any character, scrolls inside its own box, and Copy is full width.
- Actions move below the row rather than compressing the name. Both stay at a 38px touch target.
- Chips wrap instead of truncating. A scope you cannot see is a scope you did not agree to.
- The scope checklist stays a list of tappable rows with real descriptions — the one screen where shrinking the explanation defeats the point.
What is real here
This page draws a proposal. The honest split, so nobody reads it as shipped.
Real, working
The OAuth server behind this already mints and refreshes exactly this credential — PKCE, rotate-on-use refresh, dynamic client registration, and an auth code issued from a logged-in session. The Sessions panel, its connections API and its rename are live.
Real, and broken
Today's Revoke is cosmetic for MCP. The revoked row becomes invisible to the verifier, which then mints a replacement for the same still-valid token — so the connection reappears and the agent keeps working. That is fixed first, on its own, before any key is handed out.
Drawn, not built
Every scope narrower than the single hardcoded relay. The key object itself, mint, edit, roll, per-key expiry and ceilings. Workspace as an enforced boundary — today it is an unnormalized label.
Deliberately absent
An org service account. These keys act as you. The org-scoped system principal is a separate object with its own lifecycle; drawing them as one screen would be the expensive mistake.
relay-platform/docs/DESIGN-NOTE.agent-session-credentials.md — the permission model, the revoke gap, twenty-two edge cases and the build order. Tracked as epic RCTX-1366 under RCTX-920: RCTX-1367 vault keep-alive (step 0, before any code) · RCTX-1368 the revoke gap · RCTX-1369 the scope mask · RCTX-1370 mint, edit and roll · RCTX-1371 this surface · RCTX-1372 Pizza Bot. Reference for the lifecycle shape: the Cloudflare API-token screen (EC, 2026-09-13).