/connect · agents
Connect · Agents

Keys you give an agent.

A headless agent has no browser, so it cannot sign in the way you do. An agent key is a named, narrowed, revocable stand-in for your account: it says which agent, what it may do, which hat it wears, and when it stops. It can never do more than you can.

Agent keys

Everything a key can do is on its row. Nothing is hidden behind an edit screen — a permission you have to go looking for is a permission you will get wrong.

BD Sales Assistant Managed Agent · vault credential · rly_ag_…7f2c
relay:read relay:claim hat · Personal view · Sales
Active · seen 4m ago expires 12 Dec 2026 142 calls this week
Pizza Bot — prod runner Static bearer · rly_ag_…b901
relay:read relay:claim relay:send hat · Personal workspace · github:christensen-digital/relay-platform bearer · weaker
Active · seen 2h ago expires 12 Dec 2026 can send as you
CI — nightly digest Revoked 2 Sep 2026 · kept as the record
relay:read hat · Personal
Stopped working immediatelylast seen 2 Sep
scope what it may do — subtractive, never more than you hold wall a boundary — it cannot step outside this view a window — what it sees first, not what it can reach

Why the chips are on the row

The distinction the surface has to carry, or the whole thing is decorative.

A hat is a wall

A key is minted under one hat and can never leave it. The tools that switch hat or workspace are refused outright for a key — a boundary enforced only on reads is a wall with a door in it.

A view is a window

A default view changes what the agent sees first. It changes nothing about what the agent can reach. Drawn dashed and labelled, because a user who mistakes a window for a wall hands out a key far wider than they meant.

From the 2026-08-08 hats-and-lenses record: “Reveal what's sealed — you can. An agent in this hat cannot.” That sentence is the whole argument for hat-scoped keys, and it predates this page.

What is real here

This page draws a proposal. The honest split, so nobody reads it as shipped.

Real, working

The OAuth server behind this already mints and refreshes exactly this credential — PKCE, rotate-on-use refresh, dynamic client registration, and an auth code issued from a logged-in session. The Sessions panel, its connections API and its rename are live.

Real, and broken

Today's Revoke is cosmetic for MCP. The revoked row becomes invisible to the verifier, which then mints a replacement for the same still-valid token — so the connection reappears and the agent keeps working. That is fixed first, on its own, before any key is handed out.

Drawn, not built

Every scope narrower than the single hardcoded relay. The key object itself, mint, edit, roll, per-key expiry and ceilings. Workspace as an enforced boundary — today it is an unnormalized label.

Deliberately absent

An org service account. These keys act as you. The org-scoped system principal is a separate object with its own lifecycle; drawing them as one screen would be the expensive mistake.

Record: relay-platform/docs/DESIGN-NOTE.agent-session-credentials.md — the permission model, the revoke gap, twenty-two edge cases and the build order. Tracked as epic RCTX-1366 under RCTX-920: RCTX-1367 vault keep-alive (step 0, before any code) · RCTX-1368 the revoke gap · RCTX-1369 the scope mask · RCTX-1370 mint, edit and roll · RCTX-1371 this surface · RCTX-1372 Pizza Bot. Reference for the lifecycle shape: the Cloudflare API-token screen (EC, 2026-09-13).