Skip to content
Console
Browse documentation
Reference

Connected agent approvals

List and revoke agent approvals for your current workspace.

On this page

Approval lifecycle

Each approval connects one agent client to one workspace. Its access is limited by your current workspace role, the supported agent permissions and the permissions you approved. Removing workspace membership or revoking the approval stops access. Reconnecting creates a new approval; it never restores a revoked one.

List and revoke

Use GET /api/v1/account/agent-connections to list your approvals. Optional limit (1–200, default 100) and offset paginate the result. Use DELETE /api/v1/account/agent-connections/{id} to revoke one. These endpoints require a signed-in person with oauth:connections; agent credentials and API keys cannot manage approvals. Administrators with members:write may add org_wide=true to list or revoke any approval in their current workspace.

Client labels are supplied by the client and are not verified identities. The list includes the client identifier and host, workspace and person identifiers, recorded granted permissions, approval status, creation time and last-use time. Permissions may be further limited by the current workspace role. See Revoke an agent approval for the Console and CLI steps. Deleting a project also revokes existing agent approvals in its workspace; approve a fresh connection when access is needed again.

Agent budgets

Connection budgets use GET /api/v1/agent-budgets?credential_kind=oauth_connection&credential_id=<connection-id> and PUT /api/v1/agent-budgets. Own reads need activity:read; other connections need audit:read. Setting a connection policy needs an owner/admin role, api_key:write and members:write. See Manage agent budgets.