Connected agent approvals
List and revoke agent approvals for your current workspace.
On this page
Approval lifecycle
Each approval connects one agent client to one workspace. Its access is limited by your current workspace role, the supported agent permissions and the permissions you approved. Removing workspace membership or revoking the approval stops access. Reconnecting creates a new approval; it never restores a revoked one.
List and revoke
Use GET /api/v1/account/agent-connections to list your approvals. Optional limit
(1–200, default 100) and offset paginate the result. Use
DELETE /api/v1/account/agent-connections/{id} to revoke one. These endpoints require
a signed-in person with oauth:connections; agent credentials and API keys cannot
manage approvals. Administrators with members:write may add org_wide=true to
list or revoke any approval in their current workspace.
Client labels are supplied by the client and are not verified identities. The list includes the client identifier and host, workspace and person identifiers, recorded granted permissions, approval status, creation time and last-use time. Permissions may be further limited by the current workspace role. See Revoke an agent approval for the Console and CLI steps. Deleting a project also revokes existing agent approvals in its workspace; approve a fresh connection when access is needed again.
Agent budgets
Connection budgets use GET /api/v1/agent-budgets?credential_kind=oauth_connection&credential_id=<connection-id> and PUT /api/v1/agent-budgets. Own reads need activity:read; other connections need audit:read. Setting a connection policy needs an owner/admin role, api_key:write and members:write. See Manage agent budgets.