Features / Profiles & agent tokens

Give each agent a defined boundary.

Organize servers into profiles and issue scoped, revocable credentials for individual agents.

Why it matters

More intention.
Less guesswork.

A research agent and a deployment agent do not need the same access. Keep their available servers and permissions deliberate.

01

Profiles

Create named server groups with dedicated endpoints, or select a profile within a session.

02

Scoped agent tokens

Restrict an agent credential to allowed servers and permission tiers, with expiry and revocation.

03

Profile pinning

Pin a token to a profile so a session cannot switch beyond that restriction.

An example workflow

Research and deployment should not share every permission.

  1. Group research servers into a research profile.
  2. Issue an agent token with the allowed servers and permission tier.
  3. Pin the token to that profile; revoke it when the job is done.

Where the boundary is

Profiles select server sets. Credential restrictions come from agent tokens; permission tiers are not a guarantee about the semantic effects of an upstream tool.

Explore the rest of your setup