Skip to content
SecurityAgent-ready

Agent tokens can no longer create, list or revoke API keys

Key management under /api/api-keys now needs a person's session; a scoped token cannot mint a key wider than itself.

An agent's token, exchanged from the agent's own scoped key at /api/oauth/token, was accepted by POST /api/api-keys, so an agent could create an unrestricted key for its workspace. GET, POST /api/api-keys and DELETE /api/api-keys/{keyId} now answer 403 agent_cannot_manage_keys to an agent's token. A person's JWT that is limited to scopes can only create keys within those scopes (403 insufficient_scope otherwise). Dashboard sessions and full-access tokens are unchanged.

An agent can still replace its own key: POST /api/api-keys/rotate with the key in x-api-key returns a new key with exactly the same scopes, agent and expiry, and revokes the old one at once. It cannot widen anything.

The same rule now covers agent management: an agent's token cannot create, edit or revoke agents, or mint agent-bound keys with POST /api/agents/{id}/keys (403 insufficient_scope).