Skip to content
ImprovedAgent-ready

Sandbox keys can rotate, and refused payments can be retried

A self-registered sandbox key can rotate itself, discovery always states the limits in effect, a claimed workspace becomes an ordinary one, and a pay-per-call payment whose settlement was refused can be presented again.

Follow-ups to agent self-registration and pay-per-call.

  • Rotate a sandbox key yourself. POST /api/api-keys/rotate with the key in x-api-key now works for a self-registered sandbox key. The new key keeps the same workspace, scopes and expiry, so rotating never widens access or extends the key's life, and the old key stops working at once. A sandbox can rotate a limited number of times a day (sandbox.limits.key_rotations_per_day).
  • Limits you can rely on. The sandbox and registration limits are now deployment settings. /.well-known/agents.json (self_registration.limits), /llms.txt and the registration response always state the values actually enforced, so read them there rather than assuming the defaults.
  • Registration can be paused. If self-registration is temporarily closed, POST /api/agents/register answers 503 with code: self_registration_closed and Retry-After, and discovery stops listing it. Sandboxes already registered keep working. Sign up, or pay per call, instead.
  • Claimed workspaces are ordinary workspaces. When a person claims your sandbox it becomes a normal workspace on the free plan, with their email, a slug and its own test workspace, and keeps a permanent note that an agent started it: GET /api/me reports origin, created_by_agent and claimed_at, and the dashboard shows a "Started by an agent" badge.
  • Retry a refused payment. If a pay-per-call settlement is refused (for example, insufficient funds), the 402 carries code: payment_settlement_failed with retryable: true and settle_attempts_remaining. Nothing was charged, and you can present the same signed payment again, up to three settlement attempts by default. A settlement whose outcome is unknown is still never retried.