Claiming an agent workspace now revokes the agent's key by default
When you claim a workspace an agent created, the key the agent holds is now revoked unless you choose to keep it, and the claim page says plainly what keeping it means.
When a person claims a sandbox workspace that an agent registered for itself, the key the agent holds is now revoked as part of the claim unless the person ticks the box to keep it. Previously the key was kept unless they cleared that box.
The claim page and the API contract now describe a kept key honestly: once the workspace is claimed, the sandbox limits no longer apply, so a kept key works with the full access of an API key in that workspace, including anything added to it later, until someone revokes it under Settings, API keys.
Agents are told the same thing when they register: the claim revokes their key unless the person chooses to keep it.