Read an agent’s connections
GET /api/agents/{slug}/connections returns agent_id and connections, including
disabled and incomplete connections. Each entry includes:
id: the same agent-scoped connection ID used by/integrations.agent_id,name,adapter, andownership: native/MCP acting credentials belong to this agent; web keys are infrastructure with explicit inheritance. Native names are package labels, not verified external account names. Packages without credentials useagent_configurationownership.revision: a deterministic fingerprint for detecting changes on a subsequent read. It is not a write precondition or a credential-delivery permission.credentials: descriptive references with an agent owner, credential kind, intended audience, presence, and revision. They contain no secret values or database secret IDs. Native API, workspace, and MCP audiences remain separate.actions: supported management actions.- Exactly one of
native,mcp, orweb: the existing adapter’s configuration, enablement, review, health, and version information. Native tools also include their runtimedescriptionandclassfor operation review.
Cache-Control: no-store); it does not discover
remote tools or refresh OAuth. Native package slots exist before configuration;
MCP accounts appear after creation; web slots expose disabled, inherit, or
own settings. Unpackaged built-in tools have no managed connection here.
Create an MCP account
POST /api/agents/{slug}/connections takes adapter: "remote_mcp", auth_kind
(bearer or oauth), name, endpoint, and an optional bearer token. OAuth
can instead supply pre-registered client_id and client_secret fields.
Creation always requests a new independent account, even at an existing endpoint.
Bearer creation returns the existing provider_id/enabled response. OAuth
returns authorization_url and completes through the existing callback flow.
Successful authentication discovers the catalog and enables supported tools
automatically. Discovery failures remain visible and retry without erasing the
account. Explicit off states and exclusions survive later account edits.
Native and web slots are configured through actions rather than created.
Apply an action
POST /api/agents/{slug}/connections/actions accepts:
target selects a native tool name or secret kind within that
connection. It cannot select another package, agent, or infrastructure owner.
Action audit events include the connection ID, action, and validated native target;
credential values and action payloads are not copied into audit details.
Action requests apply one existing operation, not a batch transaction. Responses
and errors retain that operation’s contract. MCP and web edits still require
their stored versions; native edits retain the existing transactional config
writes and enablement checks. The listing’s fingerprint does not introduce CAS
for legacy native writes. An adapter failure never falls back to another account
or infrastructure credential. A malformed or foreign-agent ID is rejected.
Instance web defaults remain on the owner-only settings routes. This agent API
can select inheritance or an agent override, but cannot modify the instance.
There is no instance identity-connection endpoint or shared-account selector.