Agents

Register agents, issue and rotate their keys, disable them.

An agent is an identity that can ask to spend. Everything else — mandates, decisions, escrows — hangs off it, which is why credentials are per agent and never shared: the threat model stops holding the moment two processes can spend under one name.

Managed with an organization key.

Register an agent

POST/v1/agents
FieldTypeRequiredMeaning
namestringyesLowercase slug; becomes part of the id
metadataobjectnoUp to 20 string keys, yours
Request
curl -X POST https://api.saifuro.com/v1/agents \
  -H "Authorization: Bearer sk_live_..." \
  -d '{ "name": "procurement_01" }'
Response
{
  "agent": "agt_procurement_01",
  "name": "procurement_01",
  "status": "active",
  "created_at": "2026-08-17T09:15:00Z",
  "agent_key": "ak_live_9f2e..."
}

agent_key appears once, in this response, and is not retrievable afterwards. It goes to that agent's runtime and nowhere else.

Rotate a key

POST/v1/agents/{id}/keys/rotate

Returns a new agent_key, shown once. The old key stops working the moment the new one is issued — rotation is a cut, not an overlap, so schedule it with the agent's deploy.

Disable an agent

POST/v1/agents/{id}/disable

The agent's mandates stop matching, and its next authorization request returns deny_no_mandate. Effective on the next request, like revocation. Disabling is reversible with /enable; both are records.

Read

GET/v1/agents/{id}
GET/v1/agents?status=active

Paginated. Each agent object carries status (active, disabled), timestamps, and your metadata.

On this page