Agents
Register agents, issue and rotate their keys, disable them.
An agent is an identity that can ask to spend. Everything else — mandates, decisions, escrows — hangs off it, which is why credentials are per agent and never shared: the threat model stops holding the moment two processes can spend under one name.
Managed with an organization key.
Register an agent
| Field | Type | Required | Meaning |
|---|---|---|---|
name | string | yes | Lowercase slug; becomes part of the id |
metadata | object | no | Up to 20 string keys, yours |
curl -X POST https://api.saifuro.com/v1/agents \
-H "Authorization: Bearer sk_live_..." \
-d '{ "name": "procurement_01" }'{
"agent": "agt_procurement_01",
"name": "procurement_01",
"status": "active",
"created_at": "2026-08-17T09:15:00Z",
"agent_key": "ak_live_9f2e..."
}agent_key appears once, in this response, and is not retrievable afterwards. It goes to that agent's runtime and nowhere else.
Rotate a key
Returns a new agent_key, shown once. The old key stops working the moment the new one is issued — rotation is a cut, not an overlap, so schedule it with the agent's deploy.
Disable an agent
The agent's mandates stop matching, and its next authorization request returns deny_no_mandate. Effective on the next request, like revocation. Disabling is reversible with /enable; both are records.
Read
Paginated. Each agent object carries status (active, disabled), timestamps, and your metadata.

