Authentication methods
Agent API keys
Issue keys to the agents you or your customers run, and verify them on every request.
Agent API keys
API keys are the simplest credential for agents you know about — your own automations, partner integrations, customers' agents. Each key maps to one agent identity.
1. Mint a key
Show key to the agent operator once; keep only hash.
2. Verify keys in the middleware
The simplest verifier reads a map of sha256(key) → identity, e.g. from an environment
variable or config file:
Or look keys up in your own database — verify receives the raw key and returns an identity
or null:
3. The agent sends it
X-Agent-Key: agk_… works too, for APIs where Authorization is already taken by user
sessions.
Result
An unknown or revoked key gives status: 'unverified' with reason: 'api-key:unknown_or_revoked'.
Notes
- Only bearer tokens starting with the prefix (
agk_by default,apiKey.prefixto change) are treated as agent keys, so your users' ordinary session tokens are left alone. - Keys are compared by SHA-256 hash, so a database leak doesn't leak usable keys.
- Rotate by issuing a new key, then removing the old hash once the agent has switched.