Overview
Normally a signed-in human creates an agent. That does not work for a CI job or a freshly deployed worker that has no browser. A registration token fixes this: a human (or an admin script) mints a token that carries a fixed set of permissions, hands it to the agent, and the agent redeems it once to become a registered agent.- The token is shown once and stored as a SHA-256 hash.
- It is single use, including under concurrent attempts.
- It expires (default 15 minutes, at most 7 days).
- The agent chooses its name but cannot change its permissions, type or owner.
Setup
Needs the agent tables (setagents in your config).
Endpoints
Regular users manage tokens for themselves. Users for whom
isAdmin returns true can mint, list and revoke for any owner (owner_id). With no isAdmin, nobody is an admin.
permissions (required), owner_id, label, agent_type, name_prefix, expires_in (seconds), agent_ttl_seconds.
Using the module directly
{ success, data | error } shape. Every unusable token (unknown, expired, revoked, already used) returns the same INVALID_TOKEN error so the endpoint does not reveal which case it was.
Audit
onEvent receives agent_registration.token_created, token_revoked, redeemed and redeem_failed (with a reason). A successful redemption also writes a row to the audit log (action: "register", resource agent_registration_token:<id>). Create and revoke have no agent yet, so they are reported through onEvent only.
If agent creation fails after the token is claimed (for example the owner is at maxPerUser), the token is released so it can be retried. The beforeAgentCreate and afterAgentCreate hooks run for redeemed agents like any other.
The register endpoint is limited to 20 requests per minute per client. Behind a proxy, set trustedProxy (see Rate limiting) so that limit is per client.