API overview
Call the AgentConnect REST API with a personal API key — list agents, read sessions, drive schedules from scripts and CI.
| Base URL | https://api.agentconnect.md/v1 |
|---|---|
| Release | v2.0.0 |
| OpenAPI document | Download openapi.json (OpenAPI 3.1.0, 227 paths) |
Everything the console does rides a REST API at https://api.agentconnect.md — and you can call it yourself. On AgentConnect OSS, the bundled stack serves the same API at <your-control-plane-url>/api/v1. A personal API key authenticates as you, with your role, in one organization.
Create a key
Profile → API keys → New key:
- Organization — the org this key is bound to.
- Name — optional label ("ci-runner").
- Permission — what the key may call:
- Full access — everything your role allows.
- Read-only —
GETroutes, plus the MCP connector's read tools. - Agent chat — only the chat token mint, for the selected agents; see Agent chat API.
- Agents — All agents or Selected agents. The selection matters only for Agent chat.
- Expires — 30 / 60 / 90 days, 1 year, or never (90 days default).
The key is displayed exactly once — copy it then. The list afterwards shows only the tail, expiry and last-used time.
Keys are managed only from the console. An API key cannot list, create or revoke keys, nor create or delete an organization; those requests answer 403.
Use it
curl https://api.agentconnect.md/v1/orgs \
-H "Authorization: Bearer $AGENTCONNECT_API_KEY"Every resource is org-scoped under /v1/orgs/{orgId}/… — list agents, read session metadata and messages, manage schedules, trigger runs. Every operation is in the sidebar, each with a playground to send it from, and the raw OpenAPI document is linked in the table above.
Since the key carries your role, a Viewer's key can read but not mutate — handy for dashboards.
The same key also authenticates the MCP connector in headless clients — pass it as the Authorization: Bearer header instead of doing the browser OAuth flow.
Revoke
Revoke kills a key immediately — anything still using it starts getting 401s. Rotate by minting a new key first, moving your scripts, then revoking the old one.
Other credentials, for completeness
- Daemon keys — minted by Add daemon, they authenticate a machine, not a person. Shown once in the install command; revoked when the daemon is deleted.
- Bot tokens — belong to the chat platforms; see Bots.
How is this guide?