AgentConnect

API overview

Call the AgentConnect REST API with a personal API key — list agents, read sessions, drive schedules from scripts and CI.

Base URLhttps://api.agentconnect.md/v1
Releasev2.0.0
OpenAPI documentDownload openapi.json (OpenAPI 3.1.0, 227 paths)

Everything the console does rides a REST API at https://api.agentconnect.md — and you can call it yourself. On AgentConnect OSS, the bundled stack serves the same API at <your-control-plane-url>/api/v1. A personal API key authenticates as you, with your role, in one organization.

Create a key

Create a personal API key

Profile → API keys → New key:

  • Organization — the org this key is bound to.
  • Name — optional label ("ci-runner").
  • Permission — what the key may call:
    • Full access — everything your role allows.
    • Read-only — GET routes, plus the MCP connector's read tools.
    • Agent chat — only the chat token mint, for the selected agents; see Agent chat API.
  • Agents — All agents or Selected agents. The selection matters only for Agent chat.
  • Expires — 30 / 60 / 90 days, 1 year, or never (90 days default).

The key is displayed exactly once — copy it then. The list afterwards shows only the tail, expiry and last-used time.

Keys are managed only from the console. An API key cannot list, create or revoke keys, nor create or delete an organization; those requests answer 403.

Use it

curl https://api.agentconnect.md/v1/orgs \
  -H "Authorization: Bearer $AGENTCONNECT_API_KEY"

Every resource is org-scoped under /v1/orgs/{orgId}/… — list agents, read session metadata and messages, manage schedules, trigger runs. Every operation is in the sidebar, each with a playground to send it from, and the raw OpenAPI document is linked in the table above.

Since the key carries your role, a Viewer's key can read but not mutate — handy for dashboards.

The same key also authenticates the MCP connector in headless clients — pass it as the Authorization: Bearer header instead of doing the browser OAuth flow.

Revoke

Revoke kills a key immediately — anything still using it starts getting 401s. Rotate by minting a new key first, moving your scripts, then revoking the old one.

Other credentials, for completeness

  • Daemon keys — minted by Add daemon, they authenticate a machine, not a person. Shown once in the install command; revoked when the daemon is deleted.
  • Bot tokens — belong to the chat platforms; see Bots.

How is this guide?

On this page

How is this guide?