Choose a credential
An Agent Connection keeps an agent tied to its assigned account and limits. Use it when the credential will live inside an agent runtime. Use a sandbox key for integration tests.
Issue and revoke safely
1
Verify your identity
Sign in as a workspace owner or admin and complete MFA or passkey verification.
2
Create a scoped key
Open API Keys and choose the scopes your integration needs.
3
Store and test
Save the raw value in your server’s secret manager. Locus shows it only once.
Check access and test the integration before retiring the old credential.
Enterprise management scopes
Scopes do not override workspace roles. Sensitive changes, including API-key lifecycle, membership, spend controls, and payout settings, require a workspace owner or admin with recent MFA or passkey verification. An API key cannot satisfy that requirement. Custom API changes remain owner-only.
Automating Agent Connections
A server key with bothcredentials:manage and credits:move can create or rotate Agent Connections without human verification. Revocation needs only credentials:manage. Dashboard callers need an owner or admin role and recent verification.
Enterprise workspace roles and invitations
Custom API changes are restricted to the owner. The original owner cannot be removed or reassigned.
An owner or admin can invite members from Team. Assign one non-owner role to each invitee. Invitations expire after seven days; an owner or admin can resend or revoke them. Membership changes require recent MFA or passkey verification.
Check access
Use the credential endpoint to see the current credential’s scopes and role:X-Locus-Tenant-Id.
Handle authorization errors
Repeating the same request does not resolve missing access. The API reference lists each route’s requirements. See Account setup for sign-in methods.