Named agents
An organization administrator can create a named read only agent and grant it access only to selected code groups. A one time access key is shown when created and can later be rotated or revoked.
Available actions
The endpoint can list granted code groups, list active code labels and request a current code. Each request requires a bearer credential. Keep the key out of URLs and logs, use short lifetimes and revoke unused agents.
Current compatibility
This is a private connector flow. Standard remote MCP OAuth discovery and consent are not implemented. Check your client authentication requirements before planning an integration.