Skip to main content
POST
Grant (or update) an agent's access to an integration connection

Authorizations

Authorization
string
header
required

An aik_… programmatic API key (app.atako.ai → Settings → API keys) or a Supabase session JWT.

Path Parameters

agentId
string
required

Agent id

Body

application/json
connectionId
string<uuid>
allowedTools
string[]

Filtered server-side to valid connector actions.

scope
enum<string>
default:read
Available options:
read,
write,
read_write
expiresAt
string<date-time> | null
constraints
object | null

Response

id
string<uuid>
required
connectionId
string<uuid>
required
scope
enum<string>
required
Available options:
read,
write,
read_write
createdAt
string<date-time>
required
agentId
string<uuid>
allowedTools
string[]
constraints
object | null
grantedBy
string<uuid>
expiresAt
string<date-time> | null
connection
object

Only present on the list endpoint (joined).

masked
boolean

List endpoint only: true for another user's PERSONAL connection (an admin viewing a colleague's agent) — no connection name, only ownerName. Revocable, not editable.

ownerName
string | null

Masked rows only: the personal connection owner's first name.

isDefault
boolean

Present (true) ONLY on a SYNTHETIC row the list endpoint fabricates for a companyWide+defaultGranted connector (e.g. 'projects') when this agent has no explicit integration_grants row yet — it already has full access by default; this row lets the UI show that instead of "no access". id/connectionId both equal the connection's own id on a synthetic row (no real grant row exists) — DELETE on that id persists an opt-out (a real row with allowedTools:[]) instead of a no-op. Absent (never false) on a real row.