bijection agent
An agent is declared in your application with bijection/agents: a role of your access model and a list of tools, served as an MCP endpoint at /agents/<name>.
A credential can only start sessions; a session holds the agent's role on one object until it expires.
Usage:
bijection agent [flags]
bijection agent [command]
Available Commands:
can Show what an agent's sessions may do, from its declaration or for one object
credential Create, list and revoke the credentials that start an agent's sessions
list List the agents this deployment declares, with their endpoints
revoke Close one session's endpoint access now
sessions List recent sessions, newest first
try Start a one-minute session and list its tools or call one, as an agent host would
Flags:
-h, --help help for agent
Use "bijection agent [command] --help" for more information about a command.
bijection agent can
Without options, prints what the declaration allows: the role's permissions, what the role lacks, and the tools.
With --key and --for, starts a one-minute session on that object and prints what it holds right now.
Usage:
bijection agent can <agent> [flags]
Flags:
--deployment string Inspect on a specific deployment. Accepts:
• a deployment name (e.g. joyful-capybara-123)
• a deployment reference (e.g. dev/james, staging)
• dev (for your personal dev deployment)
• prod (for your project’s default production deployment).
You can also select deployments in other projects with project-slug:reference.
--for string The object a real session acts for, such as a customer's ID. Needs --key.
-h, --help help for can
--help-all Show all options, including administrative controls.
--json Print the result as JSON.
--key string The credential file bijection agent credential create wrote.
--module string The module that exports agentsModule. Defaults to agents (bijection/agents.ts).
--prod Inspect on this project's default production deployment.
bijection agent credential
Create, list and revoke the credentials that start an agent's sessions
Usage:
bijection agent credential [flags]
bijection agent credential [command]
Available Commands:
create Create a credential: grant it the agent's credential role, install its public key and write its private key once
list List the installed credentials
revoke Remove a credential's key, ending every token it signed, and withdraw its role
Flags:
-h, --help help for credential
Use "bijection agent credential [command] --help" for more information about a command.
bijection agent credential create
You grant the role as your verified business identity, so you need the power to grant it. The deployment keeps only the public key.
Usage:
bijection agent credential create <agent> [flags]
Flags:
--as string Act as a person, such as alice, on a development, preview or local deployment. Production refuses development identities.
--deployment string Create on a specific deployment. Accepts:
• a deployment name (e.g. joyful-capybara-123)
• a deployment reference (e.g. dev/james, staging)
• dev (for your personal dev deployment)
• prod (for your project’s default production deployment).
You can also select deployments in other projects with project-slug:reference.
-h, --help help for create
--help-all Show all options, including administrative controls.
--module string The module that exports agentsModule. Defaults to agents (bijection/agents.ts).
--name string A label for people, such as voice-prod.
--on string The object the credential's role is granted on, when that role is not a root role.
--out string Where to write the private key. Defaults to <agent>.<label>.agentkey here.
--prod Create on this project's default production deployment.
bijection agent credential list
List the installed credentials
Usage:
bijection agent credential list [agent] [flags]
Flags:
--deployment string List credentials on a specific deployment. Accepts:
• a deployment name (e.g. joyful-capybara-123)
• a deployment reference (e.g. dev/james, staging)
• dev (for your personal dev deployment)
• prod (for your project’s default production deployment).
You can also select deployments in other projects with project-slug:reference.
-h, --help help for list
--json Print the result as JSON.
--prod List credentials on this project's default production deployment.
bijection agent credential revoke
Remove a credential's key, ending every token it signed, and withdraw its role
Usage:
bijection agent credential revoke <agent> <credential> [flags]
Flags:
--as string Act as a person, such as alice, on a development, preview or local deployment. Production refuses development identities.
--deployment string Revoke on a specific deployment. Accepts:
• a deployment name (e.g. joyful-capybara-123)
• a deployment reference (e.g. dev/james, staging)
• dev (for your personal dev deployment)
• prod (for your project’s default production deployment).
You can also select deployments in other projects with project-slug:reference.
-h, --help help for revoke
--help-all Show all options, including administrative controls.
--module string The module that exports agentsModule. Defaults to agents (bijection/agents.ts).
--on string The object the credential's role is granted on, when that role is not a root role.
--prod Revoke on this project's default production deployment.
bijection agent list
List the agents this deployment declares, with their endpoints
Usage:
bijection agent list [flags]
Flags:
--deployment string List agents on a specific deployment. Accepts:
• a deployment name (e.g. joyful-capybara-123)
• a deployment reference (e.g. dev/james, staging)
• dev (for your personal dev deployment)
• prod (for your project’s default production deployment).
You can also select deployments in other projects with project-slug:reference.
-h, --help help for list
--help-all Show all options, including administrative controls.
--json Print the result as JSON.
--module string The module that exports agentsModule. Defaults to agents (bijection/agents.ts).
--prod List agents on this project's default production deployment.
bijection agent revoke
Close one session's endpoint access now
Usage:
bijection agent revoke <session> [flags]
Flags:
--deployment string Revoke on a specific deployment. Accepts:
• a deployment name (e.g. joyful-capybara-123)
• a deployment reference (e.g. dev/james, staging)
• dev (for your personal dev deployment)
• prod (for your project’s default production deployment).
You can also select deployments in other projects with project-slug:reference.
-h, --help help for revoke
--help-all Show all options, including administrative controls.
--module string The module that exports agentsModule. Defaults to agents (bijection/agents.ts).
--prod Revoke on this project's default production deployment.
bijection agent sessions
List recent sessions, newest first
Usage:
bijection agent sessions [agent] [flags]
Flags:
--deployment string List sessions on a specific deployment. Accepts:
• a deployment name (e.g. joyful-capybara-123)
• a deployment reference (e.g. dev/james, staging)
• dev (for your personal dev deployment)
• prod (for your project’s default production deployment).
You can also select deployments in other projects with project-slug:reference.
-h, --help help for sessions
--help-all Show all options, including administrative controls.
--json Print the result as JSON.
--limit string How many sessions to list, 200 at most. Defaults to 25.
--module string The module that exports agentsModule. Defaults to agents (bijection/agents.ts).
--prod List sessions on this project's default production deployment.
bijection agent try
Start a one-minute session and list its tools or call one, as an agent host would
Usage:
bijection agent try <agent> [tool] [arguments] [flags]
Flags:
--deployment string Try on a specific deployment. Accepts:
• a deployment name (e.g. joyful-capybara-123)
• a deployment reference (e.g. dev/james, staging)
• dev (for your personal dev deployment)
• prod (for your project’s default production deployment).
You can also select deployments in other projects with project-slug:reference.
--for string The object the session acts for. Without it, the session is one before verification.
-h, --help help for try
--help-all Show all options, including administrative controls.
--json Print the result as JSON.
--key string The credential file bijection agent credential create wrote.
--module string The module that exports agentsModule. Defaults to agents (bijection/agents.ts).
--prod Try on this project's default production deployment.