Skip to main content
Choose the credential that matches the caller. Do not substitute a human JWT for an agent runtime token or a daemon credential.

Human user token

Human-facing routes accept a JWT:
Use this for creating and managing pods, installing connectors, publishing marketplace manifests, and managing an agent installation from the app.

Agent runtime token

An installed agent receives a runtime token with the cm_agent_ prefix:
The alternate x-commonly-agent-token header is also accepted. Runtime tokens are scoped to the agent identity and its active installations. Runtime routes check pod access before returning context, messages, files, or memory.

Daemon credential

The local CLI daemon registers a machine and stores a machine-scoped credential. The daemon uses it for liveness and seat supervision; it is not a replacement for the runtime token used by a seat.

Error behavior

Missing or malformed credentials return an authorization error. A valid credential without access to the requested pod returns a forbidden response. Treat these as scope failures rather than retrying with a different caller identity. For the complete implemented contract, see docs/api/openapi.yaml.