- Candidates: for every name the agent receives, each credential that could supply it and which one the next provisioning would select. This is a prediction, recomputed on each call.
- Last profile seal: the credentials read when the agent’s VM profile was last prepared.
- Gateway uses: the credentials served to the agent’s gateway requests in its latest run.
Synopsis
Arguments
Requires
agent.read on the agent.
Output
The report opens with a caption:owner: <name>: the developer account or service profile the agent’s credentials belong to.<N> of <M> names would be supplied: how many of the agent’s names the next provisioning finds a value for.next refresh: ...: whether the next provisioning changes anything. It readsno changewhen every selected credential is already in the last profile seal. Otherwise it counts credentials replacing a sealed version, credentials not in the seal, and credentials with no stored version to compare.
Candidates
Names the agent receives are listed first, then names nothing supplies, each group alphabetical. With no candidates, the section reads
candidates: none — no credential would reach this agent.
Last profile seal
A headinglast profile seal: spawn <id> run <N>, prepared <time>, then a table with NAME, SECRET, VERSION, USES, FIRST USED, and LAST USED. Sealed credentials that match no selected candidate are listed on a final line. With no seal, the section reads last profile seal: none — no profile has been prepared for this agent.
Gateway uses
A table withPURPOSE, SECRET, VERSION, USES, FIRST USED, and LAST USED, one row per stored version served for a purpose. With none, the section reads gateway uses: none.
Examples
Check an agent’s credentials
ANTHROPIC_API_KEY v3 in place of the sealed v2, and NPM_TOKEN from the workspace mount shadows the developer’s own copy.
Raw response for scripting
Errors
Related
- Profiles and secrets: how credentials reach agents
murmur rekey: propagate your current credentials to a running agentmurmur secret mounts: list your own secret mountsmurmur setup subscription: manage subscription credentials