Skip to main content
Reports an agent’s credentials. The report is metadata only: no secret value is ever returned, and running the command records no credential use. The report has three parts:
  • Candidates: for every name the agent receives, each credential that could supply it and which one the next provisioning would select. This is a prediction, recomputed on each call.
  • Last profile seal: the credentials read when the agent’s VM profile was last prepared.
  • Gateway uses: the credentials served to the agent’s gateway requests in its latest run.
Comparing the first part with the other two shows whether the agent is running on what it would be given now.

Synopsis

On a VM, the slug is optional. If you omit it, the command reports on the current agent.

Arguments

Requires agent.read on the agent.

Output

The report opens with a caption:
  • owner: <name>: the developer account or service profile the agent’s credentials belong to.
  • <N> of <M> names would be supplied: how many of the agent’s names the next provisioning finds a value for.
  • next refresh: ...: whether the next provisioning changes anything. It reads no change when every selected credential is already in the last profile seal. Otherwise it counts credentials replacing a sealed version, credentials not in the seal, and credentials with no stored version to compare.

Candidates

Names the agent receives are listed first, then names nothing supplies, each group alphabetical. With no candidates, the section reads candidates: none — no credential would reach this agent.

Last profile seal

A heading last profile seal: spawn <id> run <N>, prepared <time>, then a table with NAME, SECRET, VERSION, USES, FIRST USED, and LAST USED. Sealed credentials that match no selected candidate are listed on a final line. With no seal, the section reads last profile seal: none — no profile has been prepared for this agent.

Gateway uses

A table with PURPOSE, SECRET, VERSION, USES, FIRST USED, and LAST USED, one row per stored version served for a purpose. With none, the section reads gateway uses: none.

Examples

Check an agent’s credentials

Here the next provisioning would deliver ANTHROPIC_API_KEY v3 in place of the sealed v2, and NPM_TOKEN from the workspace mount shadows the developer’s own copy.

Raw response for scripting

Errors