The usual sequence
1
plan_agent_share
See what a link would carry, without creating one.
2
create_agent_share
Create the link and hand the URL over.
3
list_agent_shares
Find a link again, and see how often it has been used.
4
revoke_agent_share
Kill a link and delete the archive behind it.
What travels, and what never does
The agent itself always travels: its instructions, its skills, its scheduled tasks, its webhooks, the shape of its configuration. Three buckets of data travel only if you name them ininclude:
Four things never travel, whatever you pass:
- API keys, OAuth sign-ins and passwords. The engine strips them out of the archive and the copy arrives asking for its own.
plan_agent_sharecounts them, it never names them. - The shared database and the shared files. Those belong to the workspace, not the agent, so a copy starts with empty ones. If the agent works out of them, say so to whoever you send it to.
- Chat history. Sessions stay in the sending workspace.
- Files flagged by the archive plan. A path that looks like a credential dump is refused, and no switch brings it back.
plan_agent_share
Dry run. Reads the agent on its machine and prices what a link would carry, without creating one.string
required
From
list_agents.contents — the three buckets with a count and a bytes each — plus envKeyCount and mcpAuthCount (how many credentials the copy will have to be given again, counted, never named), warnings, and includeDefaults, which is what create_agent_share uses when you say nothing: all three buckets off.
Read it before creating a link. It is how you tell the account owner what turning a switch on would actually send.
create_agent_share
Captures the agent and creates the link.string
required
object
{ memories: boolean, database: boolean, files: boolean }. Everything left out stays in this workspace. Empty by default: a call that omits include sends the agent alone.boolean
Required as soon as one of the three switches is
true. Not needed otherwise.shareId, url, the include actually applied, reused, warnings and expires: "never". The token lives inside the URL and is never returned on its own: copy the link whole.
Three behaviours worth knowing before the first call:
- The confirmation is about data, not about sharing. Sending an agent needs no ceremony. Sending someone’s memories, database or files out of the workspace does, so the second case comes back as a tool error until you call again with
confirm: true. Ask the account owner first — that is the point of the gate. - Calling it twice is free. The same agent with the same
includeand a link that is still alive hands back the existing link withreused: true, rather than taking a second snapshot. - It is not instant. The call streams the whole agent folder off its machine and uploads it. Give it time rather than retrying.
list_agent_shares
The links this workspace currently has out. Takes no arguments. Each entry carriesshareId, url, agentId, agentName, createdAt, installCount and include, alongside activeCount.
This is the only way to get a URL back after create_agent_share returned it. Every link listed is live. Revoked links are not listed. agentId comes back null once the source agent has been deleted: the link keeps working, because the snapshot never depended on it, and agentName is the name frozen at creation rather than the current one.
revoke_agent_share
Kills a link and deletes the archive behind it.From
list_agent_shares, never from the URL.boolean
required
create_agent_share and a new snapshot. Agents already installed from it are untouched, they belong to whoever installed them.