Skip to content
Access and tokens

Access and tokens

Choose what an agent may do, connect with a browser sign-in or a personal token, revoke agents, and see the limits.

Each agent you connect acts as you, in one organization, at the access level you choose. You choose the level when you approve a browser sign-in or create a token, and you can revoke an agent at any time. Your agents are listed under Settings → Agents, which you open from your name at the foot of the sidebar, under Organization.

For the setup in each app, see Connect your app.

Before you start

  • An account in an organization. Viewers can connect agents too, at Read access.

Access levels

Level What the agent can do
Read Reads projects, data, training runs, evaluations and models. Changes nothing.
Build Also adds and reviews data, creates versions and runs evaluations. Starts no GPUs.
Full Also starts training and deployments on your GPU account, after showing the price first. Owners can publish models.

An agent never gets more than your role allows:

  • A viewer can give Read at most.
  • A member can give any level. Their Full agents train and deploy, but cannot publish models.
  • Only an owner's Full agent can publish, start, extend and stop published models, as only owners can in the console.

No level reaches the owner powers that stay in the console: connections, billing, members and API keys. See What stays in the console.

Tensorant checks your role on every call. If your role is lowered, your agents drop to what the new role allows from their next call. If you leave or are removed from the organization, your agents in it are revoked, and they stay revoked if you are invited back: connect them again. If your account or the organization is disabled, they stop working.

You cannot change an agent's level after you connect it. Connect again at the level you want, then revoke the old one. A good habit is the lowest level that does the job: Read to look around, Build to prepare data and evaluate, Full to train and deploy.

Browser sign-in or token

An agent connects in one of two ways. Both act as you, in one organization, at one level, and both appear in the same list under Your agents.

Detail Browser sign-in Personal token
Apps Claude Code, Cursor, Codex, VS Code, Claude and ChatGPT Claude Code, Cursor, Codex and VS Code
Best for The simplest way to connect. No token to copy. An app that cannot open a browser, such as a script, a CI job or a remote machine, or when you want a fixed end date.
Ends After 30 days without use At the end date you chose: 30, 90 or 365 days
Shown under How as Browser sign-in Token

A browser sign-in is approved in your browser, as described in Connect your app. The app renews its own access while you use it, and each renewal moves the date under Expires to 30 days later. After 30 days without use the connection ends, and the app asks you to sign in again.

An agent works in one organization. To use another, connect it again and choose that organization.

Create a token

  1. Open your name at the foot of the sidebar, then Settings → Agents under Organization, and choose New token in Your agents.
  2. Enter a Name that says where it is used, such as "CI" or "Claude Code on my laptop". It can have up to 80 characters.
  3. Under Access, choose a level. See Access levels.
  4. Under Expires, choose 30, 90 or 365 days. It starts on 90 days.
  5. Choose Create token.
  6. In Copy your token, choose Copy token, keep it where your agent reads its secrets, then choose I copied it. Choose your app under Agent app to see its setup with your token filled in.

The token starts with ta_ and is shown only this once. Tensorant does not keep it, so a lost token cannot be shown again: revoke it and create another. Treat it like a password: anyone who has it can act as the agent until it expires or you revoke it.

To add the token to your app, see Connect with a personal access token.

Revoke an agent

  1. Open Settings → Agents.
  2. Under Your agents, find the agent. Access shows its level, How shows Browser sign-in or Token, and Last used shows when it last called Tensorant. A token also shows its first characters, such as ta_AbCdEfGh…. A browser sign-in is named after its app.
  3. Choose Revoke on its row, then Revoke agent. The dialog says "Revoke name? It stops working at once. This cannot be undone."

The agent's next call is refused. A revoked agent leaves the list, and so does one that has expired: a token after its end date, a browser sign-in after 30 days without use. To use the app again, connect it again.

Owners also see Everyone's agents: the agents of the other people in the organization, with the person's name. An owner can revoke any of them.

Email when an agent connects

Each time a new agent connects, by browser sign-in or token, Tensorant emails the person it acts for. The email names the agent, the organization, the access level, how it connected and when it expires, never the token, and says "If this was not you, revoke it now under Settings, Agents." Choose Review agents in the email to open the list. This email cannot be turned off. See Email notifications.

Limits

Limit Value
Agents per person in an organization 50, browser sign-ins and tokens together. Revoked and expired ones do not count.
Organizations per agent 1
Token lifetime 30, 90 (the default) or 365 days
Token name 80 characters
Browser sign-in Ends after 30 days without use. Each renewal by the app moves the end 30 days on.
Calls per agent 120 a minute and 8 at once

At 50 agents, New token is unavailable; hold the pointer over it to see "You have 50 agents. Revoke one first." See Limits for all the agent limits.

For the limits on what agents send, such as files and spending previews, see Tools.

When something goes wrong

These are the messages Tensorant shows on its sign-in page and the ones an agent reports, in three groups.

Connecting an app

What you see What to do
This app cannot connect: "This app is not known to Tensorant. Connect it again from the app." Start the connection again from the agent app and approve the new request.
This app cannot connect: "This app asked to return to an address it did not register" The app asked Tensorant to send you back to an address that does not match the one it registered, so Tensorant did not. Do not allow it. Remove the connection in the app and add it again. If it keeps happening, update the app or write to [email protected].
This app cannot connect: "This app sent a sign-in request Tensorant cannot accept. Return to the app and try again. If it happens again, the app needs an update." The app's request was wrong. The reason is shown below in small text, for the app's makers. Choose Return to the app and start again from it. If it keeps happening, update the app or write to [email protected].
This app cannot connect: "Tensorant is temporarily unavailable. Try again in a minute." Wait a minute and start again from the app.
This account cannot connect apps The message says why, such as "This account was disabled. Contact Tensorant support." Choose Sign out and continue to use another account.
No organization: "You need to belong to an organization first." Create an organization or accept an invitation, then start again. See Accounts.
Browser sign-in shows Your role allows less on Build or Full Your role limits the level. Ask an owner for the member role in Members, or connect at Read.
Claude or ChatGPT has no option to add a custom connector or server Your plan or workspace does not allow it. On Claude Team and Enterprise plans, an owner adds the connector first.
A token is refused Check that you pasted the whole token, starting with ta_. Then look under Settings → Agents: if the token is not listed, it expired or was revoked. Create a new one.

Access, tokens and revoking

What you see What to do
"This agent's access (Level) does not allow tool. Ask the person to connect it again with Level access." The agent's level does not include that tool. Connect again at the level named, then revoke the old one, or use the console.
"Only an organization owner's agent with Full access can use tool." Publishing tools need an owner's agent at Full. Ask an owner, or use the console.
"This agent's access (Read) does not allow this." The level is too low for what the agent tried. Connect again at a higher level.
"Agents cannot do this. Use the Tensorant console." That action stays in the console. See What stays in the console.
The agent says "Unknown tool: name" No tool has that name. Ask the agent again in other words; if it keeps happening, update the agent app.
"This agent's access was revoked or has expired. Connect it again." The agent was revoked, its token ran out, a browser sign-in went 30 days without use, or you were removed from the organization or no longer have access to it. Connect again with browser sign-in, or create a new token.
The app asks you to sign in again long before 30 days have passed Each renewal of a browser sign-in works once. When the app renews with a copy it has already used, for example from two windows at the same moment, Tensorant ends the connection in case someone else holds that copy. Connect again. If it keeps happening with one app, use a token for it instead.
"You can have 50 agents in an organization. Revoke one under Settings, Agents." Revoke an agent you no longer use.

Tools, spending and files

What the agent reports What to do
"This confirmation is unknown, already used, expired or for other arguments. Call again without confirm for a new preview." The code works once, within 10 minutes, for the exact settings you were shown. Ask the agent for a new preview and agree to that one.
"Your plan (Plan) allows N …" A plan limit stopped it. Wait for the month to turn, remove something you no longer need, or ask an owner to change the plan.
"This organization has no connections yet" or "Connect RunPod compute in Connections first" An owner connects what is missing in Connections. An agent cannot do it.
"A full run needs baseline_id: a completed baseline evaluation of this version…" Ask the agent to run a baseline evaluation of the version first, or to train a trial.
"Too many calls. Wait N seconds." Each agent may make 120 calls a minute. Wait, or ask the agent to check jobs less often. Agents are told to check a job no more often than every 30 seconds.
"Too many calls at once. Wait for the others to finish." Each agent may have 8 calls at once. Wait a moment and try again.
"This took too long to answer. Check list_activity before trying again." The work may still be running. Look at Activity, or ask the agent to, before repeating it.
"Tensorant is temporarily unavailable. Try again in a minute." Wait a minute and ask again.
"Files over 1 MB go through create_upload_link." Ask the agent to use an upload link for that file.
"This upload link is unknown, already used or expired. Ask your agent for a new one." The link works once and for 15 minutes. Ask the agent for a new one.
"This file is larger than the upload limit." Files are limited to 25 MB. Split the file.
"Too many uploads at once. Try again in a minute." Wait a minute and run the curl command again with the same link.
"This agent already has an upload in progress. Try again when it finishes." The agent sends one file through a link at a time. Wait for the other upload to finish, then run the command again with the same link.
"Send one file as the form field named file…" Use the command exactly as given, with one file after file=@.
"This agent can no longer add files: its access, or the person's role in the organization, was lowered…" Check the agent's access and your role. Then ask for a new link.

Next steps

  • Connect your app: the setup for Claude Code, Cursor, Codex, VS Code, Claude and ChatGPT.
  • Tools: what an agent can do at each access level, how spending works, and how files get in.
  • Members: roles, which set how much access an agent can have.

Need a hand? Visit troubleshooting