Onboard your agent¶
You can let a coding agent (Claude Code, Codex, Gemini CLI, ...) manage Kapelle for you: create teams, change prompts, set budgets, read runs. It does so through the Console API with a token that has the role you chose.
In the Console¶
Settings, Onboard your agent: pick the role the agent gets (viewer, operator or admin). The Console makes an API token with that role and shows two things:
- A two-sentence prompt to paste into the agent's first message. It names who the agent works for, the API address and the token, and points at Managing Kapelle through its API.
- A snippet for the agent's own instruction file (under a
## Kapelleheading), so later sessions know where Kapelle is without being told.
The token is shown once. The API address and the docs link follow the address you opened the Console on
(KAPELLE_PUBLIC_BASE_URL, KAPELLE_DOCS_BASE_URL).
What the agent is told¶
Managing Kapelle through its API is written for the agent: authentication, conventions (If-Match,
problem details, paging), safety rules (never print a secret, ask before allow-all egress, archiving or raising
a budget), every route with the role it needs, and the playbooks. The contract itself is
GET /api/v1/openapi.yaml on the deployment.
Roles¶
| Role | Can |
|---|---|
| viewer | Read everything; every write answers 403. |
| operator | Create, change and archive teams, link them, set budgets, read runs, task a team, answer and cancel runs, manage a team's documents and MCP servers, test integrations. |
| admin | Everything an operator can, plus agents, templates, environments, destinations, secrets, platform skills, users and integration settings. |
Give an agent the lowest role that does what you want, and revoke its token (Settings, API tokens) when you are done. Tokens have an expiry and cannot mint tokens or log in.
Without the Onboard tab¶
Log in to the Console API and POST /tokens (session cookie only), see the Console API.
Everything the agent needs after that is in the route reference.