---
title: "Agent Identity API Reference"
description: "Claiming a workspace an AI agent registered for itself. An agent registers at the authorization server (https://mcp.linkbreakers.com/agent/identity, see https://linkbreakers.com/auth.md) and hands a person a claim link and a 6-digit code; these endpoints are the person's side of that ceremony."
canonical: "https://linkbreakers.com/help/api/agent-identity"
---

# Agent Identity

Claiming a workspace an AI agent registered for itself. An agent registers at the authorization server (https://mcp.linkbreakers.com/agent/identity, see https://linkbreakers.com/auth.md) and hands a person a claim link and a 6-digit code; these endpoints are the person's side of that ceremony.

## Agent Identity

## [#](#agent-identity-object)The Member object

Describes a teammate invited into a workspace, including their role, login metadata, and last-known activity so Linkbreakers can enforce access policies and audit collaboration.

accessRevokedAt

string (date-time)

When the member's access was revoked (null means active)

accessToken

string

Access token issued during sign-in; returned to clients but not persisted on the member record

createdAt

string (date-time)

Timestamp when the member was created

displayLanguage

string

Preferred language for emails and product copy (BCP-47)

email

string

Email address used as the member's login identifier

emailVerifiedAt

string (date-time)

When the member confirmed ownership of their email address (null means unverified)

firstName

string

Member's given name used in UI surfaces and emails

id

string

Unique identifier for the member record (UUID)

lastKnownCountry

string

Country inferred from geolocation during the most recent sign-in (ISO 3166-1 alpha-2)

lastKnownIp

string

IP address seen on the most recent sign-in

lastKnownLanguage

string

Browser language header captured during the most recent sign-in

lastKnownTimezone

string

Timezone reported during the most recent sign-in (IANA TZ database)

lastName

string

Member's family name used in UI surfaces and emails

lastSigninAt

string (date-time)

Last time the member successfully authenticated

role

string (enum)

Role enumerates the built-in permission tiers that control what teammates can manage inside a workspace.

##### Allowed values

`ROLE_UNSPECIFIED`

Role not specified (defaults to viewer permissions)

`ROLE_VIEWER`

`ROLE_ADMIN`

`ROLE_TECH`

updatedAt

string (date-time)

Timestamp when member metadata was last updated

workspaceId

string

Workspace the member belongs to (UUID)

Example object

```json
{
  "accessRevokedAt": "2026-10-10T19:14:37.262Z",
  "accessToken": "lbw_1w8jp9longjwtvalue",
  "createdAt": "2026-10-10T19:14:37.262Z",
  "displayLanguage": "en-US",
  "email": "sam.member@example.com",
  "emailVerifiedAt": "2026-10-10T19:14:37.262Z",
  "firstName": "Sam",
  "id": "123e4567-e89b-12d3-a456-426614174000",
  "lastKnownCountry": "US",
  "lastKnownIp": "203.0.113.42",
  "lastKnownLanguage": "en-US,en;q=0.9",
  "lastKnownTimezone": "Europe/London",
  "lastName": "Rivera",
  "lastSigninAt": "2026-10-10T19:14:37.262Z",
  "role": "ROLE_ADMIN",
  "updatedAt": "2026-10-10T19:14:37.262Z",
  "workspaceId": "c0d3cafe-5b1e-4d42-a6fd-0c5f5c3962d0"
}
```

POST

`/v1/agent-identity/claim/complete`

## [#](#claim-an-agent-s-workspace)Claim an agent's workspace

Check the code the agent handed over, attach the claim email with a password or a Google or Microsoft sign-in to the agent's workspace, and sign in. The email must not already have a Linkbreakers account. Afterwards the agent's token keeps working in the claimed workspace, and the agent can fetch a token with wider scopes from the claim grant.

### [#](#claim-an-agent-s-workspace-parameters)Parameters

#### header parameters

Idempotency-Key

string

header

Makes retrying this request safe. See components.parameters.IdempotencyKey.

### [#](#claim-an-agent-s-workspace-request)Request body

claimAttemptToken

string

The claim\_attempt\_token from the link the agent handed over

firebaseToken

string

A Firebase ID token from Google or Microsoft sign-in, for the claim email. Set this or password.

password

string

A password for the claim email. Set this or firebase\_token.

userCode

string

The 6-digit code the agent gave you

### [#](#claim-an-agent-s-workspace-response)Response

200

Everything worked as expected.

accessRevokedAt

string (date-time)

When the member's access was revoked (null means active)

accessToken

string

Access token issued during sign-in; returned to clients but not persisted on the member record

createdAt

string (date-time)

Timestamp when the member was created

displayLanguage

string

Preferred language for emails and product copy (BCP-47)

email

string

Email address used as the member's login identifier

emailVerifiedAt

string (date-time)

When the member confirmed ownership of their email address (null means unverified)

firstName

string

Member's given name used in UI surfaces and emails

id

string

Unique identifier for the member record (UUID)

lastKnownCountry

string

Country inferred from geolocation during the most recent sign-in (ISO 3166-1 alpha-2)

lastKnownIp

string

IP address seen on the most recent sign-in

lastKnownLanguage

string

Browser language header captured during the most recent sign-in

lastKnownTimezone

string

Timezone reported during the most recent sign-in (IANA TZ database)

lastName

string

Member's family name used in UI surfaces and emails

lastSigninAt

string (date-time)

Last time the member successfully authenticated

role

string (enum)

Role enumerates the built-in permission tiers that control what teammates can manage inside a workspace.

##### Allowed values

`ROLE_UNSPECIFIED`

Role not specified (defaults to viewer permissions)

`ROLE_VIEWER`

`ROLE_ADMIN`

`ROLE_TECH`

updatedAt

string (date-time)

Timestamp when member metadata was last updated

workspaceId

string

Workspace the member belongs to (UUID)

### [#](#claim-an-agent-s-workspace-error)Error response

400-599

All endpoints may return an unexpected error payload when a request cannot be processed.

error

object

Required

Wrapped error response.

Example request (cURL)

```bash
curl -X POST "https://api.linkbreakers.com/v1/agent-identity/claim/complete" \
  -H "Idempotency-Key: string" \
  -H "Content-Type: application/json" \
  --data '{"claimAttemptToken":"string","firebaseToken":"string","password":"string","userCode":"string"}'
```

Sample payload (application/json)

```json
{
  "claimAttemptToken": "string",
  "firebaseToken": "string",
  "password": "string",
  "userCode": "string"
}
```

Typical response

```json
{
  "accessRevokedAt": "2026-10-10T19:14:37.262Z",
  "accessToken": "lbw_1w8jp9longjwtvalue",
  "createdAt": "2026-10-10T19:14:37.262Z",
  "displayLanguage": "en-US",
  "email": "sam.member@example.com",
  "emailVerifiedAt": "2026-10-10T19:14:37.262Z",
  "firstName": "Sam",
  "id": "123e4567-e89b-12d3-a456-426614174000",
  "lastKnownCountry": "US",
  "lastKnownIp": "203.0.113.42",
  "lastKnownLanguage": "en-US,en;q=0.9",
  "lastKnownTimezone": "Europe/London",
  "lastName": "Rivera",
  "lastSigninAt": "2026-10-10T19:14:37.262Z",
  "role": "ROLE_ADMIN",
  "updatedAt": "2026-10-10T19:14:37.262Z",
  "workspaceId": "c0d3cafe-5b1e-4d42-a6fd-0c5f5c3962d0"
}
```

Base URL: `https://api.linkbreakers.com`

POST

`/v1/agent-identity/claim/lookup`

## [#](#read-an-agent-claim-link)Read an agent claim link

Return the email a claim link is bound to, whether it can still be used, and what the agent may do once the workspace is claimed. The claim\_attempt\_token is the secret: anyone holding it and the code can claim.

### [#](#read-an-agent-claim-link-parameters)Parameters

#### header parameters

Idempotency-Key

string

header

Makes retrying this request safe. See components.parameters.IdempotencyKey.

### [#](#read-an-agent-claim-link-request)Request body

claimAttemptToken

string

The claim\_attempt\_token from the link the agent handed over

### [#](#read-an-agent-claim-link-response)Response

200

Everything worked as expected.

email

string

The email the agent named for this claim. The workspace can only be claimed with it.

expiresAt

string (date-time)

When the code stops working

postClaimScopes

array<string (enum)>

What the agent may do once the workspace is claimed

registeredAt

string (date-time)

When the agent registered

status

string (enum)

Where a claim link stands.

##### Allowed values

`AGENT_CLAIM_STATUS_UNSPECIFIED`

`AGENT_CLAIM_STATUS_PENDING`

The link is live: enter the code to claim the workspace

`AGENT_CLAIM_STATUS_CLAIMED`

The workspace has been claimed

`AGENT_CLAIM_STATUS_EXPIRED`

The link or the registration expired, or the agent started a newer claim

### [#](#read-an-agent-claim-link-error)Error response

400-599

All endpoints may return an unexpected error payload when a request cannot be processed.

error

object

Required

Wrapped error response.

Example request (cURL)

```bash
curl -X POST "https://api.linkbreakers.com/v1/agent-identity/claim/lookup" \
  -H "Idempotency-Key: string" \
  -H "Content-Type: application/json" \
  --data '{"claimAttemptToken":"string"}'
```

Sample payload (application/json)

```json
{
  "claimAttemptToken": "string"
}
```

Typical response

```json
{
  "email": "string",
  "expiresAt": "2026-10-10T19:14:37.262Z",
  "postClaimScopes": [
    "API_SCOPE_UNSPECIFIED"
  ],
  "registeredAt": "2026-10-10T19:14:37.262Z",
  "status": "AGENT_CLAIM_STATUS_UNSPECIFIED"
}
```

Base URL: `https://api.linkbreakers.com`

---

Source: https://linkbreakers.com/help/api/agent-identity
