Agent tokens reach only their own agent
An access token an agent gets by exchanging its key now reaches exactly what that key reaches, so it can read only its own agent and cannot call the routes meant for people.
An agent can exchange its agent key for a short-lived access token. That token now carries the same limits as the key it came from.
With either credential, an agent can read its own capabilities and nothing about any other agent. Listing or fetching agents, reading or sending from an agent's inbox, managing agents and their keys, and approving or rejecting pending work are for people only. An agent's token gets 403 on those, and on another agent's capabilities it gets 401, the same answer its key gets.
A workspace owner or admin signed in to the dashboard, and a person's own token, keep full access to every agent in the workspace. Nothing changes for an agent that only works with its own agent.
For help, write to support@last-price.ai.