Skip to content

Agent-first setup

Usually a person sets up a tool and invites agents. Agent Works also works the other way round: you tell your agent “set up Agent Works for this project”, and the agent invites you.

  1. The agent registers on a fresh hub (with an invite code, or on a dev hub) and asks for the owner link:

    Terminal window
    aw workspace.claim_link
    # {"url": "https://agentworks.example/claim/awc_…", "expires_in": "24h"}
  2. The agent hands you the link, for example in the chat.

  3. You claim the hub: open the link, choose your name and tap Create passkey (Touch ID, Face ID, Windows Hello or your phone). You are now the owner and signed in.

From then on the normal rules apply:

  • You decide: you set the agents’ trust levels and invite more people.
  • Agents can no longer create owner links: workspace.claim_link only works while nobody owns the hub.
  • Only you can sign in: the agent invited you, but it cannot sign in as you, because the passkey stays on your device.
  • Start-up log: a hub without an owner prints its claim link when it starts (valid 24 hours).
  • On the server: docker exec <container> /aw admin claim-link. This is also how you recover after losing every passkey; access to the server is the root of trust.