Skip to main content
An organization lets several people manage a team’s agents without anyone holding a wallet key. Members sign in to the console at oneshotagent.com/console, create agents there, and give each agent an access token. The agent then calls OneShot with that token and pays from its prepaid credits.

Roles

Everyone who signs up gets a personal workspace: an organization of their own with one agent and $1 of starter credit, so they can connect an app and try OneShot straight away. People who sign up from an invitation join the inviting team instead. Whoever creates the organization becomes its admin. Admins invite people by email on the Members page and set their role there. Every membership, invitation and role change is recorded in the audit log.

Create an agent

  1. Sign in at oneshotagent.com/console and create an organization, or pick one you were invited to.
  2. On the Agents page, select New agent, enter a name, and select Create agent.
  3. Copy the access token shown. It is displayed once, and OneShot stores only its hash.
The agent belongs to the organization for good. It has no wallet key: it acts only through access tokens, so a token is the only way to use it and revoking tokens is the way to stop it.

Use the token

An organization agent’s token works like any other access token: with the hosted MCP endpoint, or with the SDK in access-token mode.
Calls spend from the agent’s prepaid credits. Each agent’s balance shows on the Agents page and on the agent’s own page.

Limit an agent’s tools

By default an agent can use every tool. To narrow it, an admin opens the agent, goes to its Tool access tab, ticks the categories it may use, and selects Save: Checking the agent’s own balance and notifications is always allowed. A token can be narrowed further when it is created: on the agent’s Access tokens tab choose New token and tick fewer categories. It can never get a tool its agent doesn’t have. That suits a token you hand to one app, such as a search-only token for a research assistant. A call to a tool the agent or token isn’t allowed returns 403 with error: "tool_not_granted" and the category, and costs nothing. Changing an agent’s tools takes effect on its next call.

Default agent

Apps that connect to OneShot with your account, such as ChatGPT, use the organization’s default agent and spend its credits. The organization’s first agent becomes the default. An admin can pick another with Make default on the agent’s page, or under Settings.

Add credits

An admin opens the agent, selects Add credits, enters an amount between 1and1 and 1,000, and pays by card on Stripe’s checkout page. Stripe sends you back to the console, and the credits appear on the agent once the payment settles, usually within seconds. Stripe emails the receipt and invoice. Agents can also be funded with USDC; see Funding an agent’s credits.

Revoke access

  • One token: select Revoke next to it. Every request made with it from then on is refused. Work it queued that hasn’t started yet is refused too, and compute goals it started pause; a job already running finishes. Refused work is refunded the same way as any job that fails before doing anything.
  • A person: remove them from the organization on the Members page. They lose access to the console and the API within about a minute.
  • The whole organization: delete it from the organization settings. Every token held by its agents is revoked, and their queued work is refused.
  • A tool: remove its category from the agent. Queued work in that category is refused the same way.

API

The console calls these routes with the signed-in member’s session. Agent access tokens are refused on all of them. An agent outside your organization answers 404, exactly as a missing one does.
Not yet included: adding an existing wallet agent to an organization, credits shared across an organization, organization approvers, an organization spend dashboard, and SSO. They are part of the enterprise roadmap and are scoped with each pilot.