Roles
Everyone who signs up gets a personal workspace: an organization of their own with one agent and $1 of starter credit, so they can connect an app and try OneShot straight away. People who sign up from an invitation join the inviting team instead.
Whoever creates the organization becomes its admin. Admins invite people by email on the Members page and set their role there. Every membership, invitation and role change is recorded in the audit log.
Create an agent
- Sign in at oneshotagent.com/console and create an organization, or pick one you were invited to.
- On the Agents page, select New agent, enter a name, and select Create agent.
- Copy the access token shown. It is displayed once, and OneShot stores only its hash.
Use the token
An organization agent’s token works like any other access token: with the hosted MCP endpoint, or with the SDK in access-token mode.Limit an agent’s tools
By default an agent can use every tool. To narrow it, an admin opens the agent, goes to its Tool access tab, ticks the categories it may use, and selects Save:
Checking the agent’s own balance and notifications is always allowed.
A token can be narrowed further when it is created: on the agent’s Access tokens tab choose New token and tick fewer categories. It can never get a tool its agent doesn’t have. That suits a token you hand to one app, such as a search-only token for a research assistant.
A call to a tool the agent or token isn’t allowed returns
403 with error: "tool_not_granted" and the category, and costs nothing. Changing an agent’s tools takes effect on its next call.
Default agent
Apps that connect to OneShot with your account, such as ChatGPT, use the organization’s default agent and spend its credits. The organization’s first agent becomes the default. An admin can pick another with Make default on the agent’s page, or under Settings.Add credits
An admin opens the agent, selects Add credits, enters an amount between 1,000, and pays by card on Stripe’s checkout page. Stripe sends you back to the console, and the credits appear on the agent once the payment settles, usually within seconds. Stripe emails the receipt and invoice. Agents can also be funded with USDC; see Funding an agent’s credits.Revoke access
- One token: select Revoke next to it. Every request made with it from then on is refused. Work it queued that hasn’t started yet is refused too, and compute goals it started pause; a job already running finishes. Refused work is refunded the same way as any job that fails before doing anything.
- A person: remove them from the organization on the Members page. They lose access to the console and the API within about a minute.
- The whole organization: delete it from the organization settings. Every token held by its agents is revoked, and their queued work is refused.
- A tool: remove its category from the agent. Queued work in that category is refused the same way.
API
The console calls these routes with the signed-in member’s session. Agent access tokens are refused on all of them.
An agent outside your organization answers
404, exactly as a missing one does.
Not yet included: adding an existing wallet agent to an organization, credits shared across an organization, organization approvers, an organization spend dashboard, and SSO. They are part of the enterprise roadmap and are scoped with each pilot.