If you already use Hookie and want your coding agent to work in your workspace, connect it over OAuth instead. See Connected agents. Self-registration is for an agent that should have an account of its own.
1
Get a challenge
GET /v1/agents/register/challenge returns a signed challenge and the current Terms version.2
Solve it
Find a nonce whose hash with the challenge starts with enough zero bits. About a million hashes, one to three seconds of CPU.
3
Register
POST /v1/agents/register with the solution and your acceptance of the Terms. The response carries an admin API key and a claim link, each shown once.1. Get a challenge
difficulty_bits the challenge states. It is 20 normally, and 2, 4 or 6 bits more (4, 16 or 64 times the work) on a day when registrations are close to Hookie’s daily limit.
2. Solve the proof of work
Find anonce, a decimal string of at most 32 digits, such that:
difficulty_bits zero bits. Hash the UTF-8 bytes of the challenge string exactly as you received it, a colon, and the nonce. Count up from 0. At 20 bits that is about a million hashes.
3. Register
Read the Terms of Use first. By sendingaccept_terms, the agent accepts them for the person or organization it acts for (its operator), who is responsible for what it does with the account.
Idempotency-Key is optional. Use a random value such as a UUID: it makes a retry safe across challenges. It counts only with a challenge that is unexpired and solved, and only for the same agent_name and operator_contact, so the same key with a different name is a different registration. If an attempt fails with 502 identity_provider_error, the key is released: get a new challenge and send the same key again.
201 Created:
4. Use the API key
The key is an ordinary admin API key. Send it asAuthorization: Bearer hk_… to the REST API, the hosted MCP server, or the CLI:
What the key can do
Everything an admin can do in a workspace, on/admin/api/*, /mcp and the CLI: create projects, endpoints, ingest keys, rules, destinations, sources, triggers and workflows, read records, and replay deliveries. See the API reference and the MCP tools.
What it cannot do
Some actions need a person. Until someone claims the workspace, the key is refused:- billing and upgrades
- single sign-on and Directory Sync requests
- inviting members
- linking a Google Workspace domain
- creating more API keys
403 with code: "agent_not_permitted" and claim_required: true, and the message tells the agent to hand over its claim link:
agent_not_permitted without claim_required: the person who claimed the workspace does them in the console. The agent identity itself can never sign in to the console or hold an OAuth token.
5. Hand the claim link to a person
When the account needs a person, to upgrade it or to manage members, give the person responsible for the agentclaim.url.
1
They open the link
Signed in to Hookie, they see which agent and workspace it is.
2
They click Claim
They become the workspace’s owner. The link works once.
3
The agent keeps working
The agent’s key keeps its admin role, now acting for the person. They can revoke it any time in Settings → API keys.
POST /admin/api/agent-accounts/claim-preview and POST /admin/api/agent-accounts/claim with { "claim_token" }; both need a signed-in person.
Limits
Refusals
Every refusal carries a stablereason and a sentence saying what to do.