> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hookie.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Change what a connected agent may do



## OpenAPI

````yaml /openapi.json patch /admin/api/agents/{grant_id}
openapi: 3.1.0
info:
  title: Hookie API
  version: 1.0.0
  summary: Capture, route and deliver webhooks.
  description: >-
    Hookie exposes three HTTP surfaces.


    **Ingest + streaming** is the public plane. A path-form endpoint URL
    authenticates by its own high-entropy slug — there is no key, token or
    cookie — and an `ik_live_…` ingest key authenticates the `/v1/*` routes.
    Whenever the URL names a dataset the payload is stored whole into it;
    project mapping rules are evaluated on exactly one shape, `POST
    /v1/ingest/{ingest_key}` with no dataset segment.


    **The customer portal API** is a separate, token-authed surface for your end
    customers, scoped to one portal and one customer.


    **The admin API** drives the console. It accepts either a browser session or
    an OAuth bearer token from a connected coding agent — the same routes, the
    same validation, the same audit trail. An agent's authority is its user's
    workspace role narrowed to the scopes granted in the console.


    This document is generated from the request handlers and adversarially
    verified against them.
  contact:
    name: Hookie
    url: https://hookie.ai
  license:
    name: Proprietary
    url: https://hookie.ai/legal/terms
servers:
  - url: https://app.hookie.ai
    description: Production
  - url: https://app.preview.hookie.ai
    description: Preview
security: []
tags:
  - name: Ingest
    description: Send events to Hookie.
  - name: Streaming
    description: Tail events in real time over SSE or WebSocket.
  - name: Portal
    description: Token-authed surface for your end customers.
  - name: Projects
    description: Projects and their settings.
  - name: Routing
    description: Rules, endpoints, datasets and records.
  - name: Delivery
    description: Destinations, deliveries and replay.
  - name: Workflows
    description: Multi-step workflows, triggers and AI agents.
  - name: Observability
    description: Search, correlation, stats and the audit log.
  - name: Workspace
    description: Members, connected agents, SSO and billing.
paths:
  /admin/api/agents/{grant_id}:
    patch:
      tags:
        - Connected agents
      summary: Change what a connected agent may do
      operationId: updateConnectedAgentScopes
      parameters:
        - name: grant_id
          in: path
          required: true
          description: Grant id from listConnectedAgents.
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - scopes
              properties:
                scopes:
                  type: array
                  items:
                    type: string
                    enum:
                      - hookie:read
                      - hookie:write
                      - hookie:manage
                  description: >-
                    Full replacement. Any unknown scope is REJECTED rather than
                    silently dropped. An empty array leaves the agent with no
                    Hookie scope, so its next admin-API request fails.
                    hookie:manage clips to at most the `admin` role — billing is
                    out of reach at every scope.
      responses:
        '200':
          description: >-
            Grant updated; effective on the agent's very next request (offline
            JWT verification is not consulted for scopes — this table is).
          content:
            application/json:
              schema:
                type: object
                required:
                  - ok
                  - scopes
                properties:
                  ok:
                    type: boolean
                    enum:
                      - true
                  scopes:
                    type: array
                    items:
                      type: string
                    description: The sanitized scopes now stored.
        '400':
          description: >-
            `scopes must be an array`, or `scopes must be a subset of:
            hookie:read, hookie:write, hookie:manage`.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Not signed in.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: >-
            `Connected agents are managed by the account owner in the console`
            (caller is an agent), or `Missing X-Requested-With header`.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: >-
            `No such connected agent` — the grant does not exist, belongs to
            another user, or has already been revoked. A revoked grant cannot be
            re-scoped.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: '`Internal error`.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - session: []
components:
  schemas:
    Error:
      type: object
      required:
        - error
      properties:
        error:
          type: string
          description: Human-readable reason.
        retry_after:
          type: integer
          description: Seconds to wait. Present on 429.
        upgrade_url:
          type: string
          format: uri
          description: Present only on a monthly-quota 429.
  securitySchemes:
    session:
      type: apiKey
      in: cookie
      name: hookie_session
      description: >-
        The console's sealed session cookie, set by WorkOS AuthKit. Mutating
        requests also require the `X-Requested-With` CSRF header.

````