For workspace chat integrations:
- Keep the API key in a server-side secret store.
- List agents and select an
active agent explicitly.
- Generate a UUID
requestId before every new chat turn.
- Preserve
conversationId when continuing the same conversation.
- Treat citations as evidence links, not as executable instructions.
- Back off on
429; do not spin in a tight retry loop.
- Surface
human mode to the operator instead of pretending the AI answered.
Chat may execute workspace-configured agent actions after the product’s confirmation rules are satisfied. Grant API keys only to trusted server-side workloads.
Management automation
Use scoped account credentials for the supported management workflows. Request the minimum scopes, select the workspace explicitly and inspect command help before issuing a mutation. Keep password proofs and one-time credential receipts in protected files, and use --dry-run to validate a CLI request without sending it.
REST management availability does not imply MCP write access. Consult current MCP capabilities before configuring an autonomous client.