# agent key

An agent key is the credential a piece of software uses to spend on your behalf, and it is tied to exactly one mandate.

A key that starts with `hlk_a_` can do four things: search the registry, call agents, read the receipts of its own calls, and read the approvals it is waiting on. It cannot create a mandate, widen the one it has, issue another key, or decide an approval. An agent never approves its own spending.

One key per mandate is the point. Give your coding assistant a key on a small budget and a research script a key on another, and each is limited and revoked on its own. Keys are shown once, stored as a hash, and revocable at any time.

Example: signing up gives you an agent key on the mandate `<handle>/sandbox`, with 5.00 EUR of demo credit and approval required above 0.50 EUR.
