Agent JIT approvals

Agents ask through Authsia. You grant a folder, capability, and TTL — then revoke from Access Center or a paired iPhone.

Tree onlyThe grant follows descendants of the approved directory. Siblings and symlink escapes do not inherit. $HOME or / stays exact — no children.
Display onlyAttribution never changes authorization. Missing or competing sub-agent candidates show as unknown.

Scope

Named folder covers descendants, never ancestors or siblings. Root is root-only; workspace bindings select it explicitly with folder=%2F.

Allowed

JIT permits scoped list and exec only — with caller, TTL, and CLI checks.

Not JIT

access create makes reusable automation credentials. Separate path from JIT grants.

Human vs agent

TTY alone is not human auth. Eligible IDE terminals pair with an app-displayed code. Agent evidence still routes to JIT.

Recognized agent processes such as agy reuse approved grants across command shells, including commands with a terminal. A command shell exiting does not revoke the grant; agent exit, expiry, or explicit revocation ends reuse. Caller, workspace, item, and capability checks still apply.

Pairing, hooks, and setup

Generated agent instructions set AUTHSIA_AGENT_PLATFORM and AUTHSIA_AGENT_INVOKES_AUTHSIA directly before authsia; they do not invoke an env executable.

Copilot

Merges Authsia hooks into compatible settings. Preserves custom hooks. Invalid JSON gets repair guidance.

Codex

Installs rules and hooks, then trusts Authsia’s exact hook definitions. Rerun authsia agent init --agent codex to repair. Custom and disabled hooks stay.

Claude

After upgrading, rerun authsia agent init --agent claude in existing projects, then restart the client and MCP connection.

Paired list

A paired human’s direct list reuses the normal session only when Bridge reports that pairing. The Bridge does not open Agent JIT for that pairing.

Post-exit file inspection

After Agent JIT authorizes a secret-bearing exec or workspace run, Authsia conceals matched injected values in observed files as <concealed by authsia>.

Rewritten

Exact injected values plus one-layer Base64, URL-safe Base64, hex, percent/form, shell, HTML, and JSON. Encoded payloads are invalidated, not left recoverable.

Skipped

Binary, non-UTF-8, oversized, and symlink writes. No recursive decode or archive expansion. Human CLI and automation credentials do not start observation.

Warnings

None when there are no file findings. Warnings remain for detected secrets and inspection failures. Child exit status is preserved.

Network

Best-effort outbound TCP and connected UDP metadata under Activity → Network. Not blocking. Never payloads, URLs, headers, DNS, or secrets.

Commands