Agent JIT approvals
Agents ask through Authsia. You grant a folder, capability, and TTL — then revoke from Access Center or a paired iPhone.
$HOME or / stays exact — no children.Scope
Named folder covers descendants, never ancestors or siblings. Root is root-only; workspace bindings select it explicitly with folder=%2F.
Allowed
JIT permits scoped list and exec only — with caller, TTL, and CLI checks.
Not JIT
access create makes reusable automation credentials. Separate path from JIT grants.
Human vs agent
TTY alone is not human auth. Eligible IDE terminals pair with an app-displayed code. Agent evidence still routes to JIT.
Recognized agent processes such as agy reuse approved grants across command shells, including commands with a terminal. A command shell exiting does not revoke the grant; agent exit, expiry, or explicit revocation ends reuse. Caller, workspace, item, and capability checks still apply.
Pairing, hooks, and setup
Generated agent instructions set AUTHSIA_AGENT_PLATFORM and AUTHSIA_AGENT_INVOKES_AUTHSIA directly before authsia; they do not invoke an env executable.
Copilot
Merges Authsia hooks into compatible settings. Preserves custom hooks. Invalid JSON gets repair guidance.
Codex
Installs rules and hooks, then trusts Authsia’s exact hook definitions. Rerun authsia agent init --agent codex to repair. Custom and disabled hooks stay.
Claude
After upgrading, rerun authsia agent init --agent claude in existing projects, then restart the client and MCP connection.
Paired list
A paired human’s direct list reuses the normal session only when Bridge reports that pairing. The Bridge does not open Agent JIT for that pairing.
Post-exit file inspection
After Agent JIT authorizes a secret-bearing exec or workspace run, Authsia conceals matched injected values in observed files as <concealed by authsia>.
Rewritten
Exact injected values plus one-layer Base64, URL-safe Base64, hex, percent/form, shell, HTML, and JSON. Encoded payloads are invalidated, not left recoverable.
Skipped
Binary, non-UTF-8, oversized, and symlink writes. No recursive decode or archive expansion. Human CLI and automation credentials do not start observation.
Warnings
None when there are no file findings. Warnings remain for detected secrets and inspection failures. Child exit status is preserved.
Network
Best-effort outbound TCP and connected UDP metadata under Activity → Network. Not blocking. Never payloads, URLs, headers, DNS, or secrets.