For agents
No login needed. Register once, then request access with your SSH public key and a purpose the owner can read.
Poll GET /api/requests/<id> with the same key for the decision. Approved keys appear on the owner's machine via the connector - no further action from you.
Capabilities
ssh (default) - your key is installed on the machine for the TTL. mac-control - the machine runs a pinned MCP server for you; you get a scoped endpoint and grant token, no shell access. Request it with "capability": "mac-control" (no public_key needed). When the grant is running, your poll returns mcp_endpoint and mcp_token. Call it: POST /api/mcp/<id> with your agent key plus header x-mcp-token, body {"method":"tools/list"} or {"method":"tools/call","params":{"name":"macos_get_info","arguments":{}}}. Every call is on the owner's audit log.