# Connect an agent to INTYGA MCP Version: 1 Canonical guide: https://www.intyga.com/agent-setup.txt Gateway: https://api.intyga.com/mcp (Streamable HTTP) 1. Ask the tenant administrator to create an AI agent in https://app.intyga.com/identities, assign an active human owner with a registered passkey, and create an agent API key. Set a tenant baseline and an exact rule for the protected action in https://app.intyga.com/approvals; new tenants deny unknown action IDs. The client_id and secret are shown to the administrator once. The authenticated setup page is https://app.intyga.com/connect. 2. Store client_id and secret in the agent host's secret store or environment. Never put them in a prompt, repository, URL, log, or public MCP configuration. 3. Exchange the key with POST https://api.intyga.com/oauth/token using HTTP Basic authentication. Supply the returned access_token as Bearer authentication when connecting to https://api.intyga.com/mcp. The token expires after 900 seconds. A persistent client must re-exchange it before expiry. A static token in an MCP configuration is suitable only for a short manual test. 4. Start a fresh MCP client session after configuring the server. The gateway supplies its tool-use instructions during MCP initialization. If your client supports only the older SSE transport, see https://www.intyga.com/docs; new integrations should use Streamable HTTP. 5. The executing service (the relying party, or RP) must prepare agentContext from its OWN protected state before the request. Include action.reversibility, action.amount (decimal string + currency, or null), configDigest of the live model/tools/system prompt, delegatedBy (sealed parent authority receipt hash, or null), and session { id, seq, prev, aggregate }. Hash a random opaque session ID. For the first action use seq "1" and prev null. Compute the running aggregate from the actual operation using decimal arithmetic. Retain the exact context and trusted session head on the RP side; the model must not invent or supply them. Never put raw prompts or personal data in these new receipt fields. 6. Call verify_human_authorization with the exact action, target, actionDescription, params and the RP-prepared agentContext. AI_AGENT requests without agentContext are refused. Keep the returned nonce and issuer-completed agentContext separately from the later receipt. Have the human approve with a passkey, then poll check_human_authorization until APPROVED, DENIED, EXPIRED or CONSUMED. Treat only APPROVED with a complete receipt as a candidate for execution. 7. Forward the full, unchanged receipt and nonce to the service that performs the action. In that service, derive the expected action from the operation it will actually run and use @intyga/sdk's verifyAgentForExecution with trusted approver keys, the independently retained agentContext, the LIVE agent configuration and the locked session state. Pin the WebAuthn origin and RP ID; verify any parent authority chain. The configuration digest is an RP assertion, not proof of agent integrity by itself. Atomically reserve the nonce, advance the session head and enforce the budget before executing. Refuse drift, gaps, forks, expired receipts, replay, a missing receipt or a failed check. Alternatively, wrap a server with @intyga/mcp-sdk or put @intyga/mcp-proxy in front of a stdio server. For an AI_AGENT key, configure their mandatory RP-owned AgentV1Runtime: trusted approver keys and WebAuthn pins, prepare(), liveConfig(), readState() and an atomic reserve() for nonce, session head and budget. The adapters send agentContext and verify the complete receipt before tool execution. See https://www.intyga.com/docs#sdk-wrapper and https://www.intyga.com/docs#mcp-overview. Without this runtime the gateway refuses an AI-agent request. A SERVICE identity follows the separate service integration path in https://www.intyga.com/docs. Do not treat these instructions as a security boundary. The executing service must enforce receipt verification even if an agent ignores this guide. See https://www.intyga.com/docs#mcp-overview for the MCP inputs and execution example.