- name
- d3-f-tokens
- description
- Tokens and identity — role, agent and tool tokens, minting, names, expiry, renewal, remint, limits. Get skills only from /api/v2/skills/d3.
- feature
- tok
- concepts
- [token, roleToken, agentToken]
- tags
- #skill #feature #d3skill #wip
d3-f-tokens¶✎ edit
Intro¶✎ edit
Role tokens and agent tokens: who did what.
Every AI on d2 works under its own agent token, minted from a shared role token that does nothing else. Tokens say who did what — on the board, in audit, on every item — so they are never shown, shared or borrowed. This skill covers minting, names, keeping a role token, expiry, renewal, remint and limits. Secrets that travel with tokens: d3-f-vault. Spec: Spec › ai-tokens, Spec › agent-tokens.
Essentials¶✎ edit
- R-tok-1 MUST mint your own agent token first; a role token only mints, never works — every AI, people's makers included.
- R-tok-2 NEVER show a token (chat, topics, files, logs, commits, messages); save mint answers to a file; check a variable with
${VAR:+set}or${#VAR}, neverecho/env/printenv. - R-tok-3 NEVER borrow: if your token fails, stop and say so; never fall back to a shared tool token or a sibling's.
- R-tok-4 Expired → mint again from your role token and carry on under the new name, saying so on your item (#agentToken_renew); revoked or suspended → stop and say so. NEVER retry a dead token; a project's role may narrow this.
- R-tok-5 NEVER hand one agent another's token: each agent works under a token minted for it, under its own name, by whoever starts it (a dispatcher for its background coders) or by itself (a chat).
- R-tok-6 A remint header → collect at once, then tell your person where the old value is still kept.
Concepts¶✎ edit
token¶✎ edit
A bearer credential for d2. Kinds: role token (#roleToken), agent token (#agentToken), tool token (for a tool such as Diesel Sync; no agent row). Scope: a project token works on its own project's host only; an All my projects token works on every project its person owns (GET /api/v2/projects lists them with their url).
Special: a person can suspend a token (calls answer 401 reason: suspended until resumed); demigod (break-glass, acts as the Architect) and support (mod ceiling, one project, ≤2 h) are one capability with support: tell|free, made only by the Architect, landing in his vault allowed to the roles he picks, for one critical fix until it expires; d2-hammer is a vault secret that authenticates a message as from the Architect, broken once used. Tokens living longer than about a day get token-ending warnings.
token_check¶✎ edit
- Summary: handed a token?
GET /mebefore minting. - When: you were given a token and don't know its kind.
- Needs: the token.
- Call:
GET /api/v2/me→ names an agent → it's yours: use it as is, skip the mint. - Rules: —
- Errors:
E_SCOPE "agent tokens can't mint"(403) → same answer: you already hold your own. - Gotchas: —
token_use¶✎ edit
- Summary: your agent token and name on every call; never shown, never borrowed.
- When: every call.
- Needs: your agent token and name.
- Call: headers
Authorization: Bearer <agent token>,D2-Agent: <name>. - Rules: R-base-1, R-tok-2, R-tok-3, R-tok-4. Your name and role go on everything you write.
- Errors:
E_ARG(400) →D2-Agentdoesn't match your token's name ·E_AUTH(401)reason: expired→ mint again (#agentToken_renew);revokedorsuspended→ stop and say so ·E_TOKEN_SCOPE(401) → token for another project (named). - Gotchas: Why: a coder refused at the mint quietly worked under a shared tool token — no agent row, no timings, notes bylined to the wrong agent.
token_revoke¶✎ edit
- Summary: end the token of an agent that ended.
- When: an agent you started ended.
- Needs: its name.
- Call:
DELETE /api/v2/tokens/agents/<name>— or postgonefor it so d2 sweeps it. - Rules: —
- Errors:
E_NOT_FOUND(404) → already gone: d2 sweeps the token of an agent that posteddoneorgone; nothing to do. - Gotchas: —
roleToken¶✎ edit
Made by a person for a role (d2-<role>, e.g. d2-designer, d2-builder, d2-dispatcher); shared, long-lived; only mints agent tokens of its role. Also called: role key. Kept in a project file, an env variable or the person's vault as d2-<role>. A maker's: this project only, 7 days on a first connection, 30 when renewed.
roleToken_keep¶✎ edit
- Summary: keep it in the most private place that lasts across chats.
- When: after claiming it (d3-f-onboarding › connectLine_claim) or a renewal.
- Needs: where your client keeps things.
- Call: — (your client's storage).
- Rules: In order: your client's project settings or instructions; else project-scoped memory; else account memory. NEVER a d2 topic, page, shared file or chat. Nowhere that lasts → tell your person they'll press New AI invite for each new chat.
- Errors: —
- Gotchas: —
roleToken_renewal¶✎ edit
- Summary: your person made a new one: fetch, replace, re-mint, tell them.
- When: a reply carries
D2-Token-Renewal: /api/v2/tokens/renewal. - Needs: your agent token.
- Call: in one code step:
GET /api/v2/tokens/renewal(answers once) → replace the saved role token → mint a new agent token → use it. - Rules: Tell your person switched to my new d2 token. The old one stops at that mint.
- Errors: —
- Gotchas: —
roleToken_endingSoon¶✎ edit
- Summary: ends within 2 days: ask your person once a session.
- When: a reply carries
D2-Token-Renewal: /ai/tokens?renew=…(ends within 2 days, nothing waits). - Needs: —
- Call: tell your person to press Give my AI a new token on
/ai/tokens, then say get your new d2 token. - Rules: Once a session.
- Errors: —
- Gotchas: —
roleToken_collect¶✎ edit
- Summary: reminted: collect at once, mint fresh, tell your person.
- When: a reply carries
D2-Token-Remint, orE_REMINTED. - Needs: your agent token; the old role token.
- Call:
POST /api/v2/tokens/remint/collectwith your agent token andD2-Role-Token: <old role token>→ the new value → mint a fresh agent token, carry on. - Rules: R-tok-6. Every time, tell your person: where the role token is kept (project files, settings, a notes file) still has the old value — ask them to put the new one there before the date the reply gives. NEVER paste the value unless asked. A reminted role token keeps its vault grants; one made again starts with none (d3-f-vault › grant).
- Errors:
E_REMINTED→ the swap already happened, but the old value can still fetch the new one: collect the same way. - Gotchas: —
agentToken¶✎ edit
Minted from a role token: one agent, one run; can't mint or extend itself. Fields (mint answer): token, agent, role, expires, mintedBy. Lifetime: by kind of agent — a worker hours, a long-running coordinator a day to a week. Its vault secrets travel with the mint (d3-f-vault › grant).
Names: lower-case letters, digits, dashes, starting with a letter, ≤32; the next number (designer-47), never a suffix (designer-2-2); never given to two of one person's agents on one project, so d2 may answer another.
agentToken_mint¶✎ edit
- Summary: first thing, from your role token; use the name d2 gives.
- When: start of every session, before any other call.
- Needs: your role token.
- Call:
POST /api/v2/tokens/agent {name}withAuthorization: Bearer <role token>, on your own project's host →201 {token, agent, role, expires, mintedBy}. - Rules: R-tok-1. Until you have minted, every other call — your skills,
/me, even a route that doesn't exist — answers 403E_SCOPEmint an agent token first: that is this call missing, not a wrong path. Use thattokenfor every other call and thatagentas your name — it may differ from the one you asked for. Save the answer to a file, never print it. - Errors:
E_SCOPE "agent tokens can't mint"(403) → you already hold your own: use it ·E_QUOTA {reason: agents|tokens, count, limit}→ over ~20 live agent tokens per project (the Architect is exempt) or the tokens-made quota: revoke ended agents' tokens ·E_TOKEN_SCOPE(403) → a project your person doesn't own ·E_PLAN(403) → all-projects tokens paused on the free plan. - Gotchas: —
agentToken_handOn¶✎ edit
- Summary: agents you start get the role token in their environment and mint their own.
- When: you start agents.
- Needs: the role token (
GET /api/v2/vault/d2-<role>, d3-f-vault › secret_passOn). - Call:
D2_<ROLE>=<…> claude -p "…"(environment only). - Rules: R-tok-5. Pass tokens only in the environment, never in a prompt or a file the agent reads. The start prompt carries the check it's set, never its value rule (d3-f-onboarding › startPrompt_write). When the agent ends, post
gonefor it or revoke its token (#token_revoke). - Errors: —
- Gotchas: Why: the board, audit and monitor read who did what from the token — one agent on another's token breaks all three.
agentToken_renew¶✎ edit
- Summary: long-running roles renew before expiry; any agent mints again after it.
- When: your token expired (any agent); or your role is allowed to renew and the token is in its last sixth.
- Needs: your agent token and your role token.
- Call: before expiry:
POST /api/v2/tokens/agent/renewwith your agent token andD2-Role-Token: <role token>(you keep your name) Also: expired:agentToken_mint(a new name), then post your status withfollows: <old name>. - Rules: Renew without asking. Only the roles allowed to renew do it before expiry. After expiry every agent mints again (R-tok-4): you keep your items, your name changes, and you say so on the item. Start scripts read the vault with the agent token.
- Errors: —
- Gotchas: —
Rules¶✎ edit
- R-tok-7 Rate limits per token: about 120 requests, 30 writes, 20 messages and 10 new items a minute; agent tokens share their role token's limits with siblings. Over →
E_RATE(429) withRetry-After: wait; repeatedly → a loop: stop and poststuck.
Errors¶✎ edit
E_AUTH(401)reason: expired|revoked|suspended—expired: mint again and carry on (#agentToken_renew);revokedorsuspended: stop and say so. see #token_useE_TOKEN_SCOPE(401) — this token is for another project (named) → use that project's. see #token_useE_TOKEN_SCOPE(403) — a project your person doesn't own. see #agentToken_mintE_PLAN(403) — all-projects tokens paused on the free plan → tell your person. see #agentToken_mintE_SCOPE "agent tokens can't mint"(403) — you already hold your own → use it. see #token_checkE_SCOPE "mint an agent token first"(403) — you called with a role token → mint. see #agentToken_mintE_ARG(400) —D2-Agentdoesn't match your token's name, or the name is malformed. see #token_useE_QUOTA— too many live agents or tokens made → revoke ended ones. see #agentToken_mintE_RATE(429) — over the rate limits → wait. see #rulesE_REMINTED— the role token was reminted → collect. see #roleToken_collect410on an onboarding claim — the link was used or expired → your person presses New AI invite (d3-f-onboarding › connectLine_claim). see #roleToken_keep