oap identity
Manage AgentIdentity resources
oap identity apply <path>
Server-side apply an AgentIdentity YAML
oap identity canonical-id <email>
Print the canonical user ID derived from an email address.
Use this when constructing SpiceDB group-membership writes for the multiplayer-sessions feature. Example:
zed relationship create group:engineering member user:$(oap identity canonical-id alice@example.com)
The canonical form (base64-encoded lowercased email) is the same encoding channelsd uses internally, so admin-written group memberships match what's looked up at message time.
oap identity delete <name>
Delete an AgentIdentity
oap identity list
List AgentIdentity CRs
oap identity put-token <identity-name>
Read an existing AgentIdentity, look up the named credential's secretRef, and create-or-update the underlying Secret with the supplied token bytes. Lets you keep AgentIdentity YAML in git without secrets.
Exactly one of --from-literal, --from-env, --from-env-file, --from-file, --from-stdin must be supplied.
Flags:
--credential string Name of the credential within the AgentIdentity (required)
--from-env string Read token from the named environment variable (e.g. GITHUB_TOKEN)
--from-env-file string Read token from a .env file: PATH:KEY (note: PATH may not contain a colon)
--from-file string Read token from a file path
--from-literal string Token value as a literal string (avoid in shell history)
--from-stdin Read token from stdin (single line; trailing newline trimmed)
--skip-verify Skip live verification of the token against the provider (format check still applies)
oap identity refresh <identity-name>
Walk AgentIdentity.spec.credentials[*] looking for type=oauth. For each whose expires_at is within --threshold (default 5m) — or every oauth credential if --all-oauth — perform an RFC 6749 refresh-token grant against the stored token_endpoint and update the Secret in place.
--credential <name> refreshes one specific credential (skips threshold check). Refresh failures don't mutate existing Secret values.
Flags:
--all-oauth Refresh every type=oauth credential
--credential string Refresh a single credential by name
--threshold duration Refresh credentials expiring within this duration (default "5m0s")
oap identity setup <identity-name>
Identity-rooted setup (no AgentClass context). Requires at least one of --toolkits or --mcps. Each entry is the resource name (e.g. gh, kubectl, linear-readonly).
This is the experimentation path; for production agents you typically want 'oap agent setup-identity <classname>' which derives intent from the AgentClass's Toolspec/MCP graph.
Flags:
--force Re-run flows even when credential is already set up
--mcps stringSlice Comma-separated MCPServer names
--non-interactive Never prompt: verify credentials that are already provisioned and fail on any that are not
--toolkits stringSlice Comma-separated toolkit names (e.g. gh,kubectl)
oap identity show <name>
Show details of an AgentIdentity