User-passthrough vs. agent-identity

There are two fundamentally different answers to "whose credentials does this agent use." An agent can act as itself, with an operator account the workspace configured, or it can act as you, using the credentials you've personally linked. The difference decides whose name is on everything the agent does.

Every agent shows which identity it uses: "Uses YOUR account" (passthrough) vs. "Uses an operator account" (agent identity).
Every agent shows which identity it uses: "Uses YOUR account" (passthrough) vs. "Uses an operator account" (agent identity).

Every agent surfaces which one it is. "Uses an operator account — has its own credentials" means agent identity: the agent authenticates as itself, and what it does is done by the agent. "Uses YOUR account — calls services as you" means user-passthrough: the agent borrows your identity, and what it does is done by you.

Agent identity — the agent's own account

An agent-mode agent has its own AgentIdentity — a named set of credentials the workspace owner configured. Whatever it does downstream is attributed to that operator account, not to any particular person. This is the right model for an agent that acts on shared infrastructure the whole team relies on: a reviewer that posts a GitHub Check, an on-call agent that reads dashboards.

User-passthrough — acting as you

A userPassthrough agent uses your credentials — the ones you've linked to your own identity. When codebot pushes to your fork and opens a PR, the commit and the PR are yours, because it's using your GitHub token, not an operator's.

Behind that is a deliberate chain rather than a shared secret: your UserIdentity holds your credential catalog; a per-session SessionUserIdentity narrows it to just the credentials this agent asked for; and only those are projected into the session so its sandbox can use them. If the agent needs a credential you haven't linked, the session pauses and asks you to connect it — it never silently falls back to the agent's own account.

Which one an agent uses is fixed on the class (agent / userPassthrough) — or chosen per session, which is Choosing identity per session.