How-to

Work with teammates

Invite people to your organization so they can deploy too, or let everyone at your email domain join themselves — how roles work today, and what belonging to several organizations means.

Your organization is your account. Everything you make belongs to it, and anyone you invite works on the same things you do, from their own agent.

Ask for it

invite sam@company.com to my agenthost account

Sam gets no password and no key. They point their own MCP client at agenthost, sign in with that email address, and land in your organization. If Sam already uses agenthost for something else, they keep their own account and gain yours alongside it — the next time they sign in, they're asked which one the connection is for.

Roles

Everyone has a role: owner, admin or member. Ask for one explicitly if it matters:

invite sam@company.com as an admin

RoleToday
ownerEverything, including inviting people
adminEverything, including inviting people
memberEverything except inviting people

Roles are barely a boundary right now

Only inviting users is role-gated. A member can create, deploy, and delete any app or project in the organization. Treat an invitation as full trust, and use app-level invitations for anyone who should merely see something.

Let your whole team in at once

If everyone who should be here has an email address at the same domain, claim it and stop inviting people one at a time:

everyone at acme.com should be able to use our agenthost account

From then on, anyone with an @acme.com address who signs in to agenthost for the first time is shown your organization and joins it as a member — no invitation, no waiting for you.

You can claim more than one:

our people are on acme.com and acme.co.uk

What it does and doesn't do

  • It only affects people who are new to agenthost. Someone who already has an agenthost account keeps it. Claiming a domain never reaches back and collects existing users, whoever they work for.
  • They are offered it, not forced into it. The sign-in page names your organization and the domain it matched, and offers "create my own organization instead" right beside it.
  • They accept the terms for themselves. Joining records their own acceptance, with the versions they were shown. Your organization's agreement — made when it was created — is untouched: nobody joining re-signs it on your behalf.
  • They arrive as member — the least-privileged role. Promote anyone who needs more.
  • Each one takes a seat, and seats are unlimited on the paid plan. This is a paid feature: on the free plan, which is one person, there's no team to join.
  • Removing a domain removes nobody. It stops future signups; everyone already in stays in.

Claiming and unclaiming

Ask your agent to show the list before changing it — the tool replaces it rather than adding to it:

which email domains join our agenthost account?

stop taking new people from acme.co.uk

A claimed domain is an open door

Anyone who can get an address at that domain can walk into your account and see everything in it. That's the right trade for a company domain where IT controls the addresses. It is the wrong trade for a domain where anyone can sign up for a mailbox — and public providers like gmail.com are refused outright for that reason. A domain can only belong to one agenthost account; if yours is already taken, write to us.

Seeing who's in

who has access to my agenthost account?

You get everyone and the role they hold here. People who also work for other organizations keep that private — you only see their role on yours.

Belonging to more than one

This is the normal case for an agency or a freelancer: your own organization, plus one per client.

  • A connection belongs to one organization. Your agent acts inside it and can't see the others.
  • To work on a different one, connect your MCP client again and pick that organization when signing in. There's no tool that switches mid-conversation.
  • whoami lists the other organizations the same person belongs to, so your agent can tell you which one it's currently in — worth asking before a destructive request.

which agenthost organization am I connected to right now?

Removing someone

There is no tool for removing a person from an organization yet. If you need someone taken off, contact us — and in the meantime, revoke anything they hold: API tokens they minted can be revoked by id, and app invitations can be revoked individually.

Under the hood

Access is a membership: a row joining one person to one organization with one role. Every authenticated request re-checks it, so a change takes effect immediately rather than at the next sign-in. Every credential agenthost issues — OAuth grant, API token, browser session — is bound to exactly one organization, and every tool call is scoped to it.

A claimed email domain is checked at one moment only: when an address agenthost has never seen finishes proving it owns that address. The plan is re-checked at the same moment, so if an account lapses to the free plan its domains stop admitting anyone that instant, and start again if it re-subscribes — there's no list to remember to clear.

Tools: invite_user, list_users, whoami, update_account.