[{"data":1,"prerenderedAt":319},["ShallowReactive",2],{"navigation_docs":3,"-guide-authentication-permissions":168,"-guide-authentication-permissions-surround":314},[4,146],{"title":5,"icon":6,"path":7,"stem":8,"children":9,"page":36},"Guide","i-lucide-book-open","\u002Fguide","1.guide",[10,14,37,55,59,63,67,71,75,79,83,87,109,134,138,142],{"title":11,"path":12,"stem":13},"What is Agent Zero?","\u002Fguide\u002Fintroduction","1.guide\u002F1.introduction",{"title":15,"icon":16,"path":17,"stem":18,"children":19,"page":36},"API","i-lucide-plug","\u002Fguide\u002Fapi","1.guide\u002F10.api",[20,24,28,32],{"title":21,"path":22,"stem":23},"API overview","\u002Fguide\u002Fapi\u002Foverview","1.guide\u002F10.api\u002F1.overview",{"title":25,"path":26,"stem":27},"Define endpoints","\u002Fguide\u002Fapi\u002Fdefine-endpoints","1.guide\u002F10.api\u002F2.define-endpoints",{"title":29,"path":30,"stem":31},"Use the API from a client","\u002Fguide\u002Fapi\u002Fuse-from-client","1.guide\u002F10.api\u002F3.use-from-client",{"title":33,"path":34,"stem":35},"Protect endpoints","\u002Fguide\u002Fapi\u002Fprotect-endpoints","1.guide\u002F10.api\u002F4.protect-endpoints",false,{"title":38,"icon":39,"path":40,"stem":41,"children":42,"page":36},"Authentication","i-lucide-lock","\u002Fguide\u002Fauthentication","1.guide\u002F11.authentication",[43,47,51],{"title":44,"path":45,"stem":46},"Authentication overview","\u002Fguide\u002Fauthentication\u002Foverview","1.guide\u002F11.authentication\u002F1.overview",{"title":48,"path":49,"stem":50},"GitHub OAuth","\u002Fguide\u002Fauthentication\u002Foauth","1.guide\u002F11.authentication\u002F2.oauth",{"title":52,"path":53,"stem":54},"Permissions","\u002Fguide\u002Fauthentication\u002Fpermissions","1.guide\u002F11.authentication\u002F3.permissions",{"title":56,"path":57,"stem":58},"Organizations","\u002Fguide\u002Forganizations","1.guide\u002F12.organizations",{"title":60,"path":61,"stem":62},"Frontend","\u002Fguide\u002Ffrontend","1.guide\u002F13.frontend",{"title":64,"path":65,"stem":66},"Mails","\u002Fguide\u002Fmails","1.guide\u002F14.mails",{"title":68,"path":69,"stem":70},"Internationalization","\u002Fguide\u002Finternationalization","1.guide\u002F15.internationalization",{"title":72,"path":73,"stem":74},"Deployment","\u002Fguide\u002Fdeployment","1.guide\u002F16.deployment",{"title":76,"path":77,"stem":78},"Tech stack","\u002Fguide\u002Ftech-stack","1.guide\u002F2.tech-stack",{"title":80,"path":81,"stem":82},"Installation","\u002Fguide\u002Finstallation","1.guide\u002F3.installation",{"title":84,"path":85,"stem":86},"Environment variables","\u002Fguide\u002Fenvironment-variables","1.guide\u002F4.environment-variables",{"title":88,"icon":89,"path":90,"stem":91,"children":92,"page":36},"Codebase","i-lucide-folder-tree","\u002Fguide\u002Fcodebase","1.guide\u002F5.codebase",[93,97,101,105],{"title":94,"path":95,"stem":96},"Codebase structure","\u002Fguide\u002Fcodebase\u002Fstructure","1.guide\u002F5.codebase\u002F1.structure",{"title":98,"path":99,"stem":100},"Dependencies","\u002Fguide\u002Fcodebase\u002Fdependencies","1.guide\u002F5.codebase\u002F2.dependencies",{"title":102,"path":103,"stem":104},"Formatting and linting","\u002Fguide\u002Fcodebase\u002Fformatting-linting","1.guide\u002F5.codebase\u002F3.formatting-linting",{"title":106,"path":107,"stem":108},"Agent Skills","\u002Fguide\u002Fcodebase\u002Fagent-skills","1.guide\u002F5.codebase\u002F4.agent-skills",{"title":110,"icon":111,"path":112,"stem":113,"children":114,"page":36},"Architecture","i-lucide-layers","\u002Fguide\u002Farchitecture","1.guide\u002F6.architecture",[115,118,122,126,130],{"title":110,"path":116,"stem":117},"\u002Fguide\u002Farchitecture\u002Foverview","1.guide\u002F6.architecture\u002F1.overview",{"title":119,"path":120,"stem":121},"State machine","\u002Fguide\u002Farchitecture\u002Fstate-machine","1.guide\u002F6.architecture\u002F2.state-machine",{"title":123,"path":124,"stem":125},"Execution boundary","\u002Fguide\u002Farchitecture\u002Fexecution-boundary","1.guide\u002F6.architecture\u002F3.execution-boundary",{"title":127,"path":128,"stem":129},"Issue-to-PR workflow","\u002Fguide\u002Farchitecture\u002Fissue-to-pr","1.guide\u002F6.architecture\u002F4.issue-to-pr",{"title":131,"path":132,"stem":133},"Adding a capability","\u002Fguide\u002Farchitecture\u002Fadding-a-capability","1.guide\u002F6.architecture\u002F5.adding-a-capability",{"title":135,"path":136,"stem":137},"Repository policy","\u002Fguide\u002Fconfiguration","1.guide\u002F7.configuration",{"title":139,"path":140,"stem":141},"Safety model","\u002Fguide\u002Fsafety","1.guide\u002F8.safety",{"title":143,"path":144,"stem":145},"Database","\u002Fguide\u002Fdatabase","1.guide\u002F9.database",{"title":147,"icon":148,"path":149,"stem":150,"children":151,"page":36},"Reference","i-lucide-book-marked","\u002Freference","2.reference",[152,156,160,164],{"title":153,"path":154,"stem":155},"CLI","\u002Freference\u002Fcli","2.reference\u002F1.cli",{"title":157,"path":158,"stem":159},"Model providers","\u002Freference\u002Fmodel-providers","2.reference\u002F2.model-providers",{"title":161,"path":162,"stem":163},"Source-control providers","\u002Freference\u002Fsource-control-providers","2.reference\u002F3.source-control-providers",{"title":165,"path":166,"stem":167},"Sandbox providers","\u002Freference\u002Fsandbox-providers","2.reference\u002F4.sandbox-providers",{"id":169,"title":52,"body":170,"description":176,"extension":308,"links":309,"meta":310,"navigation":311,"path":53,"seo":312,"stem":54,"__hash__":313},"docs\u002F1.guide\u002F11.authentication\u002F3.permissions.md",{"type":171,"value":172,"toc":300},"minimark",[173,177,182,194,198,201,259,274,277,289,293],[174,175,176],"p",{},"Agent Zero separates three kinds of authority. None of them implies another.",[178,179,181],"h2",{"id":180},"dashboard-sessions","Dashboard sessions",[174,183,184,185,189,190,193],{},"A Better Auth session grants access to the dashboard UI. Registration is closed unless ",[186,187,188],"code",{},"AUTH_ENABLE_SIGNUP"," is exactly ",[186,191,192],{},"true",", so who holds a session is an operator decision.",[178,195,197],{"id":196},"control-plane-principals","Control-plane principals",[174,199,200],{},"Control-plane mutations require an operator-issued bearer token, with per-principal repository and execution-mode grants:",[202,203,204,217],"table",{},[205,206,207],"thead",{},[208,209,210,214],"tr",{},[211,212,213],"th",{},"Variable",[211,215,216],{},"Grants",[218,219,220,235,249],"tbody",{},[208,221,222,228],{},[223,224,225],"td",{},[186,226,227],{},"AGENT_ZERO_CONTROL_PLANE_TOKENS",[223,229,230,231,234],{},"Who may mutate at all (",[186,232,233],{},"name:token"," pairs)",[208,236,237,242],{},[223,238,239],{},[186,240,241],{},"AGENT_ZERO_CONTROL_PLANE_REPOSITORIES",[223,243,244,245,248],{},"Which repository paths ",[186,246,247],{},"tasks.create"," may target",[208,250,251,256],{},[223,252,253],{},[186,254,255],{},"AGENT_ZERO_CONTROL_PLANE_MODES",[223,257,258],{},"Which execution modes each principal may request",[174,260,261,262,265,266,269,270,273],{},"Without a mode grant, a principal is limited to the non-writable ",[186,263,264],{},"observe"," and ",[186,267,268],{},"suggest"," modes. Approval decisions record the authenticated principal's name, never a wire-supplied actor. See ",[271,272,33],"a",{"href":34},".",[178,275,135],{"id":276},"repository-policy",[174,278,279,280,283,284,286,287,273],{},"What a run may do to a checkout is decided by the target repository's own ",[186,281,282],{},".agent-zero.yml"," — mode, autofix gates, change-risk classes, and isolation requirements. A control-plane principal can request a mode, but repository policy still has to allow the work, and high-impact changes always require human approval. See ",[271,285,135],{"href":136}," and the ",[271,288,139],{"href":140},[178,290,292],{"id":291},"organization-roles","Organization roles",[174,294,295,296,299],{},"When ",[271,297,298],{"href":57},"organizations"," are enabled, membership and roles govern what a signed-in user sees and manages inside the dashboard. Organization authority never extends to the control plane or to repository policy.",{"title":301,"searchDepth":302,"depth":302,"links":303},"",2,[304,305,306,307],{"id":180,"depth":302,"text":181},{"id":196,"depth":302,"text":197},{"id":276,"depth":302,"text":135},{"id":291,"depth":302,"text":292},"md",null,{},true,{"title":52,"description":176},"ILGw0KqIkG6Y0GjPi720INbKGwY7bOA9eV_RDv2SWao",[315,317],{"title":48,"path":49,"stem":50,"description":316,"children":-1},"The login page offers a GitHub button only when both halves of the credential are set:",{"title":56,"path":57,"stem":58,"description":318,"children":-1},"The dashboard ships with optional multi-user organizations: teams that share visibility into task history and approvals.",1787482153736]