Agents

Everything the panel does goes through Kaisin's HTTP API, so everything the panel can do, an agent can do. Settings → Connect an agent gives Claude Code, Claude, or anything that speaks MCP that reach: it acts as you, with your role.

It cannot sign in, make more tokens or change your password. Those are closed to an agent whatever it asks for.

Four ways to connect

On your machine

Through the command line. There is no token to paste, and signing the command line out cuts the agent off too.

kaisin auth login admin.example.com
claude mcp add kaisin -- kaisin mcp --host admin.example.com

Any other MCP client works the same way: the command is kaisin mcp, over stdio.

Claude, or any connector

Paste the installation's MCP address into Claude under Settings → Connectors → Add custom connector, or into any MCP client that signs in with OAuth:

https://admin.example.com/api/mcp

It sends you back to Kaisin to approve it, and you can make it read-only then.

With a token

For a client that takes a URL and a header and cannot sign in by itself. Name what the token is for, create it, and copy it: it is shown once, and lasts 90 days.

claude mcp add --transport http kaisin https://admin.example.com/api/mcp \
  --header "Authorization: Bearer <token>"

As a skill

For a Claude chat without the connector. The download is a zip with a token inside it, so treat it like a password. Upload it under Capabilities in Claude's settings, then add the installation's host to the domains Claude's code sandbox may reach.

Read only

A token, a connector and a skill can each be made read-only. It can look at everything and change nothing, and it cannot reveal credentials.

What the agent is given

Three tools, not one per feature: find an endpoint, describe it, call it. They work over the API's own reference, so a feature added to Kaisin is one an agent can already use.

Each call is made as you. A 403 means your account may not do that, or that the token is read-only, and it is not something to work around.

Closing one

Every token made here is listed in Settings → Sessions beside your browsers and terminals. Closing it there stops the agent on its next request.

Agents that run inside Kaisin

Separate from all of the above. Agents in the panel are ones Kaisin runs itself: a model, a standing instruction, and a list of things it may do. Kaisin carries out the tools; the model only asks. They use a model provider key you give under Settings → Agents, which also says what leaves the installation.