Skip to content

What you're approving

Before an agent touches a workspace, a person approves it in the browser. This page explains that screen, so you know what you’re agreeing to before you press the button.

  • A client that has just opened a Hydrant tab. If you haven’t got that far, start with Connect your agent.
  • A GitHub account that’s a member of the workspace. Hydrant signs you in first (“First, prove it’s you.”), then shows the request.
  • If Hydrant’s Terms or Privacy changed since you last agreed, you’ll be asked to accept the current versions before you can approve anything.
  1. Read who’s asking. The heading names the client: “Claude Code wants in.” Underneath, Hydrant says how it knows. “Identified by” followed by a host means the client published its identity at that address. “Registered”, a date and “no verified home page” means it introduced itself and Hydrant has only its word. Approve those when you started the request yourself.
  2. Check where you go next. For a command-line tool the screen says your browser returns to this computer. That’s normal. For a web client it names the site.
  3. Pick one workspace. One workspace per connection. The first one in your list is preselected, so look before you approve. Want another? Connect again.
  4. Pick the access.
    • Read and write: same as an agent key. It can create, edit and comment as you.
    • Read only: it can look. It can’t touch.
  5. Press Approve, or Cancel to connect nothing.

“Approved. Back to” and the client’s name. The client finishes on its own. In Hydrant, everything the agent does is recorded under the client’s name and yours, like Claude Code (agent; via Sam Rivera). That attribution stays in the history after the connection is gone.

  • Outrank you. On every request the agent gets your current role in that workspace and nothing above it. Get demoted and so does it, on its next request.
  • Leave its workspace. A connection is bound to the workspace you picked. No tool accepts a different one.
  • Manage people or credentials. Members, invitations, ownership, keys and connections are browser-only.
  • Outlast you. Leave the workspace, or get removed, and every key and connection you granted there stops immediately. Rejoining doesn’t bring them back.

Assigning an issue to a named agent is a label. It grants no access and starts nothing.

  • You approved read only and now every write fails. Revoke the connection under Settings › Agents › Connections and approve again with read and write.
  • “You’re not in any workspace yet.” Create or join one first, then start again from the client.
  • “Already approved.” You pressed Approve twice, or reloaded. Go back to your client. If it’s still waiting, start again from there.
  • “Browser sign-in for agents isn’t enabled here yet.” This Hydrant deployment has the feature off. On hydrant.dev it’s on; on anything self-run, ask whoever runs it.