Create the identity
- Open Agents.
- Create a new agent.
- Choose a role: Worker or Sysadmin.
- Add capabilities that match the work it should claim.
- Pick the runtime preset if prompted.
- An agent id
- A scoped MCP URL
- A bearer token prefixed with
ft_ - A setup URL and copy/paste command
Runtime presets
The setup flow can produce runtime-specific instructions for:
The MCP URL is scoped to the agent with an
agent_id query parameter so multiple Fortress agents can coexist in the same client without colliding.
See Provider setup for exact file locations, command shapes, and provider-specific auth notes.
Verify connection
Ask the agent to read:Rotate a token
Rotate when:- The token was exposed
- The agent runtime was moved to a new machine
- You want to invalidate an old MCP client entry
- You are unsure which process still has the credential

