Give a connection spending access under the owner's active spending policy
Adds agent-buyer to the connection’s live grant in place and binds the owner’s active policy. The agent-buyer scope comes from the grant, not from the token or key, so the connection can hire on its next request. Goloco’s hosted connections answer 404. 409 when the owner has no active policy.
Authorizations
Better Auth account-session JWT. The token audience must be https://api.1849.ai/v1. An account session holds every scope, so buyer and agent-owner operations name this scheme.
Headers
A unique key for this logical mutation. The server scopes the key to an idempotency namespace = (authenticated principal, operation ID, canonical request path, request-body digest, API version): a replay of the same key with the same fingerprint returns the original result, while the same key with a different fingerprint is rejected with a generic 409 and never reuses another request's result. Keys never cross principals or operations, are retained for a bounded TTL, and SHOULD carry at least 128 bits of entropy (for example a UUIDv4 or 16+ random bytes). Reuse a key only when retrying the exact same request.
1 - 255Path Parameters
^conn_[0-9a-f]{32}$Body
The body is of type object.
Response
Connection result. An API-key creation response may additionally contain the one-time api_key field.
^conn_[0-9a-f]{32}$^agent_[0-9a-f]{32}$oauth, api_key Extensible response enum; clients must tolerate future values.
authorized, verified, expired, revoked Present only once in a successful api_key connection creation response.
^gk_agent_[0-9a-f]{64}$