> ## Documentation Index
> Fetch the complete documentation index at: https://docs.anonalabs.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Agent Self-Onboarding

> Let a coding agent set up Anona Memory from the terminal. One browser approval from you, no dashboard tour.

## What this is

A coding agent can connect itself to Anona Memory without you navigating the
dashboard beyond one approval screen. You approve the connection once, in a
browser. You never copy an API key, and never paste a password.

## The one thing you do

A browser window opens. You sign in with Google. You see the name of the client
that is asking for access, and you press Approve. That approval is the whole
security model, so read the client name before you press it.

## The flow

```
agent:  POST /oauth/register  {redirect_uris:["http://localhost:PORT/cb"]}
agent:  print .../oauth/authorize?client_id=…&code_challenge=…  then wait
human:  opens it
        -> /login?return_to=/consent?req=…
        -> Continue with Google
        -> Clerk -> POST /auth/social creates org + project + quota,
           email_verified=true
        -> /consent?req=…  -> reads client name -> Approve
agent:  code -> POST /oauth/token -> mcp_access token (+ refresh)
agent:  record / retrieve / reason / list_spaces / get_profile /
        get_model / get_user_profile
```

One human action. No inbox trip, because Clerk verified the address. No
password anywhere. No dashboard navigation beyond the consent screen itself.

## Per-client setup

| Client | Setup | Status |
| - | - | - |
| Claude Code | `claude mcp add --transport http anona-oauth https://memory.anonalabs.com/mcp` (no API key, no header) | Server side verified; native OAuth client, not yet run end to end |
| Codex | Needs an API key from the dashboard | Not yet verified completing the OAuth flow |
| Kimi | Needs an API key from the dashboard | Not yet verified completing the OAuth flow |

For Claude Code, that one command is the agent's whole job: it drives discovery,
client registration, the browser hop, and the token exchange natively. Nothing
else to configure.

If your client is not listed, or is listed as needing an API key, mint one from
the dashboard under **API keys** and follow the header-based setup in
[MCP Integration](/mcp-integration) instead.

<Warning>
  Only a client that implements OAuth 2.1 natively can complete this flow. Today
  that means Claude Code. For anything else the honest answer is that it still
  needs a key from the dashboard, which is the trip this page exists to avoid.
  If you are not on Claude Code, this page does not yet save you anything.
</Warning>

## What you get

Once connected, the agent has the MCP tools: `record`, `retrieve`, `reason`,
`list_spaces`, `get_profile`, `get_model`, and `get_user_profile`. See
[MCP Integration](/mcp-integration) for what each one does and how transports
differ.

## Limits

An OAuth credential minted this way is not an API key. It works over MCP, and
only over MCP. It does not work with the SDK or with raw HTTP calls to the REST
API. For those, mint a key from the dashboard.

## Troubleshooting

**The approval link expired.** It is valid for 15 minutes. Start the flow again
from the beginning rather than retrying the dead link.

**You approved, and the first tool call still fails with "No active API key for
this organization."** The account was created and the approval worked; the
failure is on our side, not yours. A brand-new account holds no API key by
design, and the gateway needs a way to tell the engine which organization you
are without one. If you see this, the deployment you are talking to does not
have that configured yet. Report it rather than minting a key to work around
it. The workaround hides exactly the thing we need to know is broken.

**The agent says it is connected but no memory is stored.** Ask it to run
`retrieve` on something you know it recorded. An agent that treats your "I
approved it" as proof of connection will report success it has not verified;
a tool call that returns data is the only evidence that counts.

**Do not poll the login endpoint.** It allows 10 attempts per 5 minutes per
address, so a polling loop locks you out within a minute. Wait for the human to
act instead of retrying.

**Signed up with a password instead of Google, and the approval broke.** The
password path requires verifying your email address first, and starting that
detour interrupts the consent flow you had open. Verify your address, then
start the flow again from the beginning.

**A verification email cannot be resent.** If it expired before you clicked it,
sign up again with the same address rather than waiting for a second email.

**What the new-account response is telling you.** It names verifying your
address as the next step, and that is the only thing it actually requires.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.