The short answer
After you click Approve, your coding agent can deploy apps, set variables, read logs and metrics, and create a database, a file bucket, sign-in, email and AI keys. It cannot delete an app, drop a database, read a secret back, attach a domain or add money to your AI wallet. You can take its access away at any time.
It can. Create and deploy apps, set and list variables, read logs, metrics, health and deploy history, create services, schedule jobs, run security scans, redeploy and roll back.
It cannot. Delete an app or a database, read a secret back, mint another token, attach a domain or add money to the wallet. Those need you, in a browser.
What the approval screen says
When your agent starts a login, you see a screen called "Connect your terminal?". It shows the name of the tool asking, for example Codex or Claude Code, and a code to check against the one in your agent. It says what you are granting and what you are not:
- Create projects and their databases, and deploy them
- Cannot read back the secrets you set
- Cannot delete anything
- Revocable at any time, from your account tokens
If you did not just start a login in a terminal, press Refuse. Nothing is granted until you choose.
What your agent can do
All of it goes through the Antideploy API, with the token you approved.
-
Apps and deploys. Create and list apps, deploy, redeploy, roll back, read deploy history, watch a deploy, change the address, switch deploy on push on or off, and set the root folder.
-
Variables. Set variables, list their names and remove one. Values are never returned.
-
Services. Create and inspect a database, a file bucket, sign-in and email, and create AI keys.
-
Running the app. Read logs, metrics and health, manage scheduled jobs, and run security scans.
-
Project keys. Make and revoke keys for one app, for use in CI.
What your agent cannot do
These stay in your browser on purpose, because they are irreversible, or they spend your money, or they widen access.
-
Delete an app or drop a database. You do it in the console. An agent can create a database, but it cannot delete one.
-
Read a secret back. Values are write-only. If you lose one, set it again.
-
Make another token. You approve each one, once, in a browser.
-
Add money to the AI wallet. It can give you the top-up link and wait.
-
Attach a custom domain. You do that on the app's Domains tab.
Where the token lives
The token goes in a file on your own machine, ~/.antideploy/config.json, readable only by you. It is never printed in the chat and it is never put in your project folder. Your agent is told not to display it, because anything an agent prints can end up in its transcript.
Never paste a token or key into a chat with an agent. If an agent asks you to, say no. The sentence you paste carries no access, so it is safe to share. Anyone who pastes it connects their own account, not yours.
Two kinds of credential
An account token starts with adu_. It is for your agent, it reaches your account, and it never goes in the project.
A project key starts with ad_. It is for one app, it is built to survive being committed, and it is what you use in CI. An app can have up to ten.
How to take access away
Open antideploy.com/tokens. You see each token and can revoke it. A revoked token stops working immediately, and the agent has to ask you to approve a new one.