# What can my agent do with my account?

URL: https://antideploy.com/blog/what-can-my-coding-agent-do-with-my-antideploy-account

Your agent can deploy, set variables, read logs and create services. It cannot delete anything, read a secret back or spend your money.

## At a glance

- **One approval**: You approve each token once, in a browser
- **Scoped**: The token reaches your account, nothing else
- **Write-only secrets**: Values can be set, never read back
- **Revocable**: One click at antideploy.com/tokens

Published 7 October 2026. Facts checked 7 October 2026. 4 min read.

## The short answer

After you click Approve, your coding agent can deploy apps, set variables, read logs and metrics, and create a database, a file bucket, sign-in, email and AI keys. It cannot delete an app, drop a database, read a secret back, attach a domain or add money to your AI wallet. You can take its access away at any time.

**It can.** Create and deploy apps, set and list variables, read logs, metrics, health and deploy history, create services, schedule jobs, run security scans, redeploy and roll back.

**It cannot.** Delete an app or a database, read a secret back, mint another token, attach a domain or add money to the wallet. Those need you, in a browser.

## What the approval screen says

When your agent starts a login, you see a screen called "Connect your terminal?". It shows the name of the tool asking, for example Codex or Claude Code, and a code to check against the one in your agent. It says what you are granting and what you are not:

- Create projects and their databases, and deploy them
- Cannot read back the secrets you set
- Cannot delete anything
- Revocable at any time, from your account tokens

If you did not just start a login in a terminal, press Refuse. Nothing is granted until you choose.

## What your agent can do

All of it goes through the Antideploy API, with the token you approved.

- **Apps and deploys.** Create and list apps, deploy, redeploy, roll back, read deploy history, watch a deploy, change the address, switch deploy on push on or off, and set the root folder.
- **Variables.** Set variables, list their names and remove one. Values are never returned.
- **Services.** Create and inspect a database, a file bucket, sign-in and email, and create AI keys.
- **Running the app.** Read logs, metrics and health, manage scheduled jobs, and run security scans.
- **Project keys.** Make and revoke keys for one app, for use in CI.

## What your agent cannot do

These stay in your browser on purpose, because they are irreversible, or they spend your money, or they widen access.

- **Delete an app or drop a database.** You do it in the console. An agent can create a database, but it cannot delete one.
- **Read a secret back.** Values are write-only. If you lose one, set it again.
- **Make another token.** You approve each one, once, in a browser.
- **Add money to the AI wallet.** It can give you the top-up link and wait.
- **Attach a custom domain.** You do that on the app's Domains tab.

## Where the token lives

The token goes in a file on your own machine, `~/.antideploy/config.json`, readable only by you. It is never printed in the chat and it is never put in your project folder. Your agent is told not to display it, because anything an agent prints can end up in its transcript.

Never paste a token or key into a chat with an agent. If an agent asks you to, say no. The sentence you paste carries no access, so it is safe to share. Anyone who pastes it connects their own account, not yours.

## Two kinds of credential

**An account token** starts with `adu_`. It is for your agent, it reaches your account, and it never goes in the project.

**A project key** starts with `ad_`. It is for one app, it is built to survive being committed, and it is what you use in CI. An app can have up to ten.

## How to take access away

Open [antideploy.com/tokens](https://antideploy.com/tokens). You see each token and can revoke it. A revoked token stops working immediately, and the agent has to ask you to approve a new one.

## Permission questions, answered.

Anything else? Write to us and a person answers.

[support@antideploy.com](mailto:support@antideploy.com)

### Which account did my agent connect to?

When a deploy finishes, your agent tells you where the app is live and on which Antideploy account, for example the email address and how it signs in. Many people have two accounts, so it is worth a look.

### Can a hostile README trick my agent into leaking my secrets?

Variables are write-only, so there is no call that returns a value. A trick that asks your agent to fetch a secret has nothing to fetch.

### Can my agent spend money?

No. It cannot add money to the AI wallet or change your plan. It can create an AI key, but a key on an empty wallet stops working until you top up.

### What if my agent runs on someone else's machine?

Then the token is saved on that machine. Revoke it at antideploy.com/tokens when you no longer trust that machine.

### Can I give my agent less access?

Use a project key. It belongs to one app, can deploy and read that app, and cannot make other keys.

## More guides, and the platform.

Each platform page covers one part of Antideploy: what it does, where it stops and the questions people ask. [See the whole platform](https://antideploy.com/platform), or [all the guides](https://antideploy.com/blog).

- [How to deploy an app without opening a dashboard](https://antideploy.com/blog/how-to-deploy-an-app-without-opening-a-dashboard): Your agent deploys, reads logs and sets things up. The few things that stay in a browser, and what to say.
- [How to let your agent read logs and fix a failed deploy](https://antideploy.com/blog/how-to-let-your-coding-agent-read-logs-and-fix-a-failed-deploy): The loop: read the reason, read the logs, fix the code, deploy again. And what Antideploy repairs for you.
- [Is Antideploy safe and legit?](https://antideploy.com/blog/is-antideploy-safe-and-legit): Who runs it, where your data lives, how secrets are handled, and what is not promised.

- [Agent API](https://antideploy.com/platform/agent-api)
- [Environment variables](https://antideploy.com/platform/environment-variables)
- [Console](https://antideploy.com/platform/console)
- [Security checks](https://antideploy.com/platform/security-checks)

Facts on this page were checked against the live platform on 7 October 2026.

## Deploy something. Start with one sentence.

Paste one sentence into your coding agent, click Approve once, and get a live link. No card, no trial clock.

To set this up, give your coding agent this sentence:

```text
Set this project up to deploy on Antideploy. Fetch https://antideploy.com/agent.md and follow it.
```
