Skip to content
Scalekit Docs
Talk to an Engineer Dashboard

How AgentKit works

Connections, connected accounts, identifiers and tools: the AgentKit model, every connected-account status, and the user verification modes.

You configure a connection once per app. Each user approves access once, which activates their connected account. After that, your agent calls tools with the user’s identifier, and Scalekit makes the API call with that user’s token.

  1. Once per app1 · You set up a connectionin the dashboard
  2. Once per user2 · Your user approves accessauthorization link
  3. Scalekit3 · Scalekit stores tokensconnected account is ACTIVE once any user verification passes
  4. Every tool call4 · Your agent calls a toolidentifier + tool name
Gmail, Slack, GitHub…API call with the user's tokenScalekit adds the token, calls the API and returns JSON to your agent.
Steps 1 and 2 happen once. Step 4 happens on every call. Your code never handles an OAuth token.
TermWhat it isWho creates itIn code
ConnectorA supported app, such as Gmail, and its library of tools.Scalekit, or you for a custom connectorgmail
ConnectionYour environment’s settings for one connector: an OAuth client and scopes, or the fields for API-key sign-in. All your users share it.You, once, in the dashboardconnection_name
Connected accountOne user’s link to a connection. It holds their tokens and a status.Your code creates it. The user activates it by approving access.connected_account_id
IdentifierYour app’s ID for the user. Always pass it with the connection name.Youidentifier
Authorization linkA one-time URL where the user approves access.Scalekit, when your code asks for oneget_authorization_link
User verificationThe check that the person who approved access is the user you meant.Your server, or Scalekitverify_connected_account_user
ToolOne action on a connector, with an input schema.Scalekit for built-in tools, or you for custom toolstool_name
Virtual MCP serverA URL that exposes chosen tools for one user to any MCP client.You, per agentactions.mcp
Session tokenA short-lived bearer token that lets an MCP client call a Virtual MCP server’s tools as one user. Mint one before each run.Your server, per runactions.mcp.create_session_token
API proxyA call to the app’s own API through Scalekit, which adds the user’s credentials. Use it when no built-in tool fits. See Call any API.Your codeactions.request

The In code column shows Python names. The Node.js SDK uses the camelCase form, such as connectionName and connectedAccountId. One exception: Node.js executeTool takes the connection name as connector and the tool’s inputs as toolInput. The REST API also names the connection connector.

StatusMeansWhat to do
ACTIVETokens are valid.Call tools.
PENDING_AUTHThe user hasn’t finished approving access.Send a new authorization link.
PENDING_VERIFICATIONThe user approved, but user verification hasn’t confirmed them.Finish your verify step, or check the verification mode.
EXPIREDTokens expired or were revoked and couldn’t be refreshed.Send a new authorization link.
DISCONNECTEDThe account was disconnected.Reconnect with a new authorization link.

In Python, status is a string such as "ACTIVE". In Node.js, it is the numeric ConnectorStatus enum: import it from @scalekit-sdk/node (2.18.0 or later) and compare with ConnectorStatus.ACTIVE. The REST API returns the name as a string.

Use your app’s internal user ID. It must be stable (it never changes), unique per user and hard to guess. Don’t use an email address: a user can change their email, and an old address can be reassigned to someone else, so the identifier would no longer point to the same person. An email is also easy to guess, which makes misuse easier.

Pass the identifier together with the connection name. When you pass connected_account_id instead, Scalekit ignores the identifier.

Set the mode in AgentKit > Settings > User Verification. New environments start with None.

ModeWhat happensUse it for
Custom user verifierScalekit redirects the user to your verify URL. Your server confirms the user and calls the verify API.Production (recommended)
Scalekit users onlyThe person approving access must be signed in to your Scalekit dashboard.Internal testing
NoneAnyone with the link activates the account.Development only

Verify users shows how to set up the custom user verifier.