Install Jentic One Beta
Jentic One is a self-hosted execution layer for AI agents. It lets your agent call the Jentic Control Plane API, or any other public or private API you need. You set the rules, the agent never sees your credentials, and every call is logged.
Two steps, two machines. Install the instance in a safe environment, then register your agent from wherever it runs.
Step 1: Jentic One Host machine
# On the machine that will host your Jentic One instance:
curl -fsSL "https://jentic.com/install.sh?src=apis&api=%2Fapis%2Fjentic.com%2Fjentic-one-control" | shStep 2: Agent machine
# On the machine where your agent runs (keep this separate from the instance):
curl -fsSL "https://jentic.com/install.sh?src=apis&api=%2Fapis%2Fjentic.com%2Fjentic-one-control" | sh
jentic register # connects your agent to your Jentic One instanceJentic One is in public beta. The setup above keeps your agent separate from the instance, which is what you want before using real credentials: an agent running as the same OS user as Jentic One can read its stored keys directly. Just evaluating? A single local install is fine to start. See the secure deployment guide for the tiers.
What an agent can do with Jentic Control Plane API.
Store, rotate, and delete upstream API credentials
Write permission rule sets that bound which operations an agent may call
Register agents and bind scoped credentials to them
Import and manage the API specs the platform is allowed to call
Search registered operations by intent and inspect their input schema
GET STARTED
Review an audit log of executions, events, and usage
Patterns agents use Jentic Control Plane API for, with concrete tasks.
★ Provision a scoped agent
Before an agent can call anything, an operator registers it, stores the upstream credential, and binds the two with a permission rule set that names the allowed operations. The Jentic Control Plane API performs each of these steps, so the agent starts life with exactly the access it needs. Through Jentic the operations are discovered by intent and executed against your own instance.
Register an agent, store an upstream credential, and attach a permission rule set that allows only the read operations the agent needs
Governed API catalog
An operator curates which third-party APIs the platform may call by importing their specs and reviewing the operations each one exposes. The Jentic Control Plane API imports specs, lists registered APIs, and lets an agent search operations by intent before any call is made, so the surface an agent can reach is deliberate rather than open-ended.
Import an OpenAPI spec, list the operations it exposes, and search for the one that matches a given intent
Audit and usage review
A team needs to see what its agents actually did. The Jentic Control Plane API lists executions, events, and usage statistics and exposes an audit log, so an operator can trace which operation an agent ran, when, and under which credential binding. This turns agent activity into a reviewable record rather than an opaque stream of outbound calls.
List recent executions and open the audit entry for one of them to see which operation ran and under which credential
169 endpoints — the jentic control plane api administers which registered apis an agent may call, for whom, with which credentials, and with what telemetry retained.
METHOD
PATH
DESCRIPTION
/agents
List registered agents
/agents
Register an agent
/credentials
Store an upstream credential
/permission-rule-sets
Create a permission rule set
/search
Search registered operations by intent
/audit
List audit entries
/agents
List registered agents
/agents
Register an agent
/credentials
Store an upstream credential
/permission-rule-sets
Create a permission rule set
/search
Search registered operations by intent
/audit
List audit entries
What agents get from Jentic-routed access to this vendor.
Setup
Governing agent access by hand means building credential storage, a rules engine, agent registration, and an audit trail yourself. Through Jentic you install once, import the control plane from the API Directory, store the bearer token once, and your agent calls the administration operations it needs.
Permission scoping
The control plane carries agent and credential ids in the URL path, so a rule can pin your agent to one record and the operations you pick: it can read the audit log and list agents without gaining the create or delete operations unless you add them.
Credential isolation
Your control-plane bearer token is stored once, encrypted, by your own Jentic One instance and injected at execution time. It never enters the agent's prompt, logs, or context.
Intent-based discovery
Agents search Jentic by intent such as 'write a permission rule set' or 'store a credential', and Jentic returns the matching control-plane operation with its input schema so the agent calls the right endpoint without browsing the reference docs.
Alternatives and complements available in the Jentic catalogue.
Specific to using Jentic Control Plane API through Jentic.
What authentication does the Jentic Control Plane API use?
The Jentic Control Plane API authenticates with a bearer token, per its OpenAPI spec. The upstream credentials it manages are stored separately and are never returned to callers in plaintext. Through Jentic the bearer token is stored once and injected at call time, so it never enters the agent's prompt, logs, or context.
Can I write permission rules with the Jentic Control Plane API?
Yes. The permission-rule-set operations let you create a rule set that names which operations an agent may call and attach it to a credential binding, and a dry-run operation evaluates a rule set before you commit it. The agent then runs only the operations the attached rules allow.
Can I limit what my agent is allowed to do with the Jentic Control Plane API?
Yes. The control plane carries agent and credential ids in the URL path, such as the agent and credential record operations, so a rule can pin your agent to the specific records and the operations you pick, for example reading the audit log without creating or deleting agents. Every call it makes is logged.
Is there a Jentic Control Plane API MCP server?
You don't need an MCP server to give your agent the Jentic Control Plane API. Jentic connects it directly from the API Directory: import it, store your bearer token once, and your agent calls it. Operations are discovered on demand, so no extra tool definitions sit in the agent's context.
How do I provision a scoped agent through Jentic?
Search Jentic for an intent such as 'register an agent and bind a credential' and it returns the matching operations with their input schemas, so your agent registers the record, stores the credential, and attaches a rule set in sequence. To run it on your own infrastructure, install Jentic One from its GitHub repo.
For Agents
Administer credentials, permission rule sets, registered APIs, and agent identities, and review an audit log of executions and events. The control layer that governs what an agent is allowed to call.
Use for: Store a new upstream credential, Write a permission rule set for an agent, Register an agent and bind a credential to it, List all registered APIs on the instance
Not supported: Does not forward upstream API requests, run agent workloads, or host end-user data. Use for administering credentials, permission rules, agents, and audit on your own instance only.
The Jentic Control Plane API administers which registered APIs an agent may call, for whom, with which credentials, and with what telemetry retained. It stores and rotates credentials, writes permission rule sets, registers and scopes agents, imports and manages API specs, and keeps an audit log of executions and events. It is the administrative counterpart to the data-plane proxy: where the proxy executes upstream calls, the control plane decides what those calls are allowed to be.
This API is usable in Jentic One now. Its AI-readiness score against Jentic's framework shows where it stands today and where improvements would make it even easier for agents to use.
Base layer of spec validity and structural soundness.
Aggregated quality score from linter diagnostics, weighted by severity.
Percentage of `$ref` references that resolve successfully.
Checks whether the API description parses successfully and conforms to its declared specification (e.g., OpenAPI).
Structural correctness score based on schema issues using logarithmic dampening.
Clarity, completeness, and ingestion readiness for developers and tooling.
How richly the API is illustrated with examples.
Percentage of examples that conform to their schemas.
Percentage of operations with complete response definitions (success, client error, server error).
Health of API ingestion, bundling, and resolution within Jentic pipelines.
Semantic breadth, depth, and agent comprehension for AI systems.
Coverage of descriptions across API elements.
Coverage of RFC 9457 Problem Details for error responses.
Coverage, uniqueness, and casing consistency of operationIds for AI inference.
Coverage of summaries across operations/tags/info.
Functional utility, complexity comfort, and AI orchestration readiness.
Agent comfort level based on API operational and structural complexity.
Trust, risk posture, and security compliance.
Average quality of security schemes based on authentication method strength (weakest link for OAuth2).
Findability, semantic richness, and reasoning readiness.
Clarity and depth of descriptions across API elements.
Score it yourself
Every API in the directory is allowlisted, so you can re-score it with no key required.
npx @jentic/api-scorecard-cli score <openapi-url>