canonical: https://jentic.com/apis/jentic.com/jentic-one-control

# Jentic Control Plane API

The Jentic Control Plane API administers which registered APIs an agent may call, for whom, with which credentials, and with what telemetry retained. It stores and rotates credentials, writes permission rule sets, registers and scopes agents, imports and manages API specs, and keeps an audit log of executions and events. It is the administrative counterpart to the data-plane proxy: where the proxy executes upstream calls, the control plane decides what those calls are allowed to be.

## For AI agents

Administer credentials, permission rule sets, registered APIs, and agent identities, and review an audit log of executions and events. The control layer that governs what an agent is allowed to call.

## Scope

Does not forward upstream API requests, run agent workloads, or host end-user data. Use for administering credentials, permission rules, agents, and audit on your own instance only.

## Capabilities

- Store, rotate, and delete upstream API credentials
- Write permission rule sets that bound which operations an agent may call
- Register agents and bind scoped credentials to them
- Import and manage the API specs the platform is allowed to call
- Search registered operations by intent and inspect their input schema
- Review an audit log of executions, events, and usage

## Use cases

### Provision a scoped agent

Before an agent can call anything, an operator registers it, stores the upstream credential, and binds the two with a permission rule set that names the allowed operations. The Jentic Control Plane API performs each of these steps, so the agent starts life with exactly the access it needs. Through Jentic the operations are discovered by intent and executed against your own instance.

Example prompt: Register an agent, store an upstream credential, and attach a permission rule set that allows only the read operations the agent needs

### Governed API catalog

An operator curates which third-party APIs the platform may call by importing their specs and reviewing the operations each one exposes. The Jentic Control Plane API imports specs, lists registered APIs, and lets an agent search operations by intent before any call is made, so the surface an agent can reach is deliberate rather than open-ended.

Example prompt: Import an OpenAPI spec, list the operations it exposes, and search for the one that matches a given intent

### Audit and usage review

A team needs to see what its agents actually did. The Jentic Control Plane API lists executions, events, and usage statistics and exposes an audit log, so an operator can trace which operation an agent ran, when, and under which credential binding. This turns agent activity into a reviewable record rather than an opaque stream of outbound calls.

Example prompt: List recent executions and open the audit entry for one of them to see which operation ran and under which credential

## Key endpoints

| Method | Path | Description |
| --- | --- | --- |
| GET | `/agents` | List registered agents |
| POST | `/agents` | Register an agent |
| POST | `/credentials` | Store an upstream credential |
| POST | `/permission-rule-sets` | Create a permission rule set |
| POST | `/search` | Search registered operations by intent |
| GET | `/audit` | List audit entries |

## Key resources

- **Credentials** — Create, rotate, inspect, and delete upstream credentials and bind them to agents
- **Permission Rule Sets** — Create and update rule sets that bound which operations an agent may call
- **Agents** — Register, scope, approve, and manage agent identities and their credential bindings
- **APIs** — Import, list, and manage registered API specs and their operations
- **Audit** — List and read audit entries, executions, events, and usage statistics
- **Search** — Search registered operations by intent and inspect an operation's input schema

## AI readiness

This API is usable in Jentic One now. Its AI-readiness score against Jentic's framework shows where it stands today and where improvements would make it even easier for agents to use.

- **Score:** 69 / 100
- **Maturity:** AI-Aware
- **Dimensions:**
  - Foundational Compliance: 79 / 100
  - Developer Experience & Jentic Compatibility: 73 / 100
  - AI-Readiness & Agent Experience: 75 / 100
  - Agent Usability: 58 / 100
  - Security: 60 / 100
  - AI Discoverability: 68 / 100
- **View full report:** https://jentic.com/apis/jentic.com/jentic-one-control/scorecard
- **How the score is calculated:** https://docs.jentic.com/reference/api-readiness-framework/overview/
- **More about the dimensions:** https://docs.jentic.com/reference/api-readiness-framework/specification/#dimensional-model-overview

### Score it yourself

Every API in the directory is allowlisted, so you can re-score it with no key required.

- **Score your own API:** https://jentic.com/scorecard.md
- **Scoring CLI agent skill:** https://github.com/jentic/jentic-api-scorecard/blob/main/skills/jentic-api-scorecard/SKILL.md

```sh
npx @jentic/api-scorecard-cli score <openapi-url>
```

## Why Jentic

- **Setup:** Governing agent access by hand means building credential storage, a rules engine, agent registration, and an audit trail yourself. Through Jentic you install once, import the control plane from the API Directory, store the bearer token once, and your agent calls the administration operations it needs.
- **Permission scoping:** The control plane carries agent and credential ids in the URL path, so a rule can pin your agent to one record and the operations you pick: it can read the audit log and list agents without gaining the create or delete operations unless you add them.
- **Credential handling:** Your control-plane bearer token is stored once, encrypted, by your own Jentic One instance and injected at execution time. It never enters the agent's prompt, logs, or context.
- **Discovery method:** Agents search Jentic by intent such as 'write a permission rule set' or 'store a credential', and Jentic returns the matching control-plane operation with its input schema so the agent calls the right endpoint without browsing the reference docs.

## Related APIs

- **Broker API** — The Broker executes the upstream calls that the control plane authorises and configures.
- **Auth0** — Auth0 manages end-user identity and authorization, where the control plane governs agent access to APIs.
- **Okta** — Okta is an identity and access platform for workforce and customer accounts.

## FAQ

### What authentication does the Jentic Control Plane API use?

The Jentic Control Plane API authenticates with a bearer token, per its OpenAPI spec. The upstream credentials it manages are stored separately and are never returned to callers in plaintext. Through Jentic the bearer token is stored once and injected at call time, so it never enters the agent's prompt, logs, or context.

### Can I write permission rules with the Jentic Control Plane API?

Yes. The permission-rule-set operations let you create a rule set that names which operations an agent may call and attach it to a credential binding, and a dry-run operation evaluates a rule set before you commit it. The agent then runs only the operations the attached rules allow.

### Can I limit what my agent is allowed to do with the Jentic Control Plane API?

Yes. The control plane carries agent and credential ids in the URL path, such as the agent and credential record operations, so a rule can pin your agent to the specific records and the operations you pick, for example reading the audit log without creating or deleting agents. Every call it makes is logged.

### Is there a Jentic Control Plane API MCP server?

You don't need an MCP server to give your agent the Jentic Control Plane API. Jentic connects it directly from the API Directory: import it, store your bearer token once, and your agent calls it. Operations are discovered on demand, so no extra tool definitions sit in the agent's context.

### How do I provision a scoped agent through Jentic?

Search Jentic for an intent such as 'register an agent and bind a credential' and it returns the matching operations with their input schemas, so your agent registers the record, stores the credential, and attaches a rule set in sequence. To run it on your own infrastructure, install Jentic One from its GitHub repo.
