Developers Forgebench MCP Budgets & Agent Keys

Budgets & Agent Keys

Manage spending limits, adjust rate limits, and issue API credentials for your registered agents.

Request an agent key in your coding assistant, then review it securely in your browser.

Changing agent budgets

You can inspect and update spending limits directly in chat:

"Show details for researcher-agent"
"Set researcher-agent's monthly budget to $40"
"Limit researcher-agent to 100 tool calls per hour"

How budget changes work

  1. Self-service decreases & small adjustments: Applied immediately in chat after your confirmation.
  2. Increases above self-service limits: Your assistant returns a confirm_url. You click the link, sign into the console, and approve the change.
  3. Increases that exceed total workspace caps: Submitted as an approval request for workspace admins in the Forgebench console.

Claiming agent API credentials

Forgebench enforces a Zero Secrets in Chat policy: API keys are never printed in chat transcripts.

Step 1: Request a credential

Type:

Give me an API key for researcher-agent

Your assistant returns a single-use claim link:

Here is your secure link to reveal the API key for 'researcher-agent':
https://app.forgebench.ai/confirm/cred_claim_8b39a...

(Link expires in 15 minutes)

Step 2: Reveal the key in your browser

  1. Click the link to open the credential claim page.
  2. Sign in with your Forgebench user account (must be the agent's owner or an admin).
  3. Review the agent's permissions, model allowlist, and budget.
  4. Click Reveal Key to copy the secret key (sk_agent_...).

Step 3: Run your agent with the credential

Store the key in your project's .env file (ensure .env is listed in your .gitignore):

export FORGEBENCH_AGENT_KEY="sk_agent_01h8..."
export FORGEBENCH_GATEWAY_URL="https://api.forgebench.ai/v1"

Use it in your agent codebase to make governed calls:

curl -s https://api.forgebench.ai/v1/chat/completions \
-H "Authorization: Bearer $FORGEBENCH_AGENT_KEY" \
-H "Content-Type: application/json" \
-d '{
  "model": "gpt-4o",
  "messages": [{"role": "user", "content": "hello"}]
}'

Your agent moves from sealed → registered, and upon its first successful API call through the gateway, automatically transitions to active.