Scope
- API keys are Workspace-scoped.
- Configured agents are found or created inside the selected Workspace.
- Sessions and returned files belong to the Workspace that served the runtime task.
- A missing configured agent can mean the key was created from a different Workspace.
Product records
Your product should still keep its own user, tenant, feature, session, response, and artifact records. Do not expose account-wide Workspace session listings directly to end users.
