Skip to content

Quickstart

Connect your AI agents to real-world APIs in minutes — without per-API glue code or secret sprawl.

Jentic lets your agents search, inspect, and execute APIs and workflows by intent (e.g., "get an httpbin response", "create a GitHub issue", "search recent news") with credential injection, access control, and observability. Credentials are stored encrypted and injected by the Broker at execution time, so they never reach the agent or its prompts.

Discovery
DiscoverFind the operation you need by intent
Connection
ConnectThe Broker proxies the call to the API
Credentials
CredentialsStored encrypted, injected at execution
Scoping
ScopingDefault-deny, per-operation access

Stand up an instance, grant an agent access to specific operations, and it runs search → inspect → execute — with credentials injected by the Broker at execution time, never reaching the agent.


Prerequisites

  • A machine you control to host the instance — a single local install is fine to start.
  • git, uv, and Docker running (the setup wizard uses Docker or a plain Python environment, your choice).
  • Read the secure deployment guide before pointing an instance at a real credential — an agent on the same OS user can read the credential store off disk.

Install and connect

Jentic One is a normal HTTP server your agents connect to as clients. Run the server on a machine you control, and register agents against it from wherever they run.

1. Stand up the server

On the machine that will host your instance. A setup wizard stands up the server, in Docker or a plain Python environment, your choice.

curl -fsSL https://raw.githubusercontent.com/jentic/jentic-one/main/tools/install.sh | sh

This builds the two CLIs — jenticctl (operator) and jentic (agent) — and runs jenticctl install, the interactive wizard that configures and starts a local stack.

2. Reach it from the agent side

The instance is a normal HTTP server. From wherever your agent runs, check you can reach it before wiring anything.

curl http://<your-instance-host>:8000/health

A local install answers at http://127.0.0.1:8000; use that base URL wherever <your-instance-host>:8000 appears below.

3. Register the agent

Where your agent runs, kept off the instance's machine so it can never read the stored keys. Install the CLIs only (no server wizard), then give the agent its own identity.

curl -fsSL https://raw.githubusercontent.com/jentic/jentic-one/main/tools/install.sh | JENTIC_NO_INSTALL=1 sh
jentic register   # gives this agent its own identity on your instance

register generates an Ed25519 keypair, files a dynamic client registration, then waits for an operator to approve the agent — approve it in the UI at /app. On a local install, confirm the prompted http://127.0.0.1:8000; a remote install needs --url and --broker-url. Re-running is idempotent.


Your first brokered call

From a running instance, these four steps take you to a response from a real API — with the agent never seeing your credentials.

1. Create the admin account (operator, one-time)

Open /setup in the operator web UI and create the first administrator; the page redirects to login once the account exists. This account imports APIs, stores credentials, and approves agents.

From the terminal instead:

jenticctl setup

2. Import an API

Pull an API description into your local registry from the public Jentic API Directory:

jentic catalog search httpbin               # find an API
jentic catalog import httpbin.org/httpbin   # import it into your local registry

jentic catalog run bare opens an interactive browser; jentic apis manages what you've imported. You can also register your own OpenAPI description for a private or internal service — the same custody, permissions, and audit trail apply.

3. Grant access (store the credential here, if needed)

Access is default-deny: an approved agent is bound to nothing until an operator grants it. Request access to the toolkit:

jentic access request --toolkit httpbin.org/httpbin   # returns a request id
jentic access status <request-id>                      # has it been granted?

The operator approves in the dashboard at /app/access-requests. httpbin takes no credential; for an authenticated toolkit the operator enters the secret while approving — it is encrypted at rest, never returned to a caller, and decrypted only inside the Broker at execution time. It never rides in your request.

4. Make the call

jentic search get             # find an imported operation
jentic inspect <operation>    # its method, params, and schemas
jentic execute GET:https://httpbin.org/get --json

execute takes the operation's full upstream URL (the form search and inspect report) or its operation_id. The Broker checks the agent's permissions, injects the stored credential after the check, forwards the request, and writes an execution record — visible under Monitor → Executions in the dashboard.


Starter APIs to try

Import any of these with jentic catalog import <name>, then search → inspect → execute. No-auth APIs work immediately; for the rest, the operator stores the credential while granting access.

API Auth? Example use
PostHog Required Query events, run a HogQL insight
NewsAPI Required Search recent headlines by topic
Finnhub Required Get a stock quote or company news
BulkSMS Required Send an SMS
Discord Required Post messages, react, DMs
New York Times Required Top stories, article search
TheCocktailDB None Look up a cocktail recipe by name

Connect your agent runtime

Instead of running the CLI by hand, let your agent drive it. On a machine with an agent runtime (Claude Code, Cursor, Codex, …), jentic setup registers the agent and installs the Jentic skill into the runtime's native layout, so it discovers the search → inspect → execute loop on its own:

jentic setup                # auto-detect the runtime on this machine

MCP-capable runtimes can connect over the Model Context Protocol instead: the local jentic mcp stdio server, or an operator-enabled hosted /mcp endpoint on your instance. See the MCP integration overview to combine your instance with the hosted directory search for discovery.


Troubleshooting

  • Can't reach the instance — Confirm the server is running (jenticctl status) and that curl http://<your-instance-host>:8000/health returns OK.
  • 401 / Unauthorized — The agent is approved (jentic register, then approve at /app) but the operator hasn't granted it access to the operation. Request it with jentic access request.
  • Missing credentials — Add them under Credentials in the Jentic One dashboard while approving the access request.
  • Agent stuck "waiting for approval" — Approve it in the UI at /app; re-running jentic register is safe.

Next steps