intentic
Download the app
Download the app
Connected systems

Needs

What an agent asked you to connect or provide before it can go on

On this page(8 sections)

An agent raises a need when a task stops on something only you can give: a capability, a credential, a change to its environment. These routes raise one and list an agent's own, list what is open for you, answer one or hand over its secret, withdraw one, and read or revoke the standing grants an answer left behind.

8 calls. Pick one to open it, or use the list on the right.

POST/needs/askAsk a person for something the task needs

Raises a need in the conversation the calling shell belongs to and holds the call up to `wait` seconds for an answer. Answers `met` when it is usable now (or already was), `open` when it is still waiting, and `refused` when nothing was raised or a person declined. An open need's answer reaches the conversation by itself.

What you send

FieldTypeWhere
askrequiredobjectbody
when kind is "capability"shapebody
entryrequiredThe catalog entry or a connected…stringbody
targetThe site, host or address it…stringbody
setSettings to fill in, or to…objectbody
reconnectIt is connected, but its credential…booleanbody
when kind is "secret"shapebody
namerequiredThe name it is stored under,…stringbody
whereHow it will be used: the…stringbody
linkWhere a person gets one, shown…stringbody
hintWhat a valid one looks like,…stringbody
replaceOne is stored under this name…booleanbody
when kind is "grant"shapebody
subjectrequiredA connected capability the persona leaves…"capability" | "folder" | "shelf" | "site"body
whatrequiredstringbody
when kind is "release"shapebody
subjectrequiredstringbody
when kind is "environment"shapebody
toolrequiredstringbody
stepsrequiredstringbody
whystringbody
waitSeconds to hold the call for…integerbody

What comes back

FieldType
state"met" | "open" | "refused"
messageThe sentence the CLI prints, written…string
needobject
idThe need's handle, the one `needs…string
conversationIdThe conversation that asked, and the…string
subjectWhat exactly is asked forobject
when kind is "capability"shape
entryThe catalog entry, as the catalog…string
nameWhat the catalog calls it, never…string
modeConnect something new, give a connected…"connect" | "reconnect" | "change"
instanceThe connection a reconnect or a…string
targetThe site, host or address the…string
prefillSettings the agent could fill in…object
changesFor a change: each setting and…object
reasonThe daemon's own sentence on why…string
reportedThe agent reported the credential refused…boolean
when kind is "secret"shape
nameThe name it is stored under,…string
whereHow it will be used: the…string
linkWhere a person gets one, shown…string
hintWhat a valid one looks like,…string
replaceOne is stored under this name…boolean
when kind is "grant"shape
subjectA connected capability the persona leaves…"capability" | "folder" | "shelf" | "site"
whatThe capability's id, the folder, or…string
labelWhat it is, in the daemon's…string
personaThe persona that withholds it, when…string
scopeHow far the yes went, once…"conversation" | "persona"
when kind is "release"shape
subjectThe gated account or connectorstring
approversWho may release itstring[]
when kind is "environment"shape
toolWhat the steps install, the name…string
stepsThe Dockerfile steps proposed for the…string
approvedHashThe overlay these steps were approved…string
titleThe one line it leads with,…string
whyThe agent's case for it, and…string
statusWhere it stands: open (waiting on…"open" | "working" | "met" | "declined" … (5)
createdAtWhen it was raised, in millisecondsnumber
updatedAtWhen it last moved, in millisecondsnumber
answeredByWho answered it, as the sandbox…string
outcomeHow it ended, in the daemon's…string
toldHow the agent heard the outcome,…"call" | "turn" | "queued"
unattendedRaised by a turn nobody was…boolean
codeA refusal's type, for a script…string
Try itanswered in this tab
curl
curl -X POST "$SANDBOX/needs/ask" \
  -H "x-intentic-control: $INTENTIC_TOKEN" \
  -H "content-type: application/json" \
  -d '{"ask":{"kind":"capability","entry":"…","target":"…","set":{"src/app.ts":"…","README.md":"…"},"reconnect":true},"why":"…","wait":0}'
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.needs.ask({
  "ask": {
    "kind": "capability",
    "entry": "…",
    "target": "…",
    "set": {
      "src/app.ts": "…",
      "README.md": "…"
    },
    "reconnect": true
  },
  "why": "…",
  "wait": 0
});
GET/needs/mineThis conversation's needs

Every need the calling shell's conversation raised, newest first, open or answered.

What you send

Nothing. Call it as it is.

What comes back

FieldType
needsNewest firstobject[]
idThe need's handle, the one `needs…string
conversationIdThe conversation that asked, and the…string
subjectWhat exactly is asked forobject
when kind is "capability"shape
entryThe catalog entry, as the catalog…string
nameWhat the catalog calls it, never…string
modeConnect something new, give a connected…"connect" | "reconnect" | "change"
instanceThe connection a reconnect or a…string
targetThe site, host or address the…string
prefillSettings the agent could fill in…object
changesFor a change: each setting and…object
reasonThe daemon's own sentence on why…string
reportedThe agent reported the credential refused…boolean
when kind is "secret"shape
nameThe name it is stored under,…string
whereHow it will be used: the…string
linkWhere a person gets one, shown…string
hintWhat a valid one looks like,…string
replaceOne is stored under this name…boolean
when kind is "grant"shape
subjectA connected capability the persona leaves…"capability" | "folder" | "shelf" | "site"
whatThe capability's id, the folder, or…string
labelWhat it is, in the daemon's…string
personaThe persona that withholds it, when…string
scopeHow far the yes went, once…"conversation" | "persona"
when kind is "release"shape
subjectThe gated account or connectorstring
approversWho may release itstring[]
when kind is "environment"shape
toolWhat the steps install, the name…string
stepsThe Dockerfile steps proposed for the…string
approvedHashThe overlay these steps were approved…string
titleThe one line it leads with,…string
whyThe agent's case for it, and…string
statusWhere it stands: open (waiting on…"open" | "working" | "met" | "declined" … (5)
createdAtWhen it was raised, in millisecondsnumber
updatedAtWhen it last moved, in millisecondsnumber
answeredByWho answered it, as the sandbox…string
outcomeHow it ended, in the daemon's…string
toldHow the agent heard the outcome,…"call" | "turn" | "queued"
unattendedRaised by a turn nobody was…boolean
Try itanswered in this tab
curl
curl "$SANDBOX/needs/mine" \
  -H "x-intentic-control: $INTENTIC_TOKEN"
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.needs.mine();
POST/needs/{id}/withdrawWithdraw a need

Closes one of this conversation's open needs because the task no longer needs it. Its card says so.

What you send

FieldTypeWhere
idrequiredWhich needstringaddress

What comes back

FieldType
idThe need's handle, the one `needs…string
conversationIdThe conversation that asked, and the…string
subjectWhat exactly is asked forobject
when kind is "capability"shape
entryThe catalog entry, as the catalog…string
nameWhat the catalog calls it, never…string
modeConnect something new, give a connected…"connect" | "reconnect" | "change"
instanceThe connection a reconnect or a…string
targetThe site, host or address the…string
prefillSettings the agent could fill in…object
changesFor a change: each setting and…object
reasonThe daemon's own sentence on why…string
reportedThe agent reported the credential refused…boolean
when kind is "secret"shape
nameThe name it is stored under,…string
whereHow it will be used: the…string
linkWhere a person gets one, shown…string
hintWhat a valid one looks like,…string
replaceOne is stored under this name…boolean
when kind is "grant"shape
subjectA connected capability the persona leaves…"capability" | "folder" | "shelf" | "site"
whatThe capability's id, the folder, or…string
labelWhat it is, in the daemon's…string
personaThe persona that withholds it, when…string
scopeHow far the yes went, once…"conversation" | "persona"
when kind is "release"shape
subjectThe gated account or connectorstring
approversWho may release itstring[]
when kind is "environment"shape
toolWhat the steps install, the name…string
stepsThe Dockerfile steps proposed for the…string
approvedHashThe overlay these steps were approved…string
titleThe one line it leads with,…string
whyThe agent's case for it, and…string
statusWhere it stands: open (waiting on…"open" | "working" | "met" | "declined" … (5)
createdAtWhen it was raised, in millisecondsnumber
updatedAtWhen it last moved, in millisecondsnumber
answeredByWho answered it, as the sandbox…string
outcomeHow it ended, in the daemon's…string
toldHow the agent heard the outcome,…"call" | "turn" | "queued"
unattendedRaised by a turn nobody was…boolean
Try itanswered in this tab
curl
curl -X POST "$SANDBOX/needs/a1b2c3d4/withdraw" \
  -H "x-intentic-control: $INTENTIC_TOKEN"
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.needs.withdraw({
  "id": "a1b2c3d4"
});
GET/needsWhat agents are waiting on people for

Needs across the sandbox, or one conversation's, newest first. Never a secret's value.

What you send

FieldTypeWhere
conversationIdOne conversation's needsstringquery
openOnly the ones still waitingbooleanquery

What comes back

FieldType
needsNewest firstobject[]
idThe need's handle, the one `needs…string
conversationIdThe conversation that asked, and the…string
subjectWhat exactly is asked forobject
when kind is "capability"shape
entryThe catalog entry, as the catalog…string
nameWhat the catalog calls it, never…string
modeConnect something new, give a connected…"connect" | "reconnect" | "change"
instanceThe connection a reconnect or a…string
targetThe site, host or address the…string
prefillSettings the agent could fill in…object
changesFor a change: each setting and…object
reasonThe daemon's own sentence on why…string
reportedThe agent reported the credential refused…boolean
when kind is "secret"shape
nameThe name it is stored under,…string
whereHow it will be used: the…string
linkWhere a person gets one, shown…string
hintWhat a valid one looks like,…string
replaceOne is stored under this name…boolean
when kind is "grant"shape
subjectA connected capability the persona leaves…"capability" | "folder" | "shelf" | "site"
whatThe capability's id, the folder, or…string
labelWhat it is, in the daemon's…string
personaThe persona that withholds it, when…string
scopeHow far the yes went, once…"conversation" | "persona"
when kind is "release"shape
subjectThe gated account or connectorstring
approversWho may release itstring[]
when kind is "environment"shape
toolWhat the steps install, the name…string
stepsThe Dockerfile steps proposed for the…string
approvedHashThe overlay these steps were approved…string
titleThe one line it leads with,…string
whyThe agent's case for it, and…string
statusWhere it stands: open (waiting on…"open" | "working" | "met" | "declined" … (5)
createdAtWhen it was raised, in millisecondsnumber
updatedAtWhen it last moved, in millisecondsnumber
answeredByWho answered it, as the sandbox…string
outcomeHow it ended, in the daemon's…string
toldHow the agent heard the outcome,…"call" | "turn" | "queued"
unattendedRaised by a turn nobody was…boolean
Try itanswered in this tab
curl
curl "$SANDBOX/needs" \
  -H "x-intentic-control: $INTENTIC_TOKEN"
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.needs.list();
POST/needs/{id}/answerAnswer a need

Declines it, or says yes the way its card offered: accept a connection being set up, apply a change, grant for this conversation or the persona, release a gated credential, approve an environment proposal. A release is refused from anyone the gate does not name.

What you send

FieldTypeWhere
idrequiredWhich needstringaddress
answerrequiredobjectbody
when kind is "decline"shapebody
noteWhy not, passed to the agentstringbody
when kind is "accept"shapebody
when kind is "apply"shapebody
when kind is "grant"shapebody
scoperequiredHow far a yes goes: this…"conversation" | "persona"body
when kind is "release"shapebody
when kind is "approve"shapebody

What comes back

FieldType
idThe need's handle, the one `needs…string
conversationIdThe conversation that asked, and the…string
subjectWhat exactly is asked forobject
when kind is "capability"shape
entryThe catalog entry, as the catalog…string
nameWhat the catalog calls it, never…string
modeConnect something new, give a connected…"connect" | "reconnect" | "change"
instanceThe connection a reconnect or a…string
targetThe site, host or address the…string
prefillSettings the agent could fill in…object
changesFor a change: each setting and…object
reasonThe daemon's own sentence on why…string
reportedThe agent reported the credential refused…boolean
when kind is "secret"shape
nameThe name it is stored under,…string
whereHow it will be used: the…string
linkWhere a person gets one, shown…string
hintWhat a valid one looks like,…string
replaceOne is stored under this name…boolean
when kind is "grant"shape
subjectA connected capability the persona leaves…"capability" | "folder" | "shelf" | "site"
whatThe capability's id, the folder, or…string
labelWhat it is, in the daemon's…string
personaThe persona that withholds it, when…string
scopeHow far the yes went, once…"conversation" | "persona"
when kind is "release"shape
subjectThe gated account or connectorstring
approversWho may release itstring[]
when kind is "environment"shape
toolWhat the steps install, the name…string
stepsThe Dockerfile steps proposed for the…string
approvedHashThe overlay these steps were approved…string
titleThe one line it leads with,…string
whyThe agent's case for it, and…string
statusWhere it stands: open (waiting on…"open" | "working" | "met" | "declined" … (5)
createdAtWhen it was raised, in millisecondsnumber
updatedAtWhen it last moved, in millisecondsnumber
answeredByWho answered it, as the sandbox…string
outcomeHow it ended, in the daemon's…string
toldHow the agent heard the outcome,…"call" | "turn" | "queued"
unattendedRaised by a turn nobody was…boolean
Try itanswered in this tab
curl
curl -X POST "$SANDBOX/needs/a1b2c3d4/answer" \
  -H "x-intentic-control: $INTENTIC_TOKEN" \
  -H "content-type: application/json" \
  -d '{"answer":{"kind":"decline","note":"…"}}'
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.needs.answer({
  "id": "a1b2c3d4",
  "answer": {
    "kind": "decline",
    "note": "…"
  }
});
POST/needs/{id}/secretGive a secret a need asked for

Stores the value under the name the need asked for and meets it. The value goes to the sandbox's secret store and nowhere else: not the answer, not the transcript, not a log.

What you send

FieldTypeWhere
idrequiredWhich needstringaddress
valuerequiredThe secret's valuestringbody

What comes back

FieldType
idThe need's handle, the one `needs…string
conversationIdThe conversation that asked, and the…string
subjectWhat exactly is asked forobject
when kind is "capability"shape
entryThe catalog entry, as the catalog…string
nameWhat the catalog calls it, never…string
modeConnect something new, give a connected…"connect" | "reconnect" | "change"
instanceThe connection a reconnect or a…string
targetThe site, host or address the…string
prefillSettings the agent could fill in…object
changesFor a change: each setting and…object
reasonThe daemon's own sentence on why…string
reportedThe agent reported the credential refused…boolean
when kind is "secret"shape
nameThe name it is stored under,…string
whereHow it will be used: the…string
linkWhere a person gets one, shown…string
hintWhat a valid one looks like,…string
replaceOne is stored under this name…boolean
when kind is "grant"shape
subjectA connected capability the persona leaves…"capability" | "folder" | "shelf" | "site"
whatThe capability's id, the folder, or…string
labelWhat it is, in the daemon's…string
personaThe persona that withholds it, when…string
scopeHow far the yes went, once…"conversation" | "persona"
when kind is "release"shape
subjectThe gated account or connectorstring
approversWho may release itstring[]
when kind is "environment"shape
toolWhat the steps install, the name…string
stepsThe Dockerfile steps proposed for the…string
approvedHashThe overlay these steps were approved…string
titleThe one line it leads with,…string
whyThe agent's case for it, and…string
statusWhere it stands: open (waiting on…"open" | "working" | "met" | "declined" … (5)
createdAtWhen it was raised, in millisecondsnumber
updatedAtWhen it last moved, in millisecondsnumber
answeredByWho answered it, as the sandbox…string
outcomeHow it ended, in the daemon's…string
toldHow the agent heard the outcome,…"call" | "turn" | "queued"
unattendedRaised by a turn nobody was…boolean
Try itanswered in this tab
curl
curl -X POST "$SANDBOX/needs/a1b2c3d4/secret" \
  -H "x-intentic-control: $INTENTIC_TOKEN" \
  -H "content-type: application/json" \
  -d '{"value":"…"}'
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.needs.provideSecret({
  "id": "a1b2c3d4",
  "value": "…"
});
GET/needs/grantsThe yeses still standing

What people allowed conversations beyond their persona or area, and the gated credentials released to them, by conversation. Names only, never a value.

What you send

Nothing. Call it as it is.

What comes back

FieldType
conversationsobject[]
conversationIdstring
capabilitiesConnected capabilities allowed although its persona…string[]
foldersWorkspace folders its file tools may…string[]
shelvesShelves of tools opened for it"files" | "shell" | "code" | "web" … (7)[]
installsWhether its own dependency installs run…boolean
secretsSecrets it may send past their…string[]
everythingWhether every request an allow-once could…boolean
byWho last allowed one of thosestring
updatedAtWhen one of those last changed,…number
releasesGated credentials released to it, until…object[]
subjectstring
approvedBystring
atnumber
Try itanswered in this tab
curl
curl "$SANDBOX/needs/grants" \
  -H "x-intentic-control: $INTENTIC_TOKEN"
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.needs.grants();
POST/needs/grants/revokeTake a yes back

Takes back one grant or one release. The conversation's next turn runs without it; a turn already running keeps what it mounted.

What you send

FieldTypeWhere
conversationIdrequiredstringbody
kindrequiredWhich kind of yes: a grant…"capability" | "folder" | "shelf" | "release" … (7)body
whatrequiredThe capability id, folder, shelf, released…stringbody

What comes back

FieldType
okAlways truetrue
Try itanswered in this tab
curl
curl -X POST "$SANDBOX/needs/grants/revoke" \
  -H "x-intentic-control: $INTENTIC_TOKEN" \
  -H "content-type: application/json" \
  -d '{"conversationId":"nightly-changelog","kind":"capability","what":"2026-08-21T09:14:02.000Z"}'
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.needs.revokeGrant({
  "conversationId": "nightly-changelog",
  "kind": "capability",
  "what": "2026-08-21T09:14:02.000Z"
});

Type to search every page, in the docs and the API reference.