> For clean Markdown content of this page, append .md to this URL. For the complete documentation index, see https://docs.postnuvia.com/llms.txt.

## Summary

The two API key permissions behind AgentID sign-in now use the app noun: `provider_connect` is `app_connect`, and `provider_share_owner` is `app_share_owner`. Existing keys keep their grants. The old names are removed: requests that send them get a `400`, and responses return only the new names.

### What's new?

* **`app_connect`**: sign in to apps as an inbox: connect an app, authorize an inbox, and mint sign-in keys. Same meaning and default as `provider_connect`.
* **`app_share_owner`**: share the organization owner's name and email with apps at sign-in. Same meaning as `provider_share_owner`.
* **New names in requests**: `POST /v0/api-keys`, `POST /v0/pods/{pod_id}/api-keys`, `POST /v0/inboxes/{inbox_id}/api-keys`, and `PATCH /v0/api-keys/{api_key_id}` accept only `app_connect` and `app_share_owner`.
* **New names in responses**: API key responses return only `app_connect` and `app_share_owner`.
* **Error text**: a `403` with `code: "missing_permission"` names the new permission in its `fix`, for example `app_connect`. Branch on `code`, not on the text.

### Breaking changes

⚠️ **New SDK and CLI releases expose only the new names.** The SDK and CLI releases that follow this change drop `provider_connect` and `provider_share_owner` from `ApiKeyPermissions` (TypeScript: `providerConnect` and `providerShareOwner`). Switch the field names when you upgrade:

* **TypeScript**: `providerConnect` is a type error. In untyped JavaScript the SDK drops fields it does not know before sending, so a key created with `providerConnect: true` would not get the permission.
* **CLI**: `--permissions` is checked locally, so `provider_connect` fails as an unknown property.

Earlier releases know only the former names: earlier SDKs drop `appConnect` the same way, and earlier CLIs reject `app_connect`.

⚠️ **The API rejects the former names.** A create or update that sends `provider_connect` or `provider_share_owner` returns a `400` `ValidationError` at that field, for example `'provider_connect' was renamed to 'app_connect'`, instead of creating a key without the permission. Responses no longer include the former names. There is no deprecation window, so TypeScript SDK 0.5.32, Python SDK 2.0.6, CLI 1.7.0, and earlier releases cannot set or read these permissions; upgrade first.

**`Python`**

```python title="Python"
from postnuvia import PostNuvia

client = PostNuvia(api_key="YOUR_API_KEY")

# before: permissions={"inbox_read": True, "provider_connect": True}
key = client.api_keys.create(
    name="sign-in agent",
    permissions={"inbox_read": True, "app_connect": True},
)
print(key.api_key_id)
```

**`TypeScript`**

```typescript title="TypeScript"
import { PostNuviaClient } from "postnuvia";

const client = new PostNuviaClient({ apiKey: "YOUR_API_KEY" });

// before: permissions: { inboxRead: true, providerConnect: true }
const key = await client.apiKeys.create({
  name: "sign-in agent",
  permissions: { inboxRead: true, appConnect: true },
});
console.log(key.apiKeyId);
```

### Use cases

Build agents that:

* Hold a key that signs in to apps with `app_connect` alone, without `api_key_create`
* Share the owner's name and email with an app only from keys granted `app_share_owner`

> **Note**
>
> See [Permissions](https://docs.postnuvia.com/permissions) for every API key permission.