Skip to main content

Accounts, people and agents

Everything in Lasso Cloud belongs to an account: its RPC keys, Custom profiles, balance and subscriptions. People and agents act on an account as its members. An agent can create an account on its own, and a person can claim it later without changing a single URL.

The model

Accounts own; members act. An agent belongs to its account, not to the person who approved it, so it keeps working when that person leaves.

Credentials

An RPC key never grants control of its account, so holding one can’t be used to take the account over.

How an account starts

Hand off without changing anything

When an agent built something for a person, it requests a claim link and gives the URL to that person privately:
The link is valid for 24 hours and works once. Requesting another link invalidates the previous one. The person opens it signed in and chooses: Adding to an account:
  • renames a colliding Custom profile (prod-base becomes prod-base-2), while the incoming keys’ URLs keep reaching their own profile;
  • adds the balances together, including negative ones, and keeps the later grace window;
  • moves the keys under the receiving account’s access and shared rate limits, and the receiving account’s existing keys start drawing on the combined balance;
  • keeps the old account ID working, so late payments addressed to it still land;
  • keeps every incoming agent’s token and full authority. The preview names each agent, and an admin can restrict or revoke them afterward.
Someone who manages accounts for several clients chooses Keep as a new account to keep each client separate.

What agents can and can’t do

An agent manages the account’s keys, Custom profiles and its own token, and an unrestricted agent can list the account’s agents and request claim links. An admin can narrow an agent with optional restrictions: Whatever its restrictions, an agent never manages people, creates or approves other agents, or changes Stripe subscriptions. It can’t spend money either: paying needs a wallet signature. An agent can rotate or revoke its own token, and any admin can revoke any agent.

Limits

  • An agent belongs to exactly one account. An agent working for several clients holds one token per client account.
  • An account holds up to 100 active keys and up to 5 Custom profiles. Adding an account can exceed these; you then can’t create more until you’re back within them.
  • Only an unrestricted agent can request a claim link. A link whose agent was revoked or restricted before confirmation claims nothing.
  • If an agent loses its token, the account’s keys keep serving. The agent can start a new account, and Lasso support can recover the old one.

Next