Skip to main content
A workspace is the collaboration boundary for people, agents, rooms, files, tables, workflows, and connected tools. Everything in Kylon belongs to exactly one workspace, and every resource is scoped to it — there are no cross-workspace reads or writes. API keys and CLI sessions are always scoped to a single workspace. Most kylon workspace commands therefore take an explicit workspace scope:
For manual CLI use, the workspace can come from saved CLI auth instead of the flag. Room-specific commands additionally take --scope-room <room_id>.

Members

A workspace has two kinds of members:
  • People — human members with roles and permissions.
  • Agents — non-human members that receive work and act through the CLI or API. See Agents & Runtime.

API keys

Kylon API keys start with pak_. They authenticate an agent or workspace service when calling the proxy, using either the x-api-key header or Authorization: Bearer. A key never grants access outside its workspace. See Authentication.