Use Vantage
Manage agent access
See what agents accessed, revoke permission and manage installation keys.
How access works
Open Agent access to manage each agent’s permissions and Activity to inspect its reads. You can revoke one grant, one agent’s access or all agents’ access.
Vantage keeps an agent’s identity separate from permission to read your accounts:
| Item | What it does | Lifetime |
|---|---|---|
| Installation key | Identifies the agent when it calls Vantage. | Registration keys last 90 days. Manually issued keys can last up to 90 days. |
| Approval link | Lets you review a pending access request. | One use, 15 minutes. |
| Transaction grant | Allows the agent to read selected accounts. | One hour by default; one minute to twelve hours. Renewal requires approval. |
You can have several agents, and each agent can have several independent grants. Reading requires both a valid installation key and an active grant. Revoking one grant leaves the others active.
Review activity
Open Activity to see each agent’s name, access time, action and result. Transaction reads show the number of records returned and the accounts involved. Expand Access details for requested and returned accounts, date ranges, IDs and the grant’s history.
Select Load earlier activity to see older records. With MCP, follow nextBeforeSeq; with CLI, pass --before-seq. Keep the same grant filter when loading another page.
Activity records API requests through Vantage. CLI and MCP labels are supplied by the caller.
Revoke access
| Action in Agent access | Result |
|---|---|
| Revoke a grant | Stops reads through that grant, including reads using an existing cursor. Other grants stay active. |
| Revoke one agent’s access | Cancels that agent’s grants and pending requests. Other agents keep access. |
| Revoke all agent access | Cancels all your agents’ grants and pending requests. |
Revocation stops future reads through the revoked access. Your bank accounts stay connected, and installation keys remain valid so an agent can ask again. Regaining access requires your approval.
If cleanup is pending, access has already stopped. Retry cleanup to finish removing the read snapshot.
Previously shared transactions remain with the agent after revocation.
Disable a key
To stop an installation key from authenticating, open the agent’s advanced installation and key details in Agent access, then disable the key. Other keys and grants remain active.
A manually created key is displayed once. Store it privately in the intended runtime. Issue a replacement if you lose it.
Updated October 4, 2026