ak_ntl_*) is a credential bound to one Agent. A request made with it is that agent. Give it to an agent runtime; it carries the same verified binding as an agent-scoped MCP OAuth grant.
An API key is the party-wide counterpart: it can attribute a call to an agent, but it isn’t one. An agent key is scoped to its agent, nothing else.
Agent keys
Overview
Credentials bound to a single agent
An agent key (