# Agent Keys and permissions

Give an agent one mailbox, not the whole account.

3 min read. HTML: https://sendwithflare.com/help/agent-keys/

## Least privilege

Settings → Agents & MCP creates an Agent Key. Pick entire workspace, selected domains, or selected mailboxes. New keys start with Read and Draft. Sending is opt-in.

Sending policy is Allow sends, Require human approval, or Read only. A key that requires approval does not deliver mail. FlareMail holds the send until a signed-in person approves it.

Existing `fm_live_` and `fm_test_` keys stay unrestricted and are labeled Legacy unrestricted key. Replace them with a scoped Agent Key when you can. Expired keys fail even if the token still hashes.