DocumentationAdministration

Devices and operator tokens

Review workspace connections and revoke credentials you no longer use.

Updated 2026-09-22 Read as Markdown
On this page

Connect a device

Run kastra-edge login or use the desktop login flow. Review the workspace and browser authorization before completing it. Check kastra-edge status afterward. A device connection is separate from installation of an agent’s enforcement hooks.

Review the workspace list

Open Devices in the console. The page separates active devices from operator tokens and scopes the list to the selected workspace. Review the label, issuance, recent activity, and expiry where available.

Administrator coverage views use device-attributed decisions. API-key and server-issued traffic does not carry the same device actor, so an absent device row is not proof that no application traffic occurred. Last-seen information also does not prove that every expected hook is active.

Revoke a retired connection

Select the credential you intend to revoke and review its workspace and identity before confirming. A revoked device must authenticate again to reconnect. Revoking credentials does not uninstall the binary or remove the host’s hook configuration.

Because some clients fail open on unavailable authentication, revocation does not act as an operating-system kill switch. Inspect the integration’s failure behavior and remove access at the appropriate application or infrastructure boundary when required.

Verify coverage

Connect a supported agent and observe a harmless action in Activity. Compare its device identity and environment with the expected connection. Edge setup · Operator token reference.