Devices and operator tokens
Review workspace connections and revoke credentials you no longer use.
On this page
Connect a device
Run kastra-edge login or use the desktop login flow. Review the workspace and browser authorization before completing it. Check kastra-edge status afterward. A device connection is separate from installation of an agent’s enforcement hooks.
Review the workspace list
Open Devices in the console. The page separates active devices from operator tokens and scopes the list to the selected workspace. Review the label, issuance, recent activity, and expiry where available.
Administrator coverage views use device-attributed decisions. API-key and server-issued traffic does not carry the same device actor, so an absent device row is not proof that no application traffic occurred. Last-seen information also does not prove that every expected hook is active.
Revoke a retired connection
Select the credential you intend to revoke and review its workspace and identity before confirming. A revoked device must authenticate again to reconnect. Revoking credentials does not uninstall the binary or remove the host’s hook configuration.
Because some clients fail open on unavailable authentication, revocation does not act as an operating-system kill switch. Inspect the integration’s failure behavior and remove access at the appropriate application or infrastructure boundary when required.
Verify coverage
Connect a supported agent and observe a harmless action in Activity. Compare its device identity and environment with the expected connection. Edge setup · Operator token reference.