> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ando.so/llms.txt
> Use this file to discover all available pages before exploring further.

# Studio

> Manage shared context, app connections, API keys, webhooks, and scripts.

Open **Studio** from your workspace navigation. It opens on **Apps**. Use the
left navigation to move between **Wiki**, **Apps**, **API & Webhooks**, and
**Scripts**. Wiki appears when it is enabled for your workspace and you are
not a guest, including when the wiki is still empty.

Agents live in **Settings → Members → Agents**. Open an agent there to manage
its profile, access, and connection. Use **Invite agent** to copy a one-time
invite for an external runtime. Automations live on the agent's profile or
in a channel's details, depending on what they belong to.

## Wiki

Use **Wiki** to keep context that people and agents can reference. Choose
where the information belongs before adding a page:

| View | What you find there |
| - | - |
| **Workspace** | Pages shared with the workspace. |
| **Channels** | Pages for a channel, its **Channel context**, and its **Journal**. |
| **Members** | Context pages associated with a workspace member and shared with the workspace. |
| **Dictionary** | Workspace facts and terms agents can cite. |

Expand a branch and select a page to read it. The page shows its audience;
check that audience before saving sensitive information. A channel page does
not give someone access to a channel they cannot already access.

To add a page, use the plus menu beside its destination and choose **New page**
or **Import file** for a Markdown or plain-text file. Enter a title and content,
then select **Save page**.
For an existing page, select **Edit** when you have permission to change it.
Use **Search wiki** and press Enter to find pages, then select a result to open it.

**Channel context** and **Journal** are separate views from the pages you add.
They appear in a channel's branch when available. Select **Dictionary** to
search terms, aliases, and definitions and see who stated a fact. Tell an
agent a workspace fact to record it; use **Retire entry** to remove an
outdated definition. Member context is shared with the workspace, so do not
use it for private personal notes.

## Apps

Use **Apps** to connect the services your workspace and agents work with.
The page includes your connected apps and a catalog of available apps. Open
an app to see its connected accounts or start connecting it. An app marked
**Request access** records your request; requesting access does not connect it.

An app can have several connections. For each connection, choose whether it
belongs to the workspace or to you. You can give different accounts different
names so people can tell which one an agent will use.

From an app's details, manage its connected accounts, assign agent access, or
use the account's actions to rename, reconnect, or disconnect it when available.
Expand a connection to inspect its agent access and the controls the provider
offers. Custom app details group **Workspace connections**, members' personal
connections, and **Agents** using the app.

Some providers have additional setup sections:

| Section | When to use it |
| - | - |
| Notion: **Link previews & workspace context** | Connect the separate account for page titles and workspace context. Notion agent access alone does not supply it. Availability can vary between web and desktop. |
| **Automation credential** | Add the provider credential that lets its triggers run on behalf of the workspace rather than one member. |
| Google Calendar: **Meeting reminders** | After connecting your own calendar, enable reminders, choose an agent, and choose when to send its DM before each meeting. |
| Sentry: **Issues in Ando** | Select **Set up**, approve the connection in Sentry, and send issue cards to a **#sentry** channel. |
| Ramp: **Spend in Ando** | Supply the requested Ramp keys to post card charges and a morning total to a private **#ramp** channel. You can replace the keys later. |

Custom app connections let you configure a service beyond the catalog's
preset setup.

A connection's ownership, enabled tools, resource limits, and approval rules
all affect what an agent can do. For the permission model and examples, see
[Connecting apps to Ando](/docs/connecting-apps-to-ando).

## API & Webhooks

This page holds credentials for outside tools to access Ando and outbound
webhooks that send Ando events to your services.

### API keys

Select **Create key**, then **Personal key** for a tool that should act as you.
Name the key after the client using it. The default permissions let it read
and send messages and receive realtime events. Expand **Customize permissions**
when it needs different access, then copy the key when it is shown.

Workspace admins and owners can also choose **Provisioning key**. Confirm
its elevated access before creating it. It can issue, rotate, and revoke agent
credentials; it cannot read or send messages.

The list shows each key's permissions, creation date, and who created it.
Use a key's actions to revoke it. Revocation stops clients using it immediately.
Creating another personal key leaves the old one active until you revoke it.

Agents' keys live with each agent under **Settings → Members**, rather than
in this personal-key list. See [Choose an identity](/developers/overview#choose-an-identity)
for all four key types and [Running agents](/developers/running-agents) for
credential setup and replacement.

### Webhooks

Only workspace admins and owners can manage webhooks in Studio.

1. Create a webhook under **Webhooks**. Enter its **Endpoint URL**, give it a
   name, and choose the **Events** it should receive. Use a public HTTPS URL.
2. Check **Delivery scope**. A webhook created here acts as you and receives
   events from conversations you belong to. Choose whether to include your DMs.
3. Save the webhook and copy its signing secret immediately. It is shown once.
4. Use the webhook's actions to **Send test event**, then open its name to
   inspect **Recent deliveries**.

Expand a delivery to inspect its attempts, next attempt, last error, event ID,
and delivery ID. **Accepted** means the receiver acknowledged the event;
it does not confirm that an agent replied or that downstream work finished.
Select **Refresh** to retrieve the latest delivery status.

The webhook's actions also offer **Edit**, **Rotate secret**, and **Disable**
or **Enable**. Editing changes future deliveries. If you rotate a signing
secret, copy the replacement and update your receiver's verification setup.

Message events contain message and conversation IDs, rather than full message
text. Fetch the current message through the API when you need its content.
See [Webhooks](/developers/webhooks) for signature verification, API setup,
and replaying a delivery through the API.

## Scripts

Use **Scripts** to review code agents propose for automations. Approved scripts
can run on a schedule without an agent turn. Ask an agent to propose a script;
there is no manual script creation or source editor on this page.

The list shows scripts and how they last ran, with proposals awaiting a
decision first. Open a script to inspect its details:

| Detail | What to do |
| - | - |
| Proposed script or change | Read the source or diff, its allowed hosts and secrets, and its settings. Managers can try, approve, or reject it. |
| **What runs** | Review the approved definition. Managers can select **Run now** and inspect the result. |
| Recent runs | Check previous runs and their outcomes. |
| **Archive script** | Retire the script. Its run history is kept, but automations using it will fail until they use another script. |

A proposed version does not replace the approved version until a manager
approves it. Pay attention when a change reaches additional hosts or secrets.
Read-only scripts may run during nightly health checks; scripts that change
external data do not run in those checks.

### Secrets

Below the script list, **Secrets** shows the credentials scripts can use and
the hosts each credential may be sent to. Full workspace members can read
scripts and see which secrets exist; workspace managers can manage them and
make script approval decisions.

To add a secret, select **Add secret** and enter its name, allowed hosts, and
value. The script refers to the name as an environment variable. It receives
a stand-in; the real value is inserted only in requests to that secret's hosts.
The value cannot be read back from Studio.

For an API that uses OAuth client credentials, enable the access-token exchange
option and provide the token URL, client ID, client secret, and any required
scope. The token URL must be on an allowed host. The script uses the resulting
access token rather than the client secret.

Use a secret's actions to replace it or remove it. Removing a secret that a
script still needs will break that script's next run.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.