#315

Scoped authorization tokens to prevent agent risk

In Progress
April 2026

Currently, your dev environment (npx convex dev) always acts "as you" when you're operating in an authenticated convex with your convex cloud accounts. That means, however, that if you're a project administrator, you can push prod.

This is a problem when agents "helpfully" decide to run npx convex deploy for you before you're ready.

The ability to limit the power of development keys to narrower scopes than the full power of the user is important for agentic engineering.

Development Updates

No updates yet

Total backing

70

from 2 supporters

Back this request

Sign in to back this feature request with Convex Chips and help prioritize it.

Sign in to vote