Credentials & Roles#
Open Config → Credentials & Roles to onboard users and manage provider access, team assignments, usage limits, MCP server access, and context compression.

Use Config → Teams to create teams and configure shared settings for their members.
Register provider connections under Config → Providers before assigning provider access.
Users#
Open Config → Credentials & Roles to view and manage organization users.
From this page, manage:
- Invitations
- Usage limits
- Team assignments
- Allowed providers
- MCP server access
- Context compression
- User settings
Click a user to view their details and configuration.
If a user has accepted an invitation but is not displayed in the list, click Refresh in the page header to reload the table data.
Teams#
Open Config → Teams to create groups and apply shared settings to their members, including usage limits and context compression.

After creating a team, assign users to it from Config → Credentials & Roles.
User onboarding workflow#
To onboard a user:
2. Configure access and settings After the user accepts the invitation, configure one or more of the following settings:
- Set usage limits.
- Assign the user to a team.
- Configure allowed providers.
- Grant access to MCP servers.
- Enable or disable context compression, as needed.
3. Verify access - Ask the user to sign in. - Confirm that the expected providers and tools are available.
Manage invitations#
Open Config → Credentials & Roles and click + INVITES to monitor invitations that have not yet been accepted.

The page shows the number of Pending invitations, the list of invited users, invitation details, and actions such as Resend.
For information about roles and invitation restrictions, see Access principles.
Invite users#
To invite new users to the organization:
- Open Config → Credentials & Roles and click + INVITES to open Invite Management.
- Click + INVITE.
-
On the Invite Users page, enter the email addresses and select a role.
- Email — Enter one or more email addresses.
- Add role — Select a role.
-
Click Invite.
The new invitation appears in the Invite Management table with Sent and Expires timestamps. After the user accepts, they appear on the main Credentials & Roles user list. Configure any remaining access and settings as needed, including usage limits, team assignment, and allowed providers.
Resend an invitation#
If a user did not receive or has lost their invitation email, resend the invitation.
- Open Config → Credentials & Roles and click + INVITES.
- Locate the user in the invitation list.
- In the Actions column, click Resend.
A new invitation email is sent to the user.
Export user data#
On Config → Credentials & Roles, click DOWNLOAD and choose an export format:
- XLSX spreadsheet — Download the user list as an Excel-compatible file for reporting or offline review.
- JSON file — Download the same data as JSON for automation, backups, or integration with other tools.
The export reflects the users currently visible in the table (respecting any active Search filter).
Configure limits#
Usage limits control maximum spend, token usage, and request count for users and teams.
Limits can be configured from Config → Credentials & Roles for users and Config → Teams for teams.
For newly added users, the Limits column is empty until an administrator configures at least one limit.
To configure limits:
1. Open Config → Credentials & Roles for a user, or Config → Teams for a team, and locate the Limits column (use Search if needed).
2. In the Limits column, click the
pencil icon.
3. In the Edit limits dialog, configure one or more of the following limits:
- Budget — Specifies the maximum spending limit and its reset interval.
- Tokens — Specifies the maximum number of tokens allowed during each reset period and the reset interval.
- Requests — Specifies the maximum number of API requests allowed during each reset period and the reset interval.
4. Click SAVE to apply the changes, or CANCEL to discard them.
5. Optional: Click CLEAR LIMITS to remove all configured limits for the selected user or team.
After the limits are saved, the Limits column displays the configured limits, reset intervals, and current usage.
Assign a user to a team#
The Team column assigns users to teams so shared team settings can be applied. For newly added users, the column displays Unassigned (-) until a team is assigned.
-
Open Config → Credentials & Roles and locate the user (use Search if needed).
-
In the Team column, click the
pencil icon. -
In the Assign team dialog, select a team from the Team drop-down list, or select Unassigned to remove the user from a team.
-
Click SAVE to apply the assignment, or CANCEL to discard your changes.
After the assignment is saved, the Team column displays the selected team. To change or remove the assignment, click the
pencil icon again and select a different team or Unassigned.
Before assigning users, create and configure teams on Config → Teams.
Allowed providers#
Allowed providers determine which configured provider connections are available to a user.
Configure provider access after adding a provider, when onboarding a user, or when troubleshooting a provider that does not appear in Chat.
Configure allowed providers#
- Open Config → Credentials & Roles and find the user row (use Search if needed).
- In the Allowed providers column, click the edit control for the user.
- Select one or more Active providers.
- Click SAVE.
Provider access can be assigned when the provider is created or later through Allowed providers. If Assign to new users automatically is enabled for a provider, that provider is automatically assigned to new users.
During initial setup, this step follows Add first provider in First Steps.
Chat shows only Active providers that the signed-in user is allowed to access.
Context compression#
Context compression reduces the amount of context sent with AI requests to help lower token usage and inference costs.
Configure it from:
- Config → Credentials & Roles for users.
- Config → Teams for teams.
- Config → Agents for agents.
Configure context compression#
- Open Config → Credentials & Roles for a user, Config → Teams for a team, or Config → Agents for an agent.
- Locate the required entry.
- Use Enable context compression to turn the setting on or off.
The change applies immediately; no separate save action is required.
To review savings from compression and other optimizations, see Analytics → Optimizations.