Run your first agent
This page takes you from an installed gate to an agent whose risky request waits for a person. You need a gate that is installed and connected, and a rule set with at least one ask rule.
Start the agent
Section titled “Start the agent”Put your Anthropic API key in the gate’s environment, go to your project and start Claude Code in the sandbox:
export ANTHROPIC_API_KEY=…cd ~/projectnoset run --credential ANTHROPIC_API_KEY -- claude--credential keeps the key in the gate. The agent gets a placeholder under the same name, and the gate puts the real key into requests to api.anthropic.com only. See Credentials.
Confirm who you are
Section titled “Confirm who you are”The first noset run of a Linux user on a gate asks a person to confirm who starts the agent:
Confirm that you start agents on gate build-01 as Linux user alice (once per 12 hours): open https://noset.example.com/connect?code=KQRT-WMXZ or go to https://noset.example.com/connect and enter the code KQRT-WMXZwaiting for the confirmation (until 14:05)...Open the link, sign in to Noset if you are not already, and click Confirm. The confirmation lasts 12 hours for that Linux user on that gate. It can only start agents: it cannot approve requests or change rules.
A request waits
Section titled “A request waits”Ask the agent to do something an ask rule covers, for example deleting a customer through your API. The gate holds the request and prints:
ASK DELETE api.example.com/users/12345 (rule finance-delete-customer) waiting for approval rq_… in Noset-
Approvers see the request in the Noset web app under Approvals, and in Slack or Microsoft Teams if your organization set them up. The card shows the action, the rule, who started the agent and, when the agent said so, why it asks.
-
Someone who may approve it approves. Four eyes is on by default: the person who started the agent cannot approve its own requests.
-
The gate sends the request once, and the agent gets the API’s answer.
When nobody decides in time
Section titled “When nobody decides in time”The gate holds a request for 60 seconds. If nobody decides by then, the agent gets 403 with:
Noset: waiting for approval (id rq_…), try again later.The request keeps waiting. When the agent tries the same request again after the approval, it goes through with the approval. A retry while it still waits joins the same request; it does not ask again.
If the request is denied, the agent gets 403 with the approver’s name and reason, and the action does not run.
The evidence
Section titled “The evidence”Every step is recorded: the session (who started the agent, the Linux user, the command), the request with its rule, the approval and the result. Find them under Audit log in the web app; see The noset command for noset verify.
Next: run agents in depth.