# Multiple agent tokens per org (with agent queue restrictions)

**URL:** <https://forum.buildkite.community/t/multiple-agent-tokens-per-org-with-agent-queue-restrictions/143>\
**Category:** Features Requests\
**Created:** [December 7, 2018, 4:16am UTC](https://forum.buildkite.community/t/multiple-agent-tokens-per-org-with-agent-queue-restrictions/143 "2018-12-07T04:16:30Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![moensch](https://sea2.discourse-cdn.com/flex016/user_avatar/forum.buildkite.community/moensch/32/33_2.png) [@moensch](https://forum.buildkite.community/u/moensch)\
**Post date:** [December 7, 2018, 4:16am UTC](https://forum.buildkite.community/t/multiple-agent-tokens-per-org-with-agent-queue-restrictions/143/1 "2018-12-07T04:16:30Z")

</div>

Hey all

I am currently thinking about a model where I would enable individual teams at the org to run their own buildkite agents. This would mean I’d have to hand out the one-and-only agent token I have for my org.

In order to limit blast radius if this gets compromised, it would be nice if I could have more than one agent token so one team’s sloppy handling of their token wouldn’t ruin the day for everyone else.

Now, following on from that thought: It would be _really_ cool if I could tie each one of these new agent tokens to queues, or somehow restrict them. I wouldn’t want to have a situation where some team at the org is spinning up an agent, but accidentally putting them onto the `default` queue. I’d want them to “stay in their lane” so to speak - only have a queue name for themselves so they don’t accidentally hijack some other team’s build jobs.

To summarize:

- Multiple tokens per org
- Some token-to-agent-queue restriction (agent with token X can only be assigned to queue Y)

Is something like this even remotely on the roadmap? Or of interest to others?

---

<div class="post-metadata">

**Author:** ![bresmith](https://sea2.discourse-cdn.com/flex016/user_avatar/forum.buildkite.community/bresmith/32/422_2.png) [@bresmith](https://forum.buildkite.community/u/bresmith)\
**Post date:** [January 9, 2019, 6:11pm UTC](https://forum.buildkite.community/t/multiple-agent-tokens-per-org-with-agent-queue-restrictions/143/2 "2019-01-09T18:11:30Z")

</div>

This is of use to us as well, is there any word on this?

---

<div class="post-metadata">

**Author:** ![anon18197598](https://avatars.discourse-cdn.com/v4/letter/a/9d8465/32.png) [@anon18197598](https://forum.buildkite.community/u/anon18197598)\
**Post date:** [January 10, 2019, 12:47am UTC](https://forum.buildkite.community/t/multiple-agent-tokens-per-org-with-agent-queue-restrictions/143/3 "2019-01-10T00:47:57Z")

</div>

Hey folks! In the immediate short-term, you can absolutely create multiple Agent Registration Tokens through the GraphQL API:

```auto
mutation CreateAgentToken {
  agentTokenCreate(input: {
    organizationID: "T3JnYW5pemF0aW9uLS0tYTk4OTYxYjctYWRjMS00MWFhLTg3MjYtY2ZiMmM0NmU0MmUw",
    description: "My New Agent Registration Token"
  }) {
    agentTokenEdge {
      node {
        id
        description
        token
      }
    }
  }
}

```

[https://buildkite.com/user/graphql/console/7086a9e9-93dd-4349-842e-6b31b583342b](https://buildkite.com/user/graphql/console/7086a9e9-93dd-4349-842e-6b31b583342b)

You can find your organization id at the bottom of your organization settings page.

In the longer term, we have big plans to add ways to restrict Agents, Pipelines and Teams into locked down Clusters. Will post elsewhere on that and link back here.

---

<div class="post-metadata">

**Author:** ![anon18197598](https://avatars.discourse-cdn.com/v4/letter/a/9d8465/32.png) [@anon18197598](https://forum.buildkite.community/u/anon18197598)\
**Post date:** [January 10, 2019, 5:01am UTC](https://forum.buildkite.community/t/multiple-agent-tokens-per-org-with-agent-queue-restrictions/143/4 "2019-01-10T05:01:08Z")

</div>

I explained a bit more about what we have planned for the constraints you mentioned: [Restricting access to agents](https://forum.buildkite.community/t/restricting-access-to-agents/200)

---

<div class="post-metadata">

**Author:** ![bresmith](https://sea2.discourse-cdn.com/flex016/user_avatar/forum.buildkite.community/bresmith/32/422_2.png) [@bresmith](https://forum.buildkite.community/u/bresmith)\
**Post date:** [January 10, 2019, 9:23pm UTC](https://forum.buildkite.community/t/multiple-agent-tokens-per-org-with-agent-queue-restrictions/143/5 "2019-01-10T21:23:50Z")

</div>

awesome, thank you Lachlan! We’ll give this a shot

---

<div class="post-metadata">

**Author:** ![thirtytwobits](https://sea2.discourse-cdn.com/flex016/user_avatar/forum.buildkite.community/thirtytwobits/32/542_2.png) [@thirtytwobits](https://forum.buildkite.community/u/thirtytwobits)\
**Post date:** [May 31, 2019, 6:37am UTC](https://forum.buildkite.community/t/multiple-agent-tokens-per-org-with-agent-queue-restrictions/143/6 "2019-05-31T06:37:39Z")

</div>

Buildkite has so much more functionality then is documented. I really hope you get time to significantly beef up your documentation.
