For AI agents setting up spacesheep

Settings is one MCP call — do it yourself

When someone asks you to set up spacesheep — a key, the AI model, a team, their profile, backups, Telegram — use the calls below. Send them to a page only for the three things that need a browser.

17You do it over MCPkeys, the model, config groups, email lists, teams, MCP servers, profile, who opens new pages, API keys, backups, Telegram, codes
3Needs them in a browserconnecting accounts, paying, passwords
0Not on MCP yetevery setting has a call

Do it yourself, over MCP

Save an integration's key
set_secret { name, value }
Names: GITHUB_TOKEN LINEAR_API_KEY GRANOLA_API_KEY PERPLEXITY_API_KEY TAVILY_API_KEY YDC_API_KEY SOLID_WORKSPACE_API_TOKEN MIXPANEL_API_SECRET APIFY_API_KEY INSTAGRAM_ACCESS_TOKEN. list_secrets shows names, never values; delete_secret removes one.
Pick the AI model their agent runs on
set_secret for LLM_PROVIDER, LLM_MODEL and the provider's key
Providers: anthropic openai google xai moonshot deepseek nvidia azure. Keys: ANTHROPIC_API_KEY OPENAI_API_KEY GEMINI_API_KEY XAI_API_KEY MOONSHOT_API_KEY DEEPSEEK_API_KEY NVIDIA_API_KEY, or AZURE_OPENAI_API_KEY with AZURE_OPENAI_ENDPOINT. Optional roles, as bare model ids: LLM_FAST_MODEL LLM_PREMIUM_MODEL.
Share keys with other people
config_group { action }
Actions: list create add_member remove_member set_starter copy_key set_key_use leave delete. A group's own keys: set_secret { scope: "group", group }. The starter group is the Starter config new people get.
See their teams
list_teams
Each team's people and roles, plan and seats, default team, email domains, Slack.
Change a team
manage_team { action, team, name, who, role }
Actions: create rename add remove leave set_role make_default. team is its name; leave it out for their default team. who is an @username or an email. Only the team's Team admins (role owner) can change it, except leave and make_default.
Put someone on a team and email them
invite_to_org { org, email }
Or username instead of email. On a Team they're added at once, account or not; the plan's seats are honoured. Team admins only.
Let everyone at a company domain join a team
set_team_domains { team, domains }
Needs a Team or Enterprise plan. Public mail services (gmail.com…) are refused. Leave out domains to read the current rule.
Turn "Talk to your sessions" on or off
talk_settings { enabled }
Pro and Team only. Turning it off also ends every listening session's link.
Their name, photo, @username, and who can open their new pages
account { action }
Actions: get set_name set_username set_photo remove_photo set_new_page_access. The username is picked once — confirm the spelling first. A photo is photo_key (one of theirs, from my_photos) or photo_url. set_new_page_access { new_page_access } is who can open a page they publish without naming an audience: private (the default), signed_in, or public — anyone with the link, unlisted. It never re-tiers a live page; share_space does that.
API keys: list, create, revoke
api_keys { action, name | key }
create returns the key once — hand it straight to the machine or CI that needs it. It works only from a client that itself signed in with one of their keys; a connected app (OAuth) can't mint keys. revoke takes the id or the ss_ prefix.
Daily backups: on, off, the hour, back up now
backups { action, enabled, hour_utc }
Actions: status set run_now disconnect. Pro. Connecting Google Drive itself is a consent screen — browser (below).
Linking Telegram
channels { channel: "telegram", action: "link" }
Gives a one-time code: they send /start CODE to the bot or open the t.me link — no browser. status shows Telegram and Slack; unlink ends a link and its key. Slack is connected per team by a Team admin (browser, below), not per person.
Disconnecting Google Calendar, Zoom or Linear
integrations { action: "disconnect", provider }
status lists connected accounts and pasted keys. Providers: google zoom linear. Drive is backups { action: "disconnect" }.
Connect another MCP server to their agent
mcp_servers { action, url, team }
Actions: list add remove. add checks the server's address (e.g. https://api.ycombinator.com/v1/mcp) and answers a link to Settings with the form filled in — send it; they press Connect, and sign in to the server if it asks. Nothing connects until they do. team connects it for everyone on a team they run. Once connected, their agent uses it through fetch_integration (integration mcp:<name>).
Accepting a config-group invitation
config_group { action: "accept", group }
list shows offers waiting on them under invited_to; decline is the other answer.
Redeeming a Pro or Team code
redeem_code { code, org? }
A Pro code applies to them. A Team code needs org = the slug of a team they own; a new team from a code is the Team page.
Lists of email addresses to share a space with
groups { action, group, emails, space }
Actions: list show create add remove rename delete share unshare. Pass emails as the person gave them — lines, commas, a CSV row. Everyone on a group can view a space shared with it once signed in with that address; nobody on it can edit, and nobody is emailed, so send them the link. Same as Settings → Groups.

Secret values are write-only: you can set LLM_MODEL, but not read back which model was set. Say what you set; don't claim what was there before.

These need the person, in a browser — give the link and stop

Connecting an accountGoogle Calendar, Zoom, Linear, and pressing Connect on an MCP server: Settings → Integrations. Drive backups: Settings → Backups. Slack for a team: Settings → Team.
A passwordNever type one for them: Settings → Account.