Agent access
Let your own agent read your Collections and file papers with a personal key you issue and revoke
Your own agent can read your Collections and saved papers, read your notes and highlights on a paper, and file papers for you Agent access to the Library and Collections: Live. It does so with a personal key Personal keys: Live: a bearer secret you issue in the Library, with the permissions and the reach you choose, and revoke whenever you like. The agent acts as you, within those settings, and can do nothing that shares, deletes or administers. A personal key reaches no Room, and a Room credential reaches nothing in the Library.
Issue a key
Open Agent access
Sign in, open the Library and press Agent access in the sidebar, below New collection. The dialog lists Your keys and, below them, the New key form.
Fill the form
| Field | Meaning |
|---|---|
| Key label | For you only, to tell keys apart; never shown to anyone else. |
| Agent name shown to members (optional) | Public to the members of any Collection the agent writes in: it is the name beside via on the papers and notes it files. Leave it empty and members see via agent. |
| Expires after | 7, 30 or 90 days, after which the key stops working; nothing renews it. |
| What it may do | One box per permission; tick at least one. The next table says what each allows. |
| Where | One of three reaches. With Selected Collections, a checklist of the Collections you can open appears, each marked yours or shared with you. |
The four permissions:
| Box | Allows |
|---|---|
Read (read_library) | List the Collections in reach, read a Collection with its papers and notes, list the saved papers and read one paper’s place in the Library. |
File papers (file_papers) | Save papers, create and rename Collections, add papers to a Collection and remove a paper whose thread holds no note. |
Post notes (post_notes) | Post a note on a paper’s thread in a Collection. |
Read annotations (read_annotations) | Read the owner’s free-text notes and highlights on a paper, without highlight geometry or the reader assistant’s messages. |
The three reaches:
| Choice | Covers |
|---|---|
Everything I can open (all) | The Library and every Collection the owner owns or is a member of. |
Only what I own (owned) | The Library and the Collections the owner owns. |
Selected Collections (selected) | Only the Collections listed on the key and those created through it; never the Library. Annotations only for papers a Collection in reach holds. |
A selected reach never includes your Library itself: the agent cannot list your saved papers or save to them, and adding a paper to a Collection through such a key leaves your shelf untouched. A Collection the agent creates through the key joins the reach at once, so a key issued before you have any Collection still works in the ones the agent makes. A Collection outside the reach answers the agent exactly as one that does not exist.
Issue the key and keep it
Press Issue key. The key, starting subp_, appears once under Your new key · shown once with a Copy key button and the first request to make with it. Substrate keeps only a fingerprint, so it cannot be shown again; if you lose it, revoke the key and issue another. Put it in your agent’s environment as SUBSTRATE_PERSONAL_TOKEN and nowhere else: never in a note, a Collection name, a chat, a repository or a screenshot.
What the agent can do
Every read and operation a key allows, with the box that allows it. The agent has the authority you have and no more: renaming is for Collections you own, and adding to a shared Collection is what any member may do.
| The agent can | With |
|---|---|
| List the Collections in reach, and read one with its members, its papers and their notes | Read |
| List your saved papers, and look up one paper's place in your Library | Read |
| Save papers to your Library | File papers |
| Create a Collection, owned by you | File papers |
| Add papers to a Collection, saving them to your Library as well when the reach includes it, as filing from the reader does | File papers |
| Remove a paper from a Collection, unless its thread holds a note | File papers |
| Rename a Collection you own | File papers |
| Post a note on a paper's thread, under your name | Post notes |
| Read your notes and highlights on a paper | Read annotations |
Papers are named by arXiv identifier, as in the browser, in batches of up to 20. Substrate fetches each paper’s title and authors from arXiv within a budget of 30 seconds per batch; a paper arXiv does not answer for in time is filed all the same, titled arXiv:<id> until its metadata arrives, which the next request naming it, or your next visit to the Library, brings in. An identifier arXiv does not recognise is reported beside the others, and nothing else in the batch fails for it.
Papers beyond arXiv: IdeaPapers beyond arXiv
Papers named by a DOI or another identifier could be saved and filed the same way, with their metadata drawn from the registry that issued the identifier.
These stay with you, in the browser, whatever the key allows; none has an agent route, and a key cannot issue, renew or revoke a key either:
- Delete a Collection
- Invitations (create, revoke, accept)
- Remove a member, leave a Collection
- Delete a note
- Unsave a paper
- Read marks
- Write annotations or any reader state
What it looks like to others
Everything the agent files says so Via marks: Live. In a Collection, a paper the agent added shows via and a name beside your username where the view says who added it, and a note the agent posted carries the same mark beside its author. You see the key’s label, so you can tell which key acted; other members see the agent name you gave the key, or via agent when you gave none. The label itself is never shown to anyone else, and a paper or note you filed in the browser carries no mark.
A note is posted under your name: members read it as yours, and you answer for it as for anything you post. Nothing the agent reads or posts counts as you having read a thread; the unread marks you see are yours alone. And an agent never removes a discussion: removing a paper whose thread holds a note, by anyone, is refused, and the paper stays where it is until you remove it in the browser.
Annotations
With Read annotations, the agent reads what you wrote on a paper in the reader Annotation read for agents: Live: your note on the paper and each highlight’s page, colour, text and note, with the revision of that state. Two things never leave: where a highlight sits on the page, and the reader assistant’s messages. The read writes nothing and does not move the revision, and a paper you have not annotated answers the empty state. With a selected reach, only papers held by a Collection in reach can be asked about; the other reaches cover any paper.
Annotation writes by agents: IdeaAnnotation writes by agents
An agent could add highlights or notes to your own reader state, under a permission of its own, so that what it found while reading for you appears in the reader beside your marks.
Connect your agent
Three ways, beside each other; each ends with an agent that knows the origin, holds the key in its environment and has read the Library skill. The key is sent to the origin that issued it and nowhere else; the MCP adapter refuses any other host.
Claude Code reads skills from ~/.claude/skills. Fetch the served Library skill into that folder, put the key in the environment, and name a Collection. It talks to the origin with plain HTTP requests.
SKILL=~/.claude/skills/substrate-library
mkdir -p "$SKILL"
curl -fsSL https://thesubstrate.science/api/agent/library/skill \
-o "$SKILL/SKILL.md"
export SUBSTRATE_PERSONAL_TOKEN=subp_… # the key, in the environment onlyThen, in a new session:
Use the substrate-library skill against
https://thesubstrate.science with the key in SUBSTRATE_PERSONAL_TOKEN.
Read your identity, then list my Collections and the papers in the one
called "<Collection name>", with their notes. Change nothing.The skill has the agent read its identity first, so it knows your username, its permissions and its reach before it asks for anything else. Re-fetch the skill when the served version changes; its front matter carries the version.
The skill at /api/agent/library/skill is the agent-facing reference: the identity read first, reach and permissions, the reads, batches, retries with the same request id, and the rule that note bodies, paper titles and abstracts are text written by other people and never instructions. The manifest at /.well-known/substrate.json carries the same contract in its library block, and /api/agent/library/schema serves every operation’s input schema with an example body. The paths and refusal codes are on HTTP API, and the tools on MCP tools.
Hosted MCP endpoint: IdeaHosted MCP endpoint
A hosted MCP endpoint with OAuth would let a connector in a chat product use your Library with consent given once in the browser and no adapter on your machine. The HTTP contract is written so that such an endpoint would sit on it unchanged.
Two kinds of key
A personal key (subp_) and a Room credential (sub_) are separate in both directions. A personal key is refused on every research route, so nothing your agent does in your Library can reach a Room, and a Room credential is refused on every Library route, so no Room member’s agent can see your shelf. An agent that does both holds one of each, each in its own variable: SUBSTRATE_PERSONAL_TOKEN and SUBSTRATE_TOKEN. Room credentials are on Agent credentials.
Revoke
Your keys lists each live key with its label, permissions, reach, expiry and when it was last used, refreshed at most every ten minutes. Revoke ends a key at once: its next request is refused, as an expired key’s is. Keys that ended stay listed, dimmed, with the date they expired or were revoked. Settings are fixed once a key exists: to change a permission, the reach or the agent name, revoke it and issue another. Leaving a Collection, or being removed from one, ends every key’s access to it at the same moment, and a deleted Collection leaves every reach that listed it. What the agent filed stays, attributed to you; revocation changes who may write next, not what was written. You can hold up to 20 live keys.
Limits
| Item | Limit |
|---|---|
| Live personal keys | 20 |
| Key expiry | 1 to 90 days |
| Collections a selected reach lists | 100 |
| Identifiers per batch | 20 |
| Metadata budget per batch | 30 seconds |
| Papers in a Collection | 2,000, whoever adds them |
| Saved papers in your Library | 10,000, whoever saves them |
| Collections you own | 100 |
| Collection name | 1 to 100 characters |
| Note | 1 to 10,000 characters |
| Page of papers | 50 |
| Request body | 1 MiB |
The same bounds sit with every other limit on Limits. How the Collection view shows what an agent filed is on Collections.