Developer & CI · wired today
Drive Buildkite with governed agents
Build, review and release state is where agents earn their keep. The Buildkite connector is one of 205 executable connectors and gives agents 4 read-only tools, with the credential held in the vault and every call receipted.
What agents can run against Buildkite
| Tool | What it does |
|---|---|
whoami | Get the Buildkite user account that owns the configured API access token |
list_organizations | List the Buildkite organizations the API access token can see |
list_pipelines | List the pipelines in one Buildkite organization, with their repository and current build counts |
list_builds | List recent builds for one Buildkite pipeline, newest first, optionally filtered by branch and build state |
Every tool above is read-only. Write surfaces ship only after live testing, and always behind approval gates.
What the Buildkite connector needs
You provide API token from your Buildkite account; Quox sends it as a bearer token. The credential is stored encrypted in the vault and resolved just-in-time, so agents use it without ever seeing it.
Where to get it: Buildkite's own API documentation ↗ covers creating and scoping the credential.
How proven is this?
This connector was blind shape-proven against the real Buildkite API: every endpoint it declares answered measurably differently from a deliberately bogus control request, without any account or credential involved. It is Beta: proven against the live API surface, not yet run with a real credential.
Buildkite integration FAQ
What can Quox agents do with Buildkite?
Agents can run 4 read-only tools against Buildkite: whoami, list organizations, list pipelines, list builds. Every call is receipted in the evidence trail.
What does the Buildkite integration need?
You provide API token from your Buildkite account; Quox sends it as a bearer token. The credential is stored encrypted in the vault and resolved just-in-time, so agents use it without ever seeing it.
Do agents see my Buildkite credentials?
No. Credentials live encrypted in the Quox vault and are resolved server-side at call time. Agents invoke tools; they never receive the underlying secret.
How proven is the Buildkite connector?
This connector was blind shape-proven against the real Buildkite API: every endpoint it declares answered measurably differently from a deliberately bogus control request, without any account or credential involved. It is Beta: proven against the live API surface, not yet run with a real credential.