# Bring an item under control

Source: https://immiscible.fly.dev/docs/api/post-api-w-wid-discovery-items-id-control

`POST /api/w/:wid/discovery/items/:id/control`

Owners and admins. A key or service account becomes an agent acting for its owner (the member whose email matches, else `principalId`, else you) and an agent key is issued; it is in the answer once. A project or workspace becomes an application. `revokeOriginal: true` also files a proposal to revoke the original key at the vendor.

## Authentication

Session cookie. A signed-in person: the console's session cookie. Every state-changing request also carries the header `x-immiscible-csrf: 1`, and the member's role decides what it may do. Bearer tokens are ignored on these routes, so no machine credential can reach them.

## Path parameters

- `wid` (string, required): Workspace id
- `id` (string, required): Object id

## Request

curl:

```bash
curl -X POST "https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/discovery/items/act_7Qm2c1f0/control" \
  -H "cookie: __Host-sid=$IMMISCIBLE_SESSION" \
  -H "x-immiscible-csrf: 1" \
  -H "content-type: application/json" \
  -d '{
    "name": "Growth agent",
    "revokeOriginal": true
  }'
```

Node:

```ts
const res = await fetch('https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/discovery/items/act_7Qm2c1f0/control', {
  method: 'POST',
  headers: {
    cookie: `__Host-sid=${process.env.IMMISCIBLE_SESSION}`,
    'x-immiscible-csrf': '1',
    'content-type': 'application/json',
  },
  body: JSON.stringify({
    name: 'Growth agent',
    revokeOriginal: true,
  }),
});
const data = await res.json();
console.log(res.status, data);
```

Python:

```python
import os
import requests

res = requests.post(
    "https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/discovery/items/act_7Qm2c1f0/control",
    headers={
        "cookie": f"__Host-sid={os.environ['IMMISCIBLE_SESSION']}",
        "x-immiscible-csrf": "1",
        "content-type": "application/json",
    },
    json={
        "name": "Growth agent",
        "revokeOriginal": True,
    },
)
print(res.status_code, res.json())
```

## Response

```json
{ "item": { "id": "dsc_4f2c91a7d0e3b6a81c55", "status": "managed" }, "agent": { "id": "agt_9c1e", "name": "Growth agent" }, "key": "ask_...", "keyId": "key_7d2a", "proposal": { "id": "vpr_1b2c", "kind": "revoke_key", "status": "pending" } }
```
