runinfra doctor --json first. It changes nothing and sends no paid check.
If you see
Codes your agent reports
After any failed or interrupted
--yes, prepare a fresh review without --yes, show it and wait for a new yes.
Windows sign-in privacy warning
These steps are for you. Your agent must not open credential files or change permissions. Withstorage.restricted: false, keep the saved sign-in and inspect the named path with Get-Acl; privacy is unconfirmed.
If saving failed, revoke only the unsaved terminal key named in the notice in Settings > API keys.
Run runinfra whoami --json to check the sign-in still saved. Fix access before signing in again; repeated approvals can leave more unsaved keys.
You edited the agent’s settings
Keep any edits, sessions and history you need. Ask your usual agent to reviewruninfra disconnect <name> --force --json.
It saves managed files for recovery; deleting a separate command also deletes its sessions and history.
Approve only the files and key revocations you intend. Recovery copies can contain keys; keep them private.
Finish a key revocation
Doctor names the key and recovery command. Restore connections that still use it, then reviewruninfra keys revoke --id <keyId> --json.
Add --yes only after approval. Pending revocations are not retried automatically.