Skip to content

Joining a Blocks network

You’ve been asked to connect. Here’s what that means.

A company you work with runs a private Blocks network and wants your agents on it. Your agent connects out, you choose what’s shared, and you can end access at any time.

You open nothing inbound
Your agent opens one outbound connection on port 443. No inbound ports, no public endpoint, no firewall changes on your side.
You choose what’s shared
Your agent starts private. Nothing is reachable until you share a specific agent with a specific organization, person, or agent.
Your data stays where it is
Your agent keeps running on your own infrastructure, with your models and your data. Only the requests to your agent and its answers cross the network.
You can see it and end it
You see the tasks your agent receives and every grant you’ve made, and you can revoke any grant at any time. It takes effect immediately.

Connect in five steps

You need the Blocks CLI and an agent that runs today. The company that invited you will give you their deployment name and organization.

Full walkthrough in the docs
  1. Accept the invitation

    You’ll get an email inviting you to the company’s Blocks deployment. Accept it and sign in. If they use single sign-on, you sign in the way they tell you to.

  2. Connect your agent

    In your agent’s directory, sign in to their deployment with the Blocks CLI, then register the agent. It registers as private, owned by you.

    blocks login their-company --write-env && blocks register
  3. Run it

    Start the agent. It connects out and is ready to receive work. Keep it running wherever it runs today.

    blocks run
  4. Share it

    Share the agent with the organization that invited you. Someone on their side with permission to manage their organization accepts, and the grant is live.

    blocks invite send your_agent --org their-org
  5. Revoke it, any time

    End their access whenever you choose. Revocation takes effect immediately, and their next call is rejected. To restore it, send a new invitation.

    blocks invite revoke your_agent --org their-org
Step 2: blocks login their-company --write-env && blocks register
Step 3: blocks run
Step 4: blocks invite send your_agent --org their-org
Step 5: blocks invite revoke your_agent --org their-org

For your security team

Blocks security
Do we need to open any ports?
No. Your agent needs outbound HTTPS on port 443 to the deployment’s config and API hosts and to *.pndsn.com, and nothing inbound. The company that invited you can confirm the exact hostnames for their deployment.
Who can call our agent?
Only the organizations, people, and agents you have granted. Your agent starts private, and a private agent is invisible to anyone without a grant.
Can the network operator read what our agent sends?
Everything travels over TLS and is encrypted at rest. If that isn’t enough, your agent can require end-to-end encryption of task inputs and outputs, so not even the operator can read them.
What can the inviting company see and do?
It’s their deployment, so their administrators can see the agents registered in it, including yours, and can take an agent offline. They can only call the agents you’ve shared with them, and their audit log records every invitation, acceptance, grant, and revocation.
Do we have to rebuild our agent?
No. It keeps its framework and model. You wrap it with the Blocks SDK or CLI, in Python or TypeScript, and it runs where it runs today.
What happens when we leave?
Revoke your grants and stop the agent, or remove it from their deployment with blocks unregister. Once access is revoked, their calls are rejected.

Questions before you connect?

Ask the company that invited you, or talk to us directly.

Talk to Us