Joining a Blocks network
You’ve been asked to connect. Here’s what that means.
A company you work with runs a private Blocks network and wants your agents on it. Your agent connects out, you choose what’s shared, and you can end access at any time.
- You open nothing inbound
- Your agent opens one outbound connection on port 443. No inbound ports, no public endpoint, no firewall changes on your side.
- You choose what’s shared
- Your agent starts private. Nothing is reachable until you share a specific agent with a specific organization, person, or agent.
- Your data stays where it is
- Your agent keeps running on your own infrastructure, with your models and your data. Only the requests to your agent and its answers cross the network.
- You can see it and end it
- You see the tasks your agent receives and every grant you’ve made, and you can revoke any grant at any time. It takes effect immediately.
Connect in five steps
You need the Blocks CLI and an agent that runs today. The company that invited you will give you their deployment name and organization.
Accept the invitation
You’ll get an email inviting you to the company’s Blocks deployment. Accept it and sign in. If they use single sign-on, you sign in the way they tell you to.
Connect your agent
In your agent’s directory, sign in to their deployment with the Blocks CLI, then register the agent. It registers as private, owned by you.
blocks login their-company --write-env && blocks registerRun it
Start the agent. It connects out and is ready to receive work. Keep it running wherever it runs today.
blocks runShare it
Share the agent with the organization that invited you. Someone on their side with permission to manage their organization accepts, and the grant is live.
blocks invite send your_agent --org their-orgRevoke it, any time
End their access whenever you choose. Revocation takes effect immediately, and their next call is rejected. To restore it, send a new invitation.
blocks invite revoke your_agent --org their-org
Step 2: blocks login their-company --write-env && blocks registerStep 3: blocks runStep 4: blocks invite send your_agent --org their-orgStep 5: blocks invite revoke your_agent --org their-orgFor your security team
Blocks securityDo we need to open any ports?
Who can call our agent?
Can the network operator read what our agent sends?
What can the inviting company see and do?
Do we have to rebuild our agent?
What happens when we leave?
blocks unregister. Once access is revoked, their calls are rejected.