Kits belong to a project. These commands act inside the
active one (
naive projects use), else the organization’s default; --project <project_id> selects another for one command. assign refuses a child project
from a different project than the kit — policy does not cross the boundary.--mode—open|allowlist|blocklist--tool <toolkit>.enable=A,B/.disable=A,B— per-tool filter (repeatable)--custom-auth <toolkit>=ac_xxx— white-label OAuth (repeatable)
requiresApproval per primitive) is configured
via the dashboard Account Kit editor or the REST API
(primitives_config / connections_config) — see
Approvals. Sensitive actions are gated by default.