# Command: `assistant:mcp:provision`

**Description**: Mint (rotate) a user's assistant MCP token and print delivery instructions
**Status**: completed
**Started**: 2026-10-01 09:43:33 | **Ended**: 2026-10-01 09:43:33 | **Duration**: 0s
**Jobs**: 0 dispatched / 0 completed / 0 failed

---

## Command Output

09:43:33 [INFO] Lock acquired for command: assistant:mcp:provision

09:43:33 [WARNING] ⚠️  Using operator-entered roles — snapshots must reflect real UMS state. Have the user log in soon so the login hook corrects any drift.

09:43:33 [WARNING] ⚠️  No --permissions given, so this token has no route permissions until the user logs in and the login hook fills them.

09:43:33 [INFO] 🔐 Minted assistant MCP token for kim@dilantimedia.com

09:43:33 [INFO] 1. Write this line into /srv/hermes/users/kim/env.agent:

09:43:33 [INFO] 2. Apply it on kokos-ai:

09:43:33 [INFO] docker compose up -d --force-recreate agent

09:43:33 [INFO] 📌 Token id: 1

09:43:33 [INFO] 📌 Snapshot roles: ADMIN, EMPLOYEE, IT, DOMAIN\_MANAGER

09:43:33 [INFO] 📌 Inactivity expiry if the user does not log in again: Sat, Oct 31, 2026 9:43 AM. Each Kokos login inside the window extends it by 30 days from that login. After it lapses the credential stays dead until you re-run this command.

09:43:33 [INFO] 📌 Disabling, deleting, or reassigning the Hermes registry row revokes this token immediately.

09:43:33 [WARNING] ⚠️  This plain token is shown ONCE and cannot be recovered; rotate again if lost.

09:43:33 [INFO] Lock released for assistant:mcp:provision

---

## Jobs (0)

*No jobs dispatched*

*Exported at 2026-10-04T22:17:52+00:00*
