Manus
AI · AI
Agent tasks, their messages, files, and scheduled runs under that person’s own account.
Acts as the person, not as itself
Each user connects their own account. Every call carries both identities — the agent and the person it is acting for — so the agent can never reach past what that individual can already do.
Credentials never touch the agent
Tokens live in the vault and attach server-side at call time. The agent holds a session, not a secret, and revoking access does not mean rotating a key.
Every call on the record
Who asked, which agent acted, which action ran, and the verdict that let it through — one audit trail across every integration, not one per vendor.
What an agent can do
Each action is granted on its own. An agent allowed to read is not thereby allowed to write, and the scope beside each row is what the acting user must have connected for it to run at all.
manus_get_v2_agent_detailREADRead one agent by id: its nickname, its description and its configuration via GET /v2/agent.detail
manus_get_v2_agent_listREADList the Manus agents on this account, with the ids agent.detail takes and the task listing's `agent_subtask` scope filters on via GET /v2/agent.list
manus_get_v2_browser_onlinelistREADList the user's own browser clients that are online right now and therefore available to a task. On an OAuth connection this is what the `use_my_browsers` scope covers via GET /v2/browser.onlineList
manus_get_v2_connector_listREADList the connectors -- Manus's own third-party integrations -- this credential may name in a task message. On an OAuth connection this needs the `use_connectors` scope AND the specific connector UIDs selected on the Open App, and a connector the user revoked simply disappears from here via GET /v2/connector.list
manus_get_v2_file_detailREADRead one uploaded file's metadata by id via GET /v2/file.detail
manus_get_v2_project_listREADList the projects this credential can see, with the ids that task.create and skill.list take via GET /v2/project.list
manus_get_v2_skill_listREADList the user's global skills, plus a project's own skills when `project_id` is given via GET /v2/skill.list
manus_get_v2_task_detailREADRead one task by id: its status and stop reason, title, the credits it consumed, its task and share URLs, and the structured output when a schema was armed via GET /v2/task.detail
manus_get_v2_task_listREADList the tasks this credential can see, newest first by default, filtered by scope (all, standard, project or agent_subtask), by agent, by project, or by the Open App or API key that created them. AN OAUTH TOKEN HOLDING ONLY `create_task` SEES ONLY THE TASKS THAT APP CREATED; reaching the user's other tasks needs `manage_all_tasks`, which Manus labels broad access. An API key sees everything on the account via GET /v2/task.list
manus_get_v2_task_listmessagesREADPage through a task's event stream: user and assistant messages, errors and status updates, plus tool_used, plan_update, new_plan_step and explanation events when `verbose=true`. `start_event_id` resumes from one event and cannot be combined with a cursor; `slides_format=pptx` converts HTML slide attachments to PowerPoint via GET /v2/task.listMessages
manus_get_v2_usage_availablecreditsREADRead the credits still available to this account. Manus meters agent work in credits, so this is the call that says whether task.create and task.sendMessage can succeed via GET /v2/usage.availableCredits
manus_get_v2_usage_listREADPage through this user's own credit-usage records via GET /v2/usage.list
manus_get_v2_usage_teamlogREADPage through the team's per-member usage log over a date window given as Unix timestamps in seconds, sorted by task count or by credits via GET /v2/usage.teamLog
manus_get_v2_usage_teamstatisticREADRead the team's aggregate task count and credit spend over a date window given as Unix timestamps in seconds via GET /v2/usage.teamStatistic
manus_get_v2_user_meREADResolve the Manus user this connection acts as -- the user_id behind the API key or the OAuth access token. Read-only, takes no arguments, and Manus states it needs no additional OAuth scope, which is why it is also the credential check on the paste form via GET /v2/user.me
manus_get_v2_webhook_listREADList the webhook endpoints registered on this account, with the ids webhook.delete takes via GET /v2/webhook.list
manus_get_v2_webhook_publickeyREADRead the public key Manus signs webhook deliveries with, so a receiver can verify that a notification really came from Manus via GET /v2/webhook.publicKey
manus_get_v2_website_listcheckpointsREADList a website's checkpoints -- the deployable snapshots a task produced -- addressed by `task_id` OR `website_id`, exactly one via GET /v2/website.listCheckpoints
manus_get_v2_website_statusREADRead the deployment status of the website a task publishes, addressed by `task_id` OR `website_id` -- exactly one, never both via GET /v2/website.status
manus_post_v2_agent_updateWRITEChange an agent's display name or the description shown with it. Neither field is reverted by omitting it -- send only what should change via POST /v2/agent.update
manus_post_v2_file_deleteWRITEDESTRUCTIVE AND PERMANENT. Delete an uploaded file. Manus publishes no trash and no restore endpoint for files, so there is no undo and no safer alternative to prefer -- a task that already read the file keeps its own conversation, but the file is gone via POST /v2/file.delete
manus_post_v2_file_uploadWRITERegister a filename and receive the upload target plus the `file_id` a task message attaches. AGENTIC FABRIQ DOES NOT SEND THE BYTES FOR YOU: a task can instead take a file by public `file_url` or as base64 `file_data` in the message itself via POST /v2/file.upload
manus_post_v2_project_createWRITECreate a project and optionally its default instruction, which Manus prepends to every task created inside it -- the way to enforce one behaviour across related tasks via POST /v2/project.create
manus_post_v2_task_confirmactionWRITEAnswer a task that paused for confirmation, naming the `waiting_for_event_id` from the status_update event that asked and any input its `confirm_input_schema` describes. THIS AUTHORISES THE ACTION THE AGENT WAS WAITING ON and it proceeds immediately, so read the pending event before calling this via POST /v2/task.confirmAction
manus_post_v2_task_createWRITEStart a Manus agent task from a message (text, an uploaded file_id, a public file_url, base64 file_data, or voice), optionally inside a project whose instruction is prepended, with an agent profile (standard, lite or max), a locale, a share visibility and a structured-output JSON Schema. TASKS SPEND CREDITS -- read usage.availableCredits first. `hide_in_task_list` keeps a background task out of the Manus webapp list while leaving it reachable at its task_url via POST /v2/task.create
manus_post_v2_task_deleteWRITEDESTRUCTIVE AND PERMANENT. Delete a task with its message history and attachments. Manus publishes no trash and no restore endpoint, so there is no undo; stopping the task is the reversible alternative when the intent is only to end its run. Agent-related tasks cannot be deleted at all and answer an error via POST /v2/task.delete
manus_post_v2_task_sendmessageWRITEContinue a task with another message (text, file or voice), optionally overriding the agent profile for this and later turns, replacing its connectors with a new list, clearing them entirely, or arming a structured-output schema for the next time it finishes. Omitting both connector fields reuses whatever task.create configured via POST /v2/task.sendMessage
manus_post_v2_task_stopWRITEStop a running task. The task, its messages and its attachments all survive -- only the agent's execution ends -- so this is the reversible alternative to deleting a task that is merely going the wrong way via POST /v2/task.stop
manus_post_v2_task_updateWRITERename a task, show or hide it in the Manus webapp task list, or change who may view it. `share_visibility: public` MAKES THE SHARE URL READABLE WITHOUT AUTHENTICATION by anyone who holds it; `team` limits it to the team and `private` to the creator via POST /v2/task.update
manus_post_v2_webhook_createWRITERegister an HTTPS endpoint to receive Manus task notifications by POST. It must be publicly reachable and answer 2xx; verify each delivery against the key from webhook.publicKey before trusting it via POST /v2/webhook.create
manus_post_v2_webhook_deleteWRITEDESTRUCTIVE AND PERMANENT. Remove a webhook endpoint, which stops every future delivery to it. There is no undo and no disable: re-registering the same URL creates a NEW webhook with a new id via POST /v2/webhook.delete
manus_post_v2_website_publishWRITEPublish a task's website at a visibility: `public` (anyone), `team` (team members only, which requires a Team account) or `private`. OMITTING `visibility` RESETS THE SITE TO PUBLIC rather than leaving it unchanged, and a site may cap the visibility it allows and answer 403 above that cap. Addressed by `task_id` OR `website_id`, exactly one via POST /v2/website.publish
manus_post_v2_website_updateWRITEChange a website's title, its visibility or whether new checkpoints auto-publish. Omitted fields are left unchanged and an empty string is invalid, which is the difference from website.publish. Changing `auto_publish` neither publishes existing checkpoints nor cancels a deployment already in flight via POST /v2/website.update
Often connected alongside
Put Manus behind one governed endpoint.
Same permissions, same audit trail, whatever else you connect next.