# Configure a Resource

> Add a capability, connect its authentication, and verify that it is ready for Agents.

## Before you begin {#before-you-begin}

Decide what the Agent needs to accomplish, not which internal component should perform it. Choose the closest category: AI & Models, Apps & APIs, Data, Storage, or Compute. For an external service, create the required [Credential](/docs/credentials) first and note any Policy restrictions that should apply. You need permission to create Resources in the target namespace.

## Steps {#steps}

1. Give the Resource a short, descriptive namespace-local name, such as `github-support`, `orders-readonly`, or `research-browser`.
2. Choose the focused Resource view. For model access, configure a Gateway and then one or more logical Models. For an HTTP API, create a [Service](/docs/resources/services.md). For MCP, register a reviewed [MCP Gateway](/docs/resources/mcp-gateways.md) package or adapter.
3. Enter only the settings needed to reach the service, such as a service URL, database name, model choice, region, or capacity limit.
4. Attach a Credential reference when the external service requires authentication. Secret material remains in Credentials and does not belong in Resource settings.
5. Review the available capabilities and their interruption behavior. Pay particular attention to actions that change external state or may require outcome review.
6. Attach access Policy and enable the Resource when the review is complete.

The Platform API exposes the same lifecycle:

| Method | Path | Purpose |
| --- | --- | --- |
| `GET` / `POST` | `/v1/namespaces/:namespace/resources` | List one kind with `?kind=...` or create a Resource |
| `GET` / `DELETE` | `/v1/namespaces/:namespace/resources/:kind/:id` | Inspect or delete one tenant-managed Resource |
| `GET` | `/v1/namespaces/:namespace/resources/:kind/:id/control` | Read control state |
| `POST` | `/v1/namespaces/:namespace/resources/:kind/:id/enable` | Enable with an `eventId` and optional reason |
| `POST` | `/v1/namespaces/:namespace/resources/:kind/:id/disable` | Disable with an `eventId` and optional reason |

Create payloads contain `kind`, `id`, the configured integration reference, configuration, Credential slots, Policy attachments, state, egress, and operation contract required by that Resource. Prefer the Console or a trusted template unless you are implementing platform automation. Platform-provided catalog Resources can be read but cannot be changed or deleted by a tenant.

## Verify {#verify}

Open **Resources**, search for the name, and confirm the expected category, status, and capability count. Open the detail page and check **Settings**, **Available capabilities**, and **Connections & access**. The detail page should show a canonical CRN and must not expose secret material. If the Resource depends on a Credential, verify that Credential separately without copying its value.

## Next steps {#next-steps}

Continue with [Use Resources from Agents](/docs/resources/use.md) and [Build and use Tools](/docs/resources/tools.md). For a tenant, customer, or principal-specific target, configure a scoped binding as described in [Scoped bindings](/docs/credentials/scoped-bindings) instead of duplicating Agent deployments.
