Obtaining credentials
This guide explains how to obtain all the credentials and access needed for agent development.
Obtain credentials
Get JFrog API token
- Go to https://kyndryl.jfrog.io
- Log in with your Kyndryl SSO
- Click your User Profile (top right corner) → Edit Profile
- Under Authentication Settings, click Generate an Identity Token
- Copy and save the generated token securely
Repository access
No separate TaaS or additional repository-access request is required to pull the Bridge Agent SDK. If your Kyndryl SSO account can sign in to JFrog, proceed directly with token generation and .netrc setup
Configure .netrc
- Create or edit ~/.netrc:
cat >> ~/.netrc << 'EOF'
machine kyndryl.jfrog.io
login [email protected]
password your-jfrog-api-token
EOF
chmod 600 ~/.netrc- Option A: OpenAI API key (local_dev): For local_dev mode, you need direct access to OpenAI.
Option A: Personal OpenAI account
- Sign in or create an account
- Click Create new secret ke"
- Copy and save the key (starts with sk-)
- Option B: Azure OpenAI (Kyndryl)
Contact your team lead for Kyndryl Azure OpenAI credentials.
- Configure environment
OPENAI_API_KEY=sk-your-key-here
OPENAI_API_BASE=https://api.openai.com/v1Bridge Platform credentials
For bridge_dev and production modes, you need Bridge Platform access.
Get Bridge Console access
- Request access to Bridge Console via your team lead or the KAIF onboarding team
- Log in to the Bridge Console at your account-specific URL
Create a service ID and get the SERVICE_API_KEY
The SERVICE_API_KEY is not a personal API key — it is the key associated with a Service ID (a machine/service account) on the Bridge Platform. Your agent uses this key to authenticate with the Bridge Access Management service and get a bearer token.
How to create a Service ID:
- Log in to the Bridge Admin Console for your account
- Navigate to Manage & Administer → Access Management → Service IDs)
- Click Create Service ID
- Fill in the details:
- Name: A descriptive name (e.g., incident-enrichment-agent-dev)
- Description: Purpose of this service ID
- The platform generates a service API key; copy it immediately
- Store it securely; this becomes your SERVICE_API_KEY env var
The key is shown only once at creation time. If you lose it, you must create a new Service ID.
Get account ID
- In Bridge Console, go to Account → Settings (or check the URL — the account ID is in the host name)
- Copy your Account ID (e.g., 697afe33bc0bab35cc54f8ae)
The account ID also appears in the account-specific host URL. For example https://kaiftestaccount-us-697afe33bc0bab35cc54f8ae.bridge.kyndryl.com
Get KAIF host URL
The KAIF_HOST is the global Bridge Platform URL used for Bridge Access Management , LLM, audit, and other platform services. This is different from the account-specific URL.
Variable | URL Pattern | Example |
|---|---|---|
KAIF_HOST (global) | {{global-instance}}https://-{{region}}-{{global-id}}}}.bridge.kyndryl.com | https://globalkaiffvt-us-6997f3f1ffcf5c8001488dfc.bridge.kyndryl.com |
BRIDGE_MCP_SERVER_UR (optional) | https://{{account-name}}-{{region}}-{{account-id}}.bridge.kyndryl.com/kaif/v2/mcp/tools | https://kaiftestaccount-us-697afe33bc0bab35cc54f8ae.bridge.kyndryl.com/kaif/v2/mcp/tools |
In bridge_dev mode the SDK automatically builds the MCP endpoint from KAIF_HOST ({{KAIF_HOST}}/kaif/v2/mcp/tools). You only need BRIDGE_MCP_SERVER_URL if your MCP server lives on a different host than KAIF_HOST.
Ask your KAIF platform admin for the correct KAIF_HOST URL for your environment.
MCP server access
For MCP tools (ServiceNow, Bridge Data, etc.), the SDK auto-resolves the MCP endpoint from KAIF_HOST in bridge_dev mode. You only need BRIDGE_MCP_SERVER_URL if your MCP server runs on a different host.
The MCP Server URL is account-specific:
https://{{account-name}}-{{region}}-{{account-id}}.bridge.kyndryl.com/kaif/v2/mcp/tools
Configure .env
Only needed if your MCP server URL differs from KAIF_HOST BRIDGE_MCP_SERVER_URL
MCP tool permissions
To use specific MCP tools, your account must have them provisioned. Run the MCP discovery script to see what's available for your account.
Common tools:
Tool | Description | Notes |
|---|---|---|
servicenow_search_incidents | Search ServiceNow incidents | Primary way to look up incidents |
servicenow_get_all_incidents | List ServiceNow incidents | Paginated, up to 100 |
servicenow_create_incident | Create a new incident | All 4 fields required |
bridge_execute_query | Query Bridge Data Lake (Trino SQL) | Most commonly used |
bridge_list_tables | List available tables | Enabled by default |
bridge_list_domains | List data domains | Enabled by default |
Tools like servicenow_get_ticket and servicenow_update_ticket do not exist on the current MCP server. Always verify with the discovery script before writing agent code.
Langfuse tracing (optional)
For observability and tracing:
Get Langfuse credentials
- Request Langfuse access from your team lead
- Get your project credentials from Langfuse dashboard
Configure .env
LANGFUSE_SECRET_KEY=sk-lf-...
LANGFUSE_PUBLIC_KEY=pk-lf-...
LANGFUSE_BASE_URL=https://cloud.langfuse.com