How agntpad works
Four things sit inside each other, your agent gets 14 tools, and a handful of limits are worth knowing before you hit them.
The four things
Organization
one per companyYour Microsoft tenant, and the wall around everything below. Everyone who signs in with a work account of the same tenant becomes a User here. The platform grants no access to another Organization; uploaded pages can still send data to outside services.
Space
up to 5 per personA workspace, and the thing you hand to an agent. One Owner, any number of Writers, and everyone else in your Organization can read its published Folders. You create Spaces here; agents cannot. When you create one you choose what it holds, and that choice is permanent: any text file, served as a website, or Markdown only, read with a file tree beside it. Every Space has its own origin for its home, listings, files and Markdown reader: all its Folders share browser storage and data trust, not separate sandboxes.
Folder
private, or publishedOne piece of work, and the unit of visibility. Every Folder has an address on its Space's origin; publishing it opens that address to everyone in your Organization and puts it in the listing they browse, while a private Folder stays with the Space's Owner and Writers and opens for nobody else. A Folder with an index.html opens a website on its Space's origin. Private is an access rule, not isolation from scripts in other Folders of that Space when an Owner or Writer visits.
File
text onlyHTML, CSS, JavaScript, SVG, Markdown, JSON, plain text. No images, no PDFs, no fonts — graphics have to be drawn as SVG or embedded in the page.
If it is not working
The agent cannot see a Space.
You are a reader there, not a Writer. Ask its Owner to add your work email.
Writes started failing.
A connection lasts 30 days. Extend it under Connected apps on your panel, or connect the app again.
A colleague cannot open a link.
The Folder may still be private, in which case only the Space's Owner and its Writers can open it: publish it, or add them as a Writer. Otherwise they have not signed in to agntpad.page yet, or they work at a different company.
An image will not upload.
It never will. Ask the agent to draw it as SVG, or to embed it in the page.
The agent says a file was rejected as not Markdown.
That Space is Markdown-only, so file names must end in '.md' or '.markdown'. The mode was chosen when the Space was created and cannot be changed; make a new Space if you need to serve other files.
An uploaded page cannot load an asset or find its saved settings.
Every Space's home, listings and files use its own Space subdomain. File paths start at the Folder name, such as /site/app.js. Use relative asset links, or that Space's host, rather than absolute asset links to agntpad.page: background requests to the viewer are blocked. Browser storage, including localStorage, belongs to an origin: Folders in one Space share it, but other Spaces and the viewer cannot read it. Check that you are opening the page in the same Space and browser profile where you saved the settings.
Agent tools
| Tool | What it does | Touches |
|---|---|---|
your_org_name | Tells the agent which company it is writing for. | Organization |
list_spaces_i_can_write_to | Lists the Spaces you have given it. | Space |
list_folders | Lists the Folders of a Space. | Folder |
create_folder | Makes a new Folder, private or published. | Folder |
get_folder | Lists what is in a Folder, and gives back its address. | Folder |
rename_folder | Renames one. Its address changes with it. | Folder |
set_folder_description | Writes the line your colleagues read under its name. | Folder |
change_folder_visibility | Opens a Folder to your Organization, or restricts it to the Owner and Writers. | Folder |
read_file | Reads one back. | File |
read_file_part | Reads a slice of a large one. | File |
search_space_content | Finds text across every File it is allowed to read. | File |
upload_files | Writes Files. Up to 50 in one go, all or none. | File |
edit_file | Changes part of a File without rewriting the whole thing. | File |
remove_file | Deletes one. | File |
There is no tool that deletes a Space, and none that deletes a Folder. Only a person does that, only on this site, and only the Space's Owner.
Limits
| Spaces owned per User | 5 |
| Users with write access per Organization | 10 during the beta: Owners and Writers, counted once each; readers do not count |
| Space name length | 64 characters |
| Folder name length | 64 characters |
| Folder description | 1000 characters |
| File path | 255 characters, 8 segments |
| Markdown-only Spaces | file names ending '.md' or '.markdown'; nothing else is accepted |
| File content | 400,000 characters |
| upload_files per call | 50 Files, 2,000,000 characters in total |
| edit_file per call | 50 edits |
| read_file_part | 500 lines by default, 5000 at most |
| search_space_content | query of 200 characters at most; the first match of each File with 50 characters on either side, 50 Files per call |
| Search on agntpad.page | 3 characters at least, 20 Files per page |
| Storage per Organization | 9.5 GB, full-text index included; writes past it are refused, deletes never are |
| OAuth access token lifetime | 1 hour, refresh tokens rotate; connections expire after 30 days unless extended or revoked from the panel |
Addresses
agntpad.com
The panel. You sign in here to make Spaces, add Writers and manage connected apps. Agents connect to https://agntpad.com/mcp; tools return direct Folder links on the Space's origin.
agntpad.page
The trusted viewer: Microsoft sign-in, the all-Spaces Organization directory, Organization-wide search and public docs are served here. Your colleagues sign in here, then follow direct links to individual Space hosts to read published work. Signed in, the front page searches names and contents across the Organization: everything in the Spaces you can write to, published Folders in the rest, which is exactly what browsing would show you. Public docs are also served on agntpad.com.
s-<UUIDhex>.agntpad.page
Every Space has one host, named with its UUID as 32 lowercase hexadecimal digits without hyphens. Its home is /; Folder links are https://s-<UUIDhex>.agntpad.page/<folder>/ and File links add the path after the Folder name, with no Space UUID in the path. Space home, Folder and file listings, uploaded files, the Markdown-only reader and raw Markdown all live here. A Markdown-only Space has a Folder tree on the left and renders the selected file beside it. Non-browser requests or Accept: text/markdown receive Markdown from the same Space-origin address. All Folders in the Space share this origin and browser storage. Content cannot read another Space, the viewer or the panel; cross-Space embedding and background fetches are blocked, but top-level links work. Generated UI loads same-origin resources from the reserved /.agntpad/assets/* paths and offers Account, linking to https://agntpad.page/account, rather than a logout form or viewer CSRF token. Platform docs and account routes are not served on Space hosts. A short-lived browser-bound handoff from the viewer signs you into this Space without sending it Microsoft tokens. The platform sets only Space-scoped cookies here, not panel or viewer cookies. Its session lasts at most 60 minutes and never outlives the viewer session. Viewer logout invalidates the Space sessions it authorized, not your panel session or MCP connections.
Enterprise ready
Access stays within your tenant
Reading stored content needs a work account of your own Microsoft tenant. There is no sign-in-free public content access. This is a platform access guarantee, not a promise that uploaded author scripts keep data inside your company.
Trust a Space's authors with what you can read
Raw HTML and JavaScript run without a platform Content Security Policy (CSP), including third-party scripts and network requests. On an Owner or Writer visit, scripts can read private Folders in the same Space; Readers can read only published Folders. That code can send accessible data to outside services. Use separate Spaces for work that must not share this trust.
Hosted on Cloudflare
The app runs on Cloudflare's network. Traffic is encrypted in transit, and stored data is encrypted at rest.
Content stays in the EU
Each Organization's Folders and Files live in their own storage object, created in the EU jurisdiction and pinned there for the life of the Organization. This covers platform storage, not copies sent elsewhere by uploaded scripts.
Ready for your own deployment
The whole thing is one Worker against your own Microsoft app registration, so a custom enterprise implementation is a configuration exercise, not a rewrite. Custom branding is also an option.