1. Resources
  2. /
  3. Changelog
  4. /
  5. Job acquisition tokens for ephemeral agents

Job acquisition tokens for ephemeral agents

Stack-managed ephemeral agents can now start with a credential for one job. The controller keeps its cluster agent token and issues a short-lived job acquisition token (JAT) after reserving work. The workload uses that JAT to register an agent and acquire only the named job.

A JAT expires fifteen minutes after issuance by default. The Stacks API accepts a lifetime of up to one hour, but the token expires sooner if the job reservation does. When the agent registers, Buildkite also checks that the issuing agent token is still active and applies its expiration and IP restrictions.

Agent Stack for Kubernetes

The Agent Stack for Kubernetes uses JATs by default. The controller requests one immediately before scheduling each reserved job Pod and supplies it only to the agent container. If issuance fails, the job remains unscheduled rather than receiving the cluster agent token.

Custom stacks

Custom stack implementations can use the same flow: reserve a job, wait for execution capacity, then issue a JAT through the Stacks API. Start the workload with the JAT as BUILDKITE_AGENT_TOKEN and the reserved job UUID as BUILDKITE_AGENT_ACQUIRE_JOB.

See the job acquisition token guide for the complete flow, retry guidance, and credential-handling recommendations.

Steven

Atom feed

Start turning complexity into an advantage

Create an account to get started for free.

Buildkite Pipelines

Platform

  1. Pipelines
  2. Public pipelines
  3. Test Engine
  4. Package Registries
  5. Mobile Delivery Cloud
  6. Pricing

Hosting options

  1. Self-hosted agents
  2. Mac hosted agents
  3. Linux hosted agents

Resources

  1. Docs
  2. Blog
  3. Changelog
  4. Example pipelines
  5. Plugins
  6. Webinars
  7. Case studies
  8. Events
  9. Migration Services
  10. CI/CD perspectives

Company

  1. About
  2. Careers
  3. Press
  4. Security
  5. Brand assets
  6. Contact

Solutions

  1. Replace Jenkins
  2. Workflows for MLOps
  3. Testing at scale
  4. Monorepo mojo
  5. Bazel orchestration

Compare

  1. Buildkite vs GitHub Actions
  2. Buildkite vs Depot

Legal

  1. Terms of Service
  2. Acceptable Use Policy
  3. Privacy Policy
  4. Subprocessors
  5. Service Level Agreement
  6. Supplier Code of Conduct
  7. Modern Slavery Statement

Support

  1. System status
  2. Forum
© Buildkite Pty Ltd 2026