Prerequisites
- A LangSmith account with the workspace you want to investigate.
- An API key: either a personal access token, or a service key (only organization admins can create service keys).
- The workspace ID and the API URL for your region.
Setup
1
Create an API key
In LangSmith, open the Settings page and select API Keys. For a service key, choose an organization-scoped or workspace-scoped key, and name the workspaces if you choose workspace-scoped. Set an expiration, then click Create API Key.
2
Copy the key
Copy the key and store it securely. LangSmith displays it only once.
3
Find the workspace ID
On the Settings page, find your Workspace ID under General.
4
Add the connection in CloudThinker
Go to Connections → LangSmith, fill in the three fields below, and click Connect. CloudThinker sets up the connection and shows a Connected status.
Connected means CloudThinker finished setting up the connection. Run the verify prompt below to confirm LangSmith accepts the key, workspace, and URL.
Connection details
CloudThinker’s form requires all three. LangSmith needs the workspace ID when a key covers more than one workspace, and entering it for a single-workspace key does no harm.
For any other deployment, use the API URL of that deployment.
Required permissions
A personal access token has the permissions of the user who created it. A service key has the scope you give it: one workspace, several workspaces, or the whole organization.Agent capabilities
Once connected, agents read your workspace and change nothing in LangSmith.
Billing usage is not available through this connection. Agents show summaries rather than full run inputs and outputs.
Verify the connection
Example prompts
Troubleshooting
403 Forbidden
403 Forbidden
An organization-scoped service key needs the workspace ID to read workspace resources, and LangSmith rejects the request with 403 without it. Check LANGSMITH_WORKSPACE_ID, and confirm the key’s role covers that workspace.
Nothing is found, or the wrong data comes back
Nothing is found, or the wrong data comes back
The URL must match the region where your workspace lives. Set LANGSMITH_ENDPOINT to your region’s API URL from the table above.
Lists come back empty
Lists come back empty
An empty list is not a connection failure. The workspace may have no projects, datasets, or experiments yet, or the name you asked for does not exist. Ask the agent to list what exists, then name an exact project or dataset.
Requests return 429
Requests return 429
LangSmith limits how many requests each key can make in a minute. Wait a moment, then ask again with a smaller request.
Security
- Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
- Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
- Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
- Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
- Workspace-scoped key — a key limited to one workspace keeps other workspaces out of reach.
- Expiration — set an expiration on the key, and replace it before it lapses.
Related
Langfuse Connection
LLM traces, prompts, and evaluations
Datadog Connection
Log search, metrics, and monitoring