Agent access changes the risk model.
A normal API is usually called by software your team controls. An agent-facing tool surface may be called after model reasoning over emails, docs, tickets, customer records, web pages, and other untrusted text. That makes permission design, tool granularity, auditability, and prompt-injection boundaries part of the product architecture.
The launch question is not whether an agent can call the API. The launch question is whether the agent can do useful work while each tool remains scoped, observable, reversible where possible, and safe under hostile or confused input.