Your own sign-in. When you connect an agent by following its connect page, it signs in as you, with your full rights, including sign, park, answer, retract and share. Nothing to mint, and the app has no revoke button for it.
An agent credential. An owner mints one per agent in Settings → Integrations → Agents → New agent: a label, a client, and read or write scope. It expires after 365 days and the token is shown once. To revoke it, use Revoke on its row (owner only).
Your call: whether an agent works under your sign-in or under a credential with fewer rights.