Skip to content
Console
Menu

Getting Started

Authentication

KV Store

Create an agent session

Starts a session of an agent, pinned to its current version unless `agent_version` names another.

Starts a session of an agent, pinned to its current version unless agent_version names another. Requires a secret key until end-user ownership is implemented. The session starts idle; :send starts its first turn.

Not available yet. Sylphx Agents is declared in the registry but no backend serves it: every call answers 501 with the problem code UNIMPLEMENTED.

  • Path POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/agent_sessions
  • Scope agents:sessions
  • Effect write — a successful call changes state.
  • Collection agent_sessions
  • Query agent_session_id, validate_only

#Request

FieldTypeWhat it is
parentstringThe parent to create in. Required.
agent_session_idstringThe session id, the final name segment; the server assigns one when empty.
agent_sessionAgentSessionThe session to create; only caller-writable fields are read. Required.
validate_onlyboolValidate and return the result without writing anything.

#AgentSession

FieldTypeWhat it is
namestringorgs/{org}/projects/{project}/envs/{env}/agent_sessions/{agent_session}.
metaResourceMetaResource metadata.
agentstringThe Agent the session talks to. Required.
agent_versionstringThe AgentVersion the session pinned; the Agent's current version when unset at create.
titlestringA short title; set by the caller or summarised by the runtime.
environmentEnvironmentSpecThe environment for this session; when omitted, use the pinned Agent version's default. An explicit value replaces that default.
credentialsmap<string, CredentialBinding>Session-scoped credential bindings, keyed by the tool or MCP credential name. Values are references or opaque handles, never secret values.
profilesProfileMount[]Granted platform Profiles to mount when the session starts, each by resource name and mode. The runtime never puts profile values in events.

#ResourceMeta

FieldTypeWhat it is
labelsmap<string, string>Caller-writable, indexed labels (AIP-122 label rules).
annotationsmap<string, string>Caller-writable, unindexed annotations.
display_namestringCaller-writable human-readable name.

#EnvironmentSpec

FieldTypeWhat it is
shapestringA Sylphx Sandboxes shape; empty gives sessions no environment.
idle_standbydurationPut the environment in standby after this long idle, 1m to 24h; default 10m.
templatestringThe Sandboxes image: template:<name> or an artifact image by digest, passed unchanged to the lease's image field.
repoRepositorySpecThe repository to prepare inside the fresh lease, if any.
egressLeaseNetworkThe lease's outbound policy, using the Sandboxes network contract.
budgetLeaseBudgetThe lease's CPU and cost ceiling, separate from model and tool spend.
ttldurationThe lease's maximum wall time, passed to Sandboxes as ttl. The lease is released when the session ends even if this bound has not been reached.

#CredentialBinding

FieldTypeWhat it is
secretstringA Kernel Secret of this environment, by name. One of the source group.
connectionstringA Kernel Connection (a third-party OAuth installation), by name. One of the source group.
end_user_providerstringThe end user's own grant in Sylphx Auth's agent token vault, by provider id; the session's end user must hold it. One of the source group.
placementstringHow the value is sent: bearer (default), header:<Name> or query:<name>.
handlestringAn opaque credential handle issued for this session, resolved only at egress. This is never a credential value. One of the source group.

#ProfileMount

FieldTypeWhat it is
namestringorgs/{org}/projects/{project}/envs/{env}/profiles/{profile}. Required.
modestringread_only (default) or write_back. Only a write_back grant saves changes at session end while its lease still answers; empty is read_only.

#RepositorySpec

FieldTypeWhat it is
uristringThe repository URI. Access uses the session's bound credential handles. Required.
revisionstringThe commit or ref to check out; empty uses the repository's default branch.

#LeaseNetwork

FieldTypeWhat it is
egressEgressPolicyDefault ALLOW. One of allow, deny, allowlist.
allowed_domainsstring[]Hosts reachable when egress is ALLOWLIST: exact names or one leading *. wildcard label, for example api.openai.com, *.github.com.
allowed_cidrsstring[]Public CIDRs reachable when egress is ALLOWLIST.

#LeaseBudget

FieldTypeWhat it is
max_cpu_secondsint64End CPU_BUDGET after this many vCPU-seconds of guest CPU time.
max_cost_microsint64End COST_BUDGET once the shape's list price times wall seconds reaches this many millionths of a US dollar.

#Response

FieldTypeWhat it is
namestringorgs/{org}/projects/{project}/envs/{env}/agent_sessions/{agent_session}.
uidstringases_<cell><ulid>; never reused. Output only.
metaResourceMetaResource metadata.
agentstringThe Agent the session talks to. Required.
agent_versionstringThe AgentVersion the session pinned; the Agent's current version when unset at create.
end_userstringThe Sylphx Auth end user the session belongs to, set from the caller's end-user session; empty for a session a secret key started. An end user reads and changes only their own sessions. Output only.
titlestringA short title; set by the caller or summarised by the runtime.
stateSessionStateThe session's state. Output only. One of idle, running, awaiting_approval, awaiting_client, failed.
turn_countint64The number of turns started, from 0. Output only.
last_event_sequenceint64The sequence of the newest event, from 0. Output only.
create_timetimestampWhen the session was created. Output only.
update_timetimestampWhen the last event was appended. Output only.
usageSessionUsageWhat the session has used so far. Output only.
environment_leasestringThe Sylphx Sandboxes lease attached to the session, while it has one. Output only.
environmentEnvironmentSpecThe environment for this session; when omitted, use the pinned Agent version's default. An explicit value replaces that default.
credentialsmap<string, CredentialBinding>Session-scoped credential bindings, keyed by the tool or MCP credential name. Values are references or opaque handles, never secret values.
profilesProfileMount[]Granted platform Profiles to mount when the session starts, each by resource name and mode. The runtime never puts profile values in events.

#ResourceMeta

FieldTypeWhat it is
generationint64Increases by one on every change to spec. Output only.
etagstringStrong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as If-Match or etag to make Update and Delete conditional; a mismatch fails with ABORTED / 409 ETAG_MISMATCH. Output only.
create_timetimestampWhen the Resource was created. Output only.
update_timetimestampWhen the Resource last changed. Output only.
delete_timetimestampSet while the Resource is being deleted. Output only.
labelsmap<string, string>Caller-writable, indexed labels (AIP-122 label rules).
annotationsmap<string, string>Caller-writable, unindexed annotations.
display_namestringCaller-writable human-readable name.
creatorstringThe principal that created the Resource. Output only.

#SessionUsage

FieldTypeWhat it is
active_turn_durationdurationTime turns were active. Output only.
gateway_callsint64Tool calls made through the gateway. Output only.
spend_microsint64Spend so far in micro-USD, models and tools together. Output only.

#EnvironmentSpec

FieldTypeWhat it is
shapestringA Sylphx Sandboxes shape; empty gives sessions no environment.
idle_standbydurationPut the environment in standby after this long idle, 1m to 24h; default 10m.
templatestringThe Sandboxes image: template:<name> or an artifact image by digest, passed unchanged to the lease's image field.
repoRepositorySpecThe repository to prepare inside the fresh lease, if any.
egressLeaseNetworkThe lease's outbound policy, using the Sandboxes network contract.
budgetLeaseBudgetThe lease's CPU and cost ceiling, separate from model and tool spend.
ttldurationThe lease's maximum wall time, passed to Sandboxes as ttl. The lease is released when the session ends even if this bound has not been reached.

#CredentialBinding

FieldTypeWhat it is
secretstringA Kernel Secret of this environment, by name. One of the source group.
connectionstringA Kernel Connection (a third-party OAuth installation), by name. One of the source group.
end_user_providerstringThe end user's own grant in Sylphx Auth's agent token vault, by provider id; the session's end user must hold it. One of the source group.
placementstringHow the value is sent: bearer (default), header:<Name> or query:<name>.
handlestringAn opaque credential handle issued for this session, resolved only at egress. This is never a credential value. One of the source group.

#ProfileMount

FieldTypeWhat it is
namestringorgs/{org}/projects/{project}/envs/{env}/profiles/{profile}. Required.
modestringread_only (default) or write_back. Only a write_back grant saves changes at session end while its lease still answers; empty is read_only.

#RepositorySpec

FieldTypeWhat it is
uristringThe repository URI. Access uses the session's bound credential handles. Required.
revisionstringThe commit or ref to check out; empty uses the repository's default branch.

#LeaseNetwork

FieldTypeWhat it is
egressEgressPolicyDefault ALLOW. One of allow, deny, allowlist.
allowed_domainsstring[]Hosts reachable when egress is ALLOWLIST: exact names or one leading *. wildcard label, for example api.openai.com, *.github.com.
allowed_cidrsstring[]Public CIDRs reachable when egress is ALLOWLIST.
blocked_cidrsstring[]The ranges blocked under every policy. Output only.

#LeaseBudget

FieldTypeWhat it is
max_cpu_secondsint64End CPU_BUDGET after this many vCPU-seconds of guest CPU time.
max_cost_microsint64End COST_BUDGET once the shape's list price times wall seconds reaches this many millionths of a US dollar.

#Errors

Every error arrives in the body Errors describes.

#Examples

curl -X POST "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/agent_sessions" \
  -H "Authorization: Bearer $SYLPHX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"agent":"…"}'