The name of the agent to run under the caller's environment grant. Required.
agent_version
string
The immutable agent version pinned for this task attempt. Required.
agent_session_id
string
The stable session identifier; reusing it for another attempt is refused. Required.
message
Message
The initial task message appended atomically with session acceptance. Required.
environment
EnvironmentSpec
The requested fresh lease, with a finite TTL and supported harness. Required.
credentials
map<string, CredentialBinding>
Captured credential bindings by alias; credentials never enter context.
profiles
ProfileMount[]
Granted profile mounts for the fresh session lease.
completion
CompletionCall
The pinned tool call used by the runtime to deliver the terminal result. Required.
workspace_knowledge
struct
Opaque, claim-pinned workspace knowledge, including its rendered instruction.
task_ref
string
Caller-owned opaque reference, not interpreted by Agents.
renewal
RenewalCall
Optional pinned grant-renewal call, owned by the runtime after acceptance.
runtime_credential_handle
string
Same-session handle to a caller-owned scoped Access credential. Runtime only, never installed in the guest or sent to the model. Required. Never returned again.
A Kernel Secret of this environment, by name. One of the source group.
connection
string
A Kernel Connection (a third-party OAuth installation), by name. One of the source group.
end_user_provider
string
The end user's own grant in Sylphx Auth's agent token vault, by provider id; the session's end user must hold it. One of the source group.
placement
string
How the value is sent: bearer (default), header:<Name> or query:<name>.
handle
string
An opaque credential handle issued for this session, resolved only at egress. This is never a credential value. Never returned again. One of the source group.
The authorized renewal tool name in the pinned agent version. Required.
arguments
struct
Immutable literal renewal-tool input, with credential injection by the gateway.
interval
duration
Positive interval, from five seconds to five minutes. Required.
cancel_field
string
JSON pointers into the tool response; no domain-specific field names.
reason_field
string
A response JSON pointer selecting the cancellation reason.
credential_updates
map<string, string>
Credential binding alias to a response JSON pointer for its replacement.
credential_expiries
map<string, string>
Matching aliases to issuer-returned RFC3339 expiry response pointers.
idempotency_argument
string
Top-level argument receiving a stable per-tick runtime idempotency key. Omit this argument from literal input; retries reuse it, later ticks change it.
The AgentVersion the session pinned; the Agent's current version when unset at create.
end_user
string
The Sylphx Auth end user the session belongs to, set from the caller's end-user session; empty for a session a secret key started. An end user reads and changes only their own sessions. Output only.
title
string
A short title; set by the caller or summarised by the runtime.
state
SessionState
The session's state. Output only. One of idle, running, awaiting_approval, awaiting_client, failed.
turn_count
int64
The number of turns started, from 0. Output only.
last_event_sequence
int64
The sequence of the newest event, from 0. Output only.
create_time
timestamp
When the session was created. Output only.
update_time
timestamp
When the last event was appended. Output only.
usage
SessionUsage
What the session has used so far. Output only.
environment_lease
string
The Sylphx Sandboxes lease attached to the session, while it has one. Output only.
environment
EnvironmentSpec
The environment for this session; when omitted, use the pinned Agent version's default. An explicit value replaces that default.
credentials
map<string, CredentialBinding>
Session-scoped credential bindings, keyed by the tool or MCP credential name. Values are references or opaque handles, never secret values.
profiles
ProfileMount[]
Granted platform Profiles to mount when the session starts, each by resource name and mode. The runtime never puts profile values in events.
The position in the session's log, from 1, with no gaps. Output only.
type
SessionEventType
What the event is. Output only. One of user_message, steer, agent_message, tool_call, tool_result, approval_requested, approval_decided, status, compaction, thought, file_change, response, error.
turn
int64
The turn it belongs to, from 1; 0 for an event outside a turn. Output only.
step
int64
The step within the turn, from 1, assigned by the runtime; 0 for an event that is not a step. Output only.
create_time
timestamp
When it was appended. Output only.
message
Message
For USER_MESSAGE, STEER and AGENT_MESSAGE. One of the payload group.
tool_call
ToolCall
For TOOL_CALL. One of the payload group.
tool_result
ToolResult
For TOOL_RESULT. One of the payload group.
approval
Approval
For APPROVAL_REQUESTED and APPROVAL_DECIDED. One of the payload group.
status_change
StatusChange
For STATUS. One of the payload group.
thought
Message
For THOUGHT: a reasoning summary, never private model reasoning. One of the payload group.
file_change
FileChange
For FILE_CHANGE. One of the payload group.
response
TurnResult
For RESPONSE: the completed turn's answer and usage. One of the payload group.
Increases by one on every change to spec. Output only.
etag
string
Strong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as If-Match or etag to make Update and Delete conditional; a mismatch fails with ABORTED / 409 ETAG_MISMATCH. Output only.
create_time
timestamp
When the Resource was created. Output only.
update_time
timestamp
When the Resource last changed. Output only.
delete_time
timestamp
Set while the Resource is being deleted. Output only.
A Kernel Secret of this environment, by name. One of the source group.
connection
string
A Kernel Connection (a third-party OAuth installation), by name. One of the source group.
end_user_provider
string
The end user's own grant in Sylphx Auth's agent token vault, by provider id; the session's end user must hold it. One of the source group.
placement
string
How the value is sent: bearer (default), header:<Name> or query:<name>.
handle
string
An opaque credential handle issued for this session, resolved only at egress. This is never a credential value. Never returned again. One of the source group.