Skip to content
Console
Menu

Getting Started

Authentication

KV Store

Run an agent

Atomically admits a pinned task session, initial event and pending turn.

Atomically admits a pinned task session, initial event and pending turn.

Not available yet. Sylphx Agents is declared in the registry but no backend serves it: every call answers 501 with the problem code UNIMPLEMENTED.

  • Path POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/agents/agent:run
  • Scope agents:sessions
  • Effect write — a successful call changes state.
  • Collection agents

#Request

FieldTypeWhat it is
namestringThe name of the agent to run under the caller's environment grant. Required.
agent_versionstringThe immutable agent version pinned for this task attempt. Required.
agent_session_idstringThe stable session identifier; reusing it for another attempt is refused. Required.
messageMessageThe initial task message appended atomically with session acceptance. Required.
environmentEnvironmentSpecThe requested fresh lease, with a finite TTL and supported harness. Required.
credentialsmap<string, CredentialBinding>Captured credential bindings by alias; credentials never enter context.
profilesProfileMount[]Granted profile mounts for the fresh session lease.
completionCompletionCallThe pinned tool call used by the runtime to deliver the terminal result. Required.
workspace_knowledgestructOpaque, claim-pinned workspace knowledge, including its rendered instruction.
task_refstringCaller-owned opaque reference, not interpreted by Agents.
renewalRenewalCallOptional pinned grant-renewal call, owned by the runtime after acceptance.
runtime_credential_handlestringSame-session handle to a caller-owned scoped Access credential. Runtime only, never installed in the guest or sent to the model. Required. Never returned again.

#Message

FieldTypeWhat it is
partsContentPart[]The content, in order; 1 to 64 parts. Required.

#EnvironmentSpec

FieldTypeWhat it is
shapestringA Sylphx Sandboxes shape; empty gives sessions no environment.
idle_standbydurationPut the environment in standby after this long idle, 1m to 24h; default 10m.
templatestringThe Sandboxes image: template:<name> or an artifact image by digest, passed unchanged to the lease's image field.
repoRepositorySpecThe repository to prepare inside the fresh lease, if any.
egressLeaseNetworkThe lease's outbound policy, using the Sandboxes network contract.
budgetLeaseBudgetThe lease's CPU and cost ceiling, separate from model and tool spend.
ttldurationThe lease's maximum wall time, passed to Sandboxes as ttl. The lease is released when the session ends even if this bound has not been reached.

#CredentialBinding

FieldTypeWhat it is
secretstringA Kernel Secret of this environment, by name. One of the source group.
connectionstringA Kernel Connection (a third-party OAuth installation), by name. One of the source group.
end_user_providerstringThe end user's own grant in Sylphx Auth's agent token vault, by provider id; the session's end user must hold it. One of the source group.
placementstringHow the value is sent: bearer (default), header:<Name> or query:<name>.
handlestringAn opaque credential handle issued for this session, resolved only at egress. This is never a credential value. Never returned again. One of the source group.

#ProfileMount

FieldTypeWhat it is
namestringorgs/{org}/projects/{project}/envs/{env}/profiles/{profile}. Required.
modestringread_only (default) or write_back. Only a write_back grant saves changes at session end while its lease still answers; empty is read_only.

#CompletionCall

FieldTypeWhat it is
toolstringThe authorized tool name in the pinned agent version. Required.
argumentsstructImmutable literal tool input, excluding credentials and mapped result fields.
result_fieldsmap<string, ResultField>Destination argument names mapped to runtime-produced result selectors.

#RenewalCall

FieldTypeWhat it is
toolstringThe authorized renewal tool name in the pinned agent version. Required.
argumentsstructImmutable literal renewal-tool input, with credential injection by the gateway.
intervaldurationPositive interval, from five seconds to five minutes. Required.
cancel_fieldstringJSON pointers into the tool response; no domain-specific field names.
reason_fieldstringA response JSON pointer selecting the cancellation reason.
credential_updatesmap<string, string>Credential binding alias to a response JSON pointer for its replacement.
credential_expiriesmap<string, string>Matching aliases to issuer-returned RFC3339 expiry response pointers.
idempotency_argumentstringTop-level argument receiving a stable per-tick runtime idempotency key. Omit this argument from literal input; retries reuse it, later ticks change it.

#ContentPart

FieldTypeWhat it is
textstringText. One of the part group.
fileFileRefA file, by Sylphx Data object URL or an https URL. One of the part group.

#RepositorySpec

FieldTypeWhat it is
uristringThe repository URI. Access uses the session's bound credential handles. Required.
revisionstringThe commit or ref to check out; empty uses the repository's default branch.

#LeaseNetwork

FieldTypeWhat it is
egressEgressPolicyDefault ALLOW. One of allow, deny, allowlist.
allowed_domainsstring[]Hosts reachable when egress is ALLOWLIST: exact names or one leading *. wildcard label, for example api.openai.com, *.github.com.
allowed_cidrsstring[]Public CIDRs reachable when egress is ALLOWLIST.

#LeaseBudget

FieldTypeWhat it is
max_cpu_secondsint64End CPU_BUDGET after this many vCPU-seconds of guest CPU time.
max_cost_microsint64End COST_BUDGET once the shape's list price times wall seconds reaches this many millionths of a US dollar.

#FileRef

FieldTypeWhat it is
uristringWhere the file is. Required.
media_typestringIts media type, for example image/png.
filenamestringIts display name.

#Response

FieldTypeWhat it is
sessionAgentSessionThe durably accepted session; acceptance is not task completion. Output only.
initial_eventSessionEventThe initial message event committed with the session and pending turn. Output only.
deliverystringResult-delivery progress, independent of lease cleanup. Output only.
cleanupstringLease-cleanup progress; released requires terminal lease evidence. Output only.

#AgentSession

FieldTypeWhat it is
namestringorgs/{org}/projects/{project}/envs/{env}/agent_sessions/{agent_session}.
uidstringases_<cell><ulid>; never reused. Output only.
metaResourceMetaResource metadata.
agentstringThe Agent the session talks to. Required.
agent_versionstringThe AgentVersion the session pinned; the Agent's current version when unset at create.
end_userstringThe Sylphx Auth end user the session belongs to, set from the caller's end-user session; empty for a session a secret key started. An end user reads and changes only their own sessions. Output only.
titlestringA short title; set by the caller or summarised by the runtime.
stateSessionStateThe session's state. Output only. One of idle, running, awaiting_approval, awaiting_client, failed.
turn_countint64The number of turns started, from 0. Output only.
last_event_sequenceint64The sequence of the newest event, from 0. Output only.
create_timetimestampWhen the session was created. Output only.
update_timetimestampWhen the last event was appended. Output only.
usageSessionUsageWhat the session has used so far. Output only.
environment_leasestringThe Sylphx Sandboxes lease attached to the session, while it has one. Output only.
environmentEnvironmentSpecThe environment for this session; when omitted, use the pinned Agent version's default. An explicit value replaces that default.
credentialsmap<string, CredentialBinding>Session-scoped credential bindings, keyed by the tool or MCP credential name. Values are references or opaque handles, never secret values.
profilesProfileMount[]Granted platform Profiles to mount when the session starts, each by resource name and mode. The runtime never puts profile values in events.

#SessionEvent

FieldTypeWhat it is
namestringorgs/{org}/projects/{project}/envs/{env}/agent_sessions/{agent_session}/session_events/{session_event}.
uidstringsevt_<cell><ulid>; never reused. Output only.
metaResourceMetaResource metadata.
sequenceint64The position in the session's log, from 1, with no gaps. Output only.
typeSessionEventTypeWhat the event is. Output only. One of user_message, steer, agent_message, tool_call, tool_result, approval_requested, approval_decided, status, compaction, thought, file_change, response, error.
turnint64The turn it belongs to, from 1; 0 for an event outside a turn. Output only.
stepint64The step within the turn, from 1, assigned by the runtime; 0 for an event that is not a step. Output only.
create_timetimestampWhen it was appended. Output only.
messageMessageFor USER_MESSAGE, STEER and AGENT_MESSAGE. One of the payload group.
tool_callToolCallFor TOOL_CALL. One of the payload group.
tool_resultToolResultFor TOOL_RESULT. One of the payload group.
approvalApprovalFor APPROVAL_REQUESTED and APPROVAL_DECIDED. One of the payload group.
status_changeStatusChangeFor STATUS. One of the payload group.
thoughtMessageFor THOUGHT: a reasoning summary, never private model reasoning. One of the payload group.
file_changeFileChangeFor FILE_CHANGE. One of the payload group.
responseTurnResultFor RESPONSE: the completed turn's answer and usage. One of the payload group.
errorErrorEventFor ERROR. One of the payload group.

#ResourceMeta

FieldTypeWhat it is
generationint64Increases by one on every change to spec. Output only.
etagstringStrong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as If-Match or etag to make Update and Delete conditional; a mismatch fails with ABORTED / 409 ETAG_MISMATCH. Output only.
create_timetimestampWhen the Resource was created. Output only.
update_timetimestampWhen the Resource last changed. Output only.
delete_timetimestampSet while the Resource is being deleted. Output only.
labelsmap<string, string>Caller-writable, indexed labels (AIP-122 label rules).
annotationsmap<string, string>Caller-writable, unindexed annotations.
display_namestringCaller-writable human-readable name.
creatorstringThe principal that created the Resource. Output only.

#SessionUsage

FieldTypeWhat it is
active_turn_durationdurationTime turns were active. Output only.
gateway_callsint64Tool calls made through the gateway. Output only.
spend_microsint64Spend so far in micro-USD, models and tools together. Output only.

#EnvironmentSpec

FieldTypeWhat it is
shapestringA Sylphx Sandboxes shape; empty gives sessions no environment.
idle_standbydurationPut the environment in standby after this long idle, 1m to 24h; default 10m.
templatestringThe Sandboxes image: template:<name> or an artifact image by digest, passed unchanged to the lease's image field.
repoRepositorySpecThe repository to prepare inside the fresh lease, if any.
egressLeaseNetworkThe lease's outbound policy, using the Sandboxes network contract.
budgetLeaseBudgetThe lease's CPU and cost ceiling, separate from model and tool spend.
ttldurationThe lease's maximum wall time, passed to Sandboxes as ttl. The lease is released when the session ends even if this bound has not been reached.

#CredentialBinding

FieldTypeWhat it is
secretstringA Kernel Secret of this environment, by name. One of the source group.
connectionstringA Kernel Connection (a third-party OAuth installation), by name. One of the source group.
end_user_providerstringThe end user's own grant in Sylphx Auth's agent token vault, by provider id; the session's end user must hold it. One of the source group.
placementstringHow the value is sent: bearer (default), header:<Name> or query:<name>.
handlestringAn opaque credential handle issued for this session, resolved only at egress. This is never a credential value. Never returned again. One of the source group.

#ProfileMount

FieldTypeWhat it is
namestringorgs/{org}/projects/{project}/envs/{env}/profiles/{profile}. Required.
modestringread_only (default) or write_back. Only a write_back grant saves changes at session end while its lease still answers; empty is read_only.

#Message

FieldTypeWhat it is
partsContentPart[]The content, in order; 1 to 64 parts. Required.

#ToolCall

FieldTypeWhat it is
idstringThe call's id within the session, (turn, step) based. Output only.
toolstringThe tool name. Output only.
inputstructThe input, as the model sent it. Output only.
model_call_idstringThe model's own id for the call, as sent; never used as a key. Output only.
clientboolWhether the client runs it (a ClientTool). Output only.

#ToolResult

FieldTypeWhat it is
call_idstringThe ToolCall's id. Output only.
outputvalueThe output. Output only.
errorboolWhether the call failed; output then holds the error. Output only.
durationdurationHow long the call took. Output only.

#Approval

FieldTypeWhat it is
call_idstringThe ToolCall's id. Output only.
decisionApprovalDecisionThe answer, once given; unset while it waits. Output only. One of approve, reject.
rememberboolWhether the answer covers later calls of the same tool in this session ("always allow"). Output only.
principalstringWho answered. Output only.
reasonstringThe reason given, if any. Output only.

#StatusChange

FieldTypeWhat it is
stateSessionStateThe state after the change. Output only. One of idle, running, awaiting_approval, awaiting_client, failed.
reasonstringWhy, for FAILED and INTERRUPTED: a registry error code and message. Output only.

#FileChange

FieldTypeWhat it is
pathstringThe path relative to the session's repository root. Output only.
changestringadded, modified, deleted, renamed or copied. Output only.
addedint64Lines added, when reported by the harness. Output only.
removedint64Lines removed, when reported by the harness. Output only.
old_pathstringThe previous path, for a rename or copy. Output only.
sourcestringedit for an incremental edit or final for the turn's final diff. Output only.

#TurnResult

FieldTypeWhat it is
textstringThe final response's text. Output only.
is_errorboolWhether the turn ended with an error. Output only.
usageTurnTokenUsageModel token usage reported by the harness. Output only.
cost_microsint64The reported cost, in micro-USD. Output only.
durationdurationHow long the turn ran. Output only.

#ErrorEvent

FieldTypeWhat it is
kindstringThe registry error code or harness error kind. Output only.
messagestringA safe error description. Output only.

#RepositorySpec

FieldTypeWhat it is
uristringThe repository URI. Access uses the session's bound credential handles. Required.
revisionstringThe commit or ref to check out; empty uses the repository's default branch.

#LeaseNetwork

FieldTypeWhat it is
egressEgressPolicyDefault ALLOW. One of allow, deny, allowlist.
allowed_domainsstring[]Hosts reachable when egress is ALLOWLIST: exact names or one leading *. wildcard label, for example api.openai.com, *.github.com.
allowed_cidrsstring[]Public CIDRs reachable when egress is ALLOWLIST.
blocked_cidrsstring[]The ranges blocked under every policy. Output only.

#LeaseBudget

FieldTypeWhat it is
max_cpu_secondsint64End CPU_BUDGET after this many vCPU-seconds of guest CPU time.
max_cost_microsint64End COST_BUDGET once the shape's list price times wall seconds reaches this many millionths of a US dollar.

#ContentPart

FieldTypeWhat it is
textstringText. One of the part group.
fileFileRefA file, by Sylphx Data object URL or an https URL. One of the part group.

#TurnTokenUsage

FieldTypeWhat it is
input_tokensint64Input tokens. Output only.
output_tokensint64Output tokens. Output only.
cache_read_tokensint64Input tokens read from the model's cache. Output only.
cache_write_tokensint64Input tokens written to the model's cache. Output only.

#Errors

Every error arrives in the body Errors describes.

#Examples

curl -X POST "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/agents/agent:run" \
  -H "Authorization: Bearer $SYLPHX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"agent_session_id":"…","agent_version":"…","completion":{"tool":"…"},"environment":{},"message":{"parts":[{}]},"runtime_credential_handle":"…"}'