---
# @generated by sylphx-gen 0.1.0 from contracts@f99a9bda63ea35002f40ef41b07b570c1c970750996f232cbfb0ed12313637ab. Do not edit.
title: "Run an agent"
description: "`agents.agents.run` (POST /v1/{name}:run): Atomically admits a pinned task session, initial event and pending turn."
type: reference
product: agents
summary: "Atomically admits a pinned task session, initial event and pending turn."
updated: 2026-09-28
nav: false
---

Atomically admits a pinned task session, initial event and pending turn.

**Not available yet.** Sylphx Agents is declared in the registry but no backend serves it: every call answers `501` with the problem code `UNIMPLEMENTED`.

- **Path** `POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/agents/agent:run`
- **Scope** `agents:sessions`
- **Effect** `write` — a successful call changes state.
- **Collection** [agents](/docs/api/agents)

## Request

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | The name of the agent to run under the caller's environment grant. Required. |
| `agent_version` | `string` | The immutable agent version pinned for this task attempt. Required. |
| `agent_session_id` | `string` | The stable session identifier; reusing it for another attempt is refused. Required. |
| `message` | `Message` | The initial task message appended atomically with session acceptance. Required. |
| `environment` | `EnvironmentSpec` | The requested fresh lease, with a finite TTL and supported harness. Required. |
| `credentials` | `map<string, CredentialBinding>` | Captured credential bindings by alias; credentials never enter context. |
| `profiles` | `ProfileMount[]` | Granted profile mounts for the fresh session lease. |
| `completion` | `CompletionCall` | The pinned tool call used by the runtime to deliver the terminal result. Required. |
| `workspace_knowledge` | `struct` | Opaque, claim-pinned workspace knowledge, including its rendered instruction. |
| `task_ref` | `string` | Caller-owned opaque reference, not interpreted by Agents. |
| `renewal` | `RenewalCall` | Optional pinned grant-renewal call, owned by the runtime after acceptance. |
| `runtime_credential_handle` | `string` | Same-session handle to a caller-owned scoped Access credential. Runtime only, never installed in the guest or sent to the model. Required. Never returned again. |

### Message

| Field | Type | What it is |
| --- | --- | --- |
| `parts` | `ContentPart[]` | The content, in order; 1 to 64 parts. Required. |

### EnvironmentSpec

| Field | Type | What it is |
| --- | --- | --- |
| `shape` | `string` | A Sylphx Sandboxes shape; empty gives sessions no environment. |
| `idle_standby` | `duration` | Put the environment in standby after this long idle, 1m to 24h; default 10m. |
| `template` | `string` | The Sandboxes image: `template:<name>` or an artifact image by digest, passed unchanged to the lease's `image` field. |
| `repo` | `RepositorySpec` | The repository to prepare inside the fresh lease, if any. |
| `egress` | `LeaseNetwork` | The lease's outbound policy, using the Sandboxes network contract. |
| `budget` | `LeaseBudget` | The lease's CPU and cost ceiling, separate from model and tool spend. |
| `ttl` | `duration` | The lease's maximum wall time, passed to Sandboxes as `ttl`. The lease is released when the session ends even if this bound has not been reached. |

### CredentialBinding

| Field | Type | What it is |
| --- | --- | --- |
| `secret` | `string` | A Kernel Secret of this environment, by name. One of the `source` group. |
| `connection` | `string` | A Kernel Connection (a third-party OAuth installation), by name. One of the `source` group. |
| `end_user_provider` | `string` | The end user's own grant in Sylphx Auth's agent token vault, by provider id; the session's end user must hold it. One of the `source` group. |
| `placement` | `string` | How the value is sent: `bearer` (default), `header:<Name>` or `query:<name>`. |
| `handle` | `string` | An opaque credential handle issued for this session, resolved only at egress. This is never a credential value. Never returned again. One of the `source` group. |

### ProfileMount

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/projects/{project}/envs/{env}/profiles/{profile}`. Required. |
| `mode` | `string` | `read_only` (default) or `write_back`. Only a write_back grant saves changes at session end while its lease still answers; empty is read_only. |

### CompletionCall

| Field | Type | What it is |
| --- | --- | --- |
| `tool` | `string` | The authorized tool name in the pinned agent version. Required. |
| `arguments` | `struct` | Immutable literal tool input, excluding credentials and mapped result fields. |
| `result_fields` | `map<string, ResultField>` | Destination argument names mapped to runtime-produced result selectors. |

### RenewalCall

| Field | Type | What it is |
| --- | --- | --- |
| `tool` | `string` | The authorized renewal tool name in the pinned agent version. Required. |
| `arguments` | `struct` | Immutable literal renewal-tool input, with credential injection by the gateway. |
| `interval` | `duration` | Positive interval, from five seconds to five minutes. Required. |
| `cancel_field` | `string` | JSON pointers into the tool response; no domain-specific field names. |
| `reason_field` | `string` | A response JSON pointer selecting the cancellation reason. |
| `credential_updates` | `map<string, string>` | Credential binding alias to a response JSON pointer for its replacement. |
| `credential_expiries` | `map<string, string>` | Matching aliases to issuer-returned RFC3339 expiry response pointers. |
| `idempotency_argument` | `string` | Top-level argument receiving a stable per-tick runtime idempotency key. Omit this argument from literal input; retries reuse it, later ticks change it. |

### ContentPart

| Field | Type | What it is |
| --- | --- | --- |
| `text` | `string` | Text. One of the `part` group. |
| `file` | `FileRef` | A file, by Sylphx Data object URL or an https URL. One of the `part` group. |

### RepositorySpec

| Field | Type | What it is |
| --- | --- | --- |
| `uri` | `string` | The repository URI. Access uses the session's bound credential handles. Required. |
| `revision` | `string` | The commit or ref to check out; empty uses the repository's default branch. |

### LeaseNetwork

| Field | Type | What it is |
| --- | --- | --- |
| `egress` | `EgressPolicy` | Default ALLOW. One of `allow`, `deny`, `allowlist`. |
| `allowed_domains` | `string[]` | Hosts reachable when `egress` is ALLOWLIST: exact names or one leading `*.` wildcard label, for example `api.openai.com`, `*.github.com`. |
| `allowed_cidrs` | `string[]` | Public CIDRs reachable when `egress` is ALLOWLIST. |

### LeaseBudget

| Field | Type | What it is |
| --- | --- | --- |
| `max_cpu_seconds` | `int64` | End CPU_BUDGET after this many vCPU-seconds of guest CPU time. |
| `max_cost_micros` | `int64` | End COST_BUDGET once the shape's list price times wall seconds reaches this many millionths of a US dollar. |

### FileRef

| Field | Type | What it is |
| --- | --- | --- |
| `uri` | `string` | Where the file is. Required. |
| `media_type` | `string` | Its media type, for example `image/png`. |
| `filename` | `string` | Its display name. |

## Response

| Field | Type | What it is |
| --- | --- | --- |
| `session` | `AgentSession` | The durably accepted session; acceptance is not task completion. Output only. |
| `initial_event` | `SessionEvent` | The initial message event committed with the session and pending turn. Output only. |
| `delivery` | `string` | Result-delivery progress, independent of lease cleanup. Output only. |
| `cleanup` | `string` | Lease-cleanup progress; released requires terminal lease evidence. Output only. |

### AgentSession

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/projects/{project}/envs/{env}/agent_sessions/{agent_session}`. |
| `uid` | `string` | `ases_<cell><ulid>`; never reused. Output only. |
| `meta` | `ResourceMeta` | Resource metadata. |
| `agent` | `string` | The Agent the session talks to. Required. |
| `agent_version` | `string` | The AgentVersion the session pinned; the Agent's current version when unset at create. |
| `end_user` | `string` | The Sylphx Auth end user the session belongs to, set from the caller's end-user session; empty for a session a secret key started. An end user reads and changes only their own sessions. Output only. |
| `title` | `string` | A short title; set by the caller or summarised by the runtime. |
| `state` | `SessionState` | The session's state. Output only. One of `idle`, `running`, `awaiting_approval`, `awaiting_client`, `failed`. |
| `turn_count` | `int64` | The number of turns started, from 0. Output only. |
| `last_event_sequence` | `int64` | The sequence of the newest event, from 0. Output only. |
| `create_time` | `timestamp` | When the session was created. Output only. |
| `update_time` | `timestamp` | When the last event was appended. Output only. |
| `usage` | `SessionUsage` | What the session has used so far. Output only. |
| `environment_lease` | `string` | The Sylphx Sandboxes lease attached to the session, while it has one. Output only. |
| `environment` | `EnvironmentSpec` | The environment for this session; when omitted, use the pinned Agent version's default. An explicit value replaces that default. |
| `credentials` | `map<string, CredentialBinding>` | Session-scoped credential bindings, keyed by the tool or MCP credential name. Values are references or opaque handles, never secret values. |
| `profiles` | `ProfileMount[]` | Granted platform Profiles to mount when the session starts, each by resource name and mode. The runtime never puts profile values in events. |

### SessionEvent

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/projects/{project}/envs/{env}/agent_sessions/{agent_session}/session_events/{session_event}`. |
| `uid` | `string` | `sevt_<cell><ulid>`; never reused. Output only. |
| `meta` | `ResourceMeta` | Resource metadata. |
| `sequence` | `int64` | The position in the session's log, from 1, with no gaps. Output only. |
| `type` | `SessionEventType` | What the event is. Output only. One of `user_message`, `steer`, `agent_message`, `tool_call`, `tool_result`, `approval_requested`, `approval_decided`, `status`, `compaction`, `thought`, `file_change`, `response`, `error`. |
| `turn` | `int64` | The turn it belongs to, from 1; 0 for an event outside a turn. Output only. |
| `step` | `int64` | The step within the turn, from 1, assigned by the runtime; 0 for an event that is not a step. Output only. |
| `create_time` | `timestamp` | When it was appended. Output only. |
| `message` | `Message` | For USER_MESSAGE, STEER and AGENT_MESSAGE. One of the `payload` group. |
| `tool_call` | `ToolCall` | For TOOL_CALL. One of the `payload` group. |
| `tool_result` | `ToolResult` | For TOOL_RESULT. One of the `payload` group. |
| `approval` | `Approval` | For APPROVAL_REQUESTED and APPROVAL_DECIDED. One of the `payload` group. |
| `status_change` | `StatusChange` | For STATUS. One of the `payload` group. |
| `thought` | `Message` | For THOUGHT: a reasoning summary, never private model reasoning. One of the `payload` group. |
| `file_change` | `FileChange` | For FILE_CHANGE. One of the `payload` group. |
| `response` | `TurnResult` | For RESPONSE: the completed turn's answer and usage. One of the `payload` group. |
| `error` | `ErrorEvent` | For ERROR. One of the `payload` group. |

### ResourceMeta

| Field | Type | What it is |
| --- | --- | --- |
| `generation` | `int64` | Increases by one on every change to `spec`. Output only. |
| `etag` | `string` | Strong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as `If-Match` or `etag` to make Update and Delete conditional; a mismatch fails with ABORTED / 409 `ETAG_MISMATCH`. Output only. |
| `create_time` | `timestamp` | When the Resource was created. Output only. |
| `update_time` | `timestamp` | When the Resource last changed. Output only. |
| `delete_time` | `timestamp` | Set while the Resource is being deleted. Output only. |
| `labels` | `map<string, string>` | Caller-writable, indexed labels (AIP-122 label rules). |
| `annotations` | `map<string, string>` | Caller-writable, unindexed annotations. |
| `display_name` | `string` | Caller-writable human-readable name. |
| `creator` | `string` | The principal that created the Resource. Output only. |

### SessionUsage

| Field | Type | What it is |
| --- | --- | --- |
| `active_turn_duration` | `duration` | Time turns were active. Output only. |
| `gateway_calls` | `int64` | Tool calls made through the gateway. Output only. |
| `spend_micros` | `int64` | Spend so far in micro-USD, models and tools together. Output only. |

### EnvironmentSpec

| Field | Type | What it is |
| --- | --- | --- |
| `shape` | `string` | A Sylphx Sandboxes shape; empty gives sessions no environment. |
| `idle_standby` | `duration` | Put the environment in standby after this long idle, 1m to 24h; default 10m. |
| `template` | `string` | The Sandboxes image: `template:<name>` or an artifact image by digest, passed unchanged to the lease's `image` field. |
| `repo` | `RepositorySpec` | The repository to prepare inside the fresh lease, if any. |
| `egress` | `LeaseNetwork` | The lease's outbound policy, using the Sandboxes network contract. |
| `budget` | `LeaseBudget` | The lease's CPU and cost ceiling, separate from model and tool spend. |
| `ttl` | `duration` | The lease's maximum wall time, passed to Sandboxes as `ttl`. The lease is released when the session ends even if this bound has not been reached. |

### CredentialBinding

| Field | Type | What it is |
| --- | --- | --- |
| `secret` | `string` | A Kernel Secret of this environment, by name. One of the `source` group. |
| `connection` | `string` | A Kernel Connection (a third-party OAuth installation), by name. One of the `source` group. |
| `end_user_provider` | `string` | The end user's own grant in Sylphx Auth's agent token vault, by provider id; the session's end user must hold it. One of the `source` group. |
| `placement` | `string` | How the value is sent: `bearer` (default), `header:<Name>` or `query:<name>`. |
| `handle` | `string` | An opaque credential handle issued for this session, resolved only at egress. This is never a credential value. Never returned again. One of the `source` group. |

### ProfileMount

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/projects/{project}/envs/{env}/profiles/{profile}`. Required. |
| `mode` | `string` | `read_only` (default) or `write_back`. Only a write_back grant saves changes at session end while its lease still answers; empty is read_only. |

### Message

| Field | Type | What it is |
| --- | --- | --- |
| `parts` | `ContentPart[]` | The content, in order; 1 to 64 parts. Required. |

### ToolCall

| Field | Type | What it is |
| --- | --- | --- |
| `id` | `string` | The call's id within the session, `(turn, step)` based. Output only. |
| `tool` | `string` | The tool name. Output only. |
| `input` | `struct` | The input, as the model sent it. Output only. |
| `model_call_id` | `string` | The model's own id for the call, as sent; never used as a key. Output only. |
| `client` | `bool` | Whether the client runs it (a ClientTool). Output only. |

### ToolResult

| Field | Type | What it is |
| --- | --- | --- |
| `call_id` | `string` | The ToolCall's `id`. Output only. |
| `output` | `value` | The output. Output only. |
| `error` | `bool` | Whether the call failed; `output` then holds the error. Output only. |
| `duration` | `duration` | How long the call took. Output only. |

### Approval

| Field | Type | What it is |
| --- | --- | --- |
| `call_id` | `string` | The ToolCall's `id`. Output only. |
| `decision` | `ApprovalDecision` | The answer, once given; unset while it waits. Output only. One of `approve`, `reject`. |
| `remember` | `bool` | Whether the answer covers later calls of the same tool in this session ("always allow"). Output only. |
| `principal` | `string` | Who answered. Output only. |
| `reason` | `string` | The reason given, if any. Output only. |

### StatusChange

| Field | Type | What it is |
| --- | --- | --- |
| `state` | `SessionState` | The state after the change. Output only. One of `idle`, `running`, `awaiting_approval`, `awaiting_client`, `failed`. |
| `reason` | `string` | Why, for FAILED and INTERRUPTED: a registry error code and message. Output only. |

### FileChange

| Field | Type | What it is |
| --- | --- | --- |
| `path` | `string` | The path relative to the session's repository root. Output only. |
| `change` | `string` | `added`, `modified`, `deleted`, `renamed` or `copied`. Output only. |
| `added` | `int64` | Lines added, when reported by the harness. Output only. |
| `removed` | `int64` | Lines removed, when reported by the harness. Output only. |
| `old_path` | `string` | The previous path, for a rename or copy. Output only. |
| `source` | `string` | `edit` for an incremental edit or `final` for the turn's final diff. Output only. |

### TurnResult

| Field | Type | What it is |
| --- | --- | --- |
| `text` | `string` | The final response's text. Output only. |
| `is_error` | `bool` | Whether the turn ended with an error. Output only. |
| `usage` | `TurnTokenUsage` | Model token usage reported by the harness. Output only. |
| `cost_micros` | `int64` | The reported cost, in micro-USD. Output only. |
| `duration` | `duration` | How long the turn ran. Output only. |

### ErrorEvent

| Field | Type | What it is |
| --- | --- | --- |
| `kind` | `string` | The registry error code or harness error kind. Output only. |
| `message` | `string` | A safe error description. Output only. |

### RepositorySpec

| Field | Type | What it is |
| --- | --- | --- |
| `uri` | `string` | The repository URI. Access uses the session's bound credential handles. Required. |
| `revision` | `string` | The commit or ref to check out; empty uses the repository's default branch. |

### LeaseNetwork

| Field | Type | What it is |
| --- | --- | --- |
| `egress` | `EgressPolicy` | Default ALLOW. One of `allow`, `deny`, `allowlist`. |
| `allowed_domains` | `string[]` | Hosts reachable when `egress` is ALLOWLIST: exact names or one leading `*.` wildcard label, for example `api.openai.com`, `*.github.com`. |
| `allowed_cidrs` | `string[]` | Public CIDRs reachable when `egress` is ALLOWLIST. |
| `blocked_cidrs` | `string[]` | The ranges blocked under every policy. Output only. |

### LeaseBudget

| Field | Type | What it is |
| --- | --- | --- |
| `max_cpu_seconds` | `int64` | End CPU_BUDGET after this many vCPU-seconds of guest CPU time. |
| `max_cost_micros` | `int64` | End COST_BUDGET once the shape's list price times wall seconds reaches this many millionths of a US dollar. |

### ContentPart

| Field | Type | What it is |
| --- | --- | --- |
| `text` | `string` | Text. One of the `part` group. |
| `file` | `FileRef` | A file, by Sylphx Data object URL or an https URL. One of the `part` group. |

### TurnTokenUsage

| Field | Type | What it is |
| --- | --- | --- |
| `input_tokens` | `int64` | Input tokens. Output only. |
| `output_tokens` | `int64` | Output tokens. Output only. |
| `cache_read_tokens` | `int64` | Input tokens read from the model's cache. Output only. |
| `cache_write_tokens` | `int64` | Input tokens written to the model's cache. Output only. |

## Errors

- [`UNAUTHENTICATED`](/docs/api/errors/UNAUTHENTICATED) — No valid key or token was presented.
- [`PERMISSION_DENIED`](/docs/api/errors/PERMISSION_DENIED) — The key lacks the method's permission.
- [`INVALID_FIELD`](/docs/api/errors/INVALID_FIELD) — A field failed validation.
- [`RESOURCE_ALREADY_EXISTS`](/docs/api/errors/RESOURCE_ALREADY_EXISTS) — A Resource with this name exists.
- [`IDEMPOTENCY_KEY_REUSED`](/docs/api/errors/IDEMPOTENCY_KEY_REUSED) — An Idempotency-Key was reused with another body.
- [`IDEMPOTENCY_IN_PROGRESS`](/docs/api/errors/IDEMPOTENCY_IN_PROGRESS) — The first call with this Idempotency-Key is still running.
- [`PLAN_LIMIT_REACHED`](/docs/api/errors/PLAN_LIMIT_REACHED) — The plan's limit is reached.
- [`SPEND_LIMIT_REACHED`](/docs/api/errors/SPEND_LIMIT_REACHED) — The org's spend limit is reached.

Every error arrives in the body [Errors](/docs/platform/errors) describes.

## Examples

**cURL**

```curl
curl -X POST "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/agents/agent:run" \
  -H "Authorization: Bearer $SYLPHX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"agent_session_id":"…","agent_version":"…","completion":{"tool":"…"},"environment":{},"message":{"parts":[{}]},"runtime_credential_handle":"…"}'
```

**TypeScript**

```ts
const response = await sylphx.agents.agents.run({ agentSessionId: '…', agentVersion: '…', completion: { tool: '…' }, environment: {}, message: { parts: [{}] }, name: 'orgs/acme/projects/shop/envs/production/agents/agent', runtimeCredentialHandle: '…' })
```

**Rust**

```rust
let mut req = sylphx::agents::RunAgentRequest::default();
req.agent_session_id = "…".to_string();
req.agent_version = "…".to_string();
req.completion = Some(sylphx::agents::CompletionCall {
    tool: "…".to_string(),
    ..Default::default()
});
req.environment = Some(Default::default());
req.message = Some(sylphx::agents::Message {
    parts: vec![Default::default()],
    ..Default::default()
});
req.name = "orgs/acme/projects/shop/envs/production/agents/agent".to_string();
req.runtime_credential_handle = "…".to_string();
let response = sx.agents().agents().run(req).await?;
```

**CLI**

```bash
sylphx agents agents run orgs/acme/projects/shop/envs/production/agents/agent
```

**MCP**

```json
{ "method_id": "agents.agents.run", "args": {"agent_session_id":"…","agent_version":"…","completion":{"tool":"…"},"environment":{},"message":{"parts":[{}]},"name":"orgs/acme/projects/shop/envs/production/agents/agent","runtime_credential_handle":"…"} }
```
