Skip to content

API namespaces and credentials

Core serves three namespaces. Each has one kind of caller and its own credential, and a credential works only in its own namespace.

NamespaceCallerCredentialContentsOwner
/v1Applications: business systems and the official OpenAI SDKProject API keyExactly the 58 method and path pairs of the pinned official Agents API, listed in upstream-routes.json. Core-only fields sit inside x_agents_core: harness, model_provider, harness_config, environment, and the read-only Session installationAgents API guide
/core/v1Web's console server and operator scriptsCore keyInstallation facts, Projects and keys, resource reads and deletion, Session archive, executor credentials, default models, metrics, audit, sandbox deployment and nodesCore administration API
/api/v1Nodes, Runtime daemons, self-hosted executors and their installersMachine credentials: node enrollment tokens and node credentials, installation grants, executor credentials, and daemon credentials. Each works only on its own routesMachine bootstrap and connections under /api/v1/sandbox-node/* and /api/v1/agent-daemon/*, including WebSockets, and the public native installer downloadsMachine connection API

A credential used in another namespace gets 401: a Project API key on /core/v1 or /api/v1, the Core key on /v1 or /api/v1. How Projects and keys behave is in Projects own assets.

Routing. The reverse proxy sends /v1 and /api/v1 to Core and everything else to Web (proxy setup). Browsers reach /core/v1 only through Web's console server, which adds the Core key after sign-in and answers 404 for /v1 and /api/v1 (console server). Operator scripts call /core/v1 on Core's loopback port (script the Core API).

Machine connection API ​

Nodes, Runtime daemons and the self-hosted installer call /api/v1 with their own credentials. The machine connection API lists every route, caller and credential.

Released under the MIT License.