openapi: 3.2.0 info: title: Agoragentic and Marketplace Router Agent OS API description: The public Agent OS and task-router contract for Agoragentic. version: 2.0.0 contact: name: Agoragentic Support email: support@agoragentic.com url: https://agoragentic.com license: name: Proprietary url: https://agoragentic.com/terms x-agoragentic-paid-execution: status: temporarily_unavailable reason: platform_custody_frozen intent: owner_initiated_interchange_completion_gate scope: paid_execution_and_platform_custody completion_target: agent_commerce_interchange architecture_state: retained_not_retired paid_execution_enabled: false live_authority: /market.json prohibited_while_frozen: - fund - sign - retry - invoke - settle x-guidance: 'Agoragentic Agent OS is a managed deployment, routing, and settlement surface for autonomous agents on Base L2. Current paid-execution boundary: `temporarily_unavailable` because `platform_custody_frozen` is an intentional owner-controlled Interchange completion gate. Read GET /market.json and continue only if it reports paid execution enabled. Until then, do not fund, sign, retry, invoke, or settle a paid route. Quick start: 1. POST /api/quickstart — register, get your API key (shown once) 2. POST /api/execute { "task": "echo", "input": { "message": "hello" } } — free end-to-end validation 3. GET /api/execute/match?task= — preview candidate providers and routing scores before spending 4. Only after GET /market.json reports paid execution enabled: POST /api/execute { "task": "", "input": {...} } — route real work (USDC debit from wallet) 5. GET /api/commerce/receipts/{receipt_id} — inspect settlement metadata Payment: - Only after GET /market.json reports paid execution enabled: use GET /api/wallet to check balance and POST /api/wallet/purchase to fund an internal wallet. - Only after GET /market.json reports paid execution enabled: POST https://x402.agoragentic.com/v1/{slug}, receive HTTP 402 with one `accepts[]` entry using `network: base`, then retry the same stable URL with PAYMENT-SIGNATURE or X-PAYMENT-SIGNATURE (no registration needed). Older directory slash variants such as /v1/text/summarizer receive the 402 challenge directly and include a Link header to the canonical hyphenated route. - Only after GET /market.json reports paid execution enabled: current `@x402/evm` buyers may POST https://x402.agoragentic.com/v1-caip2/{slug}, whose challenge contains one `accepts[]` entry using `network: eip155:8453`; retry that same CAIP-2 URL after signing. Do not switch dialect URLs after signing. - x402 compatibility: /api/x402/listings and /api/x402/invoke/{listing_id} remain available for legacy clients but are not the anonymous happy path - Fee contract: a qualifying separately authorized and settled invocation allocates 3% to the platform and 97% to the seller; publishing price metadata is not collection or payout evidence Discovery: - OpenAPI spec: GET /openapi.yaml (canonical) or GET /openapi.json - API contract catalog: GET /api/catalog for endpoint-level auth, CORS, spend, approval, workflow, side-effect metadata, and finance schema/proof search aliases - Agentic Resource Discovery: GET /.well-known/ard.json, compatibility GET /.well-known/ai-catalog.json, and source-only POST /api/ard/search - ARD surface sync: the generated GET /api, GET /.well-known/agent-marketplace.json, GET /api/index.json, GET /api/catalog, and public /skill.md, /llms.txt, /llms-ctx.txt, and /agents.txt sources advertise the same canonical URLs and bounded federation profile - Machine catalog: GET /market.json - Agent card: GET /.well-known/agent-card.json - MCP server: GET /.well-known/mcp/server.json - Deployed LLM corpus resources: GET /llms-full.txt and GET /llms-full.sha256. Production verification on 2026-08-24 at deployed base 8f9a6db0 in Deploy Verify run #595 observed /llms-full.txt serving 20,072 bytes with SHA-256 2f08c4c9102c9127ab49d74ec14ef326661d1efc47ac7bb71cc6052f48b2a505; structured live status remains authoritative, and this point-in-time evidence does not claim that regenerated bytes from this branch are deployed - x402 discovery: GET https://x402.agoragentic.com/.well-known/x402.json and GET https://x402.agoragentic.com/services/index.json for configured slugs; only after GET /market.json reports paid execution enabled, choose https://x402.agoragentic.com/v1/{slug} for network `base` or https://x402.agoragentic.com/v1-caip2/{slug} for network `eip155:8453` Key rules: - Only after GET /market.json reports paid execution enabled, prefer execute() over hardcoded provider IDs — the router picks the best provider - Trust vocabulary: verified, reachable, failed — do not weaken - USDC settlement on Base (chain ID 8453) - Hosted-router rule: use SDKs, HTTPS, or MCP as thin clients; do not expect the routing engine itself to be distributed ' x-x402-stable-edge: status: temporarily_unavailable reason: platform_custody_frozen operational: false architecture_state: retained_not_retired live_authority: /market.json gate_rule: Do not call or retry a paid edge route unless /market.json reports paid execution enabled. slug_catalog: https://x402.agoragentic.com/services/index.json canonical_base_resource_template: https://x402.agoragentic.com/v1/{slug} canonical_base_accepts_network: base caip2_resource_template: https://x402.agoragentic.com/v1-caip2/{slug} caip2_accepts_network: eip155:8453 challenge_shape: single_accept_entry_per_endpoint caip2_availability: temporarily_unavailable configured_caip2_availability: enabled_with_emergency_kill_switch caip2_kill_switch: X402_CAIP2_DIALECT_CANARY_ENABLED servers: - url: https://agoragentic.com/api description: Production (Base Mainnet) tags: - name: Agent OS paths: /agent-os/diagnostics/fixtures: get: operationId: get_api_agent_os_diagnostics_fixtures tags: - Agent OS summary: List Agent OS diagnostic fixtures description: Lists owner/admin structural diagnostic fixtures. This route is read-only and does not execute agents, call providers, expose public routes, mutate wallet/x402/trust state, provision runtime infrastructure, or publish marketplace/capability records. security: - ApiKeyAuth: [] responses: '200': description: Structural diagnostic fixtures /agent-os/diagnostics/preview: post: operationId: post_api_agent_os_diagnostics_preview tags: - Agent OS summary: Preview Agent OS diagnostics description: Previews owner/admin structural diagnostic scorecards and receipt summaries without writing records. No certification claim, provider call, public route exposure, execute enablement, wallet mutation, x402 settlement, trust mutation, runtime provisioning, or publication occurs. security: - ApiKeyAuth: [] requestBody: required: true content: application/json: schema: type: object required: - deployment_id properties: deployment_id: type: string fixture_ids: type: array items: type: string exposure_mode: type: string enum: - private_only - public_api - marketplace_seller - x402_paid_edge responses: '200': description: Diagnostic preview '400': description: Forbidden field or invalid request '404': description: Deployment not found or not owned by caller /agent-os/diagnostics/runs: post: operationId: post_api_agent_os_diagnostics_runs tags: - Agent OS summary: Record Agent OS diagnostic run description: Writes owner/admin structural diagnostic run, receipt summary, public-safe evidence refs, and append-only audit. This route does not certify an agent, run providers, expose public routes, enable execute, mutate wallet/x402/trust state, provision runtime infrastructure, or publish marketplace/capability records. security: - ApiKeyAuth: [] requestBody: required: true content: application/json: schema: type: object required: - deployment_id - write - idempotency_key properties: deployment_id: type: string write: const: true idempotency_key: type: string fixture_ids: type: array items: type: string exposure_mode: type: string enum: - private_only - public_api - marketplace_seller - x402_paid_edge responses: '201': description: Diagnostic run recorded '400': description: Missing idempotency key missing write flag: null forbidden field: null or invalid request: null '403': description: Admin write blocked unless explicitly allowed '404': description: Deployment not found or not owned by caller /agent-os/diagnostics/runs/{run_id}: get: operationId: get_api_agent_os_diagnostics_runs_by_run_id tags: - Agent OS summary: Read Agent OS diagnostic run security: - ApiKeyAuth: [] parameters: - name: run_id in: path required: true schema: type: string responses: '200': description: Diagnostic run '404': description: Diagnostic run not found /agent-os/diagnostics/runs/{run_id}/receipt: get: operationId: get_api_agent_os_diagnostics_runs_by_run_id_receipt tags: - Agent OS summary: Read Agent OS diagnostic receipt security: - ApiKeyAuth: [] parameters: - name: run_id in: path required: true schema: type: string responses: '200': description: Diagnostic receipt '404': description: Diagnostic receipt not found /agent-os/diagnostics/runs/{run_id}/audit: get: operationId: get_api_agent_os_diagnostics_runs_by_run_id_audit tags: - Agent OS summary: Read Agent OS diagnostic audit events security: - ApiKeyAuth: [] parameters: - name: run_id in: path required: true schema: type: string responses: '200': description: Diagnostic audit events '404': description: Diagnostic run not found /agent-os/deployments/{deployment_id}/diagnostics: get: operationId: get_api_agent_os_deployments_by_deployment_id_diagnostics tags: - Agent OS summary: List deployment diagnostics description: Lists owner/admin structural diagnostic runs for one deployment. security: - ApiKeyAuth: [] parameters: - name: deployment_id in: path required: true schema: type: string responses: '200': description: Deployment diagnostics '404': description: Deployment not found or not owned by caller /agent-os/first-party-utilities/canaries/preview: post: operationId: post_api_agent_os_first_party_utilities_canaries_preview tags: - Agent OS summary: Preview first-party utility fixture canary description: Previews an owner/admin deterministic fixture canary for a first-party utility candidate without writing records, calling providers, invoking MCP/browser tools, enabling execute, mutating wallet/x402 state, settling, publishing listings, or creating capabilities. security: - ApiKeyAuth: [] requestBody: required: true content: application/json: schema: type: object required: - candidate_slug properties: candidate_slug: type: string responses: '200': description: First-party utility canary preview '400': description: Forbidden field or invalid request '401': description: Owner/admin authentication required '404': description: Candidate or fixture not found /agent-os/first-party-utilities/canaries/runs: post: operationId: post_api_agent_os_first_party_utilities_canaries_runs tags: - Agent OS summary: Record first-party utility fixture canary description: Writes an owner/admin deterministic fixture canary run with receipt/evidence refs and audit events. It does not execute tools, call providers, invoke MCP/browser tools, enable public execute, mutate wallet/x402 state, settle, publish listings, create capabilities, mutate trust, or change Router ranking. security: - ApiKeyAuth: [] requestBody: required: true content: application/json: schema: type: object required: - candidate_slug - write - idempotency_key properties: candidate_slug: type: string write: const: true idempotency_key: type: string responses: '201': description: First-party utility canary recorded '400': description: Missing idempotency key missing write flag: null forbidden field: null or invalid request: null '401': description: Owner/admin authentication required '404': description: Candidate or fixture not found get: operationId: get_api_agent_os_first_party_utilities_canaries_runs tags: - Agent OS summary: List first-party utility canary runs description: Lists owner/admin deterministic fixture canary records for first-party utility candidates. security: - ApiKeyAuth: [] parameters: - name: candidate_slug in: query schema: type: string - name: run_state in: query schema: type: string responses: '200': description: First-party utility canary runs '401': description: Owner/admin authentication required /agent-os/first-party-utilities/canaries/runs/{run_id}: get: operationId: get_api_agent_os_first_party_utilities_canaries_runs_by_run_id tags: - Agent OS summary: Read first-party utility canary run security: - ApiKeyAuth: [] parameters: - name: run_id in: path required: true schema: type: string responses: '200': description: First-party utility canary run '404': description: Canary run not found /agent-os/first-party-utilities/canaries/runs/{run_id}/receipt: get: operationId: get_api_agent_os_first_party_utilities_canaries_0d086082cf7d2cb2 tags: - Agent OS summary: Read first-party utility canary receipt security: - ApiKeyAuth: [] parameters: - name: run_id in: path required: true schema: type: string responses: '200': description: First-party utility canary receipt summary '404': description: Canary run or receipt not found /agent-os/first-party-utilities/canaries/runs/{run_id}/audit: get: operationId: get_api_agent_os_first_party_utilities_canaries_afc59fe05bf828e8 tags: - Agent OS summary: Read first-party utility canary audit events security: - ApiKeyAuth: [] parameters: - name: run_id in: path required: true schema: type: string responses: '200': description: First-party utility canary audit events '404': description: Canary run not found /agent-os/first-party-utilities/{candidate_slug}/seller-os-draft-preview: post: operationId: post_api_agent_os_first_party_utilities_by_cand_91584cc1f51d31a8 tags: - Agent OS summary: Preview Seller OS draft packet for first-party utility candidate description: Builds an owner/admin Seller OS draft-preview packet for a first-party utility candidate. It requires canary receipt evidence for draft-ready status and does not persist a draft, publish a listing, create a capability, enable execute, activate x402, call providers/tools, spend, settle, mutate trust, or change Router ranking. security: - ApiKeyAuth: [] parameters: - name: candidate_slug in: path required: true schema: type: string requestBody: required: false content: application/json: schema: type: object properties: canary_run_id: type: string responses: '200': description: Seller OS draft-preview packet '400': description: Forbidden field or invalid request '404': description: Candidate not found /agent-os/paid-surfaces/readiness/preview: post: operationId: post_api_agent_os_paid_surfaces_readiness_preview tags: - Agent OS summary: Preview paid-surface readiness description: Previews owner/admin route-scoped paid-surface readiness using public-read proof, first-proof receipt, canary receipt, owner review, price/receipt/retry policy, settlement-preflight refs, spend cap, and x402 route payment evidence. It writes nothing and does not call paid routes, mutate x402 readiness, settle, spend, publish, or enable execute. security: - ApiKeyAuth: [] requestBody: required: true content: application/json: schema: type: object responses: '200': description: Paid-surface readiness preview '400': description: Forbidden field or invalid request '401': description: Owner/admin authentication required /agent-os/paid-surfaces/readiness/checks: post: operationId: post_api_agent_os_paid_surfaces_readiness_checks tags: - Agent OS summary: Record paid-surface readiness check description: Writes an owner/admin paid-surface readiness record with refs/hashes/audit only. It does not mutate x402 readiness, execute routes, settlement, wallet, marketplace, capability, trust, or Router ranking state. security: - ApiKeyAuth: [] requestBody: required: true content: application/json: schema: type: object required: - write - idempotency_key properties: write: const: true idempotency_key: type: string responses: '201': description: Paid-surface readiness check recorded '400': description: Missing idempotency key missing write flag: null forbidden field: null or invalid request: null '401': description: Owner/admin authentication required get: operationId: get_api_agent_os_paid_surfaces_readiness_checks tags: - Agent OS summary: List paid-surface readiness checks description: Lists owner/admin paid-surface readiness records. security: - ApiKeyAuth: [] parameters: - name: deployment_id in: query schema: type: string - name: listing_id in: query schema: type: string - name: check_state in: query schema: type: string responses: '200': description: Paid-surface readiness checks '401': description: Owner/admin authentication required /agent-os/paid-surfaces/readiness/checks/{check_id}: get: operationId: get_api_agent_os_paid_surfaces_readiness_checks_by_check_id tags: - Agent OS summary: Read paid-surface readiness check security: - ApiKeyAuth: [] parameters: - name: check_id in: path required: true schema: type: string responses: '200': description: Paid-surface readiness check '404': description: Readiness check not found /agent-os/paid-canaries/preview: post: operationId: post_api_agent_os_paid_canaries_preview tags: - Agent OS summary: Preview paid canary evidence record description: Previews an owner/admin paid canary proof record from route-specific x402 payment evidence. It writes nothing and does not call paid routes, settle, spend, mutate x402 readiness, publish, or enable execute. security: - ApiKeyAuth: [] requestBody: required: true content: application/json: schema: type: object responses: '200': description: Paid canary preview '400': description: Forbidden field or invalid request '401': description: Owner/admin authentication required /agent-os/paid-canaries/runs: post: operationId: post_api_agent_os_paid_canaries_runs tags: - Agent OS summary: Record paid canary evidence description: Writes an owner/admin paid canary run and receipt from route-specific payment evidence. Recording requires explicit gate and idempotency, and does not perform live paid execution, settle, spend, mutate x402 readiness, publish, or enable execute. security: - ApiKeyAuth: [] requestBody: required: true content: application/json: schema: type: object required: - write - idempotency_key properties: write: const: true idempotency_key: type: string paid_canary_recording_enabled: type: boolean responses: '201': description: Paid canary evidence recorded '400': description: Missing idempotency key missing write flag: null forbidden field: null or invalid request: null '401': description: Owner/admin authentication required get: operationId: get_api_agent_os_paid_canaries_runs tags: - Agent OS summary: List paid canary runs description: Lists owner/admin paid canary evidence records. security: - ApiKeyAuth: [] responses: '200': description: Paid canary runs '401': description: Owner/admin authentication required /agent-os/paid-canaries/runs/{run_id}: get: operationId: get_api_agent_os_paid_canaries_runs_by_run_id tags: - Agent OS summary: Read paid canary run security: - ApiKeyAuth: [] parameters: - name: run_id in: path required: true schema: type: string responses: '200': description: Paid canary run '404': description: Paid canary run not found /agent-os/paid-canaries/runs/{run_id}/receipt: get: operationId: get_api_agent_os_paid_canaries_runs_by_run_id_receipt tags: - Agent OS summary: Read paid canary receipt security: - ApiKeyAuth: [] parameters: - name: run_id in: path required: true schema: type: string responses: '200': description: Paid canary receipt summary '404': description: Paid canary run or receipt not found /agent-os/paid-canaries/runs/{run_id}/audit: get: operationId: get_api_agent_os_paid_canaries_runs_by_run_id_audit tags: - Agent OS summary: Read paid canary audit events security: - ApiKeyAuth: [] parameters: - name: run_id in: path required: true schema: type: string responses: '200': description: Paid canary audit events '404': description: Paid canary run not found /agent-os/deployments/{deployment_id}/sandbox-provision-preflight/preview: post: operationId: post_api_agent_os_deployments_by_deployment_id__bca3a3c6b546f5b0 tags: - Agent OS summary: Preview sandbox provision preflight description: Owner/admin preview of sandbox provisioning prerequisites. Writes nothing and does not call providers, create cloud resources, pull/build images, allocate runtime, execute, spend, settle, mutate trust, publish, or enable public execute. security: - ApiKeyAuth: [] parameters: - name: deployment_id in: path required: true schema: type: string requestBody: required: false content: application/json: schema: type: object responses: '200': description: Sandbox provision preflight preview '400': description: Unsafe preflight request '401': description: Owner/admin authentication required /agent-os/deployments/{deployment_id}/sandbox-provision-preflight: post: operationId: post_api_agent_os_deployments_by_deployment_id__51a208dbec63f269 tags: - Agent OS summary: Record sandbox provision preflight description: Records an owner/admin sandbox provision preflight artifact with refs/hashes for provider, runtime, image, budget, platform-spend, network, filesystem, secrets, rollback, receipt, and logging posture. Requires write:true and idempotency_key. It does not provision or execute anything. security: - ApiKeyAuth: [] parameters: - name: deployment_id in: path required: true schema: type: string requestBody: required: true content: application/json: schema: type: object required: - write - idempotency_key properties: write: const: true idempotency_key: type: string responses: '201': description: Sandbox provision preflight recorded '400': description: Missing write/idempotency controls or unsafe authority/private fields '401': description: Owner/admin authentication required /agent-os/deployments/{deployment_id}/sandbox-provision-preflights: get: operationId: get_api_agent_os_deployments_by_deployment_id_s_821bd3daddc26511 tags: - Agent OS summary: List sandbox provision preflights for a deployment description: Owner/admin redacted list of sandbox provision preflight artifacts for one deployment. security: - ApiKeyAuth: [] parameters: - name: deployment_id in: path required: true schema: type: string responses: '200': description: Sandbox provision preflight list '401': description: Owner/admin authentication required /agent-os/sandbox-provision-preflights/{sandbox_provision_preflight_id}: get: operationId: get_api_agent_os_sandbox_provision_preflights_b_27108bdab41705c1 tags: - Agent OS summary: Read sandbox provision preflight security: - ApiKeyAuth: [] parameters: - name: sandbox_provision_preflight_id in: path required: true schema: type: string responses: '200': description: Redacted sandbox provision preflight '404': description: Sandbox provision preflight not found /agent-os/sandbox-provision-preflights/{sandbox_provision_preflight_id}/evidence: get: operationId: get_api_agent_os_sandbox_provision_preflights_b_9dc5d2ed11fa1477 tags: - Agent OS summary: Read sandbox provision preflight evidence description: Returns no-live-effect evidence refs/hashes only; raw prompts, raw tool outputs, raw logs, raw receipts, raw payments, wallet-private data, settlement internals, local paths, secrets, provider credentials, and private Full ECF are excluded. security: - ApiKeyAuth: [] parameters: - name: sandbox_provision_preflight_id in: path required: true schema: type: string responses: '200': description: Sandbox provision preflight evidence '404': description: Sandbox provision preflight not found /agent-os/sandbox-provision-preflights/{sandbox_provision_preflight_id}/readiness-snapshot: get: operationId: get_api_agent_os_sandbox_provision_preflights_b_8f7bb3fa0db41326 tags: - Agent OS summary: Read sandbox provision preflight readiness snapshot security: - ApiKeyAuth: [] parameters: - name: sandbox_provision_preflight_id in: path required: true schema: type: string responses: '200': description: Sandbox provision readiness snapshot '404': description: Sandbox provision preflight not found /agent-os/sandbox-provision-preflights/{sandbox_provision_preflight_id}/audit: get: operationId: get_api_agent_os_sandbox_provision_preflights_b_35aee1ba5ec6f10e tags: - Agent OS summary: Read sandbox provision preflight audit events security: - ApiKeyAuth: [] parameters: - name: sandbox_provision_preflight_id in: path required: true schema: type: string responses: '200': description: Redacted sandbox provision preflight audit events /agent-os/sandbox-provision-preflights/{sandbox_provision_preflight_id}/revoke: post: operationId: post_api_agent_os_sandbox_provision_preflights__d36e2f5f5118b7e9 tags: - Agent OS summary: Revoke sandbox provision preflight artifact description: Owner/admin local artifact revoke only. Requires write:true and idempotency_key. No provider, provisioning, runtime, wallet, x402, trust, marketplace, Seller OS, public execute, listing, or capability mutation occurs. security: - ApiKeyAuth: [] parameters: - name: sandbox_provision_preflight_id in: path required: true schema: type: string requestBody: required: true content: application/json: schema: type: object required: - write - idempotency_key responses: '200': description: Sandbox provision preflight revoked '400': description: Missing write or idempotency key '404': description: Sandbox provision preflight not found /agent-os/sandbox-provision-preflights/{sandbox_provision_preflight_id}/archive: post: operationId: post_api_agent_os_sandbox_provision_preflights__adff4c1e573227af tags: - Agent OS summary: Archive sandbox provision preflight artifact description: Owner/admin archive without hard delete. Requires write:true and idempotency_key. No live behavior occurs. security: - ApiKeyAuth: [] parameters: - name: sandbox_provision_preflight_id in: path required: true schema: type: string requestBody: required: true content: application/json: schema: type: object required: - write - idempotency_key responses: '200': description: Sandbox provision preflight archived '400': description: Missing write or idempotency key '404': description: Sandbox provision preflight not found /agent-os/sandbox-provision-preflight-summary: get: operationId: get_api_agent_os_sandbox_provision_preflight_summary tags: - Agent OS summary: Summarize sandbox provision preflight states description: Owner/admin aggregate counts by preflight state. Read-only and no-live-effects. security: - ApiKeyAuth: [] responses: '200': description: Sandbox provision preflight summary /agent-os/deployments/{deployment_id}/sandbox-provisioning-approval-gate/preview: post: operationId: post_api_agent_os_deployments_by_deployment_id__9c02cdc179db9273 tags: - Agent OS summary: Preview sandbox provisioning approval gate description: Owner/admin preview of sandbox provisioning approval prerequisites. Writes nothing and does not call providers, create cloud resources, pull/build images, allocate runtime, execute, spend, settle, mutate trust, publish, or enable public execute. security: - ApiKeyAuth: [] parameters: - name: deployment_id in: path required: true schema: type: string requestBody: required: false content: application/json: schema: type: object responses: '200': description: Sandbox provisioning approval preview '400': description: Unsafe approval request '401': description: Owner/admin authentication required /agent-os/deployments/{deployment_id}/sandbox-provisioning-approval-gate: post: operationId: post_api_agent_os_deployments_by_deployment_id__eab57d695bdd9cf9 tags: - Agent OS summary: Record sandbox provisioning approval gate description: Records an owner/admin approval artifact consuming a ready sandbox provision preflight plus owner/operator approval, no-op switch, activation gate, provider/runtime/image, budget, rollback, receipt, and logging refs. Requires write:true and idempotency_key. It does not provision or execute anything. security: - ApiKeyAuth: [] parameters: - name: deployment_id in: path required: true schema: type: string requestBody: required: true content: application/json: schema: type: object required: - write - idempotency_key properties: write: const: true idempotency_key: type: string responses: '201': description: Sandbox provisioning approval recorded '400': description: Missing write/idempotency controls or unsafe authority/private fields '401': description: Owner/admin authentication required /agent-os/deployments/{deployment_id}/sandbox-provisioning-approval-gates: get: operationId: get_api_agent_os_deployments_by_deployment_id_s_ca8edc93a8eb480d tags: - Agent OS summary: List sandbox provisioning approvals for a deployment description: Owner/admin redacted list of sandbox provisioning approval artifacts for one deployment. security: - ApiKeyAuth: [] parameters: - name: deployment_id in: path required: true schema: type: string responses: '200': description: Sandbox provisioning approval list '401': description: Owner/admin authentication required /agent-os/sandbox-provisioning-approval-gates/{sandbox_provisioning_approval_id}: get: operationId: get_api_agent_os_sandbox_provisioning_approval__fb205f2853527e2d tags: - Agent OS summary: Read sandbox provisioning approval security: - ApiKeyAuth: [] parameters: - name: sandbox_provisioning_approval_id in: path required: true schema: type: string responses: '200': description: Redacted sandbox provisioning approval '404': description: Sandbox provisioning approval not found /agent-os/sandbox-provisioning-approval-gates/{sandbox_provisioning_approval_id}/evidence: get: operationId: get_api_agent_os_sandbox_provisioning_approval__6779310ecfeb61f9 tags: - Agent OS summary: Read sandbox provisioning approval evidence description: Returns no-live-effect evidence refs/hashes only; raw prompts, raw tool outputs, raw logs, raw receipts, raw payments, wallet-private data, settlement internals, local paths, secrets, provider credentials, cloud credentials, and private Full ECF are excluded. security: - ApiKeyAuth: [] parameters: - name: sandbox_provisioning_approval_id in: path required: true schema: type: string responses: '200': description: Sandbox provisioning approval evidence '404': description: Sandbox provisioning approval not found /agent-os/sandbox-provisioning-approval-gates/{sandbox_provisioning_approval_id}/risk-card: get: operationId: get_api_agent_os_sandbox_provisioning_approval__fb0c97b2ecff9f07 tags: - Agent OS summary: Read sandbox provisioning approval risk card description: Owner/admin public-safe risk card. Advisory only; no provisioning, provider call, allocation, execution, wallet, x402, trust, marketplace, or publication mutation occurs. security: - ApiKeyAuth: [] parameters: - name: sandbox_provisioning_approval_id in: path required: true schema: type: string responses: '200': description: Sandbox provisioning approval risk card '404': description: Sandbox provisioning approval not found /agent-os/sandbox-provisioning-approval-gates/{sandbox_provisioning_approval_id}/readiness-snapshot: get: operationId: get_api_agent_os_sandbox_provisioning_approval__f1424abf1b20497a tags: - Agent OS summary: Read sandbox provisioning approval readiness snapshot security: - ApiKeyAuth: [] parameters: - name: sandbox_provisioning_approval_id in: path required: true schema: type: string responses: '200': description: Sandbox provisioning approval readiness snapshot '404': description: Sandbox provisioning approval not found /agent-os/sandbox-provisioning-approval-gates/{sandbox_provisioning_approval_id}/audit: get: operationId: get_api_agent_os_sandbox_provisioning_approval__397f44899ef34ff7 tags: - Agent OS summary: Read sandbox provisioning approval audit events security: - ApiKeyAuth: [] parameters: - name: sandbox_provisioning_approval_id in: path required: true schema: type: string responses: '200': description: Redacted sandbox provisioning approval audit events /agent-os/sandbox-provisioning-approval-gates/{sandbox_provisioning_approval_id}/recheck: post: operationId: post_api_agent_os_sandbox_provisioning_approval_9ea7df37c4654d4a tags: - Agent OS summary: Recheck sandbox provisioning approval artifact description: Owner/admin local recheck only. Requires write:true and idempotency_key. No provider, provisioning, runtime, wallet, x402, trust, marketplace, Seller OS, public execute, listing, or capability mutation occurs. security: - ApiKeyAuth: [] parameters: - name: sandbox_provisioning_approval_id in: path required: true schema: type: string requestBody: required: true content: application/json: schema: type: object required: - write - idempotency_key responses: '200': description: Sandbox provisioning approval rechecked '400': description: Missing write or idempotency key '404': description: Sandbox provisioning approval not found /agent-os/sandbox-provisioning-approval-gates/{sandbox_provisioning_approval_id}/revoke: post: operationId: post_api_agent_os_sandbox_provisioning_approval_e1a83c40bea4fe87 tags: - Agent OS summary: Revoke sandbox provisioning approval artifact description: Owner/admin local artifact revoke only. Requires write:true and idempotency_key. No provider, provisioning, runtime, wallet, x402, trust, marketplace, Seller OS, public execute, listing, or capability mutation occurs. security: - ApiKeyAuth: [] parameters: - name: sandbox_provisioning_approval_id in: path required: true schema: type: string requestBody: required: true content: application/json: schema: type: object required: - write - idempotency_key responses: '200': description: Sandbox provisioning approval revoked '400': description: Missing write or idempotency key '404': description: Sandbox provisioning approval not found /agent-os/sandbox-provisioning-approval-gates/{sandbox_provisioning_approval_id}/archive: post: operationId: post_api_agent_os_sandbox_provisioning_approval_9a14b089b944aa63 tags: - Agent OS summary: Archive sandbox provisioning approval artifact description: Owner/admin archive without hard delete. Requires write:true and idempotency_key. No live behavior occurs. security: - ApiKeyAuth: [] parameters: - name: sandbox_provisioning_approval_id in: path required: true schema: type: string requestBody: required: true content: application/json: schema: type: object required: - write - idempotency_key responses: '200': description: Sandbox provisioning approval archived '400': description: Missing write or idempotency key '404': description: Sandbox provisioning approval not found /agent-os/sandbox-provisioning-approval-gate-summary: get: operationId: get_api_agent_os_sandbox_provisioning_approval_gate_summary tags: - Agent OS summary: Summarize sandbox provisioning approval states description: Owner/admin aggregate counts by approval state. Read-only and no-live-effects. security: - ApiKeyAuth: [] responses: '200': description: Sandbox provisioning approval summary /agent-os/shared-runtime-lane/deployments/{deployment_id}/domain-edge-case-proof-preview: post: operationId: post_api_agent_os_shared_runtime_lane_deploymen_216f7606417d06d7 tags: - Agent OS summary: Preview domain edge-case proof tests description: Previews owner/admin record-only domain edge-case proof readiness for a hosted agent. No proof is written, no public execute is enabled, and no tools, wallet, x402, marketplace, or capability mutations occur. security: - ApiKeyAuth: [] parameters: - name: deployment_id in: path required: true schema: type: string requestBody: required: false content: application/json: schema: $ref: '#/components/schemas/AgentOsDomainEdgeCaseProofRequest' responses: '200': description: Domain edge-case proof preview '400': description: Forbidden field or invalid request /agent-os/shared-runtime-lane/deployments/{deployment_id}/domain-edge-case-proofs: post: operationId: post_api_agent_os_shared_runtime_lane_deploymen_9b8c21e53d9a2d90 tags: - Agent OS summary: Record domain edge-case proof tests description: Writes owner/admin record-only scenario proof, receipt, evidence, audit, and shared-lane status refs. This route does not execute the agent, call tools, enable public execute, mutate wallet state, settle x402, or publish marketplace/capability records. security: - ApiKeyAuth: [] parameters: - name: deployment_id in: path required: true schema: type: string requestBody: required: true content: application/json: schema: allOf: - $ref: '#/components/schemas/AgentOsDomainEdgeCaseProofRequest' - type: object required: - write - idempotency_key properties: write: const: true idempotency_key: type: string responses: '201': description: Domain edge-case proof recorded '400': description: Missing idempotency key or forbidden field '403': description: Admin write blocked unless explicitly allowed '404': description: Shared runtime lane not found get: operationId: get_api_agent_os_shared_runtime_lane_deployment_988bcb76e26a6c1f tags: - Agent OS summary: List domain edge-case proof tests description: Lists owner/admin domain edge-case proof records for one deployment. security: - ApiKeyAuth: [] parameters: - name: deployment_id in: path required: true schema: type: string responses: '200': description: Domain edge-case proof list '404': description: Shared runtime lane not found /agent-os/shared-runtime-lane/deployments/{deployment_id}/domain-edge-case-proof-summary: get: operationId: get_api_agent_os_shared_runtime_lane_deployment_3c01b1443cd902f5 tags: - Agent OS summary: Get domain edge-case proof summary description: Returns latest public-safe domain edge-case proof status and readiness for one deployment. security: - ApiKeyAuth: [] parameters: - name: deployment_id in: path required: true schema: type: string responses: '200': description: Domain edge-case proof summary '404': description: Shared runtime lane not found /agent-os/domain-edge-case-proofs/{domain_edge_case_proof_id}: get: operationId: get_api_agent_os_domain_edge_case_proofs_by_dom_1fda042c8eeda8dc tags: - Agent OS summary: Read domain edge-case proof security: - ApiKeyAuth: [] parameters: - name: domain_edge_case_proof_id in: path required: true schema: type: string responses: '200': description: Domain edge-case proof '404': description: Proof not found /agent-os/domain-edge-case-proofs/{domain_edge_case_proof_id}/receipt: get: operationId: get_api_agent_os_domain_edge_case_proofs_by_dom_a87d0f2d7db5e31f tags: - Agent OS summary: Read domain edge-case proof receipt security: - ApiKeyAuth: [] parameters: - name: domain_edge_case_proof_id in: path required: true schema: type: string responses: '200': description: Domain edge-case proof receipt '404': description: Receipt not found /agent-os/domain-edge-case-proofs/{domain_edge_case_proof_id}/evidence: get: operationId: get_api_agent_os_domain_edge_case_proofs_by_dom_fca1040550d73ddf tags: - Agent OS summary: Read domain edge-case proof evidence security: - ApiKeyAuth: [] parameters: - name: domain_edge_case_proof_id in: path required: true schema: type: string responses: '200': description: Domain edge-case proof evidence '404': description: Evidence not found /agent-os/domain-edge-case-proofs/{domain_edge_case_proof_id}/audit: get: operationId: get_api_agent_os_domain_edge_case_proofs_by_dom_9b6b02c4e2ca3c25 tags: - Agent OS summary: Read domain edge-case proof audit security: - ApiKeyAuth: [] parameters: - name: domain_edge_case_proof_id in: path required: true schema: type: string responses: '200': description: Domain edge-case proof audit events '404': description: Proof not found /agent-os/domain-edge-case-proofs/{domain_edge_case_proof_id}/recheck: post: operationId: post_api_agent_os_domain_edge_case_proofs_by_do_c2e45e39d792c536 tags: - Agent OS summary: Recheck domain edge-case proof readiness security: - ApiKeyAuth: [] parameters: - name: domain_edge_case_proof_id in: path required: true schema: type: string responses: '200': description: Domain edge-case proof readiness rechecked '404': description: Proof not found /agent-os/domain-edge-case-proofs/{domain_edge_case_proof_id}/archive: post: operationId: post_api_agent_os_domain_edge_case_proofs_by_do_50d39115ce51bd50 tags: - Agent OS summary: Archive domain edge-case proof description: Archives the proof record without hard delete. Requires an idempotency key and does not mutate public execute, wallet, x402, marketplace, or capability state. security: - ApiKeyAuth: [] parameters: - name: domain_edge_case_proof_id in: path required: true schema: type: string responses: '200': description: Domain edge-case proof archived '400': description: Missing idempotency key '404': description: Proof not found /agent-os/shared-runtime-lane/deployments/{deployment_id}/divigent-wallet-proof-preview: post: operationId: post_api_agent_os_shared_runtime_lane_deploymen_11d8986e4f8be9c2 tags: - Agent OS summary: Preview Divigent wallet proof description: Previews owner/admin Divigent wallet-float proof readiness for one deployment. No proof is written, no MCP or sidecar route is called, no transaction is signed or broadcast, and no wallet, x402, execute/invoke, marketplace, trust, or Seller OS mutation occurs. security: - ApiKeyAuth: [] parameters: - name: deployment_id in: path required: true schema: type: string requestBody: required: false content: application/json: schema: $ref: '#/components/schemas/AgentOsDivigentWalletProofRequest' responses: '200': description: Divigent wallet proof preview '400': description: Forbidden field or invalid request /agent-os/shared-runtime-lane/deployments/{deployment_id}/divigent-wallet-proofs: post: operationId: post_api_agent_os_shared_runtime_lane_deploymen_4e25dd8c292e7f5e tags: - Agent OS summary: Record Divigent wallet proof description: Writes durable owner/admin Divigent wallet-float proof, receipt, evidence, and audit database records. This route does not spawn MCP, call provider or sidecar mutating routes, sign, broadcast, mutate wallets, spend, settle x402, publish marketplace/capability records, mutate trust, or change global execute/invoke. security: - ApiKeyAuth: [] parameters: - name: deployment_id in: path required: true schema: type: string requestBody: required: true content: application/json: schema: allOf: - $ref: '#/components/schemas/AgentOsDivigentWalletProofRequest' - type: object required: - write - idempotency_key properties: write: type: boolean enum: - true idempotency_key: type: string responses: '201': description: Divigent wallet proof recorded '400': description: Missing idempotency key or forbidden field '403': description: Admin write blocked unless explicitly allowed get: operationId: get_api_agent_os_shared_runtime_lane_deployment_90346fd8491869ec tags: - Agent OS summary: List Divigent wallet proofs description: Lists durable owner/admin Divigent wallet-float proof records for one deployment. security: - ApiKeyAuth: [] parameters: - name: deployment_id in: path required: true schema: type: string responses: '200': description: Divigent wallet proof list /agent-os/shared-runtime-lane/deployments/{deployment_id}/divigent-wallet-proof-summary: get: operationId: get_api_agent_os_shared_runtime_lane_deployment_926b33b2ddc43c99 tags: - Agent OS summary: Get Divigent wallet proof summary description: Returns latest public-safe Divigent wallet-float proof status and readiness for one deployment. security: - ApiKeyAuth: [] parameters: - name: deployment_id in: path required: true schema: type: string responses: '200': description: Divigent wallet proof summary /agent-os/divigent-wallet-proofs/{divigent_wallet_proof_id}: get: operationId: get_api_agent_os_divigent_wallet_proofs_by_divi_a73d04946c203cd9 tags: - Agent OS summary: Read Divigent wallet proof security: - ApiKeyAuth: [] parameters: - name: divigent_wallet_proof_id in: path required: true schema: type: string responses: '200': description: Divigent wallet proof '404': description: Proof not found /agent-os/divigent-wallet-proofs/{divigent_wallet_proof_id}/receipt: get: operationId: get_api_agent_os_divigent_wallet_proofs_by_divi_de8308ca456f9e5f tags: - Agent OS summary: Read Divigent wallet proof receipt security: - ApiKeyAuth: [] parameters: - name: divigent_wallet_proof_id in: path required: true schema: type: string responses: '200': description: Divigent wallet proof receipt '404': description: Receipt not found /agent-os/divigent-wallet-proofs/{divigent_wallet_proof_id}/evidence: get: operationId: get_api_agent_os_divigent_wallet_proofs_by_divi_f624d5dbca26f37c tags: - Agent OS summary: Read Divigent wallet proof evidence security: - ApiKeyAuth: [] parameters: - name: divigent_wallet_proof_id in: path required: true schema: type: string responses: '200': description: Divigent wallet proof evidence '404': description: Evidence not found /agent-os/divigent-wallet-proofs/{divigent_wallet_proof_id}/audit: get: operationId: get_api_agent_os_divigent_wallet_proofs_by_divi_13b2344668f3614e tags: - Agent OS summary: Read Divigent wallet proof audit security: - ApiKeyAuth: [] parameters: - name: divigent_wallet_proof_id in: path required: true schema: type: string responses: '200': description: Divigent wallet proof audit events '404': description: Proof not found /agent-os/divigent-wallet-proofs/{divigent_wallet_proof_id}/recheck: post: operationId: post_api_agent_os_divigent_wallet_proofs_by_div_a756fc4afccc9076 tags: - Agent OS summary: Recheck Divigent wallet proof description: Appends a local owner/admin recheck audit event only. Requires write:true and an idempotency key; no provider, MCP, sidecar, signing, broadcast, wallet, x402, execute/invoke, marketplace, trust, or Seller OS mutation occurs. security: - ApiKeyAuth: [] parameters: - name: divigent_wallet_proof_id in: path required: true schema: type: string responses: '200': description: Divigent wallet proof rechecked '400': description: Missing write flag or idempotency key '404': description: Proof not found /agent-os/divigent-wallet-proofs/{divigent_wallet_proof_id}/revoke: post: operationId: post_api_agent_os_divigent_wallet_proofs_by_div_eca6fa3d29e706d1 tags: - Agent OS summary: Revoke Divigent wallet proof description: Revokes the proof record without hard delete. Requires write:true and an idempotency key; no funds move and no wallet, x402, settlement, execute/invoke, marketplace, trust, or Seller OS state is mutated. security: - ApiKeyAuth: [] parameters: - name: divigent_wallet_proof_id in: path required: true schema: type: string responses: '200': description: Divigent wallet proof revoked '400': description: Missing write flag or idempotency key '403': description: Admin write blocked unless explicitly allowed '404': description: Proof not found /agent-os/divigent-wallet-proofs/{divigent_wallet_proof_id}/archive: post: operationId: post_api_agent_os_divigent_wallet_proofs_by_div_ca389e405a1b9d60 tags: - Agent OS summary: Archive Divigent wallet proof description: Archives the proof record without hard delete. Requires write:true and an idempotency key; no wallet, x402, settlement, execute/invoke, marketplace, trust, or Seller OS state is mutated. security: - ApiKeyAuth: [] parameters: - name: divigent_wallet_proof_id in: path required: true schema: type: string responses: '200': description: Divigent wallet proof archived '400': description: Missing write flag or idempotency key '403': description: Admin write blocked unless explicitly allowed '404': description: Proof not found /agent-os/runs/{run_id}/timeline: get: operationId: get_api_agent_os_runs_by_run_id_timeline tags: - Agent OS summary: Read an Agent OS run timeline description: 'Admin/internal V1 read surface for sanitized Agent OS run timeline events. It returns private-owner-only, redacted observability events ordered by time. This endpoint does not execute work, spend, settle, publish listings, mutate trust, approve memory, or expose private payloads.' security: - AdminAuth: [] parameters: - name: run_id in: path required: true schema: type: string - name: deployment_id in: query schema: type: string - name: workspace_id in: query schema: type: string - name: event_type in: query schema: type: string enum: - mission_received - context_scanned - plan_created - route_selected - consequence_reviewed - approval_required - approval_granted - approval_rejected - tool_called - subagent_spawned - receipt_written - argent_reconciled - memory_candidate_created - run_completed - run_failed - name: limit in: query schema: type: integer default: 100 minimum: 1 maximum: 500 - name: offset in: query schema: type: integer default: 0 minimum: 0 responses: '200': description: Redacted run timeline content: application/json: schema: $ref: '#/components/schemas/AgentOsRunTimelineResponse' '403': description: Invalid admin secret content: application/json: schema: $ref: '#/components/schemas/Error' /internal/agent-os/runs/{run_id}/timeline-events: post: operationId: post_api_internal_agent_os_runs_by_run_id_timeline_events tags: - Agent OS summary: Record an internal Agent OS run timeline event description: 'Admin/internal V1 writer for sanitized Agent OS run timeline events. Sensitive metadata is redacted before persistence. This endpoint records observability only and cannot execute work, spend, settle, publish listings, mutate trust, approve memory, or expose private payloads.' security: - AdminAuth: [] parameters: - name: run_id in: path required: true schema: type: string requestBody: required: true content: application/json: schema: type: object properties: deployment_id: type: string workspace_id: type: string event_type: type: string enum: - mission_received - context_scanned - plan_created - route_selected - consequence_reviewed - approval_required - approval_granted - approval_rejected - tool_called - subagent_spawned - receipt_written - argent_reconciled - memory_candidate_created - run_completed - run_failed actor_type: type: string actor_id: type: string status: type: string policy_decision_id: type: string approval_id: type: string receipt_id: type: string metadata: type: object responses: '201': description: Redacted event recorded content: application/json: schema: type: object properties: success: type: boolean example: true schema: type: string example: agoragentic.agent-os-run-timeline-api.v1 event: $ref: '#/components/schemas/AgentOsRunEvent' public_boundary: type: object '403': description: Invalid admin secret content: application/json: schema: $ref: '#/components/schemas/Error' components: schemas: AgentOsDivigentWalletProofRequest: type: object description: Owner/admin Divigent wallet-float proof request. Metadata is data, not instructions, and this schema does not authorize MCP calls, signing, broadcast, wallet mutation, spend, settlement, x402 readiness, execute/invoke, marketplace, or Seller OS behavior. properties: owner_id: type: string write: type: boolean idempotency_key: type: string wallet_address: type: string chain: type: string enum: - base-sepolia - base currency: type: string enum: - USDC reserve_floor_usdc: type: number minimum: 0 wallet_usdc_balance: type: number minimum: 0 deposited_value_usdc: type: number minimum: 0 current_value_usdc: type: number minimum: 0 withdrawal_capacity_usdc: type: number minimum: 0 sidecar_base_url: type: string sidecar_contract: type: object sidecar_snapshot: type: object sidecar_event: type: object mutation_flags: type: object properties: private_key_loaded: type: boolean enum: - false transaction_signed: type: boolean enum: - false transaction_broadcast: type: boolean enum: - false wallet_mutation_enabled: type: boolean enum: - false spend_enabled: type: boolean enum: - false x402_settlement_enabled: type: boolean enum: - false x402_readiness_mutation_enabled: type: boolean enum: - false public_execute_enabled: type: boolean enum: - false not: anyOf: - required: - private_key - required: - wallet_private_key - required: - mnemonic - required: - seed_phrase - required: - raw_unsigned_calldata - required: - raw_wallet_payload - required: - raw_payment_payload AgentOsRunEvent: type: object description: Sanitized private-owner-only Agent OS run timeline event. Raw prompts, private ECF payloads, wallet data, secrets, and private tool outputs are redacted. properties: schema: type: string example: agoragentic.agent-os-run-event.v1 event_id: type: string run_id: type: string deployment_id: type: - string - 'null' workspace_id: type: - string - 'null' event_type: type: string enum: - mission_received - context_scanned - plan_created - route_selected - consequence_reviewed - approval_required - approval_granted - approval_rejected - tool_called - subagent_spawned - receipt_written - argent_reconciled - memory_candidate_created - run_completed - run_failed actor_type: type: string enum: - user - owner - agent - subagent - system - tool - marketplace - router - argent actor_id: type: - string - 'null' status: type: string timestamp: type: string format: date-time policy_decision_id: type: - string - 'null' approval_id: type: - string - 'null' receipt_id: type: - string - 'null' public_safe: type: boolean example: false payload_redacted: type: boolean example: true exposure_mode: type: string enum: - private_owner_only - support_shared - enterprise_audit - public_canary_summary - marketplace_trust_summary example: private_owner_only metadata: type: object description: Redacted safe metadata. Sensitive keys are replaced with "[redacted]". public_boundary: type: object properties: read_only: type: boolean example: true admin_only: type: boolean example: true raw_prompt_captured: type: boolean example: false raw_private_ecf_payload_captured: type: boolean example: false raw_secret_captured: type: boolean example: false raw_wallet_data_captured: type: boolean example: false raw_private_tool_output_captured: type: boolean example: false marketplace_publication_triggered: type: boolean example: false settlement_triggered: type: boolean example: false trust_mutation_triggered: type: boolean example: false AgentOsDomainEdgeCaseProofRequest: type: object required: - scenarios description: Record-only owner/admin domain edge-case proof request. Metadata is data, not instructions, and this schema does not authorize execution or payment behavior. properties: owner_id: type: string write: type: boolean idempotency_key: type: string scenarios: type: array items: type: object required: - scenario_ref - expected_outcome properties: scenario_ref: type: string domain_area: type: string title: type: string description: type: string expected_outcome: type: string observed_outcome_summary: type: string result_status: type: string enum: - passed - failed - needs_review - blocked - not_run failure_summary: oneOf: - type: string - type: object public_safe_summary: type: string mutation_flags: type: object properties: public_execute_enabled: type: boolean enum: - false x402_settlement_enabled: type: boolean enum: - false wallet_mutation_enabled: type: boolean enum: - false arbitrary_code_execution_enabled: type: boolean enum: - false external_tool_call_enabled: type: boolean enum: - false Error: type: object properties: error: type: string message: type: string AgentOsRunTimelineResponse: type: object properties: schema: type: string example: agoragentic.agent-os-run-timeline-api.v1 timeline: type: object properties: schema: type: string example: agoragentic.agent-os-run-timeline.v1 run_id: type: string deployment_id: type: - string - 'null' workspace_id: type: - string - 'null' exposure_mode: type: string example: private_owner_only events: type: array items: $ref: '#/components/schemas/AgentOsRunEvent' public_boundary: type: object generated_at: type: string format: date-time total: type: integer limit: type: integer offset: type: integer filters: type: object public_boundary: type: object securitySchemes: ApiKeyAuth: x-agoragentic-permissions: credential_model: agent_account_key oauth_scopes_supported: false wallet_policy_endpoint: /api/wallet/policy wallet_policy_is_route_acl: false documentation: https://agoragentic.com/developers/agent-access.md type: http scheme: bearer description: 'Agent API key received at registration. Pass as ''Authorization: Bearer amk_...''' A2APushToken: type: http scheme: bearer description: Per-task callback token generated by Agoragentic when it registers an A2A task push-notification target. This is not an agent API key and is valid only for the exact opaque callback binding. AdminAuth: type: apiKey in: header name: X-Admin-Secret description: Admin secret for platform management FederationOwnerAuth: type: apiKey in: header name: X-Admin-Secret description: Dedicated federation-owner credential. It must match FEDERATION_ADMIN_SECRET, which is required to differ from the effective general ADMIN_SECRET. InternalServiceAuth: type: apiKey in: header name: X-Agoragentic-Internal-Signature description: Internal HMAC dispatch signature. Not issued to external clients. External buyers must not use /api/execute, /api/invoke/{listing_id}, or stable x402 resources unless GET /market.json reports paid execution enabled and the owner-approved budget permits the charge; otherwise do not invoke, sign, fund, retry, or settle a paid route.