API cheat sheet
Operations
Authentication accounts
getAuthAccount: Inspect current human account state.createAuthAccount: Create an administrator-controlled local auth account.attachGitHubIdentity: Attach an exact GitHub identity to an existing account.attachGoogleIdentity: Attach an exact Google identity to an existing account.detachAuthMethod: Detach an external sign-in identity from an account.disableAuthAccount: Disable a human account.enableAuthAccount: Re-enable a disabled human account.enrolAuthAccount: Enrol an existing account that activation skipped.revokeAuthAccountSessions: Revoke all sessions for a human account.
Authentication sessions
getAuthSession: Inspect authentication without revealing session tokens.signInEmail: Sign in with email and password.signOut: Sign out of the current session.
Service API keys
createServiceKey: Issue a service API key.revokeServiceKey: Revoke a service API key.
Authentication
completeGitHubSignIn: Complete an enrolled GitHub sign-in.completeGoogleSignIn: Complete an enrolled Google sign-in.getAuthProviders: List configured browser sign-in methods.getAuthRecovery: Inspect the recovery account designation.confirmGitHubSignIn: Confirm which session a GitHub sign-in created.confirmGoogleSignIn: Confirm which session a Google sign-in created.replaceAuthRecovery: Move the recovery designation to another administrator.startGitHubSignIn: Start GitHub sign-in for an enrolled account.startGoogleSignIn: Start Google sign-in for an enrolled account.
Installation
getInstallation: Get the singleton Installation.getInstallationDeploymentInventory: Get the complete authorized Agent deployment inventory.getObservability: Get the configured external observability destination.bootstrapInstallation: Bootstrap the singleton Installation.
Namespaces
listNamespaces: List authorized Namespaces.getNamespace: Get an exact Installation-owned Namespace.createNamespace: Create an Installation-owned Namespace.deleteNamespace: Begin or retry deletion of an empty Installation-owned Namespace.
Agents
listAgentRepositoryOptions: List approved repository choices for updating one Agent.listAgents: List authorized Agents in one exact Namespace.listRepositoryOptions: List approved repository choices for Agent creation in one Namespace.getAgent: Get an exact Namespace-owned Agent.getAgentProvisioning: Get first-time provisioning status for one exact work item.getAgentRuntimeImages: Read observed images and source commits for an Agent's active runtime.getSavedAgentPluginPolicyCapabilities: Read selected Plugin Driver policy capabilities for an active Agent with caller Agent read/update permission.createAgent: Create a Namespace-owned Agent.provisionAgent: Create a new Agent and queue first-time provisioning.updateAgent: Replace an exact Namespace-owned Agent's editable draft.deployAgent: Admit an immutable revision from the Agent's saved draft.discoverAgentModels: List provider models for Agent creation without storing the supplied credential.discoverAgentPluginDetails: Read plugin details using the selected Driver.discoverAgentPlugins: List or search available plugins for Agent creation using the selected Driver.discoverSavedAgentPluginDetails: Read plugin details for an active Agent; caller needs Agent read/update. Curated discovery needs no Secret; hosted discovery needs the Agent's bound Service Accounts Secret with caller and Agent Secret operate grants.discoverSavedAgentPlugins: List or search plugins for an active Agent; caller needs Agent read/update. Curated discovery needs no Secret; hosted discovery needs the Agent's bound Service Accounts Secret with caller and Agent Secret operate grants.lookupChannelDirectory: Search a channel directory using an authorized Namespace Secret.retryAgentProvisioning: Retry failed first-time provisioning for one exact work item.stopAgent: Stop one Agent while retaining its revision and persistent state.getAgentNativeAdmin: Resolve native admin UI launch availability for one Agent.deleteAgent: Begin or retry deletion of an exact Namespace-owned Agent and its AgentRevisions.
Agent deployments
getAgentDeployment: Get the durable deployment status for one admitted Agent revision.diagnoseAgentDeployment: Run explicit current-runtime diagnostics for one exact Agent revision.
Agent revisions
listAgentRevisions: List authorized immutable revisions for one exact Agent.getAgentRevision: Get an exact authorized immutable Agent revision.
Agent runtime credentials
getAgentRuntimeCredentials: Get metadata for one Agent's provisioned runtime credentials.provisionAgentRuntimeCredentials: Provision initial runtime credentials for one undeployed Agent.
Agent workspace files
getAgentWorkspaceFile: Read an allowed workspace file from one active Agent.putAgentWorkspaceFile: Create or replace an allowed workspace file for one active Agent.
Configurations
getConfiguration: Get an exact Namespace-owned Configuration.createConfiguration: Create a native Namespace-owned Agent Configuration.updateConfiguration: Replace values and increment an exact Namespace-owned Configuration generation.deleteConfiguration: Delete an exact unreferenced Namespace-owned Configuration.
IAM access bindings
listIAMAccessBindings: List exact Namespace IAM AccessBindings.getIAMAccessBinding: Get an exact Namespace IAM AccessBinding.createIAMAccessBinding: Create an immutable exact-resource Namespace IAM AccessBinding.deleteIAMAccessBinding: Delete one exact Namespace IAM AccessBinding.
IAM roles
listIAMRoles: List exact Namespace IAM Roles.getIAMRole: Get an exact Namespace IAM Role.createIAMRole: Create an immutable Namespace IAM Role.deleteIAMRole: Delete an unreferenced exact Namespace IAM Role.
Secrets
listSecrets: List readable Namespace-owned Secret metadata without revealing material.getSecret: Get exact Namespace-owned Secret metadata without revealing material.createSecret: Create exact Namespace-owned Secret material and return metadata only.updateSecret: Replace exact Namespace-owned Secret material and return stable metadata.deleteSecret: Delete exact unbound Namespace-owned Secret material.
Service accounts
listServiceAccounts: List authorized Namespace-owned ServiceAccounts in one exact Namespace.getServiceAccount: Get an exact Namespace-owned ServiceAccount.createServiceAccount: Create a native Namespace-owned ServiceAccount.deleteServiceAccount: Delete an exact unreferenced Namespace-owned ServiceAccount.
Service account credentials
createServiceAccountCredential: Issue a managed credential for an exact Namespace-owned ServiceAccount.updateServiceAccountCredential: Associate an exact Namespace-local credential reference with a ServiceAccount.
Backends
listBackends: List configured Backends (experimental).
Credential sources
listCredentialSources: List readable credential sources without revealing credential values.getCredentialSource: Get one credential source and its live Credential Gateway status.createCredentialSource: Register a credential source with the selected Credential Gateway.deleteCredentialSource: Remove an unreferenced credential source from the Credential Gateway.
Presets
listPresets: List readable Presets in one Namespace.getPreset: Read one exact Namespace-owned Preset.createPreset: Create a reusable Namespace-owned Agent Preset.updatePreset: Update a Preset without changing existing Agents.deletePreset: Delete a Preset without changing existing Agents.
