basePath: /
definitions:
  adminaudit.Operation:
    properties:
      action:
        type: string
      actor_label:
        type: string
      admin_credential_id:
        type: string
      created_at:
        type: string
      id:
        type: string
      project_id:
        type: string
        x-nullable: true
      request_id:
        type: string
      resource_id:
        type: string
      resource_type:
        type: string
      result_ids:
        items:
          type: object
        type: array
      trace_id:
        type: string
    type: object
  adminaudit.Page:
    properties:
      data:
        items:
          $ref: '#/definitions/adminaudit.Operation'
        type: array
      has_more:
        type: boolean
      next_cursor:
        type: string
    type: object
  api.AdminRuntimeObservation:
    properties:
      observation:
        $ref: '#/definitions/api.AdminRuntimeObservationDetail'
      project_id:
        type: string
    type: object
  api.AdminRuntimeObservationDetail:
    properties:
      allocation_created_at:
        minimum: 0
        type: integer
        x-nullable: true
      cpu:
        allOf:
          - $ref: '#/definitions/v1.RuntimeCPUObservation'
        x-nullable: true
      disk:
        allOf:
          - $ref: '#/definitions/api.RuntimeDiskObservation'
        description: |-
          Current Runtime disk usage and capacity. E2B reports them; Docker and
          microsandbox observations return null.
        x-nullable: true
      environment_id:
        format: uuid
        type: string
        x-nullable: true
      id:
        format: uuid
        type: string
      instance:
        $ref: '#/definitions/v1.RuntimeInstance'
      lifecycle_state:
        enum:
          - active
          - sleeping
          - transitioning
          - pending
          - stopped
        type: string
        x-nullable: true
      memory:
        allOf:
          - $ref: '#/definitions/v1.RuntimeMemoryObservation'
        x-nullable: true
      mode:
        enum:
          - none
          - self_hosted
          - openai_hosted
        type: string
      object:
        enum:
          - agent.runtime_observation
        type: string
      observed_at:
        minimum: 0
        type: integer
        x-nullable: true
      provider_type:
        type: string
        x-nullable: true
      reason:
        enum:
          - runtime_mode_not_observable
          - allocation_pending
          - runtime_not_running
          - source_not_configured
          - sample_timeout
          - sample_unavailable
        type: string
        x-nullable: true
      resolved_at:
        minimum: 0
        type: integer
      session_id:
        format: uuid
        type: string
      started_at:
        minimum: 0
        type: integer
        x-nullable: true
      status:
        enum:
          - observed
          - unsupported
          - unavailable
        type: string
    required:
      - allocation_created_at
      - cpu
      - disk
      - environment_id
      - id
      - instance
      - lifecycle_state
      - memory
      - mode
      - object
      - observed_at
      - provider_type
      - reason
      - resolved_at
      - session_id
      - started_at
      - status
    type: object
  api.AdminRuntimeObservationList:
    properties:
      data:
        items:
          $ref: '#/definitions/api.AdminRuntimeObservation'
        type: array
      first_id:
        type: string
      has_more:
        type: boolean
      last_id:
        type: string
      object:
        type: string
    type: object
  api.AdminSessionArchiveRequest:
    properties:
      expected_generation:
        type: integer
    type: object
  api.AdminSessionCounts:
    properties:
      failed:
        type: integer
      idle:
        type: integer
      in_progress:
        type: integer
      requires_action:
        type: integer
      total:
        type: integer
    type: object
  api.AdminSummaryResponse:
    properties:
      data:
        items:
          $ref: '#/definitions/api.AdminSummaryRow'
        type: array
      has_more:
        type: boolean
      next_cursor:
        type: string
    type: object
  api.AdminSummaryRow:
    properties:
      agent_id:
        type: string
      assets:
        $ref: '#/definitions/store.AdminAssetCounts'
      coverage:
        $ref: '#/definitions/api.AdminUsageCoverage'
      key_id:
        type: string
      last_active_at:
        type: integer
      project_id:
        type: string
      sessions:
        $ref: '#/definitions/api.AdminSessionCounts'
      usage:
        $ref: '#/definitions/v1.TokenUsage'
    type: object
  api.AdminUsageCoverage:
    properties:
      measured_sessions:
        type: integer
      ratio:
        type: number
      total_sessions:
        type: integer
    type: object
  api.CoreAPIError:
    properties:
      code:
        type: string
        x-nullable: true
      details:
        description: |-
          Details contains only documented, Core-owned facts: string, finite number,
          boolean, null or string array values. Never include request echoes, secrets
          or native/provider error text. Empty or invalid details are omitted.
        type: object
      message:
        type: string
      param:
        type: string
        x-nullable: true
      type:
        type: string
    required:
      - message
      - type
    type: object
  api.CoreErrorResponse:
    properties:
      error:
        $ref: '#/definitions/api.CoreAPIError'
    required:
      - error
    type: object
  api.CoreHarness:
    properties:
      default:
        type: boolean
      enabled:
        type: boolean
      id:
        enum:
          - claude_sdk
          - codex
          - mcode
        type: string
      model_configuration:
        allOf:
          - $ref: '#/definitions/api.HarnessModelConfiguration'
        x-nullable: true
      model_configuration_support:
        $ref: '#/definitions/v1.ModelConfigurationSupport'
      object:
        enum:
          - core.harness
        type: string
    required:
      - default
      - enabled
      - id
      - model_configuration
      - model_configuration_support
      - object
    type: object
  api.CoreHarnessList:
    properties:
      data:
        items:
          $ref: '#/definitions/api.CoreHarness'
        type: array
      object:
        enum:
          - list
        type: string
    required:
      - data
      - object
    type: object
  api.DiagnosticFailure:
    properties:
      code:
        enum:
          - harness_error
          - model_provider_required
          - runtime_unavailable
          - runtime_disconnected
          - runtime_preparation_failed
          - execution_interrupted
          - delivery_unconfirmed
          - input_rejected
          - executor_protocol_error
          - core_storage_failed
          - internal_error
          - environment_connection_timeout
          - environment_unavailable
          - environment_provisioning_failed
          - authentication_error
          - rate_limit_exceeded
          - usage_limit_exceeded
          - server_overloaded
          - server_error
          - invalid_request
          - resource_not_found
          - request_timeout
          - context_length_exceeded
          - cyber_policy
          - connection_failed
        type: string
      failed_at:
        type: string
        x-nullable: true
      params:
        type: object
    type: object
  api.EnvironmentExecutorCredentialRequest:
    properties:
      key_id:
        format: uuid
        type: string
      rotate:
        type: boolean
    type: object
  api.ExecutorConnection:
    properties:
      bound_key_id:
        format: uuid
        type: string
        x-nullable: true
      enrolled_at:
        format: date-time
        type: string
        x-nullable: true
      last_seen_at:
        format: date-time
        type: string
        x-nullable: true
      status:
        enum:
          - never_enrolled
          - connected
          - disconnected
        type: string
    required:
      - bound_key_id
      - enrolled_at
      - last_seen_at
      - status
    type: object
  api.ExecutorCredentialList:
    properties:
      connection:
        $ref: '#/definitions/api.ExecutorConnection'
      data:
        items:
          $ref: '#/definitions/sessions.ExecutorCredential'
        type: array
    required:
      - connection
      - data
    type: object
  api.HarnessModelConfiguration:
    properties:
      harness:
        enum:
          - claude_sdk
          - codex
          - mcode
        type: string
      harness_config:
        type: object
      last_error_at:
        format: date-time
        type: string
        x-nullable: true
      last_error_code:
        enum:
          - authentication_error
          - connection_failed
          - rate_limit_exceeded
          - usage_limit_exceeded
          - server_overloaded
          - server_error
          - resource_not_found
          - request_timeout
          - invalid_request
        type: string
        x-nullable: true
      last_used_at:
        format: date-time
        type: string
        x-nullable: true
      model:
        type: string
      model_provider:
        $ref: '#/definitions/v1.ModelProviderView'
      object:
        enum:
          - core.model_configuration
        type: string
      updated_at:
        type: string
    required:
      - harness
      - harness_config
      - last_error_at
      - last_error_code
      - last_used_at
      - model
      - model_provider
      - object
      - updated_at
    type: object
  api.Installation:
    properties:
      address_bindings:
        $ref: '#/definitions/deployment.AddressBindings'
      api_base_url:
        description: public_url followed by /v1; null when public_url is null.
        type: string
        x-nullable: true
      configuration:
        allOf:
          - $ref: '#/definitions/api.InstallationConfiguration'
        description: The installer's settings snapshot (OAC_SETTINGS_FILE); null when the installer did not start Core.
        x-nullable: true
      installation_id:
        description: OAC_INSTALLATION_ID; null when Core runs without the sandbox manager.
        type: string
        x-nullable: true
      local_only:
        description: True when public_url names a loopback host, reachable only from the Core host.
        type: boolean
      object:
        enum:
          - core.installation
        type: string
      public_url:
        description: 'OAC_PUBLIC_URL: the origin applications, nodes, sandboxes and self-hosted executors use. Null when unset.'
        type: string
        x-nullable: true
      source_commit:
        description: Full source commit Core was built from; null for development builds.
        type: string
        x-nullable: true
    type: object
  api.InstallationConfiguration:
    properties:
      applied_at:
        type: string
      apply_command:
        description: Command that applies config.json changes.
        type: string
      path:
        description: Absolute host path of the installation's config.json.
        type: string
      settings:
        items:
          $ref: '#/definitions/api.InstallationSetting'
        type: array
    type: object
  api.InstallationSetting:
    properties:
      changeable:
        description: False for settings fixed at installation.
        type: boolean
      configured:
        description: 'Present only for a sensitive setting: whether it has a value.'
        type: boolean
      default:
        x-nullable: true
      key:
        description: Dotted config.json key, such as ports.core.
        type: string
      restarts:
        description: Services that restart when the setting changes.
        items:
          type: string
        type: array
      sensitive:
        type: boolean
      value:
        description: Applied value; always null for a sensitive setting.
        x-nullable: true
    type: object
  api.ItemDiagnosticTiming:
    properties:
      completed_at:
        type: string
        x-nullable: true
      item_id:
        type: string
      observed_duration_ms:
        type: integer
        x-nullable: true
      started_at:
        type: string
    type: object
  api.ProjectAPIKeyRequest:
    properties:
      name:
        type: string
    type: object
  api.ProjectRequest:
    properties:
      name:
        type: string
    type: object
  api.ResourceOwnerList:
    properties:
      data:
        items:
          $ref: '#/definitions/writeaudit.ResourceOwner'
        type: array
    type: object
  api.RuntimeDiskObservation:
    properties:
      limit_bytes:
        minimum: 1
        type: integer
        x-nullable: true
      usage_bytes:
        minimum: 0
        type: integer
        x-nullable: true
    required:
      - limit_bytes
      - usage_bytes
    type: object
  api.SandboxAllocationList:
    properties:
      data:
        items:
          $ref: '#/definitions/deployment.NodeAllocation'
        type: array
    type: object
  api.SandboxDeploymentChangeInput:
    properties:
      configuration:
        type: object
      credential:
        type: object
      expected_generation:
        type: integer
      provider:
        type: string
      resources:
        allOf:
          - $ref: '#/definitions/sandbox.Resources'
        description: |-
          Per-sandbox limits, required for Docker and microsandbox. E2B may omit
          them; Core then uses the validated template build's cpus and memory_mib.
      runtime:
        $ref: '#/definitions/sandbox.RuntimeRelease'
    required:
      - expected_generation
    type: object
  api.SandboxDeploymentInput:
    properties:
      configuration:
        type: object
      credential:
        type: object
      expected_generation:
        type: integer
      provider:
        type: string
      resources:
        allOf:
          - $ref: '#/definitions/sandbox.Resources'
        description: |-
          Per-sandbox limits, required for Docker and microsandbox. E2B may omit
          them; Core then uses the validated template build's cpus and memory_mib.
      runtime:
        $ref: '#/definitions/sandbox.RuntimeRelease'
    required:
      - expected_generation
    type: object
  api.SandboxEnrollmentToken:
    properties:
      enrollment_id:
        description: Public, non-secret handle of this command; never a credential. The node it registers reports the same value as enrollment_id.
        type: string
      expires_at:
        type: string
      token:
        type: string
    type: object
  api.SandboxEnrollmentTokenRequest:
    properties:
      max_active:
        type: integer
      max_retained:
        description: Docker never suspends, so Core replaces this with max_active; microsandbox uses both limits.
        type: integer
    type: object
  api.SandboxMutationResponse:
    properties:
      deleted:
        type: boolean
      id:
        type: string
      updated:
        type: boolean
    type: object
  api.SandboxNodeList:
    properties:
      data:
        items:
          $ref: '#/definitions/deployment.Node'
        type: array
    type: object
  api.SessionDiagnosticFailure:
    properties:
      code:
        enum:
          - harness_error
          - model_provider_required
          - runtime_unavailable
          - runtime_disconnected
          - runtime_preparation_failed
          - execution_interrupted
          - delivery_unconfirmed
          - input_rejected
          - executor_protocol_error
          - core_storage_failed
          - internal_error
          - environment_connection_timeout
          - environment_unavailable
          - environment_provisioning_failed
          - authentication_error
          - rate_limit_exceeded
          - usage_limit_exceeded
          - server_overloaded
          - server_error
          - invalid_request
          - resource_not_found
          - request_timeout
          - context_length_exceeded
          - cyber_policy
          - connection_failed
        type: string
      failed_at:
        type: string
        x-nullable: true
      params:
        type: object
      source:
        enum:
          - turn
          - environment
          - environment_input
        type: string
      turn_id:
        type: string
    type: object
  api.SessionDiagnostics:
    properties:
      failure:
        allOf:
          - $ref: '#/definitions/api.SessionDiagnosticFailure'
        x-nullable: true
      object:
        enum:
          - core.session_diagnostics
        type: string
      session_id:
        type: string
      status:
        enum:
          - idle
          - in_progress
          - requires_action
          - failed
        type: string
    type: object
  api.TurnDiagnostics:
    properties:
      failure:
        allOf:
          - $ref: '#/definitions/api.DiagnosticFailure'
        x-nullable: true
      items:
        items:
          $ref: '#/definitions/api.ItemDiagnosticTiming'
        type: array
      items_truncated:
        type: boolean
      object:
        enum:
          - core.turn_diagnostics
        type: string
      session_id:
        type: string
      status:
        type: string
      turn_id:
        type: string
    type: object
  coremetrics.Database:
    properties:
      ping_ms:
        $ref: '#/definitions/coremetrics.Latency'
      pool:
        $ref: '#/definitions/coremetrics.Pool'
      series:
        items:
          $ref: '#/definitions/coremetrics.DatabaseBucket'
        type: array
      size_bytes:
        type: integer
        x-nullable: true
    type: object
  coremetrics.DatabaseBucket:
    properties:
      ping_p95_ms:
        type: number
        x-nullable: true
      pool_in_use:
        type: integer
        x-nullable: true
      start:
        type: string
    type: object
  coremetrics.Execution:
    properties:
      connected_daemons:
        type: integer
        x-nullable: true
      in_progress_turns:
        type: integer
        x-nullable: true
      interrupted:
        type: integer
        x-nullable: true
      oldest_queued_seconds:
        type: number
        x-nullable: true
      queue_wait_ms:
        $ref: '#/definitions/coremetrics.Latency'
      queued_turns:
        type: integer
        x-nullable: true
      series:
        items:
          $ref: '#/definitions/coremetrics.ExecutionBucket'
        type: array
      slots_in_use:
        type: integer
        x-nullable: true
      slots_total:
        type: integer
        x-nullable: true
      unavailable:
        type: integer
        x-nullable: true
      waiting_for_daemon:
        type: integer
        x-nullable: true
    type: object
  coremetrics.ExecutionBucket:
    properties:
      in_progress:
        type: integer
        x-nullable: true
      queue_wait_p95_ms:
        type: number
        x-nullable: true
      queued:
        type: integer
        x-nullable: true
      start:
        type: string
    type: object
  coremetrics.Job:
    properties:
      failed:
        type: integer
        x-nullable: true
      id:
        type: string
      last_run_at:
        type: string
        x-nullable: true
      processed:
        type: integer
        x-nullable: true
      status:
        type: string
    type: object
  coremetrics.Latency:
    properties:
      p50:
        type: number
        x-nullable: true
      p95:
        type: number
        x-nullable: true
    type: object
  coremetrics.Pool:
    properties:
      idle:
        type: integer
        x-nullable: true
      in_use:
        type: integer
        x-nullable: true
      max:
        type: integer
        x-nullable: true
    type: object
  coremetrics.Process:
    properties:
      cpu_cores:
        type: number
        x-nullable: true
      cpu_limit_cores:
        type: number
        x-nullable: true
      goroutines:
        type: integer
        x-nullable: true
      memory_bytes:
        type: integer
        x-nullable: true
      memory_limit_bytes:
        type: integer
        x-nullable: true
      rss_bytes:
        type: integer
        x-nullable: true
      series:
        items:
          $ref: '#/definitions/coremetrics.ProcessBucket'
        type: array
    type: object
  coremetrics.ProcessBucket:
    properties:
      cpu_cores:
        type: number
        x-nullable: true
      rss_bytes:
        type: integer
        x-nullable: true
      start:
        type: string
    type: object
  coremetrics.Range:
    properties:
      end:
        type: string
      resolution_seconds:
        type: integer
      start:
        type: string
    type: object
  coremetrics.ServiceState:
    properties:
      execution_owner:
        type: boolean
        x-nullable: true
      revision:
        type: string
        x-nullable: true
      started_at:
        type: string
        x-nullable: true
      status:
        type: string
    type: object
  coremetrics.View:
    properties:
      database:
        $ref: '#/definitions/coremetrics.Database'
      execution:
        $ref: '#/definitions/coremetrics.Execution'
      jobs:
        items:
          $ref: '#/definitions/coremetrics.Job'
        type: array
      object:
        type: string
      process:
        $ref: '#/definitions/coremetrics.Process'
      range:
        $ref: '#/definitions/coremetrics.Range'
      service:
        $ref: '#/definitions/coremetrics.ServiceState'
    type: object
  deployment.AddressBindings:
    properties:
      hosted_sandboxes:
        type: integer
      nodes:
        type: integer
      nodes_on_other_address:
        type: integer
      self_hosted_executors:
        type: integer
    type: object
  deployment.HostHistory:
    properties:
      points:
        items:
          $ref: '#/definitions/deployment.HostHistoryPoint'
        type: array
      resolution_seconds:
        type: integer
    type: object
  deployment.HostHistoryPoint:
    properties:
      available_disk_bytes_min:
        type: integer
        x-nullable: true
      cpu_utilization_max:
        type: number
        x-nullable: true
      memory_used_bytes_max:
        type: integer
        x-nullable: true
      start:
        type: string
    type: object
  deployment.Node:
    properties:
      active:
        type: integer
      available_disk_bytes:
        type: integer
      available_memory_bytes:
        type: integer
      cleanup_pending:
        type: integer
      core_url:
        description: |-
          The Core address this node enrolled with. A node whose address differs
          from the installation public URL receives no new sandboxes; re-add it.
        type: string
      cpu_count:
        type: integer
      created_at:
        type: string
      diagnostic:
        description: Fixed reason for the last reported unreadiness; absent while the provider is ready. Clients treat an unknown value as provider_unavailable.
        enum:
          - provider_unavailable
          - docker_unavailable
          - docker_limits_unsupported
          - runtime_download_failed
          - runtime_image_unavailable
          - kvm_unavailable
          - microsandbox_artifacts_unavailable
          - capacity_insufficient
        type: string
      enrollment_id:
        description: The enrollment_id of the command that registered this node (POST /core/v1/sandbox/enrollment-tokens); null for nodes enrolled before Core recorded it.
        type: string
        x-nullable: true
      id:
        type: string
      last_seen_at:
        type: string
      max_active:
        type: integer
      max_retained:
        type: integer
      name:
        type: string
      online:
        type: boolean
      provider:
        type: string
      provider_ready:
        type: boolean
      reserved:
        type: integer
      retained:
        type: integer
      rollout:
        $ref: '#/definitions/deployment.NodeRollout'
      running:
        type: integer
      snapshots:
        type: integer
    type: object
  deployment.NodeAllocation:
    properties:
      compute_phase:
        type: string
      compute_phase_changed_at:
        description: The time the allocation entered its current compute_phase, or null when unknown; an allocation that existed before Core recorded it reports null until its next phase change. For a suspended microsandbox allocation, this time plus the deployment's snapshot retention tells roughly when Core reclaims it.
        type: string
        x-nullable: true
      created_at:
        type: string
      deployment_generation:
        type: integer
      diagnostic:
        type: string
      environment_id:
        type: string
      id:
        type: string
      initialization:
        type: string
      node_id:
        type: string
      session_id:
        type: string
      state:
        type: string
      tenant_id:
        type: string
    type: object
  deployment.NodeDetail:
    properties:
      active:
        type: integer
      available_disk_bytes:
        type: integer
      available_memory_bytes:
        type: integer
      cleanup_pending:
        type: integer
      core_url:
        description: |-
          The Core address this node enrolled with. A node whose address differs
          from the installation public URL receives no new sandboxes; re-add it.
        type: string
      cpu_count:
        type: integer
      created_at:
        type: string
      diagnostic:
        description: Fixed reason for the last reported unreadiness; absent while the provider is ready. Clients treat an unknown value as provider_unavailable.
        enum:
          - provider_unavailable
          - docker_unavailable
          - docker_limits_unsupported
          - runtime_download_failed
          - runtime_image_unavailable
          - kvm_unavailable
          - microsandbox_artifacts_unavailable
          - capacity_insufficient
        type: string
      enrollment_id:
        description: The enrollment_id of the command that registered this node (POST /core/v1/sandbox/enrollment-tokens); null for nodes enrolled before Core recorded it.
        type: string
        x-nullable: true
      history:
        $ref: '#/definitions/deployment.HostHistory'
      host:
        $ref: '#/definitions/deployment.NodeHost'
      id:
        type: string
      last_seen_at:
        type: string
      max_active:
        type: integer
      max_retained:
        type: integer
      name:
        type: string
      online:
        type: boolean
      provider:
        type: string
      provider_ready:
        type: boolean
      reserved:
        type: integer
      retained:
        type: integer
      rollout:
        $ref: '#/definitions/deployment.NodeRollout'
      running:
        type: integer
      snapshots:
        type: integer
    type: object
  deployment.NodeHost:
    properties:
      available_disk_bytes:
        type: integer
        x-nullable: true
      available_memory_bytes:
        type: integer
        x-nullable: true
      cpu_utilization:
        type: number
        x-nullable: true
      effective_cpu_cores:
        type: number
        x-nullable: true
      observed_at:
        type: string
        x-nullable: true
      total_memory_bytes:
        type: integer
        x-nullable: true
    type: object
  deployment.NodeRollout:
    properties:
      diagnostic:
        enum:
          - provider_unavailable
          - docker_unavailable
          - docker_limits_unsupported
          - runtime_download_failed
          - runtime_image_unavailable
          - kvm_unavailable
          - microsandbox_artifacts_unavailable
          - capacity_insufficient
        type: string
      ready_generation:
        description: Durable serving-generation pin; online and provider_ready still gate placement.
        type: integer
        x-nullable: true
      state:
        description: Target preparation, independent of an old pin's serving readiness.
        enum:
          - ready
          - preparing
          - failed
          - update_required
          - unknown
        type: string
    type: object
  deployment.NodeUpdate:
    properties:
      max_active:
        type: integer
      max_retained:
        description: Docker never suspends, so Core replaces this with max_active; microsandbox uses both limits.
        type: integer
      name:
        type: string
    type: object
  deployment.Reset:
    properties:
      clear:
        type: string
      deadline_at:
        type: string
        x-nullable: true
      forced_at:
        type: string
        x-nullable: true
      remaining:
        $ref: '#/definitions/deployment.ResetRemaining'
      requested_at:
        type: string
    type: object
  deployment.ResetOfflineNode:
    properties:
      name:
        type: string
      node_id:
        type: string
      resources:
        type: integer
    type: object
  deployment.ResetRemaining:
    properties:
      busy:
        type: integer
      cleanup:
        type: integer
      idle:
        type: integer
      offline_nodes:
        items:
          $ref: '#/definitions/deployment.ResetOfflineNode'
        type: array
      on_offline_nodes:
        type: integer
    type: object
  deployment.ResetRequest:
    properties:
      clear:
        enum:
          - auto
          - force
        type: string
      deadline_seconds:
        maximum: 86400
        minimum: 300
        type: integer
      expected_generation:
        minimum: 0
        type: integer
    required:
      - clear
      - expected_generation
    type: object
  deployment.Resources:
    properties:
      allocations:
        type: integer
      pending:
        type: integer
    type: object
  deployment.Rollout:
    properties:
      nodes:
        allOf:
          - $ref: '#/definitions/deployment.RolloutNodes'
        x-nullable: true
      previous_generation_sandboxes:
        type: integer
      state:
        enum:
          - settled
          - preparing
        type: string
    type: object
  deployment.RolloutNodes:
    properties:
      failed:
        type: integer
      preparing:
        type: integer
      ready:
        type: integer
      unknown:
        type: integer
      update_required:
        type: integer
    type: object
  deployment.Suspension:
    properties:
      idle_seconds:
        type: integer
      retention_seconds:
        type: integer
    type: object
  deployment.View:
    properties:
      configuration:
        type: object
      core_url:
        description: 'Read-only: the installation public URL (OAC_PUBLIC_URL), which nodes and sandboxes use to reach Core. The deployment API does not accept it.'
        type: string
      credential_configured:
        type: boolean
      generation:
        type: integer
      installation_id:
        type: string
      metadata:
        type: object
      mode:
        type: string
      owner_epoch:
        type: integer
      provider:
        type: string
      reset:
        allOf:
          - $ref: '#/definitions/deployment.Reset'
        x-nullable: true
      resources:
        $ref: '#/definitions/deployment.Resources'
      rollout:
        $ref: '#/definitions/deployment.Rollout'
      specification:
        $ref: '#/definitions/sandbox.DeploymentSpec'
      specification_digest:
        type: string
      suspension:
        allOf:
          - $ref: '#/definitions/deployment.Suspension'
        description: Idle suspension policy; microsandbox only, otherwise null.
        x-nullable: true
    type: object
  projects.APIKey:
    properties:
      created_at:
        type: string
      id:
        type: string
      name:
        type: string
      prefix:
        type: string
      project_id:
        type: string
      revoked_at:
        type: string
    type: object
  projects.IssuedAPIKey:
    properties:
      created_at:
        type: string
      id:
        type: string
      key:
        type: string
      name:
        type: string
      prefix:
        type: string
      project_id:
        type: string
      revoked_at:
        type: string
    type: object
  projects.KeyPage:
    properties:
      data:
        items:
          $ref: '#/definitions/projects.APIKey'
        type: array
      has_more:
        type: boolean
    type: object
  projects.Page:
    properties:
      data:
        items:
          $ref: '#/definitions/projects.Project'
        type: array
      has_more:
        type: boolean
    type: object
  projects.Project:
    properties:
      active_key_count:
        type: integer
      archived_at:
        type: string
      created_at:
        type: string
      id:
        type: string
      name:
        type: string
    type: object
  sandbox.ConfigurationDiscoveryInput:
    properties:
      configuration:
        type: object
      credential:
        type: object
      query:
        type: object
    type: object
  sandbox.DeploymentSpec:
    properties:
      resources:
        $ref: '#/definitions/sandbox.Resources'
      runtime:
        $ref: '#/definitions/sandbox.RuntimeRelease'
    type: object
  sandbox.Resources:
    properties:
      cpus:
        type: integer
      environment_disk_mib:
        type: integer
      memory_mib:
        type: integer
      root_disk_mib:
        type: integer
    type: object
  sandbox.RuntimeRelease:
    properties:
      firmware_sha256:
        type: string
      image_id:
        type: string
      image_manifest_digest:
        type: string
      microsandbox_ref:
        type: string
      runtime_sha256:
        type: string
      source_commit:
        type: string
    type: object
  sessions.ExecutorCredential:
    properties:
      created_at:
        type: string
      key_id:
        format: uuid
        type: string
      revoked_at:
        type: string
        x-nullable: true
    type: object
  sessions.IssuedExecutorCredential:
    properties:
      environment_id:
        type: string
      executor_token:
        type: string
      key_id:
        type: string
    type: object
  sessions.ManagedArchive:
    properties:
      environment_id:
        type: string
      session_id:
        type: string
      state:
        type: string
    type: object
  store.AdminAssetCounts:
    properties:
      agents:
        type: integer
      credentials:
        type: integer
      environment_templates:
        type: integer
      files:
        type: integer
      skills:
        type: integer
      vaults:
        type: integer
    type: object
  v1.Agent:
    properties:
      id:
        type: string
      instructions:
        type: string
        x-nullable: true
      model:
        type: string
      multi_agent:
        $ref: '#/definitions/v1.MultiAgentConfig'
      name:
        type: string
        x-nullable: true
      reasoning:
        $ref: '#/definitions/v1.Reasoning'
      service_tier:
        enum:
          - auto
        type: string
      text:
        $ref: '#/definitions/v1.TextConfig'
      tools:
        items:
          type: object
        type: array
      x_agents_core:
        allOf:
          - $ref: '#/definitions/v1.AgentsCore'
        x-nullable: true
    required:
      - id
      - model
      - multi_agent
      - reasoning
      - service_tier
      - text
      - tools
    type: object
  v1.AgentDeleted:
    properties:
      deleted:
        enum:
          - true
        type: boolean
      id:
        type: string
      object:
        enum:
          - agent.deleted
        type: string
    required:
      - deleted
      - id
      - object
    type: object
  v1.AgentsCore:
    properties:
      harness:
        enum:
          - claude_sdk
          - codex
          - mcode
        type: string
      harness_config:
        type: object
    type: object
  v1.Credential:
    properties:
      auth:
        $ref: '#/definitions/v1.CredentialAuth'
      created_at:
        type: integer
      id:
        type: string
      name:
        type: string
      object:
        enum:
          - vault.credential
        type: string
      updated_at:
        type: integer
      vault_id:
        type: string
    required:
      - auth
      - created_at
      - id
      - name
      - object
      - updated_at
      - vault_id
    type: object
  v1.CredentialAuth:
    properties:
      expires_at:
        type: string
        x-nullable: true
      mcp_server_url:
        type: string
      refresh:
        allOf:
          - $ref: '#/definitions/v1.OAuthCredentialRefresh'
        x-nullable: true
      type:
        enum:
          - static_bearer
          - mcp_oauth
        type: string
    required:
      - mcp_server_url
      - type
    type: object
  v1.CredentialDeleted:
    properties:
      deleted:
        type: boolean
      id:
        type: string
      object:
        enum:
          - vault.credential.deleted
        type: string
    required:
      - deleted
      - id
      - object
    type: object
  v1.CredentialList:
    properties:
      data:
        items:
          $ref: '#/definitions/v1.Credential'
        type: array
      first_id:
        type: string
        x-nullable: true
      has_more:
        type: boolean
      last_id:
        type: string
        x-nullable: true
      object:
        enum:
          - list
        type: string
    required:
      - data
      - has_more
      - object
    type: object
  v1.EnvironmentInstallation:
    properties:
      commands:
        additionalProperties:
          type: string
        type: object
      expires_at:
        type: integer
      message:
        type: string
      status:
        enum:
          - available
          - unavailable
        type: string
      version:
        type: string
    type: object
  v1.EnvironmentNetwork:
    properties:
      access:
        enum:
          - enabled
          - disabled
          - restricted
        type: string
      allowed_domains:
        items:
          type: string
        type: array
    required:
      - access
      - allowed_domains
    type: object
  v1.EnvironmentPackagesResponse:
    properties:
      npm:
        items:
          type: string
        type: array
      python:
        items:
          type: string
        type: array
      system:
        items:
          type: string
        type: array
    required:
      - npm
      - python
      - system
    type: object
  v1.EnvironmentTemplate:
    properties:
      capability_directories:
        items:
          type: string
        type: array
      created_at:
        type: integer
      files:
        items:
          type: object
        type: array
      id:
        type: string
      name:
        type: string
        x-nullable: true
      network:
        $ref: '#/definitions/v1.EnvironmentNetwork'
      object:
        enum:
          - agent.environment.template
        type: string
      packages:
        $ref: '#/definitions/v1.EnvironmentPackagesResponse'
      plugins:
        items:
          type: object
        type: array
      skills:
        items:
          type: object
        type: array
      updated_at:
        type: integer
    required:
      - capability_directories
      - created_at
      - files
      - id
      - network
      - object
      - packages
      - plugins
      - skills
      - updated_at
    type: object
  v1.EnvironmentTemplateDeleted:
    properties:
      deleted:
        type: boolean
      id:
        type: string
      object:
        enum:
          - agent.environment.template.deleted
        type: string
    required:
      - deleted
      - id
      - object
    type: object
  v1.EnvironmentTemplateList:
    properties:
      data:
        items:
          $ref: '#/definitions/v1.EnvironmentTemplate'
        type: array
      first_id:
        type: string
        x-nullable: true
      has_more:
        type: boolean
      last_id:
        type: string
        x-nullable: true
      object:
        enum:
          - list
        type: string
    required:
      - data
      - has_more
      - object
    type: object
  v1.ExecutionHarnessConfigSelection:
    properties:
      source:
        enum:
          - session
          - agent
          - deployment
          - unknown
        type: string
      value:
        type: object
    required:
      - source
      - value
    type: object
  v1.ExecutionProviderSelection:
    properties:
      configuration:
        allOf:
          - $ref: '#/definitions/v1.ModelProviderView'
        x-nullable: true
      source:
        enum:
          - session
          - agent
          - deployment
          - unknown
        type: string
      status:
        enum:
          - available
          - redacted
          - unavailable
        type: string
    required:
      - configuration
      - source
      - status
    type: object
  v1.ExecutionSelection:
    properties:
      source:
        enum:
          - session
          - agent
          - deployment
          - unknown
        type: string
      value:
        type: string
        x-nullable: true
    required:
      - source
      - value
    type: object
  v1.InputTokenDetails:
    properties:
      cached_tokens:
        type: integer
    required:
      - cached_tokens
    type: object
  v1.Item:
    properties:
      action:
        $ref: '#/definitions/v1.WebSearchAction'
      agent_id:
        type: string
      arguments: {}
      call_id:
        type: string
      command:
        type: string
      content:
        items:
          $ref: '#/definitions/v1.ItemContent'
        type: array
      cwd:
        type: string
      duration_ms:
        type: integer
      error: {}
      exit_code:
        type: integer
      id:
        type: string
      model:
        type: string
      name:
        type: string
      output: {}
      phase:
        enum:
          - commentary
          - final_answer
        type: string
        x-nullable: true
      reasoning_effort:
        type: string
      recipient_agent_id:
        type: string
      recipient_agent_ids:
        items:
          type: string
        type: array
      role:
        enum:
          - user
          - assistant
        type: string
      sender_agent_id:
        type: string
      server_label:
        type: string
      status:
        enum:
          - in_progress
          - completed
          - failed
          - incomplete
        type: string
      summary:
        items:
          $ref: '#/definitions/v1.SummaryText'
        type: array
      turn_id:
        type: string
      type:
        enum:
          - message
          - command_execution
          - mcp_call
          - function_call
          - function_call_output
          - web_search_call
          - reasoning
          - agent_message
          - create_subagent_call
          - send_subagent_input_call
          - resume_subagent_call
          - wait_for_subagents_call
          - interrupt_subagent_call
          - close_subagent_call
        type: string
    required:
      - id
      - turn_id
      - type
    type: object
  v1.ItemContent:
    properties:
      encrypted_content:
        type: string
      image_url:
        type: string
      text:
        type: string
      type:
        enum:
          - input_text
          - output_text
          - input_image
          - encrypted_content
        type: string
    required:
      - type
    type: object
  v1.ItemList:
    properties:
      data:
        items:
          $ref: '#/definitions/v1.Item'
        type: array
      first_id:
        type: string
        x-nullable: true
      has_more:
        type: boolean
      last_id:
        type: string
        x-nullable: true
      object:
        enum:
          - list
        type: string
    required:
      - data
      - has_more
      - object
    type: object
  v1.ModelConfigurationInput:
    properties:
      harness_config:
        type: object
      model:
        type: string
      model_provider:
        $ref: '#/definitions/v1.ModelProviderInput'
    required:
      - model
      - model_provider
    type: object
  v1.ModelConfigurationSupport:
    properties:
      accepts_harness_config:
        type: boolean
      protocols:
        items:
          type: string
        type: array
      token_limits_required:
        type: boolean
    required:
      - accepts_harness_config
      - protocols
      - token_limits_required
    type: object
  v1.ModelProviderInput:
    properties:
      api_key:
        type: string
      base_url:
        type: string
      context_window:
        type: integer
      max_output_tokens:
        type: integer
      protocol:
        enum:
          - anthropic
          - responses
          - chat_completions
        type: string
    required:
      - api_key
      - base_url
      - protocol
    type: object
  v1.ModelProviderView:
    properties:
      api_key_configured:
        type: boolean
      base_url:
        type: string
      context_window:
        type: integer
      max_output_tokens:
        type: integer
      protocol:
        enum:
          - anthropic
          - responses
          - chat_completions
        type: string
    required:
      - api_key_configured
      - base_url
      - protocol
    type: object
  v1.MultiAgentConfig:
    properties:
      enabled:
        type: boolean
      max_concurrent_subagents:
        type: integer
        x-nullable: true
    required:
      - enabled
    type: object
  v1.OAuthCredentialRefresh:
    properties:
      client_id:
        type: string
      resource:
        type: string
        x-nullable: true
      scope:
        type: string
        x-nullable: true
      token_endpoint:
        type: string
      token_endpoint_auth:
        $ref: '#/definitions/v1.OAuthEndpointAuth'
    required:
      - client_id
      - token_endpoint
      - token_endpoint_auth
    type: object
  v1.OAuthEndpointAuth:
    properties:
      type:
        enum:
          - none
          - client_secret_basic
          - client_secret_post
        type: string
    required:
      - type
    type: object
  v1.OutputTokenDetails:
    properties:
      reasoning_tokens:
        type: integer
    required:
      - reasoning_tokens
    type: object
  v1.Reasoning:
    properties:
      effort:
        type: string
        x-nullable: true
      summary:
        type: string
        x-nullable: true
    type: object
  v1.RequiredAction:
    properties:
      arguments: {}
      call_id:
        type: string
      environment_id:
        type: string
      name:
        type: string
      turn_id:
        type: string
      type:
        enum:
          - function_call
          - environment_connection
        type: string
    required:
      - type
    type: object
  v1.RuntimeCPUObservation:
    properties:
      capacity_cores:
        minimum: 5e-324
        type: number
        x-nullable: true
      usage_cores:
        minimum: 0
        type: number
        x-nullable: true
      usage_seconds_total:
        minimum: 0
        type: number
        x-nullable: true
      utilization_ratio:
        minimum: 0
        type: number
        x-nullable: true
    required:
      - capacity_cores
      - usage_cores
      - usage_seconds_total
      - utilization_ratio
    type: object
  v1.RuntimeHistory:
    properties:
      coverage:
        $ref: '#/definitions/v1.RuntimeHistoryCoverage'
      generated_at:
        maximum: 9007199254740991
        minimum: 0
        type: integer
      object:
        enum:
          - agent.runtime_history
        type: string
      requested_range:
        $ref: '#/definitions/v1.RuntimeHistoryRange'
      resolution_seconds:
        maximum: 9007199254740991
        minimum: 1
        type: integer
      series:
        items:
          $ref: '#/definitions/v1.RuntimeHistorySeries'
        maxItems: 1000
        type: array
      session_id:
        format: uuid
        type: string
      source:
        enum:
          - durable
        type: string
      token_usage:
        items:
          $ref: '#/definitions/v1.RuntimeHistoryTokenUsagePoint'
        maxItems: 10000
        type: array
    required:
      - coverage
      - generated_at
      - object
      - requested_range
      - resolution_seconds
      - series
      - session_id
      - source
      - token_usage
    type: object
  v1.RuntimeHistoryCPU:
    properties:
      capacity_cores:
        minimum: 5e-324
        type: number
        x-nullable: true
      contributor_count:
        maximum: 9007199254740991
        minimum: 1
        type: integer
      utilization_ratio:
        minimum: 0
        type: number
        x-nullable: true
    required:
      - capacity_cores
      - contributor_count
      - utilization_ratio
    type: object
  v1.RuntimeHistoryCoverage:
    properties:
      buckets:
        items:
          $ref: '#/definitions/v1.RuntimeHistoryCoveragePoint'
        maxItems: 10000
        type: array
      expected_sample_count:
        maximum: 9007199254740991
        minimum: 0
        type: integer
      first_sample_at:
        maximum: 9007199254740991
        minimum: 0
        type: integer
        x-nullable: true
      last_sample_at:
        maximum: 9007199254740991
        minimum: 0
        type: integer
        x-nullable: true
      retained_start:
        maximum: 9007199254740991
        minimum: 0
        type: integer
      sample_count:
        maximum: 9007199254740991
        minimum: 0
        type: integer
    required:
      - buckets
      - expected_sample_count
      - first_sample_at
      - last_sample_at
      - retained_start
      - sample_count
    type: object
  v1.RuntimeHistoryCoveragePoint:
    properties:
      end:
        maximum: 9007199254740991
        minimum: 1
        type: integer
      first_observed_at:
        maximum: 9007199254740991
        minimum: 0
        type: integer
        x-nullable: true
      last_observed_at:
        maximum: 9007199254740991
        minimum: 0
        type: integer
        x-nullable: true
      observation_count:
        maximum: 9007199254740991
        minimum: 0
        type: integer
      observed_count:
        maximum: 9007199254740991
        minimum: 0
        type: integer
      start:
        maximum: 9007199254740991
        minimum: 0
        type: integer
      unavailable_count:
        maximum: 9007199254740991
        minimum: 0
        type: integer
    required:
      - end
      - first_observed_at
      - last_observed_at
      - observation_count
      - observed_count
      - start
      - unavailable_count
    type: object
  v1.RuntimeHistoryMemory:
    properties:
      contributor_count:
        maximum: 9007199254740991
        minimum: 1
        type: integer
      limit_bytes:
        maximum: 9007199254740991
        minimum: 1
        type: integer
        x-nullable: true
      usage_bytes:
        maximum: 9007199254740991
        minimum: 0
        type: integer
        x-nullable: true
    required:
      - contributor_count
      - limit_bytes
      - usage_bytes
    type: object
  v1.RuntimeHistoryPoint:
    properties:
      cpu:
        allOf:
          - $ref: '#/definitions/v1.RuntimeHistoryCPU'
        x-nullable: true
      end:
        maximum: 9007199254740991
        minimum: 1
        type: integer
      first_observed_at:
        maximum: 9007199254740991
        minimum: 0
        type: integer
        x-nullable: true
      last_observed_at:
        maximum: 9007199254740991
        minimum: 0
        type: integer
        x-nullable: true
      memory:
        allOf:
          - $ref: '#/definitions/v1.RuntimeHistoryMemory'
        x-nullable: true
      observation_count:
        maximum: 9007199254740991
        minimum: 0
        type: integer
      observed_count:
        maximum: 9007199254740991
        minimum: 0
        type: integer
      start:
        maximum: 9007199254740991
        minimum: 0
        type: integer
      unavailable_count:
        maximum: 9007199254740991
        minimum: 0
        type: integer
    required:
      - cpu
      - end
      - first_observed_at
      - last_observed_at
      - memory
      - observation_count
      - observed_count
      - start
      - unavailable_count
    type: object
  v1.RuntimeHistoryRange:
    properties:
      end:
        maximum: 9007199254740991
        minimum: 1
        type: integer
      start:
        maximum: 9007199254740991
        minimum: 0
        type: integer
    required:
      - end
      - start
    type: object
  v1.RuntimeHistorySeries:
    properties:
      allocation_id:
        format: uuid
        type: string
      environment_id:
        format: uuid
        type: string
      points:
        items:
          $ref: '#/definitions/v1.RuntimeHistoryPoint'
        maxItems: 10000
        type: array
      provider_type:
        pattern: '^[a-z][a-z0-9_]{0,31}$'
        type: string
      started_at:
        $ref: '#/definitions/v1.RuntimeHistoryTime'
    required:
      - allocation_id
      - environment_id
      - points
      - provider_type
      - started_at
    type: object
  v1.RuntimeHistoryTime:
    properties:
      nanoseconds:
        maximum: 999999999
        minimum: 0
        type: integer
      seconds:
        maximum: 9007199254740991
        minimum: 0
        type: integer
    required:
      - nanoseconds
      - seconds
    type: object
  v1.RuntimeHistoryTokenUsagePoint:
    properties:
      end:
        maximum: 9007199254740991
        minimum: 1
        type: integer
      input_tokens:
        maximum: 9007199254740991
        minimum: 0
        type: integer
      output_tokens:
        maximum: 9007199254740991
        minimum: 0
        type: integer
      sampled_at:
        maximum: 9007199254740991
        minimum: 0
        type: integer
      start:
        maximum: 9007199254740991
        minimum: 0
        type: integer
    required:
      - end
      - input_tokens
      - output_tokens
      - sampled_at
      - start
    type: object
  v1.RuntimeInstance:
    properties:
      allocation_id:
        format: uuid
        type: string
        x-nullable: true
      connection_generation:
        format: uuid
        type: string
        x-nullable: true
      device_id:
        format: uuid
        type: string
        x-nullable: true
      kind:
        enum:
          - managed_allocation
          - self_hosted_connection
          - none
        type: string
    required:
      - allocation_id
      - connection_generation
      - device_id
      - kind
    type: object
  v1.RuntimeMemoryObservation:
    properties:
      limit_bytes:
        minimum: 1
        type: integer
        x-nullable: true
      usage_bytes:
        minimum: 0
        type: integer
        x-nullable: true
    required:
      - limit_bytes
      - usage_bytes
    type: object
  v1.RuntimeObservation:
    properties:
      allocation_created_at:
        minimum: 0
        type: integer
        x-nullable: true
      cpu:
        allOf:
          - $ref: '#/definitions/v1.RuntimeCPUObservation'
        x-nullable: true
      environment_id:
        format: uuid
        type: string
        x-nullable: true
      id:
        format: uuid
        type: string
      instance:
        $ref: '#/definitions/v1.RuntimeInstance'
      lifecycle_state:
        enum:
          - active
          - sleeping
          - transitioning
          - pending
          - stopped
        type: string
        x-nullable: true
      memory:
        allOf:
          - $ref: '#/definitions/v1.RuntimeMemoryObservation'
        x-nullable: true
      mode:
        enum:
          - none
          - self_hosted
          - openai_hosted
        type: string
      object:
        enum:
          - agent.runtime_observation
        type: string
      observed_at:
        minimum: 0
        type: integer
        x-nullable: true
      provider_type:
        type: string
        x-nullable: true
      reason:
        enum:
          - runtime_mode_not_observable
          - allocation_pending
          - runtime_not_running
          - source_not_configured
          - sample_timeout
          - sample_unavailable
        type: string
        x-nullable: true
      resolved_at:
        minimum: 0
        type: integer
      session_id:
        format: uuid
        type: string
      started_at:
        minimum: 0
        type: integer
        x-nullable: true
      status:
        enum:
          - observed
          - unsupported
          - unavailable
        type: string
    required:
      - allocation_created_at
      - cpu
      - environment_id
      - id
      - instance
      - lifecycle_state
      - memory
      - mode
      - object
      - observed_at
      - provider_type
      - reason
      - resolved_at
      - session_id
      - started_at
      - status
    type: object
  v1.SavedAgent:
    properties:
      created_at:
        type: integer
      id:
        type: string
      instructions:
        type: string
        x-nullable: true
      metadata:
        additionalProperties:
          type: string
        type: object
      model:
        type: string
      multi_agent:
        $ref: '#/definitions/v1.MultiAgentConfig'
      name:
        type: string
        x-nullable: true
      object:
        enum:
          - agent
        type: string
      reasoning:
        $ref: '#/definitions/v1.Reasoning'
      service_tier:
        enum:
          - auto
          - default
          - flex
          - priority
          - fast
        type: string
      text:
        $ref: '#/definitions/v1.SavedAgentText'
      tools:
        items:
          type: object
        type: array
      updated_at:
        type: integer
      x_agents_core:
        allOf:
          - $ref: '#/definitions/v1.SavedAgentCore'
        x-nullable: true
    required:
      - created_at
      - id
      - metadata
      - model
      - multi_agent
      - object
      - reasoning
      - service_tier
      - text
      - tools
      - updated_at
    type: object
  v1.SavedAgentCore:
    properties:
      harness:
        enum:
          - claude_sdk
          - codex
          - mcode
        type: string
      harness_config:
        type: object
      model_provider:
        $ref: '#/definitions/v1.ModelProviderView'
    type: object
  v1.SavedAgentList:
    properties:
      data:
        items:
          $ref: '#/definitions/v1.SavedAgent'
        type: array
      first_id:
        type: string
        x-nullable: true
      has_more:
        type: boolean
      last_id:
        type: string
        x-nullable: true
      object:
        enum:
          - list
        type: string
    required:
      - data
      - has_more
      - object
    type: object
  v1.SavedAgentText:
    properties:
      format:
        $ref: '#/definitions/v1.SavedAgentTextFormat'
      verbosity:
        enum:
          - low
          - medium
          - high
        type: string
    required:
      - format
      - verbosity
    type: object
  v1.SavedAgentTextFormat:
    properties:
      schema:
        type: object
      type:
        enum:
          - text
          - json_schema
        type: string
    required:
      - type
    type: object
  v1.Session:
    properties:
      agent:
        $ref: '#/definitions/v1.Agent'
      created_at:
        type: integer
      environment:
        $ref: '#/definitions/v1.SessionEnvironment'
      error:
        type: string
        x-nullable: true
      id:
        type: string
      last_active_at:
        type: integer
      metadata:
        additionalProperties:
          type: string
        type: object
      object:
        enum:
          - agent.session
        type: string
      required_actions:
        items:
          $ref: '#/definitions/v1.RequiredAction'
        type: array
      status:
        enum:
          - idle
          - in_progress
          - requires_action
          - failed
        type: string
      usage:
        allOf:
          - $ref: '#/definitions/v1.TokenUsage'
        x-nullable: true
      vault_ids:
        items:
          type: string
        type: array
      x_agents_core:
        $ref: '#/definitions/v1.SessionCore'
    required:
      - agent
      - created_at
      - environment
      - id
      - last_active_at
      - metadata
      - object
      - required_actions
      - status
      - vault_ids
    type: object
  v1.SessionArtifact:
    properties:
      created_at:
        type: integer
      environment_id:
        type: string
      id:
        type: string
      object:
        enum:
          - agent.session.artifact
        type: string
      path:
        type: string
      session_id:
        type: string
      size_bytes:
        type: integer
      turn_id:
        type: string
    required:
      - created_at
      - environment_id
      - id
      - object
      - path
      - session_id
      - size_bytes
      - turn_id
    type: object
  v1.SessionArtifactDeleted:
    properties:
      deleted:
        type: boolean
      id:
        type: string
      object:
        enum:
          - agent.session.artifact.deleted
        type: string
    required:
      - deleted
      - id
      - object
    type: object
  v1.SessionArtifactList:
    properties:
      data:
        items:
          $ref: '#/definitions/v1.SessionArtifact'
        type: array
      first_id:
        type: string
        x-nullable: true
      has_more:
        type: boolean
      last_id:
        type: string
        x-nullable: true
      object:
        enum:
          - list
        type: string
    required:
      - data
      - has_more
      - object
    type: object
  v1.SessionCore:
    properties:
      installation:
        $ref: '#/definitions/v1.EnvironmentInstallation'
    type: object
  v1.SessionDeleted:
    properties:
      deleted:
        type: boolean
      id:
        type: string
      object:
        enum:
          - agent.session.deleted
        type: string
    required:
      - deleted
      - id
      - object
    type: object
  v1.SessionEnvironment:
    properties:
      capability_directories:
        items:
          type: string
        type: array
      files:
        items:
          type: object
        type: array
      id:
        type: string
      network:
        $ref: '#/definitions/v1.EnvironmentNetwork'
      packages:
        $ref: '#/definitions/v1.EnvironmentPackagesResponse'
      plugins:
        items:
          type: object
        type: array
      remote_url:
        type: string
      skills:
        items:
          type: object
        type: array
      type:
        enum:
          - none
          - self_hosted
          - openai_hosted
        type: string
      workspace_directory:
        type: string
    required:
      - type
    type: object
  v1.SessionExecutionConfiguration:
    properties:
      harness:
        $ref: '#/definitions/v1.ExecutionSelection'
      harness_config:
        $ref: '#/definitions/v1.ExecutionHarnessConfigSelection'
      model:
        $ref: '#/definitions/v1.ExecutionSelection'
      model_provider:
        $ref: '#/definitions/v1.ExecutionProviderSelection'
      object:
        enum:
          - agent.session.execution_configuration
        type: string
      schema_version:
        enum:
          - 1
        type: integer
      session_id:
        type: string
    required:
      - harness
      - harness_config
      - model
      - model_provider
      - object
      - schema_version
      - session_id
    type: object
  v1.SessionList:
    properties:
      data:
        items:
          $ref: '#/definitions/v1.Session'
        type: array
      first_id:
        type: string
        x-nullable: true
      has_more:
        type: boolean
      last_id:
        type: string
        x-nullable: true
      object:
        enum:
          - list
        type: string
    required:
      - data
      - has_more
      - object
    type: object
  v1.Skill:
    properties:
      created_at:
        type: integer
      default_version:
        type: string
      description:
        type: string
      id:
        type: string
      latest_version:
        type: string
      name:
        type: string
      object:
        enum:
          - skill
        type: string
    required:
      - created_at
      - default_version
      - description
      - id
      - latest_version
      - name
      - object
    type: object
  v1.SkillDeleted:
    properties:
      deleted:
        type: boolean
      id:
        type: string
      object:
        enum:
          - skill.deleted
        type: string
    required:
      - deleted
      - id
      - object
    type: object
  v1.SkillList:
    properties:
      data:
        items:
          $ref: '#/definitions/v1.Skill'
        type: array
      first_id:
        type: string
        x-nullable: true
      has_more:
        type: boolean
      last_id:
        type: string
        x-nullable: true
      object:
        enum:
          - list
        type: string
    required:
      - data
      - has_more
      - object
    type: object
  v1.SkillVersion:
    properties:
      created_at:
        type: integer
      description:
        type: string
      id:
        type: string
      name:
        type: string
      object:
        enum:
          - skill.version
        type: string
      skill_id:
        type: string
      version:
        type: string
    required:
      - created_at
      - description
      - id
      - name
      - object
      - skill_id
      - version
    type: object
  v1.SkillVersionDeleted:
    properties:
      deleted:
        type: boolean
      id:
        type: string
      object:
        enum:
          - skill.version.deleted
        type: string
      version:
        type: string
    required:
      - deleted
      - id
      - object
      - version
    type: object
  v1.SkillVersionList:
    properties:
      data:
        items:
          $ref: '#/definitions/v1.SkillVersion'
        type: array
      first_id:
        type: string
        x-nullable: true
      has_more:
        type: boolean
      last_id:
        type: string
        x-nullable: true
      object:
        enum:
          - list
        type: string
    required:
      - data
      - has_more
      - object
    type: object
  v1.SourceFile:
    properties:
      bytes:
        minimum: 0
        type: integer
      created_at:
        type: integer
      expires_at:
        type: integer
        x-nullable: true
      filename:
        type: string
      id:
        type: string
      object:
        enum:
          - file
        type: string
      purpose:
        enum:
          - user_data
        type: string
      status:
        enum:
          - processed
        type: string
      status_details:
        type: string
        x-nullable: true
    required:
      - bytes
      - created_at
      - filename
      - id
      - object
      - purpose
      - status
    type: object
  v1.SourceFileDeleted:
    properties:
      deleted:
        type: boolean
      id:
        type: string
      object:
        enum:
          - file
        type: string
    required:
      - deleted
      - id
      - object
    type: object
  v1.SourceFileList:
    properties:
      data:
        items:
          $ref: '#/definitions/v1.SourceFile'
        type: array
      first_id:
        type: string
        x-nullable: true
      has_more:
        type: boolean
      last_id:
        type: string
        x-nullable: true
      object:
        enum:
          - list
        type: string
    required:
      - data
      - has_more
      - object
    type: object
  v1.SummaryText:
    properties:
      text:
        type: string
      type:
        enum:
          - summary_text
        type: string
    required:
      - text
      - type
    type: object
  v1.TextConfig:
    properties:
      format:
        $ref: '#/definitions/v1.TextFormat'
      verbosity:
        enum:
          - low
          - medium
          - high
        type: string
    required:
      - format
      - verbosity
    type: object
  v1.TextFormat:
    properties:
      schema:
        type: object
      type:
        enum:
          - text
          - json_schema
        type: string
    required:
      - type
    type: object
  v1.TokenUsage:
    properties:
      input_tokens:
        type: integer
      input_tokens_details:
        $ref: '#/definitions/v1.InputTokenDetails'
      output_tokens:
        type: integer
      output_tokens_details:
        $ref: '#/definitions/v1.OutputTokenDetails'
      total_tokens:
        type: integer
    required:
      - input_tokens
      - input_tokens_details
      - output_tokens
      - output_tokens_details
      - total_tokens
    type: object
  v1.Turn:
    properties:
      agent_id:
        type: string
      completed_at:
        type: integer
        x-nullable: true
      created_at:
        type: integer
      error:
        allOf:
          - $ref: '#/definitions/v1.TurnError'
        x-nullable: true
      id:
        type: string
      object:
        enum:
          - agent.session.turn
        type: string
      session_id:
        type: string
      started_at:
        type: integer
        x-nullable: true
      status:
        enum:
          - queued
          - in_progress
          - waiting
          - completed
          - failed
          - cancelled
        type: string
      subagent_id:
        type: string
        x-nullable: true
      usage:
        allOf:
          - $ref: '#/definitions/v1.TokenUsage'
        x-nullable: true
    required:
      - agent_id
      - created_at
      - id
      - object
      - session_id
      - status
    type: object
  v1.TurnError:
    properties:
      code:
        enum:
          - context_length_exceeded
          - session_budget_exceeded
          - usage_limit_exceeded
          - rate_limit_exceeded
          - server_overloaded
          - cyber_policy
          - connection_failed
          - server_error
          - authentication_error
          - invalid_request
          - resource_not_found
          - sandbox_error
          - executor_version_incompatible
          - active_turn_not_steerable
          - request_timeout
          - internal_error
        type: string
      message:
        type: string
    required:
      - code
      - message
    type: object
  v1.TurnList:
    properties:
      data:
        items:
          $ref: '#/definitions/v1.Turn'
        type: array
      first_id:
        type: string
        x-nullable: true
      has_more:
        type: boolean
      last_id:
        type: string
        x-nullable: true
      object:
        enum:
          - list
        type: string
    required:
      - data
      - has_more
      - object
    type: object
  v1.Vault:
    properties:
      created_at:
        type: integer
      id:
        type: string
      metadata:
        additionalProperties:
          type: string
        type: object
      name:
        type: string
        x-nullable: true
      object:
        enum:
          - vault
        type: string
    required:
      - created_at
      - id
      - metadata
      - object
    type: object
  v1.VaultDeleted:
    properties:
      deleted:
        type: boolean
      id:
        type: string
      object:
        enum:
          - vault.deleted
        type: string
    required:
      - deleted
      - id
      - object
    type: object
  v1.VaultList:
    properties:
      data:
        items:
          $ref: '#/definitions/v1.Vault'
        type: array
      first_id:
        type: string
        x-nullable: true
      has_more:
        type: boolean
      last_id:
        type: string
        x-nullable: true
      object:
        enum:
          - list
        type: string
    required:
      - data
      - has_more
      - object
    type: object
  v1.WebSearchAction:
    properties:
      pattern:
        type: string
      queries:
        items:
          type: string
        type: array
      query:
        type: string
      type:
        enum:
          - search
          - open_page
          - find_in_page
          - other
        type: string
      url:
        type: string
    required:
      - type
    type: object
  writeaudit.APIKey:
    properties:
      id:
        type: string
      kind:
        type: string
      name:
        type: string
      prefix:
        type: string
      revoked_at:
        type: string
    type: object
  writeaudit.Operation:
    properties:
      action:
        type: string
      api_key:
        $ref: '#/definitions/writeaudit.APIKey'
      created_at:
        type: string
      id:
        type: string
      parent_id:
        type: string
      request_id:
        type: string
      resource_id:
        type: string
      resource_type:
        type: string
      trace_id:
        type: string
    type: object
  writeaudit.Page:
    properties:
      data:
        items:
          $ref: '#/definitions/writeaudit.Operation'
        type: array
      has_more:
        type: boolean
      next_cursor:
        type: string
    type: object
  writeaudit.ResourceOwner:
    properties:
      admin_audit_id:
        type: string
      api_key:
        $ref: '#/definitions/writeaudit.APIKey'
      resource_id:
        type: string
      source:
        type: string
    type: object
info:
  contact: {}
  description: Deployment and operations routes under /core/v1 for Core Web's server and operator scripts. Every operation requires the Core key; Project API keys and machine credentials are not accepted.
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
  title: OpenAgentCore Core API
  version: "1"
paths:
  /core/v1/audit-log:
    get:
      description: Core key only. Newest-first cursor pagination of safe metadata. Actor labels are unverified console labels, not authorization identities. Request bodies and secrets are never recorded.
      parameters:
        - description: Target Project ID
          in: query
          name: project_id
          type: string
        - description: Resource type
          in: query
          name: resource_type
          type: string
        - description: Resource ID
          in: query
          name: resource_id
          type: string
        - description: Mutation action
          in: query
          name: action
          type: string
        - description: Inclusive RFC3339 timestamp
          in: query
          name: created_after
          type: string
        - description: Exclusive RFC3339 timestamp
          in: query
          name: created_before
          type: string
        - default: 50
          description: Page size
          in: query
          maximum: 100
          minimum: 1
          name: limit
          type: integer
        - description: Opaque next_cursor from the preceding page
          in: query
          name: after
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/adminaudit.Page'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Query committed administrator mutations
      tags:
        - Core Administration
  /core/v1/harnesses:
    get:
      description: Core key only. Returns every harness this build supports, in name order. enabled and default are read-only views of the process configuration (OAC_DEFAULT_HARNESS and OAC_HARNESSES). model_configuration is the harness's deployment default, stored in Core, or null. Keys are never returned; api_key_configured reports that one is set.
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/api.CoreHarnessList'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: List harnesses and their deployment default model providers
      tags:
        - Deployment Model Providers
  /core/v1/harnesses/{harness}/model-configuration:
    delete:
      description: Core key only. Idempotent; each successful request is audited. Sessions that already froze the default keep it. Afterwards new openai_hosted Sessions for this harness need a Session or Agent bundle.
      parameters:
        - description: Harness
          enum:
            - claude_sdk
            - codex
            - mcode
          in: path
          name: harness
          required: true
          type: string
      responses:
        "204":
          description: No Content
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Remove a harness's deployment default model provider
      tags:
        - Deployment Model Providers
    get:
      description: Core key only. Returns the safe view; the key is never returned. 404 when the harness does not exist or has no deployment default. Nullable last_used_at, last_error_code and last_error_at are best-effort observations of committed root Turns using this exact default revision; they do not establish current readiness and may remain stale indefinitely.
      parameters:
        - description: Harness
          enum:
            - claude_sdk
            - codex
            - mcode
          in: path
          name: harness
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/api.HarnessModelConfiguration'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Retrieve a harness's deployment default model provider
      tags:
        - Deployment Model Providers
    put:
      consumes:
        - application/json
      description: Core key only. Replaces one complete deployment model configuration, including its write-only provider key. Validates through the selected Harness declaration and freezes the resolved configuration for new Sessions; existing Sessions are unchanged. See contracts/agents-api/model-execution.md#deployment-defaults for fields, source precedence and observation rules.
      parameters:
        - description: Harness
          enum:
            - claude_sdk
            - codex
            - mcode
          in: path
          name: harness
          required: true
          type: string
        - description: Complete model provider bundle
          in: body
          name: body
          required: true
          schema:
            $ref: '#/definitions/v1.ModelConfigurationInput'
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/api.HarnessModelConfiguration'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "413":
          description: Request Entity Too Large
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Replace a harness's deployment default model provider
      tags:
        - Deployment Model Providers
  /core/v1/installation:
    get:
      description: Core key only; available before any sandbox deployment exists. Reports the public URL that applications, nodes, sandboxes and self-hosted executors use, the API base URL, Core's source commit and installation ID, the installer's settings snapshot with where to change it, and what is bound to the current public URL. Sensitive settings report only whether they are configured.
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/api.Installation'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Retrieve installation facts and process settings
      tags:
        - Core Administration
  /core/v1/metrics:
    get:
      description: Core key only. Complete UTC buckets; unknown measurements are null. Samples are process-local and are not backfilled after a restart.
      parameters:
        - description: Time range (default 1h)
          enum:
            - 1h
            - 6h
            - 24h
            - 7d
          in: query
          name: range
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/coremetrics.View'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Retrieve Core operational metrics
      tags:
        - Core Administration
  /core/v1/projects:
    get:
      parameters:
        - description: Project ID cursor
          in: query
          name: after
          type: string
        - description: Page size (1-100)
          in: query
          name: limit
          type: integer
        - description: asc or desc by Project ID
          in: query
          name: order
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/projects.Page'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: List Projects and active key counts
      tags:
        - Administrator Projects
    post:
      consumes:
        - application/json
      parameters:
        - description: Project display name
          in: body
          name: body
          required: true
          schema:
            $ref: '#/definitions/api.ProjectRequest'
      produces:
        - application/json
      responses:
        "201":
          description: Created
          schema:
            $ref: '#/definitions/projects.Project'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "409":
          description: Conflict
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Create an empty independent Project
      tags:
        - Administrator Projects
  /core/v1/projects/{project_id}:
    post:
      consumes:
        - application/json
      parameters:
        - description: Project UUID
          in: path
          name: project_id
          required: true
          type: string
        - description: Project display name
          in: body
          name: body
          required: true
          schema:
            $ref: '#/definitions/api.ProjectRequest'
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/projects.Project'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "409":
          description: Conflict
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Rename a Project
      tags:
        - Administrator Projects
  /core/v1/projects/{project_id}/agents:
    get:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Last Agent ID from the previous page
          in: query
          name: after
          type: string
        - default: 20
          description: Page size; 0 is treated as 1 and values above 100 as 100
          in: query
          minimum: 0
          name: limit
          type: integer
        - default: desc
          description: Creation order; omit for descending, explicit empty values are invalid
          enum:
            - asc
            - desc
          in: query
          name: order
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SavedAgentList'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: List reusable Agents in a Project
      tags:
        - Agents
  /core/v1/projects/{project_id}/agents/{agent_id}:
    delete:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Agent ID
          in: path
          name: agent_id
          required: true
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.AgentDeleted'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "413":
          description: Request Entity Too Large
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Delete a reusable Agent in a Project
      tags:
        - Agents
    get:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Agent ID
          in: path
          name: agent_id
          required: true
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SavedAgent'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Retrieve a reusable Agent in a Project
      tags:
        - Agents
  /core/v1/projects/{project_id}/archive:
    post:
      parameters:
        - description: Project UUID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/projects.Project'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "409":
          description: Conflict
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Archive a Project and revoke all its keys while retaining assets
      tags:
        - Administrator Projects
  /core/v1/projects/{project_id}/environment-templates:
    get:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Previous Template ID
          in: query
          name: after
          type: string
        - default: 20
          description: Page size; 0 is treated as 1 and values above 100 as 100
          in: query
          minimum: 0
          name: limit
          type: integer
        - default: desc
          description: Creation order; omit for descending, explicit empty values are invalid
          enum:
            - asc
            - desc
          in: query
          name: order
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.EnvironmentTemplateList'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: List Environment Templates in a Project
      tags:
        - Environment Templates
  /core/v1/projects/{project_id}/environment-templates/{environment_template_id}:
    delete:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Template ID
          in: path
          name: environment_template_id
          required: true
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.EnvironmentTemplateDeleted'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Delete an Environment Template in a Project
      tags:
        - Environment Templates
    get:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Template ID
          in: path
          name: environment_template_id
          required: true
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.EnvironmentTemplate'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Retrieve an Environment Template in a Project
      tags:
        - Environment Templates
  /core/v1/projects/{project_id}/environments/{environment_id}/executor-credentials:
    get:
      description: Core key only. Returns metadata of the credentials restricted to this Environment, oldest first; secrets are never listed. Connection combines current credential authority and an open matching gateway peer; timestamps are historical observations, not readiness. Without a gateway it is never connected. The Environment must be a self_hosted Environment of the Project whose Session exists; otherwise 404.
      parameters:
        - description: Project UUID
          in: path
          name: project_id
          required: true
          type: string
        - description: Environment UUID
          in: path
          name: environment_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/api.ExecutorCredentialList'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: List a self_hosted Environment's executor credentials
      tags:
        - Executor Credentials
    post:
      consumes:
        - application/json
      description: Core key only. Returns a connect-only secret once, restricted to daemon enrollment and connection for this Environment, with the Project's principal as its execution principal. Repeating an issuance key_id returns 409 executor_credential_exists; after an uncertain response, list the credentials and rotate that key_id explicitly. Rotation keeps the key's Environment, invalidates the old secret and restores a revoked key; rotating an unknown key_id returns 404. In an archived Project, issuance and rotation return 409 project_archived. The Environment must be a self_hosted Environment of the Project whose Session exists; otherwise 404. Each write records an administrator audit entry without the secret.
      parameters:
        - description: Project UUID
          in: path
          name: project_id
          required: true
          type: string
        - description: Environment UUID
          in: path
          name: environment_id
          required: true
          type: string
        - description: Request
          in: body
          name: body
          required: true
          schema:
            $ref: '#/definitions/api.EnvironmentExecutorCredentialRequest'
      produces:
        - application/json
      responses:
        "201":
          description: Created
          schema:
            $ref: '#/definitions/sessions.IssuedExecutorCredential'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "409":
          description: Conflict
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Issue or explicitly rotate a self_hosted Environment executor credential
      tags:
        - Executor Credentials
  /core/v1/projects/{project_id}/environments/{environment_id}/executor-credentials/{key_id}:
    delete:
      description: Core key only. Revokes one credential restricted to this Environment; repeated revocation is safe and it also works in an archived Project. Revocation denies future enrollment and connection but does not stop executor-owned compute. The Environment must be a self_hosted Environment of the Project whose Session exists; otherwise 404.
      parameters:
        - description: Project UUID
          in: path
          name: project_id
          required: true
          type: string
        - description: Environment UUID
          in: path
          name: environment_id
          required: true
          type: string
        - description: Executor key UUID
          in: path
          name: key_id
          required: true
          type: string
      responses:
        "204":
          description: No Content
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Revoke a self_hosted Environment executor credential
      tags:
        - Executor Credentials
  /core/v1/projects/{project_id}/environments/{environment_id}/installation:
    get:
      description: Core key only. The commands contain a 30-minute installation authorization, never an executor secret. Web displays these same commands provided in public Session creation and detail responses.
      parameters:
        - description: Project UUID
          in: path
          name: project_id
          required: true
          type: string
        - description: Environment UUID
          in: path
          name: environment_id
          required: true
          type: string
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.EnvironmentInstallation'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "409":
          description: Conflict
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Get a self_hosted Session's installation commands
      tags:
        - Native Installation
  /core/v1/projects/{project_id}/files:
    get:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Last File ID from the previous page
          in: query
          name: after
          type: string
        - default: 10000
          description: Maximum page size, 1–10000
          in: query
          maximum: 10000
          minimum: 1
          name: limit
          type: integer
        - default: desc
          description: Creation order; omit for descending, explicit empty values are invalid
          enum:
            - asc
            - desc
          in: query
          name: order
          type: string
        - description: Only return Files with this purpose
          in: query
          name: purpose
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SourceFileList'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: List source files in a Project
      tags:
        - Files
  /core/v1/projects/{project_id}/files/{file_id}:
    delete:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Source file ID
          in: path
          name: file_id
          required: true
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SourceFileDeleted'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Delete a source file in a Project
      tags:
        - Files
    get:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Source file ID
          in: path
          name: file_id
          required: true
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SourceFile'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Retrieve source file metadata in a Project
      tags:
        - Files
  /core/v1/projects/{project_id}/keys:
    get:
      parameters:
        - description: Project UUID
          in: path
          name: project_id
          required: true
          type: string
        - description: Key ID cursor
          in: query
          name: after
          type: string
        - description: Page size (1-100)
          in: query
          name: limit
          type: integer
        - description: asc or desc by key ID
          in: query
          name: order
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/projects.KeyPage'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: List safe key metadata for a Project
      tags:
        - Administrator Projects
    post:
      consumes:
        - application/json
      parameters:
        - description: Project UUID
          in: path
          name: project_id
          required: true
          type: string
        - description: Key display name
          in: body
          name: body
          required: true
          schema:
            $ref: '#/definitions/api.ProjectAPIKeyRequest'
      produces:
        - application/json
      responses:
        "201":
          description: Created
          schema:
            $ref: '#/definitions/projects.IssuedAPIKey'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "409":
          description: Conflict
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Issue an independent secret in an existing Project
      tags:
        - Administrator Projects
  /core/v1/projects/{project_id}/keys/{key_id}:
    delete:
      parameters:
        - description: Project UUID
          in: path
          name: project_id
          required: true
          type: string
        - description: API key UUID
          in: path
          name: key_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/api.SandboxMutationResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "409":
          description: Conflict
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Revoke one Project key while retaining shared assets
      tags:
        - Administrator Projects
  /core/v1/projects/{project_id}/resource-owners:
    get:
      description: Core key only. The Project ID path selects its space. Returns null for resources without recorded creation provenance, including historical and foreign resources. No key secret is returned.
      parameters:
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
        - description: Resource type
          in: query
          name: resource_type
          required: true
          type: string
        - description: Comma-separated public resource IDs, maximum 100
          in: query
          name: resource_ids
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/api.ResourceOwnerList'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Batch lookup resource creation keys
      tags:
        - Write Audit
  /core/v1/projects/{project_id}/sessions:
    get:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Root Agent ID whose Sessions to return
          in: query
          name: agent_id
          type: string
        - description: Last Session ID from the previous page
          in: query
          name: after
          type: string
        - default: 20
          description: Page size; 0 is treated as 1 and values above 100 as 100
          in: query
          minimum: 0
          name: limit
          type: integer
        - default: desc
          description: Creation order; omit for descending, explicit empty values are invalid
          enum:
            - asc
            - desc
          in: query
          name: order
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SessionList'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: List execution Sessions in a Project
      tags:
        - Sessions
  /core/v1/projects/{project_id}/sessions/{session_id}:
    delete:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Session ID
          in: path
          name: session_id
          required: true
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SessionDeleted'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "409":
          description: Conflict
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "413":
          description: Request Entity Too Large
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Delete an execution Session in a Project
      tags:
        - Sessions
    get:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Session ID
          in: path
          name: session_id
          required: true
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.Session'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Retrieve an execution Session in a Project
      tags:
        - Sessions
  /core/v1/projects/{project_id}/sessions/{session_id}/archive:
    get:
      description: Core key only. Reports actual resource disposition, including expiry and failure cleanup. This is not archive provenance and does not assert active Turn settlement. Read this after an uncertain archive response; never infer released from a missing sandbox alone.
      parameters:
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
        - description: Session ID
          in: path
          name: session_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/sessions.ManagedArchive'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Retrieve a managed Session's resource cleanup state
      tags:
        - Core Administration
    post:
      consumes:
        - application/json
      description: Core key only. Requires the current deployment generation; no maintenance mode is required. Permanently closes execution, requests cancellation and releases sandbox/snapshots through existing cleanup. Session history and persisted files/artifacts remain; unpersisted workspace contents are lost. A cleanup_pending response is not proof of resource release. Does not affect caller-managed Runtime.
      parameters:
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
        - description: Session ID
          in: path
          name: session_id
          required: true
          type: string
        - description: Current deployment generation
          in: body
          name: body
          required: true
          schema:
            $ref: '#/definitions/api.AdminSessionArchiveRequest'
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/sessions.ManagedArchive'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "409":
          description: Conflict
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "413":
          description: Request Entity Too Large
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Release a managed Session's execution resources while retaining history
      tags:
        - Core Administration
  /core/v1/projects/{project_id}/sessions/{session_id}/artifacts:
    get:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Session ID
          in: path
          name: session_id
          required: true
          type: string
        - description: Producing Environment ID; an unknown or malformed ID returns an empty page
          in: query
          name: environment_id
          type: string
        - description: Last immutable artifact ID
          in: query
          name: after
          type: string
        - default: 20
          description: Page size
          in: query
          maximum: 100
          minimum: 1
          name: limit
          type: integer
        - default: desc
          description: Publication order; omit for descending, explicit empty values are invalid
          enum:
            - asc
            - desc
          in: query
          name: order
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SessionArtifactList'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: List immutable Session artifacts in a Project
      tags:
        - Artifacts
  /core/v1/projects/{project_id}/sessions/{session_id}/artifacts/{artifact_id}:
    delete:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Session ID
          in: path
          name: session_id
          required: true
          type: string
        - description: Artifact ID
          in: path
          name: artifact_id
          required: true
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SessionArtifactDeleted'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Delete a published artifact in a Project
      tags:
        - Artifacts
    get:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Session ID
          in: path
          name: session_id
          required: true
          type: string
        - description: Artifact ID
          in: path
          name: artifact_id
          required: true
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SessionArtifact'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Retrieve immutable artifact metadata in a Project
      tags:
        - Artifacts
  /core/v1/projects/{project_id}/sessions/{session_id}/artifacts/{artifact_id}/content:
    get:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Session ID
          in: path
          name: session_id
          required: true
          type: string
        - description: Artifact ID
          in: path
          name: artifact_id
          required: true
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/octet-stream
      responses:
        "200":
          description: OK
          schema:
            type: file
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Download immutable artifact bytes in a Project
      tags:
        - Artifacts
  /core/v1/projects/{project_id}/sessions/{session_id}/diagnostics:
    get:
      description: Core key only. Safe failure categories from one committed snapshot; no native text or historical inference.
      parameters:
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
        - description: Session ID
          in: path
          name: session_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/api.SessionDiagnostics'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Retrieve root Session diagnostics
      tags:
        - Sessions
  /core/v1/projects/{project_id}/sessions/{session_id}/execution-configuration:
    get:
      description: Core key only; the Project ID selects the target space and does not authenticate. Returns the committed model, harness and safe provider selection with recorded sources. This read never decrypts credentials, resolves current defaults or probes execution health. Deployment defaults frozen after they moved into Core show their safe view; older deployment selections remain redacted. Historical provenance and missing provider projections are explicitly unknown/unavailable.
      parameters:
        - description: Session ID
          in: path
          name: session_id
          required: true
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SessionExecutionConfiguration'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Retrieve a Session's frozen execution configuration in a Project
      tags:
        - Execution configuration
  /core/v1/projects/{project_id}/sessions/{session_id}/items:
    get:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Session ID
          in: path
          name: session_id
          required: true
          type: string
        - description: Last Item ID from the previous page
          in: query
          name: after
          type: string
        - default: 20
          description: Page size; 0 is treated as 1 and values above 100 as 100
          in: query
          minimum: 0
          name: limit
          type: integer
        - default: desc
          description: Creation order; omit for descending, explicit empty values are invalid
          enum:
            - asc
            - desc
          in: query
          name: order
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.ItemList'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: List persisted execution Items in a Project
      tags:
        - Items
  /core/v1/projects/{project_id}/sessions/{session_id}/runtime-history:
    get:
      description: Core key only; the Project ID selects the target space and does not authenticate. Returns stored Runtime observations for one Session. End is exclusive; the server selects a bounded resolution. Responses contain at most 1,000 series, 10,000 points per coverage/series array, and 100,000 total coverage plus series points. It never reads or changes live compute.
      parameters:
        - description: Session ID
          in: path
          name: session_id
          required: true
          type: string
        - description: Inclusive Unix-second start
          in: query
          maximum: 9007199254740991
          minimum: 0
          name: start
          required: true
          type: integer
        - description: Exclusive Unix-second end
          in: query
          maximum: 9007199254740991
          minimum: 1
          name: end
          required: true
          type: integer
        - description: Maximum points per series; defaults to the lower of 120 and the advertised service maximum
          in: query
          maximum: 10000
          minimum: 2
          name: max_points
          type: integer
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.RuntimeHistory'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "409":
          description: Conflict
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Retrieve Session Runtime history in a Project
      tags:
        - Runtime history
  /core/v1/projects/{project_id}/sessions/{session_id}/runtime-observation:
    get:
      description: Core key only; the Project ID selects the target space and does not authenticate. Returns one read-only current Runtime observation. It never provisions, renews, restarts, pauses or stops compute.
      parameters:
        - description: Session ID
          in: path
          name: session_id
          required: true
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.RuntimeObservation'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Retrieve a Session Runtime observation in a Project
      tags:
        - Runtime observations
  /core/v1/projects/{project_id}/sessions/{session_id}/turns:
    get:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Session ID
          in: path
          name: session_id
          required: true
          type: string
        - description: Last Turn ID from the previous page
          in: query
          name: after
          type: string
        - default: 20
          description: Page size
          in: query
          maximum: 100
          minimum: 1
          name: limit
          type: integer
        - default: desc
          description: Creation order; omit for descending, explicit empty values are invalid
          enum:
            - asc
            - desc
          in: query
          name: order
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.TurnList'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: List execution Turns in a Project
      tags:
        - Turns
  /core/v1/projects/{project_id}/sessions/{session_id}/turns/{turn_id}:
    get:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Session ID
          in: path
          name: session_id
          required: true
          type: string
        - description: Turn ID
          in: path
          name: turn_id
          required: true
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.Turn'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Retrieve an execution Turn in a Project
      tags:
        - Turns
  /core/v1/projects/{project_id}/sessions/{session_id}/turns/{turn_id}/diagnostics:
    get:
      description: Core key only. At most 1000 root Item receipt timings in public Item order. Receipt intervals are not native execution durations.
      parameters:
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
        - description: Session ID
          in: path
          name: session_id
          required: true
          type: string
        - description: Root Turn ID
          in: path
          name: turn_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/api.TurnDiagnostics'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Retrieve root Turn diagnostics
      tags:
        - Turns
  /core/v1/projects/{project_id}/skills:
    get:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Skill resource cursor
          in: query
          name: after
          type: string
        - default: 20
          description: Page size; 0 returns an empty page
          in: query
          maximum: 100
          minimum: 0
          name: limit
          type: integer
        - description: Creation order; omit for descending, explicit empty values are invalid
          enum:
            - asc
            - desc
          in: query
          name: order
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SkillList'
      security:
        - DeploymentAdminAuth: []
      summary: List Skills in a Project
      tags:
        - Skills
  /core/v1/projects/{project_id}/skills/{skill_id}:
    delete:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Skill ID
          in: path
          name: skill_id
          required: true
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SkillDeleted'
      security:
        - DeploymentAdminAuth: []
      summary: Delete a Skill and its versions in a Project
      tags:
        - Skills
    get:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Skill ID
          in: path
          name: skill_id
          required: true
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.Skill'
      security:
        - DeploymentAdminAuth: []
      summary: Retrieve Skill metadata in a Project
      tags:
        - Skills
  /core/v1/projects/{project_id}/skills/{skill_id}/content:
    get:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Skill ID
          in: path
          name: skill_id
          required: true
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/octet-stream
      responses:
        "200":
          description: OK
          schema:
            type: file
      security:
        - DeploymentAdminAuth: []
      summary: Download Skill content in a Project
      tags:
        - Skills
  /core/v1/projects/{project_id}/skills/{skill_id}/versions:
    get:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Skill ID
          in: path
          name: skill_id
          required: true
          type: string
        - description: Version resource cursor
          in: query
          name: after
          type: string
        - default: 20
          description: Page size; 0 returns an empty page
          in: query
          maximum: 100
          minimum: 0
          name: limit
          type: integer
        - description: Version order; omit for descending, explicit empty values are invalid
          enum:
            - asc
            - desc
          in: query
          name: order
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SkillVersionList'
      security:
        - DeploymentAdminAuth: []
      summary: List Skill versions in a Project
      tags:
        - Skills
  /core/v1/projects/{project_id}/skills/{skill_id}/versions/{version}:
    delete:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Skill ID
          in: path
          name: skill_id
          required: true
          type: string
        - description: Concrete version number
          in: path
          name: version
          required: true
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SkillVersionDeleted'
      security:
        - DeploymentAdminAuth: []
      summary: Delete a Skill version in a Project
      tags:
        - Skills
    get:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Skill ID
          in: path
          name: skill_id
          required: true
          type: string
        - description: Concrete version number
          in: path
          name: version
          required: true
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SkillVersion'
      security:
        - DeploymentAdminAuth: []
      summary: Retrieve Skill version metadata in a Project
      tags:
        - Skills
  /core/v1/projects/{project_id}/skills/{skill_id}/versions/{version}/content:
    get:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Skill ID
          in: path
          name: skill_id
          required: true
          type: string
        - description: Concrete version number
          in: path
          name: version
          required: true
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/octet-stream
      responses:
        "200":
          description: OK
          schema:
            type: file
      security:
        - DeploymentAdminAuth: []
      summary: Download immutable Skill version content in a Project
      tags:
        - Skills
  /core/v1/projects/{project_id}/vaults:
    get:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Last Vault ID from the previous page
          in: query
          name: after
          type: string
        - default: 20
          description: Requested page size, clamped to 1–100
          in: query
          name: limit
          type: integer
        - default: desc
          description: Creation order; omit for descending, explicit empty values are invalid
          enum:
            - asc
            - desc
          in: query
          name: order
          type: string
        - description: Scalar status filter
          enum:
            - active
            - archived
          in: query
          name: status
          type: string
        - collectionFormat: multi
          description: Array status filter; combined with status as a union
          in: query
          items:
            enum:
              - active
              - archived
            type: string
          name: status[]
          type: array
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.VaultList'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: List Vaults in a Project
      tags:
        - Vaults
  /core/v1/projects/{project_id}/vaults/{vault_id}:
    delete:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Vault ID
          in: path
          name: vault_id
          required: true
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.VaultDeleted'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "413":
          description: Request Entity Too Large
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Delete a Vault and all its Credentials in a Project
      tags:
        - Vaults
    get:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Vault ID
          in: path
          name: vault_id
          required: true
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.Vault'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Retrieve a Vault in a Project
      tags:
        - Vaults
  /core/v1/projects/{project_id}/vaults/{vault_id}/credentials:
    get:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Vault ID
          in: path
          name: vault_id
          required: true
          type: string
        - description: Last Credential ID from the previous page
          in: query
          name: after
          type: string
        - default: 20
          description: Requested page size, clamped to 1–100
          in: query
          name: limit
          type: integer
        - default: desc
          description: Creation order; omit for descending, explicit empty values are invalid
          enum:
            - asc
            - desc
          in: query
          name: order
          type: string
        - description: Scalar status filter
          enum:
            - active
            - archived
          in: query
          name: status
          type: string
        - collectionFormat: multi
          description: Array status filter; combined with status as a union
          in: query
          items:
            enum:
              - active
              - archived
            type: string
          name: status[]
          type: array
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.CredentialList'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: List safe Vault Credential metadata in a Project
      tags:
        - Credentials
  /core/v1/projects/{project_id}/vaults/{vault_id}/credentials/{credential_id}:
    delete:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Vault ID
          in: path
          name: vault_id
          required: true
          type: string
        - description: Credential ID
          in: path
          name: credential_id
          required: true
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.CredentialDeleted'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "413":
          description: Request Entity Too Large
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Delete a Vault Credential in a Project
      tags:
        - Credentials
    get:
      description: Core key only. Reuses the public resource projection and operation rules; the Project ID selects the target space and does not authenticate.
      parameters:
        - description: Vault ID
          in: path
          name: vault_id
          required: true
          type: string
        - description: Credential ID
          in: path
          name: credential_id
          required: true
          type: string
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.Credential'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Retrieve safe Vault Credential metadata in a Project
      tags:
        - Credentials
  /core/v1/projects/{project_id}/write-operations:
    get:
      description: Core key only. Reverse chronological keyset pagination over committed writes. Creation records remain; other records follow configured retention. The key path selects its independent space, never a caller-supplied tenant.
      parameters:
        - description: Project ID
          in: path
          name: project_id
          required: true
          type: string
        - description: Recorded creator key ID
          in: query
          name: key_id
          type: string
        - description: Resource type
          in: query
          name: resource_type
          type: string
        - description: Public resource ID
          in: query
          name: resource_id
          type: string
        - description: Inclusive RFC3339 timestamp
          in: query
          name: created_after
          type: string
        - description: Exclusive RFC3339 timestamp
          in: query
          name: created_before
          type: string
        - description: Page size, 1-100, default 50
          in: query
          name: limit
          type: integer
        - description: Opaque next_cursor from the preceding page
          in: query
          name: after
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/writeaudit.Page'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Query API-key write operations
      tags:
        - Write Audit
  /core/v1/sandbox/deployment:
    get:
      description: Core key only. Does not grant project resource access. Responses contain only explicit safe fields. E2B template_build values are those Core read when the selection was saved; this read does not call E2B.
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/deployment.View'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "409":
          description: Conflict
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Retrieve sandbox deployment
      tags:
        - Sandbox Manager
    post:
      consumes:
        - application/json
      description: Selects a provider, enforced resource limits and pinned Runtime release. Core derives the deployment's core_url from the installation public URL and rejects a core_url member with 400. E2B returns 409 sandbox_configuration_error while the public URL is loopback. E2B credentials are write-only. E2B may omit resources to adopt the validated template build's CPU and memory, returned in specification.resources. Requires explicit expected_generation, including zero at first setup. Stale retries reject before provider validation. An identical selection at the current generation is a no-op; differing selections and file-managed deployments reject. This does not create compute or execute work.
      parameters:
        - description: Deployment selection
          in: body
          name: body
          required: true
          schema:
            $ref: '#/definitions/api.SandboxDeploymentInput'
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/deployment.View'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "409":
          description: Conflict
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Initialize the deployment sandbox provider
      tags:
        - Sandbox Manager
    put:
      consumes:
        - application/json
      description: 'Requires the observed generation, the same backend type and no active reset. E2B same-team changes apply online: allocations retain immutable generation and current credentials; omitted api_key preserves it, explicit submission including the same key verifies and advances generation. Other teams require explicit reset. Node providers retain the zero-resource guard and retire old nodes/tokens on change. Core rejects core_url input. Never automatically replay an uncertain write; rollout.state is the authoritative preparation polling signal.'
      parameters:
        - description: Replacement deployment selection
          in: body
          name: body
          required: true
          schema:
            $ref: '#/definitions/api.SandboxDeploymentChangeInput'
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/deployment.View'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "409":
          description: Conflict
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Change the sandbox deployment configuration
      tags:
        - Sandbox Manager
  /core/v1/sandbox/deployment/reset:
    delete:
      description: Restores admission but never restores Sessions already archived. With no reset running this is an idempotent read, provided the generation still matches. The response is the current deployment read after the cancellation commits.
      parameters:
        - description: Current deployment generation
          in: query
          name: expected_generation
          required: true
          type: integer
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/deployment.View'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "409":
          description: Conflict
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Cancel a sandbox deployment reset
      tags:
        - Sandbox Manager
    post:
      consumes:
        - application/json
      description: Archives hosted Sessions and waits for confirmed provider cleanup, preserving history and Files/Artifacts. Auto waits for started or waiting Turns and file writes until the durable deadline; force cancels them. The same clear is idempotent; force escalates auto. Requires the current generation. Self-hosted Sessions are unchanged. The response is the current deployment read after the reset commits; resource counts are live and may already differ.
      parameters:
        - description: Reset mode and current deployment generation
          in: body
          name: body
          required: true
          schema:
            $ref: '#/definitions/deployment.ResetRequest'
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/deployment.View'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "409":
          description: Conflict
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Start or escalate a durable sandbox deployment reset
      tags:
        - Sandbox Manager
  /core/v1/sandbox/enrollment-tokens:
    post:
      consumes:
        - application/json
      description: Core key only. Does not grant project resource access. Responses contain only explicit safe fields.
      parameters:
        - description: Request
          in: body
          name: body
          required: true
          schema:
            $ref: '#/definitions/api.SandboxEnrollmentTokenRequest'
      produces:
        - application/json
      responses:
        "201":
          description: Created
          schema:
            $ref: '#/definitions/api.SandboxEnrollmentToken'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "409":
          description: Conflict
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Create a ten-minute one-use node enrollment token
      tags:
        - Sandbox Manager
  /core/v1/sandbox/nodes:
    get:
      description: Core key only. Does not grant project resource access. Responses contain only explicit safe fields.
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/api.SandboxNodeList'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "409":
          description: Conflict
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: List deployment sandbox nodes
      tags:
        - Sandbox Manager
  /core/v1/sandbox/nodes/{node_id}:
    delete:
      description: Core key only. Does not grant project resource access. Responses contain only explicit safe fields.
      parameters:
        - description: Sandbox node UUID
          in: path
          name: node_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/api.SandboxMutationResponse'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "409":
          description: Conflict
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Remove a sandbox node with no retained resources
      tags:
        - Sandbox Manager
    get:
      description: Core key only. Complete UTC buckets. Missing host measurements and offline history are null; reads never sample or backfill.
      parameters:
        - description: Sandbox node UUID
          in: path
          name: node_id
          required: true
          type: string
        - description: Time range (default 1h)
          enum:
            - 1h
            - 6h
            - 24h
          in: query
          name: range
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/deployment.NodeDetail'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Retrieve sandbox node and host history
      tags:
        - Sandbox Manager
    patch:
      consumes:
        - application/json
      description: Core key only. Does not grant project resource access. Responses contain only explicit safe fields.
      parameters:
        - description: Sandbox node UUID
          in: path
          name: node_id
          required: true
          type: string
        - description: Request
          in: body
          name: body
          required: true
          schema:
            $ref: '#/definitions/deployment.NodeUpdate'
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/api.SandboxMutationResponse'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "409":
          description: Conflict
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Update sandbox node name and capacity
      tags:
        - Sandbox Manager
  /core/v1/sandbox/nodes/{node_id}/allocations:
    get:
      description: Core key only. Does not grant project resource access. Responses contain only explicit safe fields.
      parameters:
        - description: Sandbox node UUID
          in: path
          name: node_id
          required: true
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/api.SandboxAllocationList'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "409":
          description: Conflict
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: List retained allocations on a sandbox node
      tags:
        - Sandbox Manager
  /core/v1/sandbox/providers/{provider}/discovery:
    post:
      consumes:
        - application/json
      description: Core key only. Uses transient write-only credentials. The provider validates configuration and query fields and returns safe catalog metadata. Does not save credentials, change a deployment or allocate compute. Discovery is not deployment admission.
      parameters:
        - description: Registered provider kind
          in: path
          name: provider
          required: true
          type: string
        - description: Transient provider connection and query
          in: body
          name: body
          required: true
          schema:
            $ref: '#/definitions/sandbox.ConfigurationDiscoveryInput'
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            additionalProperties: true
            type: object
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Discover sandbox provider configuration
      tags:
        - Sandbox Manager
  /core/v1/sandbox/runtime-observations:
    get:
      description: Core key only. Each observation is labelled with its owning Project ID. Uses the existing read-only Runtime sampler, with bounded concurrency and no execution or provisioning. A provider with a batch metrics read, such as E2B, samples the page's running sandboxes in one bounded request.
      parameters:
        - description: Last Session ID from the preceding page
          in: query
          name: after
          type: string
        - default: 20
          description: Page size
          in: query
          maximum: 100
          minimum: 1
          name: limit
          type: integer
        - default: desc
          description: Session creation order
          enum:
            - asc
            - desc
          in: query
          name: order
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/api.AdminRuntimeObservationList'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: List Runtime observations across managed Projects
      tags:
        - Core Administration
  /core/v1/summary:
    get:
      description: Core key only. after/limit/order paginate Projects. Agent grouping returns groups within those spaces. Date bounds filter Session creation, not current asset counts. Usage sums only non-null public Session usage; coverage includes every selected Session. Each Project is read in a consistent database snapshot. Totals are not billing records.
      parameters:
        - description: One API Project
          in: query
          name: project_id
          type: string
        - default: project
          description: Grouping
          enum:
            - project
            - agent
            - key
          in: query
          name: group_by
          type: string
        - description: Inclusive RFC3339 Session creation time
          in: query
          name: created_after
          type: string
        - description: Exclusive RFC3339 Session creation time
          in: query
          name: created_before
          type: string
        - description: Last Project ID in preceding page
          in: query
          name: after
          type: string
        - default: 20
          description: Number of Projects
          in: query
          maximum: 100
          minimum: 1
          name: limit
          type: integer
        - default: desc
          description: Project order
          enum:
            - asc
            - desc
          in: query
          name: order
          type: string
      produces:
        - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/api.AdminSummaryResponse'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/api.CoreErrorResponse'
      security:
        - DeploymentAdminAuth: []
      summary: Summarize resource counts and Session usage by Project, Agent or creator key
      tags:
        - Core Administration
schemes:
  - http
  - https
securityDefinitions:
  DeploymentAdminAuth:
    in: header
    name: Authorization
    type: apiKey
swagger: "2.0"
