basePath: /v1
definitions:
  v1.APIError:
    properties:
      code:
        type: string
        x-nullable: true
      message:
        type: string
      param:
        type: string
        x-nullable: true
      type:
        type: string
    required:
    - message
    - type
    type: object
  v1.Agent:
    properties:
      id:
        type: string
      instructions:
        type: string
        x-nullable: true
      model:
        type: string
      multi_agent:
        $ref: '#/definitions/v1.MultiAgentConfig'
      name:
        type: string
        x-nullable: true
      reasoning:
        $ref: '#/definitions/v1.Reasoning'
      service_tier:
        enum:
        - auto
        type: string
      text:
        $ref: '#/definitions/v1.TextConfig'
      tools:
        items:
          type: object
        type: array
      x_agents_core:
        allOf:
        - $ref: '#/definitions/v1.AgentsCore'
        x-nullable: true
    required:
    - id
    - model
    - multi_agent
    - reasoning
    - service_tier
    - text
    - tools
    type: object
  v1.AgentContent:
    properties:
      encrypted_content:
        type: string
      text:
        type: string
      type:
        enum:
        - output_text
        - encrypted_content
        type: string
    required:
    - type
    type: object
  v1.AgentDeleted:
    properties:
      deleted:
        enum:
        - true
        type: boolean
      id:
        type: string
      object:
        enum:
        - agent.deleted
        type: string
    required:
    - deleted
    - id
    - object
    type: object
  v1.AgentsCore:
    properties:
      harness:
        enum:
        - claude_sdk
        - codex
        - mcode
        type: string
      harness_config:
        type: object
    type: object
  v1.CreateAgentRequest:
    properties:
      instructions:
        type: string
        x-nullable: true
      metadata:
        additionalProperties:
          type: string
        type: object
        x-nullable: true
      model:
        type: string
      multi_agent:
        type: object
        x-nullable: true
      name:
        maxLength: 128
        type: string
        x-nullable: true
      reasoning:
        allOf:
        - $ref: '#/definitions/v1.Reasoning'
        x-nullable: true
      service_tier:
        enum:
        - auto
        - default
        - flex
        - priority
        - fast
        type: string
        x-nullable: true
      text:
        allOf:
        - $ref: '#/definitions/v1.SavedAgentTextInput'
        x-nullable: true
      tools:
        items:
          type: object
        type: array
        x-nullable: true
      x_agents_core:
        allOf:
        - $ref: '#/definitions/v1.SavedAgentCoreInput'
        x-nullable: true
    required:
    - model
    type: object
  v1.CreateCredentialRequest:
    properties:
      auth:
        $ref: '#/definitions/v1.CredentialAuthInput'
      name:
        type: string
    required:
    - auth
    - name
    type: object
  v1.CreateEventsRequest:
    properties:
      events:
        items:
          $ref: '#/definitions/v1.SessionInput'
        type: array
    required:
    - events
    type: object
  v1.CreateSessionRequest:
    properties:
      agent:
        $ref: '#/definitions/v1.InlineAgent'
      agent_id:
        type: string
      environment:
        $ref: '#/definitions/v1.Environment'
      input:
        description: |-
          Input accepts a string or an ordered array of user InputMessage objects.
          Required for none and streamed creation outside self_hosted; otherwise optional.
        x-nullable: true
      metadata:
        additionalProperties:
          type: string
        type: object
        x-nullable: true
      stream:
        default: false
        type: boolean
      vault_ids:
        items:
          type: string
        type: array
      x_agents_core:
        $ref: '#/definitions/v1.SessionExecutionInput'
    required:
    - environment
    type: object
  v1.CreateVaultRequest:
    properties:
      metadata:
        additionalProperties:
          type: string
        type: object
        x-nullable: true
      name:
        type: string
    type: object
  v1.Credential:
    properties:
      auth:
        $ref: '#/definitions/v1.CredentialAuth'
      created_at:
        type: integer
      id:
        type: string
      name:
        type: string
      object:
        enum:
        - vault.credential
        type: string
      updated_at:
        type: integer
      vault_id:
        type: string
    required:
    - auth
    - created_at
    - id
    - name
    - object
    - updated_at
    - vault_id
    type: object
  v1.CredentialAuth:
    properties:
      expires_at:
        type: string
        x-nullable: true
      mcp_server_url:
        type: string
      refresh:
        allOf:
        - $ref: '#/definitions/v1.OAuthCredentialRefresh'
        x-nullable: true
      type:
        enum:
        - static_bearer
        - mcp_oauth
        type: string
    required:
    - mcp_server_url
    - type
    type: object
  v1.CredentialAuthInput:
    properties:
      access_token:
        minLength: 1
        type: string
      expires_at:
        type: string
        x-nullable: true
      mcp_server_url:
        type: string
      refresh:
        allOf:
        - $ref: '#/definitions/v1.OAuthCredentialRefreshInput'
        x-nullable: true
      token:
        minLength: 1
        type: string
      type:
        enum:
        - static_bearer
        - mcp_oauth
        type: string
    required:
    - mcp_server_url
    - type
    type: object
  v1.CredentialAuthReplacement:
    properties:
      access_token:
        minLength: 1
        type: string
        x-nullable: true
      expires_at:
        type: string
        x-nullable: true
      refresh:
        allOf:
        - $ref: '#/definitions/v1.OAuthCredentialRefreshReplacement'
        x-nullable: true
      token:
        minLength: 1
        type: string
      type:
        enum:
        - static_bearer
        - mcp_oauth
        type: string
    required:
    - type
    type: object
  v1.CredentialDeleted:
    properties:
      deleted:
        type: boolean
      id:
        type: string
      object:
        enum:
        - vault.credential.deleted
        type: string
    required:
    - deleted
    - id
    - object
    type: object
  v1.CredentialList:
    properties:
      data:
        items:
          $ref: '#/definitions/v1.Credential'
        type: array
      first_id:
        type: string
        x-nullable: true
      has_more:
        type: boolean
      last_id:
        type: string
        x-nullable: true
      object:
        enum:
        - list
        type: string
    required:
    - data
    - has_more
    - object
    type: object
  v1.Environment:
    properties:
      capability_directories:
        items:
          type: string
        type: array
        x-nullable: true
      env:
        additionalProperties:
          type: string
        type: object
        x-nullable: true
      environment_template_id:
        type: string
      files:
        items:
          type: object
        type: array
        x-nullable: true
      network:
        allOf:
        - $ref: '#/definitions/v1.EnvironmentNetworkInput'
        x-nullable: true
      packages:
        allOf:
        - $ref: '#/definitions/v1.EnvironmentPackages'
        x-nullable: true
      plugins:
        items:
          type: object
        type: array
        x-nullable: true
      setup_commands:
        items:
          type: object
        type: array
        x-nullable: true
      skills:
        items:
          type: object
        type: array
        x-nullable: true
      type:
        enum:
        - none
        - self_hosted
        - openai_hosted
        type: string
      workspace_directory:
        type: string
    required:
    - type
    type: object
  v1.EnvironmentFile:
    properties:
      environment_id:
        type: string
      object:
        enum:
        - agent.environment.file
        type: string
      path:
        type: string
      size_bytes:
        minimum: 0
        type: integer
    required:
    - environment_id
    - object
    - path
    - size_bytes
    type: object
  v1.EnvironmentFileCreateRequest:
    properties:
      data:
        type: string
      file_id:
        type: string
      path:
        type: string
      type:
        enum:
        - inline
        - file_id
        type: string
    required:
    - path
    - type
    type: object
  v1.EnvironmentFileList:
    properties:
      data:
        items:
          $ref: '#/definitions/v1.EnvironmentFile'
        type: array
      has_more:
        type: boolean
      next:
        type: string
        x-nullable: true
      object:
        enum:
        - page
        type: string
    required:
    - data
    - has_more
    - object
    type: object
  v1.EnvironmentInfo:
    properties:
      files:
        items:
          type: object
        type: array
      id:
        type: string
      object:
        enum:
        - agent.environment
        type: string
      plugins:
        items:
          type: object
        type: array
      skills:
        items:
          type: object
        type: array
      status:
        enum:
        - pending
        - connected
        - disconnected
        - expired
        - failed
        type: string
      type:
        enum:
        - openai_hosted
        - self_hosted
        type: string
    required:
    - files
    - id
    - object
    - plugins
    - skills
    - status
    - type
    type: object
  v1.EnvironmentInstallation:
    properties:
      commands:
        additionalProperties:
          type: string
        type: object
      expires_at:
        type: integer
      message:
        type: string
      status:
        enum:
        - available
        - unavailable
        type: string
      version:
        type: string
    type: object
  v1.EnvironmentNetwork:
    properties:
      access:
        enum:
        - enabled
        - disabled
        - restricted
        type: string
      allowed_domains:
        items:
          type: string
        type: array
    required:
    - access
    - allowed_domains
    type: object
  v1.EnvironmentNetworkInput:
    properties:
      access:
        enum:
        - enabled
        - disabled
        - restricted
        type: string
      allowed_domains:
        items:
          type: string
        type: array
        x-nullable: true
    required:
    - access
    type: object
  v1.EnvironmentPackages:
    properties:
      npm:
        items:
          type: string
        type: array
      python:
        items:
          type: string
        type: array
    required:
    - npm
    - python
    type: object
  v1.EnvironmentPackagesInput:
    properties:
      npm:
        items:
          type: string
        type: array
        x-nullable: true
      python:
        items:
          type: string
        type: array
        x-nullable: true
    type: object
  v1.EnvironmentPackagesResponse:
    properties:
      npm:
        items:
          type: string
        type: array
      python:
        items:
          type: string
        type: array
      system:
        items:
          type: string
        type: array
    required:
    - npm
    - python
    - system
    type: object
  v1.EnvironmentTemplate:
    properties:
      capability_directories:
        items:
          type: string
        type: array
      created_at:
        type: integer
      files:
        items:
          type: object
        type: array
      id:
        type: string
      name:
        type: string
        x-nullable: true
      network:
        $ref: '#/definitions/v1.EnvironmentNetwork'
      object:
        enum:
        - agent.environment.template
        type: string
      packages:
        $ref: '#/definitions/v1.EnvironmentPackagesResponse'
      plugins:
        items:
          type: object
        type: array
      skills:
        items:
          type: object
        type: array
      updated_at:
        type: integer
    required:
    - capability_directories
    - created_at
    - files
    - id
    - network
    - object
    - packages
    - plugins
    - skills
    - updated_at
    type: object
  v1.EnvironmentTemplateDeleted:
    properties:
      deleted:
        type: boolean
      id:
        type: string
      object:
        enum:
        - agent.environment.template.deleted
        type: string
    required:
    - deleted
    - id
    - object
    type: object
  v1.EnvironmentTemplateList:
    properties:
      data:
        items:
          $ref: '#/definitions/v1.EnvironmentTemplate'
        type: array
      first_id:
        type: string
        x-nullable: true
      has_more:
        type: boolean
      last_id:
        type: string
        x-nullable: true
      object:
        enum:
        - list
        type: string
    required:
    - data
    - has_more
    - object
    type: object
  v1.EnvironmentTemplateRequest:
    properties:
      capability_directories:
        items:
          type: string
        type: array
        x-nullable: true
      env:
        additionalProperties:
          type: string
        type: object
        x-nullable: true
      files:
        items:
          type: object
        type: array
        x-nullable: true
      name:
        type: string
        x-nullable: true
      network:
        allOf:
        - $ref: '#/definitions/v1.EnvironmentNetworkInput'
        x-nullable: true
      packages:
        allOf:
        - $ref: '#/definitions/v1.EnvironmentPackagesInput'
        x-nullable: true
      plugins:
        items:
          type: object
        type: array
        x-nullable: true
      setup_commands:
        items:
          type: object
        type: array
        x-nullable: true
      skills:
        items:
          type: object
        type: array
        x-nullable: true
    type: object
  v1.ErrorResponse:
    properties:
      error:
        $ref: '#/definitions/v1.APIError'
    required:
    - error
    type: object
  v1.InlineAgent:
    properties:
      instructions:
        type: string
        x-nullable: true
      model:
        type: string
      multi_agent:
        type: object
        x-nullable: true
      reasoning:
        allOf:
        - $ref: '#/definitions/v1.Reasoning'
        x-nullable: true
      service_tier:
        enum:
        - auto
        - default
        - flex
        - priority
        - fast
        type: string
        x-nullable: true
      text:
        allOf:
        - $ref: '#/definitions/v1.SavedAgentTextInput'
        x-nullable: true
      tools:
        items:
          type: object
        type: array
        x-nullable: true
      x_agents_core:
        allOf:
        - $ref: '#/definitions/v1.AgentsCore'
        x-nullable: true
    type: object
  v1.InputContent:
    properties:
      image_url:
        type: string
      text:
        type: string
      type:
        enum:
        - input_text
        - input_image
        type: string
    required:
    - type
    type: object
  v1.InputMessage:
    properties:
      content:
        items:
          $ref: '#/definitions/v1.InputContent'
        type: array
      role:
        enum:
        - user
        type: string
      type:
        enum:
        - message
        type: string
    required:
    - content
    - role
    type: object
  v1.InputTokenDetails:
    properties:
      cached_tokens:
        type: integer
    required:
    - cached_tokens
    type: object
  v1.Item:
    properties:
      action:
        $ref: '#/definitions/v1.WebSearchAction'
      agent_id:
        type: string
      arguments: {}
      call_id:
        type: string
      command:
        type: string
      content:
        items:
          $ref: '#/definitions/v1.ItemContent'
        type: array
      cwd:
        type: string
      duration_ms:
        type: integer
      error: {}
      exit_code:
        type: integer
      id:
        type: string
      model:
        type: string
      name:
        type: string
      output: {}
      phase:
        enum:
        - commentary
        - final_answer
        type: string
        x-nullable: true
      reasoning_effort:
        type: string
      recipient_agent_id:
        type: string
      recipient_agent_ids:
        items:
          type: string
        type: array
      role:
        enum:
        - user
        - assistant
        type: string
      sender_agent_id:
        type: string
      server_label:
        type: string
      status:
        enum:
        - in_progress
        - completed
        - failed
        - incomplete
        type: string
      summary:
        items:
          $ref: '#/definitions/v1.SummaryText'
        type: array
      turn_id:
        type: string
      type:
        enum:
        - message
        - command_execution
        - mcp_call
        - function_call
        - function_call_output
        - web_search_call
        - reasoning
        - agent_message
        - create_subagent_call
        - send_subagent_input_call
        - resume_subagent_call
        - wait_for_subagents_call
        - interrupt_subagent_call
        - close_subagent_call
        type: string
    required:
    - id
    - turn_id
    - type
    type: object
  v1.ItemContent:
    properties:
      encrypted_content:
        type: string
      image_url:
        type: string
      text:
        type: string
      type:
        enum:
        - input_text
        - output_text
        - input_image
        - encrypted_content
        type: string
    required:
    - type
    type: object
  v1.ItemList:
    properties:
      data:
        items:
          $ref: '#/definitions/v1.Item'
        type: array
      first_id:
        type: string
        x-nullable: true
      has_more:
        type: boolean
      last_id:
        type: string
        x-nullable: true
      object:
        enum:
        - list
        type: string
    required:
    - data
    - has_more
    - object
    type: object
  v1.ModelProviderInput:
    properties:
      api_key:
        type: string
      base_url:
        type: string
      context_window:
        type: integer
      max_output_tokens:
        type: integer
      protocol:
        enum:
        - anthropic
        - responses
        - chat_completions
        type: string
    required:
    - api_key
    - base_url
    - protocol
    type: object
  v1.ModelProviderView:
    properties:
      api_key_configured:
        type: boolean
      base_url:
        type: string
      context_window:
        type: integer
      max_output_tokens:
        type: integer
      protocol:
        enum:
        - anthropic
        - responses
        - chat_completions
        type: string
    required:
    - api_key_configured
    - base_url
    - protocol
    type: object
  v1.MultiAgentConfig:
    properties:
      enabled:
        type: boolean
      max_concurrent_subagents:
        type: integer
        x-nullable: true
    required:
    - enabled
    type: object
  v1.OAuthCredentialRefresh:
    properties:
      client_id:
        type: string
      resource:
        type: string
        x-nullable: true
      scope:
        type: string
        x-nullable: true
      token_endpoint:
        type: string
      token_endpoint_auth:
        $ref: '#/definitions/v1.OAuthEndpointAuth'
    required:
    - client_id
    - token_endpoint
    - token_endpoint_auth
    type: object
  v1.OAuthCredentialRefreshInput:
    properties:
      client_id:
        type: string
      refresh_token:
        type: string
      resource:
        type: string
        x-nullable: true
      scope:
        type: string
        x-nullable: true
      token_endpoint:
        type: string
      token_endpoint_auth:
        $ref: '#/definitions/v1.OAuthEndpointAuthInput'
    required:
    - client_id
    - refresh_token
    - token_endpoint
    - token_endpoint_auth
    type: object
  v1.OAuthCredentialRefreshReplacement:
    properties:
      refresh_token:
        type: string
        x-nullable: true
      scope:
        type: string
        x-nullable: true
      token_endpoint_auth:
        allOf:
        - $ref: '#/definitions/v1.OAuthEndpointAuthReplacement'
        x-nullable: true
    type: object
  v1.OAuthEndpointAuth:
    properties:
      type:
        enum:
        - none
        - client_secret_basic
        - client_secret_post
        type: string
    required:
    - type
    type: object
  v1.OAuthEndpointAuthInput:
    properties:
      client_secret:
        type: string
      type:
        enum:
        - none
        - client_secret_basic
        - client_secret_post
        type: string
    required:
    - type
    type: object
  v1.OAuthEndpointAuthReplacement:
    properties:
      client_secret:
        type: string
        x-nullable: true
      type:
        enum:
        - client_secret_basic
        - client_secret_post
        type: string
    required:
    - type
    type: object
  v1.OutputTokenDetails:
    properties:
      reasoning_tokens:
        type: integer
    required:
    - reasoning_tokens
    type: object
  v1.Reasoning:
    properties:
      effort:
        type: string
        x-nullable: true
      summary:
        type: string
        x-nullable: true
    type: object
  v1.RequiredAction:
    properties:
      arguments: {}
      call_id:
        type: string
      environment_id:
        type: string
      name:
        type: string
      turn_id:
        type: string
      type:
        enum:
        - function_call
        - environment_connection
        type: string
    required:
    - type
    type: object
  v1.SavedAgent:
    properties:
      created_at:
        type: integer
      id:
        type: string
      instructions:
        type: string
        x-nullable: true
      metadata:
        additionalProperties:
          type: string
        type: object
      model:
        type: string
      multi_agent:
        $ref: '#/definitions/v1.MultiAgentConfig'
      name:
        type: string
        x-nullable: true
      object:
        enum:
        - agent
        type: string
      reasoning:
        $ref: '#/definitions/v1.Reasoning'
      service_tier:
        enum:
        - auto
        - default
        - flex
        - priority
        - fast
        type: string
      text:
        $ref: '#/definitions/v1.SavedAgentText'
      tools:
        items:
          type: object
        type: array
      updated_at:
        type: integer
      x_agents_core:
        allOf:
        - $ref: '#/definitions/v1.SavedAgentCore'
        x-nullable: true
    required:
    - created_at
    - id
    - metadata
    - model
    - multi_agent
    - object
    - reasoning
    - service_tier
    - text
    - tools
    - updated_at
    type: object
  v1.SavedAgentCore:
    properties:
      harness:
        enum:
        - claude_sdk
        - codex
        - mcode
        type: string
      harness_config:
        type: object
      model_provider:
        $ref: '#/definitions/v1.ModelProviderView'
    type: object
  v1.SavedAgentCoreInput:
    properties:
      harness:
        enum:
        - claude_sdk
        - codex
        - mcode
        type: string
      harness_config:
        type: object
      model_provider:
        allOf:
        - $ref: '#/definitions/v1.ModelProviderInput'
        x-nullable: true
    type: object
  v1.SavedAgentList:
    properties:
      data:
        items:
          $ref: '#/definitions/v1.SavedAgent'
        type: array
      first_id:
        type: string
        x-nullable: true
      has_more:
        type: boolean
      last_id:
        type: string
        x-nullable: true
      object:
        enum:
        - list
        type: string
    required:
    - data
    - has_more
    - object
    type: object
  v1.SavedAgentText:
    properties:
      format:
        $ref: '#/definitions/v1.SavedAgentTextFormat'
      verbosity:
        enum:
        - low
        - medium
        - high
        type: string
    required:
    - format
    - verbosity
    type: object
  v1.SavedAgentTextFormat:
    properties:
      schema:
        type: object
      type:
        enum:
        - text
        - json_schema
        type: string
    required:
    - type
    type: object
  v1.SavedAgentTextInput:
    properties:
      format:
        type: object
        x-nullable: true
      verbosity:
        enum:
        - low
        - medium
        - high
        type: string
        x-nullable: true
    type: object
  v1.Session:
    properties:
      agent:
        $ref: '#/definitions/v1.Agent'
      created_at:
        type: integer
      environment:
        $ref: '#/definitions/v1.SessionEnvironment'
      error:
        type: string
        x-nullable: true
      id:
        type: string
      last_active_at:
        type: integer
      metadata:
        additionalProperties:
          type: string
        type: object
      object:
        enum:
        - agent.session
        type: string
      required_actions:
        items:
          $ref: '#/definitions/v1.RequiredAction'
        type: array
      status:
        enum:
        - idle
        - in_progress
        - requires_action
        - failed
        type: string
      usage:
        allOf:
        - $ref: '#/definitions/v1.TokenUsage'
        x-nullable: true
      vault_ids:
        items:
          type: string
        type: array
      x_agents_core:
        $ref: '#/definitions/v1.SessionCore'
    required:
    - agent
    - created_at
    - environment
    - id
    - last_active_at
    - metadata
    - object
    - required_actions
    - status
    - vault_ids
    type: object
  v1.SessionArtifact:
    properties:
      created_at:
        type: integer
      environment_id:
        type: string
      id:
        type: string
      object:
        enum:
        - agent.session.artifact
        type: string
      path:
        type: string
      session_id:
        type: string
      size_bytes:
        type: integer
      turn_id:
        type: string
    required:
    - created_at
    - environment_id
    - id
    - object
    - path
    - session_id
    - size_bytes
    - turn_id
    type: object
  v1.SessionArtifactDeleted:
    properties:
      deleted:
        type: boolean
      id:
        type: string
      object:
        enum:
        - agent.session.artifact.deleted
        type: string
    required:
    - deleted
    - id
    - object
    type: object
  v1.SessionArtifactList:
    properties:
      data:
        items:
          $ref: '#/definitions/v1.SessionArtifact'
        type: array
      first_id:
        type: string
        x-nullable: true
      has_more:
        type: boolean
      last_id:
        type: string
        x-nullable: true
      object:
        enum:
        - list
        type: string
    required:
    - data
    - has_more
    - object
    type: object
  v1.SessionCore:
    properties:
      installation:
        $ref: '#/definitions/v1.EnvironmentInstallation'
    type: object
  v1.SessionDeleted:
    properties:
      deleted:
        type: boolean
      id:
        type: string
      object:
        enum:
        - agent.session.deleted
        type: string
    required:
    - deleted
    - id
    - object
    type: object
  v1.SessionEnvironment:
    properties:
      capability_directories:
        items:
          type: string
        type: array
      files:
        items:
          type: object
        type: array
      id:
        type: string
      network:
        $ref: '#/definitions/v1.EnvironmentNetwork'
      packages:
        $ref: '#/definitions/v1.EnvironmentPackagesResponse'
      plugins:
        items:
          type: object
        type: array
      remote_url:
        type: string
      skills:
        items:
          type: object
        type: array
      type:
        enum:
        - none
        - self_hosted
        - openai_hosted
        type: string
      workspace_directory:
        type: string
    required:
    - type
    type: object
  v1.SessionEnvironmentState:
    properties:
      error:
        allOf:
        - $ref: '#/definitions/v1.StreamError'
        x-nullable: true
      id:
        type: string
      status:
        enum:
        - pending
        - ready
        - connected
        - disconnected
        - failed
        type: string
      type:
        type: string
    required:
    - id
    - status
    - type
    type: object
  v1.SessionEvent:
    properties:
      content_index:
        type: integer
      delta:
        type: string
      environment:
        $ref: '#/definitions/v1.SessionEnvironmentState'
      error:
        $ref: '#/definitions/v1.StreamError'
      event_id:
        type: string
      item:
        $ref: '#/definitions/v1.Item'
      item_id:
        type: string
      output_index:
        type: integer
        x-nullable: true
      part:
        $ref: '#/definitions/v1.ItemContent'
      session:
        $ref: '#/definitions/v1.Session'
      session_id:
        type: string
      subagent:
        $ref: '#/definitions/v1.Subagent'
      text:
        type: string
      turn:
        $ref: '#/definitions/v1.Turn'
      turn_id:
        type: string
      type:
        type: string
      usage:
        allOf:
        - $ref: '#/definitions/v1.TokenUsage'
        description: |-
          Usage is present only on terminal Turn events, where it mirrors the Turn
          snapshot and is null when unknown. Other events omit it.
        x-nullable: true
    required:
    - event_id
    - type
    type: object
  v1.SessionExecutionInput:
    properties:
      environment:
        description: Environment supplies placement-independent preparation through
          the Core extension.
        type: object
      harness_config:
        type: object
      model_provider:
        $ref: '#/definitions/v1.ModelProviderInput'
    type: object
  v1.SessionInput:
    properties:
      call_id:
        type: string
      error:
        type: string
        x-nullable: true
      input:
        items:
          $ref: '#/definitions/v1.InputMessage'
        type: array
      output:
        x-nullable: true
      success:
        type: boolean
      turn_id:
        type: string
      type:
        enum:
        - agent.session.input.message
        - agent.session.input.cancel
        - agent.session.input.tool_result
        type: string
    required:
    - type
    type: object
  v1.SessionList:
    properties:
      data:
        items:
          $ref: '#/definitions/v1.Session'
        type: array
      first_id:
        type: string
        x-nullable: true
      has_more:
        type: boolean
      last_id:
        type: string
        x-nullable: true
      object:
        enum:
        - list
        type: string
    required:
    - data
    - has_more
    - object
    type: object
  v1.Skill:
    properties:
      created_at:
        type: integer
      default_version:
        type: string
      description:
        type: string
      id:
        type: string
      latest_version:
        type: string
      name:
        type: string
      object:
        enum:
        - skill
        type: string
    required:
    - created_at
    - default_version
    - description
    - id
    - latest_version
    - name
    - object
    type: object
  v1.SkillDeleted:
    properties:
      deleted:
        type: boolean
      id:
        type: string
      object:
        enum:
        - skill.deleted
        type: string
    required:
    - deleted
    - id
    - object
    type: object
  v1.SkillList:
    properties:
      data:
        items:
          $ref: '#/definitions/v1.Skill'
        type: array
      first_id:
        type: string
        x-nullable: true
      has_more:
        type: boolean
      last_id:
        type: string
        x-nullable: true
      object:
        enum:
        - list
        type: string
    required:
    - data
    - has_more
    - object
    type: object
  v1.SkillUpdateRequest:
    properties:
      default_version:
        type: string
    required:
    - default_version
    type: object
  v1.SkillVersion:
    properties:
      created_at:
        type: integer
      description:
        type: string
      id:
        type: string
      name:
        type: string
      object:
        enum:
        - skill.version
        type: string
      skill_id:
        type: string
      version:
        type: string
    required:
    - created_at
    - description
    - id
    - name
    - object
    - skill_id
    - version
    type: object
  v1.SkillVersionDeleted:
    properties:
      deleted:
        type: boolean
      id:
        type: string
      object:
        enum:
        - skill.version.deleted
        type: string
      version:
        type: string
    required:
    - deleted
    - id
    - object
    - version
    type: object
  v1.SkillVersionList:
    properties:
      data:
        items:
          $ref: '#/definitions/v1.SkillVersion'
        type: array
      first_id:
        type: string
        x-nullable: true
      has_more:
        type: boolean
      last_id:
        type: string
        x-nullable: true
      object:
        enum:
        - list
        type: string
    required:
    - data
    - has_more
    - object
    type: object
  v1.SourceFile:
    properties:
      bytes:
        minimum: 0
        type: integer
      created_at:
        type: integer
      expires_at:
        type: integer
        x-nullable: true
      filename:
        type: string
      id:
        type: string
      object:
        enum:
        - file
        type: string
      purpose:
        enum:
        - user_data
        type: string
      status:
        enum:
        - processed
        type: string
      status_details:
        type: string
        x-nullable: true
    required:
    - bytes
    - created_at
    - filename
    - id
    - object
    - purpose
    - status
    type: object
  v1.SourceFileDeleted:
    properties:
      deleted:
        type: boolean
      id:
        type: string
      object:
        enum:
        - file
        type: string
    required:
    - deleted
    - id
    - object
    type: object
  v1.SourceFileList:
    properties:
      data:
        items:
          $ref: '#/definitions/v1.SourceFile'
        type: array
      first_id:
        type: string
        x-nullable: true
      has_more:
        type: boolean
      last_id:
        type: string
        x-nullable: true
      object:
        enum:
        - list
        type: string
    required:
    - data
    - has_more
    - object
    type: object
  v1.StreamError:
    properties:
      code:
        type: string
      message:
        type: string
      param:
        description: |-
          Param is the pinned SessionError field. An error SessionEvent always
          carries it, null when unset; Environment state errors and Core's own
          stream_interrupted frame omit it.
        type: string
        x-nullable: true
      type:
        type: string
    type: object
  v1.Subagent:
    properties:
      closed_at:
        type: integer
        x-nullable: true
      id:
        type: string
      instructions:
        items:
          $ref: '#/definitions/v1.AgentContent'
        type: array
        x-nullable: true
      name:
        type: string
        x-nullable: true
      object:
        enum:
        - agent.session.subagent
        type: string
      opened_at:
        type: integer
      parent_agent_id:
        type: string
      session_id:
        type: string
      status:
        enum:
        - active
        - closed
        type: string
    required:
    - id
    - object
    - opened_at
    - parent_agent_id
    - session_id
    - status
    type: object
  v1.SubagentList:
    properties:
      data:
        items:
          $ref: '#/definitions/v1.Subagent'
        type: array
      first_id:
        type: string
        x-nullable: true
      has_more:
        type: boolean
      last_id:
        type: string
        x-nullable: true
      object:
        enum:
        - list
        type: string
    required:
    - data
    - has_more
    - object
    type: object
  v1.SummaryText:
    properties:
      text:
        type: string
      type:
        enum:
        - summary_text
        type: string
    required:
    - text
    - type
    type: object
  v1.TextConfig:
    properties:
      format:
        $ref: '#/definitions/v1.TextFormat'
      verbosity:
        enum:
        - low
        - medium
        - high
        type: string
    required:
    - format
    - verbosity
    type: object
  v1.TextFormat:
    properties:
      schema:
        type: object
      type:
        enum:
        - text
        - json_schema
        type: string
    required:
    - type
    type: object
  v1.TokenUsage:
    properties:
      input_tokens:
        type: integer
      input_tokens_details:
        $ref: '#/definitions/v1.InputTokenDetails'
      output_tokens:
        type: integer
      output_tokens_details:
        $ref: '#/definitions/v1.OutputTokenDetails'
      total_tokens:
        type: integer
    required:
    - input_tokens
    - input_tokens_details
    - output_tokens
    - output_tokens_details
    - total_tokens
    type: object
  v1.Turn:
    properties:
      agent_id:
        type: string
      completed_at:
        type: integer
        x-nullable: true
      created_at:
        type: integer
      error:
        allOf:
        - $ref: '#/definitions/v1.TurnError'
        x-nullable: true
      id:
        type: string
      object:
        enum:
        - agent.session.turn
        type: string
      session_id:
        type: string
      started_at:
        type: integer
        x-nullable: true
      status:
        enum:
        - queued
        - in_progress
        - waiting
        - completed
        - failed
        - cancelled
        type: string
      subagent_id:
        type: string
        x-nullable: true
      usage:
        allOf:
        - $ref: '#/definitions/v1.TokenUsage'
        x-nullable: true
    required:
    - agent_id
    - created_at
    - id
    - object
    - session_id
    - status
    type: object
  v1.TurnError:
    properties:
      code:
        enum:
        - context_length_exceeded
        - session_budget_exceeded
        - usage_limit_exceeded
        - rate_limit_exceeded
        - server_overloaded
        - cyber_policy
        - connection_failed
        - server_error
        - authentication_error
        - invalid_request
        - resource_not_found
        - sandbox_error
        - executor_version_incompatible
        - active_turn_not_steerable
        - request_timeout
        - internal_error
        type: string
      message:
        type: string
    required:
    - code
    - message
    type: object
  v1.TurnList:
    properties:
      data:
        items:
          $ref: '#/definitions/v1.Turn'
        type: array
      first_id:
        type: string
        x-nullable: true
      has_more:
        type: boolean
      last_id:
        type: string
        x-nullable: true
      object:
        enum:
        - list
        type: string
    required:
    - data
    - has_more
    - object
    type: object
  v1.UpdateAgentRequest:
    properties:
      instructions:
        type: string
        x-nullable: true
      metadata:
        additionalProperties:
          type: string
        type: object
        x-nullable: true
      model:
        type: string
      multi_agent:
        type: object
        x-nullable: true
      name:
        maxLength: 128
        type: string
        x-nullable: true
      reasoning:
        allOf:
        - $ref: '#/definitions/v1.Reasoning'
        x-nullable: true
      service_tier:
        enum:
        - auto
        - default
        - flex
        - priority
        - fast
        type: string
        x-nullable: true
      text:
        allOf:
        - $ref: '#/definitions/v1.SavedAgentTextInput'
        x-nullable: true
      tools:
        items:
          type: object
        type: array
        x-nullable: true
      x_agents_core:
        allOf:
        - $ref: '#/definitions/v1.SavedAgentCoreInput'
        x-nullable: true
    type: object
  v1.UpdateCredentialRequest:
    properties:
      auth:
        $ref: '#/definitions/v1.CredentialAuthReplacement'
    required:
    - auth
    type: object
  v1.UpdateSessionRequest:
    properties:
      metadata:
        additionalProperties:
          type: string
        type: object
        x-nullable: true
    required:
    - metadata
    type: object
  v1.Vault:
    properties:
      created_at:
        type: integer
      id:
        type: string
      metadata:
        additionalProperties:
          type: string
        type: object
      name:
        type: string
        x-nullable: true
      object:
        enum:
        - vault
        type: string
    required:
    - created_at
    - id
    - metadata
    - object
    type: object
  v1.VaultDeleted:
    properties:
      deleted:
        type: boolean
      id:
        type: string
      object:
        enum:
        - vault.deleted
        type: string
    required:
    - deleted
    - id
    - object
    type: object
  v1.VaultList:
    properties:
      data:
        items:
          $ref: '#/definitions/v1.Vault'
        type: array
      first_id:
        type: string
        x-nullable: true
      has_more:
        type: boolean
      last_id:
        type: string
        x-nullable: true
      object:
        enum:
        - list
        type: string
    required:
    - data
    - has_more
    - object
    type: object
  v1.WebSearchAction:
    properties:
      pattern:
        type: string
      queries:
        items:
          type: string
        type: array
      query:
        type: string
      type:
        enum:
        - search
        - open_page
        - find_in_page
        - other
        type: string
      url:
        type: string
    required:
    - type
    type: object
info:
  contact: {}
  description: Supported single-Agent execution resources from the pinned openai-python
    beta/agents contract. Bearer keys bind an execution principal to one project;
    optional OpenAI-Organization and OpenAI-Project headers must match that binding.
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
  title: OpenAgentCore Agents API
  version: "1"
paths:
  /agents:
    get:
      description: Lists only the authenticated tenant's saved Agents, independently
        of Sessions. Limit 0 is treated as 1 and larger limits as 100, as observed
        on the hosted service. The local default is 20; exact upstream default/cap
        and empty cursor fields remain unverified. An unknown, malformed or foreign
        after cursor returns not found.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Last Agent ID from the previous page
        in: query
        name: after
        type: string
      - default: 20
        description: Page size; 0 is treated as 1 and values above 100 as 100
        in: query
        minimum: 0
        name: limit
        type: integer
      - default: desc
        description: Creation order; omit for descending, explicit empty values are
          invalid
        enum:
        - asc
        - desc
        in: query
        name: order
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SavedAgentList'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: List reusable Agents
      tags:
      - Agents
    post:
      consumes:
      - application/json
      description: 'Persists configuration independently of execution. Names over
        128 characters and metadata outside 16 string pairs with 64-character keys
        and 512-character values return invalid_request_error with the official param;
        U+0000 in stored strings is rejected as a local storage limit. As on every
        Agents API JSON route, a non-JSON Content-Type, invalid UTF-8, malformed JSON,
        a repeated key at any depth or a non-object root returns invalid_request_error
        with a null param and the official message before other checks; an empty or
        null body is {}. Missing, unknown, wrongly typed or unsupported enum members
        of the pinned configuration shapes (tools, text, reasoning, service_tier,
        multi_agent) return invalid_request_error with the JSON path as param; duplicate
        function names, repeated web_search or tool_search and non-object schema root
        types return it with a null param. Supports model/name/instructions/metadata,
        explicit reasoning and service tiers, multi_agent, text/json_schema, function/tool_search/programmatic_tool_calling/web_search
        and HTTP MCP with nullable credential_id, service origin (omitted or null
        on HTTP transport is saved as service) and boolean required defaulting to
        false. Saving credential_id grants no access: Session admission checks attached
        Vault ownership and destination. MCP allowed_tools preserves null versus empty;
        saved HTTP transport includes empty headers. Model-derived reasoning defaults,
        other MCP variants and public retry conformance remain incomplete. web_search
        saves every pinned mode: omitted or null mode is saved as live and omitted
        or null context_size as medium; allowed_domains preserves null versus empty
        and a present location, including {}, includes all four keys with null for
        omitted ones, as observed officially (req_db41d2f6261b4abfb69465eafe719ab5,
        req_165d53b88445490b9146d8272c54134d). Session execution accepts only explicit
        disabled web_search and disabled programmatic_tool_calling through qualified
        Runtime controls; saved enabled forms reject at Session admission. Session
        execution admits only its supported configuration subset.'
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Reusable Agent configuration
        in: body
        name: body
        required: true
        schema:
          $ref: '#/definitions/v1.CreateAgentRequest'
      produces:
      - application/json
      responses:
        "201":
          description: Created
          schema:
            $ref: '#/definitions/v1.SavedAgent'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "413":
          description: Request Entity Too Large
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Create a reusable Agent
      tags:
      - Agents
  /agents/{agent_id}:
    delete:
      description: Deletes only the authenticated tenant's saved configuration. Existing
        Session snapshots, history and recorded creation retry identities remain independent.
        Missing and repeated deletion locally return404; exact hosted error and in-flight
        creation/deletion semantics remain unverified.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Agent ID
        in: path
        name: agent_id
        required: true
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.AgentDeleted'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "413":
          description: Request Entity Too Large
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Delete a reusable Agent
      tags:
      - Agents
    get:
      description: Reads the saved resource owned by the authenticated tenant, independently
        of execution Sessions.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Agent ID
        in: path
        name: agent_id
        required: true
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SavedAgent'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Retrieve a reusable Agent
      tags:
      - Agents
    post:
      consumes:
      - application/json
      description: Preserves omitted fields and replaces supplied fields using shared
        saved-configuration validation. Null name/instructions clear; null or empty
        metadata clears all pairs. Name, metadata and configuration validation errors
        return invalid_request_error with the official param, using the Agent create
        rules before the Agent lookup. Existing Session snapshots are unchanged. Empty
        updates advance updated_at without changing saved fields. Nested replacement/null
        defaults, model-derived reasoning and exact hosted error behavior remain incompletely
        verified.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Agent ID
        in: path
        name: agent_id
        required: true
        type: string
      - description: Supplied reusable Agent fields
        in: body
        name: body
        required: true
        schema:
          $ref: '#/definitions/v1.UpdateAgentRequest'
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SavedAgent'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "413":
          description: Request Entity Too Large
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Update a reusable Agent
      tags:
      - Agents
  /agents/environments/{environment_id}:
    get:
      description: Returns durable connection status and safe installed metadata for
        supported self_hosted and basic openai_hosted profiles. Initial files expose
        frozen safe metadata without content; Plugin/Skill entries expose only safe
        configured installation metadata. Capability-directory discoveries are not
        added to those arrays. Unsupported installation configurations remain implementation
        gaps. This read does not prepare execution, start compute or require an enabled
        execution worker. Session deletion removes the associated Environment from
        public reads; project-shared read authorization is unchanged. Connection status
        does not prove native readiness or process quiescence.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Environment ID
        in: path
        name: environment_id
        required: true
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.EnvironmentInfo'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Retrieve an execution Environment
      tags:
      - Environments
  /agents/environments/{environment_id}/files:
    get:
      description: Lists direct regular files in one authorized self_hosted or qualified
        local workspace directory. Local paths use the public /workspace root and
        must be in cleaned form. This partial implementation defaults to the workspace
        root and limit 20; recursive scope and these defaults are not verified upstream
        semantics. A missing path, a regular file or a symbolic link returns an empty
        page; links are never followed. Daemons without a local workspace binding
        use the Claude SDK adapter reader, which keeps 404 for a missing path and
        503 for a regular file or symbolic link. Well-formed unknown query keys are
        ignored; malformed query encoding and a repeated supported key are rejected.
        Sorts by case-sensitive path components, descending by default. Keep the same
        path, order and limit when using page. Each page rereads the complete bounded
        directory; changed file paths/sizes invalidate continuation locally with 400.
        There is no snapshot guarantee. An openai_hosted Environment that has not
        connected yet returns 400. Truncated or uncertain native results fail with
        503 without returning a partial page. This read never starts a Turn or admits
        model input. Actual transport disconnect/reconnect events remain observable.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Environment ID
        in: path
        name: environment_id
        required: true
        type: string
      - description: Absolute directory in cleaned form inside /workspace
        in: query
        name: path
        type: string
      - description: Maximum file count; local default 20
        in: query
        maximum: 100
        minimum: 1
        name: limit
        type: integer
      - default: desc
        description: Case-sensitive path-component order; omit for descending, explicit
          empty values are invalid
        enum:
        - asc
        - desc
        in: query
        name: order
        type: string
      - description: Opaque continuation token; keep path, order and limit unchanged
        in: query
        name: page
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.EnvironmentFileList'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: List live Environment files
      tags:
      - Environments
    post:
      consumes:
      - application/json
      description: Uploads standard Base64 bytes to a file beneath /workspace in a
        qualified local Environment and returns 201. Accepts inline bytes or a project-owned
        source file_id through the same write path. Unknown body fields are rejected
        with their name as param. Basic public hosted creation requires explicit managed
        Runtime configuration; an openai_hosted Environment that has not connected
        yet returns 400. Inline data is limited to 5 MiB decoded and a file_id copy
        to 50 MiB. Missing parent directories are created with mode 0700 and the file
        with mode 0600. An existing destination is never replaced; a directory, an
        existing file or a path through a symlink or non-directory returns 400. Idle
        writes exclude execution. Missing receipts return unavailable and retain a
        durable mutation gate without automatic replay. Error/timing parity with upstream
        remains unverified.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Environment ID
        in: path
        name: environment_id
        required: true
        type: string
      - description: Inline bytes or source file ID and absolute workspace path
        in: body
        name: request
        required: true
        schema:
          $ref: '#/definitions/v1.EnvironmentFileCreateRequest'
      produces:
      - application/json
      responses:
        "201":
          description: Created
          schema:
            $ref: '#/definitions/v1.EnvironmentFile'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "409":
          description: Conflict
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "413":
          description: Request Entity Too Large
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Create an Environment file from inline bytes or a source file
      tags:
      - Environments
  /agents/environments/templates:
    get:
      description: Lists tenant-owned safe template metadata in creation order with
        ID tie-breaking. Defaults to limit 20 and descending order; limit 0 is treated
        as 1 and larger limits as 100. Foreign, missing and malformed cursors return
        the same not found error. Concurrent-page and exact hosted error behavior
        remain unverified.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Previous Template ID
        in: query
        name: after
        type: string
      - default: 20
        description: Page size; 0 is treated as 1 and values above 100 as 100
        in: query
        minimum: 0
        name: limit
        type: integer
      - default: desc
        description: Creation order; omit for descending, explicit empty values are
          invalid
        enum:
        - asc
        - desc
        in: query
        name: order
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.EnvironmentTemplateList'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: List Environment Templates
      tags:
      - Environment Templates
    post:
      consumes:
      - application/json
      description: Saves tenant-owned hosted configuration. Supports nullable name,
        enabled/disabled or exact-domain restricted network, initial inline/file_id
        files, confidential env, ordered setup_commands, npm/Python packages inline/referenced
        Skill ZIPs, Plugin ZIPs and workspace-contained capability directories. Omitted/null
        network defaults to enabled. Restricted network requires 1–100 exact ASCII
        hostnames; other host forms and populated unsupported installations are rejected
        before persistence without echoing input. Network policy rejections return
        invalid_request_error with a null param. System dependencies must be preinstalled
        in the sandbox image or template, or on the host machine; packages.system
        is rejected. No compute is allocated. Exact hosted error/retry semantics remain
        unverified.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Reusable configuration
        in: body
        name: body
        required: true
        schema:
          $ref: '#/definitions/v1.EnvironmentTemplateRequest'
      produces:
      - application/json
      responses:
        "201":
          description: Created
          schema:
            $ref: '#/definitions/v1.EnvironmentTemplate'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "413":
          description: Request Entity Too Large
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Create an Environment Template
      tags:
      - Environment Templates
  /agents/environments/templates/{environment_template_id}:
    delete:
      description: Deletes the tenant-owned reusable configuration without changing
        or deleting existing Sessions and their frozen configuration.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Template ID
        in: path
        name: environment_template_id
        required: true
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.EnvironmentTemplateDeleted'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Delete an Environment Template
      tags:
      - Environment Templates
    get:
      description: Returns safe tenant-owned configuration metadata without allocating
        compute. Missing and foreign resources return the same not-found response.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Template ID
        in: path
        name: environment_template_id
        required: true
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.EnvironmentTemplate'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Retrieve an Environment Template
      tags:
      - Environment Templates
    post:
      consumes:
      - application/json
      description: Supplied fields replace atomically; omitted fields remain unchanged.
        Null name clears and null network resets to the pinned enabled default. Existing
        Session snapshots and creation retries remain unchanged. Initial files replace
        as a list; null/empty clears. File data is encrypted separately and excluded
        from response metadata. Skills replace as a list; null/empty clears. Skill
        archives are encrypted separately and omitted from responses. Plugins and
        capability directories replace as lists; null/empty clears. Plugin archives
        are encrypted and omitted from responses. Capability directories are snapshotted
        after setup. Environment MCP execution requires a qualified native transport
        and runtime network policy. Empty updates advance updated_at without changing
        saved fields or confidential contents. Network policy rejections return invalid_request_error
        with a null param.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Template ID
        in: path
        name: environment_template_id
        required: true
        type: string
      - description: Configuration replacements
        in: body
        name: body
        required: true
        schema:
          $ref: '#/definitions/v1.EnvironmentTemplateRequest'
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.EnvironmentTemplate'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "413":
          description: Request Entity Too Large
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Update an Environment Template
      tags:
      - Environment Templates
  /agents/sessions:
    get:
      description: Cursor and results are scoped to the authenticated execution tenant;
        an unknown, malformed or foreign after cursor returns not found. Optional
        agent_id matches the immutable root Agent ID, including inline Agents and
        historical Sessions whose saved source was updated or deleted. Omission lists
        all Agents. Returns the same Environment and pending-input activity projection
        as Session retrieval, including self_hosted Sessions.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Root Agent ID whose Sessions to return
        in: query
        name: agent_id
        type: string
      - description: Last Session ID from the previous page
        in: query
        name: after
        type: string
      - default: 20
        description: Page size; 0 is treated as 1 and values above 100 as 100
        in: query
        minimum: 0
        name: limit
        type: integer
      - default: desc
        description: Creation order; omit for descending, explicit empty values are
          invalid
        enum:
        - asc
        - desc
        in: query
        name: order
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SessionList'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: List execution Sessions
      tags:
      - Sessions
    post:
      consumes:
      - application/json
      description: 'The optional Core model_provider bundle resolves from the Session
        override, saved Agent defaults, then, for openai_hosted and none, the deployment
        default of the resolved harness; self_hosted never uses the deployment default
        and none accepts only it. openai_hosted and self_hosted Sessions that resolve
        no bundle return 400 model_provider_required with param x_agents_core.model_provider
        before any write. Core encrypts and freezes the resolved bundle; later Agent
        or deployment default edits and same-key retries cannot change it. Keys are
        never returned. Supports inline configuration or a tenant-owned saved agent_id
        with per-Session field replacements. Execution supports model/instructions,
        text verbosity, non-deferred function tools, adapter-qualified multi_agent
        with persisted Subagent reads, implicit reasoning, service tier auto and environment
        type none, subject to the configured engine. Codex additionally supports HTTP
        MCP with service origin (omitted or null on HTTP transport is saved as service),
        native allowed_tools and boolean required defaulting to false. Session vault_ids
        attach only project-owned Vaults; credential_id selects an attached static
        bearer or OAuth credential for the exact HTTPS URL, while null/omission selects
        a unique match or remains anonymous. Session reads, lists and event snapshots
        show that implicitly selected credential ID in a null or omitted credential_id,
        also after the credential is deleted; anonymous selections stay null and the
        stored caller intent is unchanged. After the input requirement and before
        any write, a credential_id without vault_ids, one outside the attached Vaults
        (one message for missing, foreign and unattached IDs) or one for another server_url
        returns 400 invalid_request_error, and several implicit matches return 409
        conflict_error. Missing decryption configuration fails dispatch without anonymous
        fallback. Required initialization uses native startup before the first native
        Turn, including cold resume, and requires a separately advertised capability;
        exact hosted creation timing and error parity remain unverified. Explicit
        environment-origin HTTP MCP is supported on managed and self-hosted workspaces
        through the same Runtime bindings; native OAuth login remains unsupported.
        The self_hosted profile uses a qualified native harness, a clean absolute
        workspace_directory and optional absolute local capability_directories prepared
        by Runtime, with optional non-deferred function tools and HTTP MCP using explicit
        environment origin, optionally authenticated by the attached Vault rules.
        Service-origin HTTP remains restricted to service-side environment:none. Remote
        MCP and remote Bearer authentication each require separately advertised combination
        support; old peers cannot receive unsupported work. Omitted/null capability_directories
        use the empty-list default; self_hosted requires configured execution plus
        executor registry. Claude SDK currently requires medium verbosity and object-root
        function schemas. It supports anonymous or attached static-bearer service-origin
        HTTP MCP on none with boolean required and separately advertised MCP/bearer/required
        runtime support. Required servers must be connected before the first native
        input is released; pending or failed startup rejects execution. The shared
        Vault selection and immutable binding rules apply; unsupported native labels/tool
        names reject before persistence. An attached Vault with no matching credential
        may remain anonymous; missing keys or failed credential lookup/decryption
        never fall back to anonymous execution. Omitted stream defaults to false;
        stream and agent_id cannot be null. Metadata may be null; non-string values
        and limit violations return invalid_request_error with a metadata or metadata.<key>
        param. The inline agent uses the Agent create configuration validation with
        agent.-prefixed params, reported before the input requirement and saved-Agent
        lookup; saved configurations with conflicting tools or schema roots reject
        admission with the same errors, and execution limits keep unsupported_or_invalid_configuration.
        Hosted network policy rejections return invalid_request_error with a null
        param. Initial input accepts a string or ordered user-message array. Codex
        and Claude SDK on none and qualified managed or self_hosted workspace profiles
        also accept inline PNG/JPEG image content; other image combinations and remote
        URLs are unsupported. None initial input atomically starts a Turn; self_hosted
        initial input is reserved while returning its Environment connection target,
        with execution deferred to native readiness and Session failure on initial
        timeout. Initial input is required for none and for streamed creation outside
        self_hosted. Omitted/null input remains valid for non-streaming hosted and
        self_hosted creation. With stream=true, returns live Session events starting
        with the committed creation snapshot and closes right after the first agent.session.idle
        recorded when a Turn ends or an input reservation stops being pending, or
        any agent.session.failed, without sending later events. A creation that admitted
        nothing closes after the snapshot; a settlement that records no event closes
        after events up to the cursor read with a settled Session projection. Required
        actions keep it open; disconnect does not cancel execution. The GET events
        stream remains live-only. New Sessions retain their authenticated creator;
        all creation retries require the same typed subject, including across key
        rotation. Saved-Agent retries and inline requests using Vault attachments
        or credential references retain caller intent independently of later resource
        changes; new hosted inline requests also freeze caller intent before deployment
        defaults resolve; unrelated non-hosted inline retries preserve resolved/default
        equivalences, and their resolved hash leaves out any deployment default. Provider
        keys enter retry hashes only as fingerprints keyed by the credential key.
        Unknown historical creators reject retries; known creators without recorded
        intent retain resolved-snapshot retry rules. These conflict policies are local
        and not verified hosted parity. A same-key stream=true retry of an existing
        creation returns 201 with no events and closes at once; retry with stream=false
        or use the GET events stream to recover. Claude SDK on none, Core-managed
        Docker openai_hosted and self_hosted supports qualified object-root json_schema
        output with medium verbosity, single-Agent execution and ordinary functions.
        Hosted execution reuses native workspace tools and Files/Artifacts; Skills,
        Plugins, capability directories, HTTP MCP, Subagent and tool_search combinations
        remain unqualified, including inherited template contents. Other non-text
        initial input remains unsupported. Basic Codex and Claude SDK openai_hosted
        creation requires an explicitly configured managed provider. The Claude workspace
        profile supports non-deferred function tools with text or successful inline
        PNG/JPEG results alongside native workspace tools; explicit environment-origin
        HTTP MCP uses the common Runtime path. MiniMax accepts public environment-origin
        HTTP MCP only with null or omitted allowed_tools and required=false; even
        an empty non-null allowlist rejects. Idle Sessions provision automatically;
        initial provisioning has no caller connection action. Network defaults to
        enabled; disabled and restricted policies reject before compute allocation
        because the current Runtime cannot enforce them. The x_agents_core.environment
        extension accepts common preparation fields for either hosted or self-hosted
        placement: environment_template_id, files, env, packages, setup_commands,
        skills, plugins and capability_directories. Duplicate fields in environment
        and the extension reject. Confidential env, npm/Python packages and ordered
        setup commands use the same Environment-owned initialization lifecycle; compute
        allocation does not own preparation. Unknown side effects are not replayed
        after disconnect or restart. System dependencies must be preinstalled in the
        sandbox image or template, or on the host machine; packages.system is rejected.
        Initial inline and tenant-owned file_id files freeze encrypted bytes before
        provisioning, then install through the common Core lifecycle before native
        execution or live Files access. With a template reference, omitted/null files,
        env, packages and setup_commands inherit. Non-null files and command lists
        replace; env overlays by key; each package manager inherits on omission/null
        and otherwise replaces its list. Empty lists clear their selected field. Tenant-owned
        environment_template_id references inherit omitted/null network and allow
        only narrowing overrides. Inline hosted network:null retains the enabled default;
        updating a Template with network:null resets its saved policy to enabled.
        Core freezes effective configuration; template updates/deletion do not alter
        Session snapshots or same-intent creation retries. Inline or tenant-owned
        skill_reference Skills share initialization. Templates preserve default/latest/explicit
        selectors; Session creation freezes concrete metadata and encrypted content
        atomically. Skill, Plugin and capability-directory list omission/null inherit;
        a non-null list replaces, including empty-list clearing. Omitted/null Skill
        version selectors resolve the default version. Source deletion/default updates
        cannot change committed Session Skill contents. Deferred function discovery
        uses type-only tool_search and per-function defer_loading in the qualified
        single-agent Claude function profile on none or a managed/user-owned workspace,
        including qualified inline image messages and text results. Explicit web_search
        mode disabled and programmatic_tool_calling enabled false use frozen common
        Runtime controls. Enabled forms, including those saved on an Agent, remain
        unqualified and reject before any write unless the Session replaces tools.
        Omitted programmatic configuration preserves native behavior, a documented
        difference from the official default-on behavior. Other combinations remain
        unqualified; see the operation coverage.'
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Creation retry key, up to 128 bytes
        in: header
        name: Idempotency-Key
        type: string
      - description: Session configuration
        in: body
        name: body
        required: true
        schema:
          $ref: '#/definitions/v1.CreateSessionRequest'
      produces:
      - application/json
      - text/event-stream
      responses:
        "201":
          description: Created
          schema:
            $ref: '#/definitions/v1.Session'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "409":
          description: Conflict
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "413":
          description: Request Entity Too Large
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Create an execution Session
      tags:
      - Sessions
  /agents/sessions/{session_id}:
    delete:
      description: Removes a durably idle or failed Session and its history from the
        public API. A Session whose root Turn is queued, in progress or waiting (including
        required actions) or whose input reservation is pending returns 409 conflict_error
        and is left unchanged; cancel it and wait until it is idle before deleting.
        Subagent child Turns and pending Environment file writes are not checked and
        do not block deletion. Repeating the deletion of the caller's own deleted
        Session returns the same confirmation; missing and foreign Sessions return
        404. Internal records and native history are retained pending separate physical
        cleanup; overlapping stream timing remains unverified.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Session ID
        in: path
        name: session_id
        required: true
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SessionDeleted'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "409":
          description: Conflict
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "413":
          description: Request Entity Too Large
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Delete an execution Session
      tags:
      - Sessions
    get:
      description: Returns supported none, self_hosted and basic openai_hosted Session
        environments. Self-hosted pending input can require a caller connection before
        a Turn exists. Hosted initial provisioning remains idle until a Turn starts;
        connection observations are not native execution readiness.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Session ID
        in: path
        name: session_id
        required: true
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.Session'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Retrieve an execution Session
      tags:
      - Sessions
    post:
      consumes:
      - application/json
      description: The metadata field is required in an update body. Send null or
        {} to clear it, or supply an object to replace all pairs. Up to 16 string
        pairs, with keys at most 64 characters and values at most 512 characters;
        violations and non-string values return invalid_request_error with a metadata
        or metadata.<key> param. U+0000 is rejected as a local storage limit. Malformed,
        missing and foreign Session IDs share the not-found response. Execution configuration
        and activity are unchanged. Returns the same safe Environment and pending-input
        activity projection as Session retrieval.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Session ID
        in: path
        name: session_id
        required: true
        type: string
      - description: Session metadata
        in: body
        name: body
        required: true
        schema:
          $ref: '#/definitions/v1.UpdateSessionRequest'
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.Session'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "413":
          description: Request Entity Too Large
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Update execution Session metadata
      tags:
      - Sessions
  /agents/sessions/{session_id}/artifacts:
    get:
      description: Lists published outputs independently of Environment availability.
        Sorting uses publication time and ID. A later Turn publishes a path again
        only when it is new, its bytes changed, or no Artifact remains for it. A malformed
        environment_id matches nothing. An after value that is not an Artifact of
        this Session, including a malformed one, returns 400 invalid_request_error
        with the message "after is not a valid artifact ID". The local default page
        size is 20; exact upstream defaults remain unverified.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Session ID
        in: path
        name: session_id
        required: true
        type: string
      - description: Producing Environment ID; an unknown or malformed ID returns
          an empty page
        in: query
        name: environment_id
        type: string
      - description: Last immutable artifact ID
        in: query
        name: after
        type: string
      - default: 20
        description: Page size
        in: query
        maximum: 100
        minimum: 1
        name: limit
        type: integer
      - default: desc
        description: Publication order; omit for descending, explicit empty values
          are invalid
        enum:
        - asc
        - desc
        in: query
        name: order
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SessionArtifactList'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: List immutable Session artifacts
      tags:
      - Artifacts
  /agents/sessions/{session_id}/artifacts/{artifact_id}:
    delete:
      description: Deletes the published copy without modifying its original workspace
        file. Already admitted content reads may finish; later reads reject.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Session ID
        in: path
        name: session_id
        required: true
        type: string
      - description: Artifact ID
        in: path
        name: artifact_id
        required: true
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SessionArtifactDeleted'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Delete a published artifact
      tags:
      - Artifacts
    get:
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Session ID
        in: path
        name: session_id
        required: true
        type: string
      - description: Artifact ID
        in: path
        name: artifact_id
        required: true
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SessionArtifact'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Retrieve immutable artifact metadata
      tags:
      - Artifacts
  /agents/sessions/{session_id}/artifacts/{artifact_id}/content:
    get:
      description: Streams stored bytes after tenant and Session authorization, including
        after Environment expiration. Exact upstream headers and Range behavior remain
        unverified.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Session ID
        in: path
        name: session_id
        required: true
        type: string
      - description: Artifact ID
        in: path
        name: artifact_id
        required: true
        type: string
      produces:
      - application/octet-stream
      responses:
        "200":
          description: OK
          schema:
            type: file
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Download immutable artifact bytes
      tags:
      - Artifacts
  /agents/sessions/{session_id}/events:
    get:
      description: |-
        Live-only events, including command output fragments from capable Codex peers as agent.output.command_execution_output.delta with stable Item/output indexes. Native text conversion and output quotas apply; completion snapshots remain authoritative. Reconnect through Session, Turn and Items reads; missed events are not replayed. A lagging stream closes with an error when its bounded buffer is exceeded. When a hosted Environment fails to provision, the stream sends agent.session.environment.failed, an error event (environment_error/sandbox_error with the safe step and exit-status reason, never command output) and agent.session.failed, then ends. Session activity includes immutable pending-input connection actions before Turn creation; self_hosted environments use the same safe output as Session retrieval.
        Active streams revalidate the original Project key every second before output; revocation, Project archival or authentication unavailability closes the stream. Authentication checks use a five-second timeout.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Session ID
        in: path
        name: session_id
        required: true
        type: string
      produces:
      - text/event-stream
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SessionEvent'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Stream live Session events
      tags:
      - Events
    post:
      consumes:
      - application/json
      description: An empty events array is a resource-authorized no-op; it creates
        no execution retry identity, Turn, Item or input receipt. For environment
        none, atomically accepts text messages, cancellation and function results.
        Messages steer active work or start a queued Turn. Qualified Codex and Claude
        SDK workspace profiles accept text and inline PNG/JPEG messages, independently
        of managed or self_hosted ownership. Under the Session lock, matching retries
        retain their original target; new active messages append to the current Turn,
        while idle messages reserve work and wait up to the original five-minute connection/admission
        deadline. Return 202 only after durable admission, without claiming native
        application; active messages create no Turn or reservation. Cancellation-only
        prepared-environment batches use existing durable cancellation admission and
        return 202 without waiting for native exit; a new cancellation conflicts while
        a pre-Turn reservation is pending. Homogeneous tool_result-only prepared-environment
        batches reuse existing scoped result admission and application receipts without
        creating a Turn or bypassing a pending reservation. Mixed prepared-environment
        batches remain unsupported. HTTP expiry/cancellation use local 409 environment_input_expired/environment_input_cancelled
        errors. New input on a Session whose hosted Environment failed to provision
        returns the observed 409 conflict_error "the hosted environment failed to
        provision"; input already waiting when it fails and expired Environments keep
        the local 409 environment_unavailable. Input the Session cannot accept in
        its current state, such as a result after cancellation or a batch while earlier
        input is pending, and a result that differs from the call's saved result return
        409 with type and code conflict_error; reusing an Idempotency-Key with a different
        batch returns the local 409 idempotency_conflict. Inside an owned Session,
        a result for an unknown call or for a call of another Turn returns 400 invalid_request_error
        and changes nothing; missing and foreign Sessions return 404. Losing execution
        ownership returns 503. The response write deadline accommodates the admission
        window for either prepared Environment, independently of new-hosted-admission
        and executor URL settings. Disconnecting the waiting HTTP request does not
        cancel retained work or restart its deadline. Retry keys identify the whole
        ordered batch. Function output accepts text or ordered text/image parts subject
        to engine support; Claude SDK accepts text results and, on none and qualified
        workspace profiles, successful inline PNG/JPEG results, preserving ordered
        content; error images and remote references reject before admission. Native
        image resizing may change bytes. Runtime image-result support is checked only
        for image-bearing delivery. Codex and Claude SDK on none and qualified managed
        or self_hosted workspace profiles accept ordered inline PNG/JPEG image messages.
        Other engines remain text-only; remote image URLs are unsupported. Image references
        are retained unchanged without service-side downloads.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Retry key, up to 128 bytes
        in: header
        name: Idempotency-Key
        type: string
      - description: Session ID
        in: path
        name: session_id
        required: true
        type: string
      - description: Ordered input events
        in: body
        name: body
        required: true
        schema:
          $ref: '#/definitions/v1.CreateEventsRequest'
      responses:
        "202":
          description: Accepted
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "409":
          description: Conflict
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "413":
          description: Request Entity Too Large
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Submit Session input events
      tags:
      - Sessions
  /agents/sessions/{session_id}/items:
    get:
      description: Returns supported message and tool Items in first-observation order.
        Native engine fields are projected explicitly; unfinished Items on terminal
        Turns are incomplete. Cursors are Items of the same tenant and Session. Any
        other after value, including a malformed one, returns 400 invalid_request_error
        with the message "Invalid session item ID in `after`".
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Session ID
        in: path
        name: session_id
        required: true
        type: string
      - description: Last Item ID from the previous page
        in: query
        name: after
        type: string
      - default: 20
        description: Page size; 0 is treated as 1 and values above 100 as 100
        in: query
        minimum: 0
        name: limit
        type: integer
      - default: desc
        description: Creation order; omit for descending, explicit empty values are
          invalid
        enum:
        - asc
        - desc
        in: query
        name: order
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.ItemList'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: List persisted execution Items
      tags:
      - Items
  /agents/sessions/{session_id}/subagents:
    get:
      description: Includes nested and closed Subagents. Cursors are Subagents of
        the same tenant and Session. Any other after value, including a malformed
        one, returns 400 invalid_request_error with the message "Invalid resource
        ID in `after`". A limit outside 1–100 is rejected.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Session ID
        in: path
        name: session_id
        required: true
        type: string
      - description: Last Subagent ID from the previous page
        in: query
        name: after
        type: string
      - default: 20
        description: Page size
        in: query
        maximum: 100
        minimum: 1
        name: limit
        type: integer
      - default: desc
        description: Resource order; omit for descending, explicit empty values are
          invalid
        enum:
        - asc
        - desc
        in: query
        name: order
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SubagentList'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: List Session Subagents
      tags:
      - Subagents
  /agents/sessions/{session_id}/subagents/{subagent_id}:
    get:
      description: Returns this Session's persisted Subagent. Active includes idle
        between Turns. Resuming preserves opened_at and clears closed_at. Unknown
        or inaccessible parent scopes return not found.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Session ID
        in: path
        name: session_id
        required: true
        type: string
      - description: Subagent ID
        in: path
        name: subagent_id
        required: true
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.Subagent'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Retrieve a Session Subagent
      tags:
      - Subagents
  /agents/sessions/{session_id}/subagents/{subagent_id}/items:
    get:
      description: Returns only this Subagent's own Items across all its Turns, not
        its descendants' Items. Cursors are Items of the same tenant, Session and
        Subagent. Any other after value, including a malformed one, returns 400 invalid_request_error
        with the message "Invalid session item ID in `after`".
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Session ID
        in: path
        name: session_id
        required: true
        type: string
      - description: Subagent ID
        in: path
        name: subagent_id
        required: true
        type: string
      - description: Last Item ID from the previous page
        in: query
        name: after
        type: string
      - default: 20
        description: Page size; 0 is treated as 1 and values above 100 as 100
        in: query
        minimum: 0
        name: limit
        type: integer
      - default: desc
        description: Resource order; omit for descending, explicit empty values are
          invalid
        enum:
        - asc
        - desc
        in: query
        name: order
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.ItemList'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: List a Subagent's Items
      tags:
      - Subagents
  /agents/sessions/{session_id}/subagents/{subagent_id}/turns:
    get:
      description: Includes this Subagent's Turns after resume, with the Session's
        Agent ID as agent_id. Cursors are Turns of the same tenant, Session and Subagent.
        Any other after value, including a malformed one, returns 400 invalid_request_error
        with the message "Invalid resource ID in `after`". Missing recorded usage
        remains null. A limit outside 1–100 is rejected.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Session ID
        in: path
        name: session_id
        required: true
        type: string
      - description: Subagent ID
        in: path
        name: subagent_id
        required: true
        type: string
      - description: Last Turn ID from the previous page
        in: query
        name: after
        type: string
      - default: 20
        description: Page size
        in: query
        maximum: 100
        minimum: 1
        name: limit
        type: integer
      - default: desc
        description: Creation order; omit for descending, explicit empty values are
          invalid
        enum:
        - asc
        - desc
        in: query
        name: order
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.TurnList'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: List a Subagent's Turns
      tags:
      - Subagents
  /agents/sessions/{session_id}/subagents/{subagent_id}/turns/{turn_id}:
    get:
      description: Returns a Turn owned by this Subagent. Its agent_id is the Session's
        Agent ID and its subagent_id identifies the Subagent. Session Turn routes
        do not return child Turns. Unknown or inaccessible parent scopes return not
        found.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Session ID
        in: path
        name: session_id
        required: true
        type: string
      - description: Subagent ID
        in: path
        name: subagent_id
        required: true
        type: string
      - description: Turn ID
        in: path
        name: turn_id
        required: true
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.Turn'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Retrieve a Subagent Turn
      tags:
      - Subagents
  /agents/sessions/{session_id}/subagents/{subagent_id}/turns/{turn_id}/items:
    get:
      description: Returns Items owned by this exact Subagent Turn. Cursors are Items
        of the same tenant, Session, Subagent and Turn. Any other after value, including
        a malformed one, returns 400 invalid_request_error with the message "Invalid
        session item ID in `after`".
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Session ID
        in: path
        name: session_id
        required: true
        type: string
      - description: Subagent ID
        in: path
        name: subagent_id
        required: true
        type: string
      - description: Turn ID
        in: path
        name: turn_id
        required: true
        type: string
      - description: Last Item ID from the previous page
        in: query
        name: after
        type: string
      - default: 20
        description: Page size; 0 is treated as 1 and values above 100 as 100
        in: query
        minimum: 0
        name: limit
        type: integer
      - default: desc
        description: Resource order; omit for descending, explicit empty values are
          invalid
        enum:
        - asc
        - desc
        in: query
        name: order
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.ItemList'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: List a Subagent Turn's Items
      tags:
      - Subagents
  /agents/sessions/{session_id}/turns:
    get:
      description: Returns the Session's root Turns in creation order; Subagent Turns
        are listed through the Subagent Turn routes. The cursor belongs to the same
        Session and tenant; any other after value, including a malformed one or a
        Subagent Turn ID, returns not found. Usage contains the latest recorded complete
        token breakdown; missing measurements remain null.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Session ID
        in: path
        name: session_id
        required: true
        type: string
      - description: Last Turn ID from the previous page
        in: query
        name: after
        type: string
      - default: 20
        description: Page size
        in: query
        maximum: 100
        minimum: 1
        name: limit
        type: integer
      - default: desc
        description: Creation order; omit for descending, explicit empty values are
          invalid
        enum:
        - asc
        - desc
        in: query
        name: order
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.TurnList'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: List execution Turns
      tags:
      - Turns
  /agents/sessions/{session_id}/turns/{turn_id}:
    get:
      description: Returns a root Turn of this Session. A Subagent Turn ID returns
        the same not found error as a missing Turn; read it through the Subagent Turn
        routes.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Session ID
        in: path
        name: session_id
        required: true
        type: string
      - description: Turn ID
        in: path
        name: turn_id
        required: true
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.Turn'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Retrieve an execution Turn
      tags:
      - Turns
  /files:
    get:
      description: Lists project-owned Files without reading their bodies. The limit
        defaults to 10000 and must be 1–10000. Equal creation times use ID ordering.
        Purpose validation precedes cursor lookup; current storage contains only user_data.
        An explicit empty purpose is treated as omitted. Repeated purpose values remain
        rejected. Hosted positive filtering, default order and concurrent-page behavior
        remain unverified. No Beta header is required.
      parameters:
      - description: Last File ID from the previous page
        in: query
        name: after
        type: string
      - default: 10000
        description: Maximum page size, 1–10000
        in: query
        maximum: 10000
        minimum: 1
        name: limit
        type: integer
      - default: desc
        description: Creation order; omit for descending, explicit empty values are
          invalid
        enum:
        - asc
        - desc
        in: query
        name: order
        type: string
      - description: Only return Files with this purpose
        in: query
        name: purpose
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SourceFileList'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: List source files
      tags:
      - Files
    post:
      consumes:
      - multipart/form-data
      description: Accepts one multipart file and purpose=user_data in either order,
        with a private 512 MiB content limit and 64 KiB envelope allowance. Commits
        only after the entire request validates. The source is project-owned, independent
        of Sessions and workspace copies. No Beta header is required. Other purposes,
        expires_after, listing, resumable Uploads, quotas/rate-limit and complete
        hosted error/status parity remain unsupported or unverified.
      parameters:
      - description: Source bytes
        in: formData
        name: file
        required: true
        type: file
      - description: user_data
        enum:
        - user_data
        in: formData
        name: purpose
        required: true
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SourceFile'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "413":
          description: Request Entity Too Large
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Upload a source file
      tags:
      - Files
  /files/{file_id}:
    delete:
      description: Atomically deletes project-owned metadata and stored bytes. Already-admitted
        reads or copies may finish. Workspace copies remain independent. Historical
        WAL/backups are not erased. No Beta header is required; exact hosted concurrent
        deletion/error semantics remain unverified.
      parameters:
      - description: Source file ID
        in: path
        name: file_id
        required: true
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SourceFileDeleted'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Delete a source file
      tags:
      - Files
    get:
      description: Returns immutable project-owned user_data file metadata. No Beta
        header is required. Other purposes, expiration and full hosted status/error
        semantics remain unimplemented or unverified.
      parameters:
      - description: Source file ID
        in: path
        name: file_id
        required: true
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SourceFile'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Retrieve source file metadata
      tags:
      - Files
  /files/{file_id}/content:
    get:
      description: Resolves project-owned File metadata before enforcing download
        policy. Public download of user_data Files returns 400; missing and foreign
        Files return the same 404. Internal initial-file and workspace copies remain
        available. No Beta header is required.
      parameters:
      - description: Source file ID
        in: path
        name: file_id
        required: true
        type: string
      produces:
      - application/json
      responses:
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Download source file bytes
      tags:
      - Files
  /skills:
    get:
      description: Lists tenant-owned metadata in timestamp order. Default page size
        20, maximum 100. Limit 0 returns an empty page whose has_more reports whether
        any Skill follows the cursor; exact hosted defaults remain unverified.
      parameters:
      - description: Skill resource cursor
        in: query
        name: after
        type: string
      - default: 20
        description: Page size; 0 returns an empty page
        in: query
        maximum: 100
        minimum: 0
        name: limit
        type: integer
      - description: Creation order; omit for descending, explicit empty values are
          invalid
        enum:
        - asc
        - desc
        in: query
        name: order
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SkillList'
      security:
      - BearerAuth: []
      summary: List Skills
      tags:
      - Skills
    post:
      consumes:
      - multipart/form-data
      description: Accepts one ZIP in files or a directory in files[]. Applies the
        qualified portable Skill bundle profile. No Beta header is required; full
        hosted upload limits and activation extensions are not qualified.
      parameters:
      - description: Skill ZIP or directory files
        in: formData
        name: files
        required: true
        type: file
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.Skill'
      security:
      - BearerAuth: []
      summary: Upload a Skill
      tags:
      - Skills
  /skills/{skill_id}:
    delete:
      description: Deletes tenant-owned source bundles. Existing Session installation
        snapshots remain independent.
      parameters:
      - description: Skill ID
        in: path
        name: skill_id
        required: true
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SkillDeleted'
      security:
      - BearerAuth: []
      summary: Delete a Skill and its versions
      tags:
      - Skills
    get:
      description: Returns tenant-owned metadata without decrypting contents or starting
        Runtime. No Beta header is required.
      parameters:
      - description: Skill ID
        in: path
        name: skill_id
        required: true
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.Skill'
      security:
      - BearerAuth: []
      summary: Retrieve Skill metadata
      tags:
      - Skills
    post:
      consumes:
      - application/json
      description: Changes only the tenant-owned default pointer; immutable versions
        and existing Session snapshots remain unchanged.
      parameters:
      - description: Skill ID
        in: path
        name: skill_id
        required: true
        type: string
      - description: Default version
        in: body
        name: body
        required: true
        schema:
          $ref: '#/definitions/v1.SkillUpdateRequest'
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.Skill'
      security:
      - BearerAuth: []
      summary: Update the default Skill version
      tags:
      - Skills
  /skills/{skill_id}/content:
    get:
      description: Downloads an authorized ZIP using the default pointer when no concrete
        version is supplied. Exact upstream unversioned selection, content headers
        and range semantics remain unverified.
      parameters:
      - description: Skill ID
        in: path
        name: skill_id
        required: true
        type: string
      produces:
      - application/octet-stream
      responses:
        "200":
          description: OK
          schema:
            type: file
      security:
      - BearerAuth: []
      summary: Download Skill content
      tags:
      - Skills
  /skills/{skill_id}/versions:
    get:
      description: Orders by version number; after identifies a version resource,
        not a version number. An after value that does not begin with skillver, or
        a version of another Skill, returns 400 invalid_value with param after; a
        missing version returns not found. No contents are decrypted. Limit 0 returns
        an empty page whose has_more reports whether any version follows the cursor.
      parameters:
      - description: Skill ID
        in: path
        name: skill_id
        required: true
        type: string
      - description: Version resource cursor
        in: query
        name: after
        type: string
      - default: 20
        description: Page size; 0 returns an empty page
        in: query
        maximum: 100
        minimum: 0
        name: limit
        type: integer
      - description: Version order; omit for descending, explicit empty values are
          invalid
        enum:
        - asc
        - desc
        in: query
        name: order
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SkillVersionList'
      security:
      - BearerAuth: []
      summary: List Skill versions
      tags:
      - Skills
    post:
      consumes:
      - multipart/form-data
      parameters:
      - description: Skill ID
        in: path
        name: skill_id
        required: true
        type: string
      - description: Skill ZIP or directory files
        in: formData
        name: files
        required: true
        type: file
      - description: Set as default
        in: formData
        name: default
        type: boolean
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SkillVersion'
      security:
      - BearerAuth: []
      summary: Upload an immutable Skill version
      tags:
      - Skills
  /skills/{skill_id}/versions/{version}:
    delete:
      description: Deleting the only remaining version also deletes the Skill; existing
        Session installation snapshots remain independent. The default version cannot
        be deleted while other versions remain. Version numbers are never reused.
      parameters:
      - description: Skill ID
        in: path
        name: skill_id
        required: true
        type: string
      - description: Concrete version number
        in: path
        name: version
        required: true
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SkillVersionDeleted'
      security:
      - BearerAuth: []
      summary: Delete a Skill version
      tags:
      - Skills
    get:
      parameters:
      - description: Skill ID
        in: path
        name: skill_id
        required: true
        type: string
      - description: Concrete version number
        in: path
        name: version
        required: true
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.SkillVersion'
      security:
      - BearerAuth: []
      summary: Retrieve Skill version metadata
      tags:
      - Skills
  /skills/{skill_id}/versions/{version}/content:
    get:
      parameters:
      - description: Skill ID
        in: path
        name: skill_id
        required: true
        type: string
      - description: Concrete version number
        in: path
        name: version
        required: true
        type: string
      produces:
      - application/octet-stream
      responses:
        "200":
          description: OK
          schema:
            type: file
      security:
      - BearerAuth: []
      summary: Download immutable Skill version content
      tags:
      - Skills
  /vaults:
    get:
      description: Lists project-owned Vaults independently of execution. An unknown,
        malformed or foreign after cursor returns not found. Includes active and archived
        records by default. Status accepts a scalar, the SDK's status[] array or both,
        filtering by their union; a repeated scalar is rejected. Limits default to
        20 and clamp to 1–100. Equal creation times use ID ordering; exact hosted
        errors and concurrent-page behavior remain unverified. Archive/delete lifecycle
        is not implemented.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Last Vault ID from the previous page
        in: query
        name: after
        type: string
      - default: 20
        description: Requested page size, clamped to 1–100
        in: query
        name: limit
        type: integer
      - default: desc
        description: Creation order; omit for descending, explicit empty values are
          invalid
        enum:
        - asc
        - desc
        in: query
        name: order
        type: string
      - description: Scalar status filter
        enum:
        - active
        - archived
        in: query
        name: status
        type: string
      - collectionFormat: multi
        description: Array status filter; combined with status as a union
        in: query
        items:
          enum:
          - active
          - archived
          type: string
        name: status[]
        type: array
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.VaultList'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: List Vaults
      tags:
      - Vaults
    post:
      consumes:
      - application/json
      description: Creates a project-owned Vault independently of execution. Omitted
        name stays null; a supplied string is trimmed and must contain 1–256 UTF-8
        bytes. Explicit null name is invalid. Omitted/null metadata becomes an empty
        object; non-string values return invalid_request_error with a metadata.<key>
        param. Metadata has a local 64 KiB encoded storage bound. U+0000 in stored
        strings is rejected as a local storage limit. Credentials, Session binding
        and hosted error/retry parity remain incomplete.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Vault name and metadata
        in: body
        name: body
        required: true
        schema:
          $ref: '#/definitions/v1.CreateVaultRequest'
      produces:
      - application/json
      responses:
        "201":
          description: Created
          schema:
            $ref: '#/definitions/v1.Vault'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "413":
          description: Request Entity Too Large
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Create a Vault
      tags:
      - Vaults
  /vaults/{vault_id}:
    delete:
      description: Atomically removes the authenticated project's Vault and all its
        stored Credentials without an encryption key, decryption or external requests.
        Existing Session snapshots, history and recorded retries retain their frozen
        identities; subsequent credential lookups fail without reselection or anonymous
        fallback. Already-resolved tokens and running Sessions are not revoked or
        cancelled. Missing/repeated deletion locally returns 404. Exact hosted archive,
        post-delete visibility and concurrent/error semantics remain unverified; physical
        erasure from native history, WAL or backups is not established.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Vault ID
        in: path
        name: vault_id
        required: true
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.VaultDeleted'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "413":
          description: Request Entity Too Large
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Delete a Vault and all its Credentials
      tags:
      - Vaults
    get:
      description: Reads a Vault owned by the authenticated project without resolving
        credentials, Sessions or execution devices. Missing and foreign IDs share
        the same not-found response; exact hosted error semantics remain unverified.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Vault ID
        in: path
        name: vault_id
        required: true
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.Vault'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Retrieve a Vault
      tags:
      - Vaults
  /vaults/{vault_id}/credentials:
    get:
      description: Lists only metadata from the authenticated project's requested
        Vault, without decryption or execution. An unknown, malformed or foreign after
        cursor, including another Vault's Credential, returns not found. Includes
        active and archived Credentials by default, independently of Vault status.
        Status accepts a scalar, the SDK status[] array or both, filtering by their
        union; a repeated scalar is rejected. Limits default to 20 and clamp to 1–100.
        Equal creation times use ID ordering. Hosted errors, concurrent-page behavior
        and archive/delete lifecycle remain unverified or unimplemented.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Vault ID
        in: path
        name: vault_id
        required: true
        type: string
      - description: Last Credential ID from the previous page
        in: query
        name: after
        type: string
      - default: 20
        description: Requested page size, clamped to 1–100
        in: query
        name: limit
        type: integer
      - default: desc
        description: Creation order; omit for descending, explicit empty values are
          invalid
        enum:
        - asc
        - desc
        in: query
        name: order
        type: string
      - description: Scalar status filter
        enum:
        - active
        - archived
        in: query
        name: status
        type: string
      - collectionFormat: multi
        description: Array status filter; combined with status as a union
        in: query
        items:
          enum:
          - active
          - archived
          type: string
        name: status[]
        type: array
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.CredentialList'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: List safe Vault Credential metadata
      tags:
      - Credentials
    post:
      consumes:
      - application/json
      description: Stores static_bearer or mcp_oauth secrets as execution-owned authenticated
        ciphertext without contacting any endpoint. Static bearer and OAuth access
        tokens must be nonempty strings; their bytes are preserved. OAuth accepts
        a required access token, nullable RFC3339 expiry and optional refresh configuration
        with none, client_secret_basic or client_secret_post authentication. Required
        name is trimmed to 1–256 UTF-8 bytes. Credential and token endpoints require
        HTTPS without userinfo or fragments. Responses contain safe metadata only,
        including explicit nullable OAuth expiry, refresh, resource and scope. Missing
        encryption configuration returns local 503. External authorization and provider
        revocation remain caller responsibilities; exact hosted error/default semantics
        remain unverified.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Vault ID
        in: path
        name: vault_id
        required: true
        type: string
      - description: Write-only credential authentication union
        in: body
        name: body
        required: true
        schema:
          $ref: '#/definitions/v1.CreateCredentialRequest'
      produces:
      - application/json
      responses:
        "201":
          description: Created
          schema:
            $ref: '#/definitions/v1.Credential'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "413":
          description: Request Entity Too Large
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Create a Vault Credential
      tags:
      - Credentials
  /vaults/{vault_id}/credentials/{credential_id}:
    delete:
      description: Removes one Credential and its encrypted token within the authenticated
        project and owning Vault, without an encryption key or secret decryption.
        Subsequent metadata reads, updates and dispatch lookups cannot use it. Existing
        Session snapshots and history retain their frozen identities; already-resolved
        tokens and running Sessions are not revoked or cancelled. This local policy
        removes the row rather than defining archived lifecycle; missing/repeated
        deletion returns 404. Exact hosted archive, post-delete visibility and retry/error
        semantics remain unverified. Provider revocation and physical erasure from
        native history, WAL or backups are separate concerns.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Vault ID
        in: path
        name: vault_id
        required: true
        type: string
      - description: Credential ID
        in: path
        name: credential_id
        required: true
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.CredentialDeleted'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "413":
          description: Request Entity Too Large
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Delete a Vault Credential
      tags:
      - Credentials
    get:
      description: Reads only non-secret metadata scoped to the authenticated project
        and owning Vault. No token decryption, network request or execution is performed.
        Unknown, foreign, wrong-Vault and malformed IDs use the same local not-found
        response; hosted error parity remains unverified.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Vault ID
        in: path
        name: vault_id
        required: true
        type: string
      - description: Credential ID
        in: path
        name: credential_id
        required: true
        type: string
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.Credential'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Retrieve safe Vault Credential metadata
      tags:
      - Credentials
    post:
      consumes:
      - application/json
      description: Explicitly empty static bearer or OAuth access tokens and OAuth
        patches without a mutable field are rejected before storage. Omitted OAuth
        access tokens preserve the existing grant when expiry or refresh fields change.
        Updates the existing static_bearer or mcp_oauth authentication method without
        network requests. OAuth access_token omission/null retains the token; a new
        token clears omitted expiry, explicit null clears expiry, and other omitted
        fields remain unchanged. OAuth refresh patches cannot add configuration or
        change client, endpoint, resource or authentication method; nullable token/client-secret
        values retain stored secrets while explicit null scope clears scope. Whole-null
        refresh and token_endpoint_auth retain existing configuration under local
        policy. Identity, destination, creation time and Session bindings remain unchanged.
        Responses expose safe metadata only. Already-dispatched work is not revoked;
        provider revocation, storage-key rotation and exact hosted concurrent-update/error
        semantics remain separate.
      parameters:
      - description: agents=v1
        in: header
        name: OpenAI-Beta
        required: true
        type: string
      - description: Vault ID
        in: path
        name: vault_id
        required: true
        type: string
      - description: Credential ID
        in: path
        name: credential_id
        required: true
        type: string
      - description: Write-only credential authentication replacement union
        in: body
        name: body
        required: true
        schema:
          $ref: '#/definitions/v1.UpdateCredentialRequest'
      produces:
      - application/json
      responses:
        "200":
          description: OK
          schema:
            $ref: '#/definitions/v1.Credential'
        "400":
          description: Bad Request
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "401":
          description: Unauthorized
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "404":
          description: Not Found
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "413":
          description: Request Entity Too Large
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "500":
          description: Internal Server Error
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
        "503":
          description: Service Unavailable
          schema:
            $ref: '#/definitions/v1.ErrorResponse'
      security:
      - BearerAuth: []
      summary: Replace Vault Credential authentication secrets
      tags:
      - Credentials
schemes:
- http
- https
securityDefinitions:
  BearerAuth:
    in: header
    name: Authorization
    type: apiKey
swagger: "2.0"
