diff --git a/.repository-projection.json b/.repository-projection.json index 3bbdf68..14d9819 100644 --- a/.repository-projection.json +++ b/.repository-projection.json @@ -3,11 +3,11 @@ "projection": "api", "projectionSchemaVersion": 1, "sourceRepository": "dx-corp/mono", - "sourceSha": "274db22a3ad92a0a22c45c0ecbc770f92c9d053d", + "sourceSha": "a971433d12b40d9042b3a64c2c074fa8fc398e69", "destinationRepository": "dx-corp/api", - "priorProjectedBase": "27c2c4cbcb7929dea8fa943c4de35d28f1e15069", - "definitionDigest": "144b18a5c1f3e7ee6e2d1abc32f80a97adfeacd088911ec659d63622fe85d18c", - "toolDigest": "898e8657d9153a2a51d7c283bf83bb3350b5d1e6", - "contentDigest": "eaa7dad3c2688e4460f1a887419a629eb6c977c81a199cab9151ee636a791ac9", + "priorProjectedBase": "a1200fef3c954a811302e7e2e4edc5ba69d86358", + "definitionDigest": "706ab7174008f35b60af88a5efbfbd24e83d57686a5a3e6cd49243d205cb4344", + "toolDigest": "ff02edcbb40b0028af10ab01a101e918341f157a", + "contentDigest": "c208c05b6098096d7609fa40fa7a54ea122b054e5b030cd14f5840194fcdc647", "publicationEligible": true } diff --git a/README.md b/README.md index 7148994..15e72c3 100644 --- a/README.md +++ b/README.md @@ -5,25 +5,42 @@ generated OpenAPI descriptions used by the Deixic SDK. The authoritative source remains `dx-corp/mono`; `.repository-projection.json` records the exact source revision used for each projection. -`deixic.v1.DeixicService` is the supported SDK facade. Its eight supported -operations and their mutation requirements are recorded in -`contracts/public-surface.json`. The additional packages in `proto/` are the -transitive message and service dependencies required to compile that facade. +`deixicpublic.v1.DeixicPublicService` is the supported public application +contract. The task SDK's eight supported operations and mutation requirements +are recorded in `contracts/public-surface.json`. The same protocol also serves +the Code client's readiness, setup, and issue-report calls and the Terraform +provider's business-object CRUD resource. The protocol imports only the Protobuf +well-known `Timestamp` type. Internal service definitions are absent from this +repository and cannot be imported into the public contract. + +## Compatibility and promotion + +The `v1` package is a durable external API. Existing field numbers, names, +types, enum values, service methods, and observable behavior remain stable. +New optional fields and methods may be added after their public meaning is +documented. Removed fields and enum values must reserve both their numbers and +names; incompatible changes require a new versioned package. The source repo +runs Buf breaking checks against the published public module. + +Promoting an internal concept requires a public use case, an explicit public +message with no internal imports or `Any` escape hatch, a server-side +projection, language client compatibility checks, and an audit of every built +artifact's complete descriptor and schema closure. Similar field layouts do +not justify sharing an internal message. The customer checkpoint format +`deixic.task.v1` is versioned separately from this wire protocol. The checked-in OpenAPI documents are generated artifacts. To regenerate them with the pinned public plugin: ```sh -buf dep update buf lint buf generate python3 scripts/contracts/normalize-openapi-generated.py openapi node scripts/distribution-validation.mjs --name api --target . ``` -`buf dep update`, generation, and validation access the Buf Schema Registry for -the locked dependencies and pinned plugin. They do not contact a Deixic -service. The normalization step preserves OpenAPI 3.1 semantics for protobuf +Generation accesses the Buf Schema Registry for the pinned plugin. It does not +contact a Deixic service. The normalization step preserves OpenAPI 3.1 semantics for protobuf oneofs, enum constraints, repeated fields, and bytes validation. This contract repository does not publish SDK packages or grant access to a diff --git a/buf.lock b/buf.lock deleted file mode 100644 index 05035e2..0000000 --- a/buf.lock +++ /dev/null @@ -1,9 +0,0 @@ -# Generated by buf. DO NOT EDIT. -version: v2 -deps: - - name: buf.build/bufbuild/protovalidate - commit: 50325440f8f24053b047484a6bf60b76 - digest: b5:74cb6f5c0853c3c10aafc701614194bbd63326bdb8ef4068214454b8894b03ba4113e04b3a33a8321cdf05336e37db4dc14a5e2495db8462566914f36086ba31 - - name: buf.build/googleapis/googleapis - commit: c17df5b2beca46928cc87d5656bd5343 - digest: b5:648a01e0170d4512dea7d564016165decd1ed6e34bef79fe54753e51ad7e27545709ad9157d7551270147d551155c595a2fb0bf5bb33b1c83040ddbce915c604 diff --git a/buf.yaml b/buf.yaml index cec2e7d..95c2f2f 100644 --- a/buf.yaml +++ b/buf.yaml @@ -1,23 +1,9 @@ version: v2 modules: - path: proto -deps: - - buf.build/bufbuild/protovalidate - - buf.build/googleapis/googleapis lint: use: - STANDARD - except: - - PACKAGE_VERSION_SUFFIX - ignore_only: - RPC_REQUEST_RESPONSE_UNIQUE: - - proto/console/v1/console.proto - - proto/deixic/v1/deixic.proto - RPC_RESPONSE_STANDARD_NAME: - - proto/console/v1/console.proto - - proto/deixic/v1/deixic.proto - RPC_REQUEST_STANDARD_NAME: - - proto/deixic/v1/deixic.proto breaking: use: - WIRE_JSON diff --git a/contracts/public-surface.json b/contracts/public-surface.json index 6b163db..fc0a88b 100644 --- a/contracts/public-surface.json +++ b/contracts/public-surface.json @@ -1,9 +1,10 @@ { "schemaVersion": 1, - "service": "deixic.v1.DeixicService", + "service": "deixicpublic.v1.DeixicPublicService", "packages": { "typescript": "@evalops/deixic-sdk", - "python": "deixic-sdk" + "python": "deixic-sdk", + "go": "github.com/dx-corp/deixic-go" }, "scope": { "constructorBound": true, @@ -20,47 +21,47 @@ }, "operations": [ { - "rpc": "GetOperatingThread", + "rpc": "GetThread", "facade": "threads.get", "kind": "query" }, { - "rpc": "ListOperatingThreadEvents", + "rpc": "ListEvents", "facade": "events.list", "kind": "query" }, { - "rpc": "WatchOperatingThread", + "rpc": "WatchEvents", "facade": "events.watch", "kind": "server-stream", "callerOwnsReconnect": true }, { - "rpc": "SubmitOperatingMessage", + "rpc": "SubmitTask", "facade": "messages.send", "kind": "mutation", "requiresIdempotencyKey": true, "acceptedIsTerminal": false }, { - "rpc": "InterruptOperatingThread", + "rpc": "InterruptTask", "facade": "controls.interrupt", "kind": "mutation", "requiresIdempotencyKey": true }, { - "rpc": "RespondOperatingThread", + "rpc": "RespondToRequest", "facade": "controls.respond", "kind": "mutation", "requiresIdempotencyKey": true }, { - "rpc": "GetOperatingReceipt", + "rpc": "GetReceipt", "facade": "receipts.get", "kind": "query" }, { - "rpc": "ResolveOperatingReceiptAction", + "rpc": "ResolveReceiptAction", "facade": "receipts.resolve", "kind": "mutation", "requiresIdempotencyKey": true diff --git a/docs/deixic-sdk.md b/docs/deixic-sdk.md index c4c2dc7..96cb47f 100644 --- a/docs/deixic-sdk.md +++ b/docs/deixic-sdk.md @@ -4,7 +4,8 @@ Use the Deixic SDK when an application needs to submit a task, follow its durable progress, interrupt it, answer a tool request, or approve or deny a requested action. -The supported clients expose eight operations from the Deixic service. They do +The supported clients expose eight operations from +`deixicpublic.v1.DeixicPublicService`. They do not expose the browser API or create a second execution path. Deixic remains the owner of task state, approvals, and action history. @@ -41,7 +42,7 @@ environment. subject, tenant, and declared scopes. The checked package contract is -[`sdk/deixic/public-surface.json`](../sdk/deixic/public-surface.json). Package -examples and error details live in the -[TypeScript README](../sdk/deixic/typescript/README.md) and -[Python README](../sdk/deixic/python/README.md). +[public-surface.json](https://github.com/dx-corp/api/blob/main/contracts/public-surface.json). +Package examples and error details live in the +[TypeScript SDK](https://github.com/dx-corp/deixic-node/blob/main/README.md) and +[Python SDK](https://github.com/dx-corp/deixic-python/blob/main/README.md). diff --git a/openapi/agentruntime/v1/runtime.openapi.yaml b/openapi/agentruntime/v1/runtime.openapi.yaml deleted file mode 100644 index 1842a9c..0000000 --- a/openapi/agentruntime/v1/runtime.openapi.yaml +++ /dev/null @@ -1,10686 +0,0 @@ -openapi: 3.1.0 -info: - title: agentruntime.v1 -paths: - /agentruntime.v1.AgentRuntimeService/HandleTrigger: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: HandleTrigger - description: |- - HandleTrigger receives a normalized product or integration trigger, - resolves agent/objective context, records an AgentRun, and dispatches it. - operationId: agentruntime.v1.AgentRuntimeService.HandleTrigger - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.HandleTriggerRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.HandleTriggerResponse' - /agentruntime.v1.AgentRuntimeService/AdmitOperatingChannelEvent: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: AdmitOperatingChannelEvent - description: |- - AdmitOperatingChannelEvent accepts provider-issued coordinates from a - channel edge that cannot know tenant ownership. Platform resolves the - installation and external actor before durably admitting the event. - operationId: agentruntime.v1.AgentRuntimeService.AdmitOperatingChannelEvent - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.AdmitOperatingChannelEventRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.AdmitOperatingChannelEventResponse' - /agentruntime.v1.AgentRuntimeService/AdmitSurfaceInvocation: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: AdmitSurfaceInvocation - description: |- - AdmitSurfaceInvocation accepts a provider-neutral invocation from a - verified surface adapter. Platform resolves installation ownership and - the external actor before binding the provider object to an operating - thread and durably admitting work. - operationId: agentruntime.v1.AgentRuntimeService.AdmitSurfaceInvocation - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.AdmitSurfaceInvocationRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.AdmitSurfaceInvocationResponse' - /agentruntime.v1.AgentRuntimeService/EnsureOrganizationEmail: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: EnsureOrganizationEmail - description: |- - Identity reconciles one approved organization and its active default workspace. - Caller scope is service-only; this request cannot select provider credentials. - operationId: agentruntime.v1.AgentRuntimeService.EnsureOrganizationEmail - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.EnsureOrganizationEmailRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.EnsureOrganizationEmailResponse' - /agentruntime.v1.AgentRuntimeService/ClaimNextRun: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: ClaimNextRun - description: |- - ClaimNextRun atomically leases the next queued or retry-ready run for a - worker. A claim transitions the run to RUNNING and increments attempt. - operationId: agentruntime.v1.AgentRuntimeService.ClaimNextRun - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.ClaimNextRunRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.ClaimNextRunResponse' - /agentruntime.v1.AgentRuntimeService/HeartbeatRun: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: HeartbeatRun - description: |- - HeartbeatRun extends an active worker lease. Expired leases are eligible - to be reclaimed by another worker from the last checkpoint. - operationId: agentruntime.v1.AgentRuntimeService.HeartbeatRun - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.HeartbeatRunRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.HeartbeatRunResponse' - /agentruntime.v1.AgentRuntimeService/RenewRunLease: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: RenewRunLease - description: |- - RenewRunLease recovers a still-owned worker lease after it has expired but - before the run has been parked, completed, or otherwise taken over. - operationId: agentruntime.v1.AgentRuntimeService.RenewRunLease - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.RenewRunLeaseRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.RenewRunLeaseResponse' - /agentruntime.v1.AgentRuntimeService/RecordRunStep: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: RecordRunStep - description: RecordRunStep upserts the durable record for one execution step. - operationId: agentruntime.v1.AgentRuntimeService.RecordRunStep - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.RecordRunStepRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.RecordRunStepResponse' - /agentruntime.v1.AgentRuntimeService/RecordRunCheckpoint: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: RecordRunCheckpoint - description: |- - RecordRunCheckpoint stores an opaque resume snapshot. Checkpoints are the - source of truth for resuming work; deterministic replay is not required. - operationId: agentruntime.v1.AgentRuntimeService.RecordRunCheckpoint - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.RecordRunCheckpointRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.RecordRunCheckpointResponse' - /agentruntime.v1.AgentRuntimeService/RecordRunArtifact: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: RecordRunArtifact - description: RecordRunArtifact links a produced artifact to the run and optional step. - operationId: agentruntime.v1.AgentRuntimeService.RecordRunArtifact - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.RecordRunArtifactRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.RecordRunArtifactResponse' - /agentruntime.v1.AgentRuntimeService/RecordRunCost: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: RecordRunCost - description: RecordRunCost links metering/cost data to the run and optional step. - operationId: agentruntime.v1.AgentRuntimeService.RecordRunCost - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.RecordRunCostRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.RecordRunCostResponse' - /agentruntime.v1.AgentRuntimeService/RecordRunStreamCursor: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: RecordRunStreamCursor - description: RecordRunStreamCursor stores a consumer cursor into the run event stream. - operationId: agentruntime.v1.AgentRuntimeService.RecordRunStreamCursor - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.RecordRunStreamCursorRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.RecordRunStreamCursorResponse' - /agentruntime.v1.AgentRuntimeService/RecordRunEvent: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: RecordRunEvent - description: |- - RecordRunEvent appends an adapter-observed lifecycle event to an existing - AgentRun without requiring a worker lease. Channel adapters use this to - attach Slack/Teams/email delivery, approval, model, and tool milestones - while Platform remains the durable source of truth for the run timeline. - operationId: agentruntime.v1.AgentRuntimeService.RecordRunEvent - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.RecordRunEventRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.RecordRunEventResponse' - /agentruntime.v1.AgentRuntimeService/ControlRun: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: ControlRun - description: |- - ControlRun records a human, channel, scheduler, or system control against - the active autonomous run/session. Controls are durable steering input; the - Slack adapter is not responsible for keeping the agent alive turn by turn. - operationId: agentruntime.v1.AgentRuntimeService.ControlRun - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.ControlRunRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.ControlRunResponse' - /agentruntime.v1.AgentRuntimeService/RecordRunWorkItem: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: RecordRunWorkItem - description: |- - RecordRunWorkItem creates or replaces one node in the autonomous work graph. - Work items, not VFS projections, are the canonical state for long-horizon - goals, child runs, waits, tool activity, blockers, and completion gates. - operationId: agentruntime.v1.AgentRuntimeService.RecordRunWorkItem - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.RecordRunWorkItemRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.RecordRunWorkItemResponse' - /agentruntime.v1.AgentRuntimeService/UpdateRunWorkItem: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: UpdateRunWorkItem - description: UpdateRunWorkItem patches progress for one autonomous work graph node. - operationId: agentruntime.v1.AgentRuntimeService.UpdateRunWorkItem - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.UpdateRunWorkItemRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.UpdateRunWorkItemResponse' - /agentruntime.v1.AgentRuntimeService/ListRunWorkItems: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: ListRunWorkItems - description: ListRunWorkItems returns the typed work graph for one run or work envelope. - operationId: agentruntime.v1.AgentRuntimeService.ListRunWorkItems - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.ListRunWorkItemsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.ListRunWorkItemsResponse' - /agentruntime.v1.AgentRuntimeService/YieldRun: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: YieldRun - description: |- - YieldRun ends the current leased run step while keeping the autonomous - session alive. Inline yields enqueue a successor AgentRun immediately; - end-session yields close the run without enqueueing more autonomous work. - Timer, approval, input, and event blocking use WaitRun/ResumeRun. - operationId: agentruntime.v1.AgentRuntimeService.YieldRun - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.YieldRunRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.YieldRunResponse' - /agentruntime.v1.AgentRuntimeService/WaitRun: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: WaitRun - description: |- - WaitRun parks the run on an approval, input, timer, or event wait and - clears the worker lease so no compute is held while blocked. - operationId: agentruntime.v1.AgentRuntimeService.WaitRun - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.WaitRunRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.WaitRunResponse' - /agentruntime.v1.AgentRuntimeService/ResumeRun: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: ResumeRun - description: ResumeRun resolves a wait and requeues the run from its latest checkpoint. - operationId: agentruntime.v1.AgentRuntimeService.ResumeRun - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.ResumeRunRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.ResumeRunResponse' - /agentruntime.v1.AgentRuntimeService/CompleteRun: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: CompleteRun - description: CompleteRun marks the run successful and releases any active lease. - operationId: agentruntime.v1.AgentRuntimeService.CompleteRun - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.CompleteRunRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.CompleteRunResponse' - /agentruntime.v1.AgentRuntimeService/FailRun: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: FailRun - description: |- - FailRun records a failed attempt. Retryable failures can move to RETRYING; - exhausted attempts stay FAILED until they are moved to the dead letter set. - operationId: agentruntime.v1.AgentRuntimeService.FailRun - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.FailRunRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.FailRunResponse' - /agentruntime.v1.AgentRuntimeService/CancelRun: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: CancelRun - description: CancelRun cancels a run before it reaches a terminal success/failure. - operationId: agentruntime.v1.AgentRuntimeService.CancelRun - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.CancelRunRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.CancelRunResponse' - /agentruntime.v1.AgentRuntimeService/RetryRun: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: RetryRun - description: RetryRun explicitly schedules a failed run for another attempt. - operationId: agentruntime.v1.AgentRuntimeService.RetryRun - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.RetryRunRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.RetryRunResponse' - /agentruntime.v1.AgentRuntimeService/DeadLetterRun: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: DeadLetterRun - description: DeadLetterRun moves an exhausted or poison run out of normal scheduling. - operationId: agentruntime.v1.AgentRuntimeService.DeadLetterRun - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.DeadLetterRunRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.DeadLetterRunResponse' - /agentruntime.v1.AgentRuntimeService/GetRun: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: GetRun - description: GetRun retrieves an AgentRun by ID. - operationId: agentruntime.v1.AgentRuntimeService.GetRun - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.GetRunRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.GetRunResponse' - /agentruntime.v1.AgentRuntimeService/GetTeammateWorkLedger: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: GetTeammateWorkLedger - description: |- - GetTeammateWorkLedger retrieves the durable teammate work projection for - one run. It joins run state, waits, memory citations, connector grants, - VFS state, proactive policy, and channel-visible status into the compact - read model workers and operator consoles use for long-horizon handoff. - operationId: agentruntime.v1.AgentRuntimeService.GetTeammateWorkLedger - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.GetTeammateWorkLedgerRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.GetTeammateWorkLedgerResponse' - /agentruntime.v1.AgentRuntimeService/ListRunsByWorkEnvelope: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: ListRunsByWorkEnvelope - description: |- - ListRunsByWorkEnvelope retrieves newest runs that belong to one durable - channel work envelope, such as a Slack thread or future email/Jira/Teams object. - operationId: agentruntime.v1.AgentRuntimeService.ListRunsByWorkEnvelope - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.ListRunsByWorkEnvelopeRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.ListRunsByWorkEnvelopeResponse' - /agentruntime.v1.AgentRuntimeService/GetChannelThreadAdoption: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: GetChannelThreadAdoption - description: |- - GetChannelThreadAdoption resolves whether a channel thread has been - explicitly adopted by an agent and can receive no-mention continuations. - operationId: agentruntime.v1.AgentRuntimeService.GetChannelThreadAdoption - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.GetChannelThreadAdoptionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.GetChannelThreadAdoptionResponse' - /agentruntime.v1.AgentRuntimeService/RecordChannelThreadAdoption: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: RecordChannelThreadAdoption - description: |- - RecordChannelThreadAdoption durably records an adapter-observed channel - thread adoption without requiring the adapter to create a new AgentRun. - operationId: agentruntime.v1.AgentRuntimeService.RecordChannelThreadAdoption - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.RecordChannelThreadAdoptionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.RecordChannelThreadAdoptionResponse' - /agentruntime.v1.AgentRuntimeService/ListChannelThreadAdoptions: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: ListChannelThreadAdoptions - description: |- - ListChannelThreadAdoptions returns the durable adoption projection for - operator/debug surfaces and channel-adapter reconciliation. - operationId: agentruntime.v1.AgentRuntimeService.ListChannelThreadAdoptions - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.ListChannelThreadAdoptionsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.ListChannelThreadAdoptionsResponse' - /agentruntime.v1.AgentRuntimeService/ListRunWaits: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: ListRunWaits - description: |- - ListRunWaits returns a pending-work projection over parked AgentRun waits - without requiring clients to replay runtime events or read full run - snapshots. - operationId: agentruntime.v1.AgentRuntimeService.ListRunWaits - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.ListRunWaitsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.ListRunWaitsResponse' - /agentruntime.v1.AgentRuntimeService/RecordChannelActionReceipt: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: RecordChannelActionReceipt - description: |- - RecordChannelActionReceipt durably records an interactive channel action, - such as a Slack approval button or slash command, before any side effects - resume runtime work. - operationId: agentruntime.v1.AgentRuntimeService.RecordChannelActionReceipt - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.RecordChannelActionReceiptRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.RecordChannelActionReceiptResponse' - /agentruntime.v1.AgentRuntimeService/GetChannelActionReceipt: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: GetChannelActionReceipt - description: GetChannelActionReceipt retrieves one recorded channel action receipt. - operationId: agentruntime.v1.AgentRuntimeService.GetChannelActionReceipt - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.GetChannelActionReceiptRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.GetChannelActionReceiptResponse' - /agentruntime.v1.AgentRuntimeService/ListChannelActionReceipts: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: ListChannelActionReceipts - description: |- - ListChannelActionReceipts returns durable channel action receipts for - audit, idempotency, and channel adapter reconciliation. - operationId: agentruntime.v1.AgentRuntimeService.ListChannelActionReceipts - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.ListChannelActionReceiptsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.ListChannelActionReceiptsResponse' - /agentruntime.v1.AgentRuntimeService/ListRunEvents: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: ListRunEvents - description: ListRunEvents returns the append-only event log for an AgentRun. - operationId: agentruntime.v1.AgentRuntimeService.ListRunEvents - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.ListRunEventsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.ListRunEventsResponse' - /agentruntime.v1.AgentRuntimeService/ListRunVirtualFiles: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: ListRunVirtualFiles - description: |- - ListRunVirtualFiles lists the durable read model of a run's virtual - filesystem, including context files and agent-authored proposal files. - operationId: agentruntime.v1.AgentRuntimeService.ListRunVirtualFiles - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.ListRunVirtualFilesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.ListRunVirtualFilesResponse' - /agentruntime.v1.AgentRuntimeService/ReadRunVirtualFile: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: ReadRunVirtualFile - description: |- - ReadRunVirtualFile reads a bounded slice of one run virtual file. Workers - should use this instead of loading every virtual file into model context. - operationId: agentruntime.v1.AgentRuntimeService.ReadRunVirtualFile - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.ReadRunVirtualFileRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.ReadRunVirtualFileResponse' - /agentruntime.v1.AgentRuntimeService/StatRunVirtualFile: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: StatRunVirtualFile - description: |- - StatRunVirtualFile returns the typed, content-free VFS projection for one - run virtual file by path. - operationId: agentruntime.v1.AgentRuntimeService.StatRunVirtualFile - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.StatRunVirtualFileRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.StatRunVirtualFileResponse' - /agentruntime.v1.AgentRuntimeService/WatchRunVirtualFiles: {} - /agentruntime.v1.AgentRuntimeService/BatchReadRunVirtualFiles: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: BatchReadRunVirtualFiles - description: |- - BatchReadRunVirtualFiles reads multiple bounded VFS slices in one request - while making per-file and total-budget truncation explicit. - operationId: agentruntime.v1.AgentRuntimeService.BatchReadRunVirtualFiles - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.BatchReadRunVirtualFilesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.BatchReadRunVirtualFilesResponse' - /agentruntime.v1.AgentRuntimeService/BuildRunVirtualFileContextPack: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: BuildRunVirtualFileContextPack - description: |- - BuildRunVirtualFileContextPack returns an ordered, cited set of VFS - snippets for a task or query so workers can hydrate model context without - hand-rolling list/search/read loops. - operationId: agentruntime.v1.AgentRuntimeService.BuildRunVirtualFileContextPack - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.BuildRunVirtualFileContextPackRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.BuildRunVirtualFileContextPackResponse' - /agentruntime.v1.AgentRuntimeService/SearchRunVirtualFiles: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: SearchRunVirtualFiles - description: |- - SearchRunVirtualFiles performs bounded literal or regex search over text - virtual files projected for an AgentRun. - operationId: agentruntime.v1.AgentRuntimeService.SearchRunVirtualFiles - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.SearchRunVirtualFilesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.SearchRunVirtualFilesResponse' - /agentruntime.v1.AgentRuntimeService/RecordRunVirtualFileProposal: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: RecordRunVirtualFileProposal - description: |- - RecordRunVirtualFileProposal writes an agent-authored file into the - proposal/workspace side of the VFS. Source mounts such as /context remain - read-only; promotion to real side effects happens through reviewers or - downstream services. - operationId: agentruntime.v1.AgentRuntimeService.RecordRunVirtualFileProposal - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.RecordRunVirtualFileProposalRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.RecordRunVirtualFileProposalResponse' - /agentruntime.v1.AgentRuntimeService/RecordRunVirtualFileTransaction: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: RecordRunVirtualFileTransaction - description: |- - RecordRunVirtualFileTransaction atomically stages a multi-file VFS change - set as durable proposal artifacts with shared revision and review metadata. - operationId: agentruntime.v1.AgentRuntimeService.RecordRunVirtualFileTransaction - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.RecordRunVirtualFileTransactionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.RecordRunVirtualFileTransactionResponse' - /agentruntime.v1.AgentRuntimeService/PromoteRunVirtualFileTransaction: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: PromoteRunVirtualFileTransaction - description: |- - PromoteRunVirtualFileTransaction records a reviewed transaction as the - accepted workspace view. Promotion is idempotent by transaction and keeps - proposal artifacts intact for audit. - operationId: agentruntime.v1.AgentRuntimeService.PromoteRunVirtualFileTransaction - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.PromoteRunVirtualFileTransactionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.PromoteRunVirtualFileTransactionResponse' - /agentruntime.v1.AgentRuntimeService/DiffRunVirtualFileTransaction: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: DiffRunVirtualFileTransaction - description: |- - DiffRunVirtualFileTransaction previews a staged VFS transaction as - per-file stats, hunks, conflicts, and unified diff text. - operationId: agentruntime.v1.AgentRuntimeService.DiffRunVirtualFileTransaction - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.DiffRunVirtualFileTransactionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.DiffRunVirtualFileTransactionResponse' - /agentruntime.v1.AgentRuntimeService/ApplyRunVirtualFileTransaction: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: ApplyRunVirtualFileTransaction - description: |- - ApplyRunVirtualFileTransaction applies a transaction when the diff is - clean, and otherwise returns structured conflicts without mutating state. - operationId: agentruntime.v1.AgentRuntimeService.ApplyRunVirtualFileTransaction - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.ApplyRunVirtualFileTransactionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.ApplyRunVirtualFileTransactionResponse' - /agentruntime.v1.AgentRuntimeService/RebaseRunVirtualFileTransaction: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: RebaseRunVirtualFileTransaction - description: |- - RebaseRunVirtualFileTransaction restages a clean transaction on top of the - latest accepted VFS revisions while preserving proposed content metadata. - operationId: agentruntime.v1.AgentRuntimeService.RebaseRunVirtualFileTransaction - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.RebaseRunVirtualFileTransactionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.RebaseRunVirtualFileTransactionResponse' - /agentruntime.v1.AgentRuntimeService/HydrateRunVirtualFileMount: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: HydrateRunVirtualFileMount - description: |- - HydrateRunVirtualFileMount resolves a lazy connector mount into bounded - run-scoped VFS files without exposing credentials to the worker. - operationId: agentruntime.v1.AgentRuntimeService.HydrateRunVirtualFileMount - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.HydrateRunVirtualFileMountRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.HydrateRunVirtualFileMountResponse' - /agentruntime.v1.AgentRuntimeService/InspectRunVirtualFiles: - post: - tags: - - agentruntime.v1.AgentRuntimeService - summary: InspectRunVirtualFiles - description: |- - InspectRunVirtualFiles returns a debug projection over mounts, - transactions, content addresses, and Cerebro indexing readiness. - operationId: agentruntime.v1.AgentRuntimeService.InspectRunVirtualFiles - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.InspectRunVirtualFilesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agentruntime.v1.InspectRunVirtualFilesResponse' -components: - schemas: - agentruntime.v1.AgentRunArtifactKind: - type: string - title: AgentRunArtifactKind - enum: - - AGENT_RUN_ARTIFACT_KIND_UNSPECIFIED - - AGENT_RUN_ARTIFACT_KIND_TOOL_RESULT - - AGENT_RUN_ARTIFACT_KIND_CHART - - AGENT_RUN_ARTIFACT_KIND_REPORT - - AGENT_RUN_ARTIFACT_KIND_FILE - - AGENT_RUN_ARTIFACT_KIND_TRANSCRIPT - - AGENT_RUN_ARTIFACT_KIND_APPROVAL_PLAN - - AGENT_RUN_ARTIFACT_KIND_SYSTEM - - AGENT_RUN_ARTIFACT_KIND_PATCH - - AGENT_RUN_ARTIFACT_KIND_PULL_REQUEST - - AGENT_RUN_ARTIFACT_KIND_PULL_REQUEST_COMMENT - - AGENT_RUN_ARTIFACT_KIND_CI_STATUS - - AGENT_RUN_ARTIFACT_KIND_RUN_PANEL - - AGENT_RUN_ARTIFACT_KIND_EVALUATION_EXAMPLE - description: AgentRunArtifactKind classifies durable output produced by a run or step. - agentruntime.v1.AgentRunState: - type: string - title: AgentRunState - enum: - - AGENT_RUN_STATE_UNSPECIFIED - - AGENT_RUN_STATE_ACCEPTED - - AGENT_RUN_STATE_QUEUED - - AGENT_RUN_STATE_RUNNING - - AGENT_RUN_STATE_WAITING - - AGENT_RUN_STATE_SUCCEEDED - - AGENT_RUN_STATE_FAILED - - AGENT_RUN_STATE_CANCELLED - - AGENT_RUN_STATE_RETRYING - - AGENT_RUN_STATE_DEAD_LETTERED - description: AgentRunState describes the runtime lifecycle of one durable attempt. - agentruntime.v1.AgentRunStepKind: - type: string - title: AgentRunStepKind - enum: - - AGENT_RUN_STEP_KIND_UNSPECIFIED - - AGENT_RUN_STEP_KIND_MODEL_CALL - - AGENT_RUN_STEP_KIND_TOOL_CALL_INTENT - - AGENT_RUN_STEP_KIND_TOOL_RESULT - - AGENT_RUN_STEP_KIND_APPROVAL_WAIT - - AGENT_RUN_STEP_KIND_ERROR - - AGENT_RUN_STEP_KIND_SYSTEM - - AGENT_RUN_STEP_KIND_CONTEXT_ENRICHMENT - - AGENT_RUN_STEP_KIND_PLAN - - AGENT_RUN_STEP_KIND_PATCH - - AGENT_RUN_STEP_KIND_TEST - - AGENT_RUN_STEP_KIND_PULL_REQUEST_SYNC - - AGENT_RUN_STEP_KIND_REVIEW_SYNC - description: AgentRunStepKind classifies the durable work represented by a run step. - agentruntime.v1.AgentRunStepState: - type: string - title: AgentRunStepState - enum: - - AGENT_RUN_STEP_STATE_UNSPECIFIED - - AGENT_RUN_STEP_STATE_PENDING - - AGENT_RUN_STEP_STATE_RUNNING - - AGENT_RUN_STEP_STATE_WAITING - - AGENT_RUN_STEP_STATE_SUCCEEDED - - AGENT_RUN_STEP_STATE_FAILED - - AGENT_RUN_STEP_STATE_CANCELLED - - AGENT_RUN_STEP_STATE_SKIPPED - description: AgentRunStepState describes progress for a single durable step record. - agentruntime.v1.AgentRunWaitState: - type: string - title: AgentRunWaitState - enum: - - AGENT_RUN_WAIT_STATE_UNSPECIFIED - - AGENT_RUN_WAIT_STATE_PENDING - - AGENT_RUN_WAIT_STATE_RESOLVED - - AGENT_RUN_WAIT_STATE_EXPIRED - - AGENT_RUN_WAIT_STATE_CANCELLED - description: AgentRunWaitState describes the read-model state of a parked wait. - agentruntime.v1.AgentRunWaitType: - type: string - title: AgentRunWaitType - enum: - - AGENT_RUN_WAIT_TYPE_UNSPECIFIED - - AGENT_RUN_WAIT_TYPE_APPROVAL - - AGENT_RUN_WAIT_TYPE_INPUT - - AGENT_RUN_WAIT_TYPE_EVENT - - AGENT_RUN_WAIT_TYPE_TIMER - description: AgentRunWaitType describes why a run released its worker lease. - agentruntime.v1.AgentWorkItemKind: - type: string - title: AgentWorkItemKind - enum: - - AGENT_WORK_ITEM_KIND_UNSPECIFIED - - AGENT_WORK_ITEM_KIND_ROOT - - AGENT_WORK_ITEM_KIND_MODEL_CALL - - AGENT_WORK_ITEM_KIND_TOOL_CALL - - AGENT_WORK_ITEM_KIND_CHILD_RUN - - AGENT_WORK_ITEM_KIND_WAIT - - AGENT_WORK_ITEM_KIND_MEMORY - - AGENT_WORK_ITEM_KIND_USER_INPUT - - AGENT_WORK_ITEM_KIND_FOLLOWUP - - AGENT_WORK_ITEM_KIND_RECOVERY - description: AgentWorkItemKind classifies nodes in the autonomous work graph. - agentruntime.v1.AgentWorkItemState: - type: string - title: AgentWorkItemState - enum: - - AGENT_WORK_ITEM_STATE_UNSPECIFIED - - AGENT_WORK_ITEM_STATE_PENDING - - AGENT_WORK_ITEM_STATE_RUNNING - - AGENT_WORK_ITEM_STATE_WAITING - - AGENT_WORK_ITEM_STATE_BLOCKED - - AGENT_WORK_ITEM_STATE_SUCCEEDED - - AGENT_WORK_ITEM_STATE_FAILED - - AGENT_WORK_ITEM_STATE_CANCELLED - description: AgentWorkItemState describes durable progress for a work graph node. - agentruntime.v1.AutonomyProcessingState: - type: string - title: AutonomyProcessingState - enum: - - AUTONOMY_PROCESSING_STATE_UNSPECIFIED - - AUTONOMY_PROCESSING_STATE_QUEUED - - AUTONOMY_PROCESSING_STATE_ORIENTING - - AUTONOMY_PROCESSING_STATE_THINKING - - AUTONOMY_PROCESSING_STATE_USING_TOOL - - AUTONOMY_PROCESSING_STATE_SPAWNING_CHILDREN - - AUTONOMY_PROCESSING_STATE_WAITING_ON_APPROVAL - - AUTONOMY_PROCESSING_STATE_WAITING_ON_EVENT - - AUTONOMY_PROCESSING_STATE_SYNTHESIZING - - AUTONOMY_PROCESSING_STATE_COMPLETING - - AUTONOMY_PROCESSING_STATE_IDLE - - AUTONOMY_PROCESSING_STATE_FAILED - description: |- - AutonomyProcessingState is the channel-safe processing presence for a - long-lived autonomous teammate. Adapters update the same visible Slack - message from this state instead of posting one reply per runtime turn. - agentruntime.v1.AutonomySessionState: - type: string - title: AutonomySessionState - enum: - - AUTONOMY_SESSION_STATE_UNSPECIFIED - - AUTONOMY_SESSION_STATE_ACTIVE - - AUTONOMY_SESSION_STATE_IDLE - - AUTONOMY_SESSION_STATE_WAITING - - AUTONOMY_SESSION_STATE_FAILED - - AUTONOMY_SESSION_STATE_CANCELLED - description: |- - AutonomySessionState is the coarse lifecycle for the long-lived teammate - session attached to a work envelope. - agentruntime.v1.ChannelActionAuthorizationOutcome: - type: string - title: ChannelActionAuthorizationOutcome - enum: - - CHANNEL_ACTION_AUTHORIZATION_OUTCOME_UNSPECIFIED - - CHANNEL_ACTION_AUTHORIZATION_OUTCOME_ALLOWED - - CHANNEL_ACTION_AUTHORIZATION_OUTCOME_DENIED - - CHANNEL_ACTION_AUTHORIZATION_OUTCOME_UNMAPPED_ACTOR - - CHANNEL_ACTION_AUTHORIZATION_OUTCOME_WRONG_APPROVER - - CHANNEL_ACTION_AUTHORIZATION_OUTCOME_EXPIRED - - CHANNEL_ACTION_AUTHORIZATION_OUTCOME_STALE - description: |- - ChannelActionAuthorizationOutcome records the actor-resolution and policy - decision for a channel action. - agentruntime.v1.ChannelActionDeliveryOutcome: - type: string - title: ChannelActionDeliveryOutcome - enum: - - CHANNEL_ACTION_DELIVERY_OUTCOME_UNSPECIFIED - - CHANNEL_ACTION_DELIVERY_OUTCOME_NOT_ATTEMPTED - - CHANNEL_ACTION_DELIVERY_OUTCOME_UPDATED - - CHANNEL_ACTION_DELIVERY_OUTCOME_FAILED - - CHANNEL_ACTION_DELIVERY_OUTCOME_SKIPPED - description: |- - ChannelActionDeliveryOutcome records whether the channel message/update was - reconciled after handling an action. - agentruntime.v1.ChannelActionExecutionOutcome: - type: string - title: ChannelActionExecutionOutcome - enum: - - CHANNEL_ACTION_EXECUTION_OUTCOME_UNSPECIFIED - - CHANNEL_ACTION_EXECUTION_OUTCOME_PENDING - - CHANNEL_ACTION_EXECUTION_OUTCOME_SUCCEEDED - - CHANNEL_ACTION_EXECUTION_OUTCOME_FAILED - - CHANNEL_ACTION_EXECUTION_OUTCOME_DUPLICATE - - CHANNEL_ACTION_EXECUTION_OUTCOME_TARGET_NOT_FOUND - - CHANNEL_ACTION_EXECUTION_OUTCOME_ALREADY_RESOLVED - - CHANNEL_ACTION_EXECUTION_OUTCOME_UNAUTHORIZED - - CHANNEL_ACTION_EXECUTION_OUTCOME_EXPIRED - - CHANNEL_ACTION_EXECUTION_OUTCOME_STALE - description: |- - ChannelActionExecutionOutcome records the durable side-effect result for a - channel action. - agentruntime.v1.ChannelActionKind: - type: string - title: ChannelActionKind - enum: - - CHANNEL_ACTION_KIND_UNSPECIFIED - - CHANNEL_ACTION_KIND_APPROVAL_DECISION - - CHANNEL_ACTION_KIND_WAIT_RESUME - - CHANNEL_ACTION_KIND_OBJECTIVE_CONTROL - - CHANNEL_ACTION_KIND_MEMORY_DECISION - - CHANNEL_ACTION_KIND_OPS_COMMAND - - CHANNEL_ACTION_KIND_GENERIC - - CHANNEL_ACTION_KIND_CODEX_INTERACTION - - CHANNEL_ACTION_KIND_BROWSER_CONTROL - - CHANNEL_ACTION_KIND_DESKTOP_CONTROL - description: |- - ChannelActionKind classifies the user or integration action submitted from a - durable channel surface. - agentruntime.v1.ChannelActionTargetKind: - type: string - title: ChannelActionTargetKind - enum: - - CHANNEL_ACTION_TARGET_KIND_UNSPECIFIED - - CHANNEL_ACTION_TARGET_KIND_RUN - - CHANNEL_ACTION_TARGET_KIND_WAIT - - CHANNEL_ACTION_TARGET_KIND_APPROVAL - - CHANNEL_ACTION_TARGET_KIND_OBJECTIVE - - CHANNEL_ACTION_TARGET_KIND_ARTIFACT - - CHANNEL_ACTION_TARGET_KIND_MEMORY_CANDIDATE - - CHANNEL_ACTION_TARGET_KIND_TOOL_EXECUTION - - CHANNEL_ACTION_TARGET_KIND_CODEX_SESSION - - CHANNEL_ACTION_TARGET_KIND_PATCH - - CHANNEL_ACTION_TARGET_KIND_PULL_REQUEST - - CHANNEL_ACTION_TARGET_KIND_BROWSER_SESSION - - CHANNEL_ACTION_TARGET_KIND_BROWSER_TAB - - CHANNEL_ACTION_TARGET_KIND_BROWSER_NATIVE_HOST - - CHANNEL_ACTION_TARGET_KIND_DESKTOP_SESSION - description: |- - ChannelActionTargetKind identifies the platform object controlled by a - channel action. - agentruntime.v1.NativeAgentEventSource: - type: string - title: NativeAgentEventSource - enum: - - NATIVE_AGENT_EVENT_SOURCE_UNSPECIFIED - - NATIVE_AGENT_EVENT_SOURCE_MAESTRO - - NATIVE_AGENT_EVENT_SOURCE_CODEX - - NATIVE_AGENT_EVENT_SOURCE_CLAUDE_CODE - - NATIVE_AGENT_EVENT_SOURCE_OTHER - description: |- - NativeAgentEventSource identifies the native Agent Workforce emitter that - produced an observed event. Platform does not infer authority from this - source; proof states below remain missing/unverified until joined to a - Platform resolver, credential, or meter authority. - agentruntime.v1.OperatingChannelContextEntityKind: - type: string - title: OperatingChannelContextEntityKind - enum: - - OPERATING_CHANNEL_CONTEXT_ENTITY_KIND_UNSPECIFIED - - OPERATING_CHANNEL_CONTEXT_ENTITY_KIND_CHANNEL - - OPERATING_CHANNEL_CONTEXT_ENTITY_KIND_MESSAGE - - OPERATING_CHANNEL_CONTEXT_ENTITY_KIND_CANVAS - - OPERATING_CHANNEL_CONTEXT_ENTITY_KIND_LIST - description: |- - A provider-owned object the actor was viewing when a channel turn began. - The edge converts Slack's polymorphic app_context JSON into this bounded - contract; Platform may use the coordinates for governed source reads but - must not treat them as tenant authority. - agentruntime.v1.RunControlMode: - type: string - title: RunControlMode - enum: - - RUN_CONTROL_MODE_UNSPECIFIED - - RUN_CONTROL_MODE_STEER - - RUN_CONTROL_MODE_FOLLOWUP - - RUN_CONTROL_MODE_COLLECT - - RUN_CONTROL_MODE_INTERRUPT - - RUN_CONTROL_MODE_CANCEL - - RUN_CONTROL_MODE_SYSTEM_WAKE - description: |- - RunControlMode describes durable input applied to an autonomous run/session. - Steering and followups are optional controls; they are not the worker loop. - agentruntime.v1.RuntimeAudience: - type: string - title: RuntimeAudience - enum: - - RUNTIME_AUDIENCE_UNSPECIFIED - - RUNTIME_AUDIENCE_AGENT - - RUNTIME_AUDIENCE_TRIGGER_ACTOR - - RUNTIME_AUDIENCE_CHANNEL - - RUNTIME_AUDIENCE_WORKSPACE_ADMINS - - RUNTIME_AUDIENCE_AUDIT - - RUNTIME_AUDIENCE_SYSTEM - description: |- - RuntimeAudience identifies the audience allowed to see a runtime event or - wait projection. Audience is separate from visibility so clients can render a - channel-safe summary while keeping admin/audit detail available elsewhere. - agentruntime.v1.RuntimeChannelKind: - type: string - title: RuntimeChannelKind - enum: - - RUNTIME_CHANNEL_KIND_UNSPECIFIED - - RUNTIME_CHANNEL_KIND_SLACK - - RUNTIME_CHANNEL_KIND_WEB - - RUNTIME_CHANNEL_KIND_API - - RUNTIME_CHANNEL_KIND_EMAIL - - RUNTIME_CHANNEL_KIND_GITHUB - - RUNTIME_CHANNEL_KIND_LINEAR - - RUNTIME_CHANNEL_KIND_JIRA - - RUNTIME_CHANNEL_KIND_IDE - - RUNTIME_CHANNEL_KIND_MONITORING - - RUNTIME_CHANNEL_KIND_BROWSER_EXTENSION - - RUNTIME_CHANNEL_KIND_DESKTOP_HELPER - - RUNTIME_CHANNEL_KIND_CALENDAR - - RUNTIME_CHANNEL_KIND_TEAMS - - RUNTIME_CHANNEL_KIND_WHATSAPP - - RUNTIME_CHANNEL_KIND_APPLE_MESSAGES - description: |- - RuntimeChannelKind classifies the inbound or outbound channel adapter that - owns the human conversation surface for a run. - agentruntime.v1.RuntimeDependencyStatus: - type: string - title: RuntimeDependencyStatus - enum: - - RUNTIME_DEPENDENCY_STATUS_UNSPECIFIED - - RUNTIME_DEPENDENCY_STATUS_RESOLVED - - RUNTIME_DEPENDENCY_STATUS_NOT_FOUND - - RUNTIME_DEPENDENCY_STATUS_NOT_CONFIGURED - - RUNTIME_DEPENDENCY_STATUS_LOADED - description: |- - RuntimeDependencyStatus describes the readiness of a platform boundary that - contributed context to an AgentRun. - agentruntime.v1.RuntimeEventType: - type: string - title: RuntimeEventType - enum: - - RUNTIME_EVENT_TYPE_UNSPECIFIED - - RUNTIME_EVENT_TYPE_TRIGGER_ACCEPTED - - RUNTIME_EVENT_TYPE_AGENT_CONFIG_RESOLVED - - RUNTIME_EVENT_TYPE_OBJECTIVE_RESOLVED - - RUNTIME_EVENT_TYPE_CONTEXT_BUILT - - RUNTIME_EVENT_TYPE_WORKER_DISPATCHED - - RUNTIME_EVENT_TYPE_RUN_FAILED - - RUNTIME_EVENT_TYPE_RUN_QUEUED - - RUNTIME_EVENT_TYPE_RUN_CLAIMED - - RUNTIME_EVENT_TYPE_LEASE_HEARTBEAT - - RUNTIME_EVENT_TYPE_STEP_RECORDED - - RUNTIME_EVENT_TYPE_CHECKPOINT_RECORDED - - RUNTIME_EVENT_TYPE_ARTIFACT_RECORDED - - RUNTIME_EVENT_TYPE_COST_RECORDED - - RUNTIME_EVENT_TYPE_RUN_WAITING - - RUNTIME_EVENT_TYPE_RUN_RESUMED - - RUNTIME_EVENT_TYPE_RUN_SUCCEEDED - - RUNTIME_EVENT_TYPE_RUN_CANCELLED - - RUNTIME_EVENT_TYPE_RUN_RETRY_SCHEDULED - - RUNTIME_EVENT_TYPE_RUN_DEAD_LETTERED - - RUNTIME_EVENT_TYPE_STREAM_CURSOR_RECORDED - - RUNTIME_EVENT_TYPE_CODEX_INTERACTION_REQUESTED - - RUNTIME_EVENT_TYPE_CODEX_INTERACTION_RESOLVED - - RUNTIME_EVENT_TYPE_CODEX_PROGRESS_RECORDED - - RUNTIME_EVENT_TYPE_CODEX_OUTPUT_SYNCED - - RUNTIME_EVENT_TYPE_CODEX_OUTCOME_OBSERVED - - RUNTIME_EVENT_TYPE_CHANNEL_MESSAGE_RECORDED - - RUNTIME_EVENT_TYPE_MODEL_RESPONSE_RECORDED - - RUNTIME_EVENT_TYPE_TOOL_CALL_RECORDED - - RUNTIME_EVENT_TYPE_TOOL_RESULT_RECORDED - - RUNTIME_EVENT_TYPE_APPROVAL_REQUESTED - - RUNTIME_EVENT_TYPE_APPROVAL_RESOLVED - - RUNTIME_EVENT_TYPE_AGENT_PROGRESS_RECORDED - - RUNTIME_EVENT_TYPE_RUN_CONTROL_RECORDED - - RUNTIME_EVENT_TYPE_WORK_ITEM_RECORDED - - RUNTIME_EVENT_TYPE_WORK_ITEM_UPDATED - - RUNTIME_EVENT_TYPE_PROCESSING_PRESENCE_RECORDED - - RUNTIME_EVENT_TYPE_AUTONOMY_SESSION_RECORDED - - RUNTIME_EVENT_TYPE_RUN_YIELDED - description: RuntimeEventType classifies append-only AgentRun events. - agentruntime.v1.RuntimeEvidenceGapReason: - type: string - title: RuntimeEvidenceGapReason - enum: - - RUNTIME_EVIDENCE_GAP_REASON_UNSPECIFIED - - RUNTIME_EVIDENCE_GAP_REASON_CREDENTIAL_UNVERIFIED - - RUNTIME_EVIDENCE_GAP_REASON_PRINCIPAL_UNRESOLVED - - RUNTIME_EVIDENCE_GAP_REASON_COST_UNRECORDED - description: |- - RuntimeEvidenceGapReason identifies the missing proof that prevents a - runtime action from being considered approval-ready. - agentruntime.v1.RuntimeEvidenceState: - type: string - title: RuntimeEvidenceState - enum: - - RUNTIME_EVIDENCE_STATE_UNSPECIFIED - - RUNTIME_EVIDENCE_STATE_NATIVE_OBSERVED - - RUNTIME_EVIDENCE_STATE_PLATFORM_PROVEN - - RUNTIME_EVIDENCE_STATE_MISSING - - RUNTIME_EVIDENCE_STATE_UNVERIFIED - description: |- - RuntimeEvidenceState records whether Platform merely observed a native event - or has joined it to a resolver/proof source. - agentruntime.v1.RuntimeRedactionKind: - type: string - title: RuntimeRedactionKind - enum: - - RUNTIME_REDACTION_KIND_UNSPECIFIED - - RUNTIME_REDACTION_KIND_PII - - RUNTIME_REDACTION_KIND_CREDENTIAL - - RUNTIME_REDACTION_KIND_TOOL_ARGS - - RUNTIME_REDACTION_KIND_POLICY_DETAIL - - RUNTIME_REDACTION_KIND_INTERNAL_CONTEXT - description: |- - RuntimeRedactionKind identifies data categories that were removed or must be - removed before channel/user rendering. - agentruntime.v1.RuntimeSensitivity: - type: string - title: RuntimeSensitivity - enum: - - RUNTIME_SENSITIVITY_UNSPECIFIED - - RUNTIME_SENSITIVITY_PUBLIC - - RUNTIME_SENSITIVITY_INTERNAL - - RUNTIME_SENSITIVITY_CONFIDENTIAL - - RUNTIME_SENSITIVITY_RESTRICTED - description: |- - RuntimeSensitivity classifies how carefully runtime payloads must be handled - before projection outside Platform. - agentruntime.v1.RuntimeTriggerKind: - type: string - title: RuntimeTriggerKind - enum: - - RUNTIME_TRIGGER_KIND_UNSPECIFIED - - RUNTIME_TRIGGER_KIND_SLACK_APP_MENTION - - RUNTIME_TRIGGER_KIND_SLACK_DIRECT_MESSAGE - - RUNTIME_TRIGGER_KIND_SLACK_SLASH_COMMAND - - RUNTIME_TRIGGER_KIND_SLACK_ACTION - - RUNTIME_TRIGGER_KIND_SLACK_THREAD_CONTINUATION - - RUNTIME_TRIGGER_KIND_SLACK_EVENT - - RUNTIME_TRIGGER_KIND_ENSEMBLE_WEB_MESSAGE - - RUNTIME_TRIGGER_KIND_ENSEMBLE_WEBHOOK_EVENT - - RUNTIME_TRIGGER_KIND_SCHEDULE - - RUNTIME_TRIGGER_KIND_EMAIL - - RUNTIME_TRIGGER_KIND_API - - RUNTIME_TRIGGER_KIND_WEB - - RUNTIME_TRIGGER_KIND_GITHUB_ISSUE_COMMENT - - RUNTIME_TRIGGER_KIND_GITHUB_PULL_REQUEST_COMMENT - - RUNTIME_TRIGGER_KIND_LINEAR_ACTION - - RUNTIME_TRIGGER_KIND_IDE_COMMAND - - RUNTIME_TRIGGER_KIND_MONITORING_ALERT - - RUNTIME_TRIGGER_KIND_PROACTIVE_PATTERN - - RUNTIME_TRIGGER_KIND_SLACK_ASSISTANT_THREAD_STARTED - - RUNTIME_TRIGGER_KIND_SLACK_ASSISTANT_THREAD_CONTEXT_CHANGED - - RUNTIME_TRIGGER_KIND_CALENDAR_EVENT_CREATED - - RUNTIME_TRIGGER_KIND_CALENDAR_EVENT_UPDATED - - RUNTIME_TRIGGER_KIND_CALENDAR_EVENT_CANCELLED - - RUNTIME_TRIGGER_KIND_TEAMS_MESSAGE - - RUNTIME_TRIGGER_KIND_TEAMS_CHANNEL_MENTION - - RUNTIME_TRIGGER_KIND_WHATSAPP_DIRECT_MESSAGE - - RUNTIME_TRIGGER_KIND_WHATSAPP_GROUP_MESSAGE - - RUNTIME_TRIGGER_KIND_WHATSAPP_BUTTON_REPLY - description: |- - RuntimeTriggerKind classifies the normalized source event that started or - resumed a run. The legacy string source_event_type remains for compatibility - with early producers and arbitrary integration event names. - agentruntime.v1.RuntimeVirtualFileOperation: - type: string - title: RuntimeVirtualFileOperation - enum: - - RUNTIME_VIRTUAL_FILE_OPERATION_UNSPECIFIED - - RUNTIME_VIRTUAL_FILE_OPERATION_WRITE - - RUNTIME_VIRTUAL_FILE_OPERATION_DELETE - - RUNTIME_VIRTUAL_FILE_OPERATION_RENAME - agentruntime.v1.RuntimeVirtualFileReasonCode: - type: string - title: RuntimeVirtualFileReasonCode - enum: - - RUNTIME_VIRTUAL_FILE_REASON_CODE_UNSPECIFIED - - RUNTIME_VIRTUAL_FILE_REASON_CODE_NOT_FOUND - - RUNTIME_VIRTUAL_FILE_REASON_CODE_FILTERED_OUT - - RUNTIME_VIRTUAL_FILE_REASON_CODE_TOTAL_BUDGET_EXHAUSTED - - RUNTIME_VIRTUAL_FILE_REASON_CODE_PATH_INVALID - - RUNTIME_VIRTUAL_FILE_REASON_CODE_CAPABILITY_DENIED - - RUNTIME_VIRTUAL_FILE_REASON_CODE_REVISION_CONFLICT - - RUNTIME_VIRTUAL_FILE_REASON_CODE_CURSOR_LAGGED - - RUNTIME_VIRTUAL_FILE_REASON_CODE_TEMPORARILY_UNAVAILABLE - description: |- - RuntimeVirtualFileReasonCode is a stable, machine-readable reason taxonomy - for VFS skips and precondition failures. Human strings may evolve; clients - should branch on this enum. - agentruntime.v1.RuntimeVirtualFileRedactionState: - type: string - title: RuntimeVirtualFileRedactionState - enum: - - RUNTIME_VIRTUAL_FILE_REDACTION_STATE_UNSPECIFIED - - RUNTIME_VIRTUAL_FILE_REDACTION_STATE_RAW - - RUNTIME_VIRTUAL_FILE_REDACTION_STATE_REDACTED - - RUNTIME_VIRTUAL_FILE_REDACTION_STATE_PREVIEW_ONLY - - RUNTIME_VIRTUAL_FILE_REDACTION_STATE_DENIED - description: |- - RuntimeVirtualFileRedactionState mirrors the workspace VFS byte plane's - redaction contract so Runtime VFS callers can discover whether content is - safe to read, preview-only, already redacted, or denied. - agentruntime.v1.RuntimeVirtualFileTransactionApplyStatus: - type: string - title: RuntimeVirtualFileTransactionApplyStatus - enum: - - RUNTIME_VIRTUAL_FILE_TRANSACTION_APPLY_STATUS_UNSPECIFIED - - RUNTIME_VIRTUAL_FILE_TRANSACTION_APPLY_STATUS_CLEAN - - RUNTIME_VIRTUAL_FILE_TRANSACTION_APPLY_STATUS_IDENTICAL - - RUNTIME_VIRTUAL_FILE_TRANSACTION_APPLY_STATUS_CONFLICT - - RUNTIME_VIRTUAL_FILE_TRANSACTION_APPLY_STATUS_MISSING_BASE - - RUNTIME_VIRTUAL_FILE_TRANSACTION_APPLY_STATUS_MISSING_TARGET - agentruntime.v1.RuntimeVirtualFileTransactionOutcome: - type: string - title: RuntimeVirtualFileTransactionOutcome - enum: - - RUNTIME_VIRTUAL_FILE_TRANSACTION_OUTCOME_UNSPECIFIED - - RUNTIME_VIRTUAL_FILE_TRANSACTION_OUTCOME_CLEAN - - RUNTIME_VIRTUAL_FILE_TRANSACTION_OUTCOME_APPLIED - - RUNTIME_VIRTUAL_FILE_TRANSACTION_OUTCOME_REBASED - - RUNTIME_VIRTUAL_FILE_TRANSACTION_OUTCOME_CONFLICT - - RUNTIME_VIRTUAL_FILE_TRANSACTION_OUTCOME_NOOP - agentruntime.v1.RuntimeVisibilityLevel: - type: string - title: RuntimeVisibilityLevel - enum: - - RUNTIME_VISIBILITY_LEVEL_UNSPECIFIED - - RUNTIME_VISIBILITY_LEVEL_AGENT_ONLY - - RUNTIME_VISIBILITY_LEVEL_USER_VISIBLE - - RUNTIME_VISIBILITY_LEVEL_CHANNEL_VISIBLE - - RUNTIME_VISIBILITY_LEVEL_ADMIN_VISIBLE - - RUNTIME_VISIBILITY_LEVEL_AUDIT_ONLY - description: |- - RuntimeVisibilityLevel declares whether runtime state can be projected to - humans or should remain internal/audit-only. Unspecified values are treated - conservatively as agent-only by service helpers and consumers. - agentruntime.v1.RuntimeWorkEnvelopeKind: - type: string - title: RuntimeWorkEnvelopeKind - enum: - - RUNTIME_WORK_ENVELOPE_KIND_UNSPECIFIED - - RUNTIME_WORK_ENVELOPE_KIND_CONVERSATION_THREAD - - RUNTIME_WORK_ENVELOPE_KIND_DIRECT_CONVERSATION - - RUNTIME_WORK_ENVELOPE_KIND_TICKET - - RUNTIME_WORK_ENVELOPE_KIND_CALENDAR_EVENT - - RUNTIME_WORK_ENVELOPE_KIND_PULL_REQUEST - - RUNTIME_WORK_ENVELOPE_KIND_INCIDENT - - RUNTIME_WORK_ENVELOPE_KIND_REPOSITORY - - RUNTIME_WORK_ENVELOPE_KIND_DOCUMENT - - RUNTIME_WORK_ENVELOPE_KIND_RECORD - description: |- - RuntimeWorkEnvelopeKind classifies the durable human/work object a trigger - belongs to. Envelopes group retries and follow-up messages across channels - without making the runtime depend on Slack-specific string labels. - agentruntime.v1.SurfaceInvocationControl: - type: string - title: SurfaceInvocationControl - enum: - - SURFACE_INVOCATION_CONTROL_UNSPECIFIED - - SURFACE_INVOCATION_CONTROL_WORK - - SURFACE_INVOCATION_CONTROL_CANCEL - agentruntime.v1.SurfaceTargetKind: - type: string - title: SurfaceTargetKind - enum: - - SURFACE_TARGET_KIND_UNSPECIFIED - - SURFACE_TARGET_KIND_CONVERSATION - - SURFACE_TARGET_KIND_TICKET - - SURFACE_TARGET_KIND_PULL_REQUEST - - SURFACE_TARGET_KIND_INCIDENT - - SURFACE_TARGET_KIND_REPOSITORY - - SURFACE_TARGET_KIND_DOCUMENT - - SURFACE_TARGET_KIND_RECORD - description: |- - SurfaceTargetKind classifies the provider object that owns interaction - context. It is deliberately independent of conversation channel shape. - agentruntime.v1.YieldContinuation: - type: string - title: YieldContinuation - enum: - - YIELD_CONTINUATION_UNSPECIFIED - - YIELD_CONTINUATION_INLINE_NEXT_STEP - - YIELD_CONTINUATION_SCHEDULED - - YIELD_CONTINUATION_WAIT - - YIELD_CONTINUATION_END_SESSION - description: |- - YieldContinuation describes how Platform should continue an autonomous - session after the current run releases its lease. - agents.v1.AgentStatus: - type: string - title: AgentStatus - enum: - - AGENT_STATUS_UNSPECIFIED - - AGENT_STATUS_ACTIVE - - AGENT_STATUS_IDLE - - AGENT_STATUS_BUSY - - AGENT_STATUS_OFFLINE - - AGENT_STATUS_DEGRADED - - AGENT_STATUS_SUSPENDED - description: AgentStatus describes the operational state of an agent. - agents.v1.AutonomyAuthority: - type: string - title: AutonomyAuthority - enum: - - AUTONOMY_AUTHORITY_UNSPECIFIED - - AUTONOMY_AUTHORITY_OWN - - AUTONOMY_AUTHORITY_RECOMMEND - - AUTONOMY_AUTHORITY_REQUIRE_APPROVAL - - AUTONOMY_AUTHORITY_DENY - description: AutonomyAuthority describes how independently a teammate may act. - agents.v1.CommitmentKind: - type: string - title: CommitmentKind - enum: - - COMMITMENT_KIND_UNSPECIFIED - - COMMITMENT_KIND_FOLLOW_UP - - COMMITMENT_KIND_WATCH - - COMMITMENT_KIND_RETRY - - COMMITMENT_KIND_SUMMARIZE - - COMMITMENT_KIND_MONITOR - - COMMITMENT_KIND_REMEDIATE - - COMMITMENT_KIND_HANDOFF - description: CommitmentKind describes the durable commitments a teammate can accept. - agents.v1.InitiativeTriggerKind: - type: string - title: InitiativeTriggerKind - enum: - - INITIATIVE_TRIGGER_KIND_UNSPECIFIED - - INITIATIVE_TRIGGER_KIND_SCHEDULE - - INITIATIVE_TRIGGER_KIND_SLACK_EVENT - - INITIATIVE_TRIGGER_KIND_PLATFORM_EVENT - - INITIATIVE_TRIGGER_KIND_OBJECTIVE_WAKE - - INITIATIVE_TRIGGER_KIND_WAIT_RESOLVED - - INITIATIVE_TRIGGER_KIND_EVAL_REGRESSION - - INITIATIVE_TRIGGER_KIND_STALLED_WORK - description: |- - InitiativeTriggerKind describes events that can let a teammate start work - without a fresh direct human prompt. - agents.v1.PresenceEvent: - type: string - title: PresenceEvent - enum: - - PRESENCE_EVENT_UNSPECIFIED - - PRESENCE_EVENT_ACCEPTED - - PRESENCE_EVENT_WAITING - - PRESENCE_EVENT_PROGRESS - - PRESENCE_EVENT_BLOCKED - - PRESENCE_EVENT_COMPLETED - - PRESENCE_EVENT_FAILED - - PRESENCE_EVENT_ESCALATED - description: PresenceEvent describes channel-visible teammate activity. - agents.v1.TeammateChannelCapability: - type: string - title: TeammateChannelCapability - enum: - - TEAMMATE_CHANNEL_CAPABILITY_UNSPECIFIED - - TEAMMATE_CHANNEL_CAPABILITY_INGEST - - TEAMMATE_CHANNEL_CAPABILITY_RENDER - description: |- - TeammateChannelCapability describes what a channel adapter can do for a - teammate profile. - agents.v1.TeammateChannelEventKind: - type: string - title: TeammateChannelEventKind - enum: - - TEAMMATE_CHANNEL_EVENT_KIND_UNSPECIFIED - - TEAMMATE_CHANNEL_EVENT_KIND_MESSAGE_CREATED - - TEAMMATE_CHANNEL_EVENT_KIND_THREAD_REPLY_CREATED - - TEAMMATE_CHANNEL_EVENT_KIND_COMMAND_INVOKED - - TEAMMATE_CHANNEL_EVENT_KIND_ACTION_INVOKED - - TEAMMATE_CHANNEL_EVENT_KIND_REACTION_ADDED - - TEAMMATE_CHANNEL_EVENT_KIND_REACTION_REMOVED - - TEAMMATE_CHANNEL_EVENT_KIND_ASSISTANT_THREAD_STARTED - - TEAMMATE_CHANNEL_EVENT_KIND_ASSISTANT_THREAD_CONTEXT_CHANGED - - TEAMMATE_CHANNEL_EVENT_KIND_EMAIL_RECEIVED - - TEAMMATE_CHANNEL_EVENT_KIND_CALENDAR_EVENT_CHANGED - - TEAMMATE_CHANNEL_EVENT_KIND_ISSUE_CHANGED - - TEAMMATE_CHANNEL_EVENT_KIND_SCHEDULED_WAKE - - TEAMMATE_CHANNEL_EVENT_KIND_WEBHOOK_RECEIVED - description: |- - TeammateChannelEventKind describes normalized inbound channel events that can - become AgentRuntime triggers. - agents.v1.TeammateChannelKind: - type: string - title: TeammateChannelKind - enum: - - TEAMMATE_CHANNEL_KIND_UNSPECIFIED - - TEAMMATE_CHANNEL_KIND_SLACK - - TEAMMATE_CHANNEL_KIND_EMAIL - - TEAMMATE_CHANNEL_KIND_CALENDAR - - TEAMMATE_CHANNEL_KIND_JIRA - - TEAMMATE_CHANNEL_KIND_TEAMS - - TEAMMATE_CHANNEL_KIND_WEB - - TEAMMATE_CHANNEL_KIND_WEBHOOK - - TEAMMATE_CHANNEL_KIND_WHATSAPP - - TEAMMATE_CHANNEL_KIND_APPLE_MESSAGES - description: |- - TeammateChannelKind identifies a product or provider channel that can ingest - user activity or render teammate runtime events. It intentionally lives in - agents/v1 instead of agentruntime/v1 so teammate profiles can describe - supported channels without creating a proto import cycle. - agents.v1.TeammateLifecycle: - type: string - title: TeammateLifecycle - enum: - - TEAMMATE_LIFECYCLE_UNSPECIFIED - - TEAMMATE_LIFECYCLE_DRAFT - - TEAMMATE_LIFECYCLE_ACTIVE - - TEAMMATE_LIFECYCLE_PAUSED - - TEAMMATE_LIFECYCLE_DEPRECATED - description: |- - TeammateLifecycle describes whether a teammate profile can be used to - initiate durable work. - agents.v1.TeammateRuntimeRenderEventKind: - type: string - title: TeammateRuntimeRenderEventKind - enum: - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_UNSPECIFIED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_TRIGGER_ACCEPTED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_RUN_STARTED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_PROGRESS - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_STEP_STARTED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_STEP_COMPLETED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_OBJECTIVE_UPDATED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_APPROVAL_REQUESTED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_APPROVAL_RESOLVED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_TOOL_PROPOSED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_TOOL_COMPLETED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_ARTIFACT_CREATED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_MEMORY_PROPOSED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_WAITING - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_RESUMED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_COMPLETED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_FAILED - description: |- - TeammateRuntimeRenderEventKind describes Platform runtime events a channel - adapter can project back into the provider surface. - codex.v1.CodexActionType: - type: string - title: CodexActionType - enum: - - CODEX_ACTION_TYPE_UNSPECIFIED - - CODEX_ACTION_TYPE_START_WORK - - CODEX_ACTION_TYPE_FOLLOW_UP - - CODEX_ACTION_TYPE_INVESTIGATE - - CODEX_ACTION_TYPE_FIX - - CODEX_ACTION_TYPE_REVIEW - - CODEX_ACTION_TYPE_TEST - - CODEX_ACTION_TYPE_EXPLAIN - - CODEX_ACTION_TYPE_RETRY - - CODEX_ACTION_TYPE_FORK - description: |- - CodexActionType describes the user intent that should shape prompting, - permissions, routing, and output expectations for a Codex run. - codex.v1.CodexAuthorityScope: - type: string - title: CodexAuthorityScope - enum: - - CODEX_AUTHORITY_SCOPE_UNSPECIFIED - - CODEX_AUTHORITY_SCOPE_DISCUSS_ONLY - - CODEX_AUTHORITY_SCOPE_READ_ONLY - - CODEX_AUTHORITY_SCOPE_WORKSPACE_WRITE - description: |- - CodexAuthorityScope is the maximum local filesystem authority requested for - delegated work. Platform policy, device mappings, and native confirmation - may only narrow this value. - codex.v1.CodexBackend: - type: string - title: CodexBackend - enum: - - CODEX_BACKEND_UNSPECIFIED - - CODEX_BACKEND_APP_SERVER - - CODEX_BACKEND_CODEX_SDK - - CODEX_BACKEND_CLAUDE_CODE - - CODEX_BACKEND_INTERNAL_AGENT - - CODEX_BACKEND_MODEL_TRIAGE - description: CodexBackend identifies the execution backend selected for a run. - codex.v1.CodexContextSourceKind: - type: string - title: CodexContextSourceKind - enum: - - CODEX_CONTEXT_SOURCE_KIND_UNSPECIFIED - - CODEX_CONTEXT_SOURCE_KIND_SLACK_MESSAGE - - CODEX_CONTEXT_SOURCE_KIND_SLACK_THREAD - - CODEX_CONTEXT_SOURCE_KIND_GITHUB_PULL_REQUEST - - CODEX_CONTEXT_SOURCE_KIND_GITHUB_ISSUE - - CODEX_CONTEXT_SOURCE_KIND_LINEAR_TICKET - - CODEX_CONTEXT_SOURCE_KIND_JIRA_TICKET - - CODEX_CONTEXT_SOURCE_KIND_SENTRY_EVENT - - CODEX_CONTEXT_SOURCE_KIND_DATADOG_DASHBOARD - - CODEX_CONTEXT_SOURCE_KIND_LOG_SNIPPET - - CODEX_CONTEXT_SOURCE_KIND_SCREENSHOT - - CODEX_CONTEXT_SOURCE_KIND_MEMORY - - CODEX_CONTEXT_SOURCE_KIND_URL - - CODEX_CONTEXT_SOURCE_KIND_CEREBRO_THING - - CODEX_CONTEXT_SOURCE_KIND_CEREBRO_FACT - - CODEX_CONTEXT_SOURCE_KIND_CEREBRO_EVENT - - CODEX_CONTEXT_SOURCE_KIND_CEREBRO_ACTION - - CODEX_CONTEXT_SOURCE_KIND_CEREBRO_PREDICTION - - CODEX_CONTEXT_SOURCE_KIND_GRANOLA_MEETING - - CODEX_CONTEXT_SOURCE_KIND_GOOGLE_EMAIL_THREAD - - CODEX_CONTEXT_SOURCE_KIND_GOOGLE_DRIVE_FILE - - CODEX_CONTEXT_SOURCE_KIND_GOOGLE_CALENDAR_EVENT - - CODEX_CONTEXT_SOURCE_KIND_DEPLOYMENT - - CODEX_CONTEXT_SOURCE_KIND_BUILD - description: |- - CodexContextSourceKind names a structured context source enriched before a - run reaches the worker. - codex.v1.CodexExecutionIntent: - type: string - title: CodexExecutionIntent - enum: - - CODEX_EXECUTION_INTENT_UNSPECIFIED - - CODEX_EXECUTION_INTENT_READ_ONLY_DIAGNOSIS - - CODEX_EXECUTION_INTENT_PATCH_AND_VERIFY - - CODEX_EXECUTION_INTENT_REVIEW_ONLY - - CODEX_EXECUTION_INTENT_TEST_AUTHORING - - CODEX_EXECUTION_INTENT_EXPLANATION - description: CodexExecutionIntent captures the expected risk and write profile. - codex.v1.CodexInteractionType: - type: string - title: CodexInteractionType - enum: - - CODEX_INTERACTION_TYPE_UNSPECIFIED - - CODEX_INTERACTION_TYPE_APPROVE_PLAN - - CODEX_INTERACTION_TYPE_REJECT_PLAN - - CODEX_INTERACTION_TYPE_APPLY_PATCH - - CODEX_INTERACTION_TYPE_DISCARD_PATCH - - CODEX_INTERACTION_TYPE_STOP_TURN - - CODEX_INTERACTION_TYPE_RETRY_TURN - - CODEX_INTERACTION_TYPE_FORK_THREAD - - CODEX_INTERACTION_TYPE_APPROVE_COMMAND - - CODEX_INTERACTION_TYPE_PROVIDE_INPUT - description: CodexInteractionType describes a channel-native control action. - codex.v1.CodexInteractivityMode: - type: string - title: CodexInteractivityMode - enum: - - CODEX_INTERACTIVITY_MODE_UNSPECIFIED - - CODEX_INTERACTIVITY_MODE_BACKGROUND - - CODEX_INTERACTIVITY_MODE_THREAD_CONVERSATION - - CODEX_INTERACTIVITY_MODE_HUMAN_APPROVAL_GATED - description: |- - CodexInteractivityMode controls how much of the run is projected back to a - human conversation surface. - codex.v1.CodexMemoryScopeKind: - type: string - title: CodexMemoryScopeKind - enum: - - CODEX_MEMORY_SCOPE_KIND_UNSPECIFIED - - CODEX_MEMORY_SCOPE_KIND_THREAD - - CODEX_MEMORY_SCOPE_KIND_REPOSITORY - - CODEX_MEMORY_SCOPE_KIND_TEAM - - CODEX_MEMORY_SCOPE_KIND_WORKSPACE - description: CodexMemoryScopeKind identifies the retrieval scope for prior run memory. - codex.v1.CodexOutputKind: - type: string - title: CodexOutputKind - enum: - - CODEX_OUTPUT_KIND_UNSPECIFIED - - CODEX_OUTPUT_KIND_THREAD_MESSAGE - - CODEX_OUTPUT_KIND_PULL_REQUEST - - CODEX_OUTPUT_KIND_PULL_REQUEST_COMMENT - - CODEX_OUTPUT_KIND_ARTIFACT - - CODEX_OUTPUT_KIND_RUN_PANEL - - CODEX_OUTPUT_KIND_EVALUATION_EXAMPLE - - CODEX_OUTPUT_KIND_DRAFT_MESSAGE - - CODEX_OUTPUT_KIND_DECISION_BRIEF - - CODEX_OUTPUT_KIND_PREPARED_FUTURE - - CODEX_OUTPUT_KIND_ISSUE - description: |- - CodexOutputKind classifies an artifact or external object the run should - create or synchronize. - codex.v1.CodexProgressStage: - type: string - title: CodexProgressStage - enum: - - CODEX_PROGRESS_STAGE_UNSPECIFIED - - CODEX_PROGRESS_STAGE_ACCEPTED - - CODEX_PROGRESS_STAGE_CONTEXT_ENRICHING - - CODEX_PROGRESS_STAGE_PLANNING - - CODEX_PROGRESS_STAGE_WAITING_FOR_APPROVAL - - CODEX_PROGRESS_STAGE_EDITING - - CODEX_PROGRESS_STAGE_TESTING - - CODEX_PROGRESS_STAGE_CREATING_OUTPUT - - CODEX_PROGRESS_STAGE_WATCHING_CI - - CODEX_PROGRESS_STAGE_COMPLETED - - CODEX_PROGRESS_STAGE_FAILED - - CODEX_PROGRESS_STAGE_CANCELLED - description: CodexProgressStage classifies user-visible run progress. - common.v1.DeliveryChannel: - type: string - title: DeliveryChannel - enum: - - DELIVERY_CHANNEL_UNSPECIFIED - - DELIVERY_CHANNEL_SLACK - - DELIVERY_CHANNEL_EMAIL - - DELIVERY_CHANNEL_WEBHOOK - - DELIVERY_CHANNEL_IN_APP - - DELIVERY_CHANNEL_PUSH - description: DeliveryChannel identifies the notification delivery channel. - common.v1.EntityType: - type: string - title: EntityType - enum: - - ENTITY_TYPE_UNSPECIFIED - - ENTITY_TYPE_CONTACT - - ENTITY_TYPE_COMPANY - - ENTITY_TYPE_DEAL - - ENTITY_TYPE_TICKET - - ENTITY_TYPE_CUSTOMER - - ENTITY_TYPE_OPPORTUNITY - description: EntityType identifies the kind of entity across systems. - common.v1.RiskLevel: - type: string - title: RiskLevel - enum: - - RISK_LEVEL_UNSPECIFIED - - RISK_LEVEL_LOW - - RISK_LEVEL_MEDIUM - - RISK_LEVEL_HIGH - - RISK_LEVEL_CRITICAL - description: RiskLevel classifies the risk of an action. - common.v1.Surface: - type: string - title: Surface - enum: - - SURFACE_UNSPECIFIED - - SURFACE_ENSEMBLE - - SURFACE_CHAT - - SURFACE_MAESTRO - - SURFACE_CONDUCTOR - - SURFACE_SLACK - - SURFACE_EXTERNAL_AGENT - description: |- - Surface identifies the product or channel surface that originated a platform - action. It is shared by runtime, audit, and product-facing services so - callers do not invent drift-prone string labels. - google.protobuf.NullValue: - type: string - title: NullValue - enum: - - NULL_VALUE - description: |- - `NullValue` is a singleton enumeration to represent the null value for the - `Value` type union. - - The JSON representation for `NullValue` is JSON `null`. - objectives.v1.MutationStatus: - type: string - title: MutationStatus - enum: - - MUTATION_STATUS_UNSPECIFIED - - MUTATION_STATUS_PENDING - - MUTATION_STATUS_APPROVED - - MUTATION_STATUS_DENIED - - MUTATION_STATUS_EXECUTED - - MUTATION_STATUS_ROLLED_BACK - description: MutationStatus describes the status of a mutation operation. - objectives.v1.ObjectiveState: - type: string - title: ObjectiveState - enum: - - OBJECTIVE_STATE_UNSPECIFIED - - OBJECTIVE_STATE_PENDING - - OBJECTIVE_STATE_RUNNING - - OBJECTIVE_STATE_BLOCKED - - OBJECTIVE_STATE_DEGRADED - - OBJECTIVE_STATE_AWAITING_APPROVAL - - OBJECTIVE_STATE_QUEUED - - OBJECTIVE_STATE_COMPLETED - - OBJECTIVE_STATE_FAILED - - OBJECTIVE_STATE_CANCELLED - description: ObjectiveState describes the lifecycle state of an objective. - agentruntime.v1.AdmitOperatingChannelEventRequest: - type: object - properties: - providerId: - type: string - title: provider_id - minLength: 1 - providerAppId: - type: string - title: provider_app_id - minLength: 1 - providerWorkspaceId: - type: string - title: provider_workspace_id - minLength: 1 - providerEnterpriseId: - type: string - title: provider_enterprise_id - sourceEventId: - type: string - title: source_event_id - minLength: 1 - sourceEventType: - type: string - title: source_event_type - minLength: 1 - providerChannelId: - type: string - title: provider_channel_id - minLength: 1 - providerRootThreadId: - type: string - title: provider_root_thread_id - minLength: 1 - providerMessageId: - type: string - title: provider_message_id - minLength: 1 - actorSubject: - type: string - title: actor_subject - minLength: 1 - normalizedText: - type: string - title: normalized_text - attachments: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.OperatingChannelAttachmentMetadata' - title: attachments - traceparent: - type: string - title: traceparent - tracestate: - type: string - title: tracestate - directConversation: - type: boolean - title: direct_conversation - explicitMention: - type: boolean - title: explicit_mention - interaction: - title: interaction - $ref: '#/components/schemas/agentruntime.v1.OperatingChannelInteraction' - slackRtsActionToken: - type: string - title: slack_rts_action_token - description: |- - Short-lived Slack RTS authority from the triggering message/app_mention. - Server-owned execution context; never forwarded to the model or receipts. - contextEntities: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.OperatingChannelContextEntity' - title: context_entities - maxItems: 20 - providerDeliveryEndpoint: - type: string - title: provider_delivery_endpoint - maxLength: 2048 - description: |- - Authenticated provider callback endpoint used only for outbound transport. - Platform validates and persists this outside model-visible context. - email: - title: email - $ref: '#/components/schemas/agentruntime.v1.OperatingChannelEmailMetadata' - title: AdmitOperatingChannelEventRequest - additionalProperties: false - description: |- - Provider-coordinate admission deliberately has no organization_id or - workspace_id fields. Those authority-bearing coordinates are resolved by - Platform through ConnectorService before any durable tenant write occurs. - agentruntime.v1.AdmitOperatingChannelEventResponse: - type: object - properties: - accepted: - type: boolean - title: accepted - duplicate: - type: boolean - title: duplicate - ignoredReason: - type: string - title: ignored_reason - conversationId: - type: string - title: conversation_id - turnId: - type: string - title: turn_id - title: AdmitOperatingChannelEventResponse - additionalProperties: false - agentruntime.v1.AdmitSurfaceInvocationRequest: - type: object - properties: - providerId: - type: string - title: provider_id - minLength: 1 - connectionId: - type: string - title: connection_id - maxLength: 512 - providerAppId: - type: string - title: provider_app_id - minLength: 1 - providerWorkspaceId: - type: string - title: provider_workspace_id - minLength: 1 - providerEnterpriseId: - type: string - title: provider_enterprise_id - maxLength: 512 - actor: - title: actor - $ref: '#/components/schemas/agentruntime.v1.SurfaceInvocationActor' - target: - title: target - $ref: '#/components/schemas/agentruntime.v1.SurfaceInvocationTarget' - trigger: - title: trigger - $ref: '#/components/schemas/agentruntime.v1.SurfaceInvocationTrigger' - text: - type: string - title: text - maxLength: 32768 - attachments: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.SurfaceInvocationAttachmentRef' - title: attachments - maxItems: 20 - contextRefs: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.SurfaceInvocationContextRef' - title: context_refs - maxItems: 20 - projectionContext: - title: projection_context - $ref: '#/components/schemas/google.protobuf.Struct' - idempotencyKey: - type: string - title: idempotency_key - maxLength: 512 - minLength: 1 - traceparent: - type: string - title: traceparent - maxLength: 512 - tracestate: - type: string - title: tracestate - maxLength: 512 - contextSnapshots: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.SurfaceInvocationContextSnapshot' - title: context_snapshots - maxItems: 20 - control: - title: control - $ref: '#/components/schemas/agentruntime.v1.SurfaceInvocationControl' - acknowledgementRequested: - type: boolean - title: acknowledgement_requested - description: |- - Providers with a native agent/session UI may request a fast, governed - acknowledgement projection while ordinary work continues. - title: AdmitSurfaceInvocationRequest - additionalProperties: false - description: |- - The adapter, not this request, verifies the provider-native webhook. A - surface-edge service can normalize Slack, Linear, Jira, Salesforce, - documents, incidents, and future providers into this one typed contract. - Tenant scope is absent by design and is resolved through ConnectorService. - agentruntime.v1.AdmitSurfaceInvocationResponse: - type: object - properties: - accepted: - type: boolean - title: accepted - duplicate: - type: boolean - title: duplicate - ignoredReason: - type: string - title: ignored_reason - conversationId: - type: string - title: conversation_id - turnId: - type: string - title: turn_id - title: AdmitSurfaceInvocationResponse - additionalProperties: false - agentruntime.v1.AgentAutonomySession: - type: object - properties: - id: - type: string - title: id - linkage: - title: linkage - $ref: '#/components/schemas/agentruntime.v1.AgentRunLinkage' - workEnvelopeId: - type: string - title: work_envelope_id - workEnvelopeKind: - title: work_envelope_kind - $ref: '#/components/schemas/agentruntime.v1.RuntimeWorkEnvelopeKind' - channelContext: - title: channel_context - $ref: '#/components/schemas/agentruntime.v1.RuntimeChannelContext' - state: - title: state - $ref: '#/components/schemas/agentruntime.v1.AutonomySessionState' - processingState: - title: processing_state - $ref: '#/components/schemas/agentruntime.v1.AutonomyProcessingState' - processingSummary: - type: string - title: processing_summary - rootRunId: - type: string - title: root_run_id - activeRunId: - type: string - title: active_run_id - currentGoal: - type: string - title: current_goal - nextAction: - type: string - title: next_action - blocker: - type: string - title: blocker - processingMessageTs: - type: string - title: processing_message_ts - assistantStreamTs: - type: string - title: assistant_stream_ts - lastPresenceEventId: - type: string - title: last_presence_event_id - lastPresenceUpdateAt: - title: last_presence_update_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - finalResponsePending: - type: boolean - title: final_response_pending - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: AgentAutonomySession - additionalProperties: false - description: |- - AgentAutonomySession is the durable teammate session projected over one - objective/work envelope. Platform owns this identity so Slack can wake, - steer, or inspect the same autonomous worker without becoming the run loop. - agentruntime.v1.AgentRun: - type: object - properties: - id: - type: string - title: id - trigger: - title: trigger - $ref: '#/components/schemas/agentruntime.v1.NormalizedTrigger' - state: - title: state - $ref: '#/components/schemas/agentruntime.v1.AgentRunState' - agent: - title: agent - $ref: '#/components/schemas/agents.v1.Agent' - agentConfig: - title: agent_config - $ref: '#/components/schemas/agents.v1.AgentConfig' - objective: - title: objective - $ref: '#/components/schemas/objectives.v1.Objective' - context: - title: context - $ref: '#/components/schemas/agentruntime.v1.RuntimeContext' - workerQueue: - type: string - title: worker_queue - errorMessage: - type: string - title: error_message - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - linkage: - title: linkage - $ref: '#/components/schemas/agentruntime.v1.AgentRunLinkage' - attempt: - type: integer - title: attempt - format: int32 - maxAttempts: - type: integer - title: max_attempts - format: int32 - lease: - title: lease - $ref: '#/components/schemas/agentruntime.v1.AgentRunLease' - latestCheckpoint: - title: latest_checkpoint - $ref: '#/components/schemas/agentruntime.v1.AgentRunCheckpoint' - steps: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.AgentRunStep' - title: steps - waits: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.AgentRunWait' - title: waits - artifacts: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.AgentRunArtifact' - title: artifacts - costs: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.AgentRunCost' - title: costs - streamCursors: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.AgentRunStreamCursor' - title: stream_cursors - queuedAt: - title: queued_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - startedAt: - title: started_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - waitingAt: - title: waiting_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - completedAt: - title: completed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - cancelledAt: - title: cancelled_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - nextRetryAt: - title: next_retry_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - deadLetteredAt: - title: dead_lettered_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - cancellationReason: - type: string - title: cancellation_reason - deadLetterReason: - type: string - title: dead_letter_reason - checkpoints: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.AgentRunCheckpoint' - title: checkpoints - traceContext: - title: trace_context - $ref: '#/components/schemas/agentruntime.v1.RuntimeTraceContext' - autonomySessionId: - type: string - title: autonomy_session_id - title: AgentRun - additionalProperties: false - description: |- - AgentRun is the canonical agent runtime execution record. It owns the - durable child records needed to resume from checkpoints and audit each - attempt without replaying model/tool side effects. - agentruntime.v1.AgentRunArtifact: - type: object - properties: - id: - type: string - title: id - linkage: - title: linkage - $ref: '#/components/schemas/agentruntime.v1.AgentRunLinkage' - stepId: - type: string - title: step_id - artifactType: - type: string - title: artifact_type - deprecated: true - uri: - type: string - title: uri - contentType: - type: string - title: content_type - digest: - type: string - title: digest - metadata: - title: metadata - $ref: '#/components/schemas/google.protobuf.Struct' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - artifactKind: - title: artifact_kind - $ref: '#/components/schemas/agentruntime.v1.AgentRunArtifactKind' - codexOutput: - title: codex_output - $ref: '#/components/schemas/codex.v1.CodexOutputTarget' - title: AgentRunArtifact - additionalProperties: false - description: AgentRunArtifact records durable output produced by a run or step. - agentruntime.v1.AgentRunCheckpoint: - type: object - properties: - id: - type: string - title: id - linkage: - title: linkage - $ref: '#/components/schemas/agentruntime.v1.AgentRunLinkage' - stepId: - type: string - title: step_id - sequence: - type: - - integer - - string - title: sequence - format: int64 - resumeToken: - type: string - title: resume_token - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Struct' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: AgentRunCheckpoint - additionalProperties: false - description: |- - AgentRunCheckpoint is an opaque resume snapshot. Workers can deserialize the - payload they own, restore local state, and continue from the next step. - agentruntime.v1.AgentRunCost: - type: object - properties: - id: - type: string - title: id - linkage: - title: linkage - $ref: '#/components/schemas/agentruntime.v1.AgentRunLinkage' - stepId: - type: string - title: step_id - meterRef: - type: string - title: meter_ref - provider: - type: string - title: provider - model: - type: string - title: model - inputTokens: - type: - - integer - - string - title: input_tokens - format: int64 - outputTokens: - type: - - integer - - string - title: output_tokens - format: int64 - totalTokens: - type: - - integer - - string - title: total_tokens - format: int64 - currency: - type: string - title: currency - estimatedCostMicros: - type: - - integer - - string - title: estimated_cost_micros - format: int64 - recordedAt: - title: recorded_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: AgentRunCost - additionalProperties: false - description: AgentRunCost records metering information associated with a run or step. - agentruntime.v1.AgentRunLease: - type: object - properties: - id: - type: string - title: id - linkage: - title: linkage - $ref: '#/components/schemas/agentruntime.v1.AgentRunLinkage' - workerId: - type: string - title: worker_id - token: - type: string - title: token - workerQueue: - type: string - title: worker_queue - attempt: - type: integer - title: attempt - format: int32 - claimedAt: - title: claimed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - heartbeatAt: - title: heartbeat_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: AgentRunLease - additionalProperties: false - description: AgentRunLease is the claim token a worker must present while mutating a run. - agentruntime.v1.AgentRunLinkage: - type: object - properties: - runId: - type: string - title: run_id - workspaceId: - type: string - title: workspace_id - agentId: - type: string - title: agent_id - objectiveId: - type: string - title: objective_id - title: AgentRunLinkage - additionalProperties: false - description: |- - AgentRunLinkage carries the shared identifiers every durable run record uses - for partitioning, authorization, and audit joins. - agentruntime.v1.AgentRunStep: - type: object - properties: - id: - type: string - title: id - linkage: - title: linkage - $ref: '#/components/schemas/agentruntime.v1.AgentRunLinkage' - name: - type: string - title: name - kind: - type: string - title: kind - deprecated: true - state: - title: state - $ref: '#/components/schemas/agentruntime.v1.AgentRunStepState' - attempt: - type: integer - title: attempt - format: int32 - input: - title: input - $ref: '#/components/schemas/google.protobuf.Struct' - output: - title: output - $ref: '#/components/schemas/google.protobuf.Struct' - errorMessage: - type: string - title: error_message - checkpointId: - type: string - title: checkpoint_id - startedAt: - title: started_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - endedAt: - title: ended_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - stepKind: - title: step_kind - $ref: '#/components/schemas/agentruntime.v1.AgentRunStepKind' - codexProgress: - title: codex_progress - $ref: '#/components/schemas/codex.v1.CodexRunProgress' - traceContext: - title: trace_context - $ref: '#/components/schemas/agentruntime.v1.RuntimeTraceContext' - title: AgentRunStep - additionalProperties: false - description: AgentRunStep is one durable unit of work within a run. - agentruntime.v1.AgentRunStreamCursor: - type: object - properties: - id: - type: string - title: id - linkage: - title: linkage - $ref: '#/components/schemas/agentruntime.v1.AgentRunLinkage' - consumer: - type: string - title: consumer - nextSequence: - type: - - integer - - string - title: next_sequence - format: int64 - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: AgentRunStreamCursor - additionalProperties: false - description: AgentRunStreamCursor stores a consumer cursor into the append-only event log. - agentruntime.v1.AgentRunWait: - type: object - properties: - id: - type: string - title: id - linkage: - title: linkage - $ref: '#/components/schemas/agentruntime.v1.AgentRunLinkage' - stepId: - type: string - title: step_id - type: - title: type - $ref: '#/components/schemas/agentruntime.v1.AgentRunWaitType' - externalRef: - type: string - title: external_ref - reason: - type: string - title: reason - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Struct' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - resumeAfter: - title: resume_after - $ref: '#/components/schemas/google.protobuf.Timestamp' - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - resolvedAt: - title: resolved_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - resolvedByEventId: - type: string - title: resolved_by_event_id - visibility: - title: visibility - $ref: '#/components/schemas/agentruntime.v1.RuntimeVisibilityMetadata' - codexInteraction: - title: codex_interaction - $ref: '#/components/schemas/codex.v1.CodexInteractionRequest' - title: AgentRunWait - additionalProperties: false - description: |- - AgentRunWait records a parked run. While active, the run has no lease and no - worker compute should be held. - agentruntime.v1.AgentRunWaitSummary: - type: object - properties: - runId: - type: string - title: run_id - waitId: - type: string - title: wait_id - workspaceId: - type: string - title: workspace_id - agentId: - type: string - title: agent_id - objectiveId: - type: string - title: objective_id - stepId: - type: string - title: step_id - type: - title: type - $ref: '#/components/schemas/agentruntime.v1.AgentRunWaitType' - state: - title: state - $ref: '#/components/schemas/agentruntime.v1.AgentRunWaitState' - externalRef: - type: string - title: external_ref - reason: - type: string - title: reason - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Struct' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - resumeAfter: - title: resume_after - $ref: '#/components/schemas/google.protobuf.Timestamp' - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - resolvedAt: - title: resolved_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - resolvedByEventId: - type: string - title: resolved_by_event_id - visibility: - title: visibility - $ref: '#/components/schemas/agentruntime.v1.RuntimeVisibilityMetadata' - channelContext: - title: channel_context - $ref: '#/components/schemas/agentruntime.v1.RuntimeChannelContext' - workEnvelope: - title: work_envelope - $ref: '#/components/schemas/agentruntime.v1.RuntimeWorkEnvelope' - title: AgentRunWaitSummary - additionalProperties: false - agentruntime.v1.AgentWorkItem: - type: object - properties: - id: - type: string - title: id - linkage: - title: linkage - $ref: '#/components/schemas/agentruntime.v1.AgentRunLinkage' - autonomySessionId: - type: string - title: autonomy_session_id - runId: - type: string - title: run_id - workEnvelopeId: - type: string - title: work_envelope_id - parentWorkItemId: - type: string - title: parent_work_item_id - ownerChildRunId: - type: string - title: owner_child_run_id - kind: - title: kind - $ref: '#/components/schemas/agentruntime.v1.AgentWorkItemKind' - state: - title: state - $ref: '#/components/schemas/agentruntime.v1.AgentWorkItemState' - title: - type: string - title: title - goal: - type: string - title: goal - nextAction: - type: string - title: next_action - blocker: - type: string - title: blocker - waitId: - type: string - title: wait_id - toolExecutionId: - type: string - title: tool_execution_id - evidenceRefs: - type: array - items: - type: string - title: evidence_refs - completionGate: - type: string - title: completion_gate - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Struct' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - startedAt: - title: started_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - completedAt: - title: completed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - failedAt: - title: failed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - cancelledAt: - title: cancelled_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: AgentWorkItem - additionalProperties: false - description: |- - AgentWorkItem is one node in the autonomous work graph. Workers and - reconcilers mutate this typed record directly; VFS ledgers are projections. - agentruntime.v1.ApplyRunVirtualFileTransactionRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - leaseToken: - type: string - title: lease_token - minLength: 1 - transactionId: - type: string - title: transaction_id - minLength: 1 - expectedParentRevisionId: - type: string - title: expected_parent_revision_id - approverId: - type: string - title: approver_id - metadata: - type: object - title: metadata - additionalProperties: - type: string - title: value - contextLines: - type: integer - title: context_lines - format: int32 - title: ApplyRunVirtualFileTransactionRequest - additionalProperties: false - agentruntime.v1.ApplyRunVirtualFileTransactionRequest.MetadataEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: MetadataEntry - additionalProperties: false - agentruntime.v1.ApplyRunVirtualFileTransactionResponse: - type: object - properties: - outcome: - title: outcome - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileTransactionOutcome' - diff: - title: diff - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileTransactionDiff' - run: - title: run - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - artifacts: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.AgentRunArtifact' - title: artifacts - files: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFile' - title: files - event: - title: event - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvent' - title: ApplyRunVirtualFileTransactionResponse - additionalProperties: false - agentruntime.v1.BatchReadRunVirtualFilesRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - selector: - title: selector - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileSelector' - perFileLimit: - type: integer - title: per_file_limit - format: int32 - totalLimit: - type: integer - title: total_limit - format: int32 - limit: - type: integer - title: limit - format: int32 - title: BatchReadRunVirtualFilesRequest - additionalProperties: false - agentruntime.v1.BatchReadRunVirtualFilesResponse: - type: object - properties: - files: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileReadResult' - title: files - totalContentBytes: - type: integer - title: total_content_bytes - format: int32 - budgetExhausted: - type: boolean - title: budget_exhausted - skippedCount: - type: integer - title: skipped_count - format: int32 - title: BatchReadRunVirtualFilesResponse - additionalProperties: false - agentruntime.v1.BuildRunVirtualFileContextPackRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - query: - type: string - title: query - selector: - title: selector - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileSelector' - seedPaths: - type: array - items: - type: string - title: seed_paths - perFileLimit: - type: integer - title: per_file_limit - format: int32 - totalLimit: - type: integer - title: total_limit - format: int32 - limit: - type: integer - title: limit - format: int32 - title: BuildRunVirtualFileContextPackRequest - additionalProperties: false - agentruntime.v1.BuildRunVirtualFileContextPackResponse: - type: object - properties: - snippets: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileReadResult' - title: snippets - totalContentBytes: - type: integer - title: total_content_bytes - format: int32 - budgetExhausted: - type: boolean - title: budget_exhausted - skippedCount: - type: integer - title: skipped_count - format: int32 - skippedPaths: - type: array - items: - type: string - title: skipped_paths - title: BuildRunVirtualFileContextPackResponse - additionalProperties: false - agentruntime.v1.CancelRunRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - reason: - type: string - title: reason - title: CancelRunRequest - additionalProperties: false - agentruntime.v1.CancelRunResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - event: - title: event - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvent' - title: CancelRunResponse - additionalProperties: false - agentruntime.v1.ChannelActionActor: - type: object - properties: - channelKind: - title: channel_kind - $ref: '#/components/schemas/agentruntime.v1.RuntimeChannelKind' - providerWorkspaceId: - type: string - title: provider_workspace_id - channelId: - type: string - title: channel_id - threadId: - type: string - title: thread_id - messageId: - type: string - title: message_id - actionId: - type: string - title: action_id - callbackId: - type: string - title: callback_id - actorChannelId: - type: string - title: actor_channel_id - actorEntityId: - type: string - title: actor_entity_id - principalId: - type: string - title: principal_id - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: ChannelActionActor - additionalProperties: false - description: |- - ChannelActionActor captures the channel coordinates and resolved platform - identity for the actor who submitted an action. - agentruntime.v1.ChannelActionActor.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - agentruntime.v1.ChannelActionReceipt: - type: object - properties: - id: - type: string - title: id - workspaceId: - type: string - title: workspace_id - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - requestHash: - type: string - title: request_hash - surfaceType: - title: surface_type - $ref: '#/components/schemas/common.v1.Surface' - actionKind: - title: action_kind - $ref: '#/components/schemas/agentruntime.v1.ChannelActionKind' - targetKind: - title: target_kind - $ref: '#/components/schemas/agentruntime.v1.ChannelActionTargetKind' - targetId: - type: string - title: target_id - runId: - type: string - title: run_id - waitId: - type: string - title: wait_id - approvalRequestId: - type: string - title: approval_request_id - objectiveId: - type: string - title: objective_id - actor: - title: actor - $ref: '#/components/schemas/agentruntime.v1.ChannelActionActor' - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Struct' - authorizationOutcome: - title: authorization_outcome - $ref: '#/components/schemas/agentruntime.v1.ChannelActionAuthorizationOutcome' - executionOutcome: - title: execution_outcome - $ref: '#/components/schemas/agentruntime.v1.ChannelActionExecutionOutcome' - deliveryOutcome: - title: delivery_outcome - $ref: '#/components/schemas/agentruntime.v1.ChannelActionDeliveryOutcome' - reason: - type: string - title: reason - errorReason: - type: string - title: error_reason - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - codexInteractionDecision: - title: codex_interaction_decision - $ref: '#/components/schemas/codex.v1.CodexInteractionDecision' - title: ChannelActionReceipt - additionalProperties: false - description: |- - ChannelActionReceipt is the durable audit and idempotency record for a - user-visible action submitted through a channel adapter. - agentruntime.v1.ChannelThreadAdoption: - type: object - properties: - id: - type: string - title: id - workspaceId: - type: string - title: workspace_id - minLength: 1 - agentId: - type: string - title: agent_id - minLength: 1 - channelKind: - title: channel_kind - $ref: '#/components/schemas/agentruntime.v1.RuntimeChannelKind' - providerWorkspaceId: - type: string - title: provider_workspace_id - channelId: - type: string - title: channel_id - minLength: 1 - threadId: - type: string - title: thread_id - minLength: 1 - workEnvelopeId: - type: string - title: work_envelope_id - firstAdoptedRunId: - type: string - title: first_adopted_run_id - lastRunId: - type: string - title: last_run_id - firstAdoptedAt: - title: first_adopted_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - lastMessageId: - type: string - title: last_message_id - lastSourceEventId: - type: string - title: last_source_event_id - lastAdoptionReason: - type: string - title: last_adoption_reason - adoptionPolicy: - type: string - title: adoption_policy - metadata: - title: metadata - $ref: '#/components/schemas/google.protobuf.Struct' - channelContext: - title: channel_context - $ref: '#/components/schemas/agentruntime.v1.RuntimeChannelContext' - workEnvelope: - title: work_envelope - $ref: '#/components/schemas/agentruntime.v1.RuntimeWorkEnvelope' - organizationId: - type: string - title: organization_id - minLength: 1 - description: |- - Tenant organization that owns this adoption row. Required for shared-runtime - isolation; storage uniqueness and list filters are organization-scoped. - title: ChannelThreadAdoption - additionalProperties: false - agentruntime.v1.ClaimNextRunRequest: - type: object - properties: - workerId: - type: string - title: worker_id - minLength: 1 - workerQueue: - type: string - title: worker_queue - leaseSeconds: - type: integer - title: lease_seconds - format: int32 - title: ClaimNextRunRequest - additionalProperties: false - agentruntime.v1.ClaimNextRunResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - lease: - title: lease - $ref: '#/components/schemas/agentruntime.v1.AgentRunLease' - events: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvent' - title: events - title: ClaimNextRunResponse - additionalProperties: false - agentruntime.v1.CompleteRunRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - leaseToken: - type: string - title: lease_token - minLength: 1 - result: - title: result - $ref: '#/components/schemas/google.protobuf.Struct' - checkpoint: - title: checkpoint - $ref: '#/components/schemas/agentruntime.v1.AgentRunCheckpoint' - title: CompleteRunRequest - additionalProperties: false - agentruntime.v1.CompleteRunResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - checkpoint: - title: checkpoint - $ref: '#/components/schemas/agentruntime.v1.AgentRunCheckpoint' - event: - title: event - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvent' - title: CompleteRunResponse - additionalProperties: false - agentruntime.v1.ControlRunRequest: - type: object - properties: - runId: - type: string - title: run_id - workspaceId: - type: string - title: workspace_id - agentId: - type: string - title: agent_id - workEnvelopeId: - type: string - title: work_envelope_id - autonomySessionId: - type: string - title: autonomy_session_id - mode: - title: mode - $ref: '#/components/schemas/agentruntime.v1.RunControlMode' - message: - type: string - title: message - idempotencyKey: - type: string - title: idempotency_key - channelContext: - title: channel_context - $ref: '#/components/schemas/agentruntime.v1.RuntimeChannelContext' - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Struct' - visibility: - title: visibility - $ref: '#/components/schemas/agentruntime.v1.RuntimeVisibilityMetadata' - title: ControlRunRequest - additionalProperties: false - agentruntime.v1.ControlRunResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - event: - title: event - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvent' - controlId: - type: string - title: control_id - cancelled: - type: boolean - title: cancelled - queuedForWorker: - type: boolean - title: queued_for_worker - title: ControlRunResponse - additionalProperties: false - agentruntime.v1.DeadLetterRunRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - reason: - type: string - title: reason - title: DeadLetterRunRequest - additionalProperties: false - agentruntime.v1.DeadLetterRunResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - event: - title: event - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvent' - title: DeadLetterRunResponse - additionalProperties: false - agentruntime.v1.DiffRunVirtualFileTransactionRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - transactionId: - type: string - title: transaction_id - minLength: 1 - contextLines: - type: integer - title: context_lines - format: int32 - title: DiffRunVirtualFileTransactionRequest - additionalProperties: false - agentruntime.v1.DiffRunVirtualFileTransactionResponse: - type: object - properties: - diff: - title: diff - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileTransactionDiff' - title: DiffRunVirtualFileTransactionResponse - additionalProperties: false - agentruntime.v1.EnsureOrganizationEmailRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - title: EnsureOrganizationEmailRequest - additionalProperties: false - description: Identity supplies these coordinates from its approved organization directory. - agentruntime.v1.EnsureOrganizationEmailResponse: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - mailbox: - type: string - title: mailbox - connectionId: - type: string - title: connection_id - title: EnsureOrganizationEmailResponse - additionalProperties: false - agentruntime.v1.FailRunRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - leaseToken: - type: string - title: lease_token - minLength: 1 - errorMessage: - type: string - title: error_message - minLength: 1 - retryable: - type: boolean - title: retryable - retryDelaySeconds: - type: integer - title: retry_delay_seconds - format: int32 - title: FailRunRequest - additionalProperties: false - agentruntime.v1.FailRunResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - event: - title: event - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvent' - title: FailRunResponse - additionalProperties: false - agentruntime.v1.GetChannelActionReceiptRequest: - type: object - properties: - id: - type: string - title: id - minLength: 1 - title: GetChannelActionReceiptRequest - additionalProperties: false - agentruntime.v1.GetChannelActionReceiptResponse: - type: object - properties: - receipt: - title: receipt - $ref: '#/components/schemas/agentruntime.v1.ChannelActionReceipt' - title: GetChannelActionReceiptResponse - additionalProperties: false - agentruntime.v1.GetChannelThreadAdoptionRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - agentId: - type: string - title: agent_id - minLength: 1 - channelKind: - title: channel_kind - $ref: '#/components/schemas/agentruntime.v1.RuntimeChannelKind' - providerWorkspaceId: - type: string - title: provider_workspace_id - channelId: - type: string - title: channel_id - minLength: 1 - threadId: - type: string - title: thread_id - minLength: 1 - includeExpired: - type: boolean - title: include_expired - organizationId: - type: string - title: organization_id - minLength: 1 - title: GetChannelThreadAdoptionRequest - additionalProperties: false - agentruntime.v1.GetChannelThreadAdoptionResponse: - type: object - properties: - adoption: - title: adoption - $ref: '#/components/schemas/agentruntime.v1.ChannelThreadAdoption' - title: GetChannelThreadAdoptionResponse - additionalProperties: false - agentruntime.v1.GetRunRequest: - type: object - properties: - id: - type: string - title: id - minLength: 1 - title: GetRunRequest - additionalProperties: false - agentruntime.v1.GetRunResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - title: GetRunResponse - additionalProperties: false - agentruntime.v1.GetTeammateWorkLedgerRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - title: GetTeammateWorkLedgerRequest - additionalProperties: false - agentruntime.v1.GetTeammateWorkLedgerResponse: - type: object - properties: - ledger: - title: ledger - $ref: '#/components/schemas/agentruntime.v1.TeammateWorkLedger' - ledgerFile: - title: ledger_file - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFile' - title: GetTeammateWorkLedgerResponse - additionalProperties: false - agentruntime.v1.HandleTriggerRequest: - type: object - properties: - trigger: - title: trigger - $ref: '#/components/schemas/agentruntime.v1.NormalizedTrigger' - title: HandleTriggerRequest - required: - - trigger - additionalProperties: false - agentruntime.v1.HandleTriggerResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - events: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvent' - title: events - idempotentReplay: - type: boolean - title: idempotent_replay - title: HandleTriggerResponse - additionalProperties: false - agentruntime.v1.HeartbeatRunRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - leaseToken: - type: string - title: lease_token - minLength: 1 - extendSeconds: - type: integer - title: extend_seconds - format: int32 - title: HeartbeatRunRequest - additionalProperties: false - agentruntime.v1.HeartbeatRunResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - lease: - title: lease - $ref: '#/components/schemas/agentruntime.v1.AgentRunLease' - event: - title: event - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvent' - title: HeartbeatRunResponse - additionalProperties: false - agentruntime.v1.HydrateRunVirtualFileMountRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - leaseToken: - type: string - title: lease_token - minLength: 1 - mount: - type: string - title: mount - minLength: 1 - providerId: - type: string - title: provider_id - connectionId: - type: string - title: connection_id - query: - type: string - title: query - limit: - type: integer - title: limit - format: int32 - metadata: - type: object - title: metadata - additionalProperties: - type: string - title: value - idempotencyKey: - type: string - title: idempotency_key - title: HydrateRunVirtualFileMountRequest - additionalProperties: false - agentruntime.v1.HydrateRunVirtualFileMountRequest.MetadataEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: MetadataEntry - additionalProperties: false - agentruntime.v1.HydrateRunVirtualFileMountResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - artifacts: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.AgentRunArtifact' - title: artifacts - files: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFile' - title: files - event: - title: event - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvent' - title: HydrateRunVirtualFileMountResponse - additionalProperties: false - agentruntime.v1.InspectRunVirtualFilesRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - title: InspectRunVirtualFilesRequest - additionalProperties: false - agentruntime.v1.InspectRunVirtualFilesResponse: - type: object - properties: - summary: - title: summary - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileInspectorSummary' - mounts: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileInspectorMount' - title: mounts - transactions: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileInspectorTransaction' - title: transactions - entries: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileEntry' - title: entries - producers: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileInspectorProducer' - title: producers - title: InspectRunVirtualFilesResponse - additionalProperties: false - agentruntime.v1.ListChannelActionReceiptsRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - actorEntityId: - type: string - title: actor_entity_id - targetKind: - title: target_kind - $ref: '#/components/schemas/agentruntime.v1.ChannelActionTargetKind' - targetId: - type: string - title: target_id - runId: - type: string - title: run_id - waitId: - type: string - title: wait_id - approvalRequestId: - type: string - title: approval_request_id - objectiveId: - type: string - title: objective_id - channelKind: - title: channel_kind - $ref: '#/components/schemas/agentruntime.v1.RuntimeChannelKind' - providerWorkspaceId: - type: string - title: provider_workspace_id - channelId: - type: string - title: channel_id - threadId: - type: string - title: thread_id - messageId: - type: string - title: message_id - actionId: - type: string - title: action_id - limit: - type: integer - title: limit - format: int32 - title: ListChannelActionReceiptsRequest - additionalProperties: false - agentruntime.v1.ListChannelActionReceiptsResponse: - type: object - properties: - receipts: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.ChannelActionReceipt' - title: receipts - title: ListChannelActionReceiptsResponse - additionalProperties: false - agentruntime.v1.ListChannelThreadAdoptionsRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - agentId: - type: string - title: agent_id - channelKind: - title: channel_kind - $ref: '#/components/schemas/agentruntime.v1.RuntimeChannelKind' - providerWorkspaceId: - type: string - title: provider_workspace_id - channelId: - type: string - title: channel_id - threadId: - type: string - title: thread_id - workEnvelopeId: - type: string - title: work_envelope_id - includeExpired: - type: boolean - title: include_expired - limit: - type: integer - title: limit - format: int32 - organizationId: - type: string - title: organization_id - minLength: 1 - description: |- - Organization scope for list filtering. Required so a shared Agent Runtime - database cannot return another tenant's adoption projection for a reused - workspace id. - title: ListChannelThreadAdoptionsRequest - additionalProperties: false - agentruntime.v1.ListChannelThreadAdoptionsResponse: - type: object - properties: - adoptions: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.ChannelThreadAdoption' - title: adoptions - title: ListChannelThreadAdoptionsResponse - additionalProperties: false - agentruntime.v1.ListRunEventsRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - audience: - title: audience - $ref: '#/components/schemas/agentruntime.v1.RuntimeAudience' - pageSize: - type: integer - title: page_size - format: int32 - pageToken: - type: string - title: page_token - title: ListRunEventsRequest - additionalProperties: false - agentruntime.v1.ListRunEventsResponse: - type: object - properties: - events: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvent' - title: events - nextPageToken: - type: string - title: next_page_token - title: ListRunEventsResponse - additionalProperties: false - agentruntime.v1.ListRunVirtualFilesRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - pathPrefix: - type: string - title: path_prefix - limit: - type: integer - title: limit - format: int32 - includeTombstones: - type: boolean - title: include_tombstones - title: ListRunVirtualFilesRequest - additionalProperties: false - agentruntime.v1.ListRunVirtualFilesResponse: - type: object - properties: - entries: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileEntry' - title: entries - title: ListRunVirtualFilesResponse - additionalProperties: false - agentruntime.v1.ListRunWaitsRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - runId: - type: string - title: run_id - agentId: - type: string - title: agent_id - objectiveId: - type: string - title: objective_id - workEnvelopeId: - type: string - title: work_envelope_id - state: - title: state - $ref: '#/components/schemas/agentruntime.v1.AgentRunWaitState' - type: - title: type - $ref: '#/components/schemas/agentruntime.v1.AgentRunWaitType' - audience: - title: audience - $ref: '#/components/schemas/agentruntime.v1.RuntimeAudience' - limit: - type: integer - title: limit - format: int32 - pageToken: - type: string - title: page_token - externalRef: - type: string - title: external_ref - description: |- - external_ref filters waits by their external join key, such as an - approvals.v1 ApprovalRequest id carried by desktop-control approval waits. - title: ListRunWaitsRequest - additionalProperties: false - agentruntime.v1.ListRunWaitsResponse: - type: object - properties: - waits: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.AgentRunWaitSummary' - title: waits - nextPageToken: - type: string - title: next_page_token - title: ListRunWaitsResponse - additionalProperties: false - agentruntime.v1.ListRunWorkItemsRequest: - type: object - properties: - runId: - type: string - title: run_id - workspaceId: - type: string - title: workspace_id - workEnvelopeId: - type: string - title: work_envelope_id - autonomySessionId: - type: string - title: autonomy_session_id - state: - title: state - $ref: '#/components/schemas/agentruntime.v1.AgentWorkItemState' - limit: - type: integer - title: limit - format: int32 - title: ListRunWorkItemsRequest - additionalProperties: false - agentruntime.v1.ListRunWorkItemsResponse: - type: object - properties: - workItems: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.AgentWorkItem' - title: work_items - title: ListRunWorkItemsResponse - additionalProperties: false - agentruntime.v1.ListRunsByWorkEnvelopeRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - workEnvelopeId: - type: string - title: work_envelope_id - minLength: 1 - limit: - type: integer - title: limit - format: int32 - title: ListRunsByWorkEnvelopeRequest - additionalProperties: false - agentruntime.v1.ListRunsByWorkEnvelopeResponse: - type: object - properties: - runs: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - title: runs - title: ListRunsByWorkEnvelopeResponse - additionalProperties: false - agentruntime.v1.NativeAgentEventEvidence: - type: object - properties: - evidenceState: - title: evidence_state - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvidenceState' - principalEvidenceState: - title: principal_evidence_state - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvidenceState' - credentialEvidenceState: - title: credential_evidence_state - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvidenceState' - costEvidenceState: - title: cost_evidence_state - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvidenceState' - nativeSource: - title: native_source - $ref: '#/components/schemas/agentruntime.v1.NativeAgentEventSource' - nativeKind: - type: string - title: native_kind - minLength: 1 - sourceEventId: - type: string - title: source_event_id - minLength: 1 - sourceEventType: - type: string - title: source_event_type - minLength: 1 - sourceEventTime: - title: source_event_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - tenantId: - type: string - title: tenant_id - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - minLength: 1 - sessionId: - type: string - title: session_id - agentRunId: - type: string - title: agent_run_id - minLength: 1 - agentRunStepId: - type: string - title: agent_run_step_id - agentId: - type: string - title: agent_id - actorId: - type: string - title: actor_id - principalId: - type: string - title: principal_id - threadId: - type: string - title: thread_id - turnId: - type: string - title: turn_id - traceId: - type: string - title: trace_id - requestId: - type: string - title: request_id - responseId: - type: string - title: response_id - parentEventId: - type: string - title: parent_event_id - toolCallId: - type: string - title: tool_call_id - toolExecutionId: - type: string - title: tool_execution_id - actionId: - type: string - title: action_id - toolNamespace: - type: string - title: tool_namespace - toolName: - type: string - title: tool_name - toolVersion: - type: string - title: tool_version - capability: - type: string - title: capability - connectorId: - type: string - title: connector_id - mutatesResource: - type: boolean - title: mutates_resource - riskLevel: - title: risk_level - $ref: '#/components/schemas/common.v1.RiskLevel' - argumentsRedacted: - type: boolean - title: arguments_redacted - outputRedacted: - type: boolean - title: output_redacted - safeArgumentsRef: - type: string - title: safe_arguments_ref - safeArgumentsSha256: - type: string - title: safe_arguments_sha256 - safeArgumentsKeyCount: - type: integer - title: safe_arguments_key_count - format: int32 - safeOutputRef: - type: string - title: safe_output_ref - safeOutputSha256: - type: string - title: safe_output_sha256 - safeOutputKeyCount: - type: integer - title: safe_output_key_count - format: int32 - redactionCount: - type: integer - title: redaction_count - format: int32 - redactions: - type: array - items: - type: string - title: redactions - evidenceGaps: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvidenceGap' - title: evidence_gaps - schema: - type: string - title: schema - minLength: 1 - title: NativeAgentEventEvidence - required: - - sourceEventTime - additionalProperties: false - description: |- - NativeAgentEventEvidence is the typed receipt primitive for safe native - Agent Workforce events from Maestro and Codex. It carries source/correlation - identifiers, redaction metadata, and safe refs only; raw prompts, tool - arguments, shell output, MCP result bodies, image bytes, transcripts, token - values, provider response bodies, and credential grants must not be copied - here. - agentruntime.v1.NativeToolAttemptEvidence: - type: object - properties: - evidenceState: - title: evidence_state - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvidenceState' - credentialEvidenceState: - title: credential_evidence_state - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvidenceState' - nativeKind: - type: string - title: native_kind - minLength: 1 - sourceEventId: - type: string - title: source_event_id - minLength: 1 - sourceEventType: - type: string - title: source_event_type - sourceEventSource: - type: string - title: source_event_source - sourceEventSubject: - type: string - title: source_event_subject - tenantId: - type: string - title: tenant_id - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - minLength: 1 - sessionId: - type: string - title: session_id - agentRunId: - type: string - title: agent_run_id - minLength: 1 - agentRunStepId: - type: string - title: agent_run_step_id - agentId: - type: string - title: agent_id - actorId: - type: string - title: actor_id - principalId: - type: string - title: principal_id - traceId: - type: string - title: trace_id - requestId: - type: string - title: request_id - responseId: - type: string - title: response_id - parentEventId: - type: string - title: parent_event_id - toolCallId: - type: string - title: tool_call_id - minLength: 1 - toolExecutionId: - type: string - title: tool_execution_id - toolNamespace: - type: string - title: tool_namespace - toolName: - type: string - title: tool_name - minLength: 1 - toolVersion: - type: string - title: tool_version - capability: - type: string - title: capability - connectorId: - type: string - title: connector_id - mutatesResource: - type: boolean - title: mutates_resource - riskLevel: - title: risk_level - $ref: '#/components/schemas/common.v1.RiskLevel' - argumentsRedacted: - type: boolean - title: arguments_redacted - safeArgumentsRef: - type: string - title: safe_arguments_ref - safeArgumentsSha256: - type: string - title: safe_arguments_sha256 - safeArgumentsKeyCount: - type: integer - title: safe_arguments_key_count - format: int32 - redactionCount: - type: integer - title: redaction_count - format: int32 - redactions: - type: array - items: - type: string - title: redactions - evidenceGaps: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvidenceGap' - title: evidence_gaps - sourceEventTime: - title: source_event_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - principalEvidenceState: - title: principal_evidence_state - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvidenceState' - costEvidenceState: - title: cost_evidence_state - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvidenceState' - title: NativeToolAttemptEvidence - additionalProperties: false - description: |- - NativeToolAttemptEvidence is the typed Platform primitive for answering - "What did the agent try to do?" from a native Maestro/Codex tool-attempt - event. It intentionally carries only redaction-safe identifiers, summaries, - and digest references; raw prompts, tool arguments, and credential grants - must not be copied here. - agentruntime.v1.NormalizedTrigger: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - agentId: - type: string - title: agent_id - minLength: 1 - surface: - type: string - title: surface - deprecated: true - channelId: - type: string - title: channel_id - description: |- - Deprecated flat channel field. New callers should send channel_context; - the runtime normalizes this field for legacy consumers and idempotency - joins. - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - sourceEventId: - type: string - title: source_event_id - sourceEventType: - type: string - title: source_event_type - deprecated: true - actorId: - type: string - title: actor_id - correlationId: - type: string - title: correlation_id - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Struct' - receivedAt: - title: received_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - surfaceType: - title: surface_type - $ref: '#/components/schemas/common.v1.Surface' - channelContext: - title: channel_context - $ref: '#/components/schemas/agentruntime.v1.RuntimeChannelContext' - triggerKind: - title: trigger_kind - $ref: '#/components/schemas/agentruntime.v1.RuntimeTriggerKind' - workEnvelope: - title: work_envelope - $ref: '#/components/schemas/agentruntime.v1.RuntimeWorkEnvelope' - codexWork: - title: codex_work - $ref: '#/components/schemas/codex.v1.CodexWorkRequest' - proactiveContext: - title: proactive_context - $ref: '#/components/schemas/agentruntime.v1.RuntimeProactiveContext' - objectiveId: - type: string - title: objective_id - description: |- - objective_id binds a trigger to an already-created Objective. Console and - other product surfaces use this when the user message first creates the - Objective, so AgentRuntime does not have to rediscover the active goal. - organizationId: - type: string - title: organization_id - minLength: 1 - title: NormalizedTrigger - additionalProperties: false - description: |- - NormalizedTrigger is the source-neutral trigger contract. Surface is an enum - so product callers share one durable taxonomy across Slack, Ensemble, Chat, - Maestro, and Conductor. The legacy string field remains for wire-compatible - migration of early callers. - agentruntime.v1.OperatingChannelAttachmentMetadata: - type: object - properties: - providerAttachmentId: - type: string - title: provider_attachment_id - minLength: 1 - kind: - type: string - title: kind - mediaType: - type: string - title: media_type - name: - type: string - title: name - sizeBytes: - type: - - integer - - string - title: size_bytes - format: int64 - title: OperatingChannelAttachmentMetadata - additionalProperties: false - description: |- - Safe attachment metadata accepted from a channel edge. Provider download - URLs, credentials, and raw attachment bodies are intentionally excluded. - agentruntime.v1.OperatingChannelContextEntity: - type: object - properties: - kind: - title: kind - $ref: '#/components/schemas/agentruntime.v1.OperatingChannelContextEntityKind' - providerWorkspaceId: - type: string - title: provider_workspace_id - maxLength: 512 - minLength: 1 - providerChannelId: - type: string - title: provider_channel_id - maxLength: 512 - providerMessageId: - type: string - title: provider_message_id - maxLength: 512 - providerResourceId: - type: string - title: provider_resource_id - maxLength: 512 - title: OperatingChannelContextEntity - additionalProperties: false - agentruntime.v1.OperatingChannelEmailMetadata: - type: object - properties: - mailbox: - type: string - title: mailbox - maxLength: 254 - sender: - type: string - title: sender - maxLength: 254 - subject: - type: string - title: subject - maxLength: 512 - title: OperatingChannelEmailMetadata - additionalProperties: false - description: |- - Email reply coordinates authenticated by the email edge and validated against - the resolved mailbox installation before persistence. Never model authority. - agentruntime.v1.OperatingChannelInteraction: - type: object - properties: - actionId: - type: string - title: action_id - maxLength: 128 - minLength: 1 - actionToken: - type: string - title: action_token - maxLength: 4096 - minLength: 1 - actionTimestamp: - type: string - title: action_timestamp - maxLength: 64 - minLength: 1 - title: OperatingChannelInteraction - additionalProperties: false - description: |- - A bounded interactive action submitted by a signed channel edge. The token - is opaque to the edge and must be validated by Platform before it resolves - any canonical receipt, question, or session control. - agentruntime.v1.PromoteRunVirtualFileTransactionRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - leaseToken: - type: string - title: lease_token - minLength: 1 - transactionId: - type: string - title: transaction_id - minLength: 1 - expectedParentRevisionId: - type: string - title: expected_parent_revision_id - approverId: - type: string - title: approver_id - metadata: - type: object - title: metadata - additionalProperties: - type: string - title: value - title: PromoteRunVirtualFileTransactionRequest - additionalProperties: false - agentruntime.v1.PromoteRunVirtualFileTransactionRequest.MetadataEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: MetadataEntry - additionalProperties: false - agentruntime.v1.PromoteRunVirtualFileTransactionResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - artifacts: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.AgentRunArtifact' - title: artifacts - files: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFile' - title: files - event: - title: event - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvent' - title: PromoteRunVirtualFileTransactionResponse - additionalProperties: false - agentruntime.v1.ReadRunVirtualFileRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - path: - type: string - title: path - minLength: 1 - offset: - type: integer - title: offset - format: int32 - limit: - type: integer - title: limit - format: int32 - includeTombstones: - type: boolean - title: include_tombstones - title: ReadRunVirtualFileRequest - additionalProperties: false - agentruntime.v1.ReadRunVirtualFileResponse: - type: object - properties: - entry: - title: entry - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileEntry' - content: - type: string - title: content - offset: - type: integer - title: offset - format: int32 - nextOffset: - type: integer - title: next_offset - format: int32 - eof: - type: boolean - title: eof - redactionState: - title: redaction_state - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileRedactionState' - redactions: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeRedaction' - title: redactions - title: ReadRunVirtualFileResponse - additionalProperties: false - agentruntime.v1.RebaseRunVirtualFileTransactionRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - leaseToken: - type: string - title: lease_token - minLength: 1 - sourceTransactionId: - type: string - title: source_transaction_id - minLength: 1 - transactionId: - type: string - title: transaction_id - metadata: - type: object - title: metadata - additionalProperties: - type: string - title: value - idempotencyKey: - type: string - title: idempotency_key - contextLines: - type: integer - title: context_lines - format: int32 - title: RebaseRunVirtualFileTransactionRequest - additionalProperties: false - agentruntime.v1.RebaseRunVirtualFileTransactionRequest.MetadataEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: MetadataEntry - additionalProperties: false - agentruntime.v1.RebaseRunVirtualFileTransactionResponse: - type: object - properties: - outcome: - title: outcome - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileTransactionOutcome' - sourceTransactionId: - type: string - title: source_transaction_id - transactionId: - type: string - title: transaction_id - diff: - title: diff - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileTransactionDiff' - run: - title: run - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - artifacts: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.AgentRunArtifact' - title: artifacts - files: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFile' - title: files - event: - title: event - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvent' - title: RebaseRunVirtualFileTransactionResponse - additionalProperties: false - agentruntime.v1.RecordChannelActionReceiptRequest: - type: object - properties: - receipt: - title: receipt - $ref: '#/components/schemas/agentruntime.v1.ChannelActionReceipt' - title: RecordChannelActionReceiptRequest - required: - - receipt - additionalProperties: false - agentruntime.v1.RecordChannelActionReceiptResponse: - type: object - properties: - receipt: - title: receipt - $ref: '#/components/schemas/agentruntime.v1.ChannelActionReceipt' - idempotentReplay: - type: boolean - title: idempotent_replay - title: RecordChannelActionReceiptResponse - additionalProperties: false - agentruntime.v1.RecordChannelThreadAdoptionRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - agentId: - type: string - title: agent_id - minLength: 1 - channelKind: - title: channel_kind - $ref: '#/components/schemas/agentruntime.v1.RuntimeChannelKind' - providerWorkspaceId: - type: string - title: provider_workspace_id - channelId: - type: string - title: channel_id - minLength: 1 - threadId: - type: string - title: thread_id - minLength: 1 - messageId: - type: string - title: message_id - sourceEventId: - type: string - title: source_event_id - adoptionReason: - type: string - title: adoption_reason - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - workEnvelopeId: - type: string - title: work_envelope_id - metadata: - title: metadata - $ref: '#/components/schemas/google.protobuf.Struct' - organizationId: - type: string - title: organization_id - minLength: 1 - title: RecordChannelThreadAdoptionRequest - additionalProperties: false - agentruntime.v1.RecordChannelThreadAdoptionResponse: - type: object - properties: - adoption: - title: adoption - $ref: '#/components/schemas/agentruntime.v1.ChannelThreadAdoption' - title: RecordChannelThreadAdoptionResponse - additionalProperties: false - agentruntime.v1.RecordRunArtifactRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - leaseToken: - type: string - title: lease_token - minLength: 1 - artifact: - title: artifact - $ref: '#/components/schemas/agentruntime.v1.AgentRunArtifact' - title: RecordRunArtifactRequest - required: - - artifact - additionalProperties: false - agentruntime.v1.RecordRunArtifactResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - artifact: - title: artifact - $ref: '#/components/schemas/agentruntime.v1.AgentRunArtifact' - event: - title: event - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvent' - title: RecordRunArtifactResponse - additionalProperties: false - agentruntime.v1.RecordRunCheckpointRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - leaseToken: - type: string - title: lease_token - minLength: 1 - checkpoint: - title: checkpoint - $ref: '#/components/schemas/agentruntime.v1.AgentRunCheckpoint' - title: RecordRunCheckpointRequest - required: - - checkpoint - additionalProperties: false - agentruntime.v1.RecordRunCheckpointResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - checkpoint: - title: checkpoint - $ref: '#/components/schemas/agentruntime.v1.AgentRunCheckpoint' - event: - title: event - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvent' - title: RecordRunCheckpointResponse - additionalProperties: false - agentruntime.v1.RecordRunCostRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - leaseToken: - type: string - title: lease_token - minLength: 1 - cost: - title: cost - $ref: '#/components/schemas/agentruntime.v1.AgentRunCost' - title: RecordRunCostRequest - required: - - cost - additionalProperties: false - agentruntime.v1.RecordRunCostResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - cost: - title: cost - $ref: '#/components/schemas/agentruntime.v1.AgentRunCost' - event: - title: event - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvent' - title: RecordRunCostResponse - additionalProperties: false - agentruntime.v1.RecordRunEventRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - type: - title: type - $ref: '#/components/schemas/agentruntime.v1.RuntimeEventType' - message: - type: string - title: message - minLength: 1 - attributes: - title: attributes - $ref: '#/components/schemas/google.protobuf.Struct' - stepId: - type: string - title: step_id - checkpointId: - type: string - title: checkpoint_id - artifactId: - type: string - title: artifact_id - costId: - type: string - title: cost_id - waitId: - type: string - title: wait_id - visibility: - title: visibility - $ref: '#/components/schemas/agentruntime.v1.RuntimeVisibilityMetadata' - nativeToolAttempt: - title: native_tool_attempt - $ref: '#/components/schemas/agentruntime.v1.NativeToolAttemptEvidence' - nativeAgentEvent: - title: native_agent_event - $ref: '#/components/schemas/agentruntime.v1.NativeAgentEventEvidence' - title: RecordRunEventRequest - additionalProperties: false - agentruntime.v1.RecordRunEventResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - event: - title: event - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvent' - title: RecordRunEventResponse - additionalProperties: false - agentruntime.v1.RecordRunStepRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - leaseToken: - type: string - title: lease_token - minLength: 1 - step: - title: step - $ref: '#/components/schemas/agentruntime.v1.AgentRunStep' - title: RecordRunStepRequest - required: - - step - additionalProperties: false - agentruntime.v1.RecordRunStepResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - step: - title: step - $ref: '#/components/schemas/agentruntime.v1.AgentRunStep' - event: - title: event - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvent' - title: RecordRunStepResponse - additionalProperties: false - agentruntime.v1.RecordRunStreamCursorRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - cursor: - title: cursor - $ref: '#/components/schemas/agentruntime.v1.AgentRunStreamCursor' - title: RecordRunStreamCursorRequest - required: - - cursor - additionalProperties: false - agentruntime.v1.RecordRunStreamCursorResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - cursor: - title: cursor - $ref: '#/components/schemas/agentruntime.v1.AgentRunStreamCursor' - event: - title: event - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvent' - title: RecordRunStreamCursorResponse - additionalProperties: false - agentruntime.v1.RecordRunVirtualFileProposalRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - leaseToken: - type: string - title: lease_token - minLength: 1 - path: - type: string - title: path - minLength: 1 - mediaType: - type: string - title: media_type - content: - type: string - title: content - proposalKind: - type: string - title: proposal_kind - stepId: - type: string - title: step_id - metadata: - type: object - title: metadata - additionalProperties: - type: string - title: value - idempotencyKey: - type: string - title: idempotency_key - sensitivity: - title: sensitivity - $ref: '#/components/schemas/agentruntime.v1.RuntimeSensitivity' - redactionState: - title: redaction_state - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileRedactionState' - redactions: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeRedaction' - title: redactions - title: RecordRunVirtualFileProposalRequest - additionalProperties: false - agentruntime.v1.RecordRunVirtualFileProposalRequest.MetadataEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: MetadataEntry - additionalProperties: false - agentruntime.v1.RecordRunVirtualFileProposalResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - artifact: - title: artifact - $ref: '#/components/schemas/agentruntime.v1.AgentRunArtifact' - file: - title: file - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFile' - event: - title: event - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvent' - title: RecordRunVirtualFileProposalResponse - additionalProperties: false - agentruntime.v1.RecordRunVirtualFileTransactionRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - leaseToken: - type: string - title: lease_token - minLength: 1 - transactionId: - type: string - title: transaction_id - parentRevisionId: - type: string - title: parent_revision_id - changes: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileChange' - title: changes - metadata: - type: object - title: metadata - additionalProperties: - type: string - title: value - idempotencyKey: - type: string - title: idempotency_key - title: RecordRunVirtualFileTransactionRequest - additionalProperties: false - agentruntime.v1.RecordRunVirtualFileTransactionRequest.MetadataEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: MetadataEntry - additionalProperties: false - agentruntime.v1.RecordRunVirtualFileTransactionResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - artifacts: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.AgentRunArtifact' - title: artifacts - files: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFile' - title: files - event: - title: event - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvent' - title: RecordRunVirtualFileTransactionResponse - additionalProperties: false - agentruntime.v1.RecordRunWorkItemRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - workItem: - title: work_item - $ref: '#/components/schemas/agentruntime.v1.AgentWorkItem' - title: RecordRunWorkItemRequest - required: - - workItem - additionalProperties: false - agentruntime.v1.RecordRunWorkItemResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - workItem: - title: work_item - $ref: '#/components/schemas/agentruntime.v1.AgentWorkItem' - event: - title: event - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvent' - title: RecordRunWorkItemResponse - additionalProperties: false - agentruntime.v1.RenewRunLeaseRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - leaseToken: - type: string - title: lease_token - minLength: 1 - extendSeconds: - type: integer - title: extend_seconds - format: int32 - title: RenewRunLeaseRequest - additionalProperties: false - agentruntime.v1.RenewRunLeaseResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - lease: - title: lease - $ref: '#/components/schemas/agentruntime.v1.AgentRunLease' - event: - title: event - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvent' - renewedAfterExpiry: - type: boolean - title: renewed_after_expiry - title: RenewRunLeaseResponse - additionalProperties: false - agentruntime.v1.ResumeRunRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - waitId: - type: string - title: wait_id - minLength: 1 - resumeEventId: - type: string - title: resume_event_id - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Struct' - codexInteractionDecision: - title: codex_interaction_decision - $ref: '#/components/schemas/codex.v1.CodexInteractionDecision' - title: ResumeRunRequest - additionalProperties: false - agentruntime.v1.ResumeRunResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - event: - title: event - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvent' - title: ResumeRunResponse - additionalProperties: false - agentruntime.v1.RetryRunRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - retryDelaySeconds: - type: integer - title: retry_delay_seconds - format: int32 - reason: - type: string - title: reason - title: RetryRunRequest - additionalProperties: false - agentruntime.v1.RetryRunResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - event: - title: event - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvent' - title: RetryRunResponse - additionalProperties: false - agentruntime.v1.RuntimeCalendarEventCoordinates: - type: object - properties: - connectionId: - type: string - title: connection_id - minLength: 1 - calendarId: - type: string - title: calendar_id - minLength: 1 - eventId: - type: string - title: event_id - minLength: 1 - recurringSeriesId: - type: string - title: recurring_series_id - recurringInstanceId: - type: string - title: recurring_instance_id - providerRevision: - type: string - title: provider_revision - title: RuntimeCalendarEventCoordinates - additionalProperties: false - description: RuntimeCalendarEventCoordinates identifies one event or recurring instance. - agentruntime.v1.RuntimeCerebroFactsContext: - type: object - properties: - provider: - type: string - title: provider - workspaceId: - type: string - title: workspace_id - query: - type: string - title: query - thingIds: - type: array - items: - type: string - title: thing_ids - factIds: - type: array - items: - type: string - title: fact_ids - eventIds: - type: array - items: - type: string - title: event_ids - sourceHealthSummary: - title: source_health_summary - $ref: '#/components/schemas/agentruntime.v1.RuntimeSourceHealthSummary' - beliefDebugSummary: - type: string - title: belief_debug_summary - rolloutId: - type: string - title: rollout_id - rolloutSummary: - type: string - title: rollout_summary - rolloutResult: - type: string - title: rollout_result - retrievalCounts: - type: object - title: retrieval_counts - additionalProperties: - type: - - integer - - string - title: value - format: int64 - title: RuntimeCerebroFactsContext - additionalProperties: false - description: |- - RuntimeCerebroFactsContext carries the identifiers and retrieval counts that - let AgentRuntime, Ensemble, and operators trace a proactive run back to - Cerebro without parsing payload maps. - agentruntime.v1.RuntimeCerebroFactsContext.RetrievalCountsEntry: - type: object - properties: - key: - type: string - title: key - value: - type: - - integer - - string - title: value - format: int64 - title: RetrievalCountsEntry - additionalProperties: false - agentruntime.v1.RuntimeChannelContext: - type: object - oneOf: - - properties: - calendar: - title: calendar - $ref: '#/components/schemas/agentruntime.v1.RuntimeCalendarEventCoordinates' - title: calendar - required: - - calendar - - properties: - email: - title: email - $ref: '#/components/schemas/agentruntime.v1.RuntimeEmailThreadCoordinates' - title: email - required: - - email - - properties: - slack: - title: slack - $ref: '#/components/schemas/agentruntime.v1.RuntimeSlackThreadCoordinates' - title: slack - required: - - slack - - properties: - teams: - title: teams - $ref: '#/components/schemas/agentruntime.v1.RuntimeTeamsThreadCoordinates' - title: teams - required: - - teams - - properties: - web: - title: web - $ref: '#/components/schemas/agentruntime.v1.RuntimeWebConversationCoordinates' - title: web - required: - - web - - properties: - whatsapp: - title: whatsapp - $ref: '#/components/schemas/agentruntime.v1.RuntimeWhatsAppConversationCoordinates' - title: whatsapp - required: - - whatsapp - properties: - calendar: - title: calendar - $ref: '#/components/schemas/agentruntime.v1.RuntimeCalendarEventCoordinates' - email: - title: email - $ref: '#/components/schemas/agentruntime.v1.RuntimeEmailThreadCoordinates' - slack: - title: slack - $ref: '#/components/schemas/agentruntime.v1.RuntimeSlackThreadCoordinates' - teams: - title: teams - $ref: '#/components/schemas/agentruntime.v1.RuntimeTeamsThreadCoordinates' - web: - title: web - $ref: '#/components/schemas/agentruntime.v1.RuntimeWebConversationCoordinates' - whatsapp: - title: whatsapp - $ref: '#/components/schemas/agentruntime.v1.RuntimeWhatsAppConversationCoordinates' - channelKind: - title: channel_kind - $ref: '#/components/schemas/agentruntime.v1.RuntimeChannelKind' - providerWorkspaceId: - type: string - title: provider_workspace_id - channelId: - type: string - title: channel_id - threadId: - type: string - title: thread_id - messageId: - type: string - title: message_id - actorId: - type: string - title: actor_id - description: |- - Deprecated overloaded actor field. New Slack and channel adapters should - set actor_channel_id for the provider-local respondent, actor_entity_id for - the resolved canonical entity, and principal_id for the authenticated - platform principal when available. - permalink: - type: string - title: permalink - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - actorChannelId: - type: string - title: actor_channel_id - actorEntityId: - type: string - title: actor_entity_id - principalId: - type: string - title: principal_id - title: RuntimeChannelContext - additionalProperties: false - description: |- - RuntimeChannelContext carries stable channel coordinates for channel - adapters. Slack teammates use provider_workspace_id for team_id, channel_id - for the conversation, thread_id for the Slack thread_ts, and message_id for - the triggering message/event timestamp. - agentruntime.v1.RuntimeChannelContext.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - agentruntime.v1.RuntimeContext: - type: object - properties: - dependencies: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeDependency' - title: dependencies - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - virtualFiles: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFile' - title: virtual_files - teammateCapabilityProfile: - title: teammate_capability_profile - description: |- - Typed profile for persistent teammate runtime capabilities. Workers and - channel renderers should use this field as the source of truth; any VFS - JSON projection is only a compatibility/read surface. - $ref: '#/components/schemas/agentruntime.v1.TeammateCapabilityProfile' - title: RuntimeContext - additionalProperties: false - description: RuntimeContext captures the boundary decisions used to construct a run. - agentruntime.v1.RuntimeContext.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - agentruntime.v1.RuntimeDependency: - type: object - properties: - service: - type: string - title: service - minLength: 1 - purpose: - type: string - title: purpose - required: - type: boolean - title: required - status: - type: string - title: status - deprecated: true - referenceId: - type: string - title: reference_id - statusType: - title: status_type - $ref: '#/components/schemas/agentruntime.v1.RuntimeDependencyStatus' - title: RuntimeDependency - additionalProperties: false - description: RuntimeDependency names one platform service boundary the runtime depends on. - agentruntime.v1.RuntimeEmailThreadCoordinates: - type: object - properties: - connectionId: - type: string - title: connection_id - minLength: 1 - mailboxId: - type: string - title: mailbox_id - minLength: 1 - threadId: - type: string - title: thread_id - minLength: 1 - messageId: - type: string - title: message_id - providerRevision: - type: string - title: provider_revision - title: RuntimeEmailThreadCoordinates - additionalProperties: false - description: RuntimeEmailThreadCoordinates identifies one provider mailbox thread. - agentruntime.v1.RuntimeEvent: - type: object - properties: - id: - type: string - title: id - runId: - type: string - title: run_id - sequence: - type: - - integer - - string - title: sequence - format: int64 - type: - title: type - $ref: '#/components/schemas/agentruntime.v1.RuntimeEventType' - message: - type: string - title: message - attributes: - title: attributes - $ref: '#/components/schemas/google.protobuf.Struct' - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - stepId: - type: string - title: step_id - checkpointId: - type: string - title: checkpoint_id - artifactId: - type: string - title: artifact_id - costId: - type: string - title: cost_id - waitId: - type: string - title: wait_id - linkage: - title: linkage - $ref: '#/components/schemas/agentruntime.v1.AgentRunLinkage' - visibility: - title: visibility - $ref: '#/components/schemas/agentruntime.v1.RuntimeVisibilityMetadata' - codexProgress: - title: codex_progress - $ref: '#/components/schemas/codex.v1.CodexRunProgress' - codexInteraction: - title: codex_interaction - $ref: '#/components/schemas/codex.v1.CodexInteractionRequest' - codexOutcome: - title: codex_outcome - $ref: '#/components/schemas/codex.v1.CodexOutcomeSignal' - traceContext: - title: trace_context - $ref: '#/components/schemas/agentruntime.v1.RuntimeTraceContext' - nativeToolAttempt: - title: native_tool_attempt - $ref: '#/components/schemas/agentruntime.v1.NativeToolAttemptEvidence' - nativeAgentEvent: - title: native_agent_event - $ref: '#/components/schemas/agentruntime.v1.NativeAgentEventEvidence' - title: RuntimeEvent - additionalProperties: false - description: |- - RuntimeEvent is appended, never mutated, for AgentRun state transitions and - runtime orchestration decisions. - agentruntime.v1.RuntimeEvidenceGap: - type: object - properties: - reason: - title: reason - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvidenceGapReason' - evidenceState: - title: evidence_state - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvidenceState' - message: - type: string - title: message - source: - type: string - title: source - sourceEventId: - type: string - title: source_event_id - runtimeEventId: - type: string - title: runtime_event_id - traceId: - type: string - title: trace_id - approvalBlocking: - type: boolean - title: approval_blocking - title: RuntimeEvidenceGap - additionalProperties: false - description: |- - RuntimeEvidenceGap records a typed, safe reason why a runtime observation is - not yet approval-ready. It carries only proof-state metadata and debug refs; - raw credentials, grants, prompts, and tool arguments must not be copied here. - agentruntime.v1.RuntimeProactiveContext: - type: object - properties: - proactiveRuntime: - type: boolean - title: proactive_runtime - proactiveIngest: - type: string - title: proactive_ingest - sourceEvent: - title: source_event - $ref: '#/components/schemas/agentruntime.v1.RuntimeProactiveSourceEvent' - thingIds: - type: array - items: - type: string - title: thing_ids - actionClass: - type: string - title: action_class - riskLevel: - type: string - title: risk_level - externalSideEffect: - type: boolean - title: external_side_effect - factsContext: - title: facts_context - $ref: '#/components/schemas/agentruntime.v1.RuntimeCerebroFactsContext' - policy: - title: policy - $ref: '#/components/schemas/agentruntime.v1.RuntimeProactivePolicy' - title: RuntimeProactiveContext - additionalProperties: false - description: |- - RuntimeProactiveContext is the first-class proactive trigger envelope. It - keeps event identity, policy hints, risk hints, and Cerebro context out of - ad hoc trigger payload conventions. - agentruntime.v1.RuntimeProactivePolicy: - type: object - properties: - wakeEnabled: - type: boolean - title: wake_enabled - nullable: true - triggerKinds: - type: array - items: - type: string - title: trigger_kinds - allowCustomerFacing: - type: boolean - title: allow_customer_facing - postRunStarted: - type: boolean - title: post_run_started - title: RuntimeProactivePolicy - additionalProperties: false - description: |- - RuntimeProactivePolicy carries teammate/channel wake controls in the same - trigger contract that AgentRuntime admission evaluates. - agentruntime.v1.RuntimeProactiveSourceEvent: - type: object - properties: - stream: - type: string - title: stream - subject: - type: string - title: subject - sequence: - type: - - integer - - string - title: sequence - format: int64 - eventId: - type: string - title: event_id - eventFamily: - type: string - title: event_family - eventType: - type: string - title: event_type - providerObjectId: - type: string - title: provider_object_id - providerId: - type: string - title: provider_id - connectionId: - type: string - title: connection_id - providerRevision: - type: string - title: provider_revision - title: RuntimeProactiveSourceEvent - additionalProperties: false - description: |- - RuntimeProactiveSourceEvent identifies the upstream event that caused a - proactive trigger candidate without copying the full source payload into the - runtime record. - agentruntime.v1.RuntimeRedaction: - type: object - properties: - kind: - title: kind - $ref: '#/components/schemas/agentruntime.v1.RuntimeRedactionKind' - fieldPath: - type: string - title: field_path - replacement: - type: string - title: replacement - reason: - type: string - title: reason - title: RuntimeRedaction - additionalProperties: false - description: |- - RuntimeRedaction records one projected field or payload category that has - been redacted for channel/user display. - agentruntime.v1.RuntimeSlackThreadCoordinates: - type: object - properties: - providerWorkspaceId: - type: string - title: provider_workspace_id - minLength: 1 - channelId: - type: string - title: channel_id - minLength: 1 - threadId: - type: string - title: thread_id - minLength: 1 - messageId: - type: string - title: message_id - title: RuntimeSlackThreadCoordinates - additionalProperties: false - description: RuntimeSlackThreadCoordinates identifies one Slack conversation thread. - agentruntime.v1.RuntimeSourceHealthSummary: - type: object - properties: - status: - type: string - title: status - checkedSources: - type: array - items: - type: string - title: checked_sources - staleSources: - type: array - items: - type: string - title: stale_sources - summary: - type: string - title: summary - title: RuntimeSourceHealthSummary - additionalProperties: false - description: |- - RuntimeSourceHealthSummary is the compact source-health projection used by - proactive runtime context. Cerebro remains the source of truth for detailed - health records. - agentruntime.v1.RuntimeTeamsThreadCoordinates: - type: object - properties: - tenantId: - type: string - title: tenant_id - minLength: 1 - conversationId: - type: string - title: conversation_id - minLength: 1 - threadId: - type: string - title: thread_id - minLength: 1 - messageId: - type: string - title: message_id - title: RuntimeTeamsThreadCoordinates - additionalProperties: false - description: |- - RuntimeTeamsThreadCoordinates identifies one Microsoft Teams chat or channel - thread. tenant_id is the Microsoft tenant, conversation_id is the channel or - chat, and thread_id is the reply-chain root (the message itself when there is - no thread). - agentruntime.v1.RuntimeTraceContext: - type: object - properties: - traceId: - type: string - title: trace_id - spanId: - type: string - title: span_id - parentSpanId: - type: string - title: parent_span_id - traceparent: - type: string - title: traceparent - tracestate: - type: string - title: tracestate - title: RuntimeTraceContext - additionalProperties: false - description: |- - RuntimeTraceContext captures the W3C trace context that causally owns a - durable AgentRun lifecycle record. It is persisted with runs, events, and - steps so retries, worker claims, and parked waits can resume the same - distributed trace instead of starting unrelated service-local traces. - agentruntime.v1.RuntimeVirtualFile: - type: object - properties: - path: - type: string - title: path - minLength: 1 - mediaType: - type: string - title: media_type - content: - type: string - title: content - sourceService: - type: string - title: source_service - sourceReferenceId: - type: string - title: source_reference_id - metadata: - type: object - title: metadata - additionalProperties: - type: string - title: value - provenance: - title: provenance - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileProvenance' - sensitivity: - title: sensitivity - $ref: '#/components/schemas/agentruntime.v1.RuntimeSensitivity' - redactionState: - title: redaction_state - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileRedactionState' - redactions: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeRedaction' - title: redactions - title: RuntimeVirtualFile - additionalProperties: false - description: |- - RuntimeVirtualFile is a read-only file projected into an agent run from - platform services. It lets workers consume rich context through a stable VFS - instead of parsing flat runtime attributes. - agentruntime.v1.RuntimeVirtualFile.MetadataEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: MetadataEntry - additionalProperties: false - agentruntime.v1.RuntimeVirtualFileChange: - type: object - properties: - path: - type: string - title: path - minLength: 1 - mediaType: - type: string - title: media_type - content: - type: string - title: content - proposalKind: - type: string - title: proposal_kind - stepId: - type: string - title: step_id - metadata: - type: object - title: metadata - additionalProperties: - type: string - title: value - sensitivity: - title: sensitivity - $ref: '#/components/schemas/agentruntime.v1.RuntimeSensitivity' - redactionState: - title: redaction_state - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileRedactionState' - redactions: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeRedaction' - title: redactions - operation: - title: operation - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileOperation' - renameFrom: - type: string - title: rename_from - title: RuntimeVirtualFileChange - additionalProperties: false - agentruntime.v1.RuntimeVirtualFileChange.MetadataEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: MetadataEntry - additionalProperties: false - agentruntime.v1.RuntimeVirtualFileDiffHunk: - type: object - properties: - oldStartLine: - type: integer - title: old_start_line - format: int32 - oldLineCount: - type: integer - title: old_line_count - format: int32 - newStartLine: - type: integer - title: new_start_line - format: int32 - newLineCount: - type: integer - title: new_line_count - format: int32 - header: - type: string - title: header - unifiedDiff: - type: string - title: unified_diff - title: RuntimeVirtualFileDiffHunk - additionalProperties: false - agentruntime.v1.RuntimeVirtualFileEntry: - type: object - properties: - path: - type: string - title: path - mediaType: - type: string - title: media_type - sourceService: - type: string - title: source_service - sourceReferenceId: - type: string - title: source_reference_id - metadata: - type: object - title: metadata - additionalProperties: - type: string - title: value - sizeBytes: - type: - - integer - - string - title: size_bytes - format: int64 - contentSha256: - type: string - title: content_sha256 - contentTruncated: - type: boolean - title: content_truncated - mount: - type: string - title: mount - kind: - type: string - title: kind - permissions: - type: string - title: permissions - view: - type: string - title: view - revisionId: - type: string - title: revision_id - parentRevisionId: - type: string - title: parent_revision_id - providerId: - type: string - title: provider_id - connectionId: - type: string - title: connection_id - cachePolicy: - type: string - title: cache_policy - policy: - type: string - title: policy - lazy: - type: boolean - title: lazy - secretRefCount: - type: integer - title: secret_ref_count - format: int32 - cerebroIndex: - type: string - title: cerebro_index - contentAddress: - type: string - title: content_address - provenance: - title: provenance - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileProvenance' - sensitivity: - title: sensitivity - $ref: '#/components/schemas/agentruntime.v1.RuntimeSensitivity' - redactionState: - title: redaction_state - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileRedactionState' - redactions: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeRedaction' - title: redactions - operation: - title: operation - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileOperation' - tombstone: - type: boolean - title: tombstone - renameFrom: - type: string - title: rename_from - renameTo: - type: string - title: rename_to - capabilities: - type: array - items: - type: string - title: capabilities - writable: - type: boolean - title: writable - readOnly: - type: boolean - title: read_only - generated: - type: boolean - title: generated - evidenceBacked: - type: boolean - title: evidence_backed - externallyIndexed: - type: boolean - title: externally_indexed - title: RuntimeVirtualFileEntry - additionalProperties: false - description: |- - RuntimeVirtualFileEntry is an ls/stat-friendly projection of one virtual - file. It intentionally omits content so callers can discover before reading. - agentruntime.v1.RuntimeVirtualFileEntry.MetadataEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: MetadataEntry - additionalProperties: false - agentruntime.v1.RuntimeVirtualFileInspectorMount: - type: object - properties: - path: - type: string - title: path - fileCount: - type: integer - title: file_count - format: int32 - sizeBytes: - type: - - integer - - string - title: size_bytes - format: int64 - lazy: - type: boolean - title: lazy - providerId: - type: string - title: provider_id - connectionId: - type: string - title: connection_id - cachePolicy: - type: string - title: cache_policy - policy: - type: string - title: policy - cerebroIndex: - type: string - title: cerebro_index - secretRefCount: - type: integer - title: secret_ref_count - format: int32 - sourceServices: - type: array - items: - type: string - title: source_services - previewOnlyFileCount: - type: integer - title: preview_only_file_count - format: int32 - deniedFileCount: - type: integer - title: denied_file_count - format: int32 - restrictedFileCount: - type: integer - title: restricted_file_count - format: int32 - capabilities: - type: array - items: - type: string - title: capabilities - writable: - type: boolean - title: writable - readOnly: - type: boolean - title: read_only - generated: - type: boolean - title: generated - evidenceBacked: - type: boolean - title: evidence_backed - externallyIndexed: - type: boolean - title: externally_indexed - title: RuntimeVirtualFileInspectorMount - additionalProperties: false - agentruntime.v1.RuntimeVirtualFileInspectorProducer: - type: object - properties: - producerService: - type: string - title: producer_service - producerKind: - type: string - title: producer_kind - fileCount: - type: integer - title: file_count - format: int32 - revisionCount: - type: integer - title: revision_count - format: int32 - runtimeEventIds: - type: array - items: - type: string - title: runtime_event_ids - artifactIds: - type: array - items: - type: string - title: artifact_ids - stepIds: - type: array - items: - type: string - title: step_ids - toolExecutionIds: - type: array - items: - type: string - title: tool_execution_ids - traceIds: - type: array - items: - type: string - title: trace_ids - hydrationIds: - type: array - items: - type: string - title: hydration_ids - transactionIds: - type: array - items: - type: string - title: transaction_ids - parentRevisionIds: - type: array - items: - type: string - title: parent_revision_ids - title: RuntimeVirtualFileInspectorProducer - additionalProperties: false - agentruntime.v1.RuntimeVirtualFileInspectorSummary: - type: object - properties: - fileCount: - type: integer - title: file_count - format: int32 - mountCount: - type: integer - title: mount_count - format: int32 - transactionCount: - type: integer - title: transaction_count - format: int32 - lazyMountCount: - type: integer - title: lazy_mount_count - format: int32 - hydratedFileCount: - type: integer - title: hydrated_file_count - format: int32 - cerebroCandidateCount: - type: integer - title: cerebro_candidate_count - format: int32 - cerebroReadyCount: - type: integer - title: cerebro_ready_count - format: int32 - acceptedFileCount: - type: integer - title: accepted_file_count - format: int32 - contentAddressCount: - type: integer - title: content_address_count - format: int32 - hydrationCacheHitCount: - type: integer - title: hydration_cache_hit_count - format: int32 - staleTransactionCount: - type: integer - title: stale_transaction_count - format: int32 - shadowedFileCount: - type: integer - title: shadowed_file_count - format: int32 - producerCount: - type: integer - title: producer_count - format: int32 - previewOnlyFileCount: - type: integer - title: preview_only_file_count - format: int32 - deniedFileCount: - type: integer - title: denied_file_count - format: int32 - restrictedFileCount: - type: integer - title: restricted_file_count - format: int32 - tombstoneFileCount: - type: integer - title: tombstone_file_count - format: int32 - deleteFileCount: - type: integer - title: delete_file_count - format: int32 - renameFileCount: - type: integer - title: rename_file_count - format: int32 - title: RuntimeVirtualFileInspectorSummary - additionalProperties: false - agentruntime.v1.RuntimeVirtualFileInspectorTransaction: - type: object - properties: - transactionId: - type: string - title: transaction_id - view: - type: string - title: view - parentRevisionId: - type: string - title: parent_revision_id - fileCount: - type: integer - title: file_count - format: int32 - policy: - type: string - title: policy - cerebroIndex: - type: string - title: cerebro_index - contentAddresses: - type: array - items: - type: string - title: content_addresses - tombstoneFileCount: - type: integer - title: tombstone_file_count - format: int32 - deleteFileCount: - type: integer - title: delete_file_count - format: int32 - renameFileCount: - type: integer - title: rename_file_count - format: int32 - title: RuntimeVirtualFileInspectorTransaction - additionalProperties: false - agentruntime.v1.RuntimeVirtualFileMatch: - type: object - properties: - path: - type: string - title: path - lineNumber: - type: integer - title: line_number - format: int32 - snippet: - type: string - title: snippet - mount: - type: string - title: mount - sourceService: - type: string - title: source_service - beforeContext: - type: array - items: - type: string - title: before_context - afterContext: - type: array - items: - type: string - title: after_context - score: - type: integer - title: score - format: int32 - matchReasons: - type: array - items: - type: string - title: match_reasons - view: - type: string - title: view - kind: - type: string - title: kind - transactionId: - type: string - title: transaction_id - title: RuntimeVirtualFileMatch - additionalProperties: false - description: RuntimeVirtualFileMatch is one bounded search match in a virtual file. - agentruntime.v1.RuntimeVirtualFileProvenance: - type: object - properties: - producerService: - type: string - title: producer_service - producerKind: - type: string - title: producer_kind - sourceReferenceId: - type: string - title: source_reference_id - runtimeEventId: - type: string - title: runtime_event_id - artifactId: - type: string - title: artifact_id - stepId: - type: string - title: step_id - toolExecutionId: - type: string - title: tool_execution_id - hydrationId: - type: string - title: hydration_id - transactionId: - type: string - title: transaction_id - promotionId: - type: string - title: promotion_id - evidenceHandle: - type: string - title: evidence_handle - traceId: - type: string - title: trace_id - spanId: - type: string - title: span_id - parentRevisionIds: - type: array - items: - type: string - title: parent_revision_ids - providerId: - type: string - title: provider_id - connectionId: - type: string - title: connection_id - title: RuntimeVirtualFileProvenance - additionalProperties: false - description: |- - RuntimeVirtualFileProvenance is the typed causal projection for a VFS - revision. Producers still preserve legacy metadata keys, but workers should - prefer this shape when explaining, citing, promoting, or rebasing files. - agentruntime.v1.RuntimeVirtualFileReadResult: - type: object - properties: - path: - type: string - title: path - entry: - title: entry - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileEntry' - content: - type: string - title: content - offset: - type: integer - title: offset - format: int32 - nextOffset: - type: integer - title: next_offset - format: int32 - eof: - type: boolean - title: eof - skipped: - type: boolean - title: skipped - skipReason: - type: string - title: skip_reason - citation: - type: string - title: citation - rank: - type: integer - title: rank - format: int32 - rankReason: - type: string - title: rank_reason - reasonCode: - title: reason_code - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileReasonCode' - redactionState: - title: redaction_state - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileRedactionState' - redactions: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeRedaction' - title: redactions - title: RuntimeVirtualFileReadResult - additionalProperties: false - agentruntime.v1.RuntimeVirtualFileSelector: - type: object - properties: - paths: - type: array - items: - type: string - title: paths - pathPrefix: - type: string - title: path_prefix - views: - type: array - items: - type: string - title: views - kinds: - type: array - items: - type: string - title: kinds - mounts: - type: array - items: - type: string - title: mounts - transactionIds: - type: array - items: - type: string - title: transaction_ids - policies: - type: array - items: - type: string - title: policies - sourceServices: - type: array - items: - type: string - title: source_services - cerebroIndexes: - type: array - items: - type: string - title: cerebro_indexes - includeTombstones: - type: boolean - title: include_tombstones - title: RuntimeVirtualFileSelector - additionalProperties: false - agentruntime.v1.RuntimeVirtualFileTransactionConflict: - type: object - properties: - path: - type: string - title: path - reasonCode: - title: reason_code - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileReasonCode' - applyStatus: - title: apply_status - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileTransactionApplyStatus' - message: - type: string - title: message - parentRevisionId: - type: string - title: parent_revision_id - baseRevisionId: - type: string - title: base_revision_id - currentRevisionId: - type: string - title: current_revision_id - proposedRevisionId: - type: string - title: proposed_revision_id - hunks: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileDiffHunk' - title: hunks - title: RuntimeVirtualFileTransactionConflict - additionalProperties: false - agentruntime.v1.RuntimeVirtualFileTransactionDiff: - type: object - properties: - transactionId: - type: string - title: transaction_id - files: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileTransactionFileDiff' - title: files - unifiedDiff: - type: string - title: unified_diff - fileCount: - type: integer - title: file_count - format: int32 - changedFileCount: - type: integer - title: changed_file_count - format: int32 - additions: - type: integer - title: additions - format: int32 - deletions: - type: integer - title: deletions - format: int32 - stale: - type: boolean - title: stale - outcome: - title: outcome - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileTransactionOutcome' - conflicts: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileTransactionConflict' - title: conflicts - title: RuntimeVirtualFileTransactionDiff - additionalProperties: false - agentruntime.v1.RuntimeVirtualFileTransactionFileDiff: - type: object - properties: - path: - type: string - title: path - operation: - title: operation - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileOperation' - applyStatus: - title: apply_status - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileTransactionApplyStatus' - parentRevisionId: - type: string - title: parent_revision_id - baseRevisionId: - type: string - title: base_revision_id - currentRevisionId: - type: string - title: current_revision_id - proposedRevisionId: - type: string - title: proposed_revision_id - baseContentSha256: - type: string - title: base_content_sha256 - currentContentSha256: - type: string - title: current_content_sha256 - proposedContentSha256: - type: string - title: proposed_content_sha256 - additions: - type: integer - title: additions - format: int32 - deletions: - type: integer - title: deletions - format: int32 - binary: - type: boolean - title: binary - tombstone: - type: boolean - title: tombstone - renameFrom: - type: string - title: rename_from - renameTo: - type: string - title: rename_to - unifiedDiff: - type: string - title: unified_diff - hunks: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileDiffHunk' - title: hunks - title: RuntimeVirtualFileTransactionFileDiff - additionalProperties: false - agentruntime.v1.RuntimeVirtualFileWatchEvent: - type: object - properties: - cursor: - type: string - title: cursor - operation: - type: string - title: operation - path: - type: string - title: path - revisionId: - type: string - title: revision_id - parentRevisionId: - type: string - title: parent_revision_id - transactionId: - type: string - title: transaction_id - view: - type: string - title: view - spanId: - type: string - title: span_id - evidenceHandle: - type: string - title: evidence_handle - runtimeEventId: - type: string - title: runtime_event_id - artifactId: - type: string - title: artifact_id - traceId: - type: string - title: trace_id - hydrationId: - type: string - title: hydration_id - promotionId: - type: string - title: promotion_id - producerService: - type: string - title: producer_service - producerKind: - type: string - title: producer_kind - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - checkpointId: - type: string - title: checkpoint_id - entry: - title: entry - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileEntry' - title: RuntimeVirtualFileWatchEvent - additionalProperties: false - agentruntime.v1.RuntimeVisibilityMetadata: - type: object - properties: - level: - title: level - $ref: '#/components/schemas/agentruntime.v1.RuntimeVisibilityLevel' - audiences: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeAudience' - title: audiences - sensitivity: - title: sensitivity - $ref: '#/components/schemas/agentruntime.v1.RuntimeSensitivity' - safeSummary: - type: string - title: safe_summary - redactions: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeRedaction' - title: redactions - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: RuntimeVisibilityMetadata - additionalProperties: false - description: |- - RuntimeVisibilityMetadata carries the projection policy for runtime events - and waits. Safe summaries are required when visibility is user/channel - visible so clients never need to render raw internal payloads. - agentruntime.v1.RuntimeVisibilityMetadata.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - agentruntime.v1.RuntimeWebConversationCoordinates: - type: object - properties: - conversationId: - type: string - title: conversation_id - minLength: 1 - messageId: - type: string - title: message_id - title: RuntimeWebConversationCoordinates - additionalProperties: false - description: RuntimeWebConversationCoordinates identifies a Platform-owned web thread. - agentruntime.v1.RuntimeWhatsAppConversationCoordinates: - type: object - properties: - wabaId: - type: string - title: waba_id - minLength: 1 - phoneNumberId: - type: string - title: phone_number_id - minLength: 1 - chatId: - type: string - title: chat_id - minLength: 1 - messageId: - type: string - title: message_id - title: RuntimeWhatsAppConversationCoordinates - additionalProperties: false - description: |- - RuntimeWhatsAppConversationCoordinates identifies one WhatsApp Business - conversation. chat_id is the peer wa_id for a 1:1 chat or the group id. - agentruntime.v1.RuntimeWorkEnvelope: - type: object - properties: - id: - type: string - title: id - minLength: 1 - kind: - title: kind - $ref: '#/components/schemas/agentruntime.v1.RuntimeWorkEnvelopeKind' - rootId: - type: string - title: root_id - parentId: - type: string - title: parent_id - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: RuntimeWorkEnvelope - additionalProperties: false - description: |- - RuntimeWorkEnvelope identifies the durable work object that groups related - normalized triggers. For Slack this is usually a conversation thread; future - adapters can map email threads, Jira tickets, calendar events, and Teams - threads into the same runtime primitive. - agentruntime.v1.RuntimeWorkEnvelope.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - agentruntime.v1.SearchRunVirtualFilesRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - query: - type: string - title: query - minLength: 1 - pathPrefix: - type: string - title: path_prefix - limit: - type: integer - title: limit - format: int32 - selector: - title: selector - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileSelector' - regex: - type: boolean - title: regex - contextLines: - type: integer - title: context_lines - format: int32 - caseSensitive: - type: boolean - title: case_sensitive - title: SearchRunVirtualFilesRequest - additionalProperties: false - agentruntime.v1.SearchRunVirtualFilesResponse: - type: object - properties: - matches: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileMatch' - title: matches - totalMatches: - type: integer - title: total_matches - format: int32 - limitExhausted: - type: boolean - title: limit_exhausted - title: SearchRunVirtualFilesResponse - additionalProperties: false - agentruntime.v1.StatRunVirtualFileRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - path: - type: string - title: path - minLength: 1 - includeTombstones: - type: boolean - title: include_tombstones - title: StatRunVirtualFileRequest - additionalProperties: false - agentruntime.v1.StatRunVirtualFileResponse: - type: object - properties: - entry: - title: entry - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileEntry' - title: StatRunVirtualFileResponse - additionalProperties: false - agentruntime.v1.SurfaceInvocationActor: - type: object - properties: - externalId: - type: string - title: external_id - minLength: 1 - displayName: - type: string - title: display_name - maxLength: 512 - title: SurfaceInvocationActor - additionalProperties: false - agentruntime.v1.SurfaceInvocationAttachmentRef: - type: object - properties: - externalId: - type: string - title: external_id - minLength: 1 - name: - type: string - title: name - minLength: 1 - contentType: - type: string - title: content_type - maxLength: 255 - canonicalUrl: - type: string - title: canonical_url - maxLength: 2048 - title: SurfaceInvocationAttachmentRef - additionalProperties: false - agentruntime.v1.SurfaceInvocationContextRef: - type: object - properties: - kind: - type: string - title: kind - minLength: 1 - externalId: - type: string - title: external_id - minLength: 1 - canonicalUrl: - type: string - title: canonical_url - maxLength: 2048 - title: SurfaceInvocationContextRef - additionalProperties: false - agentruntime.v1.SurfaceInvocationContextSnapshot: - type: object - properties: - sourceKind: - type: string - title: source_kind - maxLength: 128 - minLength: 1 - sourceExternalId: - type: string - title: source_external_id - maxLength: 512 - minLength: 1 - sourceRevision: - type: string - title: source_revision - maxLength: 512 - sourcePayloadSha256: - type: string - title: source_payload_sha256 - pattern: ^[0-9a-f]{64}$ - description: |- - Digest of the complete authenticated provider payload or governed read - response from which `content` was selected. - observedAt: - title: observed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - content: - title: content - $ref: '#/components/schemas/google.protobuf.Struct' - title: SurfaceInvocationContextSnapshot - additionalProperties: false - description: |- - A bounded provider-native context snapshot captured by the authenticated - edge. `content` is model-visible context, while the remaining fields bind it - to the provider read or signed delivery that produced it. Snapshots confer - no tenant or mutation authority. - agentruntime.v1.SurfaceInvocationTarget: - type: object - properties: - kind: - title: kind - $ref: '#/components/schemas/agentruntime.v1.SurfaceTargetKind' - externalId: - type: string - title: external_id - minLength: 1 - parentExternalId: - type: string - title: parent_external_id - maxLength: 512 - revision: - type: string - title: revision - maxLength: 512 - canonicalUrl: - type: string - title: canonical_url - maxLength: 2048 - title: SurfaceInvocationTarget - additionalProperties: false - agentruntime.v1.SurfaceInvocationTrigger: - type: object - properties: - kind: - type: string - title: kind - minLength: 1 - externalId: - type: string - title: external_id - minLength: 1 - title: SurfaceInvocationTrigger - additionalProperties: false - agentruntime.v1.TeammateCapability: - type: object - properties: - id: - type: string - title: id - owner: - type: string - title: owner - contractPaths: - type: array - items: - type: string - title: contract_paths - rpcs: - type: array - items: - type: string - title: rpcs - isolation: - type: string - title: isolation - slackVisible: - type: boolean - title: slack_visible - requiresLease: - type: boolean - title: requires_lease - proposalOnly: - type: boolean - title: proposal_only - evidenceBacked: - type: boolean - title: evidence_backed - title: TeammateCapability - additionalProperties: false - description: TeammateCapability is one Platform-owned capability made available to a run. - agentruntime.v1.TeammateCapabilityProfile: - type: object - properties: - schemaVersion: - type: string - title: schema_version - runId: - type: string - title: run_id - workspaceId: - type: string - title: workspace_id - agentId: - type: string - title: agent_id - workEnvelopeId: - type: string - title: work_envelope_id - workEnvelopeKind: - type: string - title: work_envelope_kind - surface: - type: string - title: surface - channelKind: - type: string - title: channel_kind - executionOwner: - type: string - title: execution_owner - channelIngressOwner: - type: string - title: channel_ingress_owner - channelRenderer: - type: string - title: channel_renderer - schedulerOwner: - type: string - title: scheduler_owner - memoryOwner: - type: string - title: memory_owner - evidenceOwner: - type: string - title: evidence_owner - privilegeModel: - type: string - title: privilege_model - alwaysOn: - type: boolean - title: always_on - ambient: - type: boolean - title: ambient - capabilities: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.TeammateCapability' - title: capabilities - executionPath: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.TeammateExecutionStep' - title: execution_path - isolationBoundaries: - type: array - items: - type: string - title: isolation_boundaries - contextPaths: - type: array - items: - type: string - title: context_paths - guardrails: - type: array - items: - type: string - title: guardrails - title: TeammateCapabilityProfile - additionalProperties: false - description: |- - TeammateCapabilityProfile describes the runtime capability and isolation - contract Platform grants to a persistent teammate run. - agentruntime.v1.TeammateExecutionStep: - type: object - properties: - id: - type: string - title: id - owner: - type: string - title: owner - reads: - type: array - items: - type: string - title: reads - writes: - type: array - items: - type: string - title: writes - rpcs: - type: array - items: - type: string - title: rpcs - isolation: - type: string - title: isolation - slackBehavior: - type: string - title: slack_behavior - title: TeammateExecutionStep - additionalProperties: false - description: TeammateExecutionStep is the concise ownership path for capability use. - agentruntime.v1.TeammateWorkLedger: - type: object - properties: - schemaVersion: - type: string - title: schema_version - runId: - type: string - title: run_id - linkage: - title: linkage - $ref: '#/components/schemas/agentruntime.v1.AgentRunLinkage' - state: - title: state - $ref: '#/components/schemas/agentruntime.v1.AgentRunState' - objectiveTitle: - type: string - title: objective_title - workerQueue: - type: string - title: worker_queue - attempt: - type: integer - title: attempt - format: int32 - workEnvelopeId: - type: string - title: work_envelope_id - workEnvelopeKind: - type: string - title: work_envelope_kind - workstreamId: - type: string - title: workstream_id - nextAction: - type: string - title: next_action - blockers: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.TeammateWorkLedgerBlocker' - title: blockers - connectorAccess: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.TeammateWorkLedgerConnectorAccess' - title: connector_access - memoryCitations: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.TeammateWorkLedgerMemoryCitation' - title: memory_citations - vfsSummary: - title: vfs_summary - $ref: '#/components/schemas/agentruntime.v1.TeammateWorkLedgerVfsSummary' - cerebroContext: - title: cerebro_context - $ref: '#/components/schemas/agentruntime.v1.TeammateWorkLedgerCerebroContext' - proactivePolicy: - title: proactive_policy - $ref: '#/components/schemas/agentruntime.v1.TeammateWorkLedgerProactivePolicy' - channelStatus: - title: channel_status - $ref: '#/components/schemas/agentruntime.v1.TeammateWorkLedgerChannelStatus' - evidencePaths: - type: array - items: - type: string - title: evidence_paths - handoffPolicy: - type: string - title: handoff_policy - resumeCheckpointPath: - type: string - title: resume_checkpoint_path - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - eventCount: - type: integer - title: event_count - format: int32 - activeWorkItems: - type: array - items: - $ref: '#/components/schemas/agentruntime.v1.AgentWorkItem' - title: active_work_items - activeWorkItemCount: - type: integer - title: active_work_item_count - format: int32 - blockedWorkItemCount: - type: integer - title: blocked_work_item_count - format: int32 - title: TeammateWorkLedger - additionalProperties: false - description: |- - TeammateWorkLedger is the compact, durable read model a persistent digital - teammate uses to resume work, explain what it has actually checked, and keep - Slack or other human-facing channels clean while tool-heavy work happens - under the hood. - agentruntime.v1.TeammateWorkLedgerBlocker: - type: object - properties: - waitId: - type: string - title: wait_id - type: - title: type - $ref: '#/components/schemas/agentruntime.v1.AgentRunWaitType' - reason: - type: string - title: reason - externalRef: - type: string - title: external_ref - resumeAfter: - title: resume_after - $ref: '#/components/schemas/google.protobuf.Timestamp' - visibilitySummary: - type: string - title: visibility_summary - resumeContract: - title: resume_contract - $ref: '#/components/schemas/agentruntime.v1.TeammateWorkLedgerWaitResumeContract' - title: TeammateWorkLedgerBlocker - additionalProperties: false - agentruntime.v1.TeammateWorkLedgerCerebroContext: - type: object - properties: - provider: - type: string - title: provider - query: - type: string - title: query - thingIds: - type: array - items: - type: string - title: thing_ids - factIds: - type: array - items: - type: string - title: fact_ids - eventIds: - type: array - items: - type: string - title: event_ids - eligibleFileCount: - type: integer - title: eligible_file_count - format: int32 - title: TeammateWorkLedgerCerebroContext - additionalProperties: false - agentruntime.v1.TeammateWorkLedgerChannelStatus: - type: object - properties: - channelKind: - type: string - title: channel_kind - channelId: - type: string - title: channel_id - threadId: - type: string - title: thread_id - lastVisibleEventId: - type: string - title: last_visible_event_id - lastVisibleSummary: - type: string - title: last_visible_summary - processingState: - title: processing_state - $ref: '#/components/schemas/agentruntime.v1.AutonomyProcessingState' - processingSummary: - type: string - title: processing_summary - processingMessageTs: - type: string - title: processing_message_ts - assistantStreamTs: - type: string - title: assistant_stream_ts - lastPresenceEventId: - type: string - title: last_presence_event_id - lastPresenceUpdateAt: - title: last_presence_update_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - finalResponsePending: - type: boolean - title: final_response_pending - autonomySessionId: - type: string - title: autonomy_session_id - title: TeammateWorkLedgerChannelStatus - additionalProperties: false - agentruntime.v1.TeammateWorkLedgerConnectorAccess: - type: object - properties: - mountPath: - type: string - title: mount_path - providerId: - type: string - title: provider_id - connectionId: - type: string - title: connection_id - capabilities: - type: array - items: - type: string - title: capabilities - grantRequired: - type: boolean - title: grant_required - leasePolicy: - type: string - title: lease_policy - identityMode: - type: string - title: identity_mode - credentialVersionStrategy: - type: string - title: credential_version_strategy - secretRefCount: - type: integer - title: secret_ref_count - format: int32 - credentialRefNames: - type: array - items: - type: string - title: credential_ref_names - title: TeammateWorkLedgerConnectorAccess - additionalProperties: false - agentruntime.v1.TeammateWorkLedgerMemoryCitation: - type: object - properties: - memoryId: - type: string - title: memory_id - memoryType: - type: string - title: memory_type - source: - type: string - title: source - sourceUris: - type: array - items: - type: string - title: source_uris - supersedesMemoryId: - type: string - title: supersedes_memory_id - supersededByMemoryId: - type: string - title: superseded_by_memory_id - reviewStatus: - type: string - title: review_status - entityIds: - type: array - items: - type: string - title: entity_ids - contentPreview: - type: string - title: content_preview - title: TeammateWorkLedgerMemoryCitation - additionalProperties: false - agentruntime.v1.TeammateWorkLedgerProactivePolicy: - type: object - properties: - enabled: - type: boolean - title: enabled - triggerKinds: - type: array - items: - type: string - title: trigger_kinds - progressUpdateTriggers: - type: array - items: - type: string - title: progress_update_triggers - presencePolicy: - type: string - title: presence_policy - updateBudget: - type: integer - title: update_budget - format: int32 - title: TeammateWorkLedgerProactivePolicy - additionalProperties: false - agentruntime.v1.TeammateWorkLedgerVfsSummary: - type: object - properties: - fileCount: - type: integer - title: file_count - format: int32 - mountCount: - type: integer - title: mount_count - format: int32 - connectorMountCount: - type: integer - title: connector_mount_count - format: int32 - memoryRecordCount: - type: integer - title: memory_record_count - format: int32 - transactionCount: - type: integer - title: transaction_count - format: int32 - cerebroIndexEligibleFileCount: - type: integer - title: cerebro_index_eligible_file_count - format: int32 - hasResumeCheckpoint: - type: boolean - title: has_resume_checkpoint - title: TeammateWorkLedgerVfsSummary - additionalProperties: false - agentruntime.v1.TeammateWorkLedgerWaitResumeContract: - type: object - properties: - schemaVersion: - type: string - title: schema_version - resumeRpc: - type: string - title: resume_rpc - lookupRpc: - type: string - title: lookup_rpc - lookupExternalRefField: - type: string - title: lookup_external_ref_field - requiredResumeFields: - type: array - items: - type: string - title: required_resume_fields - allowedDecisions: - type: array - items: - type: string - title: allowed_decisions - channelActionValueFields: - type: array - items: - type: string - title: channel_action_value_fields - idempotencyJoinKey: - type: string - title: idempotency_join_key - approvalRequestId: - type: string - title: approval_request_id - requiresSafeSummary: - type: boolean - title: requires_safe_summary - title: TeammateWorkLedgerWaitResumeContract - additionalProperties: false - description: |- - TeammateWorkLedgerWaitResumeContract makes parked-run resumption - machine-readable for channel adapters and workers. Slack actions can carry - only the compact value fields, then resolve the durable wait through - ListRunWaits before calling ResumeRun. - agentruntime.v1.UpdateRunWorkItemRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - workItemId: - type: string - title: work_item_id - minLength: 1 - state: - title: state - $ref: '#/components/schemas/agentruntime.v1.AgentWorkItemState' - nextAction: - type: string - title: next_action - nullable: true - blocker: - type: string - title: blocker - nullable: true - waitId: - type: string - title: wait_id - nullable: true - toolExecutionId: - type: string - title: tool_execution_id - nullable: true - evidenceRefs: - type: array - items: - type: string - title: evidence_refs - completionGate: - type: string - title: completion_gate - nullable: true - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Struct' - title: UpdateRunWorkItemRequest - additionalProperties: false - agentruntime.v1.UpdateRunWorkItemResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - workItem: - title: work_item - $ref: '#/components/schemas/agentruntime.v1.AgentWorkItem' - event: - title: event - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvent' - title: UpdateRunWorkItemResponse - additionalProperties: false - agentruntime.v1.WaitRunRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - leaseToken: - type: string - title: lease_token - minLength: 1 - wait: - title: wait - $ref: '#/components/schemas/agentruntime.v1.AgentRunWait' - checkpoint: - title: checkpoint - $ref: '#/components/schemas/agentruntime.v1.AgentRunCheckpoint' - title: WaitRunRequest - required: - - wait - additionalProperties: false - agentruntime.v1.WaitRunResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - wait: - title: wait - $ref: '#/components/schemas/agentruntime.v1.AgentRunWait' - checkpoint: - title: checkpoint - $ref: '#/components/schemas/agentruntime.v1.AgentRunCheckpoint' - event: - title: event - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvent' - title: WaitRunResponse - additionalProperties: false - agentruntime.v1.WatchRunVirtualFilesRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - sinceCursor: - type: string - title: since_cursor - limit: - type: integer - title: limit - format: int32 - follow: - type: boolean - title: follow - selector: - title: selector - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileSelector' - title: WatchRunVirtualFilesRequest - additionalProperties: false - agentruntime.v1.WatchRunVirtualFilesResponse: - type: object - properties: - event: - title: event - $ref: '#/components/schemas/agentruntime.v1.RuntimeVirtualFileWatchEvent' - title: WatchRunVirtualFilesResponse - additionalProperties: false - agentruntime.v1.YieldRunRequest: - type: object - properties: - runId: - type: string - title: run_id - minLength: 1 - leaseToken: - type: string - title: lease_token - minLength: 1 - continuation: - title: continuation - $ref: '#/components/schemas/agentruntime.v1.YieldContinuation' - checkpoint: - title: checkpoint - $ref: '#/components/schemas/agentruntime.v1.AgentRunCheckpoint' - resumeAfter: - title: resume_after - $ref: '#/components/schemas/google.protobuf.Timestamp' - wait: - title: wait - $ref: '#/components/schemas/agentruntime.v1.AgentRunWait' - presenceStatusText: - type: string - title: presence_status_text - idempotencyKey: - type: string - title: idempotency_key - yieldBudget: - type: integer - title: yield_budget - format: int32 - title: YieldRunRequest - additionalProperties: false - agentruntime.v1.YieldRunResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - successorRun: - title: successor_run - $ref: '#/components/schemas/agentruntime.v1.AgentRun' - wait: - title: wait - $ref: '#/components/schemas/agentruntime.v1.AgentRunWait' - checkpoint: - title: checkpoint - $ref: '#/components/schemas/agentruntime.v1.AgentRunCheckpoint' - event: - title: event - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvent' - presenceEvent: - title: presence_event - $ref: '#/components/schemas/agentruntime.v1.RuntimeEvent' - sessionBlocked: - type: boolean - title: session_blocked - yieldCount: - type: integer - title: yield_count - format: int32 - title: YieldRunResponse - additionalProperties: false - agents.v1.Agent: - type: object - properties: - id: - type: string - title: id - workspaceId: - type: string - title: workspace_id - name: - type: string - title: name - description: - type: string - title: description - agentType: - type: string - title: agent_type - description: |- - agent_type aligns with identity/v1 IntrospectResponse.agent_type and - IssueAgentTokenRequest.agent_type. Examples: "sdr", "support", "coding", - "ops", "research". - capabilities: - type: array - items: - type: string - title: capabilities - description: |- - capabilities aligns with identity/v1 IntrospectResponse.capabilities and - IssueAgentTokenRequest.capabilities. Used by capability-based delegation - routing. Examples: "hubspot-write", "email-send", "code-review". - surfaces: - type: array - items: - type: string - title: surfaces - description: |- - surfaces this agent can operate on. Aligns with the surface field in - meter/v1, objectives/v1, approvals/v1. Examples: "ensemble", "chat", - "maestro", "conductor", "slack". - status: - title: status - $ref: '#/components/schemas/agents.v1.AgentStatus' - activeConfigVersion: - type: integer - title: active_config_version - format: int32 - ownerId: - type: string - title: owner_id - lastHeartbeatAt: - title: last_heartbeat_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - surfaceTypes: - type: array - items: - $ref: '#/components/schemas/common.v1.Surface' - title: surface_types - a2a: - title: a2a - description: |- - a2a is the Platform-owned discovery projection for spec-native A2A peers. - Remote agents use it to discover where to fetch the Agent Card, which - transport/profile is supported, and which skills can be delegated to this - agent or its child/subagent lanes. - $ref: '#/components/schemas/agents.v1.AgentA2APeerProjection' - capacity: - title: capacity - description: |- - capacity is the registry-owned load projection used by fleet-scale - delegation discovery and operator read models. - $ref: '#/components/schemas/agents.v1.AgentCapacity' - title: Agent - additionalProperties: false - description: |- - Agent is the canonical agent definition record. - The id field is the value stored in every agent_id / agent string field - across the platform: meter/v1 RecordUsageRequest.agent_id, - objectives/v1 Objective.agent_id, approvals/v1 ApprovalRequest.agent_id, - governance/v1 EvaluateActionRequest.agent_id, memory/v1 Memory.agent, - and events/v1 Change.actor_id when actor_type is "agent". - agents.v1.AgentA2APeerProjection: - type: object - properties: - publicEndpointUrl: - type: string - title: public_endpoint_url - internalEndpointUrl: - type: string - title: internal_endpoint_url - agentCardUrl: - type: string - title: agent_card_url - protocolBinding: - type: string - title: protocol_binding - protocolVersion: - type: string - title: protocol_version - supportedExtensions: - type: array - items: - type: string - title: supported_extensions - skills: - type: array - items: - $ref: '#/components/schemas/agents.v1.AgentA2ASkill' - title: skills - securitySchemes: - type: array - items: - type: string - title: security_schemes - agentCardObservedAt: - title: agent_card_observed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - agentCardEtag: - type: string - title: agent_card_etag - agentCardHash: - type: string - title: agent_card_hash - pushNotifications: - type: boolean - title: push_notifications - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: AgentA2APeerProjection - additionalProperties: false - agents.v1.AgentA2APeerProjection.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - agents.v1.AgentA2ASkill: - type: object - properties: - id: - type: string - title: id - name: - type: string - title: name - description: - type: string - title: description - tags: - type: array - items: - type: string - title: tags - inputModes: - type: array - items: - type: string - title: input_modes - outputModes: - type: array - items: - type: string - title: output_modes - requiredContextGrants: - type: array - items: - type: string - title: required_context_grants - approvalPolicyRef: - type: string - title: approval_policy_ref - maxAutonomy: - type: string - title: max_autonomy - requiredArtifactKinds: - type: array - items: - type: string - title: required_artifact_kinds - optionalArtifactKinds: - type: array - items: - type: string - title: optional_artifact_kinds - allowedTaskClasses: - type: array - items: - type: string - title: allowed_task_classes - deniedTaskClasses: - type: array - items: - type: string - title: denied_task_classes - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: AgentA2ASkill - additionalProperties: false - agents.v1.AgentA2ASkill.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - agents.v1.AgentCapacity: - type: object - properties: - current: - type: integer - title: current - format: int32 - max: - type: integer - title: max - format: int32 - remaining: - type: integer - title: remaining - format: int32 - reservedDelegationCount: - type: integer - title: reserved_delegation_count - format: int32 - title: AgentCapacity - additionalProperties: false - agents.v1.AgentConfig: - type: object - properties: - version: - type: integer - title: version - format: int32 - agentId: - type: string - title: agent_id - skillIds: - type: array - items: - type: string - title: skill_ids - description: |- - skill_ids reference skills/v1 Skill.id — the reusable capabilities - this agent has loaded. - promptBindings: - type: object - title: prompt_bindings - additionalProperties: - type: string - title: value - description: |- - prompt_bindings maps prompt name to label (e.g., "sdr-outreach" -> "production"). - Aligns with prompts/v1 ResolveRequest.name and ResolveRequest.label. - modelPreferences: - type: object - title: model_preferences - additionalProperties: - type: string - title: value - description: |- - model_preferences maps surface to preferred model identifier - (e.g., "ensemble" -> "claude-opus-4.6"). Aligns with meter/v1 - RecordUsageRequest.model and keys/v1 ResolveProviderRefRequest.provider. - integrationIds: - type: array - items: - type: string - title: integration_ids - description: |- - integration_ids reference connectors/v1 Connection.id — the external - system connections this agent is authorized to use. - entityTypeScopes: - type: array - items: - type: string - title: entity_type_scopes - description: |- - entity_type_scopes restrict which entities/v1 EntityType values this - agent can operate on. Empty means unrestricted. - maxConcurrentObjectives: - type: integer - title: max_concurrent_objectives - format: int32 - description: |- - max_concurrent_objectives caps the number of objectives/v1 Objective - records this agent can hold in RUNNING or BLOCKED state simultaneously. - costBudgetUsd: - type: number - title: cost_budget_usd - format: double - description: |- - cost_budget_usd is the per-period spend ceiling enforced against - meter/v1 usage records for this agent. - notificationChannel: - type: string - title: notification_channel - description: |- - notification_channel specifies the preferred notifications/v1 - DeliveryChannel for this agent's escalations. Stored as string to - avoid cross-package import (e.g., "DELIVERY_CHANNEL_SLACK"). - parameters: - title: parameters - description: parameters holds arbitrary agent-specific tuning knobs. - $ref: '#/components/schemas/google.protobuf.Struct' - author: - type: string - title: author - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - entityTypeScopeEnums: - type: array - items: - $ref: '#/components/schemas/common.v1.EntityType' - title: entity_type_scope_enums - notificationChannelEnum: - title: notification_channel_enum - $ref: '#/components/schemas/common.v1.DeliveryChannel' - teammateProfile: - title: teammate_profile - $ref: '#/components/schemas/agents.v1.DigitalTeammateProfile' - connectorRequirements: - type: array - items: - $ref: '#/components/schemas/agents.v1.ConnectorRequirement' - title: connector_requirements - description: Portable provider needs. Connection IDs remain workspace-local bindings. - title: AgentConfig - additionalProperties: false - description: |- - AgentConfig is an immutable snapshot of everything that shapes an agent's - behavior. Promotion and rollback are both config version reassignments — - the same pattern as prompts/v1 Label. - agents.v1.AgentConfig.ModelPreferencesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: ModelPreferencesEntry - additionalProperties: false - agents.v1.AgentConfig.PromptBindingsEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: PromptBindingsEntry - additionalProperties: false - agents.v1.AutonomyPolicy: - type: object - properties: - rules: - type: array - items: - $ref: '#/components/schemas/agents.v1.AutonomyRule' - title: rules - defaultAuthority: - title: default_authority - $ref: '#/components/schemas/agents.v1.AutonomyAuthority' - maxRiskWithoutApproval: - title: max_risk_without_approval - $ref: '#/components/schemas/common.v1.RiskLevel' - title: AutonomyPolicy - additionalProperties: false - description: |- - AutonomyPolicy describes the default authority and specific action rules - that ToolExecution, Governance, and Approvals can enforce. - agents.v1.AutonomyRule: - type: object - properties: - actionType: - type: string - title: action_type - toolCapability: - type: string - title: tool_capability - maxRisk: - title: max_risk - $ref: '#/components/schemas/common.v1.RiskLevel' - authority: - not: - enum: - - 0 - title: authority - $ref: '#/components/schemas/agents.v1.AutonomyAuthority' - approvalPolicyRef: - type: string - title: approval_policy_ref - governancePolicyRef: - type: string - title: governance_policy_ref - rationale: - type: string - title: rationale - title: AutonomyRule - additionalProperties: false - description: AutonomyRule constrains a class of actions or tool capabilities. - agents.v1.CommitmentPolicy: - type: object - properties: - allowedKinds: - type: array - items: - $ref: '#/components/schemas/agents.v1.CommitmentKind' - title: allowed_kinds - templates: - type: array - items: - $ref: '#/components/schemas/agents.v1.CommitmentTemplate' - title: templates - defaultDueSeconds: - type: integer - title: default_due_seconds - format: int32 - maxOpenCommitments: - type: integer - title: max_open_commitments - format: int32 - requireObjectiveForCommitment: - type: boolean - title: require_objective_for_commitment - title: CommitmentPolicy - additionalProperties: false - description: |- - CommitmentPolicy describes which durable objectives and wakes can be created - from teammate commitments. - agents.v1.CommitmentTemplate: - type: object - properties: - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/agents.v1.CommitmentKind' - objectiveTitleTemplate: - type: string - title: objective_title_template - objectiveDescriptionTemplate: - type: string - title: objective_description_template - wakeReasonTemplate: - type: string - title: wake_reason_template - requiredJoinKeys: - type: array - items: - type: string - title: required_join_keys - title: CommitmentTemplate - additionalProperties: false - description: CommitmentTemplate maps a commitment kind to objective and wake templates. - agents.v1.ConnectorRequirement: - type: object - properties: - providerId: - type: string - title: provider_id - minLength: 1 - requiredCapabilities: - type: array - items: - type: string - title: required_capabilities - optionalCapabilities: - type: array - items: - type: string - title: optional_capabilities - required: - type: boolean - title: required - title: ConnectorRequirement - additionalProperties: false - agents.v1.DigitalTeammateProfile: - type: object - properties: - id: - type: string - title: id - version: - type: integer - title: version - format: int32 - workspaceId: - type: string - title: workspace_id - agentId: - type: string - title: agent_id - displayName: - type: string - title: display_name - role: - type: string - title: role - purpose: - type: string - title: purpose - ownerUserId: - type: string - title: owner_user_id - ownerTeamId: - type: string - title: owner_team_id - surfaceTypes: - type: array - items: - $ref: '#/components/schemas/common.v1.Surface' - title: surface_types - lifecycle: - title: lifecycle - $ref: '#/components/schemas/agents.v1.TeammateLifecycle' - responsibilities: - type: array - items: - $ref: '#/components/schemas/agents.v1.TeammateResponsibility' - title: responsibilities - commitmentPolicy: - title: commitment_policy - $ref: '#/components/schemas/agents.v1.CommitmentPolicy' - initiativePolicy: - title: initiative_policy - $ref: '#/components/schemas/agents.v1.InitiativePolicy' - autonomyPolicy: - title: autonomy_policy - $ref: '#/components/schemas/agents.v1.AutonomyPolicy' - memoryPolicy: - title: memory_policy - $ref: '#/components/schemas/agents.v1.MemoryPolicy' - presencePolicy: - title: presence_policy - $ref: '#/components/schemas/agents.v1.PresencePolicy' - outputPolicy: - title: output_policy - $ref: '#/components/schemas/agents.v1.OutputPolicy' - evalPolicy: - title: eval_policy - $ref: '#/components/schemas/agents.v1.EvalPolicy' - escalationPolicy: - title: escalation_policy - $ref: '#/components/schemas/agents.v1.EscalationPolicy' - labels: - type: object - title: labels - additionalProperties: - type: string - title: value - parameters: - title: parameters - $ref: '#/components/schemas/google.protobuf.Struct' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - channelManifests: - type: array - items: - $ref: '#/components/schemas/agents.v1.TeammateChannelManifest' - title: channel_manifests - title: DigitalTeammateProfile - additionalProperties: false - description: |- - DigitalTeammateProfile is the versioned contract for how an AgentConfig acts - as a durable teammate across objectives, workflows, tools, memory, evals, and - Slack or other delivery surfaces. - agents.v1.DigitalTeammateProfile.LabelsEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: LabelsEntry - additionalProperties: false - agents.v1.EscalationPolicy: - type: object - properties: - approverUserIds: - type: array - items: - type: string - title: approver_user_ids - approverTeamIds: - type: array - items: - type: string - title: approver_team_ids - escalateAfterSeconds: - type: integer - title: escalate_after_seconds - format: int32 - fallbackChannel: - title: fallback_channel - $ref: '#/components/schemas/common.v1.DeliveryChannel' - title: EscalationPolicy - additionalProperties: false - description: |- - EscalationPolicy describes who must be contacted when the teammate blocks or - needs approval. - agents.v1.EvalBinding: - type: object - properties: - suiteName: - type: string - title: suite_name - metricName: - type: string - title: metric_name - minimumScore: - type: number - title: minimum_score - format: double - failureAction: - type: string - title: failure_action - title: EvalBinding - additionalProperties: false - description: EvalBinding describes one score that should gate or monitor teammate quality. - agents.v1.EvalPolicy: - type: object - properties: - bindings: - type: array - items: - $ref: '#/components/schemas/agents.v1.EvalBinding' - title: bindings - loopDefinitionId: - type: string - title: loop_definition_id - productionSampleRateBasisPoints: - type: integer - title: production_sample_rate_basis_points - maximum: 10000 - format: int32 - title: EvalPolicy - additionalProperties: false - description: EvalPolicy binds production behavior to loop and eval scoring. - agents.v1.InitiativePolicy: - type: object - properties: - triggers: - type: array - items: - $ref: '#/components/schemas/agents.v1.InitiativeTrigger' - title: triggers - maxInitiatedRunsPerDay: - type: integer - title: max_initiated_runs_per_day - format: int32 - requireHumanSeed: - type: boolean - title: require_human_seed - title: InitiativePolicy - additionalProperties: false - description: |- - InitiativePolicy describes bounded conditions where a teammate can start or - resume work proactively. - agents.v1.InitiativeTrigger: - type: object - properties: - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/agents.v1.InitiativeTriggerKind' - triggerRef: - type: string - title: trigger_ref - filterExpr: - type: string - title: filter_expr - workflowDefinitionId: - type: string - title: workflow_definition_id - objectiveTemplateId: - type: string - title: objective_template_id - title: InitiativeTrigger - additionalProperties: false - description: InitiativeTrigger binds a proactive trigger to workflow or objective state. - agents.v1.MemoryPolicy: - type: object - properties: - allowedScopeRefs: - type: array - items: - type: string - title: allowed_scope_refs - allowUserMemory: - type: boolean - title: allow_user_memory - allowTeamMemory: - type: boolean - title: allow_team_memory - allowAgentMemory: - type: boolean - title: allow_agent_memory - requireReviewForNewMemory: - type: boolean - title: require_review_for_new_memory - defaultRetentionDays: - type: integer - title: default_retention_days - format: int32 - requiredSourceTypes: - type: array - items: - type: string - title: required_source_types - allowCrossChannelRecall: - type: boolean - title: allow_cross_channel_recall - title: MemoryPolicy - additionalProperties: false - description: MemoryPolicy describes what a teammate may recall or propose remembering. - agents.v1.OutputPolicy: - type: object - properties: - requiredArtifactKinds: - type: array - items: - type: string - title: required_artifact_kinds - optionalArtifactKinds: - type: array - items: - type: string - title: optional_artifact_kinds - renderChannelCards: - type: boolean - title: render_channel_cards - defaultVisibility: - type: string - title: default_visibility - title: OutputPolicy - additionalProperties: false - description: OutputPolicy describes durable work products and channel-safe renderings. - agents.v1.PresencePolicy: - type: object - properties: - primaryChannel: - title: primary_channel - $ref: '#/components/schemas/common.v1.DeliveryChannel' - primaryChannelId: - type: string - title: primary_channel_id - defaultThreadPolicy: - type: string - title: default_thread_policy - progressUpdateIntervalSeconds: - type: integer - title: progress_update_interval_seconds - format: int32 - visibleEvents: - type: array - items: - $ref: '#/components/schemas/agents.v1.PresenceEvent' - title: visible_events - postActionReceipts: - type: boolean - title: post_action_receipts - postBlockerUpdates: - type: boolean - title: post_blocker_updates - title: PresencePolicy - additionalProperties: false - description: |- - PresencePolicy describes how a teammate reports work back to Slack or other - delivery channels. - agents.v1.TeammateChannelManifest: - type: object - properties: - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/agents.v1.TeammateChannelKind' - label: - type: string - title: label - deliveryChannel: - not: - enum: - - 0 - title: delivery_channel - $ref: '#/components/schemas/common.v1.DeliveryChannel' - platformSurface: - title: platform_surface - $ref: '#/components/schemas/common.v1.Surface' - channelId: - type: string - title: channel_id - capabilities: - type: array - items: - $ref: '#/components/schemas/agents.v1.TeammateChannelCapability' - title: capabilities - inboundEvents: - type: array - items: - $ref: '#/components/schemas/agents.v1.TeammateChannelEventKind' - title: inbound_events - runtimeEvents: - type: array - items: - $ref: '#/components/schemas/agents.v1.TeammateRuntimeRenderEventKind' - title: runtime_events - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: TeammateChannelManifest - additionalProperties: false - description: |- - TeammateChannelManifest describes one channel adapter supported by a - teammate profile. Durable execution remains owned by AgentRuntime; this - manifest lets product surfaces declare the provider-specific ingress and - rendering coverage they can project. - agents.v1.TeammateChannelManifest.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - agents.v1.TeammateResponsibility: - type: object - properties: - id: - type: string - title: id - title: - type: string - title: title - description: - type: string - title: description - capabilityRefs: - type: array - items: - type: string - title: capability_refs - ownedEntityTypes: - type: array - items: - $ref: '#/components/schemas/common.v1.EntityType' - title: owned_entity_types - defaultSkillIds: - type: array - items: - type: string - title: default_skill_ids - promptNames: - type: array - items: - type: string - title: prompt_names - successMetricRefs: - type: array - items: - type: string - title: success_metric_refs - title: TeammateResponsibility - additionalProperties: false - description: |- - TeammateResponsibility binds a role claim to capabilities, entities, prompts, - skills, and measurable outcomes. - codex.v1.CodexApprovalPolicy: - type: object - properties: - dryRun: - type: boolean - title: dry_run - allowWrites: - type: boolean - title: allow_writes - requirePlanApproval: - type: boolean - title: require_plan_approval - requirePatchApproval: - type: boolean - title: require_patch_approval - requireCommandApproval: - type: boolean - title: require_command_approval - protectedPathGlobs: - type: array - items: - type: string - title: protected_path_globs - approverEntityIds: - type: array - items: - type: string - title: approver_entity_ids - networkEgressAllowlist: - type: array - items: - type: string - title: network_egress_allowlist - scrubSecretsFromOutputs: - type: boolean - title: scrub_secrets_from_outputs - sandboxMode: - type: string - title: sandbox_mode - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: CodexApprovalPolicy - additionalProperties: false - description: |- - CodexApprovalPolicy captures governance controls before a worker performs - write, network, or otherwise sensitive operations. - codex.v1.CodexApprovalPolicy.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - codex.v1.CodexBudgetPolicy: - type: object - properties: - maxInputTokens: - type: - - integer - - string - title: max_input_tokens - format: int64 - maxOutputTokens: - type: - - integer - - string - title: max_output_tokens - format: int64 - maxTotalTokens: - type: - - integer - - string - title: max_total_tokens - format: int64 - maxCostMicros: - type: - - integer - - string - title: max_cost_micros - format: int64 - maxRunSeconds: - type: integer - title: max_run_seconds - format: int32 - maxToolCalls: - type: integer - title: max_tool_calls - format: int32 - maxRetries: - type: integer - title: max_retries - format: int32 - title: CodexBudgetPolicy - additionalProperties: false - description: CodexBudgetPolicy defines per-run resource limits. - codex.v1.CodexContextItem: - type: object - properties: - sourceKind: - title: source_kind - $ref: '#/components/schemas/codex.v1.CodexContextSourceKind' - id: - type: string - title: id - uri: - type: string - title: uri - title: - type: string - title: title - text: - type: string - title: text - contentType: - type: string - title: content_type - digest: - type: string - title: digest - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: CodexContextItem - additionalProperties: false - description: CodexContextItem is a single enriched context object available to the run. - codex.v1.CodexContextItem.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - codex.v1.CodexConversationRef: - type: object - properties: - sessionId: - type: string - title: session_id - appServerThreadId: - type: string - title: app_server_thread_id - previousRunId: - type: string - title: previous_run_id - parentRunId: - type: string - title: parent_run_id - followupToTurnId: - type: string - title: followup_to_turn_id - channelThreadId: - type: string - title: channel_thread_id - channelMessageId: - type: string - title: channel_message_id - keepSessionAlive: - type: boolean - title: keep_session_alive - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: CodexConversationRef - additionalProperties: false - description: CodexConversationRef carries durable session coordinates across turns. - codex.v1.CodexConversationRef.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - codex.v1.CodexInteractionDecision: - type: object - properties: - interactionType: - title: interaction_type - $ref: '#/components/schemas/codex.v1.CodexInteractionType' - decision: - type: string - title: decision - reason: - type: string - title: reason - actorEntityId: - type: string - title: actor_entity_id - selectedChoice: - type: string - title: selected_choice - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Struct' - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: CodexInteractionDecision - additionalProperties: false - description: CodexInteractionDecision captures the user's response to a Codex control. - codex.v1.CodexInteractionDecision.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - codex.v1.CodexInteractionRequest: - type: object - properties: - interactionType: - title: interaction_type - $ref: '#/components/schemas/codex.v1.CodexInteractionType' - runId: - type: string - title: run_id - waitId: - type: string - title: wait_id - stepId: - type: string - title: step_id - artifactId: - type: string - title: artifact_id - patchId: - type: string - title: patch_id - prompt: - type: string - title: prompt - choices: - type: array - items: - type: string - title: choices - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Struct' - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: CodexInteractionRequest - additionalProperties: false - description: |- - CodexInteractionRequest describes a pending human decision projected to a - channel surface. - codex.v1.CodexInteractionRequest.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - codex.v1.CodexMemoryScope: - type: object - properties: - kind: - title: kind - $ref: '#/components/schemas/codex.v1.CodexMemoryScopeKind' - key: - type: string - title: key - retentionDays: - type: integer - title: retention_days - format: int32 - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: CodexMemoryScope - additionalProperties: false - description: CodexMemoryScope describes what prior run knowledge should be retrieved. - codex.v1.CodexMemoryScope.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - codex.v1.CodexOutcomeSignal: - type: object - properties: - runId: - type: string - title: run_id - pullRequestUrl: - type: string - title: pull_request_url - merged: - type: boolean - title: merged - reverted: - type: boolean - title: reverted - humanEdited: - type: boolean - title: human_edited - channelReaction: - type: string - title: channel_reaction - reviewOutcome: - type: string - title: review_outcome - observedAt: - title: observed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: CodexOutcomeSignal - additionalProperties: false - description: CodexOutcomeSignal feeds evaluation and routing loops after the run. - codex.v1.CodexOutcomeSignal.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - codex.v1.CodexOutputTarget: - type: object - properties: - kind: - title: kind - $ref: '#/components/schemas/codex.v1.CodexOutputKind' - id: - type: string - title: id - uri: - type: string - title: uri - title: - type: string - title: title - draft: - type: boolean - title: draft - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: CodexOutputTarget - additionalProperties: false - description: CodexOutputTarget describes a desired or produced external output. - codex.v1.CodexOutputTarget.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - codex.v1.CodexPreparedFutureRef: - type: object - properties: - preparedFutureId: - type: string - title: prepared_future_id - cerebroActionId: - type: string - title: cerebro_action_id - cerebroPredictionId: - type: string - title: cerebro_prediction_id - cerebroFactIds: - type: array - items: - type: string - title: cerebro_fact_ids - sourceRecordIds: - type: array - items: - type: string - title: source_record_ids - artifactIds: - type: array - items: - type: string - title: artifact_ids - approvalRequestIds: - type: array - items: - type: string - title: approval_request_ids - evidenceUri: - type: string - title: evidence_uri - sourceHealth: - type: string - title: source_health - riskLevel: - type: string - title: risk_level - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: CodexPreparedFutureRef - additionalProperties: false - description: |- - CodexPreparedFutureRef ties a Codex run to the reviewable next move it is - preparing. It is a grouping contract, not an approval or execution grant. - codex.v1.CodexPreparedFutureRef.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - codex.v1.CodexRoutingPolicy: - type: object - properties: - backend: - title: backend - $ref: '#/components/schemas/codex.v1.CodexBackend' - workerQueue: - type: string - title: worker_queue - modelTier: - type: string - title: model_tier - preferredAgentId: - type: string - title: preferred_agent_id - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: CodexRoutingPolicy - additionalProperties: false - description: CodexRoutingPolicy captures backend and worker selection. - codex.v1.CodexRoutingPolicy.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - codex.v1.CodexRunProgress: - type: object - properties: - stage: - title: stage - $ref: '#/components/schemas/codex.v1.CodexProgressStage' - safeSummary: - type: string - title: safe_summary - progressPercent: - type: integer - title: progress_percent - maximum: 100 - format: int32 - filesRead: - type: integer - title: files_read - format: int32 - filesChanged: - type: integer - title: files_changed - format: int32 - commandsRun: - type: integer - title: commands_run - format: int32 - inputTokens: - type: - - integer - - string - title: input_tokens - format: int64 - outputTokens: - type: - - integer - - string - title: output_tokens - format: int64 - estimatedCostMicros: - type: - - integer - - string - title: estimated_cost_micros - format: int64 - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: CodexRunProgress - additionalProperties: false - description: CodexRunProgress is the compact, user-visible progress projection. - codex.v1.CodexRunProgress.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - codex.v1.CodexWorkRequest: - type: object - properties: - actionType: - title: action_type - $ref: '#/components/schemas/codex.v1.CodexActionType' - executionIntent: - title: execution_intent - $ref: '#/components/schemas/codex.v1.CodexExecutionIntent' - prompt: - type: string - title: prompt - repo: - type: string - title: repo - cwd: - type: string - title: cwd - branch: - type: string - title: branch - baseBranch: - type: string - title: base_branch - tenantId: - type: string - title: tenant_id - reason: - type: string - title: reason - conversation: - title: conversation - $ref: '#/components/schemas/codex.v1.CodexConversationRef' - routing: - title: routing - $ref: '#/components/schemas/codex.v1.CodexRoutingPolicy' - budget: - title: budget - $ref: '#/components/schemas/codex.v1.CodexBudgetPolicy' - approvalPolicy: - title: approval_policy - $ref: '#/components/schemas/codex.v1.CodexApprovalPolicy' - interactivityMode: - title: interactivity_mode - $ref: '#/components/schemas/codex.v1.CodexInteractivityMode' - contextItems: - type: array - items: - $ref: '#/components/schemas/codex.v1.CodexContextItem' - title: context_items - desiredOutputs: - type: array - items: - $ref: '#/components/schemas/codex.v1.CodexOutputTarget' - title: desired_outputs - memoryScopes: - type: array - items: - $ref: '#/components/schemas/codex.v1.CodexMemoryScope' - title: memory_scopes - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - preparedFuture: - title: prepared_future - $ref: '#/components/schemas/codex.v1.CodexPreparedFutureRef' - resourceId: - type: string - title: resource_id - maxLength: 512 - pattern: ^$|^[^/\\:][^\\:]*$|^[A-Za-z][A-Za-z0-9+.-]+:([^A-Za-z/\\][^\\]*|[A-Za-z]([^:\\][^\\]*)?)$ - description: |- - Stable Platform resource identity. Local absolute paths are forbidden, - including drive-root forms after local schemes (e.g. file:C:/Windows). - requestedAuthority: - title: requested_authority - $ref: '#/components/schemas/codex.v1.CodexAuthorityScope' - title: CodexWorkRequest - additionalProperties: false - description: |+ - CodexWorkRequest is the typed payload for Slack, GitHub, Linear, CLI, IDE, - and monitoring-triggered Codex work. - resource_id must not be an absolute local path: - ``` - this.resource_id == '' || (!this.resource_id.startsWith('/') && !this.resource_id.startsWith('\\') && !this.resource_id.matches('^[A-Za-z]:[/\\\\].*') && !this.resource_id.matches('^[A-Za-z][A-Za-z0-9+.-]*:[A-Za-z]:.*')) - ``` - - codex.v1.CodexWorkRequest.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - google.protobuf.ListValue: - type: object - properties: - values: - type: array - items: - $ref: '#/components/schemas/google.protobuf.Value' - title: values - description: Repeated field of dynamically typed values. - title: ListValue - additionalProperties: false - description: |- - `ListValue` is a wrapper around a repeated field of values. - - The JSON representation for `ListValue` is JSON array. - google.protobuf.Struct: - type: object - additionalProperties: - $ref: '#/components/schemas/google.protobuf.Value' - description: |- - `Struct` represents a structured data value, consisting of fields - which map to dynamically typed values. In some languages, `Struct` - might be supported by a native representation. For example, in - scripting languages like JS a struct is represented as an - object. The details of that representation are described together - with the proto support for the language. - - The JSON representation for `Struct` is JSON object. - google.protobuf.Struct.FieldsEntry: - type: object - properties: - key: - type: string - title: key - value: - title: value - $ref: '#/components/schemas/google.protobuf.Value' - title: FieldsEntry - additionalProperties: false - google.protobuf.Timestamp: - type: string - examples: - - 1s - - 1.000340012s - format: date-time - description: |- - A Timestamp represents a point in time independent of any time zone or local - calendar, encoded as a count of seconds and fractions of seconds at - nanosecond resolution. The count is relative to an epoch at UTC midnight on - January 1, 1970, in the proleptic Gregorian calendar which extends the - Gregorian calendar backwards to year one. - - All minutes are 60 seconds long. Leap seconds are "smeared" so that no leap - second table is needed for interpretation, using a [24-hour linear - smear](https://developers.google.com/time/smear). - - The range is from 0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z. By - restricting to that range, we ensure that we can convert to and from [RFC - 3339](https://www.ietf.org/rfc/rfc3339.txt) date strings. - - # Examples - - Example 1: Compute Timestamp from POSIX `time()`. - - Timestamp timestamp; - timestamp.set_seconds(time(NULL)); - timestamp.set_nanos(0); - - Example 2: Compute Timestamp from POSIX `gettimeofday()`. - - struct timeval tv; - gettimeofday(&tv, NULL); - - Timestamp timestamp; - timestamp.set_seconds(tv.tv_sec); - timestamp.set_nanos(tv.tv_usec * 1000); - - Example 3: Compute Timestamp from Win32 `GetSystemTimeAsFileTime()`. - - FILETIME ft; - GetSystemTimeAsFileTime(&ft); - UINT64 ticks = (((UINT64)ft.dwHighDateTime) << 32) | ft.dwLowDateTime; - - // A Windows tick is 100 nanoseconds. Windows epoch 1601-01-01T00:00:00Z - // is 11644473600 seconds before Unix epoch 1970-01-01T00:00:00Z. - Timestamp timestamp; - timestamp.set_seconds((INT64) ((ticks / 10000000) - 11644473600LL)); - timestamp.set_nanos((INT32) ((ticks % 10000000) * 100)); - - Example 4: Compute Timestamp from Java `System.currentTimeMillis()`. - - long millis = System.currentTimeMillis(); - - Timestamp timestamp = Timestamp.newBuilder().setSeconds(millis / 1000) - .setNanos((int) ((millis % 1000) * 1000000)).build(); - - Example 5: Compute Timestamp from Java `Instant.now()`. - - Instant now = Instant.now(); - - Timestamp timestamp = - Timestamp.newBuilder().setSeconds(now.getEpochSecond()) - .setNanos(now.getNano()).build(); - - Example 6: Compute Timestamp from current time in Python. - - timestamp = Timestamp() - timestamp.GetCurrentTime() - - # JSON Mapping - - In JSON format, the Timestamp type is encoded as a string in the - [RFC 3339](https://www.ietf.org/rfc/rfc3339.txt) format. That is, the - format is "{year}-{month}-{day}T{hour}:{min}:{sec}[.{frac_sec}]Z" - where {year} is always expressed using four digits while {month}, {day}, - {hour}, {min}, and {sec} are zero-padded to two digits each. The fractional - seconds, which can go up to 9 digits (i.e. up to 1 nanosecond resolution), - are optional. The "Z" suffix indicates the timezone ("UTC"); the timezone - is required. A proto3 JSON serializer should always use UTC (as indicated by - "Z") when printing the Timestamp type and a proto3 JSON parser should be - able to accept both UTC and other timezones (as indicated by an offset). - - For example, "2017-01-15T01:30:15.01Z" encodes 15.01 seconds past - 01:30 UTC on January 15, 2017. - - In JavaScript, one can convert a Date object to this format using the - standard - [toISOString()](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Date/toISOString) - method. In Python, a standard `datetime.datetime` object can be converted - to this format using - [`strftime`](https://docs.python.org/2/library/time.html#time.strftime) with - the time format spec '%Y-%m-%dT%H:%M:%S.%fZ'. Likewise, in Java, one can use - the Joda Time's [`ISODateTimeFormat.dateTime()`]( - http://joda-time.sourceforge.net/apidocs/org/joda/time/format/ISODateTimeFormat.html#dateTime() - ) to obtain a formatter capable of generating timestamps in this format. - google.protobuf.Value: - oneOf: - - type: "null" - - type: number - - type: string - - type: boolean - - type: array - - type: object - additionalProperties: true - description: |- - `Value` represents a dynamically typed value which can be either - null, a number, a string, a boolean, a recursive struct value, or a - list of values. A producer of value is expected to set one of these - variants. Absence of any variant indicates an error. - - The JSON representation for `Value` is JSON value. - objectives.v1.MutationRecord: - type: object - properties: - targetIntegration: - type: string - title: target_integration - operation: - type: string - title: operation - status: - title: status - $ref: '#/components/schemas/objectives.v1.MutationStatus' - approvalId: - type: string - title: approval_id - title: MutationRecord - additionalProperties: false - description: MutationRecord tracks a write operation performed by an objective. - objectives.v1.Objective: - type: object - properties: - id: - type: string - title: id - workspaceId: - type: string - title: workspace_id - agentId: - type: string - title: agent_id - surface: - type: string - title: surface - title: - type: string - title: title - description: - type: string - title: description - state: - title: state - $ref: '#/components/schemas/objectives.v1.ObjectiveState' - provenance: - type: array - items: - $ref: '#/components/schemas/objectives.v1.ProvenanceRecord' - title: provenance - mutations: - type: array - items: - $ref: '#/components/schemas/objectives.v1.MutationRecord' - title: mutations - wakeSchedule: - title: wake_schedule - $ref: '#/components/schemas/objectives.v1.WakeSchedule' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - surfaceType: - title: surface_type - $ref: '#/components/schemas/common.v1.Surface' - idempotencyKey: - type: string - title: idempotency_key - organizationId: - type: string - title: organization_id - title: Objective - additionalProperties: false - description: Objective is the canonical agent objective record. - objectives.v1.ProvenanceRecord: - type: object - properties: - sourceIntegration: - type: string - title: source_integration - sourceId: - type: string - title: source_id - freshnessSeconds: - type: integer - title: freshness_seconds - format: int32 - confidence: - type: number - title: confidence - format: float - title: ProvenanceRecord - additionalProperties: false - description: ProvenanceRecord tracks where data came from. - objectives.v1.WakeSchedule: - type: object - properties: - wakeAt: - title: wake_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - reason: - type: string - title: reason - retryCount: - type: integer - title: retry_count - format: int32 - maxRetries: - type: integer - title: max_retries - format: int32 - backoffSeconds: - type: integer - title: backoff_seconds - format: int32 - title: WakeSchedule - additionalProperties: false - description: WakeSchedule defines when and how an objective should be reactivated. - connect-protocol-version: - type: number - title: Connect-Protocol-Version - enum: - - 1 - description: Define the version of the Connect protocol - const: 1 - connect-timeout-header: - type: number - title: Connect-Timeout-Ms - description: Define the timeout, in ms - connect.error: - type: object - properties: - code: - type: string - examples: - - not_found - enum: - - canceled - - unknown - - invalid_argument - - deadline_exceeded - - not_found - - already_exists - - permission_denied - - resource_exhausted - - failed_precondition - - aborted - - out_of_range - - unimplemented - - internal - - unavailable - - data_loss - - unauthenticated - description: The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code]. - message: - type: string - description: A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client. - detail: - $ref: '#/components/schemas/google.protobuf.Any' - title: Connect Error - additionalProperties: true - description: 'Error type returned by Connect: https://connectrpc.com/docs/go/errors/#http-representation' - google.protobuf.Any: - type: object - properties: - type: - type: string - value: - type: string - format: binary - debug: - type: object - additionalProperties: true - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. -security: [] -tags: - - name: agentruntime.v1.AgentRuntimeService - description: |- - AgentRuntimeService accepts normalized triggers and manages durable - AgentRun execution attempts. Workers claim runs by lease, checkpoint their - progress, release compute while waiting for human/input/event gates, and - resume from checkpoints rather than replaying LLM or tool calls. diff --git a/openapi/agents/v1/agents.openapi.yaml b/openapi/agents/v1/agents.openapi.yaml deleted file mode 100644 index b198ddc..0000000 --- a/openapi/agents/v1/agents.openapi.yaml +++ /dev/null @@ -1,3001 +0,0 @@ -openapi: 3.1.0 -info: - title: agents.v1 -paths: - /agents.v1.AgentService/Register: - post: - tags: - - agents.v1.AgentService - summary: Register - description: Register creates a new agent definition. - operationId: agents.v1.AgentService.Register - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.RegisterRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.RegisterResponse' - /agents.v1.AgentService/Get: - post: - tags: - - agents.v1.AgentService - summary: Get - description: Get retrieves an agent by ID. - operationId: agents.v1.AgentService.Get - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.GetRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.GetResponse' - /agents.v1.AgentService/List: - post: - tags: - - agents.v1.AgentService - summary: List - description: List returns agents matching the query filters. - operationId: agents.v1.AgentService.List - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.ListRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.ListResponse' - /agents.v1.AgentService/Update: - post: - tags: - - agents.v1.AgentService - summary: Update - description: Update modifies mutable agent metadata (name, description, surfaces). - operationId: agents.v1.AgentService.Update - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.UpdateRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.UpdateResponse' - /agents.v1.AgentService/Deregister: - post: - tags: - - agents.v1.AgentService - summary: Deregister - description: Deregister removes an agent from the registry. - operationId: agents.v1.AgentService.Deregister - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.DeregisterRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.DeregisterResponse' - /agents.v1.AgentService/PushConfig: - post: - tags: - - agents.v1.AgentService - summary: PushConfig - description: |- - PushConfig creates a new immutable configuration version for an agent. - The agent's active_config_version advances atomically. - operationId: agents.v1.AgentService.PushConfig - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.PushConfigRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.PushConfigResponse' - /agents.v1.AgentService/GetConfig: - post: - tags: - - agents.v1.AgentService - summary: GetConfig - description: GetConfig retrieves a specific configuration version. - operationId: agents.v1.AgentService.GetConfig - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.GetConfigRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.GetConfigResponse' - /agents.v1.AgentService/ListConfigs: - post: - tags: - - agents.v1.AgentService - summary: ListConfigs - description: ListConfigs returns all configuration versions for an agent. - operationId: agents.v1.AgentService.ListConfigs - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.ListConfigsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.ListConfigsResponse' - /agents.v1.AgentService/RollbackConfig: - post: - tags: - - agents.v1.AgentService - summary: RollbackConfig - description: RollbackConfig atomically reverts an agent to a prior configuration version. - operationId: agents.v1.AgentService.RollbackConfig - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.RollbackConfigRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.RollbackConfigResponse' - /agents.v1.AgentService/Delegate: - post: - tags: - - agents.v1.AgentService - summary: Delegate - description: |- - Delegate requests that another agent (or any agent with a matching - capability) accept a unit of work. The delegation is tracked as a - DelegationRecord and linked to the originating objective and optional - workflow step. - operationId: agents.v1.AgentService.Delegate - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.DelegateRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.DelegateResponse' - /agents.v1.AgentService/ResolveDelegation: - post: - tags: - - agents.v1.AgentService - summary: ResolveDelegation - description: ResolveDelegation records the outcome of a delegation. - operationId: agents.v1.AgentService.ResolveDelegation - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.ResolveDelegationRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.ResolveDelegationResponse' - /agents.v1.AgentService/RenewDelegationLease: - post: - tags: - - agents.v1.AgentService - summary: RenewDelegationLease - description: |- - RenewDelegationLease records observed remote progress for an active - delegation so reserved target capacity is not reaped while work is healthy. - operationId: agents.v1.AgentService.RenewDelegationLease - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.RenewDelegationLeaseRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.RenewDelegationLeaseResponse' - /agents.v1.AgentService/ControlA2ADelegationTask: - post: - tags: - - agents.v1.AgentService - summary: ControlA2ADelegationTask - description: |- - ControlA2ADelegationTask sends a fenced operating-plane control request to - the remote A2A task backing a Platform delegation. This is the Platform - control surface for steering, collecting from, interrupting, or canceling - a remote Maestro task or one of its subagent lanes. - operationId: agents.v1.AgentService.ControlA2ADelegationTask - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.ControlA2ADelegationTaskRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.ControlA2ADelegationTaskResponse' - /agents.v1.AgentService/GetDelegation: - post: - tags: - - agents.v1.AgentService - summary: GetDelegation - description: GetDelegation retrieves a delegation record by ID. - operationId: agents.v1.AgentService.GetDelegation - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.GetDelegationRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.GetDelegationResponse' - /agents.v1.AgentService/ListDelegations: - post: - tags: - - agents.v1.AgentService - summary: ListDelegations - description: ListDelegations returns delegations matching the query filters. - operationId: agents.v1.AgentService.ListDelegations - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.ListDelegationsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.ListDelegationsResponse' - /agents.v1.AgentService/GetA2ADelegationGraph: - post: - tags: - - agents.v1.AgentService - summary: GetA2ADelegationGraph - description: |- - GetA2ADelegationGraph returns the server-owned swarm graph for a remote - A2A delegation family. Callers may anchor the graph by root delegation id - or by any child delegation id in the lineage. - operationId: agents.v1.AgentService.GetA2ADelegationGraph - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.GetA2ADelegationGraphRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.GetA2ADelegationGraphResponse' - /agents.v1.AgentService/Heartbeat: - post: - tags: - - agents.v1.AgentService - summary: Heartbeat - description: |- - Heartbeat records agent liveness. The registry uses this to maintain - presence state and route capability-based delegation requests. - operationId: agents.v1.AgentService.Heartbeat - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.HeartbeatRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/agents.v1.HeartbeatResponse' -components: - schemas: - agents.v1.A2ADelegationTaskControlMode: - type: string - title: A2ADelegationTaskControlMode - enum: - - A2A_DELEGATION_TASK_CONTROL_MODE_UNSPECIFIED - - A2A_DELEGATION_TASK_CONTROL_MODE_STEER - - A2A_DELEGATION_TASK_CONTROL_MODE_FOLLOWUP - - A2A_DELEGATION_TASK_CONTROL_MODE_COLLECT - - A2A_DELEGATION_TASK_CONTROL_MODE_INTERRUPT - - A2A_DELEGATION_TASK_CONTROL_MODE_CANCEL - description: |- - A2ADelegationTaskControlMode describes the remote task-control action that - Platform asks the target A2A peer to apply. - agents.v1.AgentStatus: - type: string - title: AgentStatus - enum: - - AGENT_STATUS_UNSPECIFIED - - AGENT_STATUS_ACTIVE - - AGENT_STATUS_IDLE - - AGENT_STATUS_BUSY - - AGENT_STATUS_OFFLINE - - AGENT_STATUS_DEGRADED - - AGENT_STATUS_SUSPENDED - description: AgentStatus describes the operational state of an agent. - agents.v1.AutonomyAuthority: - type: string - title: AutonomyAuthority - enum: - - AUTONOMY_AUTHORITY_UNSPECIFIED - - AUTONOMY_AUTHORITY_OWN - - AUTONOMY_AUTHORITY_RECOMMEND - - AUTONOMY_AUTHORITY_REQUIRE_APPROVAL - - AUTONOMY_AUTHORITY_DENY - description: AutonomyAuthority describes how independently a teammate may act. - agents.v1.CommitmentKind: - type: string - title: CommitmentKind - enum: - - COMMITMENT_KIND_UNSPECIFIED - - COMMITMENT_KIND_FOLLOW_UP - - COMMITMENT_KIND_WATCH - - COMMITMENT_KIND_RETRY - - COMMITMENT_KIND_SUMMARIZE - - COMMITMENT_KIND_MONITOR - - COMMITMENT_KIND_REMEDIATE - - COMMITMENT_KIND_HANDOFF - description: CommitmentKind describes the durable commitments a teammate can accept. - agents.v1.DelegationStatus: - type: string - title: DelegationStatus - enum: - - DELEGATION_STATUS_UNSPECIFIED - - DELEGATION_STATUS_PENDING - - DELEGATION_STATUS_ACCEPTED - - DELEGATION_STATUS_REJECTED - - DELEGATION_STATUS_COMPLETED - - DELEGATION_STATUS_FAILED - - DELEGATION_STATUS_TIMED_OUT - description: DelegationStatus describes the lifecycle state of a delegation. - agents.v1.InitiativeTriggerKind: - type: string - title: InitiativeTriggerKind - enum: - - INITIATIVE_TRIGGER_KIND_UNSPECIFIED - - INITIATIVE_TRIGGER_KIND_SCHEDULE - - INITIATIVE_TRIGGER_KIND_SLACK_EVENT - - INITIATIVE_TRIGGER_KIND_PLATFORM_EVENT - - INITIATIVE_TRIGGER_KIND_OBJECTIVE_WAKE - - INITIATIVE_TRIGGER_KIND_WAIT_RESOLVED - - INITIATIVE_TRIGGER_KIND_EVAL_REGRESSION - - INITIATIVE_TRIGGER_KIND_STALLED_WORK - description: |- - InitiativeTriggerKind describes events that can let a teammate start work - without a fresh direct human prompt. - agents.v1.PresenceEvent: - type: string - title: PresenceEvent - enum: - - PRESENCE_EVENT_UNSPECIFIED - - PRESENCE_EVENT_ACCEPTED - - PRESENCE_EVENT_WAITING - - PRESENCE_EVENT_PROGRESS - - PRESENCE_EVENT_BLOCKED - - PRESENCE_EVENT_COMPLETED - - PRESENCE_EVENT_FAILED - - PRESENCE_EVENT_ESCALATED - description: PresenceEvent describes channel-visible teammate activity. - agents.v1.TeammateChannelCapability: - type: string - title: TeammateChannelCapability - enum: - - TEAMMATE_CHANNEL_CAPABILITY_UNSPECIFIED - - TEAMMATE_CHANNEL_CAPABILITY_INGEST - - TEAMMATE_CHANNEL_CAPABILITY_RENDER - description: |- - TeammateChannelCapability describes what a channel adapter can do for a - teammate profile. - agents.v1.TeammateChannelEventKind: - type: string - title: TeammateChannelEventKind - enum: - - TEAMMATE_CHANNEL_EVENT_KIND_UNSPECIFIED - - TEAMMATE_CHANNEL_EVENT_KIND_MESSAGE_CREATED - - TEAMMATE_CHANNEL_EVENT_KIND_THREAD_REPLY_CREATED - - TEAMMATE_CHANNEL_EVENT_KIND_COMMAND_INVOKED - - TEAMMATE_CHANNEL_EVENT_KIND_ACTION_INVOKED - - TEAMMATE_CHANNEL_EVENT_KIND_REACTION_ADDED - - TEAMMATE_CHANNEL_EVENT_KIND_REACTION_REMOVED - - TEAMMATE_CHANNEL_EVENT_KIND_ASSISTANT_THREAD_STARTED - - TEAMMATE_CHANNEL_EVENT_KIND_ASSISTANT_THREAD_CONTEXT_CHANGED - - TEAMMATE_CHANNEL_EVENT_KIND_EMAIL_RECEIVED - - TEAMMATE_CHANNEL_EVENT_KIND_CALENDAR_EVENT_CHANGED - - TEAMMATE_CHANNEL_EVENT_KIND_ISSUE_CHANGED - - TEAMMATE_CHANNEL_EVENT_KIND_SCHEDULED_WAKE - - TEAMMATE_CHANNEL_EVENT_KIND_WEBHOOK_RECEIVED - description: |- - TeammateChannelEventKind describes normalized inbound channel events that can - become AgentRuntime triggers. - agents.v1.TeammateChannelKind: - type: string - title: TeammateChannelKind - enum: - - TEAMMATE_CHANNEL_KIND_UNSPECIFIED - - TEAMMATE_CHANNEL_KIND_SLACK - - TEAMMATE_CHANNEL_KIND_EMAIL - - TEAMMATE_CHANNEL_KIND_CALENDAR - - TEAMMATE_CHANNEL_KIND_JIRA - - TEAMMATE_CHANNEL_KIND_TEAMS - - TEAMMATE_CHANNEL_KIND_WEB - - TEAMMATE_CHANNEL_KIND_WEBHOOK - - TEAMMATE_CHANNEL_KIND_WHATSAPP - - TEAMMATE_CHANNEL_KIND_APPLE_MESSAGES - description: |- - TeammateChannelKind identifies a product or provider channel that can ingest - user activity or render teammate runtime events. It intentionally lives in - agents/v1 instead of agentruntime/v1 so teammate profiles can describe - supported channels without creating a proto import cycle. - agents.v1.TeammateLifecycle: - type: string - title: TeammateLifecycle - enum: - - TEAMMATE_LIFECYCLE_UNSPECIFIED - - TEAMMATE_LIFECYCLE_DRAFT - - TEAMMATE_LIFECYCLE_ACTIVE - - TEAMMATE_LIFECYCLE_PAUSED - - TEAMMATE_LIFECYCLE_DEPRECATED - description: |- - TeammateLifecycle describes whether a teammate profile can be used to - initiate durable work. - agents.v1.TeammateRuntimeRenderEventKind: - type: string - title: TeammateRuntimeRenderEventKind - enum: - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_UNSPECIFIED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_TRIGGER_ACCEPTED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_RUN_STARTED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_PROGRESS - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_STEP_STARTED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_STEP_COMPLETED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_OBJECTIVE_UPDATED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_APPROVAL_REQUESTED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_APPROVAL_RESOLVED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_TOOL_PROPOSED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_TOOL_COMPLETED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_ARTIFACT_CREATED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_MEMORY_PROPOSED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_WAITING - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_RESUMED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_COMPLETED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_FAILED - description: |- - TeammateRuntimeRenderEventKind describes Platform runtime events a channel - adapter can project back into the provider surface. - common.v1.DeliveryChannel: - type: string - title: DeliveryChannel - enum: - - DELIVERY_CHANNEL_UNSPECIFIED - - DELIVERY_CHANNEL_SLACK - - DELIVERY_CHANNEL_EMAIL - - DELIVERY_CHANNEL_WEBHOOK - - DELIVERY_CHANNEL_IN_APP - - DELIVERY_CHANNEL_PUSH - description: DeliveryChannel identifies the notification delivery channel. - common.v1.EntityType: - type: string - title: EntityType - enum: - - ENTITY_TYPE_UNSPECIFIED - - ENTITY_TYPE_CONTACT - - ENTITY_TYPE_COMPANY - - ENTITY_TYPE_DEAL - - ENTITY_TYPE_TICKET - - ENTITY_TYPE_CUSTOMER - - ENTITY_TYPE_OPPORTUNITY - description: EntityType identifies the kind of entity across systems. - common.v1.RiskLevel: - type: string - title: RiskLevel - enum: - - RISK_LEVEL_UNSPECIFIED - - RISK_LEVEL_LOW - - RISK_LEVEL_MEDIUM - - RISK_LEVEL_HIGH - - RISK_LEVEL_CRITICAL - description: RiskLevel classifies the risk of an action. - common.v1.Surface: - type: string - title: Surface - enum: - - SURFACE_UNSPECIFIED - - SURFACE_ENSEMBLE - - SURFACE_CHAT - - SURFACE_MAESTRO - - SURFACE_CONDUCTOR - - SURFACE_SLACK - - SURFACE_EXTERNAL_AGENT - description: |- - Surface identifies the product or channel surface that originated a platform - action. It is shared by runtime, audit, and product-facing services so - callers do not invent drift-prone string labels. - google.protobuf.NullValue: - type: string - title: NullValue - enum: - - NULL_VALUE - description: |- - `NullValue` is a singleton enumeration to represent the null value for the - `Value` type union. - - The JSON representation for `NullValue` is JSON `null`. - agents.v1.A2ADelegationGraphEdge: - type: object - properties: - parentDelegationId: - type: string - title: parent_delegation_id - childDelegationId: - type: string - title: child_delegation_id - title: A2ADelegationGraphEdge - additionalProperties: false - agents.v1.A2ADelegationGraphNode: - type: object - properties: - delegation: - title: delegation - $ref: '#/components/schemas/agents.v1.DelegationRecord' - depth: - type: integer - title: depth - format: int32 - childCount: - type: integer - title: child_count - format: int32 - terminal: - type: boolean - title: terminal - title: A2ADelegationGraphNode - additionalProperties: false - agents.v1.A2ADelegationTaskControlResult: - type: object - properties: - taskId: - type: string - title: task_id - state: - type: string - title: state - controlId: - type: string - title: control_id - controlMode: - type: string - title: control_mode - cancelled: - type: boolean - title: cancelled - queuedForWorker: - type: boolean - title: queued_for_worker - parentTaskId: - type: string - title: parent_task_id - targetRunId: - type: string - title: target_run_id - appliedRunId: - type: string - title: applied_run_id - targetExternal: - type: boolean - title: target_external - subagentLaneId: - type: string - title: subagent_lane_id - workItemId: - type: string - title: work_item_id - observedAt: - title: observed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - rawPayloadWithheld: - type: boolean - title: raw_payload_withheld - title: A2ADelegationTaskControlResult - additionalProperties: false - agents.v1.Agent: - type: object - properties: - id: - type: string - title: id - workspaceId: - type: string - title: workspace_id - name: - type: string - title: name - description: - type: string - title: description - agentType: - type: string - title: agent_type - description: |- - agent_type aligns with identity/v1 IntrospectResponse.agent_type and - IssueAgentTokenRequest.agent_type. Examples: "sdr", "support", "coding", - "ops", "research". - capabilities: - type: array - items: - type: string - title: capabilities - description: |- - capabilities aligns with identity/v1 IntrospectResponse.capabilities and - IssueAgentTokenRequest.capabilities. Used by capability-based delegation - routing. Examples: "hubspot-write", "email-send", "code-review". - surfaces: - type: array - items: - type: string - title: surfaces - description: |- - surfaces this agent can operate on. Aligns with the surface field in - meter/v1, objectives/v1, approvals/v1. Examples: "ensemble", "chat", - "maestro", "conductor", "slack". - status: - title: status - $ref: '#/components/schemas/agents.v1.AgentStatus' - activeConfigVersion: - type: integer - title: active_config_version - format: int32 - ownerId: - type: string - title: owner_id - lastHeartbeatAt: - title: last_heartbeat_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - surfaceTypes: - type: array - items: - $ref: '#/components/schemas/common.v1.Surface' - title: surface_types - a2a: - title: a2a - description: |- - a2a is the Platform-owned discovery projection for spec-native A2A peers. - Remote agents use it to discover where to fetch the Agent Card, which - transport/profile is supported, and which skills can be delegated to this - agent or its child/subagent lanes. - $ref: '#/components/schemas/agents.v1.AgentA2APeerProjection' - capacity: - title: capacity - description: |- - capacity is the registry-owned load projection used by fleet-scale - delegation discovery and operator read models. - $ref: '#/components/schemas/agents.v1.AgentCapacity' - title: Agent - additionalProperties: false - description: |- - Agent is the canonical agent definition record. - The id field is the value stored in every agent_id / agent string field - across the platform: meter/v1 RecordUsageRequest.agent_id, - objectives/v1 Objective.agent_id, approvals/v1 ApprovalRequest.agent_id, - governance/v1 EvaluateActionRequest.agent_id, memory/v1 Memory.agent, - and events/v1 Change.actor_id when actor_type is "agent". - agents.v1.AgentA2APeerProjection: - type: object - properties: - publicEndpointUrl: - type: string - title: public_endpoint_url - internalEndpointUrl: - type: string - title: internal_endpoint_url - agentCardUrl: - type: string - title: agent_card_url - protocolBinding: - type: string - title: protocol_binding - protocolVersion: - type: string - title: protocol_version - supportedExtensions: - type: array - items: - type: string - title: supported_extensions - skills: - type: array - items: - $ref: '#/components/schemas/agents.v1.AgentA2ASkill' - title: skills - securitySchemes: - type: array - items: - type: string - title: security_schemes - agentCardObservedAt: - title: agent_card_observed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - agentCardEtag: - type: string - title: agent_card_etag - agentCardHash: - type: string - title: agent_card_hash - pushNotifications: - type: boolean - title: push_notifications - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: AgentA2APeerProjection - additionalProperties: false - agents.v1.AgentA2APeerProjection.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - agents.v1.AgentA2ASkill: - type: object - properties: - id: - type: string - title: id - name: - type: string - title: name - description: - type: string - title: description - tags: - type: array - items: - type: string - title: tags - inputModes: - type: array - items: - type: string - title: input_modes - outputModes: - type: array - items: - type: string - title: output_modes - requiredContextGrants: - type: array - items: - type: string - title: required_context_grants - approvalPolicyRef: - type: string - title: approval_policy_ref - maxAutonomy: - type: string - title: max_autonomy - requiredArtifactKinds: - type: array - items: - type: string - title: required_artifact_kinds - optionalArtifactKinds: - type: array - items: - type: string - title: optional_artifact_kinds - allowedTaskClasses: - type: array - items: - type: string - title: allowed_task_classes - deniedTaskClasses: - type: array - items: - type: string - title: denied_task_classes - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: AgentA2ASkill - additionalProperties: false - agents.v1.AgentA2ASkill.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - agents.v1.AgentCapacity: - type: object - properties: - current: - type: integer - title: current - format: int32 - max: - type: integer - title: max - format: int32 - remaining: - type: integer - title: remaining - format: int32 - reservedDelegationCount: - type: integer - title: reserved_delegation_count - format: int32 - title: AgentCapacity - additionalProperties: false - agents.v1.AgentConfig: - type: object - properties: - version: - type: integer - title: version - format: int32 - agentId: - type: string - title: agent_id - skillIds: - type: array - items: - type: string - title: skill_ids - description: |- - skill_ids reference skills/v1 Skill.id — the reusable capabilities - this agent has loaded. - promptBindings: - type: object - title: prompt_bindings - additionalProperties: - type: string - title: value - description: |- - prompt_bindings maps prompt name to label (e.g., "sdr-outreach" -> "production"). - Aligns with prompts/v1 ResolveRequest.name and ResolveRequest.label. - modelPreferences: - type: object - title: model_preferences - additionalProperties: - type: string - title: value - description: |- - model_preferences maps surface to preferred model identifier - (e.g., "ensemble" -> "claude-opus-4.6"). Aligns with meter/v1 - RecordUsageRequest.model and keys/v1 ResolveProviderRefRequest.provider. - integrationIds: - type: array - items: - type: string - title: integration_ids - description: |- - integration_ids reference connectors/v1 Connection.id — the external - system connections this agent is authorized to use. - entityTypeScopes: - type: array - items: - type: string - title: entity_type_scopes - description: |- - entity_type_scopes restrict which entities/v1 EntityType values this - agent can operate on. Empty means unrestricted. - maxConcurrentObjectives: - type: integer - title: max_concurrent_objectives - format: int32 - description: |- - max_concurrent_objectives caps the number of objectives/v1 Objective - records this agent can hold in RUNNING or BLOCKED state simultaneously. - costBudgetUsd: - type: number - title: cost_budget_usd - format: double - description: |- - cost_budget_usd is the per-period spend ceiling enforced against - meter/v1 usage records for this agent. - notificationChannel: - type: string - title: notification_channel - description: |- - notification_channel specifies the preferred notifications/v1 - DeliveryChannel for this agent's escalations. Stored as string to - avoid cross-package import (e.g., "DELIVERY_CHANNEL_SLACK"). - parameters: - title: parameters - description: parameters holds arbitrary agent-specific tuning knobs. - $ref: '#/components/schemas/google.protobuf.Struct' - author: - type: string - title: author - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - entityTypeScopeEnums: - type: array - items: - $ref: '#/components/schemas/common.v1.EntityType' - title: entity_type_scope_enums - notificationChannelEnum: - title: notification_channel_enum - $ref: '#/components/schemas/common.v1.DeliveryChannel' - teammateProfile: - title: teammate_profile - $ref: '#/components/schemas/agents.v1.DigitalTeammateProfile' - connectorRequirements: - type: array - items: - $ref: '#/components/schemas/agents.v1.ConnectorRequirement' - title: connector_requirements - description: Portable provider needs. Connection IDs remain workspace-local bindings. - title: AgentConfig - additionalProperties: false - description: |- - AgentConfig is an immutable snapshot of everything that shapes an agent's - behavior. Promotion and rollback are both config version reassignments — - the same pattern as prompts/v1 Label. - agents.v1.AgentConfig.ModelPreferencesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: ModelPreferencesEntry - additionalProperties: false - agents.v1.AgentConfig.PromptBindingsEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: PromptBindingsEntry - additionalProperties: false - agents.v1.AgentDiscoveryEvidence: - type: object - properties: - schema: - type: string - title: schema - decision: - type: string - title: decision - reason: - type: string - title: reason - workspaceId: - type: string - title: workspace_id - capability: - type: string - title: capability - capabilities: - type: array - items: - type: string - title: capabilities - agentType: - type: string - title: agent_type - a2aSkillId: - type: string - title: a2a_skill_id - taskClass: - type: string - title: task_class - requireA2aDispatch: - type: boolean - title: require_a2a_dispatch - surface: - type: string - title: surface - status: - type: string - title: status - candidateCount: - type: integer - title: candidate_count - format: int32 - matchedCount: - type: integer - title: matched_count - format: int32 - exclusions: - type: array - items: - $ref: '#/components/schemas/agents.v1.AgentDiscoveryExclusion' - title: exclusions - title: AgentDiscoveryEvidence - additionalProperties: false - description: |- - AgentDiscoveryEvidence is the safe, operator-auditable explanation for an - A2A/delegation discovery query. It intentionally carries identifiers, - counts, and policy labels, not task payloads or customer content. - agents.v1.AgentDiscoveryExclusion: - type: object - properties: - reason: - type: string - title: reason - count: - type: integer - title: count - format: int32 - sampleAgentIds: - type: array - items: - type: string - title: sample_agent_ids - policyReasons: - type: array - items: - type: string - title: policy_reasons - policyScopes: - type: array - items: - type: string - title: policy_scopes - allowedTaskClasses: - type: array - items: - type: string - title: allowed_task_classes - deniedTaskClasses: - type: array - items: - type: string - title: denied_task_classes - title: AgentDiscoveryExclusion - additionalProperties: false - description: |- - AgentDiscoveryExclusion summarizes why candidates did not appear in the - discovery result. Samples are agent ids only, capped by the server. - agents.v1.AutonomyPolicy: - type: object - properties: - rules: - type: array - items: - $ref: '#/components/schemas/agents.v1.AutonomyRule' - title: rules - defaultAuthority: - title: default_authority - $ref: '#/components/schemas/agents.v1.AutonomyAuthority' - maxRiskWithoutApproval: - title: max_risk_without_approval - $ref: '#/components/schemas/common.v1.RiskLevel' - title: AutonomyPolicy - additionalProperties: false - description: |- - AutonomyPolicy describes the default authority and specific action rules - that ToolExecution, Governance, and Approvals can enforce. - agents.v1.AutonomyRule: - type: object - properties: - actionType: - type: string - title: action_type - toolCapability: - type: string - title: tool_capability - maxRisk: - title: max_risk - $ref: '#/components/schemas/common.v1.RiskLevel' - authority: - not: - enum: - - 0 - title: authority - $ref: '#/components/schemas/agents.v1.AutonomyAuthority' - approvalPolicyRef: - type: string - title: approval_policy_ref - governancePolicyRef: - type: string - title: governance_policy_ref - rationale: - type: string - title: rationale - title: AutonomyRule - additionalProperties: false - description: AutonomyRule constrains a class of actions or tool capabilities. - agents.v1.CommitmentPolicy: - type: object - properties: - allowedKinds: - type: array - items: - $ref: '#/components/schemas/agents.v1.CommitmentKind' - title: allowed_kinds - templates: - type: array - items: - $ref: '#/components/schemas/agents.v1.CommitmentTemplate' - title: templates - defaultDueSeconds: - type: integer - title: default_due_seconds - format: int32 - maxOpenCommitments: - type: integer - title: max_open_commitments - format: int32 - requireObjectiveForCommitment: - type: boolean - title: require_objective_for_commitment - title: CommitmentPolicy - additionalProperties: false - description: |- - CommitmentPolicy describes which durable objectives and wakes can be created - from teammate commitments. - agents.v1.CommitmentTemplate: - type: object - properties: - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/agents.v1.CommitmentKind' - objectiveTitleTemplate: - type: string - title: objective_title_template - objectiveDescriptionTemplate: - type: string - title: objective_description_template - wakeReasonTemplate: - type: string - title: wake_reason_template - requiredJoinKeys: - type: array - items: - type: string - title: required_join_keys - title: CommitmentTemplate - additionalProperties: false - description: CommitmentTemplate maps a commitment kind to objective and wake templates. - agents.v1.ConnectorRequirement: - type: object - properties: - providerId: - type: string - title: provider_id - minLength: 1 - requiredCapabilities: - type: array - items: - type: string - title: required_capabilities - optionalCapabilities: - type: array - items: - type: string - title: optional_capabilities - required: - type: boolean - title: required - title: ConnectorRequirement - additionalProperties: false - agents.v1.ControlA2ADelegationTaskRequest: - type: object - properties: - delegationId: - type: string - title: delegation_id - minLength: 1 - mode: - not: - enum: - - 0 - title: mode - $ref: '#/components/schemas/agents.v1.A2ADelegationTaskControlMode' - message: - type: string - title: message - idempotencyKey: - type: string - title: idempotency_key - targetRunId: - type: string - title: target_run_id - description: |- - Optional target selectors allow Platform callers to control a remote - subagent lane or child run while still fencing the command by the root - remote task id stored on the delegation. - childRunId: - type: string - title: child_run_id - subagentLaneId: - type: string - title: subagent_lane_id - workItemId: - type: string - title: work_item_id - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Struct' - metadata: - title: metadata - $ref: '#/components/schemas/google.protobuf.Struct' - title: ControlA2ADelegationTaskRequest - additionalProperties: false - agents.v1.ControlA2ADelegationTaskResponse: - type: object - properties: - delegation: - title: delegation - $ref: '#/components/schemas/agents.v1.DelegationRecord' - remoteTask: - title: remote_task - $ref: '#/components/schemas/agents.v1.A2ADelegationTaskControlResult' - title: ControlA2ADelegationTaskResponse - additionalProperties: false - agents.v1.DelegateRequest: - type: object - properties: - fromAgentId: - type: string - title: from_agent_id - minLength: 1 - toAgentId: - type: string - title: to_agent_id - description: |- - Specify to_agent_id for direct delegation, or required_capability for - capability-based routing through the registry. - requiredCapability: - type: string - title: required_capability - objectiveId: - type: string - title: objective_id - workflowRunId: - type: string - title: workflow_run_id - workflowStepId: - type: string - title: workflow_step_id - contextPayload: - type: string - title: context_payload - format: byte - reason: - type: string - title: reason - a2aSkillId: - type: string - title: a2a_skill_id - title: DelegateRequest - additionalProperties: false - agents.v1.DelegateResponse: - type: object - properties: - delegation: - title: delegation - $ref: '#/components/schemas/agents.v1.DelegationRecord' - title: DelegateResponse - additionalProperties: false - agents.v1.DelegationRecord: - type: object - properties: - id: - type: string - title: id - workspaceId: - type: string - title: workspace_id - fromAgentId: - type: string - title: from_agent_id - toAgentId: - type: string - title: to_agent_id - requiredCapability: - type: string - title: required_capability - objectiveId: - type: string - title: objective_id - description: |- - objective_id links to the objectives/v1 Objective created for this - delegated unit of work. - workflowRunId: - type: string - title: workflow_run_id - description: |- - workflow_run_id and workflow_step_id link to workflows/v1 when this - delegation occurs within a workflow execution. - workflowStepId: - type: string - title: workflow_step_id - status: - title: status - $ref: '#/components/schemas/agents.v1.DelegationStatus' - contextPayload: - type: string - title: context_payload - format: byte - resultPayload: - type: string - title: result_payload - format: byte - reason: - type: string - title: reason - errorMessage: - type: string - title: error_message - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - resolvedAt: - title: resolved_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - a2aTaskId: - type: string - title: a2a_task_id - a2aMessageId: - type: string - title: a2a_message_id - a2aEndpointUrl: - type: string - title: a2a_endpoint_url - a2aDispatchStatus: - type: string - title: a2a_dispatch_status - a2aDispatchError: - type: string - title: a2a_dispatch_error - a2aSkillId: - type: string - title: a2a_skill_id - a2aDispatchedAt: - title: a2a_dispatched_at - description: |- - a2a_dispatched_at is the server time when the remote A2A task was first - accepted by the target transport. - $ref: '#/components/schemas/google.protobuf.Timestamp' - a2aLeaseRenewedAt: - title: a2a_lease_renewed_at - description: |- - a2a_lease_renewed_at is the last server time Platform observed remote A2A - progress for this delegation. - $ref: '#/components/schemas/google.protobuf.Timestamp' - a2aResumeWaitContracts: - type: array - items: - $ref: '#/components/schemas/google.protobuf.Struct' - title: a2a_resume_wait_contracts - description: |- - a2a_resume_wait_contracts are server-derived contracts that an origin - runtime can use to park the parent run on typed remote A2A callback events - after the target transport accepts the delegation. - a2aRootDelegationId: - type: string - title: a2a_root_delegation_id - description: |- - a2a_root_delegation_id identifies the root Platform delegation in an A2A - swarm chain. Root delegations use their own delegation id. - a2aParentDelegationId: - type: string - title: a2a_parent_delegation_id - description: |- - a2a_parent_delegation_id identifies the immediate parent Platform - delegation when this record was spawned by another remote A2A worker. - a2aDelegationChain: - type: array - items: - type: string - title: a2a_delegation_chain - description: |- - a2a_delegation_chain is the ordered Platform delegation lineage from root - to this delegation. - title: DelegationRecord - additionalProperties: false - description: |- - DelegationRecord tracks a typed hand-off between agents. The from_agent_id - creates an objective (objectives/v1) or references a workflow step - (workflows/v1 StepRun) and delegates execution to another agent resolved - by ID or by capability through the registry. - agents.v1.DeregisterRequest: - type: object - properties: - id: - type: string - title: id - minLength: 1 - reason: - type: string - title: reason - title: DeregisterRequest - additionalProperties: false - agents.v1.DeregisterResponse: - type: object - title: DeregisterResponse - additionalProperties: false - agents.v1.DigitalTeammateProfile: - type: object - properties: - id: - type: string - title: id - version: - type: integer - title: version - format: int32 - workspaceId: - type: string - title: workspace_id - agentId: - type: string - title: agent_id - displayName: - type: string - title: display_name - role: - type: string - title: role - purpose: - type: string - title: purpose - ownerUserId: - type: string - title: owner_user_id - ownerTeamId: - type: string - title: owner_team_id - surfaceTypes: - type: array - items: - $ref: '#/components/schemas/common.v1.Surface' - title: surface_types - lifecycle: - title: lifecycle - $ref: '#/components/schemas/agents.v1.TeammateLifecycle' - responsibilities: - type: array - items: - $ref: '#/components/schemas/agents.v1.TeammateResponsibility' - title: responsibilities - commitmentPolicy: - title: commitment_policy - $ref: '#/components/schemas/agents.v1.CommitmentPolicy' - initiativePolicy: - title: initiative_policy - $ref: '#/components/schemas/agents.v1.InitiativePolicy' - autonomyPolicy: - title: autonomy_policy - $ref: '#/components/schemas/agents.v1.AutonomyPolicy' - memoryPolicy: - title: memory_policy - $ref: '#/components/schemas/agents.v1.MemoryPolicy' - presencePolicy: - title: presence_policy - $ref: '#/components/schemas/agents.v1.PresencePolicy' - outputPolicy: - title: output_policy - $ref: '#/components/schemas/agents.v1.OutputPolicy' - evalPolicy: - title: eval_policy - $ref: '#/components/schemas/agents.v1.EvalPolicy' - escalationPolicy: - title: escalation_policy - $ref: '#/components/schemas/agents.v1.EscalationPolicy' - labels: - type: object - title: labels - additionalProperties: - type: string - title: value - parameters: - title: parameters - $ref: '#/components/schemas/google.protobuf.Struct' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - channelManifests: - type: array - items: - $ref: '#/components/schemas/agents.v1.TeammateChannelManifest' - title: channel_manifests - title: DigitalTeammateProfile - additionalProperties: false - description: |- - DigitalTeammateProfile is the versioned contract for how an AgentConfig acts - as a durable teammate across objectives, workflows, tools, memory, evals, and - Slack or other delivery surfaces. - agents.v1.DigitalTeammateProfile.LabelsEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: LabelsEntry - additionalProperties: false - agents.v1.EscalationPolicy: - type: object - properties: - approverUserIds: - type: array - items: - type: string - title: approver_user_ids - approverTeamIds: - type: array - items: - type: string - title: approver_team_ids - escalateAfterSeconds: - type: integer - title: escalate_after_seconds - format: int32 - fallbackChannel: - title: fallback_channel - $ref: '#/components/schemas/common.v1.DeliveryChannel' - title: EscalationPolicy - additionalProperties: false - description: |- - EscalationPolicy describes who must be contacted when the teammate blocks or - needs approval. - agents.v1.EvalBinding: - type: object - properties: - suiteName: - type: string - title: suite_name - metricName: - type: string - title: metric_name - minimumScore: - type: number - title: minimum_score - format: double - failureAction: - type: string - title: failure_action - title: EvalBinding - additionalProperties: false - description: EvalBinding describes one score that should gate or monitor teammate quality. - agents.v1.EvalPolicy: - type: object - properties: - bindings: - type: array - items: - $ref: '#/components/schemas/agents.v1.EvalBinding' - title: bindings - loopDefinitionId: - type: string - title: loop_definition_id - productionSampleRateBasisPoints: - type: integer - title: production_sample_rate_basis_points - maximum: 10000 - format: int32 - title: EvalPolicy - additionalProperties: false - description: EvalPolicy binds production behavior to loop and eval scoring. - agents.v1.GetA2ADelegationGraphRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - rootDelegationId: - type: string - title: root_delegation_id - description: Root Platform delegation id for the swarm graph. - delegationId: - type: string - title: delegation_id - description: |- - Any Platform delegation id in the swarm graph. If provided without - root_delegation_id, the server derives the root from recorded lineage. - maxDepth: - type: integer - title: max_depth - maximum: 100 - format: int32 - description: Maximum child depth to return from the root. Zero means no depth limit. - limit: - type: integer - title: limit - maximum: 1000 - format: int32 - description: Maximum graph nodes to return. Zero uses the server default. - title: GetA2ADelegationGraphRequest - additionalProperties: false - agents.v1.GetA2ADelegationGraphResponse: - type: object - properties: - rootDelegationId: - type: string - title: root_delegation_id - nodes: - type: array - items: - $ref: '#/components/schemas/agents.v1.A2ADelegationGraphNode' - title: nodes - edges: - type: array - items: - $ref: '#/components/schemas/agents.v1.A2ADelegationGraphEdge' - title: edges - total: - type: integer - title: total - format: int32 - truncated: - type: boolean - title: truncated - missingParentDelegationIds: - type: array - items: - type: string - title: missing_parent_delegation_ids - title: GetA2ADelegationGraphResponse - additionalProperties: false - agents.v1.GetConfigRequest: - type: object - properties: - agentId: - type: string - title: agent_id - minLength: 1 - version: - exclusiveMinimum: 0 - type: integer - title: version - format: int32 - title: GetConfigRequest - additionalProperties: false - agents.v1.GetConfigResponse: - type: object - properties: - config: - title: config - $ref: '#/components/schemas/agents.v1.AgentConfig' - title: GetConfigResponse - additionalProperties: false - agents.v1.GetDelegationRequest: - type: object - properties: - id: - type: string - title: id - minLength: 1 - title: GetDelegationRequest - additionalProperties: false - agents.v1.GetDelegationResponse: - type: object - properties: - delegation: - title: delegation - $ref: '#/components/schemas/agents.v1.DelegationRecord' - title: GetDelegationResponse - additionalProperties: false - agents.v1.GetRequest: - type: object - properties: - id: - type: string - title: id - minLength: 1 - title: GetRequest - additionalProperties: false - agents.v1.GetResponse: - type: object - properties: - agent: - title: agent - $ref: '#/components/schemas/agents.v1.Agent' - title: GetResponse - additionalProperties: false - agents.v1.HeartbeatRequest: - type: object - properties: - agentId: - type: string - title: agent_id - minLength: 1 - status: - title: status - $ref: '#/components/schemas/agents.v1.AgentStatus' - currentObjectiveIds: - type: array - items: - type: string - title: current_objective_ids - description: |- - current_objective_ids lists the objectives/v1 Objective.id values this - agent currently holds. Used for capacity-aware delegation routing. - surface: - type: string - title: surface - surfaceType: - title: surface_type - $ref: '#/components/schemas/common.v1.Surface' - a2a: - title: a2a - $ref: '#/components/schemas/agents.v1.AgentA2APeerProjection' - title: HeartbeatRequest - additionalProperties: false - agents.v1.HeartbeatResponse: - type: object - properties: - nextHeartbeatBy: - title: next_heartbeat_by - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: HeartbeatResponse - additionalProperties: false - agents.v1.InitiativePolicy: - type: object - properties: - triggers: - type: array - items: - $ref: '#/components/schemas/agents.v1.InitiativeTrigger' - title: triggers - maxInitiatedRunsPerDay: - type: integer - title: max_initiated_runs_per_day - format: int32 - requireHumanSeed: - type: boolean - title: require_human_seed - title: InitiativePolicy - additionalProperties: false - description: |- - InitiativePolicy describes bounded conditions where a teammate can start or - resume work proactively. - agents.v1.InitiativeTrigger: - type: object - properties: - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/agents.v1.InitiativeTriggerKind' - triggerRef: - type: string - title: trigger_ref - filterExpr: - type: string - title: filter_expr - workflowDefinitionId: - type: string - title: workflow_definition_id - objectiveTemplateId: - type: string - title: objective_template_id - title: InitiativeTrigger - additionalProperties: false - description: InitiativeTrigger binds a proactive trigger to workflow or objective state. - agents.v1.ListConfigsRequest: - type: object - properties: - agentId: - type: string - title: agent_id - minLength: 1 - limit: - type: integer - title: limit - maximum: 200 - format: int32 - offset: - type: integer - title: offset - format: int32 - title: ListConfigsRequest - additionalProperties: false - agents.v1.ListConfigsResponse: - type: object - properties: - configs: - type: array - items: - $ref: '#/components/schemas/agents.v1.AgentConfig' - title: configs - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - title: ListConfigsResponse - additionalProperties: false - agents.v1.ListDelegationsRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - fromAgentId: - type: string - title: from_agent_id - toAgentId: - type: string - title: to_agent_id - status: - title: status - $ref: '#/components/schemas/agents.v1.DelegationStatus' - workflowRunId: - type: string - title: workflow_run_id - limit: - type: integer - title: limit - format: int32 - offset: - type: integer - title: offset - format: int32 - a2aTaskId: - type: string - title: a2a_task_id - description: A2A remote task id returned by the target peer. - a2aMessageId: - type: string - title: a2a_message_id - description: A2A message id used for dispatch/callback correlation. - a2aSkillId: - type: string - title: a2a_skill_id - description: A2A skill id requested for the delegation. - a2aDispatchStatus: - type: string - title: a2a_dispatch_status - description: A2A transport dispatch status recorded by Platform. - a2aRootDelegationId: - type: string - title: a2a_root_delegation_id - description: Root Platform delegation id for a remote A2A swarm chain. - a2aParentDelegationId: - type: string - title: a2a_parent_delegation_id - description: Immediate parent Platform delegation id for a remote A2A swarm chain. - a2aOnly: - type: boolean - title: a2a_only - description: Limit results to delegations that have A2A transport or swarm lineage. - title: ListDelegationsRequest - additionalProperties: false - agents.v1.ListDelegationsResponse: - type: object - properties: - delegations: - type: array - items: - $ref: '#/components/schemas/agents.v1.DelegationRecord' - title: delegations - total: - type: integer - title: total - format: int32 - title: ListDelegationsResponse - additionalProperties: false - agents.v1.ListRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - agentType: - type: string - title: agent_type - capability: - type: string - title: capability - surface: - type: string - title: surface - status: - title: status - $ref: '#/components/schemas/agents.v1.AgentStatus' - limit: - type: integer - title: limit - maximum: 200 - format: int32 - offset: - type: integer - title: offset - format: int32 - surfaceType: - title: surface_type - $ref: '#/components/schemas/common.v1.Surface' - a2aSkillId: - type: string - title: a2a_skill_id - description: A2A skill ID required for fleet-scale delegation discovery. - taskClass: - type: string - title: task_class - description: Task class that must be allowed by the matched peer or skill policy. - requireA2aDispatch: - type: boolean - title: require_a2a_dispatch - description: Require peers to expose a dispatchable A2A HTTP+JSON endpoint. - eligibleForDelegation: - type: boolean - title: eligible_for_delegation - description: Use delegation-eligible discovery semantics even when only generic filters are supplied. - title: ListRequest - additionalProperties: false - agents.v1.ListResponse: - type: object - properties: - agents: - type: array - items: - $ref: '#/components/schemas/agents.v1.Agent' - title: agents - total: - type: integer - title: total - format: int32 - discoveryEvidence: - title: discovery_evidence - $ref: '#/components/schemas/agents.v1.AgentDiscoveryEvidence' - title: ListResponse - additionalProperties: false - agents.v1.MemoryPolicy: - type: object - properties: - allowedScopeRefs: - type: array - items: - type: string - title: allowed_scope_refs - allowUserMemory: - type: boolean - title: allow_user_memory - allowTeamMemory: - type: boolean - title: allow_team_memory - allowAgentMemory: - type: boolean - title: allow_agent_memory - requireReviewForNewMemory: - type: boolean - title: require_review_for_new_memory - defaultRetentionDays: - type: integer - title: default_retention_days - format: int32 - requiredSourceTypes: - type: array - items: - type: string - title: required_source_types - allowCrossChannelRecall: - type: boolean - title: allow_cross_channel_recall - title: MemoryPolicy - additionalProperties: false - description: MemoryPolicy describes what a teammate may recall or propose remembering. - agents.v1.OutputPolicy: - type: object - properties: - requiredArtifactKinds: - type: array - items: - type: string - title: required_artifact_kinds - optionalArtifactKinds: - type: array - items: - type: string - title: optional_artifact_kinds - renderChannelCards: - type: boolean - title: render_channel_cards - defaultVisibility: - type: string - title: default_visibility - title: OutputPolicy - additionalProperties: false - description: OutputPolicy describes durable work products and channel-safe renderings. - agents.v1.PresencePolicy: - type: object - properties: - primaryChannel: - title: primary_channel - $ref: '#/components/schemas/common.v1.DeliveryChannel' - primaryChannelId: - type: string - title: primary_channel_id - defaultThreadPolicy: - type: string - title: default_thread_policy - progressUpdateIntervalSeconds: - type: integer - title: progress_update_interval_seconds - format: int32 - visibleEvents: - type: array - items: - $ref: '#/components/schemas/agents.v1.PresenceEvent' - title: visible_events - postActionReceipts: - type: boolean - title: post_action_receipts - postBlockerUpdates: - type: boolean - title: post_blocker_updates - title: PresencePolicy - additionalProperties: false - description: |- - PresencePolicy describes how a teammate reports work back to Slack or other - delivery channels. - agents.v1.PushConfigRequest: - type: object - properties: - agentId: - type: string - title: agent_id - minLength: 1 - skillIds: - type: array - items: - type: string - title: skill_ids - promptBindings: - type: object - title: prompt_bindings - additionalProperties: - type: string - title: value - modelPreferences: - type: object - title: model_preferences - additionalProperties: - type: string - title: value - integrationIds: - type: array - items: - type: string - title: integration_ids - entityTypeScopes: - type: array - items: - type: string - title: entity_type_scopes - maxConcurrentObjectives: - type: integer - title: max_concurrent_objectives - format: int32 - costBudgetUsd: - type: number - title: cost_budget_usd - format: double - notificationChannel: - type: string - title: notification_channel - parameters: - title: parameters - $ref: '#/components/schemas/google.protobuf.Struct' - author: - type: string - title: author - entityTypeScopeEnums: - type: array - items: - $ref: '#/components/schemas/common.v1.EntityType' - title: entity_type_scope_enums - notificationChannelEnum: - title: notification_channel_enum - $ref: '#/components/schemas/common.v1.DeliveryChannel' - teammateProfile: - title: teammate_profile - $ref: '#/components/schemas/agents.v1.DigitalTeammateProfile' - connectorRequirements: - type: array - items: - $ref: '#/components/schemas/agents.v1.ConnectorRequirement' - title: connector_requirements - title: PushConfigRequest - additionalProperties: false - agents.v1.PushConfigRequest.ModelPreferencesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: ModelPreferencesEntry - additionalProperties: false - agents.v1.PushConfigRequest.PromptBindingsEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: PromptBindingsEntry - additionalProperties: false - agents.v1.PushConfigResponse: - type: object - properties: - config: - title: config - $ref: '#/components/schemas/agents.v1.AgentConfig' - agent: - title: agent - $ref: '#/components/schemas/agents.v1.Agent' - title: PushConfigResponse - additionalProperties: false - agents.v1.RegisterRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - name: - type: string - title: name - description: - type: string - title: description - agentType: - type: string - title: agent_type - capabilities: - type: array - items: - type: string - title: capabilities - minItems: 1 - surfaces: - type: array - items: - type: string - title: surfaces - ownerId: - type: string - title: owner_id - id: - type: string - title: id - surfaceTypes: - type: array - items: - $ref: '#/components/schemas/common.v1.Surface' - title: surface_types - a2a: - title: a2a - $ref: '#/components/schemas/agents.v1.AgentA2APeerProjection' - title: RegisterRequest - additionalProperties: false - agents.v1.RegisterResponse: - type: object - properties: - agent: - title: agent - $ref: '#/components/schemas/agents.v1.Agent' - title: RegisterResponse - additionalProperties: false - agents.v1.RenewDelegationLeaseRequest: - type: object - properties: - delegationId: - type: string - title: delegation_id - minLength: 1 - title: RenewDelegationLeaseRequest - additionalProperties: false - agents.v1.RenewDelegationLeaseResponse: - type: object - properties: - delegation: - title: delegation - $ref: '#/components/schemas/agents.v1.DelegationRecord' - title: RenewDelegationLeaseResponse - additionalProperties: false - agents.v1.ResolveDelegationRequest: - type: object - properties: - delegationId: - type: string - title: delegation_id - minLength: 1 - status: - not: - enum: - - 0 - title: status - $ref: '#/components/schemas/agents.v1.DelegationStatus' - resultPayload: - type: string - title: result_payload - format: byte - errorMessage: - type: string - title: error_message - title: ResolveDelegationRequest - additionalProperties: false - agents.v1.ResolveDelegationResponse: - type: object - properties: - delegation: - title: delegation - $ref: '#/components/schemas/agents.v1.DelegationRecord' - title: ResolveDelegationResponse - additionalProperties: false - agents.v1.RollbackConfigRequest: - type: object - properties: - agentId: - type: string - title: agent_id - minLength: 1 - targetVersion: - exclusiveMinimum: 0 - type: integer - title: target_version - format: int32 - actor: - type: string - title: actor - reason: - type: string - title: reason - title: RollbackConfigRequest - additionalProperties: false - agents.v1.RollbackConfigResponse: - type: object - properties: - config: - title: config - $ref: '#/components/schemas/agents.v1.AgentConfig' - agent: - title: agent - $ref: '#/components/schemas/agents.v1.Agent' - title: RollbackConfigResponse - additionalProperties: false - agents.v1.TeammateChannelManifest: - type: object - properties: - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/agents.v1.TeammateChannelKind' - label: - type: string - title: label - deliveryChannel: - not: - enum: - - 0 - title: delivery_channel - $ref: '#/components/schemas/common.v1.DeliveryChannel' - platformSurface: - title: platform_surface - $ref: '#/components/schemas/common.v1.Surface' - channelId: - type: string - title: channel_id - capabilities: - type: array - items: - $ref: '#/components/schemas/agents.v1.TeammateChannelCapability' - title: capabilities - inboundEvents: - type: array - items: - $ref: '#/components/schemas/agents.v1.TeammateChannelEventKind' - title: inbound_events - runtimeEvents: - type: array - items: - $ref: '#/components/schemas/agents.v1.TeammateRuntimeRenderEventKind' - title: runtime_events - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: TeammateChannelManifest - additionalProperties: false - description: |- - TeammateChannelManifest describes one channel adapter supported by a - teammate profile. Durable execution remains owned by AgentRuntime; this - manifest lets product surfaces declare the provider-specific ingress and - rendering coverage they can project. - agents.v1.TeammateChannelManifest.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - agents.v1.TeammateResponsibility: - type: object - properties: - id: - type: string - title: id - title: - type: string - title: title - description: - type: string - title: description - capabilityRefs: - type: array - items: - type: string - title: capability_refs - ownedEntityTypes: - type: array - items: - $ref: '#/components/schemas/common.v1.EntityType' - title: owned_entity_types - defaultSkillIds: - type: array - items: - type: string - title: default_skill_ids - promptNames: - type: array - items: - type: string - title: prompt_names - successMetricRefs: - type: array - items: - type: string - title: success_metric_refs - title: TeammateResponsibility - additionalProperties: false - description: |- - TeammateResponsibility binds a role claim to capabilities, entities, prompts, - skills, and measurable outcomes. - agents.v1.UpdateRequest: - type: object - properties: - id: - type: string - title: id - minLength: 1 - name: - type: string - title: name - description: - type: string - title: description - capabilities: - type: array - items: - type: string - title: capabilities - surfaces: - type: array - items: - type: string - title: surfaces - surfaceTypes: - type: array - items: - $ref: '#/components/schemas/common.v1.Surface' - title: surface_types - a2a: - title: a2a - $ref: '#/components/schemas/agents.v1.AgentA2APeerProjection' - title: UpdateRequest - additionalProperties: false - agents.v1.UpdateResponse: - type: object - properties: - agent: - title: agent - $ref: '#/components/schemas/agents.v1.Agent' - title: UpdateResponse - additionalProperties: false - google.protobuf.ListValue: - type: object - properties: - values: - type: array - items: - $ref: '#/components/schemas/google.protobuf.Value' - title: values - description: Repeated field of dynamically typed values. - title: ListValue - additionalProperties: false - description: |- - `ListValue` is a wrapper around a repeated field of values. - - The JSON representation for `ListValue` is JSON array. - google.protobuf.Struct: - type: object - additionalProperties: - $ref: '#/components/schemas/google.protobuf.Value' - description: |- - `Struct` represents a structured data value, consisting of fields - which map to dynamically typed values. In some languages, `Struct` - might be supported by a native representation. For example, in - scripting languages like JS a struct is represented as an - object. The details of that representation are described together - with the proto support for the language. - - The JSON representation for `Struct` is JSON object. - google.protobuf.Struct.FieldsEntry: - type: object - properties: - key: - type: string - title: key - value: - title: value - $ref: '#/components/schemas/google.protobuf.Value' - title: FieldsEntry - additionalProperties: false - google.protobuf.Timestamp: - type: string - examples: - - 1s - - 1.000340012s - format: date-time - description: |- - A Timestamp represents a point in time independent of any time zone or local - calendar, encoded as a count of seconds and fractions of seconds at - nanosecond resolution. The count is relative to an epoch at UTC midnight on - January 1, 1970, in the proleptic Gregorian calendar which extends the - Gregorian calendar backwards to year one. - - All minutes are 60 seconds long. Leap seconds are "smeared" so that no leap - second table is needed for interpretation, using a [24-hour linear - smear](https://developers.google.com/time/smear). - - The range is from 0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z. By - restricting to that range, we ensure that we can convert to and from [RFC - 3339](https://www.ietf.org/rfc/rfc3339.txt) date strings. - - # Examples - - Example 1: Compute Timestamp from POSIX `time()`. - - Timestamp timestamp; - timestamp.set_seconds(time(NULL)); - timestamp.set_nanos(0); - - Example 2: Compute Timestamp from POSIX `gettimeofday()`. - - struct timeval tv; - gettimeofday(&tv, NULL); - - Timestamp timestamp; - timestamp.set_seconds(tv.tv_sec); - timestamp.set_nanos(tv.tv_usec * 1000); - - Example 3: Compute Timestamp from Win32 `GetSystemTimeAsFileTime()`. - - FILETIME ft; - GetSystemTimeAsFileTime(&ft); - UINT64 ticks = (((UINT64)ft.dwHighDateTime) << 32) | ft.dwLowDateTime; - - // A Windows tick is 100 nanoseconds. Windows epoch 1601-01-01T00:00:00Z - // is 11644473600 seconds before Unix epoch 1970-01-01T00:00:00Z. - Timestamp timestamp; - timestamp.set_seconds((INT64) ((ticks / 10000000) - 11644473600LL)); - timestamp.set_nanos((INT32) ((ticks % 10000000) * 100)); - - Example 4: Compute Timestamp from Java `System.currentTimeMillis()`. - - long millis = System.currentTimeMillis(); - - Timestamp timestamp = Timestamp.newBuilder().setSeconds(millis / 1000) - .setNanos((int) ((millis % 1000) * 1000000)).build(); - - Example 5: Compute Timestamp from Java `Instant.now()`. - - Instant now = Instant.now(); - - Timestamp timestamp = - Timestamp.newBuilder().setSeconds(now.getEpochSecond()) - .setNanos(now.getNano()).build(); - - Example 6: Compute Timestamp from current time in Python. - - timestamp = Timestamp() - timestamp.GetCurrentTime() - - # JSON Mapping - - In JSON format, the Timestamp type is encoded as a string in the - [RFC 3339](https://www.ietf.org/rfc/rfc3339.txt) format. That is, the - format is "{year}-{month}-{day}T{hour}:{min}:{sec}[.{frac_sec}]Z" - where {year} is always expressed using four digits while {month}, {day}, - {hour}, {min}, and {sec} are zero-padded to two digits each. The fractional - seconds, which can go up to 9 digits (i.e. up to 1 nanosecond resolution), - are optional. The "Z" suffix indicates the timezone ("UTC"); the timezone - is required. A proto3 JSON serializer should always use UTC (as indicated by - "Z") when printing the Timestamp type and a proto3 JSON parser should be - able to accept both UTC and other timezones (as indicated by an offset). - - For example, "2017-01-15T01:30:15.01Z" encodes 15.01 seconds past - 01:30 UTC on January 15, 2017. - - In JavaScript, one can convert a Date object to this format using the - standard - [toISOString()](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Date/toISOString) - method. In Python, a standard `datetime.datetime` object can be converted - to this format using - [`strftime`](https://docs.python.org/2/library/time.html#time.strftime) with - the time format spec '%Y-%m-%dT%H:%M:%S.%fZ'. Likewise, in Java, one can use - the Joda Time's [`ISODateTimeFormat.dateTime()`]( - http://joda-time.sourceforge.net/apidocs/org/joda/time/format/ISODateTimeFormat.html#dateTime() - ) to obtain a formatter capable of generating timestamps in this format. - google.protobuf.Value: - oneOf: - - type: "null" - - type: number - - type: string - - type: boolean - - type: array - - type: object - additionalProperties: true - description: |- - `Value` represents a dynamically typed value which can be either - null, a number, a string, a boolean, a recursive struct value, or a - list of values. A producer of value is expected to set one of these - variants. Absence of any variant indicates an error. - - The JSON representation for `Value` is JSON value. - connect-protocol-version: - type: number - title: Connect-Protocol-Version - enum: - - 1 - description: Define the version of the Connect protocol - const: 1 - connect-timeout-header: - type: number - title: Connect-Timeout-Ms - description: Define the timeout, in ms - connect.error: - type: object - properties: - code: - type: string - examples: - - not_found - enum: - - canceled - - unknown - - invalid_argument - - deadline_exceeded - - not_found - - already_exists - - permission_denied - - resource_exhausted - - failed_precondition - - aborted - - out_of_range - - unimplemented - - internal - - unavailable - - data_loss - - unauthenticated - description: The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code]. - message: - type: string - description: A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client. - detail: - $ref: '#/components/schemas/google.protobuf.Any' - title: Connect Error - additionalProperties: true - description: 'Error type returned by Connect: https://connectrpc.com/docs/go/errors/#http-representation' - google.protobuf.Any: - type: object - properties: - type: - type: string - value: - type: string - format: binary - debug: - type: object - additionalProperties: true - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. -security: [] -tags: - - name: agents.v1.AgentService - description: |- - AgentService manages agent definitions, versioned configuration, and - cross-agent delegation. Every string agent_id in the platform (meter, - objectives, approvals, governance, memory) resolves to an Agent record - owned by this service. diff --git a/openapi/codex/v1/codex.openapi.yaml b/openapi/codex/v1/codex.openapi.yaml deleted file mode 100644 index ca81ac9..0000000 --- a/openapi/codex/v1/codex.openapi.yaml +++ /dev/null @@ -1,1086 +0,0 @@ -openapi: 3.1.0 -info: - title: codex.v1 -paths: {} -components: - schemas: - codex.v1.CodexActionType: - type: string - title: CodexActionType - enum: - - CODEX_ACTION_TYPE_UNSPECIFIED - - CODEX_ACTION_TYPE_START_WORK - - CODEX_ACTION_TYPE_FOLLOW_UP - - CODEX_ACTION_TYPE_INVESTIGATE - - CODEX_ACTION_TYPE_FIX - - CODEX_ACTION_TYPE_REVIEW - - CODEX_ACTION_TYPE_TEST - - CODEX_ACTION_TYPE_EXPLAIN - - CODEX_ACTION_TYPE_RETRY - - CODEX_ACTION_TYPE_FORK - description: |- - CodexActionType describes the user intent that should shape prompting, - permissions, routing, and output expectations for a Codex run. - codex.v1.CodexAuthorityScope: - type: string - title: CodexAuthorityScope - enum: - - CODEX_AUTHORITY_SCOPE_UNSPECIFIED - - CODEX_AUTHORITY_SCOPE_DISCUSS_ONLY - - CODEX_AUTHORITY_SCOPE_READ_ONLY - - CODEX_AUTHORITY_SCOPE_WORKSPACE_WRITE - description: |- - CodexAuthorityScope is the maximum local filesystem authority requested for - delegated work. Platform policy, device mappings, and native confirmation - may only narrow this value. - codex.v1.CodexBackend: - type: string - title: CodexBackend - enum: - - CODEX_BACKEND_UNSPECIFIED - - CODEX_BACKEND_APP_SERVER - - CODEX_BACKEND_CODEX_SDK - - CODEX_BACKEND_CLAUDE_CODE - - CODEX_BACKEND_INTERNAL_AGENT - - CODEX_BACKEND_MODEL_TRIAGE - description: CodexBackend identifies the execution backend selected for a run. - codex.v1.CodexContextSourceKind: - type: string - title: CodexContextSourceKind - enum: - - CODEX_CONTEXT_SOURCE_KIND_UNSPECIFIED - - CODEX_CONTEXT_SOURCE_KIND_SLACK_MESSAGE - - CODEX_CONTEXT_SOURCE_KIND_SLACK_THREAD - - CODEX_CONTEXT_SOURCE_KIND_GITHUB_PULL_REQUEST - - CODEX_CONTEXT_SOURCE_KIND_GITHUB_ISSUE - - CODEX_CONTEXT_SOURCE_KIND_LINEAR_TICKET - - CODEX_CONTEXT_SOURCE_KIND_JIRA_TICKET - - CODEX_CONTEXT_SOURCE_KIND_SENTRY_EVENT - - CODEX_CONTEXT_SOURCE_KIND_DATADOG_DASHBOARD - - CODEX_CONTEXT_SOURCE_KIND_LOG_SNIPPET - - CODEX_CONTEXT_SOURCE_KIND_SCREENSHOT - - CODEX_CONTEXT_SOURCE_KIND_MEMORY - - CODEX_CONTEXT_SOURCE_KIND_URL - - CODEX_CONTEXT_SOURCE_KIND_CEREBRO_THING - - CODEX_CONTEXT_SOURCE_KIND_CEREBRO_FACT - - CODEX_CONTEXT_SOURCE_KIND_CEREBRO_EVENT - - CODEX_CONTEXT_SOURCE_KIND_CEREBRO_ACTION - - CODEX_CONTEXT_SOURCE_KIND_CEREBRO_PREDICTION - - CODEX_CONTEXT_SOURCE_KIND_GRANOLA_MEETING - - CODEX_CONTEXT_SOURCE_KIND_GOOGLE_EMAIL_THREAD - - CODEX_CONTEXT_SOURCE_KIND_GOOGLE_DRIVE_FILE - - CODEX_CONTEXT_SOURCE_KIND_GOOGLE_CALENDAR_EVENT - - CODEX_CONTEXT_SOURCE_KIND_DEPLOYMENT - - CODEX_CONTEXT_SOURCE_KIND_BUILD - description: |- - CodexContextSourceKind names a structured context source enriched before a - run reaches the worker. - codex.v1.CodexExecutionIntent: - type: string - title: CodexExecutionIntent - enum: - - CODEX_EXECUTION_INTENT_UNSPECIFIED - - CODEX_EXECUTION_INTENT_READ_ONLY_DIAGNOSIS - - CODEX_EXECUTION_INTENT_PATCH_AND_VERIFY - - CODEX_EXECUTION_INTENT_REVIEW_ONLY - - CODEX_EXECUTION_INTENT_TEST_AUTHORING - - CODEX_EXECUTION_INTENT_EXPLANATION - description: CodexExecutionIntent captures the expected risk and write profile. - codex.v1.CodexGitState: - type: string - title: CodexGitState - enum: - - CODEX_GIT_STATE_UNSPECIFIED - - CODEX_GIT_STATE_UNCHANGED - - CODEX_GIT_STATE_DIRTY - - CODEX_GIT_STATE_COMMITTED - description: CodexGitState records the repository state without embedding branch prose. - codex.v1.CodexInteractionType: - type: string - title: CodexInteractionType - enum: - - CODEX_INTERACTION_TYPE_UNSPECIFIED - - CODEX_INTERACTION_TYPE_APPROVE_PLAN - - CODEX_INTERACTION_TYPE_REJECT_PLAN - - CODEX_INTERACTION_TYPE_APPLY_PATCH - - CODEX_INTERACTION_TYPE_DISCARD_PATCH - - CODEX_INTERACTION_TYPE_STOP_TURN - - CODEX_INTERACTION_TYPE_RETRY_TURN - - CODEX_INTERACTION_TYPE_FORK_THREAD - - CODEX_INTERACTION_TYPE_APPROVE_COMMAND - - CODEX_INTERACTION_TYPE_PROVIDE_INPUT - description: CodexInteractionType describes a channel-native control action. - codex.v1.CodexInteractivityMode: - type: string - title: CodexInteractivityMode - enum: - - CODEX_INTERACTIVITY_MODE_UNSPECIFIED - - CODEX_INTERACTIVITY_MODE_BACKGROUND - - CODEX_INTERACTIVITY_MODE_THREAD_CONVERSATION - - CODEX_INTERACTIVITY_MODE_HUMAN_APPROVAL_GATED - description: |- - CodexInteractivityMode controls how much of the run is projected back to a - human conversation surface. - codex.v1.CodexMemoryScopeKind: - type: string - title: CodexMemoryScopeKind - enum: - - CODEX_MEMORY_SCOPE_KIND_UNSPECIFIED - - CODEX_MEMORY_SCOPE_KIND_THREAD - - CODEX_MEMORY_SCOPE_KIND_REPOSITORY - - CODEX_MEMORY_SCOPE_KIND_TEAM - - CODEX_MEMORY_SCOPE_KIND_WORKSPACE - description: CodexMemoryScopeKind identifies the retrieval scope for prior run memory. - codex.v1.CodexOutputKind: - type: string - title: CodexOutputKind - enum: - - CODEX_OUTPUT_KIND_UNSPECIFIED - - CODEX_OUTPUT_KIND_THREAD_MESSAGE - - CODEX_OUTPUT_KIND_PULL_REQUEST - - CODEX_OUTPUT_KIND_PULL_REQUEST_COMMENT - - CODEX_OUTPUT_KIND_ARTIFACT - - CODEX_OUTPUT_KIND_RUN_PANEL - - CODEX_OUTPUT_KIND_EVALUATION_EXAMPLE - - CODEX_OUTPUT_KIND_DRAFT_MESSAGE - - CODEX_OUTPUT_KIND_DECISION_BRIEF - - CODEX_OUTPUT_KIND_PREPARED_FUTURE - - CODEX_OUTPUT_KIND_ISSUE - description: |- - CodexOutputKind classifies an artifact or external object the run should - create or synchronize. - codex.v1.CodexProgressStage: - type: string - title: CodexProgressStage - enum: - - CODEX_PROGRESS_STAGE_UNSPECIFIED - - CODEX_PROGRESS_STAGE_ACCEPTED - - CODEX_PROGRESS_STAGE_CONTEXT_ENRICHING - - CODEX_PROGRESS_STAGE_PLANNING - - CODEX_PROGRESS_STAGE_WAITING_FOR_APPROVAL - - CODEX_PROGRESS_STAGE_EDITING - - CODEX_PROGRESS_STAGE_TESTING - - CODEX_PROGRESS_STAGE_CREATING_OUTPUT - - CODEX_PROGRESS_STAGE_WATCHING_CI - - CODEX_PROGRESS_STAGE_COMPLETED - - CODEX_PROGRESS_STAGE_FAILED - - CODEX_PROGRESS_STAGE_CANCELLED - description: CodexProgressStage classifies user-visible run progress. - codex.v1.CodexVerificationStatus: - type: string - title: CodexVerificationStatus - enum: - - CODEX_VERIFICATION_STATUS_UNSPECIFIED - - CODEX_VERIFICATION_STATUS_NOT_RUN - - CODEX_VERIFICATION_STATUS_PASSED - - CODEX_VERIFICATION_STATUS_FAILED - - CODEX_VERIFICATION_STATUS_PARTIAL - description: CodexVerificationStatus records whether the bounded result was verified. - google.protobuf.NullValue: - type: string - title: NullValue - enum: - - NULL_VALUE - description: |- - `NullValue` is a singleton enumeration to represent the null value for the - `Value` type union. - - The JSON representation for `NullValue` is JSON `null`. - codex.v1.CodexApprovalPolicy: - type: object - properties: - dryRun: - type: boolean - title: dry_run - allowWrites: - type: boolean - title: allow_writes - requirePlanApproval: - type: boolean - title: require_plan_approval - requirePatchApproval: - type: boolean - title: require_patch_approval - requireCommandApproval: - type: boolean - title: require_command_approval - protectedPathGlobs: - type: array - items: - type: string - title: protected_path_globs - approverEntityIds: - type: array - items: - type: string - title: approver_entity_ids - networkEgressAllowlist: - type: array - items: - type: string - title: network_egress_allowlist - scrubSecretsFromOutputs: - type: boolean - title: scrub_secrets_from_outputs - sandboxMode: - type: string - title: sandbox_mode - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: CodexApprovalPolicy - additionalProperties: false - description: |- - CodexApprovalPolicy captures governance controls before a worker performs - write, network, or otherwise sensitive operations. - codex.v1.CodexApprovalPolicy.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - codex.v1.CodexBudgetPolicy: - type: object - properties: - maxInputTokens: - type: - - integer - - string - title: max_input_tokens - format: int64 - maxOutputTokens: - type: - - integer - - string - title: max_output_tokens - format: int64 - maxTotalTokens: - type: - - integer - - string - title: max_total_tokens - format: int64 - maxCostMicros: - type: - - integer - - string - title: max_cost_micros - format: int64 - maxRunSeconds: - type: integer - title: max_run_seconds - format: int32 - maxToolCalls: - type: integer - title: max_tool_calls - format: int32 - maxRetries: - type: integer - title: max_retries - format: int32 - title: CodexBudgetPolicy - additionalProperties: false - description: CodexBudgetPolicy defines per-run resource limits. - codex.v1.CodexContextItem: - type: object - properties: - sourceKind: - title: source_kind - $ref: '#/components/schemas/codex.v1.CodexContextSourceKind' - id: - type: string - title: id - uri: - type: string - title: uri - title: - type: string - title: title - text: - type: string - title: text - contentType: - type: string - title: content_type - digest: - type: string - title: digest - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: CodexContextItem - additionalProperties: false - description: CodexContextItem is a single enriched context object available to the run. - codex.v1.CodexContextItem.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - codex.v1.CodexConversationRef: - type: object - properties: - sessionId: - type: string - title: session_id - appServerThreadId: - type: string - title: app_server_thread_id - previousRunId: - type: string - title: previous_run_id - parentRunId: - type: string - title: parent_run_id - followupToTurnId: - type: string - title: followup_to_turn_id - channelThreadId: - type: string - title: channel_thread_id - channelMessageId: - type: string - title: channel_message_id - keepSessionAlive: - type: boolean - title: keep_session_alive - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: CodexConversationRef - additionalProperties: false - description: CodexConversationRef carries durable session coordinates across turns. - codex.v1.CodexConversationRef.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - codex.v1.CodexInteractionDecision: - type: object - properties: - interactionType: - title: interaction_type - $ref: '#/components/schemas/codex.v1.CodexInteractionType' - decision: - type: string - title: decision - reason: - type: string - title: reason - actorEntityId: - type: string - title: actor_entity_id - selectedChoice: - type: string - title: selected_choice - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Struct' - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: CodexInteractionDecision - additionalProperties: false - description: CodexInteractionDecision captures the user's response to a Codex control. - codex.v1.CodexInteractionDecision.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - codex.v1.CodexInteractionRequest: - type: object - properties: - interactionType: - title: interaction_type - $ref: '#/components/schemas/codex.v1.CodexInteractionType' - runId: - type: string - title: run_id - waitId: - type: string - title: wait_id - stepId: - type: string - title: step_id - artifactId: - type: string - title: artifact_id - patchId: - type: string - title: patch_id - prompt: - type: string - title: prompt - choices: - type: array - items: - type: string - title: choices - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Struct' - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: CodexInteractionRequest - additionalProperties: false - description: |- - CodexInteractionRequest describes a pending human decision projected to a - channel surface. - codex.v1.CodexInteractionRequest.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - codex.v1.CodexMemoryScope: - type: object - properties: - kind: - title: kind - $ref: '#/components/schemas/codex.v1.CodexMemoryScopeKind' - key: - type: string - title: key - retentionDays: - type: integer - title: retention_days - format: int32 - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: CodexMemoryScope - additionalProperties: false - description: CodexMemoryScope describes what prior run knowledge should be retrieved. - codex.v1.CodexMemoryScope.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - codex.v1.CodexOutcomeSignal: - type: object - properties: - runId: - type: string - title: run_id - pullRequestUrl: - type: string - title: pull_request_url - merged: - type: boolean - title: merged - reverted: - type: boolean - title: reverted - humanEdited: - type: boolean - title: human_edited - channelReaction: - type: string - title: channel_reaction - reviewOutcome: - type: string - title: review_outcome - observedAt: - title: observed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: CodexOutcomeSignal - additionalProperties: false - description: CodexOutcomeSignal feeds evaluation and routing loops after the run. - codex.v1.CodexOutcomeSignal.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - codex.v1.CodexOutputTarget: - type: object - properties: - kind: - title: kind - $ref: '#/components/schemas/codex.v1.CodexOutputKind' - id: - type: string - title: id - uri: - type: string - title: uri - title: - type: string - title: title - draft: - type: boolean - title: draft - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: CodexOutputTarget - additionalProperties: false - description: CodexOutputTarget describes a desired or produced external output. - codex.v1.CodexOutputTarget.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - codex.v1.CodexPreparedFutureRef: - type: object - properties: - preparedFutureId: - type: string - title: prepared_future_id - cerebroActionId: - type: string - title: cerebro_action_id - cerebroPredictionId: - type: string - title: cerebro_prediction_id - cerebroFactIds: - type: array - items: - type: string - title: cerebro_fact_ids - sourceRecordIds: - type: array - items: - type: string - title: source_record_ids - artifactIds: - type: array - items: - type: string - title: artifact_ids - approvalRequestIds: - type: array - items: - type: string - title: approval_request_ids - evidenceUri: - type: string - title: evidence_uri - sourceHealth: - type: string - title: source_health - riskLevel: - type: string - title: risk_level - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: CodexPreparedFutureRef - additionalProperties: false - description: |- - CodexPreparedFutureRef ties a Codex run to the reviewable next move it is - preparing. It is a grouping contract, not an approval or execution grant. - codex.v1.CodexPreparedFutureRef.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - codex.v1.CodexRoutingPolicy: - type: object - properties: - backend: - title: backend - $ref: '#/components/schemas/codex.v1.CodexBackend' - workerQueue: - type: string - title: worker_queue - modelTier: - type: string - title: model_tier - preferredAgentId: - type: string - title: preferred_agent_id - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: CodexRoutingPolicy - additionalProperties: false - description: CodexRoutingPolicy captures backend and worker selection. - codex.v1.CodexRoutingPolicy.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - codex.v1.CodexRunProgress: - type: object - properties: - stage: - title: stage - $ref: '#/components/schemas/codex.v1.CodexProgressStage' - safeSummary: - type: string - title: safe_summary - progressPercent: - type: integer - title: progress_percent - maximum: 100 - format: int32 - filesRead: - type: integer - title: files_read - format: int32 - filesChanged: - type: integer - title: files_changed - format: int32 - commandsRun: - type: integer - title: commands_run - format: int32 - inputTokens: - type: - - integer - - string - title: input_tokens - format: int64 - outputTokens: - type: - - integer - - string - title: output_tokens - format: int64 - estimatedCostMicros: - type: - - integer - - string - title: estimated_cost_micros - format: int64 - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: CodexRunProgress - additionalProperties: false - description: CodexRunProgress is the compact, user-visible progress projection. - codex.v1.CodexRunProgress.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - codex.v1.CodexWorkRequest: - type: object - properties: - actionType: - title: action_type - $ref: '#/components/schemas/codex.v1.CodexActionType' - executionIntent: - title: execution_intent - $ref: '#/components/schemas/codex.v1.CodexExecutionIntent' - prompt: - type: string - title: prompt - repo: - type: string - title: repo - cwd: - type: string - title: cwd - branch: - type: string - title: branch - baseBranch: - type: string - title: base_branch - tenantId: - type: string - title: tenant_id - reason: - type: string - title: reason - conversation: - title: conversation - $ref: '#/components/schemas/codex.v1.CodexConversationRef' - routing: - title: routing - $ref: '#/components/schemas/codex.v1.CodexRoutingPolicy' - budget: - title: budget - $ref: '#/components/schemas/codex.v1.CodexBudgetPolicy' - approvalPolicy: - title: approval_policy - $ref: '#/components/schemas/codex.v1.CodexApprovalPolicy' - interactivityMode: - title: interactivity_mode - $ref: '#/components/schemas/codex.v1.CodexInteractivityMode' - contextItems: - type: array - items: - $ref: '#/components/schemas/codex.v1.CodexContextItem' - title: context_items - desiredOutputs: - type: array - items: - $ref: '#/components/schemas/codex.v1.CodexOutputTarget' - title: desired_outputs - memoryScopes: - type: array - items: - $ref: '#/components/schemas/codex.v1.CodexMemoryScope' - title: memory_scopes - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - preparedFuture: - title: prepared_future - $ref: '#/components/schemas/codex.v1.CodexPreparedFutureRef' - resourceId: - type: string - title: resource_id - maxLength: 512 - pattern: ^$|^[^/\\:][^\\:]*$|^[A-Za-z][A-Za-z0-9+.-]+:([^A-Za-z/\\][^\\]*|[A-Za-z]([^:\\][^\\]*)?)$ - description: |- - Stable Platform resource identity. Local absolute paths are forbidden, - including drive-root forms after local schemes (e.g. file:C:/Windows). - requestedAuthority: - title: requested_authority - $ref: '#/components/schemas/codex.v1.CodexAuthorityScope' - title: CodexWorkRequest - additionalProperties: false - description: |+ - CodexWorkRequest is the typed payload for Slack, GitHub, Linear, CLI, IDE, - and monitoring-triggered Codex work. - resource_id must not be an absolute local path: - ``` - this.resource_id == '' || (!this.resource_id.startsWith('/') && !this.resource_id.startsWith('\\') && !this.resource_id.matches('^[A-Za-z]:[/\\\\].*') && !this.resource_id.matches('^[A-Za-z][A-Za-z0-9+.-]*:[A-Za-z]:.*')) - ``` - - codex.v1.CodexWorkRequest.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - codex.v1.CodexWorkResult: - type: object - properties: - outcome: - type: string - title: outcome - maxLength: 256 - minLength: 1 - summary: - type: string - title: summary - maxLength: 8192 - minLength: 1 - findings: - type: array - items: - type: string - maxLength: 1024 - maxItems: 64 - title: findings - maxItems: 64 - changedFiles: - type: array - items: - type: string - maxLength: 1024 - pattern: ^([^./\\:][^/\\:]*|\.[^./\\:][^/\\:]*|\.\.[^/\\:][^/\\:]*)(/([^./\\:][^/\\:]*|\.[^./\\:][^/\\:]*|\.\.[^/\\:][^/\\:]*))*$ - maxItems: 256 - title: changed_files - maxItems: 256 - testsRun: - type: array - items: - type: string - maxLength: 2048 - maxItems: 128 - title: tests_run - maxItems: 128 - verificationStatus: - title: verification_status - $ref: '#/components/schemas/codex.v1.CodexVerificationStatus' - evidenceRefs: - type: array - items: - type: string - maxLength: 2048 - maxItems: 128 - title: evidence_refs - maxItems: 128 - ownerInputRequired: - type: string - title: owner_input_required - maxLength: 2048 - codexThreadId: - type: string - title: codex_thread_id - maxLength: 256 - gitState: - title: git_state - $ref: '#/components/schemas/codex.v1.CodexGitState' - title: CodexWorkResult - additionalProperties: false - description: |+ - CodexWorkResult is the bounded, channel-safe completion projection for a - delegated Codex run. changed_files are relative to resource_id's mapped root. - changed_files entries must be normalized workspace-relative paths: - ``` - this.changed_files.all(path, path != '' && !path.startsWith('/') && !path.contains('\\') && !path.matches('^[A-Za-z]:.*') && !path.matches('(^|/)\\.{1,2}(/|$)') && !path.contains('//') && !path.endsWith('/')) - ``` - - google.protobuf.ListValue: - type: object - properties: - values: - type: array - items: - $ref: '#/components/schemas/google.protobuf.Value' - title: values - description: Repeated field of dynamically typed values. - title: ListValue - additionalProperties: false - description: |- - `ListValue` is a wrapper around a repeated field of values. - - The JSON representation for `ListValue` is JSON array. - google.protobuf.Struct: - type: object - additionalProperties: - $ref: '#/components/schemas/google.protobuf.Value' - description: |- - `Struct` represents a structured data value, consisting of fields - which map to dynamically typed values. In some languages, `Struct` - might be supported by a native representation. For example, in - scripting languages like JS a struct is represented as an - object. The details of that representation are described together - with the proto support for the language. - - The JSON representation for `Struct` is JSON object. - google.protobuf.Struct.FieldsEntry: - type: object - properties: - key: - type: string - title: key - value: - title: value - $ref: '#/components/schemas/google.protobuf.Value' - title: FieldsEntry - additionalProperties: false - google.protobuf.Timestamp: - type: string - examples: - - 1s - - 1.000340012s - format: date-time - description: |- - A Timestamp represents a point in time independent of any time zone or local - calendar, encoded as a count of seconds and fractions of seconds at - nanosecond resolution. The count is relative to an epoch at UTC midnight on - January 1, 1970, in the proleptic Gregorian calendar which extends the - Gregorian calendar backwards to year one. - - All minutes are 60 seconds long. Leap seconds are "smeared" so that no leap - second table is needed for interpretation, using a [24-hour linear - smear](https://developers.google.com/time/smear). - - The range is from 0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z. By - restricting to that range, we ensure that we can convert to and from [RFC - 3339](https://www.ietf.org/rfc/rfc3339.txt) date strings. - - # Examples - - Example 1: Compute Timestamp from POSIX `time()`. - - Timestamp timestamp; - timestamp.set_seconds(time(NULL)); - timestamp.set_nanos(0); - - Example 2: Compute Timestamp from POSIX `gettimeofday()`. - - struct timeval tv; - gettimeofday(&tv, NULL); - - Timestamp timestamp; - timestamp.set_seconds(tv.tv_sec); - timestamp.set_nanos(tv.tv_usec * 1000); - - Example 3: Compute Timestamp from Win32 `GetSystemTimeAsFileTime()`. - - FILETIME ft; - GetSystemTimeAsFileTime(&ft); - UINT64 ticks = (((UINT64)ft.dwHighDateTime) << 32) | ft.dwLowDateTime; - - // A Windows tick is 100 nanoseconds. Windows epoch 1601-01-01T00:00:00Z - // is 11644473600 seconds before Unix epoch 1970-01-01T00:00:00Z. - Timestamp timestamp; - timestamp.set_seconds((INT64) ((ticks / 10000000) - 11644473600LL)); - timestamp.set_nanos((INT32) ((ticks % 10000000) * 100)); - - Example 4: Compute Timestamp from Java `System.currentTimeMillis()`. - - long millis = System.currentTimeMillis(); - - Timestamp timestamp = Timestamp.newBuilder().setSeconds(millis / 1000) - .setNanos((int) ((millis % 1000) * 1000000)).build(); - - Example 5: Compute Timestamp from Java `Instant.now()`. - - Instant now = Instant.now(); - - Timestamp timestamp = - Timestamp.newBuilder().setSeconds(now.getEpochSecond()) - .setNanos(now.getNano()).build(); - - Example 6: Compute Timestamp from current time in Python. - - timestamp = Timestamp() - timestamp.GetCurrentTime() - - # JSON Mapping - - In JSON format, the Timestamp type is encoded as a string in the - [RFC 3339](https://www.ietf.org/rfc/rfc3339.txt) format. That is, the - format is "{year}-{month}-{day}T{hour}:{min}:{sec}[.{frac_sec}]Z" - where {year} is always expressed using four digits while {month}, {day}, - {hour}, {min}, and {sec} are zero-padded to two digits each. The fractional - seconds, which can go up to 9 digits (i.e. up to 1 nanosecond resolution), - are optional. The "Z" suffix indicates the timezone ("UTC"); the timezone - is required. A proto3 JSON serializer should always use UTC (as indicated by - "Z") when printing the Timestamp type and a proto3 JSON parser should be - able to accept both UTC and other timezones (as indicated by an offset). - - For example, "2017-01-15T01:30:15.01Z" encodes 15.01 seconds past - 01:30 UTC on January 15, 2017. - - In JavaScript, one can convert a Date object to this format using the - standard - [toISOString()](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Date/toISOString) - method. In Python, a standard `datetime.datetime` object can be converted - to this format using - [`strftime`](https://docs.python.org/2/library/time.html#time.strftime) with - the time format spec '%Y-%m-%dT%H:%M:%S.%fZ'. Likewise, in Java, one can use - the Joda Time's [`ISODateTimeFormat.dateTime()`]( - http://joda-time.sourceforge.net/apidocs/org/joda/time/format/ISODateTimeFormat.html#dateTime() - ) to obtain a formatter capable of generating timestamps in this format. - google.protobuf.Value: - oneOf: - - type: "null" - - type: number - - type: string - - type: boolean - - type: array - - type: object - additionalProperties: true - description: |- - `Value` represents a dynamically typed value which can be either - null, a number, a string, a boolean, a recursive struct value, or a - list of values. A producer of value is expected to set one of these - variants. Absence of any variant indicates an error. - - The JSON representation for `Value` is JSON value. -security: [] diff --git a/openapi/common/v1/analytics.openapi.yaml b/openapi/common/v1/analytics.openapi.yaml deleted file mode 100644 index 0937158..0000000 --- a/openapi/common/v1/analytics.openapi.yaml +++ /dev/null @@ -1,235 +0,0 @@ -openapi: 3.1.0 -info: - title: common.v1 -paths: {} -components: - schemas: - common.v1.InsightSource: - type: string - title: InsightSource - enum: - - INSIGHT_SOURCE_UNSPECIFIED - - INSIGHT_SOURCE_TRACES - - INSIGHT_SOURCE_ATTRIBUTION - - INSIGHT_SOURCE_METER - - INSIGHT_SOURCE_APPROVALS - - INSIGHT_SOURCE_AUDIT - - INSIGHT_SOURCE_GOVERNANCE - - INSIGHT_SOURCE_REGISTRY - - INSIGHT_SOURCE_EVAL - description: InsightSource identifies the system that produced a recommendation or rollup. - google.protobuf.NullValue: - type: string - title: NullValue - enum: - - NULL_VALUE - description: |- - `NullValue` is a singleton enumeration to represent the null value for the - `Value` type union. - - The JSON representation for `NullValue` is JSON `null`. - common.v1.EvidenceRef: - type: object - properties: - source: - title: source - $ref: '#/components/schemas/common.v1.InsightSource' - recordId: - type: string - title: record_id - description: - type: string - title: description - observedAt: - title: observed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - weight: - type: number - title: weight - format: double - metadata: - title: metadata - $ref: '#/components/schemas/google.protobuf.Struct' - lineageId: - type: string - title: lineage_id - title: EvidenceRef - additionalProperties: false - description: EvidenceRef points analytics output back to source records. - common.v1.Money: - type: object - properties: - currencyCode: - type: string - title: currency_code - amount: - type: number - title: amount - format: double - title: Money - additionalProperties: false - description: Money carries a currency code plus an amount for financial rollups. - common.v1.TimeRange: - type: object - properties: - startTime: - title: start_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - endTime: - title: end_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: TimeRange - additionalProperties: false - description: TimeRange is the canonical inclusive/exclusive window used by analytics APIs. - google.protobuf.ListValue: - type: object - properties: - values: - type: array - items: - $ref: '#/components/schemas/google.protobuf.Value' - title: values - description: Repeated field of dynamically typed values. - title: ListValue - additionalProperties: false - description: |- - `ListValue` is a wrapper around a repeated field of values. - - The JSON representation for `ListValue` is JSON array. - google.protobuf.Struct: - type: object - additionalProperties: - $ref: '#/components/schemas/google.protobuf.Value' - description: |- - `Struct` represents a structured data value, consisting of fields - which map to dynamically typed values. In some languages, `Struct` - might be supported by a native representation. For example, in - scripting languages like JS a struct is represented as an - object. The details of that representation are described together - with the proto support for the language. - - The JSON representation for `Struct` is JSON object. - google.protobuf.Struct.FieldsEntry: - type: object - properties: - key: - type: string - title: key - value: - title: value - $ref: '#/components/schemas/google.protobuf.Value' - title: FieldsEntry - additionalProperties: false - google.protobuf.Timestamp: - type: string - examples: - - 1s - - 1.000340012s - format: date-time - description: |- - A Timestamp represents a point in time independent of any time zone or local - calendar, encoded as a count of seconds and fractions of seconds at - nanosecond resolution. The count is relative to an epoch at UTC midnight on - January 1, 1970, in the proleptic Gregorian calendar which extends the - Gregorian calendar backwards to year one. - - All minutes are 60 seconds long. Leap seconds are "smeared" so that no leap - second table is needed for interpretation, using a [24-hour linear - smear](https://developers.google.com/time/smear). - - The range is from 0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z. By - restricting to that range, we ensure that we can convert to and from [RFC - 3339](https://www.ietf.org/rfc/rfc3339.txt) date strings. - - # Examples - - Example 1: Compute Timestamp from POSIX `time()`. - - Timestamp timestamp; - timestamp.set_seconds(time(NULL)); - timestamp.set_nanos(0); - - Example 2: Compute Timestamp from POSIX `gettimeofday()`. - - struct timeval tv; - gettimeofday(&tv, NULL); - - Timestamp timestamp; - timestamp.set_seconds(tv.tv_sec); - timestamp.set_nanos(tv.tv_usec * 1000); - - Example 3: Compute Timestamp from Win32 `GetSystemTimeAsFileTime()`. - - FILETIME ft; - GetSystemTimeAsFileTime(&ft); - UINT64 ticks = (((UINT64)ft.dwHighDateTime) << 32) | ft.dwLowDateTime; - - // A Windows tick is 100 nanoseconds. Windows epoch 1601-01-01T00:00:00Z - // is 11644473600 seconds before Unix epoch 1970-01-01T00:00:00Z. - Timestamp timestamp; - timestamp.set_seconds((INT64) ((ticks / 10000000) - 11644473600LL)); - timestamp.set_nanos((INT32) ((ticks % 10000000) * 100)); - - Example 4: Compute Timestamp from Java `System.currentTimeMillis()`. - - long millis = System.currentTimeMillis(); - - Timestamp timestamp = Timestamp.newBuilder().setSeconds(millis / 1000) - .setNanos((int) ((millis % 1000) * 1000000)).build(); - - Example 5: Compute Timestamp from Java `Instant.now()`. - - Instant now = Instant.now(); - - Timestamp timestamp = - Timestamp.newBuilder().setSeconds(now.getEpochSecond()) - .setNanos(now.getNano()).build(); - - Example 6: Compute Timestamp from current time in Python. - - timestamp = Timestamp() - timestamp.GetCurrentTime() - - # JSON Mapping - - In JSON format, the Timestamp type is encoded as a string in the - [RFC 3339](https://www.ietf.org/rfc/rfc3339.txt) format. That is, the - format is "{year}-{month}-{day}T{hour}:{min}:{sec}[.{frac_sec}]Z" - where {year} is always expressed using four digits while {month}, {day}, - {hour}, {min}, and {sec} are zero-padded to two digits each. The fractional - seconds, which can go up to 9 digits (i.e. up to 1 nanosecond resolution), - are optional. The "Z" suffix indicates the timezone ("UTC"); the timezone - is required. A proto3 JSON serializer should always use UTC (as indicated by - "Z") when printing the Timestamp type and a proto3 JSON parser should be - able to accept both UTC and other timezones (as indicated by an offset). - - For example, "2017-01-15T01:30:15.01Z" encodes 15.01 seconds past - 01:30 UTC on January 15, 2017. - - In JavaScript, one can convert a Date object to this format using the - standard - [toISOString()](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Date/toISOString) - method. In Python, a standard `datetime.datetime` object can be converted - to this format using - [`strftime`](https://docs.python.org/2/library/time.html#time.strftime) with - the time format spec '%Y-%m-%dT%H:%M:%S.%fZ'. Likewise, in Java, one can use - the Joda Time's [`ISODateTimeFormat.dateTime()`]( - http://joda-time.sourceforge.net/apidocs/org/joda/time/format/ISODateTimeFormat.html#dateTime() - ) to obtain a formatter capable of generating timestamps in this format. - google.protobuf.Value: - oneOf: - - type: "null" - - type: number - - type: string - - type: boolean - - type: array - - type: object - additionalProperties: true - description: |- - `Value` represents a dynamically typed value which can be either - null, a number, a string, a boolean, a recursive struct value, or a - list of values. A producer of value is expected to set one of these - variants. Absence of any variant indicates an error. - - The JSON representation for `Value` is JSON value. -security: [] diff --git a/openapi/common/v1/authz.openapi.yaml b/openapi/common/v1/authz.openapi.yaml deleted file mode 100644 index 3ba3ae9..0000000 --- a/openapi/common/v1/authz.openapi.yaml +++ /dev/null @@ -1,6 +0,0 @@ -openapi: 3.1.0 -info: - title: common.v1 -paths: {} -components: {} -security: [] diff --git a/openapi/common/v1/classification.openapi.yaml b/openapi/common/v1/classification.openapi.yaml deleted file mode 100644 index f1cdb2f..0000000 --- a/openapi/common/v1/classification.openapi.yaml +++ /dev/null @@ -1,22 +0,0 @@ -openapi: 3.1.0 -info: - title: common.v1 -paths: {} -components: - schemas: - common.v1.DataClassification: - type: string - title: DataClassification - enum: - - DATA_CLASSIFICATION_UNSPECIFIED - - DATA_CLASSIFICATION_SAFE - - DATA_CLASSIFICATION_IDENTIFIER - - DATA_CLASSIFICATION_PATH - - DATA_CLASSIFICATION_CONTENT - - DATA_CLASSIFICATION_CREDENTIAL - description: |- - DataClassification declares what kind of data a field is allowed to carry. - It is declared once, on the field, and is the input to lint enforcement - (scripts/check-proto-classification.py) and to the generated attribute - manifest consumed by runtime validators. -security: [] diff --git a/openapi/common/v1/delivery.openapi.yaml b/openapi/common/v1/delivery.openapi.yaml deleted file mode 100644 index f9da364..0000000 --- a/openapi/common/v1/delivery.openapi.yaml +++ /dev/null @@ -1,18 +0,0 @@ -openapi: 3.1.0 -info: - title: common.v1 -paths: {} -components: - schemas: - common.v1.DeliveryChannel: - type: string - title: DeliveryChannel - enum: - - DELIVERY_CHANNEL_UNSPECIFIED - - DELIVERY_CHANNEL_SLACK - - DELIVERY_CHANNEL_EMAIL - - DELIVERY_CHANNEL_WEBHOOK - - DELIVERY_CHANNEL_IN_APP - - DELIVERY_CHANNEL_PUSH - description: DeliveryChannel identifies the notification delivery channel. -security: [] diff --git a/openapi/common/v1/entity.openapi.yaml b/openapi/common/v1/entity.openapi.yaml deleted file mode 100644 index ce9100e..0000000 --- a/openapi/common/v1/entity.openapi.yaml +++ /dev/null @@ -1,19 +0,0 @@ -openapi: 3.1.0 -info: - title: common.v1 -paths: {} -components: - schemas: - common.v1.EntityType: - type: string - title: EntityType - enum: - - ENTITY_TYPE_UNSPECIFIED - - ENTITY_TYPE_CONTACT - - ENTITY_TYPE_COMPANY - - ENTITY_TYPE_DEAL - - ENTITY_TYPE_TICKET - - ENTITY_TYPE_CUSTOMER - - ENTITY_TYPE_OPPORTUNITY - description: EntityType identifies the kind of entity across systems. -security: [] diff --git a/openapi/common/v1/risk.openapi.yaml b/openapi/common/v1/risk.openapi.yaml deleted file mode 100644 index e6f90ac..0000000 --- a/openapi/common/v1/risk.openapi.yaml +++ /dev/null @@ -1,17 +0,0 @@ -openapi: 3.1.0 -info: - title: common.v1 -paths: {} -components: - schemas: - common.v1.RiskLevel: - type: string - title: RiskLevel - enum: - - RISK_LEVEL_UNSPECIFIED - - RISK_LEVEL_LOW - - RISK_LEVEL_MEDIUM - - RISK_LEVEL_HIGH - - RISK_LEVEL_CRITICAL - description: RiskLevel classifies the risk of an action. -security: [] diff --git a/openapi/common/v1/surface.openapi.yaml b/openapi/common/v1/surface.openapi.yaml deleted file mode 100644 index e8c4251..0000000 --- a/openapi/common/v1/surface.openapi.yaml +++ /dev/null @@ -1,22 +0,0 @@ -openapi: 3.1.0 -info: - title: common.v1 -paths: {} -components: - schemas: - common.v1.Surface: - type: string - title: Surface - enum: - - SURFACE_UNSPECIFIED - - SURFACE_ENSEMBLE - - SURFACE_CHAT - - SURFACE_MAESTRO - - SURFACE_CONDUCTOR - - SURFACE_SLACK - - SURFACE_EXTERNAL_AGENT - description: |- - Surface identifies the product or channel surface that originated a platform - action. It is shared by runtime, audit, and product-facing services so - callers do not invent drift-prone string labels. -security: [] diff --git a/openapi/connectors/v1/connectors.openapi.yaml b/openapi/connectors/v1/connectors.openapi.yaml deleted file mode 100644 index 4840bce..0000000 --- a/openapi/connectors/v1/connectors.openapi.yaml +++ /dev/null @@ -1,4525 +0,0 @@ -openapi: 3.1.0 -info: - title: connectors.v1 -paths: - /connectors.v1.ConnectorService/RegisterConnection: - post: - tags: - - connectors.v1.ConnectorService - summary: RegisterConnection - operationId: connectors.v1.ConnectorService.RegisterConnection - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.RegisterConnectionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.RegisterConnectionResponse' - /connectors.v1.ConnectorService/GetConnection: - post: - tags: - - connectors.v1.ConnectorService - summary: GetConnection - operationId: connectors.v1.ConnectorService.GetConnection - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.GetConnectionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.GetConnectionResponse' - /connectors.v1.ConnectorService/GetBusinessSourceRecord: - post: - tags: - - connectors.v1.ConnectorService - summary: GetBusinessSourceRecord - description: |- - Reads one validated, caller-authorized source observation for business objects. - Private/group-scoped resources are not widened into workspace records. - operationId: connectors.v1.ConnectorService.GetBusinessSourceRecord - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.GetBusinessSourceRecordRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.GetBusinessSourceRecordResponse' - /connectors.v1.ConnectorService/ListConnections: - post: - tags: - - connectors.v1.ConnectorService - summary: ListConnections - operationId: connectors.v1.ConnectorService.ListConnections - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.ListConnectionsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.ListConnectionsResponse' - /connectors.v1.ConnectorService/ListUpcomingCalls: - post: - tags: - - connectors.v1.ConnectorService - summary: ListUpcomingCalls - description: |- - ListUpcomingCalls projects tenant-owned Google Calendar event resources - into provider-neutral calls. Raw provider payloads and connection IDs - remain inside ConnectorService. - operationId: connectors.v1.ConnectorService.ListUpcomingCalls - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.ListUpcomingCallsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.ListUpcomingCallsResponse' - /connectors.v1.ConnectorService/ListProviders: - post: - tags: - - connectors.v1.ConnectorService - summary: ListProviders - operationId: connectors.v1.ConnectorService.ListProviders - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.ListProvidersRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.ListProvidersResponse' - /connectors.v1.ConnectorService/ListProviderPreviews: - post: - tags: - - connectors.v1.ConnectorService - summary: ListProviderPreviews - description: |- - Lists catalog providers that are installed in the active revision but - remain hidden from ListProviders until their generated-canary family - proofs are complete. This surface intentionally omits setup, auth, and - runtime details so callers cannot register an unqualified provider. - operationId: connectors.v1.ConnectorService.ListProviderPreviews - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.ListProviderPreviewsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.ListProviderPreviewsResponse' - /connectors.v1.ConnectorService/PreviewCustomConnector: - post: - tags: - - connectors.v1.ConnectorService - summary: PreviewCustomConnector - operationId: connectors.v1.ConnectorService.PreviewCustomConnector - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.PreviewCustomConnectorRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.PreviewCustomConnectorResponse' - /connectors.v1.ConnectorService/CreateCustomConnector: - post: - tags: - - connectors.v1.ConnectorService - summary: CreateCustomConnector - operationId: connectors.v1.ConnectorService.CreateCustomConnector - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.CreateCustomConnectorRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.CreateCustomConnectorResponse' - /connectors.v1.ConnectorService/GetCustomConnector: - post: - tags: - - connectors.v1.ConnectorService - summary: GetCustomConnector - operationId: connectors.v1.ConnectorService.GetCustomConnector - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.GetCustomConnectorRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.GetCustomConnectorResponse' - /connectors.v1.ConnectorService/ListCustomConnectors: - post: - tags: - - connectors.v1.ConnectorService - summary: ListCustomConnectors - operationId: connectors.v1.ConnectorService.ListCustomConnectors - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.ListCustomConnectorsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.ListCustomConnectorsResponse' - /connectors.v1.ConnectorService/UpdateCustomConnector: - post: - tags: - - connectors.v1.ConnectorService - summary: UpdateCustomConnector - operationId: connectors.v1.ConnectorService.UpdateCustomConnector - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.UpdateCustomConnectorRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.UpdateCustomConnectorResponse' - /connectors.v1.ConnectorService/DeleteCustomConnector: - post: - tags: - - connectors.v1.ConnectorService - summary: DeleteCustomConnector - operationId: connectors.v1.ConnectorService.DeleteCustomConnector - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.DeleteCustomConnectorRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.DeleteCustomConnectorResponse' - /connectors.v1.ConnectorService/ResolveProviderInstallation: - post: - tags: - - connectors.v1.ConnectorService - summary: ResolveProviderInstallation - description: |- - ResolveProviderInstallation maps provider-issued installation coordinates - to exactly one active, tenant-bound connection. It never returns credential - material and callers must not infer tenant scope from a provider workspace. - operationId: connectors.v1.ConnectorService.ResolveProviderInstallation - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.ResolveProviderInstallationRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.ResolveProviderInstallationResponse' - /connectors.v1.ConnectorService/EnrollSurfaceTarget: - post: - tags: - - connectors.v1.ConnectorService - summary: EnrollSurfaceTarget - description: |- - EnrollSurfaceTarget selects one exact provider object for background - observation. Provider-specific adapters verify current read access before - a durable target is created; this call never grants connector authority. - operationId: connectors.v1.ConnectorService.EnrollSurfaceTarget - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.EnrollSurfaceTargetRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.EnrollSurfaceTargetResponse' - /connectors.v1.ConnectorService/VerifyConnectionActive: - post: - tags: - - connectors.v1.ConnectorService - summary: VerifyConnectionActive - operationId: connectors.v1.ConnectorService.VerifyConnectionActive - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.VerifyConnectionActiveRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.VerifyConnectionActiveResponse' - /connectors.v1.ConnectorService/RefreshConnection: - post: - tags: - - connectors.v1.ConnectorService - summary: RefreshConnection - operationId: connectors.v1.ConnectorService.RefreshConnection - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.RefreshConnectionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.RefreshConnectionResponse' - /connectors.v1.ConnectorService/RevokeConnection: - post: - tags: - - connectors.v1.ConnectorService - summary: RevokeConnection - operationId: connectors.v1.ConnectorService.RevokeConnection - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.RevokeConnectionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.RevokeConnectionResponse' - /connectors.v1.ConnectorService/GetHealth: - post: - tags: - - connectors.v1.ConnectorService - summary: GetHealth - operationId: connectors.v1.ConnectorService.GetHealth - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.GetHealthRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.GetHealthResponse' - /connectors.v1.ConnectorService/ResolveSourceOfTruth: - post: - tags: - - connectors.v1.ConnectorService - summary: ResolveSourceOfTruth - operationId: connectors.v1.ConnectorService.ResolveSourceOfTruth - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.ResolveSourceOfTruthRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.ResolveSourceOfTruthResponse' - /connectors.v1.ConnectorService/GetDegradedReadPolicy: - post: - tags: - - connectors.v1.ConnectorService - summary: GetDegradedReadPolicy - operationId: connectors.v1.ConnectorService.GetDegradedReadPolicy - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.GetDegradedReadPolicyRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.GetDegradedReadPolicyResponse' - /connectors.v1.ConnectorService/SetSourceOfTruthPolicy: - post: - tags: - - connectors.v1.ConnectorService - summary: SetSourceOfTruthPolicy - operationId: connectors.v1.ConnectorService.SetSourceOfTruthPolicy - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.SetSourceOfTruthPolicyRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.SetSourceOfTruthPolicyResponse' - /connectors.v1.ConnectorService/GetCapabilities: - post: - tags: - - connectors.v1.ConnectorService - summary: GetCapabilities - operationId: connectors.v1.ConnectorService.GetCapabilities - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.GetCapabilitiesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.GetCapabilitiesResponse' - /connectors.v1.ConnectorService/InitiateOAuthFlow: - post: - tags: - - connectors.v1.ConnectorService - summary: InitiateOAuthFlow - description: |- - InitiateOAuthFlow returns a provider authorize URL plus a server-issued - state token. The UI launches the URL in a popup; the provider redirects - back to /integrations/{provider}/oauth-callback with the auth code, and - the UI then calls CompleteOAuthFlow. - operationId: connectors.v1.ConnectorService.InitiateOAuthFlow - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.InitiateOAuthFlowRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.InitiateOAuthFlowResponse' - /connectors.v1.ConnectorService/CompleteOAuthFlow: - post: - tags: - - connectors.v1.ConnectorService - summary: CompleteOAuthFlow - description: |- - CompleteOAuthFlow exchanges the authorization code for access/refresh - tokens. Providers that authorize more than one tenant return an explicit - selection list; the caller completes the same state with selected_tenant_id. - operationId: connectors.v1.ConnectorService.CompleteOAuthFlow - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.CompleteOAuthFlowRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.CompleteOAuthFlowResponse' - /connectors.v1.ConnectorService/InitiateMcpOAuthFlow: - post: - tags: - - connectors.v1.ConnectorService - summary: InitiateMcpOAuthFlow - description: |- - InitiateMcpOAuthFlow performs protected-resource (RFC 9728) and - authorization-server (RFC 8414) discovery, then returns a PKCE-bound - authorization URL. The connector owner persists the state binding and - returns only metadata and opaque references; token material never crosses - this contract. - operationId: connectors.v1.ConnectorService.InitiateMcpOAuthFlow - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.InitiateMcpOAuthFlowRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.InitiateMcpOAuthFlowResponse' - /connectors.v1.ConnectorService/CompleteMcpOAuthFlow: - post: - tags: - - connectors.v1.ConnectorService - summary: CompleteMcpOAuthFlow - description: |- - CompleteMcpOAuthFlow consumes the one-time state/code binding and asks the - configured secret broker to custody the resulting token set. The response - contains only an opaque connection_ref and durable grant identity. - operationId: connectors.v1.ConnectorService.CompleteMcpOAuthFlow - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.CompleteMcpOAuthFlowRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.CompleteMcpOAuthFlowResponse' - /connectors.v1.ConnectorService/RevokeMcpOAuthGrant: - post: - tags: - - connectors.v1.ConnectorService - summary: RevokeMcpOAuthGrant - operationId: connectors.v1.ConnectorService.RevokeMcpOAuthGrant - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.RevokeMcpOAuthGrantRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.RevokeMcpOAuthGrantResponse' - /connectors.v1.ConnectorService/TriggerSync: - post: - tags: - - connectors.v1.ConnectorService - summary: TriggerSync - description: |- - TriggerSync enqueues a sync run for a connection's resource stream on the - connectors owner's durable run queue. Enqueue is idempotent on - (connection_id, idempotency_key): replaying the same key returns the - existing queue row rather than creating a duplicate run. - operationId: connectors.v1.ConnectorService.TriggerSync - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.TriggerSyncRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.TriggerSyncResponse' - /connectors.v1.ConnectorService/ListConnectionStreams: - post: - tags: - - connectors.v1.ConnectorService - summary: ListConnectionStreams - operationId: connectors.v1.ConnectorService.ListConnectionStreams - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.ListConnectionStreamsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.ListConnectionStreamsResponse' - /connectors.v1.ConnectorService/GetStreamState: - post: - tags: - - connectors.v1.ConnectorService - summary: GetStreamState - operationId: connectors.v1.ConnectorService.GetStreamState - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.GetStreamStateRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.GetStreamStateResponse' - /connectors.v1.ConnectorService/ResetStreamState: - post: - tags: - - connectors.v1.ConnectorService - summary: ResetStreamState - operationId: connectors.v1.ConnectorService.ResetStreamState - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.ResetStreamStateRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.ResetStreamStateResponse' - /connectors.v1.ConnectorService/ExecuteConnectorAction: - post: - tags: - - connectors.v1.ConnectorService - summary: ExecuteConnectorAction - operationId: connectors.v1.ConnectorService.ExecuteConnectorAction - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.ExecuteConnectorActionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.ExecuteConnectorActionResponse' - /connectors.v1.ConnectorService/CreateSyncSchedule: - post: - tags: - - connectors.v1.ConnectorService - summary: CreateSyncSchedule - operationId: connectors.v1.ConnectorService.CreateSyncSchedule - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.CreateSyncScheduleRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.CreateSyncScheduleResponse' - /connectors.v1.ConnectorService/ListSyncSchedules: - post: - tags: - - connectors.v1.ConnectorService - summary: ListSyncSchedules - operationId: connectors.v1.ConnectorService.ListSyncSchedules - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.ListSyncSchedulesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/connectors.v1.ListSyncSchedulesResponse' -components: - schemas: - connectors.v1.AuthType: - type: string - title: AuthType - enum: - - AUTH_TYPE_UNSPECIFIED - - AUTH_TYPE_OAUTH2 - - AUTH_TYPE_API_KEY - - AUTH_TYPE_BASIC - - AUTH_TYPE_MTLS - - AUTH_TYPE_GITHUB_APP - - AUTH_TYPE_NONE - description: AuthType describes the authentication method for a connection. - connectors.v1.ConnectorActionErrorKind: - type: string - title: ConnectorActionErrorKind - enum: - - CONNECTOR_ACTION_ERROR_KIND_UNSPECIFIED - - CONNECTOR_ACTION_ERROR_KIND_RATE_LIMITED - - CONNECTOR_ACTION_ERROR_KIND_PROVIDER - - CONNECTOR_ACTION_ERROR_KIND_INVALID_AUTH - - CONNECTOR_ACTION_ERROR_KIND_MISSING_SCOPE - - CONNECTOR_ACTION_ERROR_KIND_INACCESSIBLE_CHANNEL - - CONNECTOR_ACTION_ERROR_KIND_AMBIGUOUS - connectors.v1.ConnectorActionExecutionState: - type: string - title: ConnectorActionExecutionState - enum: - - CONNECTOR_ACTION_EXECUTION_STATE_UNSPECIFIED - - CONNECTOR_ACTION_EXECUTION_STATE_EXECUTING - - CONNECTOR_ACTION_EXECUTION_STATE_SUCCEEDED - - CONNECTOR_ACTION_EXECUTION_STATE_FAILED - connectors.v1.ConnectorEvidenceKind: - type: string - title: ConnectorEvidenceKind - enum: - - CONNECTOR_EVIDENCE_KIND_UNSPECIFIED - - CONNECTOR_EVIDENCE_KIND_PROBE - - CONNECTOR_EVIDENCE_KIND_FIXTURE - - CONNECTOR_EVIDENCE_KIND_CANARY - - CONNECTOR_EVIDENCE_KIND_PRODUCTION - - CONNECTOR_EVIDENCE_KIND_UNPROVABLE_UNAUTHENTICATED - description: |- - ConnectorEvidenceKind identifies the bounded evidence supporting a catalog - verification level. It does not establish credential validity or transport - availability. - connectors.v1.ConnectorVerificationLevel: - type: string - title: ConnectorVerificationLevel - enum: - - CONNECTOR_VERIFICATION_LEVEL_UNSPECIFIED - - CONNECTOR_VERIFICATION_LEVEL_DECLARED - - CONNECTOR_VERIFICATION_LEVEL_SPEC_DERIVED - - CONNECTOR_VERIFICATION_LEVEL_FIXTURE_VERIFIED - - CONNECTOR_VERIFICATION_LEVEL_LIVE_VERIFIED - - CONNECTOR_VERIFICATION_LEVEL_CONTINUOUSLY_VERIFIED - description: |- - ConnectorVerificationLevel is the fail-closed evidence ladder for a - connector catalog subject. Higher levels require the canonical verification - ledger to contain evidence that justifies the promotion. - connectors.v1.CredentialState: - type: string - title: CredentialState - enum: - - CREDENTIAL_STATE_UNSPECIFIED - - CREDENTIAL_STATE_READY - - CREDENTIAL_STATE_MISSING - - CREDENTIAL_STATE_REVOKED - connectors.v1.HealthStatus: - type: string - title: HealthStatus - enum: - - HEALTH_STATUS_UNSPECIFIED - - HEALTH_STATUS_HEALTHY - - HEALTH_STATUS_DEGRADED - - HEALTH_STATUS_UNHEALTHY - - HEALTH_STATUS_UNKNOWN - description: HealthStatus describes the health state of a connection. - connectors.v1.OAuthActorMode: - type: string - title: OAuthActorMode - enum: - - O_AUTH_ACTOR_MODE_UNSPECIFIED - - O_AUTH_ACTOR_MODE_USER - - O_AUTH_ACTOR_MODE_APP - connectors.v1.ProviderContentTrust: - type: string - title: ProviderContentTrust - enum: - - PROVIDER_CONTENT_TRUST_UNSPECIFIED - - PROVIDER_CONTENT_TRUST_UNTRUSTED_PROVIDER_CONTENT - connectors.v1.ProviderInstallationState: - type: string - title: ProviderInstallationState - enum: - - PROVIDER_INSTALLATION_STATE_UNSPECIFIED - - PROVIDER_INSTALLATION_STATE_ACTIVE - - PROVIDER_INSTALLATION_STATE_RECONNECT_REQUIRED - - PROVIDER_INSTALLATION_STATE_REVOKED - description: |- - ProviderInstallationState is the lifecycle state of a provider-issued app - installation. Only ACTIVE installations may resolve for event ingress. - connectors.v1.ProviderQualificationState: - type: string - title: ProviderQualificationState - enum: - - PROVIDER_QUALIFICATION_STATE_UNSPECIFIED - - PROVIDER_QUALIFICATION_STATE_PENDING - - PROVIDER_QUALIFICATION_STATE_QUALIFIED - connectors.v1.ProviderResourceLifecycleState: - type: string - title: ProviderResourceLifecycleState - enum: - - PROVIDER_RESOURCE_LIFECYCLE_STATE_UNSPECIFIED - - PROVIDER_RESOURCE_LIFECYCLE_STATE_ACTIVE - - PROVIDER_RESOURCE_LIFECYCLE_STATE_ARCHIVED - - PROVIDER_RESOURCE_LIFECYCLE_STATE_DELETED - - PROVIDER_RESOURCE_LIFECYCLE_STATE_CONNECTION_REVOKED - - PROVIDER_RESOURCE_LIFECYCLE_STATE_QUARANTINED - connectors.v1.ProviderResourceVisibilityClass: - type: string - title: ProviderResourceVisibilityClass - enum: - - PROVIDER_RESOURCE_VISIBILITY_CLASS_UNSPECIFIED - - PROVIDER_RESOURCE_VISIBILITY_CLASS_WORKSPACE_PUBLIC - - PROVIDER_RESOURCE_VISIBILITY_CLASS_EXPLICIT_PRINCIPALS - - PROVIDER_RESOURCE_VISIBILITY_CLASS_GROUP_MEMBERSHIP - - PROVIDER_RESOURCE_VISIBILITY_CLASS_CONNECTION_PRIVATE - connectors.v1.ReplicationMode: - type: string - title: ReplicationMode - enum: - - REPLICATION_MODE_UNSPECIFIED - - REPLICATION_MODE_FULL_REFRESH - - REPLICATION_MODE_INCREMENTAL - description: Mirrors connectors_cdk::ReplicationMode (crates/connectors-cdk/src/lib.rs). - connectors.v1.SourceAuthorityFreshnessMethod: - type: string - title: SourceAuthorityFreshnessMethod - enum: - - SOURCE_AUTHORITY_FRESHNESS_METHOD_UNSPECIFIED - - SOURCE_AUTHORITY_FRESHNESS_METHOD_NOT_OBSERVED - - SOURCE_AUTHORITY_FRESHNESS_METHOD_INTROSPECTION - - SOURCE_AUTHORITY_FRESHNESS_METHOD_WEBHOOK - - SOURCE_AUTHORITY_FRESHNESS_METHOD_POLLING - - SOURCE_AUTHORITY_FRESHNESS_METHOD_SHORT_TTL - - SOURCE_AUTHORITY_FRESHNESS_METHOD_REFRESH_FAILURE - description: |- - SourceAuthorityFreshnessMethod identifies how the source observation was - obtained. NOT_OBSERVED is the explicit default when no authoritative - producer has supplied a response; it is not evidence of source access. - connectors.v1.SourceAuthorityState: - type: string - title: SourceAuthorityState - enum: - - SOURCE_AUTHORITY_STATE_UNSPECIFIED - - SOURCE_AUTHORITY_STATE_SUFFICIENT - - SOURCE_AUTHORITY_STATE_INSUFFICIENT - - SOURCE_AUTHORITY_STATE_UNKNOWN - - SOURCE_AUTHORITY_STATE_REVOKED - description: |- - SourceAuthorityState is the external source system's authority posture for - a connection. A locally active row is not source authority; callers must - receive an explicit UNKNOWN observation until an authoritative producer - reports otherwise. - connectors.v1.SourceOfTruthArea: - type: string - title: SourceOfTruthArea - enum: - - SOURCE_OF_TRUTH_AREA_UNSPECIFIED - - SOURCE_OF_TRUTH_AREA_CRM - - SOURCE_OF_TRUTH_AREA_SUPPORT - - SOURCE_OF_TRUTH_AREA_BILLING - - SOURCE_OF_TRUTH_AREA_ANALYTICS - - SOURCE_OF_TRUTH_AREA_HRIS - description: SourceOfTruthArea identifies a functional domain for source-of-truth resolution. - connectors.v1.UpcomingCallSourceState: - type: string - title: UpcomingCallSourceState - enum: - - UPCOMING_CALL_SOURCE_STATE_UNSPECIFIED - - UPCOMING_CALL_SOURCE_STATE_AVAILABLE - - UPCOMING_CALL_SOURCE_STATE_NOT_CONNECTED - description: |- - UpcomingCallSourceState distinguishes a connected calendar with no matching - calls from a workspace that has not connected a supported calendar. - connectors.v1.CompleteMcpOAuthFlowRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - serverId: - type: string - title: server_id - minLength: 1 - profileId: - type: string - title: profile_id - minLength: 1 - state: - type: string - title: state - minLength: 1 - code: - type: string - title: code - description: |- - Empty code is permitted only for a provider error response; the - Connector validates the raw iss binding before acting on any error text. - redirectUri: - type: string - title: redirect_uri - format: uri - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - profileGeneration: - exclusiveMinimum: 0 - type: - - integer - - string - title: profile_generation - format: int64 - authorizationResponseIss: - type: string - title: authorization_response_iss - description: |- - Raw RFC 9207 authorization response fields. These are additive so older - callers continue to send the same request shape. - providerError: - type: string - title: provider_error - providerErrorDescription: - type: string - title: provider_error_description - providerErrorUri: - type: string - title: provider_error_uri - title: CompleteMcpOAuthFlowRequest - additionalProperties: false - connectors.v1.CompleteMcpOAuthFlowResponse: - type: object - properties: - connectionRef: - type: string - title: connection_ref - grantId: - type: string - title: grant_id - scopes: - type: array - items: - type: string - title: scopes - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - grantVersion: - type: - - integer - - string - title: grant_version - format: int64 - profileId: - type: string - title: profile_id - title: CompleteMcpOAuthFlowResponse - additionalProperties: false - connectors.v1.CompleteOAuthFlowRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - organizationId: - type: string - title: organization_id - minLength: 1 - providerId: - type: string - title: provider_id - minLength: 1 - state: - type: string - title: state - minLength: 1 - description: State token returned from InitiateOAuthFlow. - code: - type: string - title: code - description: |- - Authorization code returned by the provider on the redirect. Required on - the first completion and empty only when selected_tenant_id completes an - already-custodied multi-tenant authorization. - redirectUri: - type: string - title: redirect_uri - minLength: 1 - description: Same redirect_uri passed to InitiateOAuthFlow; providers verify it. - displayName: - type: string - title: display_name - description: Human-friendly label persisted on the connection record. - idempotencyKey: - type: string - title: idempotency_key - githubInstallationId: - type: - - integer - - string - title: github_installation_id - format: int64 - description: |- - Untrusted GitHub callback coordinate; verified against the authenticated - provider user and configured product App before connection registration. - selectedTenantId: - type: string - title: selected_tenant_id - description: |- - Exact provider tenant selected from a prior CompleteOAuthFlow response. - Leave empty on the authorization-code exchange. The server never chooses - an authorized tenant implicitly. - title: CompleteOAuthFlowRequest - additionalProperties: false - connectors.v1.CompleteOAuthFlowResponse: - type: object - properties: - connection: - title: connection - $ref: '#/components/schemas/connectors.v1.Connection' - authorizedTenants: - type: array - items: - $ref: '#/components/schemas/connectors.v1.OAuthProviderTenant' - title: authorized_tenants - description: |- - Authorized provider tenants requiring explicit customer selection before - the connection can be registered. Empty when connection is populated. - tenantSelectionRequired: - type: boolean - title: tenant_selection_required - title: CompleteOAuthFlowResponse - additionalProperties: false - connectors.v1.Connection: - type: object - properties: - id: - type: string - title: id - workspaceId: - type: string - title: workspace_id - providerId: - type: string - title: provider_id - displayName: - type: string - title: display_name - authType: - title: auth_type - $ref: '#/components/schemas/connectors.v1.AuthType' - scopes: - type: array - items: - type: string - title: scopes - healthStatus: - title: health_status - $ref: '#/components/schemas/connectors.v1.HealthStatus' - lastHealthyAt: - title: last_healthy_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - credentialRefs: - type: object - title: credential_refs - additionalProperties: - type: string - title: value - description: |- - credential_refs mirrors non-secret credential references such as vault or - secret-manager handles. Raw credential material must not be returned here. - organizationId: - type: string - title: organization_id - healthReason: - type: string - title: health_reason - description: |- - health_reason is a short, human-readable explanation of the current - health_status — "token refreshed 2m ago", "auth failed: token revoked", - "rate-limited by upstream". The UI surfaces it on tiles and the active - card so operators don't have to dig into logs to find out why a - connection is degraded. Empty when there's nothing meaningful to add. - credentialExpiresAt: - title: credential_expires_at - description: |- - Expiry of the connection's stored OAuth credential, when known. Unset for - API-key/basic/mtls connections and for providers that do not report it. - $ref: '#/components/schemas/google.protobuf.Timestamp' - revision: - type: - - integer - - string - title: revision - format: int64 - description: Connection-owner custody revision. Zero is an unpersisted or legacy snapshot. - title: Connection - additionalProperties: false - description: Connection is the canonical external integration connection record. - connectors.v1.Connection.CredentialRefsEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: CredentialRefsEntry - additionalProperties: false - connectors.v1.ConnectionHealth: - type: object - properties: - status: - title: status - $ref: '#/components/schemas/connectors.v1.HealthStatus' - latencyMs: - type: integer - title: latency_ms - format: int32 - lastCheckAt: - title: last_check_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - errorMessage: - type: string - title: error_message - reason: - type: string - title: reason - description: |- - reason mirrors Connection.health_reason but for the live GetHealth - response. Empty when status==healthy and there's nothing to surface. - title: ConnectionHealth - additionalProperties: false - description: ConnectionHealth provides detailed health information for a connection. - connectors.v1.ConnectionStream: - type: object - properties: - streamId: - type: string - title: stream_id - stableId: - type: string - title: stable_id - replicationMode: - title: replication_mode - $ref: '#/components/schemas/connectors.v1.ReplicationMode' - selectedByDefault: - type: boolean - title: selected_by_default - primaryKey: - type: array - items: - type: string - title: primary_key - cursorField: - type: string - title: cursor_field - cursor: - title: cursor - $ref: '#/components/schemas/connectors.v1.StreamCursorState' - lastRun: - title: last_run - $ref: '#/components/schemas/connectors.v1.StreamRunSummary' - title: ConnectionStream - additionalProperties: false - connectors.v1.ConnectorActionDefinition: - type: object - properties: - id: - type: string - title: id - minLength: 1 - capability: - type: string - title: capability - minLength: 1 - httpMethod: - type: string - title: http_method - minLength: 1 - path: - type: string - title: path - minLength: 1 - approvalRequired: - type: boolean - title: approval_required - destructive: - type: boolean - title: destructive - stableId: - type: string - title: stable_id - minLength: 1 - provenance: - title: provenance - $ref: '#/components/schemas/connectors.v1.ConnectorCatalogProvenance' - baseUrl: - type: string - title: base_url - format: uri - requiredScopes: - type: array - items: - type: string - title: required_scopes - inputSchemaJson: - type: string - title: input_schema_json - digest: - type: string - title: digest - effect: - type: string - title: effect - description: |- - Canonical semantic effect for this action. Empty/unspecified is - fail-closed: only an explicit `read` effect may enter a governed - read-only execution path. This is independent of the provider HTTP - method because some read APIs (for example Tavily search) use POST. - governed: - title: governed - description: Catalog-owned tool metadata. Presence does not grant execution authority. - $ref: '#/components/schemas/connectors.v1.ConnectorGovernedAction' - surfaceProjection: - type: boolean - title: surface_projection - description: |- - This action may be emitted by a registered object-surface projector. - Presence is descriptive only; installation authority is still required. - title: ConnectorActionDefinition - additionalProperties: false - description: ConnectorActionDefinition declares one provider-native operation. - connectors.v1.ConnectorAuthBinding: - type: object - properties: - stableId: - type: string - title: stable_id - credentialField: - type: string - title: credential_field - placement: - type: string - title: placement - scheme: - type: string - title: scheme - headerName: - type: string - title: header_name - queryParam: - type: string - title: query_param - provenance: - title: provenance - $ref: '#/components/schemas/connectors.v1.ConnectorCatalogProvenance' - valuePrefix: - type: string - title: value_prefix - valueKey: - type: string - title: value_key - title: ConnectorAuthBinding - additionalProperties: false - connectors.v1.ConnectorCatalogProvenance: - type: object - properties: - basis: - type: string - title: basis - sourceUrl: - type: string - title: source_url - lastVerifiedAt: - type: string - title: last_verified_at - verificationLevel: - title: verification_level - $ref: '#/components/schemas/connectors.v1.ConnectorVerificationLevel' - evidenceKind: - title: evidence_kind - $ref: '#/components/schemas/connectors.v1.ConnectorEvidenceKind' - title: ConnectorCatalogProvenance - additionalProperties: false - description: |- - ConnectorCatalogProvenance records where a catalog-derived value came from - (for example an OpenAPI spec import), when it was last verified, and the - bounded evidence behind its current verification level. - connectors.v1.ConnectorChildResource: - type: object - properties: - familyId: - type: string - title: family_id - minLength: 1 - parentFamilyId: - type: string - title: parent_family_id - minLength: 1 - pathParams: - type: array - items: - $ref: '#/components/schemas/connectors.v1.ConnectorPathParameterBinding' - title: path_params - queryParams: - type: array - items: - $ref: '#/components/schemas/connectors.v1.ConnectorPathParameterBinding' - title: query_params - title: ConnectorChildResource - additionalProperties: false - description: |- - ConnectorChildResource declares how to enumerate a parameterized resource - path from parent records. - connectors.v1.ConnectorCostProjection: - type: object - properties: - spendMonthField: - type: string - title: spend_month_field - spendTodayField: - type: string - title: spend_today_field - assetNameFields: - type: array - items: - type: string - title: asset_name_fields - modelField: - type: string - title: model_field - sourceUrlField: - type: string - title: source_url_field - resourceIdSource: - type: string - title: resource_id_source - recordKind: - type: string - title: record_kind - periodField: - type: string - title: period_field - occurredAtField: - type: string - title: occurred_at_field - inputTokensField: - type: string - title: input_tokens_field - outputTokensField: - type: string - title: output_tokens_field - requestCountField: - type: string - title: request_count_field - requestCountValue: - type: - - integer - - string - title: request_count_value - format: int64 - spendUnit: - type: string - title: spend_unit - occurredAtFormat: - type: string - title: occurred_at_format - resultSelector: - type: string - title: result_selector - amountField: - type: string - title: amount_field - currencyField: - type: string - title: currency_field - dimensionFields: - type: array - items: - type: string - title: dimension_fields - sourceIdentityFields: - type: array - items: - type: string - title: source_identity_fields - title: ConnectorCostProjection - additionalProperties: false - connectors.v1.ConnectorCredentialField: - type: object - properties: - name: - type: string - title: name - minLength: 1 - label: - type: string - title: label - required: - type: boolean - title: required - secret: - type: boolean - title: secret - acceptedReferenceSchemes: - type: array - items: - type: string - title: accepted_reference_schemes - credentialType: - type: string - title: credential_type - versioned: - type: boolean - title: versioned - rotatable: - type: boolean - title: rotatable - revocable: - type: boolean - title: revocable - expires: - type: boolean - title: expires - stableId: - type: string - title: stable_id - minLength: 1 - provenance: - title: provenance - $ref: '#/components/schemas/connectors.v1.ConnectorCatalogProvenance' - title: ConnectorCredentialField - additionalProperties: false - description: |- - ConnectorCredentialField describes the credential reference slots accepted - by a managed provider. Values are reference handles such as vault:// or - gsm:// URIs, never raw credential material. - connectors.v1.ConnectorCredentialLifecyclePolicy: - type: object - properties: - supportedCredentialTypes: - type: array - items: - type: string - title: supported_credential_types - supportsVersioning: - type: boolean - title: supports_versioning - supportsRotation: - type: boolean - title: supports_rotation - supportsRevocation: - type: boolean - title: supports_revocation - rotationNoticeDays: - type: integer - title: rotation_notice_days - format: int32 - title: ConnectorCredentialLifecyclePolicy - additionalProperties: false - description: |- - ConnectorCredentialLifecyclePolicy describes the generic credential lifecycle - operations the platform can drive for a provider. - connectors.v1.ConnectorGovernedAction: - type: object - properties: - toolName: - type: string - title: tool_name - version: - type: integer - title: version - compatibilityAliases: - type: array - items: - type: string - title: compatibility_aliases - description: - type: string - title: description - mentionDefault: - type: boolean - title: mention_default - mentionKeywords: - type: array - items: - type: string - title: mention_keywords - outputSchemaJson: - type: string - title: output_schema_json - inputExampleJson: - type: string - title: input_example_json - outputExampleJson: - type: string - title: output_example_json - title: ConnectorGovernedAction - additionalProperties: false - description: |- - ConnectorGovernedAction preserves published tool descriptions, schemas, and - examples across compiled and durable catalog projections. Execution still - requires the connection's granted scopes and the action's effect policy. - connectors.v1.ConnectorIncrementalBinding: - type: object - properties: - requestParam: - type: string - title: request_param - comparison: - type: string - title: comparison - initialLookbackSeconds: - type: - - integer - - string - title: initial_lookback_seconds - format: int64 - nullable: true - initialLookbackFormat: - type: string - title: initial_lookback_format - sliceSeconds: - type: - - integer - - string - title: slice_seconds - format: int64 - nullable: true - resumeLookbackSeconds: - type: - - integer - - string - title: resume_lookback_seconds - format: int64 - nullable: true - title: ConnectorIncrementalBinding - additionalProperties: false - connectors.v1.ConnectorPaginationContract: - type: object - properties: - kind: - type: string - title: kind - cursorParam: - type: string - title: cursor_param - cursorResponsePath: - type: string - title: cursor_response_path - pageParam: - type: string - title: page_param - offsetParam: - type: string - title: offset_param - pageSizeParam: - type: string - title: page_size_param - pageSizeDefault: - type: integer - title: page_size_default - nullable: true - initialValue: - type: integer - title: initial_value - nullable: true - increment: - type: integer - title: increment - nullable: true - nextUrlResponsePath: - type: string - title: next_url_response_path - stopOnShortPage: - type: boolean - title: stop_on_short_page - title: ConnectorPaginationContract - additionalProperties: false - connectors.v1.ConnectorPathParameterBinding: - type: object - properties: - param: - type: string - title: param - minLength: 1 - sourceField: - type: string - title: source_field - minLength: 1 - title: ConnectorPathParameterBinding - additionalProperties: false - description: |- - ConnectorPathParameterBinding maps a "{param}" segment in a child family - path to a field from the parent record or from a path parameter inherited by - that parent. - connectors.v1.ConnectorProvider: - type: object - properties: - id: - type: string - title: id - minLength: 1 - displayName: - type: string - title: display_name - defaultAuthType: - title: default_auth_type - $ref: '#/components/schemas/connectors.v1.AuthType' - defaultScopes: - type: array - items: - type: string - title: default_scopes - capabilities: - type: array - items: - type: string - title: capabilities - supportsPkce: - type: boolean - title: supports_pkce - supportsRefresh: - type: boolean - title: supports_refresh - credentialFields: - type: array - items: - $ref: '#/components/schemas/connectors.v1.ConnectorCredentialField' - title: credential_fields - credentialLifecyclePolicy: - title: credential_lifecycle_policy - $ref: '#/components/schemas/connectors.v1.ConnectorCredentialLifecyclePolicy' - oauthSupported: - type: boolean - title: oauth_supported - description: |- - oauth_supported is true when the connectors backend can run the OAuth - flow for this provider — i.e. the provider is in oauthProviderRegistry - and its OAuth client_id/secret are present in the OAuth catalog. The - UI uses this instead of a hardcoded list to decide whether to show - the Authorize launcher or the catalog-runbook notice; that means - adding a provider in Go automatically flips it on for the UI. - catalogCategories: - type: array - items: - type: string - title: catalog_categories - description: |- - catalog_categories are backend-authored tags such as "ai" or - "governance" used by UI filtering and operator copy. - runtime: - title: runtime - description: runtime is set when the provider has an executable inventory/read runtime. - $ref: '#/components/schemas/connectors.v1.ConnectorRuntime' - stableId: - type: string - title: stable_id - aliases: - type: array - items: - type: string - title: aliases - provenance: - title: provenance - $ref: '#/components/schemas/connectors.v1.ConnectorCatalogProvenance' - authBindings: - type: array - items: - $ref: '#/components/schemas/connectors.v1.ConnectorAuthBinding' - title: auth_bindings - tier: - type: string - title: tier - description: |- - tier is derived by the catalog compiler from the executable runtime - shape. It is not an authored readiness or verification claim. - rolloutKind: - type: string - title: rollout_kind - description: |- - rollout_kind controls durable catalog exposure. Machine imports use - generated_canary until every required family has visible proof. - canaryCohortSha256: - type: string - title: canary_cohort_sha256 - description: |- - Immutable source/import cohort used to bind generated-canary proof. - Empty for built-in and tenant-owned custom providers. - description: - type: string - title: description - description: |- - Customer-facing source description. Empty means the catalog has no - authoritative description. - title: ConnectorProvider - additionalProperties: false - description: |- - ConnectorProvider describes a managed connector provider that can be used to - register a connection. - connectors.v1.ConnectorProviderPreview: - type: object - properties: - id: - type: string - title: id - minLength: 1 - displayName: - type: string - title: display_name - catalogCategories: - type: array - items: - type: string - title: catalog_categories - tier: - type: string - title: tier - rolloutKind: - type: string - title: rollout_kind - qualificationState: - title: qualification_state - $ref: '#/components/schemas/connectors.v1.ProviderQualificationState' - resourceFamilyCount: - type: integer - title: resource_family_count - format: int32 - providerActionCount: - type: integer - title: provider_action_count - format: int32 - requiredFamilyCount: - type: integer - title: required_family_count - format: int32 - qualifiedFamilyCount: - type: integer - title: qualified_family_count - format: int32 - customerVisible: - type: boolean - title: customer_visible - description: - type: string - title: description - description: Customer-facing source description. Empty means unknown. - resourceFamilies: - type: array - items: - $ref: '#/components/schemas/connectors.v1.ConnectorResourceFamilySummary' - title: resource_families - description: |- - Safe family metadata for discovery. These summaries carry no endpoint, - auth, credential, or request-planning data. - providerActionIds: - type: array - items: - type: string - title: provider_action_ids - description: Stable action identifiers are kept separate from readable resource types. - title: ConnectorProviderPreview - additionalProperties: false - description: |- - ConnectorProviderPreview is safe discovery metadata for an installed - provider that is not yet customer-visible. It deliberately excludes auth, - endpoint, credential, action, and request-planning fields. - connectors.v1.ConnectorQueryParamBinding: - type: object - properties: - name: - type: string - title: name - source: - type: string - title: source - staticValue: - type: string - title: static_value - credentialField: - type: string - title: credential_field - connectionConfigKey: - type: string - title: connection_config_key - title: ConnectorQueryParamBinding - additionalProperties: false - connectors.v1.ConnectorResourceFamily: - type: object - properties: - id: - type: string - title: id - minLength: 1 - path: - type: string - title: path - minLength: 1 - eventKind: - type: string - title: event_kind - minLength: 1 - httpMethod: - type: string - title: http_method - defaultRequestBodyJson: - type: string - title: default_request_body_json - stableId: - type: string - title: stable_id - aliases: - type: array - items: - type: string - title: aliases - provenance: - title: provenance - $ref: '#/components/schemas/connectors.v1.ConnectorCatalogProvenance' - recordSelector: - type: string - title: record_selector - primaryKey: - type: array - items: - type: string - title: primary_key - cursorField: - type: string - title: cursor_field - pagination: - title: pagination - $ref: '#/components/schemas/connectors.v1.ConnectorPaginationContract' - requestsPerWindow: - type: integer - title: requests_per_window - nullable: true - windowSeconds: - type: integer - title: window_seconds - nullable: true - maxConcurrency: - type: integer - title: max_concurrency - nullable: true - baseUrl: - type: string - title: base_url - nullable: true - queryParamBindings: - type: array - items: - $ref: '#/components/schemas/connectors.v1.ConnectorQueryParamBinding' - title: query_param_bindings - incremental: - title: incremental - $ref: '#/components/schemas/connectors.v1.ConnectorIncrementalBinding' - syntheticPrimaryKey: - type: boolean - title: synthetic_primary_key - cost: - title: cost - $ref: '#/components/schemas/connectors.v1.ConnectorCostProjection' - displayName: - type: string - title: display_name - description: |- - Customer-facing label supplied by the catalog source. Empty means the - catalog has no authoritative label; consumers must not infer one from id. - sourceCoverageTypes: - type: array - items: - type: string - title: source_coverage_types - description: |- - Exact coverage taxonomy declared by the source catalog. This is source - metadata, not a Mono canonical resource type. - sourceProjectionTemplate: - type: string - title: source_projection_template - description: |- - Projection template declared by the source catalog. It records upstream - intent and does not claim that Mono executes that domain projection. - title: ConnectorResourceFamily - additionalProperties: false - description: |- - ConnectorResourceFamily names one upstream resource collection the runtime - can read. - connectors.v1.ConnectorResourceFamilySummary: - type: object - properties: - id: - type: string - title: id - minLength: 1 - displayName: - type: string - title: display_name - sourceCoverageTypes: - type: array - items: - type: string - title: source_coverage_types - sourceProjectionTemplate: - type: string - title: source_projection_template - eventKind: - type: string - title: event_kind - minLength: 1 - title: ConnectorResourceFamilySummary - additionalProperties: false - description: |- - Safe discovery metadata for one provider resource family. Endpoint, auth, - request-planning, and response-schema details are intentionally excluded. - connectors.v1.ConnectorRuntime: - type: object - properties: - baseUrl: - type: string - title: base_url - description: |- - base_url is the provider API origin or templated origin, e.g. - "https://api.openai.com/v1" or "https://bedrock.{region}.amazonaws.com". - verificationPath: - type: string - title: verification_path - description: |- - verification_path is the endpoint the backend can probe to validate - credentials before deeper resource reads. - resourceFamilies: - type: array - items: - $ref: '#/components/schemas/connectors.v1.ConnectorResourceFamily' - title: resource_families - childResources: - type: array - items: - $ref: '#/components/schemas/connectors.v1.ConnectorChildResource' - title: child_resources - requestsPerWindow: - type: integer - title: requests_per_window - description: |- - Provider-level rate-limit defaults. Unset (all three absent) means the - provider runs unthrottled. A ConnectorResourceFamily may override any of - these three per resource family. This field replaces a previously - vestigial `repeated ConnectorActionDefinition actions = 5` that no - platform code ever populated or read (evalops/platform#5124); the tag-5 - wire type it now carries (VARINT) matches connectors-rs, the service - that actually produces these bytes. - nullable: true - windowSeconds: - type: integer - title: window_seconds - nullable: true - maxConcurrency: - type: integer - title: max_concurrency - nullable: true - staticHeaders: - type: array - items: - $ref: '#/components/schemas/connectors.v1.ConnectorStaticHeader' - title: static_headers - description: |- - Non-secret constant headers/query params applied to every request for - this runtime. Never redacted: these are not credential material. - credentialDestinationOrigins: - type: array - items: - type: string - title: credential_destination_origins - description: |- - Explicit origin templates authorized to receive this runtime's - credentials. Request execution rejects URLs outside this set before - resolving header/query credentials. - providerActions: - type: array - items: - $ref: '#/components/schemas/connectors.v1.ConnectorActionDefinition' - title: provider_actions - description: |- - ConnectorService, the catalog owner, publishes its authoritative action - inventory here. Named `provider_actions` instead of connectors-rs's - `actions` -- see the naming-debt note at the top of this file. - credentialDestinationHostSuffixes: - type: array - items: - type: string - title: credential_destination_host_suffixes - description: |- - Optional DNS suffix constraints for credential-bearing destinations whose - hostname is supplied by connection configuration. Hosts must equal a - suffix or be its dot-delimited subdomain; ports, IP literals, userinfo, - trailing dots, and encoded lookalikes are rejected before auth resolves. - title: ConnectorRuntime - additionalProperties: false - description: |- - ConnectorRuntime describes the read runtime a managed provider exposes. - The connectors backend uses this to advertise concrete upstream resources - that can be inventoried, including child resources whose path parameters - must be bound from parent records. - connectors.v1.ConnectorStaticHeader: - type: object - properties: - placement: - type: string - title: placement - name: - type: string - title: name - value: - type: string - title: value - title: ConnectorStaticHeader - additionalProperties: false - description: A non-secret constant header or query parameter applied to every request. - connectors.v1.CreateCustomConnectorRequest: - type: object - properties: - definition: - title: definition - $ref: '#/components/schemas/connectors.v1.PreviewCustomConnectorRequest' - title: CreateCustomConnectorRequest - additionalProperties: false - connectors.v1.CreateCustomConnectorResponse: - type: object - properties: - connector: - title: connector - $ref: '#/components/schemas/connectors.v1.CustomConnector' - title: CreateCustomConnectorResponse - additionalProperties: false - connectors.v1.CreateSyncScheduleRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - connectionId: - type: string - title: connection_id - streamId: - type: string - title: stream_id - intervalSeconds: - type: integer - title: interval_seconds - format: int32 - enabled: - type: boolean - title: enabled - idempotencyKey: - type: string - title: idempotency_key - title: CreateSyncScheduleRequest - additionalProperties: false - connectors.v1.CreateSyncScheduleResponse: - type: object - properties: - schedule: - title: schedule - $ref: '#/components/schemas/connectors.v1.SyncSchedule' - idempotentReplay: - type: boolean - title: idempotent_replay - title: CreateSyncScheduleResponse - additionalProperties: false - connectors.v1.CustomConnector: - type: object - properties: - id: - type: string - title: id - minLength: 1 - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - name: - type: string - title: name - minLength: 1 - description: - type: string - title: description - sourceType: - type: string - title: source_type - minLength: 1 - sourceUri: - type: string - title: source_uri - providerId: - type: string - title: provider_id - minLength: 1 - specSha256: - type: string - title: spec_sha256 - minLength: 64 - status: - type: string - title: status - minLength: 1 - actions: - type: array - items: - $ref: '#/components/schemas/connectors.v1.CustomConnectorActionMetadata' - title: actions - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - revision: - type: - - integer - - string - title: revision - format: int64 - title: CustomConnector - additionalProperties: false - connectors.v1.CustomConnectorActionMetadata: - type: object - properties: - actionId: - type: string - title: action_id - minLength: 1 - toolName: - type: string - title: tool_name - toolDescription: - type: string - title: tool_description - effect: - type: string - title: effect - enabled: - type: boolean - title: enabled - estimatedSchemaTokens: - type: integer - title: estimated_schema_tokens - descriptionProposalReviewed: - type: boolean - title: description_proposal_reviewed - title: CustomConnectorActionMetadata - additionalProperties: false - description: |- - CustomConnectorActionMetadata is the tenant-editable presentation and - policy layer. The compiled action identity (method, path, schema, and - digest) remains immutable after activation. - connectors.v1.DegradedReadPolicy: - type: object - properties: - mode: - type: string - title: mode - allowedIntegrations: - type: array - items: - type: string - title: allowed_integrations - maxAgeMinutes: - type: integer - title: max_age_minutes - format: int32 - queuePrimaryRefresh: - type: boolean - title: queue_primary_refresh - title: DegradedReadPolicy - additionalProperties: false - description: DegradedReadPolicy defines behavior when the primary source is unavailable. - connectors.v1.DeleteCustomConnectorRequest: - type: object - properties: - id: - type: string - title: id - minLength: 1 - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - title: DeleteCustomConnectorRequest - additionalProperties: false - connectors.v1.DeleteCustomConnectorResponse: - type: object - properties: - id: - type: string - title: id - status: - type: string - title: status - title: DeleteCustomConnectorResponse - additionalProperties: false - connectors.v1.EnrollSurfaceTargetRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - maxLength: 256 - minLength: 1 - workspaceId: - type: string - title: workspace_id - maxLength: 256 - minLength: 1 - connectionId: - type: string - title: connection_id - maxLength: 256 - minLength: 1 - providerId: - type: string - title: provider_id - maxLength: 128 - minLength: 1 - targetKind: - type: string - title: target_kind - maxLength: 64 - minLength: 1 - externalId: - type: string - title: external_id - maxLength: 1024 - minLength: 1 - canonicalUrl: - type: string - title: canonical_url - maxLength: 4096 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 256 - minLength: 1 - title: EnrollSurfaceTargetRequest - additionalProperties: false - connectors.v1.EnrollSurfaceTargetResponse: - type: object - properties: - connectionId: - type: string - title: connection_id - providerId: - type: string - title: provider_id - targetKind: - type: string - title: target_kind - externalId: - type: string - title: external_id - state: - type: string - title: state - idempotentReplay: - type: boolean - title: idempotent_replay - title: EnrollSurfaceTargetResponse - additionalProperties: false - connectors.v1.ExecuteConnectorActionRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - connectionId: - type: string - title: connection_id - minLength: 1 - actionId: - type: string - title: action_id - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - approvalRequestId: - type: string - title: approval_request_id - actionDigest: - type: string - title: action_digest - minLength: 1 - bodyJson: - type: string - title: body_json - expectedProviderRevision: - type: string - title: expected_provider_revision - authorityGrantId: - type: string - title: authority_grant_id - description: |- - Routine server-owned channel actions use a bounded authority grant rather - than manufacturing an approval request. Exactly one authority field is - accepted by ConnectorService. - executionAuthorityToken: - type: string - title: execution_authority_token - description: |- - Canonical owner: evalops/connectors-rs. This opaque Identity remote-work - token attests one exact action delegated by the authority-checking - caller (tool-executor's direct connector adapter or platform-worker's - proactive action dispatch). Connectors must verify both this token and - every exact request binding; neither the ordinary RPC bearer nor this - field alone is sufficient authorization. - canonicalRequestDigest: - type: string - title: canonical_request_digest - description: |- - Canonical digest of the exact action, catalog revision, authority, - expected provider revision, and normalized body. action_digest remains - the catalog digest. - title: ExecuteConnectorActionRequest - additionalProperties: false - connectors.v1.ExecuteConnectorActionResponse: - type: object - properties: - connectorActionExecutionId: - type: string - title: connector_action_execution_id - state: - type: string - title: state - description: Deprecated compatibility projection. New consumers must use action_state. - deprecated: true - providerObjectId: - type: string - title: provider_object_id - providerRevision: - type: string - title: provider_revision - idempotentReplay: - type: boolean - title: idempotent_replay - redactedResultJson: - type: string - title: redacted_result_json - actionState: - title: action_state - $ref: '#/components/schemas/connectors.v1.ConnectorActionExecutionState' - errorKind: - title: error_kind - $ref: '#/components/schemas/connectors.v1.ConnectorActionErrorKind' - errorCode: - type: string - title: error_code - retryEligible: - type: boolean - title: retry_eligible - retryAfterSeconds: - type: - - integer - - string - title: retry_after_seconds - format: int64 - nullable: true - operatorDetail: - type: string - title: operator_detail - providerChannelId: - type: string - title: provider_channel_id - providerMessageTs: - type: string - title: provider_message_ts - reconciliationRequired: - type: boolean - title: reconciliation_required - title: ExecuteConnectorActionResponse - additionalProperties: false - connectors.v1.GetBusinessSourceRecordRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - connectionId: - type: string - title: connection_id - minLength: 1 - familyStableId: - type: string - title: family_stable_id - minLength: 1 - recordId: - type: string - title: record_id - minLength: 1 - title: GetBusinessSourceRecordRequest - additionalProperties: false - description: Coordinates of a current Connector-owned observation; never caller-provided facts. - connectors.v1.GetBusinessSourceRecordResponse: - type: object - properties: - envelope: - title: envelope - $ref: '#/components/schemas/connectors.v1.ProviderResourceEnvelope' - lastEventId: - type: string - title: last_event_id - externalId: - type: string - title: external_id - displayName: - type: string - title: display_name - description: Present only when a supported provider mapping supplies a display name. - observedAt: - title: observed_at - description: Time this observation entered the current projection, not source effective time. - $ref: '#/components/schemas/google.protobuf.Timestamp' - website: - type: string - title: website - description: Optional canonical website supplied by a supported provider mapping. - title: GetBusinessSourceRecordResponse - additionalProperties: false - connectors.v1.GetCapabilitiesRequest: - type: object - properties: - connectionId: - type: string - title: connection_id - minLength: 1 - title: GetCapabilitiesRequest - additionalProperties: false - connectors.v1.GetCapabilitiesResponse: - type: object - properties: - capabilities: - type: array - items: - type: string - title: capabilities - title: GetCapabilitiesResponse - additionalProperties: false - connectors.v1.GetConnectionRequest: - type: object - properties: - id: - type: string - title: id - minLength: 1 - title: GetConnectionRequest - additionalProperties: false - connectors.v1.GetConnectionResponse: - type: object - properties: - connection: - title: connection - $ref: '#/components/schemas/connectors.v1.Connection' - title: GetConnectionResponse - additionalProperties: false - connectors.v1.GetCustomConnectorRequest: - type: object - properties: - id: - type: string - title: id - minLength: 1 - title: GetCustomConnectorRequest - additionalProperties: false - connectors.v1.GetCustomConnectorResponse: - type: object - properties: - connector: - title: connector - $ref: '#/components/schemas/connectors.v1.CustomConnector' - title: GetCustomConnectorResponse - additionalProperties: false - connectors.v1.GetDegradedReadPolicyRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - organizationId: - type: string - title: organization_id - minLength: 1 - title: GetDegradedReadPolicyRequest - additionalProperties: false - connectors.v1.GetDegradedReadPolicyResponse: - type: object - properties: - policy: - title: policy - $ref: '#/components/schemas/connectors.v1.DegradedReadPolicy' - title: GetDegradedReadPolicyResponse - additionalProperties: false - connectors.v1.GetHealthRequest: - type: object - properties: - connectionId: - type: string - title: connection_id - minLength: 1 - title: GetHealthRequest - additionalProperties: false - connectors.v1.GetHealthResponse: - type: object - properties: - health: - title: health - $ref: '#/components/schemas/connectors.v1.ConnectionHealth' - title: GetHealthResponse - additionalProperties: false - connectors.v1.GetStreamStateRequest: - type: object - properties: - connectionId: - type: string - title: connection_id - streamId: - type: string - title: stream_id - title: GetStreamStateRequest - additionalProperties: false - connectors.v1.GetStreamStateResponse: - type: object - properties: - stream: - title: stream - $ref: '#/components/schemas/connectors.v1.ConnectionStream' - partitions: - type: array - items: - $ref: '#/components/schemas/connectors.v1.SyncPartitionState' - title: partitions - deadLetterCount: - type: - - integer - - string - title: dead_letter_count - format: int64 - title: GetStreamStateResponse - additionalProperties: false - connectors.v1.InitiateMcpOAuthFlowRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - serverId: - type: string - title: server_id - minLength: 1 - profileId: - type: string - title: profile_id - minLength: 1 - profileName: - type: string - title: profile_name - minLength: 1 - subjectKind: - type: string - title: subject_kind - minLength: 1 - description: |- - principal or organization; this is a profile binding, never inferred from - a Connector Connection's created_by field. - subjectId: - type: string - title: subject_id - minLength: 1 - resourceUrl: - type: string - title: resource_url - format: uri-ref - scopes: - type: array - items: - type: string - title: scopes - redirectUri: - type: string - title: redirect_uri - format: uri - clientId: - type: string - title: client_id - description: |- - Admin-supplied public client configuration. client_secret_ref is an - opaque broker reference and is never a secret value. - clientSecretRef: - type: string - title: client_secret_ref - idempotencyKey: - type: string - title: idempotency_key - profileGeneration: - exclusiveMinimum: 0 - type: - - integer - - string - title: profile_generation - format: int64 - description: |- - Immutable Console profile generation bound to the callback. A callback - from an older reauthorization can never complete a newer generation. - title: InitiateMcpOAuthFlowRequest - additionalProperties: false - connectors.v1.InitiateMcpOAuthFlowResponse: - type: object - properties: - authorizeUrl: - type: string - title: authorize_url - state: - type: string - title: state - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - resourceMetadataUrl: - type: string - title: resource_metadata_url - authorizationServer: - type: string - title: authorization_server - scopes: - type: array - items: - type: string - title: scopes - clientId: - type: string - title: client_id - title: InitiateMcpOAuthFlowResponse - additionalProperties: false - connectors.v1.InitiateOAuthFlowRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - organizationId: - type: string - title: organization_id - minLength: 1 - providerId: - type: string - title: provider_id - minLength: 1 - scopes: - type: array - items: - type: string - title: scopes - description: |- - Optional explicit scopes. When empty the provider catalog default scopes - are used. - redirectUri: - type: string - title: redirect_uri - minLength: 1 - description: |- - Absolute URL the provider should redirect back to with the auth code. - The UI passes its own /integrations/{provider}/oauth-callback URL here. - githubExistingAccount: - type: string - title: github_existing_account - description: |- - Optional GitHub organization or username with this App already installed. - Selects user OAuth instead of new installation; never grants tenant access. - actorMode: - title: actor_mode - description: |- - Selects the provider identity represented by the resulting token. The - app actor is currently supported only by Linear agent installations. - $ref: '#/components/schemas/connectors.v1.OAuthActorMode' - actorLinkConnectionId: - type: string - title: actor_link_connection_id - description: |- - Existing connection whose provider actor should be privately linked to - the authenticated Deixic principal. This runs user OAuth only, verifies - the provider subject, and never replaces the connection's credentials. - title: InitiateOAuthFlowRequest - additionalProperties: false - connectors.v1.InitiateOAuthFlowResponse: - type: object - properties: - authorizeUrl: - type: string - title: authorize_url - description: Fully-formed URL the UI launches in the OAuth popup. - state: - type: string - title: state - description: |- - Opaque server-issued state token. The UI passes this back unchanged on - CompleteOAuthFlow so the server can replay-check the exchange. - expiresAt: - title: expires_at - description: Time at which the state token becomes invalid. - $ref: '#/components/schemas/google.protobuf.Timestamp' - githubInstallationId: - type: - - integer - - string - title: github_installation_id - format: int64 - description: |- - Untrusted coordinate for existing-installation OAuth. Completion rechecks - the authenticated provider user's ownership before registering a connection. - title: InitiateOAuthFlowResponse - additionalProperties: false - connectors.v1.ListConnectionStreamsRequest: - type: object - properties: - connectionId: - type: string - title: connection_id - title: ListConnectionStreamsRequest - additionalProperties: false - connectors.v1.ListConnectionStreamsResponse: - type: object - properties: - streams: - type: array - items: - $ref: '#/components/schemas/connectors.v1.ConnectionStream' - title: streams - title: ListConnectionStreamsResponse - additionalProperties: false - connectors.v1.ListConnectionsRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - limit: - type: integer - title: limit - maximum: 200 - format: int32 - offset: - type: integer - title: offset - format: int32 - organizationId: - type: string - title: organization_id - minLength: 1 - providerId: - type: string - title: provider_id - authType: - title: auth_type - $ref: '#/components/schemas/connectors.v1.AuthType' - capability: - type: string - title: capability - healthStatus: - title: health_status - $ref: '#/components/schemas/connectors.v1.HealthStatus' - credentialState: - title: credential_state - $ref: '#/components/schemas/connectors.v1.CredentialState' - title: ListConnectionsRequest - additionalProperties: false - connectors.v1.ListConnectionsResponse: - type: object - properties: - connections: - type: array - items: - $ref: '#/components/schemas/connectors.v1.Connection' - title: connections - total: - type: integer - title: total - format: int32 - title: ListConnectionsResponse - additionalProperties: false - connectors.v1.ListCustomConnectorsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - title: ListCustomConnectorsRequest - additionalProperties: false - connectors.v1.ListCustomConnectorsResponse: - type: object - properties: - connectors: - type: array - items: - $ref: '#/components/schemas/connectors.v1.CustomConnector' - title: connectors - title: ListCustomConnectorsResponse - additionalProperties: false - connectors.v1.ListProviderPreviewsRequest: - type: object - properties: - query: - type: string - title: query - limit: - type: integer - title: limit - maximum: 200 - format: int32 - offset: - type: integer - title: offset - format: int32 - title: ListProviderPreviewsRequest - additionalProperties: false - connectors.v1.ListProviderPreviewsResponse: - type: object - properties: - previews: - type: array - items: - $ref: '#/components/schemas/connectors.v1.ConnectorProviderPreview' - title: previews - total: - type: integer - title: total - format: int32 - catalogVersion: - type: string - title: catalog_version - visibilitySnapshot: - type: string - title: visibility_snapshot - title: ListProviderPreviewsResponse - additionalProperties: false - connectors.v1.ListProvidersRequest: - type: object - properties: - query: - type: string - title: query - authType: - title: auth_type - $ref: '#/components/schemas/connectors.v1.AuthType' - limit: - type: integer - title: limit - maximum: 200 - format: int32 - offset: - type: integer - title: offset - format: int32 - title: ListProvidersRequest - additionalProperties: false - connectors.v1.ListProvidersResponse: - type: object - properties: - providers: - type: array - items: - $ref: '#/components/schemas/connectors.v1.ConnectorProvider' - title: providers - total: - type: integer - title: total - format: int32 - catalogVersion: - type: string - title: catalog_version - visibilitySnapshot: - type: string - title: visibility_snapshot - description: |- - Changes whenever qualification visibility changes inside one catalog - revision. Clients compare this across pages and preview/ready reads and - restart the read when it differs. - title: ListProvidersResponse - additionalProperties: false - connectors.v1.ListSyncSchedulesRequest: - type: object - properties: - connectionId: - type: string - title: connection_id - title: ListSyncSchedulesRequest - additionalProperties: false - connectors.v1.ListSyncSchedulesResponse: - type: object - properties: - schedules: - type: array - items: - $ref: '#/components/schemas/connectors.v1.SyncSchedule' - title: schedules - title: ListSyncSchedulesResponse - additionalProperties: false - connectors.v1.ListUpcomingCallsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - limit: - type: integer - title: limit - maximum: 100 - format: int32 - title: ListUpcomingCallsRequest - additionalProperties: false - description: |- - ListUpcomingCallsRequest intentionally has no connection identifier. The - Connector owner resolves every eligible calendar connection from the - authenticated tenant scope. - connectors.v1.ListUpcomingCallsResponse: - type: object - properties: - calls: - type: array - items: - $ref: '#/components/schemas/connectors.v1.UpcomingCall' - title: calls - sourceState: - title: source_state - $ref: '#/components/schemas/connectors.v1.UpcomingCallSourceState' - title: ListUpcomingCallsResponse - additionalProperties: false - connectors.v1.OAuthProviderTenant: - type: object - properties: - tenantId: - type: string - title: tenant_id - tenantName: - type: string - title: tenant_name - tenantType: - type: string - title: tenant_type - title: OAuthProviderTenant - additionalProperties: false - connectors.v1.PreviewCustomConnectorRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - name: - type: string - title: name - minLength: 1 - description: - type: string - title: description - sourceType: - type: string - title: source_type - minLength: 1 - document: - type: string - title: document - sourceUri: - type: string - title: source_uri - approvedDestinationOrigins: - type: array - items: - type: string - title: approved_destination_origins - actions: - type: array - items: - $ref: '#/components/schemas/connectors.v1.CustomConnectorActionMetadata' - title: actions - descriptionsReviewed: - type: boolean - title: descriptions_reviewed - expectedSpecSha256: - type: string - title: expected_spec_sha256 - pattern: ^(|[0-9a-f]{64})$ - description: |- - expected_spec_sha256 binds a create request to the exact remote bytes - returned by preview. It is optional for preview and inline definitions, - and required by the Connectors owner when create fetches source_uri. - title: PreviewCustomConnectorRequest - additionalProperties: false - description: |+ - document or source_uri is required: - ``` - size(this.document) > 0 || size(this.source_uri) > 0 - ``` - - connectors.v1.PreviewCustomConnectorResponse: - type: object - properties: - connector: - title: connector - $ref: '#/components/schemas/connectors.v1.CustomConnector' - diagnostics: - type: array - items: - type: string - title: diagnostics - title: PreviewCustomConnectorResponse - additionalProperties: false - connectors.v1.ProviderInstallation: - type: object - properties: - connectionId: - type: string - title: connection_id - minLength: 1 - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - providerId: - type: string - title: provider_id - minLength: 1 - appId: - type: string - title: app_id - minLength: 1 - providerWorkspaceId: - type: string - title: provider_workspace_id - minLength: 1 - providerEnterpriseId: - type: string - title: provider_enterprise_id - providerBotUserId: - type: string - title: provider_bot_user_id - installState: - title: install_state - $ref: '#/components/schemas/connectors.v1.ProviderInstallationState' - healthStatus: - title: health_status - $ref: '#/components/schemas/connectors.v1.HealthStatus' - grantedScopes: - type: array - items: - type: string - title: granted_scopes - installedAt: - title: installed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - revokedAt: - title: revoked_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: ProviderInstallation - additionalProperties: false - description: |- - ProviderInstallation is a credential-free projection of provider-issued - installation identity and its owning Platform tenant. - connectors.v1.ProviderResourceEnvelope: - type: object - properties: - schemaVersion: - type: string - title: schema_version - stableResourceId: - type: string - title: stable_resource_id - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - providerId: - type: string - title: provider_id - connectionId: - type: string - title: connection_id - sourceFamilyId: - type: string - title: source_family_id - originatingPrincipalId: - type: string - title: originating_principal_id - resourceKind: - type: string - title: resource_kind - parentResourceId: - type: string - title: parent_resource_id - visibilityClass: - title: visibility_class - $ref: '#/components/schemas/connectors.v1.ProviderResourceVisibilityClass' - visibilityPrincipalIds: - type: array - items: - type: string - title: visibility_principal_ids - visibilityMembershipRef: - type: string - title: visibility_membership_ref - contentTrust: - title: content_trust - $ref: '#/components/schemas/connectors.v1.ProviderContentTrust' - payloadSha256: - type: string - title: payload_sha256 - providerRevision: - type: string - title: provider_revision - lifecycleState: - title: lifecycle_state - $ref: '#/components/schemas/connectors.v1.ProviderResourceLifecycleState' - lifecycleGeneration: - type: - - integer - - string - title: lifecycle_generation - format: int64 - purgeCorrelationId: - type: string - title: purge_correlation_id - title: ProviderResourceEnvelope - additionalProperties: false - connectors.v1.RefreshConnectionRequest: - type: object - properties: - id: - type: string - title: id - minLength: 1 - title: RefreshConnectionRequest - additionalProperties: false - connectors.v1.RefreshConnectionResponse: - type: object - properties: - connection: - title: connection - $ref: '#/components/schemas/connectors.v1.Connection' - title: RefreshConnectionResponse - additionalProperties: false - connectors.v1.RegisterConnectionRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - providerId: - type: string - title: provider_id - minLength: 1 - displayName: - type: string - title: display_name - authType: - title: auth_type - $ref: '#/components/schemas/connectors.v1.AuthType' - scopes: - type: array - items: - type: string - title: scopes - credentials: - type: object - title: credentials - additionalProperties: - type: string - title: value - organizationId: - type: string - title: organization_id - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - connectionId: - type: string - title: connection_id - description: |- - Optional client-generated final id used to bind managed credentials - before registration. The connector generates an id when omitted. - title: RegisterConnectionRequest - additionalProperties: false - connectors.v1.RegisterConnectionRequest.CredentialsEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: CredentialsEntry - additionalProperties: false - connectors.v1.RegisterConnectionResponse: - type: object - properties: - connection: - title: connection - $ref: '#/components/schemas/connectors.v1.Connection' - title: RegisterConnectionResponse - additionalProperties: false - connectors.v1.ResetStreamStateRequest: - type: object - properties: - connectionId: - type: string - title: connection_id - streamId: - type: string - title: stream_id - cursorValue: - type: string - title: cursor_value - nullable: true - idempotencyKey: - type: string - title: idempotency_key - title: ResetStreamStateRequest - additionalProperties: false - connectors.v1.ResetStreamStateResponse: - type: object - properties: - cursor: - title: cursor - $ref: '#/components/schemas/connectors.v1.StreamCursorState' - title: ResetStreamStateResponse - additionalProperties: false - connectors.v1.ResolveProviderInstallationRequest: - type: object - properties: - providerId: - type: string - title: provider_id - minLength: 1 - appId: - type: string - title: app_id - minLength: 1 - providerWorkspaceId: - type: string - title: provider_workspace_id - minLength: 1 - providerEnterpriseId: - type: string - title: provider_enterprise_id - title: ResolveProviderInstallationRequest - additionalProperties: false - connectors.v1.ResolveProviderInstallationResponse: - type: object - properties: - connection: - title: connection - $ref: '#/components/schemas/connectors.v1.Connection' - installation: - title: installation - $ref: '#/components/schemas/connectors.v1.ProviderInstallation' - title: ResolveProviderInstallationResponse - additionalProperties: false - connectors.v1.ResolveSourceOfTruthRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - area: - title: area - $ref: '#/components/schemas/connectors.v1.SourceOfTruthArea' - organizationId: - type: string - title: organization_id - minLength: 1 - title: ResolveSourceOfTruthRequest - additionalProperties: false - connectors.v1.ResolveSourceOfTruthResponse: - type: object - properties: - policy: - title: policy - $ref: '#/components/schemas/connectors.v1.SourceOfTruthPolicy' - primaryConnection: - title: primary_connection - $ref: '#/components/schemas/connectors.v1.Connection' - title: ResolveSourceOfTruthResponse - additionalProperties: false - connectors.v1.RevokeConnectionRequest: - type: object - properties: - id: - type: string - title: id - minLength: 1 - reason: - type: string - title: reason - maxLength: 512 - description: |- - reason is an optional audit-trail string the caller supplies (e.g. - "rotating credentials", "decommissioning workspace"). The - connectors service writes it onto the disconnected event so the - audit feed has actionable context instead of "Connection - disconnected." Free-form, bounded to keep the event payload sane. - title: RevokeConnectionRequest - additionalProperties: false - connectors.v1.RevokeConnectionResponse: - type: object - title: RevokeConnectionResponse - additionalProperties: false - connectors.v1.RevokeMcpOAuthGrantRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - grantId: - type: string - title: grant_id - minLength: 1 - connectionRef: - type: string - title: connection_ref - minLength: 1 - reasonCode: - type: string - title: reason_code - minLength: 1 - profileId: - type: string - title: profile_id - profileGeneration: - exclusiveMinimum: 0 - type: - - integer - - string - title: profile_generation - format: int64 - title: RevokeMcpOAuthGrantRequest - additionalProperties: false - connectors.v1.RevokeMcpOAuthGrantResponse: - type: object - properties: - revoked: - type: boolean - title: revoked - grantId: - type: string - title: grant_id - title: RevokeMcpOAuthGrantResponse - additionalProperties: false - connectors.v1.SetSourceOfTruthPolicyRequest: - type: object - properties: - policy: - title: policy - $ref: '#/components/schemas/connectors.v1.SourceOfTruthPolicy' - title: SetSourceOfTruthPolicyRequest - required: - - policy - additionalProperties: false - connectors.v1.SetSourceOfTruthPolicyResponse: - type: object - properties: - policy: - title: policy - $ref: '#/components/schemas/connectors.v1.SourceOfTruthPolicy' - title: SetSourceOfTruthPolicyResponse - additionalProperties: false - connectors.v1.SourceAuthorityObservation: - type: object - properties: - state: - title: state - $ref: '#/components/schemas/connectors.v1.SourceAuthorityState' - reason: - type: string - title: reason - maxLength: 256 - minLength: 1 - freshnessMethod: - title: freshness_method - $ref: '#/components/schemas/connectors.v1.SourceAuthorityFreshnessMethod' - observedAt: - title: observed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - lastConfirmedAt: - title: last_confirmed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - ownerSnapshotReference: - type: string - title: owner_snapshot_reference - maxLength: 256 - description: |- - Opaque owner reference only; never a token, secret, private key, or raw - provider response body. - title: SourceAuthorityObservation - additionalProperties: false - description: |- - SourceAuthorityObservation is credential-free evidence from the external - source owner. Empty optional timestamps/reference fields mean that the - owner has not supplied that evidence; they must not be inferred locally. - connectors.v1.SourceOfTruthPolicy: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - area: - title: area - $ref: '#/components/schemas/connectors.v1.SourceOfTruthArea' - primaryConnectionId: - type: string - title: primary_connection_id - minLength: 1 - fallbackConnectionId: - type: string - title: fallback_connection_id - organizationId: - type: string - title: organization_id - minLength: 1 - title: SourceOfTruthPolicy - additionalProperties: false - description: SourceOfTruthPolicy defines which connection is authoritative for a domain. - connectors.v1.StreamCursorState: - type: object - properties: - streamId: - type: string - title: stream_id - stableId: - type: string - title: stable_id - hasCursor: - type: boolean - title: has_cursor - cursorValue: - type: string - title: cursor_value - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: StreamCursorState - additionalProperties: false - connectors.v1.StreamRunSummary: - type: object - properties: - connectorRunId: - type: string - title: connector_run_id - status: - type: string - title: status - outcome: - type: string - title: outcome - startedAt: - title: started_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - finishedAt: - title: finished_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - errorDetail: - type: string - title: error_detail - title: StreamRunSummary - additionalProperties: false - connectors.v1.SyncPartitionState: - type: object - properties: - partitionKey: - type: string - title: partition_key - cursorValueJson: - type: string - title: cursor_value_json - highWatermarkJson: - type: string - title: high_watermark_json - signpostValueJson: - type: string - title: signpost_value_json - stateStatus: - type: string - title: state_status - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: SyncPartitionState - additionalProperties: false - connectors.v1.SyncSchedule: - type: object - properties: - connectionId: - type: string - title: connection_id - streamId: - type: string - title: stream_id - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - runType: - type: string - title: run_type - intervalSeconds: - type: integer - title: interval_seconds - format: int32 - enabled: - type: boolean - title: enabled - lastScheduledAt: - title: last_scheduled_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - lastCompletedAt: - title: last_completed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: SyncSchedule - additionalProperties: false - connectors.v1.TriggerSyncRequest: - type: object - properties: - connectionId: - type: string - title: connection_id - minLength: 1 - runType: - type: string - title: run_type - description: |- - Free-text run classification (for example "manual", "scheduled", - "initial"). The connectors service defaults to "manual" when empty. - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - streamId: - type: string - title: stream_id - minLength: 1 - description: Stable resource stream to execute. Required. - title: TriggerSyncRequest - additionalProperties: false - description: |- - TriggerSyncRequest enqueues one sync run. Field numbers mirror the - connectors-rs owner proto exactly; the connectors service is the - authoritative owner of this contract. - connectors.v1.TriggerSyncResponse: - type: object - properties: - queueId: - type: string - title: queue_id - connectionId: - type: string - title: connection_id - runType: - type: string - title: run_type - status: - type: string - title: status - description: |- - The queue row's actual status after the call: "queued" for a new or - revived row, or the in-flight/terminal status ("leased", "completed", - "failed", "cancelled") of an existing row the call did not disturb. - streamId: - type: string - title: stream_id - description: Durable stream identity stored on the queue row. - title: TriggerSyncResponse - additionalProperties: false - connectors.v1.UpcomingCall: - type: object - properties: - id: - type: string - title: id - minLength: 1 - title: - type: string - title: title - maxLength: 512 - joinUrl: - type: string - title: join_url - format: uri - startsAt: - title: starts_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - endsAt: - title: ends_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: UpcomingCall - additionalProperties: false - description: |- - UpcomingCall is a safe typed projection of one connected provider event. - Provider payloads and source connection IDs are deliberately omitted. - connectors.v1.UpdateCustomConnectorRequest: - type: object - properties: - id: - type: string - title: id - minLength: 1 - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - name: - type: string - title: name - description: - type: string - title: description - actions: - type: array - items: - $ref: '#/components/schemas/connectors.v1.CustomConnectorActionMetadata' - title: actions - descriptionsReviewed: - type: boolean - title: descriptions_reviewed - title: UpdateCustomConnectorRequest - additionalProperties: false - connectors.v1.UpdateCustomConnectorResponse: - type: object - properties: - connector: - title: connector - $ref: '#/components/schemas/connectors.v1.CustomConnector' - title: UpdateCustomConnectorResponse - additionalProperties: false - connectors.v1.VerifyConnectionActiveRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - connectionId: - type: string - title: connection_id - minLength: 1 - title: VerifyConnectionActiveRequest - additionalProperties: false - connectors.v1.VerifyConnectionActiveResponse: - type: object - properties: - connectionId: - type: string - title: connection_id - minLength: 1 - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - stateUpdatedAt: - title: state_updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - verifiedAt: - title: verified_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - sourceAuthority: - title: source_authority - description: |- - Completed source-owner verification supplies this observation. A local - active row alone remains UNKNOWN/NOT_OBSERVED. - $ref: '#/components/schemas/connectors.v1.SourceAuthorityObservation' - connectionRevision: - type: - - integer - - string - title: connection_revision - format: int64 - description: |- - Monotonic Connection-owner revision, including credential-reference and - OAuth installation mutations. Zero means no revision evidence was supplied. - title: VerifyConnectionActiveResponse - additionalProperties: false - google.protobuf.Timestamp: - type: string - examples: - - 1s - - 1.000340012s - format: date-time - description: |- - A Timestamp represents a point in time independent of any time zone or local - calendar, encoded as a count of seconds and fractions of seconds at - nanosecond resolution. The count is relative to an epoch at UTC midnight on - January 1, 1970, in the proleptic Gregorian calendar which extends the - Gregorian calendar backwards to year one. - - All minutes are 60 seconds long. Leap seconds are "smeared" so that no leap - second table is needed for interpretation, using a [24-hour linear - smear](https://developers.google.com/time/smear). - - The range is from 0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z. By - restricting to that range, we ensure that we can convert to and from [RFC - 3339](https://www.ietf.org/rfc/rfc3339.txt) date strings. - - # Examples - - Example 1: Compute Timestamp from POSIX `time()`. - - Timestamp timestamp; - timestamp.set_seconds(time(NULL)); - timestamp.set_nanos(0); - - Example 2: Compute Timestamp from POSIX `gettimeofday()`. - - struct timeval tv; - gettimeofday(&tv, NULL); - - Timestamp timestamp; - timestamp.set_seconds(tv.tv_sec); - timestamp.set_nanos(tv.tv_usec * 1000); - - Example 3: Compute Timestamp from Win32 `GetSystemTimeAsFileTime()`. - - FILETIME ft; - GetSystemTimeAsFileTime(&ft); - UINT64 ticks = (((UINT64)ft.dwHighDateTime) << 32) | ft.dwLowDateTime; - - // A Windows tick is 100 nanoseconds. Windows epoch 1601-01-01T00:00:00Z - // is 11644473600 seconds before Unix epoch 1970-01-01T00:00:00Z. - Timestamp timestamp; - timestamp.set_seconds((INT64) ((ticks / 10000000) - 11644473600LL)); - timestamp.set_nanos((INT32) ((ticks % 10000000) * 100)); - - Example 4: Compute Timestamp from Java `System.currentTimeMillis()`. - - long millis = System.currentTimeMillis(); - - Timestamp timestamp = Timestamp.newBuilder().setSeconds(millis / 1000) - .setNanos((int) ((millis % 1000) * 1000000)).build(); - - Example 5: Compute Timestamp from Java `Instant.now()`. - - Instant now = Instant.now(); - - Timestamp timestamp = - Timestamp.newBuilder().setSeconds(now.getEpochSecond()) - .setNanos(now.getNano()).build(); - - Example 6: Compute Timestamp from current time in Python. - - timestamp = Timestamp() - timestamp.GetCurrentTime() - - # JSON Mapping - - In JSON format, the Timestamp type is encoded as a string in the - [RFC 3339](https://www.ietf.org/rfc/rfc3339.txt) format. That is, the - format is "{year}-{month}-{day}T{hour}:{min}:{sec}[.{frac_sec}]Z" - where {year} is always expressed using four digits while {month}, {day}, - {hour}, {min}, and {sec} are zero-padded to two digits each. The fractional - seconds, which can go up to 9 digits (i.e. up to 1 nanosecond resolution), - are optional. The "Z" suffix indicates the timezone ("UTC"); the timezone - is required. A proto3 JSON serializer should always use UTC (as indicated by - "Z") when printing the Timestamp type and a proto3 JSON parser should be - able to accept both UTC and other timezones (as indicated by an offset). - - For example, "2017-01-15T01:30:15.01Z" encodes 15.01 seconds past - 01:30 UTC on January 15, 2017. - - In JavaScript, one can convert a Date object to this format using the - standard - [toISOString()](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Date/toISOString) - method. In Python, a standard `datetime.datetime` object can be converted - to this format using - [`strftime`](https://docs.python.org/2/library/time.html#time.strftime) with - the time format spec '%Y-%m-%dT%H:%M:%S.%fZ'. Likewise, in Java, one can use - the Joda Time's [`ISODateTimeFormat.dateTime()`]( - http://joda-time.sourceforge.net/apidocs/org/joda/time/format/ISODateTimeFormat.html#dateTime() - ) to obtain a formatter capable of generating timestamps in this format. - connect-protocol-version: - type: number - title: Connect-Protocol-Version - enum: - - 1 - description: Define the version of the Connect protocol - const: 1 - connect-timeout-header: - type: number - title: Connect-Timeout-Ms - description: Define the timeout, in ms - connect.error: - type: object - properties: - code: - type: string - examples: - - not_found - enum: - - canceled - - unknown - - invalid_argument - - deadline_exceeded - - not_found - - already_exists - - permission_denied - - resource_exhausted - - failed_precondition - - aborted - - out_of_range - - unimplemented - - internal - - unavailable - - data_loss - - unauthenticated - description: The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code]. - message: - type: string - description: A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client. - detail: - $ref: '#/components/schemas/google.protobuf.Any' - title: Connect Error - additionalProperties: true - description: 'Error type returned by Connect: https://connectrpc.com/docs/go/errors/#http-representation' - google.protobuf.Any: - type: object - properties: - type: - type: string - value: - type: string - format: binary - debug: - type: object - additionalProperties: true - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. -security: [] -tags: - - name: connectors.v1.ConnectorService - description: ConnectorService manages external integration connections. diff --git a/openapi/console/v1/console.openapi.yaml b/openapi/console/v1/console.openapi.yaml deleted file mode 100644 index 2d0b789..0000000 --- a/openapi/console/v1/console.openapi.yaml +++ /dev/null @@ -1,34736 +0,0 @@ -openapi: 3.1.0 -info: - title: console.v1 -paths: - /console.v1.ConsoleService/AssessComplianceSubject: - post: - tags: - - console.v1.ConsoleService - summary: AssessComplianceSubject - description: Evaluates a versioned compliance profile against owner-fetched, tenant-scoped facts. - operationId: console.v1.ConsoleService.AssessComplianceSubject - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.AssessComplianceSubjectRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.AssessComplianceSubjectResponse' - /console.v1.ConsoleService/RecordComplianceAssessment: - post: - tags: - - console.v1.ConsoleService - summary: RecordComplianceAssessment - operationId: console.v1.ConsoleService.RecordComplianceAssessment - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RecordComplianceAssessmentRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RecordComplianceAssessmentResponse' - /console.v1.ConsoleService/GetComplianceAssessment: - post: - tags: - - console.v1.ConsoleService - summary: GetComplianceAssessment - operationId: console.v1.ConsoleService.GetComplianceAssessment - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetComplianceAssessmentRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetComplianceAssessmentResponse' - /console.v1.ConsoleService/ListBusinessBlueprints: - post: - tags: - - console.v1.ConsoleService - summary: ListBusinessBlueprints - description: Lists built-in native business blueprints available to every authorized tenant. - operationId: console.v1.ConsoleService.ListBusinessBlueprints - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListBusinessBlueprintsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListBusinessBlueprintsResponse' - /console.v1.ConsoleService/CloneBusinessBlueprint: - post: - tags: - - console.v1.ConsoleService - summary: CloneBusinessBlueprint - description: Clones a pinned built-in blueprint into editable tenant-owned definitions and a draft form. - operationId: console.v1.ConsoleService.CloneBusinessBlueprint - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CloneBusinessBlueprintRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CloneBusinessBlueprintResponse' - /console.v1.ConsoleService/GetBusinessProcessDefinition: - post: - tags: - - console.v1.ConsoleService - summary: GetBusinessProcessDefinition - description: GetBusinessProcessDefinition reads immutable process definitions within the tenant. - operationId: console.v1.ConsoleService.GetBusinessProcessDefinition - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetBusinessProcessDefinitionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetBusinessProcessDefinitionResponse' - /console.v1.ConsoleService/ListBusinessProcessDefinitions: - post: - tags: - - console.v1.ConsoleService - summary: ListBusinessProcessDefinitions - description: ListBusinessProcessDefinitions reads immutable process definitions within the tenant. - operationId: console.v1.ConsoleService.ListBusinessProcessDefinitions - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListBusinessProcessDefinitionsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListBusinessProcessDefinitionsResponse' - /console.v1.ConsoleService/DefineBusinessProcess: - post: - tags: - - console.v1.ConsoleService - summary: DefineBusinessProcess - description: DefineBusinessProcess accesses the durable object-bound process owner. - operationId: console.v1.ConsoleService.DefineBusinessProcess - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DefineBusinessProcessRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DefineBusinessProcessResponse' - /console.v1.ConsoleService/StartBusinessProcess: - post: - tags: - - console.v1.ConsoleService - summary: StartBusinessProcess - description: StartBusinessProcess accesses the durable object-bound process owner. - operationId: console.v1.ConsoleService.StartBusinessProcess - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.StartBusinessProcessRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.StartBusinessProcessResponse' - /console.v1.ConsoleService/GetBusinessProcess: - post: - tags: - - console.v1.ConsoleService - summary: GetBusinessProcess - description: GetBusinessProcess accesses the durable object-bound process owner. - operationId: console.v1.ConsoleService.GetBusinessProcess - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetBusinessProcessRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetBusinessProcessResponse' - /console.v1.ConsoleService/ListBusinessProcesses: - post: - tags: - - console.v1.ConsoleService - summary: ListBusinessProcesses - description: ListBusinessProcesses accesses the durable object-bound process owner. - operationId: console.v1.ConsoleService.ListBusinessProcesses - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListBusinessProcessesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListBusinessProcessesResponse' - /console.v1.ConsoleService/TransitionBusinessProcess: - post: - tags: - - console.v1.ConsoleService - summary: TransitionBusinessProcess - description: TransitionBusinessProcess accesses the durable object-bound process owner. - operationId: console.v1.ConsoleService.TransitionBusinessProcess - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.TransitionBusinessProcessRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.TransitionBusinessProcessResponse' - /console.v1.ConsoleService/PrepareBusinessObjectAuthorityTransfer: - post: - tags: - - console.v1.ConsoleService - summary: PrepareBusinessObjectAuthorityTransfer - description: Checks source-authority readiness without changing accepted state. - operationId: console.v1.ConsoleService.PrepareBusinessObjectAuthorityTransfer - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.PrepareBusinessObjectAuthorityTransferRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.PrepareBusinessObjectAuthorityTransferResponse' - /console.v1.ConsoleService/FinalizeBusinessObjectAuthorityTransfer: - post: - tags: - - console.v1.ConsoleService - summary: FinalizeBusinessObjectAuthorityTransfer - description: Checks source-authority readiness without changing accepted state. - operationId: console.v1.ConsoleService.FinalizeBusinessObjectAuthorityTransfer - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.FinalizeBusinessObjectAuthorityTransferRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.FinalizeBusinessObjectAuthorityTransferResponse' - /console.v1.ConsoleService/DefineBusinessObjectType: - post: - tags: - - console.v1.ConsoleService - summary: DefineBusinessObjectType - description: DefineBusinessObjectType uses tenant-scoped durable business object state. - operationId: console.v1.ConsoleService.DefineBusinessObjectType - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DefineBusinessObjectTypeRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DefineBusinessObjectTypeResponse' - /console.v1.ConsoleService/GetBusinessObjectType: - post: - tags: - - console.v1.ConsoleService - summary: GetBusinessObjectType - description: GetBusinessObjectType reads an exact immutable published schema revision. - operationId: console.v1.ConsoleService.GetBusinessObjectType - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetBusinessObjectTypeRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetBusinessObjectTypeResponse' - /console.v1.ConsoleService/ListBusinessObjectTypes: - post: - tags: - - console.v1.ConsoleService - summary: ListBusinessObjectTypes - description: ListBusinessObjectTypes uses tenant-scoped durable business object state. - operationId: console.v1.ConsoleService.ListBusinessObjectTypes - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListBusinessObjectTypesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListBusinessObjectTypesResponse' - /console.v1.ConsoleService/CreateBusinessObject: - post: - tags: - - console.v1.ConsoleService - summary: CreateBusinessObject - description: CreateBusinessObject uses tenant-scoped durable business object state. - operationId: console.v1.ConsoleService.CreateBusinessObject - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateBusinessObjectRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateBusinessObjectResponse' - /console.v1.ConsoleService/GetBusinessObject: - post: - tags: - - console.v1.ConsoleService - summary: GetBusinessObject - description: GetBusinessObject uses tenant-scoped durable business object state. - operationId: console.v1.ConsoleService.GetBusinessObject - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetBusinessObjectRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetBusinessObjectResponse' - /console.v1.ConsoleService/ListBusinessObjects: - post: - tags: - - console.v1.ConsoleService - summary: ListBusinessObjects - description: ListBusinessObjects uses tenant-scoped durable business object state. - operationId: console.v1.ConsoleService.ListBusinessObjects - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListBusinessObjectsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListBusinessObjectsResponse' - /console.v1.ConsoleService/UpdateBusinessObject: - post: - tags: - - console.v1.ConsoleService - summary: UpdateBusinessObject - description: UpdateBusinessObject uses tenant-scoped durable business object state. - operationId: console.v1.ConsoleService.UpdateBusinessObject - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateBusinessObjectRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateBusinessObjectResponse' - /console.v1.ConsoleService/DeleteBusinessObject: - post: - tags: - - console.v1.ConsoleService - summary: DeleteBusinessObject - description: DeleteBusinessObject uses tenant-scoped durable business object state. - operationId: console.v1.ConsoleService.DeleteBusinessObject - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DeleteBusinessObjectRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DeleteBusinessObjectResponse' - /console.v1.ConsoleService/ListBusinessObjectRevisions: - post: - tags: - - console.v1.ConsoleService - summary: ListBusinessObjectRevisions - description: ListBusinessObjectRevisions uses tenant-scoped durable business object state. - operationId: console.v1.ConsoleService.ListBusinessObjectRevisions - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListBusinessObjectRevisionsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListBusinessObjectRevisionsResponse' - /console.v1.ConsoleService/BindBusinessObjectSource: - post: - tags: - - console.v1.ConsoleService - summary: BindBusinessObjectSource - description: BindBusinessObjectSource uses tenant-scoped durable business object state. - operationId: console.v1.ConsoleService.BindBusinessObjectSource - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.BindBusinessObjectSourceRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.BindBusinessObjectSourceResponse' - /console.v1.ConsoleService/AdmitBusinessObjectObservation: - post: - tags: - - console.v1.ConsoleService - summary: AdmitBusinessObjectObservation - description: AdmitBusinessObjectObservation uses tenant-scoped durable business object state. - operationId: console.v1.ConsoleService.AdmitBusinessObjectObservation - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.AdmitBusinessObjectObservationRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.AdmitBusinessObjectObservationResponse' - /console.v1.ConsoleService/ListBusinessObjectRelationships: - post: - tags: - - console.v1.ConsoleService - summary: ListBusinessObjectRelationships - description: ListBusinessObjectRelationships uses tenant-scoped durable business object state. - operationId: console.v1.ConsoleService.ListBusinessObjectRelationships - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListBusinessObjectRelationshipsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListBusinessObjectRelationshipsResponse' - /console.v1.ConsoleService/CreateBusinessObjectRelationship: - post: - tags: - - console.v1.ConsoleService - summary: CreateBusinessObjectRelationship - description: CreateBusinessObjectRelationship uses tenant-scoped durable business object state. - operationId: console.v1.ConsoleService.CreateBusinessObjectRelationship - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateBusinessObjectRelationshipRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateBusinessObjectRelationshipResponse' - /console.v1.ConsoleService/DeleteBusinessObjectRelationship: - post: - tags: - - console.v1.ConsoleService - summary: DeleteBusinessObjectRelationship - description: DeleteBusinessObjectRelationship uses tenant-scoped durable business object state. - operationId: console.v1.ConsoleService.DeleteBusinessObjectRelationship - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DeleteBusinessObjectRelationshipRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DeleteBusinessObjectRelationshipResponse' - /console.v1.ConsoleService/CreateCaptureForm: - post: - tags: - - console.v1.ConsoleService - summary: CreateCaptureForm - description: |- - CreateCaptureForm creates a draft with its first immutable form version. - The version pins the target BusinessObjectType revision and all typed - controls/mappings used by later public submissions. - operationId: console.v1.ConsoleService.CreateCaptureForm - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateCaptureFormRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateCaptureFormResponse' - /console.v1.ConsoleService/ListCaptureForms: - post: - tags: - - console.v1.ConsoleService - summary: ListCaptureForms - description: |- - ListCaptureForms returns the tenant's durable form identities and current - publication pointers so an administrator can rediscover state after a - reload without relying on browser-local drafts. - operationId: console.v1.ConsoleService.ListCaptureForms - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListCaptureFormsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListCaptureFormsResponse' - /console.v1.ConsoleService/GetCaptureForm: - post: - tags: - - console.v1.ConsoleService - summary: GetCaptureForm - description: |- - GetCaptureForm reads a tenant-scoped form and, when requested, one exact - immutable version. It never silently substitutes the latest version for a - caller-provided version id. - operationId: console.v1.ConsoleService.GetCaptureForm - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetCaptureFormRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetCaptureFormResponse' - /console.v1.ConsoleService/UpdateCaptureForm: - post: - tags: - - console.v1.ConsoleService - summary: UpdateCaptureForm - description: |- - UpdateCaptureForm appends a new immutable form version. Accepted or - published versions are never edited in place. - operationId: console.v1.ConsoleService.UpdateCaptureForm - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateCaptureFormRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateCaptureFormResponse' - /console.v1.ConsoleService/PublishCaptureForm: - post: - tags: - - console.v1.ConsoleService - summary: PublishCaptureForm - description: |- - PublishCaptureForm exposes one exact immutable version through a scoped - public publication. The server derives the tenant and object target from - that publication; callers cannot choose them through public input. - operationId: console.v1.ConsoleService.PublishCaptureForm - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.PublishCaptureFormRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.PublishCaptureFormResponse' - /console.v1.ConsoleService/RevokeCaptureFormPublication: - post: - tags: - - console.v1.ConsoleService - summary: RevokeCaptureFormPublication - description: |- - RevokeCaptureFormPublication closes a public publication while retaining - its immutable form history and durable submissions. - operationId: console.v1.ConsoleService.RevokeCaptureFormPublication - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RevokeCaptureFormPublicationRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RevokeCaptureFormPublicationResponse' - /console.v1.ConsoleService/CreateCaptureFormInvitation: - post: - tags: - - console.v1.ConsoleService - summary: CreateCaptureFormInvitation - description: CreateCaptureFormInvitation uses recipient verification at the Capture Forms owner. - operationId: console.v1.ConsoleService.CreateCaptureFormInvitation - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateCaptureFormInvitationRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateCaptureFormInvitationResponse' - /console.v1.ConsoleService/RevokeCaptureFormInvitation: - post: - tags: - - console.v1.ConsoleService - summary: RevokeCaptureFormInvitation - description: RevokeCaptureFormInvitation uses recipient verification at the Capture Forms owner. - operationId: console.v1.ConsoleService.RevokeCaptureFormInvitation - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RevokeCaptureFormInvitationRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RevokeCaptureFormInvitationResponse' - /console.v1.ConsoleService/GetInvitedCaptureForm: - post: - tags: - - console.v1.ConsoleService - summary: GetInvitedCaptureForm - description: GetInvitedCaptureForm uses recipient verification at the Capture Forms owner. - operationId: console.v1.ConsoleService.GetInvitedCaptureForm - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetInvitedCaptureFormRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetInvitedCaptureFormResponse' - /console.v1.ConsoleService/SubmitInvitedCaptureForm: - post: - tags: - - console.v1.ConsoleService - summary: SubmitInvitedCaptureForm - description: SubmitInvitedCaptureForm uses recipient verification at the Capture Forms owner. - operationId: console.v1.ConsoleService.SubmitInvitedCaptureForm - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitInvitedCaptureFormRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitInvitedCaptureFormResponse' - /console.v1.ConsoleService/GetPublishedCaptureForm: - post: - tags: - - console.v1.ConsoleService - summary: GetPublishedCaptureForm - description: |- - GetPublishedCaptureForm resolves one active publication using its opaque, - server-issued publication id. The id is the reusable public capability in - the form URL; public callers provide no tenant or workspace coordinates. - operationId: console.v1.ConsoleService.GetPublishedCaptureForm - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetPublishedCaptureFormRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetPublishedCaptureFormResponse' - /console.v1.ConsoleService/GetPublishedCaptureFormBrandingAsset: - post: - tags: - - console.v1.ConsoleService - summary: GetPublishedCaptureFormBrandingAsset - description: |- - GetPublishedCaptureFormBrandingAsset serves one fixed-role asset from the - exact immutable version pinned by a live publication. The publication id - is the only capability input; callers cannot select a tenant, object, or - VFS version. - operationId: console.v1.ConsoleService.GetPublishedCaptureFormBrandingAsset - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetPublishedCaptureFormBrandingAssetRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetPublishedCaptureFormBrandingAssetResponse' - /console.v1.ConsoleService/SubmitPublishedCaptureForm: - post: - tags: - - console.v1.ConsoleService - summary: SubmitPublishedCaptureForm - description: |- - SubmitPublishedCaptureForm accepts typed answers through one active, - publication-scoped public capability. The owner resolves the tenant, - pinned version, and object target from that publication id, validates every - answer, and persists a durable submission before any object mapping. - operationId: console.v1.ConsoleService.SubmitPublishedCaptureForm - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitPublishedCaptureFormRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitPublishedCaptureFormResponse' - /console.v1.ConsoleService/BeginPublishedCaptureFormUpload: - post: - tags: - - console.v1.ConsoleService - summary: BeginPublishedCaptureFormUpload - description: |- - BeginPublishedCaptureFormUpload reserves one server-owned VFS upload - grant for a FILE input on the live publication. The publication resolves - tenant, form, version, and upload constraints; public callers cannot - choose any of those coordinates. - operationId: console.v1.ConsoleService.BeginPublishedCaptureFormUpload - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.BeginPublishedCaptureFormUploadRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.BeginPublishedCaptureFormUploadResponse' - /console.v1.ConsoleService/CompletePublishedCaptureFormUpload: - post: - tags: - - console.v1.ConsoleService - summary: CompletePublishedCaptureFormUpload - description: |- - CompletePublishedCaptureFormUpload commits the exact VFS lease reserved - for one publication/input pair. The completed object/version is the only - file asset accepted in a later typed form answer. - operationId: console.v1.ConsoleService.CompletePublishedCaptureFormUpload - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CompletePublishedCaptureFormUploadRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CompletePublishedCaptureFormUploadResponse' - /console.v1.ConsoleService/GetCaptureFormSubmission: - post: - tags: - - console.v1.ConsoleService - summary: GetCaptureFormSubmission - description: |- - GetCaptureFormSubmission reads one tenant-scoped durable submission and - its accepted BusinessObject linkage, if review has accepted it. - operationId: console.v1.ConsoleService.GetCaptureFormSubmission - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetCaptureFormSubmissionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetCaptureFormSubmissionResponse' - /console.v1.ConsoleService/ListCaptureFormSubmissions: - post: - tags: - - console.v1.ConsoleService - summary: ListCaptureFormSubmissions - description: ListCaptureFormSubmissions lists bounded durable submissions for one form. - operationId: console.v1.ConsoleService.ListCaptureFormSubmissions - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListCaptureFormSubmissionsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListCaptureFormSubmissionsResponse' - /console.v1.ConsoleService/ReviewCaptureFormSubmission: - post: - tags: - - console.v1.ConsoleService - summary: ReviewCaptureFormSubmission - description: |- - ReviewCaptureFormSubmission accepts or rejects one durable submission. - Acceptance creates exactly one mapped BusinessObject through the existing - BusinessObject owner and returns its durable identity. - operationId: console.v1.ConsoleService.ReviewCaptureFormSubmission - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReviewCaptureFormSubmissionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReviewCaptureFormSubmissionResponse' - /console.v1.ConsoleService/GetInferenceCreditAutoRefill: - post: - tags: - - console.v1.ConsoleService - summary: GetInferenceCreditAutoRefill - description: GetInferenceCreditAutoRefill uses authorized workspace billing consent. - operationId: console.v1.ConsoleService.GetInferenceCreditAutoRefill - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetInferenceCreditAutoRefillRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetInferenceCreditAutoRefillResponse' - /console.v1.ConsoleService/UpdateInferenceCreditAutoRefill: - post: - tags: - - console.v1.ConsoleService - summary: UpdateInferenceCreditAutoRefill - description: UpdateInferenceCreditAutoRefill uses authorized workspace billing consent. - operationId: console.v1.ConsoleService.UpdateInferenceCreditAutoRefill - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateInferenceCreditAutoRefillRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateInferenceCreditAutoRefillResponse' - /console.v1.ConsoleService/CompleteInferenceCreditAutoRefill: - post: - tags: - - console.v1.ConsoleService - summary: CompleteInferenceCreditAutoRefill - description: CompleteInferenceCreditAutoRefill uses authorized workspace billing consent. - operationId: console.v1.ConsoleService.CompleteInferenceCreditAutoRefill - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CompleteInferenceCreditAutoRefillRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CompleteInferenceCreditAutoRefillResponse' - /console.v1.ConsoleService/ListInferenceCreditReceipts: - post: - tags: - - console.v1.ConsoleService - summary: ListInferenceCreditReceipts - description: ListInferenceCreditReceipts returns verified payments for the authorized workspace. - operationId: console.v1.ConsoleService.ListInferenceCreditReceipts - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListInferenceCreditReceiptsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListInferenceCreditReceiptsResponse' - /console.v1.ConsoleService/GetOverview: - post: - tags: - - console.v1.ConsoleService - summary: GetOverview - description: GetOverview returns the first-screen AI operations summary. - operationId: console.v1.ConsoleService.GetOverview - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOverviewRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOverviewResponse' - /console.v1.ConsoleService/GetConsoleBootSnapshot: - post: - tags: - - console.v1.ConsoleService - summary: GetConsoleBootSnapshot - description: GetConsoleBootSnapshot returns the projected first-paint console state. - operationId: console.v1.ConsoleService.GetConsoleBootSnapshot - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetConsoleBootSnapshotRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetConsoleBootSnapshotResponse' - /console.v1.ConsoleService/ListAssets: - post: - tags: - - console.v1.ConsoleService - summary: ListAssets - description: |- - ListAssets returns AI agents, provider keys, model surfaces, and - integrations visible to the current workspace. - operationId: console.v1.ConsoleService.ListAssets - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListAssetsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListAssetsResponse' - /console.v1.ConsoleService/GetAsset: - post: - tags: - - console.v1.ConsoleService - summary: GetAsset - description: GetAsset returns a single AI estate asset and related resources. - operationId: console.v1.ConsoleService.GetAsset - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetAssetRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetAssetResponse' - /console.v1.ConsoleService/ListActivity: - post: - tags: - - console.v1.ConsoleService - summary: ListActivity - description: |- - ListActivity returns normalized run, trace, approval, eval, risk, and cost - events for the console timeline. - operationId: console.v1.ConsoleService.ListActivity - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListActivityRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListActivityResponse' - /console.v1.ConsoleService/SearchStaffWorkspaceDirectory: - post: - tags: - - console.v1.ConsoleService - summary: SearchStaffWorkspaceDirectory - description: SearchStaffWorkspaceDirectory returns a bounded, metadata-only workspace directory for staff. - operationId: console.v1.ConsoleService.SearchStaffWorkspaceDirectory - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SearchStaffWorkspaceDirectoryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SearchStaffWorkspaceDirectoryResponse' - /console.v1.ConsoleService/GetStaffWorkspaceContext: - post: - tags: - - console.v1.ConsoleService - summary: GetStaffWorkspaceContext - description: GetStaffWorkspaceContext returns redacted operational summaries under an exact active grant. - operationId: console.v1.ConsoleService.GetStaffWorkspaceContext - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetStaffWorkspaceContextRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetStaffWorkspaceContextResponse' - /console.v1.ConsoleService/GetStaffManagedInferenceFunding: - post: - tags: - - console.v1.ConsoleService - summary: GetStaffManagedInferenceFunding - description: Administrative composition over the existing Meter GetPrepaidCreditBalance owner. - operationId: console.v1.ConsoleService.GetStaffManagedInferenceFunding - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetStaffManagedInferenceFundingRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.GetPrepaidCreditBalanceResponse' - /console.v1.ConsoleService/GrantStaffManagedInferenceCredits: - post: - tags: - - console.v1.ConsoleService - summary: GrantStaffManagedInferenceCredits - description: Administrative composition over the existing Meter GrantDevelopmentCredits owner. - operationId: console.v1.ConsoleService.GrantStaffManagedInferenceCredits - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GrantStaffManagedInferenceCreditsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.GrantDevelopmentCreditsResponse' - /console.v1.ConsoleService/GetStaffManagedInferenceUsage: - post: - tags: - - console.v1.ConsoleService - summary: GetStaffManagedInferenceUsage - description: Administrative composition over the existing Meter QueryUsage owner. - operationId: console.v1.ConsoleService.GetStaffManagedInferenceUsage - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetStaffManagedInferenceUsageRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.QueryUsageResponse' - /console.v1.ConsoleService/GetStaffManagedInferenceBudget: - post: - tags: - - console.v1.ConsoleService - summary: GetStaffManagedInferenceBudget - description: Administrative composition over the existing Meter GetBudgetDashboard owner. - operationId: console.v1.ConsoleService.GetStaffManagedInferenceBudget - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetStaffManagedInferenceBudgetRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.GetBudgetDashboardResponse' - /console.v1.ConsoleService/SetStaffManagedInferenceBudget: - post: - tags: - - console.v1.ConsoleService - summary: SetStaffManagedInferenceBudget - description: Administrative composition over the existing Meter SetBudget owner. - operationId: console.v1.ConsoleService.SetStaffManagedInferenceBudget - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SetStaffManagedInferenceBudgetRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.SetBudgetResponse' - /console.v1.ConsoleService/GetStaffManagedInferenceReadiness: - post: - tags: - - console.v1.ConsoleService - summary: GetStaffManagedInferenceReadiness - description: |- - Read shared managed-inference readiness across tenants for an authorized administrator. - Staff and customer readiness use the same route and tenant request contract. - buf:lint:ignore RPC_REQUEST_STANDARD_NAME - operationId: console.v1.ConsoleService.GetStaffManagedInferenceReadiness - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetStaffManagedInferenceReadinessRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetManagedInferenceReadinessResponse' - /console.v1.ConsoleService/GetManagedInferenceReadiness: - post: - tags: - - console.v1.ConsoleService - summary: GetManagedInferenceReadiness - description: |- - Reports current managed-inference prerequisites for the exact authorized tenant. - Informational only: execution issuance and admission recheck current authority. - operationId: console.v1.ConsoleService.GetManagedInferenceReadiness - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetManagedInferenceReadinessRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetManagedInferenceReadinessResponse' - /console.v1.ConsoleService/ListManagedProviderAccessGrants: - post: - tags: - - console.v1.ConsoleService - summary: ListManagedProviderAccessGrants - description: |- - ListManagedProviderAccessGrants returns the durable managed provider-access - posture for the staff control plane. Default-deny: absent or disabled rows - mean no managed access. - operationId: console.v1.ConsoleService.ListManagedProviderAccessGrants - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListManagedProviderAccessGrantsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListManagedProviderAccessGrantsResponse' - /console.v1.ConsoleService/ListManagedProviderAccessEvents: - post: - tags: - - console.v1.ConsoleService - summary: ListManagedProviderAccessEvents - description: ListManagedProviderAccessEvents reads immutable enrollment acceptance and delivery events. - operationId: console.v1.ConsoleService.ListManagedProviderAccessEvents - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListManagedProviderAccessEventsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListManagedProviderAccessEventsResponse' - /console.v1.ConsoleService/ListStaffManagedInferenceAdminEvents: - post: - tags: - - console.v1.ConsoleService - summary: ListStaffManagedInferenceAdminEvents - description: |- - ListStaffManagedInferenceAdminEvents reads Meter-owned credit and budget audit receipts. - (-- api-linter: core::0132::response-message-name=disabled - aip.dev/not-precedent: This staff facade returns the canonical Meter audit - response unchanged, preserving the published cross-service contract. --) - operationId: console.v1.ConsoleService.ListStaffManagedInferenceAdminEvents - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListStaffManagedInferenceAdminEventsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.ListManagedInferenceAdminEventsResponse' - /console.v1.ConsoleService/ListStaffManagedExecutionGrantEvents: - post: - tags: - - console.v1.ConsoleService - summary: ListStaffManagedExecutionGrantEvents - description: ListStaffManagedExecutionGrantEvents reads recorded issuer events for an exact tenant session. - operationId: console.v1.ConsoleService.ListStaffManagedExecutionGrantEvents - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListStaffManagedExecutionGrantEventsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListStaffManagedExecutionGrantEventsResponse' - /console.v1.ConsoleService/ListStaffManagedExecutionOutcomes: - post: - tags: - - console.v1.ConsoleService - summary: ListStaffManagedExecutionOutcomes - description: ListStaffManagedExecutionOutcomes reads recorded gateway decisions for an exact tenant lineage. - operationId: console.v1.ConsoleService.ListStaffManagedExecutionOutcomes - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListStaffManagedExecutionOutcomesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListStaffManagedExecutionOutcomesResponse' - /console.v1.ConsoleService/UpsertManagedProviderAccessGrant: - post: - tags: - - console.v1.ConsoleService - summary: UpsertManagedProviderAccessGrant - description: |- - UpsertManagedProviderAccessGrant enables or disables managed provider access - for one (organization, provider, environment) tuple. It persists a durable, - audited grant attributed to the acting staff principal and synchronizes the - gateway enforcement row. A note is required for every mutation. - operationId: console.v1.ConsoleService.UpsertManagedProviderAccessGrant - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpsertManagedProviderAccessGrantRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpsertManagedProviderAccessGrantResponse' - /console.v1.ConsoleService/RevokeManagedProviderAccessGrant: - post: - tags: - - console.v1.ConsoleService - summary: RevokeManagedProviderAccessGrant - description: |- - RevokeManagedProviderAccessGrant disables an existing grant without deleting - its audit history and synchronizes the gateway. A note is required. - operationId: console.v1.ConsoleService.RevokeManagedProviderAccessGrant - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RevokeManagedProviderAccessGrantRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RevokeManagedProviderAccessGrantResponse' - /console.v1.ConsoleService/GetStaffInferenceRoutingProfile: - post: - tags: - - console.v1.ConsoleService - summary: GetStaffInferenceRoutingProfile - description: |- - GetStaffInferenceRoutingProfile returns the deployment-allowlisted Dex - inference targets and the durable override for the server-configured STAFF - organization. The request intentionally carries no tenant id: callers - cannot redirect this control toward a customer organization. - operationId: console.v1.ConsoleService.GetStaffInferenceRoutingProfile - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetStaffInferenceRoutingProfileRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetStaffInferenceRoutingProfileResponse' - /console.v1.ConsoleService/UpdateStaffInferenceRoutingProfile: - post: - tags: - - console.v1.ConsoleService - summary: UpdateStaffInferenceRoutingProfile - description: |- - UpdateStaffInferenceRoutingProfile changes the Dex provider/model pair for - the server-configured STAFF organization. Targets must be registered and - deployment-allowlisted; optimistic revision matching prevents stale writes. - operationId: console.v1.ConsoleService.UpdateStaffInferenceRoutingProfile - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateStaffInferenceRoutingProfileRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateStaffInferenceRoutingProfileResponse' - /console.v1.ConsoleService/ListEvalResults: - post: - tags: - - console.v1.ConsoleService - summary: ListEvalResults - description: ListEvalResults returns online quality and eval outcomes for traced runs. - operationId: console.v1.ConsoleService.ListEvalResults - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListEvalResultsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListEvalResultsResponse' - /console.v1.ConsoleService/ListCostUsage: - post: - tags: - - console.v1.ConsoleService - summary: ListCostUsage - description: ListCostUsage returns spend and token usage for traced AI work. - operationId: console.v1.ConsoleService.ListCostUsage - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListCostUsageRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListCostUsageResponse' - /console.v1.ConsoleService/RecordProviderCostSnapshot: - post: - tags: - - console.v1.ConsoleService - summary: RecordProviderCostSnapshot - description: |- - RecordProviderCostSnapshot records a provider-owned monthly aggregate - discovered through a tenant's connected integration resources. - operationId: console.v1.ConsoleService.RecordProviderCostSnapshot - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RecordProviderCostSnapshotRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RecordProviderCostSnapshotResponse' - /console.v1.ConsoleService/ListAuthorityPosture: - post: - tags: - - console.v1.ConsoleService - summary: ListAuthorityPosture - description: |- - ListAuthorityPosture returns server-owned credential and authority posture - for agent, tool, and connector work. It lets clients ask which actor is - assuming which authority without deriving posture from UI copy. - operationId: console.v1.ConsoleService.ListAuthorityPosture - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListAuthorityPostureRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListAuthorityPostureResponse' - /console.v1.ConsoleService/ListAgentWorkforceRecords: - post: - tags: - - console.v1.ConsoleService - summary: ListAgentWorkforceRecords - description: |- - ListAgentWorkforceRecords returns the server-owned Agent Workforce read - model for security engineers. It keeps approval, action, credential, cost, - and debug evidence typed so clients do not infer it from native event text. - operationId: console.v1.ConsoleService.ListAgentWorkforceRecords - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListAgentWorkforceRecordsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListAgentWorkforceRecordsResponse' - /console.v1.ConsoleService/GetAgentProduct: - post: - tags: - - console.v1.ConsoleService - summary: GetAgentProduct - description: Reads one registered agent, its active immutable config, and its bound workspace connections. - operationId: console.v1.ConsoleService.GetAgentProduct - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetAgentProductRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetAgentProductResponse' - /console.v1.ConsoleService/CloneAgentProduct: - post: - tags: - - console.v1.ConsoleService - summary: CloneAgentProduct - description: Clones safe behavior into a distinct registered agent without workspace credentials. - operationId: console.v1.ConsoleService.CloneAgentProduct - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CloneAgentProductRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CloneAgentProductResponse' - /console.v1.ConsoleService/UpdateAgentProduct: - post: - tags: - - console.v1.ConsoleService - summary: UpdateAgentProduct - description: Replaces editable agent behavior with a new immutable configuration version. - operationId: console.v1.ConsoleService.UpdateAgentProduct - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateAgentProductRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateAgentProductResponse' - /console.v1.ConsoleService/ListOrbControlTargets: - post: - tags: - - console.v1.ConsoleService - summary: ListOrbControlTargets - description: ListOrbControlTargets returns Platform-owned projections of Orb runtime targets. - operationId: console.v1.ConsoleService.ListOrbControlTargets - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListOrbControlTargetsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListOrbControlTargetsResponse' - /console.v1.ConsoleService/GetOrbControlTarget: - post: - tags: - - console.v1.ConsoleService - summary: GetOrbControlTarget - description: GetOrbControlTarget returns one Platform-owned Orb projection and receipt. - operationId: console.v1.ConsoleService.GetOrbControlTarget - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOrbControlTargetRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOrbControlTargetResponse' - /console.v1.ConsoleService/SubmitOrbControlAction: - post: - tags: - - console.v1.ConsoleService - summary: SubmitOrbControlAction - description: SubmitOrbControlAction records a governed wake or stop command in Platform. - operationId: console.v1.ConsoleService.SubmitOrbControlAction - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitOrbControlActionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitOrbControlActionResponse' - /console.v1.ConsoleService/SubmitAgentWorkforceEvidence: - post: - tags: - - console.v1.ConsoleService - summary: SubmitAgentWorkforceEvidence - description: |- - SubmitAgentWorkforceEvidence persists operator/source evidence and returns - the server-owned Agent Workforce state after the write. Approval authority - remains derived by the backend evidence rules, not by client assertions. - operationId: console.v1.ConsoleService.SubmitAgentWorkforceEvidence - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitAgentWorkforceEvidenceRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitAgentWorkforceEvidenceResponse' - /console.v1.ConsoleService/ListFindings: - post: - tags: - - console.v1.ConsoleService - summary: ListFindings - description: ListFindings returns open risk and posture findings. - operationId: console.v1.ConsoleService.ListFindings - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListFindingsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListFindingsResponse' - /console.v1.ConsoleService/GetTraceDrilldown: - post: - tags: - - console.v1.ConsoleService - summary: GetTraceDrilldown - description: GetTraceDrilldown returns a trace summary and span tree for debugging. - operationId: console.v1.ConsoleService.GetTraceDrilldown - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetTraceDrilldownRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetTraceDrilldownResponse' - /console.v1.ConsoleService/ListIntegrationTiles: - post: - tags: - - console.v1.ConsoleService - summary: ListIntegrationTiles - description: ListIntegrationTiles returns setup and health tiles for onboarding. - operationId: console.v1.ConsoleService.ListIntegrationTiles - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListIntegrationTilesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListIntegrationTilesResponse' - /console.v1.ConsoleService/ListPinnedSources: - post: - tags: - - console.v1.ConsoleService - summary: ListPinnedSources - description: |- - ListPinnedSources returns the per-workspace pinned-source set. Pins are a - user preference (see docs/integrations/console_integration_tiles_pin_audit.md); - the FE merges them into IntegrationBackendState client-side. - operationId: console.v1.ConsoleService.ListPinnedSources - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListPinnedSourcesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListPinnedSourcesResponse' - /console.v1.ConsoleService/SetPinnedSource: - post: - tags: - - console.v1.ConsoleService - summary: SetPinnedSource - description: |- - SetPinnedSource creates or updates a single pin entry for the caller's - workspace. Idempotent. The pinned_by audit field is filled from the caller - identity server-side. - operationId: console.v1.ConsoleService.SetPinnedSource - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SetPinnedSourceRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SetPinnedSourceResponse' - /console.v1.ConsoleService/UnpinSource: - post: - tags: - - console.v1.ConsoleService - summary: UnpinSource - description: UnpinSource removes a pin entry. No-op if the pin does not exist. - operationId: console.v1.ConsoleService.UnpinSource - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UnpinSourceRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UnpinSourceResponse' - /console.v1.ConsoleService/CreateDexMcpServer: - post: - tags: - - console.v1.ConsoleService - summary: CreateDexMcpServer - description: |- - CreateDexMcpServer registers one governed Streamable HTTP MCP endpoint. - bearer_token is write-only and is never returned by read methods. - operationId: console.v1.ConsoleService.CreateDexMcpServer - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateDexMcpServerRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateDexMcpServerResponse' - /console.v1.ConsoleService/ListDexMcpServers: - post: - tags: - - console.v1.ConsoleService - summary: ListDexMcpServers - operationId: console.v1.ConsoleService.ListDexMcpServers - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListDexMcpServersRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListDexMcpServersResponse' - /console.v1.ConsoleService/GetDexMcpServer: - post: - tags: - - console.v1.ConsoleService - summary: GetDexMcpServer - operationId: console.v1.ConsoleService.GetDexMcpServer - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetDexMcpServerRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetDexMcpServerResponse' - /console.v1.ConsoleService/DiscoverDexMcpServer: - post: - tags: - - console.v1.ConsoleService - summary: DiscoverDexMcpServer - description: |- - DiscoverDexMcpServer probes one registered endpoint while it is still - disabled, persists the immutable catalog snapshot, and returns the - redacted review projection. Discovery never activates tool dispatch. - operationId: console.v1.ConsoleService.DiscoverDexMcpServer - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DiscoverDexMcpServerRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DiscoverDexMcpServerResponse' - /console.v1.ConsoleService/UpdateDexMcpServer: - post: - tags: - - console.v1.ConsoleService - summary: UpdateDexMcpServer - operationId: console.v1.ConsoleService.UpdateDexMcpServer - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateDexMcpServerRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateDexMcpServerResponse' - /console.v1.ConsoleService/DeleteDexMcpServer: - post: - tags: - - console.v1.ConsoleService - summary: DeleteDexMcpServer - operationId: console.v1.ConsoleService.DeleteDexMcpServer - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DeleteDexMcpServerRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DeleteDexMcpServerResponse' - /console.v1.ConsoleService/InitiateDexMcpOAuthProfile: - post: - tags: - - console.v1.ConsoleService - summary: InitiateDexMcpOAuthProfile - description: |- - Remote MCP OAuth profiles are named, tenant-bound control-plane objects. - Tokens remain in the Connector broker; Console responses contain redacted - state, scopes, versions, and opaque grant identities only. Personal - profiles remain principal-bound. Organization-profile creation, - completion, listing, revoke, and reauthorization additionally require the - server-enforced connectors:admin workspace-administrator authority. - operationId: console.v1.ConsoleService.InitiateDexMcpOAuthProfile - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.InitiateDexMcpOAuthProfileRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.InitiateDexMcpOAuthProfileResponse' - /console.v1.ConsoleService/CompleteDexMcpOAuthProfile: - post: - tags: - - console.v1.ConsoleService - summary: CompleteDexMcpOAuthProfile - operationId: console.v1.ConsoleService.CompleteDexMcpOAuthProfile - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CompleteDexMcpOAuthProfileRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CompleteDexMcpOAuthProfileResponse' - /console.v1.ConsoleService/ListDexMcpOAuthProfiles: - post: - tags: - - console.v1.ConsoleService - summary: ListDexMcpOAuthProfiles - operationId: console.v1.ConsoleService.ListDexMcpOAuthProfiles - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListDexMcpOAuthProfilesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListDexMcpOAuthProfilesResponse' - /console.v1.ConsoleService/RevokeDexMcpOAuthProfile: - post: - tags: - - console.v1.ConsoleService - summary: RevokeDexMcpOAuthProfile - operationId: console.v1.ConsoleService.RevokeDexMcpOAuthProfile - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RevokeDexMcpOAuthProfileRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RevokeDexMcpOAuthProfileResponse' - /console.v1.ConsoleService/ReauthorizeDexMcpOAuthProfile: - post: - tags: - - console.v1.ConsoleService - summary: ReauthorizeDexMcpOAuthProfile - operationId: console.v1.ConsoleService.ReauthorizeDexMcpOAuthProfile - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReauthorizeDexMcpOAuthProfileRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReauthorizeDexMcpOAuthProfileResponse' - /console.v1.ConsoleService/RegisterPrivateEndpoint: - post: - tags: - - console.v1.ConsoleService - summary: RegisterPrivateEndpoint - description: |- - RegisterPrivateEndpoint records a tenant-bound AWS PrivateLink, GCP PSC, - or customer-relay endpoint. Registration is non-routable until a private - route and DNS observation is verified by a server-owned attestor. - operationId: console.v1.ConsoleService.RegisterPrivateEndpoint - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RegisterPrivateEndpointRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RegisterPrivateEndpointResponse' - /console.v1.ConsoleService/VerifyPrivateEndpoint: - post: - tags: - - console.v1.ConsoleService - summary: VerifyPrivateEndpoint - description: |- - Verification is staff-only and remains unavailable until a server-owned - AWS/GCP/relay attestor can bind a fresh route and DNS observation to this - exact tenant endpoint. Caller-supplied evidence fields are compatibility - inputs only and never establish a verified route. - operationId: console.v1.ConsoleService.VerifyPrivateEndpoint - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.VerifyPrivateEndpointRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.VerifyPrivateEndpointResponse' - /console.v1.ConsoleService/ListPrivateEndpoints: - post: - tags: - - console.v1.ConsoleService - summary: ListPrivateEndpoints - operationId: console.v1.ConsoleService.ListPrivateEndpoints - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListPrivateEndpointsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListPrivateEndpointsResponse' - /console.v1.ConsoleService/DeletePrivateEndpoint: - post: - tags: - - console.v1.ConsoleService - summary: DeletePrivateEndpoint - operationId: console.v1.ConsoleService.DeletePrivateEndpoint - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DeletePrivateEndpointRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DeletePrivateEndpointResponse' - /console.v1.ConsoleService/AttachPrivateEndpointToProfile: - post: - tags: - - console.v1.ConsoleService - summary: AttachPrivateEndpointToProfile - operationId: console.v1.ConsoleService.AttachPrivateEndpointToProfile - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.AttachPrivateEndpointToProfileRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.AttachPrivateEndpointToProfileResponse' - /console.v1.ConsoleService/ListGatewayEgressOrigins: - post: - tags: - - console.v1.ConsoleService - summary: ListGatewayEgressOrigins - operationId: console.v1.ConsoleService.ListGatewayEgressOrigins - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListGatewayEgressOriginsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListGatewayEgressOriginsResponse' - /console.v1.ConsoleService/GetOnboardingPlan: - post: - tags: - - console.v1.ConsoleService - summary: GetOnboardingPlan - description: GetOnboardingPlan returns the recommended setup path for this workspace. - operationId: console.v1.ConsoleService.GetOnboardingPlan - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOnboardingPlanRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOnboardingPlanResponse' - /console.v1.ConsoleService/ListOperatingChannels: - post: - tags: - - console.v1.ConsoleService - summary: ListOperatingChannels - description: |- - ListOperatingChannels returns the chat-native company/domain channels the - Console can actually operate for this workspace. Capability state is - backend-owned so the UI does not invent domains or connection status. - operationId: console.v1.ConsoleService.ListOperatingChannels - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListOperatingChannelsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListOperatingChannelsResponse' - /console.v1.ConsoleService/ListOperatingJobs: - post: - tags: - - console.v1.ConsoleService - summary: ListOperatingJobs - description: |- - ListOperatingJobs returns the Platform-owned customer Work projection for - admitted operating-chat objectives. Job identity is the canonical - Platform objective work id; conversations and runtime attempts are typed - correlations, not competing work records. This is a read model only: - lifecycle mutations continue to route to their owning services. - operationId: console.v1.ConsoleService.ListOperatingJobs - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListOperatingJobsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListOperatingJobsResponse' - /console.v1.ConsoleService/ArchiveOperatingThread: - post: - tags: - - console.v1.ConsoleService - summary: ArchiveOperatingThread - description: |- - ArchiveOperatingThread changes only the durable conversation's list - visibility. It does not delete messages, stop execution, or mutate a - provider binding. Repeating a request with the same idempotency key and - digest returns the original result. - operationId: console.v1.ConsoleService.ArchiveOperatingThread - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ArchiveOperatingThreadRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ArchiveOperatingThreadResponse' - /console.v1.ConsoleService/ForkOperatingThread: - post: - tags: - - console.v1.ConsoleService - summary: ForkOperatingThread - description: |- - ForkOperatingThread copies one operating thread's conversation content - into a new thread owned by the caller. The fork inherits content only: - the source's model selection, Auto route, receipts, attachments, and turn - records are all dropped, because each carries authority granted to the - source's principal rather than to the forker. Repeating a request with - the same idempotency key and digest returns the original fork. - operationId: console.v1.ConsoleService.ForkOperatingThread - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ForkOperatingThreadRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ForkOperatingThreadResponse' - /console.v1.ConsoleService/RenameOperatingThread: - post: - tags: - - console.v1.ConsoleService - summary: RenameOperatingThread - description: |- - RenameOperatingThread replaces the durable user-visible title for one - owner-backed operating thread. The desired title makes retries idempotent. - operationId: console.v1.ConsoleService.RenameOperatingThread - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RenameOperatingThreadRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RenameOperatingThreadResponse' - /console.v1.ConsoleService/GetOperatingThread: - post: - tags: - - console.v1.ConsoleService - summary: GetOperatingThread - description: |- - GetOperatingThread returns the selected operating thread from its owning - backend messages and receipts. - operationId: console.v1.ConsoleService.GetOperatingThread - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOperatingThreadRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOperatingThreadResponse' - /console.v1.ConsoleService/BootstrapThreadGateway: - post: - tags: - - console.v1.ConsoleService - summary: BootstrapThreadGateway - description: |- - BootstrapThreadGateway authorizes one browser session for one exact - operating thread and returns an in-memory, short-lived direct-gateway - credential. The direct route is deployment-controlled and defaults off. - operationId: console.v1.ConsoleService.BootstrapThreadGateway - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.BootstrapThreadGatewayRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.BootstrapThreadGatewayResponse' - /console.v1.ConsoleService/PrewarmOperatingThread: - post: - tags: - - console.v1.ConsoleService - summary: PrewarmOperatingThread - description: |- - PrewarmOperatingThread allocates the durable Dex thread identity and - idempotently requests its tenant-bound RunnerSession before the composer - submits the first message. - operationId: console.v1.ConsoleService.PrewarmOperatingThread - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.PrewarmOperatingThreadRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.PrewarmOperatingThreadResponse' - /console.v1.ConsoleService/ListOperatingThreadEvents: - post: - tags: - - console.v1.ConsoleService - summary: ListOperatingThreadEvents - description: |- - ListOperatingThreadEvents replays the browser-safe execution projection - after a durable monotonic cursor. Runtime endpoints, certificates, raw - tool payloads, and provider credentials never cross this boundary. - operationId: console.v1.ConsoleService.ListOperatingThreadEvents - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListOperatingThreadEventsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListOperatingThreadEventsResponse' - /console.v1.ConsoleService/WatchOperatingThread: {} - /console.v1.ConsoleService/RespondOperatingThread: - post: - tags: - - console.v1.ConsoleService - summary: RespondOperatingThread - description: |- - RespondOperatingThread forwards one typed response to the durable hosted - runtime through the same lease, replay, and generation-fencing path as a - user turn. - operationId: console.v1.ConsoleService.RespondOperatingThread - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RespondOperatingThreadRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RespondOperatingThreadResponse' - /console.v1.ConsoleService/InterruptOperatingThread: - post: - tags: - - console.v1.ConsoleService - summary: InterruptOperatingThread - description: |- - InterruptOperatingThread stops a pending operating turn from the console. - Use this when the user stops waiting during provision or mid-run. Unlike - RespondOperatingThread, no waiting request_id is required. The owner marks - the turn interrupted, cancels open runtime work for that message, and - returns the updated thread projection. - operationId: console.v1.ConsoleService.InterruptOperatingThread - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.InterruptOperatingThreadRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.InterruptOperatingThreadResponse' - /console.v1.ConsoleService/SearchOperatingHistory: - post: - tags: - - console.v1.ConsoleService - summary: SearchOperatingHistory - description: |- - SearchOperatingHistory finds safe, workspace-scoped message and tool/receipt - projections without making the projection authoritative. - operationId: console.v1.ConsoleService.SearchOperatingHistory - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SearchOperatingHistoryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SearchOperatingHistoryResponse' - /console.v1.ConsoleService/GetOperatingHistoryContext: - post: - tags: - - console.v1.ConsoleService - summary: GetOperatingHistoryContext - description: |- - GetOperatingHistoryContext resolves a search cursor to a bounded canonical - neighborhood after reauthorizing the tenant scope. - operationId: console.v1.ConsoleService.GetOperatingHistoryContext - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOperatingHistoryContextRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOperatingHistoryContextResponse' - /console.v1.ConsoleService/AcceptOperatingProjectSnapshot: - post: - tags: - - console.v1.ConsoleService - summary: AcceptOperatingProjectSnapshot - description: Explicitly accepts a complete non-code project file snapshot. - operationId: console.v1.ConsoleService.AcceptOperatingProjectSnapshot - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.AcceptOperatingProjectSnapshotRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.AcceptOperatingProjectSnapshotResponse' - /console.v1.ConsoleService/ImportOperatingProjectSnapshot: - post: - tags: - - console.v1.ConsoleService - summary: ImportOperatingProjectSnapshot - description: Imports only the connected repository's provider-observed default-branch head. - operationId: console.v1.ConsoleService.ImportOperatingProjectSnapshot - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ImportOperatingProjectSnapshotRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.AcceptOperatingProjectSnapshotResponse' - /console.v1.ConsoleService/GetOperatingTaskEnvironment: - post: - tags: - - console.v1.ConsoleService - summary: GetOperatingTaskEnvironment - description: |- - Reads the current accepted source without changing task baselines. - Reads retained task state without acquiring or refreshing a computer. - operationId: console.v1.ConsoleService.GetOperatingTaskEnvironment - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOperatingTaskEnvironmentRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOperatingTaskEnvironmentResponse' - /console.v1.ConsoleService/GetOperatingProjectSnapshot: - post: - tags: - - console.v1.ConsoleService - summary: GetOperatingProjectSnapshot - operationId: console.v1.ConsoleService.GetOperatingProjectSnapshot - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOperatingProjectSnapshotRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.AcceptOperatingProjectSnapshotResponse' - /console.v1.ConsoleService/SubmitOperatingMessage: - post: - tags: - - console.v1.ConsoleService - summary: SubmitOperatingMessage - description: |- - SubmitOperatingMessage records a human chat turn. Backend-owned operating - work is represented by receipts only when a task or tool owner accepts it. - operationId: console.v1.ConsoleService.SubmitOperatingMessage - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitOperatingMessageRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitOperatingMessageResponse' - /console.v1.ConsoleService/SubmitOperatingCorrection: - post: - tags: - - console.v1.ConsoleService - summary: SubmitOperatingCorrection - description: |- - SubmitOperatingCorrection records explicit operator feedback as a - review-gated regression candidate. It never changes production behavior. - operationId: console.v1.ConsoleService.SubmitOperatingCorrection - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitOperatingCorrectionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitOperatingCorrectionResponse' - /console.v1.ConsoleService/SubmitOperatingFeedback: - post: - tags: - - console.v1.ConsoleService - summary: SubmitOperatingFeedback - description: |- - SubmitOperatingFeedback durably records an operator's bounded assessment - of one Dex response. Optional correction text is digested and discarded. - operationId: console.v1.ConsoleService.SubmitOperatingFeedback - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitOperatingFeedbackRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitOperatingFeedbackResponse' - /console.v1.ConsoleService/SubmitProductIssueReport: - post: - tags: - - console.v1.ConsoleService - summary: SubmitProductIssueReport - description: |- - SubmitProductIssueReport records a workspace-scoped product issue with - bounded, operator-approved browser diagnostics and an optional screenshot. - operationId: console.v1.ConsoleService.SubmitProductIssueReport - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitProductIssueReportRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitProductIssueReportResponse' - /console.v1.ConsoleService/SubmitNativeProductIssueReport: - post: - tags: - - console.v1.ConsoleService - summary: SubmitNativeProductIssueReport - description: Native clients submit to the same durable product issue owner using a narrow permission. - operationId: console.v1.ConsoleService.SubmitNativeProductIssueReport - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitNativeProductIssueReportRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitProductIssueReportResponse' - /console.v1.ConsoleService/ListStaffProductIssueReports: - post: - tags: - - console.v1.ConsoleService - summary: ListStaffProductIssueReports - description: |- - ListStaffProductIssueReports exposes bounded issue-report projections to - EvalOps staff without returning screenshot bytes. - operationId: console.v1.ConsoleService.ListStaffProductIssueReports - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListStaffProductIssueReportsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListStaffProductIssueReportsResponse' - /console.v1.ConsoleService/EngageStaffProductIssueReport: - post: - tags: - - console.v1.ConsoleService - summary: EngageStaffProductIssueReport - description: |- - EngageStaffProductIssueReport records the first durable staff - acknowledgement. Repeated calls preserve the original actor, time, and note. - operationId: console.v1.ConsoleService.EngageStaffProductIssueReport - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.EngageStaffProductIssueReportRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.EngageStaffProductIssueReportResponse' - /console.v1.ConsoleService/ListStaffProductIssueRecoveries: - post: - tags: - - console.v1.ConsoleService - summary: ListStaffProductIssueRecoveries - description: Lists the global recovery queue under verified staff authority. - operationId: console.v1.ConsoleService.ListStaffProductIssueRecoveries - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListStaffProductIssueRecoveriesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListStaffProductIssueRecoveriesResponse' - /console.v1.ConsoleService/PrepareStaffProductIssueRecovery: - post: - tags: - - console.v1.ConsoleService - summary: PrepareStaffProductIssueRecovery - description: PrepareStaffProductIssueRecovery advances the staff-reviewed recovery of charged failures. - operationId: console.v1.ConsoleService.PrepareStaffProductIssueRecovery - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.PrepareStaffProductIssueRecoveryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ProductIssueRecoveryResponse' - /console.v1.ConsoleService/ScanStaffProductIssueRecovery: - post: - tags: - - console.v1.ConsoleService - summary: ScanStaffProductIssueRecovery - description: ScanStaffProductIssueRecovery advances the staff-reviewed recovery of charged failures. - operationId: console.v1.ConsoleService.ScanStaffProductIssueRecovery - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ScanStaffProductIssueRecoveryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ProductIssueRecoveryResponse' - /console.v1.ConsoleService/ReviewStaffProductIssueRecovery: - post: - tags: - - console.v1.ConsoleService - summary: ReviewStaffProductIssueRecovery - description: ReviewStaffProductIssueRecovery advances the staff-reviewed recovery of charged failures. - operationId: console.v1.ConsoleService.ReviewStaffProductIssueRecovery - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReviewStaffProductIssueRecoveryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ProductIssueRecoveryResponse' - /console.v1.ConsoleService/ExecuteStaffProductIssueRecovery: - post: - tags: - - console.v1.ConsoleService - summary: ExecuteStaffProductIssueRecovery - description: ExecuteStaffProductIssueRecovery advances the staff-reviewed recovery of charged failures. - operationId: console.v1.ConsoleService.ExecuteStaffProductIssueRecovery - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ExecuteStaffProductIssueRecoveryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ProductIssueRecoveryResponse' - /console.v1.ConsoleService/GetProductIssueRecovery: - post: - tags: - - console.v1.ConsoleService - summary: GetProductIssueRecovery - description: GetProductIssueRecovery accesses only the authenticated recovery recipient or authorized staff. - operationId: console.v1.ConsoleService.GetProductIssueRecovery - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetProductIssueRecoveryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ProductIssueRecoveryResponse' - /console.v1.ConsoleService/ReplyProductIssueRecovery: - post: - tags: - - console.v1.ConsoleService - summary: ReplyProductIssueRecovery - description: ReplyProductIssueRecovery accesses only the authenticated recovery recipient or authorized staff. - operationId: console.v1.ConsoleService.ReplyProductIssueRecovery - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReplyProductIssueRecoveryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ProductIssueRecoveryResponse' - /console.v1.ConsoleService/GetOperatingFeedback: - post: - tags: - - console.v1.ConsoleService - summary: GetOperatingFeedback - description: |- - GetOperatingFeedback returns the latest durable feedback revision for one - Dex response, including a retraction marker when the operator removed it. - operationId: console.v1.ConsoleService.GetOperatingFeedback - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOperatingFeedbackRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOperatingFeedbackResponse' - /console.v1.ConsoleService/ResolveOperatingFeedbackRemediation: - post: - tags: - - console.v1.ConsoleService - summary: ResolveOperatingFeedbackRemediation - description: |- - ResolveOperatingFeedbackRemediation records the operator-confirmed outcome - of a real verify or retry turn linked to feedback. - operationId: console.v1.ConsoleService.ResolveOperatingFeedbackRemediation - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ResolveOperatingFeedbackRemediationRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ResolveOperatingFeedbackRemediationResponse' - /console.v1.ConsoleService/ListCustomerIntelligenceFacts: - post: - tags: - - console.v1.ConsoleService - summary: ListCustomerIntelligenceFacts - description: |- - ListCustomerIntelligenceFacts returns bounded, safe fact projections to - authorized staff. Customer members cannot browse the internal ledger. - operationId: console.v1.ConsoleService.ListCustomerIntelligenceFacts - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListCustomerIntelligenceFactsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListCustomerIntelligenceFactsResponse' - /console.v1.ConsoleService/GetCustomerIntelligenceFact: - post: - tags: - - console.v1.ConsoleService - summary: GetCustomerIntelligenceFact - description: |- - GetCustomerIntelligenceFact returns one safe current revision and its - append-only history to authorized staff. - operationId: console.v1.ConsoleService.GetCustomerIntelligenceFact - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetCustomerIntelligenceFactRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetCustomerIntelligenceFactResponse' - /console.v1.ConsoleService/ReviewCustomerIntelligenceFact: - post: - tags: - - console.v1.ConsoleService - summary: ReviewCustomerIntelligenceFact - description: |- - ReviewCustomerIntelligenceFact appends a staff review decision. It never - edits an existing revision or raises authority from model confidence. - operationId: console.v1.ConsoleService.ReviewCustomerIntelligenceFact - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReviewCustomerIntelligenceFactRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReviewCustomerIntelligenceFactResponse' - /console.v1.ConsoleService/ProposeCustomerIntelligenceFact: - post: - tags: - - console.v1.ConsoleService - summary: ProposeCustomerIntelligenceFact - description: |- - ProposeCustomerIntelligenceFact is a typed producer boundary. The handler - additionally requires an allowlisted service identity. - operationId: console.v1.ConsoleService.ProposeCustomerIntelligenceFact - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ProposeCustomerIntelligenceFactRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ProposeCustomerIntelligenceFactResponse' - /console.v1.ConsoleService/RespondToCustomerFactConfirmation: - post: - tags: - - console.v1.ConsoleService - summary: RespondToCustomerFactConfirmation - description: |- - RespondToCustomerFactConfirmation lets a customer confirm or dispute one - open, interaction-scoped intent; it is not a general fact-write API. - operationId: console.v1.ConsoleService.RespondToCustomerFactConfirmation - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RespondToCustomerFactConfirmationRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RespondToCustomerFactConfirmationResponse' - /console.v1.ConsoleService/AggregateCustomerIntelligencePatterns: - post: - tags: - - console.v1.ConsoleService - summary: AggregateCustomerIntelligencePatterns - description: |- - AggregateCustomerIntelligencePatterns returns privacy-bounded staff - aggregates without account identifiers or fact summaries. - operationId: console.v1.ConsoleService.AggregateCustomerIntelligencePatterns - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.AggregateCustomerIntelligencePatternsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.AggregateCustomerIntelligencePatternsResponse' - /console.v1.ConsoleService/ListOperatingCorrections: - post: - tags: - - console.v1.ConsoleService - summary: ListOperatingCorrections - description: ListOperatingCorrections returns the workspace's correction review queue. - operationId: console.v1.ConsoleService.ListOperatingCorrections - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListOperatingCorrectionsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListOperatingCorrectionsResponse' - /console.v1.ConsoleService/ReviewOperatingCorrection: - post: - tags: - - console.v1.ConsoleService - summary: ReviewOperatingCorrection - description: |- - ReviewOperatingCorrection explicitly approves or rejects a regression - candidate. Approval admits evaluation only; it does not promote learning. - operationId: console.v1.ConsoleService.ReviewOperatingCorrection - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReviewOperatingCorrectionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReviewOperatingCorrectionResponse' - /console.v1.ConsoleService/ListWorkspaceMemories: - post: - tags: - - console.v1.ConsoleService - summary: ListWorkspaceMemories - description: |- - ListWorkspaceMemories returns the active memories the authenticated - workspace owns. MemoryService remains the durable owner. - operationId: console.v1.ConsoleService.ListWorkspaceMemories - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListWorkspaceMemoriesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListWorkspaceMemoriesResponse' - /console.v1.ConsoleService/CorrectWorkspaceMemory: - post: - tags: - - console.v1.ConsoleService - summary: CorrectWorkspaceMemory - description: CorrectWorkspaceMemory applies one revision-fenced owner correction. - operationId: console.v1.ConsoleService.CorrectWorkspaceMemory - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CorrectWorkspaceMemoryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CorrectWorkspaceMemoryResponse' - /console.v1.ConsoleService/ReviewWorkspaceMemory: - post: - tags: - - console.v1.ConsoleService - summary: ReviewWorkspaceMemory - description: ReviewWorkspaceMemory approves or rejects a proposed memory for recall. - operationId: console.v1.ConsoleService.ReviewWorkspaceMemory - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReviewWorkspaceMemoryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReviewWorkspaceMemoryResponse' - /console.v1.ConsoleService/ForgetWorkspaceMemory: - post: - tags: - - console.v1.ConsoleService - summary: ForgetWorkspaceMemory - description: ForgetWorkspaceMemory immediately revokes one memory from active recall. - operationId: console.v1.ConsoleService.ForgetWorkspaceMemory - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ForgetWorkspaceMemoryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ForgetWorkspaceMemoryResponse' - /console.v1.ConsoleService/BeginOperatingAttachmentUpload: - post: - tags: - - console.v1.ConsoleService - summary: BeginOperatingAttachmentUpload - description: BeginOperatingAttachmentUpload validates metadata and creates a fenced VFS upload lease. - operationId: console.v1.ConsoleService.BeginOperatingAttachmentUpload - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.BeginOperatingAttachmentUploadRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.BeginOperatingAttachmentUploadResponse' - /console.v1.ConsoleService/CompleteOperatingAttachmentUpload: - post: - tags: - - console.v1.ConsoleService - summary: CompleteOperatingAttachmentUpload - description: CompleteOperatingAttachmentUpload verifies bytes and starts bounded extraction. - operationId: console.v1.ConsoleService.CompleteOperatingAttachmentUpload - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CompleteOperatingAttachmentUploadRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CompleteOperatingAttachmentUploadResponse' - /console.v1.ConsoleService/ListOperatingAttachments: - post: - tags: - - console.v1.ConsoleService - summary: ListOperatingAttachments - description: ListOperatingAttachments returns reusable workspace-scoped attachment metadata only. - operationId: console.v1.ConsoleService.ListOperatingAttachments - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListOperatingAttachmentsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListOperatingAttachmentsResponse' - /console.v1.ConsoleService/ResolveOperatingReceiptAction: - post: - tags: - - console.v1.ConsoleService - summary: ResolveOperatingReceiptAction - description: |- - ResolveOperatingReceiptAction sends a backend-returned receipt command to - its owning service. Console only advertises actions with an owning handler. - operationId: console.v1.ConsoleService.ResolveOperatingReceiptAction - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ResolveOperatingReceiptActionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ResolveOperatingReceiptActionResponse' - /console.v1.ConsoleService/GetOperatingReceipt: - post: - tags: - - console.v1.ConsoleService - summary: GetOperatingReceipt - description: GetOperatingReceipt returns one safe, UI-renderable receipt mini-app. - operationId: console.v1.ConsoleService.GetOperatingReceipt - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOperatingReceiptRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOperatingReceiptResponse' - /console.v1.ConsoleService/SubmitComputerMission: - post: - tags: - - console.v1.ConsoleService - summary: SubmitComputerMission - description: |- - SubmitComputerMission persists a confirmed, explicitly scoped autonomous - mission. Full autonomy is an authority grant on the mission contract, not - a bypass around tenant, policy, budget, audit, or cancellation controls. - operationId: console.v1.ConsoleService.SubmitComputerMission - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitComputerMissionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitComputerMissionResponse' - /console.v1.ConsoleService/GetComputerMission: - post: - tags: - - console.v1.ConsoleService - summary: GetComputerMission - description: |- - GetComputerMission returns durable mission state and its latest safe - operating receipt. - operationId: console.v1.ConsoleService.GetComputerMission - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetComputerMissionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetComputerMissionResponse' - /console.v1.ConsoleService/CancelComputerMission: - post: - tags: - - console.v1.ConsoleService - summary: CancelComputerMission - description: CancelComputerMission requests cancellation through the mission owner. - operationId: console.v1.ConsoleService.CancelComputerMission - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CancelComputerMissionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CancelComputerMissionResponse' - /console.v1.ConsoleService/ContinueComputerMission: - post: - tags: - - console.v1.ConsoleService - summary: ContinueComputerMission - description: ContinueComputerMission supplies typed user input to a waiting mission. - operationId: console.v1.ConsoleService.ContinueComputerMission - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ContinueComputerMissionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ContinueComputerMissionResponse' - /console.v1.ConsoleService/PauseComputerMission: - post: - tags: - - console.v1.ConsoleService - summary: PauseComputerMission - description: PauseComputerMission durably parks a live or queued mission. - operationId: console.v1.ConsoleService.PauseComputerMission - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.PauseComputerMissionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.PauseComputerMissionResponse' - /console.v1.ConsoleService/ResumeComputerMission: - post: - tags: - - console.v1.ConsoleService - summary: ResumeComputerMission - description: ResumeComputerMission queues a new fenced execution generation. - operationId: console.v1.ConsoleService.ResumeComputerMission - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ResumeComputerMissionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ResumeComputerMissionResponse' - /console.v1.ConsoleService/WakeComputerMission: - post: - tags: - - console.v1.ConsoleService - summary: WakeComputerMission - description: WakeComputerMission queues a sleeping or externally blocked mission. - operationId: console.v1.ConsoleService.WakeComputerMission - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.WakeComputerMissionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.WakeComputerMissionResponse' - /console.v1.ConsoleService/GuideComputerMission: - post: - tags: - - console.v1.ConsoleService - summary: GuideComputerMission - description: GuideComputerMission supplies durable guidance and queues a new generation. - operationId: console.v1.ConsoleService.GuideComputerMission - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GuideComputerMissionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GuideComputerMissionResponse' - /console.v1.ConsoleService/ListComputerMissionCanaryDefinitions: - post: - tags: - - console.v1.ConsoleService - summary: ListComputerMissionCanaryDefinitions - operationId: console.v1.ConsoleService.ListComputerMissionCanaryDefinitions - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListComputerMissionCanaryDefinitionsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListComputerMissionCanaryDefinitionsResponse' - /console.v1.ConsoleService/StartComputerMissionCanaryRun: - post: - tags: - - console.v1.ConsoleService - summary: StartComputerMissionCanaryRun - operationId: console.v1.ConsoleService.StartComputerMissionCanaryRun - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.StartComputerMissionCanaryRunRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.StartComputerMissionCanaryRunResponse' - /console.v1.ConsoleService/GetComputerMissionCanaryRun: - post: - tags: - - console.v1.ConsoleService - summary: GetComputerMissionCanaryRun - operationId: console.v1.ConsoleService.GetComputerMissionCanaryRun - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetComputerMissionCanaryRunRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetComputerMissionCanaryRunResponse' - /console.v1.ConsoleService/ListComputerMissionCanaryRuns: - post: - tags: - - console.v1.ConsoleService - summary: ListComputerMissionCanaryRuns - operationId: console.v1.ConsoleService.ListComputerMissionCanaryRuns - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListComputerMissionCanaryRunsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListComputerMissionCanaryRunsResponse' - /console.v1.ConsoleService/GetComputerMissionCanaryEvidence: - post: - tags: - - console.v1.ConsoleService - summary: GetComputerMissionCanaryEvidence - operationId: console.v1.ConsoleService.GetComputerMissionCanaryEvidence - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetComputerMissionCanaryEvidenceRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetComputerMissionCanaryEvidenceResponse' - /console.v1.ConsoleService/OperateComputerMissionCanaryRun: - post: - tags: - - console.v1.ConsoleService - summary: OperateComputerMissionCanaryRun - operationId: console.v1.ConsoleService.OperateComputerMissionCanaryRun - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.OperateComputerMissionCanaryRunRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.OperateComputerMissionCanaryRunResponse' - /console.v1.ConsoleService/CreateMissionSchedule: - post: - tags: - - console.v1.ConsoleService - summary: CreateMissionSchedule - description: |- - CreateMissionSchedule persists a cron-scheduled recurring computer - mission. The worker's schedule runner claims due schedules and fires - missions through the same durable path as SubmitComputerMission. - operationId: console.v1.ConsoleService.CreateMissionSchedule - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateMissionScheduleRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateMissionScheduleResponse' - /console.v1.ConsoleService/UpdateMissionSchedule: - post: - tags: - - console.v1.ConsoleService - summary: UpdateMissionSchedule - description: |- - UpdateMissionSchedule replaces a schedule's cron expression, name, and - mission template. - operationId: console.v1.ConsoleService.UpdateMissionSchedule - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateMissionScheduleRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateMissionScheduleResponse' - /console.v1.ConsoleService/SetMissionScheduleEnabled: - post: - tags: - - console.v1.ConsoleService - summary: SetMissionScheduleEnabled - description: |- - SetMissionScheduleEnabled enables or disables a schedule without - changing its template. A disabled schedule is never claimed by the - worker. - operationId: console.v1.ConsoleService.SetMissionScheduleEnabled - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SetMissionScheduleEnabledRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SetMissionScheduleEnabledResponse' - /console.v1.ConsoleService/ListMissionSchedules: - post: - tags: - - console.v1.ConsoleService - summary: ListMissionSchedules - description: ListMissionSchedules returns the workspace's mission schedules. - operationId: console.v1.ConsoleService.ListMissionSchedules - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListMissionSchedulesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListMissionSchedulesResponse' - /console.v1.ConsoleService/CreateConnectorTrigger: - post: - tags: - - console.v1.ConsoleService - summary: CreateConnectorTrigger - description: |- - CreateConnectorTrigger binds a tenant-scoped mission template to either a - cron tick or an authenticated connector event. Event payloads are always - projected by the worker through the trigger's allowlist before they reach - the mission context; they never change the mission authority grant. - operationId: console.v1.ConsoleService.CreateConnectorTrigger - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateConnectorTriggerRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateConnectorTriggerResponse' - /console.v1.ConsoleService/UpdateConnectorTrigger: - post: - tags: - - console.v1.ConsoleService - summary: UpdateConnectorTrigger - operationId: console.v1.ConsoleService.UpdateConnectorTrigger - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateConnectorTriggerRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateConnectorTriggerResponse' - /console.v1.ConsoleService/ListConnectorTriggers: - post: - tags: - - console.v1.ConsoleService - summary: ListConnectorTriggers - operationId: console.v1.ConsoleService.ListConnectorTriggers - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListConnectorTriggersRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListConnectorTriggersResponse' - /console.v1.ConsoleService/DeleteConnectorTrigger: - post: - tags: - - console.v1.ConsoleService - summary: DeleteConnectorTrigger - operationId: console.v1.ConsoleService.DeleteConnectorTrigger - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DeleteConnectorTriggerRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DeleteConnectorTriggerResponse' - /console.v1.ConsoleService/SetConnectorTriggerEnabled: - post: - tags: - - console.v1.ConsoleService - summary: SetConnectorTriggerEnabled - operationId: console.v1.ConsoleService.SetConnectorTriggerEnabled - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SetConnectorTriggerEnabledRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SetConnectorTriggerEnabledResponse' - /console.v1.ConsoleService/ReserveComputerMissionApexSession: - post: - tags: - - console.v1.ConsoleService - summary: ReserveComputerMissionApexSession - description: |- - ReserveComputerMissionApexSession mints Platform-owned authority for one - exact, tenant-scoped APEX attempt and Runner Host create tuple. - operationId: console.v1.ConsoleService.ReserveComputerMissionApexSession - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReserveComputerMissionApexSessionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReserveComputerMissionApexSessionResponse' - /console.v1.ConsoleService/BindComputerMissionApexSessionReservation: - post: - tags: - - console.v1.ConsoleService - summary: BindComputerMissionApexSessionReservation - description: |- - BindComputerMissionApexSessionReservation binds one physical Runner Host - session to a previously issued reservation. - operationId: console.v1.ConsoleService.BindComputerMissionApexSessionReservation - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.BindComputerMissionApexSessionReservationRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.BindComputerMissionApexSessionReservationResponse' - /console.v1.ConsoleService/BindComputerMissionApexInstructionMetadata: - post: - tags: - - console.v1.ConsoleService - summary: BindComputerMissionApexInstructionMetadata - description: |- - BindComputerMissionApexInstructionMetadata seals the exact non-plaintext - instruction tuple after dataset staging and before Runner Host hydration. - operationId: console.v1.ConsoleService.BindComputerMissionApexInstructionMetadata - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.BindComputerMissionApexInstructionMetadataRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.BindComputerMissionApexInstructionMetadataResponse' - /console.v1.ConsoleService/AuthorizeComputerMissionApexSessionAdoption: - post: - tags: - - console.v1.ConsoleService - summary: AuthorizeComputerMissionApexSessionAdoption - description: |- - AuthorizeComputerMissionApexSessionAdoption declares the typed owner - response used by Task 4; its durable authorization transaction lands there. - operationId: console.v1.ConsoleService.AuthorizeComputerMissionApexSessionAdoption - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.AuthorizeComputerMissionApexSessionAdoptionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.AuthorizeComputerMissionApexSessionAdoptionResponse' - /console.v1.ConsoleService/GetWorkspaceSettings: - post: - tags: - - console.v1.ConsoleService - summary: GetWorkspaceSettings - description: |- - GetWorkspaceSettings returns the authenticated workspace settings summary. - It is the product contract for the Settings page: fields that are not yet - backed by an owning service are returned with explicit unavailable - capabilities instead of client-local values. - operationId: console.v1.ConsoleService.GetWorkspaceSettings - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - /console.v1.ConsoleService/GetOperatorPreferences: - post: - tags: - - console.v1.ConsoleService - summary: GetOperatorPreferences - description: |- - GetOperatorPreferences returns preferences owned by the authenticated - principal in this workspace. The principal id is always derived server-side. - operationId: console.v1.ConsoleService.GetOperatorPreferences - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOperatorPreferencesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOperatorPreferencesResponse' - /console.v1.ConsoleService/UpdateOperatorPreferences: - post: - tags: - - console.v1.ConsoleService - summary: UpdateOperatorPreferences - description: |- - UpdateOperatorPreferences stores preferences for the authenticated - principal only; callers cannot target another user's profile. - operationId: console.v1.ConsoleService.UpdateOperatorPreferences - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateOperatorPreferencesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateOperatorPreferencesResponse' - /console.v1.ConsoleService/CreateConnectorProfile: - post: - tags: - - console.v1.ConsoleService - summary: CreateConnectorProfile - description: |- - CreateConnectorProfile creates a named, scoped connector configuration. - connection_id is write-only and is never returned by profile reads. - operationId: console.v1.ConsoleService.CreateConnectorProfile - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateConnectorProfileRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateConnectorProfileResponse' - /console.v1.ConsoleService/ListConnectorProfiles: - post: - tags: - - console.v1.ConsoleService - summary: ListConnectorProfiles - description: ListConnectorProfiles returns the profiles configured for one connector. - operationId: console.v1.ConsoleService.ListConnectorProfiles - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListConnectorProfilesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListConnectorProfilesResponse' - /console.v1.ConsoleService/UpdateConnectorProfile: - post: - tags: - - console.v1.ConsoleService - summary: UpdateConnectorProfile - description: UpdateConnectorProfile updates mutable profile policy fields. - operationId: console.v1.ConsoleService.UpdateConnectorProfile - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateConnectorProfileRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateConnectorProfileResponse' - /console.v1.ConsoleService/DeleteConnectorProfile: - post: - tags: - - console.v1.ConsoleService - summary: DeleteConnectorProfile - description: |- - DeleteConnectorProfile deletes a profile while preserving the durable - opt-in marker that prevents legacy connector fallback. - operationId: console.v1.ConsoleService.DeleteConnectorProfile - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DeleteConnectorProfileRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DeleteConnectorProfileResponse' - /console.v1.ConsoleService/ListConnectedCalls: - post: - tags: - - console.v1.ConsoleService - summary: ListConnectedCalls - description: |- - ListConnectedCalls returns upcoming connected calls projected by the - tenant-scoped Connectors owner, whatever meeting platform hosts them. It - never exposes connection IDs or raw calendar payloads to the browser. - operationId: console.v1.ConsoleService.ListConnectedCalls - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListConnectedCallsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListConnectedCallsResponse' - /console.v1.ConsoleService/StartMeetingCapture: - post: - tags: - - console.v1.ConsoleService - summary: StartMeetingCapture - description: |- - StartMeetingCapture records an explicitly consented request for the - workspace's connected meeting bot to join one supported meeting, capture - its finalized transcript, and index it in Cerebro for tenant-scoped Dex - retrieval. The meeting is named either by a server-validated meeting URL or - by one opted-in connected calendar call. - operationId: console.v1.ConsoleService.StartMeetingCapture - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.StartMeetingCaptureRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.StartMeetingCaptureResponse' - /console.v1.ConsoleService/GetMeetingCapture: - post: - tags: - - console.v1.ConsoleService - summary: GetMeetingCapture - description: |- - GetMeetingCapture returns the durable provider, transcript, Cerebro index, - and retrieval projection for one tenant-scoped capture request. - operationId: console.v1.ConsoleService.GetMeetingCapture - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetMeetingCaptureRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetMeetingCaptureResponse' - /console.v1.ConsoleService/ListMeetingCaptures: - post: - tags: - - console.v1.ConsoleService - summary: ListMeetingCaptures - description: ListMeetingCaptures returns recent tenant-scoped meeting captures. - operationId: console.v1.ConsoleService.ListMeetingCaptures - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListMeetingCapturesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListMeetingCapturesResponse' - /console.v1.ConsoleService/StopMeetingCapture: - post: - tags: - - console.v1.ConsoleService - summary: StopMeetingCapture - description: |- - StopMeetingCapture records the user's request to cancel a scheduled bot or - make a joined bot leave. - operationId: console.v1.ConsoleService.StopMeetingCapture - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.StopMeetingCaptureRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.StopMeetingCaptureResponse' - /console.v1.ConsoleService/ListCommitments: - post: - tags: - - console.v1.ConsoleService - summary: ListCommitments - description: |- - ListCommitments returns the workspace's tracked commitments together with - the source citations each commitment was extracted from. - operationId: console.v1.ConsoleService.ListCommitments - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListCommitmentsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListCommitmentsResponse' - /console.v1.ConsoleService/GetBillingSubscription: - post: - tags: - - console.v1.ConsoleService - summary: GetBillingSubscription - description: |- - GetBillingSubscription returns the typed billing subscription summary used - by Settings. A configured provider enriches the durable workspace billing - settings state. Billing portal sessions are created separately on demand. - operationId: console.v1.ConsoleService.GetBillingSubscription - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetBillingSubscriptionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetBillingSubscriptionResponse' - /console.v1.ConsoleService/CreateBillingPortalSession: - post: - tags: - - console.v1.ConsoleService - summary: CreateBillingPortalSession - description: |- - CreateBillingPortalSession creates a short-lived provider-hosted portal - session for the authenticated workspace. The return URL is server-owned. - operationId: console.v1.ConsoleService.CreateBillingPortalSession - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateBillingPortalSessionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateBillingPortalSessionResponse' - /console.v1.ConsoleService/CreateBillingCheckoutSession: - post: - tags: - - console.v1.ConsoleService - summary: CreateBillingCheckoutSession - description: |- - CreateBillingCheckoutSession starts provider-hosted, customer-consented - annual subscription enrollment at the server-owned contributor minimum. - operationId: console.v1.ConsoleService.CreateBillingCheckoutSession - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateBillingCheckoutSessionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateBillingCheckoutSessionResponse' - /console.v1.ConsoleService/GetInferenceCreditBalance: - post: - tags: - - console.v1.ConsoleService - summary: GetInferenceCreditBalance - description: GetInferenceCreditBalance uses the authorized workspace's prepaid inference account. - operationId: console.v1.ConsoleService.GetInferenceCreditBalance - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetInferenceCreditBalanceRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetInferenceCreditBalanceResponse' - /console.v1.ConsoleService/CreateInferenceCreditCheckout: - post: - tags: - - console.v1.ConsoleService - summary: CreateInferenceCreditCheckout - description: CreateInferenceCreditCheckout uses the authorized workspace's prepaid inference account. - operationId: console.v1.ConsoleService.CreateInferenceCreditCheckout - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateInferenceCreditCheckoutRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateInferenceCreditCheckoutResponse' - /console.v1.ConsoleService/FulfillInferenceCreditCheckout: - post: - tags: - - console.v1.ConsoleService - summary: FulfillInferenceCreditCheckout - description: FulfillInferenceCreditCheckout uses the authorized workspace's prepaid inference account. - operationId: console.v1.ConsoleService.FulfillInferenceCreditCheckout - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.FulfillInferenceCreditCheckoutRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.FulfillInferenceCreditCheckoutResponse' - /console.v1.ConsoleService/UpdateWorkspaceProfile: - post: - tags: - - console.v1.ConsoleService - summary: UpdateWorkspaceProfile - description: |- - UpdateWorkspaceProfile stores workspace-facing Settings metadata such as - labels, environment, and region. - operationId: console.v1.ConsoleService.UpdateWorkspaceProfile - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateWorkspaceProfileRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateWorkspaceProfileResponse' - /console.v1.ConsoleService/ArchiveWorkspace: - post: - tags: - - console.v1.ConsoleService - summary: ArchiveWorkspace - description: |- - ArchiveWorkspace toggles the Console-owned archived state for this - workspace. Downstream lifecycle deletion remains separate. - operationId: console.v1.ConsoleService.ArchiveWorkspace - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ArchiveWorkspaceRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ArchiveWorkspaceResponse' - /console.v1.ConsoleService/UpdateWorkspacePolicy: - post: - tags: - - console.v1.ConsoleService - summary: UpdateWorkspacePolicy - description: |- - UpdateWorkspacePolicy stores the Settings governance policy envelope used - by Console surfaces. - operationId: console.v1.ConsoleService.UpdateWorkspacePolicy - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateWorkspacePolicyRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateWorkspacePolicyResponse' - /console.v1.ConsoleService/UpdateWorkspaceDexPolicy: - post: - tags: - - console.v1.ConsoleService - summary: UpdateWorkspaceDexPolicy - description: |- - UpdateWorkspaceDexPolicy stores the operator-controlled execution, - memory, learning, and trace-content boundaries for Dex. - operationId: console.v1.ConsoleService.UpdateWorkspaceDexPolicy - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateWorkspaceDexPolicyRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateWorkspaceDexPolicyResponse' - /console.v1.ConsoleService/UpdateWorkspaceArtifactStyleGuide: - post: - tags: - - console.v1.ConsoleService - summary: UpdateWorkspaceArtifactStyleGuide - description: |- - UpdateWorkspaceArtifactStyleGuide stores the workspace-owned writing and - presentation contract that Dex must apply to generated artifacts. - operationId: console.v1.ConsoleService.UpdateWorkspaceArtifactStyleGuide - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateWorkspaceArtifactStyleGuideRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateWorkspaceArtifactStyleGuideResponse' - /console.v1.ConsoleService/EvaluateWorkspaceArtifactStyleGuide: - post: - tags: - - console.v1.ConsoleService - summary: EvaluateWorkspaceArtifactStyleGuide - description: |- - EvaluateWorkspaceArtifactStyleGuide tests unsaved policy controls against - sample response text without mutating workspace settings. - operationId: console.v1.ConsoleService.EvaluateWorkspaceArtifactStyleGuide - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.EvaluateWorkspaceArtifactStyleGuideRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.EvaluateWorkspaceArtifactStyleGuideResponse' - /console.v1.ConsoleService/UpsertWorkspaceIdentityProvider: - post: - tags: - - console.v1.ConsoleService - summary: UpsertWorkspaceIdentityProvider - description: UpsertWorkspaceIdentityProvider stores or updates an identity provider row. - operationId: console.v1.ConsoleService.UpsertWorkspaceIdentityProvider - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpsertWorkspaceIdentityProviderRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpsertWorkspaceIdentityProviderResponse' - /console.v1.ConsoleService/RemoveWorkspaceIdentityProvider: - post: - tags: - - console.v1.ConsoleService - summary: RemoveWorkspaceIdentityProvider - description: RemoveWorkspaceIdentityProvider removes a Console-owned identity provider row. - operationId: console.v1.ConsoleService.RemoveWorkspaceIdentityProvider - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RemoveWorkspaceIdentityProviderRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RemoveWorkspaceIdentityProviderResponse' - /console.v1.ConsoleService/UpsertWorkspaceIntegration: - post: - tags: - - console.v1.ConsoleService - summary: UpsertWorkspaceIntegration - description: |- - UpsertWorkspaceIntegration stores or updates a Console-owned integration - settings row. - operationId: console.v1.ConsoleService.UpsertWorkspaceIntegration - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpsertWorkspaceIntegrationRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpsertWorkspaceIntegrationResponse' - /console.v1.ConsoleService/RemoveWorkspaceIntegration: - post: - tags: - - console.v1.ConsoleService - summary: RemoveWorkspaceIntegration - description: RemoveWorkspaceIntegration removes a Console-owned integration settings row. - operationId: console.v1.ConsoleService.RemoveWorkspaceIntegration - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RemoveWorkspaceIntegrationRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RemoveWorkspaceIntegrationResponse' - /console.v1.ConsoleService/UpdateWorkspaceBilling: - post: - tags: - - console.v1.ConsoleService - summary: UpdateWorkspaceBilling - description: |- - UpdateWorkspaceBilling stores the workspace billing summary displayed in - Settings. Until a dedicated billing service is connected to Console, this - is the durable operator-managed billing read model. - operationId: console.v1.ConsoleService.UpdateWorkspaceBilling - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateWorkspaceBillingRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - /console.v1.ConsoleService/UpsertWorkspaceMember: - post: - tags: - - console.v1.ConsoleService - summary: UpsertWorkspaceMember - description: UpsertWorkspaceMember stores or updates a workspace member row. - operationId: console.v1.ConsoleService.UpsertWorkspaceMember - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpsertWorkspaceMemberRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - /console.v1.ConsoleService/RemoveWorkspaceMember: - post: - tags: - - console.v1.ConsoleService - summary: RemoveWorkspaceMember - description: RemoveWorkspaceMember removes a workspace member row. - operationId: console.v1.ConsoleService.RemoveWorkspaceMember - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RemoveWorkspaceMemberRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - /console.v1.ConsoleService/UpdateWorkspaceNotificationPreferences: - post: - tags: - - console.v1.ConsoleService - summary: UpdateWorkspaceNotificationPreferences - description: |- - UpdateWorkspaceNotificationPreferences stores Settings notification - preferences for the workspace/current operator view. - operationId: console.v1.ConsoleService.UpdateWorkspaceNotificationPreferences - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateWorkspaceNotificationPreferencesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - /console.v1.ConsoleService/EnableWorkspaceBreakGlass: - post: - tags: - - console.v1.ConsoleService - summary: EnableWorkspaceBreakGlass - description: |- - EnableWorkspaceBreakGlass records a customer-approved read-only support - access grant. The grant is durable and remains active until disabled. - operationId: console.v1.ConsoleService.EnableWorkspaceBreakGlass - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.EnableWorkspaceBreakGlassRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - /console.v1.ConsoleService/DisableWorkspaceBreakGlass: - post: - tags: - - console.v1.ConsoleService - summary: DisableWorkspaceBreakGlass - description: DisableWorkspaceBreakGlass deactivates the active support access grant. - operationId: console.v1.ConsoleService.DisableWorkspaceBreakGlass - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DisableWorkspaceBreakGlassRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - /console.v1.ConsoleService/ListWorkspaceSkills: - post: - tags: - - console.v1.ConsoleService - summary: ListWorkspaceSkills - description: |- - ListWorkspaceSkills returns the workspace-scoped Dex procedural-memory - catalog, including body, for the Settings management surface. The Dex - runtime's separate skill.list tool returns only name + description. - operationId: console.v1.ConsoleService.ListWorkspaceSkills - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListWorkspaceSkillsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListWorkspaceSkillsResponse' - /console.v1.ConsoleService/BrowseDexSkillCatalog: - post: - tags: - - console.v1.ConsoleService - summary: BrowseDexSkillCatalog - description: |- - BrowseDexSkillCatalog lists platform-curated procedures and their - installation state for the selected workspace. - operationId: console.v1.ConsoleService.BrowseDexSkillCatalog - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.BrowseDexSkillCatalogRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.BrowseDexSkillCatalogResponse' - /console.v1.ConsoleService/InstallDexSkillCatalogEntry: - post: - tags: - - console.v1.ConsoleService - summary: InstallDexSkillCatalogEntry - description: |- - InstallDexSkillCatalogEntry copies a curated procedure into the - workspace skill store and appends its audit event atomically. - operationId: console.v1.ConsoleService.InstallDexSkillCatalogEntry - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.InstallDexSkillCatalogEntryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.InstallDexSkillCatalogEntryResponse' - /console.v1.ConsoleService/CreateWorkspaceSkill: - post: - tags: - - console.v1.ConsoleService - summary: CreateWorkspaceSkill - description: |- - CreateWorkspaceSkill stores a new named Dex skill for this workspace. - Fails if a skill with the same name already exists; use - UpdateWorkspaceSkill to revise an existing one. - operationId: console.v1.ConsoleService.CreateWorkspaceSkill - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateWorkspaceSkillRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateWorkspaceSkillResponse' - /console.v1.ConsoleService/UpdateWorkspaceSkill: - post: - tags: - - console.v1.ConsoleService - summary: UpdateWorkspaceSkill - description: |- - UpdateWorkspaceSkill revises an existing named skill's description/body - and increments its version. Fails if the named skill does not exist. - operationId: console.v1.ConsoleService.UpdateWorkspaceSkill - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateWorkspaceSkillRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateWorkspaceSkillResponse' - /console.v1.ConsoleService/DeleteWorkspaceSkill: - post: - tags: - - console.v1.ConsoleService - summary: DeleteWorkspaceSkill - description: |- - DeleteWorkspaceSkill removes a named skill from this workspace. No-op if - the skill does not exist. - operationId: console.v1.ConsoleService.DeleteWorkspaceSkill - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DeleteWorkspaceSkillRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DeleteWorkspaceSkillResponse' - /console.v1.ConsoleService/ListScenarioFixtures: - post: - tags: - - console.v1.ConsoleService - summary: ListScenarioFixtures - description: ListScenarioFixtures returns Maestro replay fixtures promoted for this workspace. - operationId: console.v1.ConsoleService.ListScenarioFixtures - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListScenarioFixturesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListScenarioFixturesResponse' - /console.v1.ConsoleService/PromoteScenarioFixture: - post: - tags: - - console.v1.ConsoleService - summary: PromoteScenarioFixture - description: PromoteScenarioFixture stores a recorded Maestro replay scenario as an immutable fixture. - operationId: console.v1.ConsoleService.PromoteScenarioFixture - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.PromoteScenarioFixtureRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.PromoteScenarioFixtureResponse' - /console.v1.ConsoleService/CompareScenarioFixtures: - post: - tags: - - console.v1.ConsoleService - summary: CompareScenarioFixtures - description: CompareScenarioFixtures returns a compact diff between two promoted replay fixtures. - operationId: console.v1.ConsoleService.CompareScenarioFixtures - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CompareScenarioFixturesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CompareScenarioFixturesResponse' - /console.v1.ConsoleService/ListWorkspaceGuardrailRules: - post: - tags: - - console.v1.ConsoleService - summary: ListWorkspaceGuardrailRules - description: |- - ListWorkspaceGuardrailRules returns the workspace-configured content - guardrail rules evaluated over Dex model output. An unconfigured workspace - returns an empty set, which the runner treats as a no-op. - operationId: console.v1.ConsoleService.ListWorkspaceGuardrailRules - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListWorkspaceGuardrailRulesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListWorkspaceGuardrailRulesResponse' - /console.v1.ConsoleService/UpsertWorkspaceGuardrailRule: - post: - tags: - - console.v1.ConsoleService - summary: UpsertWorkspaceGuardrailRule - description: |- - UpsertWorkspaceGuardrailRule creates or replaces one content guardrail rule - by id in the caller's workspace. - operationId: console.v1.ConsoleService.UpsertWorkspaceGuardrailRule - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpsertWorkspaceGuardrailRuleRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListWorkspaceGuardrailRulesResponse' - /console.v1.ConsoleService/RemoveWorkspaceGuardrailRule: - post: - tags: - - console.v1.ConsoleService - summary: RemoveWorkspaceGuardrailRule - description: RemoveWorkspaceGuardrailRule deletes one content guardrail rule by id. - operationId: console.v1.ConsoleService.RemoveWorkspaceGuardrailRule - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RemoveWorkspaceGuardrailRuleRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListWorkspaceGuardrailRulesResponse' - /console.v1.ConsoleService/SetOperatingThreadController: - post: - tags: - - console.v1.ConsoleService - summary: SetOperatingThreadController - description: |- - SetOperatingThreadController transfers the live Computer controller - between Dex and the authenticated operator. The request is fenced by the - current runtime generation, replay cursor, and runtime lease generation; - a stale browser cannot steal or resume a newer controller lease. - operationId: console.v1.ConsoleService.SetOperatingThreadController - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SetOperatingThreadControllerRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SetOperatingThreadControllerResponse' - /console.v1.ConsoleService/GetPrivacySettings: - post: - tags: - - console.v1.ConsoleService - summary: GetPrivacySettings - description: |- - GetPrivacySettings returns the tenant privacy mode that platform-api seals - into every OperationContext for this tenant: the organization-wide row, the - workspace override when one exists, and the effective mode that results. - operationId: console.v1.ConsoleService.GetPrivacySettings - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetPrivacySettingsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetPrivacySettingsResponse' - /console.v1.ConsoleService/SetPrivacySettings: - post: - tags: - - console.v1.ConsoleService - summary: SetPrivacySettings - description: |- - SetPrivacySettings writes the organization-wide privacy mode or one - workspace override. Loosening the mode is a governance change, so this - carries the Console write scope rather than the read scope every member - holds. - operationId: console.v1.ConsoleService.SetPrivacySettings - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SetPrivacySettingsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetPrivacySettingsResponse' - /console.v1.ConsoleService/CreateProspectingWatchProgram: - post: - tags: - - console.v1.ConsoleService - summary: CreateProspectingWatchProgram - description: |- - CreateProspectingWatchProgram records a staff-authored Radar watch - program for one exact provider organization and workspace. - operationId: console.v1.ConsoleService.CreateProspectingWatchProgram - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateProspectingWatchProgramRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateProspectingWatchProgramResponse' - /console.v1.ConsoleService/GetProspectingWatchProgram: - post: - tags: - - console.v1.ConsoleService - summary: GetProspectingWatchProgram - description: GetProspectingWatchProgram returns one exact Radar watch program. - operationId: console.v1.ConsoleService.GetProspectingWatchProgram - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetProspectingWatchProgramRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetProspectingWatchProgramResponse' - /console.v1.ConsoleService/ListProspectingWatchPrograms: - post: - tags: - - console.v1.ConsoleService - summary: ListProspectingWatchPrograms - description: |- - ListProspectingWatchPrograms returns bounded Radar watch programs for an - exact provider organization and workspace. - operationId: console.v1.ConsoleService.ListProspectingWatchPrograms - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListProspectingWatchProgramsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListProspectingWatchProgramsResponse' - /console.v1.ConsoleService/UpdateProspectingWatchProgram: - post: - tags: - - console.v1.ConsoleService - summary: UpdateProspectingWatchProgram - description: |- - UpdateProspectingWatchProgram replaces a Radar watch-program revision with - optimistic concurrency, reason, and idempotency requirements. - operationId: console.v1.ConsoleService.UpdateProspectingWatchProgram - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateProspectingWatchProgramRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateProspectingWatchProgramResponse' - /console.v1.ConsoleService/CreateProspectingDraft: - post: - tags: - - console.v1.ConsoleService - summary: CreateProspectingDraft - description: |- - CreateProspectingDraft records a staff-authored Radar outreach draft for - one exact provider organization and workspace. It holds the draft for - review and never delivers it. - operationId: console.v1.ConsoleService.CreateProspectingDraft - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateProspectingDraftRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateProspectingDraftResponse' - /console.v1.ConsoleService/ListProspectingDrafts: - post: - tags: - - console.v1.ConsoleService - summary: ListProspectingDrafts - description: |- - ListProspectingDrafts returns bounded Radar outreach drafts for an exact - provider organization and workspace. - operationId: console.v1.ConsoleService.ListProspectingDrafts - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListProspectingDraftsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListProspectingDraftsResponse' - /console.v1.ConsoleService/ReviewProspectingDraft: - post: - tags: - - console.v1.ConsoleService - summary: ReviewProspectingDraft - description: |- - ReviewProspectingDraft records an approval or rejection against an exact - draft revision. Approval is a review decision and is never delivery - authority. - operationId: console.v1.ConsoleService.ReviewProspectingDraft - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReviewProspectingDraftRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReviewProspectingDraftResponse' - /console.v1.ConsoleService/RecordOperatingHomepageSuggestionFeedback: - post: - tags: - - console.v1.ConsoleService - summary: RecordOperatingHomepageSuggestionFeedback - description: |- - RecordOperatingHomepageSuggestionFeedback changes only the authenticated - principal's short-lived homepage projection. It never deletes the source - conversation or Cerebro evidence. Declared last to avoid renumbering - unrelated generated RPC descriptors. - operationId: console.v1.ConsoleService.RecordOperatingHomepageSuggestionFeedback - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RecordOperatingHomepageSuggestionFeedbackRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RecordOperatingHomepageSuggestionFeedbackResponse' - /console.v1.WorkspaceKeyService/GetWorkspaceKeyConfig: - post: - tags: - - console.v1.WorkspaceKeyService - summary: GetWorkspaceKeyConfig - description: GetWorkspaceKeyConfig returns the effective custody configuration. - operationId: console.v1.WorkspaceKeyService.GetWorkspaceKeyConfig - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetWorkspaceKeyConfigRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.WorkspaceKeyConfigResponse' - /console.v1.WorkspaceKeyService/PutWorkspaceKeyConfig: - post: - tags: - - console.v1.WorkspaceKeyService - summary: PutWorkspaceKeyConfig - description: PutWorkspaceKeyConfig selects the provider and key for future managed-credential uploads. - operationId: console.v1.WorkspaceKeyService.PutWorkspaceKeyConfig - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.PutWorkspaceKeyConfigRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.WorkspaceKeyConfigResponse' - /console.v1.WorkspaceKeyService/DeleteWorkspaceKeyConfig: - post: - tags: - - console.v1.WorkspaceKeyService - summary: DeleteWorkspaceKeyConfig - description: DeleteWorkspaceKeyConfig returns the workspace to platform-managed custody. - operationId: console.v1.WorkspaceKeyService.DeleteWorkspaceKeyConfig - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DeleteWorkspaceKeyConfigRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.WorkspaceKeyConfigResponse' - /console.v1.ManagedSetupService/GetManagedSetup: - post: - tags: - - console.v1.ManagedSetupService - summary: GetManagedSetup - description: |- - GetManagedSetup returns the effective managed setup document for a tenant, - preferring the workspace override over the organization document. - operationId: console.v1.ManagedSetupService.GetManagedSetup - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetManagedSetupRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ManagedSetup' - /console.v1.ManagedSetupService/SetManagedSetup: - post: - tags: - - console.v1.ManagedSetupService - summary: SetManagedSetup - description: |- - SetManagedSetup replaces the managed setup document for a tenant and - returns the stored revision with its new version. - operationId: console.v1.ManagedSetupService.SetManagedSetup - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SetManagedSetupRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ManagedSetup' -components: - schemas: - agentruntime.v1.RuntimeWorkEnvelopeKind: - type: string - title: RuntimeWorkEnvelopeKind - enum: - - RUNTIME_WORK_ENVELOPE_KIND_UNSPECIFIED - - RUNTIME_WORK_ENVELOPE_KIND_CONVERSATION_THREAD - - RUNTIME_WORK_ENVELOPE_KIND_DIRECT_CONVERSATION - - RUNTIME_WORK_ENVELOPE_KIND_TICKET - - RUNTIME_WORK_ENVELOPE_KIND_CALENDAR_EVENT - - RUNTIME_WORK_ENVELOPE_KIND_PULL_REQUEST - - RUNTIME_WORK_ENVELOPE_KIND_INCIDENT - - RUNTIME_WORK_ENVELOPE_KIND_REPOSITORY - - RUNTIME_WORK_ENVELOPE_KIND_DOCUMENT - - RUNTIME_WORK_ENVELOPE_KIND_RECORD - description: |- - RuntimeWorkEnvelopeKind classifies the durable human/work object a trigger - belongs to. Envelopes group retries and follow-up messages across channels - without making the runtime depend on Slack-specific string labels. - agents.v1.AgentStatus: - type: string - title: AgentStatus - enum: - - AGENT_STATUS_UNSPECIFIED - - AGENT_STATUS_ACTIVE - - AGENT_STATUS_IDLE - - AGENT_STATUS_BUSY - - AGENT_STATUS_OFFLINE - - AGENT_STATUS_DEGRADED - - AGENT_STATUS_SUSPENDED - description: AgentStatus describes the operational state of an agent. - agents.v1.AutonomyAuthority: - type: string - title: AutonomyAuthority - enum: - - AUTONOMY_AUTHORITY_UNSPECIFIED - - AUTONOMY_AUTHORITY_OWN - - AUTONOMY_AUTHORITY_RECOMMEND - - AUTONOMY_AUTHORITY_REQUIRE_APPROVAL - - AUTONOMY_AUTHORITY_DENY - description: AutonomyAuthority describes how independently a teammate may act. - agents.v1.CommitmentKind: - type: string - title: CommitmentKind - enum: - - COMMITMENT_KIND_UNSPECIFIED - - COMMITMENT_KIND_FOLLOW_UP - - COMMITMENT_KIND_WATCH - - COMMITMENT_KIND_RETRY - - COMMITMENT_KIND_SUMMARIZE - - COMMITMENT_KIND_MONITOR - - COMMITMENT_KIND_REMEDIATE - - COMMITMENT_KIND_HANDOFF - description: CommitmentKind describes the durable commitments a teammate can accept. - agents.v1.InitiativeTriggerKind: - type: string - title: InitiativeTriggerKind - enum: - - INITIATIVE_TRIGGER_KIND_UNSPECIFIED - - INITIATIVE_TRIGGER_KIND_SCHEDULE - - INITIATIVE_TRIGGER_KIND_SLACK_EVENT - - INITIATIVE_TRIGGER_KIND_PLATFORM_EVENT - - INITIATIVE_TRIGGER_KIND_OBJECTIVE_WAKE - - INITIATIVE_TRIGGER_KIND_WAIT_RESOLVED - - INITIATIVE_TRIGGER_KIND_EVAL_REGRESSION - - INITIATIVE_TRIGGER_KIND_STALLED_WORK - description: |- - InitiativeTriggerKind describes events that can let a teammate start work - without a fresh direct human prompt. - agents.v1.PresenceEvent: - type: string - title: PresenceEvent - enum: - - PRESENCE_EVENT_UNSPECIFIED - - PRESENCE_EVENT_ACCEPTED - - PRESENCE_EVENT_WAITING - - PRESENCE_EVENT_PROGRESS - - PRESENCE_EVENT_BLOCKED - - PRESENCE_EVENT_COMPLETED - - PRESENCE_EVENT_FAILED - - PRESENCE_EVENT_ESCALATED - description: PresenceEvent describes channel-visible teammate activity. - agents.v1.TeammateChannelCapability: - type: string - title: TeammateChannelCapability - enum: - - TEAMMATE_CHANNEL_CAPABILITY_UNSPECIFIED - - TEAMMATE_CHANNEL_CAPABILITY_INGEST - - TEAMMATE_CHANNEL_CAPABILITY_RENDER - description: |- - TeammateChannelCapability describes what a channel adapter can do for a - teammate profile. - agents.v1.TeammateChannelEventKind: - type: string - title: TeammateChannelEventKind - enum: - - TEAMMATE_CHANNEL_EVENT_KIND_UNSPECIFIED - - TEAMMATE_CHANNEL_EVENT_KIND_MESSAGE_CREATED - - TEAMMATE_CHANNEL_EVENT_KIND_THREAD_REPLY_CREATED - - TEAMMATE_CHANNEL_EVENT_KIND_COMMAND_INVOKED - - TEAMMATE_CHANNEL_EVENT_KIND_ACTION_INVOKED - - TEAMMATE_CHANNEL_EVENT_KIND_REACTION_ADDED - - TEAMMATE_CHANNEL_EVENT_KIND_REACTION_REMOVED - - TEAMMATE_CHANNEL_EVENT_KIND_ASSISTANT_THREAD_STARTED - - TEAMMATE_CHANNEL_EVENT_KIND_ASSISTANT_THREAD_CONTEXT_CHANGED - - TEAMMATE_CHANNEL_EVENT_KIND_EMAIL_RECEIVED - - TEAMMATE_CHANNEL_EVENT_KIND_CALENDAR_EVENT_CHANGED - - TEAMMATE_CHANNEL_EVENT_KIND_ISSUE_CHANGED - - TEAMMATE_CHANNEL_EVENT_KIND_SCHEDULED_WAKE - - TEAMMATE_CHANNEL_EVENT_KIND_WEBHOOK_RECEIVED - description: |- - TeammateChannelEventKind describes normalized inbound channel events that can - become AgentRuntime triggers. - agents.v1.TeammateChannelKind: - type: string - title: TeammateChannelKind - enum: - - TEAMMATE_CHANNEL_KIND_UNSPECIFIED - - TEAMMATE_CHANNEL_KIND_SLACK - - TEAMMATE_CHANNEL_KIND_EMAIL - - TEAMMATE_CHANNEL_KIND_CALENDAR - - TEAMMATE_CHANNEL_KIND_JIRA - - TEAMMATE_CHANNEL_KIND_TEAMS - - TEAMMATE_CHANNEL_KIND_WEB - - TEAMMATE_CHANNEL_KIND_WEBHOOK - - TEAMMATE_CHANNEL_KIND_WHATSAPP - - TEAMMATE_CHANNEL_KIND_APPLE_MESSAGES - description: |- - TeammateChannelKind identifies a product or provider channel that can ingest - user activity or render teammate runtime events. It intentionally lives in - agents/v1 instead of agentruntime/v1 so teammate profiles can describe - supported channels without creating a proto import cycle. - agents.v1.TeammateLifecycle: - type: string - title: TeammateLifecycle - enum: - - TEAMMATE_LIFECYCLE_UNSPECIFIED - - TEAMMATE_LIFECYCLE_DRAFT - - TEAMMATE_LIFECYCLE_ACTIVE - - TEAMMATE_LIFECYCLE_PAUSED - - TEAMMATE_LIFECYCLE_DEPRECATED - description: |- - TeammateLifecycle describes whether a teammate profile can be used to - initiate durable work. - agents.v1.TeammateRuntimeRenderEventKind: - type: string - title: TeammateRuntimeRenderEventKind - enum: - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_UNSPECIFIED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_TRIGGER_ACCEPTED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_RUN_STARTED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_PROGRESS - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_STEP_STARTED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_STEP_COMPLETED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_OBJECTIVE_UPDATED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_APPROVAL_REQUESTED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_APPROVAL_RESOLVED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_TOOL_PROPOSED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_TOOL_COMPLETED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_ARTIFACT_CREATED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_MEMORY_PROPOSED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_WAITING - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_RESUMED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_COMPLETED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_FAILED - description: |- - TeammateRuntimeRenderEventKind describes Platform runtime events a channel - adapter can project back into the provider surface. - common.v1.DeliveryChannel: - type: string - title: DeliveryChannel - enum: - - DELIVERY_CHANNEL_UNSPECIFIED - - DELIVERY_CHANNEL_SLACK - - DELIVERY_CHANNEL_EMAIL - - DELIVERY_CHANNEL_WEBHOOK - - DELIVERY_CHANNEL_IN_APP - - DELIVERY_CHANNEL_PUSH - description: DeliveryChannel identifies the notification delivery channel. - common.v1.EntityType: - type: string - title: EntityType - enum: - - ENTITY_TYPE_UNSPECIFIED - - ENTITY_TYPE_CONTACT - - ENTITY_TYPE_COMPANY - - ENTITY_TYPE_DEAL - - ENTITY_TYPE_TICKET - - ENTITY_TYPE_CUSTOMER - - ENTITY_TYPE_OPPORTUNITY - description: EntityType identifies the kind of entity across systems. - common.v1.RiskLevel: - type: string - title: RiskLevel - enum: - - RISK_LEVEL_UNSPECIFIED - - RISK_LEVEL_LOW - - RISK_LEVEL_MEDIUM - - RISK_LEVEL_HIGH - - RISK_LEVEL_CRITICAL - description: RiskLevel classifies the risk of an action. - common.v1.Surface: - type: string - title: Surface - enum: - - SURFACE_UNSPECIFIED - - SURFACE_ENSEMBLE - - SURFACE_CHAT - - SURFACE_MAESTRO - - SURFACE_CONDUCTOR - - SURFACE_SLACK - - SURFACE_EXTERNAL_AGENT - description: |- - Surface identifies the product or channel surface that originated a platform - action. It is shared by runtime, audit, and product-facing services so - callers do not invent drift-prone string labels. - connectors.v1.ConnectorEvidenceKind: - type: string - title: ConnectorEvidenceKind - enum: - - CONNECTOR_EVIDENCE_KIND_UNSPECIFIED - - CONNECTOR_EVIDENCE_KIND_PROBE - - CONNECTOR_EVIDENCE_KIND_FIXTURE - - CONNECTOR_EVIDENCE_KIND_CANARY - - CONNECTOR_EVIDENCE_KIND_PRODUCTION - - CONNECTOR_EVIDENCE_KIND_UNPROVABLE_UNAUTHENTICATED - description: |- - ConnectorEvidenceKind identifies the bounded evidence supporting a catalog - verification level. It does not establish credential validity or transport - availability. - connectors.v1.ConnectorVerificationLevel: - type: string - title: ConnectorVerificationLevel - enum: - - CONNECTOR_VERIFICATION_LEVEL_UNSPECIFIED - - CONNECTOR_VERIFICATION_LEVEL_DECLARED - - CONNECTOR_VERIFICATION_LEVEL_SPEC_DERIVED - - CONNECTOR_VERIFICATION_LEVEL_FIXTURE_VERIFIED - - CONNECTOR_VERIFICATION_LEVEL_LIVE_VERIFIED - - CONNECTOR_VERIFICATION_LEVEL_CONTINUOUSLY_VERIFIED - description: |- - ConnectorVerificationLevel is the fail-closed evidence ladder for a - connector catalog subject. Higher levels require the canonical verification - ledger to contain evidence that justifies the promotion. - connectors.v1.HealthStatus: - type: string - title: HealthStatus - enum: - - HEALTH_STATUS_UNSPECIFIED - - HEALTH_STATUS_HEALTHY - - HEALTH_STATUS_DEGRADED - - HEALTH_STATUS_UNHEALTHY - - HEALTH_STATUS_UNKNOWN - description: HealthStatus describes the health state of a connection. - connectors.v1.ProviderContentTrust: - type: string - title: ProviderContentTrust - enum: - - PROVIDER_CONTENT_TRUST_UNSPECIFIED - - PROVIDER_CONTENT_TRUST_UNTRUSTED_PROVIDER_CONTENT - connectors.v1.ProviderResourceLifecycleState: - type: string - title: ProviderResourceLifecycleState - enum: - - PROVIDER_RESOURCE_LIFECYCLE_STATE_UNSPECIFIED - - PROVIDER_RESOURCE_LIFECYCLE_STATE_ACTIVE - - PROVIDER_RESOURCE_LIFECYCLE_STATE_ARCHIVED - - PROVIDER_RESOURCE_LIFECYCLE_STATE_DELETED - - PROVIDER_RESOURCE_LIFECYCLE_STATE_CONNECTION_REVOKED - - PROVIDER_RESOURCE_LIFECYCLE_STATE_QUARANTINED - connectors.v1.ProviderResourceVisibilityClass: - type: string - title: ProviderResourceVisibilityClass - enum: - - PROVIDER_RESOURCE_VISIBILITY_CLASS_UNSPECIFIED - - PROVIDER_RESOURCE_VISIBILITY_CLASS_WORKSPACE_PUBLIC - - PROVIDER_RESOURCE_VISIBILITY_CLASS_EXPLICIT_PRINCIPALS - - PROVIDER_RESOURCE_VISIBILITY_CLASS_GROUP_MEMBERSHIP - - PROVIDER_RESOURCE_VISIBILITY_CLASS_CONNECTION_PRIVATE - connectors.v1.SourceAuthorityFreshnessMethod: - type: string - title: SourceAuthorityFreshnessMethod - enum: - - SOURCE_AUTHORITY_FRESHNESS_METHOD_UNSPECIFIED - - SOURCE_AUTHORITY_FRESHNESS_METHOD_NOT_OBSERVED - - SOURCE_AUTHORITY_FRESHNESS_METHOD_INTROSPECTION - - SOURCE_AUTHORITY_FRESHNESS_METHOD_WEBHOOK - - SOURCE_AUTHORITY_FRESHNESS_METHOD_POLLING - - SOURCE_AUTHORITY_FRESHNESS_METHOD_SHORT_TTL - - SOURCE_AUTHORITY_FRESHNESS_METHOD_REFRESH_FAILURE - description: |- - SourceAuthorityFreshnessMethod identifies how the source observation was - obtained. NOT_OBSERVED is the explicit default when no authoritative - producer has supplied a response; it is not evidence of source access. - connectors.v1.SourceAuthorityState: - type: string - title: SourceAuthorityState - enum: - - SOURCE_AUTHORITY_STATE_UNSPECIFIED - - SOURCE_AUTHORITY_STATE_SUFFICIENT - - SOURCE_AUTHORITY_STATE_INSUFFICIENT - - SOURCE_AUTHORITY_STATE_UNKNOWN - - SOURCE_AUTHORITY_STATE_REVOKED - description: |- - SourceAuthorityState is the external source system's authority posture for - a connection. A locally active row is not source authority; callers must - receive an explicit UNKNOWN observation until an authoritative producer - reports otherwise. - console.v1.BusinessFieldKind: - type: string - title: BusinessFieldKind - enum: - - BUSINESS_FIELD_KIND_UNSPECIFIED - - BUSINESS_FIELD_KIND_TEXT - - BUSINESS_FIELD_KIND_INTEGER - - BUSINESS_FIELD_KIND_BOOLEAN - - BUSINESS_FIELD_KIND_DECIMAL - - BUSINESS_FIELD_KIND_MONEY - - BUSINESS_FIELD_KIND_ENUM - - BUSINESS_FIELD_KIND_DATE - - BUSINESS_FIELD_KIND_TIMESTAMP - - BUSINESS_FIELD_KIND_REFERENCE - - BUSINESS_FIELD_KIND_ARTIFACT - - BUSINESS_FIELD_KIND_TEXT_LIST - description: Customer-defined business schemas. Field and relationship IDs remain stable across versions. - console.v1.BusinessObjectRecordKind: - type: string - title: BusinessObjectRecordKind - enum: - - BUSINESS_OBJECT_RECORD_KIND_UNSPECIFIED - - BUSINESS_OBJECT_RECORD_KIND_CRM_COMPANY - - BUSINESS_OBJECT_RECORD_KIND_CRM_CONTACT - - BUSINESS_OBJECT_RECORD_KIND_CRM_DEAL - - BUSINESS_OBJECT_RECORD_KIND_CRM_SIGNAL - - BUSINESS_OBJECT_RECORD_KIND_CRM_ACTIVITY - - BUSINESS_OBJECT_RECORD_KIND_CRM_DEPLOYMENT - - BUSINESS_OBJECT_RECORD_KIND_CRM_TASK - - BUSINESS_OBJECT_RECORD_KIND_CRM_MEETING - description: |- - Immutable domain validation and access policy. CRM kinds retain internal staff - and pipeline:crm.read/write checks even through generic object APIs. - This metadata never grants the caller those permissions. - console.v1.BusinessObjectRelationshipDirection: - type: string - title: BusinessObjectRelationshipDirection - enum: - - BUSINESS_OBJECT_RELATIONSHIP_DIRECTION_UNSPECIFIED - - BUSINESS_OBJECT_RELATIONSHIP_DIRECTION_OUTGOING - - BUSINESS_OBJECT_RELATIONSHIP_DIRECTION_INCOMING - console.v1.BusinessSourceProperty: - type: string - title: BusinessSourceProperty - enum: - - BUSINESS_SOURCE_PROPERTY_UNSPECIFIED - - BUSINESS_SOURCE_PROPERTY_DISPLAY_NAME - - BUSINESS_SOURCE_PROPERTY_EXTERNAL_ID - console.v1.BusinessSourceState: - type: string - title: BusinessSourceState - enum: - - BUSINESS_SOURCE_STATE_UNSPECIFIED - - BUSINESS_SOURCE_STATE_ACTIVE - - BUSINESS_SOURCE_STATE_DELETED - - BUSINESS_SOURCE_STATE_ACCESS_REVOKED - - BUSINESS_SOURCE_STATE_ARCHIVED - console.v1.CaptureFormBrandingAssetRole: - type: string - title: CaptureFormBrandingAssetRole - enum: - - CAPTURE_FORM_BRANDING_ASSET_ROLE_UNSPECIFIED - - CAPTURE_FORM_BRANDING_ASSET_ROLE_LOGO - - CAPTURE_FORM_BRANDING_ASSET_ROLE_FAVICON - description: |- - CaptureFormBrandingAssetRole is the fixed public selector. Object and - version coordinates remain server-owned and are never accepted by the - public asset route. - console.v1.CaptureFormFieldKind: - type: string - title: CaptureFormFieldKind - enum: - - CAPTURE_FORM_FIELD_KIND_UNSPECIFIED - - CAPTURE_FORM_FIELD_KIND_TEXT - - CAPTURE_FORM_FIELD_KIND_LONG_TEXT - - CAPTURE_FORM_FIELD_KIND_INTEGER - - CAPTURE_FORM_FIELD_KIND_DECIMAL - - CAPTURE_FORM_FIELD_KIND_BOOLEAN - - CAPTURE_FORM_FIELD_KIND_DATE - - CAPTURE_FORM_FIELD_KIND_DATETIME - - CAPTURE_FORM_FIELD_KIND_EMAIL - - CAPTURE_FORM_FIELD_KIND_PHONE - - CAPTURE_FORM_FIELD_KIND_URL - - CAPTURE_FORM_FIELD_KIND_SELECT - - CAPTURE_FORM_FIELD_KIND_MULTI_SELECT - - CAPTURE_FORM_FIELD_KIND_FILE - description: |- - CaptureFormFieldKind is intentionally closed. A client cannot smuggle a - JSON shape into a scalar field or make a hidden write through presentation. - console.v1.CaptureFormMappingState: - type: string - title: CaptureFormMappingState - enum: - - CAPTURE_FORM_MAPPING_STATE_UNSPECIFIED - - CAPTURE_FORM_MAPPING_STATE_MAPPED - - CAPTURE_FORM_MAPPING_STATE_UNMAPPED - console.v1.CaptureFormObjectResultState: - type: string - title: CaptureFormObjectResultState - enum: - - CAPTURE_FORM_OBJECT_RESULT_STATE_UNSPECIFIED - - CAPTURE_FORM_OBJECT_RESULT_STATE_CREATED - - CAPTURE_FORM_OBJECT_RESULT_STATE_PARTIAL - - CAPTURE_FORM_OBJECT_RESULT_STATE_FAILED - console.v1.CaptureFormPublicationState: - type: string - title: CaptureFormPublicationState - enum: - - CAPTURE_FORM_PUBLICATION_STATE_UNSPECIFIED - - CAPTURE_FORM_PUBLICATION_STATE_ACTIVE - - CAPTURE_FORM_PUBLICATION_STATE_REVOKED - - CAPTURE_FORM_PUBLICATION_STATE_EXPIRED - description: CaptureFormPublicationState is the lifecycle of one immutable public grant. - console.v1.CaptureFormReviewDecision: - type: string - title: CaptureFormReviewDecision - enum: - - CAPTURE_FORM_REVIEW_DECISION_UNSPECIFIED - - CAPTURE_FORM_REVIEW_DECISION_ACCEPT - - CAPTURE_FORM_REVIEW_DECISION_REJECT - console.v1.CaptureFormState: - type: string - title: CaptureFormState - enum: - - CAPTURE_FORM_STATE_UNSPECIFIED - - CAPTURE_FORM_STATE_DRAFT - - CAPTURE_FORM_STATE_ACTIVE - - CAPTURE_FORM_STATE_ARCHIVED - description: CaptureFormState is the owner-controlled lifecycle of a form identity. - console.v1.CaptureFormSubmissionState: - type: string - title: CaptureFormSubmissionState - enum: - - CAPTURE_FORM_SUBMISSION_STATE_UNSPECIFIED - - CAPTURE_FORM_SUBMISSION_STATE_RECEIVED - - CAPTURE_FORM_SUBMISSION_STATE_UNDER_REVIEW - - CAPTURE_FORM_SUBMISSION_STATE_ACCEPTED - - CAPTURE_FORM_SUBMISSION_STATE_REJECTED - - CAPTURE_FORM_SUBMISSION_STATE_FAILED - description: CaptureFormSubmissionState is the durable submission/review lifecycle. - console.v1.CaptureFormUploadState: - type: string - title: CaptureFormUploadState - enum: - - CAPTURE_FORM_UPLOAD_STATE_UNSPECIFIED - - CAPTURE_FORM_UPLOAD_STATE_GRANTED - - CAPTURE_FORM_UPLOAD_STATE_PROCESSING - - CAPTURE_FORM_UPLOAD_STATE_COMPLETED - - CAPTURE_FORM_UPLOAD_STATE_FAILED - - CAPTURE_FORM_UPLOAD_STATE_EXPIRED - console.v1.CommitmentSourceState: - type: string - title: CommitmentSourceState - enum: - - COMMITMENT_SOURCE_STATE_UNSPECIFIED - - COMMITMENT_SOURCE_STATE_AVAILABLE - - COMMITMENT_SOURCE_STATE_NOT_CONFIGURED - description: |- - CommitmentSourceState reports whether the commitment ledger can be read for - this workspace. NOT_CONFIGURED means the deployment has no commitment-ledger - origin configured, so the response carries no commitments instead of an - empty ledger that would read as "you have none". - console.v1.ComplianceFindingStatus: - type: string - title: ComplianceFindingStatus - enum: - - COMPLIANCE_FINDING_STATUS_UNSPECIFIED - - COMPLIANCE_FINDING_STATUS_SATISFIED - - COMPLIANCE_FINDING_STATUS_VIOLATED - - COMPLIANCE_FINDING_STATUS_INDETERMINATE - - COMPLIANCE_FINDING_STATUS_NOT_APPLICABLE - console.v1.ComputerMissionAuthorityMode: - type: string - title: ComputerMissionAuthorityMode - enum: - - COMPUTER_MISSION_AUTHORITY_MODE_UNSPECIFIED - - COMPUTER_MISSION_AUTHORITY_MODE_SUPERVISED - - COMPUTER_MISSION_AUTHORITY_MODE_BOUNDED_AUTONOMY - - COMPUTER_MISSION_AUTHORITY_MODE_FULL_AUTONOMY - console.v1.ComputerMissionCanaryOperatorActionKind: - type: string - title: ComputerMissionCanaryOperatorActionKind - enum: - - COMPUTER_MISSION_CANARY_OPERATOR_ACTION_KIND_UNSPECIFIED - - COMPUTER_MISSION_CANARY_OPERATOR_ACTION_KIND_PAUSE - - COMPUTER_MISSION_CANARY_OPERATOR_ACTION_KIND_CANCEL - - COMPUTER_MISSION_CANARY_OPERATOR_ACTION_KIND_NARROW_SCOPE - - COMPUTER_MISSION_CANARY_OPERATOR_ACTION_KIND_EXTEND_GRANT - console.v1.ComputerMissionCanaryRecommendation: - type: string - title: ComputerMissionCanaryRecommendation - enum: - - COMPUTER_MISSION_CANARY_RECOMMENDATION_UNSPECIFIED - - COMPUTER_MISSION_CANARY_RECOMMENDATION_HOLD - - COMPUTER_MISSION_CANARY_RECOMMENDATION_PROMOTE - - COMPUTER_MISSION_CANARY_RECOMMENDATION_ROLL_BACK - console.v1.ComputerMissionCanaryRunState: - type: string - title: ComputerMissionCanaryRunState - enum: - - COMPUTER_MISSION_CANARY_RUN_STATE_UNSPECIFIED - - COMPUTER_MISSION_CANARY_RUN_STATE_QUEUED - - COMPUTER_MISSION_CANARY_RUN_STATE_RUNNING - - COMPUTER_MISSION_CANARY_RUN_STATE_WAITING_FOR_USER - - COMPUTER_MISSION_CANARY_RUN_STATE_CLEANUP_RUNNING - - COMPUTER_MISSION_CANARY_RUN_STATE_EVALUATION_PENDING - - COMPUTER_MISSION_CANARY_RUN_STATE_PASSED - - COMPUTER_MISSION_CANARY_RUN_STATE_FAILED - - COMPUTER_MISSION_CANARY_RUN_STATE_UNSAFE - - COMPUTER_MISSION_CANARY_RUN_STATE_CLEANUP_UNCERTAIN - - COMPUTER_MISSION_CANARY_RUN_STATE_CANCELLED - console.v1.ComputerMissionCanaryScenarioKind: - type: string - title: ComputerMissionCanaryScenarioKind - enum: - - COMPUTER_MISSION_CANARY_SCENARIO_KIND_UNSPECIFIED - - COMPUTER_MISSION_CANARY_SCENARIO_KIND_CI_REPAIR - - COMPUTER_MISSION_CANARY_SCENARIO_KIND_REVIEW_OPERATIONS - - COMPUTER_MISSION_CANARY_SCENARIO_KIND_RUNNER_RECOVERY - - COMPUTER_MISSION_CANARY_SCENARIO_KIND_APPROVAL_CONTINUATION - - COMPUTER_MISSION_CANARY_SCENARIO_KIND_AMBIGUOUS_TOOL_RESPONSE - - COMPUTER_MISSION_CANARY_SCENARIO_KIND_BUDGET_STOP - console.v1.ComputerMissionCanaryScoreDimension: - type: string - title: ComputerMissionCanaryScoreDimension - enum: - - COMPUTER_MISSION_CANARY_SCORE_DIMENSION_UNSPECIFIED - - COMPUTER_MISSION_CANARY_SCORE_DIMENSION_OUTCOME_CORRECTNESS - - COMPUTER_MISSION_CANARY_SCORE_DIMENSION_HUMAN_INTERVENTION_EFFICIENCY - - COMPUTER_MISSION_CANARY_SCORE_DIMENSION_SCOPE_ADHERENCE - - COMPUTER_MISSION_CANARY_SCORE_DIMENSION_DUPLICATE_EFFECT_AVOIDANCE - - COMPUTER_MISSION_CANARY_SCORE_DIMENSION_RECOVERY_SUCCESS - - COMPUTER_MISSION_CANARY_SCORE_DIMENSION_BUDGET_EFFICIENCY - - COMPUTER_MISSION_CANARY_SCORE_DIMENSION_EVIDENCE_COMPLETENESS - - COMPUTER_MISSION_CANARY_SCORE_DIMENSION_TIME_TO_VERIFIED_COMPLETION - console.v1.ComputerMissionDecisionRoute: - type: string - title: ComputerMissionDecisionRoute - enum: - - COMPUTER_MISSION_DECISION_ROUTE_UNSPECIFIED - - COMPUTER_MISSION_DECISION_ROUTE_NO_ROUTE - - COMPUTER_MISSION_DECISION_ROUTE_SINGLE_AGENT - - COMPUTER_MISSION_DECISION_ROUTE_TOURNAMENT - console.v1.ComputerMissionEffectState: - type: string - title: ComputerMissionEffectState - enum: - - COMPUTER_MISSION_EFFECT_STATE_UNSPECIFIED - - COMPUTER_MISSION_EFFECT_STATE_INTENT_RECORDED - - COMPUTER_MISSION_EFFECT_STATE_FORWARD_ACCEPTED - - COMPUTER_MISSION_EFFECT_STATE_FORWARD_VERIFIED - - COMPUTER_MISSION_EFFECT_STATE_ROLLBACK_RUNNING - - COMPUTER_MISSION_EFFECT_STATE_ROLLED_BACK - - COMPUTER_MISSION_EFFECT_STATE_CLEANUP_VERIFIED - - COMPUTER_MISSION_EFFECT_STATE_CLEANUP_UNCERTAIN - console.v1.ComputerMissionRollbackArgumentSource: - type: string - title: ComputerMissionRollbackArgumentSource - enum: - - COMPUTER_MISSION_ROLLBACK_ARGUMENT_SOURCE_UNSPECIFIED - - COMPUTER_MISSION_ROLLBACK_ARGUMENT_SOURCE_PRE_ACTION_STATE - - COMPUTER_MISSION_ROLLBACK_ARGUMENT_SOURCE_FORWARD_RECEIPT - console.v1.ComputerMissionState: - type: string - title: ComputerMissionState - enum: - - COMPUTER_MISSION_STATE_UNSPECIFIED - - COMPUTER_MISSION_STATE_QUEUED - - COMPUTER_MISSION_STATE_RUNNING - - COMPUTER_MISSION_STATE_WAITING_FOR_USER - - COMPUTER_MISSION_STATE_CANCELLATION_REQUESTED - - COMPUTER_MISSION_STATE_SUCCEEDED - - COMPUTER_MISSION_STATE_FAILED - - COMPUTER_MISSION_STATE_BUDGET_EXHAUSTED - - COMPUTER_MISSION_STATE_CANCELLED - - COMPUTER_MISSION_STATE_CLEANUP_UNCERTAIN - - COMPUTER_MISSION_STATE_NOT_ROUTED - - COMPUTER_MISSION_STATE_PLANNING - - COMPUTER_MISSION_STATE_VERIFYING - - COMPUTER_MISSION_STATE_SLEEPING - - COMPUTER_MISSION_STATE_WAITING_FOR_APPROVAL - - COMPUTER_MISSION_STATE_WAITING_FOR_EXTERNAL_EVENT - - COMPUTER_MISSION_STATE_PAUSED - console.v1.ConnectedCallSourceState: - type: string - title: ConnectedCallSourceState - enum: - - CONNECTED_CALL_SOURCE_STATE_UNSPECIFIED - - CONNECTED_CALL_SOURCE_STATE_AVAILABLE - - CONNECTED_CALL_SOURCE_STATE_NOT_CONNECTED - console.v1.ConnectorTriggerSource: - type: string - title: ConnectorTriggerSource - enum: - - CONNECTOR_TRIGGER_SOURCE_UNSPECIFIED - - CONNECTOR_TRIGGER_SOURCE_SCHEDULED - - CONNECTOR_TRIGGER_SOURCE_CONNECTOR_EVENT - console.v1.CustomerFactConfirmationResponse: - type: string - title: CustomerFactConfirmationResponse - enum: - - CUSTOMER_FACT_CONFIRMATION_RESPONSE_UNSPECIFIED - - CUSTOMER_FACT_CONFIRMATION_RESPONSE_CONFIRM - - CUSTOMER_FACT_CONFIRMATION_RESPONSE_DISPUTE - console.v1.CustomerIntelligenceAuthority: - type: string - title: CustomerIntelligenceAuthority - enum: - - CUSTOMER_INTELLIGENCE_AUTHORITY_UNSPECIFIED - - CUSTOMER_INTELLIGENCE_AUTHORITY_INFERRED - - CUSTOMER_INTELLIGENCE_AUTHORITY_OBSERVED - - CUSTOMER_INTELLIGENCE_AUTHORITY_STATED - - CUSTOMER_INTELLIGENCE_AUTHORITY_CORROBORATED - - CUSTOMER_INTELLIGENCE_AUTHORITY_CONFIRMED - console.v1.CustomerIntelligenceEvidencePolarity: - type: string - title: CustomerIntelligenceEvidencePolarity - enum: - - CUSTOMER_INTELLIGENCE_EVIDENCE_POLARITY_UNSPECIFIED - - CUSTOMER_INTELLIGENCE_EVIDENCE_POLARITY_SUPPORTING - - CUSTOMER_INTELLIGENCE_EVIDENCE_POLARITY_CONTRADICTING - console.v1.CustomerIntelligenceLifecycleState: - type: string - title: CustomerIntelligenceLifecycleState - enum: - - CUSTOMER_INTELLIGENCE_LIFECYCLE_STATE_UNSPECIFIED - - CUSTOMER_INTELLIGENCE_LIFECYCLE_STATE_PROPOSED - - CUSTOMER_INTELLIGENCE_LIFECYCLE_STATE_ACTIVE - - CUSTOMER_INTELLIGENCE_LIFECYCLE_STATE_DISPUTED - - CUSTOMER_INTELLIGENCE_LIFECYCLE_STATE_SUPERSEDED - - CUSTOMER_INTELLIGENCE_LIFECYCLE_STATE_EXPIRED - console.v1.CustomerIntelligenceProducerKind: - type: string - title: CustomerIntelligenceProducerKind - enum: - - CUSTOMER_INTELLIGENCE_PRODUCER_KIND_UNSPECIFIED - - CUSTOMER_INTELLIGENCE_PRODUCER_KIND_PLATFORM_DETERMINISTIC_FEEDBACK - - CUSTOMER_INTELLIGENCE_PRODUCER_KIND_CEREBRO - - CUSTOMER_INTELLIGENCE_PRODUCER_KIND_STAFF_REVIEW - - CUSTOMER_INTELLIGENCE_PRODUCER_KIND_CUSTOMER_CONFIRMATION - - CUSTOMER_INTELLIGENCE_PRODUCER_KIND_OUTCOME_EVALUATOR - console.v1.CustomerIntelligenceReviewDecision: - type: string - title: CustomerIntelligenceReviewDecision - enum: - - CUSTOMER_INTELLIGENCE_REVIEW_DECISION_UNSPECIFIED - - CUSTOMER_INTELLIGENCE_REVIEW_DECISION_REQUEST_CONFIRMATION - - CUSTOMER_INTELLIGENCE_REVIEW_DECISION_REQUEST_EVIDENCE - - CUSTOMER_INTELLIGENCE_REVIEW_DECISION_CHALLENGE - - CUSTOMER_INTELLIGENCE_REVIEW_DECISION_DISPUTE - - CUSTOMER_INTELLIGENCE_REVIEW_DECISION_EXPIRE - - CUSTOMER_INTELLIGENCE_REVIEW_DECISION_SUPERSEDE - - CUSTOMER_INTELLIGENCE_REVIEW_DECISION_PROPOSE_ACTION - console.v1.CustomerIntelligenceSubjectKind: - type: string - title: CustomerIntelligenceSubjectKind - enum: - - CUSTOMER_INTELLIGENCE_SUBJECT_KIND_UNSPECIFIED - - CUSTOMER_INTELLIGENCE_SUBJECT_KIND_INTERACTION - - CUSTOMER_INTELLIGENCE_SUBJECT_KIND_WORKSPACE - - CUSTOMER_INTELLIGENCE_SUBJECT_KIND_PRODUCT_AREA - - CUSTOMER_INTELLIGENCE_SUBJECT_KIND_COHORT - console.v1.DexAutonomyMode: - type: string - title: DexAutonomyMode - enum: - - DEX_AUTONOMY_MODE_UNSPECIFIED - - DEX_AUTONOMY_MODE_SUGGEST_ONLY - - DEX_AUTONOMY_MODE_ASK_BEFORE_CHANGES - - DEX_AUTONOMY_MODE_ACT_WITHIN_POLICY - console.v1.DexComputerCorrectionLabel: - type: string - title: DexComputerCorrectionLabel - enum: - - DEX_COMPUTER_CORRECTION_LABEL_UNSPECIFIED - - DEX_COMPUTER_CORRECTION_LABEL_WRONG_TARGET - - DEX_COMPUTER_CORRECTION_LABEL_WRONG_ACTION - - DEX_COMPUTER_CORRECTION_LABEL_MISSING_OBSERVATION - - DEX_COMPUTER_CORRECTION_LABEL_EFFECT_AMBIGUOUS - - DEX_COMPUTER_CORRECTION_LABEL_UNSAFE_BOUNDARY - - DEX_COMPUTER_CORRECTION_LABEL_HANDOFF_CONFLICT - - DEX_COMPUTER_CORRECTION_LABEL_OTHER - console.v1.DexExternalActionMode: - type: string - title: DexExternalActionMode - enum: - - DEX_EXTERNAL_ACTION_MODE_UNSPECIFIED - - DEX_EXTERNAL_ACTION_MODE_ALWAYS_ASK - - DEX_EXTERNAL_ACTION_MODE_POLICY_BASED - - DEX_EXTERNAL_ACTION_MODE_DISABLED - console.v1.DexSkillCatalogExposure: - type: string - title: DexSkillCatalogExposure - enum: - - DEX_SKILL_CATALOG_EXPOSURE_UNSPECIFIED - - DEX_SKILL_CATALOG_EXPOSURE_INTERNAL - - DEX_SKILL_CATALOG_EXPOSURE_INSTALLABLE - console.v1.DexSkillFixtureKind: - type: string - title: DexSkillFixtureKind - enum: - - DEX_SKILL_FIXTURE_KIND_UNSPECIFIED - - DEX_SKILL_FIXTURE_KIND_HAPPY - - DEX_SKILL_FIXTURE_KIND_EDGE - - DEX_SKILL_FIXTURE_KIND_DENIED_UNAVAILABLE - console.v1.DexSkillLifecycleState: - type: string - title: DexSkillLifecycleState - enum: - - DEX_SKILL_LIFECYCLE_STATE_UNSPECIFIED - - DEX_SKILL_LIFECYCLE_STATE_READY - - DEX_SKILL_LIFECYCLE_STATE_MISSING_TOOL - - DEX_SKILL_LIFECYCLE_STATE_NEEDS_REVIEW - - DEX_SKILL_LIFECYCLE_STATE_DISABLED - - DEX_SKILL_LIFECYCLE_STATE_REVOKED - console.v1.DexSkillPackageFileKind: - type: string - title: DexSkillPackageFileKind - enum: - - DEX_SKILL_PACKAGE_FILE_KIND_UNSPECIFIED - - DEX_SKILL_PACKAGE_FILE_KIND_INSTRUCTIONS - - DEX_SKILL_PACKAGE_FILE_KIND_SCRIPT - - DEX_SKILL_PACKAGE_FILE_KIND_REFERENCE - - DEX_SKILL_PACKAGE_FILE_KIND_EXAMPLE - - DEX_SKILL_PACKAGE_FILE_KIND_ASSET - - DEX_SKILL_PACKAGE_FILE_KIND_TEMPLATE - - DEX_SKILL_PACKAGE_FILE_KIND_LICENSE - - DEX_SKILL_PACKAGE_FILE_KIND_OTHER - console.v1.DexSkillRuntimeReadiness: - type: string - title: DexSkillRuntimeReadiness - enum: - - DEX_SKILL_RUNTIME_READINESS_UNSPECIFIED - - DEX_SKILL_RUNTIME_READINESS_NOT_REQUIRED - - DEX_SKILL_RUNTIME_READINESS_PROBE_REQUIRED - - DEX_SKILL_RUNTIME_READINESS_READY - - DEX_SKILL_RUNTIME_READINESS_MISSING_TOOL - - DEX_SKILL_RUNTIME_READINESS_UNAVAILABLE - console.v1.GuardrailAction: - type: string - title: GuardrailAction - enum: - - GUARDRAIL_ACTION_UNSPECIFIED - - GUARDRAIL_ACTION_BLOCK - - GUARDRAIL_ACTION_REDACT - - GUARDRAIL_ACTION_FLAG - description: |- - GuardrailAction is what a matched rule does to the turn. BLOCK fails the turn - closed, REDACT masks the matched span, FLAG records the match only. - console.v1.GuardrailDetectorKind: - type: string - title: GuardrailDetectorKind - enum: - - GUARDRAIL_DETECTOR_KIND_UNSPECIFIED - - GUARDRAIL_DETECTOR_KIND_BUILTIN_EMAIL - - GUARDRAIL_DETECTOR_KIND_BUILTIN_CREDIT_CARD - - GUARDRAIL_DETECTOR_KIND_BUILTIN_SECRET - - GUARDRAIL_DETECTOR_KIND_CUSTOM_REGEX - description: |- - GuardrailDetectorKind selects the deterministic detector a rule runs over Dex - model output. Built-in detectors need no pattern; CUSTOM_REGEX carries a - workspace-authored deny pattern in `pattern`. - console.v1.ManagedInferenceBlocker: - type: string - title: ManagedInferenceBlocker - enum: - - MANAGED_INFERENCE_BLOCKER_UNSPECIFIED - - MANAGED_INFERENCE_BLOCKER_ENROLLMENT_REQUIRED - - MANAGED_INFERENCE_BLOCKER_ENROLLMENT_SUSPENDED - - MANAGED_INFERENCE_BLOCKER_GATEWAY_SYNC_PENDING - - MANAGED_INFERENCE_BLOCKER_FUNDING_REQUIRED - - MANAGED_INFERENCE_BLOCKER_FUNDING_SUSPENDED - - MANAGED_INFERENCE_BLOCKER_FUNDING_UNAVAILABLE - - MANAGED_INFERENCE_BLOCKER_ROUTE_UNAVAILABLE - - MANAGED_INFERENCE_BLOCKER_ENROLLMENT_UNAVAILABLE - - MANAGED_INFERENCE_BLOCKER_BUDGET_LIMIT_REACHED - - MANAGED_INFERENCE_BLOCKER_POLICY_UNAVAILABLE - console.v1.ManagedInferenceNextAction: - type: string - title: ManagedInferenceNextAction - enum: - - MANAGED_INFERENCE_NEXT_ACTION_UNSPECIFIED - - MANAGED_INFERENCE_NEXT_ACTION_CONTACT_ADMINISTRATOR - - MANAGED_INFERENCE_NEXT_ACTION_VIEW_FUNDING - - MANAGED_INFERENCE_NEXT_ACTION_RETRY - console.v1.ManagedInferenceReadinessStatus: - type: string - title: ManagedInferenceReadinessStatus - enum: - - MANAGED_INFERENCE_READINESS_STATUS_UNSPECIFIED - - MANAGED_INFERENCE_READINESS_STATUS_READY - - MANAGED_INFERENCE_READINESS_STATUS_ACTIVATION_REQUIRED - - MANAGED_INFERENCE_READINESS_STATUS_FUNDING_REQUIRED - - MANAGED_INFERENCE_READINESS_STATUS_LIMIT_REACHED - - MANAGED_INFERENCE_READINESS_STATUS_ACCESS_SUSPENDED - - MANAGED_INFERENCE_READINESS_STATUS_TEMPORARILY_UNAVAILABLE - description: Shared prerequisite vocabulary consumed by Grid, Deixic UI and Deixic Code. - console.v1.ManagedProviderAccessState: - type: string - title: ManagedProviderAccessState - enum: - - MANAGED_PROVIDER_ACCESS_STATE_UNSPECIFIED - - MANAGED_PROVIDER_ACCESS_STATE_ACTIVE - - MANAGED_PROVIDER_ACCESS_STATE_SUSPENDED - - MANAGED_PROVIDER_ACCESS_STATE_REVOKED - - MANAGED_PROVIDER_ACCESS_STATE_EXPIRED - description: |- - ManagedProviderAccessGrant is the durable, staff-owned entitlement that lets - an organization resolve the platform-managed provider fallback after a BYOK - miss. Absent or disabled rows are default-deny. - console.v1.McpPolicyMode: - type: string - title: McpPolicyMode - enum: - - MCP_POLICY_MODE_UNSPECIFIED - - MCP_POLICY_MODE_OPEN - - MCP_POLICY_MODE_ALLOWLIST - - MCP_POLICY_MODE_DENYLIST - description: |- - McpPolicyMode selects how a client treats an MCP server that is not named - by the policy. - console.v1.OperatingAnswerProvenance: - type: string - title: OperatingAnswerProvenance - enum: - - OPERATING_ANSWER_PROVENANCE_UNSPECIFIED - - OPERATING_ANSWER_PROVENANCE_MODEL - - OPERATING_ANSWER_PROVENANCE_REVIEWED_MODEL - - OPERATING_ANSWER_PROVENANCE_REPAIR_MODEL - - OPERATING_ANSWER_PROVENANCE_GUARDRAIL - - OPERATING_ANSWER_PROVENANCE_RECEIPT_SUMMARY - - OPERATING_ANSWER_PROVENANCE_RUNNER_FAILURE - - OPERATING_ANSWER_PROVENANCE_SUPERSEDED_TURN - - OPERATING_ANSWER_PROVENANCE_HOSTED_FRONT_FINAL - - OPERATING_ANSWER_PROVENANCE_HOSTED_FRONT_PRELIMINARY - console.v1.OperatingAttachmentProcessingState: - type: string - title: OperatingAttachmentProcessingState - enum: - - OPERATING_ATTACHMENT_PROCESSING_STATE_UNSPECIFIED - - OPERATING_ATTACHMENT_PROCESSING_STATE_UPLOADING - - OPERATING_ATTACHMENT_PROCESSING_STATE_PROCESSING - - OPERATING_ATTACHMENT_PROCESSING_STATE_READY - - OPERATING_ATTACHMENT_PROCESSING_STATE_FAILED - console.v1.OperatingAttachmentScope: - type: string - title: OperatingAttachmentScope - enum: - - OPERATING_ATTACHMENT_SCOPE_UNSPECIFIED - - OPERATING_ATTACHMENT_SCOPE_CONVERSATION - - OPERATING_ATTACHMENT_SCOPE_WORKSPACE - console.v1.OperatingCorrectionCategory: - type: string - title: OperatingCorrectionCategory - enum: - - OPERATING_CORRECTION_CATEGORY_UNSPECIFIED - - OPERATING_CORRECTION_CATEGORY_WRONG_TOPIC - - OPERATING_CORRECTION_CATEGORY_NOT_DONE - - OPERATING_CORRECTION_CATEGORY_INCORRECT_FACT - - OPERATING_CORRECTION_CATEGORY_UNSAFE_ACTION - - OPERATING_CORRECTION_CATEGORY_OTHER - console.v1.OperatingCorrectionReviewState: - type: string - title: OperatingCorrectionReviewState - enum: - - OPERATING_CORRECTION_REVIEW_STATE_UNSPECIFIED - - OPERATING_CORRECTION_REVIEW_STATE_PENDING_REVIEW - - OPERATING_CORRECTION_REVIEW_STATE_APPROVED - - OPERATING_CORRECTION_REVIEW_STATE_REJECTED - - OPERATING_CORRECTION_REVIEW_STATE_INELIGIBLE - console.v1.OperatingExecutionPlacement: - type: string - title: OperatingExecutionPlacement - enum: - - OPERATING_EXECUTION_PLACEMENT_UNSPECIFIED - - OPERATING_EXECUTION_PLACEMENT_INLINE_TURN - - OPERATING_EXECUTION_PLACEMENT_COMPUTER_MISSION - description: |- - Server-owned Auto decision pinned to an accepted task, never a channel preference. - Where an accepted Auto task executes. The classifier already picks a model - from the task's purpose; this records the execution environment that same - decision implies, so placement is durable, replayable, and attributable to - the policy version that chose it rather than re-derived at each stage. - console.v1.OperatingExecutionProfileKind: - type: string - title: OperatingExecutionProfileKind - enum: - - OPERATING_EXECUTION_PROFILE_KIND_UNSPECIFIED - - OPERATING_EXECUTION_PROFILE_KIND_DEEP_AGENT - - OPERATING_EXECUTION_PROFILE_KIND_HOSTED_FRONT_THEN_DEEP - description: |- - OperatingExecutionProfile is selected exclusively by Platform. It is not a - SubmitOperatingMessage input. Platform validates any conversation preference - before selecting the model, provider, credential lane, and action authority. - The worker receives only safe routing - attribution; credential names and secrets never cross this handoff. - console.v1.OperatingExecutionRuntime: - type: string - title: OperatingExecutionRuntime - enum: - - OPERATING_EXECUTION_RUNTIME_UNSPECIFIED - - OPERATING_EXECUTION_RUNTIME_MAESTRO - console.v1.OperatingFeedbackClassificationSource: - type: string - title: OperatingFeedbackClassificationSource - enum: - - OPERATING_FEEDBACK_CLASSIFICATION_SOURCE_UNSPECIFIED - - OPERATING_FEEDBACK_CLASSIFICATION_SOURCE_USER - - OPERATING_FEEDBACK_CLASSIFICATION_SOURCE_AGENT_SUGGESTED_USER_CONFIRMED - console.v1.OperatingFeedbackLifecycleState: - type: string - title: OperatingFeedbackLifecycleState - enum: - - OPERATING_FEEDBACK_LIFECYCLE_STATE_UNSPECIFIED - - OPERATING_FEEDBACK_LIFECYCLE_STATE_ACTIVE - - OPERATING_FEEDBACK_LIFECYCLE_STATE_SUPERSEDED - - OPERATING_FEEDBACK_LIFECYCLE_STATE_RETRACTED - console.v1.OperatingFeedbackReason: - type: string - title: OperatingFeedbackReason - enum: - - OPERATING_FEEDBACK_REASON_UNSPECIFIED - - OPERATING_FEEDBACK_REASON_HELPFUL - - OPERATING_FEEDBACK_REASON_ACCURATE - - OPERATING_FEEDBACK_REASON_CLEAR - - OPERATING_FEEDBACK_REASON_CORRECT_ACTION - - OPERATING_FEEDBACK_REASON_MISSED_REQUEST - - OPERATING_FEEDBACK_REASON_INCORRECT - - OPERATING_FEEDBACK_REASON_INCOMPLETE - - OPERATING_FEEDBACK_REASON_UNCLEAR - - OPERATING_FEEDBACK_REASON_MISSING_EVIDENCE - - OPERATING_FEEDBACK_REASON_UNSAFE - - OPERATING_FEEDBACK_REASON_OTHER - - OPERATING_FEEDBACK_REASON_COMPLETE - - OPERATING_FEEDBACK_REASON_IGNORED_INSTRUCTIONS - - OPERATING_FEEDBACK_REASON_TOOL_FAILED - - OPERATING_FEEDBACK_REASON_TOO_VERBOSE - console.v1.OperatingFeedbackRemediationAction: - type: string - title: OperatingFeedbackRemediationAction - enum: - - OPERATING_FEEDBACK_REMEDIATION_ACTION_UNSPECIFIED - - OPERATING_FEEDBACK_REMEDIATION_ACTION_NONE - - OPERATING_FEEDBACK_REMEDIATION_ACTION_VERIFY - - OPERATING_FEEDBACK_REMEDIATION_ACTION_RETRY - console.v1.OperatingFeedbackRemediationOutcome: - type: string - title: OperatingFeedbackRemediationOutcome - enum: - - OPERATING_FEEDBACK_REMEDIATION_OUTCOME_UNSPECIFIED - - OPERATING_FEEDBACK_REMEDIATION_OUTCOME_UNCONFIRMED - - OPERATING_FEEDBACK_REMEDIATION_OUTCOME_ACCEPTED - - OPERATING_FEEDBACK_REMEDIATION_OUTCOME_REJECTED - console.v1.OperatingFeedbackSentiment: - type: string - title: OperatingFeedbackSentiment - enum: - - OPERATING_FEEDBACK_SENTIMENT_UNSPECIFIED - - OPERATING_FEEDBACK_SENTIMENT_POSITIVE - - OPERATING_FEEDBACK_SENTIMENT_NEGATIVE - console.v1.OperatingHomepageSuggestionFeedbackAction: - type: string - title: OperatingHomepageSuggestionFeedbackAction - enum: - - OPERATING_HOMEPAGE_SUGGESTION_FEEDBACK_ACTION_UNSPECIFIED - - OPERATING_HOMEPAGE_SUGGESTION_FEEDBACK_ACTION_NOT_USEFUL - - OPERATING_HOMEPAGE_SUGGESTION_FEEDBACK_ACTION_FORGET - console.v1.OperatingHostedFrontDecisionKind: - type: string - title: OperatingHostedFrontDecisionKind - enum: - - OPERATING_HOSTED_FRONT_DECISION_KIND_UNSPECIFIED - - OPERATING_HOSTED_FRONT_DECISION_KIND_ANSWER_NOW - - OPERATING_HOSTED_FRONT_DECISION_KIND_ANSWER_AND_CONTINUE - - OPERATING_HOSTED_FRONT_DECISION_KIND_COMPUTER_REQUIRED - - OPERATING_HOSTED_FRONT_DECISION_KIND_CONTINUE_ONLY - description: |- - OperatingHostedFrontDecision is the server-owned semantic boundary between - an immediate hosted answer and durable private-computer continuation. The - model returns this through a declared function schema; application code must - not infer it from user or assistant prose. - console.v1.OperatingJobOrigin: - type: string - title: OperatingJobOrigin - enum: - - OPERATING_JOB_ORIGIN_UNSPECIFIED - - OPERATING_JOB_ORIGIN_CHAT - - OPERATING_JOB_ORIGIN_SCHEDULE - - OPERATING_JOB_ORIGIN_EVENT - - OPERATING_JOB_ORIGIN_API - - OPERATING_JOB_ORIGIN_SKILL - - OPERATING_JOB_ORIGIN_COMPUTER - console.v1.OperatingJobProofState: - type: string - title: OperatingJobProofState - enum: - - OPERATING_JOB_PROOF_STATE_UNSPECIFIED - - OPERATING_JOB_PROOF_STATE_UNAVAILABLE - - OPERATING_JOB_PROOF_STATE_PARTIAL - - OPERATING_JOB_PROOF_STATE_COMPLETE - description: |- - OperatingJobProofState reports only the completeness of authoritative - record references. It never upgrades a job lifecycle or claims that an - unresolved owner record succeeded. - console.v1.OperatingJobState: - type: string - title: OperatingJobState - enum: - - OPERATING_JOB_STATE_UNSPECIFIED - - OPERATING_JOB_STATE_PROPOSED - - OPERATING_JOB_STATE_QUEUED - - OPERATING_JOB_STATE_RUNNING - - OPERATING_JOB_STATE_WAITING - - OPERATING_JOB_STATE_SUCCEEDED - - OPERATING_JOB_STATE_FAILED - - OPERATING_JOB_STATE_CANCELLED - description: |- - OperatingJobState is the customer lifecycle of one durable intended - outcome. Verification is deliberately separate: succeeded never implies - verified, and failed never means blocked. - console.v1.OperatingJobVerificationState: - type: string - title: OperatingJobVerificationState - enum: - - OPERATING_JOB_VERIFICATION_STATE_UNSPECIFIED - - OPERATING_JOB_VERIFICATION_STATE_NOT_VERIFIED - - OPERATING_JOB_VERIFICATION_STATE_PENDING - - OPERATING_JOB_VERIFICATION_STATE_VERIFIED - - OPERATING_JOB_VERIFICATION_STATE_FAILED - console.v1.OperatingManagedInferenceBudgetOrigin: - type: string - title: OperatingManagedInferenceBudgetOrigin - enum: - - OPERATING_MANAGED_INFERENCE_BUDGET_ORIGIN_UNSPECIFIED - - OPERATING_MANAGED_INFERENCE_BUDGET_ORIGIN_EXPLICIT - - OPERATING_MANAGED_INFERENCE_BUDGET_ORIGIN_ROUTE_POLICY - - OPERATING_MANAGED_INFERENCE_BUDGET_ORIGIN_PROVIDER_DEFAULT - console.v1.OperatingManagedInferenceRouting: - type: string - title: OperatingManagedInferenceRouting - enum: - - OPERATING_MANAGED_INFERENCE_ROUTING_UNSPECIFIED - - OPERATING_MANAGED_INFERENCE_ROUTING_ORDERED - console.v1.OperatingSurfaceKind: - type: string - title: OperatingSurfaceKind - enum: - - OPERATING_SURFACE_KIND_UNSPECIFIED - - OPERATING_SURFACE_KIND_COMPOSER - - OPERATING_SURFACE_KIND_SLACK - - OPERATING_SURFACE_KIND_TEAMS - - OPERATING_SURFACE_KIND_WHATSAPP - - OPERATING_SURFACE_KIND_APPLE_MESSAGES - - OPERATING_SURFACE_KIND_EMAIL - console.v1.OperatingTaskEnvironmentStageKind: - type: string - title: OperatingTaskEnvironmentStageKind - enum: - - OPERATING_TASK_ENVIRONMENT_STAGE_KIND_UNSPECIFIED - - OPERATING_TASK_ENVIRONMENT_STAGE_KIND_SOURCE - - OPERATING_TASK_ENVIRONMENT_STAGE_KIND_PREPARATION - - OPERATING_TASK_ENVIRONMENT_STAGE_KIND_PROVISIONING - - OPERATING_TASK_ENVIRONMENT_STAGE_KIND_NETWORK - - OPERATING_TASK_ENVIRONMENT_STAGE_KIND_EXECUTION - - OPERATING_TASK_ENVIRONMENT_STAGE_KIND_RETAINED_STATE - console.v1.OperatingTaskEnvironmentStageState: - type: string - title: OperatingTaskEnvironmentStageState - enum: - - OPERATING_TASK_ENVIRONMENT_STAGE_STATE_UNSPECIFIED - - OPERATING_TASK_ENVIRONMENT_STAGE_STATE_NOT_REQUIRED - - OPERATING_TASK_ENVIRONMENT_STAGE_STATE_ABSENT - - OPERATING_TASK_ENVIRONMENT_STAGE_STATE_PENDING - - OPERATING_TASK_ENVIRONMENT_STAGE_STATE_READY - - OPERATING_TASK_ENVIRONMENT_STAGE_STATE_FAILED - - OPERATING_TASK_ENVIRONMENT_STAGE_STATE_RETAINED - - OPERATING_TASK_ENVIRONMENT_STAGE_STATE_UNKNOWN - console.v1.OperatingTaskKind: - type: string - title: OperatingTaskKind - enum: - - OPERATING_TASK_KIND_UNSPECIFIED - - OPERATING_TASK_KIND_CONVERSATION - - OPERATING_TASK_KIND_CODING_IMPLEMENTATION - description: |- - Explicit caller intent. This never grants execution or repository authority. - Unspecified preserves existing chat and replay clients. - console.v1.OperatingThreadArchiveFilter: - type: string - title: OperatingThreadArchiveFilter - enum: - - OPERATING_THREAD_ARCHIVE_FILTER_UNSPECIFIED - - OPERATING_THREAD_ARCHIVE_FILTER_ACTIVE_ONLY - - OPERATING_THREAD_ARCHIVE_FILTER_ARCHIVED_ONLY - - OPERATING_THREAD_ARCHIVE_FILTER_ALL - console.v1.OperatingThreadEventKind: - type: string - title: OperatingThreadEventKind - enum: - - OPERATING_THREAD_EVENT_KIND_UNSPECIFIED - - OPERATING_THREAD_EVENT_KIND_TURN_ACCEPTED - - OPERATING_THREAD_EVENT_KIND_TURN_STARTED - - OPERATING_THREAD_EVENT_KIND_PROGRESS - - OPERATING_THREAD_EVENT_KIND_APPROVAL_REQUIRED - - OPERATING_THREAD_EVENT_KIND_INPUT_REQUIRED - - OPERATING_THREAD_EVENT_KIND_ARTIFACT_RECORDED - - OPERATING_THREAD_EVENT_KIND_TURN_COMPLETED - - OPERATING_THREAD_EVENT_KIND_TURN_FAILED - - OPERATING_THREAD_EVENT_KIND_TURN_INTERRUPTED - - OPERATING_THREAD_EVENT_KIND_RUNTIME_REBOUND - - OPERATING_THREAD_EVENT_KIND_TOOL_PROPOSED - - OPERATING_THREAD_EVENT_KIND_TOOL_COMPLETED - - OPERATING_THREAD_EVENT_KIND_MEMORY_PROPOSED - - OPERATING_THREAD_EVENT_KIND_CLIENT_TOOL_REQUIRED - - OPERATING_THREAD_EVENT_KIND_EXTERNAL_RETRY_REQUIRED - console.v1.OperatingThreadExecutionState: - type: string - title: OperatingThreadExecutionState - enum: - - OPERATING_THREAD_EXECUTION_STATE_UNSPECIFIED - - OPERATING_THREAD_EXECUTION_STATE_PROVISIONING - - OPERATING_THREAD_EXECUTION_STATE_READY - - OPERATING_THREAD_EXECUTION_STATE_RUNNING - - OPERATING_THREAD_EXECUTION_STATE_WAITING - - OPERATING_THREAD_EXECUTION_STATE_DEGRADED - - OPERATING_THREAD_EXECUTION_STATE_STOPPED - console.v1.OperatingThreadRequestType: - type: string - title: OperatingThreadRequestType - enum: - - OPERATING_THREAD_REQUEST_TYPE_UNSPECIFIED - - OPERATING_THREAD_REQUEST_TYPE_APPROVAL - - OPERATING_THREAD_REQUEST_TYPE_USER_INPUT - - OPERATING_THREAD_REQUEST_TYPE_CLIENT_TOOL - - OPERATING_THREAD_REQUEST_TYPE_EXTERNAL_RETRY - console.v1.OperatingThreadResponseAction: - type: string - title: OperatingThreadResponseAction - enum: - - OPERATING_THREAD_RESPONSE_ACTION_UNSPECIFIED - - OPERATING_THREAD_RESPONSE_ACTION_APPROVE - - OPERATING_THREAD_RESPONSE_ACTION_DENY - - OPERATING_THREAD_RESPONSE_ACTION_ANSWER - - OPERATING_THREAD_RESPONSE_ACTION_RETRY - - OPERATING_THREAD_RESPONSE_ACTION_SKIP - - OPERATING_THREAD_RESPONSE_ACTION_ABORT - console.v1.OperatingThreadWaitingReason: - type: string - title: OperatingThreadWaitingReason - enum: - - OPERATING_THREAD_WAITING_REASON_UNSPECIFIED - - OPERATING_THREAD_WAITING_REASON_NONE - - OPERATING_THREAD_WAITING_REASON_APPROVAL - - OPERATING_THREAD_WAITING_REASON_USER_INPUT - - OPERATING_THREAD_WAITING_REASON_EXTERNAL_RETRY - - OPERATING_THREAD_WAITING_REASON_CLIENT_TOOL - console.v1.OperatingTurnAnswerKind: - type: string - title: OperatingTurnAnswerKind - enum: - - OPERATING_TURN_ANSWER_KIND_ANSWER_UNSPECIFIED - - OPERATING_TURN_ANSWER_KIND_NO_ANSWER - - OPERATING_TURN_ANSWER_KIND_DIRECT_ANSWER - - OPERATING_TURN_ANSWER_KIND_RECEIPT_ONLY - - OPERATING_TURN_ANSWER_KIND_WORK_STARTED - console.v1.OperatingTurnIntentKind: - type: string - title: OperatingTurnIntentKind - enum: - - OPERATING_TURN_INTENT_KIND_INTENT_UNSPECIFIED - - OPERATING_TURN_INTENT_KIND_UNKNOWN - - OPERATING_TURN_INTENT_KIND_OPERATIONAL - - OPERATING_TURN_INTENT_KIND_CAPABILITY_HELP - - OPERATING_TURN_INTENT_KIND_SETTINGS - - OPERATING_TURN_INTENT_KIND_APPROVAL - - OPERATING_TURN_INTENT_KIND_EVIDENCE - console.v1.OperatingTurnRouteKind: - type: string - title: OperatingTurnRouteKind - enum: - - OPERATING_TURN_ROUTE_KIND_ROUTE_UNSPECIFIED - - OPERATING_TURN_ROUTE_KIND_DIRECT_ANSWER - - OPERATING_TURN_ROUTE_KIND_GOVERNED_WORK - - OPERATING_TURN_ROUTE_KIND_BLOCKED - console.v1.OperatingTurnSafetyKind: - type: string - title: OperatingTurnSafetyKind - enum: - - OPERATING_TURN_SAFETY_KIND_SAFETY_UNSPECIFIED - - OPERATING_TURN_SAFETY_KIND_NOT_EVALUATED - - OPERATING_TURN_SAFETY_KIND_ALLOWED - - OPERATING_TURN_SAFETY_KIND_BLOCKED - console.v1.OperatingTurnState: - type: string - title: OperatingTurnState - enum: - - OPERATING_TURN_STATE_UNSPECIFIED - - OPERATING_TURN_STATE_ACCEPTED - - OPERATING_TURN_STATE_QUEUED - - OPERATING_TURN_STATE_RESPONDED - - OPERATING_TURN_STATE_FAILED - - OPERATING_TURN_STATE_RUNNING - - OPERATING_TURN_STATE_WAITING - - OPERATING_TURN_STATE_COMPLETED - - OPERATING_TURN_STATE_INTERRUPTED - console.v1.OperatingVerificationState: - type: string - title: OperatingVerificationState - enum: - - OPERATING_VERIFICATION_STATE_UNSPECIFIED - - OPERATING_VERIFICATION_STATE_NOT_REQUIRED - - OPERATING_VERIFICATION_STATE_PENDING - - OPERATING_VERIFICATION_STATE_VERIFIED - - OPERATING_VERIFICATION_STATE_FAILED - console.v1.PrivacySettingScope: - type: string - title: PrivacySettingScope - enum: - - PRIVACY_SETTING_SCOPE_UNSPECIFIED - - PRIVACY_SETTING_SCOPE_ORGANIZATION - - PRIVACY_SETTING_SCOPE_WORKSPACE - description: PrivacySettingScope selects which of the two rows a write targets. - console.v1.ProspectingDraftChannel: - type: string - title: ProspectingDraftChannel - enum: - - PROSPECTING_DRAFT_CHANNEL_UNSPECIFIED - - PROSPECTING_DRAFT_CHANNEL_EMAIL - description: |- - ProspectingDraftChannel is the channel a Radar outreach draft is written - for. Radar does not deliver; the channel is recorded for review only. - console.v1.ProspectingDraftReviewState: - type: string - title: ProspectingDraftReviewState - enum: - - PROSPECTING_DRAFT_REVIEW_STATE_UNSPECIFIED - - PROSPECTING_DRAFT_REVIEW_STATE_REVIEW_REQUIRED - - PROSPECTING_DRAFT_REVIEW_STATE_APPROVED - - PROSPECTING_DRAFT_REVIEW_STATE_REJECTED - description: ProspectingDraftReviewState is the durable review decision on a draft. - console.v1.ProspectingDraftTone: - type: string - title: ProspectingDraftTone - enum: - - PROSPECTING_DRAFT_TONE_UNSPECIFIED - - PROSPECTING_DRAFT_TONE_DIRECT - - PROSPECTING_DRAFT_TONE_WARM - - PROSPECTING_DRAFT_TONE_TECHNICAL - description: ProspectingDraftTone is the staff-selected register of the draft. - console.v1.ProspectingWatchProgramLifecycle: - type: string - title: ProspectingWatchProgramLifecycle - enum: - - PROSPECTING_WATCH_PROGRAM_LIFECYCLE_UNSPECIFIED - - PROSPECTING_WATCH_PROGRAM_LIFECYCLE_ACTIVE - - PROSPECTING_WATCH_PROGRAM_LIFECYCLE_PAUSED - - PROSPECTING_WATCH_PROGRAM_LIFECYCLE_ARCHIVED - description: |- - ProspectingWatchProgramLifecycle is the owner-authored lifecycle of a Radar - watch program. PAUSED is the close state; ACTIVE reopens it. - console.v1.ReceiptLifecycleState: - type: string - title: ReceiptLifecycleState - enum: - - RECEIPT_LIFECYCLE_STATE_UNSPECIFIED - - RECEIPT_LIFECYCLE_STATE_UNKNOWN - - RECEIPT_LIFECYCLE_STATE_PROPOSED - - RECEIPT_LIFECYCLE_STATE_QUEUED - - RECEIPT_LIFECYCLE_STATE_WAITING_APPROVAL - - RECEIPT_LIFECYCLE_STATE_BLOCKED - - RECEIPT_LIFECYCLE_STATE_NEEDS_INPUT - - RECEIPT_LIFECYCLE_STATE_UNAVAILABLE - - RECEIPT_LIFECYCLE_STATE_RUNNING - - RECEIPT_LIFECYCLE_STATE_SUCCEEDED - - RECEIPT_LIFECYCLE_STATE_VERIFIED - - RECEIPT_LIFECYCLE_STATE_DENIED - - RECEIPT_LIFECYCLE_STATE_CANCELLED - - RECEIPT_LIFECYCLE_STATE_FAILED - description: |- - ReceiptLifecycleState is the owner's single answer for where one receipt's - work stands. The owner resolves precedence across its typed lifecycle fields - so every client renders one state instead of re-deriving it from `status` and - payload evidence. UNSPECIFIED means the responding build did not state a - lifecycle; UNKNOWN means the owner holds lifecycle evidence it cannot name, - and clients must not present such work as finished. - console.v1.RuleScope: - type: string - title: RuleScope - enum: - - RULE_SCOPE_UNSPECIFIED - - RULE_SCOPE_ORGANIZATION - - RULE_SCOPE_WORKSPACE - description: |- - RuleScope records which tenant level a managed rule was authored at, so a - client can tell an organization-wide rule from a workspace override. - console.v1.SkillAnalysisVerdict: - type: string - title: SkillAnalysisVerdict - enum: - - SKILL_ANALYSIS_VERDICT_UNSPECIFIED - - SKILL_ANALYSIS_VERDICT_PASS - - SKILL_ANALYSIS_VERDICT_NEEDS_REVIEW - - SKILL_ANALYSIS_VERDICT_BLOCKED - - SKILL_ANALYSIS_VERDICT_UNSCANNABLE - console.v1.StaffInferenceRoutingPurpose: - type: string - title: StaffInferenceRoutingPurpose - enum: - - STAFF_INFERENCE_ROUTING_PURPOSE_UNSPECIFIED - - STAFF_INFERENCE_ROUTING_PURPOSE_DEFAULT_CHAT - - STAFF_INFERENCE_ROUTING_PURPOSE_FAST_CHEAP - - STAFF_INFERENCE_ROUTING_PURPOSE_DEEP_REASONING - - STAFF_INFERENCE_ROUTING_PURPOSE_CODING - - STAFF_INFERENCE_ROUTING_PURPOSE_EVALUATION - description: |- - StaffInferenceRoutingPurpose identifies a bounded Dex workload class. The - server, not the browser, maps call sites to these purposes. - console.v1.StaffWorkspaceAccessState: - type: string - title: StaffWorkspaceAccessState - enum: - - STAFF_WORKSPACE_ACCESS_STATE_UNSPECIFIED - - STAFF_WORKSPACE_ACCESS_STATE_DIRECTORY_ONLY - - STAFF_WORKSPACE_ACCESS_STATE_ACTIVE_READ_ONLY - - STAFF_WORKSPACE_ACCESS_STATE_EXPIRED - - STAFF_WORKSPACE_ACCESS_STATE_GRANT_MISMATCH - - STAFF_WORKSPACE_ACCESS_STATE_UNAVAILABLE - console.v1.TenantPrivacyMode: - type: string - title: TenantPrivacyMode - enum: - - TENANT_PRIVACY_MODE_UNSPECIFIED - - TENANT_PRIVACY_MODE_STANDARD - - TENANT_PRIVACY_MODE_NO_TRAINING - - TENANT_PRIVACY_MODE_RESTRICTED - description: |- - TenantPrivacyMode is how much of a tenant's data this system may copy into - systems other than the store that owns it. It is the wire spelling of - platform_core_types::PrivacyMode. - console.v1.ThreadGatewayPermission: - type: string - title: ThreadGatewayPermission - enum: - - THREAD_GATEWAY_PERMISSION_UNSPECIFIED - - THREAD_GATEWAY_PERMISSION_SUBMIT - - THREAD_GATEWAY_PERMISSION_WATCH - - THREAD_GATEWAY_PERMISSION_INTERRUPT - console.v1.WorkspaceSettingsAvailabilityStatus: - type: string - title: WorkspaceSettingsAvailabilityStatus - enum: - - WORKSPACE_SETTINGS_AVAILABILITY_STATUS_UNSPECIFIED - - WORKSPACE_SETTINGS_AVAILABILITY_STATUS_ACTIVE - - WORKSPACE_SETTINGS_AVAILABILITY_STATUS_UNAVAILABLE - console.v1.WorkspaceSettingsBillingStatus: - type: string - title: WorkspaceSettingsBillingStatus - enum: - - WORKSPACE_SETTINGS_BILLING_STATUS_UNSPECIFIED - - WORKSPACE_SETTINGS_BILLING_STATUS_ACTIVE - - WORKSPACE_SETTINGS_BILLING_STATUS_TRIALING - - WORKSPACE_SETTINGS_BILLING_STATUS_PAST_DUE - - WORKSPACE_SETTINGS_BILLING_STATUS_CANCELED - - WORKSPACE_SETTINGS_BILLING_STATUS_UNAVAILABLE - - WORKSPACE_SETTINGS_BILLING_STATUS_PAUSED - console.v1.WorkspaceSettingsIdentityProviderStatus: - type: string - title: WorkspaceSettingsIdentityProviderStatus - enum: - - WORKSPACE_SETTINGS_IDENTITY_PROVIDER_STATUS_UNSPECIFIED - - WORKSPACE_SETTINGS_IDENTITY_PROVIDER_STATUS_CONFIGURED - - WORKSPACE_SETTINGS_IDENTITY_PROVIDER_STATUS_CONNECTED - - WORKSPACE_SETTINGS_IDENTITY_PROVIDER_STATUS_DEGRADED - - WORKSPACE_SETTINGS_IDENTITY_PROVIDER_STATUS_DISABLED - - WORKSPACE_SETTINGS_IDENTITY_PROVIDER_STATUS_UNAVAILABLE - console.v1.WorkspaceSettingsIntegrationStatus: - type: string - title: WorkspaceSettingsIntegrationStatus - enum: - - WORKSPACE_SETTINGS_INTEGRATION_STATUS_UNSPECIFIED - - WORKSPACE_SETTINGS_INTEGRATION_STATUS_CONFIGURED - - WORKSPACE_SETTINGS_INTEGRATION_STATUS_CONNECTED - - WORKSPACE_SETTINGS_INTEGRATION_STATUS_HEALTHY - - WORKSPACE_SETTINGS_INTEGRATION_STATUS_DEGRADED - - WORKSPACE_SETTINGS_INTEGRATION_STATUS_DISABLED - - WORKSPACE_SETTINGS_INTEGRATION_STATUS_UNAVAILABLE - console.v1.WorkspaceSettingsMemberStatus: - type: string - title: WorkspaceSettingsMemberStatus - enum: - - WORKSPACE_SETTINGS_MEMBER_STATUS_UNSPECIFIED - - WORKSPACE_SETTINGS_MEMBER_STATUS_ACTIVE - - WORKSPACE_SETTINGS_MEMBER_STATUS_INVITED - - WORKSPACE_SETTINGS_MEMBER_STATUS_SUSPENDED - console.v1.WorkspaceSettingsOwnerServiceStatus: - type: string - title: WorkspaceSettingsOwnerServiceStatus - enum: - - WORKSPACE_SETTINGS_OWNER_SERVICE_STATUS_UNSPECIFIED - - WORKSPACE_SETTINGS_OWNER_SERVICE_STATUS_ACTIVE - - WORKSPACE_SETTINGS_OWNER_SERVICE_STATUS_PROJECTION - - WORKSPACE_SETTINGS_OWNER_SERVICE_STATUS_PARTIAL - - WORKSPACE_SETTINGS_OWNER_SERVICE_STATUS_LOCAL - - WORKSPACE_SETTINGS_OWNER_SERVICE_STATUS_UNAVAILABLE - console.v1.WorkspaceSettingsRole: - type: string - title: WorkspaceSettingsRole - enum: - - WORKSPACE_SETTINGS_ROLE_UNSPECIFIED - - WORKSPACE_SETTINGS_ROLE_VIEWER - - WORKSPACE_SETTINGS_ROLE_DEVELOPER - - WORKSPACE_SETTINGS_ROLE_BILLING_ADMIN - - WORKSPACE_SETTINGS_ROLE_ADMIN - - WORKSPACE_SETTINGS_ROLE_OWNER - console.v1.WorkspaceSettingsSource: - type: string - title: WorkspaceSettingsSource - enum: - - WORKSPACE_SETTINGS_SOURCE_UNSPECIFIED - - WORKSPACE_SETTINGS_SOURCE_CONSOLE_SETTINGS - - WORKSPACE_SETTINGS_SOURCE_CONSOLE_INVITATION - - WORKSPACE_SETTINGS_SOURCE_AUTHENTICATED_PRINCIPAL - - WORKSPACE_SETTINGS_SOURCE_MANUAL - - WORKSPACE_SETTINGS_SOURCE_SCIM - - WORKSPACE_SETTINGS_SOURCE_SAML - - WORKSPACE_SETTINGS_SOURCE_OAUTH - - WORKSPACE_SETTINGS_SOURCE_SYSTEM - - WORKSPACE_SETTINGS_SOURCE_CONSOLE_SNAPSHOT - console.v1.WorkspaceSpendBeatCadence: - type: string - title: WorkspaceSpendBeatCadence - enum: - - WORKSPACE_SPEND_BEAT_CADENCE_UNSPECIFIED - - WORKSPACE_SPEND_BEAT_CADENCE_DAILY - - WORKSPACE_SPEND_BEAT_CADENCE_WEEKLY - google.protobuf.NullValue: - type: string - title: NullValue - enum: - - NULL_VALUE - description: |- - `NullValue` is a singleton enumeration to represent the null value for the - `Value` type union. - - The JSON representation for `NullValue` is JSON `null`. - memory.v1.MemoryReviewStatus: - type: string - title: MemoryReviewStatus - enum: - - MEMORY_REVIEW_STATUS_UNSPECIFIED - - MEMORY_REVIEW_STATUS_APPROVED - - MEMORY_REVIEW_STATUS_PROPOSED - - MEMORY_REVIEW_STATUS_REJECTED - description: |- - MemoryReviewStatus controls whether a memory is active for recall or still - reviewable as a proposal. - memory.v1.Scope: - type: string - title: Scope - enum: - - SCOPE_UNSPECIFIED - - SCOPE_USER - - SCOPE_TEAM - - SCOPE_ORGANIZATION - - SCOPE_AGENT - - SCOPE_PROJECT - description: Scope controls memory visibility. - orbcontrol.v1.OrbCommandKind: - type: string - title: OrbCommandKind - enum: - - ORB_COMMAND_KIND_UNSPECIFIED - - ORB_COMMAND_KIND_WAKE - - ORB_COMMAND_KIND_STOP - description: OrbCommandKind is the first supported Platform-owned lifecycle command set. - orbcontrol.v1.OrbObservedLifecycle: - type: string - title: OrbObservedLifecycle - enum: - - ORB_OBSERVED_LIFECYCLE_UNSPECIFIED - - ORB_OBSERVED_LIFECYCLE_SLEEPING - - ORB_OBSERVED_LIFECYCLE_WAKING - - ORB_OBSERVED_LIFECYCLE_READY - - ORB_OBSERVED_LIFECYCLE_WORKING - - ORB_OBSERVED_LIFECYCLE_WAITING_FOR_YOU - - ORB_OBSERVED_LIFECYCLE_RECOVERING - - ORB_OBSERVED_LIFECYCLE_OFFLINE - description: OrbObservedLifecycle is the runtime owner's customer-safe lifecycle state. - platform.v1.RecordKind: - type: string - title: RecordKind - enum: - - RECORD_KIND_UNSPECIFIED - - RECORD_KIND_RUN - - RECORD_KIND_MODEL_RUN - - RECORD_KIND_TOOL_EXECUTION - - RECORD_KIND_POLICY_DECISION - - RECORD_KIND_APPROVAL - - RECORD_KIND_CREDENTIAL - - RECORD_KIND_CONNECTOR - - RECORD_KIND_CONNECTOR_SESSION - - RECORD_KIND_ARTIFACT - - RECORD_KIND_USAGE - - RECORD_KIND_RECEIPT - - RECORD_KIND_EVIDENCE - - RECORD_KIND_EVAL_RUN - description: |- - RecordKind identifies an authoritative operational record without copying - that record into a read model. The enclosing request supplies exact tenant - authority; the kind selects the owner resolver for record_id. - platform.v1.ResourceKind: - type: string - title: ResourceKind - enum: - - RESOURCE_KIND_UNSPECIFIED - - RESOURCE_KIND_AGENT - - RESOURCE_KIND_TOOL - - RESOURCE_KIND_REPO - - RESOURCE_KIND_DATASET - - RESOURCE_KIND_DATABASE - - RESOURCE_KIND_CRM_OBJECT - - RESOURCE_KIND_MODEL_ROUTE - - RESOURCE_KIND_EXTERNAL - - RESOURCE_KIND_VFS_OBJECT - - RESOURCE_KIND_VFS_OBJECT_VERSION - - RESOURCE_KIND_ARTIFACT - - RESOURCE_KIND_ARTIFACT_VERSION - - RESOURCE_KIND_GENERATED_ASSET - toolexecution.v1.ToolExecutionState: - type: string - title: ToolExecutionState - enum: - - TOOL_EXECUTION_STATE_UNSPECIFIED - - TOOL_EXECUTION_STATE_ACCEPTED - - TOOL_EXECUTION_STATE_POLICY_EVALUATING - - TOOL_EXECUTION_STATE_WAITING_APPROVAL - - TOOL_EXECUTION_STATE_RUNNING - - TOOL_EXECUTION_STATE_SUCCEEDED - - TOOL_EXECUTION_STATE_FAILED - - TOOL_EXECUTION_STATE_DENIED - - TOOL_EXECUTION_STATE_CANCELLED - description: ToolExecutionState is the durable lifecycle for one tool call. - traces.v1.TraceAnnotationKind: - type: string - title: TraceAnnotationKind - enum: - - TRACE_ANNOTATION_KIND_UNSPECIFIED - - TRACE_ANNOTATION_KIND_NOTE - - TRACE_ANNOTATION_KIND_ISSUE - - TRACE_ANNOTATION_KIND_GOOD - traces.v1.TraceAnnotationStatus: - type: string - title: TraceAnnotationStatus - enum: - - TRACE_ANNOTATION_STATUS_UNSPECIFIED - - TRACE_ANNOTATION_STATUS_ACTIVE - - TRACE_ANNOTATION_STATUS_RESOLVED - - TRACE_ANNOTATION_STATUS_DISMISSED - - TRACE_ANNOTATION_STATUS_ARCHIVED - agentruntime.v1.RuntimeWorkEnvelope: - type: object - properties: - id: - type: string - title: id - minLength: 1 - kind: - title: kind - $ref: '#/components/schemas/agentruntime.v1.RuntimeWorkEnvelopeKind' - rootId: - type: string - title: root_id - parentId: - type: string - title: parent_id - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: RuntimeWorkEnvelope - additionalProperties: false - description: |- - RuntimeWorkEnvelope identifies the durable work object that groups related - normalized triggers. For Slack this is usually a conversation thread; future - adapters can map email threads, Jira tickets, calendar events, and Teams - threads into the same runtime primitive. - agentruntime.v1.RuntimeWorkEnvelope.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - agents.v1.Agent: - type: object - properties: - id: - type: string - title: id - workspaceId: - type: string - title: workspace_id - name: - type: string - title: name - description: - type: string - title: description - agentType: - type: string - title: agent_type - description: |- - agent_type aligns with identity/v1 IntrospectResponse.agent_type and - IssueAgentTokenRequest.agent_type. Examples: "sdr", "support", "coding", - "ops", "research". - capabilities: - type: array - items: - type: string - title: capabilities - description: |- - capabilities aligns with identity/v1 IntrospectResponse.capabilities and - IssueAgentTokenRequest.capabilities. Used by capability-based delegation - routing. Examples: "hubspot-write", "email-send", "code-review". - surfaces: - type: array - items: - type: string - title: surfaces - description: |- - surfaces this agent can operate on. Aligns with the surface field in - meter/v1, objectives/v1, approvals/v1. Examples: "ensemble", "chat", - "maestro", "conductor", "slack". - status: - title: status - $ref: '#/components/schemas/agents.v1.AgentStatus' - activeConfigVersion: - type: integer - title: active_config_version - format: int32 - ownerId: - type: string - title: owner_id - lastHeartbeatAt: - title: last_heartbeat_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - surfaceTypes: - type: array - items: - $ref: '#/components/schemas/common.v1.Surface' - title: surface_types - a2a: - title: a2a - description: |- - a2a is the Platform-owned discovery projection for spec-native A2A peers. - Remote agents use it to discover where to fetch the Agent Card, which - transport/profile is supported, and which skills can be delegated to this - agent or its child/subagent lanes. - $ref: '#/components/schemas/agents.v1.AgentA2APeerProjection' - capacity: - title: capacity - description: |- - capacity is the registry-owned load projection used by fleet-scale - delegation discovery and operator read models. - $ref: '#/components/schemas/agents.v1.AgentCapacity' - title: Agent - additionalProperties: false - description: |- - Agent is the canonical agent definition record. - The id field is the value stored in every agent_id / agent string field - across the platform: meter/v1 RecordUsageRequest.agent_id, - objectives/v1 Objective.agent_id, approvals/v1 ApprovalRequest.agent_id, - governance/v1 EvaluateActionRequest.agent_id, memory/v1 Memory.agent, - and events/v1 Change.actor_id when actor_type is "agent". - agents.v1.AgentA2APeerProjection: - type: object - properties: - publicEndpointUrl: - type: string - title: public_endpoint_url - internalEndpointUrl: - type: string - title: internal_endpoint_url - agentCardUrl: - type: string - title: agent_card_url - protocolBinding: - type: string - title: protocol_binding - protocolVersion: - type: string - title: protocol_version - supportedExtensions: - type: array - items: - type: string - title: supported_extensions - skills: - type: array - items: - $ref: '#/components/schemas/agents.v1.AgentA2ASkill' - title: skills - securitySchemes: - type: array - items: - type: string - title: security_schemes - agentCardObservedAt: - title: agent_card_observed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - agentCardEtag: - type: string - title: agent_card_etag - agentCardHash: - type: string - title: agent_card_hash - pushNotifications: - type: boolean - title: push_notifications - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: AgentA2APeerProjection - additionalProperties: false - agents.v1.AgentA2APeerProjection.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - agents.v1.AgentA2ASkill: - type: object - properties: - id: - type: string - title: id - name: - type: string - title: name - description: - type: string - title: description - tags: - type: array - items: - type: string - title: tags - inputModes: - type: array - items: - type: string - title: input_modes - outputModes: - type: array - items: - type: string - title: output_modes - requiredContextGrants: - type: array - items: - type: string - title: required_context_grants - approvalPolicyRef: - type: string - title: approval_policy_ref - maxAutonomy: - type: string - title: max_autonomy - requiredArtifactKinds: - type: array - items: - type: string - title: required_artifact_kinds - optionalArtifactKinds: - type: array - items: - type: string - title: optional_artifact_kinds - allowedTaskClasses: - type: array - items: - type: string - title: allowed_task_classes - deniedTaskClasses: - type: array - items: - type: string - title: denied_task_classes - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: AgentA2ASkill - additionalProperties: false - agents.v1.AgentA2ASkill.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - agents.v1.AgentCapacity: - type: object - properties: - current: - type: integer - title: current - format: int32 - max: - type: integer - title: max - format: int32 - remaining: - type: integer - title: remaining - format: int32 - reservedDelegationCount: - type: integer - title: reserved_delegation_count - format: int32 - title: AgentCapacity - additionalProperties: false - agents.v1.AgentConfig: - type: object - properties: - version: - type: integer - title: version - format: int32 - agentId: - type: string - title: agent_id - skillIds: - type: array - items: - type: string - title: skill_ids - description: |- - skill_ids reference skills/v1 Skill.id — the reusable capabilities - this agent has loaded. - promptBindings: - type: object - title: prompt_bindings - additionalProperties: - type: string - title: value - description: |- - prompt_bindings maps prompt name to label (e.g., "sdr-outreach" -> "production"). - Aligns with prompts/v1 ResolveRequest.name and ResolveRequest.label. - modelPreferences: - type: object - title: model_preferences - additionalProperties: - type: string - title: value - description: |- - model_preferences maps surface to preferred model identifier - (e.g., "ensemble" -> "claude-opus-4.6"). Aligns with meter/v1 - RecordUsageRequest.model and keys/v1 ResolveProviderRefRequest.provider. - integrationIds: - type: array - items: - type: string - title: integration_ids - description: |- - integration_ids reference connectors/v1 Connection.id — the external - system connections this agent is authorized to use. - entityTypeScopes: - type: array - items: - type: string - title: entity_type_scopes - description: |- - entity_type_scopes restrict which entities/v1 EntityType values this - agent can operate on. Empty means unrestricted. - maxConcurrentObjectives: - type: integer - title: max_concurrent_objectives - format: int32 - description: |- - max_concurrent_objectives caps the number of objectives/v1 Objective - records this agent can hold in RUNNING or BLOCKED state simultaneously. - costBudgetUsd: - type: number - title: cost_budget_usd - format: double - description: |- - cost_budget_usd is the per-period spend ceiling enforced against - meter/v1 usage records for this agent. - notificationChannel: - type: string - title: notification_channel - description: |- - notification_channel specifies the preferred notifications/v1 - DeliveryChannel for this agent's escalations. Stored as string to - avoid cross-package import (e.g., "DELIVERY_CHANNEL_SLACK"). - parameters: - title: parameters - description: parameters holds arbitrary agent-specific tuning knobs. - $ref: '#/components/schemas/google.protobuf.Struct' - author: - type: string - title: author - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - entityTypeScopeEnums: - type: array - items: - $ref: '#/components/schemas/common.v1.EntityType' - title: entity_type_scope_enums - notificationChannelEnum: - title: notification_channel_enum - $ref: '#/components/schemas/common.v1.DeliveryChannel' - teammateProfile: - title: teammate_profile - $ref: '#/components/schemas/agents.v1.DigitalTeammateProfile' - connectorRequirements: - type: array - items: - $ref: '#/components/schemas/agents.v1.ConnectorRequirement' - title: connector_requirements - description: Portable provider needs. Connection IDs remain workspace-local bindings. - title: AgentConfig - additionalProperties: false - description: |- - AgentConfig is an immutable snapshot of everything that shapes an agent's - behavior. Promotion and rollback are both config version reassignments — - the same pattern as prompts/v1 Label. - agents.v1.AgentConfig.ModelPreferencesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: ModelPreferencesEntry - additionalProperties: false - agents.v1.AgentConfig.PromptBindingsEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: PromptBindingsEntry - additionalProperties: false - agents.v1.AutonomyPolicy: - type: object - properties: - rules: - type: array - items: - $ref: '#/components/schemas/agents.v1.AutonomyRule' - title: rules - defaultAuthority: - title: default_authority - $ref: '#/components/schemas/agents.v1.AutonomyAuthority' - maxRiskWithoutApproval: - title: max_risk_without_approval - $ref: '#/components/schemas/common.v1.RiskLevel' - title: AutonomyPolicy - additionalProperties: false - description: |- - AutonomyPolicy describes the default authority and specific action rules - that ToolExecution, Governance, and Approvals can enforce. - agents.v1.AutonomyRule: - type: object - properties: - actionType: - type: string - title: action_type - toolCapability: - type: string - title: tool_capability - maxRisk: - title: max_risk - $ref: '#/components/schemas/common.v1.RiskLevel' - authority: - not: - enum: - - 0 - title: authority - $ref: '#/components/schemas/agents.v1.AutonomyAuthority' - approvalPolicyRef: - type: string - title: approval_policy_ref - governancePolicyRef: - type: string - title: governance_policy_ref - rationale: - type: string - title: rationale - title: AutonomyRule - additionalProperties: false - description: AutonomyRule constrains a class of actions or tool capabilities. - agents.v1.CommitmentPolicy: - type: object - properties: - allowedKinds: - type: array - items: - $ref: '#/components/schemas/agents.v1.CommitmentKind' - title: allowed_kinds - templates: - type: array - items: - $ref: '#/components/schemas/agents.v1.CommitmentTemplate' - title: templates - defaultDueSeconds: - type: integer - title: default_due_seconds - format: int32 - maxOpenCommitments: - type: integer - title: max_open_commitments - format: int32 - requireObjectiveForCommitment: - type: boolean - title: require_objective_for_commitment - title: CommitmentPolicy - additionalProperties: false - description: |- - CommitmentPolicy describes which durable objectives and wakes can be created - from teammate commitments. - agents.v1.CommitmentTemplate: - type: object - properties: - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/agents.v1.CommitmentKind' - objectiveTitleTemplate: - type: string - title: objective_title_template - objectiveDescriptionTemplate: - type: string - title: objective_description_template - wakeReasonTemplate: - type: string - title: wake_reason_template - requiredJoinKeys: - type: array - items: - type: string - title: required_join_keys - title: CommitmentTemplate - additionalProperties: false - description: CommitmentTemplate maps a commitment kind to objective and wake templates. - agents.v1.ConnectorRequirement: - type: object - properties: - providerId: - type: string - title: provider_id - minLength: 1 - requiredCapabilities: - type: array - items: - type: string - title: required_capabilities - optionalCapabilities: - type: array - items: - type: string - title: optional_capabilities - required: - type: boolean - title: required - title: ConnectorRequirement - additionalProperties: false - agents.v1.DigitalTeammateProfile: - type: object - properties: - id: - type: string - title: id - version: - type: integer - title: version - format: int32 - workspaceId: - type: string - title: workspace_id - agentId: - type: string - title: agent_id - displayName: - type: string - title: display_name - role: - type: string - title: role - purpose: - type: string - title: purpose - ownerUserId: - type: string - title: owner_user_id - ownerTeamId: - type: string - title: owner_team_id - surfaceTypes: - type: array - items: - $ref: '#/components/schemas/common.v1.Surface' - title: surface_types - lifecycle: - title: lifecycle - $ref: '#/components/schemas/agents.v1.TeammateLifecycle' - responsibilities: - type: array - items: - $ref: '#/components/schemas/agents.v1.TeammateResponsibility' - title: responsibilities - commitmentPolicy: - title: commitment_policy - $ref: '#/components/schemas/agents.v1.CommitmentPolicy' - initiativePolicy: - title: initiative_policy - $ref: '#/components/schemas/agents.v1.InitiativePolicy' - autonomyPolicy: - title: autonomy_policy - $ref: '#/components/schemas/agents.v1.AutonomyPolicy' - memoryPolicy: - title: memory_policy - $ref: '#/components/schemas/agents.v1.MemoryPolicy' - presencePolicy: - title: presence_policy - $ref: '#/components/schemas/agents.v1.PresencePolicy' - outputPolicy: - title: output_policy - $ref: '#/components/schemas/agents.v1.OutputPolicy' - evalPolicy: - title: eval_policy - $ref: '#/components/schemas/agents.v1.EvalPolicy' - escalationPolicy: - title: escalation_policy - $ref: '#/components/schemas/agents.v1.EscalationPolicy' - labels: - type: object - title: labels - additionalProperties: - type: string - title: value - parameters: - title: parameters - $ref: '#/components/schemas/google.protobuf.Struct' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - channelManifests: - type: array - items: - $ref: '#/components/schemas/agents.v1.TeammateChannelManifest' - title: channel_manifests - title: DigitalTeammateProfile - additionalProperties: false - description: |- - DigitalTeammateProfile is the versioned contract for how an AgentConfig acts - as a durable teammate across objectives, workflows, tools, memory, evals, and - Slack or other delivery surfaces. - agents.v1.DigitalTeammateProfile.LabelsEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: LabelsEntry - additionalProperties: false - agents.v1.EscalationPolicy: - type: object - properties: - approverUserIds: - type: array - items: - type: string - title: approver_user_ids - approverTeamIds: - type: array - items: - type: string - title: approver_team_ids - escalateAfterSeconds: - type: integer - title: escalate_after_seconds - format: int32 - fallbackChannel: - title: fallback_channel - $ref: '#/components/schemas/common.v1.DeliveryChannel' - title: EscalationPolicy - additionalProperties: false - description: |- - EscalationPolicy describes who must be contacted when the teammate blocks or - needs approval. - agents.v1.EvalBinding: - type: object - properties: - suiteName: - type: string - title: suite_name - metricName: - type: string - title: metric_name - minimumScore: - type: number - title: minimum_score - format: double - failureAction: - type: string - title: failure_action - title: EvalBinding - additionalProperties: false - description: EvalBinding describes one score that should gate or monitor teammate quality. - agents.v1.EvalPolicy: - type: object - properties: - bindings: - type: array - items: - $ref: '#/components/schemas/agents.v1.EvalBinding' - title: bindings - loopDefinitionId: - type: string - title: loop_definition_id - productionSampleRateBasisPoints: - type: integer - title: production_sample_rate_basis_points - maximum: 10000 - format: int32 - title: EvalPolicy - additionalProperties: false - description: EvalPolicy binds production behavior to loop and eval scoring. - agents.v1.InitiativePolicy: - type: object - properties: - triggers: - type: array - items: - $ref: '#/components/schemas/agents.v1.InitiativeTrigger' - title: triggers - maxInitiatedRunsPerDay: - type: integer - title: max_initiated_runs_per_day - format: int32 - requireHumanSeed: - type: boolean - title: require_human_seed - title: InitiativePolicy - additionalProperties: false - description: |- - InitiativePolicy describes bounded conditions where a teammate can start or - resume work proactively. - agents.v1.InitiativeTrigger: - type: object - properties: - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/agents.v1.InitiativeTriggerKind' - triggerRef: - type: string - title: trigger_ref - filterExpr: - type: string - title: filter_expr - workflowDefinitionId: - type: string - title: workflow_definition_id - objectiveTemplateId: - type: string - title: objective_template_id - title: InitiativeTrigger - additionalProperties: false - description: InitiativeTrigger binds a proactive trigger to workflow or objective state. - agents.v1.MemoryPolicy: - type: object - properties: - allowedScopeRefs: - type: array - items: - type: string - title: allowed_scope_refs - allowUserMemory: - type: boolean - title: allow_user_memory - allowTeamMemory: - type: boolean - title: allow_team_memory - allowAgentMemory: - type: boolean - title: allow_agent_memory - requireReviewForNewMemory: - type: boolean - title: require_review_for_new_memory - defaultRetentionDays: - type: integer - title: default_retention_days - format: int32 - requiredSourceTypes: - type: array - items: - type: string - title: required_source_types - allowCrossChannelRecall: - type: boolean - title: allow_cross_channel_recall - title: MemoryPolicy - additionalProperties: false - description: MemoryPolicy describes what a teammate may recall or propose remembering. - agents.v1.OutputPolicy: - type: object - properties: - requiredArtifactKinds: - type: array - items: - type: string - title: required_artifact_kinds - optionalArtifactKinds: - type: array - items: - type: string - title: optional_artifact_kinds - renderChannelCards: - type: boolean - title: render_channel_cards - defaultVisibility: - type: string - title: default_visibility - title: OutputPolicy - additionalProperties: false - description: OutputPolicy describes durable work products and channel-safe renderings. - agents.v1.PresencePolicy: - type: object - properties: - primaryChannel: - title: primary_channel - $ref: '#/components/schemas/common.v1.DeliveryChannel' - primaryChannelId: - type: string - title: primary_channel_id - defaultThreadPolicy: - type: string - title: default_thread_policy - progressUpdateIntervalSeconds: - type: integer - title: progress_update_interval_seconds - format: int32 - visibleEvents: - type: array - items: - $ref: '#/components/schemas/agents.v1.PresenceEvent' - title: visible_events - postActionReceipts: - type: boolean - title: post_action_receipts - postBlockerUpdates: - type: boolean - title: post_blocker_updates - title: PresencePolicy - additionalProperties: false - description: |- - PresencePolicy describes how a teammate reports work back to Slack or other - delivery channels. - agents.v1.TeammateChannelManifest: - type: object - properties: - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/agents.v1.TeammateChannelKind' - label: - type: string - title: label - deliveryChannel: - not: - enum: - - 0 - title: delivery_channel - $ref: '#/components/schemas/common.v1.DeliveryChannel' - platformSurface: - title: platform_surface - $ref: '#/components/schemas/common.v1.Surface' - channelId: - type: string - title: channel_id - capabilities: - type: array - items: - $ref: '#/components/schemas/agents.v1.TeammateChannelCapability' - title: capabilities - inboundEvents: - type: array - items: - $ref: '#/components/schemas/agents.v1.TeammateChannelEventKind' - title: inbound_events - runtimeEvents: - type: array - items: - $ref: '#/components/schemas/agents.v1.TeammateRuntimeRenderEventKind' - title: runtime_events - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: TeammateChannelManifest - additionalProperties: false - description: |- - TeammateChannelManifest describes one channel adapter supported by a - teammate profile. Durable execution remains owned by AgentRuntime; this - manifest lets product surfaces declare the provider-specific ingress and - rendering coverage they can project. - agents.v1.TeammateChannelManifest.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - agents.v1.TeammateResponsibility: - type: object - properties: - id: - type: string - title: id - title: - type: string - title: title - description: - type: string - title: description - capabilityRefs: - type: array - items: - type: string - title: capability_refs - ownedEntityTypes: - type: array - items: - $ref: '#/components/schemas/common.v1.EntityType' - title: owned_entity_types - defaultSkillIds: - type: array - items: - type: string - title: default_skill_ids - promptNames: - type: array - items: - type: string - title: prompt_names - successMetricRefs: - type: array - items: - type: string - title: success_metric_refs - title: TeammateResponsibility - additionalProperties: false - description: |- - TeammateResponsibility binds a role claim to capabilities, entities, prompts, - skills, and measurable outcomes. - connectors.v1.ConnectorCatalogProvenance: - type: object - properties: - basis: - type: string - title: basis - sourceUrl: - type: string - title: source_url - lastVerifiedAt: - type: string - title: last_verified_at - verificationLevel: - title: verification_level - $ref: '#/components/schemas/connectors.v1.ConnectorVerificationLevel' - evidenceKind: - title: evidence_kind - $ref: '#/components/schemas/connectors.v1.ConnectorEvidenceKind' - title: ConnectorCatalogProvenance - additionalProperties: false - description: |- - ConnectorCatalogProvenance records where a catalog-derived value came from - (for example an OpenAPI spec import), when it was last verified, and the - bounded evidence behind its current verification level. - connectors.v1.ProviderResourceEnvelope: - type: object - properties: - schemaVersion: - type: string - title: schema_version - stableResourceId: - type: string - title: stable_resource_id - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - providerId: - type: string - title: provider_id - connectionId: - type: string - title: connection_id - sourceFamilyId: - type: string - title: source_family_id - originatingPrincipalId: - type: string - title: originating_principal_id - resourceKind: - type: string - title: resource_kind - parentResourceId: - type: string - title: parent_resource_id - visibilityClass: - title: visibility_class - $ref: '#/components/schemas/connectors.v1.ProviderResourceVisibilityClass' - visibilityPrincipalIds: - type: array - items: - type: string - title: visibility_principal_ids - visibilityMembershipRef: - type: string - title: visibility_membership_ref - contentTrust: - title: content_trust - $ref: '#/components/schemas/connectors.v1.ProviderContentTrust' - payloadSha256: - type: string - title: payload_sha256 - providerRevision: - type: string - title: provider_revision - lifecycleState: - title: lifecycle_state - $ref: '#/components/schemas/connectors.v1.ProviderResourceLifecycleState' - lifecycleGeneration: - type: - - integer - - string - title: lifecycle_generation - format: int64 - purgeCorrelationId: - type: string - title: purge_correlation_id - title: ProviderResourceEnvelope - additionalProperties: false - connectors.v1.SourceAuthorityObservation: - type: object - properties: - state: - title: state - $ref: '#/components/schemas/connectors.v1.SourceAuthorityState' - reason: - type: string - title: reason - maxLength: 256 - minLength: 1 - freshnessMethod: - title: freshness_method - $ref: '#/components/schemas/connectors.v1.SourceAuthorityFreshnessMethod' - observedAt: - title: observed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - lastConfirmedAt: - title: last_confirmed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - ownerSnapshotReference: - type: string - title: owner_snapshot_reference - maxLength: 256 - description: |- - Opaque owner reference only; never a token, secret, private key, or raw - provider response body. - title: SourceAuthorityObservation - additionalProperties: false - description: |- - SourceAuthorityObservation is credential-free evidence from the external - source owner. Empty optional timestamps/reference fields mean that the - owner has not supplied that evidence; they must not be inferred locally. - console.v1.AcceptOperatingProjectSnapshotRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - projectResourceId: - type: string - title: project_resource_id - maxLength: 255 - minLength: 1 - channelId: - type: string - title: channel_id - idempotencyKey: - type: string - title: idempotency_key - maxLength: 255 - minLength: 1 - expectedRefVersion: - type: - - integer - - string - title: expected_ref_version - format: int64 - description: Absent creates the first accepted snapshot; a value requires exact CAS. - nullable: true - files: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingProjectSnapshotFileInput' - title: files - maxItems: 1000 - description: Complete workspace manifest, including unchanged files. Omitted files are removed. - title: AcceptOperatingProjectSnapshotRequest - required: - - query - additionalProperties: false - console.v1.AcceptOperatingProjectSnapshotResponse: - type: object - properties: - projectSource: - title: project_source - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionProjectSource' - manualAcceptanceAvailable: - type: boolean - title: manual_acceptance_available - importExecutionId: - type: string - title: import_execution_id - importState: - type: string - title: import_state - importError: - type: string - title: import_error - title: AcceptOperatingProjectSnapshotResponse - additionalProperties: false - console.v1.ActivityEvent: - type: object - properties: - id: - type: string - title: id - eventType: - type: string - title: event_type - title: - type: string - title: title - detail: - type: string - title: detail - assetId: - type: string - title: asset_id - agentId: - type: string - title: agent_id - traceId: - type: string - title: trace_id - approvalId: - type: string - title: approval_id - actor: - type: string - title: actor - status: - type: string - title: status - riskLevel: - title: risk_level - $ref: '#/components/schemas/common.v1.RiskLevel' - costUsd: - type: number - title: cost_usd - format: double - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - relatedResources: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: related_resources - title: ActivityEvent - additionalProperties: false - console.v1.AdmitBusinessObjectObservationRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - objectId: - type: string - title: object_id - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - authorityEpoch: - type: - - integer - - string - title: authority_epoch - format: int64 - title: AdmitBusinessObjectObservationRequest - additionalProperties: false - console.v1.AdmitBusinessObjectObservationResponse: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/console.v1.BusinessObject' - title: AdmitBusinessObjectObservationResponse - additionalProperties: false - console.v1.AgentProductActionCatalog: - type: object - properties: - resolved: - type: boolean - title: resolved - published: - type: integer - title: published - format: int32 - scopeCompatible: - type: integer - title: scope_compatible - format: int32 - reads: - type: integer - title: reads - format: int32 - writes: - type: integer - title: writes - format: int32 - approvalRequired: - type: integer - title: approval_required - format: int32 - destructive: - type: integer - title: destructive - format: int32 - title: AgentProductActionCatalog - additionalProperties: false - console.v1.AgentProductConnection: - type: object - properties: - id: - type: string - title: id - providerId: - type: string - title: provider_id - displayName: - type: string - title: display_name - healthStatus: - title: health_status - $ref: '#/components/schemas/connectors.v1.HealthStatus' - healthReason: - type: string - title: health_reason - providerName: - type: string - title: provider_name - bound: - type: boolean - title: bound - actionCatalog: - title: action_catalog - description: |- - Connector-owned published actions compatible with this connection's - scopes. These counts do not imply agent policy admission or execution. - $ref: '#/components/schemas/console.v1.AgentProductActionCatalog' - title: AgentProductConnection - additionalProperties: false - console.v1.AgentProductPrompt: - type: object - properties: - name: - type: string - title: name - label: - type: string - title: label - content: - type: string - title: content - versionId: - type: string - title: version_id - version: - type: integer - title: version - format: int32 - resolved: - type: boolean - title: resolved - title: AgentProductPrompt - additionalProperties: false - description: |- - Prompt content is resolved by the Prompt owner for the active configuration. - An unavailable owner never turns a binding label into claimed instructions. - console.v1.AgentWorkforceActionAuthorityBoundary: - type: object - properties: - actionLabel: - type: string - title: action_label - approvalQueueState: - type: string - title: approval_queue_state - authoritySubject: - type: string - title: authority_subject - credentialProvider: - type: string - title: credential_provider - unprovenBoundary: - type: string - title: unproven_boundary - nextAction: - type: string - title: next_action - title: AgentWorkforceActionAuthorityBoundary - additionalProperties: false - console.v1.AgentWorkforceActionEvidence: - type: object - properties: - actionId: - type: string - title: action_id - toolName: - type: string - title: tool_name - connectorId: - type: string - title: connector_id - capability: - type: string - title: capability - targetSummary: - type: string - title: target_summary - decision: - type: string - title: decision - mutatesResource: - type: boolean - title: mutates_resource - riskLevel: - title: risk_level - $ref: '#/components/schemas/common.v1.RiskLevel' - safeArgumentsRef: - type: string - title: safe_arguments_ref - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - missingEvidence: - type: array - items: - type: string - title: missing_evidence - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - principalEvidenceState: - type: string - title: principal_evidence_state - credentialEvidenceState: - type: string - title: credential_evidence_state - costEvidenceState: - type: string - title: cost_evidence_state - title: AgentWorkforceActionEvidence - additionalProperties: false - console.v1.AgentWorkforceApprovalBlockerBucket: - type: object - properties: - code: - type: string - title: code - label: - type: string - title: label - detail: - type: string - title: detail - recoveryAction: - type: string - title: recovery_action - count: - type: integer - title: count - format: int32 - title: AgentWorkforceApprovalBlockerBucket - additionalProperties: false - console.v1.AgentWorkforceApprovalDisablement: - type: object - properties: - code: - type: string - title: code - description: |- - code is one of none, missing_credential_authority, - unverified_run_as_identity, missing_cost_evidence, - missing_action_evidence, security_decision_blocked, or - security_review_required. - label: - type: string - title: label - detail: - type: string - title: detail - recoveryAction: - type: string - title: recovery_action - evidenceGapIds: - type: array - items: - type: string - title: evidence_gap_ids - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - title: AgentWorkforceApprovalDisablement - additionalProperties: false - console.v1.AgentWorkforceApprovalQueueSummary: - type: object - properties: - totalRecords: - type: integer - title: total_records - format: int32 - stateBuckets: - type: array - items: - $ref: '#/components/schemas/console.v1.AgentWorkforceApprovalStateBucket' - title: state_buckets - blockerBuckets: - type: array - items: - $ref: '#/components/schemas/console.v1.AgentWorkforceApprovalBlockerBucket' - title: blocker_buckets - missingEvidenceBuckets: - type: array - items: - $ref: '#/components/schemas/console.v1.AgentWorkforceMissingEvidenceBucket' - title: missing_evidence_buckets - title: AgentWorkforceApprovalQueueSummary - additionalProperties: false - console.v1.AgentWorkforceApprovalStateBucket: - type: object - properties: - state: - type: string - title: state - label: - type: string - title: label - count: - type: integer - title: count - format: int32 - nextAction: - type: string - title: next_action - title: AgentWorkforceApprovalStateBucket - additionalProperties: false - console.v1.AgentWorkforceDebugIdentifiers: - type: object - properties: - spanIds: - type: array - items: - type: string - title: span_ids - rawReferenceIds: - type: array - items: - type: string - title: raw_reference_ids - sourceEventIds: - type: array - items: - type: string - title: source_event_ids - attributes: - title: attributes - $ref: '#/components/schemas/google.protobuf.Struct' - runId: - type: string - title: run_id - sessionId: - type: string - title: session_id - traceId: - type: string - title: trace_id - title: AgentWorkforceDebugIdentifiers - additionalProperties: false - console.v1.AgentWorkforceMissingEvidenceBucket: - type: object - properties: - label: - type: string - title: label - recoveryAction: - type: string - title: recovery_action - count: - type: integer - title: count - format: int32 - title: AgentWorkforceMissingEvidenceBucket - additionalProperties: false - console.v1.AgentWorkforceProofSummary: - type: object - properties: - principalEvidenceState: - type: string - title: principal_evidence_state - credentialEvidenceState: - type: string - title: credential_evidence_state - costEvidenceState: - type: string - title: cost_evidence_state - actionEvidenceState: - type: string - title: action_evidence_state - endpointGuardrailState: - type: string - title: endpoint_guardrail_state - approvalReady: - type: boolean - title: approval_ready - blockingReasons: - type: array - items: - type: string - title: blocking_reasons - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - title: AgentWorkforceProofSummary - additionalProperties: false - console.v1.AgentWorkforceQuestionSummary: - type: object - properties: - canApproveThis: - type: string - title: can_approve_this - evidenceMissing: - type: string - title: evidence_missing - agentSaw: - type: string - title: agent_saw - agentTriedToDo: - type: string - title: agent_tried_to_do - wasDenied: - type: string - title: was_denied - shouldDoNext: - type: string - title: should_do_next - title: AgentWorkforceQuestionSummary - additionalProperties: false - console.v1.AgentWorkforceRecord: - type: object - properties: - id: - type: string - title: id - workspaceId: - type: string - title: workspace_id - organizationId: - type: string - title: organization_id - agentId: - type: string - title: agent_id - agentName: - type: string - title: agent_name - runtime: - type: string - title: runtime - owner: - type: string - title: owner - status: - type: string - title: status - description: status is one of approval_ready, needs_evidence, needs_review, blocked, or observed. - queueState: - type: string - title: queue_state - riskLevel: - title: risk_level - $ref: '#/components/schemas/common.v1.RiskLevel' - currentWork: - type: string - title: current_work - runAsIdentity: - title: run_as_identity - $ref: '#/components/schemas/console.v1.RunAsIdentitySummary' - securityDecision: - title: security_decision - $ref: '#/components/schemas/console.v1.SecurityDecisionPacket' - actionEvidence: - type: array - items: - $ref: '#/components/schemas/console.v1.AgentWorkforceActionEvidence' - title: action_evidence - credentialAuthority: - title: credential_authority - $ref: '#/components/schemas/console.v1.CredentialAuthoritySummary' - costEvidence: - title: cost_evidence - $ref: '#/components/schemas/console.v1.CostEvidenceSummary' - nextAction: - type: string - title: next_action - missingEvidence: - type: array - items: - type: string - title: missing_evidence - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - debugIdentifiers: - title: debug_identifiers - $ref: '#/components/schemas/console.v1.AgentWorkforceDebugIdentifiers' - questionSummary: - title: question_summary - $ref: '#/components/schemas/console.v1.AgentWorkforceQuestionSummary' - approvalDisablement: - title: approval_disablement - $ref: '#/components/schemas/console.v1.AgentWorkforceApprovalDisablement' - endpointGuardrail: - title: endpoint_guardrail - $ref: '#/components/schemas/console.v1.EndpointGuardrailSummary' - proofSummary: - title: proof_summary - $ref: '#/components/schemas/console.v1.AgentWorkforceProofSummary' - approvalQueueState: - type: string - title: approval_queue_state - description: |- - approval_queue_state is one of approval_ready, approval_blocked, - needs_credential_evidence, needs_run_as_identity, - needs_cost_evidence, needs_action_evidence, security_review_required, - native_observed_only, or needs_evidence. - actionAuthorityBoundaries: - type: array - items: - $ref: '#/components/schemas/console.v1.AgentWorkforceActionAuthorityBoundary' - title: action_authority_boundaries - sourceReadiness: - type: array - items: - $ref: '#/components/schemas/console.v1.AgentWorkforceSourceReadiness' - title: source_readiness - description: |- - source_readiness is the server-owned readiness projection for the - collector/source paths that contributed observations or proof. Status is - one of configured, observing, proof_joined, approval_ready, or blocked. - title: AgentWorkforceRecord - additionalProperties: false - console.v1.AgentWorkforceSourceReadiness: - type: object - properties: - source: - type: string - title: source - description: |- - source is one of maestro, codex, claude_code, cursor, external, - llm_gateway, meter, credential_authority, identity, customer_mcp, - hook_otlp, desktop_sidecar, local_sidecar, external_agent, - external_self_report, cerebro, nimbus, or unknown. - collector: - type: string - title: collector - status: - type: string - title: status - proofStrength: - type: string - title: proof_strength - detail: - type: string - title: detail - blockingReason: - type: string - title: blocking_reason - approvalAuthority: - type: boolean - title: approval_authority - trustedMetadataOnly: - type: boolean - title: trusted_metadata_only - missingProof: - type: array - items: - type: string - title: missing_proof - joinKeys: - type: array - items: - type: string - title: join_keys - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - title: AgentWorkforceSourceReadiness - additionalProperties: false - console.v1.AgentWorkforceSubmittedEvidence: - type: object - properties: - evidenceId: - type: string - title: evidence_id - evidenceKind: - type: string - title: evidence_kind - evidenceSource: - type: string - title: evidence_source - proofStrength: - type: string - title: proof_strength - approvalAuthority: - type: boolean - title: approval_authority - trustedMetadataOnly: - type: boolean - title: trusted_metadata_only - detail: - type: string - title: detail - recordId: - type: string - title: record_id - traceId: - type: string - title: trace_id - spanId: - type: string - title: span_id - evidenceRef: - title: evidence_ref - $ref: '#/components/schemas/console.v1.RelatedResource' - title: AgentWorkforceSubmittedEvidence - additionalProperties: false - console.v1.AggregateCustomerIntelligencePatternsRequest: - type: object - properties: - productArea: - type: string - title: product_area - maxLength: 80 - journey: - type: string - title: journey - maxLength: 80 - authorities: - type: array - items: - $ref: '#/components/schemas/console.v1.CustomerIntelligenceAuthority' - title: authorities - maxItems: 6 - lifecycleStates: - type: array - items: - $ref: '#/components/schemas/console.v1.CustomerIntelligenceLifecycleState' - title: lifecycle_states - maxItems: 6 - createdAfter: - title: created_after - $ref: '#/components/schemas/google.protobuf.Timestamp' - minimumOrganizationCount: - type: integer - title: minimum_organization_count - minimum: 5 - format: int32 - title: AggregateCustomerIntelligencePatternsRequest - additionalProperties: false - console.v1.AggregateCustomerIntelligencePatternsResponse: - type: object - properties: - patterns: - type: array - items: - $ref: '#/components/schemas/console.v1.CustomerIntelligencePattern' - title: patterns - title: AggregateCustomerIntelligencePatternsResponse - additionalProperties: false - console.v1.AiAsset: - type: object - properties: - id: - type: string - title: id - name: - type: string - title: name - assetType: - type: string - title: asset_type - owner: - type: string - title: owner - teamId: - type: string - title: team_id - environment: - type: string - title: environment - source: - type: string - title: source - status: - type: string - title: status - riskLevel: - title: risk_level - $ref: '#/components/schemas/common.v1.RiskLevel' - policyState: - type: string - title: policy_state - spendUsd: - type: number - title: spend_usd - format: double - requestCount: - type: - - integer - - string - title: request_count - format: int64 - errorCount: - type: - - integer - - string - title: error_count - format: int64 - latencyP95Ms: - type: - - integer - - string - title: latency_p95_ms - format: int64 - lastSeenAt: - title: last_seen_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - tags: - type: array - items: - type: string - title: tags - relatedResources: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: related_resources - title: AiAsset - additionalProperties: false - console.v1.ArchiveOperatingThreadRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - minLength: 1 - archived: - type: boolean - title: archived - idempotencyKey: - type: string - title: idempotency_key - maxLength: 512 - minLength: 1 - title: ArchiveOperatingThreadRequest - required: - - query - additionalProperties: false - console.v1.ArchiveOperatingThreadResponse: - type: object - properties: - channel: - title: channel - $ref: '#/components/schemas/console.v1.OperatingChannel' - changed: - type: boolean - title: changed - replayed: - type: boolean - title: replayed - title: ArchiveOperatingThreadResponse - required: - - channel - additionalProperties: false - console.v1.ArchiveWorkspaceRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - archived: - type: boolean - title: archived - title: ArchiveWorkspaceRequest - required: - - query - additionalProperties: false - console.v1.ArchiveWorkspaceResponse: - type: object - properties: - settings: - title: settings - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - title: ArchiveWorkspaceResponse - required: - - settings - additionalProperties: false - console.v1.AssessComplianceSubjectRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - profileId: - type: string - title: profile_id - subjectKind: - type: string - title: subject_kind - subjectId: - type: string - title: subject_id - title: AssessComplianceSubjectRequest - additionalProperties: false - description: One versioned control profile runs against one owner-fetched subject. - console.v1.AssessComplianceSubjectResponse: - type: object - properties: - assessment: - title: assessment - $ref: '#/components/schemas/console.v1.ComplianceSubjectAssessment' - title: AssessComplianceSubjectResponse - additionalProperties: false - console.v1.AttachPrivateEndpointToProfileRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - profileId: - type: string - title: profile_id - minLength: 1 - endpointId: - type: string - title: endpoint_id - routeMode: - type: string - title: route_mode - minLength: 1 - requirePrivate: - type: boolean - title: require_private - title: AttachPrivateEndpointToProfileRequest - required: - - query - additionalProperties: false - console.v1.AttachPrivateEndpointToProfileResponse: - type: object - properties: - route: - title: route - $ref: '#/components/schemas/console.v1.PrivateProfileRoute' - title: AttachPrivateEndpointToProfileResponse - required: - - route - additionalProperties: false - console.v1.AuthorityDeniedAction: - type: object - properties: - id: - type: string - title: id - actionId: - type: string - title: action_id - toolName: - type: string - title: tool_name - policyReason: - type: string - title: policy_reason - requiredEvidence: - type: array - items: - type: string - title: required_evidence - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - title: AuthorityDeniedAction - additionalProperties: false - console.v1.AuthorityLedger: - type: object - properties: - id: - type: string - title: id - traceId: - type: string - title: trace_id - spanId: - type: string - title: span_id - actionId: - type: string - title: action_id - approvalId: - type: string - title: approval_id - costRowId: - type: string - title: cost_row_id - agentId: - type: string - title: agent_id - agentName: - type: string - title: agent_name - runAsIdentity: - type: string - title: run_as_identity - toolId: - type: string - title: tool_id - toolName: - type: string - title: tool_name - connectorId: - type: string - title: connector_id - connectorName: - type: string - title: connector_name - connectorProvider: - type: string - title: connector_provider - credentialRef: - type: string - title: credential_ref - grantLeaseId: - type: string - title: grant_lease_id - authorityId: - type: string - title: authority_id - authorityLabel: - type: string - title: authority_label - authorityType: - type: string - title: authority_type - description: |- - authority_type is a product category such as credential, connector_grant, - service_account, browser_session, runner_lease, or unknown. - authorityScope: - type: string - title: authority_scope - issuer: - type: string - title: issuer - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - authorityState: - type: string - title: authority_state - description: authority_state is one of active, expired, revoked, missing, or unknown. - attestationState: - type: string - title: attestation_state - description: attestation_state is one of attested, unverified, missing, or unknown. - attestationSummary: - type: string - title: attestation_summary - trustState: - type: string - title: trust_state - description: trust_state is one of trusted, needs_review, unverified, blocked, or unknown. - evidenceState: - type: string - title: evidence_state - description: evidence_state is one of ready, pending, missing, warning, blocked, or unknown. - evidenceSource: - type: string - title: evidence_source - costPosture: - type: string - title: cost_posture - costUsd: - type: number - title: cost_usd - format: double - inputTokens: - type: - - integer - - string - title: input_tokens - format: int64 - outputTokens: - type: - - integer - - string - title: output_tokens - format: int64 - status: - type: string - title: status - policyReason: - type: string - title: policy_reason - requiredEvidence: - type: array - items: - type: string - title: required_evidence - riskLevel: - title: risk_level - $ref: '#/components/schemas/common.v1.RiskLevel' - detail: - type: string - title: detail - nextAction: - type: string - title: next_action - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - scopeLedger: - type: array - items: - $ref: '#/components/schemas/console.v1.AuthorityScopeLedger' - title: scope_ledger - missingEvidence: - type: array - items: - $ref: '#/components/schemas/console.v1.AuthorityMissingEvidence' - title: missing_evidence - deniedActions: - type: array - items: - $ref: '#/components/schemas/console.v1.AuthorityDeniedAction' - title: denied_actions - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - evidenceGaps: - type: array - items: - $ref: '#/components/schemas/console.v1.SecurityDecisionEvidenceGap' - title: evidence_gaps - title: AuthorityLedger - additionalProperties: false - console.v1.AuthorityMissingEvidence: - type: object - properties: - id: - type: string - title: id - label: - type: string - title: label - state: - type: string - title: state - owner: - type: string - title: owner - recoveryAction: - type: string - title: recovery_action - reason: - type: string - title: reason - source: - type: string - title: source - spanIds: - type: array - items: - type: string - title: span_ids - title: AuthorityMissingEvidence - additionalProperties: false - console.v1.AuthorityScopeLedger: - type: object - properties: - group: - type: string - title: group - granted: - type: array - items: - type: string - title: granted - exercised: - type: array - items: - type: string - title: exercised - denied: - type: array - items: - type: string - title: denied - missing: - type: array - items: - type: string - title: missing - state: - type: string - title: state - policyReason: - type: string - title: policy_reason - requiredEvidence: - type: array - items: - type: string - title: required_evidence - title: AuthorityScopeLedger - additionalProperties: false - console.v1.AuthorizeComputerMissionApexSessionAdoptionRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - reservationId: - type: string - title: reservation_id - minLength: 1 - runnerSessionId: - type: string - title: runner_session_id - minLength: 1 - missionId: - type: string - title: mission_id - minLength: 1 - runtimeRunId: - type: string - title: runtime_run_id - minLength: 1 - title: AuthorizeComputerMissionApexSessionAdoptionRequest - additionalProperties: false - console.v1.AuthorizeComputerMissionApexSessionAdoptionResponse: - type: object - properties: - ownerBinding: - title: owner_binding - $ref: '#/components/schemas/remoterunner.v1.RunnerSessionOwnerBinding' - authorizationId: - type: string - title: authorization_id - minLength: 1 - authorizationDigestSha256: - type: string - title: authorization_digest_sha256 - pattern: ^[0-9a-f]{64}$ - tenantScopeId: - type: string - title: tenant_scope_id - minLength: 1 - workloadDigest: - type: string - title: workload_digest - pattern: ^sha256:[0-9a-f]{64}$ - instructionArtifactRef: - type: string - title: instruction_artifact_ref - minLength: 1 - instructionDigestSha256: - type: string - title: instruction_digest_sha256 - pattern: ^[0-9a-f]{64}$ - instructionByteCount: - type: - - integer - - string - title: instruction_byte_count - maximum: 1048576 - minimum: 1 - format: int64 - title: AuthorizeComputerMissionApexSessionAdoptionResponse - required: - - ownerBinding - additionalProperties: false - console.v1.BeginOperatingAttachmentUploadRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - minLength: 1 - filename: - type: string - title: filename - minLength: 1 - contentType: - type: string - title: content_type - minLength: 1 - sizeBytes: - exclusiveMinimum: 0 - type: - - integer - - string - title: size_bytes - maximum: 52428800 - format: int64 - sha256: - type: string - title: sha256 - minLength: 1 - scope: - not: - enum: - - 0 - title: scope - $ref: '#/components/schemas/console.v1.OperatingAttachmentScope' - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: BeginOperatingAttachmentUploadRequest - required: - - query - additionalProperties: false - console.v1.BeginOperatingAttachmentUploadResponse: - type: object - properties: - attachment: - title: attachment - $ref: '#/components/schemas/console.v1.OperatingAttachmentRef' - leaseId: - type: string - title: lease_id - leaseToken: - type: string - title: lease_token - fencingToken: - type: - - integer - - string - title: fencing_token - format: int64 - upload: - title: upload - $ref: '#/components/schemas/vfs.v1.VfsUploadTarget' - title: BeginOperatingAttachmentUploadResponse - additionalProperties: false - console.v1.BeginPublishedCaptureFormUploadRequest: - type: object - properties: - publicationId: - type: string - title: publication_id - minLength: 1 - inputId: - type: string - title: input_id - maxLength: 80 - minLength: 1 - filename: - type: string - title: filename - maxLength: 255 - minLength: 1 - contentType: - type: string - title: content_type - maxLength: 255 - minLength: 1 - sizeBytes: - exclusiveMinimum: 0 - type: - - integer - - string - title: size_bytes - maximum: 52428800 - format: int64 - sha256: - type: string - title: sha256 - pattern: ^[0-9a-f]{64}$ - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - title: BeginPublishedCaptureFormUploadRequest - additionalProperties: false - console.v1.BeginPublishedCaptureFormUploadResponse: - type: object - properties: - grant: - title: grant - $ref: '#/components/schemas/console.v1.CaptureFormUpload' - leaseId: - type: string - title: lease_id - minLength: 1 - leaseToken: - type: string - title: lease_token - maxLength: 512 - minLength: 1 - fencingToken: - exclusiveMinimum: 0 - type: - - integer - - string - title: fencing_token - format: int64 - upload: - title: upload - $ref: '#/components/schemas/vfs.v1.VfsUploadTarget' - title: BeginPublishedCaptureFormUploadResponse - required: - - grant - - upload - additionalProperties: false - console.v1.BindBusinessObjectSourceRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - objectId: - type: string - title: object_id - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - resourceId: - type: string - title: resource_id - groupIds: - type: array - items: - type: string - title: group_ids - fields: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessSourceField' - title: fields - connectionId: - type: string - title: connection_id - familyStableId: - type: string - title: family_stable_id - recordId: - type: string - title: record_id - title: BindBusinessObjectSourceRequest - additionalProperties: false - console.v1.BindBusinessObjectSourceResponse: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/console.v1.BusinessObject' - title: BindBusinessObjectSourceResponse - additionalProperties: false - console.v1.BindComputerMissionApexInstructionMetadataRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - reservationId: - type: string - title: reservation_id - minLength: 1 - attemptId: - type: string - title: attempt_id - minLength: 1 - instructionArtifactRef: - type: string - title: instruction_artifact_ref - minLength: 1 - instructionDigestSha256: - type: string - title: instruction_digest_sha256 - pattern: ^[0-9a-f]{64}$ - instructionByteCount: - type: - - integer - - string - title: instruction_byte_count - maximum: 1048576 - minimum: 1 - format: int64 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: BindComputerMissionApexInstructionMetadataRequest - additionalProperties: false - console.v1.BindComputerMissionApexInstructionMetadataResponse: - type: object - properties: - metadata: - title: metadata - $ref: '#/components/schemas/console.v1.ComputerMissionApexInstructionMetadata' - title: BindComputerMissionApexInstructionMetadataResponse - required: - - metadata - additionalProperties: false - console.v1.BindComputerMissionApexSessionReservationRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - reservationId: - type: string - title: reservation_id - minLength: 1 - runnerSessionId: - type: string - title: runner_session_id - minLength: 1 - runnerProfile: - type: string - title: runner_profile - const: apex-agents-v1 - workloadDigest: - type: string - title: workload_digest - pattern: ^sha256:[0-9a-f]{64}$ - createIdempotencyKey: - type: string - title: create_idempotency_key - minLength: 1 - description: Must exactly equal ReserveComputerMissionApexSessionRequest.idempotency_key. - title: BindComputerMissionApexSessionReservationRequest - additionalProperties: false - console.v1.BindComputerMissionApexSessionReservationResponse: - type: object - properties: - reservation: - title: reservation - $ref: '#/components/schemas/console.v1.ComputerMissionApexSessionReservation' - title: BindComputerMissionApexSessionReservationResponse - required: - - reservation - additionalProperties: false - console.v1.BootstrapThreadGatewayRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - threadId: - type: string - title: thread_id - minLength: 1 - permissions: - type: array - items: - $ref: '#/components/schemas/console.v1.ThreadGatewayPermission' - title: permissions - maxItems: 3 - minItems: 1 - uniqueItems: true - title: BootstrapThreadGatewayRequest - additionalProperties: false - console.v1.BootstrapThreadGatewayResponse: - type: object - properties: - enabled: - type: boolean - title: enabled - endpoint: - type: string - title: endpoint - accessToken: - type: string - title: access_token - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - permissions: - type: array - items: - $ref: '#/components/schemas/console.v1.ThreadGatewayPermission' - title: permissions - shadowWatchPercent: - type: integer - title: shadow_watch_percent - maximum: 100 - directWatchPercent: - type: integer - title: direct_watch_percent - maximum: 100 - directSubmitPercent: - type: integer - title: direct_submit_percent - maximum: 100 - shadowWatchAssigned: - type: boolean - title: shadow_watch_assigned - directWatchAssigned: - type: boolean - title: direct_watch_assigned - directSubmitAssigned: - type: boolean - title: direct_submit_assigned - title: BootstrapThreadGatewayResponse - additionalProperties: false - console.v1.BrowseDexSkillCatalogRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: BrowseDexSkillCatalogRequest - required: - - query - additionalProperties: false - console.v1.BrowseDexSkillCatalogResponse: - type: object - properties: - entries: - type: array - items: - $ref: '#/components/schemas/console.v1.DexSkillCatalogEntry' - title: entries - playbooks: - type: array - items: - $ref: '#/components/schemas/console.v1.DexSkillPlaybook' - title: playbooks - title: BrowseDexSkillCatalogResponse - additionalProperties: false - console.v1.BusinessArtifactReference: - type: object - properties: - artifactVersionId: - type: string - title: artifact_version_id - title: BusinessArtifactReference - additionalProperties: false - console.v1.BusinessBlueprint: - type: object - properties: - blueprintId: - type: string - title: blueprint_id - version: - type: - - integer - - string - title: version - format: int64 - contentDigest: - type: string - title: content_digest - name: - type: string - title: name - description: - type: string - title: description - objectTypes: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessObjectType' - title: object_types - process: - title: process - $ref: '#/components/schemas/console.v1.BusinessProcessDefinition' - intake: - title: intake - $ref: '#/components/schemas/console.v1.CaptureFormVersionInput' - requiredCapabilities: - type: array - items: - type: string - title: required_capabilities - description: |- - Capability identifiers required before automated execution can be enabled. - Presence in this list does not claim installation or availability. - automatedExecutionAvailable: - type: boolean - title: automated_execution_available - description: This catalog version supplies native definitions, not executable admission. - title: BusinessBlueprint - additionalProperties: false - description: |- - Built-in blueprints are immutable source templates, not tenant records or - executable grants. Clone creates native definitions in the caller's tenant. - console.v1.BusinessBlueprintSource: - type: object - properties: - blueprintId: - type: string - title: blueprint_id - version: - type: - - integer - - string - title: version - format: int64 - contentDigest: - type: string - title: content_digest - cloneId: - type: string - title: clone_id - sourceTypeId: - type: string - title: source_type_id - description: Stable template member ID. Cloned type_id is tenant-owned and editable. - title: BusinessBlueprintSource - additionalProperties: false - description: Exact built-in source retained on each cloned schema for future comparison. - console.v1.BusinessFieldDefinition: - type: object - properties: - fieldId: - type: string - title: field_id - name: - type: string - title: name - kind: - title: kind - $ref: '#/components/schemas/console.v1.BusinessFieldKind' - required: - type: boolean - title: required - unique: - type: boolean - title: unique - enumValues: - type: array - items: - type: string - title: enum_values - referenceTypeId: - type: string - title: reference_type_id - groupId: - type: string - title: group_id - description: - type: string - title: description - description: Optional help text for people entering this field. - maxLength: - type: integer - title: max_length - description: |- - TEXT only: maximum Unicode code points, from 1 through 8192. - The existing 8192-byte text bound also applies. Published limits may only relax. - nullable: true - title: BusinessFieldDefinition - additionalProperties: false - console.v1.BusinessFieldValue: - type: object - oneOf: - - properties: - artifact: - title: artifact - $ref: '#/components/schemas/console.v1.BusinessArtifactReference' - title: artifact - required: - - artifact - - properties: - boolean: - type: boolean - title: boolean - title: boolean - required: - - boolean - - properties: - date: - type: string - title: date - title: date - required: - - date - - properties: - decimal: - type: string - title: decimal - title: decimal - required: - - decimal - - properties: - enumValue: - type: string - title: enum_value - title: enum_value - required: - - enumValue - - properties: - integer: - type: - - integer - - string - title: integer - format: int64 - title: integer - required: - - integer - - properties: - money: - title: money - $ref: '#/components/schemas/console.v1.BusinessMoney' - title: money - required: - - money - - properties: - reference: - title: reference - $ref: '#/components/schemas/console.v1.BusinessObjectReference' - title: reference - required: - - reference - - properties: - text: - type: string - title: text - title: text - required: - - text - - properties: - textList: - title: text_list - $ref: '#/components/schemas/console.v1.BusinessTextList' - title: text_list - required: - - textList - - properties: - timestamp: - type: string - title: timestamp - title: timestamp - required: - - timestamp - properties: - artifact: - title: artifact - $ref: '#/components/schemas/console.v1.BusinessArtifactReference' - boolean: - type: boolean - title: boolean - date: - type: string - title: date - decimal: - type: string - title: decimal - enumValue: - type: string - title: enum_value - integer: - type: - - integer - - string - title: integer - format: int64 - money: - title: money - $ref: '#/components/schemas/console.v1.BusinessMoney' - reference: - title: reference - $ref: '#/components/schemas/console.v1.BusinessObjectReference' - text: - type: string - title: text - textList: - title: text_list - $ref: '#/components/schemas/console.v1.BusinessTextList' - timestamp: - type: string - title: timestamp - fieldId: - type: string - title: field_id - title: BusinessFieldValue - additionalProperties: false - console.v1.BusinessMoney: - type: object - properties: - amount: - type: string - title: amount - currency: - type: string - title: currency - title: BusinessMoney - additionalProperties: false - description: Exact canonical decimal text, never floating point. Currency is an ISO-style uppercase code. - console.v1.BusinessObject: - type: object - properties: - objectId: - type: string - title: object_id - typeId: - type: string - title: type_id - schemaRevision: - type: - - integer - - string - title: schema_revision - format: int64 - revision: - type: - - integer - - string - title: revision - format: int64 - values: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessFieldValue' - title: values - deleted: - type: boolean - title: deleted - source: - title: source - $ref: '#/components/schemas/console.v1.BusinessSourceBinding' - updatedAt: - type: string - title: updated_at - createdAt: - type: string - title: created_at - title: BusinessObject - additionalProperties: false - console.v1.BusinessObjectFilter: - type: object - oneOf: - - properties: - reference: - title: reference - $ref: '#/components/schemas/console.v1.BusinessObjectReferenceFilter' - title: reference - required: - - reference - - properties: - uniqueValue: - title: unique_value - $ref: '#/components/schemas/console.v1.BusinessFieldValue' - title: unique_value - required: - - uniqueValue - title: BusinessObjectFilter - additionalProperties: false - properties: - reference: - title: reference - $ref: '#/components/schemas/console.v1.BusinessObjectReferenceFilter' - uniqueValue: - title: unique_value - $ref: '#/components/schemas/console.v1.BusinessFieldValue' - console.v1.BusinessObjectReference: - type: object - properties: - objectId: - type: string - title: object_id - title: BusinessObjectReference - additionalProperties: false - console.v1.BusinessObjectReferenceFilter: - type: object - properties: - fieldId: - type: string - title: field_id - targetObjectId: - type: string - title: target_object_id - title: BusinessObjectReferenceFilter - additionalProperties: false - console.v1.BusinessObjectRelationship: - type: object - properties: - sourceObjectId: - type: string - title: source_object_id - relationshipId: - type: string - title: relationship_id - targetObjectId: - type: string - title: target_object_id - title: BusinessObjectRelationship - additionalProperties: false - console.v1.BusinessObjectRevision: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/console.v1.BusinessObject' - operationId: - type: string - title: operation_id - actorId: - type: string - title: actor_id - changeKind: - type: string - title: change_kind - evidenceRefs: - type: array - items: - type: string - title: evidence_refs - title: BusinessObjectRevision - additionalProperties: false - console.v1.BusinessObjectSourceRecovery: - type: object - properties: - objectId: - type: string - title: object_id - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - authorityEpoch: - type: - - integer - - string - title: authority_epoch - format: int64 - sourceState: - title: source_state - $ref: '#/components/schemas/console.v1.BusinessSourceState' - title: BusinessObjectSourceRecovery - additionalProperties: false - console.v1.BusinessObjectType: - type: object - properties: - typeId: - type: string - title: type_id - name: - type: string - title: name - revision: - type: - - integer - - string - title: revision - format: int64 - fields: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessFieldDefinition' - title: fields - relationships: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessRelationshipDefinition' - title: relationships - pluralName: - type: string - title: plural_name - description: Optional plural label; the stable type_id remains the machine identifier. - description: - type: string - title: description - displayFieldId: - type: string - title: display_field_id - description: Optional scalar field used to label records; references and artifacts are excluded. - blueprintSource: - title: blueprint_source - description: |- - Assigned only by native blueprint cloning and immutable across revisions. - Provenance does not grant permissions or executable capabilities. - $ref: '#/components/schemas/console.v1.BusinessBlueprintSource' - recordKind: - title: record_kind - $ref: '#/components/schemas/console.v1.BusinessObjectRecordKind' - title: BusinessObjectType - additionalProperties: false - console.v1.BusinessProcess: - type: object - properties: - processId: - type: string - title: process_id - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - definitionId: - type: string - title: definition_id - definitionRevision: - type: - - integer - - string - title: definition_revision - format: int64 - revision: - type: - - integer - - string - title: revision - format: int64 - stateId: - type: string - title: state_id - subjectObjectId: - type: string - title: subject_object_id - participants: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessProcessParticipant' - title: participants - decisionPrincipalId: - type: string - title: decision_principal_id - parentProcessId: - type: string - title: parent_process_id - createdAt: - type: string - title: created_at - updatedAt: - type: string - title: updated_at - receipts: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessProcessReceipt' - title: receipts - title: BusinessProcess - additionalProperties: false - console.v1.BusinessProcessDefinition: - type: object - properties: - definitionId: - type: string - title: definition_id - revision: - type: - - integer - - string - title: revision - format: int64 - name: - type: string - title: name - participants: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessProcessParticipantType' - title: participants - subjectRoleId: - type: string - title: subject_role_id - states: - type: array - items: - type: string - title: states - initialState: - type: string - title: initial_state - terminalStates: - type: array - items: - type: string - title: terminal_states - transitions: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessProcessTransition' - title: transitions - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - title: BusinessProcessDefinition - additionalProperties: false - console.v1.BusinessProcessFollowUp: - type: object - properties: - definitionId: - type: string - title: definition_id - definitionRevision: - type: - - integer - - string - title: definition_revision - format: int64 - subjectRoleId: - type: string - title: subject_role_id - description: Child roles map by stable role ID to this process's participants. - title: BusinessProcessFollowUp - additionalProperties: false - console.v1.BusinessProcessParticipant: - type: object - properties: - roleId: - type: string - title: role_id - objectId: - type: string - title: object_id - objectRevision: - type: - - integer - - string - title: object_revision - format: int64 - description: Pins the observed record when admitting work or accepting a decision. - title: BusinessProcessParticipant - additionalProperties: false - console.v1.BusinessProcessParticipantType: - type: object - properties: - roleId: - type: string - title: role_id - typeId: - type: string - title: type_id - schemaRevision: - type: - - integer - - string - title: schema_revision - format: int64 - title: BusinessProcessParticipantType - additionalProperties: false - description: A process has its own lifecycle; its subject's ordinary fields do not own state. - console.v1.BusinessProcessReceipt: - type: object - properties: - operationId: - type: string - title: operation_id - transitionId: - type: string - title: transition_id - fromState: - type: string - title: from_state - toState: - type: string - title: to_state - revision: - type: - - integer - - string - title: revision - format: int64 - actorId: - type: string - title: actor_id - decisionAccepted: - type: boolean - title: decision_accepted - evidence: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessProcessParticipant' - title: evidence - followUpProcessIds: - type: array - items: - type: string - title: follow_up_process_ids - recordedAt: - type: string - title: recorded_at - title: BusinessProcessReceipt - additionalProperties: false - console.v1.BusinessProcessRequirement: - type: object - properties: - requirementId: - type: string - title: requirement_id - label: - type: string - title: label - roleId: - type: string - title: role_id - expected: - title: expected - description: Equality uses the declared schema's typed value. No expression strings. - $ref: '#/components/schemas/console.v1.BusinessFieldValue' - maxAgeSeconds: - type: - - integer - - string - title: max_age_seconds - format: int64 - description: Zero disables age checking; positive ages apply to the record's updated_at. - requirePresent: - type: boolean - title: require_present - description: Requires a populated field instead of equality; expected carries only field_id. - title: BusinessProcessRequirement - additionalProperties: false - console.v1.BusinessProcessTransition: - type: object - properties: - transitionId: - type: string - title: transition_id - name: - type: string - title: name - fromState: - type: string - title: from_state - toState: - type: string - title: to_state - requirements: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessProcessRequirement' - title: requirements - requiresDecision: - type: boolean - title: requires_decision - description: Requires the instance's assigned human decision maker to accept explicitly. - followUps: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessProcessFollowUp' - title: follow_ups - description: Follow-up obligations are durable child processes admitted atomically. - title: BusinessProcessTransition - additionalProperties: false - console.v1.BusinessRelationshipDefinition: - type: object - properties: - relationshipId: - type: string - title: relationship_id - name: - type: string - title: name - targetTypeId: - type: string - title: target_type_id - title: BusinessRelationshipDefinition - additionalProperties: false - console.v1.BusinessSourceBinding: - type: object - properties: - resourceId: - type: string - title: resource_id - connectionId: - type: string - title: connection_id - groupIds: - type: array - items: - type: string - title: group_ids - fields: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessSourceField' - title: fields - authorityEpoch: - type: - - integer - - string - title: authority_epoch - format: int64 - generation: - type: - - integer - - string - title: generation - format: int64 - state: - title: state - $ref: '#/components/schemas/console.v1.BusinessSourceState' - observedDigest: - type: string - title: observed_digest - observedAt: - type: string - title: observed_at - familyStableId: - type: string - title: family_stable_id - recordId: - type: string - title: record_id - sourceEventId: - type: string - title: source_event_id - envelope: - title: envelope - $ref: '#/components/schemas/connectors.v1.ProviderResourceEnvelope' - title: BusinessSourceBinding - additionalProperties: false - console.v1.BusinessSourceField: - type: object - properties: - fieldId: - type: string - title: field_id - property: - title: property - $ref: '#/components/schemas/console.v1.BusinessSourceProperty' - title: BusinessSourceField - additionalProperties: false - console.v1.BusinessTextList: - type: object - properties: - values: - type: array - items: - type: string - title: values - title: BusinessTextList - additionalProperties: false - console.v1.CancelComputerMissionRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - missionId: - type: string - title: mission_id - minLength: 1 - reason: - type: string - title: reason - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: CancelComputerMissionRequest - required: - - query - additionalProperties: false - console.v1.CancelComputerMissionResponse: - type: object - properties: - mission: - title: mission - $ref: '#/components/schemas/console.v1.ComputerMission' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.OperatingReceipt' - title: CancelComputerMissionResponse - required: - - mission - - receipt - additionalProperties: false - console.v1.CaptureForm: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - formId: - type: string - title: form_id - minLength: 1 - name: - type: string - title: name - maxLength: 160 - minLength: 1 - description: - type: string - title: description - maxLength: 2000 - state: - title: state - $ref: '#/components/schemas/console.v1.CaptureFormState' - currentVersionId: - type: string - title: current_version_id - minLength: 1 - currentRevision: - exclusiveMinimum: 0 - type: - - integer - - string - title: current_revision - format: int64 - objectTarget: - title: object_target - $ref: '#/components/schemas/console.v1.CaptureFormObjectTarget' - branding: - title: branding - $ref: '#/components/schemas/console.v1.CaptureFormBranding' - publications: - type: array - items: - $ref: '#/components/schemas/console.v1.CaptureFormPublication' - title: publications - maxItems: 32 - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: CaptureForm - required: - - objectTarget - additionalProperties: false - console.v1.CaptureFormAnswer: - type: object - properties: - inputId: - type: string - title: input_id - maxLength: 80 - minLength: 1 - value: - title: value - $ref: '#/components/schemas/console.v1.CaptureFormTypedValue' - title: CaptureFormAnswer - required: - - value - additionalProperties: false - console.v1.CaptureFormAssetRef: - type: object - properties: - objectId: - type: string - title: object_id - maxLength: 255 - minLength: 1 - versionId: - type: string - title: version_id - maxLength: 255 - minLength: 1 - title: CaptureFormAssetRef - additionalProperties: false - description: |- - CaptureFormAssetRef references immutable, tenant-owned VFS/artifact bytes. - The form contract never accepts embedded bytes or a caller-selected URL. - console.v1.CaptureFormBranding: - type: object - properties: - displayName: - type: string - title: display_name - maxLength: 120 - tagline: - type: string - title: tagline - maxLength: 160 - description: - type: string - title: description - maxLength: 2000 - accentColor: - type: string - title: accent_color - pattern: ^$|^#[0-9a-fA-F]{6}$ - logo: - title: logo - $ref: '#/components/schemas/console.v1.CaptureFormAssetRef' - favicon: - title: favicon - $ref: '#/components/schemas/console.v1.CaptureFormAssetRef' - brandingDigest: - type: string - title: branding_digest - maxLength: 128 - validationReceiptId: - type: string - title: validation_receipt_id - maxLength: 255 - showPoweredBy: - type: boolean - title: show_powered_by - title: CaptureFormBranding - additionalProperties: false - description: |- - CaptureFormBranding is the administrator projection. Validation receipts - and asset refs are intentionally absent from public presentation messages. - console.v1.CaptureFormBrandingInput: - type: object - properties: - displayName: - type: string - title: display_name - maxLength: 120 - tagline: - type: string - title: tagline - maxLength: 160 - description: - type: string - title: description - maxLength: 2000 - accentColor: - type: string - title: accent_color - pattern: ^$|^#[0-9a-fA-F]{6}$ - logo: - title: logo - $ref: '#/components/schemas/console.v1.CaptureFormAssetRef' - favicon: - title: favicon - $ref: '#/components/schemas/console.v1.CaptureFormAssetRef' - showPoweredBy: - type: boolean - title: show_powered_by - title: CaptureFormBrandingInput - additionalProperties: false - console.v1.CaptureFormField: - type: object - oneOf: - - properties: - select: - title: select - $ref: '#/components/schemas/console.v1.CaptureFormSelectSpec' - title: select - required: - - select - - properties: - upload: - title: upload - $ref: '#/components/schemas/console.v1.CaptureFormUploadSpec' - title: upload - required: - - upload - properties: - select: - title: select - $ref: '#/components/schemas/console.v1.CaptureFormSelectSpec' - upload: - title: upload - $ref: '#/components/schemas/console.v1.CaptureFormUploadSpec' - inputId: - type: string - title: input_id - maxLength: 80 - minLength: 1 - label: - type: string - title: label - maxLength: 160 - minLength: 1 - helpText: - type: string - title: help_text - maxLength: 1000 - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/console.v1.CaptureFormFieldKind' - required: - type: boolean - title: required - position: - type: integer - title: position - maximum: 1024 - format: int32 - placeholder: - type: string - title: placeholder - maxLength: 240 - businessFieldId: - type: string - title: business_field_id - maxLength: 255 - mappingState: - not: - enum: - - 0 - title: mapping_state - $ref: '#/components/schemas/console.v1.CaptureFormMappingState' - maxLength: - type: integer - title: max_length - maximum: 8192 - format: int32 - minDecimal: - type: string - title: min_decimal - maxLength: 128 - maxDecimal: - type: string - title: max_decimal - maxLength: 128 - defaultValue: - title: default_value - $ref: '#/components/schemas/console.v1.CaptureFormTypedValue' - hidden: - type: boolean - title: hidden - title: CaptureFormField - additionalProperties: false - description: |- - CaptureFormField is the administrator-owned typed field/mapping definition. - business_field_id and hidden/default values never appear on public - projections. - console.v1.CaptureFormInvitation: - type: object - properties: - invitationId: - type: string - title: invitation_id - publicationId: - type: string - title: publication_id - recipientEmail: - type: string - title: recipient_email - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - state: - type: string - title: state - title: CaptureFormInvitation - additionalProperties: false - description: |- - Invitation IDs are opaque locators, never authentication. The owner requires - a live Identity access token with the exact verified recipient email. - console.v1.CaptureFormObjectResult: - type: object - properties: - resultId: - type: string - title: result_id - minLength: 1 - state: - title: state - $ref: '#/components/schemas/console.v1.CaptureFormObjectResultState' - objectId: - type: string - title: object_id - maxLength: 255 - objectTypeId: - type: string - title: object_type_id - maxLength: 255 - objectSchemaRevision: - type: - - integer - - string - title: object_schema_revision - format: int64 - objectRevision: - type: - - integer - - string - title: object_revision - format: int64 - mappingReceiptId: - type: string - title: mapping_receipt_id - maxLength: 255 - unmappedInputIds: - type: array - items: - type: string - maxItems: 64 - title: unmapped_input_ids - maxItems: 64 - title: CaptureFormObjectResult - additionalProperties: false - console.v1.CaptureFormObjectTarget: - type: object - properties: - typeId: - type: string - title: type_id - minLength: 1 - schemaRevision: - exclusiveMinimum: 0 - type: - - integer - - string - title: schema_revision - format: int64 - title: CaptureFormObjectTarget - additionalProperties: false - description: CaptureFormObjectTarget pins the business schema used by every version. - console.v1.CaptureFormPublicBranding: - type: object - properties: - displayName: - type: string - title: display_name - maxLength: 120 - tagline: - type: string - title: tagline - maxLength: 160 - description: - type: string - title: description - maxLength: 2000 - accentColor: - type: string - title: accent_color - pattern: ^$|^#[0-9a-fA-F]{6}$ - logoUrl: - type: string - title: logo_url - maxLength: 2048 - faviconUrl: - type: string - title: favicon_url - maxLength: 2048 - showPoweredBy: - type: boolean - title: show_powered_by - title: CaptureFormPublicBranding - additionalProperties: false - console.v1.CaptureFormPublicField: - type: object - oneOf: - - properties: - select: - title: select - $ref: '#/components/schemas/console.v1.CaptureFormSelectSpec' - title: select - required: - - select - - properties: - upload: - title: upload - $ref: '#/components/schemas/console.v1.CaptureFormUploadSpec' - title: upload - required: - - upload - properties: - select: - title: select - $ref: '#/components/schemas/console.v1.CaptureFormSelectSpec' - upload: - title: upload - $ref: '#/components/schemas/console.v1.CaptureFormUploadSpec' - inputId: - type: string - title: input_id - maxLength: 80 - minLength: 1 - label: - type: string - title: label - maxLength: 160 - minLength: 1 - helpText: - type: string - title: help_text - maxLength: 1000 - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/console.v1.CaptureFormFieldKind' - required: - type: boolean - title: required - position: - type: integer - title: position - format: int32 - placeholder: - type: string - title: placeholder - maxLength: 240 - maxLength: - type: integer - title: max_length - maximum: 8192 - format: int32 - title: CaptureFormPublicField - additionalProperties: false - console.v1.CaptureFormPublicRoute: - type: object - properties: - hostname: - type: string - title: hostname - maxLength: 253 - path: - type: string - title: path - maxLength: 512 - embedPath: - type: string - title: embed_path - maxLength: 512 - customDomainId: - type: string - title: custom_domain_id - maxLength: 255 - allowedOrigins: - type: array - items: - type: string - maxItems: 32 - title: allowed_origins - maxItems: 32 - embedEnabled: - type: boolean - title: embed_enabled - title: CaptureFormPublicRoute - additionalProperties: false - description: |- - CaptureFormPublicRoute is server-derived white-label routing metadata. A - caller supplies only a slug and an existing custom-domain reference. - console.v1.CaptureFormPublicSubmissionReceipt: - type: object - properties: - submissionId: - type: string - title: submission_id - minLength: 1 - resultId: - type: string - title: result_id - maxLength: 255 - state: - title: state - $ref: '#/components/schemas/console.v1.CaptureFormSubmissionState' - submittedAt: - title: submitted_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: CaptureFormPublicSubmissionReceipt - additionalProperties: false - description: |- - Public receipt deliberately excludes tenant coordinates, answers, owner - references, and the internal BusinessObject identity. - console.v1.CaptureFormPublication: - type: object - properties: - publicationId: - type: string - title: publication_id - minLength: 1 - description: |- - Server-generated opaque id used in a public form URL. It is stable across - admin reloads and idempotent publish retries; it is never caller-selected - as a tenant or workspace coordinate. - formId: - type: string - title: form_id - minLength: 1 - versionId: - type: string - title: version_id - minLength: 1 - state: - title: state - $ref: '#/components/schemas/console.v1.CaptureFormPublicationState' - generation: - exclusiveMinimum: 0 - type: - - integer - - string - title: generation - format: int64 - slug: - type: string - title: slug - maxLength: 80 - route: - title: route - $ref: '#/components/schemas/console.v1.CaptureFormPublicRoute' - publishedAt: - title: published_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - revokedAt: - title: revoked_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - invitationOnly: - type: boolean - title: invitation_only - title: CaptureFormPublication - additionalProperties: false - console.v1.CaptureFormPublicationInput: - type: object - properties: - slug: - type: string - title: slug - maxLength: 80 - minLength: 1 - pattern: ^[a-z0-9]+(?:-[a-z0-9]+)*$ - customDomainId: - type: string - title: custom_domain_id - maxLength: 255 - allowedOrigins: - type: array - items: - type: string - maxLength: 2048 - maxItems: 32 - title: allowed_origins - maxItems: 32 - embedEnabled: - type: boolean - title: embed_enabled - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - invitationOnly: - type: boolean - title: invitation_only - description: Refuses anonymous reads and submissions; answers require a recipient invitation. - title: CaptureFormPublicationInput - additionalProperties: false - console.v1.CaptureFormReview: - type: object - properties: - decision: - title: decision - $ref: '#/components/schemas/console.v1.CaptureFormReviewDecision' - reviewerId: - type: string - title: reviewer_id - maxLength: 255 - note: - type: string - title: note - maxLength: 4000 - reviewedAt: - title: reviewed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - supplementalValues: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessFieldValue' - title: supplemental_values - maxItems: 64 - description: |- - Typed native business-field values supplied by the reviewer for required - fields absent from the original intake. They are persisted with the - review and used only for accepted-object mapping; CaptureFormSubmission - answers always remain the original public answers unchanged. - title: CaptureFormReview - additionalProperties: false - console.v1.CaptureFormSelectOption: - type: object - properties: - optionId: - type: string - title: option_id - maxLength: 80 - minLength: 1 - label: - type: string - title: label - maxLength: 160 - minLength: 1 - description: - type: string - title: description - maxLength: 500 - disabled: - type: boolean - title: disabled - title: CaptureFormSelectOption - additionalProperties: false - console.v1.CaptureFormSelectSpec: - type: object - properties: - options: - type: array - items: - $ref: '#/components/schemas/console.v1.CaptureFormSelectOption' - title: options - maxItems: 128 - minItems: 1 - maxSelected: - type: integer - title: max_selected - maximum: 128 - minimum: 1 - format: int32 - title: CaptureFormSelectSpec - additionalProperties: false - console.v1.CaptureFormSubmission: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - submissionId: - type: string - title: submission_id - minLength: 1 - formId: - type: string - title: form_id - minLength: 1 - publicationId: - type: string - title: publication_id - minLength: 1 - versionId: - type: string - title: version_id - minLength: 1 - state: - title: state - $ref: '#/components/schemas/console.v1.CaptureFormSubmissionState' - answers: - type: array - items: - $ref: '#/components/schemas/console.v1.CaptureFormAnswer' - title: answers - maxItems: 64 - revision: - exclusiveMinimum: 0 - type: - - integer - - string - title: revision - format: int64 - review: - title: review - $ref: '#/components/schemas/console.v1.CaptureFormReview' - objectResult: - title: object_result - $ref: '#/components/schemas/console.v1.CaptureFormObjectResult' - submittedAt: - title: submitted_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: CaptureFormSubmission - additionalProperties: false - console.v1.CaptureFormTypedValue: - type: object - oneOf: - - properties: - artifact: - title: artifact - $ref: '#/components/schemas/console.v1.CaptureFormAssetRef' - title: artifact - required: - - artifact - - properties: - boolean: - type: boolean - title: boolean - title: boolean - required: - - boolean - - properties: - date: - type: string - title: date - maxLength: 32 - title: date - required: - - date - - properties: - datetime: - title: datetime - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: datetime - required: - - datetime - - properties: - decimal: - type: string - title: decimal - maxLength: 128 - title: decimal - required: - - decimal - - properties: - email: - type: string - title: email - maxLength: 320 - title: email - required: - - email - - properties: - integer: - type: - - integer - - string - title: integer - format: int64 - title: integer - required: - - integer - - properties: - optionId: - type: string - title: option_id - maxLength: 80 - title: option_id - required: - - optionId - - properties: - optionValues: - title: option_values - $ref: '#/components/schemas/console.v1.CaptureFormTypedValue.OptionValues' - title: option_values - required: - - optionValues - - properties: - phone: - type: string - title: phone - maxLength: 64 - title: phone - required: - - phone - - properties: - text: - type: string - title: text - maxLength: 8192 - title: text - required: - - text - - properties: - url: - type: string - title: url - maxLength: 2048 - title: url - required: - - url - title: CaptureFormTypedValue - additionalProperties: false - description: |- - CaptureFormTypedValue is shared by hidden defaults and durable answers. A - multi-select is a typed repeated option message, never a delimiter-encoded - scalar string. - properties: - artifact: - title: artifact - $ref: '#/components/schemas/console.v1.CaptureFormAssetRef' - boolean: - type: boolean - title: boolean - date: - type: string - title: date - maxLength: 32 - datetime: - title: datetime - $ref: '#/components/schemas/google.protobuf.Timestamp' - decimal: - type: string - title: decimal - maxLength: 128 - email: - type: string - title: email - maxLength: 320 - integer: - type: - - integer - - string - title: integer - format: int64 - optionId: - type: string - title: option_id - maxLength: 80 - optionValues: - title: option_values - $ref: '#/components/schemas/console.v1.CaptureFormTypedValue.OptionValues' - phone: - type: string - title: phone - maxLength: 64 - text: - type: string - title: text - maxLength: 8192 - url: - type: string - title: url - maxLength: 2048 - console.v1.CaptureFormTypedValue.OptionValues: - type: object - properties: - optionIds: - type: array - items: - type: string - maxLength: 80 - minLength: 1 - maxItems: 128 - title: option_ids - maxItems: 128 - minItems: 1 - title: OptionValues - additionalProperties: false - console.v1.CaptureFormUpload: - type: object - properties: - uploadId: - type: string - title: upload_id - minLength: 1 - inputId: - type: string - title: input_id - maxLength: 80 - minLength: 1 - filename: - type: string - title: filename - maxLength: 255 - minLength: 1 - contentType: - type: string - title: content_type - maxLength: 255 - minLength: 1 - sizeBytes: - exclusiveMinimum: 0 - type: - - integer - - string - title: size_bytes - maximum: 52428800 - format: int64 - sha256: - type: string - title: sha256 - pattern: ^[0-9a-f]{64}$ - state: - title: state - $ref: '#/components/schemas/console.v1.CaptureFormUploadState' - asset: - title: asset - $ref: '#/components/schemas/console.v1.CaptureFormAssetRef' - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: CaptureFormUpload - additionalProperties: false - description: |- - CaptureFormUpload is a public, publication-scoped upload grant projection. - The lease token is returned only by BeginPublishedCaptureFormUpload and is - never persisted or included in this durable projection. - console.v1.CaptureFormUploadSpec: - type: object - properties: - acceptedContentTypes: - type: array - items: - type: string - maxLength: 128 - maxItems: 32 - title: accepted_content_types - maxItems: 32 - maxSizeBytes: - exclusiveMinimum: 0 - type: - - integer - - string - title: max_size_bytes - maximum: 52428800 - format: int64 - maxFiles: - type: integer - title: max_files - format: int32 - const: 1 - title: CaptureFormUploadSpec - additionalProperties: false - console.v1.CaptureFormVersion: - type: object - properties: - formId: - type: string - title: form_id - minLength: 1 - versionId: - type: string - title: version_id - minLength: 1 - revision: - exclusiveMinimum: 0 - type: - - integer - - string - title: revision - format: int64 - objectTarget: - title: object_target - $ref: '#/components/schemas/console.v1.CaptureFormObjectTarget' - fields: - type: array - items: - $ref: '#/components/schemas/console.v1.CaptureFormField' - title: fields - maxItems: 64 - branding: - title: branding - $ref: '#/components/schemas/console.v1.CaptureFormBranding' - schemaDigest: - type: string - title: schema_digest - maxLength: 128 - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - createdBy: - type: string - title: created_by - maxLength: 255 - title: CaptureFormVersion - required: - - objectTarget - additionalProperties: false - description: |- - CaptureFormVersion is immutable after acceptance. Every public publication - stores and returns its exact version_id and schema revision. - console.v1.CaptureFormVersionInput: - type: object - properties: - objectTarget: - title: object_target - $ref: '#/components/schemas/console.v1.CaptureFormObjectTarget' - fields: - type: array - items: - $ref: '#/components/schemas/console.v1.CaptureFormField' - title: fields - maxItems: 64 - minItems: 1 - branding: - title: branding - $ref: '#/components/schemas/console.v1.CaptureFormBrandingInput' - title: CaptureFormVersionInput - required: - - objectTarget - - branding - additionalProperties: false - console.v1.CloneAgentProductRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - sourceAgentId: - type: string - title: source_agent_id - minLength: 1 - sourceConfigVersion: - exclusiveMinimum: 0 - type: integer - title: source_config_version - format: int32 - name: - type: string - title: name - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: CloneAgentProductRequest - additionalProperties: false - console.v1.CloneAgentProductResponse: - type: object - properties: - agent: - title: agent - $ref: '#/components/schemas/agents.v1.Agent' - config: - title: config - $ref: '#/components/schemas/agents.v1.AgentConfig' - title: CloneAgentProductResponse - additionalProperties: false - console.v1.CloneBusinessBlueprintRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - blueprintId: - type: string - title: blueprint_id - minLength: 1 - version: - exclusiveMinimum: 0 - type: - - integer - - string - title: version - format: int64 - contentDigest: - type: string - title: content_digest - pattern: ^[0-9a-f]{64}$ - name: - type: string - title: name - maxLength: 120 - minLength: 1 - title: CloneBusinessBlueprintRequest - additionalProperties: false - console.v1.CloneBusinessBlueprintResponse: - type: object - properties: - blueprintId: - type: string - title: blueprint_id - blueprintVersion: - type: - - integer - - string - title: blueprint_version - format: int64 - contentDigest: - type: string - title: content_digest - cloneId: - type: string - title: clone_id - description: Server-assigned UUID, stable for an identical idempotent request. - objectTypes: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessObjectType' - title: object_types - process: - title: process - $ref: '#/components/schemas/console.v1.BusinessProcessDefinition' - form: - title: form - $ref: '#/components/schemas/console.v1.CaptureForm' - automatedExecutionAvailable: - type: boolean - title: automated_execution_available - description: |- - Definitions are available for editing. Publication, execution and external - effects require their existing owner admission and are not implied here. - title: CloneBusinessBlueprintResponse - additionalProperties: false - console.v1.CodingAcceptanceContract: - type: object - properties: - taskId: - type: string - title: task_id - maxLength: 256 - repositoryId: - type: string - title: repository_id - maxLength: 512 - minLength: 1 - generation: - exclusiveMinimum: 0 - type: - - integer - - string - title: generation - format: int64 - requiredAssertionIds: - type: array - items: - type: string - maxItems: 128 - title: required_assertion_ids - maxItems: 128 - minItems: 1 - requireReview: - type: boolean - title: require_review - requireBehavior: - type: boolean - title: require_behavior - readinessRequirements: - type: array - items: - type: string - maxItems: 128 - title: readiness_requirements - maxItems: 128 - authorizedSkips: - type: array - items: - type: string - maxItems: 128 - title: authorized_skips - maxItems: 128 - authorizedDispositions: - type: array - items: - type: string - maxItems: 128 - title: authorized_dispositions - maxItems: 128 - outputPaths: - type: array - items: - type: string - maxItems: 8 - title: output_paths - maxItems: 8 - title: CodingAcceptanceContract - additionalProperties: false - description: |- - Explicit acceptance requirements for a coding task. Platform binds task_id - to the resolved conversation task; clients may leave it empty for new work. - These requirements grant no tool, repository-access, or approval authority. - console.v1.Commitment: - type: object - properties: - commitmentId: - type: string - title: commitment_id - title: - type: string - title: title - status: - type: string - title: status - conditionOfSatisfaction: - type: string - title: condition_of_satisfaction - dueAt: - title: due_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - noDateRationale: - type: string - title: no_date_rationale - description: |- - no_date_rationale explains why a commitment carries no due date. Empty - when due_at is set or when the ledger records no rationale. - ownerEmail: - type: string - title: owner_email - citations: - type: array - items: - $ref: '#/components/schemas/console.v1.CommitmentCitation' - title: citations - maxItems: 64 - observedAt: - title: observed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - meetingCaptureId: - type: string - title: meeting_capture_id - description: |- - meeting_capture_id is set when a meeting_binding citation resolves to a - meeting capture binding in this workspace. - title: Commitment - additionalProperties: false - description: |- - Commitment is the read projection of one tracked commitment. Every field is - carried from the commitment ledger; the citations are the evidence entries - the commitment was extracted from, not a summary written here. - console.v1.CommitmentCitation: - type: object - properties: - kind: - type: string - title: kind - sourceKind: - type: string - title: source_kind - sourceId: - type: string - title: source_id - sourceUri: - type: string - title: source_uri - excerpt: - type: string - title: excerpt - maxLength: 2000 - observedAt: - title: observed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: CommitmentCitation - additionalProperties: false - description: CommitmentCitation is one evidence entry the commitment was extracted from. - console.v1.CompareScenarioFixturesRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - baseFixtureId: - type: string - title: base_fixture_id - minLength: 1 - targetFixtureId: - type: string - title: target_fixture_id - minLength: 1 - maxDifferences: - type: integer - title: max_differences - maximum: 100 - format: int32 - title: CompareScenarioFixturesRequest - additionalProperties: false - console.v1.CompareScenarioFixturesResponse: - type: object - properties: - baseFixture: - title: base_fixture - $ref: '#/components/schemas/console.v1.ScenarioFixture' - targetFixture: - title: target_fixture - $ref: '#/components/schemas/console.v1.ScenarioFixture' - sharedPrefixFrames: - type: integer - title: shared_prefix_frames - format: int32 - baseFrameCount: - type: integer - title: base_frame_count - format: int32 - targetFrameCount: - type: integer - title: target_frame_count - format: int32 - firstDivergencePath: - type: string - title: first_divergence_path - firstDivergenceSummary: - type: string - title: first_divergence_summary - differences: - type: array - items: - $ref: '#/components/schemas/console.v1.ScenarioFixtureDifference' - title: differences - title: CompareScenarioFixturesResponse - additionalProperties: false - console.v1.CompleteDexMcpOAuthProfileRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - serverId: - type: string - title: server_id - minLength: 1 - profileId: - type: string - title: profile_id - minLength: 1 - state: - type: string - title: state - minLength: 1 - code: - type: string - title: code - description: |- - Empty code is permitted only for a provider error response; the - Connector validates the raw iss binding before acting on any error text. - redirectUri: - type: string - title: redirect_uri - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - profileGeneration: - exclusiveMinimum: 0 - type: - - integer - - string - title: profile_generation - format: int64 - authorizationResponseIss: - type: string - title: authorization_response_iss - description: |- - Raw RFC 9207 authorization response fields forwarded unchanged to the - Connector for validation. - providerError: - type: string - title: provider_error - providerErrorDescription: - type: string - title: provider_error_description - providerErrorUri: - type: string - title: provider_error_uri - title: CompleteDexMcpOAuthProfileRequest - required: - - query - additionalProperties: false - console.v1.CompleteDexMcpOAuthProfileResponse: - type: object - properties: - profile: - title: profile - $ref: '#/components/schemas/console.v1.DexMcpOAuthProfile' - title: CompleteDexMcpOAuthProfileResponse - required: - - profile - additionalProperties: false - console.v1.CompleteInferenceCreditAutoRefillRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - setupSessionId: - type: string - title: setup_session_id - minLength: 1 - title: CompleteInferenceCreditAutoRefillRequest - additionalProperties: false - console.v1.CompleteInferenceCreditAutoRefillResponse: - type: object - properties: - enabled: - type: boolean - title: enabled - title: CompleteInferenceCreditAutoRefillResponse - additionalProperties: false - console.v1.CompleteOperatingAttachmentUploadRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - minLength: 1 - attachmentId: - type: string - title: attachment_id - minLength: 1 - leaseId: - type: string - title: lease_id - minLength: 1 - leaseToken: - type: string - title: lease_token - minLength: 1 - fencingToken: - type: - - integer - - string - title: fencing_token - minimum: 1 - format: int64 - sizeBytes: - exclusiveMinimum: 0 - type: - - integer - - string - title: size_bytes - maximum: 52428800 - format: int64 - sha256: - type: string - title: sha256 - minLength: 1 - storageEtag: - type: string - title: storage_etag - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - completedParts: - type: array - items: - $ref: '#/components/schemas/vfs.v1.VfsCompletedUploadPart' - title: completed_parts - maxItems: 10000 - title: CompleteOperatingAttachmentUploadRequest - required: - - query - additionalProperties: false - console.v1.CompleteOperatingAttachmentUploadResponse: - type: object - properties: - attachment: - title: attachment - $ref: '#/components/schemas/console.v1.OperatingAttachmentRef' - title: CompleteOperatingAttachmentUploadResponse - additionalProperties: false - console.v1.CompletePublishedCaptureFormUploadRequest: - type: object - properties: - publicationId: - type: string - title: publication_id - minLength: 1 - inputId: - type: string - title: input_id - maxLength: 80 - minLength: 1 - uploadId: - type: string - title: upload_id - minLength: 1 - leaseId: - type: string - title: lease_id - minLength: 1 - leaseToken: - type: string - title: lease_token - maxLength: 512 - minLength: 1 - fencingToken: - exclusiveMinimum: 0 - type: - - integer - - string - title: fencing_token - format: int64 - sizeBytes: - exclusiveMinimum: 0 - type: - - integer - - string - title: size_bytes - maximum: 52428800 - format: int64 - sha256: - type: string - title: sha256 - pattern: ^[0-9a-f]{64}$ - storageEtag: - type: string - title: storage_etag - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - completedParts: - type: array - items: - $ref: '#/components/schemas/vfs.v1.VfsCompletedUploadPart' - title: completed_parts - maxItems: 10000 - title: CompletePublishedCaptureFormUploadRequest - additionalProperties: false - console.v1.CompletePublishedCaptureFormUploadResponse: - type: object - properties: - upload: - title: upload - $ref: '#/components/schemas/console.v1.CaptureFormUpload' - title: CompletePublishedCaptureFormUploadResponse - required: - - upload - additionalProperties: false - console.v1.ComplianceAssessmentRecord: - type: object - properties: - id: - type: string - title: id - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - evaluatorVersion: - type: string - title: evaluator_version - assessment: - title: assessment - $ref: '#/components/schemas/console.v1.ComplianceSubjectAssessment' - manifestDigest: - type: string - title: manifest_digest - recordedByPrincipalId: - type: string - title: recorded_by_principal_id - title: ComplianceAssessmentRecord - additionalProperties: false - console.v1.ComplianceRequirementFinding: - type: object - properties: - requirementId: - type: string - title: requirement_id - status: - title: status - $ref: '#/components/schemas/console.v1.ComplianceFindingStatus' - reasonCode: - type: string - title: reason_code - sourceRef: - type: string - title: source_ref - title: ComplianceRequirementFinding - additionalProperties: false - console.v1.ComplianceSubjectAssessment: - type: object - properties: - profileId: - type: string - title: profile_id - subjectKind: - type: string - title: subject_kind - subjectId: - type: string - title: subject_id - sourceDigest: - type: string - title: source_digest - sourceUpdatedAt: - title: source_updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - assessedAt: - title: assessed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - status: - title: status - $ref: '#/components/schemas/console.v1.ComplianceFindingStatus' - findings: - type: array - items: - $ref: '#/components/schemas/console.v1.ComplianceRequirementFinding' - title: findings - inspectedCount: - type: integer - title: inspected_count - description: This route covers exactly the one requested owner record. - expectedCount: - type: integer - title: expected_count - controlId: - type: string - title: control_id - title: ComplianceSubjectAssessment - additionalProperties: false - description: A live, bounded assessment of one execution. It is not an immutable snapshot. - console.v1.ComputerMission: - type: object - properties: - missionId: - type: string - title: mission_id - minLength: 1 - workId: - type: string - title: work_id - minLength: 1 - contract: - title: contract - $ref: '#/components/schemas/console.v1.ComputerMissionContract' - state: - title: state - $ref: '#/components/schemas/console.v1.ComputerMissionState' - completedSteps: - type: integer - title: completed_steps - completedToolCalls: - type: integer - title: completed_tool_calls - consumedTokens: - type: - - integer - - string - title: consumed_tokens - format: int64 - consumedCostMicros: - type: - - integer - - string - title: consumed_cost_micros - format: int64 - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - blocker: - type: string - title: blocker - nextAction: - type: string - title: next_action - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - tenantScopeId: - type: string - title: tenant_scope_id - minLength: 1 - authorityGrantId: - type: string - title: authority_grant_id - minLength: 1 - contractVersion: - type: string - title: contract_version - minLength: 1 - contractDigestSha256: - type: string - title: contract_digest_sha256 - pattern: ^[0-9a-f]{64}$ - runtimeRunId: - type: string - title: runtime_run_id - description: Empty until Platform Worker has created the authoritative runtime row. - activeGeneration: - type: - - integer - - string - title: active_generation - format: int64 - description: Monotonically increases whenever the mission is queued for new execution. - longHorizonBudget: - title: long_horizon_budget - $ref: '#/components/schemas/console.v1.ComputerMissionLongHorizonBudgetState' - title: ComputerMission - required: - - contract - - createdAt - - updatedAt - additionalProperties: false - console.v1.ComputerMissionApexInstructionMetadata: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - reservationId: - type: string - title: reservation_id - minLength: 1 - attemptId: - type: string - title: attempt_id - minLength: 1 - instructionArtifactRef: - type: string - title: instruction_artifact_ref - minLength: 1 - instructionDigestSha256: - type: string - title: instruction_digest_sha256 - pattern: ^[0-9a-f]{64}$ - instructionByteCount: - type: - - integer - - string - title: instruction_byte_count - maximum: 1048576 - minimum: 1 - format: int64 - state: - type: string - title: state - const: instruction_bound - title: ComputerMissionApexInstructionMetadata - additionalProperties: false - console.v1.ComputerMissionApexRunnerBinding: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - runnerSessionId: - type: string - title: runner_session_id - minLength: 1 - sandboxId: - type: string - title: sandbox_id - minLength: 1 - initialCheckpointId: - type: string - title: initial_checkpoint_id - minLength: 1 - initialSnapshotId: - type: string - title: initial_snapshot_id - minLength: 1 - workloadDigest: - type: string - title: workload_digest - pattern: ^sha256:[0-9a-f]{64}$ - provider: - type: string - title: provider - minLength: 1 - providerMode: - type: string - title: provider_mode - const: apply - reservationId: - type: string - title: reservation_id - minLength: 1 - instructionArtifactRef: - type: string - title: instruction_artifact_ref - minLength: 1 - instructionDigestSha256: - type: string - title: instruction_digest_sha256 - pattern: ^[0-9a-f]{64}$ - instructionByteCount: - type: - - integer - - string - title: instruction_byte_count - maximum: 1048576 - minimum: 1 - format: int64 - title: ComputerMissionApexRunnerBinding - additionalProperties: false - console.v1.ComputerMissionApexSessionReservation: - type: object - properties: - reservationId: - type: string - title: reservation_id - minLength: 1 - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - packRunId: - type: string - title: pack_run_id - minLength: 1 - attemptId: - type: string - title: attempt_id - minLength: 1 - runIndex: - type: integer - title: run_index - decisionRef: - type: string - title: decision_ref - minLength: 1 - decisionDigestSha256: - type: string - title: decision_digest_sha256 - pattern: ^[0-9a-f]{64}$ - runnerProfile: - type: string - title: runner_profile - minLength: 1 - workloadDigest: - type: string - title: workload_digest - pattern: ^sha256:[0-9a-f]{64}$ - runnerSessionId: - type: string - title: runner_session_id - state: - type: string - title: state - pattern: ^(reserved|session_bound|adoption_authorized)$ - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: ComputerMissionApexSessionReservation - required: - - expiresAt - additionalProperties: false - console.v1.ComputerMissionAuthorityGrant: - type: object - properties: - mode: - not: - enum: - - 0 - title: mode - $ref: '#/components/schemas/console.v1.ComputerMissionAuthorityMode' - grantedBy: - type: string - title: granted_by - minLength: 1 - grantedAt: - title: granted_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - confirmationVersion: - type: string - title: confirmation_version - const: dex.mission_authority_confirmation.v1 - title: ComputerMissionAuthorityGrant - required: - - grantedAt - additionalProperties: false - console.v1.ComputerMissionBudget: - type: object - properties: - maxSteps: - exclusiveMinimum: 0 - type: integer - title: max_steps - wallClockBudgetSeconds: - exclusiveMinimum: 0 - type: - - integer - - string - title: wall_clock_budget_seconds - format: int64 - tokenBudget: - exclusiveMinimum: 0 - type: - - integer - - string - title: token_budget - format: int64 - maxToolCalls: - exclusiveMinimum: 0 - type: integer - title: max_tool_calls - maxCostMicros: - exclusiveMinimum: 0 - type: - - integer - - string - title: max_cost_micros - format: int64 - title: ComputerMissionBudget - additionalProperties: false - console.v1.ComputerMissionCanaryDefinition: - type: object - properties: - definitionId: - type: string - title: definition_id - minLength: 1 - version: - exclusiveMinimum: 0 - type: integer - title: version - scenarioKind: - not: - enum: - - 0 - title: scenario_kind - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryScenarioKind' - objective: - type: string - title: objective - minLength: 1 - enabledEnvironments: - type: array - items: - type: string - title: enabled_environments - minItems: 1 - fixtureResourceIds: - type: array - items: - type: string - title: fixture_resource_ids - minItems: 1 - requiredCanaryTags: - type: array - items: - type: string - title: required_canary_tags - minItems: 1 - requiredCapabilities: - type: array - items: - type: string - title: required_capabilities - minItems: 1 - runnerProfile: - type: string - title: runner_profile - minLength: 1 - authorityMode: - not: - enum: - - 0 - title: authority_mode - $ref: '#/components/schemas/console.v1.ComputerMissionAuthorityMode' - maximumGrantDurationSeconds: - exclusiveMinimum: 0 - type: - - integer - - string - title: maximum_grant_duration_seconds - format: int64 - budget: - title: budget - $ref: '#/components/schemas/console.v1.ComputerMissionBudget' - requiredEvidenceGates: - type: array - items: - $ref: '#/components/schemas/console.v1.ComputerMissionEvidenceGate' - title: required_evidence_gates - minItems: 1 - expectedForwardEffects: - type: array - items: - type: string - title: expected_forward_effects - minItems: 1 - requiredCompensatingEffects: - type: array - items: - $ref: '#/components/schemas/console.v1.ComputerMissionCompensatingAction' - title: required_compensating_effects - minItems: 1 - thresholds: - type: array - items: - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryThreshold' - title: thresholds - minItems: 1 - hardSafetyGates: - type: array - items: - $ref: '#/components/schemas/console.v1.ComputerMissionEvidenceGate' - title: hard_safety_gates - minItems: 1 - plannerVersion: - type: string - title: planner_version - minLength: 1 - runtimeVersion: - type: string - title: runtime_version - minLength: 1 - toolContractVersion: - type: string - title: tool_contract_version - minLength: 1 - title: ComputerMissionCanaryDefinition - required: - - budget - additionalProperties: false - console.v1.ComputerMissionCanaryDimensionResult: - type: object - properties: - dimension: - not: - enum: - - 0 - title: dimension - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryScoreDimension' - score: - type: number - title: score - maximum: 100 - format: double - weight: - type: integer - title: weight - title: ComputerMissionCanaryDimensionResult - additionalProperties: false - console.v1.ComputerMissionCanaryEffect: - type: object - properties: - effectId: - type: string - title: effect_id - minLength: 1 - state: - not: - enum: - - 0 - title: state - $ref: '#/components/schemas/console.v1.ComputerMissionEffectState' - capability: - type: string - title: capability - minLength: 1 - resourceId: - type: string - title: resource_id - minLength: 1 - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - forwardExecutionId: - type: string - title: forward_execution_id - forwardIdempotencyKey: - type: string - title: forward_idempotency_key - rollbackExecutionId: - type: string - title: rollback_execution_id - rollbackIdempotencyKey: - type: string - title: rollback_idempotency_key - recoveryAction: - type: string - title: recovery_action - recordedAt: - title: recorded_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: ComputerMissionCanaryEffect - additionalProperties: false - console.v1.ComputerMissionCanaryEvaluation: - type: object - properties: - evaluationId: - type: string - title: evaluation_id - minLength: 1 - evaluatorVersion: - type: string - title: evaluator_version - minLength: 1 - recommendation: - not: - enum: - - 0 - title: recommendation - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryRecommendation' - aggregateScore: - type: number - title: aggregate_score - maximum: 100 - format: double - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - dimensions: - type: array - items: - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryDimensionResult' - title: dimensions - hardGates: - type: array - items: - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryHardGateResult' - title: hard_gates - policyVersion: - type: string - title: policy_version - plannerVersion: - type: string - title: planner_version - runtimeVersion: - type: string - title: runtime_version - toolContractVersion: - type: string - title: tool_contract_version - definitionId: - type: string - title: definition_id - definitionVersion: - type: integer - title: definition_version - title: ComputerMissionCanaryEvaluation - additionalProperties: false - console.v1.ComputerMissionCanaryHardGateResult: - type: object - properties: - gateId: - type: string - title: gate_id - minLength: 1 - passed: - type: boolean - title: passed - title: ComputerMissionCanaryHardGateResult - additionalProperties: false - console.v1.ComputerMissionCanaryOperatorAction: - type: object - properties: - actionId: - type: string - title: action_id - minLength: 1 - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryOperatorActionKind' - actorId: - type: string - title: actor_id - minLength: 1 - reason: - type: string - title: reason - minLength: 1 - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - scopeBefore: - title: scope_before - $ref: '#/components/schemas/console.v1.ComputerMissionScope' - scopeAfter: - title: scope_after - $ref: '#/components/schemas/console.v1.ComputerMissionScope' - budgetBefore: - title: budget_before - $ref: '#/components/schemas/console.v1.ComputerMissionBudget' - budgetAfter: - title: budget_after - $ref: '#/components/schemas/console.v1.ComputerMissionBudget' - grantExpiresAtBefore: - title: grant_expires_at_before - $ref: '#/components/schemas/google.protobuf.Timestamp' - grantExpiresAtAfter: - title: grant_expires_at_after - $ref: '#/components/schemas/google.protobuf.Timestamp' - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - title: ComputerMissionCanaryOperatorAction - required: - - occurredAt - additionalProperties: false - console.v1.ComputerMissionCanaryRun: - type: object - properties: - canaryRunId: - type: string - title: canary_run_id - minLength: 1 - canaryDefinitionId: - type: string - title: canary_definition_id - minLength: 1 - missionId: - type: string - title: mission_id - minLength: 1 - state: - not: - enum: - - 0 - title: state - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryRunState' - scope: - title: scope - $ref: '#/components/schemas/console.v1.ComputerMissionScope' - budget: - title: budget - $ref: '#/components/schemas/console.v1.ComputerMissionBudget' - grantExpiresAt: - title: grant_expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - recommendation: - title: recommendation - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryRecommendation' - title: ComputerMissionCanaryRun - required: - - scope - - budget - - grantExpiresAt - additionalProperties: false - console.v1.ComputerMissionCanaryThreshold: - type: object - properties: - dimension: - not: - enum: - - 0 - title: dimension - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryScoreDimension' - minimumScore: - type: number - title: minimum_score - maximum: 100 - format: double - title: ComputerMissionCanaryThreshold - additionalProperties: false - console.v1.ComputerMissionCapability: - type: object - properties: - name: - type: string - title: name - pattern: ^apex\.[a-z0-9_.-]+$ - inputSchema: - title: input_schema - $ref: '#/components/schemas/google.protobuf.Struct' - observerName: - type: string - title: observer_name - pattern: ^apex\.[a-z0-9_.-]+$ - schemaDigestSha256: - type: string - title: schema_digest_sha256 - pattern: ^[0-9a-f]{64}$ - dispatchName: - type: string - title: dispatch_name - pattern: ^[a-z0-9_.-]+$ - description: |- - Exact raw FastMCP catalog name. Platform authority remains namespaced by - name; dispatch_name is never planner-selectable or derived by stripping. - title: ComputerMissionCapability - required: - - inputSchema - additionalProperties: false - console.v1.ComputerMissionCompensatingAction: - type: object - properties: - forwardCapability: - type: string - title: forward_capability - minLength: 1 - forwardResourceId: - type: string - title: forward_resource_id - minLength: 1 - forwardArgumentsDigest: - type: string - title: forward_arguments_digest - minLength: 1 - forwardPreconditions: - type: array - items: - type: string - title: forward_preconditions - rollbackCapability: - type: string - title: rollback_capability - minLength: 1 - rollbackArguments: - title: rollback_arguments - $ref: '#/components/schemas/google.protobuf.Struct' - rollbackVerificationPredicate: - type: string - title: rollback_verification_predicate - minLength: 1 - rollbackSafeToRetry: - type: boolean - title: rollback_safe_to_retry - maxRollbackAttempts: - exclusiveMinimum: 0 - type: integer - title: max_rollback_attempts - rollbackDeadlineSeconds: - exclusiveMinimum: 0 - type: - - integer - - string - title: rollback_deadline_seconds - format: int64 - forwardEvidencePredicate: - type: string - title: forward_evidence_predicate - minLength: 1 - cleanupEvidencePredicate: - type: string - title: cleanup_evidence_predicate - minLength: 1 - rollbackResourceId: - type: string - title: rollback_resource_id - minLength: 1 - rollbackArgumentBindings: - type: array - items: - $ref: '#/components/schemas/console.v1.ComputerMissionRollbackArgumentBinding' - title: rollback_argument_bindings - minItems: 1 - explicitRetryDenial: - type: boolean - title: explicit_retry_denial - title: ComputerMissionCompensatingAction - required: - - rollbackArguments - additionalProperties: false - console.v1.ComputerMissionContract: - type: object - properties: - goal: - type: string - title: goal - minLength: 1 - scope: - title: scope - $ref: '#/components/schemas/console.v1.ComputerMissionScope' - authority: - title: authority - $ref: '#/components/schemas/console.v1.ComputerMissionAuthorityGrant' - budget: - title: budget - $ref: '#/components/schemas/console.v1.ComputerMissionBudget' - requiredEvidence: - type: array - items: - type: string - title: required_evidence - runnerProfile: - type: string - title: runner_profile - minLength: 1 - resumeOfMissionId: - type: string - title: resume_of_mission_id - description: |- - resume_of_mission_id links a new mission and fresh budget to a failed or - budget-exhausted predecessor in the same tenant scope. - decision: - title: decision - $ref: '#/components/schemas/console.v1.ComputerMissionDecision' - title: ComputerMissionContract - required: - - scope - - authority - - budget - - decision - additionalProperties: false - description: |+ - required_evidence must be non-empty unless an APEX runner binding is present: - ``` - size(this.required_evidence) > 0 || has(this.scope.apex_runner_binding) - ``` - - console.v1.ComputerMissionDecision: - type: object - properties: - policyVersion: - type: string - title: policy_version - minLength: 1 - route: - not: - enum: - - 0 - title: route - $ref: '#/components/schemas/console.v1.ComputerMissionDecisionRoute' - selectedCandidateId: - type: string - title: selected_candidate_id - decisionRef: - type: string - title: decision_ref - minLength: 1 - decisionDigestSha256: - type: string - title: decision_digest_sha256 - pattern: ^[0-9a-f]{64}$ - title: ComputerMissionDecision - additionalProperties: false - description: |- - ComputerMissionDecision binds mission creation to the governed routing - decision that selected an execution candidate or deliberately selected no - route. decision_digest_sha256 is the digest of the owner-produced decision - record referenced by decision_ref. - console.v1.ComputerMissionEvidenceGate: - type: object - properties: - gateId: - type: string - title: gate_id - minLength: 1 - predicate: - type: string - title: predicate - minLength: 1 - hardSafetyGate: - type: boolean - title: hard_safety_gate - title: ComputerMissionEvidenceGate - additionalProperties: false - console.v1.ComputerMissionLongHorizonBudgetState: - type: object - properties: - deadlineAt: - title: deadline_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - authorityExpiresAt: - title: authority_expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - maxActiveRunnerSeconds: - type: - - integer - - string - title: max_active_runner_seconds - format: int64 - consumedActiveRunnerSeconds: - type: - - integer - - string - title: consumed_active_runner_seconds - format: int64 - maxRecoveries: - type: integer - title: max_recoveries - consumedRecoveries: - type: integer - title: consumed_recoveries - maxConsecutiveFailures: - type: integer - title: max_consecutive_failures - consecutiveFailures: - type: integer - title: consecutive_failures - title: ComputerMissionLongHorizonBudgetState - required: - - deadlineAt - additionalProperties: false - console.v1.ComputerMissionRollbackArgumentBinding: - type: object - properties: - argument: - type: string - title: argument - minLength: 1 - source: - not: - enum: - - 0 - title: source - $ref: '#/components/schemas/console.v1.ComputerMissionRollbackArgumentSource' - sourcePath: - type: string - title: source_path - minLength: 1 - title: ComputerMissionRollbackArgumentBinding - additionalProperties: false - console.v1.ComputerMissionScope: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - resourceIds: - type: array - items: - type: string - title: resource_ids - minItems: 1 - capabilities: - type: array - items: - type: string - title: capabilities - minItems: 1 - capabilityManifests: - type: array - items: - $ref: '#/components/schemas/console.v1.ComputerMissionCapability' - title: capability_manifests - apexRunnerBinding: - title: apex_runner_binding - $ref: '#/components/schemas/console.v1.ComputerMissionApexRunnerBinding' - title: ComputerMissionScope - additionalProperties: false - console.v1.ConnectedCall: - type: object - properties: - id: - type: string - title: id - minLength: 1 - title: - type: string - title: title - maxLength: 512 - meetUrl: - type: string - title: meet_url - format: uri - startsAt: - title: starts_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - endsAt: - title: ends_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: ConnectedCall - additionalProperties: false - description: |- - ConnectedCall is one upcoming call projected from the tenant's connected - calendar. The field name meet_url is a wire-compatibility alias; it carries - the call's join URL on whatever meeting platform hosts it. - console.v1.ConnectorProfile: - type: object - properties: - id: - type: string - title: id - minLength: 1 - providerId: - type: string - title: provider_id - minLength: 1 - profileName: - type: string - title: profile_name - minLength: 1 - scopes: - type: array - items: - type: string - title: scopes - enabled: - type: boolean - title: enabled - isDefault: - type: boolean - title: is_default - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: ConnectorProfile - additionalProperties: false - console.v1.ConnectorProfileScopeSet: - type: object - properties: - values: - type: array - items: - type: string - title: values - title: ConnectorProfileScopeSet - additionalProperties: false - console.v1.ConnectorTrigger: - type: object - properties: - triggerId: - type: string - title: trigger_id - minLength: 1 - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - name: - type: string - title: name - minLength: 1 - source: - not: - enum: - - 0 - title: source - $ref: '#/components/schemas/console.v1.ConnectorTriggerSource' - cronExpression: - type: string - title: cron_expression - connectionId: - type: string - title: connection_id - providerId: - type: string - title: provider_id - eventKind: - type: string - title: event_kind - payloadFieldAllowlist: - type: array - items: - type: string - title: payload_field_allowlist - template: - title: template - $ref: '#/components/schemas/console.v1.MissionScheduleTemplate' - enabled: - type: boolean - title: enabled - nextRunAt: - title: next_run_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - lastRunAt: - title: last_run_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - lastStatus: - type: string - title: last_status - lastMissionId: - type: string - title: last_mission_id - lastEventId: - type: string - title: last_event_id - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: ConnectorTrigger - required: - - template - - createdAt - - updatedAt - additionalProperties: false - description: |- - ConnectorTrigger is a governed mission template attached to a connector - event or schedule. `payload_field_allowlist` contains dotted JSON paths; - no event field outside this list is admitted to the mission context. - console.v1.ConsoleMetric: - type: object - properties: - id: - type: string - title: id - label: - type: string - title: label - value: - type: string - title: value - unit: - type: string - title: unit - detail: - type: string - title: detail - trend: - type: string - title: trend - tone: - type: string - title: tone - title: ConsoleMetric - additionalProperties: false - console.v1.ConsoleQuery: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - timeRange: - title: time_range - $ref: '#/components/schemas/console.v1.TimeRange' - environment: - type: string - title: environment - teamId: - type: string - title: team_id - owner: - type: string - title: owner - riskLevel: - title: risk_level - $ref: '#/components/schemas/common.v1.RiskLevel' - assetType: - type: string - title: asset_type - status: - type: string - title: status - limit: - type: integer - title: limit - maximum: 500 - format: int32 - offset: - type: integer - title: offset - format: int32 - search: - type: string - title: search - provider: - type: string - title: provider - organizationId: - type: string - title: organization_id - title: ConsoleQuery - additionalProperties: false - description: ConsoleQuery is shared by read endpoints. - console.v1.ConsoleSnapshotFreshness: - type: object - properties: - generatedAt: - title: generated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - staleAgeMs: - type: - - integer - - string - title: stale_age_ms - format: int64 - degradedServices: - type: array - items: - type: string - title: degraded_services - staleSections: - type: array - items: - type: string - title: stale_sections - title: ConsoleSnapshotFreshness - additionalProperties: false - console.v1.ContinueComputerMissionRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - missionId: - type: string - title: mission_id - minLength: 1 - answer: - type: string - title: answer - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: ContinueComputerMissionRequest - required: - - query - additionalProperties: false - console.v1.ContinueComputerMissionResponse: - type: object - properties: - mission: - title: mission - $ref: '#/components/schemas/console.v1.ComputerMission' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.OperatingReceipt' - title: ContinueComputerMissionResponse - required: - - mission - - receipt - additionalProperties: false - console.v1.CorrectWorkspaceMemoryRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - memoryId: - type: string - title: memory_id - minLength: 1 - expectedRevision: - type: - - integer - - string - title: expected_revision - minimum: 1 - format: int64 - content: - type: string - title: content - maxLength: 20000 - minLength: 1 - tags: - type: array - items: - type: string - maxItems: 64 - title: tags - maxItems: 64 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: CorrectWorkspaceMemoryRequest - required: - - query - additionalProperties: false - console.v1.CorrectWorkspaceMemoryResponse: - type: object - properties: - memory: - title: memory - $ref: '#/components/schemas/console.v1.WorkspaceMemory' - title: CorrectWorkspaceMemoryResponse - required: - - memory - additionalProperties: false - console.v1.CostEvidenceSummary: - type: object - properties: - status: - type: string - title: status - description: status is one of recorded or missing. - provider: - type: string - title: provider - model: - type: string - title: model - inputTokens: - type: - - integer - - string - title: input_tokens - format: int64 - outputTokens: - type: - - integer - - string - title: output_tokens - format: int64 - totalCostUsd: - type: number - title: total_cost_usd - format: double - meterRef: - type: string - title: meter_ref - missingReason: - type: string - title: missing_reason - title: CostEvidenceSummary - additionalProperties: false - console.v1.CostUsage: - type: object - properties: - id: - type: string - title: id - traceId: - type: string - title: trace_id - assetId: - type: string - title: asset_id - provider: - type: string - title: provider - model: - type: string - title: model - spendUsd: - type: number - title: spend_usd - format: double - inputTokens: - type: - - integer - - string - title: input_tokens - format: int64 - outputTokens: - type: - - integer - - string - title: output_tokens - format: int64 - requestCount: - type: - - integer - - string - title: request_count - format: int64 - latencyMs: - type: - - integer - - string - title: latency_ms - format: int64 - status: - type: string - title: status - riskLevel: - title: risk_level - $ref: '#/components/schemas/common.v1.RiskLevel' - detail: - type: string - title: detail - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - relatedResources: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: related_resources - spendMicros: - type: - - integer - - string - title: spend_micros - format: int64 - projectId: - type: string - title: project_id - repository: - type: string - title: repository - teamId: - type: string - title: team_id - ownerId: - type: string - title: owner_id - runId: - type: string - title: run_id - attributionTraceId: - type: string - title: attribution_trace_id - requestId: - type: string - title: request_id - deploymentId: - type: string - title: deployment_id - jobId: - type: string - title: job_id - sourceHealth: - type: string - title: source_health - pricingVersion: - type: string - title: pricing_version - ingestedAt: - title: ingested_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - recordKind: - type: string - title: record_kind - description: |- - record_kind distinguishes atomic usage events from provider-owned aggregate - snapshots. Consumers use provider snapshots as authoritative totals rather - than summing them with overlapping gateway events. - spendTodayMicros: - type: - - integer - - string - title: spend_today_micros - format: int64 - description: |- - Provider-reported spend for the current UTC day when record_kind is a - provider_monthly_snapshot. The monthly total remains spend_micros. - upstreamProvider: - type: string - title: upstream_provider - description: |- - Model provider selected behind the billing source, when the source - reports that distinction. - provenance: - type: string - title: provenance - description: |- - Join quality for provider-reported rows: exact, aggregate, estimated, or - unmatched. - cacheReadTokens: - type: - - integer - - string - title: cache_read_tokens - format: int64 - description: |- - Cached-read and cache-write portions of input_tokens, when the source - reports them separately. These values are already included in input_tokens. - cacheWriteTokens: - type: - - integer - - string - title: cache_write_tokens - format: int64 - pricingSource: - type: string - title: pricing_source - description: Cost and usage evidence origins retained from the durable ledger. - usageSource: - type: string - title: usage_source - title: CostUsage - additionalProperties: false - console.v1.CostUsageAttributionSummary: - type: object - properties: - provider: - type: string - title: provider - assetId: - type: string - title: asset_id - model: - type: string - title: model - spendTodayMicros: - type: - - integer - - string - title: spend_today_micros - format: int64 - spendMonthToDateMicros: - type: - - integer - - string - title: spend_month_to_date_micros - format: int64 - requestCount: - type: - - integer - - string - title: request_count - format: int64 - inputTokens: - type: - - integer - - string - title: input_tokens - format: int64 - outputTokens: - type: - - integer - - string - title: output_tokens - format: int64 - recordKind: - type: string - title: record_kind - priorMonthToDateMicros: - type: - - integer - - string - title: prior_month_to_date_micros - format: int64 - priorRequestCount: - type: - - integer - - string - title: prior_request_count - format: int64 - priorInputTokens: - type: - - integer - - string - title: prior_input_tokens - format: int64 - priorOutputTokens: - type: - - integer - - string - title: prior_output_tokens - format: int64 - title: CostUsageAttributionSummary - additionalProperties: false - console.v1.CostUsageRunSummary: - type: object - properties: - runId: - type: string - title: run_id - recordedCostMicros: - type: - - integer - - string - title: recorded_cost_micros - format: int64 - requestCount: - type: - - integer - - string - title: request_count - format: int64 - inputTokens: - type: - - integer - - string - title: input_tokens - format: int64 - outputTokens: - type: - - integer - - string - title: output_tokens - format: int64 - cacheReadTokens: - type: - - integer - - string - title: cache_read_tokens - format: int64 - cacheWriteTokens: - type: - - integer - - string - title: cache_write_tokens - format: int64 - sourceRowCount: - type: integer - title: source_row_count - format: int32 - unpricedRowCount: - type: integer - title: unpriced_row_count - format: int32 - description: Rows without a known cost basis must never be presented as free usage. - models: - type: array - items: - type: string - maxItems: 100 - title: models - maxItems: 100 - modelsTruncated: - type: boolean - title: models_truncated - title: CostUsageRunSummary - additionalProperties: false - console.v1.CostUsageSummary: - type: object - properties: - spendTodayMicros: - type: - - integer - - string - title: spend_today_micros - format: int64 - spendMonthToDateMicros: - type: - - integer - - string - title: spend_month_to_date_micros - format: int64 - priorMonthToDateMicros: - type: - - integer - - string - title: prior_month_to_date_micros - format: int64 - requestCount: - type: - - integer - - string - title: request_count - format: int64 - inputTokens: - type: - - integer - - string - title: input_tokens - format: int64 - outputTokens: - type: - - integer - - string - title: output_tokens - format: int64 - sourceRowCount: - type: integer - title: source_row_count - format: int32 - attributions: - type: array - items: - $ref: '#/components/schemas/console.v1.CostUsageAttributionSummary' - title: attributions - asOf: - title: as_of - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: CostUsageSummary - additionalProperties: false - console.v1.CreateBillingCheckoutSessionRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - requestId: - type: string - title: request_id - format: uuid - title: CreateBillingCheckoutSessionRequest - additionalProperties: false - console.v1.CreateBillingCheckoutSessionResponse: - type: object - properties: - url: - type: string - title: url - format: uri - title: CreateBillingCheckoutSessionResponse - additionalProperties: false - console.v1.CreateBillingPortalSessionRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - title: CreateBillingPortalSessionRequest - additionalProperties: false - console.v1.CreateBillingPortalSessionResponse: - type: object - properties: - url: - type: string - title: url - format: uri - title: CreateBillingPortalSessionResponse - additionalProperties: false - console.v1.CreateBusinessObjectRelationshipRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - relationship: - title: relationship - $ref: '#/components/schemas/console.v1.BusinessObjectRelationship' - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - title: CreateBusinessObjectRelationshipRequest - additionalProperties: false - console.v1.CreateBusinessObjectRelationshipResponse: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/console.v1.BusinessObject' - title: CreateBusinessObjectRelationshipResponse - additionalProperties: false - console.v1.CreateBusinessObjectRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - typeId: - type: string - title: type_id - schemaRevision: - type: - - integer - - string - title: schema_revision - format: int64 - values: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessFieldValue' - title: values - title: CreateBusinessObjectRequest - additionalProperties: false - console.v1.CreateBusinessObjectResponse: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/console.v1.BusinessObject' - title: CreateBusinessObjectResponse - additionalProperties: false - console.v1.CreateCaptureFormInvitationRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - publicationId: - type: string - title: publication_id - minLength: 1 - recipientEmail: - type: string - title: recipient_email - format: email - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - boundValues: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessFieldValue' - title: bound_values - maxItems: 64 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - title: CreateCaptureFormInvitationRequest - required: - - expiresAt - additionalProperties: false - console.v1.CreateCaptureFormInvitationResponse: - type: object - properties: - invitation: - title: invitation - $ref: '#/components/schemas/console.v1.CaptureFormInvitation' - title: CreateCaptureFormInvitationResponse - required: - - invitation - additionalProperties: false - console.v1.CreateCaptureFormRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - name: - type: string - title: name - maxLength: 160 - minLength: 1 - description: - type: string - title: description - maxLength: 2000 - version: - title: version - $ref: '#/components/schemas/console.v1.CaptureFormVersionInput' - title: CreateCaptureFormRequest - required: - - version - additionalProperties: false - console.v1.CreateCaptureFormResponse: - type: object - properties: - form: - title: form - $ref: '#/components/schemas/console.v1.CaptureForm' - version: - title: version - $ref: '#/components/schemas/console.v1.CaptureFormVersion' - title: CreateCaptureFormResponse - required: - - form - - version - additionalProperties: false - console.v1.CreateConnectorProfileRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - providerId: - type: string - title: provider_id - minLength: 1 - profileName: - type: string - title: profile_name - minLength: 1 - connectionId: - type: string - title: connection_id - minLength: 1 - scopes: - type: array - items: - type: string - title: scopes - enabled: - type: boolean - title: enabled - nullable: true - isDefault: - type: boolean - title: is_default - title: CreateConnectorProfileRequest - required: - - query - additionalProperties: false - console.v1.CreateConnectorProfileResponse: - type: object - properties: - profile: - title: profile - $ref: '#/components/schemas/console.v1.ConnectorProfile' - title: CreateConnectorProfileResponse - required: - - profile - additionalProperties: false - console.v1.CreateConnectorTriggerRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - name: - type: string - title: name - minLength: 1 - source: - not: - enum: - - 0 - title: source - $ref: '#/components/schemas/console.v1.ConnectorTriggerSource' - cronExpression: - type: string - title: cron_expression - connectionId: - type: string - title: connection_id - providerId: - type: string - title: provider_id - eventKind: - type: string - title: event_kind - payloadFieldAllowlist: - type: array - items: - type: string - title: payload_field_allowlist - template: - title: template - $ref: '#/components/schemas/console.v1.MissionScheduleTemplate' - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: CreateConnectorTriggerRequest - required: - - query - - template - additionalProperties: false - console.v1.CreateConnectorTriggerResponse: - type: object - properties: - trigger: - title: trigger - $ref: '#/components/schemas/console.v1.ConnectorTrigger' - title: CreateConnectorTriggerResponse - required: - - trigger - additionalProperties: false - console.v1.CreateDexMcpServerRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - name: - type: string - title: name - minLength: 1 - baseUrl: - type: string - title: base_url - minLength: 1 - authKind: - type: string - title: auth_kind - bearerToken: - type: string - title: bearer_token - enabled: - type: boolean - title: enabled - title: CreateDexMcpServerRequest - required: - - query - additionalProperties: false - console.v1.CreateDexMcpServerResponse: - type: object - properties: - server: - title: server - $ref: '#/components/schemas/console.v1.DexMcpServer' - title: CreateDexMcpServerResponse - required: - - server - additionalProperties: false - console.v1.CreateInferenceCreditCheckoutRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - requestId: - type: string - title: request_id - format: uuid - creditCents: - type: - - integer - - string - title: credit_cents - format: int64 - description: Server accepts only the published USD20, USD50, and USD100 credit blocks. - title: CreateInferenceCreditCheckoutRequest - additionalProperties: false - console.v1.CreateInferenceCreditCheckoutResponse: - type: object - properties: - url: - type: string - title: url - format: uri - title: CreateInferenceCreditCheckoutResponse - additionalProperties: false - console.v1.CreateMissionScheduleRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - name: - type: string - title: name - minLength: 1 - cronExpression: - type: string - title: cron_expression - minLength: 1 - template: - title: template - $ref: '#/components/schemas/console.v1.MissionScheduleTemplate' - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: CreateMissionScheduleRequest - required: - - query - - template - additionalProperties: false - console.v1.CreateMissionScheduleResponse: - type: object - properties: - schedule: - title: schedule - $ref: '#/components/schemas/console.v1.MissionSchedule' - title: CreateMissionScheduleResponse - required: - - schedule - additionalProperties: false - console.v1.CreateProspectingDraftRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - candidateId: - type: string - title: candidate_id - maxLength: 128 - minLength: 1 - targetAccount: - title: target_account - $ref: '#/components/schemas/console.v1.ProspectingDraftTargetAccount' - channel: - not: - enum: - - 0 - title: channel - $ref: '#/components/schemas/console.v1.ProspectingDraftChannel' - tone: - not: - enum: - - 0 - title: tone - $ref: '#/components/schemas/console.v1.ProspectingDraftTone' - evidenceIds: - type: array - items: - type: string - maxItems: 50 - title: evidence_ids - maxItems: 50 - minItems: 1 - reason: - type: string - title: reason - maxLength: 512 - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 256 - minLength: 1 - title: CreateProspectingDraftRequest - required: - - query - - targetAccount - additionalProperties: false - console.v1.CreateProspectingDraftResponse: - type: object - properties: - draft: - title: draft - $ref: '#/components/schemas/console.v1.ProspectingDraft' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.ProspectingDraftMutationReceipt' - title: CreateProspectingDraftResponse - required: - - draft - - receipt - additionalProperties: false - console.v1.CreateProspectingWatchProgramRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - name: - type: string - title: name - maxLength: 128 - minLength: 1 - config: - title: config - $ref: '#/components/schemas/google.protobuf.Struct' - scoringRuleRevision: - type: string - title: scoring_rule_revision - maxLength: 128 - minLength: 1 - reason: - type: string - title: reason - maxLength: 512 - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 256 - minLength: 1 - title: CreateProspectingWatchProgramRequest - required: - - query - - config - additionalProperties: false - console.v1.CreateProspectingWatchProgramResponse: - type: object - properties: - program: - title: program - $ref: '#/components/schemas/console.v1.ProspectingWatchProgram' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.ProspectingWatchProgramMutationReceipt' - title: CreateProspectingWatchProgramResponse - required: - - program - - receipt - additionalProperties: false - console.v1.CreateWorkspaceSkillRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - name: - type: string - title: name - minLength: 1 - description: - type: string - title: description - body: - type: string - title: body - minLength: 1 - title: CreateWorkspaceSkillRequest - required: - - query - additionalProperties: false - console.v1.CreateWorkspaceSkillResponse: - type: object - properties: - skill: - title: skill - $ref: '#/components/schemas/console.v1.OperatingSkill' - title: CreateWorkspaceSkillResponse - required: - - skill - additionalProperties: false - console.v1.CredentialAuthoritySummary: - type: object - properties: - status: - type: string - title: status - description: status is one of verified, unverified, missing, revoked, expired, or blocked. - subject: - type: string - title: subject - provider: - type: string - title: provider - authorityRef: - type: string - title: authority_ref - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - revocationState: - type: string - title: revocation_state - missingAuthorities: - type: array - items: - type: string - title: missing_authorities - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - title: CredentialAuthoritySummary - additionalProperties: false - console.v1.CustomerIntelligenceEvidenceRef: - type: object - properties: - ownerType: - type: string - title: owner_type - maxLength: 80 - minLength: 1 - ownerId: - type: string - title: owner_id - maxLength: 256 - minLength: 1 - evidenceId: - type: string - title: evidence_id - maxLength: 256 - minLength: 1 - polarity: - not: - enum: - - 0 - title: polarity - $ref: '#/components/schemas/console.v1.CustomerIntelligenceEvidencePolarity' - digestSha256: - type: string - title: digest_sha256 - maxLength: 64 - minLength: 64 - safeLabel: - type: string - title: safe_label - maxLength: 120 - title: CustomerIntelligenceEvidenceRef - additionalProperties: false - console.v1.CustomerIntelligenceFact: - type: object - properties: - current: - title: current - $ref: '#/components/schemas/console.v1.CustomerIntelligenceFactRevision' - revisions: - type: array - items: - $ref: '#/components/schemas/console.v1.CustomerIntelligenceFactRevision' - title: revisions - maxItems: 100 - title: CustomerIntelligenceFact - required: - - current - additionalProperties: false - console.v1.CustomerIntelligenceFactRevision: - type: object - properties: - factId: - type: string - title: fact_id - revision: - exclusiveMinimum: 0 - type: - - integer - - string - title: revision - format: int64 - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - subjectKind: - not: - enum: - - 0 - title: subject_kind - $ref: '#/components/schemas/console.v1.CustomerIntelligenceSubjectKind' - subjectRefHash: - type: string - title: subject_ref_hash - maxLength: 64 - minLength: 64 - productArea: - type: string - title: product_area - maxLength: 80 - minLength: 1 - journey: - type: string - title: journey - maxLength: 80 - minLength: 1 - predicate: - type: string - title: predicate - maxLength: 120 - minLength: 1 - safeSummary: - type: string - title: safe_summary - maxLength: 280 - minLength: 1 - authority: - not: - enum: - - 0 - title: authority - $ref: '#/components/schemas/console.v1.CustomerIntelligenceAuthority' - lifecycleState: - not: - enum: - - 0 - title: lifecycle_state - $ref: '#/components/schemas/console.v1.CustomerIntelligenceLifecycleState' - confidenceMicros: - type: integer - title: confidence_micros - maximum: 1000000 - format: int32 - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.CustomerIntelligenceEvidenceRef' - title: evidence_refs - maxItems: 64 - producerKind: - not: - enum: - - 0 - title: producer_kind - $ref: '#/components/schemas/console.v1.CustomerIntelligenceProducerKind' - producerRef: - type: string - title: producer_ref - maxLength: 256 - modelId: - type: string - title: model_id - maxLength: 160 - runId: - type: string - title: run_id - maxLength: 256 - policyVersion: - type: string - title: policy_version - maxLength: 80 - lineageId: - type: string - title: lineage_id - maxLength: 256 - sensitivity: - type: string - title: sensitivity - maxLength: 40 - retentionClass: - type: string - title: retention_class - maxLength: 40 - validFrom: - title: valid_from - $ref: '#/components/schemas/google.protobuf.Timestamp' - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - contentFingerprintSha256: - type: string - title: content_fingerprint_sha256 - maxLength: 64 - minLength: 64 - actorId: - type: string - title: actor_id - maxLength: 256 - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: CustomerIntelligenceFactRevision - additionalProperties: false - console.v1.CustomerIntelligencePattern: - type: object - properties: - productArea: - type: string - title: product_area - journey: - type: string - title: journey - predicate: - type: string - title: predicate - organizationCount: - type: - - integer - - string - title: organization_count - minimum: 5 - format: int64 - factCount: - type: - - integer - - string - title: fact_count - minimum: 5 - format: int64 - averageConfidenceMicros: - type: integer - title: average_confidence_micros - maximum: 1000000 - format: int32 - title: CustomerIntelligencePattern - additionalProperties: false - console.v1.CustomerIntelligenceReceipt: - type: object - properties: - factId: - type: string - title: fact_id - revision: - exclusiveMinimum: 0 - type: - - integer - - string - title: revision - format: int64 - authority: - title: authority - $ref: '#/components/schemas/console.v1.CustomerIntelligenceAuthority' - lifecycleState: - title: lifecycle_state - $ref: '#/components/schemas/console.v1.CustomerIntelligenceLifecycleState' - auditDeliveryState: - type: string - title: audit_delivery_state - confirmationIntentId: - type: string - title: confirmation_intent_id - title: CustomerIntelligenceReceipt - additionalProperties: false - console.v1.DefineBusinessObjectTypeRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - definition: - title: definition - $ref: '#/components/schemas/console.v1.BusinessObjectType' - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - title: DefineBusinessObjectTypeRequest - additionalProperties: false - console.v1.DefineBusinessObjectTypeResponse: - type: object - properties: - definition: - title: definition - $ref: '#/components/schemas/console.v1.BusinessObjectType' - title: DefineBusinessObjectTypeResponse - additionalProperties: false - console.v1.DefineBusinessProcessRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - definition: - title: definition - $ref: '#/components/schemas/console.v1.BusinessProcessDefinition' - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - title: DefineBusinessProcessRequest - additionalProperties: false - console.v1.DefineBusinessProcessResponse: - type: object - properties: - definition: - title: definition - $ref: '#/components/schemas/console.v1.BusinessProcessDefinition' - title: DefineBusinessProcessResponse - additionalProperties: false - console.v1.DeleteBusinessObjectRelationshipRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - relationship: - title: relationship - $ref: '#/components/schemas/console.v1.BusinessObjectRelationship' - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - title: DeleteBusinessObjectRelationshipRequest - additionalProperties: false - console.v1.DeleteBusinessObjectRelationshipResponse: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/console.v1.BusinessObject' - title: DeleteBusinessObjectRelationshipResponse - additionalProperties: false - console.v1.DeleteBusinessObjectRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - objectId: - type: string - title: object_id - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - title: DeleteBusinessObjectRequest - additionalProperties: false - console.v1.DeleteBusinessObjectResponse: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/console.v1.BusinessObject' - title: DeleteBusinessObjectResponse - additionalProperties: false - console.v1.DeleteConnectorProfileRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - id: - type: string - title: id - minLength: 1 - title: DeleteConnectorProfileRequest - required: - - query - additionalProperties: false - console.v1.DeleteConnectorProfileResponse: - type: object - properties: - deleted: - type: boolean - title: deleted - title: DeleteConnectorProfileResponse - additionalProperties: false - console.v1.DeleteConnectorTriggerRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - triggerId: - type: string - title: trigger_id - minLength: 1 - title: DeleteConnectorTriggerRequest - required: - - query - additionalProperties: false - console.v1.DeleteConnectorTriggerResponse: - type: object - title: DeleteConnectorTriggerResponse - additionalProperties: false - console.v1.DeleteDexMcpServerRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - serverId: - type: string - title: server_id - minLength: 1 - title: DeleteDexMcpServerRequest - required: - - query - additionalProperties: false - console.v1.DeleteDexMcpServerResponse: - type: object - properties: - deleted: - type: boolean - title: deleted - title: DeleteDexMcpServerResponse - additionalProperties: false - console.v1.DeletePrivateEndpointRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - endpointId: - type: string - title: endpoint_id - minLength: 1 - reasonCode: - type: string - title: reason_code - minLength: 1 - title: DeletePrivateEndpointRequest - required: - - query - additionalProperties: false - console.v1.DeletePrivateEndpointResponse: - type: object - properties: - deleted: - type: boolean - title: deleted - endpoint: - title: endpoint - $ref: '#/components/schemas/console.v1.PrivateEndpoint' - title: DeletePrivateEndpointResponse - additionalProperties: false - console.v1.DeleteWorkspaceKeyConfigRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - title: DeleteWorkspaceKeyConfigRequest - additionalProperties: false - console.v1.DeleteWorkspaceSkillRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - name: - type: string - title: name - minLength: 1 - title: DeleteWorkspaceSkillRequest - required: - - query - additionalProperties: false - console.v1.DeleteWorkspaceSkillResponse: - type: object - title: DeleteWorkspaceSkillResponse - additionalProperties: false - console.v1.DexComputerCorrectionEpisode: - type: object - properties: - schema: - type: string - title: schema - minLength: 1 - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - correctionId: - type: string - title: correction_id - minLength: 1 - sourceEpisodeId: - type: string - title: source_episode_id - minLength: 1 - sourceEpisodeDigestSha256: - type: string - title: source_episode_digest_sha256 - maxLength: 64 - minLength: 64 - labels: - type: array - items: - $ref: '#/components/schemas/console.v1.DexComputerCorrectionLabel' - title: labels - evidenceDigestsSha256: - type: array - items: - type: string - maxLength: 64 - minLength: 64 - maxItems: 64 - title: evidence_digests_sha256 - maxItems: 64 - minItems: 1 - reviewState: - title: review_state - $ref: '#/components/schemas/console.v1.OperatingCorrectionReviewState' - productionLearning: - type: boolean - title: production_learning - reuseBoundary: - type: string - title: reuse_boundary - minLength: 1 - episodeDigestSha256: - type: string - title: episode_digest_sha256 - maxLength: 64 - minLength: 64 - title: DexComputerCorrectionEpisode - additionalProperties: false - console.v1.DexMcpCatalogTool: - type: object - properties: - name: - type: string - title: name - title: - type: string - title: title - description: - type: string - title: description - upstreamVersionIdentity: - type: string - title: upstream_version_identity - title: DexMcpCatalogTool - additionalProperties: false - description: |- - DexMcpCatalogTool is the browser-safe review projection of one discovered - tool. Schemas and arbitrary annotations remain in the immutable owner store. - console.v1.DexMcpOAuthProfile: - type: object - properties: - profileId: - type: string - title: profile_id - serverId: - type: string - title: server_id - profileName: - type: string - title: profile_name - subjectKind: - type: string - title: subject_kind - subjectId: - type: string - title: subject_id - currentGrantId: - type: string - title: current_grant_id - profileState: - type: string - title: profile_state - scopes: - type: array - items: - type: string - title: scopes - scopeVersion: - type: - - integer - - string - title: scope_version - format: int64 - enabled: - type: boolean - title: enabled - isDefault: - type: boolean - title: is_default - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - runtimeState: - type: string - title: runtime_state - runtimeReasonCode: - type: string - title: runtime_reason_code - title: DexMcpOAuthProfile - additionalProperties: false - description: |- - DexMcpOAuthProfile is a redacted projection. connection_ref is opaque and - may be used only by the owner boundary; access and refresh tokens are never - present in this message. - console.v1.DexMcpServer: - type: object - properties: - serverId: - type: string - title: server_id - name: - type: string - title: name - baseUrl: - type: string - title: base_url - transport: - type: string - title: transport - authKind: - type: string - title: auth_kind - hasToken: - type: boolean - title: has_token - enabled: - type: boolean - title: enabled - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - createdBy: - type: string - title: created_by - updatedBy: - type: string - title: updated_by - protocolVersion: - type: string - title: protocol_version - description: Negotiated MCP protocol version from the latest discovery. - healthState: - type: string - title: health_state - description: Last observed health state from the owning discovery store. - catalogDigest: - type: string - title: catalog_digest - description: Digest of the latest persisted catalog snapshot. - credentialRef: - type: string - title: credential_ref - description: Secret reference identity for the configured credential, if any. - oauthConnectionRef: - type: string - title: oauth_connection_ref - description: OAuth connection reference identity owned by the Connector owner. - connectorRef: - type: string - title: connector_ref - description: Private connector session reference identity used for routing, if any. - catalogSnapshotVersion: - type: - - integer - - string - title: catalog_snapshot_version - format: int64 - description: Monotonic version of the latest immutable catalog snapshot. - catalogDiscoveredAt: - title: catalog_discovered_at - description: Time the latest endpoint discovery completed. - $ref: '#/components/schemas/google.protobuf.Timestamp' - catalogPartial: - type: boolean - title: catalog_partial - description: True when discovery returned bounded warnings or an incomplete catalog. - discoveryWarnings: - type: array - items: - type: string - title: discovery_warnings - description: Bounded, display-safe discovery warnings. Raw upstream text is omitted. - catalogTools: - type: array - items: - $ref: '#/components/schemas/console.v1.DexMcpCatalogTool' - title: catalog_tools - description: Redacted tool metadata from the latest immutable catalog snapshot. - catalogPromptCount: - type: integer - title: catalog_prompt_count - catalogResourceCount: - type: integer - title: catalog_resource_count - privateRouteRequired: - type: boolean - title: private_route_required - description: |- - Route state is an owner projection. It never includes credentials or - claims that a cloud endpoint is deployed beyond the verified evidence. - privateEndpointId: - type: string - title: private_endpoint_id - privateRouteState: - type: string - title: private_route_state - privateRouteIdentity: - type: string - title: private_route_identity - privateRouteRevision: - type: - - integer - - string - title: private_route_revision - format: int64 - privateRouteOrigin: - type: string - title: private_route_origin - oauthProfileState: - type: string - title: oauth_profile_state - description: |- - Redacted OAuth profile projection for auth_kind=oauth. These fields carry - state, scopes, and version only; token material is never projected. - oauthScopes: - type: array - items: - type: string - title: oauth_scopes - oauthScopeVersion: - type: - - integer - - string - title: oauth_scope_version - format: int64 - oauthRuntimeReasonCode: - type: string - title: oauth_runtime_reason_code - credentialState: - type: string - title: credential_state - description: |- - CredentialDecision is a redacted readiness result from the existing - managed-credential/OAuth grant owners. It is not permission and never - contains credential material. - credentialReasonCode: - type: string - title: credential_reason_code - credentialBinding: - type: string - title: credential_binding - credentialObservedAt: - title: credential_observed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - credentialExpiresAt: - title: credential_expires_at - description: |- - Optional expiry supplied by the credential owner. Unset means the owner - did not provide an expiry; clients must not infer one from this projection. - $ref: '#/components/schemas/google.protobuf.Timestamp' - routeReadinessState: - type: string - title: route_readiness_state - description: |- - RouteDecision is a connectivity/readiness result from the existing - private endpoint and deployment egress owners. It never grants access. - routeReasonCode: - type: string - title: route_reason_code - routeBinding: - type: string - title: route_binding - routeObservedAt: - title: route_observed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - routeExpiresAt: - title: route_expires_at - description: |- - Optional expiry supplied by the route owner. Unset means the owner did - not provide an expiry; clients must not infer one from this projection. - $ref: '#/components/schemas/google.protobuf.Timestamp' - routeMode: - type: string - title: route_mode - routeProvider: - type: string - title: route_provider - sourceAuthority: - title: source_authority - description: |- - Credential-free external source authority from the Connector owner. An - absent or UNKNOWN observation is unavailable; local connection activity - never implies source sufficiency. - $ref: '#/components/schemas/connectors.v1.SourceAuthorityObservation' - title: DexMcpServer - additionalProperties: false - description: |- - DexMcpServer is the redacted Console projection of a governed MCP endpoint. - Secrets are write-only; callers can only observe whether one is configured. - Credential, OAuth, and connector values are owner reference identities; no - credential material ever appears on this projection. - console.v1.DexSkillCatalogEntry: - type: object - properties: - id: - type: string - title: id - description: - type: string - title: description - catalogVersion: - type: integer - title: catalog_version - format: int32 - installed: - type: boolean - title: installed - installedSkillName: - type: string - title: installed_skill_name - installedVersion: - type: integer - title: installed_version - format: int32 - installedCatalogVersion: - type: integer - title: installed_catalog_version - format: int32 - updateAvailable: - type: boolean - title: update_available - displayName: - type: string - title: display_name - publisher: - type: string - title: publisher - sourceUrl: - type: string - title: source_url - license: - type: string - title: license - category: - type: string - title: category - tags: - type: array - items: - type: string - title: tags - external: - type: boolean - title: external - riskLevel: - title: risk_level - description: |- - The procedure's reviewed operating risk, not a grant of authority. Any - governed tool or write still applies its own runtime policy and approval - boundary. - $ref: '#/components/schemas/common.v1.RiskLevel' - analysis: - title: analysis - $ref: '#/components/schemas/console.v1.SkillAnalysisReport' - exposure: - title: exposure - $ref: '#/components/schemas/console.v1.DexSkillCatalogExposure' - requiredTools: - type: array - items: - type: string - maxItems: 64 - title: required_tools - maxItems: 64 - description: |- - Governed tools the procedure cannot be carried out without. An empty - list means the catalog entry declares no particular tool requirement. - sourceRevision: - type: string - title: source_revision - packageDigest: - type: string - title: package_digest - packageManifest: - type: array - items: - $ref: '#/components/schemas/console.v1.DexSkillPackageFile' - title: package_manifest - description: |- - Browse returns manifest metadata only. Resource contents are loaded only - after an explicit skill.load/install path has passed its gates. - activationTrigger: - type: string - title: activation_trigger - objective: - type: string - title: objective - inputs: - type: array - items: - $ref: '#/components/schemas/console.v1.DexSkillInputDeclaration' - title: inputs - outputs: - type: array - items: - $ref: '#/components/schemas/console.v1.DexSkillOutputDeclaration' - title: outputs - orderedMethod: - type: array - items: - type: string - title: ordered_method - successCriteria: - type: array - items: - type: string - title: success_criteria - unavailableBehavior: - type: string - title: unavailable_behavior - outputContract: - type: string - title: output_contract - licenseEvidence: - title: license_evidence - $ref: '#/components/schemas/console.v1.DexSkillLicenseEvidence' - compatibility: - title: compatibility - $ref: '#/components/schemas/console.v1.DexSkillCompatibility' - qualityEvidence: - title: quality_evidence - $ref: '#/components/schemas/console.v1.DexSkillQualityEvidence' - lifecycleState: - title: lifecycle_state - $ref: '#/components/schemas/console.v1.DexSkillLifecycleState' - customerSafeRemediation: - type: string - title: customer_safe_remediation - updateDiff: - title: update_diff - $ref: '#/components/schemas/console.v1.DexSkillUpdateDiff' - runtimeReadiness: - title: runtime_readiness - description: |- - Catalog browse has no sandbox session. Runtime-dependent packages report - PROBE_REQUIRED until a trusted session-scoped environment probe runs. - This field does not gate package installation. - $ref: '#/components/schemas/console.v1.DexSkillRuntimeReadiness' - title: DexSkillCatalogEntry - additionalProperties: false - console.v1.DexSkillCompatibility: - type: object - properties: - schemaVersion: - type: string - title: schema_version - runtimes: - type: array - items: - type: string - title: runtimes - roles: - type: array - items: - type: string - title: roles - platforms: - type: array - items: - type: string - title: platforms - title: DexSkillCompatibility - additionalProperties: false - console.v1.DexSkillInputDeclaration: - type: object - properties: - name: - type: string - title: name - minLength: 1 - type: - type: string - title: type - minLength: 1 - description: - type: string - title: description - required: - type: boolean - title: required - title: DexSkillInputDeclaration - additionalProperties: false - description: |- - Typed, progressive-disclosure metadata for a lossless operating-skill - package. These fields describe a procedure and its resources; they never - grant authority or replace tenant, tool, approval, or policy checks. - console.v1.DexSkillLicenseEvidence: - type: object - properties: - spdxId: - type: string - title: spdx_id - sourcePath: - type: string - title: source_path - contentDigest: - type: string - title: content_digest - verified: - type: boolean - title: verified - included: - type: boolean - title: included - description: |- - True only when the license file itself is included in the package - manifest. False identifies path-level or repository-level evidence. - title: DexSkillLicenseEvidence - additionalProperties: false - console.v1.DexSkillOutputDeclaration: - type: object - properties: - name: - type: string - title: name - minLength: 1 - type: - type: string - title: type - minLength: 1 - description: - type: string - title: description - title: DexSkillOutputDeclaration - additionalProperties: false - console.v1.DexSkillPackageFile: - type: object - properties: - path: - type: string - title: path - minLength: 1 - mediaType: - type: string - title: media_type - minLength: 1 - sizeBytes: - type: - - integer - - string - title: size_bytes - format: int64 - contentDigest: - type: string - title: content_digest - minLength: 1 - kind: - title: kind - $ref: '#/components/schemas/console.v1.DexSkillPackageFileKind' - mode: - type: integer - title: mode - description: |- - POSIX mode bits as recorded by the imported package (for example 0644 or - 0755). This is metadata only; installation never executes a package file. - title: DexSkillPackageFile - additionalProperties: false - console.v1.DexSkillPlaybook: - type: object - properties: - id: - type: string - title: id - minLength: 1 - displayName: - type: string - title: display_name - minLength: 1 - outcomeDescription: - type: string - title: outcome_description - minLength: 1 - steps: - type: array - items: - $ref: '#/components/schemas/console.v1.DexSkillPlaybookStep' - title: steps - minItems: 1 - integrationLabels: - type: array - items: - type: string - maxItems: 16 - title: integration_labels - maxItems: 16 - title: DexSkillPlaybook - additionalProperties: false - description: |- - DexSkillPlaybook is a curated sequence of catalog skills for a common - operating outcome. integration_labels is intentionally optional: it is - populated only when the server models a concrete integration dependency. - console.v1.DexSkillPlaybookStep: - type: object - properties: - catalogSkillId: - type: string - title: catalog_skill_id - minLength: 1 - displayName: - type: string - title: display_name - minLength: 1 - description: - type: string - title: description - title: DexSkillPlaybookStep - additionalProperties: false - description: |- - DexSkillPlaybookStep is one ordered, server-authored outcome in a playbook. - The referenced catalog skill remains the source of the procedure and its - installation state; display metadata here keeps clients from inventing - step semantics locally. - console.v1.DexSkillQualityEvidence: - type: object - properties: - suiteVersion: - type: string - title: suite_version - fixtures: - type: array - items: - $ref: '#/components/schemas/console.v1.DexSkillQualityFixture' - title: fixtures - baselineId: - type: string - title: baseline_id - baselineDigest: - type: string - title: baseline_digest - publicationGatePassed: - type: boolean - title: publication_gate_passed - title: DexSkillQualityEvidence - additionalProperties: false - console.v1.DexSkillQualityFixture: - type: object - properties: - id: - type: string - title: id - minLength: 1 - kind: - title: kind - $ref: '#/components/schemas/console.v1.DexSkillFixtureKind' - triggerAssertion: - type: string - title: trigger_assertion - taskSuccessAssertion: - type: string - title: task_success_assertion - failureHandlingAssertion: - type: string - title: failure_handling_assertion - artifactAssertion: - type: string - title: artifact_assertion - baselineId: - type: string - title: baseline_id - title: DexSkillQualityFixture - additionalProperties: false - console.v1.DexSkillUpdateDiff: - type: object - properties: - fromCatalogVersion: - type: integer - title: from_catalog_version - format: int32 - toCatalogVersion: - type: integer - title: to_catalog_version - format: int32 - fromPackageDigest: - type: string - title: from_package_digest - toPackageDigest: - type: string - title: to_package_digest - addedPaths: - type: array - items: - type: string - title: added_paths - removedPaths: - type: array - items: - type: string - title: removed_paths - changedPaths: - type: array - items: - type: string - title: changed_paths - summary: - type: string - title: summary - bounded: - type: boolean - title: bounded - description: Servers cap path lists and summary text before returning this projection. - title: DexSkillUpdateDiff - additionalProperties: false - console.v1.DisableWorkspaceBreakGlassRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - grantId: - type: string - title: grant_id - title: DisableWorkspaceBreakGlassRequest - required: - - query - additionalProperties: false - console.v1.DiscoverDexMcpServerRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - serverId: - type: string - title: server_id - minLength: 1 - title: DiscoverDexMcpServerRequest - required: - - query - additionalProperties: false - console.v1.DiscoverDexMcpServerResponse: - type: object - properties: - server: - title: server - $ref: '#/components/schemas/console.v1.DexMcpServer' - title: DiscoverDexMcpServerResponse - required: - - server - additionalProperties: false - console.v1.EnableWorkspaceBreakGlassRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - grant: - title: grant - $ref: '#/components/schemas/console.v1.WorkspaceSettingsBreakGlassGrant' - title: EnableWorkspaceBreakGlassRequest - required: - - query - - grant - additionalProperties: false - console.v1.EndpointGuardrailSummary: - type: object - properties: - status: - type: string - title: status - description: status is one of allowed, missing, blocked, or unknown. - endpointId: - type: string - title: endpoint_id - route: - type: string - title: route - exposure: - type: string - title: exposure - allowlistSource: - type: string - title: allowlist_source - resolutionPolicy: - type: string - title: resolution_policy - blockedReason: - type: string - title: blocked_reason - missingControls: - type: array - items: - type: string - title: missing_controls - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - allowlistStatus: - type: string - title: allowlist_status - resolutionStatus: - type: string - title: resolution_status - title: EndpointGuardrailSummary - additionalProperties: false - console.v1.EngageStaffProductIssueReportRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - reportId: - type: string - title: report_id - minLength: 1 - note: - type: string - title: note - maxLength: 1000 - minLength: 1 - baselineTestRunId: - type: string - title: baseline_test_run_id - maxLength: 256 - description: |- - A staff-reviewed failing test becomes the reproduction reference. A verified - fix requires a successful run of the same Playbook with its assertions met. - verificationTestRunId: - type: string - title: verification_test_run_id - maxLength: 256 - title: EngageStaffProductIssueReportRequest - additionalProperties: false - console.v1.EngageStaffProductIssueReportResponse: - type: object - properties: - report: - title: report - $ref: '#/components/schemas/console.v1.StaffProductIssueReport' - title: EngageStaffProductIssueReportResponse - required: - - report - additionalProperties: false - console.v1.EvalResult: - type: object - properties: - id: - type: string - title: id - traceId: - type: string - title: trace_id - assetId: - type: string - title: asset_id - suiteId: - type: string - title: suite_id - scorer: - type: string - title: scorer - score: - type: number - title: score - maximum: 1 - format: double - threshold: - type: number - title: threshold - maximum: 1 - format: double - status: - type: string - title: status - riskLevel: - title: risk_level - $ref: '#/components/schemas/common.v1.RiskLevel' - model: - type: string - title: model - provider: - type: string - title: provider - qualityPerDollar: - type: number - title: quality_per_dollar - format: double - detail: - type: string - title: detail - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - relatedResources: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: related_resources - title: EvalResult - additionalProperties: false - console.v1.EvaluateWorkspaceArtifactStyleGuideRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - workspaceArtifactStyleGuide: - title: workspace_artifact_style_guide - $ref: '#/components/schemas/console.v1.WorkspaceArtifactStyleGuide' - sampleResponse: - type: string - title: sample_response - maxLength: 64000 - minLength: 1 - title: EvaluateWorkspaceArtifactStyleGuideRequest - required: - - query - - workspaceArtifactStyleGuide - additionalProperties: false - console.v1.EvaluateWorkspaceArtifactStyleGuideResponse: - type: object - properties: - passed: - type: boolean - title: passed - wordCount: - type: integer - title: word_count - violations: - type: array - items: - $ref: '#/components/schemas/console.v1.WorkspaceContentPolicyViolation' - title: violations - maxItems: 200 - title: EvaluateWorkspaceArtifactStyleGuideResponse - additionalProperties: false - console.v1.ExecuteStaffProductIssueRecoveryRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - maxLength: 4000 - workspaceId: - type: string - title: workspace_id - maxLength: 4000 - recoveryId: - type: string - title: recovery_id - maxLength: 4000 - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - title: ExecuteStaffProductIssueRecoveryRequest - additionalProperties: false - console.v1.FinalizeBusinessObjectAuthorityTransferRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - objectId: - type: string - title: object_id - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - transferId: - type: string - title: transfer_id - reconciliationDigest: - type: string - title: reconciliation_digest - fenceEvidenceId: - type: string - title: fence_evidence_id - title: FinalizeBusinessObjectAuthorityTransferRequest - additionalProperties: false - console.v1.FinalizeBusinessObjectAuthorityTransferResponse: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/console.v1.BusinessObject' - title: FinalizeBusinessObjectAuthorityTransferResponse - additionalProperties: false - console.v1.ForgetWorkspaceMemoryRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - memoryId: - type: string - title: memory_id - minLength: 1 - expectedRevision: - type: - - integer - - string - title: expected_revision - minimum: 1 - format: int64 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: ForgetWorkspaceMemoryRequest - required: - - query - additionalProperties: false - console.v1.ForgetWorkspaceMemoryResponse: - type: object - properties: - memoryId: - type: string - title: memory_id - title: ForgetWorkspaceMemoryResponse - additionalProperties: false - console.v1.ForkOperatingThreadRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - sourceChannelId: - type: string - title: source_channel_id - minLength: 1 - throughMessageId: - type: string - title: through_message_id - maxLength: 512 - description: |- - Copy history up to and including this message. Empty copies the whole - thread as of expected_source_conversation_revision. - expectedSourceConversationRevision: - type: - - integer - - string - title: expected_source_conversation_revision - format: int64 - description: |- - The source conversation_revision the caller observed. The fork is refused - when the source has moved since, so a fork always names a state the - caller actually read. - idempotencyKey: - type: string - title: idempotency_key - maxLength: 512 - minLength: 1 - label: - type: string - title: label - maxLength: 80 - title: ForkOperatingThreadRequest - required: - - query - additionalProperties: false - console.v1.ForkOperatingThreadResponse: - type: object - properties: - channel: - title: channel - $ref: '#/components/schemas/console.v1.OperatingChannel' - replayed: - type: boolean - title: replayed - title: ForkOperatingThreadResponse - required: - - channel - additionalProperties: false - console.v1.FulfillInferenceCreditCheckoutRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - checkoutSessionId: - type: string - title: checkout_session_id - minLength: 1 - title: FulfillInferenceCreditCheckoutRequest - additionalProperties: false - console.v1.FulfillInferenceCreditCheckoutResponse: - type: object - properties: - balance: - title: balance - $ref: '#/components/schemas/console.v1.InferenceCreditBalance' - title: FulfillInferenceCreditCheckoutResponse - additionalProperties: false - console.v1.GetAgentProductRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - agentId: - type: string - title: agent_id - minLength: 1 - title: GetAgentProductRequest - additionalProperties: false - console.v1.GetAgentProductResponse: - type: object - properties: - agent: - title: agent - $ref: '#/components/schemas/agents.v1.Agent' - config: - title: config - $ref: '#/components/schemas/agents.v1.AgentConfig' - connections: - type: array - items: - $ref: '#/components/schemas/console.v1.AgentProductConnection' - title: connections - prompts: - type: array - items: - $ref: '#/components/schemas/console.v1.AgentProductPrompt' - title: prompts - title: GetAgentProductResponse - additionalProperties: false - console.v1.GetAssetRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - assetId: - type: string - title: asset_id - minLength: 1 - title: GetAssetRequest - additionalProperties: false - console.v1.GetAssetResponse: - type: object - properties: - asset: - title: asset - $ref: '#/components/schemas/console.v1.AiAsset' - relatedResources: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: related_resources - recentActivity: - type: array - items: - $ref: '#/components/schemas/console.v1.ActivityEvent' - title: recent_activity - findings: - type: array - items: - $ref: '#/components/schemas/console.v1.RiskFinding' - title: findings - title: GetAssetResponse - additionalProperties: false - console.v1.GetBillingSubscriptionRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - title: GetBillingSubscriptionRequest - additionalProperties: false - console.v1.GetBillingSubscriptionResponse: - type: object - properties: - planName: - type: string - title: plan_name - planTier: - type: string - title: plan_tier - seatsUsed: - type: integer - title: seats_used - format: int32 - seatsTotal: - type: integer - title: seats_total - format: int32 - renewalDate: - type: string - title: renewal_date - billingContact: - type: string - title: billing_contact - billingPortalUrl: - type: string - title: billing_portal_url - status: - type: string - title: status - statusEnum: - title: status_enum - $ref: '#/components/schemas/console.v1.WorkspaceSettingsBillingStatus' - billingPortalAvailable: - type: boolean - title: billing_portal_available - title: GetBillingSubscriptionResponse - additionalProperties: false - console.v1.GetBusinessObjectRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - objectId: - type: string - title: object_id - allowSourceRecovery: - type: boolean - title: allow_source_recovery - description: |- - Opt in to content-free recovery coordinates when a currently authorized - source owner reports a tombstone newer than the accepted object snapshot. - title: GetBusinessObjectRequest - additionalProperties: false - console.v1.GetBusinessObjectResponse: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/console.v1.BusinessObject' - sourceRecovery: - title: source_recovery - description: Mutually exclusive with object. Contains no field values or source payload. - $ref: '#/components/schemas/console.v1.BusinessObjectSourceRecovery' - title: GetBusinessObjectResponse - additionalProperties: false - console.v1.GetBusinessObjectTypeRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - typeId: - type: string - title: type_id - minLength: 1 - revision: - exclusiveMinimum: 0 - type: - - integer - - string - title: revision - format: int64 - title: GetBusinessObjectTypeRequest - additionalProperties: false - description: Exact immutable schema lookup. Revision must be positive; latest is listed separately. - console.v1.GetBusinessObjectTypeResponse: - type: object - properties: - definition: - title: definition - $ref: '#/components/schemas/console.v1.BusinessObjectType' - title: GetBusinessObjectTypeResponse - additionalProperties: false - console.v1.GetBusinessProcessDefinitionRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - definitionId: - type: string - title: definition_id - revision: - type: - - integer - - string - title: revision - format: int64 - title: GetBusinessProcessDefinitionRequest - additionalProperties: false - description: Exact immutable lookup; revision must be positive. - console.v1.GetBusinessProcessDefinitionResponse: - type: object - properties: - definition: - title: definition - $ref: '#/components/schemas/console.v1.BusinessProcessDefinition' - title: GetBusinessProcessDefinitionResponse - additionalProperties: false - console.v1.GetBusinessProcessRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - processId: - type: string - title: process_id - title: GetBusinessProcessRequest - additionalProperties: false - console.v1.GetBusinessProcessResponse: - type: object - properties: - process: - title: process - $ref: '#/components/schemas/console.v1.BusinessProcess' - definition: - title: definition - $ref: '#/components/schemas/console.v1.BusinessProcessDefinition' - title: GetBusinessProcessResponse - additionalProperties: false - console.v1.GetCaptureFormRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - formId: - type: string - title: form_id - minLength: 1 - versionId: - type: string - title: version_id - maxLength: 255 - title: GetCaptureFormRequest - additionalProperties: false - console.v1.GetCaptureFormResponse: - type: object - properties: - form: - title: form - $ref: '#/components/schemas/console.v1.CaptureForm' - version: - title: version - $ref: '#/components/schemas/console.v1.CaptureFormVersion' - title: GetCaptureFormResponse - required: - - form - - version - additionalProperties: false - console.v1.GetCaptureFormSubmissionRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - submissionId: - type: string - title: submission_id - minLength: 1 - title: GetCaptureFormSubmissionRequest - additionalProperties: false - console.v1.GetCaptureFormSubmissionResponse: - type: object - properties: - submission: - title: submission - $ref: '#/components/schemas/console.v1.CaptureFormSubmission' - title: GetCaptureFormSubmissionResponse - required: - - submission - additionalProperties: false - console.v1.GetComplianceAssessmentRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - recordId: - type: string - title: record_id - title: GetComplianceAssessmentRequest - additionalProperties: false - console.v1.GetComplianceAssessmentResponse: - type: object - properties: - record: - title: record - $ref: '#/components/schemas/console.v1.ComplianceAssessmentRecord' - title: GetComplianceAssessmentResponse - additionalProperties: false - console.v1.GetComputerMissionCanaryEvidenceRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - canaryRunId: - type: string - title: canary_run_id - minLength: 1 - title: GetComputerMissionCanaryEvidenceRequest - required: - - query - additionalProperties: false - console.v1.GetComputerMissionCanaryEvidenceResponse: - type: object - properties: - effects: - type: array - items: - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryEffect' - title: effects - evaluation: - title: evaluation - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryEvaluation' - operatorActions: - type: array - items: - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryOperatorAction' - title: operator_actions - definition: - title: definition - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryDefinition' - title: GetComputerMissionCanaryEvidenceResponse - additionalProperties: false - console.v1.GetComputerMissionCanaryRunRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - canaryRunId: - type: string - title: canary_run_id - minLength: 1 - title: GetComputerMissionCanaryRunRequest - required: - - query - additionalProperties: false - console.v1.GetComputerMissionCanaryRunResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryRun' - title: GetComputerMissionCanaryRunResponse - required: - - run - additionalProperties: false - console.v1.GetComputerMissionRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - missionId: - type: string - title: mission_id - minLength: 1 - title: GetComputerMissionRequest - required: - - query - additionalProperties: false - console.v1.GetComputerMissionResponse: - type: object - properties: - mission: - title: mission - $ref: '#/components/schemas/console.v1.ComputerMission' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.OperatingReceipt' - title: GetComputerMissionResponse - required: - - mission - - receipt - additionalProperties: false - console.v1.GetConsoleBootSnapshotRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - omitOperatingThread: - type: boolean - title: omit_operating_thread - description: |- - Skip the default operating transcript when the caller only needs shared - app-shell state. Chat routes leave this false to retain first-paint data. - title: GetConsoleBootSnapshotRequest - required: - - query - additionalProperties: false - console.v1.GetConsoleBootSnapshotResponse: - type: object - properties: - settings: - title: settings - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - billingSubscription: - title: billing_subscription - $ref: '#/components/schemas/console.v1.GetBillingSubscriptionResponse' - workforce: - title: workforce - $ref: '#/components/schemas/console.v1.ListAgentWorkforceRecordsResponse' - operatingChannels: - title: operating_channels - $ref: '#/components/schemas/console.v1.ListOperatingChannelsResponse' - operatingThread: - title: operating_thread - $ref: '#/components/schemas/console.v1.GetOperatingThreadResponse' - freshness: - title: freshness - $ref: '#/components/schemas/console.v1.ConsoleSnapshotFreshness' - title: GetConsoleBootSnapshotResponse - additionalProperties: false - console.v1.GetCustomerIntelligenceFactRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - factId: - type: string - title: fact_id - minLength: 1 - includeHistory: - type: boolean - title: include_history - title: GetCustomerIntelligenceFactRequest - required: - - query - additionalProperties: false - console.v1.GetCustomerIntelligenceFactResponse: - type: object - properties: - fact: - title: fact - $ref: '#/components/schemas/console.v1.CustomerIntelligenceFact' - title: GetCustomerIntelligenceFactResponse - required: - - fact - additionalProperties: false - console.v1.GetDexMcpServerRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - serverId: - type: string - title: server_id - minLength: 1 - title: GetDexMcpServerRequest - required: - - query - additionalProperties: false - console.v1.GetDexMcpServerResponse: - type: object - properties: - server: - title: server - $ref: '#/components/schemas/console.v1.DexMcpServer' - title: GetDexMcpServerResponse - required: - - server - additionalProperties: false - console.v1.GetInferenceCreditAutoRefillRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - title: GetInferenceCreditAutoRefillRequest - additionalProperties: false - console.v1.GetInferenceCreditAutoRefillResponse: - type: object - properties: - settings: - title: settings - $ref: '#/components/schemas/console.v1.InferenceCreditAutoRefill' - title: GetInferenceCreditAutoRefillResponse - additionalProperties: false - console.v1.GetInferenceCreditBalanceRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - runId: - type: string - title: run_id - maxLength: 256 - title: GetInferenceCreditBalanceRequest - additionalProperties: false - console.v1.GetInferenceCreditBalanceResponse: - type: object - properties: - balance: - title: balance - $ref: '#/components/schemas/console.v1.InferenceCreditBalance' - blocks: - type: array - items: - $ref: '#/components/schemas/console.v1.InferenceCreditBlock' - title: blocks - checkoutAvailable: - type: boolean - title: checkout_available - pricing: - title: pricing - $ref: '#/components/schemas/console.v1.InferenceCreditPricing' - reconciliation: - title: reconciliation - description: Absent means no reconciliation evidence is available. - $ref: '#/components/schemas/console.v1.InferenceCreditReconciliation' - runBalance: - title: run_balance - description: Absent means financial task attribution is unavailable. - $ref: '#/components/schemas/console.v1.InferenceRunCreditBalance' - title: GetInferenceCreditBalanceResponse - additionalProperties: false - console.v1.GetInvitedCaptureFormRequest: - type: object - properties: - invitationId: - type: string - title: invitation_id - minLength: 1 - title: GetInvitedCaptureFormRequest - additionalProperties: false - console.v1.GetInvitedCaptureFormResponse: - type: object - properties: - form: - title: form - $ref: '#/components/schemas/console.v1.PublishedCaptureForm' - receipt: - title: receipt - description: Returned only to the verified recipient after this invitation was used. - $ref: '#/components/schemas/console.v1.CaptureFormPublicSubmissionReceipt' - title: GetInvitedCaptureFormResponse - additionalProperties: false - console.v1.GetManagedInferenceReadinessRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - provider: - type: string - title: provider - description: Both omitted selects the deployment default. Supplying only one is invalid. - model: - type: string - title: model - environment: - type: string - title: environment - description: Omitted selects production; alternate environments must be explicit. - title: GetManagedInferenceReadinessRequest - additionalProperties: false - console.v1.GetManagedInferenceReadinessResponse: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - status: - title: status - $ref: '#/components/schemas/console.v1.ManagedInferenceReadinessStatus' - blockers: - type: array - items: - $ref: '#/components/schemas/console.v1.ManagedInferenceBlocker' - title: blockers - nextActions: - type: array - items: - $ref: '#/components/schemas/console.v1.ManagedInferenceNextAction' - title: next_actions - enrollmentState: - title: enrollment_state - $ref: '#/components/schemas/console.v1.ManagedProviderAccessState' - enrollmentRevision: - type: - - integer - - string - title: enrollment_revision - format: int64 - durableEnrollment: - type: boolean - title: durable_enrollment - funding: - title: funding - $ref: '#/components/schemas/console.v1.InferenceCreditBalance' - target: - title: target - description: Evaluated configured target, not client authority to route or execute. - $ref: '#/components/schemas/console.v1.InferenceProviderTarget' - evaluatedAt: - title: evaluated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - environment: - type: string - title: environment - budget: - title: budget - description: Existing Meter budget projection; never a separate policy owner. - $ref: '#/components/schemas/meter.v1.GetBudgetDashboardResponse' - title: GetManagedInferenceReadinessResponse - additionalProperties: false - console.v1.GetManagedSetupRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - description: |- - workspace_id selects the workspace document, falling back to the - organization document when the workspace has none. Leave empty to read the - organization document directly. - title: GetManagedSetupRequest - additionalProperties: false - description: GetManagedSetupRequest selects the tenant whose managed setup to return. - console.v1.GetMeetingCaptureRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - captureId: - type: string - title: capture_id - minLength: 1 - title: GetMeetingCaptureRequest - required: - - query - additionalProperties: false - console.v1.GetMeetingCaptureResponse: - type: object - properties: - capture: - title: capture - $ref: '#/components/schemas/console.v1.MeetingCapture' - title: GetMeetingCaptureResponse - additionalProperties: false - console.v1.GetOnboardingPlanRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - environment: - type: string - title: environment - title: GetOnboardingPlanRequest - additionalProperties: false - console.v1.GetOnboardingPlanResponse: - type: object - properties: - tasks: - type: array - items: - $ref: '#/components/schemas/console.v1.OnboardingTask' - title: tasks - title: GetOnboardingPlanResponse - additionalProperties: false - console.v1.GetOperatingFeedbackRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - minLength: 1 - messageId: - type: string - title: message_id - minLength: 1 - title: GetOperatingFeedbackRequest - required: - - query - additionalProperties: false - console.v1.GetOperatingFeedbackResponse: - type: object - properties: - feedback: - title: feedback - $ref: '#/components/schemas/console.v1.OperatingFeedback' - title: GetOperatingFeedbackResponse - additionalProperties: false - console.v1.GetOperatingHistoryContextRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - contextCursor: - type: string - title: context_cursor - maxLength: 4096 - minLength: 1 - beforeCount: - type: integer - title: before_count - maximum: 20 - format: int32 - afterCount: - type: integer - title: after_count - maximum: 20 - format: int32 - title: GetOperatingHistoryContextRequest - required: - - query - additionalProperties: false - console.v1.GetOperatingHistoryContextResponse: - type: object - properties: - channelId: - type: string - title: channel_id - channelTitle: - type: string - title: channel_title - records: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingHistoryContextRecord' - title: records - title: GetOperatingHistoryContextResponse - additionalProperties: false - console.v1.GetOperatingProjectSnapshotRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - projectResourceId: - type: string - title: project_resource_id - maxLength: 255 - minLength: 1 - importExecutionId: - type: string - title: import_execution_id - nullable: true - title: GetOperatingProjectSnapshotRequest - required: - - query - additionalProperties: false - console.v1.GetOperatingReceiptRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - receiptId: - type: string - title: receipt_id - minLength: 1 - channelId: - type: string - title: channel_id - includeCodingOutputContent: - type: boolean - title: include_coding_output_content - title: GetOperatingReceiptRequest - required: - - query - additionalProperties: false - console.v1.GetOperatingReceiptResponse: - type: object - properties: - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.OperatingReceipt' - title: GetOperatingReceiptResponse - additionalProperties: false - console.v1.GetOperatingTaskEnvironmentRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - maxLength: 255 - minLength: 1 - taskId: - type: string - title: task_id - maxLength: 255 - minLength: 1 - title: GetOperatingTaskEnvironmentRequest - required: - - query - additionalProperties: false - console.v1.GetOperatingTaskEnvironmentResponse: - type: object - properties: - available: - type: boolean - title: available - hasEnvironment: - type: boolean - title: has_environment - state: - type: string - title: state - retentionDays: - type: integer - title: retention_days - format: int32 - lastActivityAt: - title: last_activity_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - expiresAt: - title: expires_at - description: Computed from current effective policy and the storage owner's activity. - $ref: '#/components/schemas/google.protobuf.Timestamp' - projectResourceId: - type: string - title: project_resource_id - cleanupAccepted: - type: boolean - title: cleanup_accepted - description: A cleanup decision was already accepted before a later policy change. - retentionHours: - type: integer - title: retention_hours - format: int32 - stages: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingTaskEnvironmentStage' - title: stages - workspaceRecipe: - title: workspace_recipe - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionWorkspaceRecipe' - title: GetOperatingTaskEnvironmentResponse - additionalProperties: false - console.v1.GetOperatingThreadRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - limit: - type: integer - title: limit - maximum: 200 - format: int32 - pageToken: - type: string - title: page_token - maxLength: 2048 - title: GetOperatingThreadRequest - required: - - query - additionalProperties: false - console.v1.GetOperatingThreadResponse: - type: object - properties: - channel: - title: channel - $ref: '#/components/schemas/console.v1.OperatingChannel' - messages: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingMessage' - title: messages - receipts: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingReceipt' - title: receipts - capabilities: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingCapabilityState' - title: capabilities - threadExecution: - title: thread_execution - $ref: '#/components/schemas/console.v1.OperatingThreadExecution' - turns: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingThreadTurn' - title: turns - replayCursor: - type: - - integer - - string - title: replay_cursor - format: int64 - nextPageToken: - type: string - title: next_page_token - maxLength: 2048 - modelSelection: - title: model_selection - $ref: '#/components/schemas/console.v1.OperatingModelSelection' - availableModels: - type: array - items: - $ref: '#/components/schemas/console.v1.InferenceProviderTarget' - title: available_models - defaultModel: - title: default_model - $ref: '#/components/schemas/console.v1.InferenceProviderTarget' - title: GetOperatingThreadResponse - additionalProperties: false - console.v1.GetOperatorPreferencesRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: GetOperatorPreferencesRequest - required: - - query - additionalProperties: false - console.v1.GetOperatorPreferencesResponse: - type: object - properties: - preferences: - title: preferences - $ref: '#/components/schemas/console.v1.OperatorPreferences' - title: GetOperatorPreferencesResponse - required: - - preferences - additionalProperties: false - console.v1.GetOrbControlTargetRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - targetId: - type: string - title: target_id - minLength: 1 - title: GetOrbControlTargetRequest - required: - - query - additionalProperties: false - description: GetOrbControlTargetRequest selects one tenant-scoped target projection. - console.v1.GetOrbControlTargetResponse: - type: object - properties: - target: - title: target - $ref: '#/components/schemas/console.v1.OrbControlTarget' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.OperatingReceipt' - title: GetOrbControlTargetResponse - additionalProperties: false - description: GetOrbControlTargetResponse returns one target projection and latest receipt. - console.v1.GetOverviewRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: GetOverviewRequest - required: - - query - additionalProperties: false - console.v1.GetOverviewResponse: - type: object - properties: - generatedAt: - title: generated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - metrics: - type: array - items: - $ref: '#/components/schemas/console.v1.ConsoleMetric' - title: metrics - topAssets: - type: array - items: - $ref: '#/components/schemas/console.v1.AiAsset' - title: top_assets - topFindings: - type: array - items: - $ref: '#/components/schemas/console.v1.RiskFinding' - title: top_findings - recentActivity: - type: array - items: - $ref: '#/components/schemas/console.v1.ActivityEvent' - title: recent_activity - integrationTiles: - type: array - items: - $ref: '#/components/schemas/console.v1.IntegrationTile' - title: integration_tiles - onboardingTasks: - type: array - items: - $ref: '#/components/schemas/console.v1.OnboardingTask' - title: onboarding_tasks - warnings: - type: array - items: - type: string - title: warnings - totalFindings: - type: integer - title: total_findings - format: int32 - title: GetOverviewResponse - additionalProperties: false - console.v1.GetPrivacySettingsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: GetPrivacySettingsRequest - required: - - query - additionalProperties: false - console.v1.GetPrivacySettingsResponse: - type: object - properties: - effectiveMode: - title: effective_mode - description: |- - Mode platform-api actually seals into OperationContext for the queried - workspace: the workspace override when one exists, otherwise the - organization row, otherwise TENANT_PRIVACY_MODE_STANDARD. - $ref: '#/components/schemas/console.v1.TenantPrivacyMode' - organization: - title: organization - description: Present only when an organization-wide row exists. - $ref: '#/components/schemas/console.v1.TenantPrivacySetting' - workspace: - title: workspace - description: Present only when an override row exists for the queried workspace. - $ref: '#/components/schemas/console.v1.TenantPrivacySetting' - title: GetPrivacySettingsResponse - additionalProperties: false - console.v1.GetProductIssueRecoveryRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - recoveryId: - type: string - title: recovery_id - maxLength: 4000 - title: GetProductIssueRecoveryRequest - additionalProperties: false - description: Durable, explicitly scoped customer recovery contract. - console.v1.GetProspectingWatchProgramRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - watchProgramId: - type: string - title: watch_program_id - minLength: 1 - title: GetProspectingWatchProgramRequest - required: - - query - additionalProperties: false - console.v1.GetProspectingWatchProgramResponse: - type: object - properties: - program: - title: program - $ref: '#/components/schemas/console.v1.ProspectingWatchProgram' - title: GetProspectingWatchProgramResponse - required: - - program - additionalProperties: false - console.v1.GetPublishedCaptureFormBrandingAssetRequest: - type: object - properties: - publicationId: - type: string - title: publication_id - minLength: 1 - description: |- - This opaque id is the only public capability input. The role is a fixed - presentation selector, never an object or version reference. - role: - not: - enum: - - 0 - title: role - $ref: '#/components/schemas/console.v1.CaptureFormBrandingAssetRole' - title: GetPublishedCaptureFormBrandingAssetRequest - additionalProperties: false - console.v1.GetPublishedCaptureFormBrandingAssetResponse: - type: object - properties: - content: - type: string - title: content - maxLength: 699052 - x-protobuf-bytes-max-length: 524288 - format: byte - contentType: - type: string - title: content_type - maxLength: 64 - minLength: 1 - digest: - type: string - title: digest - pattern: ^[0-9a-f]{64}$ - sizeBytes: - type: - - integer - - string - title: size_bytes - maximum: 524288 - format: int64 - title: GetPublishedCaptureFormBrandingAssetResponse - additionalProperties: false - console.v1.GetPublishedCaptureFormRequest: - type: object - properties: - publicationId: - type: string - title: publication_id - minLength: 1 - description: |- - This opaque id is the only public capability input. The service resolves - tenant, form, version, and publication state from its server-side record. - title: GetPublishedCaptureFormRequest - additionalProperties: false - console.v1.GetPublishedCaptureFormResponse: - type: object - properties: - form: - title: form - $ref: '#/components/schemas/console.v1.PublishedCaptureForm' - title: GetPublishedCaptureFormResponse - required: - - form - additionalProperties: false - console.v1.GetStaffInferenceRoutingProfileRequest: - type: object - title: GetStaffInferenceRoutingProfileRequest - additionalProperties: false - console.v1.GetStaffInferenceRoutingProfileResponse: - type: object - properties: - organizationId: - type: string - title: organization_id - availableTargets: - type: array - items: - $ref: '#/components/schemas/console.v1.InferenceProviderTarget' - title: available_targets - defaultTarget: - title: default_target - $ref: '#/components/schemas/console.v1.InferenceProviderTarget' - effectiveTarget: - title: effective_target - $ref: '#/components/schemas/console.v1.InferenceProviderTarget' - profile: - title: profile - description: Absent until staff persists an explicit override. - $ref: '#/components/schemas/console.v1.StaffInferenceRoutingProfile' - recentEvents: - type: array - items: - $ref: '#/components/schemas/console.v1.StaffInferenceRoutingEvent' - title: recent_events - effectiveRoutes: - type: array - items: - $ref: '#/components/schemas/console.v1.StaffInferencePurposeRoute' - title: effective_routes - title: GetStaffInferenceRoutingProfileResponse - additionalProperties: false - console.v1.GetStaffManagedInferenceBudgetRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - request: - title: request - $ref: '#/components/schemas/meter.v1.GetBudgetDashboardRequest' - title: GetStaffManagedInferenceBudgetRequest - additionalProperties: false - console.v1.GetStaffManagedInferenceFundingRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - request: - title: request - $ref: '#/components/schemas/meter.v1.GetPrepaidCreditBalanceRequest' - title: GetStaffManagedInferenceFundingRequest - additionalProperties: false - console.v1.GetStaffManagedInferenceReadinessRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - provider: - type: string - title: provider - description: Both omitted selects the deployment default. Supplying only one is invalid. - model: - type: string - title: model - environment: - type: string - title: environment - description: Omitted selects production; alternate environments must be explicit. - title: GetStaffManagedInferenceReadinessRequest - additionalProperties: false - console.v1.GetStaffManagedInferenceUsageRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - request: - title: request - $ref: '#/components/schemas/meter.v1.QueryUsageRequest' - title: GetStaffManagedInferenceUsageRequest - additionalProperties: false - console.v1.GetStaffWorkspaceContextRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - title: GetStaffWorkspaceContextRequest - additionalProperties: false - console.v1.GetStaffWorkspaceContextResponse: - type: object - properties: - context: - title: context - $ref: '#/components/schemas/console.v1.StaffWorkspaceContext' - title: GetStaffWorkspaceContextResponse - additionalProperties: false - console.v1.GetTraceDrilldownRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - traceId: - type: string - title: trace_id - minLength: 1 - title: GetTraceDrilldownRequest - additionalProperties: false - console.v1.GetTraceDrilldownResponse: - type: object - properties: - trace: - title: trace - $ref: '#/components/schemas/console.v1.TraceDrilldown' - title: GetTraceDrilldownResponse - additionalProperties: false - console.v1.GetWorkspaceKeyConfigRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - title: GetWorkspaceKeyConfigRequest - additionalProperties: false - console.v1.GetWorkspaceSettingsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: GetWorkspaceSettingsRequest - required: - - query - additionalProperties: false - console.v1.GetWorkspaceSettingsResponse: - type: object - properties: - workspace: - title: workspace - $ref: '#/components/schemas/console.v1.WorkspaceSettingsProfile' - currentPrincipal: - title: current_principal - $ref: '#/components/schemas/console.v1.WorkspaceSettingsPrincipal' - members: - type: array - items: - $ref: '#/components/schemas/console.v1.WorkspaceSettingsMember' - title: members - billing: - title: billing - $ref: '#/components/schemas/console.v1.WorkspaceSettingsBilling' - policy: - title: policy - $ref: '#/components/schemas/console.v1.WorkspaceSettingsPolicy' - notifications: - title: notifications - $ref: '#/components/schemas/console.v1.WorkspaceSettingsNotifications' - identityProviders: - type: array - items: - $ref: '#/components/schemas/console.v1.WorkspaceSettingsIdentityProvider' - title: identity_providers - integrations: - type: array - items: - $ref: '#/components/schemas/console.v1.WorkspaceSettingsIntegration' - title: integrations - capabilities: - type: array - items: - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - title: capabilities - warnings: - type: array - items: - type: string - title: warnings - activity: - type: array - items: - $ref: '#/components/schemas/console.v1.WorkspaceSettingsActivityEntry' - title: activity - ownerServices: - type: array - items: - $ref: '#/components/schemas/console.v1.WorkspaceSettingsOwnerStatus' - title: owner_services - breakGlassGrant: - title: break_glass_grant - $ref: '#/components/schemas/console.v1.WorkspaceSettingsBreakGlassGrant' - workspaces: - type: array - items: - $ref: '#/components/schemas/console.v1.WorkspaceSettingsWorkspace' - title: workspaces - dexPolicy: - title: dex_policy - $ref: '#/components/schemas/console.v1.WorkspaceDexPolicy' - artifactStyleGuide: - title: artifact_style_guide - $ref: '#/components/schemas/console.v1.WorkspaceArtifactStyleGuide' - taskEnvironmentProjects: - type: array - items: - $ref: '#/components/schemas/console.v1.TaskEnvironmentProjectOption' - title: task_environment_projects - description: Response-only project choices resolved from this tenant's repository resources. - title: GetWorkspaceSettingsResponse - additionalProperties: false - console.v1.GrantStaffManagedInferenceCreditsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - request: - title: request - $ref: '#/components/schemas/meter.v1.GrantDevelopmentCreditsRequest' - title: GrantStaffManagedInferenceCreditsRequest - additionalProperties: false - console.v1.GuideComputerMissionRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - missionId: - type: string - title: mission_id - minLength: 1 - expectedGeneration: - type: - - integer - - string - title: expected_generation - format: int64 - guidance: - type: string - title: guidance - minLength: 1 - condition: - title: condition - $ref: '#/components/schemas/google.protobuf.Struct' - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - wakeAt: - title: wake_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: GuideComputerMissionRequest - required: - - query - additionalProperties: false - console.v1.GuideComputerMissionResponse: - type: object - properties: - mission: - title: mission - $ref: '#/components/schemas/console.v1.ComputerMission' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.OperatingReceipt' - wakeId: - type: string - title: wake_id - minLength: 1 - title: GuideComputerMissionResponse - required: - - mission - - receipt - additionalProperties: false - console.v1.IdentityToolAuthorizationEvidence: - type: object - properties: - schemaVersion: - type: string - title: schema_version - minLength: 1 - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - applicationId: - type: string - title: application_id - minLength: 1 - subjectId: - type: string - title: subject_id - minLength: 1 - actorChainDigest: - type: string - title: actor_chain_digest - minLength: 1 - decisionId: - type: string - title: decision_id - minLength: 1 - authorizationLineageId: - type: string - title: authorization_lineage_id - minLength: 1 - policyId: - type: string - title: policy_id - minLength: 1 - policyVersion: - type: string - title: policy_version - minLength: 1 - policyDigest: - type: string - title: policy_digest - minLength: 1 - authorizationFingerprint: - type: string - title: authorization_fingerprint - minLength: 1 - capabilityDigest: - type: string - title: capability_digest - minLength: 1 - actionDigest: - type: string - title: action_digest - minLength: 1 - audience: - type: string - title: audience - minLength: 1 - issuedAtMs: - exclusiveMinimum: 0 - type: - - integer - - string - title: issued_at_ms - format: int64 - expiresAtMs: - exclusiveMinimum: 0 - type: - - integer - - string - title: expires_at_ms - format: int64 - title: IdentityToolAuthorizationEvidence - additionalProperties: false - console.v1.ImportOperatingProjectSnapshotRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - projectResourceId: - type: string - title: project_resource_id - maxLength: 255 - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 255 - minLength: 1 - expectedRefVersion: - type: - - integer - - string - title: expected_ref_version - format: int64 - nullable: true - title: ImportOperatingProjectSnapshotRequest - required: - - query - additionalProperties: false - description: Caller chooses the project and observed acceptance version, never a Git SHA. - console.v1.InferenceCreditAutoRefill: - type: object - properties: - enabled: - type: boolean - title: enabled - thresholdCents: - type: - - integer - - string - title: threshold_cents - format: int64 - creditCents: - type: - - integer - - string - title: credit_cents - format: int64 - monthlyCapCents: - type: - - integer - - string - title: monthly_cap_cents - format: int64 - committedCents: - type: - - integer - - string - title: committed_cents - format: int64 - description: Successful automatic charges this UTC month plus all unresolved charges. - pauseReason: - type: string - title: pause_reason - generation: - type: string - title: generation - title: InferenceCreditAutoRefill - additionalProperties: false - console.v1.InferenceCreditBalance: - type: object - properties: - compensatedMicros: - type: - - integer - - string - title: compensated_micros - format: int64 - description: Original cash charges restored through verified customer recovery. - grantedMicros: - type: - - integer - - string - title: granted_micros - format: int64 - description: Non-cash development funding remains separate from purchased credits. - expiredGrantMicros: - type: - - integer - - string - title: expired_grant_micros - format: int64 - grantSpentMicros: - type: - - integer - - string - title: grant_spent_micros - format: int64 - grantReservedMicros: - type: - - integer - - string - title: grant_reserved_micros - format: int64 - developmentCreditOnly: - type: boolean - title: development_credit_only - description: Enrolled development programs cannot consume paid credits or trigger paid refill. - admissionSuspended: - type: boolean - title: admission_suspended - reversedMicros: - type: - - integer - - string - title: reversed_micros - format: int64 - debtMicros: - type: - - integer - - string - title: debt_micros - format: int64 - purchasedMicros: - type: - - integer - - string - title: purchased_micros - format: int64 - spentMicros: - type: - - integer - - string - title: spent_micros - format: int64 - reservedMicros: - type: - - integer - - string - title: reserved_micros - format: int64 - availableMicros: - type: - - integer - - string - title: available_micros - format: int64 - title: InferenceCreditBalance - additionalProperties: false - description: Model credits are separate from subscriptions; automatic refill requires explicit consent. - console.v1.InferenceCreditBlock: - type: object - properties: - creditCents: - type: - - integer - - string - title: credit_cents - format: int64 - feeCents: - type: - - integer - - string - title: fee_cents - format: int64 - totalCents: - type: - - integer - - string - title: total_cents - format: int64 - quoteVersion: - type: string - title: quote_version - title: InferenceCreditBlock - additionalProperties: false - console.v1.InferenceCreditPricing: - type: object - properties: - provider: - type: string - title: provider - model: - type: string - title: model - pricingVersion: - type: string - title: pricing_version - inputMicrosPerMillionTokens: - type: - - integer - - string - title: input_micros_per_million_tokens - format: int64 - cachedInputMicrosPerMillionTokens: - type: - - integer - - string - title: cached_input_micros_per_million_tokens - format: int64 - outputMicrosPerMillionTokens: - type: - - integer - - string - title: output_micros_per_million_tokens - format: int64 - displayName: - type: string - title: display_name - description: Customer-facing model name, for example "GLM-5.3"; `model` is the provider id. - title: InferenceCreditPricing - additionalProperties: false - description: |- - Published per-token price of the managed default model that prepaid credits - pay for. Amounts are USD micros (1 USD = 1_000_000) per one million tokens, - so $1.40 per million tokens is 1400000. The console uses this to show what a - balance buys; it is the same contract the LLM gateway enforces at admission. - console.v1.InferenceCreditReceipt: - type: object - properties: - paymentId: - type: string - title: payment_id - paidAtUnix: - type: - - integer - - string - title: paid_at_unix - format: int64 - creditCents: - type: - - integer - - string - title: credit_cents - format: int64 - feeCents: - type: - - integer - - string - title: fee_cents - format: int64 - paidCents: - type: - - integer - - string - title: paid_cents - format: int64 - refundedCents: - type: - - integer - - string - title: refunded_cents - format: int64 - receiptUrl: - type: string - title: receipt_url - automaticRefill: - type: boolean - title: automatic_refill - title: InferenceCreditReceipt - additionalProperties: false - description: A confirmed payment receipt; amounts include only that payment, not a balance. - console.v1.InferenceCreditReconciliation: - type: object - properties: - compensatedDifferenceMicros: - type: - - integer - - string - title: compensated_difference_micros - format: int64 - balanced: - type: boolean - title: balanced - description: A comparison of materialized counters with source rows in one snapshot. - purchasedDifferenceMicros: - type: - - integer - - string - title: purchased_difference_micros - format: int64 - reversedDifferenceMicros: - type: - - integer - - string - title: reversed_difference_micros - format: int64 - spentDifferenceMicros: - type: - - integer - - string - title: spent_difference_micros - format: int64 - reservedDifferenceMicros: - type: - - integer - - string - title: reserved_difference_micros - format: int64 - disputeCountDifference: - type: - - integer - - string - title: dispute_count_difference - format: int64 - pendingReservationCount: - type: - - integer - - string - title: pending_reservation_count - format: int64 - oldestPendingAt: - title: oldest_pending_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - unfundedPaymentCount: - type: - - integer - - string - title: unfunded_payment_count - format: int64 - title: InferenceCreditReconciliation - additionalProperties: false - console.v1.InferenceProviderTarget: - type: object - properties: - provider: - type: string - title: provider - model: - type: string - title: model - displayName: - type: string - title: display_name - capabilities: - type: array - items: - type: string - title: capabilities - contextWindowTokens: - type: - - integer - - string - title: context_window_tokens - format: int64 - pricingTier: - type: string - title: pricing_tier - latencyTier: - type: string - title: latency_tier - regions: - type: array - items: - type: string - title: regions - ready: - type: boolean - title: ready - unavailableReason: - type: string - title: unavailable_reason - title: InferenceProviderTarget - additionalProperties: false - description: |- - InferenceProviderTarget is one deployment-approved provider/model pair. - Provider identity is canonicalized through model-provider-core. - console.v1.InferenceRunCreditBalance: - type: object - properties: - runId: - type: string - title: run_id - settledCostMicros: - type: - - integer - - string - title: settled_cost_micros - format: int64 - reservedMicros: - type: - - integer - - string - title: reserved_micros - format: int64 - pendingRequestCount: - type: - - integer - - string - title: pending_request_count - format: int64 - settledRequestCount: - type: - - integer - - string - title: settled_request_count - format: int64 - oldestPendingAt: - title: oldest_pending_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: InferenceRunCreditBalance - additionalProperties: false - console.v1.InitiateDexMcpOAuthProfileRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - serverId: - type: string - title: server_id - minLength: 1 - profileId: - type: string - title: profile_id - profileName: - type: string - title: profile_name - minLength: 1 - subjectKind: - type: string - title: subject_kind - minLength: 1 - subjectId: - type: string - title: subject_id - resourceUrl: - type: string - title: resource_url - minLength: 1 - scopes: - type: array - items: - type: string - title: scopes - redirectUri: - type: string - title: redirect_uri - minLength: 1 - clientId: - type: string - title: client_id - clientSecretRef: - type: string - title: client_secret_ref - isDefault: - type: boolean - title: is_default - idempotencyKey: - type: string - title: idempotency_key - title: InitiateDexMcpOAuthProfileRequest - required: - - query - additionalProperties: false - console.v1.InitiateDexMcpOAuthProfileResponse: - type: object - properties: - profile: - title: profile - $ref: '#/components/schemas/console.v1.DexMcpOAuthProfile' - authorizeUrl: - type: string - title: authorize_url - state: - type: string - title: state - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - resourceMetadataUrl: - type: string - title: resource_metadata_url - authorizationServer: - type: string - title: authorization_server - clientId: - type: string - title: client_id - title: InitiateDexMcpOAuthProfileResponse - required: - - profile - additionalProperties: false - console.v1.InstallDexSkillCatalogEntryRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - catalogId: - type: string - title: catalog_id - minLength: 1 - acceptAnalysisFindings: - type: boolean - title: accept_analysis_findings - description: |- - Required when the current typed analysis verdict is NEEDS_REVIEW. The - acknowledgement is accepted only when fields 4-6 exactly match the - current catalog payload and analysis evidence. - reviewedCatalogVersion: - type: integer - title: reviewed_catalog_version - format: int32 - reviewedAnalysisContentDigest: - type: string - title: reviewed_analysis_content_digest - reviewedAnalysisRulesetVersion: - type: string - title: reviewed_analysis_ruleset_version - reviewedSourceRevision: - type: string - title: reviewed_source_revision - reviewedPackageDigest: - type: string - title: reviewed_package_digest - title: InstallDexSkillCatalogEntryRequest - required: - - query - additionalProperties: false - console.v1.InstallDexSkillCatalogEntryResponse: - type: object - properties: - skill: - title: skill - $ref: '#/components/schemas/console.v1.OperatingSkill' - catalogSkillId: - type: string - title: catalog_skill_id - catalogVersion: - type: integer - title: catalog_version - format: int32 - reinstalled: - type: boolean - title: reinstalled - title: InstallDexSkillCatalogEntryResponse - required: - - skill - additionalProperties: false - console.v1.IntegrationCredentialField: - type: object - properties: - name: - type: string - title: name - label: - type: string - title: label - required: - type: boolean - title: required - secret: - type: boolean - title: secret - acceptedReferenceSchemes: - type: array - items: - type: string - title: accepted_reference_schemes - credentialType: - type: string - title: credential_type - title: IntegrationCredentialField - additionalProperties: false - description: |- - IntegrationCredentialField describes the credential reference slots Console - can ask a workspace admin to provide for an integration. Values submitted for - these fields must be secret references, not raw credential material. - console.v1.IntegrationResourceType: - type: object - properties: - id: - type: string - title: id - displayName: - type: string - title: display_name - sourceCoverageTypes: - type: array - items: - type: string - title: source_coverage_types - sourceProjectionTemplate: - type: string - title: source_projection_template - eventKind: - type: string - title: event_kind - title: IntegrationResourceType - additionalProperties: false - description: |- - IntegrationResourceType is safe catalog discovery metadata for one provider - resource family. source_* fields preserve the imported source taxonomy and - projection intent; they do not claim a canonical or implemented Mono mapping. - console.v1.IntegrationTile: - type: object - properties: - id: - type: string - title: id - name: - type: string - title: name - provider: - type: string - title: provider - category: - type: string - title: category - status: - type: string - title: status - detail: - type: string - title: detail - setupCommand: - type: string - title: setup_command - scopes: - type: array - items: - type: string - title: scopes - capabilities: - type: array - items: - type: string - title: capabilities - lastSeenAt: - title: last_seen_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - catalogCategories: - type: array - items: - type: string - title: catalog_categories - runtimeExecutable: - type: boolean - title: runtime_executable - resourceFamilies: - type: array - items: - type: string - title: resource_families - verificationEndpoint: - type: string - title: verification_endpoint - lifecycleStage: - type: string - title: lifecycle_stage - description: |- - lifecycle_stage is the durable source lifecycle projection rendered by the - Sources UI: needs_setup, authorizing, syncing, connected, degraded, - reconnect_required, needs_operator_config, disabled, etc. - requiredScopes: - type: array - items: - type: string - title: required_scopes - optionalScopes: - type: array - items: - type: string - title: optional_scopes - missingScopes: - type: array - items: - type: string - title: missing_scopes - syncStatus: - type: string - title: sync_status - lastSyncAt: - title: last_sync_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - nextSyncAt: - title: next_sync_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - lastSyncDurationMs: - type: integer - title: last_sync_duration_ms - format: int32 - syncedItemCount: - type: integer - title: synced_item_count - format: int32 - syncError: - type: string - title: sync_error - installAuthority: - type: string - title: install_authority - operatorConfigStatus: - type: string - title: operator_config_status - authType: - type: string - title: auth_type - oauthSupported: - type: boolean - title: oauth_supported - credentialFields: - type: array - items: - $ref: '#/components/schemas/console.v1.IntegrationCredentialField' - title: credential_fields - catalogProvenance: - title: catalog_provenance - $ref: '#/components/schemas/connectors.v1.ConnectorCatalogProvenance' - catalogTier: - type: string - title: catalog_tier - description: |- - catalog_tier is the connector catalog owner's shape-derived tier. Console - carries it verbatim and never promotes a provider's readiness. - providerActions: - type: array - items: - type: string - title: provider_actions - description: |- - provider_actions names the typed runtime actions exposed by the published - provider. Together with resource_families this distinguishes sync, - action-only, and combined providers without inferring support from labels. - catalogStatus: - type: string - title: catalog_status - description: |- - catalog_status is either ready (published and connectable) or - qualification_pending (installed preview, not connectable). - setupAllowed: - type: boolean - title: setup_allowed - configured: - type: boolean - title: configured - providerActionCount: - type: integer - title: provider_action_count - format: int32 - resourceFamilyCount: - type: integer - title: resource_family_count - format: int32 - requiredFamilyCount: - type: integer - title: required_family_count - format: int32 - qualifiedFamilyCount: - type: integer - title: qualified_family_count - format: int32 - rolloutKind: - type: string - title: rollout_kind - resourceTypes: - type: array - items: - $ref: '#/components/schemas/console.v1.IntegrationResourceType' - title: resource_types - providerDescription: - type: string - title: provider_description - title: IntegrationTile - additionalProperties: false - console.v1.InterruptOperatingThreadRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - minLength: 1 - turnId: - type: string - title: turn_id - description: When empty, the owner interrupts the lowest-sequence non-terminal turn. - idempotencyKey: - type: string - title: idempotency_key - maxLength: 512 - minLength: 1 - reason: - type: string - title: reason - maxLength: 512 - description: Optional product-safe reason shown only as audit metadata, never as model prompt. - title: InterruptOperatingThreadRequest - required: - - query - additionalProperties: false - console.v1.InterruptOperatingThreadResponse: - type: object - properties: - turnId: - type: string - title: turn_id - replayed: - type: boolean - title: replayed - threadExecution: - title: thread_execution - $ref: '#/components/schemas/console.v1.OperatingThreadExecution' - turns: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingThreadTurn' - title: turns - replayCursor: - type: - - integer - - string - title: replay_cursor - format: int64 - cancelledWorkIds: - type: array - items: - type: string - maxItems: 32 - title: cancelled_work_ids - maxItems: 32 - description: Runtime work cancelled for the interrupted turn's submitted message, if any. - title: InterruptOperatingThreadResponse - additionalProperties: false - console.v1.ListActivityRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListActivityRequest - required: - - query - additionalProperties: false - console.v1.ListActivityResponse: - type: object - properties: - events: - type: array - items: - $ref: '#/components/schemas/console.v1.ActivityEvent' - title: events - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - denialsUnavailableReason: - type: string - title: denials_unavailable_reason - description: |- - Empty when spend budget denials owned by meter were merged into `events`. - Non-empty names why they were not, so a caller can say this page is missing - denials rather than render a page that looks complete. Platform never - substitutes an empty denial set for an unread one. - title: ListActivityResponse - additionalProperties: false - console.v1.ListAgentWorkforceRecordsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - runtime: - type: string - title: runtime - queueState: - type: string - title: queue_state - includeDebug: - type: boolean - title: include_debug - sourceEventId: - type: string - title: source_event_id - maxLength: 120 - description: |- - source_event_id is an exact source-intake selector owned by the backend. - It is separate from ConsoleQuery.search so an intake lookup cannot be - widened into a generic Fleet search. - title: ListAgentWorkforceRecordsRequest - required: - - query - additionalProperties: false - console.v1.ListAgentWorkforceRecordsResponse: - type: object - properties: - records: - type: array - items: - $ref: '#/components/schemas/console.v1.AgentWorkforceRecord' - title: records - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - warnings: - type: array - items: - type: string - title: warnings - approvalQueueSummary: - title: approval_queue_summary - $ref: '#/components/schemas/console.v1.AgentWorkforceApprovalQueueSummary' - sourceReadiness: - type: array - items: - $ref: '#/components/schemas/console.v1.AgentWorkforceSourceReadiness' - title: source_readiness - description: |- - source_readiness includes configured-only Agent Workforce source paths for - rendering even when no approval-queue record exists for that source. These - rows are display readiness only and do not prove identity, credential - grants, model/cost spend, or approval readiness. - sourceEventId: - type: string - title: source_event_id - description: |- - Echoes the exact source-event selector when the response was filtered by - source_event_id. Clients may use this typed contract for backend-owned - singleton matching; an empty value means no source-event selector was - applied. - title: ListAgentWorkforceRecordsResponse - additionalProperties: false - console.v1.ListAssetsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListAssetsRequest - required: - - query - additionalProperties: false - console.v1.ListAssetsResponse: - type: object - properties: - assets: - type: array - items: - $ref: '#/components/schemas/console.v1.AiAsset' - title: assets - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - title: ListAssetsResponse - additionalProperties: false - console.v1.ListAuthorityPostureRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListAuthorityPostureRequest - required: - - query - additionalProperties: false - console.v1.ListAuthorityPostureResponse: - type: object - properties: - rows: - type: array - items: - $ref: '#/components/schemas/console.v1.AuthorityLedger' - title: rows - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - warnings: - type: array - items: - type: string - title: warnings - title: ListAuthorityPostureResponse - additionalProperties: false - console.v1.ListBusinessBlueprintsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - title: ListBusinessBlueprintsRequest - additionalProperties: false - console.v1.ListBusinessBlueprintsResponse: - type: object - properties: - blueprints: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessBlueprint' - title: blueprints - title: ListBusinessBlueprintsResponse - additionalProperties: false - console.v1.ListBusinessObjectRelationshipsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - objectId: - type: string - title: object_id - limit: - type: integer - title: limit - format: int32 - afterKey: - type: string - title: after_key - description: Tuple cursor of relationship ID and peer object ID, separated by U+001F. - direction: - title: direction - description: Unspecified preserves outgoing behavior. Incoming peers are source objects. - $ref: '#/components/schemas/console.v1.BusinessObjectRelationshipDirection' - title: ListBusinessObjectRelationshipsRequest - additionalProperties: false - console.v1.ListBusinessObjectRelationshipsResponse: - type: object - properties: - relationships: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessObjectRelationship' - title: relationships - nextKey: - type: string - title: next_key - title: ListBusinessObjectRelationshipsResponse - additionalProperties: false - console.v1.ListBusinessObjectRevisionsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - objectId: - type: string - title: object_id - limit: - type: integer - title: limit - format: int32 - beforeRevision: - type: - - integer - - string - title: before_revision - format: int64 - title: ListBusinessObjectRevisionsRequest - additionalProperties: false - console.v1.ListBusinessObjectRevisionsResponse: - type: object - properties: - revisions: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessObjectRevision' - title: revisions - nextBeforeRevision: - type: - - integer - - string - title: next_before_revision - format: int64 - title: ListBusinessObjectRevisionsResponse - additionalProperties: false - console.v1.ListBusinessObjectTypesRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - limit: - type: integer - title: limit - format: int32 - afterTypeId: - type: string - title: after_type_id - title: ListBusinessObjectTypesRequest - additionalProperties: false - console.v1.ListBusinessObjectTypesResponse: - type: object - properties: - definitions: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessObjectType' - title: definitions - nextTypeId: - type: string - title: next_type_id - title: ListBusinessObjectTypesResponse - additionalProperties: false - console.v1.ListBusinessObjectsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - typeId: - type: string - title: type_id - limit: - type: integer - title: limit - format: int32 - afterObjectId: - type: string - title: after_object_id - filter: - title: filter - description: |- - Optional exact indexed lookup; omit for ordinary record listing. - (-- api-linter: core::0132::request-field-types=disabled - aip.dev/not-precedent: Typed indexed predicates intentionally replace - an unstructured filter expression for this Connect API. --) - $ref: '#/components/schemas/console.v1.BusinessObjectFilter' - title: ListBusinessObjectsRequest - additionalProperties: false - console.v1.ListBusinessObjectsResponse: - type: object - properties: - objects: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessObject' - title: objects - nextObjectId: - type: string - title: next_object_id - title: ListBusinessObjectsResponse - additionalProperties: false - console.v1.ListBusinessProcessDefinitionsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - afterDefinitionId: - type: string - title: after_definition_id - pageSize: - type: integer - title: page_size - format: int32 - title: ListBusinessProcessDefinitionsRequest - additionalProperties: false - description: Latest revision of each definition, ordered by ID. Maximum page size is 20. - console.v1.ListBusinessProcessDefinitionsResponse: - type: object - properties: - definitions: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessProcessDefinition' - title: definitions - nextAfterDefinitionId: - type: string - title: next_after_definition_id - title: ListBusinessProcessDefinitionsResponse - additionalProperties: false - console.v1.ListBusinessProcessesRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - subjectObjectId: - type: string - title: subject_object_id - afterProcessId: - type: string - title: after_process_id - pageSize: - type: integer - title: page_size - format: int32 - title: ListBusinessProcessesRequest - additionalProperties: false - console.v1.ListBusinessProcessesResponse: - type: object - properties: - processes: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessProcess' - title: processes - description: Receipt-free snapshots; GetBusinessProcess returns bounded full history. - nextAfterProcessId: - type: string - title: next_after_process_id - title: ListBusinessProcessesResponse - additionalProperties: false - console.v1.ListCaptureFormSubmissionsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - formId: - type: string - title: form_id - minLength: 1 - state: - title: state - $ref: '#/components/schemas/console.v1.CaptureFormSubmissionState' - pageSize: - type: integer - title: page_size - maximum: 100 - format: int32 - pageToken: - type: string - title: page_token - maxLength: 512 - title: ListCaptureFormSubmissionsRequest - additionalProperties: false - console.v1.ListCaptureFormSubmissionsResponse: - type: object - properties: - submissions: - type: array - items: - $ref: '#/components/schemas/console.v1.CaptureFormSubmission' - title: submissions - maxItems: 100 - nextPageToken: - type: string - title: next_page_token - maxLength: 512 - title: ListCaptureFormSubmissionsResponse - additionalProperties: false - console.v1.ListCaptureFormsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - state: - title: state - $ref: '#/components/schemas/console.v1.CaptureFormState' - pageSize: - type: integer - title: page_size - maximum: 100 - format: int32 - pageToken: - type: string - title: page_token - maxLength: 512 - title: ListCaptureFormsRequest - additionalProperties: false - console.v1.ListCaptureFormsResponse: - type: object - properties: - forms: - type: array - items: - $ref: '#/components/schemas/console.v1.CaptureForm' - title: forms - maxItems: 100 - nextPageToken: - type: string - title: next_page_token - maxLength: 512 - title: ListCaptureFormsResponse - additionalProperties: false - console.v1.ListCommitmentsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - status: - type: string - title: status - maxLength: 32 - description: |- - status selects the lifecycle statuses to return. Empty returns the open - set (requested, accepted, delivered); "all" returns every status; any - other value returns exactly that status. - title: ListCommitmentsRequest - required: - - query - additionalProperties: false - description: ListCommitmentsRequest reads one workspace's commitment ledger. - console.v1.ListCommitmentsResponse: - type: object - properties: - commitments: - type: array - items: - $ref: '#/components/schemas/console.v1.Commitment' - title: commitments - sourceState: - title: source_state - $ref: '#/components/schemas/console.v1.CommitmentSourceState' - truncated: - type: boolean - title: truncated - description: |- - truncated is set when Cerebro filled the candidate window, so commitments - beyond this page exist. Narrow the status filter to see fewer. - title: ListCommitmentsResponse - additionalProperties: false - console.v1.ListComputerMissionCanaryDefinitionsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - title: ListComputerMissionCanaryDefinitionsRequest - required: - - query - additionalProperties: false - console.v1.ListComputerMissionCanaryDefinitionsResponse: - type: object - properties: - definitions: - type: array - items: - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryDefinition' - title: definitions - title: ListComputerMissionCanaryDefinitionsResponse - additionalProperties: false - console.v1.ListComputerMissionCanaryRunsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - title: ListComputerMissionCanaryRunsRequest - required: - - query - additionalProperties: false - console.v1.ListComputerMissionCanaryRunsResponse: - type: object - properties: - runs: - type: array - items: - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryRun' - title: runs - title: ListComputerMissionCanaryRunsResponse - additionalProperties: false - console.v1.ListConnectedCallsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListConnectedCallsRequest - required: - - query - additionalProperties: false - console.v1.ListConnectedCallsResponse: - type: object - properties: - calls: - type: array - items: - $ref: '#/components/schemas/console.v1.ConnectedCall' - title: calls - sourceState: - title: source_state - $ref: '#/components/schemas/console.v1.ConnectedCallSourceState' - title: ListConnectedCallsResponse - additionalProperties: false - console.v1.ListConnectorProfilesRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - providerId: - type: string - title: provider_id - minLength: 1 - title: ListConnectorProfilesRequest - required: - - query - additionalProperties: false - console.v1.ListConnectorProfilesResponse: - type: object - properties: - profiles: - type: array - items: - $ref: '#/components/schemas/console.v1.ConnectorProfile' - title: profiles - title: ListConnectorProfilesResponse - additionalProperties: false - console.v1.ListConnectorTriggersRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - limit: - type: integer - title: limit - format: int32 - offset: - type: integer - title: offset - format: int32 - title: ListConnectorTriggersRequest - required: - - query - additionalProperties: false - console.v1.ListConnectorTriggersResponse: - type: object - properties: - triggers: - type: array - items: - $ref: '#/components/schemas/console.v1.ConnectorTrigger' - title: triggers - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - title: ListConnectorTriggersResponse - additionalProperties: false - console.v1.ListCostUsageRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - runId: - type: string - title: run_id - maxLength: 256 - description: Exact durable run attribution; filtering happens before pagination. - title: ListCostUsageRequest - required: - - query - additionalProperties: false - console.v1.ListCostUsageResponse: - type: object - properties: - rows: - type: array - items: - $ref: '#/components/schemas/console.v1.CostUsage' - title: rows - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - summary: - title: summary - description: |- - summary is computed by Platform over the complete filtered ledger. rows is - intentionally only the bounded, newest-first explorer page. - $ref: '#/components/schemas/console.v1.CostUsageSummary' - runSummary: - title: run_summary - description: Present only for an exact run query with recorded usage. - $ref: '#/components/schemas/console.v1.CostUsageRunSummary' - title: ListCostUsageResponse - additionalProperties: false - console.v1.ListCustomerIntelligenceFactsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - authorities: - type: array - items: - $ref: '#/components/schemas/console.v1.CustomerIntelligenceAuthority' - title: authorities - maxItems: 6 - lifecycleStates: - type: array - items: - $ref: '#/components/schemas/console.v1.CustomerIntelligenceLifecycleState' - title: lifecycle_states - maxItems: 6 - subjectKind: - title: subject_kind - $ref: '#/components/schemas/console.v1.CustomerIntelligenceSubjectKind' - productArea: - type: string - title: product_area - maxLength: 80 - journey: - type: string - title: journey - maxLength: 80 - createdAfter: - title: created_after - $ref: '#/components/schemas/google.protobuf.Timestamp' - limit: - type: integer - title: limit - maximum: 200 - format: int32 - title: ListCustomerIntelligenceFactsRequest - required: - - query - additionalProperties: false - console.v1.ListCustomerIntelligenceFactsResponse: - type: object - properties: - facts: - type: array - items: - $ref: '#/components/schemas/console.v1.CustomerIntelligenceFact' - title: facts - title: ListCustomerIntelligenceFactsResponse - additionalProperties: false - console.v1.ListDexMcpOAuthProfilesRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - serverId: - type: string - title: server_id - title: ListDexMcpOAuthProfilesRequest - required: - - query - additionalProperties: false - console.v1.ListDexMcpOAuthProfilesResponse: - type: object - properties: - profiles: - type: array - items: - $ref: '#/components/schemas/console.v1.DexMcpOAuthProfile' - title: profiles - title: ListDexMcpOAuthProfilesResponse - additionalProperties: false - console.v1.ListDexMcpServersRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListDexMcpServersRequest - required: - - query - additionalProperties: false - console.v1.ListDexMcpServersResponse: - type: object - properties: - servers: - type: array - items: - $ref: '#/components/schemas/console.v1.DexMcpServer' - title: servers - title: ListDexMcpServersResponse - additionalProperties: false - console.v1.ListEvalResultsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - traceIds: - type: array - items: - type: string - maxLength: 256 - minLength: 1 - maxItems: 100 - title: trace_ids - maxItems: 100 - description: |- - Restrict the projection to the bounded set of traces already visible to - the caller. This prevents clients from draining the evaluation ledger to - join a small page of spend rows. - latestPerTrace: - type: boolean - title: latest_per_trace - title: ListEvalResultsRequest - required: - - query - additionalProperties: false - console.v1.ListEvalResultsResponse: - type: object - properties: - results: - type: array - items: - $ref: '#/components/schemas/console.v1.EvalResult' - title: results - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - title: ListEvalResultsResponse - additionalProperties: false - console.v1.ListFindingsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListFindingsRequest - required: - - query - additionalProperties: false - console.v1.ListFindingsResponse: - type: object - properties: - findings: - type: array - items: - $ref: '#/components/schemas/console.v1.RiskFinding' - title: findings - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - title: ListFindingsResponse - additionalProperties: false - console.v1.ListGatewayEgressOriginsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListGatewayEgressOriginsRequest - required: - - query - additionalProperties: false - console.v1.ListGatewayEgressOriginsResponse: - type: object - properties: - origins: - type: array - items: - type: string - title: origins - configured: - type: boolean - title: configured - source: - type: string - title: source - title: ListGatewayEgressOriginsResponse - additionalProperties: false - console.v1.ListInferenceCreditReceiptsRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - pageToken: - type: string - title: page_token - title: ListInferenceCreditReceiptsRequest - additionalProperties: false - console.v1.ListInferenceCreditReceiptsResponse: - type: object - properties: - receipts: - type: array - items: - $ref: '#/components/schemas/console.v1.InferenceCreditReceipt' - title: receipts - nextPageToken: - type: string - title: next_page_token - available: - type: boolean - title: available - title: ListInferenceCreditReceiptsResponse - additionalProperties: false - console.v1.ListIntegrationTilesRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListIntegrationTilesRequest - required: - - query - additionalProperties: false - console.v1.ListIntegrationTilesResponse: - type: object - properties: - tiles: - type: array - items: - $ref: '#/components/schemas/console.v1.IntegrationTile' - title: tiles - total: - type: integer - title: total - format: int32 - installedTotal: - type: integer - title: installed_total - format: int32 - nullable: true - previewTotal: - type: integer - title: preview_total - format: int32 - nullable: true - readyTotal: - type: integer - title: ready_total - format: int32 - configuredTotal: - type: integer - title: configured_total - format: int32 - previewInventoryUnavailable: - type: boolean - title: preview_inventory_unavailable - title: ListIntegrationTilesResponse - additionalProperties: false - console.v1.ListManagedProviderAccessEventsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - pageSize: - type: integer - title: page_size - maximum: 100 - format: int32 - pageToken: - type: string - title: page_token - title: ListManagedProviderAccessEventsRequest - additionalProperties: false - description: Exact-tenant, newest-first enrollment audit read. The cursor is the last event ID. - console.v1.ListManagedProviderAccessEventsResponse: - type: object - properties: - events: - type: array - items: - $ref: '#/components/schemas/console.v1.ManagedProviderAccessEvent' - title: events - nextPageToken: - type: string - title: next_page_token - title: ListManagedProviderAccessEventsResponse - additionalProperties: false - console.v1.ListManagedProviderAccessGrantsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - description: Optional organization filter; empty returns every grant. - title: ListManagedProviderAccessGrantsRequest - additionalProperties: false - console.v1.ListManagedProviderAccessGrantsResponse: - type: object - properties: - grants: - type: array - items: - $ref: '#/components/schemas/console.v1.ManagedProviderAccessGrant' - title: grants - gatewaySyncAvailable: - type: boolean - title: gateway_sync_available - description: |- - False when no gateway sync target is configured; the console then shows an - explicit unavailable-capability state instead of a live enable control. - title: ListManagedProviderAccessGrantsResponse - additionalProperties: false - console.v1.ListMeetingCapturesRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListMeetingCapturesRequest - required: - - query - additionalProperties: false - console.v1.ListMeetingCapturesResponse: - type: object - properties: - captures: - type: array - items: - $ref: '#/components/schemas/console.v1.MeetingCapture' - title: captures - title: ListMeetingCapturesResponse - additionalProperties: false - console.v1.ListMissionSchedulesRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - title: ListMissionSchedulesRequest - required: - - query - additionalProperties: false - console.v1.ListMissionSchedulesResponse: - type: object - properties: - schedules: - type: array - items: - $ref: '#/components/schemas/console.v1.MissionSchedule' - title: schedules - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - availableCapabilities: - type: array - items: - $ref: '#/components/schemas/console.v1.MissionScheduleCapability' - title: available_capabilities - description: |- - available_capabilities is the backend-owned inventory the durable mission - worker can dispatch. Clients must select from this catalog rather than - accepting arbitrary capability identifiers. - title: ListMissionSchedulesResponse - additionalProperties: false - console.v1.ListOperatingAttachmentsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - scope: - title: scope - $ref: '#/components/schemas/console.v1.OperatingAttachmentScope' - limit: - type: integer - title: limit - maximum: 100 - format: int32 - offset: - type: integer - title: offset - format: int32 - title: ListOperatingAttachmentsRequest - required: - - query - additionalProperties: false - console.v1.ListOperatingAttachmentsResponse: - type: object - properties: - attachments: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingAttachmentRef' - title: attachments - hasMore: - type: boolean - title: has_more - title: ListOperatingAttachmentsResponse - additionalProperties: false - console.v1.ListOperatingChannelsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - archiveFilter: - title: archive_filter - $ref: '#/components/schemas/console.v1.OperatingThreadArchiveFilter' - projectResourceId: - type: string - title: project_resource_id - maxLength: 255 - description: |- - Return only the threads bound to this source project. Empty returns every - thread in the tenant scope, bound or not. - title: ListOperatingChannelsRequest - required: - - query - additionalProperties: false - console.v1.ListOperatingChannelsResponse: - type: object - properties: - channels: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingChannel' - title: channels - capabilities: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingCapabilityState' - title: capabilities - homepageSuggestion: - title: homepage_suggestion - description: |- - One short-lived, backend-authored starter grounded in this principal's - recent operating questions and ranked against Cerebro's tenant-local - conversation memory. Absent means recall was unavailable or had no - sufficiently grounded result; clients must keep their ordinary starter. - $ref: '#/components/schemas/console.v1.OperatingHomepageSuggestion' - title: ListOperatingChannelsResponse - additionalProperties: false - console.v1.ListOperatingCorrectionsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - reviewState: - title: review_state - $ref: '#/components/schemas/console.v1.OperatingCorrectionReviewState' - limit: - type: integer - title: limit - maximum: 200 - format: int32 - title: ListOperatingCorrectionsRequest - required: - - query - additionalProperties: false - console.v1.ListOperatingCorrectionsResponse: - type: object - properties: - corrections: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingCorrectionCandidate' - title: corrections - title: ListOperatingCorrectionsResponse - additionalProperties: false - console.v1.ListOperatingJobsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListOperatingJobsRequest - required: - - query - additionalProperties: false - console.v1.ListOperatingJobsResponse: - type: object - properties: - jobs: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingJob' - title: jobs - maxItems: 200 - partial: - type: boolean - title: partial - description: True when at least one returned legacy record lacks a typed correlation. - title: ListOperatingJobsResponse - additionalProperties: false - console.v1.ListOperatingThreadEventsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - minLength: 1 - afterCursor: - type: - - integer - - string - title: after_cursor - format: int64 - limit: - type: integer - title: limit - maximum: 200 - minimum: 1 - format: int32 - title: ListOperatingThreadEventsRequest - required: - - query - additionalProperties: false - console.v1.ListOperatingThreadEventsResponse: - type: object - properties: - events: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingThreadEvent' - title: events - maxItems: 200 - nextCursor: - type: - - integer - - string - title: next_cursor - format: int64 - hasMore: - type: boolean - title: has_more - resetRequired: - type: boolean - title: reset_required - description: |- - reset_required is true only when retention removed the requested cursor. - Clients replace their projection with the accompanying snapshot. - threadExecution: - title: thread_execution - $ref: '#/components/schemas/console.v1.OperatingThreadExecution' - snapshotTurns: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingThreadTurn' - title: snapshot_turns - title: ListOperatingThreadEventsResponse - additionalProperties: false - console.v1.ListOrbControlTargetsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListOrbControlTargetsRequest - required: - - query - additionalProperties: false - description: ListOrbControlTargetsRequest selects a tenant-scoped target collection. - console.v1.ListOrbControlTargetsResponse: - type: object - properties: - targets: - type: array - items: - $ref: '#/components/schemas/console.v1.OrbControlTarget' - title: targets - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - title: ListOrbControlTargetsResponse - additionalProperties: false - description: ListOrbControlTargetsResponse returns Platform projections only. - console.v1.ListPinnedSourcesRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - title: ListPinnedSourcesRequest - additionalProperties: false - console.v1.ListPinnedSourcesResponse: - type: object - properties: - pins: - type: array - items: - $ref: '#/components/schemas/console.v1.PinnedSource' - title: pins - title: ListPinnedSourcesResponse - additionalProperties: false - console.v1.ListPrivateEndpointsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListPrivateEndpointsRequest - required: - - query - additionalProperties: false - console.v1.ListPrivateEndpointsResponse: - type: object - properties: - endpoints: - type: array - items: - $ref: '#/components/schemas/console.v1.PrivateEndpoint' - title: endpoints - title: ListPrivateEndpointsResponse - additionalProperties: false - console.v1.ListProspectingDraftsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListProspectingDraftsRequest - required: - - query - additionalProperties: false - console.v1.ListProspectingDraftsResponse: - type: object - properties: - drafts: - type: array - items: - $ref: '#/components/schemas/console.v1.ProspectingDraft' - title: drafts - maxItems: 100 - hasMore: - type: boolean - title: has_more - title: ListProspectingDraftsResponse - additionalProperties: false - console.v1.ListProspectingWatchProgramsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListProspectingWatchProgramsRequest - required: - - query - additionalProperties: false - console.v1.ListProspectingWatchProgramsResponse: - type: object - properties: - programs: - type: array - items: - $ref: '#/components/schemas/console.v1.ProspectingWatchProgram' - title: programs - maxItems: 100 - hasMore: - type: boolean - title: has_more - title: ListProspectingWatchProgramsResponse - additionalProperties: false - console.v1.ListScenarioFixturesRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - tags: - type: array - items: - type: string - title: tags - limit: - type: integer - title: limit - maximum: 500 - format: int32 - offset: - type: integer - title: offset - format: int32 - title: ListScenarioFixturesRequest - additionalProperties: false - console.v1.ListScenarioFixturesResponse: - type: object - properties: - fixtures: - type: array - items: - $ref: '#/components/schemas/console.v1.ScenarioFixture' - title: fixtures - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - title: ListScenarioFixturesResponse - additionalProperties: false - console.v1.ListStaffManagedExecutionGrantEventsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - sessionId: - type: string - title: session_id - minLength: 1 - afterSequence: - type: - - integer - - string - title: after_sequence - format: int64 - limit: - type: integer - title: limit - maximum: 100 - format: int32 - title: ListStaffManagedExecutionGrantEventsRequest - additionalProperties: false - console.v1.ListStaffManagedExecutionGrantEventsResponse: - type: object - properties: - events: - type: array - items: - $ref: '#/components/schemas/console.v1.ManagedExecutionGrantEvent' - title: events - nextSequence: - type: - - integer - - string - title: next_sequence - format: int64 - scannedCount: - type: integer - title: scanned_count - format: int32 - title: ListStaffManagedExecutionGrantEventsResponse - additionalProperties: false - console.v1.ListStaffManagedExecutionOutcomesRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - lineageId: - type: string - title: lineage_id - minLength: 1 - limit: - type: integer - title: limit - maximum: 100 - format: int32 - title: ListStaffManagedExecutionOutcomesRequest - additionalProperties: false - console.v1.ListStaffManagedExecutionOutcomesResponse: - type: object - properties: - records: - type: array - items: - $ref: '#/components/schemas/console.v1.ManagedExecutionOutcome' - title: records - atLimit: - type: boolean - title: at_limit - description: True if the bounded owner read returned the requested maximum; no claim of complete history. - title: ListStaffManagedExecutionOutcomesResponse - additionalProperties: false - console.v1.ListStaffManagedInferenceAdminEventsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - request: - title: request - $ref: '#/components/schemas/meter.v1.ListManagedInferenceAdminEventsRequest' - title: ListStaffManagedInferenceAdminEventsRequest - additionalProperties: false - console.v1.ListStaffProductIssueRecoveriesRequest: - type: object - properties: - state: - type: string - title: state - maxLength: 32 - description: Empty means all states; otherwise one existing recovery state. - pageSize: - type: integer - title: page_size - maximum: 100 - description: Zero defaults to 25; at most 100 rows. - pageToken: - type: string - title: page_token - maxLength: 4096 - title: ListStaffProductIssueRecoveriesRequest - additionalProperties: false - description: Global staff queue. Tenant scope is returned explicitly on each row. - console.v1.ListStaffProductIssueRecoveriesResponse: - type: object - properties: - recoveries: - type: array - items: - $ref: '#/components/schemas/console.v1.StaffProductIssueRecoverySummary' - title: recoveries - nextPageToken: - type: string - title: next_page_token - title: ListStaffProductIssueRecoveriesResponse - additionalProperties: false - console.v1.ListStaffProductIssueReportsRequest: - type: object - properties: - engagementState: - type: string - title: engagement_state - maxLength: 32 - limit: - type: integer - title: limit - maximum: 100 - minimum: 1 - title: ListStaffProductIssueReportsRequest - additionalProperties: false - console.v1.ListStaffProductIssueReportsResponse: - type: object - properties: - reports: - type: array - items: - $ref: '#/components/schemas/console.v1.StaffProductIssueReport' - title: reports - title: ListStaffProductIssueReportsResponse - additionalProperties: false - console.v1.ListWorkspaceGuardrailRulesRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListWorkspaceGuardrailRulesRequest - required: - - query - additionalProperties: false - console.v1.ListWorkspaceGuardrailRulesResponse: - type: object - properties: - rules: - type: array - items: - $ref: '#/components/schemas/console.v1.WorkspaceGuardrailRule' - title: rules - title: ListWorkspaceGuardrailRulesResponse - additionalProperties: false - console.v1.ListWorkspaceMemoriesRequest: - type: object - properties: - reviewStatus: - title: review_status - description: Unspecified preserves the approved-memory listing. - $ref: '#/components/schemas/memory.v1.MemoryReviewStatus' - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - limit: - type: integer - title: limit - maximum: 100 - format: int32 - offset: - type: integer - title: offset - format: int32 - title: ListWorkspaceMemoriesRequest - required: - - query - additionalProperties: false - console.v1.ListWorkspaceMemoriesResponse: - type: object - properties: - memories: - type: array - items: - $ref: '#/components/schemas/console.v1.WorkspaceMemory' - title: memories - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - title: ListWorkspaceMemoriesResponse - additionalProperties: false - console.v1.ListWorkspaceSkillsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListWorkspaceSkillsRequest - required: - - query - additionalProperties: false - console.v1.ListWorkspaceSkillsResponse: - type: object - properties: - skills: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingSkill' - title: skills - title: ListWorkspaceSkillsResponse - additionalProperties: false - console.v1.ManagedExecutionGrantEvent: - type: object - properties: - eventId: - type: string - title: event_id - sequence: - type: - - integer - - string - title: sequence - format: int64 - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - action: - type: string - title: action - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - sessionId: - type: string - title: session_id - threadId: - type: string - title: thread_id - turnId: - type: string - title: turn_id - runId: - type: string - title: run_id - requestId: - type: string - title: request_id - actorId: - type: string - title: actor_id - actorKind: - type: string - title: actor_kind - authorizationId: - type: string - title: authorization_id - issuedAtMs: - type: - - integer - - string - title: issued_at_ms - format: int64 - expiresAtMs: - type: - - integer - - string - title: expires_at_ms - format: int64 - grantEpoch: - type: - - integer - - string - title: grant_epoch - format: int64 - runtimeGeneration: - type: - - integer - - string - title: runtime_generation - format: int64 - reason: - type: string - title: reason - title: ManagedExecutionGrantEvent - additionalProperties: false - description: Safe recorded issuer metadata. Expiry is a validity bound, not a fabricated lifecycle event. - console.v1.ManagedExecutionOutcome: - type: object - properties: - recordId: - type: string - title: record_id - requestId: - type: string - title: request_id - lineageId: - type: string - title: lineage_id - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - authorizationId: - type: string - title: authorization_id - verificationStatus: - type: string - title: verification_status - verificationReason: - type: string - title: verification_reason - egressPermission: - type: boolean - title: egress_permission - lifecycleState: - type: string - title: lifecycle_state - errorCode: - type: string - title: error_code - provider: - type: string - title: provider - model: - type: string - title: model - createdAt: - type: string - title: created_at - completedAt: - type: string - title: completed_at - title: ManagedExecutionOutcome - additionalProperties: false - console.v1.ManagedProviderAccessEvent: - type: object - properties: - eventId: - type: string - title: event_id - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - provider: - type: string - title: provider - environment: - type: string - title: environment - action: - type: string - title: action - actorPrincipalId: - type: string - title: actor_principal_id - note: - type: string - title: note - gatewaySyncOutcome: - type: string - title: gateway_sync_outcome - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: ManagedProviderAccessEvent - additionalProperties: false - description: Immutable recorded fact. Pending acceptance and subsequent delivery are separate entries. - console.v1.ManagedProviderAccessGrant: - type: object - properties: - organizationId: - type: string - title: organization_id - provider: - type: string - title: provider - environment: - type: string - title: environment - enabled: - type: boolean - title: enabled - grantedBy: - type: string - title: granted_by - note: - type: string - title: note - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - grantId: - type: string - title: grant_id - revision: - type: - - integer - - string - title: revision - format: int64 - state: - title: state - $ref: '#/components/schemas/console.v1.ManagedProviderAccessState' - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - gatewaySyncOutcome: - type: string - title: gateway_sync_outcome - durableEnrollment: - type: boolean - title: durable_enrollment - description: Explicit durable enrollment; no expiry. Legacy grants remain bounded. - workspaceId: - type: string - title: workspace_id - description: Authorized workspace used for owner synchronization; enrollment remains organization-wide. - title: ManagedProviderAccessGrant - additionalProperties: false - console.v1.ManagedRule: - type: object - properties: - id: - type: string - title: id - minLength: 1 - description: id is stable across revisions and identifies the rule to a client. - title: - type: string - title: title - description: title is the short human label shown in operator surfaces. - bodyMarkdown: - type: string - title: body_markdown - description: body_markdown is the rule text delivered to the model verbatim. - scope: - title: scope - description: scope records the tenant level that authored this rule. - $ref: '#/components/schemas/console.v1.RuleScope' - title: ManagedRule - additionalProperties: false - description: |- - ManagedRule is one operator-authored instruction block that agent clients - inject into the model's system prompt. - console.v1.ManagedSetup: - type: object - properties: - version: - type: - - integer - - string - title: version - format: int64 - description: version increases monotonically per tenant on every accepted write. - issuedAt: - title: issued_at - description: issued_at is when the platform served this revision. - $ref: '#/components/schemas/google.protobuf.Timestamp' - rules: - type: array - items: - $ref: '#/components/schemas/console.v1.ManagedRule' - title: rules - description: rules are injected into the client's system prompt. - skills: - type: array - items: - $ref: '#/components/schemas/console.v1.ManagedSkillRef' - title: skills - description: skills are the skills the organization expects clients to have. - mcp: - title: mcp - description: mcp is the MCP server connection policy. - $ref: '#/components/schemas/console.v1.McpPolicy' - sandboxPolicyToml: - type: string - title: sandbox_policy_toml - description: |- - sandbox_policy_toml is the serialized sandbox policy document. The platform - validates only that it parses as TOML; the client owns its semantics. - organizationId: - type: string - title: organization_id - description: organization_id is the tenant that owns this document. - workspaceId: - type: string - title: workspace_id - description: workspace_id is empty when this document is the organization-wide one. - title: ManagedSetup - additionalProperties: false - description: |- - ManagedSetup is the organization-owned agent client configuration document. - Administrators author it once in Deixic; every agent client fetches it and - enforces it locally. - console.v1.ManagedSkillRef: - type: object - properties: - id: - type: string - title: id - minLength: 1 - description: id is the skill identifier in the client's local catalog. - source: - type: string - title: source - description: source is the marketplace or repository the skill comes from. - version: - type: string - title: version - description: version pins the expected skill revision, or is empty for any revision. - required: - type: boolean - title: required - description: required marks a skill whose absence a client must report to the operator. - title: ManagedSkillRef - additionalProperties: false - description: |- - ManagedSkillRef names a skill the organization expects agent clients to have - available. Installation is not part of this contract. - console.v1.McpPolicy: - type: object - properties: - mode: - title: mode - description: mode selects allowlist, denylist, or open handling of unlisted servers. - $ref: '#/components/schemas/console.v1.McpPolicyMode' - servers: - type: array - items: - $ref: '#/components/schemas/console.v1.McpServerRef' - title: servers - description: servers are the entries the mode decides on. - title: McpPolicy - additionalProperties: false - description: |- - McpPolicy is the organization decision about which MCP servers an agent - client may connect to. - console.v1.McpServerRef: - type: object - properties: - name: - type: string - title: name - description: name is the client-side MCP server name the policy decides on. - urlPattern: - type: string - title: url_pattern - description: url_pattern matches the server endpoint for URL-based transports. - transport: - type: string - title: transport - description: transport is the MCP transport label, such as `stdio` or `http`. - title: McpServerRef - additionalProperties: false - description: McpServerRef names one MCP server in a managed MCP policy. - console.v1.MeetingCapture: - type: object - properties: - captureId: - type: string - title: capture_id - actionIntentId: - type: string - title: action_intent_id - meetingUrl: - type: string - title: meeting_url - botName: - type: string - title: bot_name - lifecycleState: - type: string - title: lifecycle_state - providerBotId: - type: string - title: provider_bot_id - transcriptState: - type: string - title: transcript_state - transcriptSegmentCount: - type: integer - title: transcript_segment_count - format: int32 - transcriptObjectId: - type: string - title: transcript_object_id - transcriptVersionId: - type: string - title: transcript_version_id - cerebroState: - type: string - title: cerebro_state - cerebroThingId: - type: string - title: cerebro_thing_id - errorCode: - type: string - title: error_code - requiredUserAction: - type: string - title: required_user_action - joinAt: - title: join_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - leaveAt: - title: leave_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - cerebroChunkCount: - type: integer - title: cerebro_chunk_count - format: int32 - cerebroChunkIds: - type: array - items: - type: string - title: cerebro_chunk_ids - cerebroRetrievalState: - type: string - title: cerebro_retrieval_state - cerebroRetrievalCandidateId: - type: string - title: cerebro_retrieval_candidate_id - providerRecordingId: - type: string - title: provider_recording_id - providerTranscriptId: - type: string - title: provider_transcript_id - sourceKind: - type: string - title: source_kind - description: |- - "direct_url" for a pasted meeting URL, "calendar_occurrence" for an - opted-in connected calendar call. - title: - type: string - title: title - description: Calendar event title. Empty for a direct meeting URL. - occurrenceStartAt: - title: occurrence_start_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - desiredState: - type: string - title: desired_state - description: '"enabled" while the capture is wanted, "disabled" after StopMeetingCapture.' - title: MeetingCapture - additionalProperties: false - description: |- - MeetingCapture is the Platform-owned status projection. Provider state, - immutable transcript references, Cerebro indexing, and tenant-scoped - retrieval proof remain separate so clients never infer completion from - display text. - console.v1.MissionSchedule: - type: object - properties: - scheduleId: - type: string - title: schedule_id - minLength: 1 - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - name: - type: string - title: name - minLength: 1 - cronExpression: - type: string - title: cron_expression - minLength: 1 - enabled: - type: boolean - title: enabled - template: - title: template - $ref: '#/components/schemas/console.v1.MissionScheduleTemplate' - nextRunAt: - title: next_run_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - lastRunAt: - title: last_run_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - lastStatus: - type: string - title: last_status - lastMissionId: - type: string - title: last_mission_id - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: MissionSchedule - required: - - template - - nextRunAt - - createdAt - - updatedAt - additionalProperties: false - console.v1.MissionScheduleCapability: - type: object - properties: - name: - type: string - title: name - minLength: 1 - description: - type: string - title: description - minLength: 1 - title: MissionScheduleCapability - additionalProperties: false - description: |- - MissionScheduleCapability is intentionally declared at the end of this - large file so adding it does not renumber unrelated generated descriptors. - console.v1.MissionScheduleTemplate: - type: object - properties: - goal: - type: string - title: goal - minLength: 1 - runnerProfile: - type: string - title: runner_profile - minLength: 1 - channelId: - type: string - title: channel_id - minLength: 1 - authorityMode: - not: - enum: - - 0 - title: authority_mode - description: |- - Selecting FULL_AUTONOMY is the schedule's explicit typed authority - confirmation. Console binds that selection to the authenticated principal - and persists the current confirmation contract version; the worker also - requires its independent full-autonomy feature gate. - $ref: '#/components/schemas/console.v1.ComputerMissionAuthorityMode' - capabilities: - type: array - items: - type: string - title: capabilities - minItems: 1 - resourceIds: - type: array - items: - type: string - title: resource_ids - minItems: 1 - requiredEvidence: - type: array - items: - type: string - title: required_evidence - minItems: 1 - budget: - title: budget - $ref: '#/components/schemas/console.v1.ComputerMissionBudget' - title: MissionScheduleTemplate - required: - - budget - additionalProperties: false - description: |- - MissionScheduleTemplate is the typed mission payload a schedule fires on - each due tick. Field shape mirrors ComputerMissionContract minus the - scope's organization/workspace ids (the schedule already carries those) - and the authority grant/resume fields, which the worker mints fresh for - each fired mission. - console.v1.OnboardingTask: - type: object - properties: - id: - type: string - title: id - title: - type: string - title: title - detail: - type: string - title: detail - status: - type: string - title: status - ctaLabel: - type: string - title: cta_label - command: - type: string - title: command - requiredIntegrations: - type: array - items: - type: string - title: required_integrations - title: OnboardingTask - additionalProperties: false - console.v1.OperateComputerMissionCanaryRunRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - canaryRunId: - type: string - title: canary_run_id - minLength: 1 - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryOperatorActionKind' - narrowedScope: - title: narrowed_scope - $ref: '#/components/schemas/console.v1.ComputerMissionScope' - extendedBudget: - title: extended_budget - $ref: '#/components/schemas/console.v1.ComputerMissionBudget' - extendedGrantExpiresAt: - title: extended_grant_expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - reason: - type: string - title: reason - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: OperateComputerMissionCanaryRunRequest - required: - - query - additionalProperties: false - console.v1.OperateComputerMissionCanaryRunResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryRun' - action: - title: action - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryOperatorAction' - title: OperateComputerMissionCanaryRunResponse - required: - - run - - action - additionalProperties: false - console.v1.OperatingAttachmentRef: - type: object - properties: - id: - type: string - title: id - objectId: - type: string - title: object_id - versionId: - type: string - title: version_id - scope: - title: scope - $ref: '#/components/schemas/console.v1.OperatingAttachmentScope' - channelId: - type: string - title: channel_id - filename: - type: string - title: filename - contentType: - type: string - title: content_type - sizeBytes: - type: - - integer - - string - title: size_bytes - maximum: 52428800 - format: int64 - sha256: - type: string - title: sha256 - processingState: - title: processing_state - $ref: '#/components/schemas/console.v1.OperatingAttachmentProcessingState' - extractionObjectId: - type: string - title: extraction_object_id - extractionVersionId: - type: string - title: extraction_version_id - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: OperatingAttachmentRef - additionalProperties: false - console.v1.OperatingAutoModelRoute: - type: object - properties: - target: - title: target - $ref: '#/components/schemas/console.v1.OperatingModelSelection' - purpose: - title: purpose - $ref: '#/components/schemas/console.v1.StaffInferenceRoutingPurpose' - policyVersion: - type: string - title: policy_version - placement: - title: placement - $ref: '#/components/schemas/console.v1.OperatingExecutionPlacement' - title: OperatingAutoModelRoute - additionalProperties: false - console.v1.OperatingCapabilityContract: - type: object - properties: - schemaVersion: - type: string - title: schema_version - capabilityIds: - type: array - items: - type: string - title: capability_ids - skillIds: - type: array - items: - type: string - title: skill_ids - memoryOperations: - type: array - items: - type: string - title: memory_operations - executionOwner: - type: string - title: execution_owner - memoryOwner: - type: string - title: memory_owner - channelRenderer: - type: string - title: channel_renderer - proposalOnly: - type: boolean - title: proposal_only - evidenceBacked: - type: boolean - title: evidence_backed - identityAuthorization: - title: identity_authorization - description: |- - Server-derived, action-specific Identity authorization. Consumers must - reject governed effects when this evidence is absent, expired, denied, or - does not match the independent tenant/application/subject boundaries. - $ref: '#/components/schemas/console.v1.IdentityToolAuthorizationEvidence' - title: OperatingCapabilityContract - additionalProperties: false - description: |- - OperatingCapabilityContract is the bounded, provider-neutral capability - envelope attached to a durable Platform worker dispatch. It describes - ownership and safe capability names; it never carries prompts, tool - arguments, model output, credentials, or live Maestro session state. - console.v1.OperatingCapabilityRequirementState: - type: object - properties: - service: - type: string - title: service - status: - type: string - title: status - reasonCode: - type: string - title: reason_code - remediationRef: - type: string - title: remediation_ref - title: OperatingCapabilityRequirementState - additionalProperties: false - console.v1.OperatingCapabilityState: - type: object - properties: - service: - type: string - title: service - status: - type: string - title: status - label: - type: string - title: label - detail: - type: string - title: detail - missingRequirements: - type: array - items: - type: string - title: missing_requirements - missingRequirementStates: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingCapabilityRequirementState' - title: missing_requirement_states - title: OperatingCapabilityState - additionalProperties: false - description: |- - OperatingCapabilityState is the UI-safe service availability summary for an - operating channel or receipt owner. - console.v1.OperatingChannel: - type: object - properties: - id: - type: string - title: id - label: - type: string - title: label - kind: - type: string - title: kind - sourceService: - type: string - title: source_service - unreadCount: - type: integer - title: unread_count - format: int32 - openCount: - type: integer - title: open_count - format: int32 - capabilityState: - title: capability_state - $ref: '#/components/schemas/console.v1.OperatingCapabilityState' - detail: - type: string - title: detail - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - surface: - title: surface - $ref: '#/components/schemas/console.v1.OperatingSurfaceMetadata' - archived: - type: boolean - title: archived - description: |- - Archive is a list-visibility state owned by the durable channel row. It - never implies provider-binding or execution lifecycle changes. - archivedAt: - title: archived_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - archivedByPrincipalId: - type: string - title: archived_by_principal_id - description: |- - Archive provenance is durable owner metadata. It is populated only for an - archived channel and cleared when the channel is unarchived. - archivedByDisplayName: - type: string - title: archived_by_display_name - fork: - title: fork - description: |- - Fork provenance is durable owner metadata, absent on a thread that was - started directly. - $ref: '#/components/schemas/console.v1.OperatingThreadFork' - projectResourceId: - type: string - title: project_resource_id - maxLength: 255 - description: |- - The source project this thread's work belongs to, empty when the thread - has never submitted a turn against one. This is the existing - `project_resource_id` from SubmitOperatingMessageRequest, recorded durably - on the thread so several threads working the same project can be listed - together. It is a grouping, never an authority: every read still resolves - the thread under the caller's own tenant scope. - title: OperatingChannel - additionalProperties: false - description: |- - OperatingChannel identifies a company/domain/thread surface the Console can - show. It carries capability state, not local operational data. - console.v1.OperatingCodingAcceptance: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - actorId: - type: string - title: actor_id - workId: - type: string - title: work_id - runtimeRunId: - type: string - title: runtime_run_id - contract: - title: contract - $ref: '#/components/schemas/console.v1.CodingAcceptanceContract' - accepted: - type: boolean - title: accepted - contractDigest: - type: string - title: contract_digest - submissionDigest: - type: string - title: submission_digest - reasons: - type: array - items: - type: string - title: reasons - revision: - type: string - title: revision - outputs: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingCodingOutput' - title: outputs - title: OperatingCodingAcceptance - additionalProperties: false - description: |- - Read-only projection of the decision committed by Platform's fenced coding - acceptance owner. Absence is not acceptance. Artifact bytes remain separately - owned by VFS and must be read and verified by consumers. - console.v1.OperatingCodingOutput: - type: object - properties: - path: - type: string - title: path - objectId: - type: string - title: object_id - versionId: - type: string - title: version_id - sha256: - type: string - title: sha256 - sizeBytes: - type: - - integer - - string - title: size_bytes - format: int64 - content: - type: string - title: content - format: byte - description: Read from VFS only for an explicit originating-actor receipt read. Never persisted here. - title: OperatingCodingOutput - additionalProperties: false - console.v1.OperatingCorrectionCandidate: - type: object - properties: - id: - type: string - title: id - channelId: - type: string - title: channel_id - messageId: - type: string - title: message_id - category: - title: category - $ref: '#/components/schemas/console.v1.OperatingCorrectionCategory' - feedbackDigestSha256: - type: string - title: feedback_digest_sha256 - rememberRequested: - type: boolean - title: remember_requested - learningEligible: - type: boolean - title: learning_eligible - reviewState: - title: review_state - $ref: '#/components/schemas/console.v1.OperatingCorrectionReviewState' - reviewerId: - type: string - title: reviewer_id - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - maxItems: 64 - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - reviewedAt: - title: reviewed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - reviewCapability: - title: review_capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - correctionEpisode: - title: correction_episode - $ref: '#/components/schemas/console.v1.DexComputerCorrectionEpisode' - title: OperatingCorrectionCandidate - required: - - correctionEpisode - additionalProperties: false - console.v1.OperatingCustomerOutcomeIdentity: - type: object - properties: - studyOrgKey: - type: string - title: study_org_key - maxLength: 128 - description: |- - Purpose-limited HMAC of the organization identity. Empty means the study - is not enabled or the service has no configured study key. - consentState: - type: string - title: consent_state - maxLength: 32 - description: Service-owned consent/eligibility state, never inferred by the browser. - consentPolicyVersion: - type: string - title: consent_policy_version - maxLength: 64 - sourceRevision: - type: string - title: source_revision - maxLength: 64 - workflowId: - type: string - title: workflow_id - maxLength: 128 - workflowVersion: - type: string - title: workflow_version - maxLength: 64 - modelId: - type: string - title: model_id - maxLength: 128 - modelRevision: - type: string - title: model_revision - maxLength: 128 - providerId: - type: string - title: provider_id - maxLength: 128 - providerRoute: - type: string - title: provider_route - maxLength: 128 - configDigest: - type: string - title: config_digest - maxLength: 128 - promptTemplateRevision: - type: string - title: prompt_template_revision - maxLength: 128 - toolchainRevision: - type: string - title: toolchain_revision - maxLength: 128 - featureFlagSnapshotDigest: - type: string - title: feature_flag_snapshot_digest - maxLength: 128 - rolloutId: - type: string - title: rollout_id - maxLength: 128 - title: OperatingCustomerOutcomeIdentity - additionalProperties: false - console.v1.OperatingExecutionIdentity: - type: object - properties: - runtime: - title: runtime - $ref: '#/components/schemas/console.v1.OperatingExecutionRuntime' - runId: - type: string - title: run_id - maxLength: 256 - minLength: 1 - runnerSessionId: - type: string - title: runner_session_id - maxLength: 256 - minLength: 1 - protocolVersion: - type: string - title: protocol_version - maxLength: 128 - minLength: 1 - runtimeGeneration: - exclusiveMinimum: 0 - type: - - integer - - string - title: runtime_generation - format: int64 - eventCursor: - exclusiveMinimum: 0 - type: - - integer - - string - title: event_cursor - format: int64 - causalReceiptId: - type: string - title: causal_receipt_id - maxLength: 128 - description: |- - Immutable release/execution identity used to join bounded deployment and - runtime receipts. It is intentionally opaque and never carries content. - maestroSessionId: - type: string - title: maestro_session_id - maxLength: 256 - maestroRunId: - type: string - title: maestro_run_id - maxLength: 256 - residentProcessGeneration: - type: - - integer - - string - title: resident_process_generation - format: int64 - turnId: - type: string - title: turn_id - maxLength: 128 - appendReplayed: - type: boolean - title: append_replayed - title: OperatingExecutionIdentity - additionalProperties: false - description: |- - OperatingExecutionIdentity is a credential-free drill-down identity for the - hosted execution that produced a thread event. It is safe to persist with - the browser projection; Runner Host service, Pod, certificate, and cluster - coordinates remain private. - console.v1.OperatingExecutionProfile: - type: object - properties: - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/console.v1.OperatingExecutionProfileKind' - profileId: - type: string - title: profile_id - minLength: 1 - frontModel: - type: string - title: front_model - maxLength: 256 - frontProvider: - type: string - title: front_provider - maxLength: 128 - title: OperatingExecutionProfile - additionalProperties: false - console.v1.OperatingFeedback: - type: object - properties: - id: - type: string - title: id - channelId: - type: string - title: channel_id - messageId: - type: string - title: message_id - sentiment: - title: sentiment - $ref: '#/components/schemas/console.v1.OperatingFeedbackSentiment' - category: - title: category - $ref: '#/components/schemas/console.v1.OperatingCorrectionCategory' - classificationSource: - title: classification_source - $ref: '#/components/schemas/console.v1.OperatingFeedbackClassificationSource' - taxonomyVersion: - type: string - title: taxonomy_version - correctionPresent: - type: boolean - title: correction_present - correctionId: - type: string - title: correction_id - learningEligible: - type: boolean - title: learning_eligible - remediationAction: - title: remediation_action - $ref: '#/components/schemas/console.v1.OperatingFeedbackRemediationAction' - remediationAttemptId: - type: string - title: remediation_attempt_id - remediationOutcome: - title: remediation_outcome - $ref: '#/components/schemas/console.v1.OperatingFeedbackRemediationOutcome' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - resolvedAt: - title: resolved_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - reason: - title: reason - $ref: '#/components/schemas/console.v1.OperatingFeedbackReason' - lifecycleState: - title: lifecycle_state - $ref: '#/components/schemas/console.v1.OperatingFeedbackLifecycleState' - rootFeedbackId: - type: string - title: root_feedback_id - revision: - type: - - integer - - string - title: revision - format: int64 - supersedesFeedbackId: - type: string - title: supersedes_feedback_id - title: OperatingFeedback - additionalProperties: false - console.v1.OperatingHistoryContextRecord: - type: object - properties: - channelId: - type: string - title: channel_id - sourceKind: - type: string - title: source_kind - sourceId: - type: string - title: source_id - role: - type: string - title: role - toolName: - type: string - title: tool_name - status: - type: string - title: status - body: - type: string - title: body - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - sourceRef: - title: source_ref - $ref: '#/components/schemas/console.v1.RelatedResource' - title: OperatingHistoryContextRecord - additionalProperties: false - console.v1.OperatingHistorySearchFilter: - type: object - properties: - recordKinds: - type: array - items: - type: string - title: record_kinds - roles: - type: array - items: - type: string - title: roles - toolNames: - type: array - items: - type: string - title: tool_names - statuses: - type: array - items: - type: string - title: statuses - occurredAfter: - title: occurred_after - $ref: '#/components/schemas/google.protobuf.Timestamp' - occurredBefore: - title: occurred_before - $ref: '#/components/schemas/google.protobuf.Timestamp' - channelIds: - type: array - items: - type: string - title: channel_ids - title: OperatingHistorySearchFilter - additionalProperties: false - console.v1.OperatingHistorySearchResult: - type: object - properties: - channelId: - type: string - title: channel_id - channelTitle: - type: string - title: channel_title - sourceKind: - type: string - title: source_kind - sourceId: - type: string - title: source_id - role: - type: string - title: role - toolName: - type: string - title: tool_name - status: - type: string - title: status - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - excerpt: - type: string - title: excerpt - score: - type: number - title: score - format: double - contextCursor: - type: string - title: context_cursor - sourceRef: - title: source_ref - $ref: '#/components/schemas/console.v1.RelatedResource' - title: OperatingHistorySearchResult - additionalProperties: false - console.v1.OperatingHomepageSuggestion: - type: object - properties: - schema: - type: string - title: schema - const: dex.homepage_suggestion.v1 - label: - type: string - title: label - maxLength: 160 - minLength: 1 - prompt: - type: string - title: prompt - maxLength: 1000 - minLength: 1 - source: - type: string - title: source - const: cerebro - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - maxItems: 8 - generatedAt: - title: generated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: - type: string - title: title - maxLength: 60 - minLength: 1 - description: |- - Short model-generated topic title grounded in the same cited evidence as - the memory line. Absent when the model abstains or validation fails. - suggestionId: - type: string - title: suggestion_id - minLength: 1 - title: OperatingHomepageSuggestion - required: - - generatedAt - - expiresAt - additionalProperties: false - console.v1.OperatingHostedFrontDecision: - type: object - properties: - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/console.v1.OperatingHostedFrontDecisionKind' - assistantBody: - type: string - title: assistant_body - maxLength: 4096 - minLength: 1 - title: OperatingHostedFrontDecision - additionalProperties: false - console.v1.OperatingInitialActionResult: - type: object - properties: - executionId: - type: string - title: execution_id - minLength: 1 - callId: - type: string - title: call_id - minLength: 1 - toolName: - type: string - title: tool_name - minLength: 1 - readOnly: - type: boolean - title: read_only - state: - not: - enum: - - 0 - title: state - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionState' - receiptId: - type: string - title: receipt_id - minLength: 1 - safeSummary: - type: string - title: safe_summary - maxLength: 4096 - safeOutput: - title: safe_output - $ref: '#/components/schemas/google.protobuf.Struct' - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - maxItems: 32 - threadId: - type: string - title: thread_id - minLength: 1 - turnId: - type: string - title: turn_id - minLength: 1 - authorityRevision: - exclusiveMinimum: 0 - type: - - integer - - string - title: authority_revision - format: int64 - acceptedAt: - title: accepted_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - assistantDelta: - type: string - title: assistant_delta - maxLength: 4096 - minLength: 1 - description: |- - The first user-visible delta is deterministic receipt-grounded text. It - is persisted in the same dispatch as the admitted action so the deep - runtime cannot race ahead with ungrounded prose. - title: OperatingInitialActionResult - required: - - acceptedAt - additionalProperties: false - description: |- - OperatingInitialActionResult is the safe, typed join between the hosted - front action and the deep agent. The referenced ToolExecution is already - durable before this message may be attached to a dispatch. Raw arguments, - raw output, credentials, and provider responses are forbidden here. - console.v1.OperatingJob: - type: object - properties: - jobId: - type: string - title: job_id - minLength: 1 - objectiveId: - type: string - title: objective_id - minLength: 1 - title: - type: string - title: title - minLength: 1 - state: - title: state - $ref: '#/components/schemas/console.v1.OperatingJobState' - verificationState: - title: verification_state - $ref: '#/components/schemas/console.v1.OperatingJobVerificationState' - origin: - title: origin - $ref: '#/components/schemas/console.v1.OperatingJobOrigin' - channelId: - type: string - title: channel_id - submittedMessageId: - type: string - title: submitted_message_id - conversationContextId: - type: string - title: conversation_context_id - conversationTaskId: - type: string - title: conversation_task_id - conversationTaskRevision: - type: - - integer - - string - title: conversation_task_revision - format: int64 - activeRunId: - type: string - title: active_run_id - attemptCount: - type: integer - title: attempt_count - format: int32 - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - projectionComplete: - type: boolean - title: projection_complete - description: |- - False means an older producer omitted one or more typed correlations. - Clients may render the job but must not infer the missing owner data. - missingOwnerData: - type: array - items: - type: string - maxLength: 64 - minLength: 1 - maxItems: 16 - title: missing_owner_data - maxItems: 16 - recordLinks: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingJobRecordLink' - title: record_links - maxItems: 256 - description: |- - Causal references only. Record payloads remain with their authoritative - owners and are resolved under the request's authenticated tenant. - proofState: - title: proof_state - $ref: '#/components/schemas/console.v1.OperatingJobProofState' - missingProof: - type: array - items: - type: string - maxLength: 64 - minLength: 1 - maxItems: 16 - title: missing_proof - maxItems: 16 - description: |- - Stable machine-readable categories such as action_lineage, - policy_decision, usage, and terminal_receipt. - title: OperatingJob - additionalProperties: false - description: |- - OperatingJob is a bounded customer projection over owner records. It never - contains raw prompts, tool arguments/results, credentials, or receipt - payloads. job_id and objective_id are equal for this v1 projection. - console.v1.OperatingJobRecordLink: - type: object - properties: - correlationId: - type: string - title: correlation_id - minLength: 1 - relation: - type: string - title: relation - minLength: 1 - record: - title: record - $ref: '#/components/schemas/platform.v1.RecordRef' - title: OperatingJobRecordLink - required: - - record - additionalProperties: false - description: |- - OperatingJobRecordLink is one append-only causal edge from the job's active - run to an independently owned record. correlation_id groups records emitted - by the same operation milestone; relation is a bounded server-authored value. - console.v1.OperatingManagedInferenceOutputTokenBudget: - type: object - properties: - value: - type: - - integer - - string - title: value - format: int64 - nullable: true - origin: - not: - enum: - - 0 - title: origin - $ref: '#/components/schemas/console.v1.OperatingManagedInferenceBudgetOrigin' - originReference: - type: string - title: origin_reference - maxLength: 512 - title: OperatingManagedInferenceOutputTokenBudget - additionalProperties: false - console.v1.OperatingManagedInferenceProviderCandidate: - type: object - properties: - provider: - type: string - title: provider - minLength: 1 - environment: - type: string - title: environment - minLength: 1 - credentialName: - type: string - title: credential_name - maxLength: 512 - teamId: - type: string - title: team_id - maxLength: 512 - model: - type: string - title: model - minLength: 1 - title: OperatingManagedInferenceProviderCandidate - additionalProperties: false - description: |- - Exact server-selected provider candidate authorized for one managed - inference turn. Credential names are non-secret references; secret material - remains in the managed provider owner. - console.v1.OperatingManagedInferenceScope: - type: object - properties: - endpoint: - type: string - title: endpoint - const: responses - model: - type: string - title: model - minLength: 1 - providerCandidates: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingManagedInferenceProviderCandidate' - title: provider_candidates - maxItems: 16 - minItems: 1 - routing: - not: - enum: - - 0 - title: routing - $ref: '#/components/schemas/console.v1.OperatingManagedInferenceRouting' - outputTokenBudget: - title: output_token_budget - $ref: '#/components/schemas/console.v1.OperatingManagedInferenceOutputTokenBudget' - title: OperatingManagedInferenceScope - required: - - outputTokenBudget - additionalProperties: false - description: |- - Durable, content-free authority for Runner Host to sign a per-turn managed - inference authorization. Platform selects this before work creation and the - worker replays it verbatim; clients never choose or widen these fields. - console.v1.OperatingMessage: - type: object - properties: - id: - type: string - title: id - channelId: - type: string - title: channel_id - role: - type: string - title: role - actorLabel: - type: string - title: actor_label - body: - type: string - title: body - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - receiptIds: - type: array - items: - type: string - title: receipt_ids - route: - title: route - $ref: '#/components/schemas/console.v1.OperatingTurnRoute' - attachments: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingAttachmentRef' - title: attachments - turnRecord: - title: turn_record - description: |- - Safe structured state for the accepted turn. Raw prompts, tool arguments, - tool results, connector payloads, and model responses are forbidden here. - $ref: '#/components/schemas/console.v1.OperatingTurnRecord' - modelSelection: - title: model_selection - $ref: '#/components/schemas/console.v1.OperatingModelSelection' - autoModelRoute: - title: auto_model_route - $ref: '#/components/schemas/console.v1.OperatingAutoModelRoute' - title: OperatingMessage - additionalProperties: false - description: OperatingMessage is safe conversation text plus links to typed receipts. - console.v1.OperatingModelSelection: - type: object - properties: - provider: - type: string - title: provider - maxLength: 128 - model: - type: string - title: model - maxLength: 256 - title: OperatingModelSelection - additionalProperties: false - description: |- - A conversation preference, validated against the tenant's enabled targets. - An empty provider/model pair uses the organization's normal routing. - console.v1.OperatingProjectSnapshotFileInput: - type: object - properties: - path: - type: string - title: path - maxLength: 1024 - minLength: 1 - attachment: - title: attachment - $ref: '#/components/schemas/console.v1.OperatingAttachmentRef' - title: OperatingProjectSnapshotFileInput - required: - - attachment - additionalProperties: false - console.v1.OperatingReceipt: - type: object - properties: - id: - type: string - title: id - kind: - type: string - title: kind - title: - type: string - title: title - summary: - type: string - title: summary - status: - type: string - title: status - ownerService: - type: string - title: owner_service - objectId: - type: string - title: object_id - objectiveId: - type: string - title: objective_id - runId: - type: string - title: run_id - approvalRequestId: - type: string - title: approval_request_id - traceId: - type: string - title: trace_id - riskLevel: - title: risk_level - $ref: '#/components/schemas/common.v1.RiskLevel' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - allowedActions: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingReceiptAction' - title: allowed_actions - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Struct' - lifecycleState: - title: lifecycle_state - description: |- - Owner-resolved lifecycle. Thread responses strip receipt payloads, so this - is the only lifecycle statement a client can read there. - $ref: '#/components/schemas/console.v1.ReceiptLifecycleState' - codingAcceptance: - title: coding_acceptance - description: Set only by the fenced coding completion owner; absent until evaluated. - $ref: '#/components/schemas/console.v1.OperatingCodingAcceptance' - title: OperatingReceipt - additionalProperties: false - description: |- - OperatingReceipt is the mini-app object rendered inline in chat and expanded - in the inspector. Display payloads must be safe for UI rendering and must not - include raw prompts, tool arguments, credentials, tokens, connector payloads, - VFS bytes, or model responses. - console.v1.OperatingReceiptAction: - type: object - properties: - id: - type: string - title: id - label: - type: string - title: label - kind: - type: string - title: kind - targetKind: - type: string - title: target_kind - targetId: - type: string - title: target_id - requiresConfirmation: - type: boolean - title: requires_confirmation - disabledReason: - type: string - title: disabled_reason - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Struct' - title: OperatingReceiptAction - additionalProperties: false - description: OperatingReceiptAction is a typed command the backend allows for one receipt. - console.v1.OperatingRequiredInitialToolIntent: - type: object - properties: - callId: - type: string - title: call_id - maxLength: 256 - minLength: 1 - toolName: - type: string - title: tool_name - const: computer.write_file - arguments: - title: arguments - $ref: '#/components/schemas/google.protobuf.Struct' - actorId: - type: string - title: actor_id - maxLength: 256 - minLength: 1 - toolIdempotencyKey: - type: string - title: tool_idempotency_key - maxLength: 512 - minLength: 1 - sandboxSessionId: - type: string - title: sandbox_session_id - maxLength: 256 - minLength: 1 - computerHomeKey: - type: string - title: computer_home_key - maxLength: 256 - computerWorkspaceDir: - type: string - title: computer_workspace_dir - maxLength: 512 - capability: - type: string - title: capability - maxLength: 256 - minLength: 1 - operation: - type: string - title: operation - maxLength: 256 - minLength: 1 - riskLevel: - not: - enum: - - 0 - title: risk_level - $ref: '#/components/schemas/common.v1.RiskLevel' - metadata: - type: object - title: metadata - additionalProperties: - type: string - title: value - description: |- - Canonical non-secret ToolExecution metadata. Raw grant claims, - signatures, and server-owned verified authority are never persisted. - title: OperatingRequiredInitialToolIntent - required: - - arguments - additionalProperties: false - console.v1.OperatingRequiredInitialToolIntent.MetadataEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: MetadataEntry - additionalProperties: false - console.v1.OperatingRunDispatch: - type: object - properties: - runtimeRunId: - type: string - title: runtime_run_id - minLength: 1 - workId: - type: string - title: work_id - minLength: 1 - operationId: - type: string - title: operation_id - minLength: 1 - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - channelId: - type: string - title: channel_id - minLength: 1 - submittedMessageId: - type: string - title: submitted_message_id - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - traceparent: - type: string - title: traceparent - enqueuedAt: - title: enqueued_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - attachmentMounts: - type: array - items: - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionAttachmentMount' - title: attachment_mounts - capabilityContract: - title: capability_contract - description: Optional additive metadata for Platform-owned dispatch consumers. - $ref: '#/components/schemas/console.v1.OperatingCapabilityContract' - response: - title: response - $ref: '#/components/schemas/console.v1.OperatingThreadResponse' - executionProfile: - title: execution_profile - $ref: '#/components/schemas/console.v1.OperatingExecutionProfile' - initialAction: - title: initial_action - $ref: '#/components/schemas/console.v1.OperatingInitialActionResult' - hostedFrontDecision: - title: hosted_front_decision - description: |- - Present when the hosted model produced a replay-stable preliminary answer - before this durable deep-runtime dispatch was created. - $ref: '#/components/schemas/console.v1.OperatingHostedFrontDecision' - causalReceiptId: - type: string - title: causal_receipt_id - maxLength: 128 - description: |- - Immutable release/execution identity propagated across the durable queue - and hosted runtime. It is deployment-owned, not client-provided. - requiredInitialTool: - type: string - title: required_initial_tool - maxLength: 256 - description: |- - Exact server-selected Platform tool that must settle before the deep - runtime may consume initial_action. Empty preserves the read-only hosted - front contract. Mutating results are valid only when this value and the - persisted turn authority match initial_action exactly. - requiredInitialToolAuthorityRevision: - type: - - integer - - string - title: required_initial_tool_authority_revision - format: int64 - approvedPlanVersion: - type: - - integer - - string - title: approved_plan_version - format: int64 - description: |- - Optional durable task-plan authority. Both fields are set together; an - absent approved plan is represented by zero plus an empty hash. - approvedPlanContentHash: - type: string - title: approved_plan_content_hash - maxLength: 128 - requiredInitialToolIntent: - title: required_initial_tool_intent - description: |- - Canonical, non-secret required call persisted before Platform invokes the - remote ToolExecution owner. Short-lived staff grants are minted only by - the claiming worker and never enter this dispatch. - $ref: '#/components/schemas/console.v1.OperatingRequiredInitialToolIntent' - internalSkillAccessAllowed: - type: boolean - title: internal_skill_access_allowed - description: |- - Platform-accepted visibility for internal installed skill content. This - is persisted for exact replay and grants no staff, tool, or approval - authority. - managedInference: - title: managed_inference - description: |- - Exact Platform-selected managed LLM authority. Hosted Maestro dispatches - fail closed when this is absent or malformed; Runner Host adds the - ephemeral per-turn signature using its existing signing boundary. - $ref: '#/components/schemas/console.v1.OperatingManagedInferenceScope' - objectiveId: - type: string - title: objective_id - maxLength: 256 - description: |- - The canonical customer Job identity. Operating chat admits WorkKind - OBJECTIVE rows, so this equals work_id and survives every runtime attempt. - Empty only on legacy dispatches created before this additive field. - Field 25 leaves field 24 reserved for managed inference authority. - codingAcceptance: - title: coding_acceptance - description: Exact Platform-admitted coding requirements, carried unchanged on replay. - $ref: '#/components/schemas/console.v1.CodingAcceptanceContract' - taskEnvironment: - title: task_environment - description: Server-derived task coordinates, independent of whether a computer is allocated. - $ref: '#/components/schemas/console.v1.OperatingTaskEnvironmentBinding' - actorId: - type: string - title: actor_id - minLength: 1 - description: Authenticated actor whose tenant-scoped task binding admitted this dispatch. - workEnvelope: - title: work_envelope - description: |- - Provider-neutral object identity retained from the admitted surface. It - groups retries and follow-ups by durable provider object without granting - any tool or connector authority. - $ref: '#/components/schemas/agentruntime.v1.RuntimeWorkEnvelope' - surfaceContext: - title: surface_context - description: |- - Bounded, edge-authenticated provider context retained with the dispatch - and sent to Maestro on every replay. It contains provenance-bearing - surface snapshots, never provider credentials. - $ref: '#/components/schemas/google.protobuf.Struct' - title: OperatingRunDispatch - required: - - enqueuedAt - additionalProperties: false - description: |- - OperatingRunDispatch is the durable worker handoff for one submitted - operating turn. It carries stable row identities so workers can reload the - canonical Console message from Postgres. Authorized attachment mounts are - materialized here as stable VFS identities so the queued worker can hydrate - the same versions without copying attachment contents into work metadata. - console.v1.OperatingSkill: - type: object - properties: - id: - type: string - title: id - workspaceId: - type: string - title: workspace_id - minLength: 1 - name: - type: string - title: name - minLength: 1 - description: - type: string - title: description - body: - type: string - title: body - version: - type: integer - title: version - format: int32 - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - organizationId: - type: string - title: organization_id - minLength: 1 - catalogSkillId: - type: string - title: catalog_skill_id - description: |- - Catalog provenance is present only when the workspace skill was installed - from BrowseDexSkillCatalog. It lets clients keep attribution visible after - the skill moves from the library into the installed workspace list. - catalogVersion: - type: integer - title: catalog_version - format: int32 - analysis: - title: analysis - description: |- - Deterministic analysis of the exact stored description and body. Content - findings are advisory and never authorize, block, or route behavior. - $ref: '#/components/schemas/console.v1.SkillAnalysisReport' - sourceRevision: - type: string - title: source_revision - packageDigest: - type: string - title: package_digest - packageManifest: - type: array - items: - $ref: '#/components/schemas/console.v1.DexSkillPackageFile' - title: package_manifest - activationTrigger: - type: string - title: activation_trigger - objective: - type: string - title: objective - inputs: - type: array - items: - $ref: '#/components/schemas/console.v1.DexSkillInputDeclaration' - title: inputs - outputs: - type: array - items: - $ref: '#/components/schemas/console.v1.DexSkillOutputDeclaration' - title: outputs - orderedMethod: - type: array - items: - type: string - title: ordered_method - successCriteria: - type: array - items: - type: string - title: success_criteria - unavailableBehavior: - type: string - title: unavailable_behavior - outputContract: - type: string - title: output_contract - licenseEvidence: - title: license_evidence - $ref: '#/components/schemas/console.v1.DexSkillLicenseEvidence' - compatibility: - title: compatibility - $ref: '#/components/schemas/console.v1.DexSkillCompatibility' - qualityEvidence: - title: quality_evidence - $ref: '#/components/schemas/console.v1.DexSkillQualityEvidence' - lifecycleState: - title: lifecycle_state - $ref: '#/components/schemas/console.v1.DexSkillLifecycleState' - customerSafeRemediation: - type: string - title: customer_safe_remediation - updateDiff: - title: update_diff - $ref: '#/components/schemas/console.v1.DexSkillUpdateDiff' - requiredTools: - type: array - items: - type: string - title: required_tools - title: OperatingSkill - additionalProperties: false - description: |- - OperatingSkill is a workspace-scoped named procedure Dex can discover and - load at runtime (see docs on the operating_skills table). name is unique - per workspace and kebab-case; description is a single line shown in - listings; body is the markdown procedure text. - console.v1.OperatingSurfaceMetadata: - type: object - properties: - kind: - title: kind - $ref: '#/components/schemas/console.v1.OperatingSurfaceKind' - providerId: - type: string - title: provider_id - connectionId: - type: string - title: connection_id - providerWorkspaceId: - type: string - title: provider_workspace_id - providerChannelId: - type: string - title: provider_channel_id - providerThreadId: - type: string - title: provider_thread_id - bindingKind: - type: string - title: binding_kind - title: OperatingSurfaceMetadata - additionalProperties: false - description: |- - OperatingSurfaceMetadata is the credential-free origin and continuation - target for one canonical operating conversation. Provider coordinates are - always returned inside the already-authorized tenant scope. - console.v1.OperatingTaskEnvironmentBinding: - type: object - properties: - actorId: - type: string - title: actor_id - minLength: 1 - taskId: - type: string - title: task_id - minLength: 1 - homeKey: - type: string - title: home_key - minLength: 1 - workspaceDir: - type: string - title: workspace_dir - minLength: 1 - retentionDays: - type: integer - title: retention_days - format: int32 - enum: - - 0 - - 7 - - 30 - description: Workspace/project policy accepted once for this turn. - policyRevision: - type: - - integer - - string - title: policy_revision - minimum: 1 - format: int64 - projectSource: - title: project_source - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionProjectSource' - channelId: - type: string - title: channel_id - minLength: 1 - description: Authenticated operating channel that admitted this task binding. - retentionHours: - type: integer - title: retention_hours - format: int32 - enum: - - 0 - - 8 - - 168 - - 720 - workspaceRecipe: - title: workspace_recipe - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionWorkspaceRecipe' - title: OperatingTaskEnvironmentBinding - additionalProperties: false - description: Immutable task identity admitted from authenticated actor and tenant/channel scope. - console.v1.OperatingTaskEnvironmentStage: - type: object - properties: - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/console.v1.OperatingTaskEnvironmentStageKind' - state: - not: - enum: - - 0 - title: state - $ref: '#/components/schemas/console.v1.OperatingTaskEnvironmentStageState' - code: - type: string - title: code - maxLength: 128 - title: OperatingTaskEnvironmentStage - additionalProperties: false - console.v1.OperatingThreadEvent: - type: object - properties: - cursor: - exclusiveMinimum: 0 - type: - - integer - - string - title: cursor - format: int64 - eventId: - type: string - title: event_id - turnId: - type: string - title: turn_id - kind: - title: kind - $ref: '#/components/schemas/console.v1.OperatingThreadEventKind' - safeText: - type: string - title: safe_text - maxLength: 4096 - artifactRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: artifact_refs - maxItems: 32 - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - executionIdentity: - title: execution_identity - $ref: '#/components/schemas/console.v1.OperatingExecutionIdentity' - requestId: - type: string - title: request_id - maxLength: 256 - requestType: - title: request_type - $ref: '#/components/schemas/console.v1.OperatingThreadRequestType' - requestTool: - type: string - title: request_tool - maxLength: 256 - requestCallId: - type: string - title: request_call_id - maxLength: 256 - terminalError: - title: terminal_error - $ref: '#/components/schemas/console.v1.TerminalErrorEnvelope' - title: OperatingThreadEvent - additionalProperties: false - description: |- - OperatingThreadEvent is an append-only, browser-safe execution projection. - Raw prompts, tool arguments/results, and infrastructure coordinates are not - valid event fields. - console.v1.OperatingThreadExecution: - type: object - properties: - threadId: - type: string - title: thread_id - state: - title: state - $ref: '#/components/schemas/console.v1.OperatingThreadExecutionState' - activeTurnSequence: - type: - - integer - - string - title: active_turn_sequence - format: int64 - replayCursor: - type: - - integer - - string - title: replay_cursor - format: int64 - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - executionIdentity: - title: execution_identity - $ref: '#/components/schemas/console.v1.OperatingExecutionIdentity' - terminalTurnSequence: - type: - - integer - - string - title: terminal_turn_sequence - format: int64 - description: |- - The terminal turn that established the current ready/degraded state. A - non-zero marker lets clients distinguish an owner terminal projection - from an older provisioning snapshot without inspecting message copy. - controllerOwner: - type: string - title: controller_owner - maxLength: 64 - controllerLeaseGeneration: - type: - - integer - - string - title: controller_lease_generation - format: int64 - title: OperatingThreadExecution - additionalProperties: false - description: |- - OperatingThreadExecution is the user-safe projection of one durable Dex - thread. Runner, Pod, service, certificate, and cluster coordinates are - intentionally absent. - console.v1.OperatingThreadFork: - type: object - properties: - sourceChannelId: - type: string - title: source_channel_id - throughMessageId: - type: string - title: through_message_id - description: The last source message copied into the fork. - sourceConversationRevision: - type: - - integer - - string - title: source_conversation_revision - format: int64 - description: |- - The source's conversation_revision at the moment of the fork. Together - with through_message_id this names exactly what was copied. - forkedByPrincipalId: - type: string - title: forked_by_principal_id - forkedAt: - title: forked_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - copiedMessageCount: - type: integer - title: copied_message_count - format: int32 - title: OperatingThreadFork - additionalProperties: false - description: |- - Where a forked operating thread came from. - - A fork copies conversation content and nothing else. It does not inherit - the source's pinned model selection, its Auto route, its receipts, its - attachments, or its turn records, because each of those carries authority - that was granted to the source thread's principal rather than to whoever - forked it. The fork re-resolves all of them under the forking principal. - console.v1.OperatingThreadResponse: - type: object - properties: - requestId: - type: string - title: request_id - maxLength: 256 - minLength: 1 - callId: - type: string - title: call_id - maxLength: 256 - requestType: - title: request_type - $ref: '#/components/schemas/console.v1.OperatingThreadRequestType' - action: - title: action - $ref: '#/components/schemas/console.v1.OperatingThreadResponseAction' - text: - type: string - title: text - maxLength: 65536 - isError: - type: boolean - title: is_error - idempotencyKey: - type: string - title: idempotency_key - maxLength: 512 - title: OperatingThreadResponse - additionalProperties: false - console.v1.OperatingThreadTurn: - type: object - properties: - turnId: - type: string - title: turn_id - sequence: - exclusiveMinimum: 0 - type: - - integer - - string - title: sequence - format: int64 - userMessageId: - type: string - title: user_message_id - assistantMessageId: - type: string - title: assistant_message_id - state: - title: state - $ref: '#/components/schemas/console.v1.OperatingTurnState' - waitingReason: - title: waiting_reason - $ref: '#/components/schemas/console.v1.OperatingThreadWaitingReason' - firstCursor: - type: - - integer - - string - title: first_cursor - format: int64 - lastCursor: - type: - - integer - - string - title: last_cursor - format: int64 - errorCode: - type: string - title: error_code - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - completedAt: - title: completed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - terminalError: - title: terminal_error - $ref: '#/components/schemas/console.v1.TerminalErrorEnvelope' - title: OperatingThreadTurn - additionalProperties: false - console.v1.OperatingToolEvent: - type: object - properties: - callId: - type: string - title: call_id - toolName: - type: string - title: tool_name - status: - type: string - title: status - receiptId: - type: string - title: receipt_id - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - title: OperatingToolEvent - additionalProperties: false - console.v1.OperatingTurnRecord: - type: object - properties: - sessionId: - type: string - title: session_id - turnId: - type: string - title: turn_id - sequence: - type: - - integer - - string - title: sequence - format: int64 - goal: - type: string - title: goal - maxLength: 2000 - contextDigestSha256: - type: string - title: context_digest_sha256 - state: - title: state - $ref: '#/components/schemas/console.v1.OperatingTurnState' - verificationState: - title: verification_state - $ref: '#/components/schemas/console.v1.OperatingVerificationState' - toolEvents: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingToolEvent' - title: tool_events - maxItems: 64 - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - maxItems: 64 - errorCode: - type: string - title: error_code - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - answerProvenance: - title: answer_provenance - $ref: '#/components/schemas/console.v1.OperatingAnswerProvenance' - contextId: - type: string - title: context_id - maxLength: 256 - description: context_id groups independently addressable tasks in one conversation. - taskId: - type: string - title: task_id - maxLength: 256 - description: task_id remains stable while a user refines, corrects, or resumes work. - taskRevision: - type: - - integer - - string - title: task_revision - format: int64 - referenceTaskIds: - type: array - items: - type: string - maxLength: 256 - minLength: 1 - maxItems: 16 - title: reference_task_ids - maxItems: 16 - artifactIntentKind: - type: string - title: artifact_intent_kind - maxLength: 32 - description: |- - Server-owned artifact intent carried from a clarification into its next - turn. This is safe routing metadata, not model content or tool arguments. - customerOutcomeIdentity: - title: customer_outcome_identity - description: |- - Server-owned identity for the privacy-bounded customer-outcome study. - This is safe routing/evidence metadata only; it must never contain raw - prompts, outputs, customer identifiers, credentials, or tool payloads. - $ref: '#/components/schemas/console.v1.OperatingCustomerOutcomeIdentity' - projectSource: - title: project_source - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionProjectSource' - workspaceRecipe: - title: workspace_recipe - description: Accepted once with the task and replayed unchanged. - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionWorkspaceRecipe' - codingAcceptance: - title: coding_acceptance - description: |- - Exact coding requirements accepted on the first task revision. Later - revisions must match this value rather than re-running current selector - policy. Absence is meaningful for an admitted non-coding task. - $ref: '#/components/schemas/console.v1.CodingAcceptanceContract' - workspaceRecipeAdmissionVersion: - type: integer - title: workspace_recipe_admission_version - format: int32 - description: |- - Marks records admitted by the immutable workspace-recipe contract. - Zero identifies legacy records whose absent recipe/contract must replay - without reinterpretation. - title: OperatingTurnRecord - additionalProperties: false - console.v1.OperatingTurnRoute: - type: object - properties: - kind: - title: kind - $ref: '#/components/schemas/console.v1.OperatingTurnRouteKind' - intentKind: - title: intent_kind - $ref: '#/components/schemas/console.v1.OperatingTurnIntentKind' - answerKind: - title: answer_kind - $ref: '#/components/schemas/console.v1.OperatingTurnAnswerKind' - safetyKind: - title: safety_kind - $ref: '#/components/schemas/console.v1.OperatingTurnSafetyKind' - router: - type: string - title: router - decidedAt: - title: decided_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: OperatingTurnRoute - additionalProperties: false - description: |- - OperatingTurnRoute is backend-owned routing metadata for a chat turn. Clients - must use this typed contract instead of deriving behavior from prompt text or - assistant copy. - console.v1.OperatorModelPreference: - type: object - properties: - provider: - type: string - title: provider - maxLength: 128 - minLength: 1 - model: - type: string - title: model - maxLength: 256 - minLength: 1 - favorite: - type: boolean - title: favorite - hidden: - type: boolean - title: hidden - title: OperatorModelPreference - additionalProperties: false - description: Personal model browsing choices; these never grant access to a model. - console.v1.OperatorModelPreferenceUpdate: - type: object - properties: - provider: - type: string - title: provider - maxLength: 128 - minLength: 1 - model: - type: string - title: model - maxLength: 256 - minLength: 1 - favorite: - type: boolean - title: favorite - nullable: true - hidden: - type: boolean - title: hidden - nullable: true - title: OperatorModelPreferenceUpdate - additionalProperties: false - console.v1.OperatorPreferences: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - dexHatId: - type: string - title: dex_hat_id - minLength: 1 - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - developerModeEnabled: - type: boolean - title: developer_mode_enabled - modelPreferences: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatorModelPreference' - title: model_preferences - title: OperatorPreferences - additionalProperties: false - console.v1.OrbControlTarget: - type: object - properties: - id: - type: string - title: id - displayName: - type: string - title: display_name - lifecycle: - title: lifecycle - $ref: '#/components/schemas/orbcontrol.v1.OrbObservedLifecycle' - generation: - type: - - integer - - string - title: generation - format: int64 - observedRevision: - type: - - integer - - string - title: observed_revision - format: int64 - lastEventSequence: - type: - - integer - - string - title: last_event_sequence - format: int64 - residentAgent: - type: string - title: resident_agent - provisioner: - type: string - title: provisioner - ownerStatus: - type: string - title: owner_status - observedAt: - title: observed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - allowedActions: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingReceiptAction' - title: allowed_actions - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.OperatingReceipt' - title: OrbControlTarget - additionalProperties: false - description: OrbControlTarget is the Platform-owned customer-facing runtime projection. - console.v1.PauseComputerMissionRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - missionId: - type: string - title: mission_id - minLength: 1 - expectedGeneration: - type: - - integer - - string - title: expected_generation - format: int64 - reason: - type: string - title: reason - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - condition: - title: condition - $ref: '#/components/schemas/google.protobuf.Struct' - wakeAt: - title: wake_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: PauseComputerMissionRequest - required: - - query - additionalProperties: false - console.v1.PauseComputerMissionResponse: - type: object - properties: - mission: - title: mission - $ref: '#/components/schemas/console.v1.ComputerMission' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.OperatingReceipt' - wakeId: - type: string - title: wake_id - minLength: 1 - title: PauseComputerMissionResponse - required: - - mission - - receipt - additionalProperties: false - console.v1.PinnedSource: - type: object - properties: - sourceId: - type: string - title: source_id - pinnedAt: - title: pinned_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - pinnedBy: - type: string - title: pinned_by - title: PinnedSource - additionalProperties: false - console.v1.PrepareBusinessObjectAuthorityTransferRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - objectId: - type: string - title: object_id - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - authorityEpoch: - type: - - integer - - string - title: authority_epoch - format: int64 - title: PrepareBusinessObjectAuthorityTransferRequest - additionalProperties: false - console.v1.PrepareBusinessObjectAuthorityTransferResponse: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/console.v1.BusinessObject' - ready: - type: boolean - title: ready - unavailableReason: - type: string - title: unavailable_reason - title: PrepareBusinessObjectAuthorityTransferResponse - additionalProperties: false - console.v1.PrepareStaffProductIssueRecoveryRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - maxLength: 4000 - workspaceId: - type: string - title: workspace_id - maxLength: 4000 - sourceOrganizationId: - type: string - title: source_organization_id - maxLength: 4000 - sourceWorkspaceId: - type: string - title: source_workspace_id - maxLength: 4000 - reportId: - type: string - title: report_id - maxLength: 4000 - errorCode: - type: string - title: error_code - maxLength: 4000 - startUnixSeconds: - type: - - integer - - string - title: start_unix_seconds - format: int64 - endUnixSeconds: - type: - - integer - - string - title: end_unix_seconds - format: int64 - recipientPrincipalId: - type: string - title: recipient_principal_id - maxLength: 4000 - customerSummary: - type: string - title: customer_summary - maxLength: 4000 - deploymentVerification: - type: string - title: deployment_verification - maxLength: 4000 - title: PrepareStaffProductIssueRecoveryRequest - additionalProperties: false - description: Durable, explicitly scoped customer recovery contract. - console.v1.PrewarmOperatingThreadRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - maxLength: 256 - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 512 - minLength: 1 - model: - type: string - title: model - maxLength: 256 - organizationId: - type: string - title: organization_id - maxLength: 256 - workspaceId: - type: string - title: workspace_id - maxLength: 256 - title: PrewarmOperatingThreadRequest - required: - - query - additionalProperties: false - console.v1.PrewarmOperatingThreadResponse: - type: object - properties: - channelId: - type: string - title: channel_id - prewarmId: - type: string - title: prewarm_id - maestroSessionId: - type: string - title: maestro_session_id - runnerSessionId: - type: string - title: runner_session_id - runnerState: - type: string - title: runner_state - attachable: - type: boolean - title: attachable - replayed: - type: boolean - title: replayed - prewarmHit: - type: boolean - title: prewarm_hit - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - threadId: - type: string - title: thread_id - replenishmentBlocked: - type: boolean - title: replenishment_blocked - description: |- - True when a different requested draft was held behind the consumed - first turn. The response still identifies the durable existing thread so - the client can remain writable without silently minting another runner. - title: PrewarmOperatingThreadResponse - additionalProperties: false - console.v1.PrivateEndpoint: - type: object - properties: - endpointId: - type: string - title: endpoint_id - minLength: 1 - provider: - type: string - title: provider - minLength: 1 - endpointUri: - type: string - title: endpoint_uri - minLength: 1 - serviceName: - type: string - title: service_name - minLength: 1 - region: - type: string - title: region - minLength: 1 - dnsName: - type: string - title: dns_name - minLength: 1 - relayId: - type: string - title: relay_id - state: - type: string - title: state - minLength: 1 - healthState: - type: string - title: health_state - minLength: 1 - routeRevision: - type: - - integer - - string - title: route_revision - format: int64 - routeIdentity: - type: string - title: route_identity - minLength: 1 - verifiedEvidenceId: - type: string - title: verified_evidence_id - revocationReason: - type: string - title: revocation_reason - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - revokedAt: - title: revoked_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: PrivateEndpoint - additionalProperties: false - console.v1.PrivateProfileRoute: - type: object - properties: - profileId: - type: string - title: profile_id - minLength: 1 - endpointId: - type: string - title: endpoint_id - routeMode: - type: string - title: route_mode - minLength: 1 - requirePrivate: - type: boolean - title: require_private - routeRevision: - type: - - integer - - string - title: route_revision - format: int64 - state: - type: string - title: state - minLength: 1 - routeIdentity: - type: string - title: route_identity - routeOrigin: - type: string - title: route_origin - privateRoute: - type: boolean - title: private_route - title: PrivateProfileRoute - additionalProperties: false - console.v1.ProductIssueRecovery: - type: object - properties: - organizationId: - type: string - title: organization_id - maxLength: 4000 - workspaceId: - type: string - title: workspace_id - maxLength: 4000 - recoveryId: - type: string - title: recovery_id - maxLength: 4000 - reportReference: - type: string - title: report_reference - maxLength: 4000 - recipientPrincipalId: - type: string - title: recipient_principal_id - maxLength: 4000 - customerSummary: - type: string - title: customer_summary - maxLength: 4000 - state: - type: string - title: state - maxLength: 4000 - revision: - type: - - integer - - string - title: revision - format: int64 - affectedRequestCount: - type: - - integer - - string - title: affected_request_count - format: int64 - expectedCreditMicros: - type: - - integer - - string - title: expected_credit_micros - format: int64 - compensatedMicros: - type: - - integer - - string - title: compensated_micros - format: int64 - remainingRequestCount: - type: - - integer - - string - title: remaining_request_count - format: int64 - notificationId: - type: string - title: notification_id - maxLength: 4000 - lastReply: - type: string - title: last_reply - maxLength: 4000 - coverage: - type: string - title: coverage - maxLength: 4000 - deploymentVerification: - type: string - title: deployment_verification - maxLength: 4000 - title: ProductIssueRecovery - additionalProperties: false - description: Durable, explicitly scoped customer recovery contract. - console.v1.ProductIssueRecoveryResponse: - type: object - properties: - recovery: - title: recovery - $ref: '#/components/schemas/console.v1.ProductIssueRecovery' - title: ProductIssueRecoveryResponse - additionalProperties: false - description: Durable, explicitly scoped customer recovery contract. - console.v1.ProductIssueReport: - type: object - properties: - id: - type: string - title: id - reference: - type: string - title: reference - diagnosticsIncluded: - type: boolean - title: diagnostics_included - screenshotAttached: - type: boolean - title: screenshot_attached - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: ProductIssueReport - additionalProperties: false - console.v1.ProductIssueReportContext: - type: object - properties: - reproductionSteps: - type: string - title: reproduction_steps - maxLength: 4000 - model: - type: string - title: model - maxLength: 256 - evidence: - type: array - items: - $ref: '#/components/schemas/console.v1.ProductIssueReportEvidence' - title: evidence - maxItems: 10 - title: ProductIssueReportContext - additionalProperties: false - description: Explicitly selected native evidence. No session or machine-wide collection. - console.v1.ProductIssueReportEvidence: - type: object - properties: - kind: - type: string - title: kind - maxLength: 32 - sourceId: - type: string - title: source_id - maxLength: 256 - text: - type: string - title: text - maxLength: 4000 - title: ProductIssueReportEvidence - additionalProperties: false - console.v1.ProjectTaskEnvironmentRetention: - type: object - properties: - projectResourceId: - type: string - title: project_resource_id - minLength: 1 - retentionDays: - type: integer - title: retention_days - format: int32 - enum: - - 0 - - 7 - - 30 - description: Absent means inherit the workspace default. - nullable: true - retentionHours: - type: integer - title: retention_hours - format: int32 - enum: - - 8 - - 168 - - 720 - description: Preferred hour-level policy. Zero means the legacy retention_days field. - nullable: true - title: ProjectTaskEnvironmentRetention - additionalProperties: false - description: Project identity is an existing tenant-scoped Platform repository resource. - console.v1.PromoteScenarioFixtureRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - name: - type: string - title: name - minLength: 1 - scenarioJson: - type: string - title: scenario_json - minLength: 1 - recordedFromSessionId: - type: string - title: recorded_from_session_id - originalModel: - type: string - title: original_model - retentionPolicy: - type: string - title: retention_policy - tags: - type: array - items: - type: string - title: tags - title: PromoteScenarioFixtureRequest - additionalProperties: false - console.v1.PromoteScenarioFixtureResponse: - type: object - properties: - fixture: - title: fixture - $ref: '#/components/schemas/console.v1.ScenarioFixture' - title: PromoteScenarioFixtureResponse - additionalProperties: false - console.v1.ProposeCustomerIntelligenceFactRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - externalFactId: - type: string - title: external_fact_id - maxLength: 256 - subjectKind: - not: - enum: - - 0 - title: subject_kind - $ref: '#/components/schemas/console.v1.CustomerIntelligenceSubjectKind' - subjectRef: - type: string - title: subject_ref - maxLength: 256 - minLength: 1 - productArea: - type: string - title: product_area - maxLength: 80 - minLength: 1 - journey: - type: string - title: journey - maxLength: 80 - minLength: 1 - predicate: - type: string - title: predicate - maxLength: 120 - minLength: 1 - safeSummary: - type: string - title: safe_summary - maxLength: 280 - minLength: 1 - authority: - title: authority - enum: - - CUSTOMER_INTELLIGENCE_AUTHORITY_INFERRED - - CUSTOMER_INTELLIGENCE_AUTHORITY_CORROBORATED - $ref: '#/components/schemas/console.v1.CustomerIntelligenceAuthority' - confidenceMicros: - type: integer - title: confidence_micros - maximum: 1000000 - format: int32 - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.CustomerIntelligenceEvidenceRef' - title: evidence_refs - maxItems: 64 - minItems: 1 - producerKind: - title: producer_kind - enum: - - CUSTOMER_INTELLIGENCE_PRODUCER_KIND_PLATFORM_DETERMINISTIC_FEEDBACK - - CUSTOMER_INTELLIGENCE_PRODUCER_KIND_CEREBRO - $ref: '#/components/schemas/console.v1.CustomerIntelligenceProducerKind' - producerRef: - type: string - title: producer_ref - minLength: 1 - modelId: - type: string - title: model_id - maxLength: 160 - runId: - type: string - title: run_id - maxLength: 256 - policyVersion: - type: string - title: policy_version - minLength: 1 - lineageId: - type: string - title: lineage_id - minLength: 1 - retentionClass: - type: string - title: retention_class - minLength: 1 - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: ProposeCustomerIntelligenceFactRequest - required: - - query - additionalProperties: false - console.v1.ProposeCustomerIntelligenceFactResponse: - type: object - properties: - fact: - title: fact - $ref: '#/components/schemas/console.v1.CustomerIntelligenceFact' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.CustomerIntelligenceReceipt' - title: ProposeCustomerIntelligenceFactResponse - required: - - fact - - receipt - additionalProperties: false - console.v1.ProspectingDraft: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - draftId: - type: string - title: draft_id - minLength: 1 - candidateId: - type: string - title: candidate_id - maxLength: 128 - minLength: 1 - targetAccount: - title: target_account - $ref: '#/components/schemas/console.v1.ProspectingDraftTargetAccount' - channel: - title: channel - $ref: '#/components/schemas/console.v1.ProspectingDraftChannel' - tone: - title: tone - $ref: '#/components/schemas/console.v1.ProspectingDraftTone' - evidenceIds: - type: array - items: - type: string - maxItems: 50 - title: evidence_ids - maxItems: 50 - minItems: 1 - contentDigestSha256: - type: string - title: content_digest_sha256 - pattern: ^[0-9a-f]{64}$ - reviewState: - title: review_state - $ref: '#/components/schemas/console.v1.ProspectingDraftReviewState' - reviewerPrincipalId: - type: string - title: reviewer_principal_id - maxLength: 256 - reason: - type: string - title: reason - maxLength: 512 - minLength: 1 - revision: - exclusiveMinimum: 0 - type: - - integer - - string - title: revision - format: int64 - createdByPrincipalId: - type: string - title: created_by_principal_id - minLength: 1 - updatedByPrincipalId: - type: string - title: updated_by_principal_id - minLength: 1 - auditReceiptId: - type: string - title: audit_receipt_id - minLength: 1 - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: ProspectingDraft - required: - - targetAccount - - createdAt - - updatedAt - additionalProperties: false - description: |- - ProspectingDraft is a Console-owned outreach draft held for staff review. - - It carries no generator lineage and no extracted claims. Nothing has - generated this content, so those remain the generating owner's facts to - record when an agent runtime produces a draft. An approval is a review - decision and never delivery authority. - console.v1.ProspectingDraftMutationReceipt: - type: object - properties: - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - requestDigestSha256: - type: string - title: request_digest_sha256 - pattern: ^[0-9a-f]{64}$ - revision: - exclusiveMinimum: 0 - type: - - integer - - string - title: revision - format: int64 - auditReceiptId: - type: string - title: audit_receipt_id - minLength: 1 - replayed: - type: boolean - title: replayed - title: ProspectingDraftMutationReceipt - additionalProperties: false - description: |- - ProspectingDraftMutationReceipt identifies the accepted draft mutation and - whether this response is an exact idempotent replay. - console.v1.ProspectingDraftTargetAccount: - type: object - properties: - accountOrganizationId: - type: string - title: account_organization_id - minLength: 1 - accountWorkspaceId: - type: string - title: account_workspace_id - maxLength: 256 - identityRevision: - type: string - title: identity_revision - maxLength: 128 - minLength: 1 - accessGrantId: - type: string - title: access_grant_id - maxLength: 256 - title: ProspectingDraftTargetAccount - additionalProperties: false - description: |- - ProspectingDraftTargetAccount is the exact Identity-owned account the draft - is bound to. Radar supplies it; Console stores it verbatim and never derives - tenant scope from it. - console.v1.ProspectingWatchProgram: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - watchProgramId: - type: string - title: watch_program_id - minLength: 1 - name: - type: string - title: name - maxLength: 128 - minLength: 1 - config: - title: config - $ref: '#/components/schemas/google.protobuf.Struct' - scoringRuleRevision: - type: string - title: scoring_rule_revision - maxLength: 128 - minLength: 1 - lifecycle: - title: lifecycle - $ref: '#/components/schemas/console.v1.ProspectingWatchProgramLifecycle' - revision: - exclusiveMinimum: 0 - type: - - integer - - string - title: revision - format: int64 - createdByPrincipalId: - type: string - title: created_by_principal_id - minLength: 1 - updatedByPrincipalId: - type: string - title: updated_by_principal_id - minLength: 1 - reason: - type: string - title: reason - maxLength: 512 - minLength: 1 - auditReceiptId: - type: string - title: audit_receipt_id - minLength: 1 - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: ProspectingWatchProgram - required: - - config - - createdAt - - updatedAt - additionalProperties: false - description: |- - ProspectingWatchProgram is the current Console-owned Radar configuration. - It carries no Identity account, candidate, run, relationship, event, or - draft projection. - console.v1.ProspectingWatchProgramMutationReceipt: - type: object - properties: - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - requestDigestSha256: - type: string - title: request_digest_sha256 - pattern: ^[0-9a-f]{64}$ - revision: - exclusiveMinimum: 0 - type: - - integer - - string - title: revision - format: int64 - auditReceiptId: - type: string - title: audit_receipt_id - minLength: 1 - replayed: - type: boolean - title: replayed - title: ProspectingWatchProgramMutationReceipt - additionalProperties: false - description: |- - ProspectingWatchProgramMutationReceipt identifies the accepted mutation and - whether this response is an exact idempotent replay. - console.v1.PublishCaptureFormRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - formId: - type: string - title: form_id - minLength: 1 - versionId: - type: string - title: version_id - minLength: 1 - publication: - title: publication - $ref: '#/components/schemas/console.v1.CaptureFormPublicationInput' - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - title: PublishCaptureFormRequest - required: - - publication - additionalProperties: false - console.v1.PublishCaptureFormResponse: - type: object - properties: - form: - title: form - $ref: '#/components/schemas/console.v1.CaptureForm' - version: - title: version - $ref: '#/components/schemas/console.v1.CaptureFormVersion' - publication: - title: publication - $ref: '#/components/schemas/console.v1.CaptureFormPublication' - title: PublishCaptureFormResponse - required: - - form - - version - - publication - additionalProperties: false - console.v1.PublishedCaptureForm: - type: object - properties: - publicationId: - type: string - title: publication_id - minLength: 1 - formId: - type: string - title: form_id - minLength: 1 - versionId: - type: string - title: version_id - minLength: 1 - versionRevision: - exclusiveMinimum: 0 - type: - - integer - - string - title: version_revision - format: int64 - name: - type: string - title: name - maxLength: 160 - minLength: 1 - description: - type: string - title: description - maxLength: 2000 - branding: - title: branding - $ref: '#/components/schemas/console.v1.CaptureFormPublicBranding' - fields: - type: array - items: - $ref: '#/components/schemas/console.v1.CaptureFormPublicField' - title: fields - maxItems: 64 - route: - title: route - $ref: '#/components/schemas/console.v1.CaptureFormPublicRoute' - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: PublishedCaptureForm - additionalProperties: false - console.v1.PutWorkspaceKeyConfigRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - provider: - type: string - title: provider - minLength: 1 - keyArn: - type: string - title: key_arn - roleArn: - type: string - title: role_arn - externalId: - type: string - title: external_id - description: external_id is write-only and is sealed before durable storage. - title: PutWorkspaceKeyConfigRequest - additionalProperties: false - console.v1.ReauthorizeDexMcpOAuthProfileRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - serverId: - type: string - title: server_id - minLength: 1 - profileId: - type: string - title: profile_id - minLength: 1 - scopes: - type: array - items: - type: string - title: scopes - redirectUri: - type: string - title: redirect_uri - minLength: 1 - title: ReauthorizeDexMcpOAuthProfileRequest - required: - - query - additionalProperties: false - console.v1.ReauthorizeDexMcpOAuthProfileResponse: - type: object - properties: - profile: - title: profile - $ref: '#/components/schemas/console.v1.DexMcpOAuthProfile' - authorizeUrl: - type: string - title: authorize_url - state: - type: string - title: state - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - resourceMetadataUrl: - type: string - title: resource_metadata_url - authorizationServer: - type: string - title: authorization_server - clientId: - type: string - title: client_id - title: ReauthorizeDexMcpOAuthProfileResponse - required: - - profile - additionalProperties: false - console.v1.RecordComplianceAssessmentRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - profileId: - type: string - title: profile_id - subjectKind: - type: string - title: subject_kind - subjectId: - type: string - title: subject_id - idempotencyKey: - type: string - title: idempotency_key - title: RecordComplianceAssessmentRequest - additionalProperties: false - description: Records a server-evaluated snapshot. A replay key always returns its first accepted result. - console.v1.RecordComplianceAssessmentResponse: - type: object - properties: - record: - title: record - $ref: '#/components/schemas/console.v1.ComplianceAssessmentRecord' - idempotentReplay: - type: boolean - title: idempotent_replay - title: RecordComplianceAssessmentResponse - additionalProperties: false - console.v1.RecordOperatingHomepageSuggestionFeedbackRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - suggestionId: - type: string - title: suggestion_id - minLength: 1 - action: - not: - enum: - - 0 - title: action - $ref: '#/components/schemas/console.v1.OperatingHomepageSuggestionFeedbackAction' - title: RecordOperatingHomepageSuggestionFeedbackRequest - required: - - query - additionalProperties: false - description: |- - Declared at the end so this additive control does not renumber unrelated - generated message or enum descriptors in the large Console schema. - console.v1.RecordOperatingHomepageSuggestionFeedbackResponse: - type: object - properties: - changed: - type: boolean - title: changed - title: RecordOperatingHomepageSuggestionFeedbackResponse - additionalProperties: false - console.v1.RecordProviderCostSnapshotRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - connectionId: - type: string - title: connection_id - provider: - type: string - title: provider - resourceId: - type: string - title: resource_id - assetId: - type: string - title: asset_id - model: - type: string - title: model - spendMonthMicros: - type: - - integer - - string - title: spend_month_micros - format: int64 - spendTodayMicros: - type: - - integer - - string - title: spend_today_micros - format: int64 - period: - type: string - title: period - observedAt: - title: observed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - idempotencyKey: - type: string - title: idempotency_key - sourceUrl: - type: string - title: source_url - recordKind: - type: string - title: record_kind - description: Empty remains provider_monthly_snapshot for backwards compatibility. - inputTokens: - type: - - integer - - string - title: input_tokens - format: int64 - outputTokens: - type: - - integer - - string - title: output_tokens - format: int64 - requestCount: - type: - - integer - - string - title: request_count - format: int64 - upstreamProvider: - type: string - title: upstream_provider - description: |- - upstream_provider is the model provider selected behind a billing - gateway such as OpenRouter. Keep it separate from provider, which is the - source that owns the billing report. - provenance: - type: string - title: provenance - description: |- - provenance describes how the source can be joined to ledger events: - exact, aggregate, estimated, or unmatched. - title: RecordProviderCostSnapshotRequest - additionalProperties: false - console.v1.RecordProviderCostSnapshotResponse: - type: object - properties: - snapshotId: - type: string - title: snapshot_id - title: RecordProviderCostSnapshotResponse - additionalProperties: false - console.v1.RegisterPrivateEndpointRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - endpointId: - type: string - title: endpoint_id - minLength: 1 - provider: - type: string - title: provider - minLength: 1 - endpointUri: - type: string - title: endpoint_uri - minLength: 1 - serviceName: - type: string - title: service_name - minLength: 1 - region: - type: string - title: region - minLength: 1 - dnsName: - type: string - title: dns_name - minLength: 1 - relayId: - type: string - title: relay_id - title: RegisterPrivateEndpointRequest - required: - - query - additionalProperties: false - console.v1.RegisterPrivateEndpointResponse: - type: object - properties: - endpoint: - title: endpoint - $ref: '#/components/schemas/console.v1.PrivateEndpoint' - title: RegisterPrivateEndpointResponse - required: - - endpoint - additionalProperties: false - console.v1.RelatedResource: - type: object - properties: - id: - type: string - title: id - resourceType: - type: string - title: resource_type - label: - type: string - title: label - url: - type: string - title: url - title: RelatedResource - additionalProperties: false - console.v1.RemoveWorkspaceGuardrailRuleRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - id: - type: string - title: id - maxLength: 128 - minLength: 1 - title: RemoveWorkspaceGuardrailRuleRequest - required: - - query - additionalProperties: false - console.v1.RemoveWorkspaceIdentityProviderRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - id: - type: string - title: id - minLength: 1 - title: RemoveWorkspaceIdentityProviderRequest - required: - - query - additionalProperties: false - console.v1.RemoveWorkspaceIdentityProviderResponse: - type: object - properties: - settings: - title: settings - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - title: RemoveWorkspaceIdentityProviderResponse - required: - - settings - additionalProperties: false - console.v1.RemoveWorkspaceIntegrationRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - id: - type: string - title: id - minLength: 1 - title: RemoveWorkspaceIntegrationRequest - required: - - query - additionalProperties: false - console.v1.RemoveWorkspaceIntegrationResponse: - type: object - properties: - settings: - title: settings - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - title: RemoveWorkspaceIntegrationResponse - required: - - settings - additionalProperties: false - console.v1.RemoveWorkspaceMemberRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - subject: - type: string - title: subject - email: - type: string - title: email - title: RemoveWorkspaceMemberRequest - required: - - query - additionalProperties: false - console.v1.RenameOperatingThreadRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - minLength: 1 - title: - type: string - title: title - maxLength: 80 - minLength: 1 - title: RenameOperatingThreadRequest - required: - - query - additionalProperties: false - console.v1.RenameOperatingThreadResponse: - type: object - properties: - channel: - title: channel - $ref: '#/components/schemas/console.v1.OperatingChannel' - changed: - type: boolean - title: changed - title: RenameOperatingThreadResponse - required: - - channel - additionalProperties: false - console.v1.ReplyProductIssueRecoveryRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - recoveryId: - type: string - title: recovery_id - maxLength: 4000 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 4000 - message: - type: string - title: message - maxLength: 4000 - resolved: - type: boolean - title: resolved - title: ReplyProductIssueRecoveryRequest - additionalProperties: false - description: Durable, explicitly scoped customer recovery contract. - console.v1.ReserveComputerMissionApexSessionRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - packRunId: - type: string - title: pack_run_id - minLength: 1 - attemptId: - type: string - title: attempt_id - minLength: 1 - runIndex: - type: integer - title: run_index - decisionRef: - type: string - title: decision_ref - minLength: 1 - decisionDigestSha256: - type: string - title: decision_digest_sha256 - pattern: ^[0-9a-f]{64}$ - runnerProfile: - type: string - title: runner_profile - const: apex-agents-v1 - workloadDigest: - type: string - title: workload_digest - pattern: ^sha256:[0-9a-f]{64}$ - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - description: |- - The same key is used for reservation issuance and Runner Host create; bind - repeats it so Platform can reject a different physical create attempt. - title: ReserveComputerMissionApexSessionRequest - additionalProperties: false - console.v1.ReserveComputerMissionApexSessionResponse: - type: object - properties: - reservation: - title: reservation - $ref: '#/components/schemas/console.v1.ComputerMissionApexSessionReservation' - title: ReserveComputerMissionApexSessionResponse - required: - - reservation - additionalProperties: false - console.v1.ResolveOperatingFeedbackRemediationRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - feedbackId: - type: string - title: feedback_id - minLength: 1 - outcome: - title: outcome - enum: - - OPERATING_FEEDBACK_REMEDIATION_OUTCOME_ACCEPTED - - OPERATING_FEEDBACK_REMEDIATION_OUTCOME_REJECTED - $ref: '#/components/schemas/console.v1.OperatingFeedbackRemediationOutcome' - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: ResolveOperatingFeedbackRemediationRequest - required: - - query - additionalProperties: false - console.v1.ResolveOperatingFeedbackRemediationResponse: - type: object - properties: - feedback: - title: feedback - $ref: '#/components/schemas/console.v1.OperatingFeedback' - factReceipt: - title: fact_receipt - $ref: '#/components/schemas/console.v1.CustomerIntelligenceReceipt' - title: ResolveOperatingFeedbackRemediationResponse - required: - - feedback - additionalProperties: false - console.v1.ResolveOperatingReceiptActionRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - receiptId: - type: string - title: receipt_id - minLength: 1 - action: - title: action - $ref: '#/components/schemas/console.v1.OperatingReceiptAction' - idempotencyKey: - type: string - title: idempotency_key - title: ResolveOperatingReceiptActionRequest - required: - - query - - action - additionalProperties: false - console.v1.ResolveOperatingReceiptActionResponse: - type: object - properties: - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.OperatingReceipt' - capabilities: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingCapabilityState' - title: capabilities - title: ResolveOperatingReceiptActionResponse - additionalProperties: false - console.v1.RespondOperatingThreadRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - minLength: 1 - turnId: - type: string - title: turn_id - minLength: 1 - response: - title: response - $ref: '#/components/schemas/console.v1.OperatingThreadResponse' - idempotencyKey: - type: string - title: idempotency_key - maxLength: 512 - minLength: 1 - title: RespondOperatingThreadRequest - required: - - query - - response - additionalProperties: false - console.v1.RespondOperatingThreadResponse: - type: object - properties: - runtimeRunId: - type: string - title: runtime_run_id - replayed: - type: boolean - title: replayed - threadExecution: - title: thread_execution - $ref: '#/components/schemas/console.v1.OperatingThreadExecution' - turns: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingThreadTurn' - title: turns - replayCursor: - type: - - integer - - string - title: replay_cursor - format: int64 - title: RespondOperatingThreadResponse - additionalProperties: false - console.v1.RespondToCustomerFactConfirmationRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - confirmationIntentId: - type: string - title: confirmation_intent_id - minLength: 1 - response: - not: - enum: - - 0 - title: response - $ref: '#/components/schemas/console.v1.CustomerFactConfirmationResponse' - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: RespondToCustomerFactConfirmationRequest - required: - - query - additionalProperties: false - console.v1.RespondToCustomerFactConfirmationResponse: - type: object - properties: - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.CustomerIntelligenceReceipt' - title: RespondToCustomerFactConfirmationResponse - required: - - receipt - additionalProperties: false - console.v1.ResumeComputerMissionRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - missionId: - type: string - title: mission_id - minLength: 1 - expectedGeneration: - type: - - integer - - string - title: expected_generation - format: int64 - reason: - type: string - title: reason - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - condition: - title: condition - $ref: '#/components/schemas/google.protobuf.Struct' - wakeAt: - title: wake_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: ResumeComputerMissionRequest - required: - - query - additionalProperties: false - console.v1.ResumeComputerMissionResponse: - type: object - properties: - mission: - title: mission - $ref: '#/components/schemas/console.v1.ComputerMission' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.OperatingReceipt' - wakeId: - type: string - title: wake_id - minLength: 1 - title: ResumeComputerMissionResponse - required: - - mission - - receipt - additionalProperties: false - console.v1.ReviewCaptureFormSubmissionRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - submissionId: - type: string - title: submission_id - minLength: 1 - expectedRevision: - exclusiveMinimum: 0 - type: - - integer - - string - title: expected_revision - format: int64 - decision: - not: - enum: - - 0 - title: decision - $ref: '#/components/schemas/console.v1.CaptureFormReviewDecision' - note: - type: string - title: note - maxLength: 4000 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - supplementalValues: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessFieldValue' - title: supplemental_values - maxItems: 64 - description: |- - Native typed values for missing required BusinessObject fields. These are - validated against the publication's pinned schema and stored separately - from the original submission answers. - title: ReviewCaptureFormSubmissionRequest - additionalProperties: false - console.v1.ReviewCaptureFormSubmissionResponse: - type: object - properties: - submission: - title: submission - $ref: '#/components/schemas/console.v1.CaptureFormSubmission' - objectResult: - title: object_result - $ref: '#/components/schemas/console.v1.CaptureFormObjectResult' - title: ReviewCaptureFormSubmissionResponse - required: - - submission - additionalProperties: false - console.v1.ReviewCustomerIntelligenceFactRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - factId: - type: string - title: fact_id - minLength: 1 - expectedRevision: - exclusiveMinimum: 0 - type: - - integer - - string - title: expected_revision - format: int64 - decision: - not: - enum: - - 0 - title: decision - $ref: '#/components/schemas/console.v1.CustomerIntelligenceReviewDecision' - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.CustomerIntelligenceEvidenceRef' - title: evidence_refs - maxItems: 64 - replacementSafeSummary: - type: string - title: replacement_safe_summary - maxLength: 280 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: ReviewCustomerIntelligenceFactRequest - required: - - query - additionalProperties: false - console.v1.ReviewCustomerIntelligenceFactResponse: - type: object - properties: - fact: - title: fact - $ref: '#/components/schemas/console.v1.CustomerIntelligenceFact' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.CustomerIntelligenceReceipt' - title: ReviewCustomerIntelligenceFactResponse - required: - - fact - - receipt - additionalProperties: false - console.v1.ReviewOperatingCorrectionRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - correctionId: - type: string - title: correction_id - minLength: 1 - decision: - title: decision - enum: - - OPERATING_CORRECTION_REVIEW_STATE_APPROVED - - OPERATING_CORRECTION_REVIEW_STATE_REJECTED - $ref: '#/components/schemas/console.v1.OperatingCorrectionReviewState' - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - maxItems: 64 - minItems: 1 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: ReviewOperatingCorrectionRequest - required: - - query - additionalProperties: false - console.v1.ReviewOperatingCorrectionResponse: - type: object - properties: - correction: - title: correction - $ref: '#/components/schemas/console.v1.OperatingCorrectionCandidate' - title: ReviewOperatingCorrectionResponse - required: - - correction - additionalProperties: false - console.v1.ReviewProspectingDraftRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - draftId: - type: string - title: draft_id - minLength: 1 - decision: - title: decision - enum: - - PROSPECTING_DRAFT_REVIEW_STATE_APPROVED - - PROSPECTING_DRAFT_REVIEW_STATE_REJECTED - $ref: '#/components/schemas/console.v1.ProspectingDraftReviewState' - expectedRevision: - exclusiveMinimum: 0 - type: - - integer - - string - title: expected_revision - format: int64 - reason: - type: string - title: reason - maxLength: 512 - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 256 - minLength: 1 - title: ReviewProspectingDraftRequest - required: - - query - additionalProperties: false - console.v1.ReviewProspectingDraftResponse: - type: object - properties: - draft: - title: draft - $ref: '#/components/schemas/console.v1.ProspectingDraft' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.ProspectingDraftMutationReceipt' - title: ReviewProspectingDraftResponse - required: - - draft - - receipt - additionalProperties: false - console.v1.ReviewStaffProductIssueRecoveryRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - maxLength: 4000 - workspaceId: - type: string - title: workspace_id - maxLength: 4000 - recoveryId: - type: string - title: recovery_id - maxLength: 4000 - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - title: ReviewStaffProductIssueRecoveryRequest - additionalProperties: false - console.v1.ReviewWorkspaceMemoryRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - memoryId: - type: string - title: memory_id - minLength: 1 - expectedRevision: - type: - - integer - - string - title: expected_revision - minimum: 1 - format: int64 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - reviewStatus: - title: review_status - enum: - - MEMORY_REVIEW_STATUS_APPROVED - - MEMORY_REVIEW_STATUS_REJECTED - description: Only APPROVED and REJECTED are valid review decisions. - $ref: '#/components/schemas/memory.v1.MemoryReviewStatus' - title: ReviewWorkspaceMemoryRequest - required: - - query - additionalProperties: false - description: Review changes only proposal status; the memory owner preserves content. - console.v1.ReviewWorkspaceMemoryResponse: - type: object - properties: - memory: - title: memory - $ref: '#/components/schemas/console.v1.WorkspaceMemory' - title: ReviewWorkspaceMemoryResponse - required: - - memory - additionalProperties: false - console.v1.RevokeCaptureFormInvitationRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - invitationId: - type: string - title: invitation_id - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - title: RevokeCaptureFormInvitationRequest - additionalProperties: false - console.v1.RevokeCaptureFormInvitationResponse: - type: object - properties: - invitation: - title: invitation - $ref: '#/components/schemas/console.v1.CaptureFormInvitation' - title: RevokeCaptureFormInvitationResponse - required: - - invitation - additionalProperties: false - console.v1.RevokeCaptureFormPublicationRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - formId: - type: string - title: form_id - minLength: 1 - publicationId: - type: string - title: publication_id - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - title: RevokeCaptureFormPublicationRequest - additionalProperties: false - console.v1.RevokeCaptureFormPublicationResponse: - type: object - properties: - form: - title: form - $ref: '#/components/schemas/console.v1.CaptureForm' - publication: - title: publication - $ref: '#/components/schemas/console.v1.CaptureFormPublication' - title: RevokeCaptureFormPublicationResponse - required: - - form - - publication - additionalProperties: false - console.v1.RevokeDexMcpOAuthProfileRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - serverId: - type: string - title: server_id - minLength: 1 - profileId: - type: string - title: profile_id - minLength: 1 - reasonCode: - type: string - title: reason_code - minLength: 1 - profileGeneration: - exclusiveMinimum: 0 - type: - - integer - - string - title: profile_generation - format: int64 - title: RevokeDexMcpOAuthProfileRequest - required: - - query - additionalProperties: false - console.v1.RevokeDexMcpOAuthProfileResponse: - type: object - properties: - profile: - title: profile - $ref: '#/components/schemas/console.v1.DexMcpOAuthProfile' - title: RevokeDexMcpOAuthProfileResponse - required: - - profile - additionalProperties: false - console.v1.RevokeManagedProviderAccessGrantRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - provider: - type: string - title: provider - minLength: 1 - environment: - type: string - title: environment - minLength: 1 - note: - type: string - title: note - maxLength: 512 - minLength: 1 - description: Required audit note recorded with the disable action. - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - title: RevokeManagedProviderAccessGrantRequest - additionalProperties: false - console.v1.RevokeManagedProviderAccessGrantResponse: - type: object - properties: - grant: - title: grant - $ref: '#/components/schemas/console.v1.ManagedProviderAccessGrant' - title: RevokeManagedProviderAccessGrantResponse - additionalProperties: false - console.v1.RiskFinding: - type: object - properties: - id: - type: string - title: id - title: - type: string - title: title - detail: - type: string - title: detail - source: - type: string - title: source - assetId: - type: string - title: asset_id - status: - type: string - title: status - riskLevel: - title: risk_level - $ref: '#/components/schemas/common.v1.RiskLevel' - policy: - type: string - title: policy - nextAction: - type: string - title: next_action - detectedAt: - title: detected_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: RiskFinding - additionalProperties: false - console.v1.RunAsIdentitySummary: - type: object - properties: - status: - type: string - title: status - description: status is one of verified, unverified, missing, or unknown. - identity: - type: string - title: identity - source: - type: string - title: source - missingReason: - type: string - title: missing_reason - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - title: RunAsIdentitySummary - additionalProperties: false - console.v1.ScanStaffProductIssueRecoveryRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - maxLength: 4000 - workspaceId: - type: string - title: workspace_id - maxLength: 4000 - recoveryId: - type: string - title: recovery_id - maxLength: 4000 - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - title: ScanStaffProductIssueRecoveryRequest - additionalProperties: false - description: Durable, explicitly scoped customer recovery contract. - console.v1.ScenarioFixture: - type: object - properties: - id: - type: string - title: id - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - name: - type: string - title: name - recordedFromSessionId: - type: string - title: recorded_from_session_id - recordedAt: - title: recorded_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - originalModel: - type: string - title: original_model - toolCount: - type: integer - title: tool_count - format: int32 - frameCount: - type: integer - title: frame_count - format: int32 - gcsPath: - type: string - title: gcs_path - retentionPolicy: - type: string - title: retention_policy - tags: - type: array - items: - type: string - title: tags - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: ScenarioFixture - additionalProperties: false - console.v1.ScenarioFixtureDifference: - type: object - properties: - path: - type: string - title: path - kind: - type: string - title: kind - baseValue: - type: string - title: base_value - targetValue: - type: string - title: target_value - summary: - type: string - title: summary - title: ScenarioFixtureDifference - additionalProperties: false - console.v1.SearchOperatingHistoryRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - searchQuery: - type: string - title: search_query - maxLength: 1000 - minLength: 1 - filter: - title: filter - $ref: '#/components/schemas/console.v1.OperatingHistorySearchFilter' - pageSize: - type: integer - title: page_size - maximum: 25 - format: int32 - pageToken: - type: string - title: page_token - maxLength: 4096 - title: SearchOperatingHistoryRequest - required: - - query - additionalProperties: false - console.v1.SearchOperatingHistoryResponse: - type: object - properties: - results: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingHistorySearchResult' - title: results - nextPageToken: - type: string - title: next_page_token - title: SearchOperatingHistoryResponse - additionalProperties: false - console.v1.SearchStaffWorkspaceDirectoryRequest: - type: object - properties: - query: - type: string - title: query - maxLength: 128 - minLength: 1 - limit: - type: integer - title: limit - maximum: 25 - minimum: 1 - format: int32 - title: SearchStaffWorkspaceDirectoryRequest - additionalProperties: false - console.v1.SearchStaffWorkspaceDirectoryResponse: - type: object - properties: - entries: - type: array - items: - $ref: '#/components/schemas/console.v1.StaffWorkspaceDirectoryEntry' - title: entries - description: Capped at 25 entries. - title: SearchStaffWorkspaceDirectoryResponse - additionalProperties: false - console.v1.SecurityDecisionEvidenceGap: - type: object - properties: - id: - type: string - title: id - label: - type: string - title: label - state: - type: string - title: state - reason: - type: string - title: reason - source: - type: string - title: source - spanIds: - type: array - items: - type: string - title: span_ids - title: SecurityDecisionEvidenceGap - additionalProperties: false - console.v1.SecurityDecisionPacket: - type: object - properties: - id: - type: string - title: id - question: - type: string - title: question - verdict: - type: string - title: verdict - description: verdict is one of ready_to_approve, needs_review, needs_evidence, or blocked. - approvalState: - type: string - title: approval_state - description: approval_state is one of approved, pending, denied, not_required, or unknown. - governanceDecision: - type: string - title: governance_decision - riskLevel: - title: risk_level - $ref: '#/components/schemas/common.v1.RiskLevel' - summary: - type: string - title: summary - nextAction: - type: string - title: next_action - blockingReasons: - type: array - items: - type: string - title: blocking_reasons - evidenceGaps: - type: array - items: - $ref: '#/components/schemas/console.v1.SecurityDecisionEvidenceGap' - title: evidence_gaps - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - title: SecurityDecisionPacket - additionalProperties: false - console.v1.SetConnectorTriggerEnabledRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - triggerId: - type: string - title: trigger_id - minLength: 1 - enabled: - type: boolean - title: enabled - title: SetConnectorTriggerEnabledRequest - required: - - query - additionalProperties: false - console.v1.SetConnectorTriggerEnabledResponse: - type: object - properties: - trigger: - title: trigger - $ref: '#/components/schemas/console.v1.ConnectorTrigger' - title: SetConnectorTriggerEnabledResponse - required: - - trigger - additionalProperties: false - console.v1.SetManagedSetupRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - description: |- - workspace_id writes a workspace override. Leave empty to write the - organization document. - setup: - title: setup - description: |- - setup carries the document body. Its version, issued_at, organization_id, - and workspace_id fields are server-owned and ignored on write. - $ref: '#/components/schemas/console.v1.ManagedSetup' - title: SetManagedSetupRequest - required: - - setup - additionalProperties: false - description: SetManagedSetupRequest replaces the managed setup document for one tenant. - console.v1.SetMissionScheduleEnabledRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - scheduleId: - type: string - title: schedule_id - minLength: 1 - enabled: - type: boolean - title: enabled - title: SetMissionScheduleEnabledRequest - required: - - query - additionalProperties: false - console.v1.SetMissionScheduleEnabledResponse: - type: object - properties: - schedule: - title: schedule - $ref: '#/components/schemas/console.v1.MissionSchedule' - title: SetMissionScheduleEnabledResponse - required: - - schedule - additionalProperties: false - console.v1.SetOperatingThreadControllerRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - minLength: 1 - action: - type: string - title: action - maxLength: 64 - minLength: 1 - expectedRuntimeGeneration: - type: - - integer - - string - title: expected_runtime_generation - format: int64 - expectedReplayCursor: - type: - - integer - - string - title: expected_replay_cursor - format: int64 - expectedControllerLeaseGeneration: - type: - - integer - - string - title: expected_controller_lease_generation - format: int64 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 512 - minLength: 1 - title: SetOperatingThreadControllerRequest - required: - - query - additionalProperties: false - console.v1.SetOperatingThreadControllerResponse: - type: object - properties: - replayed: - type: boolean - title: replayed - threadExecution: - title: thread_execution - $ref: '#/components/schemas/console.v1.OperatingThreadExecution' - replayCursor: - type: - - integer - - string - title: replay_cursor - format: int64 - title: SetOperatingThreadControllerResponse - required: - - threadExecution - additionalProperties: false - console.v1.SetPinnedSourceRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - sourceId: - type: string - title: source_id - minLength: 1 - title: SetPinnedSourceRequest - additionalProperties: false - console.v1.SetPinnedSourceResponse: - type: object - properties: - pin: - title: pin - $ref: '#/components/schemas/console.v1.PinnedSource' - title: SetPinnedSourceResponse - additionalProperties: false - console.v1.SetPrivacySettingsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - scope: - not: - enum: - - 0 - title: scope - $ref: '#/components/schemas/console.v1.PrivacySettingScope' - mode: - not: - enum: - - 0 - title: mode - $ref: '#/components/schemas/console.v1.TenantPrivacyMode' - title: SetPrivacySettingsRequest - required: - - query - additionalProperties: false - console.v1.SetStaffManagedInferenceBudgetRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - request: - title: request - $ref: '#/components/schemas/meter.v1.SetBudgetRequest' - reason: - type: string - title: reason - requestId: - type: string - title: request_id - title: SetStaffManagedInferenceBudgetRequest - additionalProperties: false - console.v1.SkillAnalysisFinding: - type: object - properties: - ruleId: - type: string - title: rule_id - title: - type: string - title: title - detail: - type: string - title: detail - severity: - title: severity - $ref: '#/components/schemas/common.v1.RiskLevel' - advisory: - type: boolean - title: advisory - description: |- - Advisory findings are bounded content-review signals. They never affect - the verdict or authorize, block, or route product behavior. - title: SkillAnalysisFinding - additionalProperties: false - console.v1.SkillAnalysisReport: - type: object - properties: - verdict: - title: verdict - $ref: '#/components/schemas/console.v1.SkillAnalysisVerdict' - contentDigest: - type: string - title: content_digest - rulesetVersion: - type: string - title: ruleset_version - coveredSurfaces: - type: array - items: - type: string - title: covered_surfaces - requiredTools: - type: array - items: - type: string - title: required_tools - findings: - type: array - items: - $ref: '#/components/schemas/console.v1.SkillAnalysisFinding' - title: findings - title: SkillAnalysisReport - additionalProperties: false - description: |- - SkillAnalysisReport is deterministic evidence about the exact skill payload - being displayed, saved, or offered for installation. It is not a permission - grant and never replaces runtime authorization or approval policy. - console.v1.StaffComputerEnvironment: - type: object - properties: - provider: - type: string - title: provider - region: - type: string - title: region - lifecycleState: - type: string - title: lifecycle_state - title: StaffComputerEnvironment - additionalProperties: false - console.v1.StaffContextCapability: - type: object - properties: - available: - type: boolean - title: available - reason: - type: string - title: reason - title: StaffContextCapability - additionalProperties: false - console.v1.StaffFailureSummary: - type: object - properties: - eventId: - type: string - title: event_id - category: - type: string - title: category - safeSummary: - type: string - title: safe_summary - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: StaffFailureSummary - additionalProperties: false - console.v1.StaffGrantEventSummary: - type: object - properties: - grantId: - type: string - title: grant_id - action: - type: string - title: action - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: StaffGrantEventSummary - additionalProperties: false - console.v1.StaffInferencePurposeRoute: - type: object - properties: - purpose: - title: purpose - $ref: '#/components/schemas/console.v1.StaffInferenceRoutingPurpose' - primaryTarget: - title: primary_target - $ref: '#/components/schemas/console.v1.InferenceProviderTarget' - canaryTarget: - title: canary_target - description: Optional deterministic canary target for this purpose. - $ref: '#/components/schemas/console.v1.InferenceProviderTarget' - canaryPercent: - type: integer - title: canary_percent - title: StaffInferencePurposeRoute - additionalProperties: false - console.v1.StaffInferenceRoutingEvent: - type: object - properties: - revision: - type: - - integer - - string - title: revision - format: int64 - routes: - type: array - items: - $ref: '#/components/schemas/console.v1.StaffInferencePurposeRoute' - title: routes - usesDeploymentDefault: - type: boolean - title: uses_deployment_default - actorPrincipalId: - type: string - title: actor_principal_id - note: - type: string - title: note - action: - type: string - title: action - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: StaffInferenceRoutingEvent - additionalProperties: false - console.v1.StaffInferenceRoutingProfile: - type: object - properties: - organizationId: - type: string - title: organization_id - provider: - type: string - title: provider - model: - type: string - title: model - revision: - type: - - integer - - string - title: revision - format: int64 - updatedBy: - type: string - title: updated_by - note: - type: string - title: note - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - routes: - type: array - items: - $ref: '#/components/schemas/console.v1.StaffInferencePurposeRoute' - title: routes - usesDeploymentDefault: - type: boolean - title: uses_deployment_default - title: StaffInferenceRoutingProfile - additionalProperties: false - description: |- - StaffInferenceRoutingProfile is the durable Dex inference override for the - single server-configured STAFF organization. - console.v1.StaffProductIssueRecoverySummary: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - recoveryId: - type: string - title: recovery_id - reportReference: - type: string - title: report_reference - recipientPrincipalId: - type: string - title: recipient_principal_id - customerSummary: - type: string - title: customer_summary - state: - type: string - title: state - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - lastReply: - type: string - title: last_reply - title: StaffProductIssueRecoverySummary - additionalProperties: false - console.v1.StaffProductIssueReport: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - id: - type: string - title: id - reference: - type: string - title: reference - description: - type: string - title: description - expectedBehavior: - type: string - title: expected_behavior - pageUrl: - type: string - title: page_url - appVersion: - type: string - title: app_version - browser: - type: string - title: browser - viewport: - type: string - title: viewport - diagnosticsIncluded: - type: boolean - title: diagnostics_included - screenshotAttached: - type: boolean - title: screenshot_attached - screenshotFilename: - type: string - title: screenshot_filename - screenshotContentType: - type: string - title: screenshot_content_type - createdByPrincipalId: - type: string - title: created_by_principal_id - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - engagementState: - type: string - title: engagement_state - engagedAt: - title: engaged_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - engagedByPrincipalId: - type: string - title: engaged_by_principal_id - engagementNote: - type: string - title: engagement_note - context: - title: context - $ref: '#/components/schemas/console.v1.ProductIssueReportContext' - symptomGroup: - type: string - title: symptom_group - description: Exact normalized symptom grouping, scoped to one organization and workspace. - baselineTestRunId: - type: string - title: baseline_test_run_id - verificationTestRunId: - type: string - title: verification_test_run_id - regressionState: - type: string - title: regression_state - title: StaffProductIssueReport - additionalProperties: false - console.v1.StaffReceiptSummary: - type: object - properties: - id: - type: string - title: id - kind: - type: string - title: kind - status: - type: string - title: status - summary: - type: string - title: summary - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: StaffReceiptSummary - additionalProperties: false - console.v1.StaffTraceSummary: - type: object - properties: - traceId: - type: string - title: trace_id - summary: - type: string - title: summary - status: - type: string - title: status - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: StaffTraceSummary - additionalProperties: false - console.v1.StaffWorkspaceContext: - type: object - properties: - accessState: - title: access_state - $ref: '#/components/schemas/console.v1.StaffWorkspaceAccessState' - grantEvents: - type: array - items: - $ref: '#/components/schemas/console.v1.StaffGrantEventSummary' - title: grant_events - description: Each collection is newest-first and capped at 25. - receipts: - type: array - items: - $ref: '#/components/schemas/console.v1.StaffReceiptSummary' - title: receipts - traces: - type: array - items: - $ref: '#/components/schemas/console.v1.StaffTraceSummary' - title: traces - failures: - type: array - items: - $ref: '#/components/schemas/console.v1.StaffFailureSummary' - title: failures - computerEnvironment: - title: computer_environment - $ref: '#/components/schemas/console.v1.StaffComputerEnvironment' - grantEventsCapability: - title: grant_events_capability - $ref: '#/components/schemas/console.v1.StaffContextCapability' - receiptsCapability: - title: receipts_capability - $ref: '#/components/schemas/console.v1.StaffContextCapability' - tracesCapability: - title: traces_capability - $ref: '#/components/schemas/console.v1.StaffContextCapability' - failuresCapability: - title: failures_capability - $ref: '#/components/schemas/console.v1.StaffContextCapability' - computerEnvironmentCapability: - title: computer_environment_capability - $ref: '#/components/schemas/console.v1.StaffContextCapability' - activeGrantApprover: - type: string - title: active_grant_approver - activeGrantExpiresAt: - title: active_grant_expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: StaffWorkspaceContext - additionalProperties: false - console.v1.StaffWorkspaceDirectoryEntry: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - organizationName: - type: string - title: organization_name - workspaceName: - type: string - title: workspace_name - region: - type: string - title: region - environment: - type: string - title: environment - accessState: - title: access_state - $ref: '#/components/schemas/console.v1.StaffWorkspaceAccessState' - title: StaffWorkspaceDirectoryEntry - additionalProperties: false - console.v1.StartBusinessProcessRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - definitionId: - type: string - title: definition_id - definitionRevision: - type: - - integer - - string - title: definition_revision - format: int64 - participants: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessProcessParticipant' - title: participants - decisionPrincipalId: - type: string - title: decision_principal_id - title: StartBusinessProcessRequest - additionalProperties: false - console.v1.StartBusinessProcessResponse: - type: object - properties: - process: - title: process - $ref: '#/components/schemas/console.v1.BusinessProcess' - title: StartBusinessProcessResponse - additionalProperties: false - console.v1.StartComputerMissionCanaryRunRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - channelId: - type: string - title: channel_id - minLength: 1 - canaryDefinitionId: - type: string - title: canary_definition_id - minLength: 1 - environment: - type: string - title: environment - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: StartComputerMissionCanaryRunRequest - required: - - query - additionalProperties: false - console.v1.StartComputerMissionCanaryRunResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryRun' - mission: - title: mission - $ref: '#/components/schemas/console.v1.ComputerMission' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.OperatingReceipt' - title: StartComputerMissionCanaryRunResponse - required: - - run - - mission - - receipt - additionalProperties: false - console.v1.StartMeetingCaptureRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - meetUrl: - type: string - title: meet_url - maxLength: 2000 - description: |- - Optional when connected_call_id is set. Otherwise one server-validated - meeting URL (Google Meet, Zoom, Microsoft Teams, or Webex). The field name - stays meet_url for wire and TypeScript compatibility. - recallConnectionId: - type: string - title: recall_connection_id - description: |- - Deprecated compatibility input. Platform ignores it and resolves the - tenant's active Recall connection server-side. - deprecated: true - idempotencyKey: - type: string - title: idempotency_key - maxLength: 200 - minLength: 1 - maximumDurationMinutes: - type: integer - title: maximum_duration_minutes - maximum: 240 - minimum: 1 - format: int32 - recordingConsentAttested: - type: boolean - title: recording_consent_attested - languageCode: - type: string - title: language_code - maxLength: 35 - connectedCallId: - type: string - title: connected_call_id - maxLength: 200 - description: |- - Optional. When set, Platform resolves the call from the tenant's connected - calendar (ListConnectedCalls id), uses its meeting URL and start/end times, - and records a calendar-sourced capture. meet_url is ignored when set. - title: StartMeetingCaptureRequest - required: - - query - additionalProperties: false - description: |- - StartMeetingCaptureRequest names one meeting, either by a server-validated - meeting URL or by one opted-in connected calendar call. The transcript - callback and provider credentials are deployment-owned and cannot be - redirected by the browser. - console.v1.StartMeetingCaptureResponse: - type: object - properties: - capture: - title: capture - $ref: '#/components/schemas/console.v1.MeetingCapture' - title: StartMeetingCaptureResponse - additionalProperties: false - console.v1.StopMeetingCaptureRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - captureId: - type: string - title: capture_id - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 200 - minLength: 1 - title: StopMeetingCaptureRequest - required: - - query - additionalProperties: false - description: |- - StopMeetingCaptureRequest records the user's request to stop one capture. - Platform chooses cancel-versus-leave from the durable binding lifecycle; the - browser cannot select the provider action. - console.v1.StopMeetingCaptureResponse: - type: object - properties: - capture: - title: capture - $ref: '#/components/schemas/console.v1.MeetingCapture' - title: StopMeetingCaptureResponse - additionalProperties: false - console.v1.SubmitAgentWorkforceEvidenceRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - recordId: - type: string - title: record_id - description: |- - record_id targets an existing Agent Workforce record. When present, the - backend resolves it to trace/run/session identifiers before writing. - traceId: - type: string - title: trace_id - runId: - type: string - title: run_id - sessionId: - type: string - title: session_id - agentId: - type: string - title: agent_id - runtime: - type: string - title: runtime - evidenceKind: - type: string - title: evidence_kind - minLength: 1 - description: |- - evidence_kind is one of advisory_self_report, credential_authority, - cost_usage, attempted_action, or approval_packet. - evidenceSource: - type: string - title: evidence_source - description: |- - evidence_source identifies the submitting/owning source. Advisory/native - sources such as external_self_report, nimbus, cerebro, or customer_mcp are - retained as context but must not unlock approval authority. - evidenceRef: - type: string - title: evidence_ref - minLength: 1 - subject: - type: string - title: subject - provider: - type: string - title: provider - actionId: - type: string - title: action_id - toolName: - type: string - title: tool_name - targetSummary: - type: string - title: target_summary - mutatesResource: - type: boolean - title: mutates_resource - costUsd: - type: number - title: cost_usd - format: double - inputTokens: - type: - - integer - - string - title: input_tokens - format: int64 - outputTokens: - type: - - integer - - string - title: output_tokens - format: int64 - model: - type: string - title: model - connectorId: - type: string - title: connector_id - capability: - type: string - title: capability - note: - type: string - title: note - title: SubmitAgentWorkforceEvidenceRequest - required: - - query - additionalProperties: false - console.v1.SubmitAgentWorkforceEvidenceResponse: - type: object - properties: - submittedEvidence: - title: submitted_evidence - $ref: '#/components/schemas/console.v1.AgentWorkforceSubmittedEvidence' - record: - title: record - $ref: '#/components/schemas/console.v1.AgentWorkforceRecord' - recordsResponse: - title: records_response - $ref: '#/components/schemas/console.v1.ListAgentWorkforceRecordsResponse' - remainingMissingEvidence: - type: array - items: - type: string - title: remaining_missing_evidence - approvalAllowed: - type: boolean - title: approval_allowed - nextAction: - type: string - title: next_action - warnings: - type: array - items: - type: string - title: warnings - title: SubmitAgentWorkforceEvidenceResponse - additionalProperties: false - console.v1.SubmitComputerMissionRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - channelId: - type: string - title: channel_id - minLength: 1 - contract: - title: contract - $ref: '#/components/schemas/console.v1.ComputerMissionContract' - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: SubmitComputerMissionRequest - required: - - query - - contract - additionalProperties: false - console.v1.SubmitComputerMissionResponse: - type: object - properties: - mission: - title: mission - $ref: '#/components/schemas/console.v1.ComputerMission' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.OperatingReceipt' - title: SubmitComputerMissionResponse - required: - - mission - - receipt - additionalProperties: false - console.v1.SubmitInvitedCaptureFormRequest: - type: object - properties: - invitationId: - type: string - title: invitation_id - minLength: 1 - answers: - type: array - items: - $ref: '#/components/schemas/console.v1.CaptureFormAnswer' - title: answers - maxItems: 64 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - title: SubmitInvitedCaptureFormRequest - additionalProperties: false - console.v1.SubmitInvitedCaptureFormResponse: - type: object - properties: - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.CaptureFormPublicSubmissionReceipt' - title: SubmitInvitedCaptureFormResponse - required: - - receipt - additionalProperties: false - console.v1.SubmitNativeProductIssueReportRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - description: - type: string - title: description - maxLength: 4000 - minLength: 1 - expectedBehavior: - type: string - title: expected_behavior - maxLength: 4000 - appVersion: - type: string - title: app_version - maxLength: 128 - includeDiagnostics: - type: boolean - title: include_diagnostics - idempotencyKey: - type: string - title: idempotency_key - maxLength: 512 - minLength: 1 - context: - title: context - $ref: '#/components/schemas/console.v1.ProductIssueReportContext' - title: SubmitNativeProductIssueReportRequest - required: - - query - additionalProperties: false - description: |- - Native reports reuse the product issue owner with a bounded diagnostic projection. - Tags match the canonical submission fields; browser-only fields are reserved. - console.v1.SubmitOperatingCorrectionRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - minLength: 1 - messageId: - type: string - title: message_id - minLength: 1 - category: - not: - enum: - - 0 - title: category - $ref: '#/components/schemas/console.v1.OperatingCorrectionCategory' - feedback: - type: string - title: feedback - maxLength: 4000 - remember: - type: boolean - title: remember - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: SubmitOperatingCorrectionRequest - required: - - query - additionalProperties: false - console.v1.SubmitOperatingCorrectionResponse: - type: object - properties: - correction: - title: correction - $ref: '#/components/schemas/console.v1.OperatingCorrectionCandidate' - title: SubmitOperatingCorrectionResponse - required: - - correction - additionalProperties: false - console.v1.SubmitOperatingFeedbackRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - minLength: 1 - messageId: - type: string - title: message_id - minLength: 1 - sentiment: - not: - enum: - - 0 - title: sentiment - $ref: '#/components/schemas/console.v1.OperatingFeedbackSentiment' - category: - title: category - $ref: '#/components/schemas/console.v1.OperatingCorrectionCategory' - classificationSource: - not: - enum: - - 0 - title: classification_source - $ref: '#/components/schemas/console.v1.OperatingFeedbackClassificationSource' - correction: - type: string - title: correction - maxLength: 4000 - remember: - type: boolean - title: remember - remediationAction: - not: - enum: - - 0 - title: remediation_action - $ref: '#/components/schemas/console.v1.OperatingFeedbackRemediationAction' - remediationAttemptId: - type: string - title: remediation_attempt_id - maxLength: 256 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - reason: - title: reason - $ref: '#/components/schemas/console.v1.OperatingFeedbackReason' - lifecycleState: - title: lifecycle_state - $ref: '#/components/schemas/console.v1.OperatingFeedbackLifecycleState' - supersedesFeedbackId: - type: string - title: supersedes_feedback_id - maxLength: 256 - title: SubmitOperatingFeedbackRequest - required: - - query - additionalProperties: false - console.v1.SubmitOperatingFeedbackResponse: - type: object - properties: - feedback: - title: feedback - $ref: '#/components/schemas/console.v1.OperatingFeedback' - correction: - title: correction - $ref: '#/components/schemas/console.v1.OperatingCorrectionCandidate' - factReceipt: - title: fact_receipt - $ref: '#/components/schemas/console.v1.CustomerIntelligenceReceipt' - title: SubmitOperatingFeedbackResponse - required: - - feedback - additionalProperties: false - console.v1.SubmitOperatingMessageRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - body: - type: string - title: body - maxLength: 20000 - idempotencyKey: - type: string - title: idempotency_key - attachments: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingAttachmentRef' - title: attachments - maxItems: 1 - continuationTaskId: - type: string - title: continuation_task_id - maxLength: 256 - description: |- - continuation_task_id resumes existing work. Omit it to create a new task. - The server owns task creation and revision assignment. - referenceTaskIds: - type: array - items: - type: string - maxLength: 256 - minLength: 1 - maxItems: 16 - title: reference_task_ids - maxItems: 16 - draftPrewarmId: - type: string - title: draft_prewarm_id - maxLength: 256 - description: |- - The id returned by PrewarmOperatingThread. The server verifies it is - tenant- and principal-bound before reusing the prepared RunnerSession. - modelSelection: - title: model_selection - description: |- - Omitted preserves the conversation preference; an empty message resets Auto. - This is a preference, never managed inference authorization. - $ref: '#/components/schemas/console.v1.OperatingModelSelection' - codingAcceptance: - title: coding_acceptance - description: Opt in to evidence-backed coding acceptance; absence preserves ordinary chat. - $ref: '#/components/schemas/console.v1.CodingAcceptanceContract' - projectResourceId: - type: string - title: project_resource_id - maxLength: 255 - minLength: 1 - nullable: true - taskKind: - title: task_kind - description: |- - New coding implementation submissions require an admitted coding_acceptance - contract. No classification is inferred from the body or project name. - $ref: '#/components/schemas/console.v1.OperatingTaskKind' - title: SubmitOperatingMessageRequest - required: - - query - additionalProperties: false - console.v1.SubmitOperatingMessageResponse: - type: object - properties: - message: - title: message - $ref: '#/components/schemas/console.v1.OperatingMessage' - receipts: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingReceipt' - title: receipts - capabilities: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingCapabilityState' - title: capabilities - messages: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingMessage' - title: messages - description: |- - Full turn messages written by the submit. `message` remains the canonical - submitted human turn for older clients. - route: - title: route - $ref: '#/components/schemas/console.v1.OperatingTurnRoute' - acceptedTurn: - title: accepted_turn - $ref: '#/components/schemas/console.v1.OperatingThreadTurn' - replayCursor: - type: - - integer - - string - title: replay_cursor - format: int64 - title: SubmitOperatingMessageResponse - additionalProperties: false - console.v1.SubmitOrbControlActionRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - targetId: - type: string - title: target_id - minLength: 1 - action: - not: - enum: - - 0 - title: action - $ref: '#/components/schemas/orbcontrol.v1.OrbCommandKind' - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - expectedGeneration: - type: - - integer - - string - title: expected_generation - format: int64 - title: SubmitOrbControlActionRequest - required: - - query - additionalProperties: false - description: SubmitOrbControlActionRequest records one generation-fenced user intent. - console.v1.SubmitOrbControlActionResponse: - type: object - properties: - target: - title: target - $ref: '#/components/schemas/console.v1.OrbControlTarget' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.OperatingReceipt' - title: SubmitOrbControlActionResponse - required: - - receipt - additionalProperties: false - description: SubmitOrbControlActionResponse returns acceptance state, not inferred completion. - console.v1.SubmitProductIssueReportRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - description: - type: string - title: description - maxLength: 4000 - minLength: 1 - expectedBehavior: - type: string - title: expected_behavior - maxLength: 4000 - pageUrl: - type: string - title: page_url - maxLength: 2048 - appVersion: - type: string - title: app_version - maxLength: 128 - browser: - type: string - title: browser - maxLength: 512 - viewport: - type: string - title: viewport - maxLength: 64 - screenshotFilename: - type: string - title: screenshot_filename - maxLength: 255 - screenshotContentType: - type: string - title: screenshot_content_type - maxLength: 64 - screenshot: - type: string - title: screenshot - maxLength: 6990508 - x-protobuf-bytes-max-length: 5242880 - format: byte - includeDiagnostics: - type: boolean - title: include_diagnostics - idempotencyKey: - type: string - title: idempotency_key - maxLength: 512 - minLength: 1 - context: - title: context - $ref: '#/components/schemas/console.v1.ProductIssueReportContext' - title: SubmitProductIssueReportRequest - required: - - query - additionalProperties: false - console.v1.SubmitProductIssueReportResponse: - type: object - properties: - report: - title: report - $ref: '#/components/schemas/console.v1.ProductIssueReport' - title: SubmitProductIssueReportResponse - required: - - report - additionalProperties: false - console.v1.SubmitPublishedCaptureFormRequest: - type: object - properties: - publicationId: - type: string - title: publication_id - minLength: 1 - description: |- - This opaque id is the only public capability input. Tenant and object - coordinates are derived from the immutable publication record. - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - answers: - type: array - items: - $ref: '#/components/schemas/console.v1.CaptureFormAnswer' - title: answers - maxItems: 64 - title: SubmitPublishedCaptureFormRequest - additionalProperties: false - console.v1.SubmitPublishedCaptureFormResponse: - type: object - properties: - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.CaptureFormPublicSubmissionReceipt' - title: SubmitPublishedCaptureFormResponse - required: - - receipt - additionalProperties: false - console.v1.TaskEnvironmentProjectOption: - type: object - properties: - projectResourceId: - type: string - title: project_resource_id - displayName: - type: string - title: display_name - title: TaskEnvironmentProjectOption - additionalProperties: false - console.v1.TenantPrivacySetting: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - mode: - title: mode - $ref: '#/components/schemas/console.v1.TenantPrivacyMode' - updatedBy: - type: string - title: updated_by - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: TenantPrivacySetting - additionalProperties: false - description: |- - TenantPrivacySetting is one stored row. workspace_id is empty on the - organization-wide row. - console.v1.TerminalErrorEnvelope: - type: object - properties: - schemaVersion: - type: integer - title: schema_version - const: "1" - kind: - type: string - title: kind - maxLength: 128 - minLength: 1 - boundary: - type: string - title: boundary - maxLength: 128 - minLength: 1 - code: - type: string - title: code - maxLength: 128 - minLength: 1 - retryable: - type: boolean - title: retryable - providerRequestId: - type: string - title: provider_request_id - maxLength: 256 - displaySafeMessage: - type: string - title: display_safe_message - maxLength: 4096 - minLength: 1 - title: TerminalErrorEnvelope - additionalProperties: false - description: |- - TerminalErrorEnvelope is the browser-safe, provider-neutral classification - of one terminal execution failure. retryable is observational metadata; it - does not grant a caller permission to repeat work. - console.v1.TimeRange: - type: object - properties: - startTime: - title: start_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - endTime: - title: end_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: TimeRange - additionalProperties: false - description: TimeRange bounds console queries. - console.v1.TraceCompletenessSignal: - type: object - properties: - id: - type: string - title: id - title: - type: string - title: title - detail: - type: string - title: detail - status: - type: string - title: status - description: status is one of ready, pending, warning, or blocked. - spanIds: - type: array - items: - type: string - title: span_ids - title: TraceCompletenessSignal - additionalProperties: false - console.v1.TraceDrilldown: - type: object - properties: - traceId: - type: string - title: trace_id - rootName: - type: string - title: root_name - assetId: - type: string - title: asset_id - status: - type: string - title: status - totalLatencyMs: - type: - - integer - - string - title: total_latency_ms - format: int64 - inputTokens: - type: - - integer - - string - title: input_tokens - format: int64 - outputTokens: - type: - - integer - - string - title: output_tokens - format: int64 - costUsd: - type: number - title: cost_usd - format: double - evalScore: - type: number - title: eval_score - format: double - riskLevel: - title: risk_level - $ref: '#/components/schemas/common.v1.RiskLevel' - spans: - type: array - items: - $ref: '#/components/schemas/console.v1.TraceSpan' - title: spans - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - annotations: - type: array - items: - $ref: '#/components/schemas/traces.v1.TraceAnnotation' - title: annotations - suggestedLabels: - type: array - items: - type: string - title: suggested_labels - evidenceSource: - type: string - title: evidence_source - description: |- - evidence_source names the backing read path used for this drilldown - ("traces-store", "console-snapshot", etc.) so the UI can distinguish a - live trace lookup from a stale projection. - completenessSignals: - type: array - items: - $ref: '#/components/schemas/console.v1.TraceCompletenessSignal' - title: completeness_signals - description: |- - completeness_signals explain which evidence families are present, pending, - or broken for the trace. They are product-facing diagnostics, not raw test - failures. - securityDecisionPacket: - title: security_decision_packet - description: |- - security_decision_packet is the server-owned answer to the operator - question "Can I approve this?" It joins governance, approval readiness, - risk, and missing evidence so clients do not infer approval state from - labels or text matching. - $ref: '#/components/schemas/console.v1.SecurityDecisionPacket' - title: TraceDrilldown - additionalProperties: false - console.v1.TraceSpan: - type: object - properties: - spanId: - type: string - title: span_id - parentSpanId: - type: string - title: parent_span_id - name: - type: string - title: name - kind: - type: string - title: kind - model: - type: string - title: model - provider: - type: string - title: provider - status: - type: string - title: status - latencyMs: - type: - - integer - - string - title: latency_ms - format: int64 - costUsd: - type: number - title: cost_usd - format: double - inputTokens: - type: - - integer - - string - title: input_tokens - format: int64 - outputTokens: - type: - - integer - - string - title: output_tokens - format: int64 - governanceDecision: - type: string - title: governance_decision - startedAt: - title: started_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - endedAt: - title: ended_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - attributes: - title: attributes - $ref: '#/components/schemas/google.protobuf.Struct' - references: - type: array - items: - $ref: '#/components/schemas/console.v1.TraceSpanReference' - title: references - title: TraceSpan - additionalProperties: false - console.v1.TraceSpanReference: - type: object - properties: - id: - type: string - title: id - resourceType: - type: string - title: resource_type - label: - type: string - title: label - url: - type: string - title: url - title: TraceSpanReference - additionalProperties: false - console.v1.TransitionBusinessProcessRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - processId: - type: string - title: process_id - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - transitionId: - type: string - title: transition_id - participants: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessProcessParticipant' - title: participants - description: Every role must name its exact current record revision. This fences decisions. - acceptDecision: - type: boolean - title: accept_decision - title: TransitionBusinessProcessRequest - additionalProperties: false - console.v1.TransitionBusinessProcessResponse: - type: object - properties: - process: - title: process - $ref: '#/components/schemas/console.v1.BusinessProcess' - accepted: - type: boolean - title: accepted - unmetRequirementIds: - type: array - items: - type: string - title: unmet_requirement_ids - title: TransitionBusinessProcessResponse - additionalProperties: false - console.v1.UnpinSourceRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - sourceId: - type: string - title: source_id - minLength: 1 - title: UnpinSourceRequest - additionalProperties: false - console.v1.UnpinSourceResponse: - type: object - title: UnpinSourceResponse - additionalProperties: false - console.v1.UpdateAgentProductRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - agentId: - type: string - title: agent_id - minLength: 1 - expectedConfigVersion: - exclusiveMinimum: 0 - type: integer - title: expected_config_version - format: int32 - name: - type: string - title: name - minLength: 1 - description: - type: string - title: description - promptBindings: - type: object - title: prompt_bindings - additionalProperties: - type: string - title: value - integrationIds: - type: array - items: - type: string - title: integration_ids - connectorRequirements: - type: array - items: - $ref: '#/components/schemas/agents.v1.ConnectorRequirement' - title: connector_requirements - role: - type: string - title: role - purpose: - type: string - title: purpose - responsibilities: - type: array - items: - $ref: '#/components/schemas/agents.v1.TeammateResponsibility' - title: responsibilities - triggers: - type: array - items: - $ref: '#/components/schemas/agents.v1.InitiativeTrigger' - title: triggers - title: UpdateAgentProductRequest - additionalProperties: false - console.v1.UpdateAgentProductRequest.PromptBindingsEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: PromptBindingsEntry - additionalProperties: false - console.v1.UpdateAgentProductResponse: - type: object - properties: - agent: - title: agent - $ref: '#/components/schemas/agents.v1.Agent' - config: - title: config - $ref: '#/components/schemas/agents.v1.AgentConfig' - title: UpdateAgentProductResponse - additionalProperties: false - console.v1.UpdateBusinessObjectRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - objectId: - type: string - title: object_id - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - values: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessFieldValue' - title: values - schemaRevision: - type: - - integer - - string - title: schema_revision - format: int64 - title: UpdateBusinessObjectRequest - additionalProperties: false - console.v1.UpdateBusinessObjectResponse: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/console.v1.BusinessObject' - title: UpdateBusinessObjectResponse - additionalProperties: false - console.v1.UpdateCaptureFormRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - formId: - type: string - title: form_id - minLength: 1 - expectedRevision: - exclusiveMinimum: 0 - type: - - integer - - string - title: expected_revision - format: int64 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - name: - type: string - title: name - maxLength: 160 - minLength: 1 - description: - type: string - title: description - maxLength: 2000 - version: - title: version - $ref: '#/components/schemas/console.v1.CaptureFormVersionInput' - title: UpdateCaptureFormRequest - required: - - version - additionalProperties: false - console.v1.UpdateCaptureFormResponse: - type: object - properties: - form: - title: form - $ref: '#/components/schemas/console.v1.CaptureForm' - version: - title: version - $ref: '#/components/schemas/console.v1.CaptureFormVersion' - title: UpdateCaptureFormResponse - required: - - form - - version - additionalProperties: false - console.v1.UpdateConnectorProfileRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - id: - type: string - title: id - minLength: 1 - enabled: - type: boolean - title: enabled - nullable: true - isDefault: - type: boolean - title: is_default - nullable: true - scopes: - title: scopes - $ref: '#/components/schemas/console.v1.ConnectorProfileScopeSet' - title: UpdateConnectorProfileRequest - required: - - query - additionalProperties: false - console.v1.UpdateConnectorProfileResponse: - type: object - properties: - profile: - title: profile - $ref: '#/components/schemas/console.v1.ConnectorProfile' - title: UpdateConnectorProfileResponse - required: - - profile - additionalProperties: false - console.v1.UpdateConnectorTriggerRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - triggerId: - type: string - title: trigger_id - minLength: 1 - name: - type: string - title: name - minLength: 1 - source: - not: - enum: - - 0 - title: source - $ref: '#/components/schemas/console.v1.ConnectorTriggerSource' - cronExpression: - type: string - title: cron_expression - connectionId: - type: string - title: connection_id - providerId: - type: string - title: provider_id - eventKind: - type: string - title: event_kind - payloadFieldAllowlist: - type: array - items: - type: string - title: payload_field_allowlist - template: - title: template - $ref: '#/components/schemas/console.v1.MissionScheduleTemplate' - title: UpdateConnectorTriggerRequest - required: - - query - - template - additionalProperties: false - console.v1.UpdateConnectorTriggerResponse: - type: object - properties: - trigger: - title: trigger - $ref: '#/components/schemas/console.v1.ConnectorTrigger' - title: UpdateConnectorTriggerResponse - required: - - trigger - additionalProperties: false - console.v1.UpdateDexMcpServerRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - serverId: - type: string - title: server_id - minLength: 1 - baseUrl: - type: string - title: base_url - nullable: true - enabled: - type: boolean - title: enabled - nullable: true - bearerToken: - type: string - title: bearer_token - nullable: true - clearToken: - type: boolean - title: clear_token - title: UpdateDexMcpServerRequest - required: - - query - additionalProperties: false - console.v1.UpdateDexMcpServerResponse: - type: object - properties: - server: - title: server - $ref: '#/components/schemas/console.v1.DexMcpServer' - title: UpdateDexMcpServerResponse - required: - - server - additionalProperties: false - console.v1.UpdateInferenceCreditAutoRefillRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - requestId: - type: string - title: request_id - format: uuid - enabled: - type: boolean - title: enabled - thresholdCents: - type: - - integer - - string - title: threshold_cents - format: int64 - creditCents: - type: - - integer - - string - title: credit_cents - format: int64 - monthlyCapCents: - type: - - integer - - string - title: monthly_cap_cents - format: int64 - consent: - type: boolean - title: consent - description: Explicit agreement to the displayed threshold, gross charge and UTC monthly cap. - expectedGeneration: - type: string - title: expected_generation - title: UpdateInferenceCreditAutoRefillRequest - additionalProperties: false - console.v1.UpdateInferenceCreditAutoRefillResponse: - type: object - properties: - setupUrl: - type: string - title: setup_url - generation: - type: string - title: generation - title: UpdateInferenceCreditAutoRefillResponse - additionalProperties: false - console.v1.UpdateMissionScheduleRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - scheduleId: - type: string - title: schedule_id - minLength: 1 - name: - type: string - title: name - minLength: 1 - cronExpression: - type: string - title: cron_expression - minLength: 1 - template: - title: template - $ref: '#/components/schemas/console.v1.MissionScheduleTemplate' - title: UpdateMissionScheduleRequest - required: - - query - - template - additionalProperties: false - console.v1.UpdateMissionScheduleResponse: - type: object - properties: - schedule: - title: schedule - $ref: '#/components/schemas/console.v1.MissionSchedule' - title: UpdateMissionScheduleResponse - required: - - schedule - additionalProperties: false - console.v1.UpdateOperatorPreferencesRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - dexHatId: - type: string - title: dex_hat_id - description: Omitted only for a model_preference update; existing profile updates require a hat. - developerModeEnabled: - type: boolean - title: developer_mode_enabled - nullable: true - modelPreference: - title: model_preference - $ref: '#/components/schemas/console.v1.OperatorModelPreferenceUpdate' - title: UpdateOperatorPreferencesRequest - required: - - query - additionalProperties: false - console.v1.UpdateOperatorPreferencesResponse: - type: object - properties: - preferences: - title: preferences - $ref: '#/components/schemas/console.v1.OperatorPreferences' - title: UpdateOperatorPreferencesResponse - required: - - preferences - additionalProperties: false - console.v1.UpdateProspectingWatchProgramRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - watchProgramId: - type: string - title: watch_program_id - minLength: 1 - name: - type: string - title: name - maxLength: 128 - minLength: 1 - config: - title: config - $ref: '#/components/schemas/google.protobuf.Struct' - scoringRuleRevision: - type: string - title: scoring_rule_revision - maxLength: 128 - minLength: 1 - lifecycle: - not: - enum: - - 0 - title: lifecycle - $ref: '#/components/schemas/console.v1.ProspectingWatchProgramLifecycle' - expectedRevision: - exclusiveMinimum: 0 - type: - - integer - - string - title: expected_revision - format: int64 - reason: - type: string - title: reason - maxLength: 512 - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 256 - minLength: 1 - title: UpdateProspectingWatchProgramRequest - required: - - query - - config - additionalProperties: false - console.v1.UpdateProspectingWatchProgramResponse: - type: object - properties: - program: - title: program - $ref: '#/components/schemas/console.v1.ProspectingWatchProgram' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.ProspectingWatchProgramMutationReceipt' - title: UpdateProspectingWatchProgramResponse - required: - - program - - receipt - additionalProperties: false - console.v1.UpdateStaffInferenceRoutingProfileRequest: - type: object - properties: - provider: - type: string - title: provider - model: - type: string - title: model - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - note: - type: string - title: note - maxLength: 512 - minLength: 1 - purpose: - title: purpose - $ref: '#/components/schemas/console.v1.StaffInferenceRoutingPurpose' - resetToDefault: - type: boolean - title: reset_to_default - description: |- - Reset every purpose to the deployment default while retaining revisioned - audit history. - canaryProvider: - type: string - title: canary_provider - canaryModel: - type: string - title: canary_model - canaryPercent: - type: integer - title: canary_percent - maximum: 50 - rollbackRevision: - type: - - integer - - string - title: rollback_revision - format: int64 - description: Restore the complete snapshot recorded at this prior revision. - title: UpdateStaffInferenceRoutingProfileRequest - additionalProperties: false - console.v1.UpdateStaffInferenceRoutingProfileResponse: - type: object - properties: - profile: - title: profile - $ref: '#/components/schemas/console.v1.StaffInferenceRoutingProfile' - effectiveTarget: - title: effective_target - $ref: '#/components/schemas/console.v1.InferenceProviderTarget' - title: UpdateStaffInferenceRoutingProfileResponse - required: - - profile - - effectiveTarget - additionalProperties: false - console.v1.UpdateWorkspaceArtifactStyleGuideRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - workspaceArtifactStyleGuide: - title: workspace_artifact_style_guide - $ref: '#/components/schemas/console.v1.WorkspaceArtifactStyleGuide' - title: UpdateWorkspaceArtifactStyleGuideRequest - required: - - query - - workspaceArtifactStyleGuide - additionalProperties: false - console.v1.UpdateWorkspaceArtifactStyleGuideResponse: - type: object - properties: - settings: - title: settings - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - title: UpdateWorkspaceArtifactStyleGuideResponse - required: - - settings - additionalProperties: false - console.v1.UpdateWorkspaceBillingRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - billing: - title: billing - $ref: '#/components/schemas/console.v1.WorkspaceSettingsBilling' - title: UpdateWorkspaceBillingRequest - required: - - query - - billing - additionalProperties: false - console.v1.UpdateWorkspaceDexPolicyRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - dexPolicy: - title: dex_policy - description: |- - (-- api-linter: core::0134::request-resource-field=disabled - aip.dev/not-precedent: The public dex_policy source and ProtoJSON names - predate AIP-134 and remain compatibility contracts. --) - $ref: '#/components/schemas/console.v1.WorkspaceDexPolicy' - title: UpdateWorkspaceDexPolicyRequest - required: - - query - - dexPolicy - additionalProperties: false - console.v1.UpdateWorkspaceDexPolicyResponse: - type: object - properties: - settings: - title: settings - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - title: UpdateWorkspaceDexPolicyResponse - required: - - settings - additionalProperties: false - console.v1.UpdateWorkspaceNotificationPreferencesRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - notifications: - title: notifications - $ref: '#/components/schemas/console.v1.WorkspaceSettingsNotifications' - title: UpdateWorkspaceNotificationPreferencesRequest - required: - - query - - notifications - additionalProperties: false - console.v1.UpdateWorkspacePolicyRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - policy: - title: policy - $ref: '#/components/schemas/console.v1.WorkspaceSettingsPolicy' - title: UpdateWorkspacePolicyRequest - required: - - query - - policy - additionalProperties: false - console.v1.UpdateWorkspacePolicyResponse: - type: object - properties: - settings: - title: settings - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - title: UpdateWorkspacePolicyResponse - required: - - settings - additionalProperties: false - console.v1.UpdateWorkspaceProfileRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - profile: - title: profile - $ref: '#/components/schemas/console.v1.WorkspaceSettingsProfile' - title: UpdateWorkspaceProfileRequest - required: - - query - - profile - additionalProperties: false - console.v1.UpdateWorkspaceProfileResponse: - type: object - properties: - settings: - title: settings - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - title: UpdateWorkspaceProfileResponse - required: - - settings - additionalProperties: false - console.v1.UpdateWorkspaceSkillRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - name: - type: string - title: name - minLength: 1 - description: - type: string - title: description - body: - type: string - title: body - minLength: 1 - title: UpdateWorkspaceSkillRequest - required: - - query - additionalProperties: false - console.v1.UpdateWorkspaceSkillResponse: - type: object - properties: - skill: - title: skill - $ref: '#/components/schemas/console.v1.OperatingSkill' - title: UpdateWorkspaceSkillResponse - required: - - skill - additionalProperties: false - console.v1.UpsertManagedProviderAccessGrantRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - provider: - type: string - title: provider - minLength: 1 - environment: - type: string - title: environment - minLength: 1 - enabled: - type: boolean - title: enabled - note: - type: string - title: note - maxLength: 512 - minLength: 1 - description: Required audit note recorded with every enable/disable action. - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - description: Zero creates a new grant; updates must present the current revision. - state: - title: state - $ref: '#/components/schemas/console.v1.ManagedProviderAccessState' - expiresAt: - title: expires_at - description: Legacy grants retain a bounded expiry. Mutually exclusive with durable_enrollment. - $ref: '#/components/schemas/google.protobuf.Timestamp' - durableEnrollment: - type: boolean - title: durable_enrollment - description: Explicit staff-authorized enrollment independent of execution-token lifetime. - workspaceId: - type: string - title: workspace_id - description: Required for durable enrollment. Persisted for exact-tenant synchronization retries. - title: UpsertManagedProviderAccessGrantRequest - additionalProperties: false - console.v1.UpsertManagedProviderAccessGrantResponse: - type: object - properties: - grant: - title: grant - $ref: '#/components/schemas/console.v1.ManagedProviderAccessGrant' - title: UpsertManagedProviderAccessGrantResponse - additionalProperties: false - console.v1.UpsertWorkspaceGuardrailRuleRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - rule: - title: rule - $ref: '#/components/schemas/console.v1.WorkspaceGuardrailRule' - title: UpsertWorkspaceGuardrailRuleRequest - required: - - query - - rule - additionalProperties: false - console.v1.UpsertWorkspaceIdentityProviderRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - provider: - title: provider - $ref: '#/components/schemas/console.v1.WorkspaceSettingsIdentityProvider' - title: UpsertWorkspaceIdentityProviderRequest - required: - - query - - provider - additionalProperties: false - console.v1.UpsertWorkspaceIdentityProviderResponse: - type: object - properties: - settings: - title: settings - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - title: UpsertWorkspaceIdentityProviderResponse - required: - - settings - additionalProperties: false - console.v1.UpsertWorkspaceIntegrationRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - integration: - title: integration - $ref: '#/components/schemas/console.v1.WorkspaceSettingsIntegration' - title: UpsertWorkspaceIntegrationRequest - required: - - query - - integration - additionalProperties: false - console.v1.UpsertWorkspaceIntegrationResponse: - type: object - properties: - settings: - title: settings - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - title: UpsertWorkspaceIntegrationResponse - required: - - settings - additionalProperties: false - console.v1.UpsertWorkspaceMemberRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - member: - title: member - $ref: '#/components/schemas/console.v1.WorkspaceSettingsMember' - title: UpsertWorkspaceMemberRequest - required: - - query - - member - additionalProperties: false - console.v1.VerifyPrivateEndpointRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - endpointId: - type: string - title: endpoint_id - minLength: 1 - evidenceId: - type: string - title: evidence_id - minLength: 1 - description: |- - Retained for wire compatibility. The server ignores caller-supplied - evidence until a server-owned attestor is configured. - provider: - type: string - title: provider - minLength: 1 - description: Retained for wire compatibility; not trusted as proof. - privateRouteObserved: - type: boolean - title: private_route_observed - description: Retained for wire compatibility; not trusted as proof. - dnsValidated: - type: boolean - title: dns_validated - title: VerifyPrivateEndpointRequest - required: - - query - additionalProperties: false - console.v1.VerifyPrivateEndpointResponse: - type: object - properties: - endpoint: - title: endpoint - $ref: '#/components/schemas/console.v1.PrivateEndpoint' - title: VerifyPrivateEndpointResponse - required: - - endpoint - additionalProperties: false - console.v1.WakeComputerMissionRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - missionId: - type: string - title: mission_id - minLength: 1 - expectedGeneration: - type: - - integer - - string - title: expected_generation - format: int64 - reason: - type: string - title: reason - minLength: 1 - condition: - title: condition - $ref: '#/components/schemas/google.protobuf.Struct' - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - wakeAt: - title: wake_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: WakeComputerMissionRequest - required: - - query - additionalProperties: false - console.v1.WakeComputerMissionResponse: - type: object - properties: - mission: - title: mission - $ref: '#/components/schemas/console.v1.ComputerMission' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.OperatingReceipt' - wakeId: - type: string - title: wake_id - minLength: 1 - title: WakeComputerMissionResponse - required: - - mission - - receipt - additionalProperties: false - console.v1.WatchOperatingThreadRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - minLength: 1 - afterCursor: - type: - - integer - - string - title: after_cursor - format: int64 - title: WatchOperatingThreadRequest - required: - - query - additionalProperties: false - console.v1.WatchOperatingThreadResponse: - type: object - properties: - events: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingThreadEvent' - title: events - maxItems: 50 - nextCursor: - type: - - integer - - string - title: next_cursor - format: int64 - resetRequired: - type: boolean - title: reset_required - threadExecution: - title: thread_execution - $ref: '#/components/schemas/console.v1.OperatingThreadExecution' - snapshotTurns: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingThreadTurn' - title: snapshot_turns - title: WatchOperatingThreadResponse - additionalProperties: false - console.v1.WorkspaceArtifactStyleGuide: - type: object - properties: - enabled: - type: boolean - title: enabled - voiceAndTone: - type: string - title: voice_and_tone - maxLength: 4000 - description: |- - Deprecated compatibility projection of the selected default voice's - guidance. New clients use brand_voices and default_brand_voice_id. - documentGuidance: - type: string - title: document_guidance - maxLength: 8000 - presentationGuidance: - type: string - title: presentation_guidance - maxLength: 8000 - requiredTerms: - type: array - items: - type: string - maxItems: 100 - title: required_terms - maxItems: 100 - forbiddenTerms: - type: array - items: - type: string - maxItems: 100 - title: forbidden_terms - maxItems: 100 - version: - type: - - integer - - string - title: version - format: int64 - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updateCapability: - title: update_capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - responseGuidance: - type: string - title: response_guidance - maxLength: 8000 - requireCitations: - type: boolean - title: require_citations - maxResponseWords: - type: integer - title: max_response_words - maximum: 4000 - allowedCitationDomains: - type: array - items: - type: string - maxItems: 100 - title: allowed_citation_domains - maxItems: 100 - brandVoices: - type: array - items: - $ref: '#/components/schemas/console.v1.WorkspaceBrandVoice' - title: brand_voices - description: |- - Reusable voice assets available to this workspace. Deixic does not impose - a plan or item-count limit; transport and field-size limits still apply to - each request. A voice id has meaning only inside the authorized - organization/workspace pair that returned it. - defaultBrandVoiceId: - type: string - title: default_brand_voice_id - maxLength: 128 - description: |- - Empty means that the workspace has no voice assignment. A non-empty id - must resolve to one active voice in brand_voices; unknown or archived - selections are rejected rather than inherited from another workspace. - title: WorkspaceArtifactStyleGuide - additionalProperties: false - description: |- - WorkspaceArtifactStyleGuide is the workspace-owned Content & AI policy for - user-visible content Dex authors across responses, actions, documents, and - presentations. The historical message name is retained for wire - compatibility. Guidance shapes generation while deterministic controls are - enforced at response and durable-artifact boundaries. - console.v1.WorkspaceBrandVoice: - type: object - properties: - voiceId: - type: string - title: voice_id - maxLength: 128 - name: - type: string - title: name - maxLength: 80 - description: - type: string - title: description - maxLength: 280 - guidance: - type: string - title: guidance - maxLength: 4000 - archived: - type: boolean - title: archived - scopes: - type: array - items: - $ref: '#/components/schemas/console.v1.WorkspaceBrandVoice.Scope' - title: scopes - description: |- - Scopes describe where the company intends to reuse this voice. They are - policy metadata, never authorization input. Kinds are customer-defined so - teams can use organization, team, brand, executive, product, campaign, - customer, or another vocabulary without a schema migration. - version: - type: - - integer - - string - title: version - format: int64 - description: |- - Server-managed revision of this voice asset. It advances only when the - voice's name, description, guidance, scopes, or archive state changes. - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: WorkspaceBrandVoice - additionalProperties: false - description: |- - WorkspaceBrandVoice is declared at the end of this large file so the - additive settings field does not renumber unrelated generated descriptors. - It is a reusable set of writing instructions projected through a workspace's - Content & AI policy. Archiving preserves stable references while preventing - future assignment. - console.v1.WorkspaceBrandVoice.Scope: - type: object - properties: - kind: - type: string - title: kind - maxLength: 64 - value: - type: string - title: value - maxLength: 256 - title: Scope - additionalProperties: false - console.v1.WorkspaceContentPolicyViolation: - type: object - properties: - code: - type: string - title: code - message: - type: string - title: message - title: WorkspaceContentPolicyViolation - additionalProperties: false - console.v1.WorkspaceDexPolicy: - type: object - properties: - autonomyMode: - not: - enum: - - 0 - title: autonomy_mode - $ref: '#/components/schemas/console.v1.DexAutonomyMode' - externalActionMode: - not: - enum: - - 0 - title: external_action_mode - $ref: '#/components/schemas/console.v1.DexExternalActionMode' - projectMemoryEnabled: - type: boolean - title: project_memory_enabled - preferenceMemoryEnabled: - type: boolean - title: preference_memory_enabled - learningFromCorrectionsEnabled: - type: boolean - title: learning_from_corrections_enabled - proactivityEnabled: - type: boolean - title: proactivity_enabled - traceContentCaptureEnabled: - type: boolean - title: trace_content_capture_enabled - maxTurnSeconds: - type: integer - title: max_turn_seconds - maximum: 900 - minimum: 5 - format: int32 - maxToolCalls: - type: integer - title: max_tool_calls - maximum: 64 - format: int32 - maxConcurrency: - type: integer - title: max_concurrency - maximum: 8 - minimum: 1 - format: int32 - maxCostMicros: - type: - - integer - - string - title: max_cost_micros - maximum: 100000000 - format: int64 - allowedSystems: - type: array - items: - type: string - maxItems: 64 - title: allowed_systems - maxItems: 64 - updateCapability: - title: update_capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - reviewCorrectionsCapability: - title: review_corrections_capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - customerIntelligenceEnabled: - type: boolean - title: customer_intelligence_enabled - commitmentNudgesEnabled: - type: boolean - title: commitment_nudges_enabled - description: |- - Proactive commitment-ledger nudges (due-date reminders projected into the - operating channel). On in Dex Standard; workspaces can opt out. The - deployment ceiling DEX_COMMITMENT_NUDGES_ENABLED must also be on, so a - workspace can narrow the ceiling but never widen it. - mcpDispatchEnabled: - type: boolean - title: mcp_dispatch_enabled - description: |- - Opt-in for model-visible governed MCP dispatch (policy-filtered - discovery, Gate admission, and durable approval continuation). Off by - default; the deployment ceiling DEX_MCP_TOOLS_ENABLED must also be on. - Workspaces can narrow the ceiling, never widen it. - subagentDelegationEnabled: - type: boolean - title: subagent_delegation_enabled - description: |- - Customer-facing Subagents opt-in for Dex child-run delegation. Off by - default; the deployment ceiling DEX_DELEGATE_ENABLED must also be on. - Workspaces can narrow the ceiling, never widen it. - title: WorkspaceDexPolicy - additionalProperties: false - console.v1.WorkspaceGuardrailRule: - type: object - properties: - id: - type: string - title: id - maxLength: 128 - minLength: 1 - name: - type: string - title: name - maxLength: 256 - minLength: 1 - detectorKind: - title: detector_kind - $ref: '#/components/schemas/console.v1.GuardrailDetectorKind' - pattern: - type: string - title: pattern - maxLength: 4096 - description: |- - Regex source, required only when detector_kind is CUSTOM_REGEX. Empty for - built-in detectors. - action: - title: action - $ref: '#/components/schemas/console.v1.GuardrailAction' - enabled: - type: boolean - title: enabled - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: WorkspaceGuardrailRule - additionalProperties: false - description: |- - WorkspaceGuardrailRule is one workspace-configured content guardrail applied - to Dex model output. - console.v1.WorkspaceKeyConfigResponse: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - provider: - type: string - title: provider - keyArn: - type: string - title: key_arn - roleArn: - type: string - title: role_arn - hasExternalId: - type: boolean - title: has_external_id - updatedAt: - type: string - title: updated_at - title: WorkspaceKeyConfigResponse - additionalProperties: false - console.v1.WorkspaceMemory: - type: object - properties: - reviewStatus: - title: review_status - $ref: '#/components/schemas/memory.v1.MemoryReviewStatus' - id: - type: string - title: id - minLength: 1 - scope: - title: scope - $ref: '#/components/schemas/memory.v1.Scope' - content: - type: string - title: content - type: - type: string - title: type - tags: - type: array - items: - type: string - maxItems: 64 - title: tags - maxItems: 64 - revision: - type: - - integer - - string - title: revision - minimum: 1 - format: int64 - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: WorkspaceMemory - additionalProperties: false - description: |- - WorkspaceMemory is the customer-safe projection of an owner record. It - deliberately excludes embeddings, internal actor ids, and provenance refs. - console.v1.WorkspaceSettingsActivityEntry: - type: object - properties: - id: - type: string - title: id - section: - type: string - title: section - action: - type: string - title: action - actorSubject: - type: string - title: actor_subject - actorEmail: - type: string - title: actor_email - summary: - type: string - title: summary - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - details: - type: object - title: details - additionalProperties: - type: string - title: value - title: WorkspaceSettingsActivityEntry - additionalProperties: false - console.v1.WorkspaceSettingsActivityEntry.DetailsEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: DetailsEntry - additionalProperties: false - console.v1.WorkspaceSettingsBilling: - type: object - properties: - status: - type: string - title: status - plan: - type: string - title: plan - seatsUsed: - type: integer - title: seats_used - format: int32 - seatsTotal: - type: integer - title: seats_total - format: int32 - renewalAt: - title: renewal_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - billingContact: - type: string - title: billing_contact - manageCapability: - title: manage_capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - statusEnum: - title: status_enum - $ref: '#/components/schemas/console.v1.WorkspaceSettingsBillingStatus' - title: WorkspaceSettingsBilling - additionalProperties: false - console.v1.WorkspaceSettingsBreakGlassGrant: - type: object - properties: - id: - type: string - title: id - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - customerApprovedBy: - type: string - title: customer_approved_by - reason: - type: string - title: reason - supportUserEmail: - type: string - title: support_user_email - readOnly: - type: boolean - title: read_only - enabledAt: - title: enabled_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - disabledAt: - title: disabled_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - manageCapability: - title: manage_capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: WorkspaceSettingsBreakGlassGrant - additionalProperties: false - console.v1.WorkspaceSettingsCapability: - type: object - properties: - id: - type: string - title: id - label: - type: string - title: label - available: - type: boolean - title: available - reason: - type: string - title: reason - actionUrl: - type: string - title: action_url - title: WorkspaceSettingsCapability - additionalProperties: false - console.v1.WorkspaceSettingsIdentityProvider: - type: object - properties: - id: - type: string - title: id - name: - type: string - title: name - detail: - type: string - title: detail - status: - type: string - title: status - configureCapability: - title: configure_capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - source: - type: string - title: source - statusEnum: - title: status_enum - $ref: '#/components/schemas/console.v1.WorkspaceSettingsIdentityProviderStatus' - sourceEnum: - title: source_enum - $ref: '#/components/schemas/console.v1.WorkspaceSettingsSource' - title: WorkspaceSettingsIdentityProvider - additionalProperties: false - console.v1.WorkspaceSettingsIntegration: - type: object - properties: - id: - type: string - title: id - name: - type: string - title: name - provider: - type: string - title: provider - category: - type: string - title: category - detail: - type: string - title: detail - status: - type: string - title: status - configureCapability: - title: configure_capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - source: - type: string - title: source - statusEnum: - title: status_enum - $ref: '#/components/schemas/console.v1.WorkspaceSettingsIntegrationStatus' - sourceEnum: - title: source_enum - $ref: '#/components/schemas/console.v1.WorkspaceSettingsSource' - title: WorkspaceSettingsIntegration - additionalProperties: false - console.v1.WorkspaceSettingsMember: - type: object - properties: - subject: - type: string - title: subject - displayName: - type: string - title: display_name - email: - type: string - title: email - role: - type: string - title: role - description: Legacy display label. New clients should use rbac_role. - source: - type: string - title: source - manageCapability: - title: manage_capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - rbacRole: - title: rbac_role - $ref: '#/components/schemas/console.v1.WorkspaceSettingsRole' - status: - type: string - title: status - managed: - type: boolean - title: managed - provisioningSource: - type: string - title: provisioning_source - lastSeenAt: - title: last_seen_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - statusEnum: - title: status_enum - $ref: '#/components/schemas/console.v1.WorkspaceSettingsMemberStatus' - sourceEnum: - title: source_enum - $ref: '#/components/schemas/console.v1.WorkspaceSettingsSource' - provisioningSourceEnum: - title: provisioning_source_enum - $ref: '#/components/schemas/console.v1.WorkspaceSettingsSource' - title: WorkspaceSettingsMember - additionalProperties: false - console.v1.WorkspaceSettingsNotificationPreference: - type: object - properties: - id: - type: string - title: id - label: - type: string - title: label - detail: - type: string - title: detail - enabled: - type: boolean - title: enabled - updateCapability: - title: update_capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - title: WorkspaceSettingsNotificationPreference - additionalProperties: false - console.v1.WorkspaceSettingsNotifications: - type: object - properties: - status: - type: string - title: status - preferences: - type: array - items: - $ref: '#/components/schemas/console.v1.WorkspaceSettingsNotificationPreference' - title: preferences - statusEnum: - title: status_enum - $ref: '#/components/schemas/console.v1.WorkspaceSettingsAvailabilityStatus' - spendBeat: - title: spend_beat - $ref: '#/components/schemas/console.v1.WorkspaceSpendBeatSettings' - title: WorkspaceSettingsNotifications - additionalProperties: false - console.v1.WorkspaceSettingsOwnerStatus: - type: object - properties: - id: - type: string - title: id - label: - type: string - title: label - ownerService: - type: string - title: owner_service - status: - type: string - title: status - summary: - type: string - title: summary - settings: - type: array - items: - type: string - title: settings - capability: - title: capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - checkedAt: - title: checked_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - statusEnum: - title: status_enum - $ref: '#/components/schemas/console.v1.WorkspaceSettingsOwnerServiceStatus' - title: WorkspaceSettingsOwnerStatus - additionalProperties: false - console.v1.WorkspaceSettingsPolicy: - type: object - properties: - status: - type: string - title: status - requireHumanApprovalForWrites: - type: boolean - title: require_human_approval_for_writes - blockMissingEvidence: - type: boolean - title: block_missing_evidence - autoRevokeIdleLeases: - type: boolean - title: auto_revoke_idle_leases - allowCrossAccountAccess: - type: boolean - title: allow_cross_account_access - maxLeaseTtl: - type: string - title: max_lease_ttl - evidenceRequirement: - type: string - title: evidence_requirement - updateCapability: - title: update_capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - requireMfa: - type: boolean - title: require_mfa - enforceSso: - type: boolean - title: enforce_sso - scimProvisioning: - type: boolean - title: scim_provisioning - defaultMemberRole: - type: string - title: default_member_role - description: Legacy display label. New clients should use default_member_rbac_role. - sessionTtl: - type: string - title: session_ttl - allowedDomains: - type: array - items: - type: string - title: allowed_domains - ipAllowlist: - type: array - items: - type: string - title: ip_allowlist - auditLogRetentionDays: - type: integer - title: audit_log_retention_days - format: int32 - dataRetentionDays: - type: integer - title: data_retention_days - format: int32 - defaultMemberRbacRole: - title: default_member_rbac_role - $ref: '#/components/schemas/console.v1.WorkspaceSettingsRole' - statusEnum: - title: status_enum - $ref: '#/components/schemas/console.v1.WorkspaceSettingsAvailabilityStatus' - taskEnvironmentRetention: - title: task_environment_retention - description: Separate inactivity policy for unaccepted task-computer state. - $ref: '#/components/schemas/console.v1.WorkspaceTaskEnvironmentRetention' - title: WorkspaceSettingsPolicy - additionalProperties: false - console.v1.WorkspaceSettingsPrincipal: - type: object - properties: - subject: - type: string - title: subject - userSubject: - type: string - title: user_subject - displayName: - type: string - title: display_name - role: - type: string - title: role - description: Legacy display label. New clients should use rbac_role. - human: - type: boolean - title: human - rbacRole: - title: rbac_role - $ref: '#/components/schemas/console.v1.WorkspaceSettingsRole' - title: WorkspaceSettingsPrincipal - additionalProperties: false - console.v1.WorkspaceSettingsProfile: - type: object - properties: - organizationId: - type: string - title: organization_id - organizationLabel: - type: string - title: organization_label - workspaceId: - type: string - title: workspace_id - workspaceLabel: - type: string - title: workspace_label - environment: - type: string - title: environment - region: - type: string - title: region - archived: - type: boolean - title: archived - archivedAt: - title: archived_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updateCapability: - title: update_capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - archiveCapability: - title: archive_capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - title: WorkspaceSettingsProfile - additionalProperties: false - console.v1.WorkspaceSettingsWorkspace: - type: object - properties: - organizationId: - type: string - title: organization_id - organizationLabel: - type: string - title: organization_label - workspaceId: - type: string - title: workspace_id - workspaceLabel: - type: string - title: workspace_label - environment: - type: string - title: environment - region: - type: string - title: region - current: - type: boolean - title: current - archived: - type: boolean - title: archived - archivedAt: - title: archived_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - rbacRole: - title: rbac_role - $ref: '#/components/schemas/console.v1.WorkspaceSettingsRole' - capabilities: - type: array - items: - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - title: capabilities - source: - type: string - title: source - title: WorkspaceSettingsWorkspace - additionalProperties: false - console.v1.WorkspaceSpendBeatSettings: - type: object - properties: - enabled: - type: boolean - title: enabled - paused: - type: boolean - title: paused - slackConnectionId: - type: string - title: slack_connection_id - maxLength: 256 - slackChannelId: - type: string - title: slack_channel_id - maxLength: 256 - cadence: - title: cadence - $ref: '#/components/schemas/console.v1.WorkspaceSpendBeatCadence' - timezone: - type: string - title: timezone - maxLength: 128 - localHour: - type: integer - title: local_hour - maximum: 23 - localMinute: - type: integer - title: local_minute - maximum: 59 - weeklyDayMondayZero: - type: integer - title: weekly_day_monday_zero - maximum: 6 - description: Monday=0 through Sunday=6. Used only for weekly cadence. - materialityThresholdBp: - type: integer - title: materiality_threshold_bp - maximum: 100000 - minimum: 1 - materialityAbsoluteMicros: - type: - - integer - - string - title: materiality_absolute_micros - format: int64 - cooldownSeconds: - type: integer - title: cooldown_seconds - maximum: 2592000 - quietHoursStart: - type: string - title: quiet_hours_start - maxLength: 5 - quietHoursEnd: - type: string - title: quiet_hours_end - maxLength: 5 - maxDailyNotifications: - type: integer - title: max_daily_notifications - maximum: 24 - updateCapability: - title: update_capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - title: WorkspaceSpendBeatSettings - additionalProperties: false - description: |- - WorkspaceSpendBeatSettings is the server-authoritative opt-in for scheduled - AI spend briefs and material-drift alerts. Destination ids are re-authorized - at delivery time; storing them here never grants connector access. - console.v1.WorkspaceTaskEnvironmentRetention: - type: object - properties: - retentionDays: - type: integer - title: retention_days - format: int32 - enum: - - 0 - - 7 - - 30 - projects: - type: array - items: - $ref: '#/components/schemas/console.v1.ProjectTaskEnvironmentRetention' - title: projects - policyRevision: - type: - - integer - - string - title: policy_revision - format: int64 - description: |- - Server-owned monotonic revision across workspace and project policy changes. - Mutations ignore caller-supplied values. - retentionHours: - type: integer - title: retention_hours - format: int32 - enum: - - 0 - - 8 - - 168 - - 720 - description: Preferred hour-level policy. Zero means the legacy retention_days field. - title: WorkspaceTaskEnvironmentRetention - additionalProperties: false - google.protobuf.ListValue: - type: object - properties: - values: - type: array - items: - $ref: '#/components/schemas/google.protobuf.Value' - title: values - description: Repeated field of dynamically typed values. - title: ListValue - additionalProperties: false - description: |- - `ListValue` is a wrapper around a repeated field of values. - - The JSON representation for `ListValue` is JSON array. - google.protobuf.Struct: - type: object - additionalProperties: - $ref: '#/components/schemas/google.protobuf.Value' - description: |- - `Struct` represents a structured data value, consisting of fields - which map to dynamically typed values. In some languages, `Struct` - might be supported by a native representation. For example, in - scripting languages like JS a struct is represented as an - object. The details of that representation are described together - with the proto support for the language. - - The JSON representation for `Struct` is JSON object. - google.protobuf.Struct.FieldsEntry: - type: object - properties: - key: - type: string - title: key - value: - title: value - $ref: '#/components/schemas/google.protobuf.Value' - title: FieldsEntry - additionalProperties: false - google.protobuf.Timestamp: - type: string - examples: - - 1s - - 1.000340012s - format: date-time - description: |- - A Timestamp represents a point in time independent of any time zone or local - calendar, encoded as a count of seconds and fractions of seconds at - nanosecond resolution. The count is relative to an epoch at UTC midnight on - January 1, 1970, in the proleptic Gregorian calendar which extends the - Gregorian calendar backwards to year one. - - All minutes are 60 seconds long. Leap seconds are "smeared" so that no leap - second table is needed for interpretation, using a [24-hour linear - smear](https://developers.google.com/time/smear). - - The range is from 0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z. By - restricting to that range, we ensure that we can convert to and from [RFC - 3339](https://www.ietf.org/rfc/rfc3339.txt) date strings. - - # Examples - - Example 1: Compute Timestamp from POSIX `time()`. - - Timestamp timestamp; - timestamp.set_seconds(time(NULL)); - timestamp.set_nanos(0); - - Example 2: Compute Timestamp from POSIX `gettimeofday()`. - - struct timeval tv; - gettimeofday(&tv, NULL); - - Timestamp timestamp; - timestamp.set_seconds(tv.tv_sec); - timestamp.set_nanos(tv.tv_usec * 1000); - - Example 3: Compute Timestamp from Win32 `GetSystemTimeAsFileTime()`. - - FILETIME ft; - GetSystemTimeAsFileTime(&ft); - UINT64 ticks = (((UINT64)ft.dwHighDateTime) << 32) | ft.dwLowDateTime; - - // A Windows tick is 100 nanoseconds. Windows epoch 1601-01-01T00:00:00Z - // is 11644473600 seconds before Unix epoch 1970-01-01T00:00:00Z. - Timestamp timestamp; - timestamp.set_seconds((INT64) ((ticks / 10000000) - 11644473600LL)); - timestamp.set_nanos((INT32) ((ticks % 10000000) * 100)); - - Example 4: Compute Timestamp from Java `System.currentTimeMillis()`. - - long millis = System.currentTimeMillis(); - - Timestamp timestamp = Timestamp.newBuilder().setSeconds(millis / 1000) - .setNanos((int) ((millis % 1000) * 1000000)).build(); - - Example 5: Compute Timestamp from Java `Instant.now()`. - - Instant now = Instant.now(); - - Timestamp timestamp = - Timestamp.newBuilder().setSeconds(now.getEpochSecond()) - .setNanos(now.getNano()).build(); - - Example 6: Compute Timestamp from current time in Python. - - timestamp = Timestamp() - timestamp.GetCurrentTime() - - # JSON Mapping - - In JSON format, the Timestamp type is encoded as a string in the - [RFC 3339](https://www.ietf.org/rfc/rfc3339.txt) format. That is, the - format is "{year}-{month}-{day}T{hour}:{min}:{sec}[.{frac_sec}]Z" - where {year} is always expressed using four digits while {month}, {day}, - {hour}, {min}, and {sec} are zero-padded to two digits each. The fractional - seconds, which can go up to 9 digits (i.e. up to 1 nanosecond resolution), - are optional. The "Z" suffix indicates the timezone ("UTC"); the timezone - is required. A proto3 JSON serializer should always use UTC (as indicated by - "Z") when printing the Timestamp type and a proto3 JSON parser should be - able to accept both UTC and other timezones (as indicated by an offset). - - For example, "2017-01-15T01:30:15.01Z" encodes 15.01 seconds past - 01:30 UTC on January 15, 2017. - - In JavaScript, one can convert a Date object to this format using the - standard - [toISOString()](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Date/toISOString) - method. In Python, a standard `datetime.datetime` object can be converted - to this format using - [`strftime`](https://docs.python.org/2/library/time.html#time.strftime) with - the time format spec '%Y-%m-%dT%H:%M:%S.%fZ'. Likewise, in Java, one can use - the Joda Time's [`ISODateTimeFormat.dateTime()`]( - http://joda-time.sourceforge.net/apidocs/org/joda/time/format/ISODateTimeFormat.html#dateTime() - ) to obtain a formatter capable of generating timestamps in this format. - google.protobuf.Value: - oneOf: - - type: "null" - - type: number - - type: string - - type: boolean - - type: array - - type: object - additionalProperties: true - description: |- - `Value` represents a dynamically typed value which can be either - null, a number, a string, a boolean, a recursive struct value, or a - list of values. A producer of value is expected to set one of these - variants. Absence of any variant indicates an error. - - The JSON representation for `Value` is JSON value. - meter.v1.AdminMutationAuditContext: - type: object - properties: - delegatedActorSubject: - type: string - title: delegated_actor_subject - reason: - type: string - title: reason - requestId: - type: string - title: request_id - title: AdminMutationAuditContext - additionalProperties: false - description: Delegation is accepted only from the authenticated Platform managed-access service. - meter.v1.Budget: - type: object - properties: - id: - type: string - title: id - organizationId: - type: string - title: organization_id - teamId: - type: string - title: team_id - workspaceId: - type: string - title: workspace_id - description: |- - Empty means the budget governs every workspace in the organization. - A non-empty value means the budget governs only that workspace. - period: - type: string - title: period - limitUsd: - exclusiveMinimum: 0 - type: number - title: limit_usd - format: double - alertThresholdPct: - type: integer - title: alert_threshold_pct - format: int32 - warningThresholdsPct: - type: array - items: - type: integer - format: int32 - title: warning_thresholds_pct - hardCap: - type: boolean - title: hard_cap - currentSpendUsd: - type: number - title: current_spend_usd - format: double - lastAlertThresholdPct: - type: integer - title: last_alert_threshold_pct - format: int32 - periodStart: - title: period_start - $ref: '#/components/schemas/google.protobuf.Timestamp' - nextResetAt: - title: next_reset_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: Budget - additionalProperties: false - meter.v1.BudgetDenial: - type: object - properties: - budgetId: - type: string - title: budget_id - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - teamId: - type: string - title: team_id - deniedAt: - title: denied_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - requestId: - type: string - title: request_id - traceId: - type: string - title: trace_id - amountUsd: - type: number - title: amount_usd - format: double - model: - type: string - title: model - provider: - type: string - title: provider - denialReason: - type: string - title: denial_reason - id: - type: string - title: id - description: |- - Stable row identity. A reader that lists denials needs it to key a row it - shows next to rows from another owner. - title: BudgetDenial - additionalProperties: false - description: |- - A budget refusal meter recorded when CheckBudget returned allowed=false. - Meter owns this record; model-gateway does not report it back. - meter.v1.BudgetStatus: - type: object - properties: - budgetId: - type: string - title: budget_id - organizationId: - type: string - title: organization_id - teamId: - type: string - title: team_id - workspaceId: - type: string - title: workspace_id - description: Empty means the budget governs every workspace in the organization. - period: - type: string - title: period - limitUsd: - type: number - title: limit_usd - format: double - currentSpendUsd: - type: number - title: current_spend_usd - format: double - remainingUsd: - type: number - title: remaining_usd - format: double - usagePct: - type: number - title: usage_pct - format: double - alertTriggered: - type: boolean - title: alert_triggered - hardCap: - type: boolean - title: hard_cap - hardCapReached: - type: boolean - title: hard_cap_reached - triggeredThresholdPct: - type: integer - title: triggered_threshold_pct - format: int32 - warningThresholdsPct: - type: array - items: - type: integer - format: int32 - title: warning_thresholds_pct - lastAlertThresholdPct: - type: integer - title: last_alert_threshold_pct - format: int32 - spendVelocityUsdPerHour: - type: number - title: spend_velocity_usd_per_hour - format: double - estimatedExhaustionHours: - type: number - title: estimated_exhaustion_hours - format: double - periodStart: - title: period_start - $ref: '#/components/schemas/google.protobuf.Timestamp' - nextResetAt: - title: next_reset_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: BudgetStatus - additionalProperties: false - meter.v1.DevelopmentCreditGrant: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - programId: - type: string - title: program_id - grantId: - type: string - title: grant_id - creditMicros: - type: - - integer - - string - title: credit_micros - format: int64 - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - reason: - type: string - title: reason - provenance: - type: string - title: provenance - actorSubject: - type: string - title: actor_subject - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - dailyBudgetMicros: - exclusiveMinimum: 0 - type: - - integer - - string - title: daily_budget_micros - format: int64 - description: Server-configured organization-wide daily spend ceiling, including outstanding holds. - alertRecipientId: - type: string - title: alert_recipient_id - description: Server-configured Identity user receiving operational alerts, independent of the grant issuer. - title: DevelopmentCreditGrant - additionalProperties: false - description: Billing's accepted immutable grant receipt. The authenticated issuer is server-derived. - meter.v1.DevelopmentCreditProgramPolicy: - type: object - properties: - maxGrantMicros: - exclusiveMinimum: 0 - type: - - integer - - string - title: max_grant_micros - format: int64 - programBudgetMicros: - exclusiveMinimum: 0 - type: - - integer - - string - title: program_budget_micros - format: int64 - dailyBudgetMicros: - exclusiveMinimum: 0 - type: - - integer - - string - title: daily_budget_micros - format: int64 - maxLifetimeSeconds: - exclusiveMinimum: 0 - type: - - integer - - string - title: max_lifetime_seconds - format: int64 - alertRecipientId: - type: string - title: alert_recipient_id - title: DevelopmentCreditProgramPolicy - additionalProperties: false - description: |- - Immutable sponsored program limits. Enrollment is accepted atomically with its - first grant and requires meter:credits:enroll-development in addition to issuance. - meter.v1.GetBudgetDashboardRequest: - type: object - properties: - teamId: - type: string - title: team_id - workspaceId: - type: string - title: workspace_id - description: |- - Empty reports only organization-wide budgets. A non-empty value must equal - the workspace the caller was authorized for and additionally reports that - workspace's budgets. - title: GetBudgetDashboardRequest - additionalProperties: false - meter.v1.GetBudgetDashboardResponse: - type: object - properties: - organizationId: - type: string - title: organization_id - teamId: - type: string - title: team_id - generatedAt: - title: generated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - totalBudgets: - type: integer - title: total_budgets - format: int32 - totalLimitUsd: - type: number - title: total_limit_usd - format: double - totalSpendUsd: - type: number - title: total_spend_usd - format: double - totalRemainingUsd: - type: number - title: total_remaining_usd - format: double - warningBudgets: - type: integer - title: warning_budgets - format: int32 - hardCapBudgets: - type: integer - title: hard_cap_budgets - format: int32 - hardCapReachedBudgets: - type: integer - title: hard_cap_reached_budgets - format: int32 - statuses: - type: array - items: - $ref: '#/components/schemas/meter.v1.BudgetStatus' - title: statuses - workspaceId: - type: string - title: workspace_id - lastDenial: - title: last_denial - description: The most recent refusal in this scope, absent when nothing was refused. - $ref: '#/components/schemas/meter.v1.BudgetDenial' - title: GetBudgetDashboardResponse - additionalProperties: false - meter.v1.GetPrepaidCreditBalanceRequest: - type: object - properties: - runId: - type: string - title: run_id - maxLength: 256 - workspaceId: - type: string - title: workspace_id - minLength: 1 - title: GetPrepaidCreditBalanceRequest - additionalProperties: false - meter.v1.GetPrepaidCreditBalanceResponse: - type: object - properties: - balance: - title: balance - $ref: '#/components/schemas/meter.v1.PrepaidCreditBalance' - reconciliation: - title: reconciliation - description: Absent when no account exists or an older Meter serves this response. - $ref: '#/components/schemas/meter.v1.PrepaidCreditReconciliation' - runBalance: - title: run_balance - description: Absent for missing attribution or older servers, never an inferred zero. - $ref: '#/components/schemas/meter.v1.PrepaidRunBalance' - developmentProgramPolicy: - title: development_program_policy - description: Immutable owner enrollment limits; absent for legacy or unenrolled programs. - $ref: '#/components/schemas/meter.v1.DevelopmentCreditProgramPolicy' - developmentProgramId: - type: string - title: development_program_id - title: GetPrepaidCreditBalanceResponse - additionalProperties: false - meter.v1.GrantDevelopmentCreditsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - programId: - type: string - title: program_id - minLength: 1 - grantId: - type: string - title: grant_id - minLength: 1 - creditMicros: - exclusiveMinimum: 0 - type: - - integer - - string - title: credit_micros - format: int64 - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - reason: - type: string - title: reason - minLength: 1 - provenance: - type: string - title: provenance - minLength: 1 - enrollmentPolicy: - title: enrollment_policy - description: Optional first enrollment; immutable exact retries only. Omit on later grants. - $ref: '#/components/schemas/meter.v1.DevelopmentCreditProgramPolicy' - title: GrantDevelopmentCreditsRequest - required: - - expiresAt - additionalProperties: false - description: Grant identities and provenance are immutable across retries. Expiry requires microsecond precision. - meter.v1.GrantDevelopmentCreditsResponse: - type: object - properties: - grant: - title: grant - $ref: '#/components/schemas/meter.v1.DevelopmentCreditGrant' - title: GrantDevelopmentCreditsResponse - additionalProperties: false - meter.v1.ListManagedInferenceAdminEventsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - pageSize: - type: integer - title: page_size - maximum: 100 - format: int32 - pageToken: - type: string - title: page_token - title: ListManagedInferenceAdminEventsRequest - additionalProperties: false - meter.v1.ListManagedInferenceAdminEventsResponse: - type: object - properties: - events: - type: array - items: - $ref: '#/components/schemas/meter.v1.ManagedInferenceAdminEvent' - title: events - nextPageToken: - type: string - title: next_page_token - title: ListManagedInferenceAdminEventsResponse - additionalProperties: false - meter.v1.ManagedInferenceAdminEvent: - type: object - properties: - eventId: - type: string - title: event_id - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - actorSubject: - type: string - title: actor_subject - delegatedActorSubject: - type: string - title: delegated_actor_subject - action: - type: string - title: action - resourceId: - type: string - title: resource_id - reason: - type: string - title: reason - outcome: - type: string - title: outcome - beforeBudget: - title: before_budget - $ref: '#/components/schemas/meter.v1.ManagedInferenceBudgetSnapshot' - afterBudget: - title: after_budget - $ref: '#/components/schemas/meter.v1.ManagedInferenceBudgetSnapshot' - creditMicros: - type: - - integer - - string - title: credit_micros - format: int64 - programId: - type: string - title: program_id - provenance: - type: string - title: provenance - requestId: - type: string - title: request_id - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - title: ManagedInferenceAdminEvent - additionalProperties: false - meter.v1.ManagedInferenceBudgetSnapshot: - type: object - properties: - period: - type: string - title: period - limitUsd: - type: number - title: limit_usd - format: double - warningThresholdsPct: - type: array - items: - type: integer - format: int32 - title: warning_thresholds_pct - hardCap: - type: boolean - title: hard_cap - title: ManagedInferenceBudgetSnapshot - additionalProperties: false - meter.v1.PrepaidCreditBalance: - type: object - properties: - compensatedMicros: - type: - - integer - - string - title: compensated_micros - format: int64 - description: Cash recovery, separate from purchases and non-cash grants. - developmentCreditOnly: - type: boolean - title: development_credit_only - description: Enrolled development programs cannot consume paid credits or trigger paid refill. - grantedMicros: - type: - - integer - - string - title: granted_micros - format: int64 - description: Non-cash development funding, kept separate from purchased credits. - expiredGrantMicros: - type: - - integer - - string - title: expired_grant_micros - format: int64 - grantSpentMicros: - type: - - integer - - string - title: grant_spent_micros - format: int64 - grantReservedMicros: - type: - - integer - - string - title: grant_reserved_micros - format: int64 - admissionSuspended: - type: boolean - title: admission_suspended - reversedMicros: - type: - - integer - - string - title: reversed_micros - format: int64 - debtMicros: - type: - - integer - - string - title: debt_micros - format: int64 - purchasedMicros: - type: - - integer - - string - title: purchased_micros - format: int64 - spentMicros: - type: - - integer - - string - title: spent_micros - format: int64 - reservedMicros: - type: - - integer - - string - title: reserved_micros - format: int64 - availableMicros: - type: - - integer - - string - title: available_micros - format: int64 - title: PrepaidCreditBalance - additionalProperties: false - description: |- - Prepaid credits are USD amounts in integer millionths of a dollar. - Meter owns funding, reservations, settlement, and the available balance. - meter.v1.PrepaidCreditReconciliation: - type: object - properties: - compensatedDifferenceMicros: - type: - - integer - - string - title: compensated_difference_micros - format: int64 - grantedDifferenceMicros: - type: - - integer - - string - title: granted_difference_micros - format: int64 - invalidGrantAllocationCount: - type: - - integer - - string - title: invalid_grant_allocation_count - format: int64 - balanced: - type: boolean - title: balanced - description: A comparison of materialized counters with source rows in one snapshot. - purchasedDifferenceMicros: - type: - - integer - - string - title: purchased_difference_micros - format: int64 - reversedDifferenceMicros: - type: - - integer - - string - title: reversed_difference_micros - format: int64 - spentDifferenceMicros: - type: - - integer - - string - title: spent_difference_micros - format: int64 - reservedDifferenceMicros: - type: - - integer - - string - title: reserved_difference_micros - format: int64 - disputeCountDifference: - type: - - integer - - string - title: dispute_count_difference - format: int64 - pendingReservationCount: - type: - - integer - - string - title: pending_reservation_count - format: int64 - oldestPendingAt: - title: oldest_pending_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - unfundedPaymentCount: - type: - - integer - - string - title: unfunded_payment_count - format: int64 - title: PrepaidCreditReconciliation - additionalProperties: false - meter.v1.PrepaidRunBalance: - type: object - properties: - runId: - type: string - title: run_id - settledCostMicros: - type: - - integer - - string - title: settled_cost_micros - format: int64 - reservedMicros: - type: - - integer - - string - title: reserved_micros - format: int64 - pendingRequestCount: - type: - - integer - - string - title: pending_request_count - format: int64 - settledRequestCount: - type: - - integer - - string - title: settled_request_count - format: int64 - oldestPendingAt: - title: oldest_pending_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: PrepaidRunBalance - additionalProperties: false - meter.v1.QueryUsageRequest: - type: object - properties: - teamId: - type: string - title: team_id - agentId: - type: string - title: agent_id - eventType: - type: string - title: event_type - model: - type: string - title: model - provider: - type: string - title: provider - metadataKey: - type: string - title: metadata_key - metadataValue: - type: string - title: metadata_value - startTime: - title: start_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - endTime: - title: end_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - limit: - type: integer - title: limit - maximum: 200 - format: int32 - offset: - type: integer - title: offset - format: int32 - callerIdentity: - type: string - title: caller_identity - title: QueryUsageRequest - additionalProperties: false - meter.v1.QueryUsageResponse: - type: object - properties: - records: - type: array - items: - $ref: '#/components/schemas/meter.v1.UsageRecord' - title: records - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - title: QueryUsageResponse - additionalProperties: false - meter.v1.SetBudgetRequest: - type: object - properties: - auditContext: - title: audit_context - $ref: '#/components/schemas/meter.v1.AdminMutationAuditContext' - budgetId: - type: string - title: budget_id - teamId: - type: string - title: team_id - period: - type: string - title: period - description: |- - Changing the period of an existing budget restarts the spend window: the - service sets period_start to now, clears current_spend_usd, and derives a - new next_reset_at. Sending the same period leaves the window untouched. - limitUsd: - exclusiveMinimum: 0 - type: number - title: limit_usd - format: double - warningThresholdsPct: - type: array - items: - type: integer - format: int32 - title: warning_thresholds_pct - hardCap: - type: boolean - title: hard_cap - workspaceId: - type: string - title: workspace_id - description: |- - Empty creates or updates an organization-wide budget. A non-empty value - must equal the workspace the caller was authorized for. - idempotencyKey: - type: string - title: idempotency_key - maxLength: 256 - description: |- - Empty preserves legacy non-idempotent callers. New callers supply a stable - key for this exact organization and authenticated workspace. - title: SetBudgetRequest - additionalProperties: false - meter.v1.SetBudgetResponse: - type: object - properties: - budget: - title: budget - $ref: '#/components/schemas/meter.v1.Budget' - title: SetBudgetResponse - additionalProperties: false - meter.v1.UsageRecord: - type: object - properties: - id: - type: string - title: id - timestamp: - title: timestamp - $ref: '#/components/schemas/google.protobuf.Timestamp' - organizationId: - type: string - title: organization_id - teamId: - type: string - title: team_id - agentId: - type: string - title: agent_id - surface: - type: string - title: surface - eventType: - type: string - title: event_type - model: - type: string - title: model - provider: - type: string - title: provider - inputTokens: - type: - - integer - - string - title: input_tokens - format: int64 - outputTokens: - type: - - integer - - string - title: output_tokens - format: int64 - cacheReadTokens: - type: - - integer - - string - title: cache_read_tokens - format: int64 - cacheWriteTokens: - type: - - integer - - string - title: cache_write_tokens - format: int64 - totalCostUsd: - type: number - title: total_cost_usd - format: double - requestId: - type: string - title: request_id - data: - title: data - $ref: '#/components/schemas/google.protobuf.Struct' - metadata: - title: metadata - $ref: '#/components/schemas/google.protobuf.Struct' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - callerIdentity: - type: string - title: caller_identity - title: UsageRecord - additionalProperties: false - platform.v1.RecordRef: - type: object - properties: - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/platform.v1.RecordKind' - recordId: - type: string - title: record_id - minLength: 1 - revision: - type: string - title: revision - description: Owner-defined immutable revision or digest when the reference is pinned. - title: RecordRef - additionalProperties: false - description: |- - RecordRef is the canonical, content-free pointer used by customer read - models to join independently owned operational records. It is correlation, - never authority: consumers must resolve it through the owning service under - the authenticated tenant carried by the enclosing request. - platform.v1.ResourceRef: - type: object - properties: - resourceId: - type: string - title: resource_id - minLength: 1 - kind: - title: kind - $ref: '#/components/schemas/platform.v1.ResourceKind' - versionId: - type: string - title: version_id - description: Stable immutable version identity, when the reference is version-bound. - version: - type: integer - title: version - format: int32 - description: |- - Owner-defined monotonic version number. Zero means the latest version - when version_id is empty; version_id wins when both are supplied. - title: ResourceRef - additionalProperties: false - description: |- - ResourceRef is the canonical structured pointer for durable Platform - content. It is intentionally not a URI: callers carry organization and - workspace authority in the surrounding request, while a resolver owned by - the resource's service decides whether a reference yields metadata, VFS - identity, or a short-lived byte-access grant. - remoterunner.v1.RunnerSessionOwnerBinding: - type: object - properties: - missionId: - type: string - title: mission_id - minLength: 1 - runtimeRunId: - type: string - title: runtime_run_id - minLength: 1 - authorityGrantId: - type: string - title: authority_grant_id - minLength: 1 - contractVersion: - type: string - title: contract_version - minLength: 1 - runnerProfile: - type: string - title: runner_profile - minLength: 1 - policyVersion: - type: string - title: policy_version - decisionRoute: - type: string - title: decision_route - selectedCandidateId: - type: string - title: selected_candidate_id - decisionRef: - type: string - title: decision_ref - decisionDigestSha256: - type: string - title: decision_digest_sha256 - title: RunnerSessionOwnerBinding - additionalProperties: false - toolexecution.v1.ToolExecutionAttachmentMount: - type: object - properties: - objectId: - type: string - title: object_id - minLength: 1 - versionId: - type: string - title: version_id - minLength: 1 - filename: - type: string - title: filename - minLength: 1 - sha256: - type: string - title: sha256 - minLength: 1 - sizeBytes: - exclusiveMinimum: 0 - type: - - integer - - string - title: size_bytes - maximum: 52428800 - format: int64 - destinationPath: - type: string - title: destination_path - minLength: 1 - resourceRef: - title: resource_ref - $ref: '#/components/schemas/platform.v1.ResourceRef' - title: ToolExecutionAttachmentMount - additionalProperties: false - description: |- - ToolExecutionAttachmentMount is an immutable, server-authorized VFS version - materialized read-only under the execution's attachment root. - toolexecution.v1.ToolExecutionProjectSource: - type: object - properties: - projectResourceId: - type: string - title: project_resource_id - acceptedRefName: - type: string - title: accepted_ref_name - acceptedRefVersion: - type: - - integer - - string - title: accepted_ref_version - format: int64 - acceptedSnapshotId: - type: string - title: accepted_snapshot_id - sourceWorkspaceId: - type: string - title: source_workspace_id - sourceWorkspaceVersion: - type: - - integer - - string - title: source_workspace_version - format: int64 - files: - type: array - items: - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionProjectSourceFile' - title: files - maxItems: 1000 - title: ToolExecutionProjectSource - additionalProperties: false - description: Server-owned, pinned accepted source. Never a writable shared directory. - toolexecution.v1.ToolExecutionProjectSourceFile: - type: object - properties: - path: - type: string - title: path - objectId: - type: string - title: object_id - versionId: - type: string - title: version_id - sha256: - type: string - title: sha256 - sizeBytes: - type: - - integer - - string - title: size_bytes - format: int64 - executable: - type: boolean - title: executable - title: ToolExecutionProjectSourceFile - additionalProperties: false - description: An immutable file restored below the private task workspace. - toolexecution.v1.ToolExecutionWorkspaceRecipe: - type: object - properties: - schemaVersion: - type: string - title: schema_version - const: deixic.workspace_recipe.v1 - recipeId: - type: string - title: recipe_id - minLength: 1 - recipeVersion: - type: - - integer - - string - title: recipe_version - minimum: 1 - format: int64 - recipeDigest: - type: string - title: recipe_digest - minLength: 1 - sourceManifestDigest: - type: string - title: source_manifest_digest - minLength: 1 - requiredRuntimes: - type: array - items: - type: string - maxLength: 64 - minLength: 1 - maxItems: 16 - title: required_runtimes - maxItems: 16 - preparationTool: - type: string - title: preparation_tool - const: computer.check_runtimes - executionOwner: - type: string - title: execution_owner - const: platform-api.dex - title: ToolExecutionWorkspaceRecipe - additionalProperties: false - description: |- - Versioned, server-owned preparation recipe for one task workspace. The - recipe carries bounded declarative requirements; it cannot contain shell - commands, repository hooks, credentials, or approval policy. - traces.v1.TraceAnnotation: - type: object - properties: - annotationId: - type: string - title: annotation_id - traceId: - type: string - title: trace_id - minLength: 1 - spanId: - type: string - title: span_id - kind: - title: kind - $ref: '#/components/schemas/traces.v1.TraceAnnotationKind' - note: - type: string - title: note - labels: - type: array - items: - type: string - title: labels - source: - type: string - title: source - metadata: - title: metadata - $ref: '#/components/schemas/google.protobuf.Struct' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - status: - title: status - $ref: '#/components/schemas/traces.v1.TraceAnnotationStatus' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - resolvedAt: - title: resolved_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - resolvedBy: - type: string - title: resolved_by - title: TraceAnnotation - additionalProperties: false - vfs.v1.VfsCompletedUploadPart: - type: object - properties: - partNumber: - exclusiveMinimum: 0 - type: integer - title: part_number - format: int32 - etag: - type: string - title: etag - minLength: 1 - title: VfsCompletedUploadPart - additionalProperties: false - vfs.v1.VfsUploadPartTarget: - type: object - properties: - partNumber: - exclusiveMinimum: 0 - type: integer - title: part_number - format: int32 - offset: - type: - - integer - - string - title: offset - format: int64 - sizeBytes: - exclusiveMinimum: 0 - type: - - integer - - string - title: size_bytes - format: int64 - url: - type: string - title: url - minLength: 1 - method: - type: string - title: method - minLength: 1 - headers: - type: object - title: headers - additionalProperties: - type: string - title: value - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: VfsUploadPartTarget - additionalProperties: false - vfs.v1.VfsUploadPartTarget.HeadersEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: HeadersEntry - additionalProperties: false - vfs.v1.VfsUploadTarget: - type: object - properties: - url: - type: string - title: url - method: - type: string - title: method - minLength: 1 - headers: - type: object - title: headers - additionalProperties: - type: string - title: value - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - maxSizeBytes: - exclusiveMinimum: 0 - type: - - integer - - string - title: max_size_bytes - maximum: 52428800 - format: int64 - parts: - type: array - items: - $ref: '#/components/schemas/vfs.v1.VfsUploadPartTarget' - title: parts - title: VfsUploadTarget - additionalProperties: false - vfs.v1.VfsUploadTarget.HeadersEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: HeadersEntry - additionalProperties: false - connect-protocol-version: - type: number - title: Connect-Protocol-Version - enum: - - 1 - description: Define the version of the Connect protocol - const: 1 - connect-timeout-header: - type: number - title: Connect-Timeout-Ms - description: Define the timeout, in ms - connect.error: - type: object - properties: - code: - type: string - examples: - - not_found - enum: - - canceled - - unknown - - invalid_argument - - deadline_exceeded - - not_found - - already_exists - - permission_denied - - resource_exhausted - - failed_precondition - - aborted - - out_of_range - - unimplemented - - internal - - unavailable - - data_loss - - unauthenticated - description: The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code]. - message: - type: string - description: A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client. - detail: - $ref: '#/components/schemas/google.protobuf.Any' - title: Connect Error - additionalProperties: true - description: 'Error type returned by Connect: https://connectrpc.com/docs/go/errors/#http-representation' - google.protobuf.Any: - type: object - properties: - type: - type: string - value: - type: string - format: binary - debug: - type: object - additionalProperties: true - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. -security: [] -tags: - - name: console.v1.ConsoleService - description: |- - ConsoleService provides the product-facing AI operations read model for the - EvalOps web console. It composes agent inventory, traces, approvals, - governance, usage, integrations, and posture without exposing protocol - details such as MCP as the primary product contract. - - name: console.v1.WorkspaceKeyService - description: |- - WorkspaceKeyService manages workspace-level managed-credential key custody. - The external ID is write-only and is never present in a response. - - name: console.v1.ManagedSetupService - description: |- - ManagedSetupService serves the organization-owned agent client configuration - that administrators define once and every agent client enforces. Reads are - available to members so a running client can refresh; writes are an - administrative action. diff --git a/openapi/deixic/v1/deixic.openapi.yaml b/openapi/deixic/v1/deixic.openapi.yaml deleted file mode 100644 index 9085d6a..0000000 --- a/openapi/deixic/v1/deixic.openapi.yaml +++ /dev/null @@ -1,33155 +0,0 @@ -openapi: 3.1.0 -info: - title: deixic.v1 -paths: - /deixic.v1.DeixicService/AssessComplianceSubject: - post: - tags: - - deixic.v1.DeixicService - summary: AssessComplianceSubject - description: Evaluates a versioned compliance profile against owner-fetched, tenant-scoped facts. - operationId: deixic.v1.DeixicService.AssessComplianceSubject - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.AssessComplianceSubjectRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.AssessComplianceSubjectResponse' - /deixic.v1.DeixicService/RecordComplianceAssessment: - post: - tags: - - deixic.v1.DeixicService - summary: RecordComplianceAssessment - operationId: deixic.v1.DeixicService.RecordComplianceAssessment - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RecordComplianceAssessmentRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RecordComplianceAssessmentResponse' - /deixic.v1.DeixicService/GetComplianceAssessment: - post: - tags: - - deixic.v1.DeixicService - summary: GetComplianceAssessment - operationId: deixic.v1.DeixicService.GetComplianceAssessment - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetComplianceAssessmentRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetComplianceAssessmentResponse' - /deixic.v1.DeixicService/ListBusinessBlueprints: - post: - tags: - - deixic.v1.DeixicService - summary: ListBusinessBlueprints - description: Lists built-in native business blueprints available to every authorized tenant. - operationId: deixic.v1.DeixicService.ListBusinessBlueprints - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListBusinessBlueprintsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListBusinessBlueprintsResponse' - /deixic.v1.DeixicService/CloneBusinessBlueprint: - post: - tags: - - deixic.v1.DeixicService - summary: CloneBusinessBlueprint - description: Clones a pinned built-in blueprint into editable tenant-owned definitions and a draft form. - operationId: deixic.v1.DeixicService.CloneBusinessBlueprint - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CloneBusinessBlueprintRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CloneBusinessBlueprintResponse' - /deixic.v1.DeixicService/GetBusinessProcessDefinition: - post: - tags: - - deixic.v1.DeixicService - summary: GetBusinessProcessDefinition - description: GetBusinessProcessDefinition reads immutable process definitions within the tenant. - operationId: deixic.v1.DeixicService.GetBusinessProcessDefinition - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetBusinessProcessDefinitionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetBusinessProcessDefinitionResponse' - /deixic.v1.DeixicService/ListBusinessProcessDefinitions: - post: - tags: - - deixic.v1.DeixicService - summary: ListBusinessProcessDefinitions - description: ListBusinessProcessDefinitions reads immutable process definitions within the tenant. - operationId: deixic.v1.DeixicService.ListBusinessProcessDefinitions - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListBusinessProcessDefinitionsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListBusinessProcessDefinitionsResponse' - /deixic.v1.DeixicService/DefineBusinessProcess: - post: - tags: - - deixic.v1.DeixicService - summary: DefineBusinessProcess - description: DefineBusinessProcess accesses the durable object-bound process owner. - operationId: deixic.v1.DeixicService.DefineBusinessProcess - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DefineBusinessProcessRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DefineBusinessProcessResponse' - /deixic.v1.DeixicService/StartBusinessProcess: - post: - tags: - - deixic.v1.DeixicService - summary: StartBusinessProcess - description: StartBusinessProcess accesses the durable object-bound process owner. - operationId: deixic.v1.DeixicService.StartBusinessProcess - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.StartBusinessProcessRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.StartBusinessProcessResponse' - /deixic.v1.DeixicService/GetBusinessProcess: - post: - tags: - - deixic.v1.DeixicService - summary: GetBusinessProcess - description: GetBusinessProcess accesses the durable object-bound process owner. - operationId: deixic.v1.DeixicService.GetBusinessProcess - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetBusinessProcessRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetBusinessProcessResponse' - /deixic.v1.DeixicService/ListBusinessProcesses: - post: - tags: - - deixic.v1.DeixicService - summary: ListBusinessProcesses - description: ListBusinessProcesses accesses the durable object-bound process owner. - operationId: deixic.v1.DeixicService.ListBusinessProcesses - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListBusinessProcessesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListBusinessProcessesResponse' - /deixic.v1.DeixicService/TransitionBusinessProcess: - post: - tags: - - deixic.v1.DeixicService - summary: TransitionBusinessProcess - description: TransitionBusinessProcess accesses the durable object-bound process owner. - operationId: deixic.v1.DeixicService.TransitionBusinessProcess - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.TransitionBusinessProcessRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.TransitionBusinessProcessResponse' - /deixic.v1.DeixicService/PrepareBusinessObjectAuthorityTransfer: - post: - tags: - - deixic.v1.DeixicService - summary: PrepareBusinessObjectAuthorityTransfer - description: Checks source-authority readiness without changing accepted state. - operationId: deixic.v1.DeixicService.PrepareBusinessObjectAuthorityTransfer - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.PrepareBusinessObjectAuthorityTransferRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.PrepareBusinessObjectAuthorityTransferResponse' - /deixic.v1.DeixicService/FinalizeBusinessObjectAuthorityTransfer: - post: - tags: - - deixic.v1.DeixicService - summary: FinalizeBusinessObjectAuthorityTransfer - description: Checks source-authority readiness without changing accepted state. - operationId: deixic.v1.DeixicService.FinalizeBusinessObjectAuthorityTransfer - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.FinalizeBusinessObjectAuthorityTransferRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.FinalizeBusinessObjectAuthorityTransferResponse' - /deixic.v1.DeixicService/DefineBusinessObjectType: - post: - tags: - - deixic.v1.DeixicService - summary: DefineBusinessObjectType - description: DefineBusinessObjectType uses tenant-scoped durable business object state. - operationId: deixic.v1.DeixicService.DefineBusinessObjectType - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DefineBusinessObjectTypeRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DefineBusinessObjectTypeResponse' - /deixic.v1.DeixicService/GetBusinessObjectType: - post: - tags: - - deixic.v1.DeixicService - summary: GetBusinessObjectType - description: GetBusinessObjectType reads an exact immutable published schema revision. - operationId: deixic.v1.DeixicService.GetBusinessObjectType - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetBusinessObjectTypeRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetBusinessObjectTypeResponse' - /deixic.v1.DeixicService/ListBusinessObjectTypes: - post: - tags: - - deixic.v1.DeixicService - summary: ListBusinessObjectTypes - description: ListBusinessObjectTypes uses tenant-scoped durable business object state. - operationId: deixic.v1.DeixicService.ListBusinessObjectTypes - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListBusinessObjectTypesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListBusinessObjectTypesResponse' - /deixic.v1.DeixicService/CreateBusinessObject: - post: - tags: - - deixic.v1.DeixicService - summary: CreateBusinessObject - description: CreateBusinessObject uses tenant-scoped durable business object state. - operationId: deixic.v1.DeixicService.CreateBusinessObject - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateBusinessObjectRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateBusinessObjectResponse' - /deixic.v1.DeixicService/GetBusinessObject: - post: - tags: - - deixic.v1.DeixicService - summary: GetBusinessObject - description: GetBusinessObject uses tenant-scoped durable business object state. - operationId: deixic.v1.DeixicService.GetBusinessObject - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetBusinessObjectRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetBusinessObjectResponse' - /deixic.v1.DeixicService/ListBusinessObjects: - post: - tags: - - deixic.v1.DeixicService - summary: ListBusinessObjects - description: ListBusinessObjects uses tenant-scoped durable business object state. - operationId: deixic.v1.DeixicService.ListBusinessObjects - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListBusinessObjectsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListBusinessObjectsResponse' - /deixic.v1.DeixicService/UpdateBusinessObject: - post: - tags: - - deixic.v1.DeixicService - summary: UpdateBusinessObject - description: UpdateBusinessObject uses tenant-scoped durable business object state. - operationId: deixic.v1.DeixicService.UpdateBusinessObject - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateBusinessObjectRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateBusinessObjectResponse' - /deixic.v1.DeixicService/DeleteBusinessObject: - post: - tags: - - deixic.v1.DeixicService - summary: DeleteBusinessObject - description: DeleteBusinessObject uses tenant-scoped durable business object state. - operationId: deixic.v1.DeixicService.DeleteBusinessObject - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DeleteBusinessObjectRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DeleteBusinessObjectResponse' - /deixic.v1.DeixicService/ListBusinessObjectRevisions: - post: - tags: - - deixic.v1.DeixicService - summary: ListBusinessObjectRevisions - description: ListBusinessObjectRevisions uses tenant-scoped durable business object state. - operationId: deixic.v1.DeixicService.ListBusinessObjectRevisions - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListBusinessObjectRevisionsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListBusinessObjectRevisionsResponse' - /deixic.v1.DeixicService/BindBusinessObjectSource: - post: - tags: - - deixic.v1.DeixicService - summary: BindBusinessObjectSource - description: BindBusinessObjectSource uses tenant-scoped durable business object state. - operationId: deixic.v1.DeixicService.BindBusinessObjectSource - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.BindBusinessObjectSourceRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.BindBusinessObjectSourceResponse' - /deixic.v1.DeixicService/AdmitBusinessObjectObservation: - post: - tags: - - deixic.v1.DeixicService - summary: AdmitBusinessObjectObservation - description: AdmitBusinessObjectObservation uses tenant-scoped durable business object state. - operationId: deixic.v1.DeixicService.AdmitBusinessObjectObservation - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.AdmitBusinessObjectObservationRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.AdmitBusinessObjectObservationResponse' - /deixic.v1.DeixicService/ListBusinessObjectRelationships: - post: - tags: - - deixic.v1.DeixicService - summary: ListBusinessObjectRelationships - description: ListBusinessObjectRelationships uses tenant-scoped durable business object state. - operationId: deixic.v1.DeixicService.ListBusinessObjectRelationships - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListBusinessObjectRelationshipsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListBusinessObjectRelationshipsResponse' - /deixic.v1.DeixicService/CreateBusinessObjectRelationship: - post: - tags: - - deixic.v1.DeixicService - summary: CreateBusinessObjectRelationship - description: CreateBusinessObjectRelationship uses tenant-scoped durable business object state. - operationId: deixic.v1.DeixicService.CreateBusinessObjectRelationship - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateBusinessObjectRelationshipRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateBusinessObjectRelationshipResponse' - /deixic.v1.DeixicService/DeleteBusinessObjectRelationship: - post: - tags: - - deixic.v1.DeixicService - summary: DeleteBusinessObjectRelationship - description: DeleteBusinessObjectRelationship uses tenant-scoped durable business object state. - operationId: deixic.v1.DeixicService.DeleteBusinessObjectRelationship - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DeleteBusinessObjectRelationshipRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DeleteBusinessObjectRelationshipResponse' - /deixic.v1.DeixicService/CreateCaptureForm: - post: - tags: - - deixic.v1.DeixicService - summary: CreateCaptureForm - description: Uses the canonical console.v1.ConsoleService capture-form contract. - operationId: deixic.v1.DeixicService.CreateCaptureForm - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateCaptureFormRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateCaptureFormResponse' - /deixic.v1.DeixicService/ListCaptureForms: - post: - tags: - - deixic.v1.DeixicService - summary: ListCaptureForms - description: Uses the canonical console.v1.ConsoleService capture-form contract. - operationId: deixic.v1.DeixicService.ListCaptureForms - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListCaptureFormsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListCaptureFormsResponse' - /deixic.v1.DeixicService/GetCaptureForm: - post: - tags: - - deixic.v1.DeixicService - summary: GetCaptureForm - description: Uses the canonical console.v1.ConsoleService capture-form contract. - operationId: deixic.v1.DeixicService.GetCaptureForm - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetCaptureFormRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetCaptureFormResponse' - /deixic.v1.DeixicService/UpdateCaptureForm: - post: - tags: - - deixic.v1.DeixicService - summary: UpdateCaptureForm - description: Uses the canonical console.v1.ConsoleService capture-form contract. - operationId: deixic.v1.DeixicService.UpdateCaptureForm - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateCaptureFormRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateCaptureFormResponse' - /deixic.v1.DeixicService/PublishCaptureForm: - post: - tags: - - deixic.v1.DeixicService - summary: PublishCaptureForm - description: Uses the canonical console.v1.ConsoleService capture-form contract. - operationId: deixic.v1.DeixicService.PublishCaptureForm - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.PublishCaptureFormRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.PublishCaptureFormResponse' - /deixic.v1.DeixicService/RevokeCaptureFormPublication: - post: - tags: - - deixic.v1.DeixicService - summary: RevokeCaptureFormPublication - description: Uses the canonical console.v1.ConsoleService capture-form contract. - operationId: deixic.v1.DeixicService.RevokeCaptureFormPublication - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RevokeCaptureFormPublicationRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RevokeCaptureFormPublicationResponse' - /deixic.v1.DeixicService/CreateCaptureFormInvitation: - post: - tags: - - deixic.v1.DeixicService - summary: CreateCaptureFormInvitation - description: CreateCaptureFormInvitation uses recipient verification at the Capture Forms owner. - operationId: deixic.v1.DeixicService.CreateCaptureFormInvitation - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateCaptureFormInvitationRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateCaptureFormInvitationResponse' - /deixic.v1.DeixicService/RevokeCaptureFormInvitation: - post: - tags: - - deixic.v1.DeixicService - summary: RevokeCaptureFormInvitation - description: RevokeCaptureFormInvitation uses recipient verification at the Capture Forms owner. - operationId: deixic.v1.DeixicService.RevokeCaptureFormInvitation - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RevokeCaptureFormInvitationRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RevokeCaptureFormInvitationResponse' - /deixic.v1.DeixicService/GetInvitedCaptureForm: - post: - tags: - - deixic.v1.DeixicService - summary: GetInvitedCaptureForm - description: GetInvitedCaptureForm uses recipient verification at the Capture Forms owner. - operationId: deixic.v1.DeixicService.GetInvitedCaptureForm - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetInvitedCaptureFormRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetInvitedCaptureFormResponse' - /deixic.v1.DeixicService/SubmitInvitedCaptureForm: - post: - tags: - - deixic.v1.DeixicService - summary: SubmitInvitedCaptureForm - description: SubmitInvitedCaptureForm uses recipient verification at the Capture Forms owner. - operationId: deixic.v1.DeixicService.SubmitInvitedCaptureForm - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitInvitedCaptureFormRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitInvitedCaptureFormResponse' - /deixic.v1.DeixicService/GetPublishedCaptureForm: - post: - tags: - - deixic.v1.DeixicService - summary: GetPublishedCaptureForm - description: Uses the canonical console.v1.ConsoleService capture-form contract. - operationId: deixic.v1.DeixicService.GetPublishedCaptureForm - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetPublishedCaptureFormRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetPublishedCaptureFormResponse' - /deixic.v1.DeixicService/GetPublishedCaptureFormBrandingAsset: - post: - tags: - - deixic.v1.DeixicService - summary: GetPublishedCaptureFormBrandingAsset - description: Uses the canonical console.v1.ConsoleService capture-form contract. - operationId: deixic.v1.DeixicService.GetPublishedCaptureFormBrandingAsset - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetPublishedCaptureFormBrandingAssetRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetPublishedCaptureFormBrandingAssetResponse' - /deixic.v1.DeixicService/SubmitPublishedCaptureForm: - post: - tags: - - deixic.v1.DeixicService - summary: SubmitPublishedCaptureForm - description: Uses the canonical console.v1.ConsoleService capture-form contract. - operationId: deixic.v1.DeixicService.SubmitPublishedCaptureForm - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitPublishedCaptureFormRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitPublishedCaptureFormResponse' - /deixic.v1.DeixicService/BeginPublishedCaptureFormUpload: - post: - tags: - - deixic.v1.DeixicService - summary: BeginPublishedCaptureFormUpload - description: Uses the canonical console.v1.ConsoleService capture-form contract. - operationId: deixic.v1.DeixicService.BeginPublishedCaptureFormUpload - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.BeginPublishedCaptureFormUploadRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.BeginPublishedCaptureFormUploadResponse' - /deixic.v1.DeixicService/CompletePublishedCaptureFormUpload: - post: - tags: - - deixic.v1.DeixicService - summary: CompletePublishedCaptureFormUpload - description: Uses the canonical console.v1.ConsoleService capture-form contract. - operationId: deixic.v1.DeixicService.CompletePublishedCaptureFormUpload - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CompletePublishedCaptureFormUploadRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CompletePublishedCaptureFormUploadResponse' - /deixic.v1.DeixicService/GetCaptureFormSubmission: - post: - tags: - - deixic.v1.DeixicService - summary: GetCaptureFormSubmission - description: Uses the canonical console.v1.ConsoleService capture-form contract. - operationId: deixic.v1.DeixicService.GetCaptureFormSubmission - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetCaptureFormSubmissionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetCaptureFormSubmissionResponse' - /deixic.v1.DeixicService/ListCaptureFormSubmissions: - post: - tags: - - deixic.v1.DeixicService - summary: ListCaptureFormSubmissions - description: Uses the canonical console.v1.ConsoleService capture-form contract. - operationId: deixic.v1.DeixicService.ListCaptureFormSubmissions - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListCaptureFormSubmissionsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListCaptureFormSubmissionsResponse' - /deixic.v1.DeixicService/ReviewCaptureFormSubmission: - post: - tags: - - deixic.v1.DeixicService - summary: ReviewCaptureFormSubmission - description: Uses the canonical console.v1.ConsoleService capture-form contract. - operationId: deixic.v1.DeixicService.ReviewCaptureFormSubmission - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReviewCaptureFormSubmissionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReviewCaptureFormSubmissionResponse' - /deixic.v1.DeixicService/GetInferenceCreditAutoRefill: - post: - tags: - - deixic.v1.DeixicService - summary: GetInferenceCreditAutoRefill - description: GetInferenceCreditAutoRefill uses authorized workspace billing consent. - operationId: deixic.v1.DeixicService.GetInferenceCreditAutoRefill - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetInferenceCreditAutoRefillRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetInferenceCreditAutoRefillResponse' - /deixic.v1.DeixicService/UpdateInferenceCreditAutoRefill: - post: - tags: - - deixic.v1.DeixicService - summary: UpdateInferenceCreditAutoRefill - description: UpdateInferenceCreditAutoRefill uses authorized workspace billing consent. - operationId: deixic.v1.DeixicService.UpdateInferenceCreditAutoRefill - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateInferenceCreditAutoRefillRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateInferenceCreditAutoRefillResponse' - /deixic.v1.DeixicService/CompleteInferenceCreditAutoRefill: - post: - tags: - - deixic.v1.DeixicService - summary: CompleteInferenceCreditAutoRefill - description: CompleteInferenceCreditAutoRefill uses authorized workspace billing consent. - operationId: deixic.v1.DeixicService.CompleteInferenceCreditAutoRefill - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CompleteInferenceCreditAutoRefillRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CompleteInferenceCreditAutoRefillResponse' - /deixic.v1.DeixicService/ListInferenceCreditReceipts: - post: - tags: - - deixic.v1.DeixicService - summary: ListInferenceCreditReceipts - description: ListInferenceCreditReceipts returns verified payments for the authorized workspace. - operationId: deixic.v1.DeixicService.ListInferenceCreditReceipts - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListInferenceCreditReceiptsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListInferenceCreditReceiptsResponse' - /deixic.v1.DeixicService/GetInferenceCreditBalance: - post: - tags: - - deixic.v1.DeixicService - summary: GetInferenceCreditBalance - description: Uses the canonical console.v1.ConsoleService.GetInferenceCreditBalance message contract. - operationId: deixic.v1.DeixicService.GetInferenceCreditBalance - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetInferenceCreditBalanceRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetInferenceCreditBalanceResponse' - /deixic.v1.DeixicService/CreateInferenceCreditCheckout: - post: - tags: - - deixic.v1.DeixicService - summary: CreateInferenceCreditCheckout - description: Uses the canonical console.v1.ConsoleService.CreateInferenceCreditCheckout message contract. - operationId: deixic.v1.DeixicService.CreateInferenceCreditCheckout - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateInferenceCreditCheckoutRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateInferenceCreditCheckoutResponse' - /deixic.v1.DeixicService/FulfillInferenceCreditCheckout: - post: - tags: - - deixic.v1.DeixicService - summary: FulfillInferenceCreditCheckout - description: Uses the canonical console.v1.ConsoleService.FulfillInferenceCreditCheckout message contract. - operationId: deixic.v1.DeixicService.FulfillInferenceCreditCheckout - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.FulfillInferenceCreditCheckoutRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.FulfillInferenceCreditCheckoutResponse' - /deixic.v1.DeixicService/GetOverview: - post: - tags: - - deixic.v1.DeixicService - summary: GetOverview - description: Uses the canonical console.v1.ConsoleService.GetOverview message contract. - operationId: deixic.v1.DeixicService.GetOverview - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOverviewRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOverviewResponse' - /deixic.v1.DeixicService/ListAssets: - post: - tags: - - deixic.v1.DeixicService - summary: ListAssets - description: Uses the canonical console.v1.ConsoleService.ListAssets message contract. - operationId: deixic.v1.DeixicService.ListAssets - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListAssetsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListAssetsResponse' - /deixic.v1.DeixicService/GetAsset: - post: - tags: - - deixic.v1.DeixicService - summary: GetAsset - description: Uses the canonical console.v1.ConsoleService.GetAsset message contract. - operationId: deixic.v1.DeixicService.GetAsset - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetAssetRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetAssetResponse' - /deixic.v1.DeixicService/ListFindings: - post: - tags: - - deixic.v1.DeixicService - summary: ListFindings - description: Uses the canonical console.v1.ConsoleService.ListFindings message contract. - operationId: deixic.v1.DeixicService.ListFindings - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListFindingsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListFindingsResponse' - /deixic.v1.DeixicService/GetTraceDrilldown: - post: - tags: - - deixic.v1.DeixicService - summary: GetTraceDrilldown - description: Uses the canonical console.v1.ConsoleService.GetTraceDrilldown message contract. - operationId: deixic.v1.DeixicService.GetTraceDrilldown - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetTraceDrilldownRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetTraceDrilldownResponse' - /deixic.v1.DeixicService/GetOnboardingPlan: - post: - tags: - - deixic.v1.DeixicService - summary: GetOnboardingPlan - description: Uses the canonical console.v1.ConsoleService.GetOnboardingPlan message contract. - operationId: deixic.v1.DeixicService.GetOnboardingPlan - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOnboardingPlanRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOnboardingPlanResponse' - /deixic.v1.DeixicService/ListAuthorityPosture: - post: - tags: - - deixic.v1.DeixicService - summary: ListAuthorityPosture - description: Uses the canonical console.v1.ConsoleService.ListAuthorityPosture message contract. - operationId: deixic.v1.DeixicService.ListAuthorityPosture - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListAuthorityPostureRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListAuthorityPostureResponse' - /deixic.v1.DeixicService/ListAgentWorkforceRecords: - post: - tags: - - deixic.v1.DeixicService - summary: ListAgentWorkforceRecords - description: Uses the canonical console.v1.ConsoleService.ListAgentWorkforceRecords message contract. - operationId: deixic.v1.DeixicService.ListAgentWorkforceRecords - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListAgentWorkforceRecordsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListAgentWorkforceRecordsResponse' - /deixic.v1.DeixicService/GetAgentProduct: - post: - tags: - - deixic.v1.DeixicService - summary: GetAgentProduct - description: Reads the registered agent product object from its versioned and connector owners. - operationId: deixic.v1.DeixicService.GetAgentProduct - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetAgentProductRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetAgentProductResponse' - /deixic.v1.DeixicService/CloneAgentProduct: - post: - tags: - - deixic.v1.DeixicService - summary: CloneAgentProduct - description: Clones safe agent behavior through the registry owner for the current workspace. - operationId: deixic.v1.DeixicService.CloneAgentProduct - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CloneAgentProductRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CloneAgentProductResponse' - /deixic.v1.DeixicService/UpdateAgentProduct: - post: - tags: - - deixic.v1.DeixicService - summary: UpdateAgentProduct - description: Writes editable agent behavior through the registry's immutable versioned owner. - operationId: deixic.v1.DeixicService.UpdateAgentProduct - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateAgentProductRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateAgentProductResponse' - /deixic.v1.DeixicService/SubmitAgentWorkforceEvidence: - post: - tags: - - deixic.v1.DeixicService - summary: SubmitAgentWorkforceEvidence - description: Uses the canonical console.v1.ConsoleService.SubmitAgentWorkforceEvidence message contract. - operationId: deixic.v1.DeixicService.SubmitAgentWorkforceEvidence - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitAgentWorkforceEvidenceRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitAgentWorkforceEvidenceResponse' - /deixic.v1.DeixicService/ListIntegrationTiles: - post: - tags: - - deixic.v1.DeixicService - summary: ListIntegrationTiles - description: Uses the canonical console.v1.ConsoleService.ListIntegrationTiles message contract. - operationId: deixic.v1.DeixicService.ListIntegrationTiles - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListIntegrationTilesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListIntegrationTilesResponse' - /deixic.v1.DeixicService/ListPinnedSources: - post: - tags: - - deixic.v1.DeixicService - summary: ListPinnedSources - description: Uses the canonical console.v1.ConsoleService.ListPinnedSources message contract. - operationId: deixic.v1.DeixicService.ListPinnedSources - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListPinnedSourcesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListPinnedSourcesResponse' - /deixic.v1.DeixicService/ListOrbControlTargets: - post: - tags: - - deixic.v1.DeixicService - summary: ListOrbControlTargets - description: Uses the canonical console.v1.ConsoleService.ListOrbControlTargets message contract. - operationId: deixic.v1.DeixicService.ListOrbControlTargets - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListOrbControlTargetsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListOrbControlTargetsResponse' - /deixic.v1.DeixicService/GetOrbControlTarget: - post: - tags: - - deixic.v1.DeixicService - summary: GetOrbControlTarget - description: Uses the canonical console.v1.ConsoleService.GetOrbControlTarget message contract. - operationId: deixic.v1.DeixicService.GetOrbControlTarget - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOrbControlTargetRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOrbControlTargetResponse' - /deixic.v1.DeixicService/SubmitOrbControlAction: - post: - tags: - - deixic.v1.DeixicService - summary: SubmitOrbControlAction - description: Uses the canonical console.v1.ConsoleService.SubmitOrbControlAction message contract. - operationId: deixic.v1.DeixicService.SubmitOrbControlAction - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitOrbControlActionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitOrbControlActionResponse' - /deixic.v1.DeixicService/SetPinnedSource: - post: - tags: - - deixic.v1.DeixicService - summary: SetPinnedSource - description: Uses the canonical console.v1.ConsoleService.SetPinnedSource message contract. - operationId: deixic.v1.DeixicService.SetPinnedSource - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SetPinnedSourceRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SetPinnedSourceResponse' - /deixic.v1.DeixicService/UnpinSource: - post: - tags: - - deixic.v1.DeixicService - summary: UnpinSource - description: Uses the canonical console.v1.ConsoleService.UnpinSource message contract. - operationId: deixic.v1.DeixicService.UnpinSource - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UnpinSourceRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UnpinSourceResponse' - /deixic.v1.DeixicService/ListActivity: - post: - tags: - - deixic.v1.DeixicService - summary: ListActivity - description: Uses the canonical console.v1.ConsoleService.ListActivity message contract. - operationId: deixic.v1.DeixicService.ListActivity - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListActivityRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListActivityResponse' - /deixic.v1.DeixicService/SearchStaffWorkspaceDirectory: - post: - tags: - - deixic.v1.DeixicService - summary: SearchStaffWorkspaceDirectory - description: Uses the canonical console.v1.ConsoleService.SearchStaffWorkspaceDirectory message contract. - operationId: deixic.v1.DeixicService.SearchStaffWorkspaceDirectory - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SearchStaffWorkspaceDirectoryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SearchStaffWorkspaceDirectoryResponse' - /deixic.v1.DeixicService/GetStaffWorkspaceContext: - post: - tags: - - deixic.v1.DeixicService - summary: GetStaffWorkspaceContext - description: Uses the canonical console.v1.ConsoleService.GetStaffWorkspaceContext message contract. - operationId: deixic.v1.DeixicService.GetStaffWorkspaceContext - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetStaffWorkspaceContextRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetStaffWorkspaceContextResponse' - /deixic.v1.DeixicService/GetStaffManagedInferenceFunding: - post: - tags: - - deixic.v1.DeixicService - summary: GetStaffManagedInferenceFunding - description: Administrative composition over the existing Meter GetPrepaidCreditBalance owner. - operationId: deixic.v1.DeixicService.GetStaffManagedInferenceFunding - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetStaffManagedInferenceFundingRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.GetPrepaidCreditBalanceResponse' - /deixic.v1.DeixicService/GrantStaffManagedInferenceCredits: - post: - tags: - - deixic.v1.DeixicService - summary: GrantStaffManagedInferenceCredits - description: Administrative composition over the existing Meter GrantDevelopmentCredits owner. - operationId: deixic.v1.DeixicService.GrantStaffManagedInferenceCredits - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GrantStaffManagedInferenceCreditsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.GrantDevelopmentCreditsResponse' - /deixic.v1.DeixicService/GetStaffManagedInferenceUsage: - post: - tags: - - deixic.v1.DeixicService - summary: GetStaffManagedInferenceUsage - description: Administrative composition over the existing Meter QueryUsage owner. - operationId: deixic.v1.DeixicService.GetStaffManagedInferenceUsage - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetStaffManagedInferenceUsageRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.QueryUsageResponse' - /deixic.v1.DeixicService/GetStaffManagedInferenceBudget: - post: - tags: - - deixic.v1.DeixicService - summary: GetStaffManagedInferenceBudget - description: Administrative composition over the existing Meter GetBudgetDashboard owner. - operationId: deixic.v1.DeixicService.GetStaffManagedInferenceBudget - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetStaffManagedInferenceBudgetRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.GetBudgetDashboardResponse' - /deixic.v1.DeixicService/SetStaffManagedInferenceBudget: - post: - tags: - - deixic.v1.DeixicService - summary: SetStaffManagedInferenceBudget - description: Administrative composition over the existing Meter SetBudget owner. - operationId: deixic.v1.DeixicService.SetStaffManagedInferenceBudget - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SetStaffManagedInferenceBudgetRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.SetBudgetResponse' - /deixic.v1.DeixicService/GetStaffManagedInferenceReadiness: - post: - tags: - - deixic.v1.DeixicService - summary: GetStaffManagedInferenceReadiness - description: Read shared managed-inference readiness across tenants for an authorized administrator. - operationId: deixic.v1.DeixicService.GetStaffManagedInferenceReadiness - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetStaffManagedInferenceReadinessRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetManagedInferenceReadinessResponse' - /deixic.v1.DeixicService/GetManagedInferenceReadiness: - post: - tags: - - deixic.v1.DeixicService - summary: GetManagedInferenceReadiness - description: |- - Reports current managed-inference prerequisites for the exact authorized tenant. - Informational only: execution issuance and admission recheck current authority. - operationId: deixic.v1.DeixicService.GetManagedInferenceReadiness - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetManagedInferenceReadinessRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetManagedInferenceReadinessResponse' - /deixic.v1.DeixicService/ListManagedProviderAccessEvents: - post: - tags: - - deixic.v1.DeixicService - summary: ListManagedProviderAccessEvents - description: Reads the canonical tenant-scoped ListManagedProviderAccessEvents audit contract. - operationId: deixic.v1.DeixicService.ListManagedProviderAccessEvents - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListManagedProviderAccessEventsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListManagedProviderAccessEventsResponse' - /deixic.v1.DeixicService/ListStaffManagedInferenceAdminEvents: - post: - tags: - - deixic.v1.DeixicService - summary: ListStaffManagedInferenceAdminEvents - description: |- - Reads the canonical tenant-scoped ListStaffManagedInferenceAdminEvents audit contract. - (-- api-linter: core::0132::response-message-name=disabled - aip.dev/not-precedent: This staff facade returns the canonical Meter audit - response unchanged, preserving the published cross-service contract. --) - operationId: deixic.v1.DeixicService.ListStaffManagedInferenceAdminEvents - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListStaffManagedInferenceAdminEventsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.ListManagedInferenceAdminEventsResponse' - /deixic.v1.DeixicService/ListStaffManagedExecutionGrantEvents: - post: - tags: - - deixic.v1.DeixicService - summary: ListStaffManagedExecutionGrantEvents - description: Reads the canonical tenant-scoped ListStaffManagedExecutionGrantEvents audit contract. - operationId: deixic.v1.DeixicService.ListStaffManagedExecutionGrantEvents - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListStaffManagedExecutionGrantEventsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListStaffManagedExecutionGrantEventsResponse' - /deixic.v1.DeixicService/ListStaffManagedExecutionOutcomes: - post: - tags: - - deixic.v1.DeixicService - summary: ListStaffManagedExecutionOutcomes - description: Reads the canonical tenant-scoped ListStaffManagedExecutionOutcomes audit contract. - operationId: deixic.v1.DeixicService.ListStaffManagedExecutionOutcomes - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListStaffManagedExecutionOutcomesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListStaffManagedExecutionOutcomesResponse' - /deixic.v1.DeixicService/ListManagedProviderAccessGrants: - post: - tags: - - deixic.v1.DeixicService - summary: ListManagedProviderAccessGrants - description: Uses the canonical console.v1.ConsoleService.ListManagedProviderAccessGrants message contract. - operationId: deixic.v1.DeixicService.ListManagedProviderAccessGrants - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListManagedProviderAccessGrantsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListManagedProviderAccessGrantsResponse' - /deixic.v1.DeixicService/UpsertManagedProviderAccessGrant: - post: - tags: - - deixic.v1.DeixicService - summary: UpsertManagedProviderAccessGrant - description: Uses the canonical console.v1.ConsoleService.UpsertManagedProviderAccessGrant message contract. - operationId: deixic.v1.DeixicService.UpsertManagedProviderAccessGrant - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpsertManagedProviderAccessGrantRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpsertManagedProviderAccessGrantResponse' - /deixic.v1.DeixicService/RevokeManagedProviderAccessGrant: - post: - tags: - - deixic.v1.DeixicService - summary: RevokeManagedProviderAccessGrant - description: Uses the canonical console.v1.ConsoleService.RevokeManagedProviderAccessGrant message contract. - operationId: deixic.v1.DeixicService.RevokeManagedProviderAccessGrant - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RevokeManagedProviderAccessGrantRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RevokeManagedProviderAccessGrantResponse' - /deixic.v1.DeixicService/GetStaffInferenceRoutingProfile: - post: - tags: - - deixic.v1.DeixicService - summary: GetStaffInferenceRoutingProfile - description: Uses the canonical console.v1.ConsoleService.GetStaffInferenceRoutingProfile message contract. - operationId: deixic.v1.DeixicService.GetStaffInferenceRoutingProfile - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetStaffInferenceRoutingProfileRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetStaffInferenceRoutingProfileResponse' - /deixic.v1.DeixicService/UpdateStaffInferenceRoutingProfile: - post: - tags: - - deixic.v1.DeixicService - summary: UpdateStaffInferenceRoutingProfile - description: Uses the canonical console.v1.ConsoleService.UpdateStaffInferenceRoutingProfile message contract. - operationId: deixic.v1.DeixicService.UpdateStaffInferenceRoutingProfile - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateStaffInferenceRoutingProfileRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateStaffInferenceRoutingProfileResponse' - /deixic.v1.DeixicService/ListCostUsage: - post: - tags: - - deixic.v1.DeixicService - summary: ListCostUsage - description: Uses the canonical console.v1.ConsoleService.ListCostUsage message contract. - operationId: deixic.v1.DeixicService.ListCostUsage - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListCostUsageRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListCostUsageResponse' - /deixic.v1.DeixicService/ListEvalResults: - post: - tags: - - deixic.v1.DeixicService - summary: ListEvalResults - description: Uses the canonical console.v1.ConsoleService.ListEvalResults message contract. - operationId: deixic.v1.DeixicService.ListEvalResults - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListEvalResultsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListEvalResultsResponse' - /deixic.v1.DeixicService/RecordProviderCostSnapshot: - post: - tags: - - deixic.v1.DeixicService - summary: RecordProviderCostSnapshot - description: Uses the canonical console.v1.ConsoleService.RecordProviderCostSnapshot message contract. - operationId: deixic.v1.DeixicService.RecordProviderCostSnapshot - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RecordProviderCostSnapshotRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RecordProviderCostSnapshotResponse' - /deixic.v1.DeixicService/GetDeixicBootSnapshot: - post: - tags: - - deixic.v1.DeixicService - summary: GetDeixicBootSnapshot - description: |- - Uses the canonical console.v1.ConsoleService.GetConsoleBootSnapshot message contract. - (-- api-linter: core::0131::request-message-name=disabled - aip.dev/not-precedent: Deixic renames only the routed method while retaining - the canonical Console request bytes for legacy wire compatibility. --) - operationId: deixic.v1.DeixicService.GetDeixicBootSnapshot - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetConsoleBootSnapshotRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetConsoleBootSnapshotResponse' - /deixic.v1.DeixicService/GetOperatorPreferences: - post: - tags: - - deixic.v1.DeixicService - summary: GetOperatorPreferences - description: Uses the canonical console.v1.ConsoleService.GetOperatorPreferences message contract. - operationId: deixic.v1.DeixicService.GetOperatorPreferences - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOperatorPreferencesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOperatorPreferencesResponse' - /deixic.v1.DeixicService/UpdateOperatorPreferences: - post: - tags: - - deixic.v1.DeixicService - summary: UpdateOperatorPreferences - description: Uses the canonical console.v1.ConsoleService.UpdateOperatorPreferences message contract. - operationId: deixic.v1.DeixicService.UpdateOperatorPreferences - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateOperatorPreferencesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateOperatorPreferencesResponse' - /deixic.v1.DeixicService/ListWorkspaceGuardrailRules: - post: - tags: - - deixic.v1.DeixicService - summary: ListWorkspaceGuardrailRules - description: Uses the canonical console.v1.ConsoleService.ListWorkspaceGuardrailRules message contract. - operationId: deixic.v1.DeixicService.ListWorkspaceGuardrailRules - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListWorkspaceGuardrailRulesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListWorkspaceGuardrailRulesResponse' - /deixic.v1.DeixicService/UpsertWorkspaceGuardrailRule: - post: - tags: - - deixic.v1.DeixicService - summary: UpsertWorkspaceGuardrailRule - description: Uses the canonical console.v1.ConsoleService.UpsertWorkspaceGuardrailRule message contract. - operationId: deixic.v1.DeixicService.UpsertWorkspaceGuardrailRule - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpsertWorkspaceGuardrailRuleRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListWorkspaceGuardrailRulesResponse' - /deixic.v1.DeixicService/RemoveWorkspaceGuardrailRule: - post: - tags: - - deixic.v1.DeixicService - summary: RemoveWorkspaceGuardrailRule - description: Uses the canonical console.v1.ConsoleService.RemoveWorkspaceGuardrailRule message contract. - operationId: deixic.v1.DeixicService.RemoveWorkspaceGuardrailRule - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RemoveWorkspaceGuardrailRuleRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListWorkspaceGuardrailRulesResponse' - /deixic.v1.DeixicService/CreateDexMcpServer: - post: - tags: - - deixic.v1.DeixicService - summary: CreateDexMcpServer - description: Uses the canonical console.v1.ConsoleService.CreateDexMcpServer message contract. - operationId: deixic.v1.DeixicService.CreateDexMcpServer - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateDexMcpServerRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateDexMcpServerResponse' - /deixic.v1.DeixicService/ListDexMcpServers: - post: - tags: - - deixic.v1.DeixicService - summary: ListDexMcpServers - description: Uses the canonical console.v1.ConsoleService.ListDexMcpServers message contract. - operationId: deixic.v1.DeixicService.ListDexMcpServers - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListDexMcpServersRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListDexMcpServersResponse' - /deixic.v1.DeixicService/GetDexMcpServer: - post: - tags: - - deixic.v1.DeixicService - summary: GetDexMcpServer - description: Uses the canonical console.v1.ConsoleService.GetDexMcpServer message contract. - operationId: deixic.v1.DeixicService.GetDexMcpServer - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetDexMcpServerRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetDexMcpServerResponse' - /deixic.v1.DeixicService/DiscoverDexMcpServer: - post: - tags: - - deixic.v1.DeixicService - summary: DiscoverDexMcpServer - description: Uses the canonical console.v1.ConsoleService.DiscoverDexMcpServer message contract. - operationId: deixic.v1.DeixicService.DiscoverDexMcpServer - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DiscoverDexMcpServerRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DiscoverDexMcpServerResponse' - /deixic.v1.DeixicService/UpdateDexMcpServer: - post: - tags: - - deixic.v1.DeixicService - summary: UpdateDexMcpServer - description: Uses the canonical console.v1.ConsoleService.UpdateDexMcpServer message contract. - operationId: deixic.v1.DeixicService.UpdateDexMcpServer - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateDexMcpServerRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateDexMcpServerResponse' - /deixic.v1.DeixicService/DeleteDexMcpServer: - post: - tags: - - deixic.v1.DeixicService - summary: DeleteDexMcpServer - description: Uses the canonical console.v1.ConsoleService.DeleteDexMcpServer message contract. - operationId: deixic.v1.DeixicService.DeleteDexMcpServer - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DeleteDexMcpServerRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DeleteDexMcpServerResponse' - /deixic.v1.DeixicService/InitiateDexMcpOAuthProfile: - post: - tags: - - deixic.v1.DeixicService - summary: InitiateDexMcpOAuthProfile - description: Uses the canonical console.v1.ConsoleService.InitiateDexMcpOAuthProfile message contract. - operationId: deixic.v1.DeixicService.InitiateDexMcpOAuthProfile - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.InitiateDexMcpOAuthProfileRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.InitiateDexMcpOAuthProfileResponse' - /deixic.v1.DeixicService/CompleteDexMcpOAuthProfile: - post: - tags: - - deixic.v1.DeixicService - summary: CompleteDexMcpOAuthProfile - description: Uses the canonical console.v1.ConsoleService.CompleteDexMcpOAuthProfile message contract. - operationId: deixic.v1.DeixicService.CompleteDexMcpOAuthProfile - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CompleteDexMcpOAuthProfileRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CompleteDexMcpOAuthProfileResponse' - /deixic.v1.DeixicService/ListDexMcpOAuthProfiles: - post: - tags: - - deixic.v1.DeixicService - summary: ListDexMcpOAuthProfiles - description: Uses the canonical console.v1.ConsoleService.ListDexMcpOAuthProfiles message contract. - operationId: deixic.v1.DeixicService.ListDexMcpOAuthProfiles - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListDexMcpOAuthProfilesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListDexMcpOAuthProfilesResponse' - /deixic.v1.DeixicService/RevokeDexMcpOAuthProfile: - post: - tags: - - deixic.v1.DeixicService - summary: RevokeDexMcpOAuthProfile - description: Uses the canonical console.v1.ConsoleService.RevokeDexMcpOAuthProfile message contract. - operationId: deixic.v1.DeixicService.RevokeDexMcpOAuthProfile - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RevokeDexMcpOAuthProfileRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RevokeDexMcpOAuthProfileResponse' - /deixic.v1.DeixicService/ReauthorizeDexMcpOAuthProfile: - post: - tags: - - deixic.v1.DeixicService - summary: ReauthorizeDexMcpOAuthProfile - description: Uses the canonical console.v1.ConsoleService.ReauthorizeDexMcpOAuthProfile message contract. - operationId: deixic.v1.DeixicService.ReauthorizeDexMcpOAuthProfile - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReauthorizeDexMcpOAuthProfileRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReauthorizeDexMcpOAuthProfileResponse' - /deixic.v1.DeixicService/RegisterPrivateEndpoint: - post: - tags: - - deixic.v1.DeixicService - summary: RegisterPrivateEndpoint - description: Uses the canonical console.v1.ConsoleService.RegisterPrivateEndpoint message contract. - operationId: deixic.v1.DeixicService.RegisterPrivateEndpoint - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RegisterPrivateEndpointRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RegisterPrivateEndpointResponse' - /deixic.v1.DeixicService/VerifyPrivateEndpoint: - post: - tags: - - deixic.v1.DeixicService - summary: VerifyPrivateEndpoint - description: Uses the canonical console.v1.ConsoleService.VerifyPrivateEndpoint message contract. - operationId: deixic.v1.DeixicService.VerifyPrivateEndpoint - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.VerifyPrivateEndpointRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.VerifyPrivateEndpointResponse' - /deixic.v1.DeixicService/ListPrivateEndpoints: - post: - tags: - - deixic.v1.DeixicService - summary: ListPrivateEndpoints - description: Uses the canonical console.v1.ConsoleService.ListPrivateEndpoints message contract. - operationId: deixic.v1.DeixicService.ListPrivateEndpoints - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListPrivateEndpointsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListPrivateEndpointsResponse' - /deixic.v1.DeixicService/DeletePrivateEndpoint: - post: - tags: - - deixic.v1.DeixicService - summary: DeletePrivateEndpoint - description: Uses the canonical console.v1.ConsoleService.DeletePrivateEndpoint message contract. - operationId: deixic.v1.DeixicService.DeletePrivateEndpoint - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DeletePrivateEndpointRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DeletePrivateEndpointResponse' - /deixic.v1.DeixicService/AttachPrivateEndpointToProfile: - post: - tags: - - deixic.v1.DeixicService - summary: AttachPrivateEndpointToProfile - description: Uses the canonical console.v1.ConsoleService.AttachPrivateEndpointToProfile message contract. - operationId: deixic.v1.DeixicService.AttachPrivateEndpointToProfile - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.AttachPrivateEndpointToProfileRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.AttachPrivateEndpointToProfileResponse' - /deixic.v1.DeixicService/ListGatewayEgressOrigins: - post: - tags: - - deixic.v1.DeixicService - summary: ListGatewayEgressOrigins - description: Uses the canonical console.v1.ConsoleService.ListGatewayEgressOrigins message contract. - operationId: deixic.v1.DeixicService.ListGatewayEgressOrigins - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListGatewayEgressOriginsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListGatewayEgressOriginsResponse' - /deixic.v1.DeixicService/ListOperatingChannels: - post: - tags: - - deixic.v1.DeixicService - summary: ListOperatingChannels - description: Uses the canonical console.v1.ConsoleService.ListOperatingChannels message contract. - operationId: deixic.v1.DeixicService.ListOperatingChannels - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListOperatingChannelsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListOperatingChannelsResponse' - /deixic.v1.DeixicService/ListOperatingJobs: - post: - tags: - - deixic.v1.DeixicService - summary: ListOperatingJobs - description: Uses the canonical console.v1.ConsoleService.ListOperatingJobs message contract. - operationId: deixic.v1.DeixicService.ListOperatingJobs - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListOperatingJobsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListOperatingJobsResponse' - /deixic.v1.DeixicService/ArchiveOperatingThread: - post: - tags: - - deixic.v1.DeixicService - summary: ArchiveOperatingThread - description: Uses the canonical console.v1.ConsoleService.ArchiveOperatingThread message contract. - operationId: deixic.v1.DeixicService.ArchiveOperatingThread - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ArchiveOperatingThreadRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ArchiveOperatingThreadResponse' - /deixic.v1.DeixicService/ForkOperatingThread: - post: - tags: - - deixic.v1.DeixicService - summary: ForkOperatingThread - description: Uses the canonical console.v1.ConsoleService.ForkOperatingThread message contract. - operationId: deixic.v1.DeixicService.ForkOperatingThread - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ForkOperatingThreadRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ForkOperatingThreadResponse' - /deixic.v1.DeixicService/RenameOperatingThread: - post: - tags: - - deixic.v1.DeixicService - summary: RenameOperatingThread - description: Uses the canonical console.v1.ConsoleService.RenameOperatingThread message contract. - operationId: deixic.v1.DeixicService.RenameOperatingThread - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RenameOperatingThreadRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RenameOperatingThreadResponse' - /deixic.v1.DeixicService/GetOperatingThread: - post: - tags: - - deixic.v1.DeixicService - summary: GetOperatingThread - description: Uses the canonical console.v1.ConsoleService.GetOperatingThread message contract. - operationId: deixic.v1.DeixicService.GetOperatingThread - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOperatingThreadRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOperatingThreadResponse' - /deixic.v1.DeixicService/BootstrapThreadGateway: - post: - tags: - - deixic.v1.DeixicService - summary: BootstrapThreadGateway - description: Uses the canonical console.v1.ConsoleService.BootstrapThreadGateway message contract. - operationId: deixic.v1.DeixicService.BootstrapThreadGateway - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.BootstrapThreadGatewayRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.BootstrapThreadGatewayResponse' - /deixic.v1.DeixicService/PrewarmOperatingThread: - post: - tags: - - deixic.v1.DeixicService - summary: PrewarmOperatingThread - description: Uses the canonical console.v1.ConsoleService.PrewarmOperatingThread message contract. - operationId: deixic.v1.DeixicService.PrewarmOperatingThread - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.PrewarmOperatingThreadRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.PrewarmOperatingThreadResponse' - /deixic.v1.DeixicService/RespondOperatingThread: - post: - tags: - - deixic.v1.DeixicService - summary: RespondOperatingThread - description: Uses the canonical console.v1.ConsoleService.RespondOperatingThread message contract. - operationId: deixic.v1.DeixicService.RespondOperatingThread - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RespondOperatingThreadRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RespondOperatingThreadResponse' - /deixic.v1.DeixicService/InterruptOperatingThread: - post: - tags: - - deixic.v1.DeixicService - summary: InterruptOperatingThread - description: Uses the canonical console.v1.ConsoleService.InterruptOperatingThread message contract. - operationId: deixic.v1.DeixicService.InterruptOperatingThread - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.InterruptOperatingThreadRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.InterruptOperatingThreadResponse' - /deixic.v1.DeixicService/SetOperatingThreadController: - post: - tags: - - deixic.v1.DeixicService - summary: SetOperatingThreadController - description: Uses the canonical console.v1.ConsoleService.SetOperatingThreadController message contract. - operationId: deixic.v1.DeixicService.SetOperatingThreadController - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SetOperatingThreadControllerRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SetOperatingThreadControllerResponse' - /deixic.v1.DeixicService/ListOperatingThreadEvents: - post: - tags: - - deixic.v1.DeixicService - summary: ListOperatingThreadEvents - description: Uses the canonical console.v1.ConsoleService.ListOperatingThreadEvents message contract. - operationId: deixic.v1.DeixicService.ListOperatingThreadEvents - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListOperatingThreadEventsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListOperatingThreadEventsResponse' - /deixic.v1.DeixicService/WatchOperatingThread: {} - /deixic.v1.DeixicService/SearchOperatingHistory: - post: - tags: - - deixic.v1.DeixicService - summary: SearchOperatingHistory - description: Uses the canonical console.v1.ConsoleService.SearchOperatingHistory message contract. - operationId: deixic.v1.DeixicService.SearchOperatingHistory - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SearchOperatingHistoryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SearchOperatingHistoryResponse' - /deixic.v1.DeixicService/GetOperatingHistoryContext: - post: - tags: - - deixic.v1.DeixicService - summary: GetOperatingHistoryContext - description: Uses the canonical console.v1.ConsoleService.GetOperatingHistoryContext message contract. - operationId: deixic.v1.DeixicService.GetOperatingHistoryContext - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOperatingHistoryContextRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOperatingHistoryContextResponse' - /deixic.v1.DeixicService/GetOperatingReceipt: - post: - tags: - - deixic.v1.DeixicService - summary: GetOperatingReceipt - description: Uses the canonical console.v1.ConsoleService.GetOperatingReceipt message contract. - operationId: deixic.v1.DeixicService.GetOperatingReceipt - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOperatingReceiptRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOperatingReceiptResponse' - /deixic.v1.DeixicService/SubmitComputerMission: - post: - tags: - - deixic.v1.DeixicService - summary: SubmitComputerMission - description: Uses the canonical console.v1.ConsoleService.SubmitComputerMission message contract. - operationId: deixic.v1.DeixicService.SubmitComputerMission - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitComputerMissionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitComputerMissionResponse' - /deixic.v1.DeixicService/GetComputerMission: - post: - tags: - - deixic.v1.DeixicService - summary: GetComputerMission - description: Uses the canonical console.v1.ConsoleService.GetComputerMission message contract. - operationId: deixic.v1.DeixicService.GetComputerMission - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetComputerMissionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetComputerMissionResponse' - /deixic.v1.DeixicService/CancelComputerMission: - post: - tags: - - deixic.v1.DeixicService - summary: CancelComputerMission - description: Uses the canonical console.v1.ConsoleService.CancelComputerMission message contract. - operationId: deixic.v1.DeixicService.CancelComputerMission - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CancelComputerMissionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CancelComputerMissionResponse' - /deixic.v1.DeixicService/ContinueComputerMission: - post: - tags: - - deixic.v1.DeixicService - summary: ContinueComputerMission - description: Uses the canonical console.v1.ConsoleService.ContinueComputerMission message contract. - operationId: deixic.v1.DeixicService.ContinueComputerMission - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ContinueComputerMissionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ContinueComputerMissionResponse' - /deixic.v1.DeixicService/PauseComputerMission: - post: - tags: - - deixic.v1.DeixicService - summary: PauseComputerMission - description: Uses the canonical console.v1.ConsoleService.PauseComputerMission message contract. - operationId: deixic.v1.DeixicService.PauseComputerMission - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.PauseComputerMissionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.PauseComputerMissionResponse' - /deixic.v1.DeixicService/ResumeComputerMission: - post: - tags: - - deixic.v1.DeixicService - summary: ResumeComputerMission - description: Uses the canonical console.v1.ConsoleService.ResumeComputerMission message contract. - operationId: deixic.v1.DeixicService.ResumeComputerMission - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ResumeComputerMissionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ResumeComputerMissionResponse' - /deixic.v1.DeixicService/WakeComputerMission: - post: - tags: - - deixic.v1.DeixicService - summary: WakeComputerMission - description: Uses the canonical console.v1.ConsoleService.WakeComputerMission message contract. - operationId: deixic.v1.DeixicService.WakeComputerMission - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.WakeComputerMissionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.WakeComputerMissionResponse' - /deixic.v1.DeixicService/GuideComputerMission: - post: - tags: - - deixic.v1.DeixicService - summary: GuideComputerMission - description: Uses the canonical console.v1.ConsoleService.GuideComputerMission message contract. - operationId: deixic.v1.DeixicService.GuideComputerMission - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GuideComputerMissionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GuideComputerMissionResponse' - /deixic.v1.DeixicService/ListComputerMissionCanaryDefinitions: - post: - tags: - - deixic.v1.DeixicService - summary: ListComputerMissionCanaryDefinitions - description: Uses the canonical console.v1.ConsoleService.ListComputerMissionCanaryDefinitions message contract. - operationId: deixic.v1.DeixicService.ListComputerMissionCanaryDefinitions - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListComputerMissionCanaryDefinitionsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListComputerMissionCanaryDefinitionsResponse' - /deixic.v1.DeixicService/StartComputerMissionCanaryRun: - post: - tags: - - deixic.v1.DeixicService - summary: StartComputerMissionCanaryRun - description: Uses the canonical console.v1.ConsoleService.StartComputerMissionCanaryRun message contract. - operationId: deixic.v1.DeixicService.StartComputerMissionCanaryRun - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.StartComputerMissionCanaryRunRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.StartComputerMissionCanaryRunResponse' - /deixic.v1.DeixicService/GetComputerMissionCanaryRun: - post: - tags: - - deixic.v1.DeixicService - summary: GetComputerMissionCanaryRun - description: Uses the canonical console.v1.ConsoleService.GetComputerMissionCanaryRun message contract. - operationId: deixic.v1.DeixicService.GetComputerMissionCanaryRun - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetComputerMissionCanaryRunRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetComputerMissionCanaryRunResponse' - /deixic.v1.DeixicService/ListComputerMissionCanaryRuns: - post: - tags: - - deixic.v1.DeixicService - summary: ListComputerMissionCanaryRuns - description: Uses the canonical console.v1.ConsoleService.ListComputerMissionCanaryRuns message contract. - operationId: deixic.v1.DeixicService.ListComputerMissionCanaryRuns - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListComputerMissionCanaryRunsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListComputerMissionCanaryRunsResponse' - /deixic.v1.DeixicService/GetComputerMissionCanaryEvidence: - post: - tags: - - deixic.v1.DeixicService - summary: GetComputerMissionCanaryEvidence - description: Uses the canonical console.v1.ConsoleService.GetComputerMissionCanaryEvidence message contract. - operationId: deixic.v1.DeixicService.GetComputerMissionCanaryEvidence - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetComputerMissionCanaryEvidenceRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetComputerMissionCanaryEvidenceResponse' - /deixic.v1.DeixicService/OperateComputerMissionCanaryRun: - post: - tags: - - deixic.v1.DeixicService - summary: OperateComputerMissionCanaryRun - description: Uses the canonical console.v1.ConsoleService.OperateComputerMissionCanaryRun message contract. - operationId: deixic.v1.DeixicService.OperateComputerMissionCanaryRun - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.OperateComputerMissionCanaryRunRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.OperateComputerMissionCanaryRunResponse' - /deixic.v1.DeixicService/CreateMissionSchedule: - post: - tags: - - deixic.v1.DeixicService - summary: CreateMissionSchedule - description: Uses the canonical console.v1.ConsoleService.CreateMissionSchedule message contract. - operationId: deixic.v1.DeixicService.CreateMissionSchedule - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateMissionScheduleRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateMissionScheduleResponse' - /deixic.v1.DeixicService/UpdateMissionSchedule: - post: - tags: - - deixic.v1.DeixicService - summary: UpdateMissionSchedule - description: Uses the canonical console.v1.ConsoleService.UpdateMissionSchedule message contract. - operationId: deixic.v1.DeixicService.UpdateMissionSchedule - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateMissionScheduleRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateMissionScheduleResponse' - /deixic.v1.DeixicService/SetMissionScheduleEnabled: - post: - tags: - - deixic.v1.DeixicService - summary: SetMissionScheduleEnabled - description: Uses the canonical console.v1.ConsoleService.SetMissionScheduleEnabled message contract. - operationId: deixic.v1.DeixicService.SetMissionScheduleEnabled - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SetMissionScheduleEnabledRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SetMissionScheduleEnabledResponse' - /deixic.v1.DeixicService/ListMissionSchedules: - post: - tags: - - deixic.v1.DeixicService - summary: ListMissionSchedules - description: Uses the canonical console.v1.ConsoleService.ListMissionSchedules message contract. - operationId: deixic.v1.DeixicService.ListMissionSchedules - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListMissionSchedulesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListMissionSchedulesResponse' - /deixic.v1.DeixicService/CreateConnectorTrigger: - post: - tags: - - deixic.v1.DeixicService - summary: CreateConnectorTrigger - description: Uses the canonical console.v1.ConsoleService.CreateConnectorTrigger message contract. - operationId: deixic.v1.DeixicService.CreateConnectorTrigger - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateConnectorTriggerRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateConnectorTriggerResponse' - /deixic.v1.DeixicService/UpdateConnectorTrigger: - post: - tags: - - deixic.v1.DeixicService - summary: UpdateConnectorTrigger - description: Uses the canonical console.v1.ConsoleService.UpdateConnectorTrigger message contract. - operationId: deixic.v1.DeixicService.UpdateConnectorTrigger - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateConnectorTriggerRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateConnectorTriggerResponse' - /deixic.v1.DeixicService/ListConnectorTriggers: - post: - tags: - - deixic.v1.DeixicService - summary: ListConnectorTriggers - description: Uses the canonical console.v1.ConsoleService.ListConnectorTriggers message contract. - operationId: deixic.v1.DeixicService.ListConnectorTriggers - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListConnectorTriggersRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListConnectorTriggersResponse' - /deixic.v1.DeixicService/DeleteConnectorTrigger: - post: - tags: - - deixic.v1.DeixicService - summary: DeleteConnectorTrigger - description: Uses the canonical console.v1.ConsoleService.DeleteConnectorTrigger message contract. - operationId: deixic.v1.DeixicService.DeleteConnectorTrigger - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DeleteConnectorTriggerRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DeleteConnectorTriggerResponse' - /deixic.v1.DeixicService/SetConnectorTriggerEnabled: - post: - tags: - - deixic.v1.DeixicService - summary: SetConnectorTriggerEnabled - description: Uses the canonical console.v1.ConsoleService.SetConnectorTriggerEnabled message contract. - operationId: deixic.v1.DeixicService.SetConnectorTriggerEnabled - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SetConnectorTriggerEnabledRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SetConnectorTriggerEnabledResponse' - /deixic.v1.DeixicService/ReserveComputerMissionApexSession: - post: - tags: - - deixic.v1.DeixicService - summary: ReserveComputerMissionApexSession - description: Uses the canonical console.v1.ConsoleService.ReserveComputerMissionApexSession message contract. - operationId: deixic.v1.DeixicService.ReserveComputerMissionApexSession - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReserveComputerMissionApexSessionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReserveComputerMissionApexSessionResponse' - /deixic.v1.DeixicService/BindComputerMissionApexSessionReservation: - post: - tags: - - deixic.v1.DeixicService - summary: BindComputerMissionApexSessionReservation - description: Uses the canonical console.v1.ConsoleService.BindComputerMissionApexSessionReservation message contract. - operationId: deixic.v1.DeixicService.BindComputerMissionApexSessionReservation - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.BindComputerMissionApexSessionReservationRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.BindComputerMissionApexSessionReservationResponse' - /deixic.v1.DeixicService/BindComputerMissionApexInstructionMetadata: - post: - tags: - - deixic.v1.DeixicService - summary: BindComputerMissionApexInstructionMetadata - description: Uses the canonical console.v1.ConsoleService.BindComputerMissionApexInstructionMetadata message contract. - operationId: deixic.v1.DeixicService.BindComputerMissionApexInstructionMetadata - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.BindComputerMissionApexInstructionMetadataRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.BindComputerMissionApexInstructionMetadataResponse' - /deixic.v1.DeixicService/AuthorizeComputerMissionApexSessionAdoption: - post: - tags: - - deixic.v1.DeixicService - summary: AuthorizeComputerMissionApexSessionAdoption - description: Uses the canonical console.v1.ConsoleService.AuthorizeComputerMissionApexSessionAdoption message contract. - operationId: deixic.v1.DeixicService.AuthorizeComputerMissionApexSessionAdoption - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.AuthorizeComputerMissionApexSessionAdoptionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.AuthorizeComputerMissionApexSessionAdoptionResponse' - /deixic.v1.DeixicService/ResolveOperatingReceiptAction: - post: - tags: - - deixic.v1.DeixicService - summary: ResolveOperatingReceiptAction - description: Uses the canonical console.v1.ConsoleService.ResolveOperatingReceiptAction message contract. - operationId: deixic.v1.DeixicService.ResolveOperatingReceiptAction - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ResolveOperatingReceiptActionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ResolveOperatingReceiptActionResponse' - /deixic.v1.DeixicService/SubmitOperatingMessage: - post: - tags: - - deixic.v1.DeixicService - summary: SubmitOperatingMessage - description: Uses the canonical console.v1.ConsoleService.SubmitOperatingMessage message contract. - operationId: deixic.v1.DeixicService.SubmitOperatingMessage - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitOperatingMessageRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitOperatingMessageResponse' - /deixic.v1.DeixicService/SubmitOperatingCorrection: - post: - tags: - - deixic.v1.DeixicService - summary: SubmitOperatingCorrection - description: Uses the canonical console.v1.ConsoleService.SubmitOperatingCorrection message contract. - operationId: deixic.v1.DeixicService.SubmitOperatingCorrection - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitOperatingCorrectionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitOperatingCorrectionResponse' - /deixic.v1.DeixicService/ListWorkspaceMemories: - post: - tags: - - deixic.v1.DeixicService - summary: ListWorkspaceMemories - description: Uses the canonical console.v1.ConsoleService.ListWorkspaceMemories message contract. - operationId: deixic.v1.DeixicService.ListWorkspaceMemories - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListWorkspaceMemoriesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListWorkspaceMemoriesResponse' - /deixic.v1.DeixicService/CorrectWorkspaceMemory: - post: - tags: - - deixic.v1.DeixicService - summary: CorrectWorkspaceMemory - description: Uses the canonical console.v1.ConsoleService.CorrectWorkspaceMemory message contract. - operationId: deixic.v1.DeixicService.CorrectWorkspaceMemory - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CorrectWorkspaceMemoryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CorrectWorkspaceMemoryResponse' - /deixic.v1.DeixicService/ReviewWorkspaceMemory: - post: - tags: - - deixic.v1.DeixicService - summary: ReviewWorkspaceMemory - description: Uses the canonical console.v1.ConsoleService.ReviewWorkspaceMemory message contract. - operationId: deixic.v1.DeixicService.ReviewWorkspaceMemory - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReviewWorkspaceMemoryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReviewWorkspaceMemoryResponse' - /deixic.v1.DeixicService/ForgetWorkspaceMemory: - post: - tags: - - deixic.v1.DeixicService - summary: ForgetWorkspaceMemory - description: Uses the canonical console.v1.ConsoleService.ForgetWorkspaceMemory message contract. - operationId: deixic.v1.DeixicService.ForgetWorkspaceMemory - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ForgetWorkspaceMemoryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ForgetWorkspaceMemoryResponse' - /deixic.v1.DeixicService/SubmitOperatingFeedback: - post: - tags: - - deixic.v1.DeixicService - summary: SubmitOperatingFeedback - description: Uses the canonical console.v1.ConsoleService.SubmitOperatingFeedback message contract. - operationId: deixic.v1.DeixicService.SubmitOperatingFeedback - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitOperatingFeedbackRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitOperatingFeedbackResponse' - /deixic.v1.DeixicService/RecordOperatingHomepageSuggestionFeedback: - post: - tags: - - deixic.v1.DeixicService - summary: RecordOperatingHomepageSuggestionFeedback - description: Uses the canonical console.v1.ConsoleService.RecordOperatingHomepageSuggestionFeedback message contract. - operationId: deixic.v1.DeixicService.RecordOperatingHomepageSuggestionFeedback - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RecordOperatingHomepageSuggestionFeedbackRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RecordOperatingHomepageSuggestionFeedbackResponse' - /deixic.v1.DeixicService/SubmitProductIssueReport: - post: - tags: - - deixic.v1.DeixicService - summary: SubmitProductIssueReport - description: Uses the canonical console.v1.ConsoleService.SubmitProductIssueReport message contract. - operationId: deixic.v1.DeixicService.SubmitProductIssueReport - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitProductIssueReportRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitProductIssueReportResponse' - /deixic.v1.DeixicService/SubmitNativeProductIssueReport: - post: - tags: - - deixic.v1.DeixicService - summary: SubmitNativeProductIssueReport - description: Native clients submit to the same durable product issue owner using a narrow permission. - operationId: deixic.v1.DeixicService.SubmitNativeProductIssueReport - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitNativeProductIssueReportRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SubmitProductIssueReportResponse' - /deixic.v1.DeixicService/ListStaffProductIssueReports: - post: - tags: - - deixic.v1.DeixicService - summary: ListStaffProductIssueReports - description: Uses the canonical console.v1.ConsoleService.ListStaffProductIssueReports message contract. - operationId: deixic.v1.DeixicService.ListStaffProductIssueReports - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListStaffProductIssueReportsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListStaffProductIssueReportsResponse' - /deixic.v1.DeixicService/EngageStaffProductIssueReport: - post: - tags: - - deixic.v1.DeixicService - summary: EngageStaffProductIssueReport - description: Uses the canonical console.v1.ConsoleService.EngageStaffProductIssueReport message contract. - operationId: deixic.v1.DeixicService.EngageStaffProductIssueReport - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.EngageStaffProductIssueReportRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.EngageStaffProductIssueReportResponse' - /deixic.v1.DeixicService/ListStaffProductIssueRecoveries: - post: - tags: - - deixic.v1.DeixicService - summary: ListStaffProductIssueRecoveries - description: Lists the global recovery queue under verified staff authority. - operationId: deixic.v1.DeixicService.ListStaffProductIssueRecoveries - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListStaffProductIssueRecoveriesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListStaffProductIssueRecoveriesResponse' - /deixic.v1.DeixicService/PrepareStaffProductIssueRecovery: - post: - tags: - - deixic.v1.DeixicService - summary: PrepareStaffProductIssueRecovery - description: PrepareStaffProductIssueRecovery advances the staff-reviewed recovery of charged failures. - operationId: deixic.v1.DeixicService.PrepareStaffProductIssueRecovery - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.PrepareStaffProductIssueRecoveryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ProductIssueRecoveryResponse' - /deixic.v1.DeixicService/ScanStaffProductIssueRecovery: - post: - tags: - - deixic.v1.DeixicService - summary: ScanStaffProductIssueRecovery - description: ScanStaffProductIssueRecovery advances the staff-reviewed recovery of charged failures. - operationId: deixic.v1.DeixicService.ScanStaffProductIssueRecovery - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ScanStaffProductIssueRecoveryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ProductIssueRecoveryResponse' - /deixic.v1.DeixicService/ReviewStaffProductIssueRecovery: - post: - tags: - - deixic.v1.DeixicService - summary: ReviewStaffProductIssueRecovery - description: ReviewStaffProductIssueRecovery advances the staff-reviewed recovery of charged failures. - operationId: deixic.v1.DeixicService.ReviewStaffProductIssueRecovery - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReviewStaffProductIssueRecoveryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ProductIssueRecoveryResponse' - /deixic.v1.DeixicService/ExecuteStaffProductIssueRecovery: - post: - tags: - - deixic.v1.DeixicService - summary: ExecuteStaffProductIssueRecovery - description: ExecuteStaffProductIssueRecovery advances the staff-reviewed recovery of charged failures. - operationId: deixic.v1.DeixicService.ExecuteStaffProductIssueRecovery - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ExecuteStaffProductIssueRecoveryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ProductIssueRecoveryResponse' - /deixic.v1.DeixicService/GetProductIssueRecovery: - post: - tags: - - deixic.v1.DeixicService - summary: GetProductIssueRecovery - description: GetProductIssueRecovery accesses only the authenticated recovery recipient or authorized staff. - operationId: deixic.v1.DeixicService.GetProductIssueRecovery - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetProductIssueRecoveryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ProductIssueRecoveryResponse' - /deixic.v1.DeixicService/ReplyProductIssueRecovery: - post: - tags: - - deixic.v1.DeixicService - summary: ReplyProductIssueRecovery - description: ReplyProductIssueRecovery accesses only the authenticated recovery recipient or authorized staff. - operationId: deixic.v1.DeixicService.ReplyProductIssueRecovery - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReplyProductIssueRecoveryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ProductIssueRecoveryResponse' - /deixic.v1.DeixicService/GetOperatingFeedback: - post: - tags: - - deixic.v1.DeixicService - summary: GetOperatingFeedback - description: Uses the canonical console.v1.ConsoleService.GetOperatingFeedback message contract. - operationId: deixic.v1.DeixicService.GetOperatingFeedback - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOperatingFeedbackRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOperatingFeedbackResponse' - /deixic.v1.DeixicService/ResolveOperatingFeedbackRemediation: - post: - tags: - - deixic.v1.DeixicService - summary: ResolveOperatingFeedbackRemediation - description: Uses the canonical console.v1.ConsoleService.ResolveOperatingFeedbackRemediation message contract. - operationId: deixic.v1.DeixicService.ResolveOperatingFeedbackRemediation - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ResolveOperatingFeedbackRemediationRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ResolveOperatingFeedbackRemediationResponse' - /deixic.v1.DeixicService/ListCustomerIntelligenceFacts: - post: - tags: - - deixic.v1.DeixicService - summary: ListCustomerIntelligenceFacts - description: Uses the canonical console.v1.ConsoleService.ListCustomerIntelligenceFacts message contract. - operationId: deixic.v1.DeixicService.ListCustomerIntelligenceFacts - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListCustomerIntelligenceFactsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListCustomerIntelligenceFactsResponse' - /deixic.v1.DeixicService/GetCustomerIntelligenceFact: - post: - tags: - - deixic.v1.DeixicService - summary: GetCustomerIntelligenceFact - description: Uses the canonical console.v1.ConsoleService.GetCustomerIntelligenceFact message contract. - operationId: deixic.v1.DeixicService.GetCustomerIntelligenceFact - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetCustomerIntelligenceFactRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetCustomerIntelligenceFactResponse' - /deixic.v1.DeixicService/ReviewCustomerIntelligenceFact: - post: - tags: - - deixic.v1.DeixicService - summary: ReviewCustomerIntelligenceFact - description: Uses the canonical console.v1.ConsoleService.ReviewCustomerIntelligenceFact message contract. - operationId: deixic.v1.DeixicService.ReviewCustomerIntelligenceFact - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReviewCustomerIntelligenceFactRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReviewCustomerIntelligenceFactResponse' - /deixic.v1.DeixicService/ProposeCustomerIntelligenceFact: - post: - tags: - - deixic.v1.DeixicService - summary: ProposeCustomerIntelligenceFact - description: Uses the canonical console.v1.ConsoleService.ProposeCustomerIntelligenceFact message contract. - operationId: deixic.v1.DeixicService.ProposeCustomerIntelligenceFact - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ProposeCustomerIntelligenceFactRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ProposeCustomerIntelligenceFactResponse' - /deixic.v1.DeixicService/RespondToCustomerFactConfirmation: - post: - tags: - - deixic.v1.DeixicService - summary: RespondToCustomerFactConfirmation - description: Uses the canonical console.v1.ConsoleService.RespondToCustomerFactConfirmation message contract. - operationId: deixic.v1.DeixicService.RespondToCustomerFactConfirmation - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RespondToCustomerFactConfirmationRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RespondToCustomerFactConfirmationResponse' - /deixic.v1.DeixicService/AggregateCustomerIntelligencePatterns: - post: - tags: - - deixic.v1.DeixicService - summary: AggregateCustomerIntelligencePatterns - description: Uses the canonical console.v1.ConsoleService.AggregateCustomerIntelligencePatterns message contract. - operationId: deixic.v1.DeixicService.AggregateCustomerIntelligencePatterns - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.AggregateCustomerIntelligencePatternsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.AggregateCustomerIntelligencePatternsResponse' - /deixic.v1.DeixicService/CreateProspectingWatchProgram: - post: - tags: - - deixic.v1.DeixicService - summary: CreateProspectingWatchProgram - description: Uses the canonical console.v1.ConsoleService.CreateProspectingWatchProgram message contract. - operationId: deixic.v1.DeixicService.CreateProspectingWatchProgram - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateProspectingWatchProgramRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateProspectingWatchProgramResponse' - /deixic.v1.DeixicService/GetProspectingWatchProgram: - post: - tags: - - deixic.v1.DeixicService - summary: GetProspectingWatchProgram - description: Uses the canonical console.v1.ConsoleService.GetProspectingWatchProgram message contract. - operationId: deixic.v1.DeixicService.GetProspectingWatchProgram - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetProspectingWatchProgramRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetProspectingWatchProgramResponse' - /deixic.v1.DeixicService/ListProspectingWatchPrograms: - post: - tags: - - deixic.v1.DeixicService - summary: ListProspectingWatchPrograms - description: Uses the canonical console.v1.ConsoleService.ListProspectingWatchPrograms message contract. - operationId: deixic.v1.DeixicService.ListProspectingWatchPrograms - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListProspectingWatchProgramsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListProspectingWatchProgramsResponse' - /deixic.v1.DeixicService/UpdateProspectingWatchProgram: - post: - tags: - - deixic.v1.DeixicService - summary: UpdateProspectingWatchProgram - description: Uses the canonical console.v1.ConsoleService.UpdateProspectingWatchProgram message contract. - operationId: deixic.v1.DeixicService.UpdateProspectingWatchProgram - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateProspectingWatchProgramRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateProspectingWatchProgramResponse' - /deixic.v1.DeixicService/CreateProspectingDraft: - post: - tags: - - deixic.v1.DeixicService - summary: CreateProspectingDraft - description: Uses the canonical console.v1.ConsoleService.CreateProspectingDraft message contract. - operationId: deixic.v1.DeixicService.CreateProspectingDraft - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateProspectingDraftRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateProspectingDraftResponse' - /deixic.v1.DeixicService/ListProspectingDrafts: - post: - tags: - - deixic.v1.DeixicService - summary: ListProspectingDrafts - description: Uses the canonical console.v1.ConsoleService.ListProspectingDrafts message contract. - operationId: deixic.v1.DeixicService.ListProspectingDrafts - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListProspectingDraftsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListProspectingDraftsResponse' - /deixic.v1.DeixicService/ReviewProspectingDraft: - post: - tags: - - deixic.v1.DeixicService - summary: ReviewProspectingDraft - description: Uses the canonical console.v1.ConsoleService.ReviewProspectingDraft message contract. - operationId: deixic.v1.DeixicService.ReviewProspectingDraft - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReviewProspectingDraftRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReviewProspectingDraftResponse' - /deixic.v1.DeixicService/ListOperatingCorrections: - post: - tags: - - deixic.v1.DeixicService - summary: ListOperatingCorrections - description: Uses the canonical console.v1.ConsoleService.ListOperatingCorrections message contract. - operationId: deixic.v1.DeixicService.ListOperatingCorrections - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListOperatingCorrectionsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListOperatingCorrectionsResponse' - /deixic.v1.DeixicService/ReviewOperatingCorrection: - post: - tags: - - deixic.v1.DeixicService - summary: ReviewOperatingCorrection - description: Uses the canonical console.v1.ConsoleService.ReviewOperatingCorrection message contract. - operationId: deixic.v1.DeixicService.ReviewOperatingCorrection - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReviewOperatingCorrectionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ReviewOperatingCorrectionResponse' - /deixic.v1.DeixicService/BeginOperatingAttachmentUpload: - post: - tags: - - deixic.v1.DeixicService - summary: BeginOperatingAttachmentUpload - description: Uses the canonical console.v1.ConsoleService.BeginOperatingAttachmentUpload message contract. - operationId: deixic.v1.DeixicService.BeginOperatingAttachmentUpload - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.BeginOperatingAttachmentUploadRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.BeginOperatingAttachmentUploadResponse' - /deixic.v1.DeixicService/CompleteOperatingAttachmentUpload: - post: - tags: - - deixic.v1.DeixicService - summary: CompleteOperatingAttachmentUpload - description: Uses the canonical console.v1.ConsoleService.CompleteOperatingAttachmentUpload message contract. - operationId: deixic.v1.DeixicService.CompleteOperatingAttachmentUpload - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CompleteOperatingAttachmentUploadRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CompleteOperatingAttachmentUploadResponse' - /deixic.v1.DeixicService/AcceptOperatingProjectSnapshot: - post: - tags: - - deixic.v1.DeixicService - summary: AcceptOperatingProjectSnapshot - description: Explicit acceptance of a complete immutable project file snapshot. - operationId: deixic.v1.DeixicService.AcceptOperatingProjectSnapshot - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.AcceptOperatingProjectSnapshotRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.AcceptOperatingProjectSnapshotResponse' - /deixic.v1.DeixicService/ImportOperatingProjectSnapshot: - post: - tags: - - deixic.v1.DeixicService - summary: ImportOperatingProjectSnapshot - description: Imports the connected code repository's provider-observed default branch. - operationId: deixic.v1.DeixicService.ImportOperatingProjectSnapshot - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ImportOperatingProjectSnapshotRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.AcceptOperatingProjectSnapshotResponse' - /deixic.v1.DeixicService/GetOperatingTaskEnvironment: - post: - tags: - - deixic.v1.DeixicService - summary: GetOperatingTaskEnvironment - description: |- - Reads the current accepted project file snapshot. - Reads retained task state without acquiring or refreshing a computer. - operationId: deixic.v1.DeixicService.GetOperatingTaskEnvironment - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOperatingTaskEnvironmentRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOperatingTaskEnvironmentResponse' - /deixic.v1.DeixicService/GetOperatingProjectSnapshot: - post: - tags: - - deixic.v1.DeixicService - summary: GetOperatingProjectSnapshot - operationId: deixic.v1.DeixicService.GetOperatingProjectSnapshot - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetOperatingProjectSnapshotRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.AcceptOperatingProjectSnapshotResponse' - /deixic.v1.DeixicService/ListOperatingAttachments: - post: - tags: - - deixic.v1.DeixicService - summary: ListOperatingAttachments - description: Uses the canonical console.v1.ConsoleService.ListOperatingAttachments message contract. - operationId: deixic.v1.DeixicService.ListOperatingAttachments - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListOperatingAttachmentsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListOperatingAttachmentsResponse' - /deixic.v1.DeixicService/GetPrivacySettings: - post: - tags: - - deixic.v1.DeixicService - summary: GetPrivacySettings - description: Uses the canonical console.v1.ConsoleService.GetPrivacySettings message contract. - operationId: deixic.v1.DeixicService.GetPrivacySettings - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetPrivacySettingsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetPrivacySettingsResponse' - /deixic.v1.DeixicService/SetPrivacySettings: - post: - tags: - - deixic.v1.DeixicService - summary: SetPrivacySettings - description: Uses the canonical console.v1.ConsoleService.SetPrivacySettings message contract. - operationId: deixic.v1.DeixicService.SetPrivacySettings - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.SetPrivacySettingsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetPrivacySettingsResponse' - /deixic.v1.DeixicService/GetWorkspaceSettings: - post: - tags: - - deixic.v1.DeixicService - summary: GetWorkspaceSettings - description: Uses the canonical console.v1.ConsoleService.GetWorkspaceSettings message contract. - operationId: deixic.v1.DeixicService.GetWorkspaceSettings - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - /deixic.v1.DeixicService/GetBillingSubscription: - post: - tags: - - deixic.v1.DeixicService - summary: GetBillingSubscription - description: Uses the canonical console.v1.ConsoleService.GetBillingSubscription message contract. - operationId: deixic.v1.DeixicService.GetBillingSubscription - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetBillingSubscriptionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetBillingSubscriptionResponse' - /deixic.v1.DeixicService/CreateBillingPortalSession: - post: - tags: - - deixic.v1.DeixicService - summary: CreateBillingPortalSession - description: Uses the canonical console.v1.ConsoleService.CreateBillingPortalSession message contract. - operationId: deixic.v1.DeixicService.CreateBillingPortalSession - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateBillingPortalSessionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateBillingPortalSessionResponse' - /deixic.v1.DeixicService/CreateBillingCheckoutSession: - post: - tags: - - deixic.v1.DeixicService - summary: CreateBillingCheckoutSession - description: Uses the canonical console.v1.ConsoleService.CreateBillingCheckoutSession message contract. - operationId: deixic.v1.DeixicService.CreateBillingCheckoutSession - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateBillingCheckoutSessionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateBillingCheckoutSessionResponse' - /deixic.v1.DeixicService/UpdateWorkspaceProfile: - post: - tags: - - deixic.v1.DeixicService - summary: UpdateWorkspaceProfile - description: Uses the canonical console.v1.ConsoleService.UpdateWorkspaceProfile message contract. - operationId: deixic.v1.DeixicService.UpdateWorkspaceProfile - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateWorkspaceProfileRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateWorkspaceProfileResponse' - /deixic.v1.DeixicService/ArchiveWorkspace: - post: - tags: - - deixic.v1.DeixicService - summary: ArchiveWorkspace - description: Uses the canonical console.v1.ConsoleService.ArchiveWorkspace message contract. - operationId: deixic.v1.DeixicService.ArchiveWorkspace - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ArchiveWorkspaceRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ArchiveWorkspaceResponse' - /deixic.v1.DeixicService/UpdateWorkspacePolicy: - post: - tags: - - deixic.v1.DeixicService - summary: UpdateWorkspacePolicy - description: Uses the canonical console.v1.ConsoleService.UpdateWorkspacePolicy message contract. - operationId: deixic.v1.DeixicService.UpdateWorkspacePolicy - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateWorkspacePolicyRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateWorkspacePolicyResponse' - /deixic.v1.DeixicService/UpdateWorkspaceDexPolicy: - post: - tags: - - deixic.v1.DeixicService - summary: UpdateWorkspaceDexPolicy - description: Uses the canonical console.v1.ConsoleService.UpdateWorkspaceDexPolicy message contract. - operationId: deixic.v1.DeixicService.UpdateWorkspaceDexPolicy - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateWorkspaceDexPolicyRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateWorkspaceDexPolicyResponse' - /deixic.v1.DeixicService/UpdateWorkspaceArtifactStyleGuide: - post: - tags: - - deixic.v1.DeixicService - summary: UpdateWorkspaceArtifactStyleGuide - description: Uses the canonical console.v1.ConsoleService.UpdateWorkspaceArtifactStyleGuide message contract. - operationId: deixic.v1.DeixicService.UpdateWorkspaceArtifactStyleGuide - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateWorkspaceArtifactStyleGuideRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateWorkspaceArtifactStyleGuideResponse' - /deixic.v1.DeixicService/EvaluateWorkspaceArtifactStyleGuide: - post: - tags: - - deixic.v1.DeixicService - summary: EvaluateWorkspaceArtifactStyleGuide - description: Uses the canonical console.v1.ConsoleService.EvaluateWorkspaceArtifactStyleGuide message contract. - operationId: deixic.v1.DeixicService.EvaluateWorkspaceArtifactStyleGuide - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.EvaluateWorkspaceArtifactStyleGuideRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.EvaluateWorkspaceArtifactStyleGuideResponse' - /deixic.v1.DeixicService/UpsertWorkspaceIdentityProvider: - post: - tags: - - deixic.v1.DeixicService - summary: UpsertWorkspaceIdentityProvider - description: Uses the canonical console.v1.ConsoleService.UpsertWorkspaceIdentityProvider message contract. - operationId: deixic.v1.DeixicService.UpsertWorkspaceIdentityProvider - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpsertWorkspaceIdentityProviderRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpsertWorkspaceIdentityProviderResponse' - /deixic.v1.DeixicService/RemoveWorkspaceIdentityProvider: - post: - tags: - - deixic.v1.DeixicService - summary: RemoveWorkspaceIdentityProvider - description: Uses the canonical console.v1.ConsoleService.RemoveWorkspaceIdentityProvider message contract. - operationId: deixic.v1.DeixicService.RemoveWorkspaceIdentityProvider - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RemoveWorkspaceIdentityProviderRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RemoveWorkspaceIdentityProviderResponse' - /deixic.v1.DeixicService/UpsertWorkspaceIntegration: - post: - tags: - - deixic.v1.DeixicService - summary: UpsertWorkspaceIntegration - description: Uses the canonical console.v1.ConsoleService.UpsertWorkspaceIntegration message contract. - operationId: deixic.v1.DeixicService.UpsertWorkspaceIntegration - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpsertWorkspaceIntegrationRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpsertWorkspaceIntegrationResponse' - /deixic.v1.DeixicService/RemoveWorkspaceIntegration: - post: - tags: - - deixic.v1.DeixicService - summary: RemoveWorkspaceIntegration - description: Uses the canonical console.v1.ConsoleService.RemoveWorkspaceIntegration message contract. - operationId: deixic.v1.DeixicService.RemoveWorkspaceIntegration - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RemoveWorkspaceIntegrationRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RemoveWorkspaceIntegrationResponse' - /deixic.v1.DeixicService/UpdateWorkspaceBilling: - post: - tags: - - deixic.v1.DeixicService - summary: UpdateWorkspaceBilling - description: Uses the canonical console.v1.ConsoleService.UpdateWorkspaceBilling message contract. - operationId: deixic.v1.DeixicService.UpdateWorkspaceBilling - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateWorkspaceBillingRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - /deixic.v1.DeixicService/UpsertWorkspaceMember: - post: - tags: - - deixic.v1.DeixicService - summary: UpsertWorkspaceMember - description: Uses the canonical console.v1.ConsoleService.UpsertWorkspaceMember message contract. - operationId: deixic.v1.DeixicService.UpsertWorkspaceMember - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpsertWorkspaceMemberRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - /deixic.v1.DeixicService/RemoveWorkspaceMember: - post: - tags: - - deixic.v1.DeixicService - summary: RemoveWorkspaceMember - description: Uses the canonical console.v1.ConsoleService.RemoveWorkspaceMember message contract. - operationId: deixic.v1.DeixicService.RemoveWorkspaceMember - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.RemoveWorkspaceMemberRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - /deixic.v1.DeixicService/UpdateWorkspaceNotificationPreferences: - post: - tags: - - deixic.v1.DeixicService - summary: UpdateWorkspaceNotificationPreferences - description: Uses the canonical console.v1.ConsoleService.UpdateWorkspaceNotificationPreferences message contract. - operationId: deixic.v1.DeixicService.UpdateWorkspaceNotificationPreferences - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateWorkspaceNotificationPreferencesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - /deixic.v1.DeixicService/EnableWorkspaceBreakGlass: - post: - tags: - - deixic.v1.DeixicService - summary: EnableWorkspaceBreakGlass - description: Uses the canonical console.v1.ConsoleService.EnableWorkspaceBreakGlass message contract. - operationId: deixic.v1.DeixicService.EnableWorkspaceBreakGlass - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.EnableWorkspaceBreakGlassRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - /deixic.v1.DeixicService/DisableWorkspaceBreakGlass: - post: - tags: - - deixic.v1.DeixicService - summary: DisableWorkspaceBreakGlass - description: Uses the canonical console.v1.ConsoleService.DisableWorkspaceBreakGlass message contract. - operationId: deixic.v1.DeixicService.DisableWorkspaceBreakGlass - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DisableWorkspaceBreakGlassRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - /deixic.v1.DeixicService/ListWorkspaceSkills: - post: - tags: - - deixic.v1.DeixicService - summary: ListWorkspaceSkills - description: Uses the canonical console.v1.ConsoleService.ListWorkspaceSkills message contract. - operationId: deixic.v1.DeixicService.ListWorkspaceSkills - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListWorkspaceSkillsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListWorkspaceSkillsResponse' - /deixic.v1.DeixicService/BrowseDexSkillCatalog: - post: - tags: - - deixic.v1.DeixicService - summary: BrowseDexSkillCatalog - description: Uses the canonical console.v1.ConsoleService.BrowseDexSkillCatalog message contract. - operationId: deixic.v1.DeixicService.BrowseDexSkillCatalog - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.BrowseDexSkillCatalogRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.BrowseDexSkillCatalogResponse' - /deixic.v1.DeixicService/InstallDexSkillCatalogEntry: - post: - tags: - - deixic.v1.DeixicService - summary: InstallDexSkillCatalogEntry - description: Uses the canonical console.v1.ConsoleService.InstallDexSkillCatalogEntry message contract. - operationId: deixic.v1.DeixicService.InstallDexSkillCatalogEntry - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.InstallDexSkillCatalogEntryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.InstallDexSkillCatalogEntryResponse' - /deixic.v1.DeixicService/CreateWorkspaceSkill: - post: - tags: - - deixic.v1.DeixicService - summary: CreateWorkspaceSkill - description: Uses the canonical console.v1.ConsoleService.CreateWorkspaceSkill message contract. - operationId: deixic.v1.DeixicService.CreateWorkspaceSkill - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateWorkspaceSkillRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateWorkspaceSkillResponse' - /deixic.v1.DeixicService/UpdateWorkspaceSkill: - post: - tags: - - deixic.v1.DeixicService - summary: UpdateWorkspaceSkill - description: Uses the canonical console.v1.ConsoleService.UpdateWorkspaceSkill message contract. - operationId: deixic.v1.DeixicService.UpdateWorkspaceSkill - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateWorkspaceSkillRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateWorkspaceSkillResponse' - /deixic.v1.DeixicService/DeleteWorkspaceSkill: - post: - tags: - - deixic.v1.DeixicService - summary: DeleteWorkspaceSkill - description: Uses the canonical console.v1.ConsoleService.DeleteWorkspaceSkill message contract. - operationId: deixic.v1.DeixicService.DeleteWorkspaceSkill - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DeleteWorkspaceSkillRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DeleteWorkspaceSkillResponse' - /deixic.v1.DeixicService/ListScenarioFixtures: - post: - tags: - - deixic.v1.DeixicService - summary: ListScenarioFixtures - description: Uses the canonical console.v1.ConsoleService.ListScenarioFixtures message contract. - operationId: deixic.v1.DeixicService.ListScenarioFixtures - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListScenarioFixturesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListScenarioFixturesResponse' - /deixic.v1.DeixicService/PromoteScenarioFixture: - post: - tags: - - deixic.v1.DeixicService - summary: PromoteScenarioFixture - description: Uses the canonical console.v1.ConsoleService.PromoteScenarioFixture message contract. - operationId: deixic.v1.DeixicService.PromoteScenarioFixture - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.PromoteScenarioFixtureRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.PromoteScenarioFixtureResponse' - /deixic.v1.DeixicService/CompareScenarioFixtures: - post: - tags: - - deixic.v1.DeixicService - summary: CompareScenarioFixtures - description: Uses the canonical console.v1.ConsoleService.CompareScenarioFixtures message contract. - operationId: deixic.v1.DeixicService.CompareScenarioFixtures - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CompareScenarioFixturesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CompareScenarioFixturesResponse' - /deixic.v1.DeixicService/CreateConnectorProfile: - post: - tags: - - deixic.v1.DeixicService - summary: CreateConnectorProfile - description: Uses the canonical console.v1.ConsoleService.CreateConnectorProfile message contract. - operationId: deixic.v1.DeixicService.CreateConnectorProfile - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateConnectorProfileRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.CreateConnectorProfileResponse' - /deixic.v1.DeixicService/ListConnectorProfiles: - post: - tags: - - deixic.v1.DeixicService - summary: ListConnectorProfiles - description: Uses the canonical console.v1.ConsoleService.ListConnectorProfiles message contract. - operationId: deixic.v1.DeixicService.ListConnectorProfiles - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListConnectorProfilesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListConnectorProfilesResponse' - /deixic.v1.DeixicService/UpdateConnectorProfile: - post: - tags: - - deixic.v1.DeixicService - summary: UpdateConnectorProfile - description: Uses the canonical console.v1.ConsoleService.UpdateConnectorProfile message contract. - operationId: deixic.v1.DeixicService.UpdateConnectorProfile - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateConnectorProfileRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.UpdateConnectorProfileResponse' - /deixic.v1.DeixicService/DeleteConnectorProfile: - post: - tags: - - deixic.v1.DeixicService - summary: DeleteConnectorProfile - description: Uses the canonical console.v1.ConsoleService.DeleteConnectorProfile message contract. - operationId: deixic.v1.DeixicService.DeleteConnectorProfile - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DeleteConnectorProfileRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.DeleteConnectorProfileResponse' - /deixic.v1.DeixicService/ListConnectedCalls: - post: - tags: - - deixic.v1.DeixicService - summary: ListConnectedCalls - description: Uses the canonical console.v1.ConsoleService.ListConnectedCalls message contract. - operationId: deixic.v1.DeixicService.ListConnectedCalls - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListConnectedCallsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListConnectedCallsResponse' - /deixic.v1.DeixicService/StartMeetingCapture: - post: - tags: - - deixic.v1.DeixicService - summary: StartMeetingCapture - description: Uses the canonical console.v1.ConsoleService.StartMeetingCapture message contract. - operationId: deixic.v1.DeixicService.StartMeetingCapture - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.StartMeetingCaptureRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.StartMeetingCaptureResponse' - /deixic.v1.DeixicService/GetMeetingCapture: - post: - tags: - - deixic.v1.DeixicService - summary: GetMeetingCapture - description: Uses the canonical console.v1.ConsoleService.GetMeetingCapture message contract. - operationId: deixic.v1.DeixicService.GetMeetingCapture - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetMeetingCaptureRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.GetMeetingCaptureResponse' - /deixic.v1.DeixicService/ListMeetingCaptures: - post: - tags: - - deixic.v1.DeixicService - summary: ListMeetingCaptures - description: Uses the canonical console.v1.ConsoleService.ListMeetingCaptures message contract. - operationId: deixic.v1.DeixicService.ListMeetingCaptures - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListMeetingCapturesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListMeetingCapturesResponse' - /deixic.v1.DeixicService/StopMeetingCapture: - post: - tags: - - deixic.v1.DeixicService - summary: StopMeetingCapture - description: Uses the canonical console.v1.ConsoleService.StopMeetingCapture message contract. - operationId: deixic.v1.DeixicService.StopMeetingCapture - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.StopMeetingCaptureRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.StopMeetingCaptureResponse' - /deixic.v1.DeixicService/ListCommitments: - post: - tags: - - deixic.v1.DeixicService - summary: ListCommitments - description: Uses the canonical console.v1.ConsoleService.ListCommitments message contract. - operationId: deixic.v1.DeixicService.ListCommitments - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListCommitmentsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/console.v1.ListCommitmentsResponse' -components: - schemas: - agents.v1.AgentStatus: - type: string - title: AgentStatus - enum: - - AGENT_STATUS_UNSPECIFIED - - AGENT_STATUS_ACTIVE - - AGENT_STATUS_IDLE - - AGENT_STATUS_BUSY - - AGENT_STATUS_OFFLINE - - AGENT_STATUS_DEGRADED - - AGENT_STATUS_SUSPENDED - description: AgentStatus describes the operational state of an agent. - agents.v1.AutonomyAuthority: - type: string - title: AutonomyAuthority - enum: - - AUTONOMY_AUTHORITY_UNSPECIFIED - - AUTONOMY_AUTHORITY_OWN - - AUTONOMY_AUTHORITY_RECOMMEND - - AUTONOMY_AUTHORITY_REQUIRE_APPROVAL - - AUTONOMY_AUTHORITY_DENY - description: AutonomyAuthority describes how independently a teammate may act. - agents.v1.CommitmentKind: - type: string - title: CommitmentKind - enum: - - COMMITMENT_KIND_UNSPECIFIED - - COMMITMENT_KIND_FOLLOW_UP - - COMMITMENT_KIND_WATCH - - COMMITMENT_KIND_RETRY - - COMMITMENT_KIND_SUMMARIZE - - COMMITMENT_KIND_MONITOR - - COMMITMENT_KIND_REMEDIATE - - COMMITMENT_KIND_HANDOFF - description: CommitmentKind describes the durable commitments a teammate can accept. - agents.v1.InitiativeTriggerKind: - type: string - title: InitiativeTriggerKind - enum: - - INITIATIVE_TRIGGER_KIND_UNSPECIFIED - - INITIATIVE_TRIGGER_KIND_SCHEDULE - - INITIATIVE_TRIGGER_KIND_SLACK_EVENT - - INITIATIVE_TRIGGER_KIND_PLATFORM_EVENT - - INITIATIVE_TRIGGER_KIND_OBJECTIVE_WAKE - - INITIATIVE_TRIGGER_KIND_WAIT_RESOLVED - - INITIATIVE_TRIGGER_KIND_EVAL_REGRESSION - - INITIATIVE_TRIGGER_KIND_STALLED_WORK - description: |- - InitiativeTriggerKind describes events that can let a teammate start work - without a fresh direct human prompt. - agents.v1.PresenceEvent: - type: string - title: PresenceEvent - enum: - - PRESENCE_EVENT_UNSPECIFIED - - PRESENCE_EVENT_ACCEPTED - - PRESENCE_EVENT_WAITING - - PRESENCE_EVENT_PROGRESS - - PRESENCE_EVENT_BLOCKED - - PRESENCE_EVENT_COMPLETED - - PRESENCE_EVENT_FAILED - - PRESENCE_EVENT_ESCALATED - description: PresenceEvent describes channel-visible teammate activity. - agents.v1.TeammateChannelCapability: - type: string - title: TeammateChannelCapability - enum: - - TEAMMATE_CHANNEL_CAPABILITY_UNSPECIFIED - - TEAMMATE_CHANNEL_CAPABILITY_INGEST - - TEAMMATE_CHANNEL_CAPABILITY_RENDER - description: |- - TeammateChannelCapability describes what a channel adapter can do for a - teammate profile. - agents.v1.TeammateChannelEventKind: - type: string - title: TeammateChannelEventKind - enum: - - TEAMMATE_CHANNEL_EVENT_KIND_UNSPECIFIED - - TEAMMATE_CHANNEL_EVENT_KIND_MESSAGE_CREATED - - TEAMMATE_CHANNEL_EVENT_KIND_THREAD_REPLY_CREATED - - TEAMMATE_CHANNEL_EVENT_KIND_COMMAND_INVOKED - - TEAMMATE_CHANNEL_EVENT_KIND_ACTION_INVOKED - - TEAMMATE_CHANNEL_EVENT_KIND_REACTION_ADDED - - TEAMMATE_CHANNEL_EVENT_KIND_REACTION_REMOVED - - TEAMMATE_CHANNEL_EVENT_KIND_ASSISTANT_THREAD_STARTED - - TEAMMATE_CHANNEL_EVENT_KIND_ASSISTANT_THREAD_CONTEXT_CHANGED - - TEAMMATE_CHANNEL_EVENT_KIND_EMAIL_RECEIVED - - TEAMMATE_CHANNEL_EVENT_KIND_CALENDAR_EVENT_CHANGED - - TEAMMATE_CHANNEL_EVENT_KIND_ISSUE_CHANGED - - TEAMMATE_CHANNEL_EVENT_KIND_SCHEDULED_WAKE - - TEAMMATE_CHANNEL_EVENT_KIND_WEBHOOK_RECEIVED - description: |- - TeammateChannelEventKind describes normalized inbound channel events that can - become AgentRuntime triggers. - agents.v1.TeammateChannelKind: - type: string - title: TeammateChannelKind - enum: - - TEAMMATE_CHANNEL_KIND_UNSPECIFIED - - TEAMMATE_CHANNEL_KIND_SLACK - - TEAMMATE_CHANNEL_KIND_EMAIL - - TEAMMATE_CHANNEL_KIND_CALENDAR - - TEAMMATE_CHANNEL_KIND_JIRA - - TEAMMATE_CHANNEL_KIND_TEAMS - - TEAMMATE_CHANNEL_KIND_WEB - - TEAMMATE_CHANNEL_KIND_WEBHOOK - - TEAMMATE_CHANNEL_KIND_WHATSAPP - - TEAMMATE_CHANNEL_KIND_APPLE_MESSAGES - description: |- - TeammateChannelKind identifies a product or provider channel that can ingest - user activity or render teammate runtime events. It intentionally lives in - agents/v1 instead of agentruntime/v1 so teammate profiles can describe - supported channels without creating a proto import cycle. - agents.v1.TeammateLifecycle: - type: string - title: TeammateLifecycle - enum: - - TEAMMATE_LIFECYCLE_UNSPECIFIED - - TEAMMATE_LIFECYCLE_DRAFT - - TEAMMATE_LIFECYCLE_ACTIVE - - TEAMMATE_LIFECYCLE_PAUSED - - TEAMMATE_LIFECYCLE_DEPRECATED - description: |- - TeammateLifecycle describes whether a teammate profile can be used to - initiate durable work. - agents.v1.TeammateRuntimeRenderEventKind: - type: string - title: TeammateRuntimeRenderEventKind - enum: - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_UNSPECIFIED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_TRIGGER_ACCEPTED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_RUN_STARTED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_PROGRESS - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_STEP_STARTED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_STEP_COMPLETED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_OBJECTIVE_UPDATED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_APPROVAL_REQUESTED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_APPROVAL_RESOLVED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_TOOL_PROPOSED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_TOOL_COMPLETED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_ARTIFACT_CREATED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_MEMORY_PROPOSED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_WAITING - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_RESUMED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_COMPLETED - - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_FAILED - description: |- - TeammateRuntimeRenderEventKind describes Platform runtime events a channel - adapter can project back into the provider surface. - common.v1.DeliveryChannel: - type: string - title: DeliveryChannel - enum: - - DELIVERY_CHANNEL_UNSPECIFIED - - DELIVERY_CHANNEL_SLACK - - DELIVERY_CHANNEL_EMAIL - - DELIVERY_CHANNEL_WEBHOOK - - DELIVERY_CHANNEL_IN_APP - - DELIVERY_CHANNEL_PUSH - description: DeliveryChannel identifies the notification delivery channel. - common.v1.EntityType: - type: string - title: EntityType - enum: - - ENTITY_TYPE_UNSPECIFIED - - ENTITY_TYPE_CONTACT - - ENTITY_TYPE_COMPANY - - ENTITY_TYPE_DEAL - - ENTITY_TYPE_TICKET - - ENTITY_TYPE_CUSTOMER - - ENTITY_TYPE_OPPORTUNITY - description: EntityType identifies the kind of entity across systems. - common.v1.RiskLevel: - type: string - title: RiskLevel - enum: - - RISK_LEVEL_UNSPECIFIED - - RISK_LEVEL_LOW - - RISK_LEVEL_MEDIUM - - RISK_LEVEL_HIGH - - RISK_LEVEL_CRITICAL - description: RiskLevel classifies the risk of an action. - common.v1.Surface: - type: string - title: Surface - enum: - - SURFACE_UNSPECIFIED - - SURFACE_ENSEMBLE - - SURFACE_CHAT - - SURFACE_MAESTRO - - SURFACE_CONDUCTOR - - SURFACE_SLACK - - SURFACE_EXTERNAL_AGENT - description: |- - Surface identifies the product or channel surface that originated a platform - action. It is shared by runtime, audit, and product-facing services so - callers do not invent drift-prone string labels. - connectors.v1.ConnectorEvidenceKind: - type: string - title: ConnectorEvidenceKind - enum: - - CONNECTOR_EVIDENCE_KIND_UNSPECIFIED - - CONNECTOR_EVIDENCE_KIND_PROBE - - CONNECTOR_EVIDENCE_KIND_FIXTURE - - CONNECTOR_EVIDENCE_KIND_CANARY - - CONNECTOR_EVIDENCE_KIND_PRODUCTION - - CONNECTOR_EVIDENCE_KIND_UNPROVABLE_UNAUTHENTICATED - description: |- - ConnectorEvidenceKind identifies the bounded evidence supporting a catalog - verification level. It does not establish credential validity or transport - availability. - connectors.v1.ConnectorVerificationLevel: - type: string - title: ConnectorVerificationLevel - enum: - - CONNECTOR_VERIFICATION_LEVEL_UNSPECIFIED - - CONNECTOR_VERIFICATION_LEVEL_DECLARED - - CONNECTOR_VERIFICATION_LEVEL_SPEC_DERIVED - - CONNECTOR_VERIFICATION_LEVEL_FIXTURE_VERIFIED - - CONNECTOR_VERIFICATION_LEVEL_LIVE_VERIFIED - - CONNECTOR_VERIFICATION_LEVEL_CONTINUOUSLY_VERIFIED - description: |- - ConnectorVerificationLevel is the fail-closed evidence ladder for a - connector catalog subject. Higher levels require the canonical verification - ledger to contain evidence that justifies the promotion. - connectors.v1.HealthStatus: - type: string - title: HealthStatus - enum: - - HEALTH_STATUS_UNSPECIFIED - - HEALTH_STATUS_HEALTHY - - HEALTH_STATUS_DEGRADED - - HEALTH_STATUS_UNHEALTHY - - HEALTH_STATUS_UNKNOWN - description: HealthStatus describes the health state of a connection. - connectors.v1.ProviderContentTrust: - type: string - title: ProviderContentTrust - enum: - - PROVIDER_CONTENT_TRUST_UNSPECIFIED - - PROVIDER_CONTENT_TRUST_UNTRUSTED_PROVIDER_CONTENT - connectors.v1.ProviderResourceLifecycleState: - type: string - title: ProviderResourceLifecycleState - enum: - - PROVIDER_RESOURCE_LIFECYCLE_STATE_UNSPECIFIED - - PROVIDER_RESOURCE_LIFECYCLE_STATE_ACTIVE - - PROVIDER_RESOURCE_LIFECYCLE_STATE_ARCHIVED - - PROVIDER_RESOURCE_LIFECYCLE_STATE_DELETED - - PROVIDER_RESOURCE_LIFECYCLE_STATE_CONNECTION_REVOKED - - PROVIDER_RESOURCE_LIFECYCLE_STATE_QUARANTINED - connectors.v1.ProviderResourceVisibilityClass: - type: string - title: ProviderResourceVisibilityClass - enum: - - PROVIDER_RESOURCE_VISIBILITY_CLASS_UNSPECIFIED - - PROVIDER_RESOURCE_VISIBILITY_CLASS_WORKSPACE_PUBLIC - - PROVIDER_RESOURCE_VISIBILITY_CLASS_EXPLICIT_PRINCIPALS - - PROVIDER_RESOURCE_VISIBILITY_CLASS_GROUP_MEMBERSHIP - - PROVIDER_RESOURCE_VISIBILITY_CLASS_CONNECTION_PRIVATE - connectors.v1.SourceAuthorityFreshnessMethod: - type: string - title: SourceAuthorityFreshnessMethod - enum: - - SOURCE_AUTHORITY_FRESHNESS_METHOD_UNSPECIFIED - - SOURCE_AUTHORITY_FRESHNESS_METHOD_NOT_OBSERVED - - SOURCE_AUTHORITY_FRESHNESS_METHOD_INTROSPECTION - - SOURCE_AUTHORITY_FRESHNESS_METHOD_WEBHOOK - - SOURCE_AUTHORITY_FRESHNESS_METHOD_POLLING - - SOURCE_AUTHORITY_FRESHNESS_METHOD_SHORT_TTL - - SOURCE_AUTHORITY_FRESHNESS_METHOD_REFRESH_FAILURE - description: |- - SourceAuthorityFreshnessMethod identifies how the source observation was - obtained. NOT_OBSERVED is the explicit default when no authoritative - producer has supplied a response; it is not evidence of source access. - connectors.v1.SourceAuthorityState: - type: string - title: SourceAuthorityState - enum: - - SOURCE_AUTHORITY_STATE_UNSPECIFIED - - SOURCE_AUTHORITY_STATE_SUFFICIENT - - SOURCE_AUTHORITY_STATE_INSUFFICIENT - - SOURCE_AUTHORITY_STATE_UNKNOWN - - SOURCE_AUTHORITY_STATE_REVOKED - description: |- - SourceAuthorityState is the external source system's authority posture for - a connection. A locally active row is not source authority; callers must - receive an explicit UNKNOWN observation until an authoritative producer - reports otherwise. - console.v1.BusinessFieldKind: - type: string - title: BusinessFieldKind - enum: - - BUSINESS_FIELD_KIND_UNSPECIFIED - - BUSINESS_FIELD_KIND_TEXT - - BUSINESS_FIELD_KIND_INTEGER - - BUSINESS_FIELD_KIND_BOOLEAN - - BUSINESS_FIELD_KIND_DECIMAL - - BUSINESS_FIELD_KIND_MONEY - - BUSINESS_FIELD_KIND_ENUM - - BUSINESS_FIELD_KIND_DATE - - BUSINESS_FIELD_KIND_TIMESTAMP - - BUSINESS_FIELD_KIND_REFERENCE - - BUSINESS_FIELD_KIND_ARTIFACT - - BUSINESS_FIELD_KIND_TEXT_LIST - description: Customer-defined business schemas. Field and relationship IDs remain stable across versions. - console.v1.BusinessObjectRecordKind: - type: string - title: BusinessObjectRecordKind - enum: - - BUSINESS_OBJECT_RECORD_KIND_UNSPECIFIED - - BUSINESS_OBJECT_RECORD_KIND_CRM_COMPANY - - BUSINESS_OBJECT_RECORD_KIND_CRM_CONTACT - - BUSINESS_OBJECT_RECORD_KIND_CRM_DEAL - - BUSINESS_OBJECT_RECORD_KIND_CRM_SIGNAL - - BUSINESS_OBJECT_RECORD_KIND_CRM_ACTIVITY - - BUSINESS_OBJECT_RECORD_KIND_CRM_DEPLOYMENT - - BUSINESS_OBJECT_RECORD_KIND_CRM_TASK - - BUSINESS_OBJECT_RECORD_KIND_CRM_MEETING - description: |- - Immutable domain validation and access policy. CRM kinds retain internal staff - and pipeline:crm.read/write checks even through generic object APIs. - This metadata never grants the caller those permissions. - console.v1.BusinessObjectRelationshipDirection: - type: string - title: BusinessObjectRelationshipDirection - enum: - - BUSINESS_OBJECT_RELATIONSHIP_DIRECTION_UNSPECIFIED - - BUSINESS_OBJECT_RELATIONSHIP_DIRECTION_OUTGOING - - BUSINESS_OBJECT_RELATIONSHIP_DIRECTION_INCOMING - console.v1.BusinessSourceProperty: - type: string - title: BusinessSourceProperty - enum: - - BUSINESS_SOURCE_PROPERTY_UNSPECIFIED - - BUSINESS_SOURCE_PROPERTY_DISPLAY_NAME - - BUSINESS_SOURCE_PROPERTY_EXTERNAL_ID - console.v1.BusinessSourceState: - type: string - title: BusinessSourceState - enum: - - BUSINESS_SOURCE_STATE_UNSPECIFIED - - BUSINESS_SOURCE_STATE_ACTIVE - - BUSINESS_SOURCE_STATE_DELETED - - BUSINESS_SOURCE_STATE_ACCESS_REVOKED - - BUSINESS_SOURCE_STATE_ARCHIVED - console.v1.CaptureFormBrandingAssetRole: - type: string - title: CaptureFormBrandingAssetRole - enum: - - CAPTURE_FORM_BRANDING_ASSET_ROLE_UNSPECIFIED - - CAPTURE_FORM_BRANDING_ASSET_ROLE_LOGO - - CAPTURE_FORM_BRANDING_ASSET_ROLE_FAVICON - description: |- - CaptureFormBrandingAssetRole is the fixed public selector. Object and - version coordinates remain server-owned and are never accepted by the - public asset route. - console.v1.CaptureFormFieldKind: - type: string - title: CaptureFormFieldKind - enum: - - CAPTURE_FORM_FIELD_KIND_UNSPECIFIED - - CAPTURE_FORM_FIELD_KIND_TEXT - - CAPTURE_FORM_FIELD_KIND_LONG_TEXT - - CAPTURE_FORM_FIELD_KIND_INTEGER - - CAPTURE_FORM_FIELD_KIND_DECIMAL - - CAPTURE_FORM_FIELD_KIND_BOOLEAN - - CAPTURE_FORM_FIELD_KIND_DATE - - CAPTURE_FORM_FIELD_KIND_DATETIME - - CAPTURE_FORM_FIELD_KIND_EMAIL - - CAPTURE_FORM_FIELD_KIND_PHONE - - CAPTURE_FORM_FIELD_KIND_URL - - CAPTURE_FORM_FIELD_KIND_SELECT - - CAPTURE_FORM_FIELD_KIND_MULTI_SELECT - - CAPTURE_FORM_FIELD_KIND_FILE - description: |- - CaptureFormFieldKind is intentionally closed. A client cannot smuggle a - JSON shape into a scalar field or make a hidden write through presentation. - console.v1.CaptureFormMappingState: - type: string - title: CaptureFormMappingState - enum: - - CAPTURE_FORM_MAPPING_STATE_UNSPECIFIED - - CAPTURE_FORM_MAPPING_STATE_MAPPED - - CAPTURE_FORM_MAPPING_STATE_UNMAPPED - console.v1.CaptureFormObjectResultState: - type: string - title: CaptureFormObjectResultState - enum: - - CAPTURE_FORM_OBJECT_RESULT_STATE_UNSPECIFIED - - CAPTURE_FORM_OBJECT_RESULT_STATE_CREATED - - CAPTURE_FORM_OBJECT_RESULT_STATE_PARTIAL - - CAPTURE_FORM_OBJECT_RESULT_STATE_FAILED - console.v1.CaptureFormPublicationState: - type: string - title: CaptureFormPublicationState - enum: - - CAPTURE_FORM_PUBLICATION_STATE_UNSPECIFIED - - CAPTURE_FORM_PUBLICATION_STATE_ACTIVE - - CAPTURE_FORM_PUBLICATION_STATE_REVOKED - - CAPTURE_FORM_PUBLICATION_STATE_EXPIRED - description: CaptureFormPublicationState is the lifecycle of one immutable public grant. - console.v1.CaptureFormReviewDecision: - type: string - title: CaptureFormReviewDecision - enum: - - CAPTURE_FORM_REVIEW_DECISION_UNSPECIFIED - - CAPTURE_FORM_REVIEW_DECISION_ACCEPT - - CAPTURE_FORM_REVIEW_DECISION_REJECT - console.v1.CaptureFormState: - type: string - title: CaptureFormState - enum: - - CAPTURE_FORM_STATE_UNSPECIFIED - - CAPTURE_FORM_STATE_DRAFT - - CAPTURE_FORM_STATE_ACTIVE - - CAPTURE_FORM_STATE_ARCHIVED - description: CaptureFormState is the owner-controlled lifecycle of a form identity. - console.v1.CaptureFormSubmissionState: - type: string - title: CaptureFormSubmissionState - enum: - - CAPTURE_FORM_SUBMISSION_STATE_UNSPECIFIED - - CAPTURE_FORM_SUBMISSION_STATE_RECEIVED - - CAPTURE_FORM_SUBMISSION_STATE_UNDER_REVIEW - - CAPTURE_FORM_SUBMISSION_STATE_ACCEPTED - - CAPTURE_FORM_SUBMISSION_STATE_REJECTED - - CAPTURE_FORM_SUBMISSION_STATE_FAILED - description: CaptureFormSubmissionState is the durable submission/review lifecycle. - console.v1.CaptureFormUploadState: - type: string - title: CaptureFormUploadState - enum: - - CAPTURE_FORM_UPLOAD_STATE_UNSPECIFIED - - CAPTURE_FORM_UPLOAD_STATE_GRANTED - - CAPTURE_FORM_UPLOAD_STATE_PROCESSING - - CAPTURE_FORM_UPLOAD_STATE_COMPLETED - - CAPTURE_FORM_UPLOAD_STATE_FAILED - - CAPTURE_FORM_UPLOAD_STATE_EXPIRED - console.v1.CommitmentSourceState: - type: string - title: CommitmentSourceState - enum: - - COMMITMENT_SOURCE_STATE_UNSPECIFIED - - COMMITMENT_SOURCE_STATE_AVAILABLE - - COMMITMENT_SOURCE_STATE_NOT_CONFIGURED - description: |- - CommitmentSourceState reports whether the commitment ledger can be read for - this workspace. NOT_CONFIGURED means the deployment has no commitment-ledger - origin configured, so the response carries no commitments instead of an - empty ledger that would read as "you have none". - console.v1.ComplianceFindingStatus: - type: string - title: ComplianceFindingStatus - enum: - - COMPLIANCE_FINDING_STATUS_UNSPECIFIED - - COMPLIANCE_FINDING_STATUS_SATISFIED - - COMPLIANCE_FINDING_STATUS_VIOLATED - - COMPLIANCE_FINDING_STATUS_INDETERMINATE - - COMPLIANCE_FINDING_STATUS_NOT_APPLICABLE - console.v1.ComputerMissionAuthorityMode: - type: string - title: ComputerMissionAuthorityMode - enum: - - COMPUTER_MISSION_AUTHORITY_MODE_UNSPECIFIED - - COMPUTER_MISSION_AUTHORITY_MODE_SUPERVISED - - COMPUTER_MISSION_AUTHORITY_MODE_BOUNDED_AUTONOMY - - COMPUTER_MISSION_AUTHORITY_MODE_FULL_AUTONOMY - console.v1.ComputerMissionCanaryOperatorActionKind: - type: string - title: ComputerMissionCanaryOperatorActionKind - enum: - - COMPUTER_MISSION_CANARY_OPERATOR_ACTION_KIND_UNSPECIFIED - - COMPUTER_MISSION_CANARY_OPERATOR_ACTION_KIND_PAUSE - - COMPUTER_MISSION_CANARY_OPERATOR_ACTION_KIND_CANCEL - - COMPUTER_MISSION_CANARY_OPERATOR_ACTION_KIND_NARROW_SCOPE - - COMPUTER_MISSION_CANARY_OPERATOR_ACTION_KIND_EXTEND_GRANT - console.v1.ComputerMissionCanaryRecommendation: - type: string - title: ComputerMissionCanaryRecommendation - enum: - - COMPUTER_MISSION_CANARY_RECOMMENDATION_UNSPECIFIED - - COMPUTER_MISSION_CANARY_RECOMMENDATION_HOLD - - COMPUTER_MISSION_CANARY_RECOMMENDATION_PROMOTE - - COMPUTER_MISSION_CANARY_RECOMMENDATION_ROLL_BACK - console.v1.ComputerMissionCanaryRunState: - type: string - title: ComputerMissionCanaryRunState - enum: - - COMPUTER_MISSION_CANARY_RUN_STATE_UNSPECIFIED - - COMPUTER_MISSION_CANARY_RUN_STATE_QUEUED - - COMPUTER_MISSION_CANARY_RUN_STATE_RUNNING - - COMPUTER_MISSION_CANARY_RUN_STATE_WAITING_FOR_USER - - COMPUTER_MISSION_CANARY_RUN_STATE_CLEANUP_RUNNING - - COMPUTER_MISSION_CANARY_RUN_STATE_EVALUATION_PENDING - - COMPUTER_MISSION_CANARY_RUN_STATE_PASSED - - COMPUTER_MISSION_CANARY_RUN_STATE_FAILED - - COMPUTER_MISSION_CANARY_RUN_STATE_UNSAFE - - COMPUTER_MISSION_CANARY_RUN_STATE_CLEANUP_UNCERTAIN - - COMPUTER_MISSION_CANARY_RUN_STATE_CANCELLED - console.v1.ComputerMissionCanaryScenarioKind: - type: string - title: ComputerMissionCanaryScenarioKind - enum: - - COMPUTER_MISSION_CANARY_SCENARIO_KIND_UNSPECIFIED - - COMPUTER_MISSION_CANARY_SCENARIO_KIND_CI_REPAIR - - COMPUTER_MISSION_CANARY_SCENARIO_KIND_REVIEW_OPERATIONS - - COMPUTER_MISSION_CANARY_SCENARIO_KIND_RUNNER_RECOVERY - - COMPUTER_MISSION_CANARY_SCENARIO_KIND_APPROVAL_CONTINUATION - - COMPUTER_MISSION_CANARY_SCENARIO_KIND_AMBIGUOUS_TOOL_RESPONSE - - COMPUTER_MISSION_CANARY_SCENARIO_KIND_BUDGET_STOP - console.v1.ComputerMissionCanaryScoreDimension: - type: string - title: ComputerMissionCanaryScoreDimension - enum: - - COMPUTER_MISSION_CANARY_SCORE_DIMENSION_UNSPECIFIED - - COMPUTER_MISSION_CANARY_SCORE_DIMENSION_OUTCOME_CORRECTNESS - - COMPUTER_MISSION_CANARY_SCORE_DIMENSION_HUMAN_INTERVENTION_EFFICIENCY - - COMPUTER_MISSION_CANARY_SCORE_DIMENSION_SCOPE_ADHERENCE - - COMPUTER_MISSION_CANARY_SCORE_DIMENSION_DUPLICATE_EFFECT_AVOIDANCE - - COMPUTER_MISSION_CANARY_SCORE_DIMENSION_RECOVERY_SUCCESS - - COMPUTER_MISSION_CANARY_SCORE_DIMENSION_BUDGET_EFFICIENCY - - COMPUTER_MISSION_CANARY_SCORE_DIMENSION_EVIDENCE_COMPLETENESS - - COMPUTER_MISSION_CANARY_SCORE_DIMENSION_TIME_TO_VERIFIED_COMPLETION - console.v1.ComputerMissionDecisionRoute: - type: string - title: ComputerMissionDecisionRoute - enum: - - COMPUTER_MISSION_DECISION_ROUTE_UNSPECIFIED - - COMPUTER_MISSION_DECISION_ROUTE_NO_ROUTE - - COMPUTER_MISSION_DECISION_ROUTE_SINGLE_AGENT - - COMPUTER_MISSION_DECISION_ROUTE_TOURNAMENT - console.v1.ComputerMissionEffectState: - type: string - title: ComputerMissionEffectState - enum: - - COMPUTER_MISSION_EFFECT_STATE_UNSPECIFIED - - COMPUTER_MISSION_EFFECT_STATE_INTENT_RECORDED - - COMPUTER_MISSION_EFFECT_STATE_FORWARD_ACCEPTED - - COMPUTER_MISSION_EFFECT_STATE_FORWARD_VERIFIED - - COMPUTER_MISSION_EFFECT_STATE_ROLLBACK_RUNNING - - COMPUTER_MISSION_EFFECT_STATE_ROLLED_BACK - - COMPUTER_MISSION_EFFECT_STATE_CLEANUP_VERIFIED - - COMPUTER_MISSION_EFFECT_STATE_CLEANUP_UNCERTAIN - console.v1.ComputerMissionRollbackArgumentSource: - type: string - title: ComputerMissionRollbackArgumentSource - enum: - - COMPUTER_MISSION_ROLLBACK_ARGUMENT_SOURCE_UNSPECIFIED - - COMPUTER_MISSION_ROLLBACK_ARGUMENT_SOURCE_PRE_ACTION_STATE - - COMPUTER_MISSION_ROLLBACK_ARGUMENT_SOURCE_FORWARD_RECEIPT - console.v1.ComputerMissionState: - type: string - title: ComputerMissionState - enum: - - COMPUTER_MISSION_STATE_UNSPECIFIED - - COMPUTER_MISSION_STATE_QUEUED - - COMPUTER_MISSION_STATE_RUNNING - - COMPUTER_MISSION_STATE_WAITING_FOR_USER - - COMPUTER_MISSION_STATE_CANCELLATION_REQUESTED - - COMPUTER_MISSION_STATE_SUCCEEDED - - COMPUTER_MISSION_STATE_FAILED - - COMPUTER_MISSION_STATE_BUDGET_EXHAUSTED - - COMPUTER_MISSION_STATE_CANCELLED - - COMPUTER_MISSION_STATE_CLEANUP_UNCERTAIN - - COMPUTER_MISSION_STATE_NOT_ROUTED - - COMPUTER_MISSION_STATE_PLANNING - - COMPUTER_MISSION_STATE_VERIFYING - - COMPUTER_MISSION_STATE_SLEEPING - - COMPUTER_MISSION_STATE_WAITING_FOR_APPROVAL - - COMPUTER_MISSION_STATE_WAITING_FOR_EXTERNAL_EVENT - - COMPUTER_MISSION_STATE_PAUSED - console.v1.ConnectedCallSourceState: - type: string - title: ConnectedCallSourceState - enum: - - CONNECTED_CALL_SOURCE_STATE_UNSPECIFIED - - CONNECTED_CALL_SOURCE_STATE_AVAILABLE - - CONNECTED_CALL_SOURCE_STATE_NOT_CONNECTED - console.v1.ConnectorTriggerSource: - type: string - title: ConnectorTriggerSource - enum: - - CONNECTOR_TRIGGER_SOURCE_UNSPECIFIED - - CONNECTOR_TRIGGER_SOURCE_SCHEDULED - - CONNECTOR_TRIGGER_SOURCE_CONNECTOR_EVENT - console.v1.CustomerFactConfirmationResponse: - type: string - title: CustomerFactConfirmationResponse - enum: - - CUSTOMER_FACT_CONFIRMATION_RESPONSE_UNSPECIFIED - - CUSTOMER_FACT_CONFIRMATION_RESPONSE_CONFIRM - - CUSTOMER_FACT_CONFIRMATION_RESPONSE_DISPUTE - console.v1.CustomerIntelligenceAuthority: - type: string - title: CustomerIntelligenceAuthority - enum: - - CUSTOMER_INTELLIGENCE_AUTHORITY_UNSPECIFIED - - CUSTOMER_INTELLIGENCE_AUTHORITY_INFERRED - - CUSTOMER_INTELLIGENCE_AUTHORITY_OBSERVED - - CUSTOMER_INTELLIGENCE_AUTHORITY_STATED - - CUSTOMER_INTELLIGENCE_AUTHORITY_CORROBORATED - - CUSTOMER_INTELLIGENCE_AUTHORITY_CONFIRMED - console.v1.CustomerIntelligenceEvidencePolarity: - type: string - title: CustomerIntelligenceEvidencePolarity - enum: - - CUSTOMER_INTELLIGENCE_EVIDENCE_POLARITY_UNSPECIFIED - - CUSTOMER_INTELLIGENCE_EVIDENCE_POLARITY_SUPPORTING - - CUSTOMER_INTELLIGENCE_EVIDENCE_POLARITY_CONTRADICTING - console.v1.CustomerIntelligenceLifecycleState: - type: string - title: CustomerIntelligenceLifecycleState - enum: - - CUSTOMER_INTELLIGENCE_LIFECYCLE_STATE_UNSPECIFIED - - CUSTOMER_INTELLIGENCE_LIFECYCLE_STATE_PROPOSED - - CUSTOMER_INTELLIGENCE_LIFECYCLE_STATE_ACTIVE - - CUSTOMER_INTELLIGENCE_LIFECYCLE_STATE_DISPUTED - - CUSTOMER_INTELLIGENCE_LIFECYCLE_STATE_SUPERSEDED - - CUSTOMER_INTELLIGENCE_LIFECYCLE_STATE_EXPIRED - console.v1.CustomerIntelligenceProducerKind: - type: string - title: CustomerIntelligenceProducerKind - enum: - - CUSTOMER_INTELLIGENCE_PRODUCER_KIND_UNSPECIFIED - - CUSTOMER_INTELLIGENCE_PRODUCER_KIND_PLATFORM_DETERMINISTIC_FEEDBACK - - CUSTOMER_INTELLIGENCE_PRODUCER_KIND_CEREBRO - - CUSTOMER_INTELLIGENCE_PRODUCER_KIND_STAFF_REVIEW - - CUSTOMER_INTELLIGENCE_PRODUCER_KIND_CUSTOMER_CONFIRMATION - - CUSTOMER_INTELLIGENCE_PRODUCER_KIND_OUTCOME_EVALUATOR - console.v1.CustomerIntelligenceReviewDecision: - type: string - title: CustomerIntelligenceReviewDecision - enum: - - CUSTOMER_INTELLIGENCE_REVIEW_DECISION_UNSPECIFIED - - CUSTOMER_INTELLIGENCE_REVIEW_DECISION_REQUEST_CONFIRMATION - - CUSTOMER_INTELLIGENCE_REVIEW_DECISION_REQUEST_EVIDENCE - - CUSTOMER_INTELLIGENCE_REVIEW_DECISION_CHALLENGE - - CUSTOMER_INTELLIGENCE_REVIEW_DECISION_DISPUTE - - CUSTOMER_INTELLIGENCE_REVIEW_DECISION_EXPIRE - - CUSTOMER_INTELLIGENCE_REVIEW_DECISION_SUPERSEDE - - CUSTOMER_INTELLIGENCE_REVIEW_DECISION_PROPOSE_ACTION - console.v1.CustomerIntelligenceSubjectKind: - type: string - title: CustomerIntelligenceSubjectKind - enum: - - CUSTOMER_INTELLIGENCE_SUBJECT_KIND_UNSPECIFIED - - CUSTOMER_INTELLIGENCE_SUBJECT_KIND_INTERACTION - - CUSTOMER_INTELLIGENCE_SUBJECT_KIND_WORKSPACE - - CUSTOMER_INTELLIGENCE_SUBJECT_KIND_PRODUCT_AREA - - CUSTOMER_INTELLIGENCE_SUBJECT_KIND_COHORT - console.v1.DexAutonomyMode: - type: string - title: DexAutonomyMode - enum: - - DEX_AUTONOMY_MODE_UNSPECIFIED - - DEX_AUTONOMY_MODE_SUGGEST_ONLY - - DEX_AUTONOMY_MODE_ASK_BEFORE_CHANGES - - DEX_AUTONOMY_MODE_ACT_WITHIN_POLICY - console.v1.DexComputerCorrectionLabel: - type: string - title: DexComputerCorrectionLabel - enum: - - DEX_COMPUTER_CORRECTION_LABEL_UNSPECIFIED - - DEX_COMPUTER_CORRECTION_LABEL_WRONG_TARGET - - DEX_COMPUTER_CORRECTION_LABEL_WRONG_ACTION - - DEX_COMPUTER_CORRECTION_LABEL_MISSING_OBSERVATION - - DEX_COMPUTER_CORRECTION_LABEL_EFFECT_AMBIGUOUS - - DEX_COMPUTER_CORRECTION_LABEL_UNSAFE_BOUNDARY - - DEX_COMPUTER_CORRECTION_LABEL_HANDOFF_CONFLICT - - DEX_COMPUTER_CORRECTION_LABEL_OTHER - console.v1.DexExternalActionMode: - type: string - title: DexExternalActionMode - enum: - - DEX_EXTERNAL_ACTION_MODE_UNSPECIFIED - - DEX_EXTERNAL_ACTION_MODE_ALWAYS_ASK - - DEX_EXTERNAL_ACTION_MODE_POLICY_BASED - - DEX_EXTERNAL_ACTION_MODE_DISABLED - console.v1.DexSkillCatalogExposure: - type: string - title: DexSkillCatalogExposure - enum: - - DEX_SKILL_CATALOG_EXPOSURE_UNSPECIFIED - - DEX_SKILL_CATALOG_EXPOSURE_INTERNAL - - DEX_SKILL_CATALOG_EXPOSURE_INSTALLABLE - console.v1.DexSkillFixtureKind: - type: string - title: DexSkillFixtureKind - enum: - - DEX_SKILL_FIXTURE_KIND_UNSPECIFIED - - DEX_SKILL_FIXTURE_KIND_HAPPY - - DEX_SKILL_FIXTURE_KIND_EDGE - - DEX_SKILL_FIXTURE_KIND_DENIED_UNAVAILABLE - console.v1.DexSkillLifecycleState: - type: string - title: DexSkillLifecycleState - enum: - - DEX_SKILL_LIFECYCLE_STATE_UNSPECIFIED - - DEX_SKILL_LIFECYCLE_STATE_READY - - DEX_SKILL_LIFECYCLE_STATE_MISSING_TOOL - - DEX_SKILL_LIFECYCLE_STATE_NEEDS_REVIEW - - DEX_SKILL_LIFECYCLE_STATE_DISABLED - - DEX_SKILL_LIFECYCLE_STATE_REVOKED - console.v1.DexSkillPackageFileKind: - type: string - title: DexSkillPackageFileKind - enum: - - DEX_SKILL_PACKAGE_FILE_KIND_UNSPECIFIED - - DEX_SKILL_PACKAGE_FILE_KIND_INSTRUCTIONS - - DEX_SKILL_PACKAGE_FILE_KIND_SCRIPT - - DEX_SKILL_PACKAGE_FILE_KIND_REFERENCE - - DEX_SKILL_PACKAGE_FILE_KIND_EXAMPLE - - DEX_SKILL_PACKAGE_FILE_KIND_ASSET - - DEX_SKILL_PACKAGE_FILE_KIND_TEMPLATE - - DEX_SKILL_PACKAGE_FILE_KIND_LICENSE - - DEX_SKILL_PACKAGE_FILE_KIND_OTHER - console.v1.DexSkillRuntimeReadiness: - type: string - title: DexSkillRuntimeReadiness - enum: - - DEX_SKILL_RUNTIME_READINESS_UNSPECIFIED - - DEX_SKILL_RUNTIME_READINESS_NOT_REQUIRED - - DEX_SKILL_RUNTIME_READINESS_PROBE_REQUIRED - - DEX_SKILL_RUNTIME_READINESS_READY - - DEX_SKILL_RUNTIME_READINESS_MISSING_TOOL - - DEX_SKILL_RUNTIME_READINESS_UNAVAILABLE - console.v1.GuardrailAction: - type: string - title: GuardrailAction - enum: - - GUARDRAIL_ACTION_UNSPECIFIED - - GUARDRAIL_ACTION_BLOCK - - GUARDRAIL_ACTION_REDACT - - GUARDRAIL_ACTION_FLAG - description: |- - GuardrailAction is what a matched rule does to the turn. BLOCK fails the turn - closed, REDACT masks the matched span, FLAG records the match only. - console.v1.GuardrailDetectorKind: - type: string - title: GuardrailDetectorKind - enum: - - GUARDRAIL_DETECTOR_KIND_UNSPECIFIED - - GUARDRAIL_DETECTOR_KIND_BUILTIN_EMAIL - - GUARDRAIL_DETECTOR_KIND_BUILTIN_CREDIT_CARD - - GUARDRAIL_DETECTOR_KIND_BUILTIN_SECRET - - GUARDRAIL_DETECTOR_KIND_CUSTOM_REGEX - description: |- - GuardrailDetectorKind selects the deterministic detector a rule runs over Dex - model output. Built-in detectors need no pattern; CUSTOM_REGEX carries a - workspace-authored deny pattern in `pattern`. - console.v1.ManagedInferenceBlocker: - type: string - title: ManagedInferenceBlocker - enum: - - MANAGED_INFERENCE_BLOCKER_UNSPECIFIED - - MANAGED_INFERENCE_BLOCKER_ENROLLMENT_REQUIRED - - MANAGED_INFERENCE_BLOCKER_ENROLLMENT_SUSPENDED - - MANAGED_INFERENCE_BLOCKER_GATEWAY_SYNC_PENDING - - MANAGED_INFERENCE_BLOCKER_FUNDING_REQUIRED - - MANAGED_INFERENCE_BLOCKER_FUNDING_SUSPENDED - - MANAGED_INFERENCE_BLOCKER_FUNDING_UNAVAILABLE - - MANAGED_INFERENCE_BLOCKER_ROUTE_UNAVAILABLE - - MANAGED_INFERENCE_BLOCKER_ENROLLMENT_UNAVAILABLE - - MANAGED_INFERENCE_BLOCKER_BUDGET_LIMIT_REACHED - - MANAGED_INFERENCE_BLOCKER_POLICY_UNAVAILABLE - console.v1.ManagedInferenceNextAction: - type: string - title: ManagedInferenceNextAction - enum: - - MANAGED_INFERENCE_NEXT_ACTION_UNSPECIFIED - - MANAGED_INFERENCE_NEXT_ACTION_CONTACT_ADMINISTRATOR - - MANAGED_INFERENCE_NEXT_ACTION_VIEW_FUNDING - - MANAGED_INFERENCE_NEXT_ACTION_RETRY - console.v1.ManagedInferenceReadinessStatus: - type: string - title: ManagedInferenceReadinessStatus - enum: - - MANAGED_INFERENCE_READINESS_STATUS_UNSPECIFIED - - MANAGED_INFERENCE_READINESS_STATUS_READY - - MANAGED_INFERENCE_READINESS_STATUS_ACTIVATION_REQUIRED - - MANAGED_INFERENCE_READINESS_STATUS_FUNDING_REQUIRED - - MANAGED_INFERENCE_READINESS_STATUS_LIMIT_REACHED - - MANAGED_INFERENCE_READINESS_STATUS_ACCESS_SUSPENDED - - MANAGED_INFERENCE_READINESS_STATUS_TEMPORARILY_UNAVAILABLE - description: Shared prerequisite vocabulary consumed by Grid, Deixic UI and Deixic Code. - console.v1.ManagedProviderAccessState: - type: string - title: ManagedProviderAccessState - enum: - - MANAGED_PROVIDER_ACCESS_STATE_UNSPECIFIED - - MANAGED_PROVIDER_ACCESS_STATE_ACTIVE - - MANAGED_PROVIDER_ACCESS_STATE_SUSPENDED - - MANAGED_PROVIDER_ACCESS_STATE_REVOKED - - MANAGED_PROVIDER_ACCESS_STATE_EXPIRED - description: |- - ManagedProviderAccessGrant is the durable, staff-owned entitlement that lets - an organization resolve the platform-managed provider fallback after a BYOK - miss. Absent or disabled rows are default-deny. - console.v1.OperatingAnswerProvenance: - type: string - title: OperatingAnswerProvenance - enum: - - OPERATING_ANSWER_PROVENANCE_UNSPECIFIED - - OPERATING_ANSWER_PROVENANCE_MODEL - - OPERATING_ANSWER_PROVENANCE_REVIEWED_MODEL - - OPERATING_ANSWER_PROVENANCE_REPAIR_MODEL - - OPERATING_ANSWER_PROVENANCE_GUARDRAIL - - OPERATING_ANSWER_PROVENANCE_RECEIPT_SUMMARY - - OPERATING_ANSWER_PROVENANCE_RUNNER_FAILURE - - OPERATING_ANSWER_PROVENANCE_SUPERSEDED_TURN - - OPERATING_ANSWER_PROVENANCE_HOSTED_FRONT_FINAL - - OPERATING_ANSWER_PROVENANCE_HOSTED_FRONT_PRELIMINARY - console.v1.OperatingAttachmentProcessingState: - type: string - title: OperatingAttachmentProcessingState - enum: - - OPERATING_ATTACHMENT_PROCESSING_STATE_UNSPECIFIED - - OPERATING_ATTACHMENT_PROCESSING_STATE_UPLOADING - - OPERATING_ATTACHMENT_PROCESSING_STATE_PROCESSING - - OPERATING_ATTACHMENT_PROCESSING_STATE_READY - - OPERATING_ATTACHMENT_PROCESSING_STATE_FAILED - console.v1.OperatingAttachmentScope: - type: string - title: OperatingAttachmentScope - enum: - - OPERATING_ATTACHMENT_SCOPE_UNSPECIFIED - - OPERATING_ATTACHMENT_SCOPE_CONVERSATION - - OPERATING_ATTACHMENT_SCOPE_WORKSPACE - console.v1.OperatingCorrectionCategory: - type: string - title: OperatingCorrectionCategory - enum: - - OPERATING_CORRECTION_CATEGORY_UNSPECIFIED - - OPERATING_CORRECTION_CATEGORY_WRONG_TOPIC - - OPERATING_CORRECTION_CATEGORY_NOT_DONE - - OPERATING_CORRECTION_CATEGORY_INCORRECT_FACT - - OPERATING_CORRECTION_CATEGORY_UNSAFE_ACTION - - OPERATING_CORRECTION_CATEGORY_OTHER - console.v1.OperatingCorrectionReviewState: - type: string - title: OperatingCorrectionReviewState - enum: - - OPERATING_CORRECTION_REVIEW_STATE_UNSPECIFIED - - OPERATING_CORRECTION_REVIEW_STATE_PENDING_REVIEW - - OPERATING_CORRECTION_REVIEW_STATE_APPROVED - - OPERATING_CORRECTION_REVIEW_STATE_REJECTED - - OPERATING_CORRECTION_REVIEW_STATE_INELIGIBLE - console.v1.OperatingExecutionPlacement: - type: string - title: OperatingExecutionPlacement - enum: - - OPERATING_EXECUTION_PLACEMENT_UNSPECIFIED - - OPERATING_EXECUTION_PLACEMENT_INLINE_TURN - - OPERATING_EXECUTION_PLACEMENT_COMPUTER_MISSION - description: |- - Server-owned Auto decision pinned to an accepted task, never a channel preference. - Where an accepted Auto task executes. The classifier already picks a model - from the task's purpose; this records the execution environment that same - decision implies, so placement is durable, replayable, and attributable to - the policy version that chose it rather than re-derived at each stage. - console.v1.OperatingExecutionRuntime: - type: string - title: OperatingExecutionRuntime - enum: - - OPERATING_EXECUTION_RUNTIME_UNSPECIFIED - - OPERATING_EXECUTION_RUNTIME_MAESTRO - console.v1.OperatingFeedbackClassificationSource: - type: string - title: OperatingFeedbackClassificationSource - enum: - - OPERATING_FEEDBACK_CLASSIFICATION_SOURCE_UNSPECIFIED - - OPERATING_FEEDBACK_CLASSIFICATION_SOURCE_USER - - OPERATING_FEEDBACK_CLASSIFICATION_SOURCE_AGENT_SUGGESTED_USER_CONFIRMED - console.v1.OperatingFeedbackLifecycleState: - type: string - title: OperatingFeedbackLifecycleState - enum: - - OPERATING_FEEDBACK_LIFECYCLE_STATE_UNSPECIFIED - - OPERATING_FEEDBACK_LIFECYCLE_STATE_ACTIVE - - OPERATING_FEEDBACK_LIFECYCLE_STATE_SUPERSEDED - - OPERATING_FEEDBACK_LIFECYCLE_STATE_RETRACTED - console.v1.OperatingFeedbackReason: - type: string - title: OperatingFeedbackReason - enum: - - OPERATING_FEEDBACK_REASON_UNSPECIFIED - - OPERATING_FEEDBACK_REASON_HELPFUL - - OPERATING_FEEDBACK_REASON_ACCURATE - - OPERATING_FEEDBACK_REASON_CLEAR - - OPERATING_FEEDBACK_REASON_CORRECT_ACTION - - OPERATING_FEEDBACK_REASON_MISSED_REQUEST - - OPERATING_FEEDBACK_REASON_INCORRECT - - OPERATING_FEEDBACK_REASON_INCOMPLETE - - OPERATING_FEEDBACK_REASON_UNCLEAR - - OPERATING_FEEDBACK_REASON_MISSING_EVIDENCE - - OPERATING_FEEDBACK_REASON_UNSAFE - - OPERATING_FEEDBACK_REASON_OTHER - - OPERATING_FEEDBACK_REASON_COMPLETE - - OPERATING_FEEDBACK_REASON_IGNORED_INSTRUCTIONS - - OPERATING_FEEDBACK_REASON_TOOL_FAILED - - OPERATING_FEEDBACK_REASON_TOO_VERBOSE - console.v1.OperatingFeedbackRemediationAction: - type: string - title: OperatingFeedbackRemediationAction - enum: - - OPERATING_FEEDBACK_REMEDIATION_ACTION_UNSPECIFIED - - OPERATING_FEEDBACK_REMEDIATION_ACTION_NONE - - OPERATING_FEEDBACK_REMEDIATION_ACTION_VERIFY - - OPERATING_FEEDBACK_REMEDIATION_ACTION_RETRY - console.v1.OperatingFeedbackRemediationOutcome: - type: string - title: OperatingFeedbackRemediationOutcome - enum: - - OPERATING_FEEDBACK_REMEDIATION_OUTCOME_UNSPECIFIED - - OPERATING_FEEDBACK_REMEDIATION_OUTCOME_UNCONFIRMED - - OPERATING_FEEDBACK_REMEDIATION_OUTCOME_ACCEPTED - - OPERATING_FEEDBACK_REMEDIATION_OUTCOME_REJECTED - console.v1.OperatingFeedbackSentiment: - type: string - title: OperatingFeedbackSentiment - enum: - - OPERATING_FEEDBACK_SENTIMENT_UNSPECIFIED - - OPERATING_FEEDBACK_SENTIMENT_POSITIVE - - OPERATING_FEEDBACK_SENTIMENT_NEGATIVE - console.v1.OperatingHomepageSuggestionFeedbackAction: - type: string - title: OperatingHomepageSuggestionFeedbackAction - enum: - - OPERATING_HOMEPAGE_SUGGESTION_FEEDBACK_ACTION_UNSPECIFIED - - OPERATING_HOMEPAGE_SUGGESTION_FEEDBACK_ACTION_NOT_USEFUL - - OPERATING_HOMEPAGE_SUGGESTION_FEEDBACK_ACTION_FORGET - console.v1.OperatingJobOrigin: - type: string - title: OperatingJobOrigin - enum: - - OPERATING_JOB_ORIGIN_UNSPECIFIED - - OPERATING_JOB_ORIGIN_CHAT - - OPERATING_JOB_ORIGIN_SCHEDULE - - OPERATING_JOB_ORIGIN_EVENT - - OPERATING_JOB_ORIGIN_API - - OPERATING_JOB_ORIGIN_SKILL - - OPERATING_JOB_ORIGIN_COMPUTER - console.v1.OperatingJobProofState: - type: string - title: OperatingJobProofState - enum: - - OPERATING_JOB_PROOF_STATE_UNSPECIFIED - - OPERATING_JOB_PROOF_STATE_UNAVAILABLE - - OPERATING_JOB_PROOF_STATE_PARTIAL - - OPERATING_JOB_PROOF_STATE_COMPLETE - description: |- - OperatingJobProofState reports only the completeness of authoritative - record references. It never upgrades a job lifecycle or claims that an - unresolved owner record succeeded. - console.v1.OperatingJobState: - type: string - title: OperatingJobState - enum: - - OPERATING_JOB_STATE_UNSPECIFIED - - OPERATING_JOB_STATE_PROPOSED - - OPERATING_JOB_STATE_QUEUED - - OPERATING_JOB_STATE_RUNNING - - OPERATING_JOB_STATE_WAITING - - OPERATING_JOB_STATE_SUCCEEDED - - OPERATING_JOB_STATE_FAILED - - OPERATING_JOB_STATE_CANCELLED - description: |- - OperatingJobState is the customer lifecycle of one durable intended - outcome. Verification is deliberately separate: succeeded never implies - verified, and failed never means blocked. - console.v1.OperatingJobVerificationState: - type: string - title: OperatingJobVerificationState - enum: - - OPERATING_JOB_VERIFICATION_STATE_UNSPECIFIED - - OPERATING_JOB_VERIFICATION_STATE_NOT_VERIFIED - - OPERATING_JOB_VERIFICATION_STATE_PENDING - - OPERATING_JOB_VERIFICATION_STATE_VERIFIED - - OPERATING_JOB_VERIFICATION_STATE_FAILED - console.v1.OperatingSurfaceKind: - type: string - title: OperatingSurfaceKind - enum: - - OPERATING_SURFACE_KIND_UNSPECIFIED - - OPERATING_SURFACE_KIND_COMPOSER - - OPERATING_SURFACE_KIND_SLACK - - OPERATING_SURFACE_KIND_TEAMS - - OPERATING_SURFACE_KIND_WHATSAPP - - OPERATING_SURFACE_KIND_APPLE_MESSAGES - - OPERATING_SURFACE_KIND_EMAIL - console.v1.OperatingTaskEnvironmentStageKind: - type: string - title: OperatingTaskEnvironmentStageKind - enum: - - OPERATING_TASK_ENVIRONMENT_STAGE_KIND_UNSPECIFIED - - OPERATING_TASK_ENVIRONMENT_STAGE_KIND_SOURCE - - OPERATING_TASK_ENVIRONMENT_STAGE_KIND_PREPARATION - - OPERATING_TASK_ENVIRONMENT_STAGE_KIND_PROVISIONING - - OPERATING_TASK_ENVIRONMENT_STAGE_KIND_NETWORK - - OPERATING_TASK_ENVIRONMENT_STAGE_KIND_EXECUTION - - OPERATING_TASK_ENVIRONMENT_STAGE_KIND_RETAINED_STATE - console.v1.OperatingTaskEnvironmentStageState: - type: string - title: OperatingTaskEnvironmentStageState - enum: - - OPERATING_TASK_ENVIRONMENT_STAGE_STATE_UNSPECIFIED - - OPERATING_TASK_ENVIRONMENT_STAGE_STATE_NOT_REQUIRED - - OPERATING_TASK_ENVIRONMENT_STAGE_STATE_ABSENT - - OPERATING_TASK_ENVIRONMENT_STAGE_STATE_PENDING - - OPERATING_TASK_ENVIRONMENT_STAGE_STATE_READY - - OPERATING_TASK_ENVIRONMENT_STAGE_STATE_FAILED - - OPERATING_TASK_ENVIRONMENT_STAGE_STATE_RETAINED - - OPERATING_TASK_ENVIRONMENT_STAGE_STATE_UNKNOWN - console.v1.OperatingTaskKind: - type: string - title: OperatingTaskKind - enum: - - OPERATING_TASK_KIND_UNSPECIFIED - - OPERATING_TASK_KIND_CONVERSATION - - OPERATING_TASK_KIND_CODING_IMPLEMENTATION - description: |- - Explicit caller intent. This never grants execution or repository authority. - Unspecified preserves existing chat and replay clients. - console.v1.OperatingThreadArchiveFilter: - type: string - title: OperatingThreadArchiveFilter - enum: - - OPERATING_THREAD_ARCHIVE_FILTER_UNSPECIFIED - - OPERATING_THREAD_ARCHIVE_FILTER_ACTIVE_ONLY - - OPERATING_THREAD_ARCHIVE_FILTER_ARCHIVED_ONLY - - OPERATING_THREAD_ARCHIVE_FILTER_ALL - console.v1.OperatingThreadEventKind: - type: string - title: OperatingThreadEventKind - enum: - - OPERATING_THREAD_EVENT_KIND_UNSPECIFIED - - OPERATING_THREAD_EVENT_KIND_TURN_ACCEPTED - - OPERATING_THREAD_EVENT_KIND_TURN_STARTED - - OPERATING_THREAD_EVENT_KIND_PROGRESS - - OPERATING_THREAD_EVENT_KIND_APPROVAL_REQUIRED - - OPERATING_THREAD_EVENT_KIND_INPUT_REQUIRED - - OPERATING_THREAD_EVENT_KIND_ARTIFACT_RECORDED - - OPERATING_THREAD_EVENT_KIND_TURN_COMPLETED - - OPERATING_THREAD_EVENT_KIND_TURN_FAILED - - OPERATING_THREAD_EVENT_KIND_TURN_INTERRUPTED - - OPERATING_THREAD_EVENT_KIND_RUNTIME_REBOUND - - OPERATING_THREAD_EVENT_KIND_TOOL_PROPOSED - - OPERATING_THREAD_EVENT_KIND_TOOL_COMPLETED - - OPERATING_THREAD_EVENT_KIND_MEMORY_PROPOSED - - OPERATING_THREAD_EVENT_KIND_CLIENT_TOOL_REQUIRED - - OPERATING_THREAD_EVENT_KIND_EXTERNAL_RETRY_REQUIRED - console.v1.OperatingThreadExecutionState: - type: string - title: OperatingThreadExecutionState - enum: - - OPERATING_THREAD_EXECUTION_STATE_UNSPECIFIED - - OPERATING_THREAD_EXECUTION_STATE_PROVISIONING - - OPERATING_THREAD_EXECUTION_STATE_READY - - OPERATING_THREAD_EXECUTION_STATE_RUNNING - - OPERATING_THREAD_EXECUTION_STATE_WAITING - - OPERATING_THREAD_EXECUTION_STATE_DEGRADED - - OPERATING_THREAD_EXECUTION_STATE_STOPPED - console.v1.OperatingThreadRequestType: - type: string - title: OperatingThreadRequestType - enum: - - OPERATING_THREAD_REQUEST_TYPE_UNSPECIFIED - - OPERATING_THREAD_REQUEST_TYPE_APPROVAL - - OPERATING_THREAD_REQUEST_TYPE_USER_INPUT - - OPERATING_THREAD_REQUEST_TYPE_CLIENT_TOOL - - OPERATING_THREAD_REQUEST_TYPE_EXTERNAL_RETRY - console.v1.OperatingThreadResponseAction: - type: string - title: OperatingThreadResponseAction - enum: - - OPERATING_THREAD_RESPONSE_ACTION_UNSPECIFIED - - OPERATING_THREAD_RESPONSE_ACTION_APPROVE - - OPERATING_THREAD_RESPONSE_ACTION_DENY - - OPERATING_THREAD_RESPONSE_ACTION_ANSWER - - OPERATING_THREAD_RESPONSE_ACTION_RETRY - - OPERATING_THREAD_RESPONSE_ACTION_SKIP - - OPERATING_THREAD_RESPONSE_ACTION_ABORT - console.v1.OperatingThreadWaitingReason: - type: string - title: OperatingThreadWaitingReason - enum: - - OPERATING_THREAD_WAITING_REASON_UNSPECIFIED - - OPERATING_THREAD_WAITING_REASON_NONE - - OPERATING_THREAD_WAITING_REASON_APPROVAL - - OPERATING_THREAD_WAITING_REASON_USER_INPUT - - OPERATING_THREAD_WAITING_REASON_EXTERNAL_RETRY - - OPERATING_THREAD_WAITING_REASON_CLIENT_TOOL - console.v1.OperatingTurnAnswerKind: - type: string - title: OperatingTurnAnswerKind - enum: - - OPERATING_TURN_ANSWER_KIND_ANSWER_UNSPECIFIED - - OPERATING_TURN_ANSWER_KIND_NO_ANSWER - - OPERATING_TURN_ANSWER_KIND_DIRECT_ANSWER - - OPERATING_TURN_ANSWER_KIND_RECEIPT_ONLY - - OPERATING_TURN_ANSWER_KIND_WORK_STARTED - console.v1.OperatingTurnIntentKind: - type: string - title: OperatingTurnIntentKind - enum: - - OPERATING_TURN_INTENT_KIND_INTENT_UNSPECIFIED - - OPERATING_TURN_INTENT_KIND_UNKNOWN - - OPERATING_TURN_INTENT_KIND_OPERATIONAL - - OPERATING_TURN_INTENT_KIND_CAPABILITY_HELP - - OPERATING_TURN_INTENT_KIND_SETTINGS - - OPERATING_TURN_INTENT_KIND_APPROVAL - - OPERATING_TURN_INTENT_KIND_EVIDENCE - console.v1.OperatingTurnRouteKind: - type: string - title: OperatingTurnRouteKind - enum: - - OPERATING_TURN_ROUTE_KIND_ROUTE_UNSPECIFIED - - OPERATING_TURN_ROUTE_KIND_DIRECT_ANSWER - - OPERATING_TURN_ROUTE_KIND_GOVERNED_WORK - - OPERATING_TURN_ROUTE_KIND_BLOCKED - console.v1.OperatingTurnSafetyKind: - type: string - title: OperatingTurnSafetyKind - enum: - - OPERATING_TURN_SAFETY_KIND_SAFETY_UNSPECIFIED - - OPERATING_TURN_SAFETY_KIND_NOT_EVALUATED - - OPERATING_TURN_SAFETY_KIND_ALLOWED - - OPERATING_TURN_SAFETY_KIND_BLOCKED - console.v1.OperatingTurnState: - type: string - title: OperatingTurnState - enum: - - OPERATING_TURN_STATE_UNSPECIFIED - - OPERATING_TURN_STATE_ACCEPTED - - OPERATING_TURN_STATE_QUEUED - - OPERATING_TURN_STATE_RESPONDED - - OPERATING_TURN_STATE_FAILED - - OPERATING_TURN_STATE_RUNNING - - OPERATING_TURN_STATE_WAITING - - OPERATING_TURN_STATE_COMPLETED - - OPERATING_TURN_STATE_INTERRUPTED - console.v1.OperatingVerificationState: - type: string - title: OperatingVerificationState - enum: - - OPERATING_VERIFICATION_STATE_UNSPECIFIED - - OPERATING_VERIFICATION_STATE_NOT_REQUIRED - - OPERATING_VERIFICATION_STATE_PENDING - - OPERATING_VERIFICATION_STATE_VERIFIED - - OPERATING_VERIFICATION_STATE_FAILED - console.v1.PrivacySettingScope: - type: string - title: PrivacySettingScope - enum: - - PRIVACY_SETTING_SCOPE_UNSPECIFIED - - PRIVACY_SETTING_SCOPE_ORGANIZATION - - PRIVACY_SETTING_SCOPE_WORKSPACE - description: PrivacySettingScope selects which of the two rows a write targets. - console.v1.ProspectingDraftChannel: - type: string - title: ProspectingDraftChannel - enum: - - PROSPECTING_DRAFT_CHANNEL_UNSPECIFIED - - PROSPECTING_DRAFT_CHANNEL_EMAIL - description: |- - ProspectingDraftChannel is the channel a Radar outreach draft is written - for. Radar does not deliver; the channel is recorded for review only. - console.v1.ProspectingDraftReviewState: - type: string - title: ProspectingDraftReviewState - enum: - - PROSPECTING_DRAFT_REVIEW_STATE_UNSPECIFIED - - PROSPECTING_DRAFT_REVIEW_STATE_REVIEW_REQUIRED - - PROSPECTING_DRAFT_REVIEW_STATE_APPROVED - - PROSPECTING_DRAFT_REVIEW_STATE_REJECTED - description: ProspectingDraftReviewState is the durable review decision on a draft. - console.v1.ProspectingDraftTone: - type: string - title: ProspectingDraftTone - enum: - - PROSPECTING_DRAFT_TONE_UNSPECIFIED - - PROSPECTING_DRAFT_TONE_DIRECT - - PROSPECTING_DRAFT_TONE_WARM - - PROSPECTING_DRAFT_TONE_TECHNICAL - description: ProspectingDraftTone is the staff-selected register of the draft. - console.v1.ProspectingWatchProgramLifecycle: - type: string - title: ProspectingWatchProgramLifecycle - enum: - - PROSPECTING_WATCH_PROGRAM_LIFECYCLE_UNSPECIFIED - - PROSPECTING_WATCH_PROGRAM_LIFECYCLE_ACTIVE - - PROSPECTING_WATCH_PROGRAM_LIFECYCLE_PAUSED - - PROSPECTING_WATCH_PROGRAM_LIFECYCLE_ARCHIVED - description: |- - ProspectingWatchProgramLifecycle is the owner-authored lifecycle of a Radar - watch program. PAUSED is the close state; ACTIVE reopens it. - console.v1.ReceiptLifecycleState: - type: string - title: ReceiptLifecycleState - enum: - - RECEIPT_LIFECYCLE_STATE_UNSPECIFIED - - RECEIPT_LIFECYCLE_STATE_UNKNOWN - - RECEIPT_LIFECYCLE_STATE_PROPOSED - - RECEIPT_LIFECYCLE_STATE_QUEUED - - RECEIPT_LIFECYCLE_STATE_WAITING_APPROVAL - - RECEIPT_LIFECYCLE_STATE_BLOCKED - - RECEIPT_LIFECYCLE_STATE_NEEDS_INPUT - - RECEIPT_LIFECYCLE_STATE_UNAVAILABLE - - RECEIPT_LIFECYCLE_STATE_RUNNING - - RECEIPT_LIFECYCLE_STATE_SUCCEEDED - - RECEIPT_LIFECYCLE_STATE_VERIFIED - - RECEIPT_LIFECYCLE_STATE_DENIED - - RECEIPT_LIFECYCLE_STATE_CANCELLED - - RECEIPT_LIFECYCLE_STATE_FAILED - description: |- - ReceiptLifecycleState is the owner's single answer for where one receipt's - work stands. The owner resolves precedence across its typed lifecycle fields - so every client renders one state instead of re-deriving it from `status` and - payload evidence. UNSPECIFIED means the responding build did not state a - lifecycle; UNKNOWN means the owner holds lifecycle evidence it cannot name, - and clients must not present such work as finished. - console.v1.SkillAnalysisVerdict: - type: string - title: SkillAnalysisVerdict - enum: - - SKILL_ANALYSIS_VERDICT_UNSPECIFIED - - SKILL_ANALYSIS_VERDICT_PASS - - SKILL_ANALYSIS_VERDICT_NEEDS_REVIEW - - SKILL_ANALYSIS_VERDICT_BLOCKED - - SKILL_ANALYSIS_VERDICT_UNSCANNABLE - console.v1.StaffInferenceRoutingPurpose: - type: string - title: StaffInferenceRoutingPurpose - enum: - - STAFF_INFERENCE_ROUTING_PURPOSE_UNSPECIFIED - - STAFF_INFERENCE_ROUTING_PURPOSE_DEFAULT_CHAT - - STAFF_INFERENCE_ROUTING_PURPOSE_FAST_CHEAP - - STAFF_INFERENCE_ROUTING_PURPOSE_DEEP_REASONING - - STAFF_INFERENCE_ROUTING_PURPOSE_CODING - - STAFF_INFERENCE_ROUTING_PURPOSE_EVALUATION - description: |- - StaffInferenceRoutingPurpose identifies a bounded Dex workload class. The - server, not the browser, maps call sites to these purposes. - console.v1.StaffWorkspaceAccessState: - type: string - title: StaffWorkspaceAccessState - enum: - - STAFF_WORKSPACE_ACCESS_STATE_UNSPECIFIED - - STAFF_WORKSPACE_ACCESS_STATE_DIRECTORY_ONLY - - STAFF_WORKSPACE_ACCESS_STATE_ACTIVE_READ_ONLY - - STAFF_WORKSPACE_ACCESS_STATE_EXPIRED - - STAFF_WORKSPACE_ACCESS_STATE_GRANT_MISMATCH - - STAFF_WORKSPACE_ACCESS_STATE_UNAVAILABLE - console.v1.TenantPrivacyMode: - type: string - title: TenantPrivacyMode - enum: - - TENANT_PRIVACY_MODE_UNSPECIFIED - - TENANT_PRIVACY_MODE_STANDARD - - TENANT_PRIVACY_MODE_NO_TRAINING - - TENANT_PRIVACY_MODE_RESTRICTED - description: |- - TenantPrivacyMode is how much of a tenant's data this system may copy into - systems other than the store that owns it. It is the wire spelling of - platform_core_types::PrivacyMode. - console.v1.ThreadGatewayPermission: - type: string - title: ThreadGatewayPermission - enum: - - THREAD_GATEWAY_PERMISSION_UNSPECIFIED - - THREAD_GATEWAY_PERMISSION_SUBMIT - - THREAD_GATEWAY_PERMISSION_WATCH - - THREAD_GATEWAY_PERMISSION_INTERRUPT - console.v1.WorkspaceSettingsAvailabilityStatus: - type: string - title: WorkspaceSettingsAvailabilityStatus - enum: - - WORKSPACE_SETTINGS_AVAILABILITY_STATUS_UNSPECIFIED - - WORKSPACE_SETTINGS_AVAILABILITY_STATUS_ACTIVE - - WORKSPACE_SETTINGS_AVAILABILITY_STATUS_UNAVAILABLE - console.v1.WorkspaceSettingsBillingStatus: - type: string - title: WorkspaceSettingsBillingStatus - enum: - - WORKSPACE_SETTINGS_BILLING_STATUS_UNSPECIFIED - - WORKSPACE_SETTINGS_BILLING_STATUS_ACTIVE - - WORKSPACE_SETTINGS_BILLING_STATUS_TRIALING - - WORKSPACE_SETTINGS_BILLING_STATUS_PAST_DUE - - WORKSPACE_SETTINGS_BILLING_STATUS_CANCELED - - WORKSPACE_SETTINGS_BILLING_STATUS_UNAVAILABLE - - WORKSPACE_SETTINGS_BILLING_STATUS_PAUSED - console.v1.WorkspaceSettingsIdentityProviderStatus: - type: string - title: WorkspaceSettingsIdentityProviderStatus - enum: - - WORKSPACE_SETTINGS_IDENTITY_PROVIDER_STATUS_UNSPECIFIED - - WORKSPACE_SETTINGS_IDENTITY_PROVIDER_STATUS_CONFIGURED - - WORKSPACE_SETTINGS_IDENTITY_PROVIDER_STATUS_CONNECTED - - WORKSPACE_SETTINGS_IDENTITY_PROVIDER_STATUS_DEGRADED - - WORKSPACE_SETTINGS_IDENTITY_PROVIDER_STATUS_DISABLED - - WORKSPACE_SETTINGS_IDENTITY_PROVIDER_STATUS_UNAVAILABLE - console.v1.WorkspaceSettingsIntegrationStatus: - type: string - title: WorkspaceSettingsIntegrationStatus - enum: - - WORKSPACE_SETTINGS_INTEGRATION_STATUS_UNSPECIFIED - - WORKSPACE_SETTINGS_INTEGRATION_STATUS_CONFIGURED - - WORKSPACE_SETTINGS_INTEGRATION_STATUS_CONNECTED - - WORKSPACE_SETTINGS_INTEGRATION_STATUS_HEALTHY - - WORKSPACE_SETTINGS_INTEGRATION_STATUS_DEGRADED - - WORKSPACE_SETTINGS_INTEGRATION_STATUS_DISABLED - - WORKSPACE_SETTINGS_INTEGRATION_STATUS_UNAVAILABLE - console.v1.WorkspaceSettingsMemberStatus: - type: string - title: WorkspaceSettingsMemberStatus - enum: - - WORKSPACE_SETTINGS_MEMBER_STATUS_UNSPECIFIED - - WORKSPACE_SETTINGS_MEMBER_STATUS_ACTIVE - - WORKSPACE_SETTINGS_MEMBER_STATUS_INVITED - - WORKSPACE_SETTINGS_MEMBER_STATUS_SUSPENDED - console.v1.WorkspaceSettingsOwnerServiceStatus: - type: string - title: WorkspaceSettingsOwnerServiceStatus - enum: - - WORKSPACE_SETTINGS_OWNER_SERVICE_STATUS_UNSPECIFIED - - WORKSPACE_SETTINGS_OWNER_SERVICE_STATUS_ACTIVE - - WORKSPACE_SETTINGS_OWNER_SERVICE_STATUS_PROJECTION - - WORKSPACE_SETTINGS_OWNER_SERVICE_STATUS_PARTIAL - - WORKSPACE_SETTINGS_OWNER_SERVICE_STATUS_LOCAL - - WORKSPACE_SETTINGS_OWNER_SERVICE_STATUS_UNAVAILABLE - console.v1.WorkspaceSettingsRole: - type: string - title: WorkspaceSettingsRole - enum: - - WORKSPACE_SETTINGS_ROLE_UNSPECIFIED - - WORKSPACE_SETTINGS_ROLE_VIEWER - - WORKSPACE_SETTINGS_ROLE_DEVELOPER - - WORKSPACE_SETTINGS_ROLE_BILLING_ADMIN - - WORKSPACE_SETTINGS_ROLE_ADMIN - - WORKSPACE_SETTINGS_ROLE_OWNER - console.v1.WorkspaceSettingsSource: - type: string - title: WorkspaceSettingsSource - enum: - - WORKSPACE_SETTINGS_SOURCE_UNSPECIFIED - - WORKSPACE_SETTINGS_SOURCE_CONSOLE_SETTINGS - - WORKSPACE_SETTINGS_SOURCE_CONSOLE_INVITATION - - WORKSPACE_SETTINGS_SOURCE_AUTHENTICATED_PRINCIPAL - - WORKSPACE_SETTINGS_SOURCE_MANUAL - - WORKSPACE_SETTINGS_SOURCE_SCIM - - WORKSPACE_SETTINGS_SOURCE_SAML - - WORKSPACE_SETTINGS_SOURCE_OAUTH - - WORKSPACE_SETTINGS_SOURCE_SYSTEM - - WORKSPACE_SETTINGS_SOURCE_CONSOLE_SNAPSHOT - console.v1.WorkspaceSpendBeatCadence: - type: string - title: WorkspaceSpendBeatCadence - enum: - - WORKSPACE_SPEND_BEAT_CADENCE_UNSPECIFIED - - WORKSPACE_SPEND_BEAT_CADENCE_DAILY - - WORKSPACE_SPEND_BEAT_CADENCE_WEEKLY - google.protobuf.NullValue: - type: string - title: NullValue - enum: - - NULL_VALUE - description: |- - `NullValue` is a singleton enumeration to represent the null value for the - `Value` type union. - - The JSON representation for `NullValue` is JSON `null`. - memory.v1.MemoryReviewStatus: - type: string - title: MemoryReviewStatus - enum: - - MEMORY_REVIEW_STATUS_UNSPECIFIED - - MEMORY_REVIEW_STATUS_APPROVED - - MEMORY_REVIEW_STATUS_PROPOSED - - MEMORY_REVIEW_STATUS_REJECTED - description: |- - MemoryReviewStatus controls whether a memory is active for recall or still - reviewable as a proposal. - memory.v1.Scope: - type: string - title: Scope - enum: - - SCOPE_UNSPECIFIED - - SCOPE_USER - - SCOPE_TEAM - - SCOPE_ORGANIZATION - - SCOPE_AGENT - - SCOPE_PROJECT - description: Scope controls memory visibility. - orbcontrol.v1.OrbCommandKind: - type: string - title: OrbCommandKind - enum: - - ORB_COMMAND_KIND_UNSPECIFIED - - ORB_COMMAND_KIND_WAKE - - ORB_COMMAND_KIND_STOP - description: OrbCommandKind is the first supported Platform-owned lifecycle command set. - orbcontrol.v1.OrbObservedLifecycle: - type: string - title: OrbObservedLifecycle - enum: - - ORB_OBSERVED_LIFECYCLE_UNSPECIFIED - - ORB_OBSERVED_LIFECYCLE_SLEEPING - - ORB_OBSERVED_LIFECYCLE_WAKING - - ORB_OBSERVED_LIFECYCLE_READY - - ORB_OBSERVED_LIFECYCLE_WORKING - - ORB_OBSERVED_LIFECYCLE_WAITING_FOR_YOU - - ORB_OBSERVED_LIFECYCLE_RECOVERING - - ORB_OBSERVED_LIFECYCLE_OFFLINE - description: OrbObservedLifecycle is the runtime owner's customer-safe lifecycle state. - platform.v1.RecordKind: - type: string - title: RecordKind - enum: - - RECORD_KIND_UNSPECIFIED - - RECORD_KIND_RUN - - RECORD_KIND_MODEL_RUN - - RECORD_KIND_TOOL_EXECUTION - - RECORD_KIND_POLICY_DECISION - - RECORD_KIND_APPROVAL - - RECORD_KIND_CREDENTIAL - - RECORD_KIND_CONNECTOR - - RECORD_KIND_CONNECTOR_SESSION - - RECORD_KIND_ARTIFACT - - RECORD_KIND_USAGE - - RECORD_KIND_RECEIPT - - RECORD_KIND_EVIDENCE - - RECORD_KIND_EVAL_RUN - description: |- - RecordKind identifies an authoritative operational record without copying - that record into a read model. The enclosing request supplies exact tenant - authority; the kind selects the owner resolver for record_id. - traces.v1.TraceAnnotationKind: - type: string - title: TraceAnnotationKind - enum: - - TRACE_ANNOTATION_KIND_UNSPECIFIED - - TRACE_ANNOTATION_KIND_NOTE - - TRACE_ANNOTATION_KIND_ISSUE - - TRACE_ANNOTATION_KIND_GOOD - traces.v1.TraceAnnotationStatus: - type: string - title: TraceAnnotationStatus - enum: - - TRACE_ANNOTATION_STATUS_UNSPECIFIED - - TRACE_ANNOTATION_STATUS_ACTIVE - - TRACE_ANNOTATION_STATUS_RESOLVED - - TRACE_ANNOTATION_STATUS_DISMISSED - - TRACE_ANNOTATION_STATUS_ARCHIVED - agents.v1.Agent: - type: object - properties: - id: - type: string - title: id - workspaceId: - type: string - title: workspace_id - name: - type: string - title: name - description: - type: string - title: description - agentType: - type: string - title: agent_type - description: |- - agent_type aligns with identity/v1 IntrospectResponse.agent_type and - IssueAgentTokenRequest.agent_type. Examples: "sdr", "support", "coding", - "ops", "research". - capabilities: - type: array - items: - type: string - title: capabilities - description: |- - capabilities aligns with identity/v1 IntrospectResponse.capabilities and - IssueAgentTokenRequest.capabilities. Used by capability-based delegation - routing. Examples: "hubspot-write", "email-send", "code-review". - surfaces: - type: array - items: - type: string - title: surfaces - description: |- - surfaces this agent can operate on. Aligns with the surface field in - meter/v1, objectives/v1, approvals/v1. Examples: "ensemble", "chat", - "maestro", "conductor", "slack". - status: - title: status - $ref: '#/components/schemas/agents.v1.AgentStatus' - activeConfigVersion: - type: integer - title: active_config_version - format: int32 - ownerId: - type: string - title: owner_id - lastHeartbeatAt: - title: last_heartbeat_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - surfaceTypes: - type: array - items: - $ref: '#/components/schemas/common.v1.Surface' - title: surface_types - a2a: - title: a2a - description: |- - a2a is the Platform-owned discovery projection for spec-native A2A peers. - Remote agents use it to discover where to fetch the Agent Card, which - transport/profile is supported, and which skills can be delegated to this - agent or its child/subagent lanes. - $ref: '#/components/schemas/agents.v1.AgentA2APeerProjection' - capacity: - title: capacity - description: |- - capacity is the registry-owned load projection used by fleet-scale - delegation discovery and operator read models. - $ref: '#/components/schemas/agents.v1.AgentCapacity' - title: Agent - additionalProperties: false - description: |- - Agent is the canonical agent definition record. - The id field is the value stored in every agent_id / agent string field - across the platform: meter/v1 RecordUsageRequest.agent_id, - objectives/v1 Objective.agent_id, approvals/v1 ApprovalRequest.agent_id, - governance/v1 EvaluateActionRequest.agent_id, memory/v1 Memory.agent, - and events/v1 Change.actor_id when actor_type is "agent". - agents.v1.AgentA2APeerProjection: - type: object - properties: - publicEndpointUrl: - type: string - title: public_endpoint_url - internalEndpointUrl: - type: string - title: internal_endpoint_url - agentCardUrl: - type: string - title: agent_card_url - protocolBinding: - type: string - title: protocol_binding - protocolVersion: - type: string - title: protocol_version - supportedExtensions: - type: array - items: - type: string - title: supported_extensions - skills: - type: array - items: - $ref: '#/components/schemas/agents.v1.AgentA2ASkill' - title: skills - securitySchemes: - type: array - items: - type: string - title: security_schemes - agentCardObservedAt: - title: agent_card_observed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - agentCardEtag: - type: string - title: agent_card_etag - agentCardHash: - type: string - title: agent_card_hash - pushNotifications: - type: boolean - title: push_notifications - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: AgentA2APeerProjection - additionalProperties: false - agents.v1.AgentA2APeerProjection.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - agents.v1.AgentA2ASkill: - type: object - properties: - id: - type: string - title: id - name: - type: string - title: name - description: - type: string - title: description - tags: - type: array - items: - type: string - title: tags - inputModes: - type: array - items: - type: string - title: input_modes - outputModes: - type: array - items: - type: string - title: output_modes - requiredContextGrants: - type: array - items: - type: string - title: required_context_grants - approvalPolicyRef: - type: string - title: approval_policy_ref - maxAutonomy: - type: string - title: max_autonomy - requiredArtifactKinds: - type: array - items: - type: string - title: required_artifact_kinds - optionalArtifactKinds: - type: array - items: - type: string - title: optional_artifact_kinds - allowedTaskClasses: - type: array - items: - type: string - title: allowed_task_classes - deniedTaskClasses: - type: array - items: - type: string - title: denied_task_classes - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: AgentA2ASkill - additionalProperties: false - agents.v1.AgentA2ASkill.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - agents.v1.AgentCapacity: - type: object - properties: - current: - type: integer - title: current - format: int32 - max: - type: integer - title: max - format: int32 - remaining: - type: integer - title: remaining - format: int32 - reservedDelegationCount: - type: integer - title: reserved_delegation_count - format: int32 - title: AgentCapacity - additionalProperties: false - agents.v1.AgentConfig: - type: object - properties: - version: - type: integer - title: version - format: int32 - agentId: - type: string - title: agent_id - skillIds: - type: array - items: - type: string - title: skill_ids - description: |- - skill_ids reference skills/v1 Skill.id — the reusable capabilities - this agent has loaded. - promptBindings: - type: object - title: prompt_bindings - additionalProperties: - type: string - title: value - description: |- - prompt_bindings maps prompt name to label (e.g., "sdr-outreach" -> "production"). - Aligns with prompts/v1 ResolveRequest.name and ResolveRequest.label. - modelPreferences: - type: object - title: model_preferences - additionalProperties: - type: string - title: value - description: |- - model_preferences maps surface to preferred model identifier - (e.g., "ensemble" -> "claude-opus-4.6"). Aligns with meter/v1 - RecordUsageRequest.model and keys/v1 ResolveProviderRefRequest.provider. - integrationIds: - type: array - items: - type: string - title: integration_ids - description: |- - integration_ids reference connectors/v1 Connection.id — the external - system connections this agent is authorized to use. - entityTypeScopes: - type: array - items: - type: string - title: entity_type_scopes - description: |- - entity_type_scopes restrict which entities/v1 EntityType values this - agent can operate on. Empty means unrestricted. - maxConcurrentObjectives: - type: integer - title: max_concurrent_objectives - format: int32 - description: |- - max_concurrent_objectives caps the number of objectives/v1 Objective - records this agent can hold in RUNNING or BLOCKED state simultaneously. - costBudgetUsd: - type: number - title: cost_budget_usd - format: double - description: |- - cost_budget_usd is the per-period spend ceiling enforced against - meter/v1 usage records for this agent. - notificationChannel: - type: string - title: notification_channel - description: |- - notification_channel specifies the preferred notifications/v1 - DeliveryChannel for this agent's escalations. Stored as string to - avoid cross-package import (e.g., "DELIVERY_CHANNEL_SLACK"). - parameters: - title: parameters - description: parameters holds arbitrary agent-specific tuning knobs. - $ref: '#/components/schemas/google.protobuf.Struct' - author: - type: string - title: author - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - entityTypeScopeEnums: - type: array - items: - $ref: '#/components/schemas/common.v1.EntityType' - title: entity_type_scope_enums - notificationChannelEnum: - title: notification_channel_enum - $ref: '#/components/schemas/common.v1.DeliveryChannel' - teammateProfile: - title: teammate_profile - $ref: '#/components/schemas/agents.v1.DigitalTeammateProfile' - connectorRequirements: - type: array - items: - $ref: '#/components/schemas/agents.v1.ConnectorRequirement' - title: connector_requirements - description: Portable provider needs. Connection IDs remain workspace-local bindings. - title: AgentConfig - additionalProperties: false - description: |- - AgentConfig is an immutable snapshot of everything that shapes an agent's - behavior. Promotion and rollback are both config version reassignments — - the same pattern as prompts/v1 Label. - agents.v1.AgentConfig.ModelPreferencesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: ModelPreferencesEntry - additionalProperties: false - agents.v1.AgentConfig.PromptBindingsEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: PromptBindingsEntry - additionalProperties: false - agents.v1.AutonomyPolicy: - type: object - properties: - rules: - type: array - items: - $ref: '#/components/schemas/agents.v1.AutonomyRule' - title: rules - defaultAuthority: - title: default_authority - $ref: '#/components/schemas/agents.v1.AutonomyAuthority' - maxRiskWithoutApproval: - title: max_risk_without_approval - $ref: '#/components/schemas/common.v1.RiskLevel' - title: AutonomyPolicy - additionalProperties: false - description: |- - AutonomyPolicy describes the default authority and specific action rules - that ToolExecution, Governance, and Approvals can enforce. - agents.v1.AutonomyRule: - type: object - properties: - actionType: - type: string - title: action_type - toolCapability: - type: string - title: tool_capability - maxRisk: - title: max_risk - $ref: '#/components/schemas/common.v1.RiskLevel' - authority: - not: - enum: - - 0 - title: authority - $ref: '#/components/schemas/agents.v1.AutonomyAuthority' - approvalPolicyRef: - type: string - title: approval_policy_ref - governancePolicyRef: - type: string - title: governance_policy_ref - rationale: - type: string - title: rationale - title: AutonomyRule - additionalProperties: false - description: AutonomyRule constrains a class of actions or tool capabilities. - agents.v1.CommitmentPolicy: - type: object - properties: - allowedKinds: - type: array - items: - $ref: '#/components/schemas/agents.v1.CommitmentKind' - title: allowed_kinds - templates: - type: array - items: - $ref: '#/components/schemas/agents.v1.CommitmentTemplate' - title: templates - defaultDueSeconds: - type: integer - title: default_due_seconds - format: int32 - maxOpenCommitments: - type: integer - title: max_open_commitments - format: int32 - requireObjectiveForCommitment: - type: boolean - title: require_objective_for_commitment - title: CommitmentPolicy - additionalProperties: false - description: |- - CommitmentPolicy describes which durable objectives and wakes can be created - from teammate commitments. - agents.v1.CommitmentTemplate: - type: object - properties: - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/agents.v1.CommitmentKind' - objectiveTitleTemplate: - type: string - title: objective_title_template - objectiveDescriptionTemplate: - type: string - title: objective_description_template - wakeReasonTemplate: - type: string - title: wake_reason_template - requiredJoinKeys: - type: array - items: - type: string - title: required_join_keys - title: CommitmentTemplate - additionalProperties: false - description: CommitmentTemplate maps a commitment kind to objective and wake templates. - agents.v1.ConnectorRequirement: - type: object - properties: - providerId: - type: string - title: provider_id - minLength: 1 - requiredCapabilities: - type: array - items: - type: string - title: required_capabilities - optionalCapabilities: - type: array - items: - type: string - title: optional_capabilities - required: - type: boolean - title: required - title: ConnectorRequirement - additionalProperties: false - agents.v1.DigitalTeammateProfile: - type: object - properties: - id: - type: string - title: id - version: - type: integer - title: version - format: int32 - workspaceId: - type: string - title: workspace_id - agentId: - type: string - title: agent_id - displayName: - type: string - title: display_name - role: - type: string - title: role - purpose: - type: string - title: purpose - ownerUserId: - type: string - title: owner_user_id - ownerTeamId: - type: string - title: owner_team_id - surfaceTypes: - type: array - items: - $ref: '#/components/schemas/common.v1.Surface' - title: surface_types - lifecycle: - title: lifecycle - $ref: '#/components/schemas/agents.v1.TeammateLifecycle' - responsibilities: - type: array - items: - $ref: '#/components/schemas/agents.v1.TeammateResponsibility' - title: responsibilities - commitmentPolicy: - title: commitment_policy - $ref: '#/components/schemas/agents.v1.CommitmentPolicy' - initiativePolicy: - title: initiative_policy - $ref: '#/components/schemas/agents.v1.InitiativePolicy' - autonomyPolicy: - title: autonomy_policy - $ref: '#/components/schemas/agents.v1.AutonomyPolicy' - memoryPolicy: - title: memory_policy - $ref: '#/components/schemas/agents.v1.MemoryPolicy' - presencePolicy: - title: presence_policy - $ref: '#/components/schemas/agents.v1.PresencePolicy' - outputPolicy: - title: output_policy - $ref: '#/components/schemas/agents.v1.OutputPolicy' - evalPolicy: - title: eval_policy - $ref: '#/components/schemas/agents.v1.EvalPolicy' - escalationPolicy: - title: escalation_policy - $ref: '#/components/schemas/agents.v1.EscalationPolicy' - labels: - type: object - title: labels - additionalProperties: - type: string - title: value - parameters: - title: parameters - $ref: '#/components/schemas/google.protobuf.Struct' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - channelManifests: - type: array - items: - $ref: '#/components/schemas/agents.v1.TeammateChannelManifest' - title: channel_manifests - title: DigitalTeammateProfile - additionalProperties: false - description: |- - DigitalTeammateProfile is the versioned contract for how an AgentConfig acts - as a durable teammate across objectives, workflows, tools, memory, evals, and - Slack or other delivery surfaces. - agents.v1.DigitalTeammateProfile.LabelsEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: LabelsEntry - additionalProperties: false - agents.v1.EscalationPolicy: - type: object - properties: - approverUserIds: - type: array - items: - type: string - title: approver_user_ids - approverTeamIds: - type: array - items: - type: string - title: approver_team_ids - escalateAfterSeconds: - type: integer - title: escalate_after_seconds - format: int32 - fallbackChannel: - title: fallback_channel - $ref: '#/components/schemas/common.v1.DeliveryChannel' - title: EscalationPolicy - additionalProperties: false - description: |- - EscalationPolicy describes who must be contacted when the teammate blocks or - needs approval. - agents.v1.EvalBinding: - type: object - properties: - suiteName: - type: string - title: suite_name - metricName: - type: string - title: metric_name - minimumScore: - type: number - title: minimum_score - format: double - failureAction: - type: string - title: failure_action - title: EvalBinding - additionalProperties: false - description: EvalBinding describes one score that should gate or monitor teammate quality. - agents.v1.EvalPolicy: - type: object - properties: - bindings: - type: array - items: - $ref: '#/components/schemas/agents.v1.EvalBinding' - title: bindings - loopDefinitionId: - type: string - title: loop_definition_id - productionSampleRateBasisPoints: - type: integer - title: production_sample_rate_basis_points - maximum: 10000 - format: int32 - title: EvalPolicy - additionalProperties: false - description: EvalPolicy binds production behavior to loop and eval scoring. - agents.v1.InitiativePolicy: - type: object - properties: - triggers: - type: array - items: - $ref: '#/components/schemas/agents.v1.InitiativeTrigger' - title: triggers - maxInitiatedRunsPerDay: - type: integer - title: max_initiated_runs_per_day - format: int32 - requireHumanSeed: - type: boolean - title: require_human_seed - title: InitiativePolicy - additionalProperties: false - description: |- - InitiativePolicy describes bounded conditions where a teammate can start or - resume work proactively. - agents.v1.InitiativeTrigger: - type: object - properties: - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/agents.v1.InitiativeTriggerKind' - triggerRef: - type: string - title: trigger_ref - filterExpr: - type: string - title: filter_expr - workflowDefinitionId: - type: string - title: workflow_definition_id - objectiveTemplateId: - type: string - title: objective_template_id - title: InitiativeTrigger - additionalProperties: false - description: InitiativeTrigger binds a proactive trigger to workflow or objective state. - agents.v1.MemoryPolicy: - type: object - properties: - allowedScopeRefs: - type: array - items: - type: string - title: allowed_scope_refs - allowUserMemory: - type: boolean - title: allow_user_memory - allowTeamMemory: - type: boolean - title: allow_team_memory - allowAgentMemory: - type: boolean - title: allow_agent_memory - requireReviewForNewMemory: - type: boolean - title: require_review_for_new_memory - defaultRetentionDays: - type: integer - title: default_retention_days - format: int32 - requiredSourceTypes: - type: array - items: - type: string - title: required_source_types - allowCrossChannelRecall: - type: boolean - title: allow_cross_channel_recall - title: MemoryPolicy - additionalProperties: false - description: MemoryPolicy describes what a teammate may recall or propose remembering. - agents.v1.OutputPolicy: - type: object - properties: - requiredArtifactKinds: - type: array - items: - type: string - title: required_artifact_kinds - optionalArtifactKinds: - type: array - items: - type: string - title: optional_artifact_kinds - renderChannelCards: - type: boolean - title: render_channel_cards - defaultVisibility: - type: string - title: default_visibility - title: OutputPolicy - additionalProperties: false - description: OutputPolicy describes durable work products and channel-safe renderings. - agents.v1.PresencePolicy: - type: object - properties: - primaryChannel: - title: primary_channel - $ref: '#/components/schemas/common.v1.DeliveryChannel' - primaryChannelId: - type: string - title: primary_channel_id - defaultThreadPolicy: - type: string - title: default_thread_policy - progressUpdateIntervalSeconds: - type: integer - title: progress_update_interval_seconds - format: int32 - visibleEvents: - type: array - items: - $ref: '#/components/schemas/agents.v1.PresenceEvent' - title: visible_events - postActionReceipts: - type: boolean - title: post_action_receipts - postBlockerUpdates: - type: boolean - title: post_blocker_updates - title: PresencePolicy - additionalProperties: false - description: |- - PresencePolicy describes how a teammate reports work back to Slack or other - delivery channels. - agents.v1.TeammateChannelManifest: - type: object - properties: - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/agents.v1.TeammateChannelKind' - label: - type: string - title: label - deliveryChannel: - not: - enum: - - 0 - title: delivery_channel - $ref: '#/components/schemas/common.v1.DeliveryChannel' - platformSurface: - title: platform_surface - $ref: '#/components/schemas/common.v1.Surface' - channelId: - type: string - title: channel_id - capabilities: - type: array - items: - $ref: '#/components/schemas/agents.v1.TeammateChannelCapability' - title: capabilities - inboundEvents: - type: array - items: - $ref: '#/components/schemas/agents.v1.TeammateChannelEventKind' - title: inbound_events - runtimeEvents: - type: array - items: - $ref: '#/components/schemas/agents.v1.TeammateRuntimeRenderEventKind' - title: runtime_events - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - title: TeammateChannelManifest - additionalProperties: false - description: |- - TeammateChannelManifest describes one channel adapter supported by a - teammate profile. Durable execution remains owned by AgentRuntime; this - manifest lets product surfaces declare the provider-specific ingress and - rendering coverage they can project. - agents.v1.TeammateChannelManifest.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - agents.v1.TeammateResponsibility: - type: object - properties: - id: - type: string - title: id - title: - type: string - title: title - description: - type: string - title: description - capabilityRefs: - type: array - items: - type: string - title: capability_refs - ownedEntityTypes: - type: array - items: - $ref: '#/components/schemas/common.v1.EntityType' - title: owned_entity_types - defaultSkillIds: - type: array - items: - type: string - title: default_skill_ids - promptNames: - type: array - items: - type: string - title: prompt_names - successMetricRefs: - type: array - items: - type: string - title: success_metric_refs - title: TeammateResponsibility - additionalProperties: false - description: |- - TeammateResponsibility binds a role claim to capabilities, entities, prompts, - skills, and measurable outcomes. - connectors.v1.ConnectorCatalogProvenance: - type: object - properties: - basis: - type: string - title: basis - sourceUrl: - type: string - title: source_url - lastVerifiedAt: - type: string - title: last_verified_at - verificationLevel: - title: verification_level - $ref: '#/components/schemas/connectors.v1.ConnectorVerificationLevel' - evidenceKind: - title: evidence_kind - $ref: '#/components/schemas/connectors.v1.ConnectorEvidenceKind' - title: ConnectorCatalogProvenance - additionalProperties: false - description: |- - ConnectorCatalogProvenance records where a catalog-derived value came from - (for example an OpenAPI spec import), when it was last verified, and the - bounded evidence behind its current verification level. - connectors.v1.ProviderResourceEnvelope: - type: object - properties: - schemaVersion: - type: string - title: schema_version - stableResourceId: - type: string - title: stable_resource_id - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - providerId: - type: string - title: provider_id - connectionId: - type: string - title: connection_id - sourceFamilyId: - type: string - title: source_family_id - originatingPrincipalId: - type: string - title: originating_principal_id - resourceKind: - type: string - title: resource_kind - parentResourceId: - type: string - title: parent_resource_id - visibilityClass: - title: visibility_class - $ref: '#/components/schemas/connectors.v1.ProviderResourceVisibilityClass' - visibilityPrincipalIds: - type: array - items: - type: string - title: visibility_principal_ids - visibilityMembershipRef: - type: string - title: visibility_membership_ref - contentTrust: - title: content_trust - $ref: '#/components/schemas/connectors.v1.ProviderContentTrust' - payloadSha256: - type: string - title: payload_sha256 - providerRevision: - type: string - title: provider_revision - lifecycleState: - title: lifecycle_state - $ref: '#/components/schemas/connectors.v1.ProviderResourceLifecycleState' - lifecycleGeneration: - type: - - integer - - string - title: lifecycle_generation - format: int64 - purgeCorrelationId: - type: string - title: purge_correlation_id - title: ProviderResourceEnvelope - additionalProperties: false - connectors.v1.SourceAuthorityObservation: - type: object - properties: - state: - title: state - $ref: '#/components/schemas/connectors.v1.SourceAuthorityState' - reason: - type: string - title: reason - maxLength: 256 - minLength: 1 - freshnessMethod: - title: freshness_method - $ref: '#/components/schemas/connectors.v1.SourceAuthorityFreshnessMethod' - observedAt: - title: observed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - lastConfirmedAt: - title: last_confirmed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - ownerSnapshotReference: - type: string - title: owner_snapshot_reference - maxLength: 256 - description: |- - Opaque owner reference only; never a token, secret, private key, or raw - provider response body. - title: SourceAuthorityObservation - additionalProperties: false - description: |- - SourceAuthorityObservation is credential-free evidence from the external - source owner. Empty optional timestamps/reference fields mean that the - owner has not supplied that evidence; they must not be inferred locally. - console.v1.AcceptOperatingProjectSnapshotRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - projectResourceId: - type: string - title: project_resource_id - maxLength: 255 - minLength: 1 - channelId: - type: string - title: channel_id - idempotencyKey: - type: string - title: idempotency_key - maxLength: 255 - minLength: 1 - expectedRefVersion: - type: - - integer - - string - title: expected_ref_version - format: int64 - description: Absent creates the first accepted snapshot; a value requires exact CAS. - nullable: true - files: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingProjectSnapshotFileInput' - title: files - maxItems: 1000 - description: Complete workspace manifest, including unchanged files. Omitted files are removed. - title: AcceptOperatingProjectSnapshotRequest - required: - - query - additionalProperties: false - console.v1.AcceptOperatingProjectSnapshotResponse: - type: object - properties: - projectSource: - title: project_source - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionProjectSource' - manualAcceptanceAvailable: - type: boolean - title: manual_acceptance_available - importExecutionId: - type: string - title: import_execution_id - importState: - type: string - title: import_state - importError: - type: string - title: import_error - title: AcceptOperatingProjectSnapshotResponse - additionalProperties: false - console.v1.ActivityEvent: - type: object - properties: - id: - type: string - title: id - eventType: - type: string - title: event_type - title: - type: string - title: title - detail: - type: string - title: detail - assetId: - type: string - title: asset_id - agentId: - type: string - title: agent_id - traceId: - type: string - title: trace_id - approvalId: - type: string - title: approval_id - actor: - type: string - title: actor - status: - type: string - title: status - riskLevel: - title: risk_level - $ref: '#/components/schemas/common.v1.RiskLevel' - costUsd: - type: number - title: cost_usd - format: double - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - relatedResources: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: related_resources - title: ActivityEvent - additionalProperties: false - console.v1.AdmitBusinessObjectObservationRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - objectId: - type: string - title: object_id - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - authorityEpoch: - type: - - integer - - string - title: authority_epoch - format: int64 - title: AdmitBusinessObjectObservationRequest - additionalProperties: false - console.v1.AdmitBusinessObjectObservationResponse: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/console.v1.BusinessObject' - title: AdmitBusinessObjectObservationResponse - additionalProperties: false - console.v1.AgentProductActionCatalog: - type: object - properties: - resolved: - type: boolean - title: resolved - published: - type: integer - title: published - format: int32 - scopeCompatible: - type: integer - title: scope_compatible - format: int32 - reads: - type: integer - title: reads - format: int32 - writes: - type: integer - title: writes - format: int32 - approvalRequired: - type: integer - title: approval_required - format: int32 - destructive: - type: integer - title: destructive - format: int32 - title: AgentProductActionCatalog - additionalProperties: false - console.v1.AgentProductConnection: - type: object - properties: - id: - type: string - title: id - providerId: - type: string - title: provider_id - displayName: - type: string - title: display_name - healthStatus: - title: health_status - $ref: '#/components/schemas/connectors.v1.HealthStatus' - healthReason: - type: string - title: health_reason - providerName: - type: string - title: provider_name - bound: - type: boolean - title: bound - actionCatalog: - title: action_catalog - description: |- - Connector-owned published actions compatible with this connection's - scopes. These counts do not imply agent policy admission or execution. - $ref: '#/components/schemas/console.v1.AgentProductActionCatalog' - title: AgentProductConnection - additionalProperties: false - console.v1.AgentProductPrompt: - type: object - properties: - name: - type: string - title: name - label: - type: string - title: label - content: - type: string - title: content - versionId: - type: string - title: version_id - version: - type: integer - title: version - format: int32 - resolved: - type: boolean - title: resolved - title: AgentProductPrompt - additionalProperties: false - description: |- - Prompt content is resolved by the Prompt owner for the active configuration. - An unavailable owner never turns a binding label into claimed instructions. - console.v1.AgentWorkforceActionAuthorityBoundary: - type: object - properties: - actionLabel: - type: string - title: action_label - approvalQueueState: - type: string - title: approval_queue_state - authoritySubject: - type: string - title: authority_subject - credentialProvider: - type: string - title: credential_provider - unprovenBoundary: - type: string - title: unproven_boundary - nextAction: - type: string - title: next_action - title: AgentWorkforceActionAuthorityBoundary - additionalProperties: false - console.v1.AgentWorkforceActionEvidence: - type: object - properties: - actionId: - type: string - title: action_id - toolName: - type: string - title: tool_name - connectorId: - type: string - title: connector_id - capability: - type: string - title: capability - targetSummary: - type: string - title: target_summary - decision: - type: string - title: decision - mutatesResource: - type: boolean - title: mutates_resource - riskLevel: - title: risk_level - $ref: '#/components/schemas/common.v1.RiskLevel' - safeArgumentsRef: - type: string - title: safe_arguments_ref - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - missingEvidence: - type: array - items: - type: string - title: missing_evidence - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - principalEvidenceState: - type: string - title: principal_evidence_state - credentialEvidenceState: - type: string - title: credential_evidence_state - costEvidenceState: - type: string - title: cost_evidence_state - title: AgentWorkforceActionEvidence - additionalProperties: false - console.v1.AgentWorkforceApprovalBlockerBucket: - type: object - properties: - code: - type: string - title: code - label: - type: string - title: label - detail: - type: string - title: detail - recoveryAction: - type: string - title: recovery_action - count: - type: integer - title: count - format: int32 - title: AgentWorkforceApprovalBlockerBucket - additionalProperties: false - console.v1.AgentWorkforceApprovalDisablement: - type: object - properties: - code: - type: string - title: code - description: |- - code is one of none, missing_credential_authority, - unverified_run_as_identity, missing_cost_evidence, - missing_action_evidence, security_decision_blocked, or - security_review_required. - label: - type: string - title: label - detail: - type: string - title: detail - recoveryAction: - type: string - title: recovery_action - evidenceGapIds: - type: array - items: - type: string - title: evidence_gap_ids - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - title: AgentWorkforceApprovalDisablement - additionalProperties: false - console.v1.AgentWorkforceApprovalQueueSummary: - type: object - properties: - totalRecords: - type: integer - title: total_records - format: int32 - stateBuckets: - type: array - items: - $ref: '#/components/schemas/console.v1.AgentWorkforceApprovalStateBucket' - title: state_buckets - blockerBuckets: - type: array - items: - $ref: '#/components/schemas/console.v1.AgentWorkforceApprovalBlockerBucket' - title: blocker_buckets - missingEvidenceBuckets: - type: array - items: - $ref: '#/components/schemas/console.v1.AgentWorkforceMissingEvidenceBucket' - title: missing_evidence_buckets - title: AgentWorkforceApprovalQueueSummary - additionalProperties: false - console.v1.AgentWorkforceApprovalStateBucket: - type: object - properties: - state: - type: string - title: state - label: - type: string - title: label - count: - type: integer - title: count - format: int32 - nextAction: - type: string - title: next_action - title: AgentWorkforceApprovalStateBucket - additionalProperties: false - console.v1.AgentWorkforceDebugIdentifiers: - type: object - properties: - spanIds: - type: array - items: - type: string - title: span_ids - rawReferenceIds: - type: array - items: - type: string - title: raw_reference_ids - sourceEventIds: - type: array - items: - type: string - title: source_event_ids - attributes: - title: attributes - $ref: '#/components/schemas/google.protobuf.Struct' - runId: - type: string - title: run_id - sessionId: - type: string - title: session_id - traceId: - type: string - title: trace_id - title: AgentWorkforceDebugIdentifiers - additionalProperties: false - console.v1.AgentWorkforceMissingEvidenceBucket: - type: object - properties: - label: - type: string - title: label - recoveryAction: - type: string - title: recovery_action - count: - type: integer - title: count - format: int32 - title: AgentWorkforceMissingEvidenceBucket - additionalProperties: false - console.v1.AgentWorkforceProofSummary: - type: object - properties: - principalEvidenceState: - type: string - title: principal_evidence_state - credentialEvidenceState: - type: string - title: credential_evidence_state - costEvidenceState: - type: string - title: cost_evidence_state - actionEvidenceState: - type: string - title: action_evidence_state - endpointGuardrailState: - type: string - title: endpoint_guardrail_state - approvalReady: - type: boolean - title: approval_ready - blockingReasons: - type: array - items: - type: string - title: blocking_reasons - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - title: AgentWorkforceProofSummary - additionalProperties: false - console.v1.AgentWorkforceQuestionSummary: - type: object - properties: - canApproveThis: - type: string - title: can_approve_this - evidenceMissing: - type: string - title: evidence_missing - agentSaw: - type: string - title: agent_saw - agentTriedToDo: - type: string - title: agent_tried_to_do - wasDenied: - type: string - title: was_denied - shouldDoNext: - type: string - title: should_do_next - title: AgentWorkforceQuestionSummary - additionalProperties: false - console.v1.AgentWorkforceRecord: - type: object - properties: - id: - type: string - title: id - workspaceId: - type: string - title: workspace_id - organizationId: - type: string - title: organization_id - agentId: - type: string - title: agent_id - agentName: - type: string - title: agent_name - runtime: - type: string - title: runtime - owner: - type: string - title: owner - status: - type: string - title: status - description: status is one of approval_ready, needs_evidence, needs_review, blocked, or observed. - queueState: - type: string - title: queue_state - riskLevel: - title: risk_level - $ref: '#/components/schemas/common.v1.RiskLevel' - currentWork: - type: string - title: current_work - runAsIdentity: - title: run_as_identity - $ref: '#/components/schemas/console.v1.RunAsIdentitySummary' - securityDecision: - title: security_decision - $ref: '#/components/schemas/console.v1.SecurityDecisionPacket' - actionEvidence: - type: array - items: - $ref: '#/components/schemas/console.v1.AgentWorkforceActionEvidence' - title: action_evidence - credentialAuthority: - title: credential_authority - $ref: '#/components/schemas/console.v1.CredentialAuthoritySummary' - costEvidence: - title: cost_evidence - $ref: '#/components/schemas/console.v1.CostEvidenceSummary' - nextAction: - type: string - title: next_action - missingEvidence: - type: array - items: - type: string - title: missing_evidence - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - debugIdentifiers: - title: debug_identifiers - $ref: '#/components/schemas/console.v1.AgentWorkforceDebugIdentifiers' - questionSummary: - title: question_summary - $ref: '#/components/schemas/console.v1.AgentWorkforceQuestionSummary' - approvalDisablement: - title: approval_disablement - $ref: '#/components/schemas/console.v1.AgentWorkforceApprovalDisablement' - endpointGuardrail: - title: endpoint_guardrail - $ref: '#/components/schemas/console.v1.EndpointGuardrailSummary' - proofSummary: - title: proof_summary - $ref: '#/components/schemas/console.v1.AgentWorkforceProofSummary' - approvalQueueState: - type: string - title: approval_queue_state - description: |- - approval_queue_state is one of approval_ready, approval_blocked, - needs_credential_evidence, needs_run_as_identity, - needs_cost_evidence, needs_action_evidence, security_review_required, - native_observed_only, or needs_evidence. - actionAuthorityBoundaries: - type: array - items: - $ref: '#/components/schemas/console.v1.AgentWorkforceActionAuthorityBoundary' - title: action_authority_boundaries - sourceReadiness: - type: array - items: - $ref: '#/components/schemas/console.v1.AgentWorkforceSourceReadiness' - title: source_readiness - description: |- - source_readiness is the server-owned readiness projection for the - collector/source paths that contributed observations or proof. Status is - one of configured, observing, proof_joined, approval_ready, or blocked. - title: AgentWorkforceRecord - additionalProperties: false - console.v1.AgentWorkforceSourceReadiness: - type: object - properties: - source: - type: string - title: source - description: |- - source is one of maestro, codex, claude_code, cursor, external, - llm_gateway, meter, credential_authority, identity, customer_mcp, - hook_otlp, desktop_sidecar, local_sidecar, external_agent, - external_self_report, cerebro, nimbus, or unknown. - collector: - type: string - title: collector - status: - type: string - title: status - proofStrength: - type: string - title: proof_strength - detail: - type: string - title: detail - blockingReason: - type: string - title: blocking_reason - approvalAuthority: - type: boolean - title: approval_authority - trustedMetadataOnly: - type: boolean - title: trusted_metadata_only - missingProof: - type: array - items: - type: string - title: missing_proof - joinKeys: - type: array - items: - type: string - title: join_keys - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - title: AgentWorkforceSourceReadiness - additionalProperties: false - console.v1.AgentWorkforceSubmittedEvidence: - type: object - properties: - evidenceId: - type: string - title: evidence_id - evidenceKind: - type: string - title: evidence_kind - evidenceSource: - type: string - title: evidence_source - proofStrength: - type: string - title: proof_strength - approvalAuthority: - type: boolean - title: approval_authority - trustedMetadataOnly: - type: boolean - title: trusted_metadata_only - detail: - type: string - title: detail - recordId: - type: string - title: record_id - traceId: - type: string - title: trace_id - spanId: - type: string - title: span_id - evidenceRef: - title: evidence_ref - $ref: '#/components/schemas/console.v1.RelatedResource' - title: AgentWorkforceSubmittedEvidence - additionalProperties: false - console.v1.AggregateCustomerIntelligencePatternsRequest: - type: object - properties: - productArea: - type: string - title: product_area - maxLength: 80 - journey: - type: string - title: journey - maxLength: 80 - authorities: - type: array - items: - $ref: '#/components/schemas/console.v1.CustomerIntelligenceAuthority' - title: authorities - maxItems: 6 - lifecycleStates: - type: array - items: - $ref: '#/components/schemas/console.v1.CustomerIntelligenceLifecycleState' - title: lifecycle_states - maxItems: 6 - createdAfter: - title: created_after - $ref: '#/components/schemas/google.protobuf.Timestamp' - minimumOrganizationCount: - type: integer - title: minimum_organization_count - minimum: 5 - format: int32 - title: AggregateCustomerIntelligencePatternsRequest - additionalProperties: false - console.v1.AggregateCustomerIntelligencePatternsResponse: - type: object - properties: - patterns: - type: array - items: - $ref: '#/components/schemas/console.v1.CustomerIntelligencePattern' - title: patterns - title: AggregateCustomerIntelligencePatternsResponse - additionalProperties: false - console.v1.AiAsset: - type: object - properties: - id: - type: string - title: id - name: - type: string - title: name - assetType: - type: string - title: asset_type - owner: - type: string - title: owner - teamId: - type: string - title: team_id - environment: - type: string - title: environment - source: - type: string - title: source - status: - type: string - title: status - riskLevel: - title: risk_level - $ref: '#/components/schemas/common.v1.RiskLevel' - policyState: - type: string - title: policy_state - spendUsd: - type: number - title: spend_usd - format: double - requestCount: - type: - - integer - - string - title: request_count - format: int64 - errorCount: - type: - - integer - - string - title: error_count - format: int64 - latencyP95Ms: - type: - - integer - - string - title: latency_p95_ms - format: int64 - lastSeenAt: - title: last_seen_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - tags: - type: array - items: - type: string - title: tags - relatedResources: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: related_resources - title: AiAsset - additionalProperties: false - console.v1.ArchiveOperatingThreadRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - minLength: 1 - archived: - type: boolean - title: archived - idempotencyKey: - type: string - title: idempotency_key - maxLength: 512 - minLength: 1 - title: ArchiveOperatingThreadRequest - required: - - query - additionalProperties: false - console.v1.ArchiveOperatingThreadResponse: - type: object - properties: - channel: - title: channel - $ref: '#/components/schemas/console.v1.OperatingChannel' - changed: - type: boolean - title: changed - replayed: - type: boolean - title: replayed - title: ArchiveOperatingThreadResponse - required: - - channel - additionalProperties: false - console.v1.ArchiveWorkspaceRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - archived: - type: boolean - title: archived - title: ArchiveWorkspaceRequest - required: - - query - additionalProperties: false - console.v1.ArchiveWorkspaceResponse: - type: object - properties: - settings: - title: settings - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - title: ArchiveWorkspaceResponse - required: - - settings - additionalProperties: false - console.v1.AssessComplianceSubjectRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - profileId: - type: string - title: profile_id - subjectKind: - type: string - title: subject_kind - subjectId: - type: string - title: subject_id - title: AssessComplianceSubjectRequest - additionalProperties: false - description: One versioned control profile runs against one owner-fetched subject. - console.v1.AssessComplianceSubjectResponse: - type: object - properties: - assessment: - title: assessment - $ref: '#/components/schemas/console.v1.ComplianceSubjectAssessment' - title: AssessComplianceSubjectResponse - additionalProperties: false - console.v1.AttachPrivateEndpointToProfileRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - profileId: - type: string - title: profile_id - minLength: 1 - endpointId: - type: string - title: endpoint_id - routeMode: - type: string - title: route_mode - minLength: 1 - requirePrivate: - type: boolean - title: require_private - title: AttachPrivateEndpointToProfileRequest - required: - - query - additionalProperties: false - console.v1.AttachPrivateEndpointToProfileResponse: - type: object - properties: - route: - title: route - $ref: '#/components/schemas/console.v1.PrivateProfileRoute' - title: AttachPrivateEndpointToProfileResponse - required: - - route - additionalProperties: false - console.v1.AuthorityDeniedAction: - type: object - properties: - id: - type: string - title: id - actionId: - type: string - title: action_id - toolName: - type: string - title: tool_name - policyReason: - type: string - title: policy_reason - requiredEvidence: - type: array - items: - type: string - title: required_evidence - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - title: AuthorityDeniedAction - additionalProperties: false - console.v1.AuthorityLedger: - type: object - properties: - id: - type: string - title: id - traceId: - type: string - title: trace_id - spanId: - type: string - title: span_id - actionId: - type: string - title: action_id - approvalId: - type: string - title: approval_id - costRowId: - type: string - title: cost_row_id - agentId: - type: string - title: agent_id - agentName: - type: string - title: agent_name - runAsIdentity: - type: string - title: run_as_identity - toolId: - type: string - title: tool_id - toolName: - type: string - title: tool_name - connectorId: - type: string - title: connector_id - connectorName: - type: string - title: connector_name - connectorProvider: - type: string - title: connector_provider - credentialRef: - type: string - title: credential_ref - grantLeaseId: - type: string - title: grant_lease_id - authorityId: - type: string - title: authority_id - authorityLabel: - type: string - title: authority_label - authorityType: - type: string - title: authority_type - description: |- - authority_type is a product category such as credential, connector_grant, - service_account, browser_session, runner_lease, or unknown. - authorityScope: - type: string - title: authority_scope - issuer: - type: string - title: issuer - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - authorityState: - type: string - title: authority_state - description: authority_state is one of active, expired, revoked, missing, or unknown. - attestationState: - type: string - title: attestation_state - description: attestation_state is one of attested, unverified, missing, or unknown. - attestationSummary: - type: string - title: attestation_summary - trustState: - type: string - title: trust_state - description: trust_state is one of trusted, needs_review, unverified, blocked, or unknown. - evidenceState: - type: string - title: evidence_state - description: evidence_state is one of ready, pending, missing, warning, blocked, or unknown. - evidenceSource: - type: string - title: evidence_source - costPosture: - type: string - title: cost_posture - costUsd: - type: number - title: cost_usd - format: double - inputTokens: - type: - - integer - - string - title: input_tokens - format: int64 - outputTokens: - type: - - integer - - string - title: output_tokens - format: int64 - status: - type: string - title: status - policyReason: - type: string - title: policy_reason - requiredEvidence: - type: array - items: - type: string - title: required_evidence - riskLevel: - title: risk_level - $ref: '#/components/schemas/common.v1.RiskLevel' - detail: - type: string - title: detail - nextAction: - type: string - title: next_action - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - scopeLedger: - type: array - items: - $ref: '#/components/schemas/console.v1.AuthorityScopeLedger' - title: scope_ledger - missingEvidence: - type: array - items: - $ref: '#/components/schemas/console.v1.AuthorityMissingEvidence' - title: missing_evidence - deniedActions: - type: array - items: - $ref: '#/components/schemas/console.v1.AuthorityDeniedAction' - title: denied_actions - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - evidenceGaps: - type: array - items: - $ref: '#/components/schemas/console.v1.SecurityDecisionEvidenceGap' - title: evidence_gaps - title: AuthorityLedger - additionalProperties: false - console.v1.AuthorityMissingEvidence: - type: object - properties: - id: - type: string - title: id - label: - type: string - title: label - state: - type: string - title: state - owner: - type: string - title: owner - recoveryAction: - type: string - title: recovery_action - reason: - type: string - title: reason - source: - type: string - title: source - spanIds: - type: array - items: - type: string - title: span_ids - title: AuthorityMissingEvidence - additionalProperties: false - console.v1.AuthorityScopeLedger: - type: object - properties: - group: - type: string - title: group - granted: - type: array - items: - type: string - title: granted - exercised: - type: array - items: - type: string - title: exercised - denied: - type: array - items: - type: string - title: denied - missing: - type: array - items: - type: string - title: missing - state: - type: string - title: state - policyReason: - type: string - title: policy_reason - requiredEvidence: - type: array - items: - type: string - title: required_evidence - title: AuthorityScopeLedger - additionalProperties: false - console.v1.AuthorizeComputerMissionApexSessionAdoptionRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - reservationId: - type: string - title: reservation_id - minLength: 1 - runnerSessionId: - type: string - title: runner_session_id - minLength: 1 - missionId: - type: string - title: mission_id - minLength: 1 - runtimeRunId: - type: string - title: runtime_run_id - minLength: 1 - title: AuthorizeComputerMissionApexSessionAdoptionRequest - additionalProperties: false - console.v1.AuthorizeComputerMissionApexSessionAdoptionResponse: - type: object - properties: - ownerBinding: - title: owner_binding - $ref: '#/components/schemas/remoterunner.v1.RunnerSessionOwnerBinding' - authorizationId: - type: string - title: authorization_id - minLength: 1 - authorizationDigestSha256: - type: string - title: authorization_digest_sha256 - pattern: ^[0-9a-f]{64}$ - tenantScopeId: - type: string - title: tenant_scope_id - minLength: 1 - workloadDigest: - type: string - title: workload_digest - pattern: ^sha256:[0-9a-f]{64}$ - instructionArtifactRef: - type: string - title: instruction_artifact_ref - minLength: 1 - instructionDigestSha256: - type: string - title: instruction_digest_sha256 - pattern: ^[0-9a-f]{64}$ - instructionByteCount: - type: - - integer - - string - title: instruction_byte_count - maximum: 1048576 - minimum: 1 - format: int64 - title: AuthorizeComputerMissionApexSessionAdoptionResponse - required: - - ownerBinding - additionalProperties: false - console.v1.BeginOperatingAttachmentUploadRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - minLength: 1 - filename: - type: string - title: filename - minLength: 1 - contentType: - type: string - title: content_type - minLength: 1 - sizeBytes: - exclusiveMinimum: 0 - type: - - integer - - string - title: size_bytes - maximum: 52428800 - format: int64 - sha256: - type: string - title: sha256 - minLength: 1 - scope: - not: - enum: - - 0 - title: scope - $ref: '#/components/schemas/console.v1.OperatingAttachmentScope' - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: BeginOperatingAttachmentUploadRequest - required: - - query - additionalProperties: false - console.v1.BeginOperatingAttachmentUploadResponse: - type: object - properties: - attachment: - title: attachment - $ref: '#/components/schemas/console.v1.OperatingAttachmentRef' - leaseId: - type: string - title: lease_id - leaseToken: - type: string - title: lease_token - fencingToken: - type: - - integer - - string - title: fencing_token - format: int64 - upload: - title: upload - $ref: '#/components/schemas/vfs.v1.VfsUploadTarget' - title: BeginOperatingAttachmentUploadResponse - additionalProperties: false - console.v1.BeginPublishedCaptureFormUploadRequest: - type: object - properties: - publicationId: - type: string - title: publication_id - minLength: 1 - inputId: - type: string - title: input_id - maxLength: 80 - minLength: 1 - filename: - type: string - title: filename - maxLength: 255 - minLength: 1 - contentType: - type: string - title: content_type - maxLength: 255 - minLength: 1 - sizeBytes: - exclusiveMinimum: 0 - type: - - integer - - string - title: size_bytes - maximum: 52428800 - format: int64 - sha256: - type: string - title: sha256 - pattern: ^[0-9a-f]{64}$ - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - title: BeginPublishedCaptureFormUploadRequest - additionalProperties: false - console.v1.BeginPublishedCaptureFormUploadResponse: - type: object - properties: - grant: - title: grant - $ref: '#/components/schemas/console.v1.CaptureFormUpload' - leaseId: - type: string - title: lease_id - minLength: 1 - leaseToken: - type: string - title: lease_token - maxLength: 512 - minLength: 1 - fencingToken: - exclusiveMinimum: 0 - type: - - integer - - string - title: fencing_token - format: int64 - upload: - title: upload - $ref: '#/components/schemas/vfs.v1.VfsUploadTarget' - title: BeginPublishedCaptureFormUploadResponse - required: - - grant - - upload - additionalProperties: false - console.v1.BindBusinessObjectSourceRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - objectId: - type: string - title: object_id - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - resourceId: - type: string - title: resource_id - groupIds: - type: array - items: - type: string - title: group_ids - fields: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessSourceField' - title: fields - connectionId: - type: string - title: connection_id - familyStableId: - type: string - title: family_stable_id - recordId: - type: string - title: record_id - title: BindBusinessObjectSourceRequest - additionalProperties: false - console.v1.BindBusinessObjectSourceResponse: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/console.v1.BusinessObject' - title: BindBusinessObjectSourceResponse - additionalProperties: false - console.v1.BindComputerMissionApexInstructionMetadataRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - reservationId: - type: string - title: reservation_id - minLength: 1 - attemptId: - type: string - title: attempt_id - minLength: 1 - instructionArtifactRef: - type: string - title: instruction_artifact_ref - minLength: 1 - instructionDigestSha256: - type: string - title: instruction_digest_sha256 - pattern: ^[0-9a-f]{64}$ - instructionByteCount: - type: - - integer - - string - title: instruction_byte_count - maximum: 1048576 - minimum: 1 - format: int64 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: BindComputerMissionApexInstructionMetadataRequest - additionalProperties: false - console.v1.BindComputerMissionApexInstructionMetadataResponse: - type: object - properties: - metadata: - title: metadata - $ref: '#/components/schemas/console.v1.ComputerMissionApexInstructionMetadata' - title: BindComputerMissionApexInstructionMetadataResponse - required: - - metadata - additionalProperties: false - console.v1.BindComputerMissionApexSessionReservationRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - reservationId: - type: string - title: reservation_id - minLength: 1 - runnerSessionId: - type: string - title: runner_session_id - minLength: 1 - runnerProfile: - type: string - title: runner_profile - const: apex-agents-v1 - workloadDigest: - type: string - title: workload_digest - pattern: ^sha256:[0-9a-f]{64}$ - createIdempotencyKey: - type: string - title: create_idempotency_key - minLength: 1 - description: Must exactly equal ReserveComputerMissionApexSessionRequest.idempotency_key. - title: BindComputerMissionApexSessionReservationRequest - additionalProperties: false - console.v1.BindComputerMissionApexSessionReservationResponse: - type: object - properties: - reservation: - title: reservation - $ref: '#/components/schemas/console.v1.ComputerMissionApexSessionReservation' - title: BindComputerMissionApexSessionReservationResponse - required: - - reservation - additionalProperties: false - console.v1.BootstrapThreadGatewayRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - threadId: - type: string - title: thread_id - minLength: 1 - permissions: - type: array - items: - $ref: '#/components/schemas/console.v1.ThreadGatewayPermission' - title: permissions - maxItems: 3 - minItems: 1 - uniqueItems: true - title: BootstrapThreadGatewayRequest - additionalProperties: false - console.v1.BootstrapThreadGatewayResponse: - type: object - properties: - enabled: - type: boolean - title: enabled - endpoint: - type: string - title: endpoint - accessToken: - type: string - title: access_token - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - permissions: - type: array - items: - $ref: '#/components/schemas/console.v1.ThreadGatewayPermission' - title: permissions - shadowWatchPercent: - type: integer - title: shadow_watch_percent - maximum: 100 - directWatchPercent: - type: integer - title: direct_watch_percent - maximum: 100 - directSubmitPercent: - type: integer - title: direct_submit_percent - maximum: 100 - shadowWatchAssigned: - type: boolean - title: shadow_watch_assigned - directWatchAssigned: - type: boolean - title: direct_watch_assigned - directSubmitAssigned: - type: boolean - title: direct_submit_assigned - title: BootstrapThreadGatewayResponse - additionalProperties: false - console.v1.BrowseDexSkillCatalogRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: BrowseDexSkillCatalogRequest - required: - - query - additionalProperties: false - console.v1.BrowseDexSkillCatalogResponse: - type: object - properties: - entries: - type: array - items: - $ref: '#/components/schemas/console.v1.DexSkillCatalogEntry' - title: entries - playbooks: - type: array - items: - $ref: '#/components/schemas/console.v1.DexSkillPlaybook' - title: playbooks - title: BrowseDexSkillCatalogResponse - additionalProperties: false - console.v1.BusinessArtifactReference: - type: object - properties: - artifactVersionId: - type: string - title: artifact_version_id - title: BusinessArtifactReference - additionalProperties: false - console.v1.BusinessBlueprint: - type: object - properties: - blueprintId: - type: string - title: blueprint_id - version: - type: - - integer - - string - title: version - format: int64 - contentDigest: - type: string - title: content_digest - name: - type: string - title: name - description: - type: string - title: description - objectTypes: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessObjectType' - title: object_types - process: - title: process - $ref: '#/components/schemas/console.v1.BusinessProcessDefinition' - intake: - title: intake - $ref: '#/components/schemas/console.v1.CaptureFormVersionInput' - requiredCapabilities: - type: array - items: - type: string - title: required_capabilities - description: |- - Capability identifiers required before automated execution can be enabled. - Presence in this list does not claim installation or availability. - automatedExecutionAvailable: - type: boolean - title: automated_execution_available - description: This catalog version supplies native definitions, not executable admission. - title: BusinessBlueprint - additionalProperties: false - description: |- - Built-in blueprints are immutable source templates, not tenant records or - executable grants. Clone creates native definitions in the caller's tenant. - console.v1.BusinessBlueprintSource: - type: object - properties: - blueprintId: - type: string - title: blueprint_id - version: - type: - - integer - - string - title: version - format: int64 - contentDigest: - type: string - title: content_digest - cloneId: - type: string - title: clone_id - sourceTypeId: - type: string - title: source_type_id - description: Stable template member ID. Cloned type_id is tenant-owned and editable. - title: BusinessBlueprintSource - additionalProperties: false - description: Exact built-in source retained on each cloned schema for future comparison. - console.v1.BusinessFieldDefinition: - type: object - properties: - fieldId: - type: string - title: field_id - name: - type: string - title: name - kind: - title: kind - $ref: '#/components/schemas/console.v1.BusinessFieldKind' - required: - type: boolean - title: required - unique: - type: boolean - title: unique - enumValues: - type: array - items: - type: string - title: enum_values - referenceTypeId: - type: string - title: reference_type_id - groupId: - type: string - title: group_id - description: - type: string - title: description - description: Optional help text for people entering this field. - maxLength: - type: integer - title: max_length - description: |- - TEXT only: maximum Unicode code points, from 1 through 8192. - The existing 8192-byte text bound also applies. Published limits may only relax. - nullable: true - title: BusinessFieldDefinition - additionalProperties: false - console.v1.BusinessFieldValue: - type: object - oneOf: - - properties: - artifact: - title: artifact - $ref: '#/components/schemas/console.v1.BusinessArtifactReference' - title: artifact - required: - - artifact - - properties: - boolean: - type: boolean - title: boolean - title: boolean - required: - - boolean - - properties: - date: - type: string - title: date - title: date - required: - - date - - properties: - decimal: - type: string - title: decimal - title: decimal - required: - - decimal - - properties: - enumValue: - type: string - title: enum_value - title: enum_value - required: - - enumValue - - properties: - integer: - type: - - integer - - string - title: integer - format: int64 - title: integer - required: - - integer - - properties: - money: - title: money - $ref: '#/components/schemas/console.v1.BusinessMoney' - title: money - required: - - money - - properties: - reference: - title: reference - $ref: '#/components/schemas/console.v1.BusinessObjectReference' - title: reference - required: - - reference - - properties: - text: - type: string - title: text - title: text - required: - - text - - properties: - textList: - title: text_list - $ref: '#/components/schemas/console.v1.BusinessTextList' - title: text_list - required: - - textList - - properties: - timestamp: - type: string - title: timestamp - title: timestamp - required: - - timestamp - properties: - artifact: - title: artifact - $ref: '#/components/schemas/console.v1.BusinessArtifactReference' - boolean: - type: boolean - title: boolean - date: - type: string - title: date - decimal: - type: string - title: decimal - enumValue: - type: string - title: enum_value - integer: - type: - - integer - - string - title: integer - format: int64 - money: - title: money - $ref: '#/components/schemas/console.v1.BusinessMoney' - reference: - title: reference - $ref: '#/components/schemas/console.v1.BusinessObjectReference' - text: - type: string - title: text - textList: - title: text_list - $ref: '#/components/schemas/console.v1.BusinessTextList' - timestamp: - type: string - title: timestamp - fieldId: - type: string - title: field_id - title: BusinessFieldValue - additionalProperties: false - console.v1.BusinessMoney: - type: object - properties: - amount: - type: string - title: amount - currency: - type: string - title: currency - title: BusinessMoney - additionalProperties: false - description: Exact canonical decimal text, never floating point. Currency is an ISO-style uppercase code. - console.v1.BusinessObject: - type: object - properties: - objectId: - type: string - title: object_id - typeId: - type: string - title: type_id - schemaRevision: - type: - - integer - - string - title: schema_revision - format: int64 - revision: - type: - - integer - - string - title: revision - format: int64 - values: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessFieldValue' - title: values - deleted: - type: boolean - title: deleted - source: - title: source - $ref: '#/components/schemas/console.v1.BusinessSourceBinding' - updatedAt: - type: string - title: updated_at - createdAt: - type: string - title: created_at - title: BusinessObject - additionalProperties: false - console.v1.BusinessObjectFilter: - type: object - oneOf: - - properties: - reference: - title: reference - $ref: '#/components/schemas/console.v1.BusinessObjectReferenceFilter' - title: reference - required: - - reference - - properties: - uniqueValue: - title: unique_value - $ref: '#/components/schemas/console.v1.BusinessFieldValue' - title: unique_value - required: - - uniqueValue - title: BusinessObjectFilter - additionalProperties: false - properties: - reference: - title: reference - $ref: '#/components/schemas/console.v1.BusinessObjectReferenceFilter' - uniqueValue: - title: unique_value - $ref: '#/components/schemas/console.v1.BusinessFieldValue' - console.v1.BusinessObjectReference: - type: object - properties: - objectId: - type: string - title: object_id - title: BusinessObjectReference - additionalProperties: false - console.v1.BusinessObjectReferenceFilter: - type: object - properties: - fieldId: - type: string - title: field_id - targetObjectId: - type: string - title: target_object_id - title: BusinessObjectReferenceFilter - additionalProperties: false - console.v1.BusinessObjectRelationship: - type: object - properties: - sourceObjectId: - type: string - title: source_object_id - relationshipId: - type: string - title: relationship_id - targetObjectId: - type: string - title: target_object_id - title: BusinessObjectRelationship - additionalProperties: false - console.v1.BusinessObjectRevision: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/console.v1.BusinessObject' - operationId: - type: string - title: operation_id - actorId: - type: string - title: actor_id - changeKind: - type: string - title: change_kind - evidenceRefs: - type: array - items: - type: string - title: evidence_refs - title: BusinessObjectRevision - additionalProperties: false - console.v1.BusinessObjectSourceRecovery: - type: object - properties: - objectId: - type: string - title: object_id - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - authorityEpoch: - type: - - integer - - string - title: authority_epoch - format: int64 - sourceState: - title: source_state - $ref: '#/components/schemas/console.v1.BusinessSourceState' - title: BusinessObjectSourceRecovery - additionalProperties: false - console.v1.BusinessObjectType: - type: object - properties: - typeId: - type: string - title: type_id - name: - type: string - title: name - revision: - type: - - integer - - string - title: revision - format: int64 - fields: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessFieldDefinition' - title: fields - relationships: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessRelationshipDefinition' - title: relationships - pluralName: - type: string - title: plural_name - description: Optional plural label; the stable type_id remains the machine identifier. - description: - type: string - title: description - displayFieldId: - type: string - title: display_field_id - description: Optional scalar field used to label records; references and artifacts are excluded. - blueprintSource: - title: blueprint_source - description: |- - Assigned only by native blueprint cloning and immutable across revisions. - Provenance does not grant permissions or executable capabilities. - $ref: '#/components/schemas/console.v1.BusinessBlueprintSource' - recordKind: - title: record_kind - $ref: '#/components/schemas/console.v1.BusinessObjectRecordKind' - title: BusinessObjectType - additionalProperties: false - console.v1.BusinessProcess: - type: object - properties: - processId: - type: string - title: process_id - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - definitionId: - type: string - title: definition_id - definitionRevision: - type: - - integer - - string - title: definition_revision - format: int64 - revision: - type: - - integer - - string - title: revision - format: int64 - stateId: - type: string - title: state_id - subjectObjectId: - type: string - title: subject_object_id - participants: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessProcessParticipant' - title: participants - decisionPrincipalId: - type: string - title: decision_principal_id - parentProcessId: - type: string - title: parent_process_id - createdAt: - type: string - title: created_at - updatedAt: - type: string - title: updated_at - receipts: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessProcessReceipt' - title: receipts - title: BusinessProcess - additionalProperties: false - console.v1.BusinessProcessDefinition: - type: object - properties: - definitionId: - type: string - title: definition_id - revision: - type: - - integer - - string - title: revision - format: int64 - name: - type: string - title: name - participants: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessProcessParticipantType' - title: participants - subjectRoleId: - type: string - title: subject_role_id - states: - type: array - items: - type: string - title: states - initialState: - type: string - title: initial_state - terminalStates: - type: array - items: - type: string - title: terminal_states - transitions: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessProcessTransition' - title: transitions - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - title: BusinessProcessDefinition - additionalProperties: false - console.v1.BusinessProcessFollowUp: - type: object - properties: - definitionId: - type: string - title: definition_id - definitionRevision: - type: - - integer - - string - title: definition_revision - format: int64 - subjectRoleId: - type: string - title: subject_role_id - description: Child roles map by stable role ID to this process's participants. - title: BusinessProcessFollowUp - additionalProperties: false - console.v1.BusinessProcessParticipant: - type: object - properties: - roleId: - type: string - title: role_id - objectId: - type: string - title: object_id - objectRevision: - type: - - integer - - string - title: object_revision - format: int64 - description: Pins the observed record when admitting work or accepting a decision. - title: BusinessProcessParticipant - additionalProperties: false - console.v1.BusinessProcessParticipantType: - type: object - properties: - roleId: - type: string - title: role_id - typeId: - type: string - title: type_id - schemaRevision: - type: - - integer - - string - title: schema_revision - format: int64 - title: BusinessProcessParticipantType - additionalProperties: false - description: A process has its own lifecycle; its subject's ordinary fields do not own state. - console.v1.BusinessProcessReceipt: - type: object - properties: - operationId: - type: string - title: operation_id - transitionId: - type: string - title: transition_id - fromState: - type: string - title: from_state - toState: - type: string - title: to_state - revision: - type: - - integer - - string - title: revision - format: int64 - actorId: - type: string - title: actor_id - decisionAccepted: - type: boolean - title: decision_accepted - evidence: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessProcessParticipant' - title: evidence - followUpProcessIds: - type: array - items: - type: string - title: follow_up_process_ids - recordedAt: - type: string - title: recorded_at - title: BusinessProcessReceipt - additionalProperties: false - console.v1.BusinessProcessRequirement: - type: object - properties: - requirementId: - type: string - title: requirement_id - label: - type: string - title: label - roleId: - type: string - title: role_id - expected: - title: expected - description: Equality uses the declared schema's typed value. No expression strings. - $ref: '#/components/schemas/console.v1.BusinessFieldValue' - maxAgeSeconds: - type: - - integer - - string - title: max_age_seconds - format: int64 - description: Zero disables age checking; positive ages apply to the record's updated_at. - requirePresent: - type: boolean - title: require_present - description: Requires a populated field instead of equality; expected carries only field_id. - title: BusinessProcessRequirement - additionalProperties: false - console.v1.BusinessProcessTransition: - type: object - properties: - transitionId: - type: string - title: transition_id - name: - type: string - title: name - fromState: - type: string - title: from_state - toState: - type: string - title: to_state - requirements: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessProcessRequirement' - title: requirements - requiresDecision: - type: boolean - title: requires_decision - description: Requires the instance's assigned human decision maker to accept explicitly. - followUps: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessProcessFollowUp' - title: follow_ups - description: Follow-up obligations are durable child processes admitted atomically. - title: BusinessProcessTransition - additionalProperties: false - console.v1.BusinessRelationshipDefinition: - type: object - properties: - relationshipId: - type: string - title: relationship_id - name: - type: string - title: name - targetTypeId: - type: string - title: target_type_id - title: BusinessRelationshipDefinition - additionalProperties: false - console.v1.BusinessSourceBinding: - type: object - properties: - resourceId: - type: string - title: resource_id - connectionId: - type: string - title: connection_id - groupIds: - type: array - items: - type: string - title: group_ids - fields: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessSourceField' - title: fields - authorityEpoch: - type: - - integer - - string - title: authority_epoch - format: int64 - generation: - type: - - integer - - string - title: generation - format: int64 - state: - title: state - $ref: '#/components/schemas/console.v1.BusinessSourceState' - observedDigest: - type: string - title: observed_digest - observedAt: - type: string - title: observed_at - familyStableId: - type: string - title: family_stable_id - recordId: - type: string - title: record_id - sourceEventId: - type: string - title: source_event_id - envelope: - title: envelope - $ref: '#/components/schemas/connectors.v1.ProviderResourceEnvelope' - title: BusinessSourceBinding - additionalProperties: false - console.v1.BusinessSourceField: - type: object - properties: - fieldId: - type: string - title: field_id - property: - title: property - $ref: '#/components/schemas/console.v1.BusinessSourceProperty' - title: BusinessSourceField - additionalProperties: false - console.v1.BusinessTextList: - type: object - properties: - values: - type: array - items: - type: string - title: values - title: BusinessTextList - additionalProperties: false - console.v1.CancelComputerMissionRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - missionId: - type: string - title: mission_id - minLength: 1 - reason: - type: string - title: reason - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: CancelComputerMissionRequest - required: - - query - additionalProperties: false - console.v1.CancelComputerMissionResponse: - type: object - properties: - mission: - title: mission - $ref: '#/components/schemas/console.v1.ComputerMission' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.OperatingReceipt' - title: CancelComputerMissionResponse - required: - - mission - - receipt - additionalProperties: false - console.v1.CaptureForm: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - formId: - type: string - title: form_id - minLength: 1 - name: - type: string - title: name - maxLength: 160 - minLength: 1 - description: - type: string - title: description - maxLength: 2000 - state: - title: state - $ref: '#/components/schemas/console.v1.CaptureFormState' - currentVersionId: - type: string - title: current_version_id - minLength: 1 - currentRevision: - exclusiveMinimum: 0 - type: - - integer - - string - title: current_revision - format: int64 - objectTarget: - title: object_target - $ref: '#/components/schemas/console.v1.CaptureFormObjectTarget' - branding: - title: branding - $ref: '#/components/schemas/console.v1.CaptureFormBranding' - publications: - type: array - items: - $ref: '#/components/schemas/console.v1.CaptureFormPublication' - title: publications - maxItems: 32 - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: CaptureForm - required: - - objectTarget - additionalProperties: false - console.v1.CaptureFormAnswer: - type: object - properties: - inputId: - type: string - title: input_id - maxLength: 80 - minLength: 1 - value: - title: value - $ref: '#/components/schemas/console.v1.CaptureFormTypedValue' - title: CaptureFormAnswer - required: - - value - additionalProperties: false - console.v1.CaptureFormAssetRef: - type: object - properties: - objectId: - type: string - title: object_id - maxLength: 255 - minLength: 1 - versionId: - type: string - title: version_id - maxLength: 255 - minLength: 1 - title: CaptureFormAssetRef - additionalProperties: false - description: |- - CaptureFormAssetRef references immutable, tenant-owned VFS/artifact bytes. - The form contract never accepts embedded bytes or a caller-selected URL. - console.v1.CaptureFormBranding: - type: object - properties: - displayName: - type: string - title: display_name - maxLength: 120 - tagline: - type: string - title: tagline - maxLength: 160 - description: - type: string - title: description - maxLength: 2000 - accentColor: - type: string - title: accent_color - pattern: ^$|^#[0-9a-fA-F]{6}$ - logo: - title: logo - $ref: '#/components/schemas/console.v1.CaptureFormAssetRef' - favicon: - title: favicon - $ref: '#/components/schemas/console.v1.CaptureFormAssetRef' - brandingDigest: - type: string - title: branding_digest - maxLength: 128 - validationReceiptId: - type: string - title: validation_receipt_id - maxLength: 255 - showPoweredBy: - type: boolean - title: show_powered_by - title: CaptureFormBranding - additionalProperties: false - description: |- - CaptureFormBranding is the administrator projection. Validation receipts - and asset refs are intentionally absent from public presentation messages. - console.v1.CaptureFormBrandingInput: - type: object - properties: - displayName: - type: string - title: display_name - maxLength: 120 - tagline: - type: string - title: tagline - maxLength: 160 - description: - type: string - title: description - maxLength: 2000 - accentColor: - type: string - title: accent_color - pattern: ^$|^#[0-9a-fA-F]{6}$ - logo: - title: logo - $ref: '#/components/schemas/console.v1.CaptureFormAssetRef' - favicon: - title: favicon - $ref: '#/components/schemas/console.v1.CaptureFormAssetRef' - showPoweredBy: - type: boolean - title: show_powered_by - title: CaptureFormBrandingInput - additionalProperties: false - console.v1.CaptureFormField: - type: object - oneOf: - - properties: - select: - title: select - $ref: '#/components/schemas/console.v1.CaptureFormSelectSpec' - title: select - required: - - select - - properties: - upload: - title: upload - $ref: '#/components/schemas/console.v1.CaptureFormUploadSpec' - title: upload - required: - - upload - properties: - select: - title: select - $ref: '#/components/schemas/console.v1.CaptureFormSelectSpec' - upload: - title: upload - $ref: '#/components/schemas/console.v1.CaptureFormUploadSpec' - inputId: - type: string - title: input_id - maxLength: 80 - minLength: 1 - label: - type: string - title: label - maxLength: 160 - minLength: 1 - helpText: - type: string - title: help_text - maxLength: 1000 - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/console.v1.CaptureFormFieldKind' - required: - type: boolean - title: required - position: - type: integer - title: position - maximum: 1024 - format: int32 - placeholder: - type: string - title: placeholder - maxLength: 240 - businessFieldId: - type: string - title: business_field_id - maxLength: 255 - mappingState: - not: - enum: - - 0 - title: mapping_state - $ref: '#/components/schemas/console.v1.CaptureFormMappingState' - maxLength: - type: integer - title: max_length - maximum: 8192 - format: int32 - minDecimal: - type: string - title: min_decimal - maxLength: 128 - maxDecimal: - type: string - title: max_decimal - maxLength: 128 - defaultValue: - title: default_value - $ref: '#/components/schemas/console.v1.CaptureFormTypedValue' - hidden: - type: boolean - title: hidden - title: CaptureFormField - additionalProperties: false - description: |- - CaptureFormField is the administrator-owned typed field/mapping definition. - business_field_id and hidden/default values never appear on public - projections. - console.v1.CaptureFormInvitation: - type: object - properties: - invitationId: - type: string - title: invitation_id - publicationId: - type: string - title: publication_id - recipientEmail: - type: string - title: recipient_email - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - state: - type: string - title: state - title: CaptureFormInvitation - additionalProperties: false - description: |- - Invitation IDs are opaque locators, never authentication. The owner requires - a live Identity access token with the exact verified recipient email. - console.v1.CaptureFormObjectResult: - type: object - properties: - resultId: - type: string - title: result_id - minLength: 1 - state: - title: state - $ref: '#/components/schemas/console.v1.CaptureFormObjectResultState' - objectId: - type: string - title: object_id - maxLength: 255 - objectTypeId: - type: string - title: object_type_id - maxLength: 255 - objectSchemaRevision: - type: - - integer - - string - title: object_schema_revision - format: int64 - objectRevision: - type: - - integer - - string - title: object_revision - format: int64 - mappingReceiptId: - type: string - title: mapping_receipt_id - maxLength: 255 - unmappedInputIds: - type: array - items: - type: string - maxItems: 64 - title: unmapped_input_ids - maxItems: 64 - title: CaptureFormObjectResult - additionalProperties: false - console.v1.CaptureFormObjectTarget: - type: object - properties: - typeId: - type: string - title: type_id - minLength: 1 - schemaRevision: - exclusiveMinimum: 0 - type: - - integer - - string - title: schema_revision - format: int64 - title: CaptureFormObjectTarget - additionalProperties: false - description: CaptureFormObjectTarget pins the business schema used by every version. - console.v1.CaptureFormPublicBranding: - type: object - properties: - displayName: - type: string - title: display_name - maxLength: 120 - tagline: - type: string - title: tagline - maxLength: 160 - description: - type: string - title: description - maxLength: 2000 - accentColor: - type: string - title: accent_color - pattern: ^$|^#[0-9a-fA-F]{6}$ - logoUrl: - type: string - title: logo_url - maxLength: 2048 - faviconUrl: - type: string - title: favicon_url - maxLength: 2048 - showPoweredBy: - type: boolean - title: show_powered_by - title: CaptureFormPublicBranding - additionalProperties: false - console.v1.CaptureFormPublicField: - type: object - oneOf: - - properties: - select: - title: select - $ref: '#/components/schemas/console.v1.CaptureFormSelectSpec' - title: select - required: - - select - - properties: - upload: - title: upload - $ref: '#/components/schemas/console.v1.CaptureFormUploadSpec' - title: upload - required: - - upload - properties: - select: - title: select - $ref: '#/components/schemas/console.v1.CaptureFormSelectSpec' - upload: - title: upload - $ref: '#/components/schemas/console.v1.CaptureFormUploadSpec' - inputId: - type: string - title: input_id - maxLength: 80 - minLength: 1 - label: - type: string - title: label - maxLength: 160 - minLength: 1 - helpText: - type: string - title: help_text - maxLength: 1000 - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/console.v1.CaptureFormFieldKind' - required: - type: boolean - title: required - position: - type: integer - title: position - format: int32 - placeholder: - type: string - title: placeholder - maxLength: 240 - maxLength: - type: integer - title: max_length - maximum: 8192 - format: int32 - title: CaptureFormPublicField - additionalProperties: false - console.v1.CaptureFormPublicRoute: - type: object - properties: - hostname: - type: string - title: hostname - maxLength: 253 - path: - type: string - title: path - maxLength: 512 - embedPath: - type: string - title: embed_path - maxLength: 512 - customDomainId: - type: string - title: custom_domain_id - maxLength: 255 - allowedOrigins: - type: array - items: - type: string - maxItems: 32 - title: allowed_origins - maxItems: 32 - embedEnabled: - type: boolean - title: embed_enabled - title: CaptureFormPublicRoute - additionalProperties: false - description: |- - CaptureFormPublicRoute is server-derived white-label routing metadata. A - caller supplies only a slug and an existing custom-domain reference. - console.v1.CaptureFormPublicSubmissionReceipt: - type: object - properties: - submissionId: - type: string - title: submission_id - minLength: 1 - resultId: - type: string - title: result_id - maxLength: 255 - state: - title: state - $ref: '#/components/schemas/console.v1.CaptureFormSubmissionState' - submittedAt: - title: submitted_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: CaptureFormPublicSubmissionReceipt - additionalProperties: false - description: |- - Public receipt deliberately excludes tenant coordinates, answers, owner - references, and the internal BusinessObject identity. - console.v1.CaptureFormPublication: - type: object - properties: - publicationId: - type: string - title: publication_id - minLength: 1 - description: |- - Server-generated opaque id used in a public form URL. It is stable across - admin reloads and idempotent publish retries; it is never caller-selected - as a tenant or workspace coordinate. - formId: - type: string - title: form_id - minLength: 1 - versionId: - type: string - title: version_id - minLength: 1 - state: - title: state - $ref: '#/components/schemas/console.v1.CaptureFormPublicationState' - generation: - exclusiveMinimum: 0 - type: - - integer - - string - title: generation - format: int64 - slug: - type: string - title: slug - maxLength: 80 - route: - title: route - $ref: '#/components/schemas/console.v1.CaptureFormPublicRoute' - publishedAt: - title: published_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - revokedAt: - title: revoked_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - invitationOnly: - type: boolean - title: invitation_only - title: CaptureFormPublication - additionalProperties: false - console.v1.CaptureFormPublicationInput: - type: object - properties: - slug: - type: string - title: slug - maxLength: 80 - minLength: 1 - pattern: ^[a-z0-9]+(?:-[a-z0-9]+)*$ - customDomainId: - type: string - title: custom_domain_id - maxLength: 255 - allowedOrigins: - type: array - items: - type: string - maxLength: 2048 - maxItems: 32 - title: allowed_origins - maxItems: 32 - embedEnabled: - type: boolean - title: embed_enabled - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - invitationOnly: - type: boolean - title: invitation_only - description: Refuses anonymous reads and submissions; answers require a recipient invitation. - title: CaptureFormPublicationInput - additionalProperties: false - console.v1.CaptureFormReview: - type: object - properties: - decision: - title: decision - $ref: '#/components/schemas/console.v1.CaptureFormReviewDecision' - reviewerId: - type: string - title: reviewer_id - maxLength: 255 - note: - type: string - title: note - maxLength: 4000 - reviewedAt: - title: reviewed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - supplementalValues: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessFieldValue' - title: supplemental_values - maxItems: 64 - description: |- - Typed native business-field values supplied by the reviewer for required - fields absent from the original intake. They are persisted with the - review and used only for accepted-object mapping; CaptureFormSubmission - answers always remain the original public answers unchanged. - title: CaptureFormReview - additionalProperties: false - console.v1.CaptureFormSelectOption: - type: object - properties: - optionId: - type: string - title: option_id - maxLength: 80 - minLength: 1 - label: - type: string - title: label - maxLength: 160 - minLength: 1 - description: - type: string - title: description - maxLength: 500 - disabled: - type: boolean - title: disabled - title: CaptureFormSelectOption - additionalProperties: false - console.v1.CaptureFormSelectSpec: - type: object - properties: - options: - type: array - items: - $ref: '#/components/schemas/console.v1.CaptureFormSelectOption' - title: options - maxItems: 128 - minItems: 1 - maxSelected: - type: integer - title: max_selected - maximum: 128 - minimum: 1 - format: int32 - title: CaptureFormSelectSpec - additionalProperties: false - console.v1.CaptureFormSubmission: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - submissionId: - type: string - title: submission_id - minLength: 1 - formId: - type: string - title: form_id - minLength: 1 - publicationId: - type: string - title: publication_id - minLength: 1 - versionId: - type: string - title: version_id - minLength: 1 - state: - title: state - $ref: '#/components/schemas/console.v1.CaptureFormSubmissionState' - answers: - type: array - items: - $ref: '#/components/schemas/console.v1.CaptureFormAnswer' - title: answers - maxItems: 64 - revision: - exclusiveMinimum: 0 - type: - - integer - - string - title: revision - format: int64 - review: - title: review - $ref: '#/components/schemas/console.v1.CaptureFormReview' - objectResult: - title: object_result - $ref: '#/components/schemas/console.v1.CaptureFormObjectResult' - submittedAt: - title: submitted_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: CaptureFormSubmission - additionalProperties: false - console.v1.CaptureFormTypedValue: - type: object - oneOf: - - properties: - artifact: - title: artifact - $ref: '#/components/schemas/console.v1.CaptureFormAssetRef' - title: artifact - required: - - artifact - - properties: - boolean: - type: boolean - title: boolean - title: boolean - required: - - boolean - - properties: - date: - type: string - title: date - maxLength: 32 - title: date - required: - - date - - properties: - datetime: - title: datetime - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: datetime - required: - - datetime - - properties: - decimal: - type: string - title: decimal - maxLength: 128 - title: decimal - required: - - decimal - - properties: - email: - type: string - title: email - maxLength: 320 - title: email - required: - - email - - properties: - integer: - type: - - integer - - string - title: integer - format: int64 - title: integer - required: - - integer - - properties: - optionId: - type: string - title: option_id - maxLength: 80 - title: option_id - required: - - optionId - - properties: - optionValues: - title: option_values - $ref: '#/components/schemas/console.v1.CaptureFormTypedValue.OptionValues' - title: option_values - required: - - optionValues - - properties: - phone: - type: string - title: phone - maxLength: 64 - title: phone - required: - - phone - - properties: - text: - type: string - title: text - maxLength: 8192 - title: text - required: - - text - - properties: - url: - type: string - title: url - maxLength: 2048 - title: url - required: - - url - title: CaptureFormTypedValue - additionalProperties: false - description: |- - CaptureFormTypedValue is shared by hidden defaults and durable answers. A - multi-select is a typed repeated option message, never a delimiter-encoded - scalar string. - properties: - artifact: - title: artifact - $ref: '#/components/schemas/console.v1.CaptureFormAssetRef' - boolean: - type: boolean - title: boolean - date: - type: string - title: date - maxLength: 32 - datetime: - title: datetime - $ref: '#/components/schemas/google.protobuf.Timestamp' - decimal: - type: string - title: decimal - maxLength: 128 - email: - type: string - title: email - maxLength: 320 - integer: - type: - - integer - - string - title: integer - format: int64 - optionId: - type: string - title: option_id - maxLength: 80 - optionValues: - title: option_values - $ref: '#/components/schemas/console.v1.CaptureFormTypedValue.OptionValues' - phone: - type: string - title: phone - maxLength: 64 - text: - type: string - title: text - maxLength: 8192 - url: - type: string - title: url - maxLength: 2048 - console.v1.CaptureFormTypedValue.OptionValues: - type: object - properties: - optionIds: - type: array - items: - type: string - maxLength: 80 - minLength: 1 - maxItems: 128 - title: option_ids - maxItems: 128 - minItems: 1 - title: OptionValues - additionalProperties: false - console.v1.CaptureFormUpload: - type: object - properties: - uploadId: - type: string - title: upload_id - minLength: 1 - inputId: - type: string - title: input_id - maxLength: 80 - minLength: 1 - filename: - type: string - title: filename - maxLength: 255 - minLength: 1 - contentType: - type: string - title: content_type - maxLength: 255 - minLength: 1 - sizeBytes: - exclusiveMinimum: 0 - type: - - integer - - string - title: size_bytes - maximum: 52428800 - format: int64 - sha256: - type: string - title: sha256 - pattern: ^[0-9a-f]{64}$ - state: - title: state - $ref: '#/components/schemas/console.v1.CaptureFormUploadState' - asset: - title: asset - $ref: '#/components/schemas/console.v1.CaptureFormAssetRef' - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: CaptureFormUpload - additionalProperties: false - description: |- - CaptureFormUpload is a public, publication-scoped upload grant projection. - The lease token is returned only by BeginPublishedCaptureFormUpload and is - never persisted or included in this durable projection. - console.v1.CaptureFormUploadSpec: - type: object - properties: - acceptedContentTypes: - type: array - items: - type: string - maxLength: 128 - maxItems: 32 - title: accepted_content_types - maxItems: 32 - maxSizeBytes: - exclusiveMinimum: 0 - type: - - integer - - string - title: max_size_bytes - maximum: 52428800 - format: int64 - maxFiles: - type: integer - title: max_files - format: int32 - const: 1 - title: CaptureFormUploadSpec - additionalProperties: false - console.v1.CaptureFormVersion: - type: object - properties: - formId: - type: string - title: form_id - minLength: 1 - versionId: - type: string - title: version_id - minLength: 1 - revision: - exclusiveMinimum: 0 - type: - - integer - - string - title: revision - format: int64 - objectTarget: - title: object_target - $ref: '#/components/schemas/console.v1.CaptureFormObjectTarget' - fields: - type: array - items: - $ref: '#/components/schemas/console.v1.CaptureFormField' - title: fields - maxItems: 64 - branding: - title: branding - $ref: '#/components/schemas/console.v1.CaptureFormBranding' - schemaDigest: - type: string - title: schema_digest - maxLength: 128 - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - createdBy: - type: string - title: created_by - maxLength: 255 - title: CaptureFormVersion - required: - - objectTarget - additionalProperties: false - description: |- - CaptureFormVersion is immutable after acceptance. Every public publication - stores and returns its exact version_id and schema revision. - console.v1.CaptureFormVersionInput: - type: object - properties: - objectTarget: - title: object_target - $ref: '#/components/schemas/console.v1.CaptureFormObjectTarget' - fields: - type: array - items: - $ref: '#/components/schemas/console.v1.CaptureFormField' - title: fields - maxItems: 64 - minItems: 1 - branding: - title: branding - $ref: '#/components/schemas/console.v1.CaptureFormBrandingInput' - title: CaptureFormVersionInput - required: - - objectTarget - - branding - additionalProperties: false - console.v1.CloneAgentProductRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - sourceAgentId: - type: string - title: source_agent_id - minLength: 1 - sourceConfigVersion: - exclusiveMinimum: 0 - type: integer - title: source_config_version - format: int32 - name: - type: string - title: name - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: CloneAgentProductRequest - additionalProperties: false - console.v1.CloneAgentProductResponse: - type: object - properties: - agent: - title: agent - $ref: '#/components/schemas/agents.v1.Agent' - config: - title: config - $ref: '#/components/schemas/agents.v1.AgentConfig' - title: CloneAgentProductResponse - additionalProperties: false - console.v1.CloneBusinessBlueprintRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - blueprintId: - type: string - title: blueprint_id - minLength: 1 - version: - exclusiveMinimum: 0 - type: - - integer - - string - title: version - format: int64 - contentDigest: - type: string - title: content_digest - pattern: ^[0-9a-f]{64}$ - name: - type: string - title: name - maxLength: 120 - minLength: 1 - title: CloneBusinessBlueprintRequest - additionalProperties: false - console.v1.CloneBusinessBlueprintResponse: - type: object - properties: - blueprintId: - type: string - title: blueprint_id - blueprintVersion: - type: - - integer - - string - title: blueprint_version - format: int64 - contentDigest: - type: string - title: content_digest - cloneId: - type: string - title: clone_id - description: Server-assigned UUID, stable for an identical idempotent request. - objectTypes: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessObjectType' - title: object_types - process: - title: process - $ref: '#/components/schemas/console.v1.BusinessProcessDefinition' - form: - title: form - $ref: '#/components/schemas/console.v1.CaptureForm' - automatedExecutionAvailable: - type: boolean - title: automated_execution_available - description: |- - Definitions are available for editing. Publication, execution and external - effects require their existing owner admission and are not implied here. - title: CloneBusinessBlueprintResponse - additionalProperties: false - console.v1.CodingAcceptanceContract: - type: object - properties: - taskId: - type: string - title: task_id - maxLength: 256 - repositoryId: - type: string - title: repository_id - maxLength: 512 - minLength: 1 - generation: - exclusiveMinimum: 0 - type: - - integer - - string - title: generation - format: int64 - requiredAssertionIds: - type: array - items: - type: string - maxItems: 128 - title: required_assertion_ids - maxItems: 128 - minItems: 1 - requireReview: - type: boolean - title: require_review - requireBehavior: - type: boolean - title: require_behavior - readinessRequirements: - type: array - items: - type: string - maxItems: 128 - title: readiness_requirements - maxItems: 128 - authorizedSkips: - type: array - items: - type: string - maxItems: 128 - title: authorized_skips - maxItems: 128 - authorizedDispositions: - type: array - items: - type: string - maxItems: 128 - title: authorized_dispositions - maxItems: 128 - outputPaths: - type: array - items: - type: string - maxItems: 8 - title: output_paths - maxItems: 8 - title: CodingAcceptanceContract - additionalProperties: false - description: |- - Explicit acceptance requirements for a coding task. Platform binds task_id - to the resolved conversation task; clients may leave it empty for new work. - These requirements grant no tool, repository-access, or approval authority. - console.v1.Commitment: - type: object - properties: - commitmentId: - type: string - title: commitment_id - title: - type: string - title: title - status: - type: string - title: status - conditionOfSatisfaction: - type: string - title: condition_of_satisfaction - dueAt: - title: due_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - noDateRationale: - type: string - title: no_date_rationale - description: |- - no_date_rationale explains why a commitment carries no due date. Empty - when due_at is set or when the ledger records no rationale. - ownerEmail: - type: string - title: owner_email - citations: - type: array - items: - $ref: '#/components/schemas/console.v1.CommitmentCitation' - title: citations - maxItems: 64 - observedAt: - title: observed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - meetingCaptureId: - type: string - title: meeting_capture_id - description: |- - meeting_capture_id is set when a meeting_binding citation resolves to a - meeting capture binding in this workspace. - title: Commitment - additionalProperties: false - description: |- - Commitment is the read projection of one tracked commitment. Every field is - carried from the commitment ledger; the citations are the evidence entries - the commitment was extracted from, not a summary written here. - console.v1.CommitmentCitation: - type: object - properties: - kind: - type: string - title: kind - sourceKind: - type: string - title: source_kind - sourceId: - type: string - title: source_id - sourceUri: - type: string - title: source_uri - excerpt: - type: string - title: excerpt - maxLength: 2000 - observedAt: - title: observed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: CommitmentCitation - additionalProperties: false - description: CommitmentCitation is one evidence entry the commitment was extracted from. - console.v1.CompareScenarioFixturesRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - baseFixtureId: - type: string - title: base_fixture_id - minLength: 1 - targetFixtureId: - type: string - title: target_fixture_id - minLength: 1 - maxDifferences: - type: integer - title: max_differences - maximum: 100 - format: int32 - title: CompareScenarioFixturesRequest - additionalProperties: false - console.v1.CompareScenarioFixturesResponse: - type: object - properties: - baseFixture: - title: base_fixture - $ref: '#/components/schemas/console.v1.ScenarioFixture' - targetFixture: - title: target_fixture - $ref: '#/components/schemas/console.v1.ScenarioFixture' - sharedPrefixFrames: - type: integer - title: shared_prefix_frames - format: int32 - baseFrameCount: - type: integer - title: base_frame_count - format: int32 - targetFrameCount: - type: integer - title: target_frame_count - format: int32 - firstDivergencePath: - type: string - title: first_divergence_path - firstDivergenceSummary: - type: string - title: first_divergence_summary - differences: - type: array - items: - $ref: '#/components/schemas/console.v1.ScenarioFixtureDifference' - title: differences - title: CompareScenarioFixturesResponse - additionalProperties: false - console.v1.CompleteDexMcpOAuthProfileRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - serverId: - type: string - title: server_id - minLength: 1 - profileId: - type: string - title: profile_id - minLength: 1 - state: - type: string - title: state - minLength: 1 - code: - type: string - title: code - description: |- - Empty code is permitted only for a provider error response; the - Connector validates the raw iss binding before acting on any error text. - redirectUri: - type: string - title: redirect_uri - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - profileGeneration: - exclusiveMinimum: 0 - type: - - integer - - string - title: profile_generation - format: int64 - authorizationResponseIss: - type: string - title: authorization_response_iss - description: |- - Raw RFC 9207 authorization response fields forwarded unchanged to the - Connector for validation. - providerError: - type: string - title: provider_error - providerErrorDescription: - type: string - title: provider_error_description - providerErrorUri: - type: string - title: provider_error_uri - title: CompleteDexMcpOAuthProfileRequest - required: - - query - additionalProperties: false - console.v1.CompleteDexMcpOAuthProfileResponse: - type: object - properties: - profile: - title: profile - $ref: '#/components/schemas/console.v1.DexMcpOAuthProfile' - title: CompleteDexMcpOAuthProfileResponse - required: - - profile - additionalProperties: false - console.v1.CompleteInferenceCreditAutoRefillRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - setupSessionId: - type: string - title: setup_session_id - minLength: 1 - title: CompleteInferenceCreditAutoRefillRequest - additionalProperties: false - console.v1.CompleteInferenceCreditAutoRefillResponse: - type: object - properties: - enabled: - type: boolean - title: enabled - title: CompleteInferenceCreditAutoRefillResponse - additionalProperties: false - console.v1.CompleteOperatingAttachmentUploadRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - minLength: 1 - attachmentId: - type: string - title: attachment_id - minLength: 1 - leaseId: - type: string - title: lease_id - minLength: 1 - leaseToken: - type: string - title: lease_token - minLength: 1 - fencingToken: - type: - - integer - - string - title: fencing_token - minimum: 1 - format: int64 - sizeBytes: - exclusiveMinimum: 0 - type: - - integer - - string - title: size_bytes - maximum: 52428800 - format: int64 - sha256: - type: string - title: sha256 - minLength: 1 - storageEtag: - type: string - title: storage_etag - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - completedParts: - type: array - items: - $ref: '#/components/schemas/vfs.v1.VfsCompletedUploadPart' - title: completed_parts - maxItems: 10000 - title: CompleteOperatingAttachmentUploadRequest - required: - - query - additionalProperties: false - console.v1.CompleteOperatingAttachmentUploadResponse: - type: object - properties: - attachment: - title: attachment - $ref: '#/components/schemas/console.v1.OperatingAttachmentRef' - title: CompleteOperatingAttachmentUploadResponse - additionalProperties: false - console.v1.CompletePublishedCaptureFormUploadRequest: - type: object - properties: - publicationId: - type: string - title: publication_id - minLength: 1 - inputId: - type: string - title: input_id - maxLength: 80 - minLength: 1 - uploadId: - type: string - title: upload_id - minLength: 1 - leaseId: - type: string - title: lease_id - minLength: 1 - leaseToken: - type: string - title: lease_token - maxLength: 512 - minLength: 1 - fencingToken: - exclusiveMinimum: 0 - type: - - integer - - string - title: fencing_token - format: int64 - sizeBytes: - exclusiveMinimum: 0 - type: - - integer - - string - title: size_bytes - maximum: 52428800 - format: int64 - sha256: - type: string - title: sha256 - pattern: ^[0-9a-f]{64}$ - storageEtag: - type: string - title: storage_etag - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - completedParts: - type: array - items: - $ref: '#/components/schemas/vfs.v1.VfsCompletedUploadPart' - title: completed_parts - maxItems: 10000 - title: CompletePublishedCaptureFormUploadRequest - additionalProperties: false - console.v1.CompletePublishedCaptureFormUploadResponse: - type: object - properties: - upload: - title: upload - $ref: '#/components/schemas/console.v1.CaptureFormUpload' - title: CompletePublishedCaptureFormUploadResponse - required: - - upload - additionalProperties: false - console.v1.ComplianceAssessmentRecord: - type: object - properties: - id: - type: string - title: id - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - evaluatorVersion: - type: string - title: evaluator_version - assessment: - title: assessment - $ref: '#/components/schemas/console.v1.ComplianceSubjectAssessment' - manifestDigest: - type: string - title: manifest_digest - recordedByPrincipalId: - type: string - title: recorded_by_principal_id - title: ComplianceAssessmentRecord - additionalProperties: false - console.v1.ComplianceRequirementFinding: - type: object - properties: - requirementId: - type: string - title: requirement_id - status: - title: status - $ref: '#/components/schemas/console.v1.ComplianceFindingStatus' - reasonCode: - type: string - title: reason_code - sourceRef: - type: string - title: source_ref - title: ComplianceRequirementFinding - additionalProperties: false - console.v1.ComplianceSubjectAssessment: - type: object - properties: - profileId: - type: string - title: profile_id - subjectKind: - type: string - title: subject_kind - subjectId: - type: string - title: subject_id - sourceDigest: - type: string - title: source_digest - sourceUpdatedAt: - title: source_updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - assessedAt: - title: assessed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - status: - title: status - $ref: '#/components/schemas/console.v1.ComplianceFindingStatus' - findings: - type: array - items: - $ref: '#/components/schemas/console.v1.ComplianceRequirementFinding' - title: findings - inspectedCount: - type: integer - title: inspected_count - description: This route covers exactly the one requested owner record. - expectedCount: - type: integer - title: expected_count - controlId: - type: string - title: control_id - title: ComplianceSubjectAssessment - additionalProperties: false - description: A live, bounded assessment of one execution. It is not an immutable snapshot. - console.v1.ComputerMission: - type: object - properties: - missionId: - type: string - title: mission_id - minLength: 1 - workId: - type: string - title: work_id - minLength: 1 - contract: - title: contract - $ref: '#/components/schemas/console.v1.ComputerMissionContract' - state: - title: state - $ref: '#/components/schemas/console.v1.ComputerMissionState' - completedSteps: - type: integer - title: completed_steps - completedToolCalls: - type: integer - title: completed_tool_calls - consumedTokens: - type: - - integer - - string - title: consumed_tokens - format: int64 - consumedCostMicros: - type: - - integer - - string - title: consumed_cost_micros - format: int64 - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - blocker: - type: string - title: blocker - nextAction: - type: string - title: next_action - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - tenantScopeId: - type: string - title: tenant_scope_id - minLength: 1 - authorityGrantId: - type: string - title: authority_grant_id - minLength: 1 - contractVersion: - type: string - title: contract_version - minLength: 1 - contractDigestSha256: - type: string - title: contract_digest_sha256 - pattern: ^[0-9a-f]{64}$ - runtimeRunId: - type: string - title: runtime_run_id - description: Empty until Platform Worker has created the authoritative runtime row. - activeGeneration: - type: - - integer - - string - title: active_generation - format: int64 - description: Monotonically increases whenever the mission is queued for new execution. - longHorizonBudget: - title: long_horizon_budget - $ref: '#/components/schemas/console.v1.ComputerMissionLongHorizonBudgetState' - title: ComputerMission - required: - - contract - - createdAt - - updatedAt - additionalProperties: false - console.v1.ComputerMissionApexInstructionMetadata: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - reservationId: - type: string - title: reservation_id - minLength: 1 - attemptId: - type: string - title: attempt_id - minLength: 1 - instructionArtifactRef: - type: string - title: instruction_artifact_ref - minLength: 1 - instructionDigestSha256: - type: string - title: instruction_digest_sha256 - pattern: ^[0-9a-f]{64}$ - instructionByteCount: - type: - - integer - - string - title: instruction_byte_count - maximum: 1048576 - minimum: 1 - format: int64 - state: - type: string - title: state - const: instruction_bound - title: ComputerMissionApexInstructionMetadata - additionalProperties: false - console.v1.ComputerMissionApexRunnerBinding: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - runnerSessionId: - type: string - title: runner_session_id - minLength: 1 - sandboxId: - type: string - title: sandbox_id - minLength: 1 - initialCheckpointId: - type: string - title: initial_checkpoint_id - minLength: 1 - initialSnapshotId: - type: string - title: initial_snapshot_id - minLength: 1 - workloadDigest: - type: string - title: workload_digest - pattern: ^sha256:[0-9a-f]{64}$ - provider: - type: string - title: provider - minLength: 1 - providerMode: - type: string - title: provider_mode - const: apply - reservationId: - type: string - title: reservation_id - minLength: 1 - instructionArtifactRef: - type: string - title: instruction_artifact_ref - minLength: 1 - instructionDigestSha256: - type: string - title: instruction_digest_sha256 - pattern: ^[0-9a-f]{64}$ - instructionByteCount: - type: - - integer - - string - title: instruction_byte_count - maximum: 1048576 - minimum: 1 - format: int64 - title: ComputerMissionApexRunnerBinding - additionalProperties: false - console.v1.ComputerMissionApexSessionReservation: - type: object - properties: - reservationId: - type: string - title: reservation_id - minLength: 1 - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - packRunId: - type: string - title: pack_run_id - minLength: 1 - attemptId: - type: string - title: attempt_id - minLength: 1 - runIndex: - type: integer - title: run_index - decisionRef: - type: string - title: decision_ref - minLength: 1 - decisionDigestSha256: - type: string - title: decision_digest_sha256 - pattern: ^[0-9a-f]{64}$ - runnerProfile: - type: string - title: runner_profile - minLength: 1 - workloadDigest: - type: string - title: workload_digest - pattern: ^sha256:[0-9a-f]{64}$ - runnerSessionId: - type: string - title: runner_session_id - state: - type: string - title: state - pattern: ^(reserved|session_bound|adoption_authorized)$ - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: ComputerMissionApexSessionReservation - required: - - expiresAt - additionalProperties: false - console.v1.ComputerMissionAuthorityGrant: - type: object - properties: - mode: - not: - enum: - - 0 - title: mode - $ref: '#/components/schemas/console.v1.ComputerMissionAuthorityMode' - grantedBy: - type: string - title: granted_by - minLength: 1 - grantedAt: - title: granted_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - confirmationVersion: - type: string - title: confirmation_version - const: dex.mission_authority_confirmation.v1 - title: ComputerMissionAuthorityGrant - required: - - grantedAt - additionalProperties: false - console.v1.ComputerMissionBudget: - type: object - properties: - maxSteps: - exclusiveMinimum: 0 - type: integer - title: max_steps - wallClockBudgetSeconds: - exclusiveMinimum: 0 - type: - - integer - - string - title: wall_clock_budget_seconds - format: int64 - tokenBudget: - exclusiveMinimum: 0 - type: - - integer - - string - title: token_budget - format: int64 - maxToolCalls: - exclusiveMinimum: 0 - type: integer - title: max_tool_calls - maxCostMicros: - exclusiveMinimum: 0 - type: - - integer - - string - title: max_cost_micros - format: int64 - title: ComputerMissionBudget - additionalProperties: false - console.v1.ComputerMissionCanaryDefinition: - type: object - properties: - definitionId: - type: string - title: definition_id - minLength: 1 - version: - exclusiveMinimum: 0 - type: integer - title: version - scenarioKind: - not: - enum: - - 0 - title: scenario_kind - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryScenarioKind' - objective: - type: string - title: objective - minLength: 1 - enabledEnvironments: - type: array - items: - type: string - title: enabled_environments - minItems: 1 - fixtureResourceIds: - type: array - items: - type: string - title: fixture_resource_ids - minItems: 1 - requiredCanaryTags: - type: array - items: - type: string - title: required_canary_tags - minItems: 1 - requiredCapabilities: - type: array - items: - type: string - title: required_capabilities - minItems: 1 - runnerProfile: - type: string - title: runner_profile - minLength: 1 - authorityMode: - not: - enum: - - 0 - title: authority_mode - $ref: '#/components/schemas/console.v1.ComputerMissionAuthorityMode' - maximumGrantDurationSeconds: - exclusiveMinimum: 0 - type: - - integer - - string - title: maximum_grant_duration_seconds - format: int64 - budget: - title: budget - $ref: '#/components/schemas/console.v1.ComputerMissionBudget' - requiredEvidenceGates: - type: array - items: - $ref: '#/components/schemas/console.v1.ComputerMissionEvidenceGate' - title: required_evidence_gates - minItems: 1 - expectedForwardEffects: - type: array - items: - type: string - title: expected_forward_effects - minItems: 1 - requiredCompensatingEffects: - type: array - items: - $ref: '#/components/schemas/console.v1.ComputerMissionCompensatingAction' - title: required_compensating_effects - minItems: 1 - thresholds: - type: array - items: - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryThreshold' - title: thresholds - minItems: 1 - hardSafetyGates: - type: array - items: - $ref: '#/components/schemas/console.v1.ComputerMissionEvidenceGate' - title: hard_safety_gates - minItems: 1 - plannerVersion: - type: string - title: planner_version - minLength: 1 - runtimeVersion: - type: string - title: runtime_version - minLength: 1 - toolContractVersion: - type: string - title: tool_contract_version - minLength: 1 - title: ComputerMissionCanaryDefinition - required: - - budget - additionalProperties: false - console.v1.ComputerMissionCanaryDimensionResult: - type: object - properties: - dimension: - not: - enum: - - 0 - title: dimension - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryScoreDimension' - score: - type: number - title: score - maximum: 100 - format: double - weight: - type: integer - title: weight - title: ComputerMissionCanaryDimensionResult - additionalProperties: false - console.v1.ComputerMissionCanaryEffect: - type: object - properties: - effectId: - type: string - title: effect_id - minLength: 1 - state: - not: - enum: - - 0 - title: state - $ref: '#/components/schemas/console.v1.ComputerMissionEffectState' - capability: - type: string - title: capability - minLength: 1 - resourceId: - type: string - title: resource_id - minLength: 1 - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - forwardExecutionId: - type: string - title: forward_execution_id - forwardIdempotencyKey: - type: string - title: forward_idempotency_key - rollbackExecutionId: - type: string - title: rollback_execution_id - rollbackIdempotencyKey: - type: string - title: rollback_idempotency_key - recoveryAction: - type: string - title: recovery_action - recordedAt: - title: recorded_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: ComputerMissionCanaryEffect - additionalProperties: false - console.v1.ComputerMissionCanaryEvaluation: - type: object - properties: - evaluationId: - type: string - title: evaluation_id - minLength: 1 - evaluatorVersion: - type: string - title: evaluator_version - minLength: 1 - recommendation: - not: - enum: - - 0 - title: recommendation - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryRecommendation' - aggregateScore: - type: number - title: aggregate_score - maximum: 100 - format: double - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - dimensions: - type: array - items: - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryDimensionResult' - title: dimensions - hardGates: - type: array - items: - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryHardGateResult' - title: hard_gates - policyVersion: - type: string - title: policy_version - plannerVersion: - type: string - title: planner_version - runtimeVersion: - type: string - title: runtime_version - toolContractVersion: - type: string - title: tool_contract_version - definitionId: - type: string - title: definition_id - definitionVersion: - type: integer - title: definition_version - title: ComputerMissionCanaryEvaluation - additionalProperties: false - console.v1.ComputerMissionCanaryHardGateResult: - type: object - properties: - gateId: - type: string - title: gate_id - minLength: 1 - passed: - type: boolean - title: passed - title: ComputerMissionCanaryHardGateResult - additionalProperties: false - console.v1.ComputerMissionCanaryOperatorAction: - type: object - properties: - actionId: - type: string - title: action_id - minLength: 1 - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryOperatorActionKind' - actorId: - type: string - title: actor_id - minLength: 1 - reason: - type: string - title: reason - minLength: 1 - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - scopeBefore: - title: scope_before - $ref: '#/components/schemas/console.v1.ComputerMissionScope' - scopeAfter: - title: scope_after - $ref: '#/components/schemas/console.v1.ComputerMissionScope' - budgetBefore: - title: budget_before - $ref: '#/components/schemas/console.v1.ComputerMissionBudget' - budgetAfter: - title: budget_after - $ref: '#/components/schemas/console.v1.ComputerMissionBudget' - grantExpiresAtBefore: - title: grant_expires_at_before - $ref: '#/components/schemas/google.protobuf.Timestamp' - grantExpiresAtAfter: - title: grant_expires_at_after - $ref: '#/components/schemas/google.protobuf.Timestamp' - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - title: ComputerMissionCanaryOperatorAction - required: - - occurredAt - additionalProperties: false - console.v1.ComputerMissionCanaryRun: - type: object - properties: - canaryRunId: - type: string - title: canary_run_id - minLength: 1 - canaryDefinitionId: - type: string - title: canary_definition_id - minLength: 1 - missionId: - type: string - title: mission_id - minLength: 1 - state: - not: - enum: - - 0 - title: state - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryRunState' - scope: - title: scope - $ref: '#/components/schemas/console.v1.ComputerMissionScope' - budget: - title: budget - $ref: '#/components/schemas/console.v1.ComputerMissionBudget' - grantExpiresAt: - title: grant_expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - recommendation: - title: recommendation - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryRecommendation' - title: ComputerMissionCanaryRun - required: - - scope - - budget - - grantExpiresAt - additionalProperties: false - console.v1.ComputerMissionCanaryThreshold: - type: object - properties: - dimension: - not: - enum: - - 0 - title: dimension - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryScoreDimension' - minimumScore: - type: number - title: minimum_score - maximum: 100 - format: double - title: ComputerMissionCanaryThreshold - additionalProperties: false - console.v1.ComputerMissionCapability: - type: object - properties: - name: - type: string - title: name - pattern: ^apex\.[a-z0-9_.-]+$ - inputSchema: - title: input_schema - $ref: '#/components/schemas/google.protobuf.Struct' - observerName: - type: string - title: observer_name - pattern: ^apex\.[a-z0-9_.-]+$ - schemaDigestSha256: - type: string - title: schema_digest_sha256 - pattern: ^[0-9a-f]{64}$ - dispatchName: - type: string - title: dispatch_name - pattern: ^[a-z0-9_.-]+$ - description: |- - Exact raw FastMCP catalog name. Platform authority remains namespaced by - name; dispatch_name is never planner-selectable or derived by stripping. - title: ComputerMissionCapability - required: - - inputSchema - additionalProperties: false - console.v1.ComputerMissionCompensatingAction: - type: object - properties: - forwardCapability: - type: string - title: forward_capability - minLength: 1 - forwardResourceId: - type: string - title: forward_resource_id - minLength: 1 - forwardArgumentsDigest: - type: string - title: forward_arguments_digest - minLength: 1 - forwardPreconditions: - type: array - items: - type: string - title: forward_preconditions - rollbackCapability: - type: string - title: rollback_capability - minLength: 1 - rollbackArguments: - title: rollback_arguments - $ref: '#/components/schemas/google.protobuf.Struct' - rollbackVerificationPredicate: - type: string - title: rollback_verification_predicate - minLength: 1 - rollbackSafeToRetry: - type: boolean - title: rollback_safe_to_retry - maxRollbackAttempts: - exclusiveMinimum: 0 - type: integer - title: max_rollback_attempts - rollbackDeadlineSeconds: - exclusiveMinimum: 0 - type: - - integer - - string - title: rollback_deadline_seconds - format: int64 - forwardEvidencePredicate: - type: string - title: forward_evidence_predicate - minLength: 1 - cleanupEvidencePredicate: - type: string - title: cleanup_evidence_predicate - minLength: 1 - rollbackResourceId: - type: string - title: rollback_resource_id - minLength: 1 - rollbackArgumentBindings: - type: array - items: - $ref: '#/components/schemas/console.v1.ComputerMissionRollbackArgumentBinding' - title: rollback_argument_bindings - minItems: 1 - explicitRetryDenial: - type: boolean - title: explicit_retry_denial - title: ComputerMissionCompensatingAction - required: - - rollbackArguments - additionalProperties: false - console.v1.ComputerMissionContract: - type: object - properties: - goal: - type: string - title: goal - minLength: 1 - scope: - title: scope - $ref: '#/components/schemas/console.v1.ComputerMissionScope' - authority: - title: authority - $ref: '#/components/schemas/console.v1.ComputerMissionAuthorityGrant' - budget: - title: budget - $ref: '#/components/schemas/console.v1.ComputerMissionBudget' - requiredEvidence: - type: array - items: - type: string - title: required_evidence - runnerProfile: - type: string - title: runner_profile - minLength: 1 - resumeOfMissionId: - type: string - title: resume_of_mission_id - description: |- - resume_of_mission_id links a new mission and fresh budget to a failed or - budget-exhausted predecessor in the same tenant scope. - decision: - title: decision - $ref: '#/components/schemas/console.v1.ComputerMissionDecision' - title: ComputerMissionContract - required: - - scope - - authority - - budget - - decision - additionalProperties: false - description: |+ - required_evidence must be non-empty unless an APEX runner binding is present: - ``` - size(this.required_evidence) > 0 || has(this.scope.apex_runner_binding) - ``` - - console.v1.ComputerMissionDecision: - type: object - properties: - policyVersion: - type: string - title: policy_version - minLength: 1 - route: - not: - enum: - - 0 - title: route - $ref: '#/components/schemas/console.v1.ComputerMissionDecisionRoute' - selectedCandidateId: - type: string - title: selected_candidate_id - decisionRef: - type: string - title: decision_ref - minLength: 1 - decisionDigestSha256: - type: string - title: decision_digest_sha256 - pattern: ^[0-9a-f]{64}$ - title: ComputerMissionDecision - additionalProperties: false - description: |- - ComputerMissionDecision binds mission creation to the governed routing - decision that selected an execution candidate or deliberately selected no - route. decision_digest_sha256 is the digest of the owner-produced decision - record referenced by decision_ref. - console.v1.ComputerMissionEvidenceGate: - type: object - properties: - gateId: - type: string - title: gate_id - minLength: 1 - predicate: - type: string - title: predicate - minLength: 1 - hardSafetyGate: - type: boolean - title: hard_safety_gate - title: ComputerMissionEvidenceGate - additionalProperties: false - console.v1.ComputerMissionLongHorizonBudgetState: - type: object - properties: - deadlineAt: - title: deadline_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - authorityExpiresAt: - title: authority_expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - maxActiveRunnerSeconds: - type: - - integer - - string - title: max_active_runner_seconds - format: int64 - consumedActiveRunnerSeconds: - type: - - integer - - string - title: consumed_active_runner_seconds - format: int64 - maxRecoveries: - type: integer - title: max_recoveries - consumedRecoveries: - type: integer - title: consumed_recoveries - maxConsecutiveFailures: - type: integer - title: max_consecutive_failures - consecutiveFailures: - type: integer - title: consecutive_failures - title: ComputerMissionLongHorizonBudgetState - required: - - deadlineAt - additionalProperties: false - console.v1.ComputerMissionRollbackArgumentBinding: - type: object - properties: - argument: - type: string - title: argument - minLength: 1 - source: - not: - enum: - - 0 - title: source - $ref: '#/components/schemas/console.v1.ComputerMissionRollbackArgumentSource' - sourcePath: - type: string - title: source_path - minLength: 1 - title: ComputerMissionRollbackArgumentBinding - additionalProperties: false - console.v1.ComputerMissionScope: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - resourceIds: - type: array - items: - type: string - title: resource_ids - minItems: 1 - capabilities: - type: array - items: - type: string - title: capabilities - minItems: 1 - capabilityManifests: - type: array - items: - $ref: '#/components/schemas/console.v1.ComputerMissionCapability' - title: capability_manifests - apexRunnerBinding: - title: apex_runner_binding - $ref: '#/components/schemas/console.v1.ComputerMissionApexRunnerBinding' - title: ComputerMissionScope - additionalProperties: false - console.v1.ConnectedCall: - type: object - properties: - id: - type: string - title: id - minLength: 1 - title: - type: string - title: title - maxLength: 512 - meetUrl: - type: string - title: meet_url - format: uri - startsAt: - title: starts_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - endsAt: - title: ends_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: ConnectedCall - additionalProperties: false - description: |- - ConnectedCall is one upcoming call projected from the tenant's connected - calendar. The field name meet_url is a wire-compatibility alias; it carries - the call's join URL on whatever meeting platform hosts it. - console.v1.ConnectorProfile: - type: object - properties: - id: - type: string - title: id - minLength: 1 - providerId: - type: string - title: provider_id - minLength: 1 - profileName: - type: string - title: profile_name - minLength: 1 - scopes: - type: array - items: - type: string - title: scopes - enabled: - type: boolean - title: enabled - isDefault: - type: boolean - title: is_default - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: ConnectorProfile - additionalProperties: false - console.v1.ConnectorProfileScopeSet: - type: object - properties: - values: - type: array - items: - type: string - title: values - title: ConnectorProfileScopeSet - additionalProperties: false - console.v1.ConnectorTrigger: - type: object - properties: - triggerId: - type: string - title: trigger_id - minLength: 1 - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - name: - type: string - title: name - minLength: 1 - source: - not: - enum: - - 0 - title: source - $ref: '#/components/schemas/console.v1.ConnectorTriggerSource' - cronExpression: - type: string - title: cron_expression - connectionId: - type: string - title: connection_id - providerId: - type: string - title: provider_id - eventKind: - type: string - title: event_kind - payloadFieldAllowlist: - type: array - items: - type: string - title: payload_field_allowlist - template: - title: template - $ref: '#/components/schemas/console.v1.MissionScheduleTemplate' - enabled: - type: boolean - title: enabled - nextRunAt: - title: next_run_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - lastRunAt: - title: last_run_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - lastStatus: - type: string - title: last_status - lastMissionId: - type: string - title: last_mission_id - lastEventId: - type: string - title: last_event_id - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: ConnectorTrigger - required: - - template - - createdAt - - updatedAt - additionalProperties: false - description: |- - ConnectorTrigger is a governed mission template attached to a connector - event or schedule. `payload_field_allowlist` contains dotted JSON paths; - no event field outside this list is admitted to the mission context. - console.v1.ConsoleMetric: - type: object - properties: - id: - type: string - title: id - label: - type: string - title: label - value: - type: string - title: value - unit: - type: string - title: unit - detail: - type: string - title: detail - trend: - type: string - title: trend - tone: - type: string - title: tone - title: ConsoleMetric - additionalProperties: false - console.v1.ConsoleQuery: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - timeRange: - title: time_range - $ref: '#/components/schemas/console.v1.TimeRange' - environment: - type: string - title: environment - teamId: - type: string - title: team_id - owner: - type: string - title: owner - riskLevel: - title: risk_level - $ref: '#/components/schemas/common.v1.RiskLevel' - assetType: - type: string - title: asset_type - status: - type: string - title: status - limit: - type: integer - title: limit - maximum: 500 - format: int32 - offset: - type: integer - title: offset - format: int32 - search: - type: string - title: search - provider: - type: string - title: provider - organizationId: - type: string - title: organization_id - title: ConsoleQuery - additionalProperties: false - description: ConsoleQuery is shared by read endpoints. - console.v1.ConsoleSnapshotFreshness: - type: object - properties: - generatedAt: - title: generated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - staleAgeMs: - type: - - integer - - string - title: stale_age_ms - format: int64 - degradedServices: - type: array - items: - type: string - title: degraded_services - staleSections: - type: array - items: - type: string - title: stale_sections - title: ConsoleSnapshotFreshness - additionalProperties: false - console.v1.ContinueComputerMissionRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - missionId: - type: string - title: mission_id - minLength: 1 - answer: - type: string - title: answer - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: ContinueComputerMissionRequest - required: - - query - additionalProperties: false - console.v1.ContinueComputerMissionResponse: - type: object - properties: - mission: - title: mission - $ref: '#/components/schemas/console.v1.ComputerMission' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.OperatingReceipt' - title: ContinueComputerMissionResponse - required: - - mission - - receipt - additionalProperties: false - console.v1.CorrectWorkspaceMemoryRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - memoryId: - type: string - title: memory_id - minLength: 1 - expectedRevision: - type: - - integer - - string - title: expected_revision - minimum: 1 - format: int64 - content: - type: string - title: content - maxLength: 20000 - minLength: 1 - tags: - type: array - items: - type: string - maxItems: 64 - title: tags - maxItems: 64 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: CorrectWorkspaceMemoryRequest - required: - - query - additionalProperties: false - console.v1.CorrectWorkspaceMemoryResponse: - type: object - properties: - memory: - title: memory - $ref: '#/components/schemas/console.v1.WorkspaceMemory' - title: CorrectWorkspaceMemoryResponse - required: - - memory - additionalProperties: false - console.v1.CostEvidenceSummary: - type: object - properties: - status: - type: string - title: status - description: status is one of recorded or missing. - provider: - type: string - title: provider - model: - type: string - title: model - inputTokens: - type: - - integer - - string - title: input_tokens - format: int64 - outputTokens: - type: - - integer - - string - title: output_tokens - format: int64 - totalCostUsd: - type: number - title: total_cost_usd - format: double - meterRef: - type: string - title: meter_ref - missingReason: - type: string - title: missing_reason - title: CostEvidenceSummary - additionalProperties: false - console.v1.CostUsage: - type: object - properties: - id: - type: string - title: id - traceId: - type: string - title: trace_id - assetId: - type: string - title: asset_id - provider: - type: string - title: provider - model: - type: string - title: model - spendUsd: - type: number - title: spend_usd - format: double - inputTokens: - type: - - integer - - string - title: input_tokens - format: int64 - outputTokens: - type: - - integer - - string - title: output_tokens - format: int64 - requestCount: - type: - - integer - - string - title: request_count - format: int64 - latencyMs: - type: - - integer - - string - title: latency_ms - format: int64 - status: - type: string - title: status - riskLevel: - title: risk_level - $ref: '#/components/schemas/common.v1.RiskLevel' - detail: - type: string - title: detail - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - relatedResources: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: related_resources - spendMicros: - type: - - integer - - string - title: spend_micros - format: int64 - projectId: - type: string - title: project_id - repository: - type: string - title: repository - teamId: - type: string - title: team_id - ownerId: - type: string - title: owner_id - runId: - type: string - title: run_id - attributionTraceId: - type: string - title: attribution_trace_id - requestId: - type: string - title: request_id - deploymentId: - type: string - title: deployment_id - jobId: - type: string - title: job_id - sourceHealth: - type: string - title: source_health - pricingVersion: - type: string - title: pricing_version - ingestedAt: - title: ingested_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - recordKind: - type: string - title: record_kind - description: |- - record_kind distinguishes atomic usage events from provider-owned aggregate - snapshots. Consumers use provider snapshots as authoritative totals rather - than summing them with overlapping gateway events. - spendTodayMicros: - type: - - integer - - string - title: spend_today_micros - format: int64 - description: |- - Provider-reported spend for the current UTC day when record_kind is a - provider_monthly_snapshot. The monthly total remains spend_micros. - upstreamProvider: - type: string - title: upstream_provider - description: |- - Model provider selected behind the billing source, when the source - reports that distinction. - provenance: - type: string - title: provenance - description: |- - Join quality for provider-reported rows: exact, aggregate, estimated, or - unmatched. - cacheReadTokens: - type: - - integer - - string - title: cache_read_tokens - format: int64 - description: |- - Cached-read and cache-write portions of input_tokens, when the source - reports them separately. These values are already included in input_tokens. - cacheWriteTokens: - type: - - integer - - string - title: cache_write_tokens - format: int64 - pricingSource: - type: string - title: pricing_source - description: Cost and usage evidence origins retained from the durable ledger. - usageSource: - type: string - title: usage_source - title: CostUsage - additionalProperties: false - console.v1.CostUsageAttributionSummary: - type: object - properties: - provider: - type: string - title: provider - assetId: - type: string - title: asset_id - model: - type: string - title: model - spendTodayMicros: - type: - - integer - - string - title: spend_today_micros - format: int64 - spendMonthToDateMicros: - type: - - integer - - string - title: spend_month_to_date_micros - format: int64 - requestCount: - type: - - integer - - string - title: request_count - format: int64 - inputTokens: - type: - - integer - - string - title: input_tokens - format: int64 - outputTokens: - type: - - integer - - string - title: output_tokens - format: int64 - recordKind: - type: string - title: record_kind - priorMonthToDateMicros: - type: - - integer - - string - title: prior_month_to_date_micros - format: int64 - priorRequestCount: - type: - - integer - - string - title: prior_request_count - format: int64 - priorInputTokens: - type: - - integer - - string - title: prior_input_tokens - format: int64 - priorOutputTokens: - type: - - integer - - string - title: prior_output_tokens - format: int64 - title: CostUsageAttributionSummary - additionalProperties: false - console.v1.CostUsageRunSummary: - type: object - properties: - runId: - type: string - title: run_id - recordedCostMicros: - type: - - integer - - string - title: recorded_cost_micros - format: int64 - requestCount: - type: - - integer - - string - title: request_count - format: int64 - inputTokens: - type: - - integer - - string - title: input_tokens - format: int64 - outputTokens: - type: - - integer - - string - title: output_tokens - format: int64 - cacheReadTokens: - type: - - integer - - string - title: cache_read_tokens - format: int64 - cacheWriteTokens: - type: - - integer - - string - title: cache_write_tokens - format: int64 - sourceRowCount: - type: integer - title: source_row_count - format: int32 - unpricedRowCount: - type: integer - title: unpriced_row_count - format: int32 - description: Rows without a known cost basis must never be presented as free usage. - models: - type: array - items: - type: string - maxItems: 100 - title: models - maxItems: 100 - modelsTruncated: - type: boolean - title: models_truncated - title: CostUsageRunSummary - additionalProperties: false - console.v1.CostUsageSummary: - type: object - properties: - spendTodayMicros: - type: - - integer - - string - title: spend_today_micros - format: int64 - spendMonthToDateMicros: - type: - - integer - - string - title: spend_month_to_date_micros - format: int64 - priorMonthToDateMicros: - type: - - integer - - string - title: prior_month_to_date_micros - format: int64 - requestCount: - type: - - integer - - string - title: request_count - format: int64 - inputTokens: - type: - - integer - - string - title: input_tokens - format: int64 - outputTokens: - type: - - integer - - string - title: output_tokens - format: int64 - sourceRowCount: - type: integer - title: source_row_count - format: int32 - attributions: - type: array - items: - $ref: '#/components/schemas/console.v1.CostUsageAttributionSummary' - title: attributions - asOf: - title: as_of - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: CostUsageSummary - additionalProperties: false - console.v1.CreateBillingCheckoutSessionRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - requestId: - type: string - title: request_id - format: uuid - title: CreateBillingCheckoutSessionRequest - additionalProperties: false - console.v1.CreateBillingCheckoutSessionResponse: - type: object - properties: - url: - type: string - title: url - format: uri - title: CreateBillingCheckoutSessionResponse - additionalProperties: false - console.v1.CreateBillingPortalSessionRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - title: CreateBillingPortalSessionRequest - additionalProperties: false - console.v1.CreateBillingPortalSessionResponse: - type: object - properties: - url: - type: string - title: url - format: uri - title: CreateBillingPortalSessionResponse - additionalProperties: false - console.v1.CreateBusinessObjectRelationshipRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - relationship: - title: relationship - $ref: '#/components/schemas/console.v1.BusinessObjectRelationship' - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - title: CreateBusinessObjectRelationshipRequest - additionalProperties: false - console.v1.CreateBusinessObjectRelationshipResponse: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/console.v1.BusinessObject' - title: CreateBusinessObjectRelationshipResponse - additionalProperties: false - console.v1.CreateBusinessObjectRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - typeId: - type: string - title: type_id - schemaRevision: - type: - - integer - - string - title: schema_revision - format: int64 - values: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessFieldValue' - title: values - title: CreateBusinessObjectRequest - additionalProperties: false - console.v1.CreateBusinessObjectResponse: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/console.v1.BusinessObject' - title: CreateBusinessObjectResponse - additionalProperties: false - console.v1.CreateCaptureFormInvitationRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - publicationId: - type: string - title: publication_id - minLength: 1 - recipientEmail: - type: string - title: recipient_email - format: email - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - boundValues: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessFieldValue' - title: bound_values - maxItems: 64 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - title: CreateCaptureFormInvitationRequest - required: - - expiresAt - additionalProperties: false - console.v1.CreateCaptureFormInvitationResponse: - type: object - properties: - invitation: - title: invitation - $ref: '#/components/schemas/console.v1.CaptureFormInvitation' - title: CreateCaptureFormInvitationResponse - required: - - invitation - additionalProperties: false - console.v1.CreateCaptureFormRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - name: - type: string - title: name - maxLength: 160 - minLength: 1 - description: - type: string - title: description - maxLength: 2000 - version: - title: version - $ref: '#/components/schemas/console.v1.CaptureFormVersionInput' - title: CreateCaptureFormRequest - required: - - version - additionalProperties: false - console.v1.CreateCaptureFormResponse: - type: object - properties: - form: - title: form - $ref: '#/components/schemas/console.v1.CaptureForm' - version: - title: version - $ref: '#/components/schemas/console.v1.CaptureFormVersion' - title: CreateCaptureFormResponse - required: - - form - - version - additionalProperties: false - console.v1.CreateConnectorProfileRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - providerId: - type: string - title: provider_id - minLength: 1 - profileName: - type: string - title: profile_name - minLength: 1 - connectionId: - type: string - title: connection_id - minLength: 1 - scopes: - type: array - items: - type: string - title: scopes - enabled: - type: boolean - title: enabled - nullable: true - isDefault: - type: boolean - title: is_default - title: CreateConnectorProfileRequest - required: - - query - additionalProperties: false - console.v1.CreateConnectorProfileResponse: - type: object - properties: - profile: - title: profile - $ref: '#/components/schemas/console.v1.ConnectorProfile' - title: CreateConnectorProfileResponse - required: - - profile - additionalProperties: false - console.v1.CreateConnectorTriggerRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - name: - type: string - title: name - minLength: 1 - source: - not: - enum: - - 0 - title: source - $ref: '#/components/schemas/console.v1.ConnectorTriggerSource' - cronExpression: - type: string - title: cron_expression - connectionId: - type: string - title: connection_id - providerId: - type: string - title: provider_id - eventKind: - type: string - title: event_kind - payloadFieldAllowlist: - type: array - items: - type: string - title: payload_field_allowlist - template: - title: template - $ref: '#/components/schemas/console.v1.MissionScheduleTemplate' - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: CreateConnectorTriggerRequest - required: - - query - - template - additionalProperties: false - console.v1.CreateConnectorTriggerResponse: - type: object - properties: - trigger: - title: trigger - $ref: '#/components/schemas/console.v1.ConnectorTrigger' - title: CreateConnectorTriggerResponse - required: - - trigger - additionalProperties: false - console.v1.CreateDexMcpServerRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - name: - type: string - title: name - minLength: 1 - baseUrl: - type: string - title: base_url - minLength: 1 - authKind: - type: string - title: auth_kind - bearerToken: - type: string - title: bearer_token - enabled: - type: boolean - title: enabled - title: CreateDexMcpServerRequest - required: - - query - additionalProperties: false - console.v1.CreateDexMcpServerResponse: - type: object - properties: - server: - title: server - $ref: '#/components/schemas/console.v1.DexMcpServer' - title: CreateDexMcpServerResponse - required: - - server - additionalProperties: false - console.v1.CreateInferenceCreditCheckoutRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - requestId: - type: string - title: request_id - format: uuid - creditCents: - type: - - integer - - string - title: credit_cents - format: int64 - description: Server accepts only the published USD20, USD50, and USD100 credit blocks. - title: CreateInferenceCreditCheckoutRequest - additionalProperties: false - console.v1.CreateInferenceCreditCheckoutResponse: - type: object - properties: - url: - type: string - title: url - format: uri - title: CreateInferenceCreditCheckoutResponse - additionalProperties: false - console.v1.CreateMissionScheduleRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - name: - type: string - title: name - minLength: 1 - cronExpression: - type: string - title: cron_expression - minLength: 1 - template: - title: template - $ref: '#/components/schemas/console.v1.MissionScheduleTemplate' - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: CreateMissionScheduleRequest - required: - - query - - template - additionalProperties: false - console.v1.CreateMissionScheduleResponse: - type: object - properties: - schedule: - title: schedule - $ref: '#/components/schemas/console.v1.MissionSchedule' - title: CreateMissionScheduleResponse - required: - - schedule - additionalProperties: false - console.v1.CreateProspectingDraftRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - candidateId: - type: string - title: candidate_id - maxLength: 128 - minLength: 1 - targetAccount: - title: target_account - $ref: '#/components/schemas/console.v1.ProspectingDraftTargetAccount' - channel: - not: - enum: - - 0 - title: channel - $ref: '#/components/schemas/console.v1.ProspectingDraftChannel' - tone: - not: - enum: - - 0 - title: tone - $ref: '#/components/schemas/console.v1.ProspectingDraftTone' - evidenceIds: - type: array - items: - type: string - maxItems: 50 - title: evidence_ids - maxItems: 50 - minItems: 1 - reason: - type: string - title: reason - maxLength: 512 - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 256 - minLength: 1 - title: CreateProspectingDraftRequest - required: - - query - - targetAccount - additionalProperties: false - console.v1.CreateProspectingDraftResponse: - type: object - properties: - draft: - title: draft - $ref: '#/components/schemas/console.v1.ProspectingDraft' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.ProspectingDraftMutationReceipt' - title: CreateProspectingDraftResponse - required: - - draft - - receipt - additionalProperties: false - console.v1.CreateProspectingWatchProgramRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - name: - type: string - title: name - maxLength: 128 - minLength: 1 - config: - title: config - $ref: '#/components/schemas/google.protobuf.Struct' - scoringRuleRevision: - type: string - title: scoring_rule_revision - maxLength: 128 - minLength: 1 - reason: - type: string - title: reason - maxLength: 512 - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 256 - minLength: 1 - title: CreateProspectingWatchProgramRequest - required: - - query - - config - additionalProperties: false - console.v1.CreateProspectingWatchProgramResponse: - type: object - properties: - program: - title: program - $ref: '#/components/schemas/console.v1.ProspectingWatchProgram' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.ProspectingWatchProgramMutationReceipt' - title: CreateProspectingWatchProgramResponse - required: - - program - - receipt - additionalProperties: false - console.v1.CreateWorkspaceSkillRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - name: - type: string - title: name - minLength: 1 - description: - type: string - title: description - body: - type: string - title: body - minLength: 1 - title: CreateWorkspaceSkillRequest - required: - - query - additionalProperties: false - console.v1.CreateWorkspaceSkillResponse: - type: object - properties: - skill: - title: skill - $ref: '#/components/schemas/console.v1.OperatingSkill' - title: CreateWorkspaceSkillResponse - required: - - skill - additionalProperties: false - console.v1.CredentialAuthoritySummary: - type: object - properties: - status: - type: string - title: status - description: status is one of verified, unverified, missing, revoked, expired, or blocked. - subject: - type: string - title: subject - provider: - type: string - title: provider - authorityRef: - type: string - title: authority_ref - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - revocationState: - type: string - title: revocation_state - missingAuthorities: - type: array - items: - type: string - title: missing_authorities - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - title: CredentialAuthoritySummary - additionalProperties: false - console.v1.CustomerIntelligenceEvidenceRef: - type: object - properties: - ownerType: - type: string - title: owner_type - maxLength: 80 - minLength: 1 - ownerId: - type: string - title: owner_id - maxLength: 256 - minLength: 1 - evidenceId: - type: string - title: evidence_id - maxLength: 256 - minLength: 1 - polarity: - not: - enum: - - 0 - title: polarity - $ref: '#/components/schemas/console.v1.CustomerIntelligenceEvidencePolarity' - digestSha256: - type: string - title: digest_sha256 - maxLength: 64 - minLength: 64 - safeLabel: - type: string - title: safe_label - maxLength: 120 - title: CustomerIntelligenceEvidenceRef - additionalProperties: false - console.v1.CustomerIntelligenceFact: - type: object - properties: - current: - title: current - $ref: '#/components/schemas/console.v1.CustomerIntelligenceFactRevision' - revisions: - type: array - items: - $ref: '#/components/schemas/console.v1.CustomerIntelligenceFactRevision' - title: revisions - maxItems: 100 - title: CustomerIntelligenceFact - required: - - current - additionalProperties: false - console.v1.CustomerIntelligenceFactRevision: - type: object - properties: - factId: - type: string - title: fact_id - revision: - exclusiveMinimum: 0 - type: - - integer - - string - title: revision - format: int64 - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - subjectKind: - not: - enum: - - 0 - title: subject_kind - $ref: '#/components/schemas/console.v1.CustomerIntelligenceSubjectKind' - subjectRefHash: - type: string - title: subject_ref_hash - maxLength: 64 - minLength: 64 - productArea: - type: string - title: product_area - maxLength: 80 - minLength: 1 - journey: - type: string - title: journey - maxLength: 80 - minLength: 1 - predicate: - type: string - title: predicate - maxLength: 120 - minLength: 1 - safeSummary: - type: string - title: safe_summary - maxLength: 280 - minLength: 1 - authority: - not: - enum: - - 0 - title: authority - $ref: '#/components/schemas/console.v1.CustomerIntelligenceAuthority' - lifecycleState: - not: - enum: - - 0 - title: lifecycle_state - $ref: '#/components/schemas/console.v1.CustomerIntelligenceLifecycleState' - confidenceMicros: - type: integer - title: confidence_micros - maximum: 1000000 - format: int32 - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.CustomerIntelligenceEvidenceRef' - title: evidence_refs - maxItems: 64 - producerKind: - not: - enum: - - 0 - title: producer_kind - $ref: '#/components/schemas/console.v1.CustomerIntelligenceProducerKind' - producerRef: - type: string - title: producer_ref - maxLength: 256 - modelId: - type: string - title: model_id - maxLength: 160 - runId: - type: string - title: run_id - maxLength: 256 - policyVersion: - type: string - title: policy_version - maxLength: 80 - lineageId: - type: string - title: lineage_id - maxLength: 256 - sensitivity: - type: string - title: sensitivity - maxLength: 40 - retentionClass: - type: string - title: retention_class - maxLength: 40 - validFrom: - title: valid_from - $ref: '#/components/schemas/google.protobuf.Timestamp' - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - contentFingerprintSha256: - type: string - title: content_fingerprint_sha256 - maxLength: 64 - minLength: 64 - actorId: - type: string - title: actor_id - maxLength: 256 - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: CustomerIntelligenceFactRevision - additionalProperties: false - console.v1.CustomerIntelligencePattern: - type: object - properties: - productArea: - type: string - title: product_area - journey: - type: string - title: journey - predicate: - type: string - title: predicate - organizationCount: - type: - - integer - - string - title: organization_count - minimum: 5 - format: int64 - factCount: - type: - - integer - - string - title: fact_count - minimum: 5 - format: int64 - averageConfidenceMicros: - type: integer - title: average_confidence_micros - maximum: 1000000 - format: int32 - title: CustomerIntelligencePattern - additionalProperties: false - console.v1.CustomerIntelligenceReceipt: - type: object - properties: - factId: - type: string - title: fact_id - revision: - exclusiveMinimum: 0 - type: - - integer - - string - title: revision - format: int64 - authority: - title: authority - $ref: '#/components/schemas/console.v1.CustomerIntelligenceAuthority' - lifecycleState: - title: lifecycle_state - $ref: '#/components/schemas/console.v1.CustomerIntelligenceLifecycleState' - auditDeliveryState: - type: string - title: audit_delivery_state - confirmationIntentId: - type: string - title: confirmation_intent_id - title: CustomerIntelligenceReceipt - additionalProperties: false - console.v1.DefineBusinessObjectTypeRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - definition: - title: definition - $ref: '#/components/schemas/console.v1.BusinessObjectType' - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - title: DefineBusinessObjectTypeRequest - additionalProperties: false - console.v1.DefineBusinessObjectTypeResponse: - type: object - properties: - definition: - title: definition - $ref: '#/components/schemas/console.v1.BusinessObjectType' - title: DefineBusinessObjectTypeResponse - additionalProperties: false - console.v1.DefineBusinessProcessRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - definition: - title: definition - $ref: '#/components/schemas/console.v1.BusinessProcessDefinition' - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - title: DefineBusinessProcessRequest - additionalProperties: false - console.v1.DefineBusinessProcessResponse: - type: object - properties: - definition: - title: definition - $ref: '#/components/schemas/console.v1.BusinessProcessDefinition' - title: DefineBusinessProcessResponse - additionalProperties: false - console.v1.DeleteBusinessObjectRelationshipRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - relationship: - title: relationship - $ref: '#/components/schemas/console.v1.BusinessObjectRelationship' - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - title: DeleteBusinessObjectRelationshipRequest - additionalProperties: false - console.v1.DeleteBusinessObjectRelationshipResponse: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/console.v1.BusinessObject' - title: DeleteBusinessObjectRelationshipResponse - additionalProperties: false - console.v1.DeleteBusinessObjectRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - objectId: - type: string - title: object_id - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - title: DeleteBusinessObjectRequest - additionalProperties: false - console.v1.DeleteBusinessObjectResponse: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/console.v1.BusinessObject' - title: DeleteBusinessObjectResponse - additionalProperties: false - console.v1.DeleteConnectorProfileRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - id: - type: string - title: id - minLength: 1 - title: DeleteConnectorProfileRequest - required: - - query - additionalProperties: false - console.v1.DeleteConnectorProfileResponse: - type: object - properties: - deleted: - type: boolean - title: deleted - title: DeleteConnectorProfileResponse - additionalProperties: false - console.v1.DeleteConnectorTriggerRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - triggerId: - type: string - title: trigger_id - minLength: 1 - title: DeleteConnectorTriggerRequest - required: - - query - additionalProperties: false - console.v1.DeleteConnectorTriggerResponse: - type: object - title: DeleteConnectorTriggerResponse - additionalProperties: false - console.v1.DeleteDexMcpServerRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - serverId: - type: string - title: server_id - minLength: 1 - title: DeleteDexMcpServerRequest - required: - - query - additionalProperties: false - console.v1.DeleteDexMcpServerResponse: - type: object - properties: - deleted: - type: boolean - title: deleted - title: DeleteDexMcpServerResponse - additionalProperties: false - console.v1.DeletePrivateEndpointRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - endpointId: - type: string - title: endpoint_id - minLength: 1 - reasonCode: - type: string - title: reason_code - minLength: 1 - title: DeletePrivateEndpointRequest - required: - - query - additionalProperties: false - console.v1.DeletePrivateEndpointResponse: - type: object - properties: - deleted: - type: boolean - title: deleted - endpoint: - title: endpoint - $ref: '#/components/schemas/console.v1.PrivateEndpoint' - title: DeletePrivateEndpointResponse - additionalProperties: false - console.v1.DeleteWorkspaceSkillRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - name: - type: string - title: name - minLength: 1 - title: DeleteWorkspaceSkillRequest - required: - - query - additionalProperties: false - console.v1.DeleteWorkspaceSkillResponse: - type: object - title: DeleteWorkspaceSkillResponse - additionalProperties: false - console.v1.DexComputerCorrectionEpisode: - type: object - properties: - schema: - type: string - title: schema - minLength: 1 - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - correctionId: - type: string - title: correction_id - minLength: 1 - sourceEpisodeId: - type: string - title: source_episode_id - minLength: 1 - sourceEpisodeDigestSha256: - type: string - title: source_episode_digest_sha256 - maxLength: 64 - minLength: 64 - labels: - type: array - items: - $ref: '#/components/schemas/console.v1.DexComputerCorrectionLabel' - title: labels - evidenceDigestsSha256: - type: array - items: - type: string - maxLength: 64 - minLength: 64 - maxItems: 64 - title: evidence_digests_sha256 - maxItems: 64 - minItems: 1 - reviewState: - title: review_state - $ref: '#/components/schemas/console.v1.OperatingCorrectionReviewState' - productionLearning: - type: boolean - title: production_learning - reuseBoundary: - type: string - title: reuse_boundary - minLength: 1 - episodeDigestSha256: - type: string - title: episode_digest_sha256 - maxLength: 64 - minLength: 64 - title: DexComputerCorrectionEpisode - additionalProperties: false - console.v1.DexMcpCatalogTool: - type: object - properties: - name: - type: string - title: name - title: - type: string - title: title - description: - type: string - title: description - upstreamVersionIdentity: - type: string - title: upstream_version_identity - title: DexMcpCatalogTool - additionalProperties: false - description: |- - DexMcpCatalogTool is the browser-safe review projection of one discovered - tool. Schemas and arbitrary annotations remain in the immutable owner store. - console.v1.DexMcpOAuthProfile: - type: object - properties: - profileId: - type: string - title: profile_id - serverId: - type: string - title: server_id - profileName: - type: string - title: profile_name - subjectKind: - type: string - title: subject_kind - subjectId: - type: string - title: subject_id - currentGrantId: - type: string - title: current_grant_id - profileState: - type: string - title: profile_state - scopes: - type: array - items: - type: string - title: scopes - scopeVersion: - type: - - integer - - string - title: scope_version - format: int64 - enabled: - type: boolean - title: enabled - isDefault: - type: boolean - title: is_default - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - runtimeState: - type: string - title: runtime_state - runtimeReasonCode: - type: string - title: runtime_reason_code - title: DexMcpOAuthProfile - additionalProperties: false - description: |- - DexMcpOAuthProfile is a redacted projection. connection_ref is opaque and - may be used only by the owner boundary; access and refresh tokens are never - present in this message. - console.v1.DexMcpServer: - type: object - properties: - serverId: - type: string - title: server_id - name: - type: string - title: name - baseUrl: - type: string - title: base_url - transport: - type: string - title: transport - authKind: - type: string - title: auth_kind - hasToken: - type: boolean - title: has_token - enabled: - type: boolean - title: enabled - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - createdBy: - type: string - title: created_by - updatedBy: - type: string - title: updated_by - protocolVersion: - type: string - title: protocol_version - description: Negotiated MCP protocol version from the latest discovery. - healthState: - type: string - title: health_state - description: Last observed health state from the owning discovery store. - catalogDigest: - type: string - title: catalog_digest - description: Digest of the latest persisted catalog snapshot. - credentialRef: - type: string - title: credential_ref - description: Secret reference identity for the configured credential, if any. - oauthConnectionRef: - type: string - title: oauth_connection_ref - description: OAuth connection reference identity owned by the Connector owner. - connectorRef: - type: string - title: connector_ref - description: Private connector session reference identity used for routing, if any. - catalogSnapshotVersion: - type: - - integer - - string - title: catalog_snapshot_version - format: int64 - description: Monotonic version of the latest immutable catalog snapshot. - catalogDiscoveredAt: - title: catalog_discovered_at - description: Time the latest endpoint discovery completed. - $ref: '#/components/schemas/google.protobuf.Timestamp' - catalogPartial: - type: boolean - title: catalog_partial - description: True when discovery returned bounded warnings or an incomplete catalog. - discoveryWarnings: - type: array - items: - type: string - title: discovery_warnings - description: Bounded, display-safe discovery warnings. Raw upstream text is omitted. - catalogTools: - type: array - items: - $ref: '#/components/schemas/console.v1.DexMcpCatalogTool' - title: catalog_tools - description: Redacted tool metadata from the latest immutable catalog snapshot. - catalogPromptCount: - type: integer - title: catalog_prompt_count - catalogResourceCount: - type: integer - title: catalog_resource_count - privateRouteRequired: - type: boolean - title: private_route_required - description: |- - Route state is an owner projection. It never includes credentials or - claims that a cloud endpoint is deployed beyond the verified evidence. - privateEndpointId: - type: string - title: private_endpoint_id - privateRouteState: - type: string - title: private_route_state - privateRouteIdentity: - type: string - title: private_route_identity - privateRouteRevision: - type: - - integer - - string - title: private_route_revision - format: int64 - privateRouteOrigin: - type: string - title: private_route_origin - oauthProfileState: - type: string - title: oauth_profile_state - description: |- - Redacted OAuth profile projection for auth_kind=oauth. These fields carry - state, scopes, and version only; token material is never projected. - oauthScopes: - type: array - items: - type: string - title: oauth_scopes - oauthScopeVersion: - type: - - integer - - string - title: oauth_scope_version - format: int64 - oauthRuntimeReasonCode: - type: string - title: oauth_runtime_reason_code - credentialState: - type: string - title: credential_state - description: |- - CredentialDecision is a redacted readiness result from the existing - managed-credential/OAuth grant owners. It is not permission and never - contains credential material. - credentialReasonCode: - type: string - title: credential_reason_code - credentialBinding: - type: string - title: credential_binding - credentialObservedAt: - title: credential_observed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - credentialExpiresAt: - title: credential_expires_at - description: |- - Optional expiry supplied by the credential owner. Unset means the owner - did not provide an expiry; clients must not infer one from this projection. - $ref: '#/components/schemas/google.protobuf.Timestamp' - routeReadinessState: - type: string - title: route_readiness_state - description: |- - RouteDecision is a connectivity/readiness result from the existing - private endpoint and deployment egress owners. It never grants access. - routeReasonCode: - type: string - title: route_reason_code - routeBinding: - type: string - title: route_binding - routeObservedAt: - title: route_observed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - routeExpiresAt: - title: route_expires_at - description: |- - Optional expiry supplied by the route owner. Unset means the owner did - not provide an expiry; clients must not infer one from this projection. - $ref: '#/components/schemas/google.protobuf.Timestamp' - routeMode: - type: string - title: route_mode - routeProvider: - type: string - title: route_provider - sourceAuthority: - title: source_authority - description: |- - Credential-free external source authority from the Connector owner. An - absent or UNKNOWN observation is unavailable; local connection activity - never implies source sufficiency. - $ref: '#/components/schemas/connectors.v1.SourceAuthorityObservation' - title: DexMcpServer - additionalProperties: false - description: |- - DexMcpServer is the redacted Console projection of a governed MCP endpoint. - Secrets are write-only; callers can only observe whether one is configured. - Credential, OAuth, and connector values are owner reference identities; no - credential material ever appears on this projection. - console.v1.DexSkillCatalogEntry: - type: object - properties: - id: - type: string - title: id - description: - type: string - title: description - catalogVersion: - type: integer - title: catalog_version - format: int32 - installed: - type: boolean - title: installed - installedSkillName: - type: string - title: installed_skill_name - installedVersion: - type: integer - title: installed_version - format: int32 - installedCatalogVersion: - type: integer - title: installed_catalog_version - format: int32 - updateAvailable: - type: boolean - title: update_available - displayName: - type: string - title: display_name - publisher: - type: string - title: publisher - sourceUrl: - type: string - title: source_url - license: - type: string - title: license - category: - type: string - title: category - tags: - type: array - items: - type: string - title: tags - external: - type: boolean - title: external - riskLevel: - title: risk_level - description: |- - The procedure's reviewed operating risk, not a grant of authority. Any - governed tool or write still applies its own runtime policy and approval - boundary. - $ref: '#/components/schemas/common.v1.RiskLevel' - analysis: - title: analysis - $ref: '#/components/schemas/console.v1.SkillAnalysisReport' - exposure: - title: exposure - $ref: '#/components/schemas/console.v1.DexSkillCatalogExposure' - requiredTools: - type: array - items: - type: string - maxItems: 64 - title: required_tools - maxItems: 64 - description: |- - Governed tools the procedure cannot be carried out without. An empty - list means the catalog entry declares no particular tool requirement. - sourceRevision: - type: string - title: source_revision - packageDigest: - type: string - title: package_digest - packageManifest: - type: array - items: - $ref: '#/components/schemas/console.v1.DexSkillPackageFile' - title: package_manifest - description: |- - Browse returns manifest metadata only. Resource contents are loaded only - after an explicit skill.load/install path has passed its gates. - activationTrigger: - type: string - title: activation_trigger - objective: - type: string - title: objective - inputs: - type: array - items: - $ref: '#/components/schemas/console.v1.DexSkillInputDeclaration' - title: inputs - outputs: - type: array - items: - $ref: '#/components/schemas/console.v1.DexSkillOutputDeclaration' - title: outputs - orderedMethod: - type: array - items: - type: string - title: ordered_method - successCriteria: - type: array - items: - type: string - title: success_criteria - unavailableBehavior: - type: string - title: unavailable_behavior - outputContract: - type: string - title: output_contract - licenseEvidence: - title: license_evidence - $ref: '#/components/schemas/console.v1.DexSkillLicenseEvidence' - compatibility: - title: compatibility - $ref: '#/components/schemas/console.v1.DexSkillCompatibility' - qualityEvidence: - title: quality_evidence - $ref: '#/components/schemas/console.v1.DexSkillQualityEvidence' - lifecycleState: - title: lifecycle_state - $ref: '#/components/schemas/console.v1.DexSkillLifecycleState' - customerSafeRemediation: - type: string - title: customer_safe_remediation - updateDiff: - title: update_diff - $ref: '#/components/schemas/console.v1.DexSkillUpdateDiff' - runtimeReadiness: - title: runtime_readiness - description: |- - Catalog browse has no sandbox session. Runtime-dependent packages report - PROBE_REQUIRED until a trusted session-scoped environment probe runs. - This field does not gate package installation. - $ref: '#/components/schemas/console.v1.DexSkillRuntimeReadiness' - title: DexSkillCatalogEntry - additionalProperties: false - console.v1.DexSkillCompatibility: - type: object - properties: - schemaVersion: - type: string - title: schema_version - runtimes: - type: array - items: - type: string - title: runtimes - roles: - type: array - items: - type: string - title: roles - platforms: - type: array - items: - type: string - title: platforms - title: DexSkillCompatibility - additionalProperties: false - console.v1.DexSkillInputDeclaration: - type: object - properties: - name: - type: string - title: name - minLength: 1 - type: - type: string - title: type - minLength: 1 - description: - type: string - title: description - required: - type: boolean - title: required - title: DexSkillInputDeclaration - additionalProperties: false - description: |- - Typed, progressive-disclosure metadata for a lossless operating-skill - package. These fields describe a procedure and its resources; they never - grant authority or replace tenant, tool, approval, or policy checks. - console.v1.DexSkillLicenseEvidence: - type: object - properties: - spdxId: - type: string - title: spdx_id - sourcePath: - type: string - title: source_path - contentDigest: - type: string - title: content_digest - verified: - type: boolean - title: verified - included: - type: boolean - title: included - description: |- - True only when the license file itself is included in the package - manifest. False identifies path-level or repository-level evidence. - title: DexSkillLicenseEvidence - additionalProperties: false - console.v1.DexSkillOutputDeclaration: - type: object - properties: - name: - type: string - title: name - minLength: 1 - type: - type: string - title: type - minLength: 1 - description: - type: string - title: description - title: DexSkillOutputDeclaration - additionalProperties: false - console.v1.DexSkillPackageFile: - type: object - properties: - path: - type: string - title: path - minLength: 1 - mediaType: - type: string - title: media_type - minLength: 1 - sizeBytes: - type: - - integer - - string - title: size_bytes - format: int64 - contentDigest: - type: string - title: content_digest - minLength: 1 - kind: - title: kind - $ref: '#/components/schemas/console.v1.DexSkillPackageFileKind' - mode: - type: integer - title: mode - description: |- - POSIX mode bits as recorded by the imported package (for example 0644 or - 0755). This is metadata only; installation never executes a package file. - title: DexSkillPackageFile - additionalProperties: false - console.v1.DexSkillPlaybook: - type: object - properties: - id: - type: string - title: id - minLength: 1 - displayName: - type: string - title: display_name - minLength: 1 - outcomeDescription: - type: string - title: outcome_description - minLength: 1 - steps: - type: array - items: - $ref: '#/components/schemas/console.v1.DexSkillPlaybookStep' - title: steps - minItems: 1 - integrationLabels: - type: array - items: - type: string - maxItems: 16 - title: integration_labels - maxItems: 16 - title: DexSkillPlaybook - additionalProperties: false - description: |- - DexSkillPlaybook is a curated sequence of catalog skills for a common - operating outcome. integration_labels is intentionally optional: it is - populated only when the server models a concrete integration dependency. - console.v1.DexSkillPlaybookStep: - type: object - properties: - catalogSkillId: - type: string - title: catalog_skill_id - minLength: 1 - displayName: - type: string - title: display_name - minLength: 1 - description: - type: string - title: description - title: DexSkillPlaybookStep - additionalProperties: false - description: |- - DexSkillPlaybookStep is one ordered, server-authored outcome in a playbook. - The referenced catalog skill remains the source of the procedure and its - installation state; display metadata here keeps clients from inventing - step semantics locally. - console.v1.DexSkillQualityEvidence: - type: object - properties: - suiteVersion: - type: string - title: suite_version - fixtures: - type: array - items: - $ref: '#/components/schemas/console.v1.DexSkillQualityFixture' - title: fixtures - baselineId: - type: string - title: baseline_id - baselineDigest: - type: string - title: baseline_digest - publicationGatePassed: - type: boolean - title: publication_gate_passed - title: DexSkillQualityEvidence - additionalProperties: false - console.v1.DexSkillQualityFixture: - type: object - properties: - id: - type: string - title: id - minLength: 1 - kind: - title: kind - $ref: '#/components/schemas/console.v1.DexSkillFixtureKind' - triggerAssertion: - type: string - title: trigger_assertion - taskSuccessAssertion: - type: string - title: task_success_assertion - failureHandlingAssertion: - type: string - title: failure_handling_assertion - artifactAssertion: - type: string - title: artifact_assertion - baselineId: - type: string - title: baseline_id - title: DexSkillQualityFixture - additionalProperties: false - console.v1.DexSkillUpdateDiff: - type: object - properties: - fromCatalogVersion: - type: integer - title: from_catalog_version - format: int32 - toCatalogVersion: - type: integer - title: to_catalog_version - format: int32 - fromPackageDigest: - type: string - title: from_package_digest - toPackageDigest: - type: string - title: to_package_digest - addedPaths: - type: array - items: - type: string - title: added_paths - removedPaths: - type: array - items: - type: string - title: removed_paths - changedPaths: - type: array - items: - type: string - title: changed_paths - summary: - type: string - title: summary - bounded: - type: boolean - title: bounded - description: Servers cap path lists and summary text before returning this projection. - title: DexSkillUpdateDiff - additionalProperties: false - console.v1.DisableWorkspaceBreakGlassRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - grantId: - type: string - title: grant_id - title: DisableWorkspaceBreakGlassRequest - required: - - query - additionalProperties: false - console.v1.DiscoverDexMcpServerRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - serverId: - type: string - title: server_id - minLength: 1 - title: DiscoverDexMcpServerRequest - required: - - query - additionalProperties: false - console.v1.DiscoverDexMcpServerResponse: - type: object - properties: - server: - title: server - $ref: '#/components/schemas/console.v1.DexMcpServer' - title: DiscoverDexMcpServerResponse - required: - - server - additionalProperties: false - console.v1.EnableWorkspaceBreakGlassRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - grant: - title: grant - $ref: '#/components/schemas/console.v1.WorkspaceSettingsBreakGlassGrant' - title: EnableWorkspaceBreakGlassRequest - required: - - query - - grant - additionalProperties: false - console.v1.EndpointGuardrailSummary: - type: object - properties: - status: - type: string - title: status - description: status is one of allowed, missing, blocked, or unknown. - endpointId: - type: string - title: endpoint_id - route: - type: string - title: route - exposure: - type: string - title: exposure - allowlistSource: - type: string - title: allowlist_source - resolutionPolicy: - type: string - title: resolution_policy - blockedReason: - type: string - title: blocked_reason - missingControls: - type: array - items: - type: string - title: missing_controls - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - allowlistStatus: - type: string - title: allowlist_status - resolutionStatus: - type: string - title: resolution_status - title: EndpointGuardrailSummary - additionalProperties: false - console.v1.EngageStaffProductIssueReportRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - reportId: - type: string - title: report_id - minLength: 1 - note: - type: string - title: note - maxLength: 1000 - minLength: 1 - baselineTestRunId: - type: string - title: baseline_test_run_id - maxLength: 256 - description: |- - A staff-reviewed failing test becomes the reproduction reference. A verified - fix requires a successful run of the same Playbook with its assertions met. - verificationTestRunId: - type: string - title: verification_test_run_id - maxLength: 256 - title: EngageStaffProductIssueReportRequest - additionalProperties: false - console.v1.EngageStaffProductIssueReportResponse: - type: object - properties: - report: - title: report - $ref: '#/components/schemas/console.v1.StaffProductIssueReport' - title: EngageStaffProductIssueReportResponse - required: - - report - additionalProperties: false - console.v1.EvalResult: - type: object - properties: - id: - type: string - title: id - traceId: - type: string - title: trace_id - assetId: - type: string - title: asset_id - suiteId: - type: string - title: suite_id - scorer: - type: string - title: scorer - score: - type: number - title: score - maximum: 1 - format: double - threshold: - type: number - title: threshold - maximum: 1 - format: double - status: - type: string - title: status - riskLevel: - title: risk_level - $ref: '#/components/schemas/common.v1.RiskLevel' - model: - type: string - title: model - provider: - type: string - title: provider - qualityPerDollar: - type: number - title: quality_per_dollar - format: double - detail: - type: string - title: detail - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - relatedResources: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: related_resources - title: EvalResult - additionalProperties: false - console.v1.EvaluateWorkspaceArtifactStyleGuideRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - workspaceArtifactStyleGuide: - title: workspace_artifact_style_guide - $ref: '#/components/schemas/console.v1.WorkspaceArtifactStyleGuide' - sampleResponse: - type: string - title: sample_response - maxLength: 64000 - minLength: 1 - title: EvaluateWorkspaceArtifactStyleGuideRequest - required: - - query - - workspaceArtifactStyleGuide - additionalProperties: false - console.v1.EvaluateWorkspaceArtifactStyleGuideResponse: - type: object - properties: - passed: - type: boolean - title: passed - wordCount: - type: integer - title: word_count - violations: - type: array - items: - $ref: '#/components/schemas/console.v1.WorkspaceContentPolicyViolation' - title: violations - maxItems: 200 - title: EvaluateWorkspaceArtifactStyleGuideResponse - additionalProperties: false - console.v1.ExecuteStaffProductIssueRecoveryRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - maxLength: 4000 - workspaceId: - type: string - title: workspace_id - maxLength: 4000 - recoveryId: - type: string - title: recovery_id - maxLength: 4000 - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - title: ExecuteStaffProductIssueRecoveryRequest - additionalProperties: false - console.v1.FinalizeBusinessObjectAuthorityTransferRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - objectId: - type: string - title: object_id - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - transferId: - type: string - title: transfer_id - reconciliationDigest: - type: string - title: reconciliation_digest - fenceEvidenceId: - type: string - title: fence_evidence_id - title: FinalizeBusinessObjectAuthorityTransferRequest - additionalProperties: false - console.v1.FinalizeBusinessObjectAuthorityTransferResponse: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/console.v1.BusinessObject' - title: FinalizeBusinessObjectAuthorityTransferResponse - additionalProperties: false - console.v1.ForgetWorkspaceMemoryRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - memoryId: - type: string - title: memory_id - minLength: 1 - expectedRevision: - type: - - integer - - string - title: expected_revision - minimum: 1 - format: int64 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: ForgetWorkspaceMemoryRequest - required: - - query - additionalProperties: false - console.v1.ForgetWorkspaceMemoryResponse: - type: object - properties: - memoryId: - type: string - title: memory_id - title: ForgetWorkspaceMemoryResponse - additionalProperties: false - console.v1.ForkOperatingThreadRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - sourceChannelId: - type: string - title: source_channel_id - minLength: 1 - throughMessageId: - type: string - title: through_message_id - maxLength: 512 - description: |- - Copy history up to and including this message. Empty copies the whole - thread as of expected_source_conversation_revision. - expectedSourceConversationRevision: - type: - - integer - - string - title: expected_source_conversation_revision - format: int64 - description: |- - The source conversation_revision the caller observed. The fork is refused - when the source has moved since, so a fork always names a state the - caller actually read. - idempotencyKey: - type: string - title: idempotency_key - maxLength: 512 - minLength: 1 - label: - type: string - title: label - maxLength: 80 - title: ForkOperatingThreadRequest - required: - - query - additionalProperties: false - console.v1.ForkOperatingThreadResponse: - type: object - properties: - channel: - title: channel - $ref: '#/components/schemas/console.v1.OperatingChannel' - replayed: - type: boolean - title: replayed - title: ForkOperatingThreadResponse - required: - - channel - additionalProperties: false - console.v1.FulfillInferenceCreditCheckoutRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - checkoutSessionId: - type: string - title: checkout_session_id - minLength: 1 - title: FulfillInferenceCreditCheckoutRequest - additionalProperties: false - console.v1.FulfillInferenceCreditCheckoutResponse: - type: object - properties: - balance: - title: balance - $ref: '#/components/schemas/console.v1.InferenceCreditBalance' - title: FulfillInferenceCreditCheckoutResponse - additionalProperties: false - console.v1.GetAgentProductRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - agentId: - type: string - title: agent_id - minLength: 1 - title: GetAgentProductRequest - additionalProperties: false - console.v1.GetAgentProductResponse: - type: object - properties: - agent: - title: agent - $ref: '#/components/schemas/agents.v1.Agent' - config: - title: config - $ref: '#/components/schemas/agents.v1.AgentConfig' - connections: - type: array - items: - $ref: '#/components/schemas/console.v1.AgentProductConnection' - title: connections - prompts: - type: array - items: - $ref: '#/components/schemas/console.v1.AgentProductPrompt' - title: prompts - title: GetAgentProductResponse - additionalProperties: false - console.v1.GetAssetRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - assetId: - type: string - title: asset_id - minLength: 1 - title: GetAssetRequest - additionalProperties: false - console.v1.GetAssetResponse: - type: object - properties: - asset: - title: asset - $ref: '#/components/schemas/console.v1.AiAsset' - relatedResources: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: related_resources - recentActivity: - type: array - items: - $ref: '#/components/schemas/console.v1.ActivityEvent' - title: recent_activity - findings: - type: array - items: - $ref: '#/components/schemas/console.v1.RiskFinding' - title: findings - title: GetAssetResponse - additionalProperties: false - console.v1.GetBillingSubscriptionRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - title: GetBillingSubscriptionRequest - additionalProperties: false - console.v1.GetBillingSubscriptionResponse: - type: object - properties: - planName: - type: string - title: plan_name - planTier: - type: string - title: plan_tier - seatsUsed: - type: integer - title: seats_used - format: int32 - seatsTotal: - type: integer - title: seats_total - format: int32 - renewalDate: - type: string - title: renewal_date - billingContact: - type: string - title: billing_contact - billingPortalUrl: - type: string - title: billing_portal_url - status: - type: string - title: status - statusEnum: - title: status_enum - $ref: '#/components/schemas/console.v1.WorkspaceSettingsBillingStatus' - billingPortalAvailable: - type: boolean - title: billing_portal_available - title: GetBillingSubscriptionResponse - additionalProperties: false - console.v1.GetBusinessObjectRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - objectId: - type: string - title: object_id - allowSourceRecovery: - type: boolean - title: allow_source_recovery - description: |- - Opt in to content-free recovery coordinates when a currently authorized - source owner reports a tombstone newer than the accepted object snapshot. - title: GetBusinessObjectRequest - additionalProperties: false - console.v1.GetBusinessObjectResponse: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/console.v1.BusinessObject' - sourceRecovery: - title: source_recovery - description: Mutually exclusive with object. Contains no field values or source payload. - $ref: '#/components/schemas/console.v1.BusinessObjectSourceRecovery' - title: GetBusinessObjectResponse - additionalProperties: false - console.v1.GetBusinessObjectTypeRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - typeId: - type: string - title: type_id - minLength: 1 - revision: - exclusiveMinimum: 0 - type: - - integer - - string - title: revision - format: int64 - title: GetBusinessObjectTypeRequest - additionalProperties: false - description: Exact immutable schema lookup. Revision must be positive; latest is listed separately. - console.v1.GetBusinessObjectTypeResponse: - type: object - properties: - definition: - title: definition - $ref: '#/components/schemas/console.v1.BusinessObjectType' - title: GetBusinessObjectTypeResponse - additionalProperties: false - console.v1.GetBusinessProcessDefinitionRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - definitionId: - type: string - title: definition_id - revision: - type: - - integer - - string - title: revision - format: int64 - title: GetBusinessProcessDefinitionRequest - additionalProperties: false - description: Exact immutable lookup; revision must be positive. - console.v1.GetBusinessProcessDefinitionResponse: - type: object - properties: - definition: - title: definition - $ref: '#/components/schemas/console.v1.BusinessProcessDefinition' - title: GetBusinessProcessDefinitionResponse - additionalProperties: false - console.v1.GetBusinessProcessRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - processId: - type: string - title: process_id - title: GetBusinessProcessRequest - additionalProperties: false - console.v1.GetBusinessProcessResponse: - type: object - properties: - process: - title: process - $ref: '#/components/schemas/console.v1.BusinessProcess' - definition: - title: definition - $ref: '#/components/schemas/console.v1.BusinessProcessDefinition' - title: GetBusinessProcessResponse - additionalProperties: false - console.v1.GetCaptureFormRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - formId: - type: string - title: form_id - minLength: 1 - versionId: - type: string - title: version_id - maxLength: 255 - title: GetCaptureFormRequest - additionalProperties: false - console.v1.GetCaptureFormResponse: - type: object - properties: - form: - title: form - $ref: '#/components/schemas/console.v1.CaptureForm' - version: - title: version - $ref: '#/components/schemas/console.v1.CaptureFormVersion' - title: GetCaptureFormResponse - required: - - form - - version - additionalProperties: false - console.v1.GetCaptureFormSubmissionRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - submissionId: - type: string - title: submission_id - minLength: 1 - title: GetCaptureFormSubmissionRequest - additionalProperties: false - console.v1.GetCaptureFormSubmissionResponse: - type: object - properties: - submission: - title: submission - $ref: '#/components/schemas/console.v1.CaptureFormSubmission' - title: GetCaptureFormSubmissionResponse - required: - - submission - additionalProperties: false - console.v1.GetComplianceAssessmentRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - recordId: - type: string - title: record_id - title: GetComplianceAssessmentRequest - additionalProperties: false - console.v1.GetComplianceAssessmentResponse: - type: object - properties: - record: - title: record - $ref: '#/components/schemas/console.v1.ComplianceAssessmentRecord' - title: GetComplianceAssessmentResponse - additionalProperties: false - console.v1.GetComputerMissionCanaryEvidenceRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - canaryRunId: - type: string - title: canary_run_id - minLength: 1 - title: GetComputerMissionCanaryEvidenceRequest - required: - - query - additionalProperties: false - console.v1.GetComputerMissionCanaryEvidenceResponse: - type: object - properties: - effects: - type: array - items: - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryEffect' - title: effects - evaluation: - title: evaluation - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryEvaluation' - operatorActions: - type: array - items: - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryOperatorAction' - title: operator_actions - definition: - title: definition - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryDefinition' - title: GetComputerMissionCanaryEvidenceResponse - additionalProperties: false - console.v1.GetComputerMissionCanaryRunRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - canaryRunId: - type: string - title: canary_run_id - minLength: 1 - title: GetComputerMissionCanaryRunRequest - required: - - query - additionalProperties: false - console.v1.GetComputerMissionCanaryRunResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryRun' - title: GetComputerMissionCanaryRunResponse - required: - - run - additionalProperties: false - console.v1.GetComputerMissionRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - missionId: - type: string - title: mission_id - minLength: 1 - title: GetComputerMissionRequest - required: - - query - additionalProperties: false - console.v1.GetComputerMissionResponse: - type: object - properties: - mission: - title: mission - $ref: '#/components/schemas/console.v1.ComputerMission' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.OperatingReceipt' - title: GetComputerMissionResponse - required: - - mission - - receipt - additionalProperties: false - console.v1.GetConsoleBootSnapshotRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - omitOperatingThread: - type: boolean - title: omit_operating_thread - description: |- - Skip the default operating transcript when the caller only needs shared - app-shell state. Chat routes leave this false to retain first-paint data. - title: GetConsoleBootSnapshotRequest - required: - - query - additionalProperties: false - console.v1.GetConsoleBootSnapshotResponse: - type: object - properties: - settings: - title: settings - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - billingSubscription: - title: billing_subscription - $ref: '#/components/schemas/console.v1.GetBillingSubscriptionResponse' - workforce: - title: workforce - $ref: '#/components/schemas/console.v1.ListAgentWorkforceRecordsResponse' - operatingChannels: - title: operating_channels - $ref: '#/components/schemas/console.v1.ListOperatingChannelsResponse' - operatingThread: - title: operating_thread - $ref: '#/components/schemas/console.v1.GetOperatingThreadResponse' - freshness: - title: freshness - $ref: '#/components/schemas/console.v1.ConsoleSnapshotFreshness' - title: GetConsoleBootSnapshotResponse - additionalProperties: false - console.v1.GetCustomerIntelligenceFactRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - factId: - type: string - title: fact_id - minLength: 1 - includeHistory: - type: boolean - title: include_history - title: GetCustomerIntelligenceFactRequest - required: - - query - additionalProperties: false - console.v1.GetCustomerIntelligenceFactResponse: - type: object - properties: - fact: - title: fact - $ref: '#/components/schemas/console.v1.CustomerIntelligenceFact' - title: GetCustomerIntelligenceFactResponse - required: - - fact - additionalProperties: false - console.v1.GetDexMcpServerRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - serverId: - type: string - title: server_id - minLength: 1 - title: GetDexMcpServerRequest - required: - - query - additionalProperties: false - console.v1.GetDexMcpServerResponse: - type: object - properties: - server: - title: server - $ref: '#/components/schemas/console.v1.DexMcpServer' - title: GetDexMcpServerResponse - required: - - server - additionalProperties: false - console.v1.GetInferenceCreditAutoRefillRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - title: GetInferenceCreditAutoRefillRequest - additionalProperties: false - console.v1.GetInferenceCreditAutoRefillResponse: - type: object - properties: - settings: - title: settings - $ref: '#/components/schemas/console.v1.InferenceCreditAutoRefill' - title: GetInferenceCreditAutoRefillResponse - additionalProperties: false - console.v1.GetInferenceCreditBalanceRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - runId: - type: string - title: run_id - maxLength: 256 - title: GetInferenceCreditBalanceRequest - additionalProperties: false - console.v1.GetInferenceCreditBalanceResponse: - type: object - properties: - balance: - title: balance - $ref: '#/components/schemas/console.v1.InferenceCreditBalance' - blocks: - type: array - items: - $ref: '#/components/schemas/console.v1.InferenceCreditBlock' - title: blocks - checkoutAvailable: - type: boolean - title: checkout_available - pricing: - title: pricing - $ref: '#/components/schemas/console.v1.InferenceCreditPricing' - reconciliation: - title: reconciliation - description: Absent means no reconciliation evidence is available. - $ref: '#/components/schemas/console.v1.InferenceCreditReconciliation' - runBalance: - title: run_balance - description: Absent means financial task attribution is unavailable. - $ref: '#/components/schemas/console.v1.InferenceRunCreditBalance' - title: GetInferenceCreditBalanceResponse - additionalProperties: false - console.v1.GetInvitedCaptureFormRequest: - type: object - properties: - invitationId: - type: string - title: invitation_id - minLength: 1 - title: GetInvitedCaptureFormRequest - additionalProperties: false - console.v1.GetInvitedCaptureFormResponse: - type: object - properties: - form: - title: form - $ref: '#/components/schemas/console.v1.PublishedCaptureForm' - receipt: - title: receipt - description: Returned only to the verified recipient after this invitation was used. - $ref: '#/components/schemas/console.v1.CaptureFormPublicSubmissionReceipt' - title: GetInvitedCaptureFormResponse - additionalProperties: false - console.v1.GetManagedInferenceReadinessRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - provider: - type: string - title: provider - description: Both omitted selects the deployment default. Supplying only one is invalid. - model: - type: string - title: model - environment: - type: string - title: environment - description: Omitted selects production; alternate environments must be explicit. - title: GetManagedInferenceReadinessRequest - additionalProperties: false - console.v1.GetManagedInferenceReadinessResponse: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - status: - title: status - $ref: '#/components/schemas/console.v1.ManagedInferenceReadinessStatus' - blockers: - type: array - items: - $ref: '#/components/schemas/console.v1.ManagedInferenceBlocker' - title: blockers - nextActions: - type: array - items: - $ref: '#/components/schemas/console.v1.ManagedInferenceNextAction' - title: next_actions - enrollmentState: - title: enrollment_state - $ref: '#/components/schemas/console.v1.ManagedProviderAccessState' - enrollmentRevision: - type: - - integer - - string - title: enrollment_revision - format: int64 - durableEnrollment: - type: boolean - title: durable_enrollment - funding: - title: funding - $ref: '#/components/schemas/console.v1.InferenceCreditBalance' - target: - title: target - description: Evaluated configured target, not client authority to route or execute. - $ref: '#/components/schemas/console.v1.InferenceProviderTarget' - evaluatedAt: - title: evaluated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - environment: - type: string - title: environment - budget: - title: budget - description: Existing Meter budget projection; never a separate policy owner. - $ref: '#/components/schemas/meter.v1.GetBudgetDashboardResponse' - title: GetManagedInferenceReadinessResponse - additionalProperties: false - console.v1.GetMeetingCaptureRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - captureId: - type: string - title: capture_id - minLength: 1 - title: GetMeetingCaptureRequest - required: - - query - additionalProperties: false - console.v1.GetMeetingCaptureResponse: - type: object - properties: - capture: - title: capture - $ref: '#/components/schemas/console.v1.MeetingCapture' - title: GetMeetingCaptureResponse - additionalProperties: false - console.v1.GetOnboardingPlanRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - environment: - type: string - title: environment - title: GetOnboardingPlanRequest - additionalProperties: false - console.v1.GetOnboardingPlanResponse: - type: object - properties: - tasks: - type: array - items: - $ref: '#/components/schemas/console.v1.OnboardingTask' - title: tasks - title: GetOnboardingPlanResponse - additionalProperties: false - console.v1.GetOperatingFeedbackRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - minLength: 1 - messageId: - type: string - title: message_id - minLength: 1 - title: GetOperatingFeedbackRequest - required: - - query - additionalProperties: false - console.v1.GetOperatingFeedbackResponse: - type: object - properties: - feedback: - title: feedback - $ref: '#/components/schemas/console.v1.OperatingFeedback' - title: GetOperatingFeedbackResponse - additionalProperties: false - console.v1.GetOperatingHistoryContextRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - contextCursor: - type: string - title: context_cursor - maxLength: 4096 - minLength: 1 - beforeCount: - type: integer - title: before_count - maximum: 20 - format: int32 - afterCount: - type: integer - title: after_count - maximum: 20 - format: int32 - title: GetOperatingHistoryContextRequest - required: - - query - additionalProperties: false - console.v1.GetOperatingHistoryContextResponse: - type: object - properties: - channelId: - type: string - title: channel_id - channelTitle: - type: string - title: channel_title - records: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingHistoryContextRecord' - title: records - title: GetOperatingHistoryContextResponse - additionalProperties: false - console.v1.GetOperatingProjectSnapshotRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - projectResourceId: - type: string - title: project_resource_id - maxLength: 255 - minLength: 1 - importExecutionId: - type: string - title: import_execution_id - nullable: true - title: GetOperatingProjectSnapshotRequest - required: - - query - additionalProperties: false - console.v1.GetOperatingReceiptRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - receiptId: - type: string - title: receipt_id - minLength: 1 - channelId: - type: string - title: channel_id - includeCodingOutputContent: - type: boolean - title: include_coding_output_content - title: GetOperatingReceiptRequest - required: - - query - additionalProperties: false - console.v1.GetOperatingReceiptResponse: - type: object - properties: - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.OperatingReceipt' - title: GetOperatingReceiptResponse - additionalProperties: false - console.v1.GetOperatingTaskEnvironmentRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - maxLength: 255 - minLength: 1 - taskId: - type: string - title: task_id - maxLength: 255 - minLength: 1 - title: GetOperatingTaskEnvironmentRequest - required: - - query - additionalProperties: false - console.v1.GetOperatingTaskEnvironmentResponse: - type: object - properties: - available: - type: boolean - title: available - hasEnvironment: - type: boolean - title: has_environment - state: - type: string - title: state - retentionDays: - type: integer - title: retention_days - format: int32 - lastActivityAt: - title: last_activity_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - expiresAt: - title: expires_at - description: Computed from current effective policy and the storage owner's activity. - $ref: '#/components/schemas/google.protobuf.Timestamp' - projectResourceId: - type: string - title: project_resource_id - cleanupAccepted: - type: boolean - title: cleanup_accepted - description: A cleanup decision was already accepted before a later policy change. - retentionHours: - type: integer - title: retention_hours - format: int32 - stages: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingTaskEnvironmentStage' - title: stages - workspaceRecipe: - title: workspace_recipe - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionWorkspaceRecipe' - title: GetOperatingTaskEnvironmentResponse - additionalProperties: false - console.v1.GetOperatingThreadRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - limit: - type: integer - title: limit - maximum: 200 - format: int32 - pageToken: - type: string - title: page_token - maxLength: 2048 - title: GetOperatingThreadRequest - required: - - query - additionalProperties: false - console.v1.GetOperatingThreadResponse: - type: object - properties: - channel: - title: channel - $ref: '#/components/schemas/console.v1.OperatingChannel' - messages: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingMessage' - title: messages - receipts: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingReceipt' - title: receipts - capabilities: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingCapabilityState' - title: capabilities - threadExecution: - title: thread_execution - $ref: '#/components/schemas/console.v1.OperatingThreadExecution' - turns: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingThreadTurn' - title: turns - replayCursor: - type: - - integer - - string - title: replay_cursor - format: int64 - nextPageToken: - type: string - title: next_page_token - maxLength: 2048 - modelSelection: - title: model_selection - $ref: '#/components/schemas/console.v1.OperatingModelSelection' - availableModels: - type: array - items: - $ref: '#/components/schemas/console.v1.InferenceProviderTarget' - title: available_models - defaultModel: - title: default_model - $ref: '#/components/schemas/console.v1.InferenceProviderTarget' - title: GetOperatingThreadResponse - additionalProperties: false - console.v1.GetOperatorPreferencesRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: GetOperatorPreferencesRequest - required: - - query - additionalProperties: false - console.v1.GetOperatorPreferencesResponse: - type: object - properties: - preferences: - title: preferences - $ref: '#/components/schemas/console.v1.OperatorPreferences' - title: GetOperatorPreferencesResponse - required: - - preferences - additionalProperties: false - console.v1.GetOrbControlTargetRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - targetId: - type: string - title: target_id - minLength: 1 - title: GetOrbControlTargetRequest - required: - - query - additionalProperties: false - description: GetOrbControlTargetRequest selects one tenant-scoped target projection. - console.v1.GetOrbControlTargetResponse: - type: object - properties: - target: - title: target - $ref: '#/components/schemas/console.v1.OrbControlTarget' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.OperatingReceipt' - title: GetOrbControlTargetResponse - additionalProperties: false - description: GetOrbControlTargetResponse returns one target projection and latest receipt. - console.v1.GetOverviewRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: GetOverviewRequest - required: - - query - additionalProperties: false - console.v1.GetOverviewResponse: - type: object - properties: - generatedAt: - title: generated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - metrics: - type: array - items: - $ref: '#/components/schemas/console.v1.ConsoleMetric' - title: metrics - topAssets: - type: array - items: - $ref: '#/components/schemas/console.v1.AiAsset' - title: top_assets - topFindings: - type: array - items: - $ref: '#/components/schemas/console.v1.RiskFinding' - title: top_findings - recentActivity: - type: array - items: - $ref: '#/components/schemas/console.v1.ActivityEvent' - title: recent_activity - integrationTiles: - type: array - items: - $ref: '#/components/schemas/console.v1.IntegrationTile' - title: integration_tiles - onboardingTasks: - type: array - items: - $ref: '#/components/schemas/console.v1.OnboardingTask' - title: onboarding_tasks - warnings: - type: array - items: - type: string - title: warnings - totalFindings: - type: integer - title: total_findings - format: int32 - title: GetOverviewResponse - additionalProperties: false - console.v1.GetPrivacySettingsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: GetPrivacySettingsRequest - required: - - query - additionalProperties: false - console.v1.GetPrivacySettingsResponse: - type: object - properties: - effectiveMode: - title: effective_mode - description: |- - Mode platform-api actually seals into OperationContext for the queried - workspace: the workspace override when one exists, otherwise the - organization row, otherwise TENANT_PRIVACY_MODE_STANDARD. - $ref: '#/components/schemas/console.v1.TenantPrivacyMode' - organization: - title: organization - description: Present only when an organization-wide row exists. - $ref: '#/components/schemas/console.v1.TenantPrivacySetting' - workspace: - title: workspace - description: Present only when an override row exists for the queried workspace. - $ref: '#/components/schemas/console.v1.TenantPrivacySetting' - title: GetPrivacySettingsResponse - additionalProperties: false - console.v1.GetProductIssueRecoveryRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - recoveryId: - type: string - title: recovery_id - maxLength: 4000 - title: GetProductIssueRecoveryRequest - additionalProperties: false - description: Durable, explicitly scoped customer recovery contract. - console.v1.GetProspectingWatchProgramRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - watchProgramId: - type: string - title: watch_program_id - minLength: 1 - title: GetProspectingWatchProgramRequest - required: - - query - additionalProperties: false - console.v1.GetProspectingWatchProgramResponse: - type: object - properties: - program: - title: program - $ref: '#/components/schemas/console.v1.ProspectingWatchProgram' - title: GetProspectingWatchProgramResponse - required: - - program - additionalProperties: false - console.v1.GetPublishedCaptureFormBrandingAssetRequest: - type: object - properties: - publicationId: - type: string - title: publication_id - minLength: 1 - description: |- - This opaque id is the only public capability input. The role is a fixed - presentation selector, never an object or version reference. - role: - not: - enum: - - 0 - title: role - $ref: '#/components/schemas/console.v1.CaptureFormBrandingAssetRole' - title: GetPublishedCaptureFormBrandingAssetRequest - additionalProperties: false - console.v1.GetPublishedCaptureFormBrandingAssetResponse: - type: object - properties: - content: - type: string - title: content - maxLength: 699052 - x-protobuf-bytes-max-length: 524288 - format: byte - contentType: - type: string - title: content_type - maxLength: 64 - minLength: 1 - digest: - type: string - title: digest - pattern: ^[0-9a-f]{64}$ - sizeBytes: - type: - - integer - - string - title: size_bytes - maximum: 524288 - format: int64 - title: GetPublishedCaptureFormBrandingAssetResponse - additionalProperties: false - console.v1.GetPublishedCaptureFormRequest: - type: object - properties: - publicationId: - type: string - title: publication_id - minLength: 1 - description: |- - This opaque id is the only public capability input. The service resolves - tenant, form, version, and publication state from its server-side record. - title: GetPublishedCaptureFormRequest - additionalProperties: false - console.v1.GetPublishedCaptureFormResponse: - type: object - properties: - form: - title: form - $ref: '#/components/schemas/console.v1.PublishedCaptureForm' - title: GetPublishedCaptureFormResponse - required: - - form - additionalProperties: false - console.v1.GetStaffInferenceRoutingProfileRequest: - type: object - title: GetStaffInferenceRoutingProfileRequest - additionalProperties: false - console.v1.GetStaffInferenceRoutingProfileResponse: - type: object - properties: - organizationId: - type: string - title: organization_id - availableTargets: - type: array - items: - $ref: '#/components/schemas/console.v1.InferenceProviderTarget' - title: available_targets - defaultTarget: - title: default_target - $ref: '#/components/schemas/console.v1.InferenceProviderTarget' - effectiveTarget: - title: effective_target - $ref: '#/components/schemas/console.v1.InferenceProviderTarget' - profile: - title: profile - description: Absent until staff persists an explicit override. - $ref: '#/components/schemas/console.v1.StaffInferenceRoutingProfile' - recentEvents: - type: array - items: - $ref: '#/components/schemas/console.v1.StaffInferenceRoutingEvent' - title: recent_events - effectiveRoutes: - type: array - items: - $ref: '#/components/schemas/console.v1.StaffInferencePurposeRoute' - title: effective_routes - title: GetStaffInferenceRoutingProfileResponse - additionalProperties: false - console.v1.GetStaffManagedInferenceBudgetRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - request: - title: request - $ref: '#/components/schemas/meter.v1.GetBudgetDashboardRequest' - title: GetStaffManagedInferenceBudgetRequest - additionalProperties: false - console.v1.GetStaffManagedInferenceFundingRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - request: - title: request - $ref: '#/components/schemas/meter.v1.GetPrepaidCreditBalanceRequest' - title: GetStaffManagedInferenceFundingRequest - additionalProperties: false - console.v1.GetStaffManagedInferenceReadinessRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - provider: - type: string - title: provider - description: Both omitted selects the deployment default. Supplying only one is invalid. - model: - type: string - title: model - environment: - type: string - title: environment - description: Omitted selects production; alternate environments must be explicit. - title: GetStaffManagedInferenceReadinessRequest - additionalProperties: false - console.v1.GetStaffManagedInferenceUsageRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - request: - title: request - $ref: '#/components/schemas/meter.v1.QueryUsageRequest' - title: GetStaffManagedInferenceUsageRequest - additionalProperties: false - console.v1.GetStaffWorkspaceContextRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - title: GetStaffWorkspaceContextRequest - additionalProperties: false - console.v1.GetStaffWorkspaceContextResponse: - type: object - properties: - context: - title: context - $ref: '#/components/schemas/console.v1.StaffWorkspaceContext' - title: GetStaffWorkspaceContextResponse - additionalProperties: false - console.v1.GetTraceDrilldownRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - traceId: - type: string - title: trace_id - minLength: 1 - title: GetTraceDrilldownRequest - additionalProperties: false - console.v1.GetTraceDrilldownResponse: - type: object - properties: - trace: - title: trace - $ref: '#/components/schemas/console.v1.TraceDrilldown' - title: GetTraceDrilldownResponse - additionalProperties: false - console.v1.GetWorkspaceSettingsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: GetWorkspaceSettingsRequest - required: - - query - additionalProperties: false - console.v1.GetWorkspaceSettingsResponse: - type: object - properties: - workspace: - title: workspace - $ref: '#/components/schemas/console.v1.WorkspaceSettingsProfile' - currentPrincipal: - title: current_principal - $ref: '#/components/schemas/console.v1.WorkspaceSettingsPrincipal' - members: - type: array - items: - $ref: '#/components/schemas/console.v1.WorkspaceSettingsMember' - title: members - billing: - title: billing - $ref: '#/components/schemas/console.v1.WorkspaceSettingsBilling' - policy: - title: policy - $ref: '#/components/schemas/console.v1.WorkspaceSettingsPolicy' - notifications: - title: notifications - $ref: '#/components/schemas/console.v1.WorkspaceSettingsNotifications' - identityProviders: - type: array - items: - $ref: '#/components/schemas/console.v1.WorkspaceSettingsIdentityProvider' - title: identity_providers - integrations: - type: array - items: - $ref: '#/components/schemas/console.v1.WorkspaceSettingsIntegration' - title: integrations - capabilities: - type: array - items: - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - title: capabilities - warnings: - type: array - items: - type: string - title: warnings - activity: - type: array - items: - $ref: '#/components/schemas/console.v1.WorkspaceSettingsActivityEntry' - title: activity - ownerServices: - type: array - items: - $ref: '#/components/schemas/console.v1.WorkspaceSettingsOwnerStatus' - title: owner_services - breakGlassGrant: - title: break_glass_grant - $ref: '#/components/schemas/console.v1.WorkspaceSettingsBreakGlassGrant' - workspaces: - type: array - items: - $ref: '#/components/schemas/console.v1.WorkspaceSettingsWorkspace' - title: workspaces - dexPolicy: - title: dex_policy - $ref: '#/components/schemas/console.v1.WorkspaceDexPolicy' - artifactStyleGuide: - title: artifact_style_guide - $ref: '#/components/schemas/console.v1.WorkspaceArtifactStyleGuide' - taskEnvironmentProjects: - type: array - items: - $ref: '#/components/schemas/console.v1.TaskEnvironmentProjectOption' - title: task_environment_projects - description: Response-only project choices resolved from this tenant's repository resources. - title: GetWorkspaceSettingsResponse - additionalProperties: false - console.v1.GrantStaffManagedInferenceCreditsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - request: - title: request - $ref: '#/components/schemas/meter.v1.GrantDevelopmentCreditsRequest' - title: GrantStaffManagedInferenceCreditsRequest - additionalProperties: false - console.v1.GuideComputerMissionRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - missionId: - type: string - title: mission_id - minLength: 1 - expectedGeneration: - type: - - integer - - string - title: expected_generation - format: int64 - guidance: - type: string - title: guidance - minLength: 1 - condition: - title: condition - $ref: '#/components/schemas/google.protobuf.Struct' - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - wakeAt: - title: wake_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: GuideComputerMissionRequest - required: - - query - additionalProperties: false - console.v1.GuideComputerMissionResponse: - type: object - properties: - mission: - title: mission - $ref: '#/components/schemas/console.v1.ComputerMission' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.OperatingReceipt' - wakeId: - type: string - title: wake_id - minLength: 1 - title: GuideComputerMissionResponse - required: - - mission - - receipt - additionalProperties: false - console.v1.ImportOperatingProjectSnapshotRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - projectResourceId: - type: string - title: project_resource_id - maxLength: 255 - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 255 - minLength: 1 - expectedRefVersion: - type: - - integer - - string - title: expected_ref_version - format: int64 - nullable: true - title: ImportOperatingProjectSnapshotRequest - required: - - query - additionalProperties: false - description: Caller chooses the project and observed acceptance version, never a Git SHA. - console.v1.InferenceCreditAutoRefill: - type: object - properties: - enabled: - type: boolean - title: enabled - thresholdCents: - type: - - integer - - string - title: threshold_cents - format: int64 - creditCents: - type: - - integer - - string - title: credit_cents - format: int64 - monthlyCapCents: - type: - - integer - - string - title: monthly_cap_cents - format: int64 - committedCents: - type: - - integer - - string - title: committed_cents - format: int64 - description: Successful automatic charges this UTC month plus all unresolved charges. - pauseReason: - type: string - title: pause_reason - generation: - type: string - title: generation - title: InferenceCreditAutoRefill - additionalProperties: false - console.v1.InferenceCreditBalance: - type: object - properties: - compensatedMicros: - type: - - integer - - string - title: compensated_micros - format: int64 - description: Original cash charges restored through verified customer recovery. - grantedMicros: - type: - - integer - - string - title: granted_micros - format: int64 - description: Non-cash development funding remains separate from purchased credits. - expiredGrantMicros: - type: - - integer - - string - title: expired_grant_micros - format: int64 - grantSpentMicros: - type: - - integer - - string - title: grant_spent_micros - format: int64 - grantReservedMicros: - type: - - integer - - string - title: grant_reserved_micros - format: int64 - developmentCreditOnly: - type: boolean - title: development_credit_only - description: Enrolled development programs cannot consume paid credits or trigger paid refill. - admissionSuspended: - type: boolean - title: admission_suspended - reversedMicros: - type: - - integer - - string - title: reversed_micros - format: int64 - debtMicros: - type: - - integer - - string - title: debt_micros - format: int64 - purchasedMicros: - type: - - integer - - string - title: purchased_micros - format: int64 - spentMicros: - type: - - integer - - string - title: spent_micros - format: int64 - reservedMicros: - type: - - integer - - string - title: reserved_micros - format: int64 - availableMicros: - type: - - integer - - string - title: available_micros - format: int64 - title: InferenceCreditBalance - additionalProperties: false - description: Model credits are separate from subscriptions; automatic refill requires explicit consent. - console.v1.InferenceCreditBlock: - type: object - properties: - creditCents: - type: - - integer - - string - title: credit_cents - format: int64 - feeCents: - type: - - integer - - string - title: fee_cents - format: int64 - totalCents: - type: - - integer - - string - title: total_cents - format: int64 - quoteVersion: - type: string - title: quote_version - title: InferenceCreditBlock - additionalProperties: false - console.v1.InferenceCreditPricing: - type: object - properties: - provider: - type: string - title: provider - model: - type: string - title: model - pricingVersion: - type: string - title: pricing_version - inputMicrosPerMillionTokens: - type: - - integer - - string - title: input_micros_per_million_tokens - format: int64 - cachedInputMicrosPerMillionTokens: - type: - - integer - - string - title: cached_input_micros_per_million_tokens - format: int64 - outputMicrosPerMillionTokens: - type: - - integer - - string - title: output_micros_per_million_tokens - format: int64 - displayName: - type: string - title: display_name - description: Customer-facing model name, for example "GLM-5.3"; `model` is the provider id. - title: InferenceCreditPricing - additionalProperties: false - description: |- - Published per-token price of the managed default model that prepaid credits - pay for. Amounts are USD micros (1 USD = 1_000_000) per one million tokens, - so $1.40 per million tokens is 1400000. The console uses this to show what a - balance buys; it is the same contract the LLM gateway enforces at admission. - console.v1.InferenceCreditReceipt: - type: object - properties: - paymentId: - type: string - title: payment_id - paidAtUnix: - type: - - integer - - string - title: paid_at_unix - format: int64 - creditCents: - type: - - integer - - string - title: credit_cents - format: int64 - feeCents: - type: - - integer - - string - title: fee_cents - format: int64 - paidCents: - type: - - integer - - string - title: paid_cents - format: int64 - refundedCents: - type: - - integer - - string - title: refunded_cents - format: int64 - receiptUrl: - type: string - title: receipt_url - automaticRefill: - type: boolean - title: automatic_refill - title: InferenceCreditReceipt - additionalProperties: false - description: A confirmed payment receipt; amounts include only that payment, not a balance. - console.v1.InferenceCreditReconciliation: - type: object - properties: - compensatedDifferenceMicros: - type: - - integer - - string - title: compensated_difference_micros - format: int64 - balanced: - type: boolean - title: balanced - description: A comparison of materialized counters with source rows in one snapshot. - purchasedDifferenceMicros: - type: - - integer - - string - title: purchased_difference_micros - format: int64 - reversedDifferenceMicros: - type: - - integer - - string - title: reversed_difference_micros - format: int64 - spentDifferenceMicros: - type: - - integer - - string - title: spent_difference_micros - format: int64 - reservedDifferenceMicros: - type: - - integer - - string - title: reserved_difference_micros - format: int64 - disputeCountDifference: - type: - - integer - - string - title: dispute_count_difference - format: int64 - pendingReservationCount: - type: - - integer - - string - title: pending_reservation_count - format: int64 - oldestPendingAt: - title: oldest_pending_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - unfundedPaymentCount: - type: - - integer - - string - title: unfunded_payment_count - format: int64 - title: InferenceCreditReconciliation - additionalProperties: false - console.v1.InferenceProviderTarget: - type: object - properties: - provider: - type: string - title: provider - model: - type: string - title: model - displayName: - type: string - title: display_name - capabilities: - type: array - items: - type: string - title: capabilities - contextWindowTokens: - type: - - integer - - string - title: context_window_tokens - format: int64 - pricingTier: - type: string - title: pricing_tier - latencyTier: - type: string - title: latency_tier - regions: - type: array - items: - type: string - title: regions - ready: - type: boolean - title: ready - unavailableReason: - type: string - title: unavailable_reason - title: InferenceProviderTarget - additionalProperties: false - description: |- - InferenceProviderTarget is one deployment-approved provider/model pair. - Provider identity is canonicalized through model-provider-core. - console.v1.InferenceRunCreditBalance: - type: object - properties: - runId: - type: string - title: run_id - settledCostMicros: - type: - - integer - - string - title: settled_cost_micros - format: int64 - reservedMicros: - type: - - integer - - string - title: reserved_micros - format: int64 - pendingRequestCount: - type: - - integer - - string - title: pending_request_count - format: int64 - settledRequestCount: - type: - - integer - - string - title: settled_request_count - format: int64 - oldestPendingAt: - title: oldest_pending_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: InferenceRunCreditBalance - additionalProperties: false - console.v1.InitiateDexMcpOAuthProfileRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - serverId: - type: string - title: server_id - minLength: 1 - profileId: - type: string - title: profile_id - profileName: - type: string - title: profile_name - minLength: 1 - subjectKind: - type: string - title: subject_kind - minLength: 1 - subjectId: - type: string - title: subject_id - resourceUrl: - type: string - title: resource_url - minLength: 1 - scopes: - type: array - items: - type: string - title: scopes - redirectUri: - type: string - title: redirect_uri - minLength: 1 - clientId: - type: string - title: client_id - clientSecretRef: - type: string - title: client_secret_ref - isDefault: - type: boolean - title: is_default - idempotencyKey: - type: string - title: idempotency_key - title: InitiateDexMcpOAuthProfileRequest - required: - - query - additionalProperties: false - console.v1.InitiateDexMcpOAuthProfileResponse: - type: object - properties: - profile: - title: profile - $ref: '#/components/schemas/console.v1.DexMcpOAuthProfile' - authorizeUrl: - type: string - title: authorize_url - state: - type: string - title: state - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - resourceMetadataUrl: - type: string - title: resource_metadata_url - authorizationServer: - type: string - title: authorization_server - clientId: - type: string - title: client_id - title: InitiateDexMcpOAuthProfileResponse - required: - - profile - additionalProperties: false - console.v1.InstallDexSkillCatalogEntryRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - catalogId: - type: string - title: catalog_id - minLength: 1 - acceptAnalysisFindings: - type: boolean - title: accept_analysis_findings - description: |- - Required when the current typed analysis verdict is NEEDS_REVIEW. The - acknowledgement is accepted only when fields 4-6 exactly match the - current catalog payload and analysis evidence. - reviewedCatalogVersion: - type: integer - title: reviewed_catalog_version - format: int32 - reviewedAnalysisContentDigest: - type: string - title: reviewed_analysis_content_digest - reviewedAnalysisRulesetVersion: - type: string - title: reviewed_analysis_ruleset_version - reviewedSourceRevision: - type: string - title: reviewed_source_revision - reviewedPackageDigest: - type: string - title: reviewed_package_digest - title: InstallDexSkillCatalogEntryRequest - required: - - query - additionalProperties: false - console.v1.InstallDexSkillCatalogEntryResponse: - type: object - properties: - skill: - title: skill - $ref: '#/components/schemas/console.v1.OperatingSkill' - catalogSkillId: - type: string - title: catalog_skill_id - catalogVersion: - type: integer - title: catalog_version - format: int32 - reinstalled: - type: boolean - title: reinstalled - title: InstallDexSkillCatalogEntryResponse - required: - - skill - additionalProperties: false - console.v1.IntegrationCredentialField: - type: object - properties: - name: - type: string - title: name - label: - type: string - title: label - required: - type: boolean - title: required - secret: - type: boolean - title: secret - acceptedReferenceSchemes: - type: array - items: - type: string - title: accepted_reference_schemes - credentialType: - type: string - title: credential_type - title: IntegrationCredentialField - additionalProperties: false - description: |- - IntegrationCredentialField describes the credential reference slots Console - can ask a workspace admin to provide for an integration. Values submitted for - these fields must be secret references, not raw credential material. - console.v1.IntegrationResourceType: - type: object - properties: - id: - type: string - title: id - displayName: - type: string - title: display_name - sourceCoverageTypes: - type: array - items: - type: string - title: source_coverage_types - sourceProjectionTemplate: - type: string - title: source_projection_template - eventKind: - type: string - title: event_kind - title: IntegrationResourceType - additionalProperties: false - description: |- - IntegrationResourceType is safe catalog discovery metadata for one provider - resource family. source_* fields preserve the imported source taxonomy and - projection intent; they do not claim a canonical or implemented Mono mapping. - console.v1.IntegrationTile: - type: object - properties: - id: - type: string - title: id - name: - type: string - title: name - provider: - type: string - title: provider - category: - type: string - title: category - status: - type: string - title: status - detail: - type: string - title: detail - setupCommand: - type: string - title: setup_command - scopes: - type: array - items: - type: string - title: scopes - capabilities: - type: array - items: - type: string - title: capabilities - lastSeenAt: - title: last_seen_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - catalogCategories: - type: array - items: - type: string - title: catalog_categories - runtimeExecutable: - type: boolean - title: runtime_executable - resourceFamilies: - type: array - items: - type: string - title: resource_families - verificationEndpoint: - type: string - title: verification_endpoint - lifecycleStage: - type: string - title: lifecycle_stage - description: |- - lifecycle_stage is the durable source lifecycle projection rendered by the - Sources UI: needs_setup, authorizing, syncing, connected, degraded, - reconnect_required, needs_operator_config, disabled, etc. - requiredScopes: - type: array - items: - type: string - title: required_scopes - optionalScopes: - type: array - items: - type: string - title: optional_scopes - missingScopes: - type: array - items: - type: string - title: missing_scopes - syncStatus: - type: string - title: sync_status - lastSyncAt: - title: last_sync_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - nextSyncAt: - title: next_sync_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - lastSyncDurationMs: - type: integer - title: last_sync_duration_ms - format: int32 - syncedItemCount: - type: integer - title: synced_item_count - format: int32 - syncError: - type: string - title: sync_error - installAuthority: - type: string - title: install_authority - operatorConfigStatus: - type: string - title: operator_config_status - authType: - type: string - title: auth_type - oauthSupported: - type: boolean - title: oauth_supported - credentialFields: - type: array - items: - $ref: '#/components/schemas/console.v1.IntegrationCredentialField' - title: credential_fields - catalogProvenance: - title: catalog_provenance - $ref: '#/components/schemas/connectors.v1.ConnectorCatalogProvenance' - catalogTier: - type: string - title: catalog_tier - description: |- - catalog_tier is the connector catalog owner's shape-derived tier. Console - carries it verbatim and never promotes a provider's readiness. - providerActions: - type: array - items: - type: string - title: provider_actions - description: |- - provider_actions names the typed runtime actions exposed by the published - provider. Together with resource_families this distinguishes sync, - action-only, and combined providers without inferring support from labels. - catalogStatus: - type: string - title: catalog_status - description: |- - catalog_status is either ready (published and connectable) or - qualification_pending (installed preview, not connectable). - setupAllowed: - type: boolean - title: setup_allowed - configured: - type: boolean - title: configured - providerActionCount: - type: integer - title: provider_action_count - format: int32 - resourceFamilyCount: - type: integer - title: resource_family_count - format: int32 - requiredFamilyCount: - type: integer - title: required_family_count - format: int32 - qualifiedFamilyCount: - type: integer - title: qualified_family_count - format: int32 - rolloutKind: - type: string - title: rollout_kind - resourceTypes: - type: array - items: - $ref: '#/components/schemas/console.v1.IntegrationResourceType' - title: resource_types - providerDescription: - type: string - title: provider_description - title: IntegrationTile - additionalProperties: false - console.v1.InterruptOperatingThreadRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - minLength: 1 - turnId: - type: string - title: turn_id - description: When empty, the owner interrupts the lowest-sequence non-terminal turn. - idempotencyKey: - type: string - title: idempotency_key - maxLength: 512 - minLength: 1 - reason: - type: string - title: reason - maxLength: 512 - description: Optional product-safe reason shown only as audit metadata, never as model prompt. - title: InterruptOperatingThreadRequest - required: - - query - additionalProperties: false - console.v1.InterruptOperatingThreadResponse: - type: object - properties: - turnId: - type: string - title: turn_id - replayed: - type: boolean - title: replayed - threadExecution: - title: thread_execution - $ref: '#/components/schemas/console.v1.OperatingThreadExecution' - turns: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingThreadTurn' - title: turns - replayCursor: - type: - - integer - - string - title: replay_cursor - format: int64 - cancelledWorkIds: - type: array - items: - type: string - maxItems: 32 - title: cancelled_work_ids - maxItems: 32 - description: Runtime work cancelled for the interrupted turn's submitted message, if any. - title: InterruptOperatingThreadResponse - additionalProperties: false - console.v1.ListActivityRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListActivityRequest - required: - - query - additionalProperties: false - console.v1.ListActivityResponse: - type: object - properties: - events: - type: array - items: - $ref: '#/components/schemas/console.v1.ActivityEvent' - title: events - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - denialsUnavailableReason: - type: string - title: denials_unavailable_reason - description: |- - Empty when spend budget denials owned by meter were merged into `events`. - Non-empty names why they were not, so a caller can say this page is missing - denials rather than render a page that looks complete. Platform never - substitutes an empty denial set for an unread one. - title: ListActivityResponse - additionalProperties: false - console.v1.ListAgentWorkforceRecordsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - runtime: - type: string - title: runtime - queueState: - type: string - title: queue_state - includeDebug: - type: boolean - title: include_debug - sourceEventId: - type: string - title: source_event_id - maxLength: 120 - description: |- - source_event_id is an exact source-intake selector owned by the backend. - It is separate from ConsoleQuery.search so an intake lookup cannot be - widened into a generic Fleet search. - title: ListAgentWorkforceRecordsRequest - required: - - query - additionalProperties: false - console.v1.ListAgentWorkforceRecordsResponse: - type: object - properties: - records: - type: array - items: - $ref: '#/components/schemas/console.v1.AgentWorkforceRecord' - title: records - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - warnings: - type: array - items: - type: string - title: warnings - approvalQueueSummary: - title: approval_queue_summary - $ref: '#/components/schemas/console.v1.AgentWorkforceApprovalQueueSummary' - sourceReadiness: - type: array - items: - $ref: '#/components/schemas/console.v1.AgentWorkforceSourceReadiness' - title: source_readiness - description: |- - source_readiness includes configured-only Agent Workforce source paths for - rendering even when no approval-queue record exists for that source. These - rows are display readiness only and do not prove identity, credential - grants, model/cost spend, or approval readiness. - sourceEventId: - type: string - title: source_event_id - description: |- - Echoes the exact source-event selector when the response was filtered by - source_event_id. Clients may use this typed contract for backend-owned - singleton matching; an empty value means no source-event selector was - applied. - title: ListAgentWorkforceRecordsResponse - additionalProperties: false - console.v1.ListAssetsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListAssetsRequest - required: - - query - additionalProperties: false - console.v1.ListAssetsResponse: - type: object - properties: - assets: - type: array - items: - $ref: '#/components/schemas/console.v1.AiAsset' - title: assets - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - title: ListAssetsResponse - additionalProperties: false - console.v1.ListAuthorityPostureRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListAuthorityPostureRequest - required: - - query - additionalProperties: false - console.v1.ListAuthorityPostureResponse: - type: object - properties: - rows: - type: array - items: - $ref: '#/components/schemas/console.v1.AuthorityLedger' - title: rows - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - warnings: - type: array - items: - type: string - title: warnings - title: ListAuthorityPostureResponse - additionalProperties: false - console.v1.ListBusinessBlueprintsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - title: ListBusinessBlueprintsRequest - additionalProperties: false - console.v1.ListBusinessBlueprintsResponse: - type: object - properties: - blueprints: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessBlueprint' - title: blueprints - title: ListBusinessBlueprintsResponse - additionalProperties: false - console.v1.ListBusinessObjectRelationshipsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - objectId: - type: string - title: object_id - limit: - type: integer - title: limit - format: int32 - afterKey: - type: string - title: after_key - description: Tuple cursor of relationship ID and peer object ID, separated by U+001F. - direction: - title: direction - description: Unspecified preserves outgoing behavior. Incoming peers are source objects. - $ref: '#/components/schemas/console.v1.BusinessObjectRelationshipDirection' - title: ListBusinessObjectRelationshipsRequest - additionalProperties: false - console.v1.ListBusinessObjectRelationshipsResponse: - type: object - properties: - relationships: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessObjectRelationship' - title: relationships - nextKey: - type: string - title: next_key - title: ListBusinessObjectRelationshipsResponse - additionalProperties: false - console.v1.ListBusinessObjectRevisionsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - objectId: - type: string - title: object_id - limit: - type: integer - title: limit - format: int32 - beforeRevision: - type: - - integer - - string - title: before_revision - format: int64 - title: ListBusinessObjectRevisionsRequest - additionalProperties: false - console.v1.ListBusinessObjectRevisionsResponse: - type: object - properties: - revisions: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessObjectRevision' - title: revisions - nextBeforeRevision: - type: - - integer - - string - title: next_before_revision - format: int64 - title: ListBusinessObjectRevisionsResponse - additionalProperties: false - console.v1.ListBusinessObjectTypesRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - limit: - type: integer - title: limit - format: int32 - afterTypeId: - type: string - title: after_type_id - title: ListBusinessObjectTypesRequest - additionalProperties: false - console.v1.ListBusinessObjectTypesResponse: - type: object - properties: - definitions: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessObjectType' - title: definitions - nextTypeId: - type: string - title: next_type_id - title: ListBusinessObjectTypesResponse - additionalProperties: false - console.v1.ListBusinessObjectsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - typeId: - type: string - title: type_id - limit: - type: integer - title: limit - format: int32 - afterObjectId: - type: string - title: after_object_id - filter: - title: filter - description: |- - Optional exact indexed lookup; omit for ordinary record listing. - (-- api-linter: core::0132::request-field-types=disabled - aip.dev/not-precedent: Typed indexed predicates intentionally replace - an unstructured filter expression for this Connect API. --) - $ref: '#/components/schemas/console.v1.BusinessObjectFilter' - title: ListBusinessObjectsRequest - additionalProperties: false - console.v1.ListBusinessObjectsResponse: - type: object - properties: - objects: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessObject' - title: objects - nextObjectId: - type: string - title: next_object_id - title: ListBusinessObjectsResponse - additionalProperties: false - console.v1.ListBusinessProcessDefinitionsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - afterDefinitionId: - type: string - title: after_definition_id - pageSize: - type: integer - title: page_size - format: int32 - title: ListBusinessProcessDefinitionsRequest - additionalProperties: false - description: Latest revision of each definition, ordered by ID. Maximum page size is 20. - console.v1.ListBusinessProcessDefinitionsResponse: - type: object - properties: - definitions: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessProcessDefinition' - title: definitions - nextAfterDefinitionId: - type: string - title: next_after_definition_id - title: ListBusinessProcessDefinitionsResponse - additionalProperties: false - console.v1.ListBusinessProcessesRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - subjectObjectId: - type: string - title: subject_object_id - afterProcessId: - type: string - title: after_process_id - pageSize: - type: integer - title: page_size - format: int32 - title: ListBusinessProcessesRequest - additionalProperties: false - console.v1.ListBusinessProcessesResponse: - type: object - properties: - processes: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessProcess' - title: processes - description: Receipt-free snapshots; GetBusinessProcess returns bounded full history. - nextAfterProcessId: - type: string - title: next_after_process_id - title: ListBusinessProcessesResponse - additionalProperties: false - console.v1.ListCaptureFormSubmissionsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - formId: - type: string - title: form_id - minLength: 1 - state: - title: state - $ref: '#/components/schemas/console.v1.CaptureFormSubmissionState' - pageSize: - type: integer - title: page_size - maximum: 100 - format: int32 - pageToken: - type: string - title: page_token - maxLength: 512 - title: ListCaptureFormSubmissionsRequest - additionalProperties: false - console.v1.ListCaptureFormSubmissionsResponse: - type: object - properties: - submissions: - type: array - items: - $ref: '#/components/schemas/console.v1.CaptureFormSubmission' - title: submissions - maxItems: 100 - nextPageToken: - type: string - title: next_page_token - maxLength: 512 - title: ListCaptureFormSubmissionsResponse - additionalProperties: false - console.v1.ListCaptureFormsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - state: - title: state - $ref: '#/components/schemas/console.v1.CaptureFormState' - pageSize: - type: integer - title: page_size - maximum: 100 - format: int32 - pageToken: - type: string - title: page_token - maxLength: 512 - title: ListCaptureFormsRequest - additionalProperties: false - console.v1.ListCaptureFormsResponse: - type: object - properties: - forms: - type: array - items: - $ref: '#/components/schemas/console.v1.CaptureForm' - title: forms - maxItems: 100 - nextPageToken: - type: string - title: next_page_token - maxLength: 512 - title: ListCaptureFormsResponse - additionalProperties: false - console.v1.ListCommitmentsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - status: - type: string - title: status - maxLength: 32 - description: |- - status selects the lifecycle statuses to return. Empty returns the open - set (requested, accepted, delivered); "all" returns every status; any - other value returns exactly that status. - title: ListCommitmentsRequest - required: - - query - additionalProperties: false - description: ListCommitmentsRequest reads one workspace's commitment ledger. - console.v1.ListCommitmentsResponse: - type: object - properties: - commitments: - type: array - items: - $ref: '#/components/schemas/console.v1.Commitment' - title: commitments - sourceState: - title: source_state - $ref: '#/components/schemas/console.v1.CommitmentSourceState' - truncated: - type: boolean - title: truncated - description: |- - truncated is set when Cerebro filled the candidate window, so commitments - beyond this page exist. Narrow the status filter to see fewer. - title: ListCommitmentsResponse - additionalProperties: false - console.v1.ListComputerMissionCanaryDefinitionsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - title: ListComputerMissionCanaryDefinitionsRequest - required: - - query - additionalProperties: false - console.v1.ListComputerMissionCanaryDefinitionsResponse: - type: object - properties: - definitions: - type: array - items: - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryDefinition' - title: definitions - title: ListComputerMissionCanaryDefinitionsResponse - additionalProperties: false - console.v1.ListComputerMissionCanaryRunsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - title: ListComputerMissionCanaryRunsRequest - required: - - query - additionalProperties: false - console.v1.ListComputerMissionCanaryRunsResponse: - type: object - properties: - runs: - type: array - items: - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryRun' - title: runs - title: ListComputerMissionCanaryRunsResponse - additionalProperties: false - console.v1.ListConnectedCallsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListConnectedCallsRequest - required: - - query - additionalProperties: false - console.v1.ListConnectedCallsResponse: - type: object - properties: - calls: - type: array - items: - $ref: '#/components/schemas/console.v1.ConnectedCall' - title: calls - sourceState: - title: source_state - $ref: '#/components/schemas/console.v1.ConnectedCallSourceState' - title: ListConnectedCallsResponse - additionalProperties: false - console.v1.ListConnectorProfilesRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - providerId: - type: string - title: provider_id - minLength: 1 - title: ListConnectorProfilesRequest - required: - - query - additionalProperties: false - console.v1.ListConnectorProfilesResponse: - type: object - properties: - profiles: - type: array - items: - $ref: '#/components/schemas/console.v1.ConnectorProfile' - title: profiles - title: ListConnectorProfilesResponse - additionalProperties: false - console.v1.ListConnectorTriggersRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - limit: - type: integer - title: limit - format: int32 - offset: - type: integer - title: offset - format: int32 - title: ListConnectorTriggersRequest - required: - - query - additionalProperties: false - console.v1.ListConnectorTriggersResponse: - type: object - properties: - triggers: - type: array - items: - $ref: '#/components/schemas/console.v1.ConnectorTrigger' - title: triggers - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - title: ListConnectorTriggersResponse - additionalProperties: false - console.v1.ListCostUsageRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - runId: - type: string - title: run_id - maxLength: 256 - description: Exact durable run attribution; filtering happens before pagination. - title: ListCostUsageRequest - required: - - query - additionalProperties: false - console.v1.ListCostUsageResponse: - type: object - properties: - rows: - type: array - items: - $ref: '#/components/schemas/console.v1.CostUsage' - title: rows - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - summary: - title: summary - description: |- - summary is computed by Platform over the complete filtered ledger. rows is - intentionally only the bounded, newest-first explorer page. - $ref: '#/components/schemas/console.v1.CostUsageSummary' - runSummary: - title: run_summary - description: Present only for an exact run query with recorded usage. - $ref: '#/components/schemas/console.v1.CostUsageRunSummary' - title: ListCostUsageResponse - additionalProperties: false - console.v1.ListCustomerIntelligenceFactsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - authorities: - type: array - items: - $ref: '#/components/schemas/console.v1.CustomerIntelligenceAuthority' - title: authorities - maxItems: 6 - lifecycleStates: - type: array - items: - $ref: '#/components/schemas/console.v1.CustomerIntelligenceLifecycleState' - title: lifecycle_states - maxItems: 6 - subjectKind: - title: subject_kind - $ref: '#/components/schemas/console.v1.CustomerIntelligenceSubjectKind' - productArea: - type: string - title: product_area - maxLength: 80 - journey: - type: string - title: journey - maxLength: 80 - createdAfter: - title: created_after - $ref: '#/components/schemas/google.protobuf.Timestamp' - limit: - type: integer - title: limit - maximum: 200 - format: int32 - title: ListCustomerIntelligenceFactsRequest - required: - - query - additionalProperties: false - console.v1.ListCustomerIntelligenceFactsResponse: - type: object - properties: - facts: - type: array - items: - $ref: '#/components/schemas/console.v1.CustomerIntelligenceFact' - title: facts - title: ListCustomerIntelligenceFactsResponse - additionalProperties: false - console.v1.ListDexMcpOAuthProfilesRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - serverId: - type: string - title: server_id - title: ListDexMcpOAuthProfilesRequest - required: - - query - additionalProperties: false - console.v1.ListDexMcpOAuthProfilesResponse: - type: object - properties: - profiles: - type: array - items: - $ref: '#/components/schemas/console.v1.DexMcpOAuthProfile' - title: profiles - title: ListDexMcpOAuthProfilesResponse - additionalProperties: false - console.v1.ListDexMcpServersRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListDexMcpServersRequest - required: - - query - additionalProperties: false - console.v1.ListDexMcpServersResponse: - type: object - properties: - servers: - type: array - items: - $ref: '#/components/schemas/console.v1.DexMcpServer' - title: servers - title: ListDexMcpServersResponse - additionalProperties: false - console.v1.ListEvalResultsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - traceIds: - type: array - items: - type: string - maxLength: 256 - minLength: 1 - maxItems: 100 - title: trace_ids - maxItems: 100 - description: |- - Restrict the projection to the bounded set of traces already visible to - the caller. This prevents clients from draining the evaluation ledger to - join a small page of spend rows. - latestPerTrace: - type: boolean - title: latest_per_trace - title: ListEvalResultsRequest - required: - - query - additionalProperties: false - console.v1.ListEvalResultsResponse: - type: object - properties: - results: - type: array - items: - $ref: '#/components/schemas/console.v1.EvalResult' - title: results - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - title: ListEvalResultsResponse - additionalProperties: false - console.v1.ListFindingsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListFindingsRequest - required: - - query - additionalProperties: false - console.v1.ListFindingsResponse: - type: object - properties: - findings: - type: array - items: - $ref: '#/components/schemas/console.v1.RiskFinding' - title: findings - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - title: ListFindingsResponse - additionalProperties: false - console.v1.ListGatewayEgressOriginsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListGatewayEgressOriginsRequest - required: - - query - additionalProperties: false - console.v1.ListGatewayEgressOriginsResponse: - type: object - properties: - origins: - type: array - items: - type: string - title: origins - configured: - type: boolean - title: configured - source: - type: string - title: source - title: ListGatewayEgressOriginsResponse - additionalProperties: false - console.v1.ListInferenceCreditReceiptsRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - pageToken: - type: string - title: page_token - title: ListInferenceCreditReceiptsRequest - additionalProperties: false - console.v1.ListInferenceCreditReceiptsResponse: - type: object - properties: - receipts: - type: array - items: - $ref: '#/components/schemas/console.v1.InferenceCreditReceipt' - title: receipts - nextPageToken: - type: string - title: next_page_token - available: - type: boolean - title: available - title: ListInferenceCreditReceiptsResponse - additionalProperties: false - console.v1.ListIntegrationTilesRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListIntegrationTilesRequest - required: - - query - additionalProperties: false - console.v1.ListIntegrationTilesResponse: - type: object - properties: - tiles: - type: array - items: - $ref: '#/components/schemas/console.v1.IntegrationTile' - title: tiles - total: - type: integer - title: total - format: int32 - installedTotal: - type: integer - title: installed_total - format: int32 - nullable: true - previewTotal: - type: integer - title: preview_total - format: int32 - nullable: true - readyTotal: - type: integer - title: ready_total - format: int32 - configuredTotal: - type: integer - title: configured_total - format: int32 - previewInventoryUnavailable: - type: boolean - title: preview_inventory_unavailable - title: ListIntegrationTilesResponse - additionalProperties: false - console.v1.ListManagedProviderAccessEventsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - pageSize: - type: integer - title: page_size - maximum: 100 - format: int32 - pageToken: - type: string - title: page_token - title: ListManagedProviderAccessEventsRequest - additionalProperties: false - description: Exact-tenant, newest-first enrollment audit read. The cursor is the last event ID. - console.v1.ListManagedProviderAccessEventsResponse: - type: object - properties: - events: - type: array - items: - $ref: '#/components/schemas/console.v1.ManagedProviderAccessEvent' - title: events - nextPageToken: - type: string - title: next_page_token - title: ListManagedProviderAccessEventsResponse - additionalProperties: false - console.v1.ListManagedProviderAccessGrantsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - description: Optional organization filter; empty returns every grant. - title: ListManagedProviderAccessGrantsRequest - additionalProperties: false - console.v1.ListManagedProviderAccessGrantsResponse: - type: object - properties: - grants: - type: array - items: - $ref: '#/components/schemas/console.v1.ManagedProviderAccessGrant' - title: grants - gatewaySyncAvailable: - type: boolean - title: gateway_sync_available - description: |- - False when no gateway sync target is configured; the console then shows an - explicit unavailable-capability state instead of a live enable control. - title: ListManagedProviderAccessGrantsResponse - additionalProperties: false - console.v1.ListMeetingCapturesRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListMeetingCapturesRequest - required: - - query - additionalProperties: false - console.v1.ListMeetingCapturesResponse: - type: object - properties: - captures: - type: array - items: - $ref: '#/components/schemas/console.v1.MeetingCapture' - title: captures - title: ListMeetingCapturesResponse - additionalProperties: false - console.v1.ListMissionSchedulesRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - title: ListMissionSchedulesRequest - required: - - query - additionalProperties: false - console.v1.ListMissionSchedulesResponse: - type: object - properties: - schedules: - type: array - items: - $ref: '#/components/schemas/console.v1.MissionSchedule' - title: schedules - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - availableCapabilities: - type: array - items: - $ref: '#/components/schemas/console.v1.MissionScheduleCapability' - title: available_capabilities - description: |- - available_capabilities is the backend-owned inventory the durable mission - worker can dispatch. Clients must select from this catalog rather than - accepting arbitrary capability identifiers. - title: ListMissionSchedulesResponse - additionalProperties: false - console.v1.ListOperatingAttachmentsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - scope: - title: scope - $ref: '#/components/schemas/console.v1.OperatingAttachmentScope' - limit: - type: integer - title: limit - maximum: 100 - format: int32 - offset: - type: integer - title: offset - format: int32 - title: ListOperatingAttachmentsRequest - required: - - query - additionalProperties: false - console.v1.ListOperatingAttachmentsResponse: - type: object - properties: - attachments: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingAttachmentRef' - title: attachments - hasMore: - type: boolean - title: has_more - title: ListOperatingAttachmentsResponse - additionalProperties: false - console.v1.ListOperatingChannelsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - archiveFilter: - title: archive_filter - $ref: '#/components/schemas/console.v1.OperatingThreadArchiveFilter' - projectResourceId: - type: string - title: project_resource_id - maxLength: 255 - description: |- - Return only the threads bound to this source project. Empty returns every - thread in the tenant scope, bound or not. - title: ListOperatingChannelsRequest - required: - - query - additionalProperties: false - console.v1.ListOperatingChannelsResponse: - type: object - properties: - channels: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingChannel' - title: channels - capabilities: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingCapabilityState' - title: capabilities - homepageSuggestion: - title: homepage_suggestion - description: |- - One short-lived, backend-authored starter grounded in this principal's - recent operating questions and ranked against Cerebro's tenant-local - conversation memory. Absent means recall was unavailable or had no - sufficiently grounded result; clients must keep their ordinary starter. - $ref: '#/components/schemas/console.v1.OperatingHomepageSuggestion' - title: ListOperatingChannelsResponse - additionalProperties: false - console.v1.ListOperatingCorrectionsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - reviewState: - title: review_state - $ref: '#/components/schemas/console.v1.OperatingCorrectionReviewState' - limit: - type: integer - title: limit - maximum: 200 - format: int32 - title: ListOperatingCorrectionsRequest - required: - - query - additionalProperties: false - console.v1.ListOperatingCorrectionsResponse: - type: object - properties: - corrections: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingCorrectionCandidate' - title: corrections - title: ListOperatingCorrectionsResponse - additionalProperties: false - console.v1.ListOperatingJobsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListOperatingJobsRequest - required: - - query - additionalProperties: false - console.v1.ListOperatingJobsResponse: - type: object - properties: - jobs: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingJob' - title: jobs - maxItems: 200 - partial: - type: boolean - title: partial - description: True when at least one returned legacy record lacks a typed correlation. - title: ListOperatingJobsResponse - additionalProperties: false - console.v1.ListOperatingThreadEventsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - minLength: 1 - afterCursor: - type: - - integer - - string - title: after_cursor - format: int64 - limit: - type: integer - title: limit - maximum: 200 - minimum: 1 - format: int32 - title: ListOperatingThreadEventsRequest - required: - - query - additionalProperties: false - console.v1.ListOperatingThreadEventsResponse: - type: object - properties: - events: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingThreadEvent' - title: events - maxItems: 200 - nextCursor: - type: - - integer - - string - title: next_cursor - format: int64 - hasMore: - type: boolean - title: has_more - resetRequired: - type: boolean - title: reset_required - description: |- - reset_required is true only when retention removed the requested cursor. - Clients replace their projection with the accompanying snapshot. - threadExecution: - title: thread_execution - $ref: '#/components/schemas/console.v1.OperatingThreadExecution' - snapshotTurns: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingThreadTurn' - title: snapshot_turns - title: ListOperatingThreadEventsResponse - additionalProperties: false - console.v1.ListOrbControlTargetsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListOrbControlTargetsRequest - required: - - query - additionalProperties: false - description: ListOrbControlTargetsRequest selects a tenant-scoped target collection. - console.v1.ListOrbControlTargetsResponse: - type: object - properties: - targets: - type: array - items: - $ref: '#/components/schemas/console.v1.OrbControlTarget' - title: targets - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - title: ListOrbControlTargetsResponse - additionalProperties: false - description: ListOrbControlTargetsResponse returns Platform projections only. - console.v1.ListPinnedSourcesRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - title: ListPinnedSourcesRequest - additionalProperties: false - console.v1.ListPinnedSourcesResponse: - type: object - properties: - pins: - type: array - items: - $ref: '#/components/schemas/console.v1.PinnedSource' - title: pins - title: ListPinnedSourcesResponse - additionalProperties: false - console.v1.ListPrivateEndpointsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListPrivateEndpointsRequest - required: - - query - additionalProperties: false - console.v1.ListPrivateEndpointsResponse: - type: object - properties: - endpoints: - type: array - items: - $ref: '#/components/schemas/console.v1.PrivateEndpoint' - title: endpoints - title: ListPrivateEndpointsResponse - additionalProperties: false - console.v1.ListProspectingDraftsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListProspectingDraftsRequest - required: - - query - additionalProperties: false - console.v1.ListProspectingDraftsResponse: - type: object - properties: - drafts: - type: array - items: - $ref: '#/components/schemas/console.v1.ProspectingDraft' - title: drafts - maxItems: 100 - hasMore: - type: boolean - title: has_more - title: ListProspectingDraftsResponse - additionalProperties: false - console.v1.ListProspectingWatchProgramsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListProspectingWatchProgramsRequest - required: - - query - additionalProperties: false - console.v1.ListProspectingWatchProgramsResponse: - type: object - properties: - programs: - type: array - items: - $ref: '#/components/schemas/console.v1.ProspectingWatchProgram' - title: programs - maxItems: 100 - hasMore: - type: boolean - title: has_more - title: ListProspectingWatchProgramsResponse - additionalProperties: false - console.v1.ListScenarioFixturesRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - tags: - type: array - items: - type: string - title: tags - limit: - type: integer - title: limit - maximum: 500 - format: int32 - offset: - type: integer - title: offset - format: int32 - title: ListScenarioFixturesRequest - additionalProperties: false - console.v1.ListScenarioFixturesResponse: - type: object - properties: - fixtures: - type: array - items: - $ref: '#/components/schemas/console.v1.ScenarioFixture' - title: fixtures - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - title: ListScenarioFixturesResponse - additionalProperties: false - console.v1.ListStaffManagedExecutionGrantEventsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - sessionId: - type: string - title: session_id - minLength: 1 - afterSequence: - type: - - integer - - string - title: after_sequence - format: int64 - limit: - type: integer - title: limit - maximum: 100 - format: int32 - title: ListStaffManagedExecutionGrantEventsRequest - additionalProperties: false - console.v1.ListStaffManagedExecutionGrantEventsResponse: - type: object - properties: - events: - type: array - items: - $ref: '#/components/schemas/console.v1.ManagedExecutionGrantEvent' - title: events - nextSequence: - type: - - integer - - string - title: next_sequence - format: int64 - scannedCount: - type: integer - title: scanned_count - format: int32 - title: ListStaffManagedExecutionGrantEventsResponse - additionalProperties: false - console.v1.ListStaffManagedExecutionOutcomesRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - lineageId: - type: string - title: lineage_id - minLength: 1 - limit: - type: integer - title: limit - maximum: 100 - format: int32 - title: ListStaffManagedExecutionOutcomesRequest - additionalProperties: false - console.v1.ListStaffManagedExecutionOutcomesResponse: - type: object - properties: - records: - type: array - items: - $ref: '#/components/schemas/console.v1.ManagedExecutionOutcome' - title: records - atLimit: - type: boolean - title: at_limit - description: True if the bounded owner read returned the requested maximum; no claim of complete history. - title: ListStaffManagedExecutionOutcomesResponse - additionalProperties: false - console.v1.ListStaffManagedInferenceAdminEventsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - request: - title: request - $ref: '#/components/schemas/meter.v1.ListManagedInferenceAdminEventsRequest' - title: ListStaffManagedInferenceAdminEventsRequest - additionalProperties: false - console.v1.ListStaffProductIssueRecoveriesRequest: - type: object - properties: - state: - type: string - title: state - maxLength: 32 - description: Empty means all states; otherwise one existing recovery state. - pageSize: - type: integer - title: page_size - maximum: 100 - description: Zero defaults to 25; at most 100 rows. - pageToken: - type: string - title: page_token - maxLength: 4096 - title: ListStaffProductIssueRecoveriesRequest - additionalProperties: false - description: Global staff queue. Tenant scope is returned explicitly on each row. - console.v1.ListStaffProductIssueRecoveriesResponse: - type: object - properties: - recoveries: - type: array - items: - $ref: '#/components/schemas/console.v1.StaffProductIssueRecoverySummary' - title: recoveries - nextPageToken: - type: string - title: next_page_token - title: ListStaffProductIssueRecoveriesResponse - additionalProperties: false - console.v1.ListStaffProductIssueReportsRequest: - type: object - properties: - engagementState: - type: string - title: engagement_state - maxLength: 32 - limit: - type: integer - title: limit - maximum: 100 - minimum: 1 - title: ListStaffProductIssueReportsRequest - additionalProperties: false - console.v1.ListStaffProductIssueReportsResponse: - type: object - properties: - reports: - type: array - items: - $ref: '#/components/schemas/console.v1.StaffProductIssueReport' - title: reports - title: ListStaffProductIssueReportsResponse - additionalProperties: false - console.v1.ListWorkspaceGuardrailRulesRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListWorkspaceGuardrailRulesRequest - required: - - query - additionalProperties: false - console.v1.ListWorkspaceGuardrailRulesResponse: - type: object - properties: - rules: - type: array - items: - $ref: '#/components/schemas/console.v1.WorkspaceGuardrailRule' - title: rules - title: ListWorkspaceGuardrailRulesResponse - additionalProperties: false - console.v1.ListWorkspaceMemoriesRequest: - type: object - properties: - reviewStatus: - title: review_status - description: Unspecified preserves the approved-memory listing. - $ref: '#/components/schemas/memory.v1.MemoryReviewStatus' - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - limit: - type: integer - title: limit - maximum: 100 - format: int32 - offset: - type: integer - title: offset - format: int32 - title: ListWorkspaceMemoriesRequest - required: - - query - additionalProperties: false - console.v1.ListWorkspaceMemoriesResponse: - type: object - properties: - memories: - type: array - items: - $ref: '#/components/schemas/console.v1.WorkspaceMemory' - title: memories - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - title: ListWorkspaceMemoriesResponse - additionalProperties: false - console.v1.ListWorkspaceSkillsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - title: ListWorkspaceSkillsRequest - required: - - query - additionalProperties: false - console.v1.ListWorkspaceSkillsResponse: - type: object - properties: - skills: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingSkill' - title: skills - title: ListWorkspaceSkillsResponse - additionalProperties: false - console.v1.ManagedExecutionGrantEvent: - type: object - properties: - eventId: - type: string - title: event_id - sequence: - type: - - integer - - string - title: sequence - format: int64 - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - action: - type: string - title: action - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - sessionId: - type: string - title: session_id - threadId: - type: string - title: thread_id - turnId: - type: string - title: turn_id - runId: - type: string - title: run_id - requestId: - type: string - title: request_id - actorId: - type: string - title: actor_id - actorKind: - type: string - title: actor_kind - authorizationId: - type: string - title: authorization_id - issuedAtMs: - type: - - integer - - string - title: issued_at_ms - format: int64 - expiresAtMs: - type: - - integer - - string - title: expires_at_ms - format: int64 - grantEpoch: - type: - - integer - - string - title: grant_epoch - format: int64 - runtimeGeneration: - type: - - integer - - string - title: runtime_generation - format: int64 - reason: - type: string - title: reason - title: ManagedExecutionGrantEvent - additionalProperties: false - description: Safe recorded issuer metadata. Expiry is a validity bound, not a fabricated lifecycle event. - console.v1.ManagedExecutionOutcome: - type: object - properties: - recordId: - type: string - title: record_id - requestId: - type: string - title: request_id - lineageId: - type: string - title: lineage_id - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - authorizationId: - type: string - title: authorization_id - verificationStatus: - type: string - title: verification_status - verificationReason: - type: string - title: verification_reason - egressPermission: - type: boolean - title: egress_permission - lifecycleState: - type: string - title: lifecycle_state - errorCode: - type: string - title: error_code - provider: - type: string - title: provider - model: - type: string - title: model - createdAt: - type: string - title: created_at - completedAt: - type: string - title: completed_at - title: ManagedExecutionOutcome - additionalProperties: false - console.v1.ManagedProviderAccessEvent: - type: object - properties: - eventId: - type: string - title: event_id - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - provider: - type: string - title: provider - environment: - type: string - title: environment - action: - type: string - title: action - actorPrincipalId: - type: string - title: actor_principal_id - note: - type: string - title: note - gatewaySyncOutcome: - type: string - title: gateway_sync_outcome - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: ManagedProviderAccessEvent - additionalProperties: false - description: Immutable recorded fact. Pending acceptance and subsequent delivery are separate entries. - console.v1.ManagedProviderAccessGrant: - type: object - properties: - organizationId: - type: string - title: organization_id - provider: - type: string - title: provider - environment: - type: string - title: environment - enabled: - type: boolean - title: enabled - grantedBy: - type: string - title: granted_by - note: - type: string - title: note - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - grantId: - type: string - title: grant_id - revision: - type: - - integer - - string - title: revision - format: int64 - state: - title: state - $ref: '#/components/schemas/console.v1.ManagedProviderAccessState' - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - gatewaySyncOutcome: - type: string - title: gateway_sync_outcome - durableEnrollment: - type: boolean - title: durable_enrollment - description: Explicit durable enrollment; no expiry. Legacy grants remain bounded. - workspaceId: - type: string - title: workspace_id - description: Authorized workspace used for owner synchronization; enrollment remains organization-wide. - title: ManagedProviderAccessGrant - additionalProperties: false - console.v1.MeetingCapture: - type: object - properties: - captureId: - type: string - title: capture_id - actionIntentId: - type: string - title: action_intent_id - meetingUrl: - type: string - title: meeting_url - botName: - type: string - title: bot_name - lifecycleState: - type: string - title: lifecycle_state - providerBotId: - type: string - title: provider_bot_id - transcriptState: - type: string - title: transcript_state - transcriptSegmentCount: - type: integer - title: transcript_segment_count - format: int32 - transcriptObjectId: - type: string - title: transcript_object_id - transcriptVersionId: - type: string - title: transcript_version_id - cerebroState: - type: string - title: cerebro_state - cerebroThingId: - type: string - title: cerebro_thing_id - errorCode: - type: string - title: error_code - requiredUserAction: - type: string - title: required_user_action - joinAt: - title: join_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - leaveAt: - title: leave_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - cerebroChunkCount: - type: integer - title: cerebro_chunk_count - format: int32 - cerebroChunkIds: - type: array - items: - type: string - title: cerebro_chunk_ids - cerebroRetrievalState: - type: string - title: cerebro_retrieval_state - cerebroRetrievalCandidateId: - type: string - title: cerebro_retrieval_candidate_id - providerRecordingId: - type: string - title: provider_recording_id - providerTranscriptId: - type: string - title: provider_transcript_id - sourceKind: - type: string - title: source_kind - description: |- - "direct_url" for a pasted meeting URL, "calendar_occurrence" for an - opted-in connected calendar call. - title: - type: string - title: title - description: Calendar event title. Empty for a direct meeting URL. - occurrenceStartAt: - title: occurrence_start_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - desiredState: - type: string - title: desired_state - description: '"enabled" while the capture is wanted, "disabled" after StopMeetingCapture.' - title: MeetingCapture - additionalProperties: false - description: |- - MeetingCapture is the Platform-owned status projection. Provider state, - immutable transcript references, Cerebro indexing, and tenant-scoped - retrieval proof remain separate so clients never infer completion from - display text. - console.v1.MissionSchedule: - type: object - properties: - scheduleId: - type: string - title: schedule_id - minLength: 1 - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - name: - type: string - title: name - minLength: 1 - cronExpression: - type: string - title: cron_expression - minLength: 1 - enabled: - type: boolean - title: enabled - template: - title: template - $ref: '#/components/schemas/console.v1.MissionScheduleTemplate' - nextRunAt: - title: next_run_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - lastRunAt: - title: last_run_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - lastStatus: - type: string - title: last_status - lastMissionId: - type: string - title: last_mission_id - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: MissionSchedule - required: - - template - - nextRunAt - - createdAt - - updatedAt - additionalProperties: false - console.v1.MissionScheduleCapability: - type: object - properties: - name: - type: string - title: name - minLength: 1 - description: - type: string - title: description - minLength: 1 - title: MissionScheduleCapability - additionalProperties: false - description: |- - MissionScheduleCapability is intentionally declared at the end of this - large file so adding it does not renumber unrelated generated descriptors. - console.v1.MissionScheduleTemplate: - type: object - properties: - goal: - type: string - title: goal - minLength: 1 - runnerProfile: - type: string - title: runner_profile - minLength: 1 - channelId: - type: string - title: channel_id - minLength: 1 - authorityMode: - not: - enum: - - 0 - title: authority_mode - description: |- - Selecting FULL_AUTONOMY is the schedule's explicit typed authority - confirmation. Console binds that selection to the authenticated principal - and persists the current confirmation contract version; the worker also - requires its independent full-autonomy feature gate. - $ref: '#/components/schemas/console.v1.ComputerMissionAuthorityMode' - capabilities: - type: array - items: - type: string - title: capabilities - minItems: 1 - resourceIds: - type: array - items: - type: string - title: resource_ids - minItems: 1 - requiredEvidence: - type: array - items: - type: string - title: required_evidence - minItems: 1 - budget: - title: budget - $ref: '#/components/schemas/console.v1.ComputerMissionBudget' - title: MissionScheduleTemplate - required: - - budget - additionalProperties: false - description: |- - MissionScheduleTemplate is the typed mission payload a schedule fires on - each due tick. Field shape mirrors ComputerMissionContract minus the - scope's organization/workspace ids (the schedule already carries those) - and the authority grant/resume fields, which the worker mints fresh for - each fired mission. - console.v1.OnboardingTask: - type: object - properties: - id: - type: string - title: id - title: - type: string - title: title - detail: - type: string - title: detail - status: - type: string - title: status - ctaLabel: - type: string - title: cta_label - command: - type: string - title: command - requiredIntegrations: - type: array - items: - type: string - title: required_integrations - title: OnboardingTask - additionalProperties: false - console.v1.OperateComputerMissionCanaryRunRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - canaryRunId: - type: string - title: canary_run_id - minLength: 1 - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryOperatorActionKind' - narrowedScope: - title: narrowed_scope - $ref: '#/components/schemas/console.v1.ComputerMissionScope' - extendedBudget: - title: extended_budget - $ref: '#/components/schemas/console.v1.ComputerMissionBudget' - extendedGrantExpiresAt: - title: extended_grant_expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - reason: - type: string - title: reason - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: OperateComputerMissionCanaryRunRequest - required: - - query - additionalProperties: false - console.v1.OperateComputerMissionCanaryRunResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryRun' - action: - title: action - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryOperatorAction' - title: OperateComputerMissionCanaryRunResponse - required: - - run - - action - additionalProperties: false - console.v1.OperatingAttachmentRef: - type: object - properties: - id: - type: string - title: id - objectId: - type: string - title: object_id - versionId: - type: string - title: version_id - scope: - title: scope - $ref: '#/components/schemas/console.v1.OperatingAttachmentScope' - channelId: - type: string - title: channel_id - filename: - type: string - title: filename - contentType: - type: string - title: content_type - sizeBytes: - type: - - integer - - string - title: size_bytes - maximum: 52428800 - format: int64 - sha256: - type: string - title: sha256 - processingState: - title: processing_state - $ref: '#/components/schemas/console.v1.OperatingAttachmentProcessingState' - extractionObjectId: - type: string - title: extraction_object_id - extractionVersionId: - type: string - title: extraction_version_id - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: OperatingAttachmentRef - additionalProperties: false - console.v1.OperatingAutoModelRoute: - type: object - properties: - target: - title: target - $ref: '#/components/schemas/console.v1.OperatingModelSelection' - purpose: - title: purpose - $ref: '#/components/schemas/console.v1.StaffInferenceRoutingPurpose' - policyVersion: - type: string - title: policy_version - placement: - title: placement - $ref: '#/components/schemas/console.v1.OperatingExecutionPlacement' - title: OperatingAutoModelRoute - additionalProperties: false - console.v1.OperatingCapabilityRequirementState: - type: object - properties: - service: - type: string - title: service - status: - type: string - title: status - reasonCode: - type: string - title: reason_code - remediationRef: - type: string - title: remediation_ref - title: OperatingCapabilityRequirementState - additionalProperties: false - console.v1.OperatingCapabilityState: - type: object - properties: - service: - type: string - title: service - status: - type: string - title: status - label: - type: string - title: label - detail: - type: string - title: detail - missingRequirements: - type: array - items: - type: string - title: missing_requirements - missingRequirementStates: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingCapabilityRequirementState' - title: missing_requirement_states - title: OperatingCapabilityState - additionalProperties: false - description: |- - OperatingCapabilityState is the UI-safe service availability summary for an - operating channel or receipt owner. - console.v1.OperatingChannel: - type: object - properties: - id: - type: string - title: id - label: - type: string - title: label - kind: - type: string - title: kind - sourceService: - type: string - title: source_service - unreadCount: - type: integer - title: unread_count - format: int32 - openCount: - type: integer - title: open_count - format: int32 - capabilityState: - title: capability_state - $ref: '#/components/schemas/console.v1.OperatingCapabilityState' - detail: - type: string - title: detail - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - surface: - title: surface - $ref: '#/components/schemas/console.v1.OperatingSurfaceMetadata' - archived: - type: boolean - title: archived - description: |- - Archive is a list-visibility state owned by the durable channel row. It - never implies provider-binding or execution lifecycle changes. - archivedAt: - title: archived_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - archivedByPrincipalId: - type: string - title: archived_by_principal_id - description: |- - Archive provenance is durable owner metadata. It is populated only for an - archived channel and cleared when the channel is unarchived. - archivedByDisplayName: - type: string - title: archived_by_display_name - fork: - title: fork - description: |- - Fork provenance is durable owner metadata, absent on a thread that was - started directly. - $ref: '#/components/schemas/console.v1.OperatingThreadFork' - projectResourceId: - type: string - title: project_resource_id - maxLength: 255 - description: |- - The source project this thread's work belongs to, empty when the thread - has never submitted a turn against one. This is the existing - `project_resource_id` from SubmitOperatingMessageRequest, recorded durably - on the thread so several threads working the same project can be listed - together. It is a grouping, never an authority: every read still resolves - the thread under the caller's own tenant scope. - title: OperatingChannel - additionalProperties: false - description: |- - OperatingChannel identifies a company/domain/thread surface the Console can - show. It carries capability state, not local operational data. - console.v1.OperatingCodingAcceptance: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - actorId: - type: string - title: actor_id - workId: - type: string - title: work_id - runtimeRunId: - type: string - title: runtime_run_id - contract: - title: contract - $ref: '#/components/schemas/console.v1.CodingAcceptanceContract' - accepted: - type: boolean - title: accepted - contractDigest: - type: string - title: contract_digest - submissionDigest: - type: string - title: submission_digest - reasons: - type: array - items: - type: string - title: reasons - revision: - type: string - title: revision - outputs: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingCodingOutput' - title: outputs - title: OperatingCodingAcceptance - additionalProperties: false - description: |- - Read-only projection of the decision committed by Platform's fenced coding - acceptance owner. Absence is not acceptance. Artifact bytes remain separately - owned by VFS and must be read and verified by consumers. - console.v1.OperatingCodingOutput: - type: object - properties: - path: - type: string - title: path - objectId: - type: string - title: object_id - versionId: - type: string - title: version_id - sha256: - type: string - title: sha256 - sizeBytes: - type: - - integer - - string - title: size_bytes - format: int64 - content: - type: string - title: content - format: byte - description: Read from VFS only for an explicit originating-actor receipt read. Never persisted here. - title: OperatingCodingOutput - additionalProperties: false - console.v1.OperatingCorrectionCandidate: - type: object - properties: - id: - type: string - title: id - channelId: - type: string - title: channel_id - messageId: - type: string - title: message_id - category: - title: category - $ref: '#/components/schemas/console.v1.OperatingCorrectionCategory' - feedbackDigestSha256: - type: string - title: feedback_digest_sha256 - rememberRequested: - type: boolean - title: remember_requested - learningEligible: - type: boolean - title: learning_eligible - reviewState: - title: review_state - $ref: '#/components/schemas/console.v1.OperatingCorrectionReviewState' - reviewerId: - type: string - title: reviewer_id - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - maxItems: 64 - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - reviewedAt: - title: reviewed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - reviewCapability: - title: review_capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - correctionEpisode: - title: correction_episode - $ref: '#/components/schemas/console.v1.DexComputerCorrectionEpisode' - title: OperatingCorrectionCandidate - required: - - correctionEpisode - additionalProperties: false - console.v1.OperatingCustomerOutcomeIdentity: - type: object - properties: - studyOrgKey: - type: string - title: study_org_key - maxLength: 128 - description: |- - Purpose-limited HMAC of the organization identity. Empty means the study - is not enabled or the service has no configured study key. - consentState: - type: string - title: consent_state - maxLength: 32 - description: Service-owned consent/eligibility state, never inferred by the browser. - consentPolicyVersion: - type: string - title: consent_policy_version - maxLength: 64 - sourceRevision: - type: string - title: source_revision - maxLength: 64 - workflowId: - type: string - title: workflow_id - maxLength: 128 - workflowVersion: - type: string - title: workflow_version - maxLength: 64 - modelId: - type: string - title: model_id - maxLength: 128 - modelRevision: - type: string - title: model_revision - maxLength: 128 - providerId: - type: string - title: provider_id - maxLength: 128 - providerRoute: - type: string - title: provider_route - maxLength: 128 - configDigest: - type: string - title: config_digest - maxLength: 128 - promptTemplateRevision: - type: string - title: prompt_template_revision - maxLength: 128 - toolchainRevision: - type: string - title: toolchain_revision - maxLength: 128 - featureFlagSnapshotDigest: - type: string - title: feature_flag_snapshot_digest - maxLength: 128 - rolloutId: - type: string - title: rollout_id - maxLength: 128 - title: OperatingCustomerOutcomeIdentity - additionalProperties: false - console.v1.OperatingExecutionIdentity: - type: object - properties: - runtime: - title: runtime - $ref: '#/components/schemas/console.v1.OperatingExecutionRuntime' - runId: - type: string - title: run_id - maxLength: 256 - minLength: 1 - runnerSessionId: - type: string - title: runner_session_id - maxLength: 256 - minLength: 1 - protocolVersion: - type: string - title: protocol_version - maxLength: 128 - minLength: 1 - runtimeGeneration: - exclusiveMinimum: 0 - type: - - integer - - string - title: runtime_generation - format: int64 - eventCursor: - exclusiveMinimum: 0 - type: - - integer - - string - title: event_cursor - format: int64 - causalReceiptId: - type: string - title: causal_receipt_id - maxLength: 128 - description: |- - Immutable release/execution identity used to join bounded deployment and - runtime receipts. It is intentionally opaque and never carries content. - maestroSessionId: - type: string - title: maestro_session_id - maxLength: 256 - maestroRunId: - type: string - title: maestro_run_id - maxLength: 256 - residentProcessGeneration: - type: - - integer - - string - title: resident_process_generation - format: int64 - turnId: - type: string - title: turn_id - maxLength: 128 - appendReplayed: - type: boolean - title: append_replayed - title: OperatingExecutionIdentity - additionalProperties: false - description: |- - OperatingExecutionIdentity is a credential-free drill-down identity for the - hosted execution that produced a thread event. It is safe to persist with - the browser projection; Runner Host service, Pod, certificate, and cluster - coordinates remain private. - console.v1.OperatingFeedback: - type: object - properties: - id: - type: string - title: id - channelId: - type: string - title: channel_id - messageId: - type: string - title: message_id - sentiment: - title: sentiment - $ref: '#/components/schemas/console.v1.OperatingFeedbackSentiment' - category: - title: category - $ref: '#/components/schemas/console.v1.OperatingCorrectionCategory' - classificationSource: - title: classification_source - $ref: '#/components/schemas/console.v1.OperatingFeedbackClassificationSource' - taxonomyVersion: - type: string - title: taxonomy_version - correctionPresent: - type: boolean - title: correction_present - correctionId: - type: string - title: correction_id - learningEligible: - type: boolean - title: learning_eligible - remediationAction: - title: remediation_action - $ref: '#/components/schemas/console.v1.OperatingFeedbackRemediationAction' - remediationAttemptId: - type: string - title: remediation_attempt_id - remediationOutcome: - title: remediation_outcome - $ref: '#/components/schemas/console.v1.OperatingFeedbackRemediationOutcome' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - resolvedAt: - title: resolved_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - reason: - title: reason - $ref: '#/components/schemas/console.v1.OperatingFeedbackReason' - lifecycleState: - title: lifecycle_state - $ref: '#/components/schemas/console.v1.OperatingFeedbackLifecycleState' - rootFeedbackId: - type: string - title: root_feedback_id - revision: - type: - - integer - - string - title: revision - format: int64 - supersedesFeedbackId: - type: string - title: supersedes_feedback_id - title: OperatingFeedback - additionalProperties: false - console.v1.OperatingHistoryContextRecord: - type: object - properties: - channelId: - type: string - title: channel_id - sourceKind: - type: string - title: source_kind - sourceId: - type: string - title: source_id - role: - type: string - title: role - toolName: - type: string - title: tool_name - status: - type: string - title: status - body: - type: string - title: body - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - sourceRef: - title: source_ref - $ref: '#/components/schemas/console.v1.RelatedResource' - title: OperatingHistoryContextRecord - additionalProperties: false - console.v1.OperatingHistorySearchFilter: - type: object - properties: - recordKinds: - type: array - items: - type: string - title: record_kinds - roles: - type: array - items: - type: string - title: roles - toolNames: - type: array - items: - type: string - title: tool_names - statuses: - type: array - items: - type: string - title: statuses - occurredAfter: - title: occurred_after - $ref: '#/components/schemas/google.protobuf.Timestamp' - occurredBefore: - title: occurred_before - $ref: '#/components/schemas/google.protobuf.Timestamp' - channelIds: - type: array - items: - type: string - title: channel_ids - title: OperatingHistorySearchFilter - additionalProperties: false - console.v1.OperatingHistorySearchResult: - type: object - properties: - channelId: - type: string - title: channel_id - channelTitle: - type: string - title: channel_title - sourceKind: - type: string - title: source_kind - sourceId: - type: string - title: source_id - role: - type: string - title: role - toolName: - type: string - title: tool_name - status: - type: string - title: status - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - excerpt: - type: string - title: excerpt - score: - type: number - title: score - format: double - contextCursor: - type: string - title: context_cursor - sourceRef: - title: source_ref - $ref: '#/components/schemas/console.v1.RelatedResource' - title: OperatingHistorySearchResult - additionalProperties: false - console.v1.OperatingHomepageSuggestion: - type: object - properties: - schema: - type: string - title: schema - const: dex.homepage_suggestion.v1 - label: - type: string - title: label - maxLength: 160 - minLength: 1 - prompt: - type: string - title: prompt - maxLength: 1000 - minLength: 1 - source: - type: string - title: source - const: cerebro - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - maxItems: 8 - generatedAt: - title: generated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: - type: string - title: title - maxLength: 60 - minLength: 1 - description: |- - Short model-generated topic title grounded in the same cited evidence as - the memory line. Absent when the model abstains or validation fails. - suggestionId: - type: string - title: suggestion_id - minLength: 1 - title: OperatingHomepageSuggestion - required: - - generatedAt - - expiresAt - additionalProperties: false - console.v1.OperatingJob: - type: object - properties: - jobId: - type: string - title: job_id - minLength: 1 - objectiveId: - type: string - title: objective_id - minLength: 1 - title: - type: string - title: title - minLength: 1 - state: - title: state - $ref: '#/components/schemas/console.v1.OperatingJobState' - verificationState: - title: verification_state - $ref: '#/components/schemas/console.v1.OperatingJobVerificationState' - origin: - title: origin - $ref: '#/components/schemas/console.v1.OperatingJobOrigin' - channelId: - type: string - title: channel_id - submittedMessageId: - type: string - title: submitted_message_id - conversationContextId: - type: string - title: conversation_context_id - conversationTaskId: - type: string - title: conversation_task_id - conversationTaskRevision: - type: - - integer - - string - title: conversation_task_revision - format: int64 - activeRunId: - type: string - title: active_run_id - attemptCount: - type: integer - title: attempt_count - format: int32 - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - projectionComplete: - type: boolean - title: projection_complete - description: |- - False means an older producer omitted one or more typed correlations. - Clients may render the job but must not infer the missing owner data. - missingOwnerData: - type: array - items: - type: string - maxLength: 64 - minLength: 1 - maxItems: 16 - title: missing_owner_data - maxItems: 16 - recordLinks: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingJobRecordLink' - title: record_links - maxItems: 256 - description: |- - Causal references only. Record payloads remain with their authoritative - owners and are resolved under the request's authenticated tenant. - proofState: - title: proof_state - $ref: '#/components/schemas/console.v1.OperatingJobProofState' - missingProof: - type: array - items: - type: string - maxLength: 64 - minLength: 1 - maxItems: 16 - title: missing_proof - maxItems: 16 - description: |- - Stable machine-readable categories such as action_lineage, - policy_decision, usage, and terminal_receipt. - title: OperatingJob - additionalProperties: false - description: |- - OperatingJob is a bounded customer projection over owner records. It never - contains raw prompts, tool arguments/results, credentials, or receipt - payloads. job_id and objective_id are equal for this v1 projection. - console.v1.OperatingJobRecordLink: - type: object - properties: - correlationId: - type: string - title: correlation_id - minLength: 1 - relation: - type: string - title: relation - minLength: 1 - record: - title: record - $ref: '#/components/schemas/platform.v1.RecordRef' - title: OperatingJobRecordLink - required: - - record - additionalProperties: false - description: |- - OperatingJobRecordLink is one append-only causal edge from the job's active - run to an independently owned record. correlation_id groups records emitted - by the same operation milestone; relation is a bounded server-authored value. - console.v1.OperatingMessage: - type: object - properties: - id: - type: string - title: id - channelId: - type: string - title: channel_id - role: - type: string - title: role - actorLabel: - type: string - title: actor_label - body: - type: string - title: body - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - receiptIds: - type: array - items: - type: string - title: receipt_ids - route: - title: route - $ref: '#/components/schemas/console.v1.OperatingTurnRoute' - attachments: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingAttachmentRef' - title: attachments - turnRecord: - title: turn_record - description: |- - Safe structured state for the accepted turn. Raw prompts, tool arguments, - tool results, connector payloads, and model responses are forbidden here. - $ref: '#/components/schemas/console.v1.OperatingTurnRecord' - modelSelection: - title: model_selection - $ref: '#/components/schemas/console.v1.OperatingModelSelection' - autoModelRoute: - title: auto_model_route - $ref: '#/components/schemas/console.v1.OperatingAutoModelRoute' - title: OperatingMessage - additionalProperties: false - description: OperatingMessage is safe conversation text plus links to typed receipts. - console.v1.OperatingModelSelection: - type: object - properties: - provider: - type: string - title: provider - maxLength: 128 - model: - type: string - title: model - maxLength: 256 - title: OperatingModelSelection - additionalProperties: false - description: |- - A conversation preference, validated against the tenant's enabled targets. - An empty provider/model pair uses the organization's normal routing. - console.v1.OperatingProjectSnapshotFileInput: - type: object - properties: - path: - type: string - title: path - maxLength: 1024 - minLength: 1 - attachment: - title: attachment - $ref: '#/components/schemas/console.v1.OperatingAttachmentRef' - title: OperatingProjectSnapshotFileInput - required: - - attachment - additionalProperties: false - console.v1.OperatingReceipt: - type: object - properties: - id: - type: string - title: id - kind: - type: string - title: kind - title: - type: string - title: title - summary: - type: string - title: summary - status: - type: string - title: status - ownerService: - type: string - title: owner_service - objectId: - type: string - title: object_id - objectiveId: - type: string - title: objective_id - runId: - type: string - title: run_id - approvalRequestId: - type: string - title: approval_request_id - traceId: - type: string - title: trace_id - riskLevel: - title: risk_level - $ref: '#/components/schemas/common.v1.RiskLevel' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - allowedActions: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingReceiptAction' - title: allowed_actions - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Struct' - lifecycleState: - title: lifecycle_state - description: |- - Owner-resolved lifecycle. Thread responses strip receipt payloads, so this - is the only lifecycle statement a client can read there. - $ref: '#/components/schemas/console.v1.ReceiptLifecycleState' - codingAcceptance: - title: coding_acceptance - description: Set only by the fenced coding completion owner; absent until evaluated. - $ref: '#/components/schemas/console.v1.OperatingCodingAcceptance' - title: OperatingReceipt - additionalProperties: false - description: |- - OperatingReceipt is the mini-app object rendered inline in chat and expanded - in the inspector. Display payloads must be safe for UI rendering and must not - include raw prompts, tool arguments, credentials, tokens, connector payloads, - VFS bytes, or model responses. - console.v1.OperatingReceiptAction: - type: object - properties: - id: - type: string - title: id - label: - type: string - title: label - kind: - type: string - title: kind - targetKind: - type: string - title: target_kind - targetId: - type: string - title: target_id - requiresConfirmation: - type: boolean - title: requires_confirmation - disabledReason: - type: string - title: disabled_reason - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Struct' - title: OperatingReceiptAction - additionalProperties: false - description: OperatingReceiptAction is a typed command the backend allows for one receipt. - console.v1.OperatingSkill: - type: object - properties: - id: - type: string - title: id - workspaceId: - type: string - title: workspace_id - minLength: 1 - name: - type: string - title: name - minLength: 1 - description: - type: string - title: description - body: - type: string - title: body - version: - type: integer - title: version - format: int32 - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - organizationId: - type: string - title: organization_id - minLength: 1 - catalogSkillId: - type: string - title: catalog_skill_id - description: |- - Catalog provenance is present only when the workspace skill was installed - from BrowseDexSkillCatalog. It lets clients keep attribution visible after - the skill moves from the library into the installed workspace list. - catalogVersion: - type: integer - title: catalog_version - format: int32 - analysis: - title: analysis - description: |- - Deterministic analysis of the exact stored description and body. Content - findings are advisory and never authorize, block, or route behavior. - $ref: '#/components/schemas/console.v1.SkillAnalysisReport' - sourceRevision: - type: string - title: source_revision - packageDigest: - type: string - title: package_digest - packageManifest: - type: array - items: - $ref: '#/components/schemas/console.v1.DexSkillPackageFile' - title: package_manifest - activationTrigger: - type: string - title: activation_trigger - objective: - type: string - title: objective - inputs: - type: array - items: - $ref: '#/components/schemas/console.v1.DexSkillInputDeclaration' - title: inputs - outputs: - type: array - items: - $ref: '#/components/schemas/console.v1.DexSkillOutputDeclaration' - title: outputs - orderedMethod: - type: array - items: - type: string - title: ordered_method - successCriteria: - type: array - items: - type: string - title: success_criteria - unavailableBehavior: - type: string - title: unavailable_behavior - outputContract: - type: string - title: output_contract - licenseEvidence: - title: license_evidence - $ref: '#/components/schemas/console.v1.DexSkillLicenseEvidence' - compatibility: - title: compatibility - $ref: '#/components/schemas/console.v1.DexSkillCompatibility' - qualityEvidence: - title: quality_evidence - $ref: '#/components/schemas/console.v1.DexSkillQualityEvidence' - lifecycleState: - title: lifecycle_state - $ref: '#/components/schemas/console.v1.DexSkillLifecycleState' - customerSafeRemediation: - type: string - title: customer_safe_remediation - updateDiff: - title: update_diff - $ref: '#/components/schemas/console.v1.DexSkillUpdateDiff' - requiredTools: - type: array - items: - type: string - title: required_tools - title: OperatingSkill - additionalProperties: false - description: |- - OperatingSkill is a workspace-scoped named procedure Dex can discover and - load at runtime (see docs on the operating_skills table). name is unique - per workspace and kebab-case; description is a single line shown in - listings; body is the markdown procedure text. - console.v1.OperatingSurfaceMetadata: - type: object - properties: - kind: - title: kind - $ref: '#/components/schemas/console.v1.OperatingSurfaceKind' - providerId: - type: string - title: provider_id - connectionId: - type: string - title: connection_id - providerWorkspaceId: - type: string - title: provider_workspace_id - providerChannelId: - type: string - title: provider_channel_id - providerThreadId: - type: string - title: provider_thread_id - bindingKind: - type: string - title: binding_kind - title: OperatingSurfaceMetadata - additionalProperties: false - description: |- - OperatingSurfaceMetadata is the credential-free origin and continuation - target for one canonical operating conversation. Provider coordinates are - always returned inside the already-authorized tenant scope. - console.v1.OperatingTaskEnvironmentStage: - type: object - properties: - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/console.v1.OperatingTaskEnvironmentStageKind' - state: - not: - enum: - - 0 - title: state - $ref: '#/components/schemas/console.v1.OperatingTaskEnvironmentStageState' - code: - type: string - title: code - maxLength: 128 - title: OperatingTaskEnvironmentStage - additionalProperties: false - console.v1.OperatingThreadEvent: - type: object - properties: - cursor: - exclusiveMinimum: 0 - type: - - integer - - string - title: cursor - format: int64 - eventId: - type: string - title: event_id - turnId: - type: string - title: turn_id - kind: - title: kind - $ref: '#/components/schemas/console.v1.OperatingThreadEventKind' - safeText: - type: string - title: safe_text - maxLength: 4096 - artifactRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: artifact_refs - maxItems: 32 - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - executionIdentity: - title: execution_identity - $ref: '#/components/schemas/console.v1.OperatingExecutionIdentity' - requestId: - type: string - title: request_id - maxLength: 256 - requestType: - title: request_type - $ref: '#/components/schemas/console.v1.OperatingThreadRequestType' - requestTool: - type: string - title: request_tool - maxLength: 256 - requestCallId: - type: string - title: request_call_id - maxLength: 256 - terminalError: - title: terminal_error - $ref: '#/components/schemas/console.v1.TerminalErrorEnvelope' - title: OperatingThreadEvent - additionalProperties: false - description: |- - OperatingThreadEvent is an append-only, browser-safe execution projection. - Raw prompts, tool arguments/results, and infrastructure coordinates are not - valid event fields. - console.v1.OperatingThreadExecution: - type: object - properties: - threadId: - type: string - title: thread_id - state: - title: state - $ref: '#/components/schemas/console.v1.OperatingThreadExecutionState' - activeTurnSequence: - type: - - integer - - string - title: active_turn_sequence - format: int64 - replayCursor: - type: - - integer - - string - title: replay_cursor - format: int64 - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - executionIdentity: - title: execution_identity - $ref: '#/components/schemas/console.v1.OperatingExecutionIdentity' - terminalTurnSequence: - type: - - integer - - string - title: terminal_turn_sequence - format: int64 - description: |- - The terminal turn that established the current ready/degraded state. A - non-zero marker lets clients distinguish an owner terminal projection - from an older provisioning snapshot without inspecting message copy. - controllerOwner: - type: string - title: controller_owner - maxLength: 64 - controllerLeaseGeneration: - type: - - integer - - string - title: controller_lease_generation - format: int64 - title: OperatingThreadExecution - additionalProperties: false - description: |- - OperatingThreadExecution is the user-safe projection of one durable Dex - thread. Runner, Pod, service, certificate, and cluster coordinates are - intentionally absent. - console.v1.OperatingThreadFork: - type: object - properties: - sourceChannelId: - type: string - title: source_channel_id - throughMessageId: - type: string - title: through_message_id - description: The last source message copied into the fork. - sourceConversationRevision: - type: - - integer - - string - title: source_conversation_revision - format: int64 - description: |- - The source's conversation_revision at the moment of the fork. Together - with through_message_id this names exactly what was copied. - forkedByPrincipalId: - type: string - title: forked_by_principal_id - forkedAt: - title: forked_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - copiedMessageCount: - type: integer - title: copied_message_count - format: int32 - title: OperatingThreadFork - additionalProperties: false - description: |- - Where a forked operating thread came from. - - A fork copies conversation content and nothing else. It does not inherit - the source's pinned model selection, its Auto route, its receipts, its - attachments, or its turn records, because each of those carries authority - that was granted to the source thread's principal rather than to whoever - forked it. The fork re-resolves all of them under the forking principal. - console.v1.OperatingThreadResponse: - type: object - properties: - requestId: - type: string - title: request_id - maxLength: 256 - minLength: 1 - callId: - type: string - title: call_id - maxLength: 256 - requestType: - title: request_type - $ref: '#/components/schemas/console.v1.OperatingThreadRequestType' - action: - title: action - $ref: '#/components/schemas/console.v1.OperatingThreadResponseAction' - text: - type: string - title: text - maxLength: 65536 - isError: - type: boolean - title: is_error - idempotencyKey: - type: string - title: idempotency_key - maxLength: 512 - title: OperatingThreadResponse - additionalProperties: false - console.v1.OperatingThreadTurn: - type: object - properties: - turnId: - type: string - title: turn_id - sequence: - exclusiveMinimum: 0 - type: - - integer - - string - title: sequence - format: int64 - userMessageId: - type: string - title: user_message_id - assistantMessageId: - type: string - title: assistant_message_id - state: - title: state - $ref: '#/components/schemas/console.v1.OperatingTurnState' - waitingReason: - title: waiting_reason - $ref: '#/components/schemas/console.v1.OperatingThreadWaitingReason' - firstCursor: - type: - - integer - - string - title: first_cursor - format: int64 - lastCursor: - type: - - integer - - string - title: last_cursor - format: int64 - errorCode: - type: string - title: error_code - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - completedAt: - title: completed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - terminalError: - title: terminal_error - $ref: '#/components/schemas/console.v1.TerminalErrorEnvelope' - title: OperatingThreadTurn - additionalProperties: false - console.v1.OperatingToolEvent: - type: object - properties: - callId: - type: string - title: call_id - toolName: - type: string - title: tool_name - status: - type: string - title: status - receiptId: - type: string - title: receipt_id - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - title: OperatingToolEvent - additionalProperties: false - console.v1.OperatingTurnRecord: - type: object - properties: - sessionId: - type: string - title: session_id - turnId: - type: string - title: turn_id - sequence: - type: - - integer - - string - title: sequence - format: int64 - goal: - type: string - title: goal - maxLength: 2000 - contextDigestSha256: - type: string - title: context_digest_sha256 - state: - title: state - $ref: '#/components/schemas/console.v1.OperatingTurnState' - verificationState: - title: verification_state - $ref: '#/components/schemas/console.v1.OperatingVerificationState' - toolEvents: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingToolEvent' - title: tool_events - maxItems: 64 - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - maxItems: 64 - errorCode: - type: string - title: error_code - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - answerProvenance: - title: answer_provenance - $ref: '#/components/schemas/console.v1.OperatingAnswerProvenance' - contextId: - type: string - title: context_id - maxLength: 256 - description: context_id groups independently addressable tasks in one conversation. - taskId: - type: string - title: task_id - maxLength: 256 - description: task_id remains stable while a user refines, corrects, or resumes work. - taskRevision: - type: - - integer - - string - title: task_revision - format: int64 - referenceTaskIds: - type: array - items: - type: string - maxLength: 256 - minLength: 1 - maxItems: 16 - title: reference_task_ids - maxItems: 16 - artifactIntentKind: - type: string - title: artifact_intent_kind - maxLength: 32 - description: |- - Server-owned artifact intent carried from a clarification into its next - turn. This is safe routing metadata, not model content or tool arguments. - customerOutcomeIdentity: - title: customer_outcome_identity - description: |- - Server-owned identity for the privacy-bounded customer-outcome study. - This is safe routing/evidence metadata only; it must never contain raw - prompts, outputs, customer identifiers, credentials, or tool payloads. - $ref: '#/components/schemas/console.v1.OperatingCustomerOutcomeIdentity' - projectSource: - title: project_source - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionProjectSource' - workspaceRecipe: - title: workspace_recipe - description: Accepted once with the task and replayed unchanged. - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionWorkspaceRecipe' - codingAcceptance: - title: coding_acceptance - description: |- - Exact coding requirements accepted on the first task revision. Later - revisions must match this value rather than re-running current selector - policy. Absence is meaningful for an admitted non-coding task. - $ref: '#/components/schemas/console.v1.CodingAcceptanceContract' - workspaceRecipeAdmissionVersion: - type: integer - title: workspace_recipe_admission_version - format: int32 - description: |- - Marks records admitted by the immutable workspace-recipe contract. - Zero identifies legacy records whose absent recipe/contract must replay - without reinterpretation. - title: OperatingTurnRecord - additionalProperties: false - console.v1.OperatingTurnRoute: - type: object - properties: - kind: - title: kind - $ref: '#/components/schemas/console.v1.OperatingTurnRouteKind' - intentKind: - title: intent_kind - $ref: '#/components/schemas/console.v1.OperatingTurnIntentKind' - answerKind: - title: answer_kind - $ref: '#/components/schemas/console.v1.OperatingTurnAnswerKind' - safetyKind: - title: safety_kind - $ref: '#/components/schemas/console.v1.OperatingTurnSafetyKind' - router: - type: string - title: router - decidedAt: - title: decided_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: OperatingTurnRoute - additionalProperties: false - description: |- - OperatingTurnRoute is backend-owned routing metadata for a chat turn. Clients - must use this typed contract instead of deriving behavior from prompt text or - assistant copy. - console.v1.OperatorModelPreference: - type: object - properties: - provider: - type: string - title: provider - maxLength: 128 - minLength: 1 - model: - type: string - title: model - maxLength: 256 - minLength: 1 - favorite: - type: boolean - title: favorite - hidden: - type: boolean - title: hidden - title: OperatorModelPreference - additionalProperties: false - description: Personal model browsing choices; these never grant access to a model. - console.v1.OperatorModelPreferenceUpdate: - type: object - properties: - provider: - type: string - title: provider - maxLength: 128 - minLength: 1 - model: - type: string - title: model - maxLength: 256 - minLength: 1 - favorite: - type: boolean - title: favorite - nullable: true - hidden: - type: boolean - title: hidden - nullable: true - title: OperatorModelPreferenceUpdate - additionalProperties: false - console.v1.OperatorPreferences: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - dexHatId: - type: string - title: dex_hat_id - minLength: 1 - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - developerModeEnabled: - type: boolean - title: developer_mode_enabled - modelPreferences: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatorModelPreference' - title: model_preferences - title: OperatorPreferences - additionalProperties: false - console.v1.OrbControlTarget: - type: object - properties: - id: - type: string - title: id - displayName: - type: string - title: display_name - lifecycle: - title: lifecycle - $ref: '#/components/schemas/orbcontrol.v1.OrbObservedLifecycle' - generation: - type: - - integer - - string - title: generation - format: int64 - observedRevision: - type: - - integer - - string - title: observed_revision - format: int64 - lastEventSequence: - type: - - integer - - string - title: last_event_sequence - format: int64 - residentAgent: - type: string - title: resident_agent - provisioner: - type: string - title: provisioner - ownerStatus: - type: string - title: owner_status - observedAt: - title: observed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - allowedActions: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingReceiptAction' - title: allowed_actions - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.OperatingReceipt' - title: OrbControlTarget - additionalProperties: false - description: OrbControlTarget is the Platform-owned customer-facing runtime projection. - console.v1.PauseComputerMissionRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - missionId: - type: string - title: mission_id - minLength: 1 - expectedGeneration: - type: - - integer - - string - title: expected_generation - format: int64 - reason: - type: string - title: reason - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - condition: - title: condition - $ref: '#/components/schemas/google.protobuf.Struct' - wakeAt: - title: wake_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: PauseComputerMissionRequest - required: - - query - additionalProperties: false - console.v1.PauseComputerMissionResponse: - type: object - properties: - mission: - title: mission - $ref: '#/components/schemas/console.v1.ComputerMission' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.OperatingReceipt' - wakeId: - type: string - title: wake_id - minLength: 1 - title: PauseComputerMissionResponse - required: - - mission - - receipt - additionalProperties: false - console.v1.PinnedSource: - type: object - properties: - sourceId: - type: string - title: source_id - pinnedAt: - title: pinned_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - pinnedBy: - type: string - title: pinned_by - title: PinnedSource - additionalProperties: false - console.v1.PrepareBusinessObjectAuthorityTransferRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - objectId: - type: string - title: object_id - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - authorityEpoch: - type: - - integer - - string - title: authority_epoch - format: int64 - title: PrepareBusinessObjectAuthorityTransferRequest - additionalProperties: false - console.v1.PrepareBusinessObjectAuthorityTransferResponse: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/console.v1.BusinessObject' - ready: - type: boolean - title: ready - unavailableReason: - type: string - title: unavailable_reason - title: PrepareBusinessObjectAuthorityTransferResponse - additionalProperties: false - console.v1.PrepareStaffProductIssueRecoveryRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - maxLength: 4000 - workspaceId: - type: string - title: workspace_id - maxLength: 4000 - sourceOrganizationId: - type: string - title: source_organization_id - maxLength: 4000 - sourceWorkspaceId: - type: string - title: source_workspace_id - maxLength: 4000 - reportId: - type: string - title: report_id - maxLength: 4000 - errorCode: - type: string - title: error_code - maxLength: 4000 - startUnixSeconds: - type: - - integer - - string - title: start_unix_seconds - format: int64 - endUnixSeconds: - type: - - integer - - string - title: end_unix_seconds - format: int64 - recipientPrincipalId: - type: string - title: recipient_principal_id - maxLength: 4000 - customerSummary: - type: string - title: customer_summary - maxLength: 4000 - deploymentVerification: - type: string - title: deployment_verification - maxLength: 4000 - title: PrepareStaffProductIssueRecoveryRequest - additionalProperties: false - description: Durable, explicitly scoped customer recovery contract. - console.v1.PrewarmOperatingThreadRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - maxLength: 256 - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 512 - minLength: 1 - model: - type: string - title: model - maxLength: 256 - organizationId: - type: string - title: organization_id - maxLength: 256 - workspaceId: - type: string - title: workspace_id - maxLength: 256 - title: PrewarmOperatingThreadRequest - required: - - query - additionalProperties: false - console.v1.PrewarmOperatingThreadResponse: - type: object - properties: - channelId: - type: string - title: channel_id - prewarmId: - type: string - title: prewarm_id - maestroSessionId: - type: string - title: maestro_session_id - runnerSessionId: - type: string - title: runner_session_id - runnerState: - type: string - title: runner_state - attachable: - type: boolean - title: attachable - replayed: - type: boolean - title: replayed - prewarmHit: - type: boolean - title: prewarm_hit - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - threadId: - type: string - title: thread_id - replenishmentBlocked: - type: boolean - title: replenishment_blocked - description: |- - True when a different requested draft was held behind the consumed - first turn. The response still identifies the durable existing thread so - the client can remain writable without silently minting another runner. - title: PrewarmOperatingThreadResponse - additionalProperties: false - console.v1.PrivateEndpoint: - type: object - properties: - endpointId: - type: string - title: endpoint_id - minLength: 1 - provider: - type: string - title: provider - minLength: 1 - endpointUri: - type: string - title: endpoint_uri - minLength: 1 - serviceName: - type: string - title: service_name - minLength: 1 - region: - type: string - title: region - minLength: 1 - dnsName: - type: string - title: dns_name - minLength: 1 - relayId: - type: string - title: relay_id - state: - type: string - title: state - minLength: 1 - healthState: - type: string - title: health_state - minLength: 1 - routeRevision: - type: - - integer - - string - title: route_revision - format: int64 - routeIdentity: - type: string - title: route_identity - minLength: 1 - verifiedEvidenceId: - type: string - title: verified_evidence_id - revocationReason: - type: string - title: revocation_reason - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - revokedAt: - title: revoked_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: PrivateEndpoint - additionalProperties: false - console.v1.PrivateProfileRoute: - type: object - properties: - profileId: - type: string - title: profile_id - minLength: 1 - endpointId: - type: string - title: endpoint_id - routeMode: - type: string - title: route_mode - minLength: 1 - requirePrivate: - type: boolean - title: require_private - routeRevision: - type: - - integer - - string - title: route_revision - format: int64 - state: - type: string - title: state - minLength: 1 - routeIdentity: - type: string - title: route_identity - routeOrigin: - type: string - title: route_origin - privateRoute: - type: boolean - title: private_route - title: PrivateProfileRoute - additionalProperties: false - console.v1.ProductIssueRecovery: - type: object - properties: - organizationId: - type: string - title: organization_id - maxLength: 4000 - workspaceId: - type: string - title: workspace_id - maxLength: 4000 - recoveryId: - type: string - title: recovery_id - maxLength: 4000 - reportReference: - type: string - title: report_reference - maxLength: 4000 - recipientPrincipalId: - type: string - title: recipient_principal_id - maxLength: 4000 - customerSummary: - type: string - title: customer_summary - maxLength: 4000 - state: - type: string - title: state - maxLength: 4000 - revision: - type: - - integer - - string - title: revision - format: int64 - affectedRequestCount: - type: - - integer - - string - title: affected_request_count - format: int64 - expectedCreditMicros: - type: - - integer - - string - title: expected_credit_micros - format: int64 - compensatedMicros: - type: - - integer - - string - title: compensated_micros - format: int64 - remainingRequestCount: - type: - - integer - - string - title: remaining_request_count - format: int64 - notificationId: - type: string - title: notification_id - maxLength: 4000 - lastReply: - type: string - title: last_reply - maxLength: 4000 - coverage: - type: string - title: coverage - maxLength: 4000 - deploymentVerification: - type: string - title: deployment_verification - maxLength: 4000 - title: ProductIssueRecovery - additionalProperties: false - description: Durable, explicitly scoped customer recovery contract. - console.v1.ProductIssueRecoveryResponse: - type: object - properties: - recovery: - title: recovery - $ref: '#/components/schemas/console.v1.ProductIssueRecovery' - title: ProductIssueRecoveryResponse - additionalProperties: false - description: Durable, explicitly scoped customer recovery contract. - console.v1.ProductIssueReport: - type: object - properties: - id: - type: string - title: id - reference: - type: string - title: reference - diagnosticsIncluded: - type: boolean - title: diagnostics_included - screenshotAttached: - type: boolean - title: screenshot_attached - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: ProductIssueReport - additionalProperties: false - console.v1.ProductIssueReportContext: - type: object - properties: - reproductionSteps: - type: string - title: reproduction_steps - maxLength: 4000 - model: - type: string - title: model - maxLength: 256 - evidence: - type: array - items: - $ref: '#/components/schemas/console.v1.ProductIssueReportEvidence' - title: evidence - maxItems: 10 - title: ProductIssueReportContext - additionalProperties: false - description: Explicitly selected native evidence. No session or machine-wide collection. - console.v1.ProductIssueReportEvidence: - type: object - properties: - kind: - type: string - title: kind - maxLength: 32 - sourceId: - type: string - title: source_id - maxLength: 256 - text: - type: string - title: text - maxLength: 4000 - title: ProductIssueReportEvidence - additionalProperties: false - console.v1.ProjectTaskEnvironmentRetention: - type: object - properties: - projectResourceId: - type: string - title: project_resource_id - minLength: 1 - retentionDays: - type: integer - title: retention_days - format: int32 - enum: - - 0 - - 7 - - 30 - description: Absent means inherit the workspace default. - nullable: true - retentionHours: - type: integer - title: retention_hours - format: int32 - enum: - - 8 - - 168 - - 720 - description: Preferred hour-level policy. Zero means the legacy retention_days field. - nullable: true - title: ProjectTaskEnvironmentRetention - additionalProperties: false - description: Project identity is an existing tenant-scoped Platform repository resource. - console.v1.PromoteScenarioFixtureRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - name: - type: string - title: name - minLength: 1 - scenarioJson: - type: string - title: scenario_json - minLength: 1 - recordedFromSessionId: - type: string - title: recorded_from_session_id - originalModel: - type: string - title: original_model - retentionPolicy: - type: string - title: retention_policy - tags: - type: array - items: - type: string - title: tags - title: PromoteScenarioFixtureRequest - additionalProperties: false - console.v1.PromoteScenarioFixtureResponse: - type: object - properties: - fixture: - title: fixture - $ref: '#/components/schemas/console.v1.ScenarioFixture' - title: PromoteScenarioFixtureResponse - additionalProperties: false - console.v1.ProposeCustomerIntelligenceFactRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - externalFactId: - type: string - title: external_fact_id - maxLength: 256 - subjectKind: - not: - enum: - - 0 - title: subject_kind - $ref: '#/components/schemas/console.v1.CustomerIntelligenceSubjectKind' - subjectRef: - type: string - title: subject_ref - maxLength: 256 - minLength: 1 - productArea: - type: string - title: product_area - maxLength: 80 - minLength: 1 - journey: - type: string - title: journey - maxLength: 80 - minLength: 1 - predicate: - type: string - title: predicate - maxLength: 120 - minLength: 1 - safeSummary: - type: string - title: safe_summary - maxLength: 280 - minLength: 1 - authority: - title: authority - enum: - - CUSTOMER_INTELLIGENCE_AUTHORITY_INFERRED - - CUSTOMER_INTELLIGENCE_AUTHORITY_CORROBORATED - $ref: '#/components/schemas/console.v1.CustomerIntelligenceAuthority' - confidenceMicros: - type: integer - title: confidence_micros - maximum: 1000000 - format: int32 - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.CustomerIntelligenceEvidenceRef' - title: evidence_refs - maxItems: 64 - minItems: 1 - producerKind: - title: producer_kind - enum: - - CUSTOMER_INTELLIGENCE_PRODUCER_KIND_PLATFORM_DETERMINISTIC_FEEDBACK - - CUSTOMER_INTELLIGENCE_PRODUCER_KIND_CEREBRO - $ref: '#/components/schemas/console.v1.CustomerIntelligenceProducerKind' - producerRef: - type: string - title: producer_ref - minLength: 1 - modelId: - type: string - title: model_id - maxLength: 160 - runId: - type: string - title: run_id - maxLength: 256 - policyVersion: - type: string - title: policy_version - minLength: 1 - lineageId: - type: string - title: lineage_id - minLength: 1 - retentionClass: - type: string - title: retention_class - minLength: 1 - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: ProposeCustomerIntelligenceFactRequest - required: - - query - additionalProperties: false - console.v1.ProposeCustomerIntelligenceFactResponse: - type: object - properties: - fact: - title: fact - $ref: '#/components/schemas/console.v1.CustomerIntelligenceFact' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.CustomerIntelligenceReceipt' - title: ProposeCustomerIntelligenceFactResponse - required: - - fact - - receipt - additionalProperties: false - console.v1.ProspectingDraft: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - draftId: - type: string - title: draft_id - minLength: 1 - candidateId: - type: string - title: candidate_id - maxLength: 128 - minLength: 1 - targetAccount: - title: target_account - $ref: '#/components/schemas/console.v1.ProspectingDraftTargetAccount' - channel: - title: channel - $ref: '#/components/schemas/console.v1.ProspectingDraftChannel' - tone: - title: tone - $ref: '#/components/schemas/console.v1.ProspectingDraftTone' - evidenceIds: - type: array - items: - type: string - maxItems: 50 - title: evidence_ids - maxItems: 50 - minItems: 1 - contentDigestSha256: - type: string - title: content_digest_sha256 - pattern: ^[0-9a-f]{64}$ - reviewState: - title: review_state - $ref: '#/components/schemas/console.v1.ProspectingDraftReviewState' - reviewerPrincipalId: - type: string - title: reviewer_principal_id - maxLength: 256 - reason: - type: string - title: reason - maxLength: 512 - minLength: 1 - revision: - exclusiveMinimum: 0 - type: - - integer - - string - title: revision - format: int64 - createdByPrincipalId: - type: string - title: created_by_principal_id - minLength: 1 - updatedByPrincipalId: - type: string - title: updated_by_principal_id - minLength: 1 - auditReceiptId: - type: string - title: audit_receipt_id - minLength: 1 - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: ProspectingDraft - required: - - targetAccount - - createdAt - - updatedAt - additionalProperties: false - description: |- - ProspectingDraft is a Console-owned outreach draft held for staff review. - - It carries no generator lineage and no extracted claims. Nothing has - generated this content, so those remain the generating owner's facts to - record when an agent runtime produces a draft. An approval is a review - decision and never delivery authority. - console.v1.ProspectingDraftMutationReceipt: - type: object - properties: - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - requestDigestSha256: - type: string - title: request_digest_sha256 - pattern: ^[0-9a-f]{64}$ - revision: - exclusiveMinimum: 0 - type: - - integer - - string - title: revision - format: int64 - auditReceiptId: - type: string - title: audit_receipt_id - minLength: 1 - replayed: - type: boolean - title: replayed - title: ProspectingDraftMutationReceipt - additionalProperties: false - description: |- - ProspectingDraftMutationReceipt identifies the accepted draft mutation and - whether this response is an exact idempotent replay. - console.v1.ProspectingDraftTargetAccount: - type: object - properties: - accountOrganizationId: - type: string - title: account_organization_id - minLength: 1 - accountWorkspaceId: - type: string - title: account_workspace_id - maxLength: 256 - identityRevision: - type: string - title: identity_revision - maxLength: 128 - minLength: 1 - accessGrantId: - type: string - title: access_grant_id - maxLength: 256 - title: ProspectingDraftTargetAccount - additionalProperties: false - description: |- - ProspectingDraftTargetAccount is the exact Identity-owned account the draft - is bound to. Radar supplies it; Console stores it verbatim and never derives - tenant scope from it. - console.v1.ProspectingWatchProgram: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - watchProgramId: - type: string - title: watch_program_id - minLength: 1 - name: - type: string - title: name - maxLength: 128 - minLength: 1 - config: - title: config - $ref: '#/components/schemas/google.protobuf.Struct' - scoringRuleRevision: - type: string - title: scoring_rule_revision - maxLength: 128 - minLength: 1 - lifecycle: - title: lifecycle - $ref: '#/components/schemas/console.v1.ProspectingWatchProgramLifecycle' - revision: - exclusiveMinimum: 0 - type: - - integer - - string - title: revision - format: int64 - createdByPrincipalId: - type: string - title: created_by_principal_id - minLength: 1 - updatedByPrincipalId: - type: string - title: updated_by_principal_id - minLength: 1 - reason: - type: string - title: reason - maxLength: 512 - minLength: 1 - auditReceiptId: - type: string - title: audit_receipt_id - minLength: 1 - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: ProspectingWatchProgram - required: - - config - - createdAt - - updatedAt - additionalProperties: false - description: |- - ProspectingWatchProgram is the current Console-owned Radar configuration. - It carries no Identity account, candidate, run, relationship, event, or - draft projection. - console.v1.ProspectingWatchProgramMutationReceipt: - type: object - properties: - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - requestDigestSha256: - type: string - title: request_digest_sha256 - pattern: ^[0-9a-f]{64}$ - revision: - exclusiveMinimum: 0 - type: - - integer - - string - title: revision - format: int64 - auditReceiptId: - type: string - title: audit_receipt_id - minLength: 1 - replayed: - type: boolean - title: replayed - title: ProspectingWatchProgramMutationReceipt - additionalProperties: false - description: |- - ProspectingWatchProgramMutationReceipt identifies the accepted mutation and - whether this response is an exact idempotent replay. - console.v1.PublishCaptureFormRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - formId: - type: string - title: form_id - minLength: 1 - versionId: - type: string - title: version_id - minLength: 1 - publication: - title: publication - $ref: '#/components/schemas/console.v1.CaptureFormPublicationInput' - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - title: PublishCaptureFormRequest - required: - - publication - additionalProperties: false - console.v1.PublishCaptureFormResponse: - type: object - properties: - form: - title: form - $ref: '#/components/schemas/console.v1.CaptureForm' - version: - title: version - $ref: '#/components/schemas/console.v1.CaptureFormVersion' - publication: - title: publication - $ref: '#/components/schemas/console.v1.CaptureFormPublication' - title: PublishCaptureFormResponse - required: - - form - - version - - publication - additionalProperties: false - console.v1.PublishedCaptureForm: - type: object - properties: - publicationId: - type: string - title: publication_id - minLength: 1 - formId: - type: string - title: form_id - minLength: 1 - versionId: - type: string - title: version_id - minLength: 1 - versionRevision: - exclusiveMinimum: 0 - type: - - integer - - string - title: version_revision - format: int64 - name: - type: string - title: name - maxLength: 160 - minLength: 1 - description: - type: string - title: description - maxLength: 2000 - branding: - title: branding - $ref: '#/components/schemas/console.v1.CaptureFormPublicBranding' - fields: - type: array - items: - $ref: '#/components/schemas/console.v1.CaptureFormPublicField' - title: fields - maxItems: 64 - route: - title: route - $ref: '#/components/schemas/console.v1.CaptureFormPublicRoute' - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: PublishedCaptureForm - additionalProperties: false - console.v1.ReauthorizeDexMcpOAuthProfileRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - serverId: - type: string - title: server_id - minLength: 1 - profileId: - type: string - title: profile_id - minLength: 1 - scopes: - type: array - items: - type: string - title: scopes - redirectUri: - type: string - title: redirect_uri - minLength: 1 - title: ReauthorizeDexMcpOAuthProfileRequest - required: - - query - additionalProperties: false - console.v1.ReauthorizeDexMcpOAuthProfileResponse: - type: object - properties: - profile: - title: profile - $ref: '#/components/schemas/console.v1.DexMcpOAuthProfile' - authorizeUrl: - type: string - title: authorize_url - state: - type: string - title: state - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - resourceMetadataUrl: - type: string - title: resource_metadata_url - authorizationServer: - type: string - title: authorization_server - clientId: - type: string - title: client_id - title: ReauthorizeDexMcpOAuthProfileResponse - required: - - profile - additionalProperties: false - console.v1.RecordComplianceAssessmentRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - profileId: - type: string - title: profile_id - subjectKind: - type: string - title: subject_kind - subjectId: - type: string - title: subject_id - idempotencyKey: - type: string - title: idempotency_key - title: RecordComplianceAssessmentRequest - additionalProperties: false - description: Records a server-evaluated snapshot. A replay key always returns its first accepted result. - console.v1.RecordComplianceAssessmentResponse: - type: object - properties: - record: - title: record - $ref: '#/components/schemas/console.v1.ComplianceAssessmentRecord' - idempotentReplay: - type: boolean - title: idempotent_replay - title: RecordComplianceAssessmentResponse - additionalProperties: false - console.v1.RecordOperatingHomepageSuggestionFeedbackRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - suggestionId: - type: string - title: suggestion_id - minLength: 1 - action: - not: - enum: - - 0 - title: action - $ref: '#/components/schemas/console.v1.OperatingHomepageSuggestionFeedbackAction' - title: RecordOperatingHomepageSuggestionFeedbackRequest - required: - - query - additionalProperties: false - description: |- - Declared at the end so this additive control does not renumber unrelated - generated message or enum descriptors in the large Console schema. - console.v1.RecordOperatingHomepageSuggestionFeedbackResponse: - type: object - properties: - changed: - type: boolean - title: changed - title: RecordOperatingHomepageSuggestionFeedbackResponse - additionalProperties: false - console.v1.RecordProviderCostSnapshotRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - connectionId: - type: string - title: connection_id - provider: - type: string - title: provider - resourceId: - type: string - title: resource_id - assetId: - type: string - title: asset_id - model: - type: string - title: model - spendMonthMicros: - type: - - integer - - string - title: spend_month_micros - format: int64 - spendTodayMicros: - type: - - integer - - string - title: spend_today_micros - format: int64 - period: - type: string - title: period - observedAt: - title: observed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - idempotencyKey: - type: string - title: idempotency_key - sourceUrl: - type: string - title: source_url - recordKind: - type: string - title: record_kind - description: Empty remains provider_monthly_snapshot for backwards compatibility. - inputTokens: - type: - - integer - - string - title: input_tokens - format: int64 - outputTokens: - type: - - integer - - string - title: output_tokens - format: int64 - requestCount: - type: - - integer - - string - title: request_count - format: int64 - upstreamProvider: - type: string - title: upstream_provider - description: |- - upstream_provider is the model provider selected behind a billing - gateway such as OpenRouter. Keep it separate from provider, which is the - source that owns the billing report. - provenance: - type: string - title: provenance - description: |- - provenance describes how the source can be joined to ledger events: - exact, aggregate, estimated, or unmatched. - title: RecordProviderCostSnapshotRequest - additionalProperties: false - console.v1.RecordProviderCostSnapshotResponse: - type: object - properties: - snapshotId: - type: string - title: snapshot_id - title: RecordProviderCostSnapshotResponse - additionalProperties: false - console.v1.RegisterPrivateEndpointRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - endpointId: - type: string - title: endpoint_id - minLength: 1 - provider: - type: string - title: provider - minLength: 1 - endpointUri: - type: string - title: endpoint_uri - minLength: 1 - serviceName: - type: string - title: service_name - minLength: 1 - region: - type: string - title: region - minLength: 1 - dnsName: - type: string - title: dns_name - minLength: 1 - relayId: - type: string - title: relay_id - title: RegisterPrivateEndpointRequest - required: - - query - additionalProperties: false - console.v1.RegisterPrivateEndpointResponse: - type: object - properties: - endpoint: - title: endpoint - $ref: '#/components/schemas/console.v1.PrivateEndpoint' - title: RegisterPrivateEndpointResponse - required: - - endpoint - additionalProperties: false - console.v1.RelatedResource: - type: object - properties: - id: - type: string - title: id - resourceType: - type: string - title: resource_type - label: - type: string - title: label - url: - type: string - title: url - title: RelatedResource - additionalProperties: false - console.v1.RemoveWorkspaceGuardrailRuleRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - id: - type: string - title: id - maxLength: 128 - minLength: 1 - title: RemoveWorkspaceGuardrailRuleRequest - required: - - query - additionalProperties: false - console.v1.RemoveWorkspaceIdentityProviderRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - id: - type: string - title: id - minLength: 1 - title: RemoveWorkspaceIdentityProviderRequest - required: - - query - additionalProperties: false - console.v1.RemoveWorkspaceIdentityProviderResponse: - type: object - properties: - settings: - title: settings - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - title: RemoveWorkspaceIdentityProviderResponse - required: - - settings - additionalProperties: false - console.v1.RemoveWorkspaceIntegrationRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - id: - type: string - title: id - minLength: 1 - title: RemoveWorkspaceIntegrationRequest - required: - - query - additionalProperties: false - console.v1.RemoveWorkspaceIntegrationResponse: - type: object - properties: - settings: - title: settings - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - title: RemoveWorkspaceIntegrationResponse - required: - - settings - additionalProperties: false - console.v1.RemoveWorkspaceMemberRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - subject: - type: string - title: subject - email: - type: string - title: email - title: RemoveWorkspaceMemberRequest - required: - - query - additionalProperties: false - console.v1.RenameOperatingThreadRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - minLength: 1 - title: - type: string - title: title - maxLength: 80 - minLength: 1 - title: RenameOperatingThreadRequest - required: - - query - additionalProperties: false - console.v1.RenameOperatingThreadResponse: - type: object - properties: - channel: - title: channel - $ref: '#/components/schemas/console.v1.OperatingChannel' - changed: - type: boolean - title: changed - title: RenameOperatingThreadResponse - required: - - channel - additionalProperties: false - console.v1.ReplyProductIssueRecoveryRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - recoveryId: - type: string - title: recovery_id - maxLength: 4000 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 4000 - message: - type: string - title: message - maxLength: 4000 - resolved: - type: boolean - title: resolved - title: ReplyProductIssueRecoveryRequest - additionalProperties: false - description: Durable, explicitly scoped customer recovery contract. - console.v1.ReserveComputerMissionApexSessionRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - packRunId: - type: string - title: pack_run_id - minLength: 1 - attemptId: - type: string - title: attempt_id - minLength: 1 - runIndex: - type: integer - title: run_index - decisionRef: - type: string - title: decision_ref - minLength: 1 - decisionDigestSha256: - type: string - title: decision_digest_sha256 - pattern: ^[0-9a-f]{64}$ - runnerProfile: - type: string - title: runner_profile - const: apex-agents-v1 - workloadDigest: - type: string - title: workload_digest - pattern: ^sha256:[0-9a-f]{64}$ - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - description: |- - The same key is used for reservation issuance and Runner Host create; bind - repeats it so Platform can reject a different physical create attempt. - title: ReserveComputerMissionApexSessionRequest - additionalProperties: false - console.v1.ReserveComputerMissionApexSessionResponse: - type: object - properties: - reservation: - title: reservation - $ref: '#/components/schemas/console.v1.ComputerMissionApexSessionReservation' - title: ReserveComputerMissionApexSessionResponse - required: - - reservation - additionalProperties: false - console.v1.ResolveOperatingFeedbackRemediationRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - feedbackId: - type: string - title: feedback_id - minLength: 1 - outcome: - title: outcome - enum: - - OPERATING_FEEDBACK_REMEDIATION_OUTCOME_ACCEPTED - - OPERATING_FEEDBACK_REMEDIATION_OUTCOME_REJECTED - $ref: '#/components/schemas/console.v1.OperatingFeedbackRemediationOutcome' - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: ResolveOperatingFeedbackRemediationRequest - required: - - query - additionalProperties: false - console.v1.ResolveOperatingFeedbackRemediationResponse: - type: object - properties: - feedback: - title: feedback - $ref: '#/components/schemas/console.v1.OperatingFeedback' - factReceipt: - title: fact_receipt - $ref: '#/components/schemas/console.v1.CustomerIntelligenceReceipt' - title: ResolveOperatingFeedbackRemediationResponse - required: - - feedback - additionalProperties: false - console.v1.ResolveOperatingReceiptActionRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - receiptId: - type: string - title: receipt_id - minLength: 1 - action: - title: action - $ref: '#/components/schemas/console.v1.OperatingReceiptAction' - idempotencyKey: - type: string - title: idempotency_key - title: ResolveOperatingReceiptActionRequest - required: - - query - - action - additionalProperties: false - console.v1.ResolveOperatingReceiptActionResponse: - type: object - properties: - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.OperatingReceipt' - capabilities: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingCapabilityState' - title: capabilities - title: ResolveOperatingReceiptActionResponse - additionalProperties: false - console.v1.RespondOperatingThreadRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - minLength: 1 - turnId: - type: string - title: turn_id - minLength: 1 - response: - title: response - $ref: '#/components/schemas/console.v1.OperatingThreadResponse' - idempotencyKey: - type: string - title: idempotency_key - maxLength: 512 - minLength: 1 - title: RespondOperatingThreadRequest - required: - - query - - response - additionalProperties: false - console.v1.RespondOperatingThreadResponse: - type: object - properties: - runtimeRunId: - type: string - title: runtime_run_id - replayed: - type: boolean - title: replayed - threadExecution: - title: thread_execution - $ref: '#/components/schemas/console.v1.OperatingThreadExecution' - turns: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingThreadTurn' - title: turns - replayCursor: - type: - - integer - - string - title: replay_cursor - format: int64 - title: RespondOperatingThreadResponse - additionalProperties: false - console.v1.RespondToCustomerFactConfirmationRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - confirmationIntentId: - type: string - title: confirmation_intent_id - minLength: 1 - response: - not: - enum: - - 0 - title: response - $ref: '#/components/schemas/console.v1.CustomerFactConfirmationResponse' - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: RespondToCustomerFactConfirmationRequest - required: - - query - additionalProperties: false - console.v1.RespondToCustomerFactConfirmationResponse: - type: object - properties: - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.CustomerIntelligenceReceipt' - title: RespondToCustomerFactConfirmationResponse - required: - - receipt - additionalProperties: false - console.v1.ResumeComputerMissionRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - missionId: - type: string - title: mission_id - minLength: 1 - expectedGeneration: - type: - - integer - - string - title: expected_generation - format: int64 - reason: - type: string - title: reason - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - condition: - title: condition - $ref: '#/components/schemas/google.protobuf.Struct' - wakeAt: - title: wake_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: ResumeComputerMissionRequest - required: - - query - additionalProperties: false - console.v1.ResumeComputerMissionResponse: - type: object - properties: - mission: - title: mission - $ref: '#/components/schemas/console.v1.ComputerMission' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.OperatingReceipt' - wakeId: - type: string - title: wake_id - minLength: 1 - title: ResumeComputerMissionResponse - required: - - mission - - receipt - additionalProperties: false - console.v1.ReviewCaptureFormSubmissionRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - submissionId: - type: string - title: submission_id - minLength: 1 - expectedRevision: - exclusiveMinimum: 0 - type: - - integer - - string - title: expected_revision - format: int64 - decision: - not: - enum: - - 0 - title: decision - $ref: '#/components/schemas/console.v1.CaptureFormReviewDecision' - note: - type: string - title: note - maxLength: 4000 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - supplementalValues: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessFieldValue' - title: supplemental_values - maxItems: 64 - description: |- - Native typed values for missing required BusinessObject fields. These are - validated against the publication's pinned schema and stored separately - from the original submission answers. - title: ReviewCaptureFormSubmissionRequest - additionalProperties: false - console.v1.ReviewCaptureFormSubmissionResponse: - type: object - properties: - submission: - title: submission - $ref: '#/components/schemas/console.v1.CaptureFormSubmission' - objectResult: - title: object_result - $ref: '#/components/schemas/console.v1.CaptureFormObjectResult' - title: ReviewCaptureFormSubmissionResponse - required: - - submission - additionalProperties: false - console.v1.ReviewCustomerIntelligenceFactRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - factId: - type: string - title: fact_id - minLength: 1 - expectedRevision: - exclusiveMinimum: 0 - type: - - integer - - string - title: expected_revision - format: int64 - decision: - not: - enum: - - 0 - title: decision - $ref: '#/components/schemas/console.v1.CustomerIntelligenceReviewDecision' - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.CustomerIntelligenceEvidenceRef' - title: evidence_refs - maxItems: 64 - replacementSafeSummary: - type: string - title: replacement_safe_summary - maxLength: 280 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: ReviewCustomerIntelligenceFactRequest - required: - - query - additionalProperties: false - console.v1.ReviewCustomerIntelligenceFactResponse: - type: object - properties: - fact: - title: fact - $ref: '#/components/schemas/console.v1.CustomerIntelligenceFact' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.CustomerIntelligenceReceipt' - title: ReviewCustomerIntelligenceFactResponse - required: - - fact - - receipt - additionalProperties: false - console.v1.ReviewOperatingCorrectionRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - correctionId: - type: string - title: correction_id - minLength: 1 - decision: - title: decision - enum: - - OPERATING_CORRECTION_REVIEW_STATE_APPROVED - - OPERATING_CORRECTION_REVIEW_STATE_REJECTED - $ref: '#/components/schemas/console.v1.OperatingCorrectionReviewState' - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - maxItems: 64 - minItems: 1 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: ReviewOperatingCorrectionRequest - required: - - query - additionalProperties: false - console.v1.ReviewOperatingCorrectionResponse: - type: object - properties: - correction: - title: correction - $ref: '#/components/schemas/console.v1.OperatingCorrectionCandidate' - title: ReviewOperatingCorrectionResponse - required: - - correction - additionalProperties: false - console.v1.ReviewProspectingDraftRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - draftId: - type: string - title: draft_id - minLength: 1 - decision: - title: decision - enum: - - PROSPECTING_DRAFT_REVIEW_STATE_APPROVED - - PROSPECTING_DRAFT_REVIEW_STATE_REJECTED - $ref: '#/components/schemas/console.v1.ProspectingDraftReviewState' - expectedRevision: - exclusiveMinimum: 0 - type: - - integer - - string - title: expected_revision - format: int64 - reason: - type: string - title: reason - maxLength: 512 - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 256 - minLength: 1 - title: ReviewProspectingDraftRequest - required: - - query - additionalProperties: false - console.v1.ReviewProspectingDraftResponse: - type: object - properties: - draft: - title: draft - $ref: '#/components/schemas/console.v1.ProspectingDraft' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.ProspectingDraftMutationReceipt' - title: ReviewProspectingDraftResponse - required: - - draft - - receipt - additionalProperties: false - console.v1.ReviewStaffProductIssueRecoveryRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - maxLength: 4000 - workspaceId: - type: string - title: workspace_id - maxLength: 4000 - recoveryId: - type: string - title: recovery_id - maxLength: 4000 - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - title: ReviewStaffProductIssueRecoveryRequest - additionalProperties: false - console.v1.ReviewWorkspaceMemoryRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - memoryId: - type: string - title: memory_id - minLength: 1 - expectedRevision: - type: - - integer - - string - title: expected_revision - minimum: 1 - format: int64 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - reviewStatus: - title: review_status - enum: - - MEMORY_REVIEW_STATUS_APPROVED - - MEMORY_REVIEW_STATUS_REJECTED - description: Only APPROVED and REJECTED are valid review decisions. - $ref: '#/components/schemas/memory.v1.MemoryReviewStatus' - title: ReviewWorkspaceMemoryRequest - required: - - query - additionalProperties: false - description: Review changes only proposal status; the memory owner preserves content. - console.v1.ReviewWorkspaceMemoryResponse: - type: object - properties: - memory: - title: memory - $ref: '#/components/schemas/console.v1.WorkspaceMemory' - title: ReviewWorkspaceMemoryResponse - required: - - memory - additionalProperties: false - console.v1.RevokeCaptureFormInvitationRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - invitationId: - type: string - title: invitation_id - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - title: RevokeCaptureFormInvitationRequest - additionalProperties: false - console.v1.RevokeCaptureFormInvitationResponse: - type: object - properties: - invitation: - title: invitation - $ref: '#/components/schemas/console.v1.CaptureFormInvitation' - title: RevokeCaptureFormInvitationResponse - required: - - invitation - additionalProperties: false - console.v1.RevokeCaptureFormPublicationRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - formId: - type: string - title: form_id - minLength: 1 - publicationId: - type: string - title: publication_id - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - title: RevokeCaptureFormPublicationRequest - additionalProperties: false - console.v1.RevokeCaptureFormPublicationResponse: - type: object - properties: - form: - title: form - $ref: '#/components/schemas/console.v1.CaptureForm' - publication: - title: publication - $ref: '#/components/schemas/console.v1.CaptureFormPublication' - title: RevokeCaptureFormPublicationResponse - required: - - form - - publication - additionalProperties: false - console.v1.RevokeDexMcpOAuthProfileRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - serverId: - type: string - title: server_id - minLength: 1 - profileId: - type: string - title: profile_id - minLength: 1 - reasonCode: - type: string - title: reason_code - minLength: 1 - profileGeneration: - exclusiveMinimum: 0 - type: - - integer - - string - title: profile_generation - format: int64 - title: RevokeDexMcpOAuthProfileRequest - required: - - query - additionalProperties: false - console.v1.RevokeDexMcpOAuthProfileResponse: - type: object - properties: - profile: - title: profile - $ref: '#/components/schemas/console.v1.DexMcpOAuthProfile' - title: RevokeDexMcpOAuthProfileResponse - required: - - profile - additionalProperties: false - console.v1.RevokeManagedProviderAccessGrantRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - provider: - type: string - title: provider - minLength: 1 - environment: - type: string - title: environment - minLength: 1 - note: - type: string - title: note - maxLength: 512 - minLength: 1 - description: Required audit note recorded with the disable action. - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - title: RevokeManagedProviderAccessGrantRequest - additionalProperties: false - console.v1.RevokeManagedProviderAccessGrantResponse: - type: object - properties: - grant: - title: grant - $ref: '#/components/schemas/console.v1.ManagedProviderAccessGrant' - title: RevokeManagedProviderAccessGrantResponse - additionalProperties: false - console.v1.RiskFinding: - type: object - properties: - id: - type: string - title: id - title: - type: string - title: title - detail: - type: string - title: detail - source: - type: string - title: source - assetId: - type: string - title: asset_id - status: - type: string - title: status - riskLevel: - title: risk_level - $ref: '#/components/schemas/common.v1.RiskLevel' - policy: - type: string - title: policy - nextAction: - type: string - title: next_action - detectedAt: - title: detected_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: RiskFinding - additionalProperties: false - console.v1.RunAsIdentitySummary: - type: object - properties: - status: - type: string - title: status - description: status is one of verified, unverified, missing, or unknown. - identity: - type: string - title: identity - source: - type: string - title: source - missingReason: - type: string - title: missing_reason - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - title: RunAsIdentitySummary - additionalProperties: false - console.v1.ScanStaffProductIssueRecoveryRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - maxLength: 4000 - workspaceId: - type: string - title: workspace_id - maxLength: 4000 - recoveryId: - type: string - title: recovery_id - maxLength: 4000 - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - title: ScanStaffProductIssueRecoveryRequest - additionalProperties: false - description: Durable, explicitly scoped customer recovery contract. - console.v1.ScenarioFixture: - type: object - properties: - id: - type: string - title: id - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - name: - type: string - title: name - recordedFromSessionId: - type: string - title: recorded_from_session_id - recordedAt: - title: recorded_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - originalModel: - type: string - title: original_model - toolCount: - type: integer - title: tool_count - format: int32 - frameCount: - type: integer - title: frame_count - format: int32 - gcsPath: - type: string - title: gcs_path - retentionPolicy: - type: string - title: retention_policy - tags: - type: array - items: - type: string - title: tags - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: ScenarioFixture - additionalProperties: false - console.v1.ScenarioFixtureDifference: - type: object - properties: - path: - type: string - title: path - kind: - type: string - title: kind - baseValue: - type: string - title: base_value - targetValue: - type: string - title: target_value - summary: - type: string - title: summary - title: ScenarioFixtureDifference - additionalProperties: false - console.v1.SearchOperatingHistoryRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - searchQuery: - type: string - title: search_query - maxLength: 1000 - minLength: 1 - filter: - title: filter - $ref: '#/components/schemas/console.v1.OperatingHistorySearchFilter' - pageSize: - type: integer - title: page_size - maximum: 25 - format: int32 - pageToken: - type: string - title: page_token - maxLength: 4096 - title: SearchOperatingHistoryRequest - required: - - query - additionalProperties: false - console.v1.SearchOperatingHistoryResponse: - type: object - properties: - results: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingHistorySearchResult' - title: results - nextPageToken: - type: string - title: next_page_token - title: SearchOperatingHistoryResponse - additionalProperties: false - console.v1.SearchStaffWorkspaceDirectoryRequest: - type: object - properties: - query: - type: string - title: query - maxLength: 128 - minLength: 1 - limit: - type: integer - title: limit - maximum: 25 - minimum: 1 - format: int32 - title: SearchStaffWorkspaceDirectoryRequest - additionalProperties: false - console.v1.SearchStaffWorkspaceDirectoryResponse: - type: object - properties: - entries: - type: array - items: - $ref: '#/components/schemas/console.v1.StaffWorkspaceDirectoryEntry' - title: entries - description: Capped at 25 entries. - title: SearchStaffWorkspaceDirectoryResponse - additionalProperties: false - console.v1.SecurityDecisionEvidenceGap: - type: object - properties: - id: - type: string - title: id - label: - type: string - title: label - state: - type: string - title: state - reason: - type: string - title: reason - source: - type: string - title: source - spanIds: - type: array - items: - type: string - title: span_ids - title: SecurityDecisionEvidenceGap - additionalProperties: false - console.v1.SecurityDecisionPacket: - type: object - properties: - id: - type: string - title: id - question: - type: string - title: question - verdict: - type: string - title: verdict - description: verdict is one of ready_to_approve, needs_review, needs_evidence, or blocked. - approvalState: - type: string - title: approval_state - description: approval_state is one of approved, pending, denied, not_required, or unknown. - governanceDecision: - type: string - title: governance_decision - riskLevel: - title: risk_level - $ref: '#/components/schemas/common.v1.RiskLevel' - summary: - type: string - title: summary - nextAction: - type: string - title: next_action - blockingReasons: - type: array - items: - type: string - title: blocking_reasons - evidenceGaps: - type: array - items: - $ref: '#/components/schemas/console.v1.SecurityDecisionEvidenceGap' - title: evidence_gaps - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/console.v1.RelatedResource' - title: evidence_refs - title: SecurityDecisionPacket - additionalProperties: false - console.v1.SetConnectorTriggerEnabledRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - triggerId: - type: string - title: trigger_id - minLength: 1 - enabled: - type: boolean - title: enabled - title: SetConnectorTriggerEnabledRequest - required: - - query - additionalProperties: false - console.v1.SetConnectorTriggerEnabledResponse: - type: object - properties: - trigger: - title: trigger - $ref: '#/components/schemas/console.v1.ConnectorTrigger' - title: SetConnectorTriggerEnabledResponse - required: - - trigger - additionalProperties: false - console.v1.SetMissionScheduleEnabledRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - scheduleId: - type: string - title: schedule_id - minLength: 1 - enabled: - type: boolean - title: enabled - title: SetMissionScheduleEnabledRequest - required: - - query - additionalProperties: false - console.v1.SetMissionScheduleEnabledResponse: - type: object - properties: - schedule: - title: schedule - $ref: '#/components/schemas/console.v1.MissionSchedule' - title: SetMissionScheduleEnabledResponse - required: - - schedule - additionalProperties: false - console.v1.SetOperatingThreadControllerRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - minLength: 1 - action: - type: string - title: action - maxLength: 64 - minLength: 1 - expectedRuntimeGeneration: - type: - - integer - - string - title: expected_runtime_generation - format: int64 - expectedReplayCursor: - type: - - integer - - string - title: expected_replay_cursor - format: int64 - expectedControllerLeaseGeneration: - type: - - integer - - string - title: expected_controller_lease_generation - format: int64 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 512 - minLength: 1 - title: SetOperatingThreadControllerRequest - required: - - query - additionalProperties: false - console.v1.SetOperatingThreadControllerResponse: - type: object - properties: - replayed: - type: boolean - title: replayed - threadExecution: - title: thread_execution - $ref: '#/components/schemas/console.v1.OperatingThreadExecution' - replayCursor: - type: - - integer - - string - title: replay_cursor - format: int64 - title: SetOperatingThreadControllerResponse - required: - - threadExecution - additionalProperties: false - console.v1.SetPinnedSourceRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - sourceId: - type: string - title: source_id - minLength: 1 - title: SetPinnedSourceRequest - additionalProperties: false - console.v1.SetPinnedSourceResponse: - type: object - properties: - pin: - title: pin - $ref: '#/components/schemas/console.v1.PinnedSource' - title: SetPinnedSourceResponse - additionalProperties: false - console.v1.SetPrivacySettingsRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - scope: - not: - enum: - - 0 - title: scope - $ref: '#/components/schemas/console.v1.PrivacySettingScope' - mode: - not: - enum: - - 0 - title: mode - $ref: '#/components/schemas/console.v1.TenantPrivacyMode' - title: SetPrivacySettingsRequest - required: - - query - additionalProperties: false - console.v1.SetStaffManagedInferenceBudgetRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - request: - title: request - $ref: '#/components/schemas/meter.v1.SetBudgetRequest' - reason: - type: string - title: reason - requestId: - type: string - title: request_id - title: SetStaffManagedInferenceBudgetRequest - additionalProperties: false - console.v1.SkillAnalysisFinding: - type: object - properties: - ruleId: - type: string - title: rule_id - title: - type: string - title: title - detail: - type: string - title: detail - severity: - title: severity - $ref: '#/components/schemas/common.v1.RiskLevel' - advisory: - type: boolean - title: advisory - description: |- - Advisory findings are bounded content-review signals. They never affect - the verdict or authorize, block, or route product behavior. - title: SkillAnalysisFinding - additionalProperties: false - console.v1.SkillAnalysisReport: - type: object - properties: - verdict: - title: verdict - $ref: '#/components/schemas/console.v1.SkillAnalysisVerdict' - contentDigest: - type: string - title: content_digest - rulesetVersion: - type: string - title: ruleset_version - coveredSurfaces: - type: array - items: - type: string - title: covered_surfaces - requiredTools: - type: array - items: - type: string - title: required_tools - findings: - type: array - items: - $ref: '#/components/schemas/console.v1.SkillAnalysisFinding' - title: findings - title: SkillAnalysisReport - additionalProperties: false - description: |- - SkillAnalysisReport is deterministic evidence about the exact skill payload - being displayed, saved, or offered for installation. It is not a permission - grant and never replaces runtime authorization or approval policy. - console.v1.StaffComputerEnvironment: - type: object - properties: - provider: - type: string - title: provider - region: - type: string - title: region - lifecycleState: - type: string - title: lifecycle_state - title: StaffComputerEnvironment - additionalProperties: false - console.v1.StaffContextCapability: - type: object - properties: - available: - type: boolean - title: available - reason: - type: string - title: reason - title: StaffContextCapability - additionalProperties: false - console.v1.StaffFailureSummary: - type: object - properties: - eventId: - type: string - title: event_id - category: - type: string - title: category - safeSummary: - type: string - title: safe_summary - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: StaffFailureSummary - additionalProperties: false - console.v1.StaffGrantEventSummary: - type: object - properties: - grantId: - type: string - title: grant_id - action: - type: string - title: action - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: StaffGrantEventSummary - additionalProperties: false - console.v1.StaffInferencePurposeRoute: - type: object - properties: - purpose: - title: purpose - $ref: '#/components/schemas/console.v1.StaffInferenceRoutingPurpose' - primaryTarget: - title: primary_target - $ref: '#/components/schemas/console.v1.InferenceProviderTarget' - canaryTarget: - title: canary_target - description: Optional deterministic canary target for this purpose. - $ref: '#/components/schemas/console.v1.InferenceProviderTarget' - canaryPercent: - type: integer - title: canary_percent - title: StaffInferencePurposeRoute - additionalProperties: false - console.v1.StaffInferenceRoutingEvent: - type: object - properties: - revision: - type: - - integer - - string - title: revision - format: int64 - routes: - type: array - items: - $ref: '#/components/schemas/console.v1.StaffInferencePurposeRoute' - title: routes - usesDeploymentDefault: - type: boolean - title: uses_deployment_default - actorPrincipalId: - type: string - title: actor_principal_id - note: - type: string - title: note - action: - type: string - title: action - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: StaffInferenceRoutingEvent - additionalProperties: false - console.v1.StaffInferenceRoutingProfile: - type: object - properties: - organizationId: - type: string - title: organization_id - provider: - type: string - title: provider - model: - type: string - title: model - revision: - type: - - integer - - string - title: revision - format: int64 - updatedBy: - type: string - title: updated_by - note: - type: string - title: note - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - routes: - type: array - items: - $ref: '#/components/schemas/console.v1.StaffInferencePurposeRoute' - title: routes - usesDeploymentDefault: - type: boolean - title: uses_deployment_default - title: StaffInferenceRoutingProfile - additionalProperties: false - description: |- - StaffInferenceRoutingProfile is the durable Dex inference override for the - single server-configured STAFF organization. - console.v1.StaffProductIssueRecoverySummary: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - recoveryId: - type: string - title: recovery_id - reportReference: - type: string - title: report_reference - recipientPrincipalId: - type: string - title: recipient_principal_id - customerSummary: - type: string - title: customer_summary - state: - type: string - title: state - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - lastReply: - type: string - title: last_reply - title: StaffProductIssueRecoverySummary - additionalProperties: false - console.v1.StaffProductIssueReport: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - id: - type: string - title: id - reference: - type: string - title: reference - description: - type: string - title: description - expectedBehavior: - type: string - title: expected_behavior - pageUrl: - type: string - title: page_url - appVersion: - type: string - title: app_version - browser: - type: string - title: browser - viewport: - type: string - title: viewport - diagnosticsIncluded: - type: boolean - title: diagnostics_included - screenshotAttached: - type: boolean - title: screenshot_attached - screenshotFilename: - type: string - title: screenshot_filename - screenshotContentType: - type: string - title: screenshot_content_type - createdByPrincipalId: - type: string - title: created_by_principal_id - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - engagementState: - type: string - title: engagement_state - engagedAt: - title: engaged_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - engagedByPrincipalId: - type: string - title: engaged_by_principal_id - engagementNote: - type: string - title: engagement_note - context: - title: context - $ref: '#/components/schemas/console.v1.ProductIssueReportContext' - symptomGroup: - type: string - title: symptom_group - description: Exact normalized symptom grouping, scoped to one organization and workspace. - baselineTestRunId: - type: string - title: baseline_test_run_id - verificationTestRunId: - type: string - title: verification_test_run_id - regressionState: - type: string - title: regression_state - title: StaffProductIssueReport - additionalProperties: false - console.v1.StaffReceiptSummary: - type: object - properties: - id: - type: string - title: id - kind: - type: string - title: kind - status: - type: string - title: status - summary: - type: string - title: summary - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: StaffReceiptSummary - additionalProperties: false - console.v1.StaffTraceSummary: - type: object - properties: - traceId: - type: string - title: trace_id - summary: - type: string - title: summary - status: - type: string - title: status - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: StaffTraceSummary - additionalProperties: false - console.v1.StaffWorkspaceContext: - type: object - properties: - accessState: - title: access_state - $ref: '#/components/schemas/console.v1.StaffWorkspaceAccessState' - grantEvents: - type: array - items: - $ref: '#/components/schemas/console.v1.StaffGrantEventSummary' - title: grant_events - description: Each collection is newest-first and capped at 25. - receipts: - type: array - items: - $ref: '#/components/schemas/console.v1.StaffReceiptSummary' - title: receipts - traces: - type: array - items: - $ref: '#/components/schemas/console.v1.StaffTraceSummary' - title: traces - failures: - type: array - items: - $ref: '#/components/schemas/console.v1.StaffFailureSummary' - title: failures - computerEnvironment: - title: computer_environment - $ref: '#/components/schemas/console.v1.StaffComputerEnvironment' - grantEventsCapability: - title: grant_events_capability - $ref: '#/components/schemas/console.v1.StaffContextCapability' - receiptsCapability: - title: receipts_capability - $ref: '#/components/schemas/console.v1.StaffContextCapability' - tracesCapability: - title: traces_capability - $ref: '#/components/schemas/console.v1.StaffContextCapability' - failuresCapability: - title: failures_capability - $ref: '#/components/schemas/console.v1.StaffContextCapability' - computerEnvironmentCapability: - title: computer_environment_capability - $ref: '#/components/schemas/console.v1.StaffContextCapability' - activeGrantApprover: - type: string - title: active_grant_approver - activeGrantExpiresAt: - title: active_grant_expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: StaffWorkspaceContext - additionalProperties: false - console.v1.StaffWorkspaceDirectoryEntry: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - organizationName: - type: string - title: organization_name - workspaceName: - type: string - title: workspace_name - region: - type: string - title: region - environment: - type: string - title: environment - accessState: - title: access_state - $ref: '#/components/schemas/console.v1.StaffWorkspaceAccessState' - title: StaffWorkspaceDirectoryEntry - additionalProperties: false - console.v1.StartBusinessProcessRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - definitionId: - type: string - title: definition_id - definitionRevision: - type: - - integer - - string - title: definition_revision - format: int64 - participants: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessProcessParticipant' - title: participants - decisionPrincipalId: - type: string - title: decision_principal_id - title: StartBusinessProcessRequest - additionalProperties: false - console.v1.StartBusinessProcessResponse: - type: object - properties: - process: - title: process - $ref: '#/components/schemas/console.v1.BusinessProcess' - title: StartBusinessProcessResponse - additionalProperties: false - console.v1.StartComputerMissionCanaryRunRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - channelId: - type: string - title: channel_id - minLength: 1 - canaryDefinitionId: - type: string - title: canary_definition_id - minLength: 1 - environment: - type: string - title: environment - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: StartComputerMissionCanaryRunRequest - required: - - query - additionalProperties: false - console.v1.StartComputerMissionCanaryRunResponse: - type: object - properties: - run: - title: run - $ref: '#/components/schemas/console.v1.ComputerMissionCanaryRun' - mission: - title: mission - $ref: '#/components/schemas/console.v1.ComputerMission' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.OperatingReceipt' - title: StartComputerMissionCanaryRunResponse - required: - - run - - mission - - receipt - additionalProperties: false - console.v1.StartMeetingCaptureRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - meetUrl: - type: string - title: meet_url - maxLength: 2000 - description: |- - Optional when connected_call_id is set. Otherwise one server-validated - meeting URL (Google Meet, Zoom, Microsoft Teams, or Webex). The field name - stays meet_url for wire and TypeScript compatibility. - recallConnectionId: - type: string - title: recall_connection_id - description: |- - Deprecated compatibility input. Platform ignores it and resolves the - tenant's active Recall connection server-side. - deprecated: true - idempotencyKey: - type: string - title: idempotency_key - maxLength: 200 - minLength: 1 - maximumDurationMinutes: - type: integer - title: maximum_duration_minutes - maximum: 240 - minimum: 1 - format: int32 - recordingConsentAttested: - type: boolean - title: recording_consent_attested - languageCode: - type: string - title: language_code - maxLength: 35 - connectedCallId: - type: string - title: connected_call_id - maxLength: 200 - description: |- - Optional. When set, Platform resolves the call from the tenant's connected - calendar (ListConnectedCalls id), uses its meeting URL and start/end times, - and records a calendar-sourced capture. meet_url is ignored when set. - title: StartMeetingCaptureRequest - required: - - query - additionalProperties: false - description: |- - StartMeetingCaptureRequest names one meeting, either by a server-validated - meeting URL or by one opted-in connected calendar call. The transcript - callback and provider credentials are deployment-owned and cannot be - redirected by the browser. - console.v1.StartMeetingCaptureResponse: - type: object - properties: - capture: - title: capture - $ref: '#/components/schemas/console.v1.MeetingCapture' - title: StartMeetingCaptureResponse - additionalProperties: false - console.v1.StopMeetingCaptureRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - captureId: - type: string - title: capture_id - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 200 - minLength: 1 - title: StopMeetingCaptureRequest - required: - - query - additionalProperties: false - description: |- - StopMeetingCaptureRequest records the user's request to stop one capture. - Platform chooses cancel-versus-leave from the durable binding lifecycle; the - browser cannot select the provider action. - console.v1.StopMeetingCaptureResponse: - type: object - properties: - capture: - title: capture - $ref: '#/components/schemas/console.v1.MeetingCapture' - title: StopMeetingCaptureResponse - additionalProperties: false - console.v1.SubmitAgentWorkforceEvidenceRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - recordId: - type: string - title: record_id - description: |- - record_id targets an existing Agent Workforce record. When present, the - backend resolves it to trace/run/session identifiers before writing. - traceId: - type: string - title: trace_id - runId: - type: string - title: run_id - sessionId: - type: string - title: session_id - agentId: - type: string - title: agent_id - runtime: - type: string - title: runtime - evidenceKind: - type: string - title: evidence_kind - minLength: 1 - description: |- - evidence_kind is one of advisory_self_report, credential_authority, - cost_usage, attempted_action, or approval_packet. - evidenceSource: - type: string - title: evidence_source - description: |- - evidence_source identifies the submitting/owning source. Advisory/native - sources such as external_self_report, nimbus, cerebro, or customer_mcp are - retained as context but must not unlock approval authority. - evidenceRef: - type: string - title: evidence_ref - minLength: 1 - subject: - type: string - title: subject - provider: - type: string - title: provider - actionId: - type: string - title: action_id - toolName: - type: string - title: tool_name - targetSummary: - type: string - title: target_summary - mutatesResource: - type: boolean - title: mutates_resource - costUsd: - type: number - title: cost_usd - format: double - inputTokens: - type: - - integer - - string - title: input_tokens - format: int64 - outputTokens: - type: - - integer - - string - title: output_tokens - format: int64 - model: - type: string - title: model - connectorId: - type: string - title: connector_id - capability: - type: string - title: capability - note: - type: string - title: note - title: SubmitAgentWorkforceEvidenceRequest - required: - - query - additionalProperties: false - console.v1.SubmitAgentWorkforceEvidenceResponse: - type: object - properties: - submittedEvidence: - title: submitted_evidence - $ref: '#/components/schemas/console.v1.AgentWorkforceSubmittedEvidence' - record: - title: record - $ref: '#/components/schemas/console.v1.AgentWorkforceRecord' - recordsResponse: - title: records_response - $ref: '#/components/schemas/console.v1.ListAgentWorkforceRecordsResponse' - remainingMissingEvidence: - type: array - items: - type: string - title: remaining_missing_evidence - approvalAllowed: - type: boolean - title: approval_allowed - nextAction: - type: string - title: next_action - warnings: - type: array - items: - type: string - title: warnings - title: SubmitAgentWorkforceEvidenceResponse - additionalProperties: false - console.v1.SubmitComputerMissionRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - channelId: - type: string - title: channel_id - minLength: 1 - contract: - title: contract - $ref: '#/components/schemas/console.v1.ComputerMissionContract' - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: SubmitComputerMissionRequest - required: - - query - - contract - additionalProperties: false - console.v1.SubmitComputerMissionResponse: - type: object - properties: - mission: - title: mission - $ref: '#/components/schemas/console.v1.ComputerMission' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.OperatingReceipt' - title: SubmitComputerMissionResponse - required: - - mission - - receipt - additionalProperties: false - console.v1.SubmitInvitedCaptureFormRequest: - type: object - properties: - invitationId: - type: string - title: invitation_id - minLength: 1 - answers: - type: array - items: - $ref: '#/components/schemas/console.v1.CaptureFormAnswer' - title: answers - maxItems: 64 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - title: SubmitInvitedCaptureFormRequest - additionalProperties: false - console.v1.SubmitInvitedCaptureFormResponse: - type: object - properties: - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.CaptureFormPublicSubmissionReceipt' - title: SubmitInvitedCaptureFormResponse - required: - - receipt - additionalProperties: false - console.v1.SubmitNativeProductIssueReportRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - description: - type: string - title: description - maxLength: 4000 - minLength: 1 - expectedBehavior: - type: string - title: expected_behavior - maxLength: 4000 - appVersion: - type: string - title: app_version - maxLength: 128 - includeDiagnostics: - type: boolean - title: include_diagnostics - idempotencyKey: - type: string - title: idempotency_key - maxLength: 512 - minLength: 1 - context: - title: context - $ref: '#/components/schemas/console.v1.ProductIssueReportContext' - title: SubmitNativeProductIssueReportRequest - required: - - query - additionalProperties: false - description: |- - Native reports reuse the product issue owner with a bounded diagnostic projection. - Tags match the canonical submission fields; browser-only fields are reserved. - console.v1.SubmitOperatingCorrectionRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - minLength: 1 - messageId: - type: string - title: message_id - minLength: 1 - category: - not: - enum: - - 0 - title: category - $ref: '#/components/schemas/console.v1.OperatingCorrectionCategory' - feedback: - type: string - title: feedback - maxLength: 4000 - remember: - type: boolean - title: remember - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: SubmitOperatingCorrectionRequest - required: - - query - additionalProperties: false - console.v1.SubmitOperatingCorrectionResponse: - type: object - properties: - correction: - title: correction - $ref: '#/components/schemas/console.v1.OperatingCorrectionCandidate' - title: SubmitOperatingCorrectionResponse - required: - - correction - additionalProperties: false - console.v1.SubmitOperatingFeedbackRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - minLength: 1 - messageId: - type: string - title: message_id - minLength: 1 - sentiment: - not: - enum: - - 0 - title: sentiment - $ref: '#/components/schemas/console.v1.OperatingFeedbackSentiment' - category: - title: category - $ref: '#/components/schemas/console.v1.OperatingCorrectionCategory' - classificationSource: - not: - enum: - - 0 - title: classification_source - $ref: '#/components/schemas/console.v1.OperatingFeedbackClassificationSource' - correction: - type: string - title: correction - maxLength: 4000 - remember: - type: boolean - title: remember - remediationAction: - not: - enum: - - 0 - title: remediation_action - $ref: '#/components/schemas/console.v1.OperatingFeedbackRemediationAction' - remediationAttemptId: - type: string - title: remediation_attempt_id - maxLength: 256 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - reason: - title: reason - $ref: '#/components/schemas/console.v1.OperatingFeedbackReason' - lifecycleState: - title: lifecycle_state - $ref: '#/components/schemas/console.v1.OperatingFeedbackLifecycleState' - supersedesFeedbackId: - type: string - title: supersedes_feedback_id - maxLength: 256 - title: SubmitOperatingFeedbackRequest - required: - - query - additionalProperties: false - console.v1.SubmitOperatingFeedbackResponse: - type: object - properties: - feedback: - title: feedback - $ref: '#/components/schemas/console.v1.OperatingFeedback' - correction: - title: correction - $ref: '#/components/schemas/console.v1.OperatingCorrectionCandidate' - factReceipt: - title: fact_receipt - $ref: '#/components/schemas/console.v1.CustomerIntelligenceReceipt' - title: SubmitOperatingFeedbackResponse - required: - - feedback - additionalProperties: false - console.v1.SubmitOperatingMessageRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - body: - type: string - title: body - maxLength: 20000 - idempotencyKey: - type: string - title: idempotency_key - attachments: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingAttachmentRef' - title: attachments - maxItems: 1 - continuationTaskId: - type: string - title: continuation_task_id - maxLength: 256 - description: |- - continuation_task_id resumes existing work. Omit it to create a new task. - The server owns task creation and revision assignment. - referenceTaskIds: - type: array - items: - type: string - maxLength: 256 - minLength: 1 - maxItems: 16 - title: reference_task_ids - maxItems: 16 - draftPrewarmId: - type: string - title: draft_prewarm_id - maxLength: 256 - description: |- - The id returned by PrewarmOperatingThread. The server verifies it is - tenant- and principal-bound before reusing the prepared RunnerSession. - modelSelection: - title: model_selection - description: |- - Omitted preserves the conversation preference; an empty message resets Auto. - This is a preference, never managed inference authorization. - $ref: '#/components/schemas/console.v1.OperatingModelSelection' - codingAcceptance: - title: coding_acceptance - description: Opt in to evidence-backed coding acceptance; absence preserves ordinary chat. - $ref: '#/components/schemas/console.v1.CodingAcceptanceContract' - projectResourceId: - type: string - title: project_resource_id - maxLength: 255 - minLength: 1 - nullable: true - taskKind: - title: task_kind - description: |- - New coding implementation submissions require an admitted coding_acceptance - contract. No classification is inferred from the body or project name. - $ref: '#/components/schemas/console.v1.OperatingTaskKind' - title: SubmitOperatingMessageRequest - required: - - query - additionalProperties: false - console.v1.SubmitOperatingMessageResponse: - type: object - properties: - message: - title: message - $ref: '#/components/schemas/console.v1.OperatingMessage' - receipts: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingReceipt' - title: receipts - capabilities: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingCapabilityState' - title: capabilities - messages: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingMessage' - title: messages - description: |- - Full turn messages written by the submit. `message` remains the canonical - submitted human turn for older clients. - route: - title: route - $ref: '#/components/schemas/console.v1.OperatingTurnRoute' - acceptedTurn: - title: accepted_turn - $ref: '#/components/schemas/console.v1.OperatingThreadTurn' - replayCursor: - type: - - integer - - string - title: replay_cursor - format: int64 - title: SubmitOperatingMessageResponse - additionalProperties: false - console.v1.SubmitOrbControlActionRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - targetId: - type: string - title: target_id - minLength: 1 - action: - not: - enum: - - 0 - title: action - $ref: '#/components/schemas/orbcontrol.v1.OrbCommandKind' - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - expectedGeneration: - type: - - integer - - string - title: expected_generation - format: int64 - title: SubmitOrbControlActionRequest - required: - - query - additionalProperties: false - description: SubmitOrbControlActionRequest records one generation-fenced user intent. - console.v1.SubmitOrbControlActionResponse: - type: object - properties: - target: - title: target - $ref: '#/components/schemas/console.v1.OrbControlTarget' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.OperatingReceipt' - title: SubmitOrbControlActionResponse - required: - - receipt - additionalProperties: false - description: SubmitOrbControlActionResponse returns acceptance state, not inferred completion. - console.v1.SubmitProductIssueReportRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - description: - type: string - title: description - maxLength: 4000 - minLength: 1 - expectedBehavior: - type: string - title: expected_behavior - maxLength: 4000 - pageUrl: - type: string - title: page_url - maxLength: 2048 - appVersion: - type: string - title: app_version - maxLength: 128 - browser: - type: string - title: browser - maxLength: 512 - viewport: - type: string - title: viewport - maxLength: 64 - screenshotFilename: - type: string - title: screenshot_filename - maxLength: 255 - screenshotContentType: - type: string - title: screenshot_content_type - maxLength: 64 - screenshot: - type: string - title: screenshot - maxLength: 6990508 - x-protobuf-bytes-max-length: 5242880 - format: byte - includeDiagnostics: - type: boolean - title: include_diagnostics - idempotencyKey: - type: string - title: idempotency_key - maxLength: 512 - minLength: 1 - context: - title: context - $ref: '#/components/schemas/console.v1.ProductIssueReportContext' - title: SubmitProductIssueReportRequest - required: - - query - additionalProperties: false - console.v1.SubmitProductIssueReportResponse: - type: object - properties: - report: - title: report - $ref: '#/components/schemas/console.v1.ProductIssueReport' - title: SubmitProductIssueReportResponse - required: - - report - additionalProperties: false - console.v1.SubmitPublishedCaptureFormRequest: - type: object - properties: - publicationId: - type: string - title: publication_id - minLength: 1 - description: |- - This opaque id is the only public capability input. Tenant and object - coordinates are derived from the immutable publication record. - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - answers: - type: array - items: - $ref: '#/components/schemas/console.v1.CaptureFormAnswer' - title: answers - maxItems: 64 - title: SubmitPublishedCaptureFormRequest - additionalProperties: false - console.v1.SubmitPublishedCaptureFormResponse: - type: object - properties: - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.CaptureFormPublicSubmissionReceipt' - title: SubmitPublishedCaptureFormResponse - required: - - receipt - additionalProperties: false - console.v1.TaskEnvironmentProjectOption: - type: object - properties: - projectResourceId: - type: string - title: project_resource_id - displayName: - type: string - title: display_name - title: TaskEnvironmentProjectOption - additionalProperties: false - console.v1.TenantPrivacySetting: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - mode: - title: mode - $ref: '#/components/schemas/console.v1.TenantPrivacyMode' - updatedBy: - type: string - title: updated_by - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: TenantPrivacySetting - additionalProperties: false - description: |- - TenantPrivacySetting is one stored row. workspace_id is empty on the - organization-wide row. - console.v1.TerminalErrorEnvelope: - type: object - properties: - schemaVersion: - type: integer - title: schema_version - const: "1" - kind: - type: string - title: kind - maxLength: 128 - minLength: 1 - boundary: - type: string - title: boundary - maxLength: 128 - minLength: 1 - code: - type: string - title: code - maxLength: 128 - minLength: 1 - retryable: - type: boolean - title: retryable - providerRequestId: - type: string - title: provider_request_id - maxLength: 256 - displaySafeMessage: - type: string - title: display_safe_message - maxLength: 4096 - minLength: 1 - title: TerminalErrorEnvelope - additionalProperties: false - description: |- - TerminalErrorEnvelope is the browser-safe, provider-neutral classification - of one terminal execution failure. retryable is observational metadata; it - does not grant a caller permission to repeat work. - console.v1.TimeRange: - type: object - properties: - startTime: - title: start_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - endTime: - title: end_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: TimeRange - additionalProperties: false - description: TimeRange bounds console queries. - console.v1.TraceCompletenessSignal: - type: object - properties: - id: - type: string - title: id - title: - type: string - title: title - detail: - type: string - title: detail - status: - type: string - title: status - description: status is one of ready, pending, warning, or blocked. - spanIds: - type: array - items: - type: string - title: span_ids - title: TraceCompletenessSignal - additionalProperties: false - console.v1.TraceDrilldown: - type: object - properties: - traceId: - type: string - title: trace_id - rootName: - type: string - title: root_name - assetId: - type: string - title: asset_id - status: - type: string - title: status - totalLatencyMs: - type: - - integer - - string - title: total_latency_ms - format: int64 - inputTokens: - type: - - integer - - string - title: input_tokens - format: int64 - outputTokens: - type: - - integer - - string - title: output_tokens - format: int64 - costUsd: - type: number - title: cost_usd - format: double - evalScore: - type: number - title: eval_score - format: double - riskLevel: - title: risk_level - $ref: '#/components/schemas/common.v1.RiskLevel' - spans: - type: array - items: - $ref: '#/components/schemas/console.v1.TraceSpan' - title: spans - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - annotations: - type: array - items: - $ref: '#/components/schemas/traces.v1.TraceAnnotation' - title: annotations - suggestedLabels: - type: array - items: - type: string - title: suggested_labels - evidenceSource: - type: string - title: evidence_source - description: |- - evidence_source names the backing read path used for this drilldown - ("traces-store", "console-snapshot", etc.) so the UI can distinguish a - live trace lookup from a stale projection. - completenessSignals: - type: array - items: - $ref: '#/components/schemas/console.v1.TraceCompletenessSignal' - title: completeness_signals - description: |- - completeness_signals explain which evidence families are present, pending, - or broken for the trace. They are product-facing diagnostics, not raw test - failures. - securityDecisionPacket: - title: security_decision_packet - description: |- - security_decision_packet is the server-owned answer to the operator - question "Can I approve this?" It joins governance, approval readiness, - risk, and missing evidence so clients do not infer approval state from - labels or text matching. - $ref: '#/components/schemas/console.v1.SecurityDecisionPacket' - title: TraceDrilldown - additionalProperties: false - console.v1.TraceSpan: - type: object - properties: - spanId: - type: string - title: span_id - parentSpanId: - type: string - title: parent_span_id - name: - type: string - title: name - kind: - type: string - title: kind - model: - type: string - title: model - provider: - type: string - title: provider - status: - type: string - title: status - latencyMs: - type: - - integer - - string - title: latency_ms - format: int64 - costUsd: - type: number - title: cost_usd - format: double - inputTokens: - type: - - integer - - string - title: input_tokens - format: int64 - outputTokens: - type: - - integer - - string - title: output_tokens - format: int64 - governanceDecision: - type: string - title: governance_decision - startedAt: - title: started_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - endedAt: - title: ended_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - attributes: - title: attributes - $ref: '#/components/schemas/google.protobuf.Struct' - references: - type: array - items: - $ref: '#/components/schemas/console.v1.TraceSpanReference' - title: references - title: TraceSpan - additionalProperties: false - console.v1.TraceSpanReference: - type: object - properties: - id: - type: string - title: id - resourceType: - type: string - title: resource_type - label: - type: string - title: label - url: - type: string - title: url - title: TraceSpanReference - additionalProperties: false - console.v1.TransitionBusinessProcessRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - processId: - type: string - title: process_id - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - transitionId: - type: string - title: transition_id - participants: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessProcessParticipant' - title: participants - description: Every role must name its exact current record revision. This fences decisions. - acceptDecision: - type: boolean - title: accept_decision - title: TransitionBusinessProcessRequest - additionalProperties: false - console.v1.TransitionBusinessProcessResponse: - type: object - properties: - process: - title: process - $ref: '#/components/schemas/console.v1.BusinessProcess' - accepted: - type: boolean - title: accepted - unmetRequirementIds: - type: array - items: - type: string - title: unmet_requirement_ids - title: TransitionBusinessProcessResponse - additionalProperties: false - console.v1.UnpinSourceRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - sourceId: - type: string - title: source_id - minLength: 1 - title: UnpinSourceRequest - additionalProperties: false - console.v1.UnpinSourceResponse: - type: object - title: UnpinSourceResponse - additionalProperties: false - console.v1.UpdateAgentProductRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - agentId: - type: string - title: agent_id - minLength: 1 - expectedConfigVersion: - exclusiveMinimum: 0 - type: integer - title: expected_config_version - format: int32 - name: - type: string - title: name - minLength: 1 - description: - type: string - title: description - promptBindings: - type: object - title: prompt_bindings - additionalProperties: - type: string - title: value - integrationIds: - type: array - items: - type: string - title: integration_ids - connectorRequirements: - type: array - items: - $ref: '#/components/schemas/agents.v1.ConnectorRequirement' - title: connector_requirements - role: - type: string - title: role - purpose: - type: string - title: purpose - responsibilities: - type: array - items: - $ref: '#/components/schemas/agents.v1.TeammateResponsibility' - title: responsibilities - triggers: - type: array - items: - $ref: '#/components/schemas/agents.v1.InitiativeTrigger' - title: triggers - title: UpdateAgentProductRequest - additionalProperties: false - console.v1.UpdateAgentProductRequest.PromptBindingsEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: PromptBindingsEntry - additionalProperties: false - console.v1.UpdateAgentProductResponse: - type: object - properties: - agent: - title: agent - $ref: '#/components/schemas/agents.v1.Agent' - config: - title: config - $ref: '#/components/schemas/agents.v1.AgentConfig' - title: UpdateAgentProductResponse - additionalProperties: false - console.v1.UpdateBusinessObjectRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - idempotencyKey: - type: string - title: idempotency_key - objectId: - type: string - title: object_id - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - values: - type: array - items: - $ref: '#/components/schemas/console.v1.BusinessFieldValue' - title: values - schemaRevision: - type: - - integer - - string - title: schema_revision - format: int64 - title: UpdateBusinessObjectRequest - additionalProperties: false - console.v1.UpdateBusinessObjectResponse: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/console.v1.BusinessObject' - title: UpdateBusinessObjectResponse - additionalProperties: false - console.v1.UpdateCaptureFormRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - formId: - type: string - title: form_id - minLength: 1 - expectedRevision: - exclusiveMinimum: 0 - type: - - integer - - string - title: expected_revision - format: int64 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 128 - minLength: 1 - name: - type: string - title: name - maxLength: 160 - minLength: 1 - description: - type: string - title: description - maxLength: 2000 - version: - title: version - $ref: '#/components/schemas/console.v1.CaptureFormVersionInput' - title: UpdateCaptureFormRequest - required: - - version - additionalProperties: false - console.v1.UpdateCaptureFormResponse: - type: object - properties: - form: - title: form - $ref: '#/components/schemas/console.v1.CaptureForm' - version: - title: version - $ref: '#/components/schemas/console.v1.CaptureFormVersion' - title: UpdateCaptureFormResponse - required: - - form - - version - additionalProperties: false - console.v1.UpdateConnectorProfileRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - id: - type: string - title: id - minLength: 1 - enabled: - type: boolean - title: enabled - nullable: true - isDefault: - type: boolean - title: is_default - nullable: true - scopes: - title: scopes - $ref: '#/components/schemas/console.v1.ConnectorProfileScopeSet' - title: UpdateConnectorProfileRequest - required: - - query - additionalProperties: false - console.v1.UpdateConnectorProfileResponse: - type: object - properties: - profile: - title: profile - $ref: '#/components/schemas/console.v1.ConnectorProfile' - title: UpdateConnectorProfileResponse - required: - - profile - additionalProperties: false - console.v1.UpdateConnectorTriggerRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - triggerId: - type: string - title: trigger_id - minLength: 1 - name: - type: string - title: name - minLength: 1 - source: - not: - enum: - - 0 - title: source - $ref: '#/components/schemas/console.v1.ConnectorTriggerSource' - cronExpression: - type: string - title: cron_expression - connectionId: - type: string - title: connection_id - providerId: - type: string - title: provider_id - eventKind: - type: string - title: event_kind - payloadFieldAllowlist: - type: array - items: - type: string - title: payload_field_allowlist - template: - title: template - $ref: '#/components/schemas/console.v1.MissionScheduleTemplate' - title: UpdateConnectorTriggerRequest - required: - - query - - template - additionalProperties: false - console.v1.UpdateConnectorTriggerResponse: - type: object - properties: - trigger: - title: trigger - $ref: '#/components/schemas/console.v1.ConnectorTrigger' - title: UpdateConnectorTriggerResponse - required: - - trigger - additionalProperties: false - console.v1.UpdateDexMcpServerRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - serverId: - type: string - title: server_id - minLength: 1 - baseUrl: - type: string - title: base_url - nullable: true - enabled: - type: boolean - title: enabled - nullable: true - bearerToken: - type: string - title: bearer_token - nullable: true - clearToken: - type: boolean - title: clear_token - title: UpdateDexMcpServerRequest - required: - - query - additionalProperties: false - console.v1.UpdateDexMcpServerResponse: - type: object - properties: - server: - title: server - $ref: '#/components/schemas/console.v1.DexMcpServer' - title: UpdateDexMcpServerResponse - required: - - server - additionalProperties: false - console.v1.UpdateInferenceCreditAutoRefillRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - requestId: - type: string - title: request_id - format: uuid - enabled: - type: boolean - title: enabled - thresholdCents: - type: - - integer - - string - title: threshold_cents - format: int64 - creditCents: - type: - - integer - - string - title: credit_cents - format: int64 - monthlyCapCents: - type: - - integer - - string - title: monthly_cap_cents - format: int64 - consent: - type: boolean - title: consent - description: Explicit agreement to the displayed threshold, gross charge and UTC monthly cap. - expectedGeneration: - type: string - title: expected_generation - title: UpdateInferenceCreditAutoRefillRequest - additionalProperties: false - console.v1.UpdateInferenceCreditAutoRefillResponse: - type: object - properties: - setupUrl: - type: string - title: setup_url - generation: - type: string - title: generation - title: UpdateInferenceCreditAutoRefillResponse - additionalProperties: false - console.v1.UpdateMissionScheduleRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - scheduleId: - type: string - title: schedule_id - minLength: 1 - name: - type: string - title: name - minLength: 1 - cronExpression: - type: string - title: cron_expression - minLength: 1 - template: - title: template - $ref: '#/components/schemas/console.v1.MissionScheduleTemplate' - title: UpdateMissionScheduleRequest - required: - - query - - template - additionalProperties: false - console.v1.UpdateMissionScheduleResponse: - type: object - properties: - schedule: - title: schedule - $ref: '#/components/schemas/console.v1.MissionSchedule' - title: UpdateMissionScheduleResponse - required: - - schedule - additionalProperties: false - console.v1.UpdateOperatorPreferencesRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - dexHatId: - type: string - title: dex_hat_id - description: Omitted only for a model_preference update; existing profile updates require a hat. - developerModeEnabled: - type: boolean - title: developer_mode_enabled - nullable: true - modelPreference: - title: model_preference - $ref: '#/components/schemas/console.v1.OperatorModelPreferenceUpdate' - title: UpdateOperatorPreferencesRequest - required: - - query - additionalProperties: false - console.v1.UpdateOperatorPreferencesResponse: - type: object - properties: - preferences: - title: preferences - $ref: '#/components/schemas/console.v1.OperatorPreferences' - title: UpdateOperatorPreferencesResponse - required: - - preferences - additionalProperties: false - console.v1.UpdateProspectingWatchProgramRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - watchProgramId: - type: string - title: watch_program_id - minLength: 1 - name: - type: string - title: name - maxLength: 128 - minLength: 1 - config: - title: config - $ref: '#/components/schemas/google.protobuf.Struct' - scoringRuleRevision: - type: string - title: scoring_rule_revision - maxLength: 128 - minLength: 1 - lifecycle: - not: - enum: - - 0 - title: lifecycle - $ref: '#/components/schemas/console.v1.ProspectingWatchProgramLifecycle' - expectedRevision: - exclusiveMinimum: 0 - type: - - integer - - string - title: expected_revision - format: int64 - reason: - type: string - title: reason - maxLength: 512 - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 256 - minLength: 1 - title: UpdateProspectingWatchProgramRequest - required: - - query - - config - additionalProperties: false - console.v1.UpdateProspectingWatchProgramResponse: - type: object - properties: - program: - title: program - $ref: '#/components/schemas/console.v1.ProspectingWatchProgram' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.ProspectingWatchProgramMutationReceipt' - title: UpdateProspectingWatchProgramResponse - required: - - program - - receipt - additionalProperties: false - console.v1.UpdateStaffInferenceRoutingProfileRequest: - type: object - properties: - provider: - type: string - title: provider - model: - type: string - title: model - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - note: - type: string - title: note - maxLength: 512 - minLength: 1 - purpose: - title: purpose - $ref: '#/components/schemas/console.v1.StaffInferenceRoutingPurpose' - resetToDefault: - type: boolean - title: reset_to_default - description: |- - Reset every purpose to the deployment default while retaining revisioned - audit history. - canaryProvider: - type: string - title: canary_provider - canaryModel: - type: string - title: canary_model - canaryPercent: - type: integer - title: canary_percent - maximum: 50 - rollbackRevision: - type: - - integer - - string - title: rollback_revision - format: int64 - description: Restore the complete snapshot recorded at this prior revision. - title: UpdateStaffInferenceRoutingProfileRequest - additionalProperties: false - console.v1.UpdateStaffInferenceRoutingProfileResponse: - type: object - properties: - profile: - title: profile - $ref: '#/components/schemas/console.v1.StaffInferenceRoutingProfile' - effectiveTarget: - title: effective_target - $ref: '#/components/schemas/console.v1.InferenceProviderTarget' - title: UpdateStaffInferenceRoutingProfileResponse - required: - - profile - - effectiveTarget - additionalProperties: false - console.v1.UpdateWorkspaceArtifactStyleGuideRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - workspaceArtifactStyleGuide: - title: workspace_artifact_style_guide - $ref: '#/components/schemas/console.v1.WorkspaceArtifactStyleGuide' - title: UpdateWorkspaceArtifactStyleGuideRequest - required: - - query - - workspaceArtifactStyleGuide - additionalProperties: false - console.v1.UpdateWorkspaceArtifactStyleGuideResponse: - type: object - properties: - settings: - title: settings - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - title: UpdateWorkspaceArtifactStyleGuideResponse - required: - - settings - additionalProperties: false - console.v1.UpdateWorkspaceBillingRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - billing: - title: billing - $ref: '#/components/schemas/console.v1.WorkspaceSettingsBilling' - title: UpdateWorkspaceBillingRequest - required: - - query - - billing - additionalProperties: false - console.v1.UpdateWorkspaceDexPolicyRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - dexPolicy: - title: dex_policy - description: |- - (-- api-linter: core::0134::request-resource-field=disabled - aip.dev/not-precedent: The public dex_policy source and ProtoJSON names - predate AIP-134 and remain compatibility contracts. --) - $ref: '#/components/schemas/console.v1.WorkspaceDexPolicy' - title: UpdateWorkspaceDexPolicyRequest - required: - - query - - dexPolicy - additionalProperties: false - console.v1.UpdateWorkspaceDexPolicyResponse: - type: object - properties: - settings: - title: settings - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - title: UpdateWorkspaceDexPolicyResponse - required: - - settings - additionalProperties: false - console.v1.UpdateWorkspaceNotificationPreferencesRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - notifications: - title: notifications - $ref: '#/components/schemas/console.v1.WorkspaceSettingsNotifications' - title: UpdateWorkspaceNotificationPreferencesRequest - required: - - query - - notifications - additionalProperties: false - console.v1.UpdateWorkspacePolicyRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - policy: - title: policy - $ref: '#/components/schemas/console.v1.WorkspaceSettingsPolicy' - title: UpdateWorkspacePolicyRequest - required: - - query - - policy - additionalProperties: false - console.v1.UpdateWorkspacePolicyResponse: - type: object - properties: - settings: - title: settings - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - title: UpdateWorkspacePolicyResponse - required: - - settings - additionalProperties: false - console.v1.UpdateWorkspaceProfileRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - profile: - title: profile - $ref: '#/components/schemas/console.v1.WorkspaceSettingsProfile' - title: UpdateWorkspaceProfileRequest - required: - - query - - profile - additionalProperties: false - console.v1.UpdateWorkspaceProfileResponse: - type: object - properties: - settings: - title: settings - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - title: UpdateWorkspaceProfileResponse - required: - - settings - additionalProperties: false - console.v1.UpdateWorkspaceSkillRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - name: - type: string - title: name - minLength: 1 - description: - type: string - title: description - body: - type: string - title: body - minLength: 1 - title: UpdateWorkspaceSkillRequest - required: - - query - additionalProperties: false - console.v1.UpdateWorkspaceSkillResponse: - type: object - properties: - skill: - title: skill - $ref: '#/components/schemas/console.v1.OperatingSkill' - title: UpdateWorkspaceSkillResponse - required: - - skill - additionalProperties: false - console.v1.UpsertManagedProviderAccessGrantRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - provider: - type: string - title: provider - minLength: 1 - environment: - type: string - title: environment - minLength: 1 - enabled: - type: boolean - title: enabled - note: - type: string - title: note - maxLength: 512 - minLength: 1 - description: Required audit note recorded with every enable/disable action. - expectedRevision: - type: - - integer - - string - title: expected_revision - format: int64 - description: Zero creates a new grant; updates must present the current revision. - state: - title: state - $ref: '#/components/schemas/console.v1.ManagedProviderAccessState' - expiresAt: - title: expires_at - description: Legacy grants retain a bounded expiry. Mutually exclusive with durable_enrollment. - $ref: '#/components/schemas/google.protobuf.Timestamp' - durableEnrollment: - type: boolean - title: durable_enrollment - description: Explicit staff-authorized enrollment independent of execution-token lifetime. - workspaceId: - type: string - title: workspace_id - description: Required for durable enrollment. Persisted for exact-tenant synchronization retries. - title: UpsertManagedProviderAccessGrantRequest - additionalProperties: false - console.v1.UpsertManagedProviderAccessGrantResponse: - type: object - properties: - grant: - title: grant - $ref: '#/components/schemas/console.v1.ManagedProviderAccessGrant' - title: UpsertManagedProviderAccessGrantResponse - additionalProperties: false - console.v1.UpsertWorkspaceGuardrailRuleRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - rule: - title: rule - $ref: '#/components/schemas/console.v1.WorkspaceGuardrailRule' - title: UpsertWorkspaceGuardrailRuleRequest - required: - - query - - rule - additionalProperties: false - console.v1.UpsertWorkspaceIdentityProviderRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - provider: - title: provider - $ref: '#/components/schemas/console.v1.WorkspaceSettingsIdentityProvider' - title: UpsertWorkspaceIdentityProviderRequest - required: - - query - - provider - additionalProperties: false - console.v1.UpsertWorkspaceIdentityProviderResponse: - type: object - properties: - settings: - title: settings - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - title: UpsertWorkspaceIdentityProviderResponse - required: - - settings - additionalProperties: false - console.v1.UpsertWorkspaceIntegrationRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - integration: - title: integration - $ref: '#/components/schemas/console.v1.WorkspaceSettingsIntegration' - title: UpsertWorkspaceIntegrationRequest - required: - - query - - integration - additionalProperties: false - console.v1.UpsertWorkspaceIntegrationResponse: - type: object - properties: - settings: - title: settings - $ref: '#/components/schemas/console.v1.GetWorkspaceSettingsResponse' - title: UpsertWorkspaceIntegrationResponse - required: - - settings - additionalProperties: false - console.v1.UpsertWorkspaceMemberRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - member: - title: member - $ref: '#/components/schemas/console.v1.WorkspaceSettingsMember' - title: UpsertWorkspaceMemberRequest - required: - - query - - member - additionalProperties: false - console.v1.VerifyPrivateEndpointRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - endpointId: - type: string - title: endpoint_id - minLength: 1 - evidenceId: - type: string - title: evidence_id - minLength: 1 - description: |- - Retained for wire compatibility. The server ignores caller-supplied - evidence until a server-owned attestor is configured. - provider: - type: string - title: provider - minLength: 1 - description: Retained for wire compatibility; not trusted as proof. - privateRouteObserved: - type: boolean - title: private_route_observed - description: Retained for wire compatibility; not trusted as proof. - dnsValidated: - type: boolean - title: dns_validated - title: VerifyPrivateEndpointRequest - required: - - query - additionalProperties: false - console.v1.VerifyPrivateEndpointResponse: - type: object - properties: - endpoint: - title: endpoint - $ref: '#/components/schemas/console.v1.PrivateEndpoint' - title: VerifyPrivateEndpointResponse - required: - - endpoint - additionalProperties: false - console.v1.WakeComputerMissionRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - organizationId: - type: string - title: organization_id - minLength: 1 - missionId: - type: string - title: mission_id - minLength: 1 - expectedGeneration: - type: - - integer - - string - title: expected_generation - format: int64 - reason: - type: string - title: reason - minLength: 1 - condition: - title: condition - $ref: '#/components/schemas/google.protobuf.Struct' - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - wakeAt: - title: wake_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: WakeComputerMissionRequest - required: - - query - additionalProperties: false - console.v1.WakeComputerMissionResponse: - type: object - properties: - mission: - title: mission - $ref: '#/components/schemas/console.v1.ComputerMission' - receipt: - title: receipt - $ref: '#/components/schemas/console.v1.OperatingReceipt' - wakeId: - type: string - title: wake_id - minLength: 1 - title: WakeComputerMissionResponse - required: - - mission - - receipt - additionalProperties: false - console.v1.WatchOperatingThreadRequest: - type: object - properties: - query: - title: query - $ref: '#/components/schemas/console.v1.ConsoleQuery' - channelId: - type: string - title: channel_id - minLength: 1 - afterCursor: - type: - - integer - - string - title: after_cursor - format: int64 - title: WatchOperatingThreadRequest - required: - - query - additionalProperties: false - console.v1.WatchOperatingThreadResponse: - type: object - properties: - events: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingThreadEvent' - title: events - maxItems: 50 - nextCursor: - type: - - integer - - string - title: next_cursor - format: int64 - resetRequired: - type: boolean - title: reset_required - threadExecution: - title: thread_execution - $ref: '#/components/schemas/console.v1.OperatingThreadExecution' - snapshotTurns: - type: array - items: - $ref: '#/components/schemas/console.v1.OperatingThreadTurn' - title: snapshot_turns - title: WatchOperatingThreadResponse - additionalProperties: false - console.v1.WorkspaceArtifactStyleGuide: - type: object - properties: - enabled: - type: boolean - title: enabled - voiceAndTone: - type: string - title: voice_and_tone - maxLength: 4000 - description: |- - Deprecated compatibility projection of the selected default voice's - guidance. New clients use brand_voices and default_brand_voice_id. - documentGuidance: - type: string - title: document_guidance - maxLength: 8000 - presentationGuidance: - type: string - title: presentation_guidance - maxLength: 8000 - requiredTerms: - type: array - items: - type: string - maxItems: 100 - title: required_terms - maxItems: 100 - forbiddenTerms: - type: array - items: - type: string - maxItems: 100 - title: forbidden_terms - maxItems: 100 - version: - type: - - integer - - string - title: version - format: int64 - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updateCapability: - title: update_capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - responseGuidance: - type: string - title: response_guidance - maxLength: 8000 - requireCitations: - type: boolean - title: require_citations - maxResponseWords: - type: integer - title: max_response_words - maximum: 4000 - allowedCitationDomains: - type: array - items: - type: string - maxItems: 100 - title: allowed_citation_domains - maxItems: 100 - brandVoices: - type: array - items: - $ref: '#/components/schemas/console.v1.WorkspaceBrandVoice' - title: brand_voices - description: |- - Reusable voice assets available to this workspace. Deixic does not impose - a plan or item-count limit; transport and field-size limits still apply to - each request. A voice id has meaning only inside the authorized - organization/workspace pair that returned it. - defaultBrandVoiceId: - type: string - title: default_brand_voice_id - maxLength: 128 - description: |- - Empty means that the workspace has no voice assignment. A non-empty id - must resolve to one active voice in brand_voices; unknown or archived - selections are rejected rather than inherited from another workspace. - title: WorkspaceArtifactStyleGuide - additionalProperties: false - description: |- - WorkspaceArtifactStyleGuide is the workspace-owned Content & AI policy for - user-visible content Dex authors across responses, actions, documents, and - presentations. The historical message name is retained for wire - compatibility. Guidance shapes generation while deterministic controls are - enforced at response and durable-artifact boundaries. - console.v1.WorkspaceBrandVoice: - type: object - properties: - voiceId: - type: string - title: voice_id - maxLength: 128 - name: - type: string - title: name - maxLength: 80 - description: - type: string - title: description - maxLength: 280 - guidance: - type: string - title: guidance - maxLength: 4000 - archived: - type: boolean - title: archived - scopes: - type: array - items: - $ref: '#/components/schemas/console.v1.WorkspaceBrandVoice.Scope' - title: scopes - description: |- - Scopes describe where the company intends to reuse this voice. They are - policy metadata, never authorization input. Kinds are customer-defined so - teams can use organization, team, brand, executive, product, campaign, - customer, or another vocabulary without a schema migration. - version: - type: - - integer - - string - title: version - format: int64 - description: |- - Server-managed revision of this voice asset. It advances only when the - voice's name, description, guidance, scopes, or archive state changes. - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: WorkspaceBrandVoice - additionalProperties: false - description: |- - WorkspaceBrandVoice is declared at the end of this large file so the - additive settings field does not renumber unrelated generated descriptors. - It is a reusable set of writing instructions projected through a workspace's - Content & AI policy. Archiving preserves stable references while preventing - future assignment. - console.v1.WorkspaceBrandVoice.Scope: - type: object - properties: - kind: - type: string - title: kind - maxLength: 64 - value: - type: string - title: value - maxLength: 256 - title: Scope - additionalProperties: false - console.v1.WorkspaceContentPolicyViolation: - type: object - properties: - code: - type: string - title: code - message: - type: string - title: message - title: WorkspaceContentPolicyViolation - additionalProperties: false - console.v1.WorkspaceDexPolicy: - type: object - properties: - autonomyMode: - not: - enum: - - 0 - title: autonomy_mode - $ref: '#/components/schemas/console.v1.DexAutonomyMode' - externalActionMode: - not: - enum: - - 0 - title: external_action_mode - $ref: '#/components/schemas/console.v1.DexExternalActionMode' - projectMemoryEnabled: - type: boolean - title: project_memory_enabled - preferenceMemoryEnabled: - type: boolean - title: preference_memory_enabled - learningFromCorrectionsEnabled: - type: boolean - title: learning_from_corrections_enabled - proactivityEnabled: - type: boolean - title: proactivity_enabled - traceContentCaptureEnabled: - type: boolean - title: trace_content_capture_enabled - maxTurnSeconds: - type: integer - title: max_turn_seconds - maximum: 900 - minimum: 5 - format: int32 - maxToolCalls: - type: integer - title: max_tool_calls - maximum: 64 - format: int32 - maxConcurrency: - type: integer - title: max_concurrency - maximum: 8 - minimum: 1 - format: int32 - maxCostMicros: - type: - - integer - - string - title: max_cost_micros - maximum: 100000000 - format: int64 - allowedSystems: - type: array - items: - type: string - maxItems: 64 - title: allowed_systems - maxItems: 64 - updateCapability: - title: update_capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - reviewCorrectionsCapability: - title: review_corrections_capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - customerIntelligenceEnabled: - type: boolean - title: customer_intelligence_enabled - commitmentNudgesEnabled: - type: boolean - title: commitment_nudges_enabled - description: |- - Proactive commitment-ledger nudges (due-date reminders projected into the - operating channel). On in Dex Standard; workspaces can opt out. The - deployment ceiling DEX_COMMITMENT_NUDGES_ENABLED must also be on, so a - workspace can narrow the ceiling but never widen it. - mcpDispatchEnabled: - type: boolean - title: mcp_dispatch_enabled - description: |- - Opt-in for model-visible governed MCP dispatch (policy-filtered - discovery, Gate admission, and durable approval continuation). Off by - default; the deployment ceiling DEX_MCP_TOOLS_ENABLED must also be on. - Workspaces can narrow the ceiling, never widen it. - subagentDelegationEnabled: - type: boolean - title: subagent_delegation_enabled - description: |- - Customer-facing Subagents opt-in for Dex child-run delegation. Off by - default; the deployment ceiling DEX_DELEGATE_ENABLED must also be on. - Workspaces can narrow the ceiling, never widen it. - title: WorkspaceDexPolicy - additionalProperties: false - console.v1.WorkspaceGuardrailRule: - type: object - properties: - id: - type: string - title: id - maxLength: 128 - minLength: 1 - name: - type: string - title: name - maxLength: 256 - minLength: 1 - detectorKind: - title: detector_kind - $ref: '#/components/schemas/console.v1.GuardrailDetectorKind' - pattern: - type: string - title: pattern - maxLength: 4096 - description: |- - Regex source, required only when detector_kind is CUSTOM_REGEX. Empty for - built-in detectors. - action: - title: action - $ref: '#/components/schemas/console.v1.GuardrailAction' - enabled: - type: boolean - title: enabled - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: WorkspaceGuardrailRule - additionalProperties: false - description: |- - WorkspaceGuardrailRule is one workspace-configured content guardrail applied - to Dex model output. - console.v1.WorkspaceMemory: - type: object - properties: - reviewStatus: - title: review_status - $ref: '#/components/schemas/memory.v1.MemoryReviewStatus' - id: - type: string - title: id - minLength: 1 - scope: - title: scope - $ref: '#/components/schemas/memory.v1.Scope' - content: - type: string - title: content - type: - type: string - title: type - tags: - type: array - items: - type: string - maxItems: 64 - title: tags - maxItems: 64 - revision: - type: - - integer - - string - title: revision - minimum: 1 - format: int64 - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: WorkspaceMemory - additionalProperties: false - description: |- - WorkspaceMemory is the customer-safe projection of an owner record. It - deliberately excludes embeddings, internal actor ids, and provenance refs. - console.v1.WorkspaceSettingsActivityEntry: - type: object - properties: - id: - type: string - title: id - section: - type: string - title: section - action: - type: string - title: action - actorSubject: - type: string - title: actor_subject - actorEmail: - type: string - title: actor_email - summary: - type: string - title: summary - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - details: - type: object - title: details - additionalProperties: - type: string - title: value - title: WorkspaceSettingsActivityEntry - additionalProperties: false - console.v1.WorkspaceSettingsActivityEntry.DetailsEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: DetailsEntry - additionalProperties: false - console.v1.WorkspaceSettingsBilling: - type: object - properties: - status: - type: string - title: status - plan: - type: string - title: plan - seatsUsed: - type: integer - title: seats_used - format: int32 - seatsTotal: - type: integer - title: seats_total - format: int32 - renewalAt: - title: renewal_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - billingContact: - type: string - title: billing_contact - manageCapability: - title: manage_capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - statusEnum: - title: status_enum - $ref: '#/components/schemas/console.v1.WorkspaceSettingsBillingStatus' - title: WorkspaceSettingsBilling - additionalProperties: false - console.v1.WorkspaceSettingsBreakGlassGrant: - type: object - properties: - id: - type: string - title: id - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - customerApprovedBy: - type: string - title: customer_approved_by - reason: - type: string - title: reason - supportUserEmail: - type: string - title: support_user_email - readOnly: - type: boolean - title: read_only - enabledAt: - title: enabled_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - disabledAt: - title: disabled_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - manageCapability: - title: manage_capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: WorkspaceSettingsBreakGlassGrant - additionalProperties: false - console.v1.WorkspaceSettingsCapability: - type: object - properties: - id: - type: string - title: id - label: - type: string - title: label - available: - type: boolean - title: available - reason: - type: string - title: reason - actionUrl: - type: string - title: action_url - title: WorkspaceSettingsCapability - additionalProperties: false - console.v1.WorkspaceSettingsIdentityProvider: - type: object - properties: - id: - type: string - title: id - name: - type: string - title: name - detail: - type: string - title: detail - status: - type: string - title: status - configureCapability: - title: configure_capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - source: - type: string - title: source - statusEnum: - title: status_enum - $ref: '#/components/schemas/console.v1.WorkspaceSettingsIdentityProviderStatus' - sourceEnum: - title: source_enum - $ref: '#/components/schemas/console.v1.WorkspaceSettingsSource' - title: WorkspaceSettingsIdentityProvider - additionalProperties: false - console.v1.WorkspaceSettingsIntegration: - type: object - properties: - id: - type: string - title: id - name: - type: string - title: name - provider: - type: string - title: provider - category: - type: string - title: category - detail: - type: string - title: detail - status: - type: string - title: status - configureCapability: - title: configure_capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - source: - type: string - title: source - statusEnum: - title: status_enum - $ref: '#/components/schemas/console.v1.WorkspaceSettingsIntegrationStatus' - sourceEnum: - title: source_enum - $ref: '#/components/schemas/console.v1.WorkspaceSettingsSource' - title: WorkspaceSettingsIntegration - additionalProperties: false - console.v1.WorkspaceSettingsMember: - type: object - properties: - subject: - type: string - title: subject - displayName: - type: string - title: display_name - email: - type: string - title: email - role: - type: string - title: role - description: Legacy display label. New clients should use rbac_role. - source: - type: string - title: source - manageCapability: - title: manage_capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - rbacRole: - title: rbac_role - $ref: '#/components/schemas/console.v1.WorkspaceSettingsRole' - status: - type: string - title: status - managed: - type: boolean - title: managed - provisioningSource: - type: string - title: provisioning_source - lastSeenAt: - title: last_seen_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - statusEnum: - title: status_enum - $ref: '#/components/schemas/console.v1.WorkspaceSettingsMemberStatus' - sourceEnum: - title: source_enum - $ref: '#/components/schemas/console.v1.WorkspaceSettingsSource' - provisioningSourceEnum: - title: provisioning_source_enum - $ref: '#/components/schemas/console.v1.WorkspaceSettingsSource' - title: WorkspaceSettingsMember - additionalProperties: false - console.v1.WorkspaceSettingsNotificationPreference: - type: object - properties: - id: - type: string - title: id - label: - type: string - title: label - detail: - type: string - title: detail - enabled: - type: boolean - title: enabled - updateCapability: - title: update_capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - title: WorkspaceSettingsNotificationPreference - additionalProperties: false - console.v1.WorkspaceSettingsNotifications: - type: object - properties: - status: - type: string - title: status - preferences: - type: array - items: - $ref: '#/components/schemas/console.v1.WorkspaceSettingsNotificationPreference' - title: preferences - statusEnum: - title: status_enum - $ref: '#/components/schemas/console.v1.WorkspaceSettingsAvailabilityStatus' - spendBeat: - title: spend_beat - $ref: '#/components/schemas/console.v1.WorkspaceSpendBeatSettings' - title: WorkspaceSettingsNotifications - additionalProperties: false - console.v1.WorkspaceSettingsOwnerStatus: - type: object - properties: - id: - type: string - title: id - label: - type: string - title: label - ownerService: - type: string - title: owner_service - status: - type: string - title: status - summary: - type: string - title: summary - settings: - type: array - items: - type: string - title: settings - capability: - title: capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - checkedAt: - title: checked_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - statusEnum: - title: status_enum - $ref: '#/components/schemas/console.v1.WorkspaceSettingsOwnerServiceStatus' - title: WorkspaceSettingsOwnerStatus - additionalProperties: false - console.v1.WorkspaceSettingsPolicy: - type: object - properties: - status: - type: string - title: status - requireHumanApprovalForWrites: - type: boolean - title: require_human_approval_for_writes - blockMissingEvidence: - type: boolean - title: block_missing_evidence - autoRevokeIdleLeases: - type: boolean - title: auto_revoke_idle_leases - allowCrossAccountAccess: - type: boolean - title: allow_cross_account_access - maxLeaseTtl: - type: string - title: max_lease_ttl - evidenceRequirement: - type: string - title: evidence_requirement - updateCapability: - title: update_capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - requireMfa: - type: boolean - title: require_mfa - enforceSso: - type: boolean - title: enforce_sso - scimProvisioning: - type: boolean - title: scim_provisioning - defaultMemberRole: - type: string - title: default_member_role - description: Legacy display label. New clients should use default_member_rbac_role. - sessionTtl: - type: string - title: session_ttl - allowedDomains: - type: array - items: - type: string - title: allowed_domains - ipAllowlist: - type: array - items: - type: string - title: ip_allowlist - auditLogRetentionDays: - type: integer - title: audit_log_retention_days - format: int32 - dataRetentionDays: - type: integer - title: data_retention_days - format: int32 - defaultMemberRbacRole: - title: default_member_rbac_role - $ref: '#/components/schemas/console.v1.WorkspaceSettingsRole' - statusEnum: - title: status_enum - $ref: '#/components/schemas/console.v1.WorkspaceSettingsAvailabilityStatus' - taskEnvironmentRetention: - title: task_environment_retention - description: Separate inactivity policy for unaccepted task-computer state. - $ref: '#/components/schemas/console.v1.WorkspaceTaskEnvironmentRetention' - title: WorkspaceSettingsPolicy - additionalProperties: false - console.v1.WorkspaceSettingsPrincipal: - type: object - properties: - subject: - type: string - title: subject - userSubject: - type: string - title: user_subject - displayName: - type: string - title: display_name - role: - type: string - title: role - description: Legacy display label. New clients should use rbac_role. - human: - type: boolean - title: human - rbacRole: - title: rbac_role - $ref: '#/components/schemas/console.v1.WorkspaceSettingsRole' - title: WorkspaceSettingsPrincipal - additionalProperties: false - console.v1.WorkspaceSettingsProfile: - type: object - properties: - organizationId: - type: string - title: organization_id - organizationLabel: - type: string - title: organization_label - workspaceId: - type: string - title: workspace_id - workspaceLabel: - type: string - title: workspace_label - environment: - type: string - title: environment - region: - type: string - title: region - archived: - type: boolean - title: archived - archivedAt: - title: archived_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updateCapability: - title: update_capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - archiveCapability: - title: archive_capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - title: WorkspaceSettingsProfile - additionalProperties: false - console.v1.WorkspaceSettingsWorkspace: - type: object - properties: - organizationId: - type: string - title: organization_id - organizationLabel: - type: string - title: organization_label - workspaceId: - type: string - title: workspace_id - workspaceLabel: - type: string - title: workspace_label - environment: - type: string - title: environment - region: - type: string - title: region - current: - type: boolean - title: current - archived: - type: boolean - title: archived - archivedAt: - title: archived_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - rbacRole: - title: rbac_role - $ref: '#/components/schemas/console.v1.WorkspaceSettingsRole' - capabilities: - type: array - items: - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - title: capabilities - source: - type: string - title: source - title: WorkspaceSettingsWorkspace - additionalProperties: false - console.v1.WorkspaceSpendBeatSettings: - type: object - properties: - enabled: - type: boolean - title: enabled - paused: - type: boolean - title: paused - slackConnectionId: - type: string - title: slack_connection_id - maxLength: 256 - slackChannelId: - type: string - title: slack_channel_id - maxLength: 256 - cadence: - title: cadence - $ref: '#/components/schemas/console.v1.WorkspaceSpendBeatCadence' - timezone: - type: string - title: timezone - maxLength: 128 - localHour: - type: integer - title: local_hour - maximum: 23 - localMinute: - type: integer - title: local_minute - maximum: 59 - weeklyDayMondayZero: - type: integer - title: weekly_day_monday_zero - maximum: 6 - description: Monday=0 through Sunday=6. Used only for weekly cadence. - materialityThresholdBp: - type: integer - title: materiality_threshold_bp - maximum: 100000 - minimum: 1 - materialityAbsoluteMicros: - type: - - integer - - string - title: materiality_absolute_micros - format: int64 - cooldownSeconds: - type: integer - title: cooldown_seconds - maximum: 2592000 - quietHoursStart: - type: string - title: quiet_hours_start - maxLength: 5 - quietHoursEnd: - type: string - title: quiet_hours_end - maxLength: 5 - maxDailyNotifications: - type: integer - title: max_daily_notifications - maximum: 24 - updateCapability: - title: update_capability - $ref: '#/components/schemas/console.v1.WorkspaceSettingsCapability' - title: WorkspaceSpendBeatSettings - additionalProperties: false - description: |- - WorkspaceSpendBeatSettings is the server-authoritative opt-in for scheduled - AI spend briefs and material-drift alerts. Destination ids are re-authorized - at delivery time; storing them here never grants connector access. - console.v1.WorkspaceTaskEnvironmentRetention: - type: object - properties: - retentionDays: - type: integer - title: retention_days - format: int32 - enum: - - 0 - - 7 - - 30 - projects: - type: array - items: - $ref: '#/components/schemas/console.v1.ProjectTaskEnvironmentRetention' - title: projects - policyRevision: - type: - - integer - - string - title: policy_revision - format: int64 - description: |- - Server-owned monotonic revision across workspace and project policy changes. - Mutations ignore caller-supplied values. - retentionHours: - type: integer - title: retention_hours - format: int32 - enum: - - 0 - - 8 - - 168 - - 720 - description: Preferred hour-level policy. Zero means the legacy retention_days field. - title: WorkspaceTaskEnvironmentRetention - additionalProperties: false - google.protobuf.ListValue: - type: object - properties: - values: - type: array - items: - $ref: '#/components/schemas/google.protobuf.Value' - title: values - description: Repeated field of dynamically typed values. - title: ListValue - additionalProperties: false - description: |- - `ListValue` is a wrapper around a repeated field of values. - - The JSON representation for `ListValue` is JSON array. - google.protobuf.Struct: - type: object - additionalProperties: - $ref: '#/components/schemas/google.protobuf.Value' - description: |- - `Struct` represents a structured data value, consisting of fields - which map to dynamically typed values. In some languages, `Struct` - might be supported by a native representation. For example, in - scripting languages like JS a struct is represented as an - object. The details of that representation are described together - with the proto support for the language. - - The JSON representation for `Struct` is JSON object. - google.protobuf.Struct.FieldsEntry: - type: object - properties: - key: - type: string - title: key - value: - title: value - $ref: '#/components/schemas/google.protobuf.Value' - title: FieldsEntry - additionalProperties: false - google.protobuf.Timestamp: - type: string - examples: - - 1s - - 1.000340012s - format: date-time - description: |- - A Timestamp represents a point in time independent of any time zone or local - calendar, encoded as a count of seconds and fractions of seconds at - nanosecond resolution. The count is relative to an epoch at UTC midnight on - January 1, 1970, in the proleptic Gregorian calendar which extends the - Gregorian calendar backwards to year one. - - All minutes are 60 seconds long. Leap seconds are "smeared" so that no leap - second table is needed for interpretation, using a [24-hour linear - smear](https://developers.google.com/time/smear). - - The range is from 0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z. By - restricting to that range, we ensure that we can convert to and from [RFC - 3339](https://www.ietf.org/rfc/rfc3339.txt) date strings. - - # Examples - - Example 1: Compute Timestamp from POSIX `time()`. - - Timestamp timestamp; - timestamp.set_seconds(time(NULL)); - timestamp.set_nanos(0); - - Example 2: Compute Timestamp from POSIX `gettimeofday()`. - - struct timeval tv; - gettimeofday(&tv, NULL); - - Timestamp timestamp; - timestamp.set_seconds(tv.tv_sec); - timestamp.set_nanos(tv.tv_usec * 1000); - - Example 3: Compute Timestamp from Win32 `GetSystemTimeAsFileTime()`. - - FILETIME ft; - GetSystemTimeAsFileTime(&ft); - UINT64 ticks = (((UINT64)ft.dwHighDateTime) << 32) | ft.dwLowDateTime; - - // A Windows tick is 100 nanoseconds. Windows epoch 1601-01-01T00:00:00Z - // is 11644473600 seconds before Unix epoch 1970-01-01T00:00:00Z. - Timestamp timestamp; - timestamp.set_seconds((INT64) ((ticks / 10000000) - 11644473600LL)); - timestamp.set_nanos((INT32) ((ticks % 10000000) * 100)); - - Example 4: Compute Timestamp from Java `System.currentTimeMillis()`. - - long millis = System.currentTimeMillis(); - - Timestamp timestamp = Timestamp.newBuilder().setSeconds(millis / 1000) - .setNanos((int) ((millis % 1000) * 1000000)).build(); - - Example 5: Compute Timestamp from Java `Instant.now()`. - - Instant now = Instant.now(); - - Timestamp timestamp = - Timestamp.newBuilder().setSeconds(now.getEpochSecond()) - .setNanos(now.getNano()).build(); - - Example 6: Compute Timestamp from current time in Python. - - timestamp = Timestamp() - timestamp.GetCurrentTime() - - # JSON Mapping - - In JSON format, the Timestamp type is encoded as a string in the - [RFC 3339](https://www.ietf.org/rfc/rfc3339.txt) format. That is, the - format is "{year}-{month}-{day}T{hour}:{min}:{sec}[.{frac_sec}]Z" - where {year} is always expressed using four digits while {month}, {day}, - {hour}, {min}, and {sec} are zero-padded to two digits each. The fractional - seconds, which can go up to 9 digits (i.e. up to 1 nanosecond resolution), - are optional. The "Z" suffix indicates the timezone ("UTC"); the timezone - is required. A proto3 JSON serializer should always use UTC (as indicated by - "Z") when printing the Timestamp type and a proto3 JSON parser should be - able to accept both UTC and other timezones (as indicated by an offset). - - For example, "2017-01-15T01:30:15.01Z" encodes 15.01 seconds past - 01:30 UTC on January 15, 2017. - - In JavaScript, one can convert a Date object to this format using the - standard - [toISOString()](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Date/toISOString) - method. In Python, a standard `datetime.datetime` object can be converted - to this format using - [`strftime`](https://docs.python.org/2/library/time.html#time.strftime) with - the time format spec '%Y-%m-%dT%H:%M:%S.%fZ'. Likewise, in Java, one can use - the Joda Time's [`ISODateTimeFormat.dateTime()`]( - http://joda-time.sourceforge.net/apidocs/org/joda/time/format/ISODateTimeFormat.html#dateTime() - ) to obtain a formatter capable of generating timestamps in this format. - google.protobuf.Value: - oneOf: - - type: "null" - - type: number - - type: string - - type: boolean - - type: array - - type: object - additionalProperties: true - description: |- - `Value` represents a dynamically typed value which can be either - null, a number, a string, a boolean, a recursive struct value, or a - list of values. A producer of value is expected to set one of these - variants. Absence of any variant indicates an error. - - The JSON representation for `Value` is JSON value. - meter.v1.AdminMutationAuditContext: - type: object - properties: - delegatedActorSubject: - type: string - title: delegated_actor_subject - reason: - type: string - title: reason - requestId: - type: string - title: request_id - title: AdminMutationAuditContext - additionalProperties: false - description: Delegation is accepted only from the authenticated Platform managed-access service. - meter.v1.Budget: - type: object - properties: - id: - type: string - title: id - organizationId: - type: string - title: organization_id - teamId: - type: string - title: team_id - workspaceId: - type: string - title: workspace_id - description: |- - Empty means the budget governs every workspace in the organization. - A non-empty value means the budget governs only that workspace. - period: - type: string - title: period - limitUsd: - exclusiveMinimum: 0 - type: number - title: limit_usd - format: double - alertThresholdPct: - type: integer - title: alert_threshold_pct - format: int32 - warningThresholdsPct: - type: array - items: - type: integer - format: int32 - title: warning_thresholds_pct - hardCap: - type: boolean - title: hard_cap - currentSpendUsd: - type: number - title: current_spend_usd - format: double - lastAlertThresholdPct: - type: integer - title: last_alert_threshold_pct - format: int32 - periodStart: - title: period_start - $ref: '#/components/schemas/google.protobuf.Timestamp' - nextResetAt: - title: next_reset_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: Budget - additionalProperties: false - meter.v1.BudgetDenial: - type: object - properties: - budgetId: - type: string - title: budget_id - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - teamId: - type: string - title: team_id - deniedAt: - title: denied_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - requestId: - type: string - title: request_id - traceId: - type: string - title: trace_id - amountUsd: - type: number - title: amount_usd - format: double - model: - type: string - title: model - provider: - type: string - title: provider - denialReason: - type: string - title: denial_reason - id: - type: string - title: id - description: |- - Stable row identity. A reader that lists denials needs it to key a row it - shows next to rows from another owner. - title: BudgetDenial - additionalProperties: false - description: |- - A budget refusal meter recorded when CheckBudget returned allowed=false. - Meter owns this record; model-gateway does not report it back. - meter.v1.BudgetStatus: - type: object - properties: - budgetId: - type: string - title: budget_id - organizationId: - type: string - title: organization_id - teamId: - type: string - title: team_id - workspaceId: - type: string - title: workspace_id - description: Empty means the budget governs every workspace in the organization. - period: - type: string - title: period - limitUsd: - type: number - title: limit_usd - format: double - currentSpendUsd: - type: number - title: current_spend_usd - format: double - remainingUsd: - type: number - title: remaining_usd - format: double - usagePct: - type: number - title: usage_pct - format: double - alertTriggered: - type: boolean - title: alert_triggered - hardCap: - type: boolean - title: hard_cap - hardCapReached: - type: boolean - title: hard_cap_reached - triggeredThresholdPct: - type: integer - title: triggered_threshold_pct - format: int32 - warningThresholdsPct: - type: array - items: - type: integer - format: int32 - title: warning_thresholds_pct - lastAlertThresholdPct: - type: integer - title: last_alert_threshold_pct - format: int32 - spendVelocityUsdPerHour: - type: number - title: spend_velocity_usd_per_hour - format: double - estimatedExhaustionHours: - type: number - title: estimated_exhaustion_hours - format: double - periodStart: - title: period_start - $ref: '#/components/schemas/google.protobuf.Timestamp' - nextResetAt: - title: next_reset_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: BudgetStatus - additionalProperties: false - meter.v1.DevelopmentCreditGrant: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - programId: - type: string - title: program_id - grantId: - type: string - title: grant_id - creditMicros: - type: - - integer - - string - title: credit_micros - format: int64 - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - reason: - type: string - title: reason - provenance: - type: string - title: provenance - actorSubject: - type: string - title: actor_subject - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - dailyBudgetMicros: - exclusiveMinimum: 0 - type: - - integer - - string - title: daily_budget_micros - format: int64 - description: Server-configured organization-wide daily spend ceiling, including outstanding holds. - alertRecipientId: - type: string - title: alert_recipient_id - description: Server-configured Identity user receiving operational alerts, independent of the grant issuer. - title: DevelopmentCreditGrant - additionalProperties: false - description: Billing's accepted immutable grant receipt. The authenticated issuer is server-derived. - meter.v1.DevelopmentCreditProgramPolicy: - type: object - properties: - maxGrantMicros: - exclusiveMinimum: 0 - type: - - integer - - string - title: max_grant_micros - format: int64 - programBudgetMicros: - exclusiveMinimum: 0 - type: - - integer - - string - title: program_budget_micros - format: int64 - dailyBudgetMicros: - exclusiveMinimum: 0 - type: - - integer - - string - title: daily_budget_micros - format: int64 - maxLifetimeSeconds: - exclusiveMinimum: 0 - type: - - integer - - string - title: max_lifetime_seconds - format: int64 - alertRecipientId: - type: string - title: alert_recipient_id - title: DevelopmentCreditProgramPolicy - additionalProperties: false - description: |- - Immutable sponsored program limits. Enrollment is accepted atomically with its - first grant and requires meter:credits:enroll-development in addition to issuance. - meter.v1.GetBudgetDashboardRequest: - type: object - properties: - teamId: - type: string - title: team_id - workspaceId: - type: string - title: workspace_id - description: |- - Empty reports only organization-wide budgets. A non-empty value must equal - the workspace the caller was authorized for and additionally reports that - workspace's budgets. - title: GetBudgetDashboardRequest - additionalProperties: false - meter.v1.GetBudgetDashboardResponse: - type: object - properties: - organizationId: - type: string - title: organization_id - teamId: - type: string - title: team_id - generatedAt: - title: generated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - totalBudgets: - type: integer - title: total_budgets - format: int32 - totalLimitUsd: - type: number - title: total_limit_usd - format: double - totalSpendUsd: - type: number - title: total_spend_usd - format: double - totalRemainingUsd: - type: number - title: total_remaining_usd - format: double - warningBudgets: - type: integer - title: warning_budgets - format: int32 - hardCapBudgets: - type: integer - title: hard_cap_budgets - format: int32 - hardCapReachedBudgets: - type: integer - title: hard_cap_reached_budgets - format: int32 - statuses: - type: array - items: - $ref: '#/components/schemas/meter.v1.BudgetStatus' - title: statuses - workspaceId: - type: string - title: workspace_id - lastDenial: - title: last_denial - description: The most recent refusal in this scope, absent when nothing was refused. - $ref: '#/components/schemas/meter.v1.BudgetDenial' - title: GetBudgetDashboardResponse - additionalProperties: false - meter.v1.GetPrepaidCreditBalanceRequest: - type: object - properties: - runId: - type: string - title: run_id - maxLength: 256 - workspaceId: - type: string - title: workspace_id - minLength: 1 - title: GetPrepaidCreditBalanceRequest - additionalProperties: false - meter.v1.GetPrepaidCreditBalanceResponse: - type: object - properties: - balance: - title: balance - $ref: '#/components/schemas/meter.v1.PrepaidCreditBalance' - reconciliation: - title: reconciliation - description: Absent when no account exists or an older Meter serves this response. - $ref: '#/components/schemas/meter.v1.PrepaidCreditReconciliation' - runBalance: - title: run_balance - description: Absent for missing attribution or older servers, never an inferred zero. - $ref: '#/components/schemas/meter.v1.PrepaidRunBalance' - developmentProgramPolicy: - title: development_program_policy - description: Immutable owner enrollment limits; absent for legacy or unenrolled programs. - $ref: '#/components/schemas/meter.v1.DevelopmentCreditProgramPolicy' - developmentProgramId: - type: string - title: development_program_id - title: GetPrepaidCreditBalanceResponse - additionalProperties: false - meter.v1.GrantDevelopmentCreditsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - programId: - type: string - title: program_id - minLength: 1 - grantId: - type: string - title: grant_id - minLength: 1 - creditMicros: - exclusiveMinimum: 0 - type: - - integer - - string - title: credit_micros - format: int64 - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - reason: - type: string - title: reason - minLength: 1 - provenance: - type: string - title: provenance - minLength: 1 - enrollmentPolicy: - title: enrollment_policy - description: Optional first enrollment; immutable exact retries only. Omit on later grants. - $ref: '#/components/schemas/meter.v1.DevelopmentCreditProgramPolicy' - title: GrantDevelopmentCreditsRequest - required: - - expiresAt - additionalProperties: false - description: Grant identities and provenance are immutable across retries. Expiry requires microsecond precision. - meter.v1.GrantDevelopmentCreditsResponse: - type: object - properties: - grant: - title: grant - $ref: '#/components/schemas/meter.v1.DevelopmentCreditGrant' - title: GrantDevelopmentCreditsResponse - additionalProperties: false - meter.v1.ListManagedInferenceAdminEventsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - pageSize: - type: integer - title: page_size - maximum: 100 - format: int32 - pageToken: - type: string - title: page_token - title: ListManagedInferenceAdminEventsRequest - additionalProperties: false - meter.v1.ListManagedInferenceAdminEventsResponse: - type: object - properties: - events: - type: array - items: - $ref: '#/components/schemas/meter.v1.ManagedInferenceAdminEvent' - title: events - nextPageToken: - type: string - title: next_page_token - title: ListManagedInferenceAdminEventsResponse - additionalProperties: false - meter.v1.ManagedInferenceAdminEvent: - type: object - properties: - eventId: - type: string - title: event_id - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - actorSubject: - type: string - title: actor_subject - delegatedActorSubject: - type: string - title: delegated_actor_subject - action: - type: string - title: action - resourceId: - type: string - title: resource_id - reason: - type: string - title: reason - outcome: - type: string - title: outcome - beforeBudget: - title: before_budget - $ref: '#/components/schemas/meter.v1.ManagedInferenceBudgetSnapshot' - afterBudget: - title: after_budget - $ref: '#/components/schemas/meter.v1.ManagedInferenceBudgetSnapshot' - creditMicros: - type: - - integer - - string - title: credit_micros - format: int64 - programId: - type: string - title: program_id - provenance: - type: string - title: provenance - requestId: - type: string - title: request_id - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - title: ManagedInferenceAdminEvent - additionalProperties: false - meter.v1.ManagedInferenceBudgetSnapshot: - type: object - properties: - period: - type: string - title: period - limitUsd: - type: number - title: limit_usd - format: double - warningThresholdsPct: - type: array - items: - type: integer - format: int32 - title: warning_thresholds_pct - hardCap: - type: boolean - title: hard_cap - title: ManagedInferenceBudgetSnapshot - additionalProperties: false - meter.v1.PrepaidCreditBalance: - type: object - properties: - compensatedMicros: - type: - - integer - - string - title: compensated_micros - format: int64 - description: Cash recovery, separate from purchases and non-cash grants. - developmentCreditOnly: - type: boolean - title: development_credit_only - description: Enrolled development programs cannot consume paid credits or trigger paid refill. - grantedMicros: - type: - - integer - - string - title: granted_micros - format: int64 - description: Non-cash development funding, kept separate from purchased credits. - expiredGrantMicros: - type: - - integer - - string - title: expired_grant_micros - format: int64 - grantSpentMicros: - type: - - integer - - string - title: grant_spent_micros - format: int64 - grantReservedMicros: - type: - - integer - - string - title: grant_reserved_micros - format: int64 - admissionSuspended: - type: boolean - title: admission_suspended - reversedMicros: - type: - - integer - - string - title: reversed_micros - format: int64 - debtMicros: - type: - - integer - - string - title: debt_micros - format: int64 - purchasedMicros: - type: - - integer - - string - title: purchased_micros - format: int64 - spentMicros: - type: - - integer - - string - title: spent_micros - format: int64 - reservedMicros: - type: - - integer - - string - title: reserved_micros - format: int64 - availableMicros: - type: - - integer - - string - title: available_micros - format: int64 - title: PrepaidCreditBalance - additionalProperties: false - description: |- - Prepaid credits are USD amounts in integer millionths of a dollar. - Meter owns funding, reservations, settlement, and the available balance. - meter.v1.PrepaidCreditReconciliation: - type: object - properties: - compensatedDifferenceMicros: - type: - - integer - - string - title: compensated_difference_micros - format: int64 - grantedDifferenceMicros: - type: - - integer - - string - title: granted_difference_micros - format: int64 - invalidGrantAllocationCount: - type: - - integer - - string - title: invalid_grant_allocation_count - format: int64 - balanced: - type: boolean - title: balanced - description: A comparison of materialized counters with source rows in one snapshot. - purchasedDifferenceMicros: - type: - - integer - - string - title: purchased_difference_micros - format: int64 - reversedDifferenceMicros: - type: - - integer - - string - title: reversed_difference_micros - format: int64 - spentDifferenceMicros: - type: - - integer - - string - title: spent_difference_micros - format: int64 - reservedDifferenceMicros: - type: - - integer - - string - title: reserved_difference_micros - format: int64 - disputeCountDifference: - type: - - integer - - string - title: dispute_count_difference - format: int64 - pendingReservationCount: - type: - - integer - - string - title: pending_reservation_count - format: int64 - oldestPendingAt: - title: oldest_pending_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - unfundedPaymentCount: - type: - - integer - - string - title: unfunded_payment_count - format: int64 - title: PrepaidCreditReconciliation - additionalProperties: false - meter.v1.PrepaidRunBalance: - type: object - properties: - runId: - type: string - title: run_id - settledCostMicros: - type: - - integer - - string - title: settled_cost_micros - format: int64 - reservedMicros: - type: - - integer - - string - title: reserved_micros - format: int64 - pendingRequestCount: - type: - - integer - - string - title: pending_request_count - format: int64 - settledRequestCount: - type: - - integer - - string - title: settled_request_count - format: int64 - oldestPendingAt: - title: oldest_pending_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: PrepaidRunBalance - additionalProperties: false - meter.v1.QueryUsageRequest: - type: object - properties: - teamId: - type: string - title: team_id - agentId: - type: string - title: agent_id - eventType: - type: string - title: event_type - model: - type: string - title: model - provider: - type: string - title: provider - metadataKey: - type: string - title: metadata_key - metadataValue: - type: string - title: metadata_value - startTime: - title: start_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - endTime: - title: end_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - limit: - type: integer - title: limit - maximum: 200 - format: int32 - offset: - type: integer - title: offset - format: int32 - callerIdentity: - type: string - title: caller_identity - title: QueryUsageRequest - additionalProperties: false - meter.v1.QueryUsageResponse: - type: object - properties: - records: - type: array - items: - $ref: '#/components/schemas/meter.v1.UsageRecord' - title: records - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - title: QueryUsageResponse - additionalProperties: false - meter.v1.SetBudgetRequest: - type: object - properties: - auditContext: - title: audit_context - $ref: '#/components/schemas/meter.v1.AdminMutationAuditContext' - budgetId: - type: string - title: budget_id - teamId: - type: string - title: team_id - period: - type: string - title: period - description: |- - Changing the period of an existing budget restarts the spend window: the - service sets period_start to now, clears current_spend_usd, and derives a - new next_reset_at. Sending the same period leaves the window untouched. - limitUsd: - exclusiveMinimum: 0 - type: number - title: limit_usd - format: double - warningThresholdsPct: - type: array - items: - type: integer - format: int32 - title: warning_thresholds_pct - hardCap: - type: boolean - title: hard_cap - workspaceId: - type: string - title: workspace_id - description: |- - Empty creates or updates an organization-wide budget. A non-empty value - must equal the workspace the caller was authorized for. - idempotencyKey: - type: string - title: idempotency_key - maxLength: 256 - description: |- - Empty preserves legacy non-idempotent callers. New callers supply a stable - key for this exact organization and authenticated workspace. - title: SetBudgetRequest - additionalProperties: false - meter.v1.SetBudgetResponse: - type: object - properties: - budget: - title: budget - $ref: '#/components/schemas/meter.v1.Budget' - title: SetBudgetResponse - additionalProperties: false - meter.v1.UsageRecord: - type: object - properties: - id: - type: string - title: id - timestamp: - title: timestamp - $ref: '#/components/schemas/google.protobuf.Timestamp' - organizationId: - type: string - title: organization_id - teamId: - type: string - title: team_id - agentId: - type: string - title: agent_id - surface: - type: string - title: surface - eventType: - type: string - title: event_type - model: - type: string - title: model - provider: - type: string - title: provider - inputTokens: - type: - - integer - - string - title: input_tokens - format: int64 - outputTokens: - type: - - integer - - string - title: output_tokens - format: int64 - cacheReadTokens: - type: - - integer - - string - title: cache_read_tokens - format: int64 - cacheWriteTokens: - type: - - integer - - string - title: cache_write_tokens - format: int64 - totalCostUsd: - type: number - title: total_cost_usd - format: double - requestId: - type: string - title: request_id - data: - title: data - $ref: '#/components/schemas/google.protobuf.Struct' - metadata: - title: metadata - $ref: '#/components/schemas/google.protobuf.Struct' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - callerIdentity: - type: string - title: caller_identity - title: UsageRecord - additionalProperties: false - platform.v1.RecordRef: - type: object - properties: - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/platform.v1.RecordKind' - recordId: - type: string - title: record_id - minLength: 1 - revision: - type: string - title: revision - description: Owner-defined immutable revision or digest when the reference is pinned. - title: RecordRef - additionalProperties: false - description: |- - RecordRef is the canonical, content-free pointer used by customer read - models to join independently owned operational records. It is correlation, - never authority: consumers must resolve it through the owning service under - the authenticated tenant carried by the enclosing request. - remoterunner.v1.RunnerSessionOwnerBinding: - type: object - properties: - missionId: - type: string - title: mission_id - minLength: 1 - runtimeRunId: - type: string - title: runtime_run_id - minLength: 1 - authorityGrantId: - type: string - title: authority_grant_id - minLength: 1 - contractVersion: - type: string - title: contract_version - minLength: 1 - runnerProfile: - type: string - title: runner_profile - minLength: 1 - policyVersion: - type: string - title: policy_version - decisionRoute: - type: string - title: decision_route - selectedCandidateId: - type: string - title: selected_candidate_id - decisionRef: - type: string - title: decision_ref - decisionDigestSha256: - type: string - title: decision_digest_sha256 - title: RunnerSessionOwnerBinding - additionalProperties: false - toolexecution.v1.ToolExecutionProjectSource: - type: object - properties: - projectResourceId: - type: string - title: project_resource_id - acceptedRefName: - type: string - title: accepted_ref_name - acceptedRefVersion: - type: - - integer - - string - title: accepted_ref_version - format: int64 - acceptedSnapshotId: - type: string - title: accepted_snapshot_id - sourceWorkspaceId: - type: string - title: source_workspace_id - sourceWorkspaceVersion: - type: - - integer - - string - title: source_workspace_version - format: int64 - files: - type: array - items: - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionProjectSourceFile' - title: files - maxItems: 1000 - title: ToolExecutionProjectSource - additionalProperties: false - description: Server-owned, pinned accepted source. Never a writable shared directory. - toolexecution.v1.ToolExecutionProjectSourceFile: - type: object - properties: - path: - type: string - title: path - objectId: - type: string - title: object_id - versionId: - type: string - title: version_id - sha256: - type: string - title: sha256 - sizeBytes: - type: - - integer - - string - title: size_bytes - format: int64 - executable: - type: boolean - title: executable - title: ToolExecutionProjectSourceFile - additionalProperties: false - description: An immutable file restored below the private task workspace. - toolexecution.v1.ToolExecutionWorkspaceRecipe: - type: object - properties: - schemaVersion: - type: string - title: schema_version - const: deixic.workspace_recipe.v1 - recipeId: - type: string - title: recipe_id - minLength: 1 - recipeVersion: - type: - - integer - - string - title: recipe_version - minimum: 1 - format: int64 - recipeDigest: - type: string - title: recipe_digest - minLength: 1 - sourceManifestDigest: - type: string - title: source_manifest_digest - minLength: 1 - requiredRuntimes: - type: array - items: - type: string - maxLength: 64 - minLength: 1 - maxItems: 16 - title: required_runtimes - maxItems: 16 - preparationTool: - type: string - title: preparation_tool - const: computer.check_runtimes - executionOwner: - type: string - title: execution_owner - const: platform-api.dex - title: ToolExecutionWorkspaceRecipe - additionalProperties: false - description: |- - Versioned, server-owned preparation recipe for one task workspace. The - recipe carries bounded declarative requirements; it cannot contain shell - commands, repository hooks, credentials, or approval policy. - traces.v1.TraceAnnotation: - type: object - properties: - annotationId: - type: string - title: annotation_id - traceId: - type: string - title: trace_id - minLength: 1 - spanId: - type: string - title: span_id - kind: - title: kind - $ref: '#/components/schemas/traces.v1.TraceAnnotationKind' - note: - type: string - title: note - labels: - type: array - items: - type: string - title: labels - source: - type: string - title: source - metadata: - title: metadata - $ref: '#/components/schemas/google.protobuf.Struct' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - status: - title: status - $ref: '#/components/schemas/traces.v1.TraceAnnotationStatus' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - resolvedAt: - title: resolved_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - resolvedBy: - type: string - title: resolved_by - title: TraceAnnotation - additionalProperties: false - vfs.v1.VfsCompletedUploadPart: - type: object - properties: - partNumber: - exclusiveMinimum: 0 - type: integer - title: part_number - format: int32 - etag: - type: string - title: etag - minLength: 1 - title: VfsCompletedUploadPart - additionalProperties: false - vfs.v1.VfsUploadPartTarget: - type: object - properties: - partNumber: - exclusiveMinimum: 0 - type: integer - title: part_number - format: int32 - offset: - type: - - integer - - string - title: offset - format: int64 - sizeBytes: - exclusiveMinimum: 0 - type: - - integer - - string - title: size_bytes - format: int64 - url: - type: string - title: url - minLength: 1 - method: - type: string - title: method - minLength: 1 - headers: - type: object - title: headers - additionalProperties: - type: string - title: value - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: VfsUploadPartTarget - additionalProperties: false - vfs.v1.VfsUploadPartTarget.HeadersEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: HeadersEntry - additionalProperties: false - vfs.v1.VfsUploadTarget: - type: object - properties: - url: - type: string - title: url - method: - type: string - title: method - minLength: 1 - headers: - type: object - title: headers - additionalProperties: - type: string - title: value - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - maxSizeBytes: - exclusiveMinimum: 0 - type: - - integer - - string - title: max_size_bytes - maximum: 52428800 - format: int64 - parts: - type: array - items: - $ref: '#/components/schemas/vfs.v1.VfsUploadPartTarget' - title: parts - title: VfsUploadTarget - additionalProperties: false - vfs.v1.VfsUploadTarget.HeadersEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: HeadersEntry - additionalProperties: false - connect-protocol-version: - type: number - title: Connect-Protocol-Version - enum: - - 1 - description: Define the version of the Connect protocol - const: 1 - connect-timeout-header: - type: number - title: Connect-Timeout-Ms - description: Define the timeout, in ms - connect.error: - type: object - properties: - code: - type: string - examples: - - not_found - enum: - - canceled - - unknown - - invalid_argument - - deadline_exceeded - - not_found - - already_exists - - permission_denied - - resource_exhausted - - failed_precondition - - aborted - - out_of_range - - unimplemented - - internal - - unavailable - - data_loss - - unauthenticated - description: The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code]. - message: - type: string - description: A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client. - detail: - $ref: '#/components/schemas/google.protobuf.Any' - title: Connect Error - additionalProperties: true - description: 'Error type returned by Connect: https://connectrpc.com/docs/go/errors/#http-representation' - google.protobuf.Any: - type: object - properties: - type: - type: string - value: - type: string - format: binary - debug: - type: object - additionalProperties: true - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. -security: [] -tags: - - name: deixic.v1.DeixicService - description: |- - DeixicService is the producer-owned browser contract served by Platform API. - Canonical message schemas remain in console.v1 for wire compatibility. diff --git a/openapi/deixicpublic/v1/sdk.openapi.yaml b/openapi/deixicpublic/v1/sdk.openapi.yaml new file mode 100644 index 0000000..8796aaf --- /dev/null +++ b/openapi/deixicpublic/v1/sdk.openapi.yaml @@ -0,0 +1,2268 @@ +openapi: 3.1.0 +info: + title: deixicpublic.v1 +paths: + /deixicpublic.v1.DeixicPublicService/GetThread: + post: + tags: + - deixicpublic.v1.DeixicPublicService + summary: GetThread + operationId: deixicpublic.v1.DeixicPublicService.GetThread + parameters: + - name: Connect-Protocol-Version + in: header + required: true + schema: + $ref: '#/components/schemas/connect-protocol-version' + - name: Connect-Timeout-Ms + in: header + schema: + $ref: '#/components/schemas/connect-timeout-header' + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.GetThreadRequest' + required: true + responses: + default: + description: Error + content: + application/json: + schema: + $ref: '#/components/schemas/connect.error' + "200": + description: Success + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.GetThreadResponse' + /deixicpublic.v1.DeixicPublicService/ListThreads: + post: + tags: + - deixicpublic.v1.DeixicPublicService + summary: ListThreads + operationId: deixicpublic.v1.DeixicPublicService.ListThreads + parameters: + - name: Connect-Protocol-Version + in: header + required: true + schema: + $ref: '#/components/schemas/connect-protocol-version' + - name: Connect-Timeout-Ms + in: header + schema: + $ref: '#/components/schemas/connect-timeout-header' + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.ListThreadsRequest' + required: true + responses: + default: + description: Error + content: + application/json: + schema: + $ref: '#/components/schemas/connect.error' + "200": + description: Success + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.ListThreadsResponse' + /deixicpublic.v1.DeixicPublicService/RenameThread: + post: + tags: + - deixicpublic.v1.DeixicPublicService + summary: RenameThread + operationId: deixicpublic.v1.DeixicPublicService.RenameThread + parameters: + - name: Connect-Protocol-Version + in: header + required: true + schema: + $ref: '#/components/schemas/connect-protocol-version' + - name: Connect-Timeout-Ms + in: header + schema: + $ref: '#/components/schemas/connect-timeout-header' + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.RenameThreadRequest' + required: true + responses: + default: + description: Error + content: + application/json: + schema: + $ref: '#/components/schemas/connect.error' + "200": + description: Success + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.RenameThreadResponse' + /deixicpublic.v1.DeixicPublicService/ArchiveThread: + post: + tags: + - deixicpublic.v1.DeixicPublicService + summary: ArchiveThread + operationId: deixicpublic.v1.DeixicPublicService.ArchiveThread + parameters: + - name: Connect-Protocol-Version + in: header + required: true + schema: + $ref: '#/components/schemas/connect-protocol-version' + - name: Connect-Timeout-Ms + in: header + schema: + $ref: '#/components/schemas/connect-timeout-header' + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.ArchiveThreadRequest' + required: true + responses: + default: + description: Error + content: + application/json: + schema: + $ref: '#/components/schemas/connect.error' + "200": + description: Success + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.ArchiveThreadResponse' + /deixicpublic.v1.DeixicPublicService/ListEvents: + post: + tags: + - deixicpublic.v1.DeixicPublicService + summary: ListEvents + operationId: deixicpublic.v1.DeixicPublicService.ListEvents + parameters: + - name: Connect-Protocol-Version + in: header + required: true + schema: + $ref: '#/components/schemas/connect-protocol-version' + - name: Connect-Timeout-Ms + in: header + schema: + $ref: '#/components/schemas/connect-timeout-header' + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.ListEventsRequest' + required: true + responses: + default: + description: Error + content: + application/json: + schema: + $ref: '#/components/schemas/connect.error' + "200": + description: Success + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.ListEventsResponse' + /deixicpublic.v1.DeixicPublicService/WatchEvents: {} + /deixicpublic.v1.DeixicPublicService/SubmitTask: + post: + tags: + - deixicpublic.v1.DeixicPublicService + summary: SubmitTask + operationId: deixicpublic.v1.DeixicPublicService.SubmitTask + parameters: + - name: Connect-Protocol-Version + in: header + required: true + schema: + $ref: '#/components/schemas/connect-protocol-version' + - name: Connect-Timeout-Ms + in: header + schema: + $ref: '#/components/schemas/connect-timeout-header' + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.SubmitTaskRequest' + required: true + responses: + default: + description: Error + content: + application/json: + schema: + $ref: '#/components/schemas/connect.error' + "200": + description: Success + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.SubmitTaskResponse' + /deixicpublic.v1.DeixicPublicService/InterruptTask: + post: + tags: + - deixicpublic.v1.DeixicPublicService + summary: InterruptTask + operationId: deixicpublic.v1.DeixicPublicService.InterruptTask + parameters: + - name: Connect-Protocol-Version + in: header + required: true + schema: + $ref: '#/components/schemas/connect-protocol-version' + - name: Connect-Timeout-Ms + in: header + schema: + $ref: '#/components/schemas/connect-timeout-header' + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.InterruptTaskRequest' + required: true + responses: + default: + description: Error + content: + application/json: + schema: + $ref: '#/components/schemas/connect.error' + "200": + description: Success + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.InterruptTaskResponse' + /deixicpublic.v1.DeixicPublicService/RespondToRequest: + post: + tags: + - deixicpublic.v1.DeixicPublicService + summary: RespondToRequest + operationId: deixicpublic.v1.DeixicPublicService.RespondToRequest + parameters: + - name: Connect-Protocol-Version + in: header + required: true + schema: + $ref: '#/components/schemas/connect-protocol-version' + - name: Connect-Timeout-Ms + in: header + schema: + $ref: '#/components/schemas/connect-timeout-header' + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.RespondToRequestRequest' + required: true + responses: + default: + description: Error + content: + application/json: + schema: + $ref: '#/components/schemas/connect.error' + "200": + description: Success + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.RespondToRequestResponse' + /deixicpublic.v1.DeixicPublicService/GetReceipt: + post: + tags: + - deixicpublic.v1.DeixicPublicService + summary: GetReceipt + operationId: deixicpublic.v1.DeixicPublicService.GetReceipt + parameters: + - name: Connect-Protocol-Version + in: header + required: true + schema: + $ref: '#/components/schemas/connect-protocol-version' + - name: Connect-Timeout-Ms + in: header + schema: + $ref: '#/components/schemas/connect-timeout-header' + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.GetReceiptRequest' + required: true + responses: + default: + description: Error + content: + application/json: + schema: + $ref: '#/components/schemas/connect.error' + "200": + description: Success + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.GetReceiptResponse' + /deixicpublic.v1.DeixicPublicService/ResolveReceiptAction: + post: + tags: + - deixicpublic.v1.DeixicPublicService + summary: ResolveReceiptAction + operationId: deixicpublic.v1.DeixicPublicService.ResolveReceiptAction + parameters: + - name: Connect-Protocol-Version + in: header + required: true + schema: + $ref: '#/components/schemas/connect-protocol-version' + - name: Connect-Timeout-Ms + in: header + schema: + $ref: '#/components/schemas/connect-timeout-header' + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.ResolveReceiptActionRequest' + required: true + responses: + default: + description: Error + content: + application/json: + schema: + $ref: '#/components/schemas/connect.error' + "200": + description: Success + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.ResolveReceiptActionResponse' + /deixicpublic.v1.DeixicPublicService/GetModelReadiness: + post: + tags: + - deixicpublic.v1.DeixicPublicService + summary: GetModelReadiness + operationId: deixicpublic.v1.DeixicPublicService.GetModelReadiness + parameters: + - name: Connect-Protocol-Version + in: header + required: true + schema: + $ref: '#/components/schemas/connect-protocol-version' + - name: Connect-Timeout-Ms + in: header + schema: + $ref: '#/components/schemas/connect-timeout-header' + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.GetModelReadinessRequest' + required: true + responses: + default: + description: Error + content: + application/json: + schema: + $ref: '#/components/schemas/connect.error' + "200": + description: Success + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.GetModelReadinessResponse' + /deixicpublic.v1.DeixicPublicService/GetClientSetup: + post: + tags: + - deixicpublic.v1.DeixicPublicService + summary: GetClientSetup + operationId: deixicpublic.v1.DeixicPublicService.GetClientSetup + parameters: + - name: Connect-Protocol-Version + in: header + required: true + schema: + $ref: '#/components/schemas/connect-protocol-version' + - name: Connect-Timeout-Ms + in: header + schema: + $ref: '#/components/schemas/connect-timeout-header' + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.GetClientSetupRequest' + required: true + responses: + default: + description: Error + content: + application/json: + schema: + $ref: '#/components/schemas/connect.error' + "200": + description: Success + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.GetClientSetupResponse' + /deixicpublic.v1.DeixicPublicService/SubmitIssueReport: + post: + tags: + - deixicpublic.v1.DeixicPublicService + summary: SubmitIssueReport + operationId: deixicpublic.v1.DeixicPublicService.SubmitIssueReport + parameters: + - name: Connect-Protocol-Version + in: header + required: true + schema: + $ref: '#/components/schemas/connect-protocol-version' + - name: Connect-Timeout-Ms + in: header + schema: + $ref: '#/components/schemas/connect-timeout-header' + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.SubmitIssueReportRequest' + required: true + responses: + default: + description: Error + content: + application/json: + schema: + $ref: '#/components/schemas/connect.error' + "200": + description: Success + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.SubmitIssueReportResponse' + /deixicpublic.v1.DeixicPublicService/CreateBusinessObject: + post: + tags: + - deixicpublic.v1.DeixicPublicService + summary: CreateBusinessObject + operationId: deixicpublic.v1.DeixicPublicService.CreateBusinessObject + parameters: + - name: Connect-Protocol-Version + in: header + required: true + schema: + $ref: '#/components/schemas/connect-protocol-version' + - name: Connect-Timeout-Ms + in: header + schema: + $ref: '#/components/schemas/connect-timeout-header' + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.CreateBusinessObjectRequest' + required: true + responses: + default: + description: Error + content: + application/json: + schema: + $ref: '#/components/schemas/connect.error' + "200": + description: Success + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.CreateBusinessObjectResponse' + /deixicpublic.v1.DeixicPublicService/GetBusinessObject: + post: + tags: + - deixicpublic.v1.DeixicPublicService + summary: GetBusinessObject + operationId: deixicpublic.v1.DeixicPublicService.GetBusinessObject + parameters: + - name: Connect-Protocol-Version + in: header + required: true + schema: + $ref: '#/components/schemas/connect-protocol-version' + - name: Connect-Timeout-Ms + in: header + schema: + $ref: '#/components/schemas/connect-timeout-header' + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.GetBusinessObjectRequest' + required: true + responses: + default: + description: Error + content: + application/json: + schema: + $ref: '#/components/schemas/connect.error' + "200": + description: Success + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.GetBusinessObjectResponse' + /deixicpublic.v1.DeixicPublicService/UpdateBusinessObject: + post: + tags: + - deixicpublic.v1.DeixicPublicService + summary: UpdateBusinessObject + operationId: deixicpublic.v1.DeixicPublicService.UpdateBusinessObject + parameters: + - name: Connect-Protocol-Version + in: header + required: true + schema: + $ref: '#/components/schemas/connect-protocol-version' + - name: Connect-Timeout-Ms + in: header + schema: + $ref: '#/components/schemas/connect-timeout-header' + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.UpdateBusinessObjectRequest' + required: true + responses: + default: + description: Error + content: + application/json: + schema: + $ref: '#/components/schemas/connect.error' + "200": + description: Success + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.UpdateBusinessObjectResponse' + /deixicpublic.v1.DeixicPublicService/DeleteBusinessObject: + post: + tags: + - deixicpublic.v1.DeixicPublicService + summary: DeleteBusinessObject + operationId: deixicpublic.v1.DeixicPublicService.DeleteBusinessObject + parameters: + - name: Connect-Protocol-Version + in: header + required: true + schema: + $ref: '#/components/schemas/connect-protocol-version' + - name: Connect-Timeout-Ms + in: header + schema: + $ref: '#/components/schemas/connect-timeout-header' + requestBody: + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.DeleteBusinessObjectRequest' + required: true + responses: + default: + description: Error + content: + application/json: + schema: + $ref: '#/components/schemas/connect.error' + "200": + description: Success + content: + application/json: + schema: + $ref: '#/components/schemas/deixicpublic.v1.DeleteBusinessObjectResponse' +components: + schemas: + deixicpublic.v1.ClientMcpMode: + type: string + title: ClientMcpMode + enum: + - CLIENT_MCP_MODE_UNSPECIFIED + - CLIENT_MCP_MODE_OPEN + - CLIENT_MCP_MODE_ALLOWLIST + - CLIENT_MCP_MODE_DENYLIST + deixicpublic.v1.ClientRuleScope: + type: string + title: ClientRuleScope + enum: + - CLIENT_RULE_SCOPE_UNSPECIFIED + - CLIENT_RULE_SCOPE_ORGANIZATION + - CLIENT_RULE_SCOPE_WORKSPACE + deixicpublic.v1.EventKind: + type: string + title: EventKind + enum: + - EVENT_KIND_UNSPECIFIED + - EVENT_KIND_TURN_ACCEPTED + - EVENT_KIND_TURN_STARTED + - EVENT_KIND_PROGRESS + - EVENT_KIND_APPROVAL_REQUIRED + - EVENT_KIND_INPUT_REQUIRED + - EVENT_KIND_ARTIFACT_RECORDED + - EVENT_KIND_TURN_COMPLETED + - EVENT_KIND_TURN_FAILED + - EVENT_KIND_TURN_INTERRUPTED + - EVENT_KIND_CLIENT_TOOL_REQUIRED + - EVENT_KIND_EXTERNAL_RETRY_REQUIRED + deixicpublic.v1.MessageRole: + type: string + title: MessageRole + enum: + - MESSAGE_ROLE_UNSPECIFIED + - MESSAGE_ROLE_USER + - MESSAGE_ROLE_ASSISTANT + - MESSAGE_ROLE_SYSTEM + deixicpublic.v1.ModelNextAction: + type: string + title: ModelNextAction + enum: + - MODEL_NEXT_ACTION_UNSPECIFIED + - MODEL_NEXT_ACTION_CONTACT_ADMINISTRATOR + - MODEL_NEXT_ACTION_VIEW_FUNDING + - MODEL_NEXT_ACTION_RETRY + deixicpublic.v1.ModelReadinessState: + type: string + title: ModelReadinessState + enum: + - MODEL_READINESS_STATE_UNSPECIFIED + - MODEL_READINESS_STATE_READY + - MODEL_READINESS_STATE_ACTIVATION_REQUIRED + - MODEL_READINESS_STATE_FUNDING_REQUIRED + - MODEL_READINESS_STATE_LIMIT_REACHED + - MODEL_READINESS_STATE_ACCESS_SUSPENDED + - MODEL_READINESS_STATE_TEMPORARILY_UNAVAILABLE + description: |- + Model readiness is an application-level decision; billing and routing + implementation details stay behind this projection. + deixicpublic.v1.ReceiptState: + type: string + title: ReceiptState + enum: + - RECEIPT_STATE_UNSPECIFIED + - RECEIPT_STATE_UNKNOWN + - RECEIPT_STATE_PROPOSED + - RECEIPT_STATE_QUEUED + - RECEIPT_STATE_WAITING_APPROVAL + - RECEIPT_STATE_BLOCKED + - RECEIPT_STATE_NEEDS_INPUT + - RECEIPT_STATE_UNAVAILABLE + - RECEIPT_STATE_RUNNING + - RECEIPT_STATE_SUCCEEDED + - RECEIPT_STATE_VERIFIED + - RECEIPT_STATE_DENIED + - RECEIPT_STATE_CANCELLED + - RECEIPT_STATE_FAILED + deixicpublic.v1.RequestKind: + type: string + title: RequestKind + enum: + - REQUEST_KIND_UNSPECIFIED + - REQUEST_KIND_APPROVAL + - REQUEST_KIND_USER_INPUT + - REQUEST_KIND_CLIENT_TOOL + - REQUEST_KIND_EXTERNAL_RETRY + deixicpublic.v1.ResponseAction: + type: string + title: ResponseAction + enum: + - RESPONSE_ACTION_UNSPECIFIED + - RESPONSE_ACTION_APPROVE + - RESPONSE_ACTION_DENY + - RESPONSE_ACTION_ANSWER + - RESPONSE_ACTION_RETRY + - RESPONSE_ACTION_SKIP + - RESPONSE_ACTION_ABORT + deixicpublic.v1.TurnState: + type: string + title: TurnState + enum: + - TURN_STATE_UNSPECIFIED + - TURN_STATE_ACCEPTED + - TURN_STATE_RUNNING + - TURN_STATE_WAITING + - TURN_STATE_RESPONDED + - TURN_STATE_COMPLETED + - TURN_STATE_FAILED + - TURN_STATE_INTERRUPTED + deixicpublic.v1.WaitingReason: + type: string + title: WaitingReason + enum: + - WAITING_REASON_UNSPECIFIED + - WAITING_REASON_APPROVAL + - WAITING_REASON_USER_INPUT + - WAITING_REASON_CLIENT_TOOL + - WAITING_REASON_EXTERNAL_RETRY + deixicpublic.v1.ArchiveThreadRequest: + type: object + properties: + scope: + title: scope + $ref: '#/components/schemas/deixicpublic.v1.Scope' + threadId: + type: string + title: thread_id + archived: + type: boolean + title: archived + idempotencyKey: + type: string + title: idempotency_key + title: ArchiveThreadRequest + additionalProperties: false + deixicpublic.v1.ArchiveThreadResponse: + type: object + properties: + thread: + title: thread + $ref: '#/components/schemas/deixicpublic.v1.Thread' + changed: + type: boolean + title: changed + replayed: + type: boolean + title: replayed + title: ArchiveThreadResponse + additionalProperties: false + deixicpublic.v1.AvailableModel: + type: object + properties: + provider: + type: string + title: provider + model: + type: string + title: model + ready: + type: boolean + title: ready + displayName: + type: string + title: display_name + title: AvailableModel + additionalProperties: false + deixicpublic.v1.BusinessArtifactReference: + type: object + properties: + artifactVersionId: + type: string + title: artifact_version_id + title: BusinessArtifactReference + additionalProperties: false + deixicpublic.v1.BusinessFieldValue: + type: object + oneOf: + - properties: + artifact: + title: artifact + $ref: '#/components/schemas/deixicpublic.v1.BusinessArtifactReference' + title: artifact + required: + - artifact + - properties: + boolean: + type: boolean + title: boolean + title: boolean + required: + - boolean + - properties: + date: + type: string + title: date + title: date + required: + - date + - properties: + decimal: + type: string + title: decimal + title: decimal + required: + - decimal + - properties: + enumValue: + type: string + title: enum_value + title: enum_value + required: + - enumValue + - properties: + integer: + type: + - integer + - string + title: integer + format: int64 + title: integer + required: + - integer + - properties: + money: + title: money + $ref: '#/components/schemas/deixicpublic.v1.BusinessMoney' + title: money + required: + - money + - properties: + reference: + title: reference + $ref: '#/components/schemas/deixicpublic.v1.BusinessObjectReference' + title: reference + required: + - reference + - properties: + text: + type: string + title: text + title: text + required: + - text + - properties: + textList: + title: text_list + $ref: '#/components/schemas/deixicpublic.v1.BusinessTextList' + title: text_list + required: + - textList + - properties: + timestamp: + type: string + title: timestamp + title: timestamp + required: + - timestamp + properties: + artifact: + title: artifact + $ref: '#/components/schemas/deixicpublic.v1.BusinessArtifactReference' + boolean: + type: boolean + title: boolean + date: + type: string + title: date + decimal: + type: string + title: decimal + enumValue: + type: string + title: enum_value + integer: + type: + - integer + - string + title: integer + format: int64 + money: + title: money + $ref: '#/components/schemas/deixicpublic.v1.BusinessMoney' + reference: + title: reference + $ref: '#/components/schemas/deixicpublic.v1.BusinessObjectReference' + text: + type: string + title: text + textList: + title: text_list + $ref: '#/components/schemas/deixicpublic.v1.BusinessTextList' + timestamp: + type: string + title: timestamp + fieldId: + type: string + title: field_id + title: BusinessFieldValue + additionalProperties: false + deixicpublic.v1.BusinessMoney: + type: object + properties: + amount: + type: string + title: amount + currency: + type: string + title: currency + title: BusinessMoney + additionalProperties: false + description: |- + This resource is the supported Terraform provider contract. Source authority, + connector state and recovery coordinates belong to the implementation. + deixicpublic.v1.BusinessObject: + type: object + properties: + objectId: + type: string + title: object_id + typeId: + type: string + title: type_id + schemaRevision: + type: + - integer + - string + title: schema_revision + format: int64 + revision: + type: + - integer + - string + title: revision + format: int64 + values: + type: array + items: + $ref: '#/components/schemas/deixicpublic.v1.BusinessFieldValue' + title: values + deleted: + type: boolean + title: deleted + updatedAt: + type: string + title: updated_at + createdAt: + type: string + title: created_at + title: BusinessObject + additionalProperties: false + deixicpublic.v1.BusinessObjectReference: + type: object + properties: + objectId: + type: string + title: object_id + title: BusinessObjectReference + additionalProperties: false + deixicpublic.v1.BusinessTextList: + type: object + properties: + values: + type: array + items: + type: string + title: values + title: BusinessTextList + additionalProperties: false + deixicpublic.v1.ClientMcpPolicy: + type: object + properties: + mode: + title: mode + $ref: '#/components/schemas/deixicpublic.v1.ClientMcpMode' + servers: + type: array + items: + $ref: '#/components/schemas/deixicpublic.v1.ClientMcpServer' + title: servers + title: ClientMcpPolicy + additionalProperties: false + deixicpublic.v1.ClientMcpServer: + type: object + properties: + name: + type: string + title: name + urlPattern: + type: string + title: url_pattern + transport: + type: string + title: transport + title: ClientMcpServer + additionalProperties: false + deixicpublic.v1.ClientRule: + type: object + properties: + id: + type: string + title: id + title: + type: string + title: title + bodyMarkdown: + type: string + title: body_markdown + scope: + title: scope + $ref: '#/components/schemas/deixicpublic.v1.ClientRuleScope' + title: ClientRule + additionalProperties: false + deixicpublic.v1.ClientSkill: + type: object + properties: + id: + type: string + title: id + source: + type: string + title: source + version: + type: string + title: version + required: + type: boolean + title: required + title: ClientSkill + additionalProperties: false + deixicpublic.v1.CodingAcceptance: + type: object + properties: + accepted: + type: boolean + title: accepted + contractDigest: + type: string + title: contract_digest + submissionDigest: + type: string + title: submission_digest + reasons: + type: array + items: + type: string + title: reasons + revision: + type: string + title: revision + outputs: + type: array + items: + $ref: '#/components/schemas/deixicpublic.v1.CodingOutput' + title: outputs + title: CodingAcceptance + additionalProperties: false + deixicpublic.v1.CodingContract: + type: object + properties: + repositoryId: + type: string + title: repository_id + generation: + type: + - integer + - string + title: generation + format: int64 + requiredAssertionIds: + type: array + items: + type: string + title: required_assertion_ids + requireReview: + type: boolean + title: require_review + requireBehavior: + type: boolean + title: require_behavior + readinessRequirements: + type: array + items: + type: string + title: readiness_requirements + authorizedSkips: + type: array + items: + type: string + title: authorized_skips + authorizedDispositions: + type: array + items: + type: string + title: authorized_dispositions + outputPaths: + type: array + items: + type: string + title: output_paths + title: CodingContract + additionalProperties: false + deixicpublic.v1.CodingOutput: + type: object + properties: + path: + type: string + title: path + objectId: + type: string + title: object_id + versionId: + type: string + title: version_id + sha256: + type: string + title: sha256 + sizeBytes: + type: + - integer + - string + title: size_bytes + format: int64 + content: + type: string + title: content + format: byte + description: Included only in an explicitly requested receipt read by the authorized actor. + title: CodingOutput + additionalProperties: false + deixicpublic.v1.CreateBusinessObjectRequest: + type: object + properties: + organizationId: + type: string + title: organization_id + workspaceId: + type: string + title: workspace_id + idempotencyKey: + type: string + title: idempotency_key + typeId: + type: string + title: type_id + schemaRevision: + type: + - integer + - string + title: schema_revision + format: int64 + values: + type: array + items: + $ref: '#/components/schemas/deixicpublic.v1.BusinessFieldValue' + title: values + title: CreateBusinessObjectRequest + additionalProperties: false + deixicpublic.v1.CreateBusinessObjectResponse: + type: object + properties: + object: + title: object + $ref: '#/components/schemas/deixicpublic.v1.BusinessObject' + title: CreateBusinessObjectResponse + additionalProperties: false + deixicpublic.v1.DeleteBusinessObjectRequest: + type: object + properties: + organizationId: + type: string + title: organization_id + workspaceId: + type: string + title: workspace_id + idempotencyKey: + type: string + title: idempotency_key + objectId: + type: string + title: object_id + expectedRevision: + type: + - integer + - string + title: expected_revision + format: int64 + title: DeleteBusinessObjectRequest + additionalProperties: false + deixicpublic.v1.DeleteBusinessObjectResponse: + type: object + properties: + object: + title: object + $ref: '#/components/schemas/deixicpublic.v1.BusinessObject' + title: DeleteBusinessObjectResponse + additionalProperties: false + deixicpublic.v1.ErrorDetail: + type: object + properties: + code: + type: string + title: code + message: + type: string + title: message + requestId: + type: string + title: request_id + retryable: + type: boolean + title: retryable + title: ErrorDetail + additionalProperties: false + deixicpublic.v1.EvidenceReference: + type: object + properties: + kind: + type: string + title: kind + id: + type: string + title: id + label: + type: string + title: label + uri: + type: string + title: uri + title: EvidenceReference + additionalProperties: false + deixicpublic.v1.GetBusinessObjectRequest: + type: object + properties: + organizationId: + type: string + title: organization_id + workspaceId: + type: string + title: workspace_id + objectId: + type: string + title: object_id + title: GetBusinessObjectRequest + additionalProperties: false + deixicpublic.v1.GetBusinessObjectResponse: + type: object + properties: + object: + title: object + $ref: '#/components/schemas/deixicpublic.v1.BusinessObject' + title: GetBusinessObjectResponse + additionalProperties: false + deixicpublic.v1.GetClientSetupRequest: + type: object + properties: + scope: + title: scope + $ref: '#/components/schemas/deixicpublic.v1.Scope' + title: GetClientSetupRequest + additionalProperties: false + deixicpublic.v1.GetClientSetupResponse: + type: object + properties: + scope: + title: scope + $ref: '#/components/schemas/deixicpublic.v1.Scope' + version: + type: + - integer + - string + title: version + format: int64 + issuedAt: + title: issued_at + $ref: '#/components/schemas/google.protobuf.Timestamp' + rules: + type: array + items: + $ref: '#/components/schemas/deixicpublic.v1.ClientRule' + title: rules + skills: + type: array + items: + $ref: '#/components/schemas/deixicpublic.v1.ClientSkill' + title: skills + mcp: + title: mcp + $ref: '#/components/schemas/deixicpublic.v1.ClientMcpPolicy' + sandboxPolicyToml: + type: string + title: sandbox_policy_toml + title: GetClientSetupResponse + additionalProperties: false + deixicpublic.v1.GetModelReadinessRequest: + type: object + properties: + scope: + title: scope + $ref: '#/components/schemas/deixicpublic.v1.Scope' + selection: + title: selection + $ref: '#/components/schemas/deixicpublic.v1.ModelSelection' + environment: + type: string + title: environment + title: GetModelReadinessRequest + additionalProperties: false + deixicpublic.v1.GetModelReadinessResponse: + type: object + properties: + scope: + title: scope + $ref: '#/components/schemas/deixicpublic.v1.Scope' + selection: + title: selection + $ref: '#/components/schemas/deixicpublic.v1.ModelSelection' + environment: + type: string + title: environment + state: + title: state + $ref: '#/components/schemas/deixicpublic.v1.ModelReadinessState' + nextActions: + type: array + items: + $ref: '#/components/schemas/deixicpublic.v1.ModelNextAction' + title: next_actions + evaluatedAt: + title: evaluated_at + $ref: '#/components/schemas/google.protobuf.Timestamp' + title: GetModelReadinessResponse + additionalProperties: false + deixicpublic.v1.GetReceiptRequest: + type: object + properties: + scope: + title: scope + $ref: '#/components/schemas/deixicpublic.v1.Scope' + receiptId: + type: string + title: receipt_id + threadId: + type: string + title: thread_id + includeCodingOutputContent: + type: boolean + title: include_coding_output_content + title: GetReceiptRequest + additionalProperties: false + deixicpublic.v1.GetReceiptResponse: + type: object + properties: + receipt: + title: receipt + $ref: '#/components/schemas/deixicpublic.v1.Receipt' + title: GetReceiptResponse + additionalProperties: false + deixicpublic.v1.GetThreadRequest: + type: object + properties: + scope: + title: scope + $ref: '#/components/schemas/deixicpublic.v1.Scope' + threadId: + type: string + title: thread_id + limit: + type: integer + title: limit + format: int32 + pageToken: + type: string + title: page_token + title: GetThreadRequest + additionalProperties: false + deixicpublic.v1.GetThreadResponse: + type: object + properties: + thread: + title: thread + $ref: '#/components/schemas/deixicpublic.v1.Thread' + messages: + type: array + items: + $ref: '#/components/schemas/deixicpublic.v1.TaskMessage' + title: messages + receipts: + type: array + items: + $ref: '#/components/schemas/deixicpublic.v1.Receipt' + title: receipts + turns: + type: array + items: + $ref: '#/components/schemas/deixicpublic.v1.TaskTurn' + title: turns + replayCursor: + type: + - integer + - string + title: replay_cursor + format: int64 + nextPageToken: + type: string + title: next_page_token + setup: + title: setup + $ref: '#/components/schemas/deixicpublic.v1.SetupReadiness' + title: GetThreadResponse + additionalProperties: false + deixicpublic.v1.InterruptTaskRequest: + type: object + properties: + scope: + title: scope + $ref: '#/components/schemas/deixicpublic.v1.Scope' + threadId: + type: string + title: thread_id + turnId: + type: string + title: turn_id + idempotencyKey: + type: string + title: idempotency_key + reason: + type: string + title: reason + title: InterruptTaskRequest + additionalProperties: false + deixicpublic.v1.InterruptTaskResponse: + type: object + properties: + turnId: + type: string + title: turn_id + replayed: + type: boolean + title: replayed + turns: + type: array + items: + $ref: '#/components/schemas/deixicpublic.v1.TaskTurn' + title: turns + replayCursor: + type: + - integer + - string + title: replay_cursor + format: int64 + title: InterruptTaskResponse + additionalProperties: false + deixicpublic.v1.IssueContext: + type: object + properties: + reproductionSteps: + type: string + title: reproduction_steps + model: + type: string + title: model + evidence: + type: array + items: + $ref: '#/components/schemas/deixicpublic.v1.IssueEvidence' + title: evidence + title: IssueContext + additionalProperties: false + deixicpublic.v1.IssueEvidence: + type: object + properties: + kind: + type: string + title: kind + sourceId: + type: string + title: source_id + text: + type: string + title: text + title: IssueEvidence + additionalProperties: false + deixicpublic.v1.IssueReport: + type: object + properties: + id: + type: string + title: id + reference: + type: string + title: reference + title: IssueReport + additionalProperties: false + deixicpublic.v1.ListEventsRequest: + type: object + properties: + scope: + title: scope + $ref: '#/components/schemas/deixicpublic.v1.Scope' + threadId: + type: string + title: thread_id + afterCursor: + type: + - integer + - string + title: after_cursor + format: int64 + limit: + type: integer + title: limit + format: int32 + title: ListEventsRequest + additionalProperties: false + deixicpublic.v1.ListEventsResponse: + type: object + properties: + events: + type: array + items: + $ref: '#/components/schemas/deixicpublic.v1.TaskEvent' + title: events + nextCursor: + type: + - integer + - string + title: next_cursor + format: int64 + hasMore: + type: boolean + title: has_more + resetRequired: + type: boolean + title: reset_required + snapshot: + title: snapshot + $ref: '#/components/schemas/deixicpublic.v1.Thread' + snapshotTurns: + type: array + items: + $ref: '#/components/schemas/deixicpublic.v1.TaskTurn' + title: snapshot_turns + title: ListEventsResponse + additionalProperties: false + deixicpublic.v1.ListThreadsRequest: + type: object + properties: + scope: + title: scope + $ref: '#/components/schemas/deixicpublic.v1.Scope' + archived: + type: boolean + title: archived + title: ListThreadsRequest + additionalProperties: false + deixicpublic.v1.ListThreadsResponse: + type: object + properties: + threads: + type: array + items: + $ref: '#/components/schemas/deixicpublic.v1.Thread' + title: threads + title: ListThreadsResponse + additionalProperties: false + deixicpublic.v1.ModelSelection: + type: object + properties: + provider: + type: string + title: provider + model: + type: string + title: model + title: ModelSelection + additionalProperties: false + deixicpublic.v1.Receipt: + type: object + properties: + id: + type: string + title: id + kind: + type: string + title: kind + title: + type: string + title: title + summary: + type: string + title: summary + state: + title: state + $ref: '#/components/schemas/deixicpublic.v1.ReceiptState' + updatedAt: + title: updated_at + $ref: '#/components/schemas/google.protobuf.Timestamp' + allowedActions: + type: array + items: + $ref: '#/components/schemas/deixicpublic.v1.ReceiptAction' + title: allowed_actions + evidence: + type: array + items: + $ref: '#/components/schemas/deixicpublic.v1.EvidenceReference' + title: evidence + codingAcceptance: + title: coding_acceptance + $ref: '#/components/schemas/deixicpublic.v1.CodingAcceptance' + title: Receipt + additionalProperties: false + deixicpublic.v1.ReceiptAction: + type: object + properties: + id: + type: string + title: id + label: + type: string + title: label + kind: + type: string + title: kind + requiresConfirmation: + type: boolean + title: requires_confirmation + disabledReason: + type: string + title: disabled_reason + title: ReceiptAction + additionalProperties: false + deixicpublic.v1.RenameThreadRequest: + type: object + properties: + scope: + title: scope + $ref: '#/components/schemas/deixicpublic.v1.Scope' + threadId: + type: string + title: thread_id + title: + type: string + title: title + title: RenameThreadRequest + additionalProperties: false + deixicpublic.v1.RenameThreadResponse: + type: object + properties: + thread: + title: thread + $ref: '#/components/schemas/deixicpublic.v1.Thread' + changed: + type: boolean + title: changed + title: RenameThreadResponse + additionalProperties: false + deixicpublic.v1.ResolveReceiptActionRequest: + type: object + properties: + scope: + title: scope + $ref: '#/components/schemas/deixicpublic.v1.Scope' + receiptId: + type: string + title: receipt_id + actionId: + type: string + title: action_id + idempotencyKey: + type: string + title: idempotency_key + title: ResolveReceiptActionRequest + additionalProperties: false + deixicpublic.v1.ResolveReceiptActionResponse: + type: object + properties: + receipt: + title: receipt + $ref: '#/components/schemas/deixicpublic.v1.Receipt' + title: ResolveReceiptActionResponse + additionalProperties: false + deixicpublic.v1.RespondToRequestRequest: + type: object + properties: + scope: + title: scope + $ref: '#/components/schemas/deixicpublic.v1.Scope' + threadId: + type: string + title: thread_id + turnId: + type: string + title: turn_id + requestId: + type: string + title: request_id + callId: + type: string + title: call_id + requestKind: + title: request_kind + $ref: '#/components/schemas/deixicpublic.v1.RequestKind' + action: + title: action + $ref: '#/components/schemas/deixicpublic.v1.ResponseAction' + text: + type: string + title: text + isError: + type: boolean + title: is_error + idempotencyKey: + type: string + title: idempotency_key + title: RespondToRequestRequest + additionalProperties: false + deixicpublic.v1.RespondToRequestResponse: + type: object + properties: + replayed: + type: boolean + title: replayed + turns: + type: array + items: + $ref: '#/components/schemas/deixicpublic.v1.TaskTurn' + title: turns + replayCursor: + type: + - integer + - string + title: replay_cursor + format: int64 + title: RespondToRequestResponse + additionalProperties: false + deixicpublic.v1.Scope: + type: object + properties: + organizationId: + type: string + title: organization_id + workspaceId: + type: string + title: workspace_id + title: Scope + additionalProperties: false + deixicpublic.v1.SetupReadiness: + type: object + properties: + accessible: + type: boolean + title: accessible + missingRequirements: + type: array + items: + type: string + title: missing_requirements + selection: + title: selection + $ref: '#/components/schemas/deixicpublic.v1.ModelSelection' + defaultModel: + title: default_model + $ref: '#/components/schemas/deixicpublic.v1.AvailableModel' + availableModels: + type: array + items: + $ref: '#/components/schemas/deixicpublic.v1.AvailableModel' + title: available_models + nextAction: + type: string + title: next_action + title: SetupReadiness + additionalProperties: false + deixicpublic.v1.SubmitIssueReportRequest: + type: object + properties: + scope: + title: scope + $ref: '#/components/schemas/deixicpublic.v1.Scope' + description: + type: string + title: description + expectedBehavior: + type: string + title: expected_behavior + appVersion: + type: string + title: app_version + includeDiagnostics: + type: boolean + title: include_diagnostics + idempotencyKey: + type: string + title: idempotency_key + context: + title: context + $ref: '#/components/schemas/deixicpublic.v1.IssueContext' + title: SubmitIssueReportRequest + additionalProperties: false + deixicpublic.v1.SubmitIssueReportResponse: + type: object + properties: + report: + title: report + $ref: '#/components/schemas/deixicpublic.v1.IssueReport' + title: SubmitIssueReportResponse + additionalProperties: false + deixicpublic.v1.SubmitTaskRequest: + type: object + properties: + scope: + title: scope + $ref: '#/components/schemas/deixicpublic.v1.Scope' + threadId: + type: string + title: thread_id + body: + type: string + title: body + idempotencyKey: + type: string + title: idempotency_key + continuationTaskId: + type: string + title: continuation_task_id + referenceTaskIds: + type: array + items: + type: string + title: reference_task_ids + modelSelection: + title: model_selection + $ref: '#/components/schemas/deixicpublic.v1.ModelSelection' + codingContract: + title: coding_contract + $ref: '#/components/schemas/deixicpublic.v1.CodingContract' + projectResourceId: + type: string + title: project_resource_id + title: SubmitTaskRequest + additionalProperties: false + deixicpublic.v1.SubmitTaskResponse: + type: object + properties: + message: + title: message + $ref: '#/components/schemas/deixicpublic.v1.TaskMessage' + acceptedTurn: + title: accepted_turn + $ref: '#/components/schemas/deixicpublic.v1.TaskTurn' + replayCursor: + type: + - integer + - string + title: replay_cursor + format: int64 + receipts: + type: array + items: + $ref: '#/components/schemas/deixicpublic.v1.Receipt' + title: receipts + title: SubmitTaskResponse + additionalProperties: false + deixicpublic.v1.TaskEvent: + type: object + properties: + cursor: + type: + - integer + - string + title: cursor + format: int64 + id: + type: string + title: id + turnId: + type: string + title: turn_id + kind: + title: kind + $ref: '#/components/schemas/deixicpublic.v1.EventKind' + text: + type: string + title: text + evidence: + type: array + items: + $ref: '#/components/schemas/deixicpublic.v1.EvidenceReference' + title: evidence + createdAt: + title: created_at + $ref: '#/components/schemas/google.protobuf.Timestamp' + requestId: + type: string + title: request_id + requestKind: + title: request_kind + $ref: '#/components/schemas/deixicpublic.v1.RequestKind' + toolName: + type: string + title: tool_name + callId: + type: string + title: call_id + terminalError: + title: terminal_error + $ref: '#/components/schemas/deixicpublic.v1.ErrorDetail' + title: TaskEvent + additionalProperties: false + deixicpublic.v1.TaskMessage: + type: object + properties: + id: + type: string + title: id + role: + title: role + $ref: '#/components/schemas/deixicpublic.v1.MessageRole' + body: + type: string + title: body + createdAt: + title: created_at + $ref: '#/components/schemas/google.protobuf.Timestamp' + receiptIds: + type: array + items: + type: string + title: receipt_ids + title: TaskMessage + additionalProperties: false + deixicpublic.v1.TaskTurn: + type: object + properties: + turnId: + type: string + title: turn_id + sequence: + type: + - integer + - string + title: sequence + format: int64 + userMessageId: + type: string + title: user_message_id + assistantMessageId: + type: string + title: assistant_message_id + state: + title: state + $ref: '#/components/schemas/deixicpublic.v1.TurnState' + waitingReason: + title: waiting_reason + $ref: '#/components/schemas/deixicpublic.v1.WaitingReason' + firstCursor: + type: + - integer + - string + title: first_cursor + format: int64 + lastCursor: + type: + - integer + - string + title: last_cursor + format: int64 + terminalError: + title: terminal_error + $ref: '#/components/schemas/deixicpublic.v1.ErrorDetail' + createdAt: + title: created_at + $ref: '#/components/schemas/google.protobuf.Timestamp' + updatedAt: + title: updated_at + $ref: '#/components/schemas/google.protobuf.Timestamp' + completedAt: + title: completed_at + $ref: '#/components/schemas/google.protobuf.Timestamp' + title: TaskTurn + additionalProperties: false + deixicpublic.v1.Thread: + type: object + properties: + id: + type: string + title: id + title: + type: string + title: title + replayCursor: + type: + - integer + - string + title: replay_cursor + format: int64 + activeTurnSequence: + type: + - integer + - string + title: active_turn_sequence + format: int64 + updatedAt: + title: updated_at + $ref: '#/components/schemas/google.protobuf.Timestamp' + unreadCount: + type: integer + title: unread_count + format: int32 + openCount: + type: integer + title: open_count + format: int32 + archived: + type: boolean + title: archived + title: Thread + additionalProperties: false + deixicpublic.v1.UpdateBusinessObjectRequest: + type: object + properties: + organizationId: + type: string + title: organization_id + workspaceId: + type: string + title: workspace_id + idempotencyKey: + type: string + title: idempotency_key + objectId: + type: string + title: object_id + expectedRevision: + type: + - integer + - string + title: expected_revision + format: int64 + values: + type: array + items: + $ref: '#/components/schemas/deixicpublic.v1.BusinessFieldValue' + title: values + schemaRevision: + type: + - integer + - string + title: schema_revision + format: int64 + title: UpdateBusinessObjectRequest + additionalProperties: false + deixicpublic.v1.UpdateBusinessObjectResponse: + type: object + properties: + object: + title: object + $ref: '#/components/schemas/deixicpublic.v1.BusinessObject' + title: UpdateBusinessObjectResponse + additionalProperties: false + deixicpublic.v1.WatchEventsRequest: + type: object + properties: + scope: + title: scope + $ref: '#/components/schemas/deixicpublic.v1.Scope' + threadId: + type: string + title: thread_id + afterCursor: + type: + - integer + - string + title: after_cursor + format: int64 + title: WatchEventsRequest + additionalProperties: false + deixicpublic.v1.WatchEventsResponse: + type: object + properties: + events: + type: array + items: + $ref: '#/components/schemas/deixicpublic.v1.TaskEvent' + title: events + nextCursor: + type: + - integer + - string + title: next_cursor + format: int64 + resetRequired: + type: boolean + title: reset_required + snapshot: + title: snapshot + $ref: '#/components/schemas/deixicpublic.v1.Thread' + snapshotTurns: + type: array + items: + $ref: '#/components/schemas/deixicpublic.v1.TaskTurn' + title: snapshot_turns + title: WatchEventsResponse + additionalProperties: false + google.protobuf.Timestamp: + type: string + examples: + - 1s + - 1.000340012s + format: date-time + description: |- + A Timestamp represents a point in time independent of any time zone or local + calendar, encoded as a count of seconds and fractions of seconds at + nanosecond resolution. The count is relative to an epoch at UTC midnight on + January 1, 1970, in the proleptic Gregorian calendar which extends the + Gregorian calendar backwards to year one. + + All minutes are 60 seconds long. Leap seconds are "smeared" so that no leap + second table is needed for interpretation, using a [24-hour linear + smear](https://developers.google.com/time/smear). + + The range is from 0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z. By + restricting to that range, we ensure that we can convert to and from [RFC + 3339](https://www.ietf.org/rfc/rfc3339.txt) date strings. + + # Examples + + Example 1: Compute Timestamp from POSIX `time()`. + + Timestamp timestamp; + timestamp.set_seconds(time(NULL)); + timestamp.set_nanos(0); + + Example 2: Compute Timestamp from POSIX `gettimeofday()`. + + struct timeval tv; + gettimeofday(&tv, NULL); + + Timestamp timestamp; + timestamp.set_seconds(tv.tv_sec); + timestamp.set_nanos(tv.tv_usec * 1000); + + Example 3: Compute Timestamp from Win32 `GetSystemTimeAsFileTime()`. + + FILETIME ft; + GetSystemTimeAsFileTime(&ft); + UINT64 ticks = (((UINT64)ft.dwHighDateTime) << 32) | ft.dwLowDateTime; + + // A Windows tick is 100 nanoseconds. Windows epoch 1601-01-01T00:00:00Z + // is 11644473600 seconds before Unix epoch 1970-01-01T00:00:00Z. + Timestamp timestamp; + timestamp.set_seconds((INT64) ((ticks / 10000000) - 11644473600LL)); + timestamp.set_nanos((INT32) ((ticks % 10000000) * 100)); + + Example 4: Compute Timestamp from Java `System.currentTimeMillis()`. + + long millis = System.currentTimeMillis(); + + Timestamp timestamp = Timestamp.newBuilder().setSeconds(millis / 1000) + .setNanos((int) ((millis % 1000) * 1000000)).build(); + + Example 5: Compute Timestamp from Java `Instant.now()`. + + Instant now = Instant.now(); + + Timestamp timestamp = + Timestamp.newBuilder().setSeconds(now.getEpochSecond()) + .setNanos(now.getNano()).build(); + + Example 6: Compute Timestamp from current time in Python. + + timestamp = Timestamp() + timestamp.GetCurrentTime() + + # JSON Mapping + + In JSON format, the Timestamp type is encoded as a string in the + [RFC 3339](https://www.ietf.org/rfc/rfc3339.txt) format. That is, the + format is "{year}-{month}-{day}T{hour}:{min}:{sec}[.{frac_sec}]Z" + where {year} is always expressed using four digits while {month}, {day}, + {hour}, {min}, and {sec} are zero-padded to two digits each. The fractional + seconds, which can go up to 9 digits (i.e. up to 1 nanosecond resolution), + are optional. The "Z" suffix indicates the timezone ("UTC"); the timezone + is required. A proto3 JSON serializer should always use UTC (as indicated by + "Z") when printing the Timestamp type and a proto3 JSON parser should be + able to accept both UTC and other timezones (as indicated by an offset). + + For example, "2017-01-15T01:30:15.01Z" encodes 15.01 seconds past + 01:30 UTC on January 15, 2017. + + In JavaScript, one can convert a Date object to this format using the + standard + [toISOString()](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Date/toISOString) + method. In Python, a standard `datetime.datetime` object can be converted + to this format using + [`strftime`](https://docs.python.org/2/library/time.html#time.strftime) with + the time format spec '%Y-%m-%dT%H:%M:%S.%fZ'. Likewise, in Java, one can use + the Joda Time's [`ISODateTimeFormat.dateTime()`]( + http://joda-time.sourceforge.net/apidocs/org/joda/time/format/ISODateTimeFormat.html#dateTime() + ) to obtain a formatter capable of generating timestamps in this format. + connect-protocol-version: + type: number + title: Connect-Protocol-Version + enum: + - 1 + description: Define the version of the Connect protocol + const: 1 + connect-timeout-header: + type: number + title: Connect-Timeout-Ms + description: Define the timeout, in ms + connect.error: + type: object + properties: + code: + type: string + examples: + - not_found + enum: + - canceled + - unknown + - invalid_argument + - deadline_exceeded + - not_found + - already_exists + - permission_denied + - resource_exhausted + - failed_precondition + - aborted + - out_of_range + - unimplemented + - internal + - unavailable + - data_loss + - unauthenticated + description: The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code]. + message: + type: string + description: A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client. + detail: + $ref: '#/components/schemas/google.protobuf.Any' + title: Connect Error + additionalProperties: true + description: 'Error type returned by Connect: https://connectrpc.com/docs/go/errors/#http-representation' + google.protobuf.Any: + type: object + properties: + type: + type: string + value: + type: string + format: binary + debug: + type: object + additionalProperties: true + additionalProperties: true + description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. +security: [] +tags: + - name: deixicpublic.v1.DeixicPublicService + description: |- + This is the complete application SDK wire contract. Public messages are + projections owned by this service, not aliases of implementation records. diff --git a/openapi/memory/v1/memory.openapi.yaml b/openapi/memory/v1/memory.openapi.yaml deleted file mode 100644 index 3ddc767..0000000 --- a/openapi/memory/v1/memory.openapi.yaml +++ /dev/null @@ -1,1978 +0,0 @@ -openapi: 3.1.0 -info: - title: memory.v1 -paths: - /memory.v1.MemoryService/Store: - post: - tags: - - memory.v1.MemoryService - summary: Store - operationId: memory.v1.MemoryService.Store - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.StoreRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.StoreResponse' - /memory.v1.MemoryService/StoreBatch: - post: - tags: - - memory.v1.MemoryService - summary: StoreBatch - operationId: memory.v1.MemoryService.StoreBatch - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.StoreBatchRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.StoreBatchResponse' - /memory.v1.MemoryService/Recall: - post: - tags: - - memory.v1.MemoryService - summary: Recall - operationId: memory.v1.MemoryService.Recall - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.RecallRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.RecallResponse' - /memory.v1.MemoryService/RecallKnowledge: - post: - tags: - - memory.v1.MemoryService - summary: RecallKnowledge - operationId: memory.v1.MemoryService.RecallKnowledge - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.RecallKnowledgeRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.RecallKnowledgeResponse' - /memory.v1.MemoryService/GetMemory: - post: - tags: - - memory.v1.MemoryService - summary: GetMemory - operationId: memory.v1.MemoryService.GetMemory - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.GetMemoryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.GetMemoryResponse' - /memory.v1.MemoryService/ExplainMemory: - post: - tags: - - memory.v1.MemoryService - summary: ExplainMemory - operationId: memory.v1.MemoryService.ExplainMemory - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.ExplainMemoryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.ExplainMemoryResponse' - /memory.v1.MemoryService/ClusterMemories: - post: - tags: - - memory.v1.MemoryService - summary: ClusterMemories - operationId: memory.v1.MemoryService.ClusterMemories - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.ClusterMemoriesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.ClusterMemoriesResponse' - /memory.v1.MemoryService/Update: - post: - tags: - - memory.v1.MemoryService - summary: Update - operationId: memory.v1.MemoryService.Update - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.UpdateRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.UpdateResponse' - /memory.v1.MemoryService/PromoteReviewedLearning: - post: - tags: - - memory.v1.MemoryService - summary: PromoteReviewedLearning - description: |- - PromoteReviewedLearning atomically approves an exact proposed memory and - persists the immutable planner-impact receipt that authorized activation. - operationId: memory.v1.MemoryService.PromoteReviewedLearning - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.PromoteReviewedLearningRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.PromoteReviewedLearningResponse' - /memory.v1.MemoryService/Delete: - post: - tags: - - memory.v1.MemoryService - summary: Delete - operationId: memory.v1.MemoryService.Delete - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.DeleteRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.DeleteResponse' - /memory.v1.MemoryService/List: - post: - tags: - - memory.v1.MemoryService - summary: List - operationId: memory.v1.MemoryService.List - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.ListRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.ListResponse' - /memory.v1.MemoryService/LinkMemories: - post: - tags: - - memory.v1.MemoryService - summary: LinkMemories - operationId: memory.v1.MemoryService.LinkMemories - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.LinkMemoriesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.LinkMemoriesResponse' - /memory.v1.MemoryService/ListMemoryRelationships: - post: - tags: - - memory.v1.MemoryService - summary: ListMemoryRelationships - operationId: memory.v1.MemoryService.ListMemoryRelationships - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.ListMemoryRelationshipsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.ListMemoryRelationshipsResponse' - /memory.v1.MemoryService/DeleteMemoryRelationship: - post: - tags: - - memory.v1.MemoryService - summary: DeleteMemoryRelationship - operationId: memory.v1.MemoryService.DeleteMemoryRelationship - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.DeleteMemoryRelationshipRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.DeleteMemoryRelationshipResponse' - /memory.v1.MemoryService/GetOperatingRules: - post: - tags: - - memory.v1.MemoryService - summary: GetOperatingRules - operationId: memory.v1.MemoryService.GetOperatingRules - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.GetOperatingRulesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.GetOperatingRulesResponse' - /memory.v1.MemoryService/Consolidate: - post: - tags: - - memory.v1.MemoryService - summary: Consolidate - operationId: memory.v1.MemoryService.Consolidate - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.ConsolidateRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/memory.v1.ConsolidateResponse' -components: - schemas: - memory.v1.MemoryLifecycleEventType: - type: string - title: MemoryLifecycleEventType - enum: - - MEMORY_LIFECYCLE_EVENT_TYPE_UNSPECIFIED - - MEMORY_LIFECYCLE_EVENT_TYPE_CREATED - - MEMORY_LIFECYCLE_EVENT_TYPE_CORRECTED - - MEMORY_LIFECYCLE_EVENT_TYPE_FORGOTTEN - - MEMORY_LIFECYCLE_EVENT_TYPE_REVIEWED - memory.v1.MemoryLifecycleState: - type: string - title: MemoryLifecycleState - enum: - - MEMORY_LIFECYCLE_STATE_UNSPECIFIED - - MEMORY_LIFECYCLE_STATE_ACTIVE - - MEMORY_LIFECYCLE_STATE_FORGOTTEN - memory.v1.MemoryReviewStatus: - type: string - title: MemoryReviewStatus - enum: - - MEMORY_REVIEW_STATUS_UNSPECIFIED - - MEMORY_REVIEW_STATUS_APPROVED - - MEMORY_REVIEW_STATUS_PROPOSED - - MEMORY_REVIEW_STATUS_REJECTED - description: |- - MemoryReviewStatus controls whether a memory is active for recall or still - reviewable as a proposal. - memory.v1.Scope: - type: string - title: Scope - enum: - - SCOPE_UNSPECIFIED - - SCOPE_USER - - SCOPE_TEAM - - SCOPE_ORGANIZATION - - SCOPE_AGENT - - SCOPE_PROJECT - description: Scope controls memory visibility. - platform.v1.ResourceKind: - type: string - title: ResourceKind - enum: - - RESOURCE_KIND_UNSPECIFIED - - RESOURCE_KIND_AGENT - - RESOURCE_KIND_TOOL - - RESOURCE_KIND_REPO - - RESOURCE_KIND_DATASET - - RESOURCE_KIND_DATABASE - - RESOURCE_KIND_CRM_OBJECT - - RESOURCE_KIND_MODEL_ROUTE - - RESOURCE_KIND_EXTERNAL - - RESOURCE_KIND_VFS_OBJECT - - RESOURCE_KIND_VFS_OBJECT_VERSION - - RESOURCE_KIND_ARTIFACT - - RESOURCE_KIND_ARTIFACT_VERSION - - RESOURCE_KIND_GENERATED_ASSET - google.protobuf.Timestamp: - type: string - examples: - - 1s - - 1.000340012s - format: date-time - description: |- - A Timestamp represents a point in time independent of any time zone or local - calendar, encoded as a count of seconds and fractions of seconds at - nanosecond resolution. The count is relative to an epoch at UTC midnight on - January 1, 1970, in the proleptic Gregorian calendar which extends the - Gregorian calendar backwards to year one. - - All minutes are 60 seconds long. Leap seconds are "smeared" so that no leap - second table is needed for interpretation, using a [24-hour linear - smear](https://developers.google.com/time/smear). - - The range is from 0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z. By - restricting to that range, we ensure that we can convert to and from [RFC - 3339](https://www.ietf.org/rfc/rfc3339.txt) date strings. - - # Examples - - Example 1: Compute Timestamp from POSIX `time()`. - - Timestamp timestamp; - timestamp.set_seconds(time(NULL)); - timestamp.set_nanos(0); - - Example 2: Compute Timestamp from POSIX `gettimeofday()`. - - struct timeval tv; - gettimeofday(&tv, NULL); - - Timestamp timestamp; - timestamp.set_seconds(tv.tv_sec); - timestamp.set_nanos(tv.tv_usec * 1000); - - Example 3: Compute Timestamp from Win32 `GetSystemTimeAsFileTime()`. - - FILETIME ft; - GetSystemTimeAsFileTime(&ft); - UINT64 ticks = (((UINT64)ft.dwHighDateTime) << 32) | ft.dwLowDateTime; - - // A Windows tick is 100 nanoseconds. Windows epoch 1601-01-01T00:00:00Z - // is 11644473600 seconds before Unix epoch 1970-01-01T00:00:00Z. - Timestamp timestamp; - timestamp.set_seconds((INT64) ((ticks / 10000000) - 11644473600LL)); - timestamp.set_nanos((INT32) ((ticks % 10000000) * 100)); - - Example 4: Compute Timestamp from Java `System.currentTimeMillis()`. - - long millis = System.currentTimeMillis(); - - Timestamp timestamp = Timestamp.newBuilder().setSeconds(millis / 1000) - .setNanos((int) ((millis % 1000) * 1000000)).build(); - - Example 5: Compute Timestamp from Java `Instant.now()`. - - Instant now = Instant.now(); - - Timestamp timestamp = - Timestamp.newBuilder().setSeconds(now.getEpochSecond()) - .setNanos(now.getNano()).build(); - - Example 6: Compute Timestamp from current time in Python. - - timestamp = Timestamp() - timestamp.GetCurrentTime() - - # JSON Mapping - - In JSON format, the Timestamp type is encoded as a string in the - [RFC 3339](https://www.ietf.org/rfc/rfc3339.txt) format. That is, the - format is "{year}-{month}-{day}T{hour}:{min}:{sec}[.{frac_sec}]Z" - where {year} is always expressed using four digits while {month}, {day}, - {hour}, {min}, and {sec} are zero-padded to two digits each. The fractional - seconds, which can go up to 9 digits (i.e. up to 1 nanosecond resolution), - are optional. The "Z" suffix indicates the timezone ("UTC"); the timezone - is required. A proto3 JSON serializer should always use UTC (as indicated by - "Z") when printing the Timestamp type and a proto3 JSON parser should be - able to accept both UTC and other timezones (as indicated by an offset). - - For example, "2017-01-15T01:30:15.01Z" encodes 15.01 seconds past - 01:30 UTC on January 15, 2017. - - In JavaScript, one can convert a Date object to this format using the - standard - [toISOString()](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Date/toISOString) - method. In Python, a standard `datetime.datetime` object can be converted - to this format using - [`strftime`](https://docs.python.org/2/library/time.html#time.strftime) with - the time format spec '%Y-%m-%dT%H:%M:%S.%fZ'. Likewise, in Java, one can use - the Joda Time's [`ISODateTimeFormat.dateTime()`]( - http://joda-time.sourceforge.net/apidocs/org/joda/time/format/ISODateTimeFormat.html#dateTime() - ) to obtain a formatter capable of generating timestamps in this format. - memory.v1.ClusterMemoriesRequest: - type: object - properties: - scope: - title: scope - $ref: '#/components/schemas/memory.v1.Scope' - projectId: - type: string - title: project_id - teamId: - type: string - title: team_id - repository: - type: string - title: repository - agent: - type: string - title: agent - type: - type: string - title: type - agentId: - type: string - title: agent_id - userId: - type: string - title: user_id - reviewStatus: - title: review_status - $ref: '#/components/schemas/memory.v1.MemoryReviewStatus' - maxClusters: - type: integer - title: max_clusters - format: int32 - limitPerCluster: - type: integer - title: limit_per_cluster - format: int32 - minSimilarity: - type: number - title: min_similarity - format: float - title: ClusterMemoriesRequest - additionalProperties: false - memory.v1.ClusterMemoriesResponse: - type: object - properties: - clusters: - type: array - items: - $ref: '#/components/schemas/memory.v1.MemoryCluster' - title: clusters - title: ClusterMemoriesResponse - additionalProperties: false - memory.v1.ConsolidateRequest: - type: object - properties: - scope: - title: scope - $ref: '#/components/schemas/memory.v1.Scope' - projectId: - type: string - title: project_id - type: - type: string - title: type - sourcePrefix: - type: string - title: source_prefix - title: ConsolidateRequest - additionalProperties: false - memory.v1.ConsolidateResponse: - type: object - properties: - merged: - type: integer - title: merged - format: int32 - pruned: - type: integer - title: pruned - format: int32 - title: ConsolidateResponse - additionalProperties: false - memory.v1.DeleteMemoryRelationshipRequest: - type: object - properties: - id: - type: string - title: id - minLength: 1 - title: DeleteMemoryRelationshipRequest - additionalProperties: false - memory.v1.DeleteMemoryRelationshipResponse: - type: object - title: DeleteMemoryRelationshipResponse - additionalProperties: false - memory.v1.DeleteRequest: - type: object - properties: - id: - type: string - title: id - minLength: 1 - expectedRevision: - type: - - integer - - string - title: expected_revision - minimum: 1 - format: int64 - nullable: true - idempotencyKey: - type: string - title: idempotency_key - actorId: - type: string - title: actor_id - policyRef: - type: string - title: policy_ref - provenanceRef: - type: string - title: provenance_ref - useReason: - type: string - title: use_reason - title: DeleteRequest - additionalProperties: false - memory.v1.DeleteResponse: - type: object - title: DeleteResponse - additionalProperties: false - memory.v1.ExplainMemoryRequest: - type: object - properties: - id: - type: string - title: id - minLength: 1 - title: ExplainMemoryRequest - additionalProperties: false - memory.v1.ExplainMemoryResponse: - type: object - properties: - events: - type: array - items: - $ref: '#/components/schemas/memory.v1.MemoryLifecycleEvent' - title: events - title: ExplainMemoryResponse - additionalProperties: false - memory.v1.GetMemoryRequest: - type: object - properties: - id: - type: string - title: id - minLength: 1 - title: GetMemoryRequest - additionalProperties: false - memory.v1.GetMemoryResponse: - type: object - properties: - memory: - title: memory - $ref: '#/components/schemas/memory.v1.Memory' - title: GetMemoryResponse - additionalProperties: false - memory.v1.GetOperatingRulesRequest: - type: object - properties: - scope: - title: scope - $ref: '#/components/schemas/memory.v1.Scope' - projectId: - type: string - title: project_id - teamId: - type: string - title: team_id - repository: - type: string - title: repository - agent: - type: string - title: agent - limit: - type: integer - title: limit - format: int32 - offset: - type: integer - title: offset - format: int32 - agentId: - type: string - title: agent_id - userId: - type: string - title: user_id - reviewStatus: - title: review_status - $ref: '#/components/schemas/memory.v1.MemoryReviewStatus' - title: GetOperatingRulesRequest - additionalProperties: false - memory.v1.GetOperatingRulesResponse: - type: object - properties: - memories: - type: array - items: - $ref: '#/components/schemas/memory.v1.Memory' - title: memories - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - title: GetOperatingRulesResponse - additionalProperties: false - memory.v1.LinkMemoriesRequest: - type: object - properties: - sourceMemoryId: - type: string - title: source_memory_id - minLength: 1 - targetMemoryId: - type: string - title: target_memory_id - minLength: 1 - type: - type: string - title: type - minLength: 1 - confidence: - type: number - title: confidence - format: float - validFrom: - title: valid_from - $ref: '#/components/schemas/google.protobuf.Timestamp' - validUntil: - title: valid_until - $ref: '#/components/schemas/google.protobuf.Timestamp' - id: - type: string - title: id - title: LinkMemoriesRequest - additionalProperties: false - memory.v1.LinkMemoriesResponse: - type: object - properties: - relationship: - title: relationship - $ref: '#/components/schemas/memory.v1.MemoryRelationship' - title: LinkMemoriesResponse - additionalProperties: false - memory.v1.ListMemoryRelationshipsRequest: - type: object - properties: - memoryId: - type: string - title: memory_id - sourceMemoryId: - type: string - title: source_memory_id - targetMemoryId: - type: string - title: target_memory_id - types: - type: array - items: - type: string - title: types - asOf: - title: as_of - $ref: '#/components/schemas/google.protobuf.Timestamp' - limit: - type: integer - title: limit - format: int32 - offset: - type: integer - title: offset - format: int32 - title: ListMemoryRelationshipsRequest - additionalProperties: false - memory.v1.ListMemoryRelationshipsResponse: - type: object - properties: - relationships: - type: array - items: - $ref: '#/components/schemas/memory.v1.MemoryRelationship' - title: relationships - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - title: ListMemoryRelationshipsResponse - additionalProperties: false - memory.v1.ListRequest: - type: object - properties: - scope: - title: scope - $ref: '#/components/schemas/memory.v1.Scope' - projectId: - type: string - title: project_id - teamId: - type: string - title: team_id - repository: - type: string - title: repository - agent: - type: string - title: agent - limit: - type: integer - title: limit - format: int32 - offset: - type: integer - title: offset - format: int32 - type: - type: string - title: type - agentId: - type: string - title: agent_id - userId: - type: string - title: user_id - reviewStatus: - title: review_status - $ref: '#/components/schemas/memory.v1.MemoryReviewStatus' - entityIds: - type: array - items: - type: string - title: entity_ids - source: - type: string - title: source - sourcePrefix: - type: string - title: source_prefix - title: ListRequest - additionalProperties: false - memory.v1.ListResponse: - type: object - properties: - memories: - type: array - items: - $ref: '#/components/schemas/memory.v1.Memory' - title: memories - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - title: ListResponse - additionalProperties: false - memory.v1.Memory: - type: object - properties: - id: - type: string - title: id - scope: - title: scope - $ref: '#/components/schemas/memory.v1.Scope' - content: - type: string - title: content - type: - type: string - title: type - source: - type: string - title: source - confidence: - type: number - title: confidence - format: float - pinned: - type: boolean - title: pinned - embedding: - type: array - items: - type: number - format: float - title: embedding - description: Packed float encoding — ~4x smaller than JSON float arrays. - workspaceId: - type: string - title: workspace_id - userId: - type: string - title: user_id - projectId: - type: string - title: project_id - teamId: - type: string - title: team_id - repository: - type: string - title: repository - agent: - type: string - title: agent - isPolicy: - type: boolean - title: is_policy - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - tags: - type: array - items: - type: string - title: tags - agentId: - type: string - title: agent_id - sourceReferences: - type: array - items: - $ref: '#/components/schemas/memory.v1.SourceReference' - title: source_references - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - supersedesMemoryId: - type: string - title: supersedes_memory_id - supersededByMemoryId: - type: string - title: superseded_by_memory_id - reviewStatus: - title: review_status - $ref: '#/components/schemas/memory.v1.MemoryReviewStatus' - proposedBy: - type: string - title: proposed_by - proposalReason: - type: string - title: proposal_reason - entityIds: - type: array - items: - type: string - title: entity_ids - revision: - type: - - integer - - string - title: revision - format: int64 - lifecycleState: - title: lifecycle_state - $ref: '#/components/schemas/memory.v1.MemoryLifecycleState' - title: Memory - additionalProperties: false - description: |- - Memory is the canonical memory record. - Unifies chat's Memory proto and ensemble's TypeScript memory types. - memory.v1.MemoryCluster: - type: object - properties: - id: - type: string - title: id - topic: - type: string - title: topic - results: - type: array - items: - $ref: '#/components/schemas/memory.v1.RecallResult' - title: results - centroid: - type: array - items: - type: number - format: float - title: centroid - similarity: - type: number - title: similarity - format: float - title: MemoryCluster - additionalProperties: false - memory.v1.MemoryLifecycleEvent: - type: object - properties: - eventId: - type: string - title: event_id - memoryId: - type: string - title: memory_id - revision: - type: - - integer - - string - title: revision - format: int64 - eventType: - title: event_type - $ref: '#/components/schemas/memory.v1.MemoryLifecycleEventType' - previousContentDigest: - type: string - title: previous_content_digest - contentDigest: - type: string - title: content_digest - actorId: - type: string - title: actor_id - policyRef: - type: string - title: policy_ref - provenanceRef: - type: string - title: provenance_ref - useReason: - type: string - title: use_reason - idempotencyKey: - type: string - title: idempotency_key - recordedAt: - title: recorded_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: MemoryLifecycleEvent - additionalProperties: false - description: |- - MemoryLifecycleEvent is a content-free, immutable owner receipt. The - content digests bind an explanation to a revision without copying forgotten - memory content into the explanation response. - memory.v1.MemoryRelationship: - type: object - properties: - id: - type: string - title: id - sourceMemoryId: - type: string - title: source_memory_id - targetMemoryId: - type: string - title: target_memory_id - type: - type: string - title: type - confidence: - type: number - title: confidence - format: float - validFrom: - title: valid_from - $ref: '#/components/schemas/google.protobuf.Timestamp' - validUntil: - title: valid_until - $ref: '#/components/schemas/google.protobuf.Timestamp' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - organizationId: - type: string - title: organization_id - title: MemoryRelationship - additionalProperties: false - description: MemoryRelationship links two memories into a queryable memory graph. - memory.v1.PromoteReviewedLearningRequest: - type: object - properties: - memoryId: - type: string - title: memory_id - minLength: 1 - expectedRevision: - type: - - integer - - string - title: expected_revision - minimum: 1 - format: int64 - nullable: true - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - actorId: - type: string - title: actor_id - minLength: 1 - policyRef: - type: string - title: policy_ref - minLength: 1 - provenanceRef: - type: string - title: provenance_ref - minLength: 1 - useReason: - type: string - title: use_reason - minLength: 1 - impact: - title: impact - $ref: '#/components/schemas/memory.v1.ReviewedLearningImpact' - title: PromoteReviewedLearningRequest - required: - - impact - additionalProperties: false - memory.v1.PromoteReviewedLearningResponse: - type: object - properties: - memory: - title: memory - $ref: '#/components/schemas/memory.v1.Memory' - receipt: - title: receipt - $ref: '#/components/schemas/memory.v1.ReviewedLearningPromotionReceipt' - title: PromoteReviewedLearningResponse - additionalProperties: false - memory.v1.RecallKnowledgeRequest: - type: object - properties: - conditions: - type: array - items: - type: string - title: conditions - scope: - title: scope - $ref: '#/components/schemas/memory.v1.Scope' - topK: - type: integer - title: top_k - format: int32 - projectId: - type: string - title: project_id - teamId: - type: string - title: team_id - repository: - type: string - title: repository - agent: - type: string - title: agent - agentId: - type: string - title: agent_id - userId: - type: string - title: user_id - reviewStatus: - title: review_status - $ref: '#/components/schemas/memory.v1.MemoryReviewStatus' - title: RecallKnowledgeRequest - additionalProperties: false - memory.v1.RecallKnowledgeResponse: - type: object - properties: - results: - type: array - items: - $ref: '#/components/schemas/memory.v1.RecallResult' - title: results - title: RecallKnowledgeResponse - additionalProperties: false - memory.v1.RecallRequest: - type: object - properties: - query: - type: string - title: query - scope: - title: scope - $ref: '#/components/schemas/memory.v1.Scope' - topK: - type: integer - title: top_k - format: int32 - minSimilarity: - type: number - title: min_similarity - format: float - projectId: - type: string - title: project_id - teamId: - type: string - title: team_id - repository: - type: string - title: repository - agent: - type: string - title: agent - type: - type: string - title: type - agentId: - type: string - title: agent_id - userId: - type: string - title: user_id - reviewStatus: - title: review_status - $ref: '#/components/schemas/memory.v1.MemoryReviewStatus' - entityIds: - type: array - items: - type: string - title: entity_ids - relationshipDepth: - type: integer - title: relationship_depth - format: int32 - relationshipTypes: - type: array - items: - type: string - title: relationship_types - asOf: - title: as_of - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: RecallRequest - additionalProperties: false - memory.v1.RecallResponse: - type: object - properties: - results: - type: array - items: - $ref: '#/components/schemas/memory.v1.RecallResult' - title: results - title: RecallResponse - additionalProperties: false - memory.v1.RecallResult: - type: object - properties: - memory: - title: memory - $ref: '#/components/schemas/memory.v1.Memory' - similarity: - type: number - title: similarity - format: float - graphDistance: - type: integer - title: graph_distance - format: int32 - relationshipPath: - type: array - items: - $ref: '#/components/schemas/memory.v1.MemoryRelationship' - title: relationship_path - title: RecallResult - additionalProperties: false - memory.v1.ReviewedLearningImpact: - type: object - properties: - candidateDigestSha256: - type: string - title: candidate_digest_sha256 - pattern: ^[0-9a-f]{64}$ - reviewId: - type: string - title: review_id - minLength: 1 - reviewerId: - type: string - title: reviewer_id - minLength: 1 - evaluationId: - type: string - title: evaluation_id - minLength: 1 - evaluatorId: - type: string - title: evaluator_id - minLength: 1 - evaluationSuiteId: - type: string - title: evaluation_suite_id - minLength: 1 - evaluationSuiteVersion: - type: string - title: evaluation_suite_version - minLength: 1 - taskSetDigestSha256: - type: string - title: task_set_digest_sha256 - pattern: ^[0-9a-f]{64}$ - baselinePlannerVersion: - type: string - title: baseline_planner_version - minLength: 1 - treatmentPlannerVersion: - type: string - title: treatment_planner_version - minLength: 1 - sampleCount: - type: integer - title: sample_count - minimum: 1 - baselineScoreBasisPoints: - type: integer - title: baseline_score_basis_points - maximum: 10000 - format: int32 - treatmentScoreBasisPoints: - type: integer - title: treatment_score_basis_points - maximum: 10000 - format: int32 - confidenceLowerBoundBasisPoints: - type: integer - title: confidence_lower_bound_basis_points - maximum: 10000 - minimum: -10000 - format: int32 - guardrailRegressionCount: - type: integer - title: guardrail_regression_count - sourceReplayArtifactDigestsSha256: - type: array - items: - type: string - title: source_replay_artifact_digests_sha256 - minItems: 1 - evidenceRefs: - type: array - items: - type: string - title: evidence_refs - minItems: 1 - title: ReviewedLearningImpact - additionalProperties: false - description: |- - ReviewedLearningImpact is the aggregate, content-free output of the - dex-core reviewed-learning decision. MemoryService verifies that the - candidate digest still matches the proposed row before activation. - memory.v1.ReviewedLearningPromotionReceipt: - type: object - properties: - receiptId: - type: string - title: receipt_id - memoryId: - type: string - title: memory_id - memoryRevision: - type: - - integer - - string - title: memory_revision - format: int64 - lifecycleEventId: - type: string - title: lifecycle_event_id - impact: - title: impact - $ref: '#/components/schemas/memory.v1.ReviewedLearningImpact' - actorId: - type: string - title: actor_id - policyRef: - type: string - title: policy_ref - provenanceRef: - type: string - title: provenance_ref - useReason: - type: string - title: use_reason - recordedAt: - title: recorded_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: ReviewedLearningPromotionReceipt - additionalProperties: false - description: |- - ReviewedLearningPromotionReceipt is immutable evidence that one exact - proposal revision became recallable under one measured planner evaluation. - memory.v1.SourceReference: - type: object - properties: - uri: - type: string - title: uri - title: - type: string - title: title - type: - type: string - title: type - metadata: - type: object - title: metadata - additionalProperties: - type: string - title: value - resourceRef: - title: resource_ref - $ref: '#/components/schemas/platform.v1.ResourceRef' - title: SourceReference - additionalProperties: false - description: SourceReference captures structured provenance for a memory. - memory.v1.SourceReference.MetadataEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: MetadataEntry - additionalProperties: false - memory.v1.StoreBatchRequest: - type: object - properties: - memories: - type: array - items: - $ref: '#/components/schemas/memory.v1.StoreRequest' - title: memories - minItems: 1 - continueOnError: - type: boolean - title: continue_on_error - title: StoreBatchRequest - additionalProperties: false - memory.v1.StoreBatchResponse: - type: object - properties: - results: - type: array - items: - $ref: '#/components/schemas/memory.v1.StoreBatchResult' - title: results - title: StoreBatchResponse - additionalProperties: false - memory.v1.StoreBatchResult: - type: object - properties: - index: - type: integer - title: index - format: int32 - memory: - title: memory - $ref: '#/components/schemas/memory.v1.Memory' - error: - type: string - title: error - title: StoreBatchResult - additionalProperties: false - memory.v1.StoreRequest: - type: object - properties: - scope: - title: scope - $ref: '#/components/schemas/memory.v1.Scope' - content: - type: string - title: content - minLength: 1 - type: - type: string - title: type - minLength: 1 - source: - type: string - title: source - confidence: - type: number - title: confidence - format: float - projectId: - type: string - title: project_id - teamId: - type: string - title: team_id - repository: - type: string - title: repository - agent: - type: string - title: agent - isPolicy: - type: boolean - title: is_policy - tags: - type: array - items: - type: string - title: tags - id: - type: string - title: id - agentId: - type: string - title: agent_id - userId: - type: string - title: user_id - pinned: - type: boolean - title: pinned - sourceReferences: - type: array - items: - $ref: '#/components/schemas/memory.v1.SourceReference' - title: source_references - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - supersedesMemoryId: - type: string - title: supersedes_memory_id - reviewStatus: - title: review_status - $ref: '#/components/schemas/memory.v1.MemoryReviewStatus' - proposedBy: - type: string - title: proposed_by - proposalReason: - type: string - title: proposal_reason - entityIds: - type: array - items: - type: string - title: entity_ids - title: StoreRequest - additionalProperties: false - memory.v1.StoreResponse: - type: object - properties: - memory: - title: memory - $ref: '#/components/schemas/memory.v1.Memory' - title: StoreResponse - additionalProperties: false - memory.v1.UpdateRequest: - type: object - properties: - id: - type: string - title: id - minLength: 1 - content: - type: string - title: content - description: |- - Leave empty for review-only updates; the server preserves existing content - and tags. - type: - type: string - title: type - confidence: - type: number - title: confidence - format: float - tags: - type: array - items: - type: string - title: tags - source: - type: string - title: source - pinned: - type: boolean - title: pinned - isPolicy: - type: boolean - title: is_policy - sourceReferences: - type: array - items: - $ref: '#/components/schemas/memory.v1.SourceReference' - title: source_references - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - reviewStatus: - title: review_status - $ref: '#/components/schemas/memory.v1.MemoryReviewStatus' - proposedBy: - type: string - title: proposed_by - proposalReason: - type: string - title: proposal_reason - entityIds: - type: array - items: - type: string - title: entity_ids - expectedRevision: - type: - - integer - - string - title: expected_revision - minimum: 1 - format: int64 - nullable: true - idempotencyKey: - type: string - title: idempotency_key - actorId: - type: string - title: actor_id - policyRef: - type: string - title: policy_ref - provenanceRef: - type: string - title: provenance_ref - useReason: - type: string - title: use_reason - title: UpdateRequest - additionalProperties: false - memory.v1.UpdateResponse: - type: object - properties: - memory: - title: memory - $ref: '#/components/schemas/memory.v1.Memory' - title: UpdateResponse - additionalProperties: false - platform.v1.ResourceRef: - type: object - properties: - resourceId: - type: string - title: resource_id - minLength: 1 - kind: - title: kind - $ref: '#/components/schemas/platform.v1.ResourceKind' - versionId: - type: string - title: version_id - description: Stable immutable version identity, when the reference is version-bound. - version: - type: integer - title: version - format: int32 - description: |- - Owner-defined monotonic version number. Zero means the latest version - when version_id is empty; version_id wins when both are supplied. - title: ResourceRef - additionalProperties: false - description: |- - ResourceRef is the canonical structured pointer for durable Platform - content. It is intentionally not a URI: callers carry organization and - workspace authority in the surrounding request, while a resolver owned by - the resource's service decides whether a reference yields metadata, VFS - identity, or a short-lived byte-access grant. - connect-protocol-version: - type: number - title: Connect-Protocol-Version - enum: - - 1 - description: Define the version of the Connect protocol - const: 1 - connect-timeout-header: - type: number - title: Connect-Timeout-Ms - description: Define the timeout, in ms - connect.error: - type: object - properties: - code: - type: string - examples: - - not_found - enum: - - canceled - - unknown - - invalid_argument - - deadline_exceeded - - not_found - - already_exists - - permission_denied - - resource_exhausted - - failed_precondition - - aborted - - out_of_range - - unimplemented - - internal - - unavailable - - data_loss - - unauthenticated - description: The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code]. - message: - type: string - description: A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client. - detail: - $ref: '#/components/schemas/google.protobuf.Any' - title: Connect Error - additionalProperties: true - description: 'Error type returned by Connect: https://connectrpc.com/docs/go/errors/#http-representation' - google.protobuf.Any: - type: object - properties: - type: - type: string - value: - type: string - format: binary - debug: - type: object - additionalProperties: true - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. -security: [] -tags: - - name: memory.v1.MemoryService - description: |- - MemoryService provides semantic memory storage and recall. - Canonical contract for evalops/memory, replacing hand-written structs - in chat (externalmemory/client.go) and ensemble (src/lib/memory/). diff --git a/openapi/meter/v1/meter.openapi.yaml b/openapi/meter/v1/meter.openapi.yaml deleted file mode 100644 index 9b21ba4..0000000 --- a/openapi/meter/v1/meter.openapi.yaml +++ /dev/null @@ -1,3714 +0,0 @@ -openapi: 3.1.0 -info: - title: meter.v1 -paths: - /meter.v1.MeterService/GetPrepaidCreditBalance: - post: - tags: - - meter.v1.MeterService - summary: GetPrepaidCreditBalance - description: |- - GetPrepaidCreditBalance operates only on the caller's authorized organization and workspace. - Grid staff composition returns this canonical Meter receipt unchanged. - buf:lint:ignore RPC_REQUEST_RESPONSE_UNIQUE - operationId: meter.v1.MeterService.GetPrepaidCreditBalance - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.GetPrepaidCreditBalanceRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.GetPrepaidCreditBalanceResponse' - /meter.v1.MeterService/GrantDevelopmentCredits: - post: - tags: - - meter.v1.MeterService - summary: GrantDevelopmentCredits - description: |- - GrantDevelopmentCredits issues an audited non-cash grant for the configured internal development program. - Grid staff composition returns this canonical Meter receipt unchanged. - buf:lint:ignore RPC_REQUEST_RESPONSE_UNIQUE - operationId: meter.v1.MeterService.GrantDevelopmentCredits - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.GrantDevelopmentCreditsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.GrantDevelopmentCreditsResponse' - /meter.v1.MeterService/FundPrepaidCredits: - post: - tags: - - meter.v1.MeterService - summary: FundPrepaidCredits - description: FundPrepaidCredits operates only on the caller's authorized organization and workspace. - operationId: meter.v1.MeterService.FundPrepaidCredits - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.FundPrepaidCreditsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.FundPrepaidCreditsResponse' - /meter.v1.MeterService/ReversePrepaidCredits: - post: - tags: - - meter.v1.MeterService - summary: ReversePrepaidCredits - operationId: meter.v1.MeterService.ReversePrepaidCredits - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.ReversePrepaidCreditsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.ReversePrepaidCreditsResponse' - /meter.v1.MeterService/ApplyPrepaidPaymentDispute: - post: - tags: - - meter.v1.MeterService - summary: ApplyPrepaidPaymentDispute - operationId: meter.v1.MeterService.ApplyPrepaidPaymentDispute - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.ApplyPrepaidPaymentDisputeRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.ApplyPrepaidPaymentDisputeResponse' - /meter.v1.MeterService/ReservePrepaidCredits: - post: - tags: - - meter.v1.MeterService - summary: ReservePrepaidCredits - description: ReservePrepaidCredits operates only on the caller's authorized organization and workspace. - operationId: meter.v1.MeterService.ReservePrepaidCredits - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.ReservePrepaidCreditsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.ReservePrepaidCreditsResponse' - /meter.v1.MeterService/AuthorizeWorkSpend: - post: - tags: - - meter.v1.MeterService - summary: AuthorizeWorkSpend - description: Platform admits one immutable Work allowance before dispatch. - operationId: meter.v1.MeterService.AuthorizeWorkSpend - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.AuthorizeWorkSpendRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.AuthorizeWorkSpendResponse' - /meter.v1.MeterService/ReserveWorkCredits: - post: - tags: - - meter.v1.MeterService - summary: ReserveWorkCredits - description: A separate method makes older monetary adapters reject Work reservations. - operationId: meter.v1.MeterService.ReserveWorkCredits - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.ReserveWorkCreditsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.ReserveWorkCreditsResponse' - /meter.v1.MeterService/PreviewPrepaidCompensation: - post: - tags: - - meter.v1.MeterService - summary: PreviewPrepaidCompensation - description: Read original settlement eligibility without accepting or issuing compensation. - operationId: meter.v1.MeterService.PreviewPrepaidCompensation - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.PreviewPrepaidCompensationRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.PreviewPrepaidCompensationResponse' - /meter.v1.MeterService/CompensatePrepaidCredit: - post: - tags: - - meter.v1.MeterService - summary: CompensatePrepaidCredit - description: Restore a cash-funded settled request once across all recovery incidents. - operationId: meter.v1.MeterService.CompensatePrepaidCredit - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.CompensatePrepaidCreditRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.CompensatePrepaidCreditResponse' - /meter.v1.MeterService/SettlePrepaidCredits: - post: - tags: - - meter.v1.MeterService - summary: SettlePrepaidCredits - description: SettlePrepaidCredits operates only on the caller's authorized organization and workspace. - operationId: meter.v1.MeterService.SettlePrepaidCredits - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.SettlePrepaidCreditsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.SettlePrepaidCreditsResponse' - /meter.v1.MeterService/RecordUsage: - post: - tags: - - meter.v1.MeterService - summary: RecordUsage - operationId: meter.v1.MeterService.RecordUsage - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.RecordUsageRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.RecordUsageResponse' - /meter.v1.MeterService/RecordUsageBatch: - post: - tags: - - meter.v1.MeterService - summary: RecordUsageBatch - operationId: meter.v1.MeterService.RecordUsageBatch - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.RecordUsageBatchRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.RecordUsageBatchResponse' - /meter.v1.MeterService/ListManagedInferenceAdminEvents: - post: - tags: - - meter.v1.MeterService - summary: ListManagedInferenceAdminEvents - description: |- - Read accepted funding receipts and policy changes for one exact tenant. - The staff adapter deliberately returns this same owner response. - buf:lint:ignore RPC_REQUEST_RESPONSE_UNIQUE - operationId: meter.v1.MeterService.ListManagedInferenceAdminEvents - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.ListManagedInferenceAdminEventsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.ListManagedInferenceAdminEventsResponse' - /meter.v1.MeterService/SetBudget: - post: - tags: - - meter.v1.MeterService - summary: SetBudget - description: |- - Grid staff composition returns this canonical Meter receipt unchanged. - buf:lint:ignore RPC_REQUEST_RESPONSE_UNIQUE - operationId: meter.v1.MeterService.SetBudget - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.SetBudgetRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.SetBudgetResponse' - /meter.v1.MeterService/CheckBudget: - post: - tags: - - meter.v1.MeterService - summary: CheckBudget - operationId: meter.v1.MeterService.CheckBudget - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.CheckBudgetRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.CheckBudgetResponse' - /meter.v1.MeterService/GetBudgetDashboard: - post: - tags: - - meter.v1.MeterService - summary: GetBudgetDashboard - description: |- - Grid staff composition returns this canonical Meter receipt unchanged. - buf:lint:ignore RPC_REQUEST_RESPONSE_UNIQUE - operationId: meter.v1.MeterService.GetBudgetDashboard - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.GetBudgetDashboardRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.GetBudgetDashboardResponse' - /meter.v1.MeterService/ListBudgetDenials: - post: - tags: - - meter.v1.MeterService - summary: ListBudgetDenials - description: |- - ListBudgetDenials returns the refusals CheckBudget recorded, newest first. - GetBudgetDashboard reports only the single most recent refusal; this reads - a bounded, time-windowed page of them so a caller can show the refusals a - window contains rather than one. Scope comes from the authorized caller, - the same rule GetBudgetDashboard applies to last_denial. - operationId: meter.v1.MeterService.ListBudgetDenials - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.ListBudgetDenialsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.ListBudgetDenialsResponse' - /meter.v1.MeterService/QueryUsage: - post: - tags: - - meter.v1.MeterService - summary: QueryUsage - description: |- - Grid staff composition returns this canonical Meter receipt unchanged. - buf:lint:ignore RPC_REQUEST_RESPONSE_UNIQUE - operationId: meter.v1.MeterService.QueryUsage - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.QueryUsageRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.QueryUsageResponse' - /meter.v1.MeterService/GetUsageSummary: - post: - tags: - - meter.v1.MeterService - summary: GetUsageSummary - operationId: meter.v1.MeterService.GetUsageSummary - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.GetUsageSummaryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.GetUsageSummaryResponse' - /meter.v1.MeterService/GetMeterSummary: - post: - tags: - - meter.v1.MeterService - summary: GetMeterSummary - operationId: meter.v1.MeterService.GetMeterSummary - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.GetMeterSummaryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.GetMeterSummaryResponse' - /meter.v1.MeterService/GetAdoptionMetrics: - post: - tags: - - meter.v1.MeterService - summary: GetAdoptionMetrics - operationId: meter.v1.MeterService.GetAdoptionMetrics - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.GetAdoptionMetricsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.GetAdoptionMetricsResponse' - /meter.v1.MeterService/ListActiveUsers: - post: - tags: - - meter.v1.MeterService - summary: ListActiveUsers - operationId: meter.v1.MeterService.ListActiveUsers - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.ListActiveUsersRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.ListActiveUsersResponse' - /meter.v1.MeterService/IngestWideEvent: - post: - tags: - - meter.v1.MeterService - summary: IngestWideEvent - operationId: meter.v1.MeterService.IngestWideEvent - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.IngestWideEventRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.IngestWideEventResponse' - /meter.v1.MeterService/IngestWideEventBatch: - post: - tags: - - meter.v1.MeterService - summary: IngestWideEventBatch - operationId: meter.v1.MeterService.IngestWideEventBatch - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.IngestWideEventBatchRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.IngestWideEventBatchResponse' - /meter.v1.MeterService/QueryWideEvents: - post: - tags: - - meter.v1.MeterService - summary: QueryWideEvents - operationId: meter.v1.MeterService.QueryWideEvents - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.QueryWideEventsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.QueryWideEventsResponse' - /meter.v1.MeterService/GetEventDashboard: - post: - tags: - - meter.v1.MeterService - summary: GetEventDashboard - operationId: meter.v1.MeterService.GetEventDashboard - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.GetEventDashboardRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/meter.v1.GetEventDashboardResponse' -components: - schemas: - google.protobuf.NullValue: - type: string - title: NullValue - enum: - - NULL_VALUE - description: |- - `NullValue` is a singleton enumeration to represent the null value for the - `Value` type union. - - The JSON representation for `NullValue` is JSON `null`. - meter.v1.PrepaidPaymentDisputeState: - type: string - title: PrepaidPaymentDisputeState - enum: - - PREPAID_PAYMENT_DISPUTE_STATE_UNSPECIFIED - - PREPAID_PAYMENT_DISPUTE_STATE_OPEN - - PREPAID_PAYMENT_DISPUTE_STATE_WON - - PREPAID_PAYMENT_DISPUTE_STATE_LOST - meter.v1.SummaryGroupBy: - type: string - title: SummaryGroupBy - enum: - - SUMMARY_GROUP_BY_UNSPECIFIED - - SUMMARY_GROUP_BY_MODEL - - SUMMARY_GROUP_BY_PROVIDER - - SUMMARY_GROUP_BY_TEAM - - SUMMARY_GROUP_BY_AGENT - - SUMMARY_GROUP_BY_SURFACE - - SUMMARY_GROUP_BY_METADATA - - SUMMARY_GROUP_BY_USER - - SUMMARY_GROUP_BY_TIME_BUCKET - google.protobuf.ListValue: - type: object - properties: - values: - type: array - items: - $ref: '#/components/schemas/google.protobuf.Value' - title: values - description: Repeated field of dynamically typed values. - title: ListValue - additionalProperties: false - description: |- - `ListValue` is a wrapper around a repeated field of values. - - The JSON representation for `ListValue` is JSON array. - google.protobuf.Struct: - type: object - additionalProperties: - $ref: '#/components/schemas/google.protobuf.Value' - description: |- - `Struct` represents a structured data value, consisting of fields - which map to dynamically typed values. In some languages, `Struct` - might be supported by a native representation. For example, in - scripting languages like JS a struct is represented as an - object. The details of that representation are described together - with the proto support for the language. - - The JSON representation for `Struct` is JSON object. - google.protobuf.Struct.FieldsEntry: - type: object - properties: - key: - type: string - title: key - value: - title: value - $ref: '#/components/schemas/google.protobuf.Value' - title: FieldsEntry - additionalProperties: false - google.protobuf.Timestamp: - type: string - examples: - - 1s - - 1.000340012s - format: date-time - description: |- - A Timestamp represents a point in time independent of any time zone or local - calendar, encoded as a count of seconds and fractions of seconds at - nanosecond resolution. The count is relative to an epoch at UTC midnight on - January 1, 1970, in the proleptic Gregorian calendar which extends the - Gregorian calendar backwards to year one. - - All minutes are 60 seconds long. Leap seconds are "smeared" so that no leap - second table is needed for interpretation, using a [24-hour linear - smear](https://developers.google.com/time/smear). - - The range is from 0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z. By - restricting to that range, we ensure that we can convert to and from [RFC - 3339](https://www.ietf.org/rfc/rfc3339.txt) date strings. - - # Examples - - Example 1: Compute Timestamp from POSIX `time()`. - - Timestamp timestamp; - timestamp.set_seconds(time(NULL)); - timestamp.set_nanos(0); - - Example 2: Compute Timestamp from POSIX `gettimeofday()`. - - struct timeval tv; - gettimeofday(&tv, NULL); - - Timestamp timestamp; - timestamp.set_seconds(tv.tv_sec); - timestamp.set_nanos(tv.tv_usec * 1000); - - Example 3: Compute Timestamp from Win32 `GetSystemTimeAsFileTime()`. - - FILETIME ft; - GetSystemTimeAsFileTime(&ft); - UINT64 ticks = (((UINT64)ft.dwHighDateTime) << 32) | ft.dwLowDateTime; - - // A Windows tick is 100 nanoseconds. Windows epoch 1601-01-01T00:00:00Z - // is 11644473600 seconds before Unix epoch 1970-01-01T00:00:00Z. - Timestamp timestamp; - timestamp.set_seconds((INT64) ((ticks / 10000000) - 11644473600LL)); - timestamp.set_nanos((INT32) ((ticks % 10000000) * 100)); - - Example 4: Compute Timestamp from Java `System.currentTimeMillis()`. - - long millis = System.currentTimeMillis(); - - Timestamp timestamp = Timestamp.newBuilder().setSeconds(millis / 1000) - .setNanos((int) ((millis % 1000) * 1000000)).build(); - - Example 5: Compute Timestamp from Java `Instant.now()`. - - Instant now = Instant.now(); - - Timestamp timestamp = - Timestamp.newBuilder().setSeconds(now.getEpochSecond()) - .setNanos(now.getNano()).build(); - - Example 6: Compute Timestamp from current time in Python. - - timestamp = Timestamp() - timestamp.GetCurrentTime() - - # JSON Mapping - - In JSON format, the Timestamp type is encoded as a string in the - [RFC 3339](https://www.ietf.org/rfc/rfc3339.txt) format. That is, the - format is "{year}-{month}-{day}T{hour}:{min}:{sec}[.{frac_sec}]Z" - where {year} is always expressed using four digits while {month}, {day}, - {hour}, {min}, and {sec} are zero-padded to two digits each. The fractional - seconds, which can go up to 9 digits (i.e. up to 1 nanosecond resolution), - are optional. The "Z" suffix indicates the timezone ("UTC"); the timezone - is required. A proto3 JSON serializer should always use UTC (as indicated by - "Z") when printing the Timestamp type and a proto3 JSON parser should be - able to accept both UTC and other timezones (as indicated by an offset). - - For example, "2017-01-15T01:30:15.01Z" encodes 15.01 seconds past - 01:30 UTC on January 15, 2017. - - In JavaScript, one can convert a Date object to this format using the - standard - [toISOString()](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Date/toISOString) - method. In Python, a standard `datetime.datetime` object can be converted - to this format using - [`strftime`](https://docs.python.org/2/library/time.html#time.strftime) with - the time format spec '%Y-%m-%dT%H:%M:%S.%fZ'. Likewise, in Java, one can use - the Joda Time's [`ISODateTimeFormat.dateTime()`]( - http://joda-time.sourceforge.net/apidocs/org/joda/time/format/ISODateTimeFormat.html#dateTime() - ) to obtain a formatter capable of generating timestamps in this format. - google.protobuf.Value: - oneOf: - - type: "null" - - type: number - - type: string - - type: boolean - - type: array - - type: object - additionalProperties: true - description: |- - `Value` represents a dynamically typed value which can be either - null, a number, a string, a boolean, a recursive struct value, or a - list of values. A producer of value is expected to set one of these - variants. Absence of any variant indicates an error. - - The JSON representation for `Value` is JSON value. - meter.v1.ActiveUser: - type: object - properties: - callerIdentity: - type: string - title: caller_identity - teamId: - type: string - title: team_id - firstSeen: - title: first_seen - $ref: '#/components/schemas/google.protobuf.Timestamp' - lastSeen: - title: last_seen - $ref: '#/components/schemas/google.protobuf.Timestamp' - requestCount: - type: - - integer - - string - title: request_count - format: int64 - totalCostUsd: - type: number - title: total_cost_usd - format: double - models: - type: array - items: - type: string - title: models - providers: - type: array - items: - type: string - title: providers - agents: - type: array - items: - type: string - title: agents - title: ActiveUser - additionalProperties: false - meter.v1.AdminMutationAuditContext: - type: object - properties: - delegatedActorSubject: - type: string - title: delegated_actor_subject - reason: - type: string - title: reason - requestId: - type: string - title: request_id - title: AdminMutationAuditContext - additionalProperties: false - description: Delegation is accepted only from the authenticated Platform managed-access service. - meter.v1.AdoptionCohort: - type: object - properties: - cohort: - type: string - title: cohort - users: - type: - - integer - - string - title: users - format: int64 - retainedUsers: - type: - - integer - - string - title: retained_users - format: int64 - retentionRate: - type: number - title: retention_rate - format: double - title: AdoptionCohort - additionalProperties: false - meter.v1.AdoptionDimensionBucket: - type: object - properties: - key: - type: string - title: key - activeUsers: - type: - - integer - - string - title: active_users - format: int64 - requestCount: - type: - - integer - - string - title: request_count - format: int64 - totalCostUsd: - type: number - title: total_cost_usd - format: double - title: AdoptionDimensionBucket - additionalProperties: false - meter.v1.AdoptionFrequencyBucket: - type: object - properties: - key: - type: string - title: key - users: - type: - - integer - - string - title: users - format: int64 - title: AdoptionFrequencyBucket - additionalProperties: false - meter.v1.AdoptionTimeBucket: - type: object - properties: - key: - type: string - title: key - startTime: - title: start_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - activeUsers: - type: - - integer - - string - title: active_users - format: int64 - requestCount: - type: - - integer - - string - title: request_count - format: int64 - totalCostUsd: - type: number - title: total_cost_usd - format: double - title: AdoptionTimeBucket - additionalProperties: false - meter.v1.ApplyPrepaidPaymentDisputeRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - paymentIntentId: - type: string - title: payment_intent_id - minLength: 1 - checkoutSessionId: - type: string - title: checkout_session_id - minLength: 1 - originalCreditMicros: - exclusiveMinimum: 0 - type: - - integer - - string - title: original_credit_micros - format: int64 - disputeId: - type: string - title: dispute_id - minLength: 1 - state: - title: state - $ref: '#/components/schemas/meter.v1.PrepaidPaymentDisputeState' - reversedCreditMicros: - type: - - integer - - string - title: reversed_credit_micros - format: int64 - title: ApplyPrepaidPaymentDisputeRequest - additionalProperties: false - meter.v1.ApplyPrepaidPaymentDisputeResponse: - type: object - properties: - balance: - title: balance - $ref: '#/components/schemas/meter.v1.PrepaidCreditBalance' - title: ApplyPrepaidPaymentDisputeResponse - additionalProperties: false - meter.v1.AuthorizeWorkSpendRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - authorityId: - type: string - title: authority_id - minLength: 1 - workId: - type: string - title: work_id - minLength: 1 - maxChargeMicros: - exclusiveMinimum: 0 - type: - - integer - - string - title: max_charge_micros - format: int64 - priceBookVersion: - type: string - title: price_book_version - minLength: 1 - validUntil: - title: valid_until - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: AuthorizeWorkSpendRequest - required: - - validUntil - additionalProperties: false - description: Platform's immutable, replay-safe admission of managed inference for a Work. - meter.v1.AuthorizeWorkSpendResponse: - type: object - properties: - authorityId: - type: string - title: authority_id - title: AuthorizeWorkSpendResponse - additionalProperties: false - meter.v1.Budget: - type: object - properties: - id: - type: string - title: id - organizationId: - type: string - title: organization_id - teamId: - type: string - title: team_id - workspaceId: - type: string - title: workspace_id - description: |- - Empty means the budget governs every workspace in the organization. - A non-empty value means the budget governs only that workspace. - period: - type: string - title: period - limitUsd: - exclusiveMinimum: 0 - type: number - title: limit_usd - format: double - alertThresholdPct: - type: integer - title: alert_threshold_pct - format: int32 - warningThresholdsPct: - type: array - items: - type: integer - format: int32 - title: warning_thresholds_pct - hardCap: - type: boolean - title: hard_cap - currentSpendUsd: - type: number - title: current_spend_usd - format: double - lastAlertThresholdPct: - type: integer - title: last_alert_threshold_pct - format: int32 - periodStart: - title: period_start - $ref: '#/components/schemas/google.protobuf.Timestamp' - nextResetAt: - title: next_reset_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: Budget - additionalProperties: false - meter.v1.BudgetDenial: - type: object - properties: - budgetId: - type: string - title: budget_id - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - teamId: - type: string - title: team_id - deniedAt: - title: denied_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - requestId: - type: string - title: request_id - traceId: - type: string - title: trace_id - amountUsd: - type: number - title: amount_usd - format: double - model: - type: string - title: model - provider: - type: string - title: provider - denialReason: - type: string - title: denial_reason - id: - type: string - title: id - description: |- - Stable row identity. A reader that lists denials needs it to key a row it - shows next to rows from another owner. - title: BudgetDenial - additionalProperties: false - description: |- - A budget refusal meter recorded when CheckBudget returned allowed=false. - Meter owns this record; model-gateway does not report it back. - meter.v1.BudgetStatus: - type: object - properties: - budgetId: - type: string - title: budget_id - organizationId: - type: string - title: organization_id - teamId: - type: string - title: team_id - workspaceId: - type: string - title: workspace_id - description: Empty means the budget governs every workspace in the organization. - period: - type: string - title: period - limitUsd: - type: number - title: limit_usd - format: double - currentSpendUsd: - type: number - title: current_spend_usd - format: double - remainingUsd: - type: number - title: remaining_usd - format: double - usagePct: - type: number - title: usage_pct - format: double - alertTriggered: - type: boolean - title: alert_triggered - hardCap: - type: boolean - title: hard_cap - hardCapReached: - type: boolean - title: hard_cap_reached - triggeredThresholdPct: - type: integer - title: triggered_threshold_pct - format: int32 - warningThresholdsPct: - type: array - items: - type: integer - format: int32 - title: warning_thresholds_pct - lastAlertThresholdPct: - type: integer - title: last_alert_threshold_pct - format: int32 - spendVelocityUsdPerHour: - type: number - title: spend_velocity_usd_per_hour - format: double - estimatedExhaustionHours: - type: number - title: estimated_exhaustion_hours - format: double - periodStart: - title: period_start - $ref: '#/components/schemas/google.protobuf.Timestamp' - nextResetAt: - title: next_reset_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: BudgetStatus - additionalProperties: false - meter.v1.BudgetWarning: - type: object - properties: - budgetId: - type: string - title: budget_id - thresholdPct: - type: integer - title: threshold_pct - format: int32 - usagePct: - type: number - title: usage_pct - format: double - message: - type: string - title: message - title: BudgetWarning - additionalProperties: false - meter.v1.CheckBudgetRequest: - type: object - properties: - teamId: - type: string - title: team_id - estimatedCostUsd: - type: number - title: estimated_cost_usd - format: double - workspaceId: - type: string - title: workspace_id - description: |- - Empty checks only organization-wide budgets. A non-empty value must equal - the workspace the caller was authorized for and additionally checks that - workspace's budgets. - requestId: - type: string - title: request_id - description: |- - Attribution the service persists when the check denies. The caller sends - what it knows about the request being admitted. - traceId: - type: string - title: trace_id - model: - type: string - title: model - provider: - type: string - title: provider - title: CheckBudgetRequest - additionalProperties: false - meter.v1.CheckBudgetResponse: - type: object - properties: - allowed: - type: boolean - title: allowed - denialReason: - type: string - title: denial_reason - remainingBudgetUsd: - type: number - title: remaining_budget_usd - format: double - statuses: - type: array - items: - $ref: '#/components/schemas/meter.v1.BudgetStatus' - title: statuses - warnings: - type: array - items: - $ref: '#/components/schemas/meter.v1.BudgetWarning' - title: warnings - title: CheckBudgetResponse - additionalProperties: false - meter.v1.CompensatePrepaidCreditRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - maxLength: 256 - minLength: 1 - gatewayRequestId: - type: string - title: gateway_request_id - maxLength: 256 - minLength: 1 - incidentId: - type: string - title: incident_id - maxLength: 256 - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - maxLength: 256 - minLength: 1 - title: CompensatePrepaidCreditRequest - additionalProperties: false - description: Organization and actor come exclusively from the authenticated recovery service. - meter.v1.CompensatePrepaidCreditResponse: - type: object - properties: - compensatedMicros: - exclusiveMinimum: 0 - type: - - integer - - string - title: compensated_micros - format: int64 - receiptId: - type: string - title: receipt_id - duplicate: - type: boolean - title: duplicate - description: Another incident or retry already restored this original charge. - title: CompensatePrepaidCreditResponse - additionalProperties: false - meter.v1.DevelopmentCreditGrant: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - programId: - type: string - title: program_id - grantId: - type: string - title: grant_id - creditMicros: - type: - - integer - - string - title: credit_micros - format: int64 - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - reason: - type: string - title: reason - provenance: - type: string - title: provenance - actorSubject: - type: string - title: actor_subject - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - dailyBudgetMicros: - exclusiveMinimum: 0 - type: - - integer - - string - title: daily_budget_micros - format: int64 - description: Server-configured organization-wide daily spend ceiling, including outstanding holds. - alertRecipientId: - type: string - title: alert_recipient_id - description: Server-configured Identity user receiving operational alerts, independent of the grant issuer. - title: DevelopmentCreditGrant - additionalProperties: false - description: Billing's accepted immutable grant receipt. The authenticated issuer is server-derived. - meter.v1.DevelopmentCreditProgramPolicy: - type: object - properties: - maxGrantMicros: - exclusiveMinimum: 0 - type: - - integer - - string - title: max_grant_micros - format: int64 - programBudgetMicros: - exclusiveMinimum: 0 - type: - - integer - - string - title: program_budget_micros - format: int64 - dailyBudgetMicros: - exclusiveMinimum: 0 - type: - - integer - - string - title: daily_budget_micros - format: int64 - maxLifetimeSeconds: - exclusiveMinimum: 0 - type: - - integer - - string - title: max_lifetime_seconds - format: int64 - alertRecipientId: - type: string - title: alert_recipient_id - title: DevelopmentCreditProgramPolicy - additionalProperties: false - description: |- - Immutable sponsored program limits. Enrollment is accepted atomically with its - first grant and requires meter:credits:enroll-development in addition to issuance. - meter.v1.EventDashboardBucket: - type: object - properties: - key: - type: string - title: key - count: - type: - - integer - - string - title: count - format: int64 - totalCostUsd: - type: number - title: total_cost_usd - format: double - title: EventDashboardBucket - additionalProperties: false - meter.v1.FundPrepaidCreditsRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - paymentIntentId: - type: string - title: payment_intent_id - minLength: 1 - checkoutSessionId: - type: string - title: checkout_session_id - minLength: 1 - creditMicros: - exclusiveMinimum: 0 - type: - - integer - - string - title: credit_micros - format: int64 - title: FundPrepaidCreditsRequest - additionalProperties: false - meter.v1.FundPrepaidCreditsResponse: - type: object - properties: - balance: - title: balance - $ref: '#/components/schemas/meter.v1.PrepaidCreditBalance' - title: FundPrepaidCreditsResponse - additionalProperties: false - meter.v1.GetAdoptionMetricsRequest: - type: object - properties: - teamId: - type: string - title: team_id - agentId: - type: string - title: agent_id - eventType: - type: string - title: event_type - model: - type: string - title: model - provider: - type: string - title: provider - surface: - type: string - title: surface - startTime: - title: start_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - endTime: - title: end_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - timeBucket: - type: string - title: time_bucket - title: GetAdoptionMetricsRequest - additionalProperties: false - meter.v1.GetAdoptionMetricsResponse: - type: object - properties: - dailyActiveUsers: - type: - - integer - - string - title: daily_active_users - format: int64 - weeklyActiveUsers: - type: - - integer - - string - title: weekly_active_users - format: int64 - monthlyActiveUsers: - type: - - integer - - string - title: monthly_active_users - format: int64 - totalActiveUsers: - type: - - integer - - string - title: total_active_users - format: int64 - totalTeams: - type: - - integer - - string - title: total_teams - format: int64 - requestCount: - type: - - integer - - string - title: request_count - format: int64 - totalCostUsd: - type: number - title: total_cost_usd - format: double - activeUsersByBucket: - type: array - items: - $ref: '#/components/schemas/meter.v1.AdoptionTimeBucket' - title: active_users_by_bucket - cohorts: - type: array - items: - $ref: '#/components/schemas/meter.v1.AdoptionCohort' - title: cohorts - frequencyDistribution: - type: array - items: - $ref: '#/components/schemas/meter.v1.AdoptionFrequencyBucket' - title: frequency_distribution - byTeam: - type: array - items: - $ref: '#/components/schemas/meter.v1.AdoptionDimensionBucket' - title: by_team - byModel: - type: array - items: - $ref: '#/components/schemas/meter.v1.AdoptionDimensionBucket' - title: by_model - byProvider: - type: array - items: - $ref: '#/components/schemas/meter.v1.AdoptionDimensionBucket' - title: by_provider - byAgent: - type: array - items: - $ref: '#/components/schemas/meter.v1.AdoptionDimensionBucket' - title: by_agent - title: GetAdoptionMetricsResponse - additionalProperties: false - meter.v1.GetBudgetDashboardRequest: - type: object - properties: - teamId: - type: string - title: team_id - workspaceId: - type: string - title: workspace_id - description: |- - Empty reports only organization-wide budgets. A non-empty value must equal - the workspace the caller was authorized for and additionally reports that - workspace's budgets. - title: GetBudgetDashboardRequest - additionalProperties: false - meter.v1.GetBudgetDashboardResponse: - type: object - properties: - organizationId: - type: string - title: organization_id - teamId: - type: string - title: team_id - generatedAt: - title: generated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - totalBudgets: - type: integer - title: total_budgets - format: int32 - totalLimitUsd: - type: number - title: total_limit_usd - format: double - totalSpendUsd: - type: number - title: total_spend_usd - format: double - totalRemainingUsd: - type: number - title: total_remaining_usd - format: double - warningBudgets: - type: integer - title: warning_budgets - format: int32 - hardCapBudgets: - type: integer - title: hard_cap_budgets - format: int32 - hardCapReachedBudgets: - type: integer - title: hard_cap_reached_budgets - format: int32 - statuses: - type: array - items: - $ref: '#/components/schemas/meter.v1.BudgetStatus' - title: statuses - workspaceId: - type: string - title: workspace_id - lastDenial: - title: last_denial - description: The most recent refusal in this scope, absent when nothing was refused. - $ref: '#/components/schemas/meter.v1.BudgetDenial' - title: GetBudgetDashboardResponse - additionalProperties: false - meter.v1.GetEventDashboardRequest: - type: object - properties: - teamId: - type: string - title: team_id - agentId: - type: string - title: agent_id - surface: - type: string - title: surface - eventType: - type: string - title: event_type - model: - type: string - title: model - provider: - type: string - title: provider - metadataKey: - type: string - title: metadata_key - metadataValue: - type: string - title: metadata_value - startTime: - title: start_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - endTime: - title: end_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - topN: - type: integer - title: top_n - format: int32 - title: GetEventDashboardRequest - additionalProperties: false - meter.v1.GetEventDashboardResponse: - type: object - properties: - totalEvents: - type: - - integer - - string - title: total_events - format: int64 - totalInputTokens: - type: - - integer - - string - title: total_input_tokens - format: int64 - totalOutputTokens: - type: - - integer - - string - title: total_output_tokens - format: int64 - totalCacheReadTokens: - type: - - integer - - string - title: total_cache_read_tokens - format: int64 - totalCacheWriteTokens: - type: - - integer - - string - title: total_cache_write_tokens - format: int64 - totalCostUsd: - type: number - title: total_cost_usd - format: double - byEventType: - type: array - items: - $ref: '#/components/schemas/meter.v1.EventDashboardBucket' - title: by_event_type - bySurface: - type: array - items: - $ref: '#/components/schemas/meter.v1.EventDashboardBucket' - title: by_surface - byModel: - type: array - items: - $ref: '#/components/schemas/meter.v1.EventDashboardBucket' - title: by_model - byProvider: - type: array - items: - $ref: '#/components/schemas/meter.v1.EventDashboardBucket' - title: by_provider - title: GetEventDashboardResponse - additionalProperties: false - meter.v1.GetMeterSummaryRequest: - type: object - properties: - meterId: - type: string - title: meter_id - teamId: - type: string - title: team_id - agentId: - type: string - title: agent_id - groupBy: - title: group_by - $ref: '#/components/schemas/meter.v1.SummaryGroupBy' - startTime: - title: start_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - endTime: - title: end_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: GetMeterSummaryRequest - additionalProperties: false - meter.v1.GetMeterSummaryResponse: - type: object - properties: - meterId: - type: string - title: meter_id - buckets: - type: array - items: - $ref: '#/components/schemas/meter.v1.MeterSummaryBucket' - title: buckets - title: GetMeterSummaryResponse - additionalProperties: false - meter.v1.GetPrepaidCreditBalanceRequest: - type: object - properties: - runId: - type: string - title: run_id - maxLength: 256 - workspaceId: - type: string - title: workspace_id - minLength: 1 - title: GetPrepaidCreditBalanceRequest - additionalProperties: false - meter.v1.GetPrepaidCreditBalanceResponse: - type: object - properties: - balance: - title: balance - $ref: '#/components/schemas/meter.v1.PrepaidCreditBalance' - reconciliation: - title: reconciliation - description: Absent when no account exists or an older Meter serves this response. - $ref: '#/components/schemas/meter.v1.PrepaidCreditReconciliation' - runBalance: - title: run_balance - description: Absent for missing attribution or older servers, never an inferred zero. - $ref: '#/components/schemas/meter.v1.PrepaidRunBalance' - developmentProgramPolicy: - title: development_program_policy - description: Immutable owner enrollment limits; absent for legacy or unenrolled programs. - $ref: '#/components/schemas/meter.v1.DevelopmentCreditProgramPolicy' - developmentProgramId: - type: string - title: development_program_id - title: GetPrepaidCreditBalanceResponse - additionalProperties: false - meter.v1.GetUsageSummaryRequest: - type: object - properties: - teamId: - type: string - title: team_id - agentId: - type: string - title: agent_id - groupBy: - title: group_by - $ref: '#/components/schemas/meter.v1.SummaryGroupBy' - groupMetadataKey: - type: string - title: group_metadata_key - metadataKey: - type: string - title: metadata_key - metadataValue: - type: string - title: metadata_value - startTime: - title: start_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - endTime: - title: end_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - callerIdentity: - type: string - title: caller_identity - timeBucket: - type: string - title: time_bucket - eventType: - type: string - title: event_type - model: - type: string - title: model - provider: - type: string - title: provider - title: GetUsageSummaryRequest - additionalProperties: false - meter.v1.GetUsageSummaryResponse: - type: object - properties: - buckets: - type: array - items: - $ref: '#/components/schemas/meter.v1.UsageSummary' - title: buckets - title: GetUsageSummaryResponse - additionalProperties: false - meter.v1.GrantDevelopmentCreditsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - programId: - type: string - title: program_id - minLength: 1 - grantId: - type: string - title: grant_id - minLength: 1 - creditMicros: - exclusiveMinimum: 0 - type: - - integer - - string - title: credit_micros - format: int64 - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - reason: - type: string - title: reason - minLength: 1 - provenance: - type: string - title: provenance - minLength: 1 - enrollmentPolicy: - title: enrollment_policy - description: Optional first enrollment; immutable exact retries only. Omit on later grants. - $ref: '#/components/schemas/meter.v1.DevelopmentCreditProgramPolicy' - title: GrantDevelopmentCreditsRequest - required: - - expiresAt - additionalProperties: false - description: Grant identities and provenance are immutable across retries. Expiry requires microsecond precision. - meter.v1.GrantDevelopmentCreditsResponse: - type: object - properties: - grant: - title: grant - $ref: '#/components/schemas/meter.v1.DevelopmentCreditGrant' - title: GrantDevelopmentCreditsResponse - additionalProperties: false - meter.v1.IngestWideEventBatchItemResult: - type: object - properties: - inputIndex: - type: integer - title: input_index - format: int32 - succeeded: - type: boolean - title: succeeded - eventId: - type: string - title: event_id - description: 'Set when succeeded=true: the persisted event_id.' - failureCode: - type: string - title: failure_code - description: Set when succeeded=false. - failureMessage: - type: string - title: failure_message - title: IngestWideEventBatchItemResult - additionalProperties: false - meter.v1.IngestWideEventBatchRequest: - type: object - properties: - events: - type: array - items: - $ref: '#/components/schemas/meter.v1.IngestWideEventRequest' - title: events - maxItems: 100 - minItems: 1 - title: IngestWideEventBatchRequest - additionalProperties: false - meter.v1.IngestWideEventBatchResponse: - type: object - properties: - results: - type: array - items: - $ref: '#/components/schemas/meter.v1.IngestWideEventBatchItemResult' - title: results - description: Per-event result keyed by input index (0-based). - budgetExceeded: - type: boolean - title: budget_exceeded - description: Top-level signal — true if any event hit a budget cap. - budgetMessage: - type: string - title: budget_message - title: IngestWideEventBatchResponse - additionalProperties: false - meter.v1.IngestWideEventRequest: - type: object - properties: - timestamp: - title: timestamp - $ref: '#/components/schemas/google.protobuf.Timestamp' - teamId: - type: string - title: team_id - agentId: - type: string - title: agent_id - surface: - type: string - title: surface - eventType: - type: string - title: event_type - model: - type: string - title: model - provider: - type: string - title: provider - requestId: - type: string - title: request_id - metadata: - title: metadata - $ref: '#/components/schemas/google.protobuf.Struct' - data: - title: data - $ref: '#/components/schemas/google.protobuf.Struct' - metrics: - title: metrics - $ref: '#/components/schemas/meter.v1.WideEventMetrics' - title: IngestWideEventRequest - additionalProperties: false - meter.v1.IngestWideEventResponse: - type: object - properties: - event: - title: event - $ref: '#/components/schemas/meter.v1.WideEvent' - budgetExceeded: - type: boolean - title: budget_exceeded - description: true when this event pushed the agent or team over budget - budgetMessage: - type: string - title: budget_message - description: human-readable budget status, empty when within budget - title: IngestWideEventResponse - additionalProperties: false - meter.v1.ListActiveUsersRequest: - type: object - properties: - teamId: - type: string - title: team_id - agentId: - type: string - title: agent_id - eventType: - type: string - title: event_type - model: - type: string - title: model - provider: - type: string - title: provider - surface: - type: string - title: surface - startTime: - title: start_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - endTime: - title: end_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - limit: - type: integer - title: limit - maximum: 200 - format: int32 - offset: - type: integer - title: offset - format: int32 - title: ListActiveUsersRequest - additionalProperties: false - meter.v1.ListActiveUsersResponse: - type: object - properties: - users: - type: array - items: - $ref: '#/components/schemas/meter.v1.ActiveUser' - title: users - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - title: ListActiveUsersResponse - additionalProperties: false - meter.v1.ListBudgetDenialsRequest: - type: object - properties: - teamId: - type: string - title: team_id - workspaceId: - type: string - title: workspace_id - description: |- - Empty reads only organization-wide denials. A non-empty value must equal - the workspace the caller was authorized for. - startTime: - title: start_time - description: Inclusive lower bound on denied_at. Absent reads from the oldest row. - $ref: '#/components/schemas/google.protobuf.Timestamp' - endTime: - title: end_time - description: Exclusive upper bound on denied_at. Absent reads to the newest row. - $ref: '#/components/schemas/google.protobuf.Timestamp' - limit: - type: integer - title: limit - maximum: 200 - format: int32 - description: Zero applies the server default of 200, which is also the ceiling. - offset: - type: integer - title: offset - format: int32 - title: ListBudgetDenialsRequest - additionalProperties: false - meter.v1.ListBudgetDenialsResponse: - type: object - properties: - denials: - type: array - items: - $ref: '#/components/schemas/meter.v1.BudgetDenial' - title: denials - description: Newest first, at most `limit` rows. - hasMore: - type: boolean - title: has_more - description: |- - True when at least one further row matched past this page. Meter does not - count the whole match set, so no total is reported. - title: ListBudgetDenialsResponse - additionalProperties: false - meter.v1.ListManagedInferenceAdminEventsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - pageSize: - type: integer - title: page_size - maximum: 100 - format: int32 - pageToken: - type: string - title: page_token - title: ListManagedInferenceAdminEventsRequest - additionalProperties: false - meter.v1.ListManagedInferenceAdminEventsResponse: - type: object - properties: - events: - type: array - items: - $ref: '#/components/schemas/meter.v1.ManagedInferenceAdminEvent' - title: events - nextPageToken: - type: string - title: next_page_token - title: ListManagedInferenceAdminEventsResponse - additionalProperties: false - meter.v1.ManagedInferenceAdminEvent: - type: object - properties: - eventId: - type: string - title: event_id - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - actorSubject: - type: string - title: actor_subject - delegatedActorSubject: - type: string - title: delegated_actor_subject - action: - type: string - title: action - resourceId: - type: string - title: resource_id - reason: - type: string - title: reason - outcome: - type: string - title: outcome - beforeBudget: - title: before_budget - $ref: '#/components/schemas/meter.v1.ManagedInferenceBudgetSnapshot' - afterBudget: - title: after_budget - $ref: '#/components/schemas/meter.v1.ManagedInferenceBudgetSnapshot' - creditMicros: - type: - - integer - - string - title: credit_micros - format: int64 - programId: - type: string - title: program_id - provenance: - type: string - title: provenance - requestId: - type: string - title: request_id - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - title: ManagedInferenceAdminEvent - additionalProperties: false - meter.v1.ManagedInferenceBudgetSnapshot: - type: object - properties: - period: - type: string - title: period - limitUsd: - type: number - title: limit_usd - format: double - warningThresholdsPct: - type: array - items: - type: integer - format: int32 - title: warning_thresholds_pct - hardCap: - type: boolean - title: hard_cap - title: ManagedInferenceBudgetSnapshot - additionalProperties: false - meter.v1.MeterSummaryBucket: - type: object - properties: - key: - type: string - title: key - value: - type: number - title: value - format: double - recordCount: - type: - - integer - - string - title: record_count - format: int64 - title: MeterSummaryBucket - additionalProperties: false - meter.v1.PrepaidCompensationEligibility: - type: object - properties: - gatewayRequestId: - type: string - title: gateway_request_id - eligible: - type: boolean - title: eligible - creditMicros: - type: - - integer - - string - title: credit_micros - format: int64 - reason: - type: string - title: reason - description: 'Stable owner codes: eligible, not_found, unsettled, zero_charge, grant_funded.' - title: PrepaidCompensationEligibility - additionalProperties: false - meter.v1.PrepaidCreditBalance: - type: object - properties: - compensatedMicros: - type: - - integer - - string - title: compensated_micros - format: int64 - description: Cash recovery, separate from purchases and non-cash grants. - developmentCreditOnly: - type: boolean - title: development_credit_only - description: Enrolled development programs cannot consume paid credits or trigger paid refill. - grantedMicros: - type: - - integer - - string - title: granted_micros - format: int64 - description: Non-cash development funding, kept separate from purchased credits. - expiredGrantMicros: - type: - - integer - - string - title: expired_grant_micros - format: int64 - grantSpentMicros: - type: - - integer - - string - title: grant_spent_micros - format: int64 - grantReservedMicros: - type: - - integer - - string - title: grant_reserved_micros - format: int64 - admissionSuspended: - type: boolean - title: admission_suspended - reversedMicros: - type: - - integer - - string - title: reversed_micros - format: int64 - debtMicros: - type: - - integer - - string - title: debt_micros - format: int64 - purchasedMicros: - type: - - integer - - string - title: purchased_micros - format: int64 - spentMicros: - type: - - integer - - string - title: spent_micros - format: int64 - reservedMicros: - type: - - integer - - string - title: reserved_micros - format: int64 - availableMicros: - type: - - integer - - string - title: available_micros - format: int64 - title: PrepaidCreditBalance - additionalProperties: false - description: |- - Prepaid credits are USD amounts in integer millionths of a dollar. - Meter owns funding, reservations, settlement, and the available balance. - meter.v1.PrepaidCreditReconciliation: - type: object - properties: - compensatedDifferenceMicros: - type: - - integer - - string - title: compensated_difference_micros - format: int64 - grantedDifferenceMicros: - type: - - integer - - string - title: granted_difference_micros - format: int64 - invalidGrantAllocationCount: - type: - - integer - - string - title: invalid_grant_allocation_count - format: int64 - balanced: - type: boolean - title: balanced - description: A comparison of materialized counters with source rows in one snapshot. - purchasedDifferenceMicros: - type: - - integer - - string - title: purchased_difference_micros - format: int64 - reversedDifferenceMicros: - type: - - integer - - string - title: reversed_difference_micros - format: int64 - spentDifferenceMicros: - type: - - integer - - string - title: spent_difference_micros - format: int64 - reservedDifferenceMicros: - type: - - integer - - string - title: reserved_difference_micros - format: int64 - disputeCountDifference: - type: - - integer - - string - title: dispute_count_difference - format: int64 - pendingReservationCount: - type: - - integer - - string - title: pending_reservation_count - format: int64 - oldestPendingAt: - title: oldest_pending_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - unfundedPaymentCount: - type: - - integer - - string - title: unfunded_payment_count - format: int64 - title: PrepaidCreditReconciliation - additionalProperties: false - meter.v1.PrepaidRunBalance: - type: object - properties: - runId: - type: string - title: run_id - settledCostMicros: - type: - - integer - - string - title: settled_cost_micros - format: int64 - reservedMicros: - type: - - integer - - string - title: reserved_micros - format: int64 - pendingRequestCount: - type: - - integer - - string - title: pending_request_count - format: int64 - settledRequestCount: - type: - - integer - - string - title: settled_request_count - format: int64 - oldestPendingAt: - title: oldest_pending_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: PrepaidRunBalance - additionalProperties: false - meter.v1.PreviewPrepaidCompensationRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - maxLength: 256 - minLength: 1 - gatewayRequestIds: - type: array - items: - type: string - maxItems: 100 - title: gateway_request_ids - maxItems: 100 - minItems: 1 - title: PreviewPrepaidCompensationRequest - additionalProperties: false - meter.v1.PreviewPrepaidCompensationResponse: - type: object - properties: - entries: - type: array - items: - $ref: '#/components/schemas/meter.v1.PrepaidCompensationEligibility' - title: entries - title: PreviewPrepaidCompensationResponse - additionalProperties: false - meter.v1.QueryUsageRequest: - type: object - properties: - teamId: - type: string - title: team_id - agentId: - type: string - title: agent_id - eventType: - type: string - title: event_type - model: - type: string - title: model - provider: - type: string - title: provider - metadataKey: - type: string - title: metadata_key - metadataValue: - type: string - title: metadata_value - startTime: - title: start_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - endTime: - title: end_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - limit: - type: integer - title: limit - maximum: 200 - format: int32 - offset: - type: integer - title: offset - format: int32 - callerIdentity: - type: string - title: caller_identity - title: QueryUsageRequest - additionalProperties: false - meter.v1.QueryUsageResponse: - type: object - properties: - records: - type: array - items: - $ref: '#/components/schemas/meter.v1.UsageRecord' - title: records - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - title: QueryUsageResponse - additionalProperties: false - meter.v1.QueryWideEventsRequest: - type: object - properties: - teamId: - type: string - title: team_id - agentId: - type: string - title: agent_id - surface: - type: string - title: surface - eventType: - type: string - title: event_type - model: - type: string - title: model - provider: - type: string - title: provider - metadataKey: - type: string - title: metadata_key - metadataValue: - type: string - title: metadata_value - startTime: - title: start_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - endTime: - title: end_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - limit: - type: integer - title: limit - format: int32 - offset: - type: integer - title: offset - format: int32 - title: QueryWideEventsRequest - additionalProperties: false - meter.v1.QueryWideEventsResponse: - type: object - properties: - events: - type: array - items: - $ref: '#/components/schemas/meter.v1.WideEvent' - title: events - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - title: QueryWideEventsResponse - additionalProperties: false - meter.v1.RecordUsageBatchRequest: - type: object - properties: - records: - type: array - items: - $ref: '#/components/schemas/meter.v1.RecordUsageRequest' - title: records - minItems: 1 - title: RecordUsageBatchRequest - additionalProperties: false - meter.v1.RecordUsageBatchResponse: - type: object - properties: - records: - type: array - items: - $ref: '#/components/schemas/meter.v1.UsageRecord' - title: records - title: RecordUsageBatchResponse - additionalProperties: false - meter.v1.RecordUsageRequest: - type: object - properties: - teamId: - type: string - title: team_id - agentId: - type: string - title: agent_id - surface: - type: string - title: surface - eventType: - type: string - title: event_type - model: - type: string - title: model - provider: - type: string - title: provider - inputTokens: - type: - - integer - - string - title: input_tokens - format: int64 - outputTokens: - type: - - integer - - string - title: output_tokens - format: int64 - cacheReadTokens: - type: - - integer - - string - title: cache_read_tokens - format: int64 - cacheWriteTokens: - type: - - integer - - string - title: cache_write_tokens - format: int64 - totalCostUsd: - type: number - title: total_cost_usd - format: double - requestId: - type: string - title: request_id - metadata: - title: metadata - $ref: '#/components/schemas/google.protobuf.Struct' - data: - title: data - $ref: '#/components/schemas/google.protobuf.Struct' - callerIdentity: - type: string - title: caller_identity - title: RecordUsageRequest - additionalProperties: false - meter.v1.RecordUsageResponse: - type: object - properties: - record: - title: record - $ref: '#/components/schemas/meter.v1.UsageRecord' - title: RecordUsageResponse - additionalProperties: false - meter.v1.ReservePrepaidCreditsRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - gatewayRequestId: - type: string - title: gateway_request_id - minLength: 1 - amountMicros: - exclusiveMinimum: 0 - type: - - integer - - string - title: amount_micros - format: int64 - runId: - type: string - title: run_id - maxLength: 256 - description: Issued only by the authenticated Gateway after managed scope verification. - title: ReservePrepaidCreditsRequest - additionalProperties: false - meter.v1.ReservePrepaidCreditsResponse: - type: object - properties: - reservedMicros: - type: - - integer - - string - title: reserved_micros - format: int64 - settled: - type: boolean - title: settled - description: A completed reservation cannot authorize a second upstream request. - created: - type: boolean - title: created - description: True only for the atomic first reservation; false never authorizes execution. - title: ReservePrepaidCreditsResponse - additionalProperties: false - meter.v1.ReserveWorkCreditsRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - authorityId: - type: string - title: authority_id - minLength: 1 - workId: - type: string - title: work_id - minLength: 1 - priceBookVersion: - type: string - title: price_book_version - minLength: 1 - gatewayRequestId: - type: string - title: gateway_request_id - minLength: 1 - runId: - type: string - title: run_id - minLength: 1 - amountMicros: - exclusiveMinimum: 0 - type: - - integer - - string - title: amount_micros - format: int64 - title: ReserveWorkCreditsRequest - additionalProperties: false - meter.v1.ReserveWorkCreditsResponse: - type: object - properties: - reservedMicros: - type: - - integer - - string - title: reserved_micros - format: int64 - settled: - type: boolean - title: settled - description: A completed reservation cannot authorize a second upstream request. - created: - type: boolean - title: created - description: True only for the atomic first reservation; false never authorizes execution. - title: ReserveWorkCreditsResponse - additionalProperties: false - meter.v1.ReversePrepaidCreditsRequest: - type: object - properties: - originalCreditMicros: - exclusiveMinimum: 0 - type: - - integer - - string - title: original_credit_micros - format: int64 - checkoutSessionId: - type: string - title: checkout_session_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - paymentIntentId: - type: string - title: payment_intent_id - minLength: 1 - reversalId: - type: string - title: reversal_id - minLength: 1 - reversedCreditMicros: - type: - - integer - - string - title: reversed_credit_micros - format: int64 - title: ReversePrepaidCreditsRequest - additionalProperties: false - description: Cumulative verified payment reversal; event retries never restore funds. - meter.v1.ReversePrepaidCreditsResponse: - type: object - properties: - balance: - title: balance - $ref: '#/components/schemas/meter.v1.PrepaidCreditBalance' - title: ReversePrepaidCreditsResponse - additionalProperties: false - meter.v1.SetBudgetRequest: - type: object - properties: - auditContext: - title: audit_context - $ref: '#/components/schemas/meter.v1.AdminMutationAuditContext' - budgetId: - type: string - title: budget_id - teamId: - type: string - title: team_id - period: - type: string - title: period - description: |- - Changing the period of an existing budget restarts the spend window: the - service sets period_start to now, clears current_spend_usd, and derives a - new next_reset_at. Sending the same period leaves the window untouched. - limitUsd: - exclusiveMinimum: 0 - type: number - title: limit_usd - format: double - warningThresholdsPct: - type: array - items: - type: integer - format: int32 - title: warning_thresholds_pct - hardCap: - type: boolean - title: hard_cap - workspaceId: - type: string - title: workspace_id - description: |- - Empty creates or updates an organization-wide budget. A non-empty value - must equal the workspace the caller was authorized for. - idempotencyKey: - type: string - title: idempotency_key - maxLength: 256 - description: |- - Empty preserves legacy non-idempotent callers. New callers supply a stable - key for this exact organization and authenticated workspace. - title: SetBudgetRequest - additionalProperties: false - meter.v1.SetBudgetResponse: - type: object - properties: - budget: - title: budget - $ref: '#/components/schemas/meter.v1.Budget' - title: SetBudgetResponse - additionalProperties: false - meter.v1.SettlePrepaidCreditsRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - gatewayRequestId: - type: string - title: gateway_request_id - minLength: 1 - actualCostMicros: - type: - - integer - - string - title: actual_cost_micros - format: int64 - title: SettlePrepaidCreditsRequest - additionalProperties: false - meter.v1.SettlePrepaidCreditsResponse: - type: object - properties: - actualCostMicros: - type: - - integer - - string - title: actual_cost_micros - format: int64 - title: SettlePrepaidCreditsResponse - additionalProperties: false - meter.v1.UsageRecord: - type: object - properties: - id: - type: string - title: id - timestamp: - title: timestamp - $ref: '#/components/schemas/google.protobuf.Timestamp' - organizationId: - type: string - title: organization_id - teamId: - type: string - title: team_id - agentId: - type: string - title: agent_id - surface: - type: string - title: surface - eventType: - type: string - title: event_type - model: - type: string - title: model - provider: - type: string - title: provider - inputTokens: - type: - - integer - - string - title: input_tokens - format: int64 - outputTokens: - type: - - integer - - string - title: output_tokens - format: int64 - cacheReadTokens: - type: - - integer - - string - title: cache_read_tokens - format: int64 - cacheWriteTokens: - type: - - integer - - string - title: cache_write_tokens - format: int64 - totalCostUsd: - type: number - title: total_cost_usd - format: double - requestId: - type: string - title: request_id - data: - title: data - $ref: '#/components/schemas/google.protobuf.Struct' - metadata: - title: metadata - $ref: '#/components/schemas/google.protobuf.Struct' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - callerIdentity: - type: string - title: caller_identity - title: UsageRecord - additionalProperties: false - meter.v1.UsageSummary: - type: object - properties: - key: - type: string - title: key - totalInputTokens: - type: - - integer - - string - title: total_input_tokens - format: int64 - totalOutputTokens: - type: - - integer - - string - title: total_output_tokens - format: int64 - totalCacheReadTokens: - type: - - integer - - string - title: total_cache_read_tokens - format: int64 - totalCacheWriteTokens: - type: - - integer - - string - title: total_cache_write_tokens - format: int64 - totalCostUsd: - type: number - title: total_cost_usd - format: double - recordCount: - type: - - integer - - string - title: record_count - format: int64 - gatewayRequestCount: - type: - - integer - - string - title: gateway_request_count - format: int64 - description: Gateway coverage only; other usage sources are excluded from these counts. - unattributedRequestCount: - type: - - integer - - string - title: unattributed_request_count - format: int64 - description: No verified workload link, including older records without verification evidence. - unattributedTokenCount: - type: - - integer - - string - title: unattributed_token_count - format: int64 - unpricedRequestCount: - type: - - integer - - string - title: unpriced_request_count - format: int64 - unpricedTokenCount: - type: - - integer - - string - title: unpriced_token_count - format: int64 - costIncomplete: - type: boolean - title: cost_incomplete - description: True when the bucket includes gateway usage with unavailable pricing. - knownTotalCostUsd: - type: number - title: known_total_cost_usd - format: double - description: |- - Known subtotal, absent when no record has available pricing. A genuine - priced zero remains present. total_cost_usd retains its legacy sum, which - may include unavailable-price placeholders and is not a completeness claim. - nullable: true - title: UsageSummary - additionalProperties: false - meter.v1.WideEvent: - type: object - properties: - id: - type: string - title: id - timestamp: - title: timestamp - $ref: '#/components/schemas/google.protobuf.Timestamp' - organizationId: - type: string - title: organization_id - teamId: - type: string - title: team_id - agentId: - type: string - title: agent_id - surface: - type: string - title: surface - eventType: - type: string - title: event_type - model: - type: string - title: model - provider: - type: string - title: provider - requestId: - type: string - title: request_id - metadata: - title: metadata - $ref: '#/components/schemas/google.protobuf.Struct' - data: - title: data - $ref: '#/components/schemas/google.protobuf.Struct' - metrics: - title: metrics - $ref: '#/components/schemas/meter.v1.WideEventMetrics' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: WideEvent - additionalProperties: false - meter.v1.WideEventAttributes: - type: object - properties: - eventId: - type: string - title: event_id - conversationId: - type: string - title: conversation_id - messageId: - type: string - title: message_id - workspaceId: - type: string - title: workspace_id - sessionId: - type: string - title: session_id - executionSource: - type: string - title: execution_source - lifecyclePhase: - type: string - title: lifecycle_phase - outcome: - type: string - title: outcome - errorType: - type: string - title: error_type - skillId: - type: string - title: skill_id - skillName: - type: string - title: skill_name - feedbackType: - type: string - title: feedback_type - generationId: - type: string - title: generation_id - requestMethod: - type: string - title: request_method - requestPath: - type: string - title: request_path - cancelledByUser: - type: boolean - title: cancelled_by_user - responseTruncated: - type: boolean - title: response_truncated - title: WideEventAttributes - additionalProperties: false - description: |- - WideEventAttributes declares every metadata key a wide event may carry. - - IngestWideEventRequest.metadata is a google.protobuf.Struct, so the wire - format cannot constrain its keys. This message is the declaration of record: - one field per allowed key, each carrying its data classification. - scripts/gen-classification-manifest.py projects it into - gen/classification/manifest.json, and the meter ingest path drops any - metadata key the manifest does not name. - - This message is not sent on the wire. Adding a key here is how a producer - gets a new wide-event attribute accepted. - meter.v1.WideEventMetrics: - type: object - properties: - inputTokens: - type: - - integer - - string - title: input_tokens - format: int64 - outputTokens: - type: - - integer - - string - title: output_tokens - format: int64 - cacheReadTokens: - type: - - integer - - string - title: cache_read_tokens - format: int64 - cacheWriteTokens: - type: - - integer - - string - title: cache_write_tokens - format: int64 - totalCostUsd: - type: number - title: total_cost_usd - format: double - durationMs: - type: - - integer - - string - title: duration_ms - format: int64 - timeToFirstTokenMs: - type: - - integer - - string - title: time_to_first_token_ms - format: int64 - toolCallsCount: - type: - - integer - - string - title: tool_calls_count - format: int64 - title: WideEventMetrics - additionalProperties: false - connect-protocol-version: - type: number - title: Connect-Protocol-Version - enum: - - 1 - description: Define the version of the Connect protocol - const: 1 - connect-timeout-header: - type: number - title: Connect-Timeout-Ms - description: Define the timeout, in ms - connect.error: - type: object - properties: - code: - type: string - examples: - - not_found - enum: - - canceled - - unknown - - invalid_argument - - deadline_exceeded - - not_found - - already_exists - - permission_denied - - resource_exhausted - - failed_precondition - - aborted - - out_of_range - - unimplemented - - internal - - unavailable - - data_loss - - unauthenticated - description: The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code]. - message: - type: string - description: A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client. - detail: - $ref: '#/components/schemas/google.protobuf.Any' - title: Connect Error - additionalProperties: true - description: 'Error type returned by Connect: https://connectrpc.com/docs/go/errors/#http-representation' - google.protobuf.Any: - type: object - properties: - type: - type: string - value: - type: string - format: binary - debug: - type: object - additionalProperties: true - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. -security: [] -tags: - - name: meter.v1.MeterService - description: MeterService records and queries usage across EvalOps services. diff --git a/openapi/objectives/v1/objectives.openapi.yaml b/openapi/objectives/v1/objectives.openapi.yaml deleted file mode 100644 index 96fd285..0000000 --- a/openapi/objectives/v1/objectives.openapi.yaml +++ /dev/null @@ -1,1384 +0,0 @@ -openapi: 3.1.0 -info: - title: objectives.v1 -paths: - /objectives.v1.ObjectiveService/Create: - post: - tags: - - objectives.v1.ObjectiveService - summary: Create - operationId: objectives.v1.ObjectiveService.Create - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.CreateRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.CreateResponse' - /objectives.v1.ObjectiveService/Get: - post: - tags: - - objectives.v1.ObjectiveService - summary: Get - operationId: objectives.v1.ObjectiveService.Get - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.GetRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.GetResponse' - /objectives.v1.ObjectiveService/Transition: - post: - tags: - - objectives.v1.ObjectiveService - summary: Transition - operationId: objectives.v1.ObjectiveService.Transition - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.TransitionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.TransitionResponse' - /objectives.v1.ObjectiveService/Wake: - post: - tags: - - objectives.v1.ObjectiveService - summary: Wake - operationId: objectives.v1.ObjectiveService.Wake - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.WakeRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.WakeResponse' - /objectives.v1.ObjectiveService/ScheduleWake: - post: - tags: - - objectives.v1.ObjectiveService - summary: ScheduleWake - operationId: objectives.v1.ObjectiveService.ScheduleWake - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.ScheduleWakeRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.ScheduleWakeResponse' - /objectives.v1.ObjectiveService/Query: - post: - tags: - - objectives.v1.ObjectiveService - summary: Query - operationId: objectives.v1.ObjectiveService.Query - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.QueryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.QueryResponse' - /objectives.v1.ObjectiveService/RecordProvenance: - post: - tags: - - objectives.v1.ObjectiveService - summary: RecordProvenance - operationId: objectives.v1.ObjectiveService.RecordProvenance - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.RecordProvenanceRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.RecordProvenanceResponse' - /objectives.v1.ObjectiveService/RecordMutation: - post: - tags: - - objectives.v1.ObjectiveService - summary: RecordMutation - operationId: objectives.v1.ObjectiveService.RecordMutation - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.RecordMutationRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.RecordMutationResponse' - /objectives.v1.ObjectiveService/GetGovernanceEvaluation: - post: - tags: - - objectives.v1.ObjectiveService - summary: GetGovernanceEvaluation - operationId: objectives.v1.ObjectiveService.GetGovernanceEvaluation - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.GetGovernanceEvaluationRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.GetGovernanceEvaluationResponse' - /objectives.v1.ObjectiveService/Cancel: - post: - tags: - - objectives.v1.ObjectiveService - summary: Cancel - operationId: objectives.v1.ObjectiveService.Cancel - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.CancelRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.CancelResponse' - /objectives.v1.ObjectiveService/AppendTurn: - post: - tags: - - objectives.v1.ObjectiveService - summary: AppendTurn - operationId: objectives.v1.ObjectiveService.AppendTurn - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.AppendTurnRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.AppendTurnResponse' - /objectives.v1.ObjectiveService/RunStep: - post: - tags: - - objectives.v1.ObjectiveService - summary: RunStep - operationId: objectives.v1.ObjectiveService.RunStep - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.RunStepRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.RunStepResponse' - /objectives.v1.ObjectiveService/WaitForEvent: - post: - tags: - - objectives.v1.ObjectiveService - summary: WaitForEvent - operationId: objectives.v1.ObjectiveService.WaitForEvent - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.WaitForEventRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.WaitForEventResponse' - /objectives.v1.ObjectiveService/ListTurns: - post: - tags: - - objectives.v1.ObjectiveService - summary: ListTurns - operationId: objectives.v1.ObjectiveService.ListTurns - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.ListTurnsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.ListTurnsResponse' - /objectives.v1.ObjectiveService/QueryTurns: - post: - tags: - - objectives.v1.ObjectiveService - summary: QueryTurns - operationId: objectives.v1.ObjectiveService.QueryTurns - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.QueryTurnsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/objectives.v1.QueryTurnsResponse' -components: - schemas: - common.v1.Surface: - type: string - title: Surface - enum: - - SURFACE_UNSPECIFIED - - SURFACE_ENSEMBLE - - SURFACE_CHAT - - SURFACE_MAESTRO - - SURFACE_CONDUCTOR - - SURFACE_SLACK - - SURFACE_EXTERNAL_AGENT - description: |- - Surface identifies the product or channel surface that originated a platform - action. It is shared by runtime, audit, and product-facing services so - callers do not invent drift-prone string labels. - objectives.v1.MutationStatus: - type: string - title: MutationStatus - enum: - - MUTATION_STATUS_UNSPECIFIED - - MUTATION_STATUS_PENDING - - MUTATION_STATUS_APPROVED - - MUTATION_STATUS_DENIED - - MUTATION_STATUS_EXECUTED - - MUTATION_STATUS_ROLLED_BACK - description: MutationStatus describes the status of a mutation operation. - objectives.v1.ObjectiveState: - type: string - title: ObjectiveState - enum: - - OBJECTIVE_STATE_UNSPECIFIED - - OBJECTIVE_STATE_PENDING - - OBJECTIVE_STATE_RUNNING - - OBJECTIVE_STATE_BLOCKED - - OBJECTIVE_STATE_DEGRADED - - OBJECTIVE_STATE_AWAITING_APPROVAL - - OBJECTIVE_STATE_QUEUED - - OBJECTIVE_STATE_COMPLETED - - OBJECTIVE_STATE_FAILED - - OBJECTIVE_STATE_CANCELLED - description: ObjectiveState describes the lifecycle state of an objective. - objectives.v1.TurnKind: - type: string - title: TurnKind - enum: - - TURN_KIND_UNSPECIFIED - - TURN_KIND_USER_MESSAGE - - TURN_KIND_LLM_CALL - - TURN_KIND_TOOL_CALL - - TURN_KIND_APPROVAL_WAIT - - TURN_KIND_SLEEP - - TURN_KIND_EVENT_WAIT - description: TurnKind identifies the durable work represented by an objective turn. - objectives.v1.TurnStatus: - type: string - title: TurnStatus - enum: - - TURN_STATUS_UNSPECIFIED - - TURN_STATUS_PENDING - - TURN_STATUS_RUNNING - - TURN_STATUS_COMPLETED - - TURN_STATUS_FAILED - - TURN_STATUS_REPLAY - description: TurnStatus describes replayable execution state for a journaled turn. - google.protobuf.Any: - type: object - properties: - type: - type: string - value: - type: string - format: binary - debug: - type: object - additionalProperties: true - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. - google.protobuf.Timestamp: - type: string - examples: - - 1s - - 1.000340012s - format: date-time - description: |- - A Timestamp represents a point in time independent of any time zone or local - calendar, encoded as a count of seconds and fractions of seconds at - nanosecond resolution. The count is relative to an epoch at UTC midnight on - January 1, 1970, in the proleptic Gregorian calendar which extends the - Gregorian calendar backwards to year one. - - All minutes are 60 seconds long. Leap seconds are "smeared" so that no leap - second table is needed for interpretation, using a [24-hour linear - smear](https://developers.google.com/time/smear). - - The range is from 0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z. By - restricting to that range, we ensure that we can convert to and from [RFC - 3339](https://www.ietf.org/rfc/rfc3339.txt) date strings. - - # Examples - - Example 1: Compute Timestamp from POSIX `time()`. - - Timestamp timestamp; - timestamp.set_seconds(time(NULL)); - timestamp.set_nanos(0); - - Example 2: Compute Timestamp from POSIX `gettimeofday()`. - - struct timeval tv; - gettimeofday(&tv, NULL); - - Timestamp timestamp; - timestamp.set_seconds(tv.tv_sec); - timestamp.set_nanos(tv.tv_usec * 1000); - - Example 3: Compute Timestamp from Win32 `GetSystemTimeAsFileTime()`. - - FILETIME ft; - GetSystemTimeAsFileTime(&ft); - UINT64 ticks = (((UINT64)ft.dwHighDateTime) << 32) | ft.dwLowDateTime; - - // A Windows tick is 100 nanoseconds. Windows epoch 1601-01-01T00:00:00Z - // is 11644473600 seconds before Unix epoch 1970-01-01T00:00:00Z. - Timestamp timestamp; - timestamp.set_seconds((INT64) ((ticks / 10000000) - 11644473600LL)); - timestamp.set_nanos((INT32) ((ticks % 10000000) * 100)); - - Example 4: Compute Timestamp from Java `System.currentTimeMillis()`. - - long millis = System.currentTimeMillis(); - - Timestamp timestamp = Timestamp.newBuilder().setSeconds(millis / 1000) - .setNanos((int) ((millis % 1000) * 1000000)).build(); - - Example 5: Compute Timestamp from Java `Instant.now()`. - - Instant now = Instant.now(); - - Timestamp timestamp = - Timestamp.newBuilder().setSeconds(now.getEpochSecond()) - .setNanos(now.getNano()).build(); - - Example 6: Compute Timestamp from current time in Python. - - timestamp = Timestamp() - timestamp.GetCurrentTime() - - # JSON Mapping - - In JSON format, the Timestamp type is encoded as a string in the - [RFC 3339](https://www.ietf.org/rfc/rfc3339.txt) format. That is, the - format is "{year}-{month}-{day}T{hour}:{min}:{sec}[.{frac_sec}]Z" - where {year} is always expressed using four digits while {month}, {day}, - {hour}, {min}, and {sec} are zero-padded to two digits each. The fractional - seconds, which can go up to 9 digits (i.e. up to 1 nanosecond resolution), - are optional. The "Z" suffix indicates the timezone ("UTC"); the timezone - is required. A proto3 JSON serializer should always use UTC (as indicated by - "Z") when printing the Timestamp type and a proto3 JSON parser should be - able to accept both UTC and other timezones (as indicated by an offset). - - For example, "2017-01-15T01:30:15.01Z" encodes 15.01 seconds past - 01:30 UTC on January 15, 2017. - - In JavaScript, one can convert a Date object to this format using the - standard - [toISOString()](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Date/toISOString) - method. In Python, a standard `datetime.datetime` object can be converted - to this format using - [`strftime`](https://docs.python.org/2/library/time.html#time.strftime) with - the time format spec '%Y-%m-%dT%H:%M:%S.%fZ'. Likewise, in Java, one can use - the Joda Time's [`ISODateTimeFormat.dateTime()`]( - http://joda-time.sourceforge.net/apidocs/org/joda/time/format/ISODateTimeFormat.html#dateTime() - ) to obtain a formatter capable of generating timestamps in this format. - objectives.v1.AppendTurnRequest: - type: object - properties: - objectiveId: - type: string - title: objective_id - minLength: 1 - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/objectives.v1.TurnKind' - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Any' - idempotencyKey: - type: string - title: idempotency_key - sequence: - type: integer - title: sequence - format: int32 - result: - title: result - $ref: '#/components/schemas/google.protobuf.Any' - status: - title: status - $ref: '#/components/schemas/objectives.v1.TurnStatus' - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - title: AppendTurnRequest - additionalProperties: false - objectives.v1.AppendTurnResponse: - type: object - properties: - turn: - title: turn - $ref: '#/components/schemas/objectives.v1.Turn' - replayed: - type: boolean - title: replayed - title: AppendTurnResponse - additionalProperties: false - objectives.v1.CancelRequest: - type: object - properties: - id: - type: string - title: id - minLength: 1 - reason: - type: string - title: reason - title: CancelRequest - additionalProperties: false - objectives.v1.CancelResponse: - type: object - properties: - objective: - title: objective - $ref: '#/components/schemas/objectives.v1.Objective' - title: CancelResponse - additionalProperties: false - objectives.v1.CreateRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - agentId: - type: string - title: agent_id - surface: - type: string - title: surface - title: - type: string - title: title - minLength: 1 - description: - type: string - title: description - surfaceType: - title: surface_type - $ref: '#/components/schemas/common.v1.Surface' - idempotencyKey: - type: string - title: idempotency_key - provenance: - type: array - items: - $ref: '#/components/schemas/objectives.v1.ProvenanceRecord' - title: provenance - organizationId: - type: string - title: organization_id - title: CreateRequest - additionalProperties: false - objectives.v1.CreateResponse: - type: object - properties: - objective: - title: objective - $ref: '#/components/schemas/objectives.v1.Objective' - title: CreateResponse - additionalProperties: false - objectives.v1.GetGovernanceEvaluationRequest: - type: object - properties: - objectiveId: - type: string - title: objective_id - minLength: 1 - title: GetGovernanceEvaluationRequest - additionalProperties: false - objectives.v1.GetGovernanceEvaluationResponse: - type: object - properties: - objectiveId: - type: string - title: objective_id - compliant: - type: boolean - title: compliant - violations: - type: array - items: - type: string - title: violations - title: GetGovernanceEvaluationResponse - additionalProperties: false - objectives.v1.GetRequest: - type: object - properties: - id: - type: string - title: id - minLength: 1 - title: GetRequest - additionalProperties: false - objectives.v1.GetResponse: - type: object - properties: - objective: - title: objective - $ref: '#/components/schemas/objectives.v1.Objective' - title: GetResponse - additionalProperties: false - objectives.v1.ListTurnsRequest: - type: object - properties: - objectiveId: - type: string - title: objective_id - minLength: 1 - limit: - type: integer - title: limit - maximum: 200 - format: int32 - offset: - type: integer - title: offset - format: int32 - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - title: ListTurnsRequest - additionalProperties: false - objectives.v1.ListTurnsResponse: - type: object - properties: - turns: - type: array - items: - $ref: '#/components/schemas/objectives.v1.Turn' - title: turns - total: - type: integer - title: total - format: int32 - title: ListTurnsResponse - additionalProperties: false - objectives.v1.MutationRecord: - type: object - properties: - targetIntegration: - type: string - title: target_integration - operation: - type: string - title: operation - status: - title: status - $ref: '#/components/schemas/objectives.v1.MutationStatus' - approvalId: - type: string - title: approval_id - title: MutationRecord - additionalProperties: false - description: MutationRecord tracks a write operation performed by an objective. - objectives.v1.Objective: - type: object - properties: - id: - type: string - title: id - workspaceId: - type: string - title: workspace_id - agentId: - type: string - title: agent_id - surface: - type: string - title: surface - title: - type: string - title: title - description: - type: string - title: description - state: - title: state - $ref: '#/components/schemas/objectives.v1.ObjectiveState' - provenance: - type: array - items: - $ref: '#/components/schemas/objectives.v1.ProvenanceRecord' - title: provenance - mutations: - type: array - items: - $ref: '#/components/schemas/objectives.v1.MutationRecord' - title: mutations - wakeSchedule: - title: wake_schedule - $ref: '#/components/schemas/objectives.v1.WakeSchedule' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - surfaceType: - title: surface_type - $ref: '#/components/schemas/common.v1.Surface' - idempotencyKey: - type: string - title: idempotency_key - organizationId: - type: string - title: organization_id - title: Objective - additionalProperties: false - description: Objective is the canonical agent objective record. - objectives.v1.ObjectiveTurn: - type: object - properties: - objective: - title: objective - $ref: '#/components/schemas/objectives.v1.Objective' - turn: - title: turn - $ref: '#/components/schemas/objectives.v1.Turn' - title: ObjectiveTurn - additionalProperties: false - objectives.v1.ProvenanceRecord: - type: object - properties: - sourceIntegration: - type: string - title: source_integration - sourceId: - type: string - title: source_id - freshnessSeconds: - type: integer - title: freshness_seconds - format: int32 - confidence: - type: number - title: confidence - format: float - title: ProvenanceRecord - additionalProperties: false - description: ProvenanceRecord tracks where data came from. - objectives.v1.QueryRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - agentId: - type: string - title: agent_id - state: - title: state - $ref: '#/components/schemas/objectives.v1.ObjectiveState' - limit: - type: integer - title: limit - maximum: 200 - format: int32 - offset: - type: integer - title: offset - format: int32 - organizationId: - type: string - title: organization_id - title: QueryRequest - additionalProperties: false - objectives.v1.QueryResponse: - type: object - properties: - objectives: - type: array - items: - $ref: '#/components/schemas/objectives.v1.Objective' - title: objectives - total: - type: integer - title: total - format: int32 - title: QueryResponse - additionalProperties: false - objectives.v1.QueryTurnsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - minLength: 1 - agentId: - type: string - title: agent_id - limit: - type: integer - title: limit - maximum: 200 - format: int32 - offset: - type: integer - title: offset - format: int32 - payloadChannelId: - type: string - title: payload_channel_id - omitTotal: - type: boolean - title: omit_total - title: QueryTurnsRequest - additionalProperties: false - objectives.v1.QueryTurnsResponse: - type: object - properties: - turns: - type: array - items: - $ref: '#/components/schemas/objectives.v1.ObjectiveTurn' - title: turns - total: - type: integer - title: total - format: int32 - title: QueryTurnsResponse - additionalProperties: false - objectives.v1.RecordMutationRequest: - type: object - properties: - objectiveId: - type: string - title: objective_id - minLength: 1 - mutation: - title: mutation - $ref: '#/components/schemas/objectives.v1.MutationRecord' - title: RecordMutationRequest - required: - - mutation - additionalProperties: false - objectives.v1.RecordMutationResponse: - type: object - properties: - objective: - title: objective - $ref: '#/components/schemas/objectives.v1.Objective' - title: RecordMutationResponse - additionalProperties: false - objectives.v1.RecordProvenanceRequest: - type: object - properties: - objectiveId: - type: string - title: objective_id - minLength: 1 - provenance: - title: provenance - $ref: '#/components/schemas/objectives.v1.ProvenanceRecord' - title: RecordProvenanceRequest - required: - - provenance - additionalProperties: false - objectives.v1.RecordProvenanceResponse: - type: object - properties: - objective: - title: objective - $ref: '#/components/schemas/objectives.v1.Objective' - title: RecordProvenanceResponse - additionalProperties: false - objectives.v1.RunStepRequest: - type: object - properties: - objectiveId: - type: string - title: objective_id - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/objectives.v1.TurnKind' - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Any' - result: - title: result - $ref: '#/components/schemas/google.protobuf.Any' - title: RunStepRequest - additionalProperties: false - objectives.v1.RunStepResponse: - type: object - properties: - turn: - title: turn - $ref: '#/components/schemas/objectives.v1.Turn' - replayed: - type: boolean - title: replayed - title: RunStepResponse - additionalProperties: false - objectives.v1.ScheduleWakeRequest: - type: object - properties: - id: - type: string - title: id - minLength: 1 - wakeSchedule: - title: wake_schedule - $ref: '#/components/schemas/objectives.v1.WakeSchedule' - state: - title: state - description: State to hold until wake_at is due. If unspecified, the service uses BLOCKED. - $ref: '#/components/schemas/objectives.v1.ObjectiveState' - title: ScheduleWakeRequest - required: - - wakeSchedule - additionalProperties: false - objectives.v1.ScheduleWakeResponse: - type: object - properties: - objective: - title: objective - $ref: '#/components/schemas/objectives.v1.Objective' - title: ScheduleWakeResponse - additionalProperties: false - objectives.v1.TransitionRequest: - type: object - properties: - id: - type: string - title: id - minLength: 1 - state: - not: - enum: - - 0 - title: state - $ref: '#/components/schemas/objectives.v1.ObjectiveState' - reason: - type: string - title: reason - title: TransitionRequest - additionalProperties: false - objectives.v1.TransitionResponse: - type: object - properties: - objective: - title: objective - $ref: '#/components/schemas/objectives.v1.Objective' - title: TransitionResponse - additionalProperties: false - objectives.v1.Turn: - type: object - properties: - id: - type: string - title: id - objectiveId: - type: string - title: objective_id - sequence: - type: integer - title: sequence - format: int32 - kind: - title: kind - $ref: '#/components/schemas/objectives.v1.TurnKind' - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Any' - result: - title: result - $ref: '#/components/schemas/google.protobuf.Any' - status: - title: status - $ref: '#/components/schemas/objectives.v1.TurnStatus' - startedAt: - title: started_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - completedAt: - title: completed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - idempotencyKey: - type: string - title: idempotency_key - title: Turn - additionalProperties: false - description: Turn is the per-objective replay journal used by agent sessions. - objectives.v1.WaitForEventPayload: - type: object - properties: - eventSubject: - type: string - title: event_subject - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Any' - title: WaitForEventPayload - additionalProperties: false - objectives.v1.WaitForEventRequest: - type: object - properties: - objectiveId: - type: string - title: objective_id - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - eventSubject: - type: string - title: event_subject - minLength: 1 - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Any' - title: WaitForEventRequest - additionalProperties: false - objectives.v1.WaitForEventResponse: - type: object - properties: - turn: - title: turn - $ref: '#/components/schemas/objectives.v1.Turn' - replayed: - type: boolean - title: replayed - title: WaitForEventResponse - additionalProperties: false - objectives.v1.WakeRequest: - type: object - properties: - id: - type: string - title: id - minLength: 1 - title: WakeRequest - additionalProperties: false - objectives.v1.WakeResponse: - type: object - properties: - objective: - title: objective - $ref: '#/components/schemas/objectives.v1.Objective' - title: WakeResponse - additionalProperties: false - objectives.v1.WakeSchedule: - type: object - properties: - wakeAt: - title: wake_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - reason: - type: string - title: reason - retryCount: - type: integer - title: retry_count - format: int32 - maxRetries: - type: integer - title: max_retries - format: int32 - backoffSeconds: - type: integer - title: backoff_seconds - format: int32 - title: WakeSchedule - additionalProperties: false - description: WakeSchedule defines when and how an objective should be reactivated. - connect-protocol-version: - type: number - title: Connect-Protocol-Version - enum: - - 1 - description: Define the version of the Connect protocol - const: 1 - connect-timeout-header: - type: number - title: Connect-Timeout-Ms - description: Define the timeout, in ms - connect.error: - type: object - properties: - code: - type: string - examples: - - not_found - enum: - - canceled - - unknown - - invalid_argument - - deadline_exceeded - - not_found - - already_exists - - permission_denied - - resource_exhausted - - failed_precondition - - aborted - - out_of_range - - unimplemented - - internal - - unavailable - - data_loss - - unauthenticated - description: The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code]. - message: - type: string - description: A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client. - detail: - $ref: '#/components/schemas/google.protobuf.Any' - title: Connect Error - additionalProperties: true - description: 'Error type returned by Connect: https://connectrpc.com/docs/go/errors/#http-representation' -security: [] -tags: - - name: objectives.v1.ObjectiveService - description: ObjectiveService manages agent objectives and their lifecycle. diff --git a/openapi/orbcontrol/v1/orb_control.openapi.yaml b/openapi/orbcontrol/v1/orb_control.openapi.yaml deleted file mode 100644 index 08d2bf5..0000000 --- a/openapi/orbcontrol/v1/orb_control.openapi.yaml +++ /dev/null @@ -1,574 +0,0 @@ -openapi: 3.1.0 -info: - title: orbcontrol.v1 -paths: - /orbcontrol.v1.OrbControlOwnerService/SubmitOrbCommand: - post: - tags: - - orbcontrol.v1.OrbControlOwnerService - summary: SubmitOrbCommand - description: SubmitOrbCommand accepts or replays one exact lifecycle command. - operationId: orbcontrol.v1.OrbControlOwnerService.SubmitOrbCommand - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/orbcontrol.v1.SubmitOrbCommandRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/orbcontrol.v1.SubmitOrbCommandResponse' - /orbcontrol.v1.OrbControlOwnerService/GetOrbObservedState: - post: - tags: - - orbcontrol.v1.OrbControlOwnerService - summary: GetOrbObservedState - description: GetOrbObservedState returns the runtime owner's current fenced projection. - operationId: orbcontrol.v1.OrbControlOwnerService.GetOrbObservedState - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/orbcontrol.v1.GetOrbObservedStateRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/orbcontrol.v1.GetOrbObservedStateResponse' - /orbcontrol.v1.OrbControlOwnerService/StreamOrbEvents: - post: - tags: - - orbcontrol.v1.OrbControlOwnerService - summary: StreamOrbEvents - description: StreamOrbEvents returns a bounded page from the tenant-wide durable cursor. - operationId: orbcontrol.v1.OrbControlOwnerService.StreamOrbEvents - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/orbcontrol.v1.StreamOrbEventsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/orbcontrol.v1.StreamOrbEventsResponse' -components: - schemas: - orbcontrol.v1.OrbCommandAcceptance: - type: string - title: OrbCommandAcceptance - enum: - - ORB_COMMAND_ACCEPTANCE_UNSPECIFIED - - ORB_COMMAND_ACCEPTANCE_ACCEPTED - - ORB_COMMAND_ACCEPTANCE_REPLAYED - - ORB_COMMAND_ACCEPTANCE_REJECTED - description: OrbCommandAcceptance distinguishes a new acceptance from an exact replay. - orbcontrol.v1.OrbCommandKind: - type: string - title: OrbCommandKind - enum: - - ORB_COMMAND_KIND_UNSPECIFIED - - ORB_COMMAND_KIND_WAKE - - ORB_COMMAND_KIND_STOP - description: OrbCommandKind is the first supported Platform-owned lifecycle command set. - orbcontrol.v1.OrbControlEventKind: - type: string - title: OrbControlEventKind - enum: - - ORB_CONTROL_EVENT_KIND_UNSPECIFIED - - ORB_CONTROL_EVENT_KIND_SNAPSHOT - - ORB_CONTROL_EVENT_KIND_COMMAND_ACCEPTED - - ORB_CONTROL_EVENT_KIND_LIFECYCLE_CHANGED - - ORB_CONTROL_EVENT_KIND_COMMAND_COMPLETED - - ORB_CONTROL_EVENT_KIND_COMMAND_FAILED - description: OrbControlEventKind identifies durable owner observations. - orbcontrol.v1.OrbObservedLifecycle: - type: string - title: OrbObservedLifecycle - enum: - - ORB_OBSERVED_LIFECYCLE_UNSPECIFIED - - ORB_OBSERVED_LIFECYCLE_SLEEPING - - ORB_OBSERVED_LIFECYCLE_WAKING - - ORB_OBSERVED_LIFECYCLE_READY - - ORB_OBSERVED_LIFECYCLE_WORKING - - ORB_OBSERVED_LIFECYCLE_WAITING_FOR_YOU - - ORB_OBSERVED_LIFECYCLE_RECOVERING - - ORB_OBSERVED_LIFECYCLE_OFFLINE - description: OrbObservedLifecycle is the runtime owner's customer-safe lifecycle state. - google.protobuf.Timestamp: - type: string - examples: - - 1s - - 1.000340012s - format: date-time - description: |- - A Timestamp represents a point in time independent of any time zone or local - calendar, encoded as a count of seconds and fractions of seconds at - nanosecond resolution. The count is relative to an epoch at UTC midnight on - January 1, 1970, in the proleptic Gregorian calendar which extends the - Gregorian calendar backwards to year one. - - All minutes are 60 seconds long. Leap seconds are "smeared" so that no leap - second table is needed for interpretation, using a [24-hour linear - smear](https://developers.google.com/time/smear). - - The range is from 0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z. By - restricting to that range, we ensure that we can convert to and from [RFC - 3339](https://www.ietf.org/rfc/rfc3339.txt) date strings. - - # Examples - - Example 1: Compute Timestamp from POSIX `time()`. - - Timestamp timestamp; - timestamp.set_seconds(time(NULL)); - timestamp.set_nanos(0); - - Example 2: Compute Timestamp from POSIX `gettimeofday()`. - - struct timeval tv; - gettimeofday(&tv, NULL); - - Timestamp timestamp; - timestamp.set_seconds(tv.tv_sec); - timestamp.set_nanos(tv.tv_usec * 1000); - - Example 3: Compute Timestamp from Win32 `GetSystemTimeAsFileTime()`. - - FILETIME ft; - GetSystemTimeAsFileTime(&ft); - UINT64 ticks = (((UINT64)ft.dwHighDateTime) << 32) | ft.dwLowDateTime; - - // A Windows tick is 100 nanoseconds. Windows epoch 1601-01-01T00:00:00Z - // is 11644473600 seconds before Unix epoch 1970-01-01T00:00:00Z. - Timestamp timestamp; - timestamp.set_seconds((INT64) ((ticks / 10000000) - 11644473600LL)); - timestamp.set_nanos((INT32) ((ticks % 10000000) * 100)); - - Example 4: Compute Timestamp from Java `System.currentTimeMillis()`. - - long millis = System.currentTimeMillis(); - - Timestamp timestamp = Timestamp.newBuilder().setSeconds(millis / 1000) - .setNanos((int) ((millis % 1000) * 1000000)).build(); - - Example 5: Compute Timestamp from Java `Instant.now()`. - - Instant now = Instant.now(); - - Timestamp timestamp = - Timestamp.newBuilder().setSeconds(now.getEpochSecond()) - .setNanos(now.getNano()).build(); - - Example 6: Compute Timestamp from current time in Python. - - timestamp = Timestamp() - timestamp.GetCurrentTime() - - # JSON Mapping - - In JSON format, the Timestamp type is encoded as a string in the - [RFC 3339](https://www.ietf.org/rfc/rfc3339.txt) format. That is, the - format is "{year}-{month}-{day}T{hour}:{min}:{sec}[.{frac_sec}]Z" - where {year} is always expressed using four digits while {month}, {day}, - {hour}, {min}, and {sec} are zero-padded to two digits each. The fractional - seconds, which can go up to 9 digits (i.e. up to 1 nanosecond resolution), - are optional. The "Z" suffix indicates the timezone ("UTC"); the timezone - is required. A proto3 JSON serializer should always use UTC (as indicated by - "Z") when printing the Timestamp type and a proto3 JSON parser should be - able to accept both UTC and other timezones (as indicated by an offset). - - For example, "2017-01-15T01:30:15.01Z" encodes 15.01 seconds past - 01:30 UTC on January 15, 2017. - - In JavaScript, one can convert a Date object to this format using the - standard - [toISOString()](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Date/toISOString) - method. In Python, a standard `datetime.datetime` object can be converted - to this format using - [`strftime`](https://docs.python.org/2/library/time.html#time.strftime) with - the time format spec '%Y-%m-%dT%H:%M:%S.%fZ'. Likewise, in Java, one can use - the Joda Time's [`ISODateTimeFormat.dateTime()`]( - http://joda-time.sourceforge.net/apidocs/org/joda/time/format/ISODateTimeFormat.html#dateTime() - ) to obtain a formatter capable of generating timestamps in this format. - orbcontrol.v1.GetOrbObservedStateRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - targetId: - type: string - title: target_id - minLength: 1 - title: GetOrbObservedStateRequest - additionalProperties: false - description: GetOrbObservedStateRequest selects one tenant-scoped runtime target. - orbcontrol.v1.GetOrbObservedStateResponse: - type: object - properties: - state: - title: state - $ref: '#/components/schemas/orbcontrol.v1.OrbObservedState' - title: GetOrbObservedStateResponse - required: - - state - additionalProperties: false - description: GetOrbObservedStateResponse returns one authoritative runtime projection. - orbcontrol.v1.OrbCommand: - type: object - properties: - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/orbcontrol.v1.OrbCommandKind' - title: OrbCommand - additionalProperties: false - description: OrbCommand is the normalized mutation payload persisted by both planes. - orbcontrol.v1.OrbControlEvent: - type: object - properties: - sequence: - type: - - integer - - string - title: sequence - format: int64 - eventId: - type: string - title: event_id - targetId: - type: string - title: target_id - generation: - type: - - integer - - string - title: generation - format: int64 - observedRevision: - type: - - integer - - string - title: observed_revision - format: int64 - kind: - title: kind - $ref: '#/components/schemas/orbcontrol.v1.OrbControlEventKind' - state: - title: state - $ref: '#/components/schemas/orbcontrol.v1.OrbObservedState' - operationId: - type: string - title: operation_id - commandId: - type: string - title: command_id - reasonCode: - type: string - title: reason_code - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: OrbControlEvent - additionalProperties: false - description: OrbControlEvent is one workspace-ordered observed-state transition. - orbcontrol.v1.OrbObservedState: - type: object - properties: - targetId: - type: string - title: target_id - displayName: - type: string - title: display_name - lifecycle: - title: lifecycle - $ref: '#/components/schemas/orbcontrol.v1.OrbObservedLifecycle' - generation: - type: - - integer - - string - title: generation - format: int64 - observedRevision: - type: - - integer - - string - title: observed_revision - format: int64 - lastEventSequence: - type: - - integer - - string - title: last_event_sequence - format: int64 - residentAgent: - type: string - title: resident_agent - provisioner: - type: string - title: provisioner - activeOperationId: - type: string - title: active_operation_id - observedAt: - title: observed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: OrbObservedState - additionalProperties: false - description: OrbObservedState is the authoritative runtime projection for one target. - orbcontrol.v1.StreamOrbEventsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - afterSequence: - type: - - integer - - string - title: after_sequence - format: int64 - limit: - type: integer - title: limit - maximum: 500 - title: StreamOrbEventsRequest - additionalProperties: false - description: StreamOrbEventsRequest resumes a tenant-wide cursor after one sequence. - orbcontrol.v1.StreamOrbEventsResponse: - type: object - properties: - events: - type: array - items: - $ref: '#/components/schemas/orbcontrol.v1.OrbControlEvent' - title: events - maxItems: 500 - nextSequence: - type: - - integer - - string - title: next_sequence - format: int64 - hasMore: - type: boolean - title: has_more - title: StreamOrbEventsResponse - additionalProperties: false - description: StreamOrbEventsResponse is a bounded durable cursor page. - orbcontrol.v1.SubmitOrbCommandRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - targetId: - type: string - title: target_id - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - lineageId: - type: string - title: lineage_id - minLength: 1 - operationId: - type: string - title: operation_id - minLength: 1 - expectedGeneration: - type: - - integer - - string - title: expected_generation - format: int64 - command: - title: command - $ref: '#/components/schemas/orbcontrol.v1.OrbCommand' - title: SubmitOrbCommandRequest - required: - - command - additionalProperties: false - description: SubmitOrbCommandRequest carries one exact tenant-scoped owner command. - orbcontrol.v1.SubmitOrbCommandResponse: - type: object - properties: - acceptance: - title: acceptance - $ref: '#/components/schemas/orbcontrol.v1.OrbCommandAcceptance' - commandId: - type: string - title: command_id - operationId: - type: string - title: operation_id - idempotencyKey: - type: string - title: idempotency_key - acceptedGeneration: - type: - - integer - - string - title: accepted_generation - format: int64 - observedRevision: - type: - - integer - - string - title: observed_revision - format: int64 - eventSequence: - type: - - integer - - string - title: event_sequence - format: int64 - reasonCode: - type: string - title: reason_code - title: SubmitOrbCommandResponse - additionalProperties: false - description: SubmitOrbCommandResponse acknowledges ownership without claiming completion. - connect-protocol-version: - type: number - title: Connect-Protocol-Version - enum: - - 1 - description: Define the version of the Connect protocol - const: 1 - connect-timeout-header: - type: number - title: Connect-Timeout-Ms - description: Define the timeout, in ms - connect.error: - type: object - properties: - code: - type: string - examples: - - not_found - enum: - - canceled - - unknown - - invalid_argument - - deadline_exceeded - - not_found - - already_exists - - permission_denied - - resource_exhausted - - failed_precondition - - aborted - - out_of_range - - unimplemented - - internal - - unavailable - - data_loss - - unauthenticated - description: The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code]. - message: - type: string - description: A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client. - detail: - $ref: '#/components/schemas/google.protobuf.Any' - title: Connect Error - additionalProperties: true - description: 'Error type returned by Connect: https://connectrpc.com/docs/go/errors/#http-representation' - google.protobuf.Any: - type: object - properties: - type: - type: string - value: - type: string - format: binary - debug: - type: object - additionalProperties: true - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. -security: [] -tags: - - name: orbcontrol.v1.OrbControlOwnerService - description: |- - OrbControlOwnerService is the narrow Platform-to-Orb runtime-owner boundary. - Commands are idempotent and generation-fenced; completion is established by - observed state and ordered events rather than by submission acknowledgement. diff --git a/openapi/platform/v1/platform.openapi.yaml b/openapi/platform/v1/platform.openapi.yaml deleted file mode 100644 index f1d113c..0000000 --- a/openapi/platform/v1/platform.openapi.yaml +++ /dev/null @@ -1,2116 +0,0 @@ -openapi: 3.1.0 -info: - title: platform.v1 -paths: - /platform.v1.PlatformService/GetBootstrap: - post: - tags: - - platform.v1.PlatformService - summary: GetBootstrap - description: GetBootstrap returns tenant-scoped platform capabilities for the frontend. - operationId: platform.v1.PlatformService.GetBootstrap - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/platform.v1.GetBootstrapRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/platform.v1.GetBootstrapResponse' - /platform.v1.PlatformService/CreateWork: - post: - tags: - - platform.v1.PlatformService - summary: CreateWork - description: CreateWork creates a stateful work owner record through an operation record. - operationId: platform.v1.PlatformService.CreateWork - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/platform.v1.CreateWorkRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/platform.v1.CreateWorkResponse' - /platform.v1.PlatformService/ProposeAction: - post: - tags: - - platform.v1.PlatformService - summary: ProposeAction - description: ProposeAction records an action intent even when execution is blocked. - operationId: platform.v1.PlatformService.ProposeAction - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/platform.v1.ProposeActionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/platform.v1.ProposeActionResponse' - /platform.v1.PlatformService/CreateArtifact: - post: - tags: - - platform.v1.PlatformService - summary: CreateArtifact - description: CreateArtifact creates a versioned artifact through an operation record. - operationId: platform.v1.PlatformService.CreateArtifact - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/platform.v1.CreateArtifactRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/platform.v1.CreateArtifactResponse' - /platform.v1.PlatformService/RecordEvidence: - post: - tags: - - platform.v1.PlatformService - summary: RecordEvidence - description: RecordEvidence records audit, trace, usage, attestation, replay, or lineage evidence. - operationId: platform.v1.PlatformService.RecordEvidence - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/platform.v1.RecordEvidenceRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/platform.v1.RecordEvidenceResponse' - /platform.v1.PlatformService/RecordScore: - post: - tags: - - platform.v1.PlatformService - summary: RecordScore - description: RecordScore records a queryable eval score on the same operation spine. - operationId: platform.v1.PlatformService.RecordScore - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/platform.v1.RecordScoreRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/platform.v1.RecordScoreResponse' - /platform.v1.PlatformService/ApplyRecommendation: - post: - tags: - - platform.v1.PlatformService - summary: ApplyRecommendation - description: ApplyRecommendation closes the eval loop by recording a rollout decision. - operationId: platform.v1.PlatformService.ApplyRecommendation - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/platform.v1.ApplyRecommendationRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/platform.v1.ApplyRecommendationResponse' -components: - schemas: - google.protobuf.NullValue: - type: string - title: NullValue - enum: - - NULL_VALUE - description: |- - `NullValue` is a singleton enumeration to represent the null value for the - `Value` type union. - - The JSON representation for `NullValue` is JSON `null`. - platform.v1.ActionExecutionState: - type: string - title: ActionExecutionState - enum: - - ACTION_EXECUTION_STATE_UNSPECIFIED - - ACTION_EXECUTION_STATE_PROPOSED - - ACTION_EXECUTION_STATE_APPROVED - - ACTION_EXECUTION_STATE_BLOCKED - - ACTION_EXECUTION_STATE_EXECUTING - - ACTION_EXECUTION_STATE_SUCCEEDED - - ACTION_EXECUTION_STATE_FAILED - - ACTION_EXECUTION_STATE_CANCELLED - platform.v1.ApprovalState: - type: string - title: ApprovalState - enum: - - APPROVAL_STATE_UNSPECIFIED - - APPROVAL_STATE_NOT_REQUIRED - - APPROVAL_STATE_REQUIRED - - APPROVAL_STATE_RESOLVED - - APPROVAL_STATE_DENIED - - APPROVAL_STATE_EXPIRED - platform.v1.ArtifactKind: - type: string - title: ArtifactKind - enum: - - ARTIFACT_KIND_UNSPECIFIED - - ARTIFACT_KIND_PROMPT - - ARTIFACT_KIND_SKILL - - ARTIFACT_KIND_AGENT_CONFIG - - ARTIFACT_KIND_EVAL_SUITE - - ARTIFACT_KIND_SCENARIO - - ARTIFACT_KIND_GENERATED_FILE - - ARTIFACT_KIND_CONTEXT_ITEM - - ARTIFACT_KIND_VFS_OBJECT - - ARTIFACT_KIND_MODEL_ROUTE - platform.v1.ArtifactState: - type: string - title: ArtifactState - enum: - - ARTIFACT_STATE_UNSPECIFIED - - ARTIFACT_STATE_DRAFT - - ARTIFACT_STATE_ACTIVE - - ARTIFACT_STATE_DEPRECATED - - ARTIFACT_STATE_ARCHIVED - platform.v1.AttributionSubjectKind: - type: string - title: AttributionSubjectKind - enum: - - ATTRIBUTION_SUBJECT_KIND_UNSPECIFIED - - ATTRIBUTION_SUBJECT_KIND_TENANT - - ATTRIBUTION_SUBJECT_KIND_PRINCIPAL - - ATTRIBUTION_SUBJECT_KIND_ACTION_INTENT - - ATTRIBUTION_SUBJECT_KIND_WORK_ITEM - - ATTRIBUTION_SUBJECT_KIND_ARTIFACT_VERSION - - ATTRIBUTION_SUBJECT_KIND_RESOURCE - - ATTRIBUTION_SUBJECT_KIND_TRACE_SPAN - - ATTRIBUTION_SUBJECT_KIND_USAGE_ENTRY - - ATTRIBUTION_SUBJECT_KIND_SPEND_ENTRY - - ATTRIBUTION_SUBJECT_KIND_COST_CENTER - platform.v1.AuthorityDecisionKind: - type: string - title: AuthorityDecisionKind - enum: - - AUTHORITY_DECISION_KIND_UNSPECIFIED - - AUTHORITY_DECISION_KIND_ALLOW - - AUTHORITY_DECISION_KIND_DENY - - AUTHORITY_DECISION_KIND_REQUIRE_APPROVAL - - AUTHORITY_DECISION_KIND_APPROVAL_RESOLVED - - AUTHORITY_DECISION_KIND_GRANT_EXPIRED - - AUTHORITY_DECISION_KIND_DELEGATION_NARROWED - platform.v1.CapabilityStatus: - type: string - title: CapabilityStatus - enum: - - CAPABILITY_STATUS_UNSPECIFIED - - CAPABILITY_STATUS_AVAILABLE - - CAPABILITY_STATUS_UNAVAILABLE - platform.v1.EvidenceKind: - type: string - title: EvidenceKind - enum: - - EVIDENCE_KIND_UNSPECIFIED - - EVIDENCE_KIND_AUDIT_EVENT - - EVIDENCE_KIND_TRACE_SPAN - - EVIDENCE_KIND_USAGE - - EVIDENCE_KIND_ATTESTATION - - EVIDENCE_KIND_REPLAY_BUNDLE - - EVIDENCE_KIND_LINEAGE - - EVIDENCE_KIND_SCORE - platform.v1.OutboxStatus: - type: string - title: OutboxStatus - enum: - - OUTBOX_STATUS_UNSPECIFIED - - OUTBOX_STATUS_PENDING - - OUTBOX_STATUS_PUBLISHED - - OUTBOX_STATUS_FAILED - platform.v1.PolicyKind: - type: string - title: PolicyKind - enum: - - POLICY_KIND_UNSPECIFIED - - POLICY_KIND_AUTHORITY - - POLICY_KIND_CREDENTIAL - - POLICY_KIND_SOURCE_OF_TRUTH - - POLICY_KIND_LIFECYCLE - - POLICY_KIND_BILLING - platform.v1.PrincipalKind: - type: string - title: PrincipalKind - enum: - - PRINCIPAL_KIND_UNSPECIFIED - - PRINCIPAL_KIND_HUMAN - - PRINCIPAL_KIND_SERVICE_ACCOUNT - - PRINCIPAL_KIND_AGENT - - PRINCIPAL_KIND_DEVICE - - PRINCIPAL_KIND_WORKLOAD - platform.v1.RecommendationKind: - type: string - title: RecommendationKind - enum: - - RECOMMENDATION_KIND_UNSPECIFIED - - RECOMMENDATION_KIND_PROMOTE_CANDIDATE - - RECOMMENDATION_KIND_ROLLBACK - - RECOMMENDATION_KIND_REWEIGHT - - RECOMMENDATION_KIND_HOLD - platform.v1.RecommendationState: - type: string - title: RecommendationState - enum: - - RECOMMENDATION_STATE_UNSPECIFIED - - RECOMMENDATION_STATE_PROPOSED - - RECOMMENDATION_STATE_APPLIED - - RECOMMENDATION_STATE_REJECTED - platform.v1.RecordKind: - type: string - title: RecordKind - enum: - - RECORD_KIND_UNSPECIFIED - - RECORD_KIND_RUN - - RECORD_KIND_MODEL_RUN - - RECORD_KIND_TOOL_EXECUTION - - RECORD_KIND_POLICY_DECISION - - RECORD_KIND_APPROVAL - - RECORD_KIND_CREDENTIAL - - RECORD_KIND_CONNECTOR - - RECORD_KIND_CONNECTOR_SESSION - - RECORD_KIND_ARTIFACT - - RECORD_KIND_USAGE - - RECORD_KIND_RECEIPT - - RECORD_KIND_EVIDENCE - - RECORD_KIND_EVAL_RUN - description: |- - RecordKind identifies an authoritative operational record without copying - that record into a read model. The enclosing request supplies exact tenant - authority; the kind selects the owner resolver for record_id. - platform.v1.ResourceKind: - type: string - title: ResourceKind - enum: - - RESOURCE_KIND_UNSPECIFIED - - RESOURCE_KIND_AGENT - - RESOURCE_KIND_TOOL - - RESOURCE_KIND_REPO - - RESOURCE_KIND_DATASET - - RESOURCE_KIND_DATABASE - - RESOURCE_KIND_CRM_OBJECT - - RESOURCE_KIND_MODEL_ROUTE - - RESOURCE_KIND_EXTERNAL - - RESOURCE_KIND_VFS_OBJECT - - RESOURCE_KIND_VFS_OBJECT_VERSION - - RESOURCE_KIND_ARTIFACT - - RESOURCE_KIND_ARTIFACT_VERSION - - RESOURCE_KIND_GENERATED_ASSET - platform.v1.RiskTier: - type: string - title: RiskTier - enum: - - RISK_TIER_UNSPECIFIED - - RISK_TIER_LOW - - RISK_TIER_MEDIUM - - RISK_TIER_HIGH - - RISK_TIER_CRITICAL - platform.v1.UsageMetricKind: - type: string - title: UsageMetricKind - enum: - - USAGE_METRIC_KIND_UNSPECIFIED - - USAGE_METRIC_KIND_INPUT_TOKEN - - USAGE_METRIC_KIND_OUTPUT_TOKEN - - USAGE_METRIC_KIND_CACHED_INPUT_TOKEN - - USAGE_METRIC_KIND_TOOL_CALL - - USAGE_METRIC_KIND_RUNNER_SECOND - - USAGE_METRIC_KIND_STORAGE_BYTE_HOUR - - USAGE_METRIC_KIND_NETWORK_BYTE - - USAGE_METRIC_KIND_CUSTOM - platform.v1.WorkKind: - type: string - title: WorkKind - enum: - - WORK_KIND_UNSPECIFIED - - WORK_KIND_OBJECTIVE - - WORK_KIND_WORKFLOW - - WORK_KIND_AGENT_RUN - - WORK_KIND_STEP - - WORK_KIND_WAIT - - WORK_KIND_RETRY - - WORK_KIND_TOOL_EXECUTION - - WORK_KIND_RUNNER_SESSION - - WORK_KIND_EVAL_RUN - - WORK_KIND_COMPUTER_MISSION - - WORK_KIND_ARTIFACT_RENDER - platform.v1.WorkRemediationClassification: - type: string - title: WorkRemediationClassification - enum: - - WORK_REMEDIATION_CLASSIFICATION_UNSPECIFIED - - WORK_REMEDIATION_CLASSIFICATION_AUTO_EXECUTABLE - - WORK_REMEDIATION_CLASSIFICATION_APPROVAL_EXECUTABLE - - WORK_REMEDIATION_CLASSIFICATION_MANUAL_WORK - - WORK_REMEDIATION_CLASSIFICATION_BLOCKED - platform.v1.WorkRemediationEvidenceIndependence: - type: string - title: WorkRemediationEvidenceIndependence - enum: - - WORK_REMEDIATION_EVIDENCE_INDEPENDENCE_UNSPECIFIED - - WORK_REMEDIATION_EVIDENCE_INDEPENDENCE_ACTION_OUTPUT - - WORK_REMEDIATION_EVIDENCE_INDEPENDENCE_INDEPENDENT_OBSERVATION - platform.v1.WorkState: - type: string - title: WorkState - enum: - - WORK_STATE_UNSPECIFIED - - WORK_STATE_PROPOSED - - WORK_STATE_QUEUED - - WORK_STATE_RUNNING - - WORK_STATE_WAITING - - WORK_STATE_SUCCEEDED - - WORK_STATE_FAILED - - WORK_STATE_CANCELLED - google.protobuf.ListValue: - type: object - properties: - values: - type: array - items: - $ref: '#/components/schemas/google.protobuf.Value' - title: values - description: Repeated field of dynamically typed values. - title: ListValue - additionalProperties: false - description: |- - `ListValue` is a wrapper around a repeated field of values. - - The JSON representation for `ListValue` is JSON array. - google.protobuf.Struct: - type: object - additionalProperties: - $ref: '#/components/schemas/google.protobuf.Value' - description: |- - `Struct` represents a structured data value, consisting of fields - which map to dynamically typed values. In some languages, `Struct` - might be supported by a native representation. For example, in - scripting languages like JS a struct is represented as an - object. The details of that representation are described together - with the proto support for the language. - - The JSON representation for `Struct` is JSON object. - google.protobuf.Struct.FieldsEntry: - type: object - properties: - key: - type: string - title: key - value: - title: value - $ref: '#/components/schemas/google.protobuf.Value' - title: FieldsEntry - additionalProperties: false - google.protobuf.Timestamp: - type: string - examples: - - 1s - - 1.000340012s - format: date-time - description: |- - A Timestamp represents a point in time independent of any time zone or local - calendar, encoded as a count of seconds and fractions of seconds at - nanosecond resolution. The count is relative to an epoch at UTC midnight on - January 1, 1970, in the proleptic Gregorian calendar which extends the - Gregorian calendar backwards to year one. - - All minutes are 60 seconds long. Leap seconds are "smeared" so that no leap - second table is needed for interpretation, using a [24-hour linear - smear](https://developers.google.com/time/smear). - - The range is from 0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z. By - restricting to that range, we ensure that we can convert to and from [RFC - 3339](https://www.ietf.org/rfc/rfc3339.txt) date strings. - - # Examples - - Example 1: Compute Timestamp from POSIX `time()`. - - Timestamp timestamp; - timestamp.set_seconds(time(NULL)); - timestamp.set_nanos(0); - - Example 2: Compute Timestamp from POSIX `gettimeofday()`. - - struct timeval tv; - gettimeofday(&tv, NULL); - - Timestamp timestamp; - timestamp.set_seconds(tv.tv_sec); - timestamp.set_nanos(tv.tv_usec * 1000); - - Example 3: Compute Timestamp from Win32 `GetSystemTimeAsFileTime()`. - - FILETIME ft; - GetSystemTimeAsFileTime(&ft); - UINT64 ticks = (((UINT64)ft.dwHighDateTime) << 32) | ft.dwLowDateTime; - - // A Windows tick is 100 nanoseconds. Windows epoch 1601-01-01T00:00:00Z - // is 11644473600 seconds before Unix epoch 1970-01-01T00:00:00Z. - Timestamp timestamp; - timestamp.set_seconds((INT64) ((ticks / 10000000) - 11644473600LL)); - timestamp.set_nanos((INT32) ((ticks % 10000000) * 100)); - - Example 4: Compute Timestamp from Java `System.currentTimeMillis()`. - - long millis = System.currentTimeMillis(); - - Timestamp timestamp = Timestamp.newBuilder().setSeconds(millis / 1000) - .setNanos((int) ((millis % 1000) * 1000000)).build(); - - Example 5: Compute Timestamp from Java `Instant.now()`. - - Instant now = Instant.now(); - - Timestamp timestamp = - Timestamp.newBuilder().setSeconds(now.getEpochSecond()) - .setNanos(now.getNano()).build(); - - Example 6: Compute Timestamp from current time in Python. - - timestamp = Timestamp() - timestamp.GetCurrentTime() - - # JSON Mapping - - In JSON format, the Timestamp type is encoded as a string in the - [RFC 3339](https://www.ietf.org/rfc/rfc3339.txt) format. That is, the - format is "{year}-{month}-{day}T{hour}:{min}:{sec}[.{frac_sec}]Z" - where {year} is always expressed using four digits while {month}, {day}, - {hour}, {min}, and {sec} are zero-padded to two digits each. The fractional - seconds, which can go up to 9 digits (i.e. up to 1 nanosecond resolution), - are optional. The "Z" suffix indicates the timezone ("UTC"); the timezone - is required. A proto3 JSON serializer should always use UTC (as indicated by - "Z") when printing the Timestamp type and a proto3 JSON parser should be - able to accept both UTC and other timezones (as indicated by an offset). - - For example, "2017-01-15T01:30:15.01Z" encodes 15.01 seconds past - 01:30 UTC on January 15, 2017. - - In JavaScript, one can convert a Date object to this format using the - standard - [toISOString()](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Date/toISOString) - method. In Python, a standard `datetime.datetime` object can be converted - to this format using - [`strftime`](https://docs.python.org/2/library/time.html#time.strftime) with - the time format spec '%Y-%m-%dT%H:%M:%S.%fZ'. Likewise, in Java, one can use - the Joda Time's [`ISODateTimeFormat.dateTime()`]( - http://joda-time.sourceforge.net/apidocs/org/joda/time/format/ISODateTimeFormat.html#dateTime() - ) to obtain a formatter capable of generating timestamps in this format. - google.protobuf.Value: - oneOf: - - type: "null" - - type: number - - type: string - - type: boolean - - type: array - - type: object - additionalProperties: true - description: |- - `Value` represents a dynamically typed value which can be either - null, a number, a string, a boolean, a recursive struct value, or a - list of values. A producer of value is expected to set one of these - variants. Absence of any variant indicates an error. - - The JSON representation for `Value` is JSON value. - platform.v1.ActionIntent: - type: object - properties: - actionIntentId: - type: string - title: action_intent_id - minLength: 1 - scope: - title: scope - $ref: '#/components/schemas/platform.v1.TenantScope' - proposedBy: - title: proposed_by - $ref: '#/components/schemas/platform.v1.Principal' - actionType: - type: string - title: action_type - minLength: 1 - targetResource: - title: target_resource - $ref: '#/components/schemas/platform.v1.ResourceRef' - inputDigest: - type: string - title: input_digest - minLength: 1 - riskTier: - title: risk_tier - $ref: '#/components/schemas/platform.v1.RiskTier' - authorityDecision: - title: authority_decision - $ref: '#/components/schemas/platform.v1.AuthorityDecision' - approvalState: - title: approval_state - $ref: '#/components/schemas/platform.v1.ApprovalState' - executionState: - title: execution_state - $ref: '#/components/schemas/platform.v1.ActionExecutionState' - lineageId: - type: string - title: lineage_id - minLength: 1 - evidence: - title: evidence - $ref: '#/components/schemas/google.protobuf.Struct' - result: - title: result - $ref: '#/components/schemas/google.protobuf.Struct' - evalAssignment: - title: eval_assignment - $ref: '#/components/schemas/platform.v1.EvalAssignment' - title: ActionIntent - required: - - scope - - proposedBy - - authorityDecision - additionalProperties: false - platform.v1.Actor: - type: object - properties: - principal: - title: principal - $ref: '#/components/schemas/platform.v1.Principal' - sessionId: - type: string - title: session_id - title: Actor - required: - - principal - additionalProperties: false - platform.v1.ApplyRecommendationRequest: - type: object - properties: - context: - title: context - $ref: '#/components/schemas/platform.v1.OperationContext' - kind: - title: kind - $ref: '#/components/schemas/platform.v1.RecommendationKind' - subjectId: - type: string - title: subject_id - minLength: 1 - actionType: - type: string - title: action_type - minLength: 1 - inputDigest: - type: string - title: input_digest - minLength: 1 - riskTier: - title: risk_tier - $ref: '#/components/schemas/platform.v1.RiskTier' - targetResource: - title: target_resource - $ref: '#/components/schemas/platform.v1.ResourceRef' - evalAssignment: - title: eval_assignment - $ref: '#/components/schemas/platform.v1.EvalAssignment' - scoreId: - type: string - title: score_id - rationale: - title: rationale - $ref: '#/components/schemas/google.protobuf.Struct' - title: ApplyRecommendationRequest - required: - - context - additionalProperties: false - platform.v1.ApplyRecommendationResponse: - type: object - properties: - recommendation: - title: recommendation - $ref: '#/components/schemas/platform.v1.Recommendation' - actionIntent: - title: action_intent - $ref: '#/components/schemas/platform.v1.ActionIntent' - receipt: - title: receipt - $ref: '#/components/schemas/platform.v1.OperationReceipt' - title: ApplyRecommendationResponse - required: - - recommendation - - actionIntent - - receipt - additionalProperties: false - platform.v1.Artifact: - type: object - properties: - artifactId: - type: string - title: artifact_id - minLength: 1 - scope: - title: scope - $ref: '#/components/schemas/platform.v1.TenantScope' - kind: - title: kind - $ref: '#/components/schemas/platform.v1.ArtifactKind' - state: - title: state - $ref: '#/components/schemas/platform.v1.ArtifactState' - latestVersionId: - type: string - title: latest_version_id - minLength: 1 - lineageId: - type: string - title: lineage_id - minLength: 1 - resourceRef: - title: resource_ref - $ref: '#/components/schemas/platform.v1.ResourceRef' - title: Artifact - required: - - scope - additionalProperties: false - platform.v1.ArtifactVersion: - type: object - properties: - artifactVersionId: - type: string - title: artifact_version_id - minLength: 1 - artifactId: - type: string - title: artifact_id - minLength: 1 - label: - type: string - title: label - minLength: 1 - contentRef: - type: string - title: content_ref - minLength: 1 - createdBy: - title: created_by - $ref: '#/components/schemas/platform.v1.Principal' - lineageId: - type: string - title: lineage_id - minLength: 1 - labels: - type: array - items: - type: string - title: labels - metadata: - title: metadata - $ref: '#/components/schemas/google.protobuf.Struct' - resourceRef: - title: resource_ref - $ref: '#/components/schemas/platform.v1.ResourceRef' - title: ArtifactVersion - required: - - createdBy - additionalProperties: false - platform.v1.AttributionEdge: - type: object - properties: - attributionEdgeId: - type: string - title: attribution_edge_id - minLength: 1 - operationId: - type: string - title: operation_id - minLength: 1 - scope: - title: scope - $ref: '#/components/schemas/platform.v1.TenantScope' - sourceKind: - title: source_kind - $ref: '#/components/schemas/platform.v1.AttributionSubjectKind' - sourceId: - type: string - title: source_id - minLength: 1 - targetKind: - title: target_kind - $ref: '#/components/schemas/platform.v1.AttributionSubjectKind' - targetId: - type: string - title: target_id - minLength: 1 - relation: - type: string - title: relation - minLength: 1 - weightMicros: - type: - - integer - - string - title: weight_micros - format: int64 - lineageId: - type: string - title: lineage_id - minLength: 1 - evidenceId: - type: string - title: evidence_id - title: AttributionEdge - required: - - scope - additionalProperties: false - platform.v1.AuthorityDecision: - type: object - properties: - decisionId: - type: string - title: decision_id - minLength: 1 - kind: - title: kind - $ref: '#/components/schemas/platform.v1.AuthorityDecisionKind' - policyRefs: - type: array - items: - $ref: '#/components/schemas/platform.v1.PolicyRef' - title: policy_refs - reasons: - type: array - items: - type: string - title: reasons - approvalRequestId: - type: string - title: approval_request_id - grantId: - type: string - title: grant_id - evaluatedAt: - title: evaluated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: AuthorityDecision - additionalProperties: false - platform.v1.CreateArtifactRequest: - type: object - properties: - context: - title: context - $ref: '#/components/schemas/platform.v1.OperationContext' - artifact: - title: artifact - $ref: '#/components/schemas/platform.v1.NewArtifactVersion' - title: CreateArtifactRequest - required: - - context - - artifact - additionalProperties: false - platform.v1.CreateArtifactResponse: - type: object - properties: - artifact: - title: artifact - $ref: '#/components/schemas/platform.v1.Artifact' - version: - title: version - $ref: '#/components/schemas/platform.v1.ArtifactVersion' - receipt: - title: receipt - $ref: '#/components/schemas/platform.v1.OperationReceipt' - title: CreateArtifactResponse - required: - - artifact - - version - - receipt - additionalProperties: false - platform.v1.CreateWorkRequest: - type: object - properties: - context: - title: context - $ref: '#/components/schemas/platform.v1.OperationContext' - work: - title: work - $ref: '#/components/schemas/platform.v1.NewWorkItem' - title: CreateWorkRequest - required: - - context - - work - additionalProperties: false - platform.v1.CreateWorkResponse: - type: object - properties: - work: - title: work - $ref: '#/components/schemas/platform.v1.WorkItem' - receipt: - title: receipt - $ref: '#/components/schemas/platform.v1.OperationReceipt' - title: CreateWorkResponse - required: - - work - - receipt - additionalProperties: false - platform.v1.DomainEvent: - type: object - properties: - eventId: - type: string - title: event_id - minLength: 1 - operationId: - type: string - title: operation_id - minLength: 1 - scope: - title: scope - $ref: '#/components/schemas/platform.v1.TenantScope' - ownerType: - type: string - title: owner_type - minLength: 1 - ownerId: - type: string - title: owner_id - minLength: 1 - eventType: - type: string - title: event_type - minLength: 1 - lineageId: - type: string - title: lineage_id - minLength: 1 - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Struct' - title: DomainEvent - required: - - scope - additionalProperties: false - platform.v1.EvalAssignment: - type: object - properties: - cohortId: - type: string - title: cohort_id - minLength: 1 - candidateId: - type: string - title: candidate_id - minLength: 1 - baselineId: - type: string - title: baseline_id - assignmentId: - type: string - title: assignment_id - title: EvalAssignment - additionalProperties: false - platform.v1.EvidenceRecord: - type: object - properties: - evidenceId: - type: string - title: evidence_id - minLength: 1 - scope: - title: scope - $ref: '#/components/schemas/platform.v1.TenantScope' - kind: - title: kind - $ref: '#/components/schemas/platform.v1.EvidenceKind' - subjectId: - type: string - title: subject_id - minLength: 1 - lineageId: - type: string - title: lineage_id - minLength: 1 - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Struct' - title: EvidenceRecord - required: - - scope - additionalProperties: false - platform.v1.GetBootstrapRequest: - type: object - properties: - scope: - title: scope - $ref: '#/components/schemas/platform.v1.TenantScope' - title: GetBootstrapRequest - required: - - scope - additionalProperties: false - platform.v1.GetBootstrapResponse: - type: object - properties: - scope: - title: scope - $ref: '#/components/schemas/platform.v1.TenantScope' - capabilities: - type: array - items: - $ref: '#/components/schemas/platform.v1.PlatformCapability' - title: capabilities - title: GetBootstrapResponse - required: - - scope - additionalProperties: false - platform.v1.NewArtifactVersion: - type: object - properties: - artifactId: - type: string - title: artifact_id - minLength: 1 - kind: - title: kind - $ref: '#/components/schemas/platform.v1.ArtifactKind' - label: - type: string - title: label - minLength: 1 - contentRef: - type: string - title: content_ref - minLength: 1 - labels: - type: array - items: - type: string - title: labels - metadata: - title: metadata - $ref: '#/components/schemas/google.protobuf.Struct' - resourceRef: - title: resource_ref - $ref: '#/components/schemas/platform.v1.ResourceRef' - title: NewArtifactVersion - additionalProperties: false - platform.v1.NewWorkItem: - type: object - properties: - kind: - title: kind - $ref: '#/components/schemas/platform.v1.WorkKind' - title: - type: string - title: title - minLength: 1 - parentWorkId: - type: string - title: parent_work_id - metadata: - title: metadata - $ref: '#/components/schemas/google.protobuf.Struct' - evalAssignment: - title: eval_assignment - $ref: '#/components/schemas/platform.v1.EvalAssignment' - remediationPlan: - title: remediation_plan - description: Immutable, versioned remediation plan owned by this Work item. - $ref: '#/components/schemas/platform.v1.WorkRemediationPlan' - title: NewWorkItem - additionalProperties: false - platform.v1.OperationContext: - type: object - properties: - scope: - title: scope - $ref: '#/components/schemas/platform.v1.TenantScope' - actor: - title: actor - $ref: '#/components/schemas/platform.v1.Actor' - authority: - title: authority - $ref: '#/components/schemas/platform.v1.AuthorityDecision' - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - lineageId: - type: string - title: lineage_id - minLength: 1 - requestId: - type: string - title: request_id - minLength: 1 - now: - title: now - $ref: '#/components/schemas/google.protobuf.Timestamp' - evidence: - title: evidence - $ref: '#/components/schemas/google.protobuf.Struct' - title: OperationContext - required: - - scope - - actor - - authority - - now - additionalProperties: false - platform.v1.OperationReceipt: - type: object - properties: - operationRecord: - title: operation_record - $ref: '#/components/schemas/platform.v1.OperationRecord' - domainEvent: - title: domain_event - $ref: '#/components/schemas/platform.v1.DomainEvent' - outboxMessage: - title: outbox_message - $ref: '#/components/schemas/platform.v1.OutboxMessage' - replayed: - type: boolean - title: replayed - title: OperationReceipt - required: - - operationRecord - - domainEvent - - outboxMessage - additionalProperties: false - platform.v1.OperationRecord: - type: object - properties: - operationId: - type: string - title: operation_id - minLength: 1 - scope: - title: scope - $ref: '#/components/schemas/platform.v1.TenantScope' - actor: - title: actor - $ref: '#/components/schemas/platform.v1.Actor' - authority: - title: authority - $ref: '#/components/schemas/platform.v1.AuthorityDecision' - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - lineageId: - type: string - title: lineage_id - minLength: 1 - requestId: - type: string - title: request_id - minLength: 1 - recordedAt: - title: recorded_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - operationType: - type: string - title: operation_type - minLength: 1 - ownerType: - type: string - title: owner_type - minLength: 1 - ownerId: - type: string - title: owner_id - minLength: 1 - title: OperationRecord - required: - - scope - - actor - - authority - - recordedAt - additionalProperties: false - platform.v1.OutboxMessage: - type: object - properties: - outboxMessageId: - type: string - title: outbox_message_id - minLength: 1 - operationId: - type: string - title: operation_id - minLength: 1 - domainEventId: - type: string - title: domain_event_id - minLength: 1 - topic: - type: string - title: topic - minLength: 1 - status: - title: status - $ref: '#/components/schemas/platform.v1.OutboxStatus' - lineageId: - type: string - title: lineage_id - minLength: 1 - title: OutboxMessage - additionalProperties: false - platform.v1.PlatformCapability: - type: object - properties: - name: - type: string - title: name - minLength: 1 - status: - title: status - $ref: '#/components/schemas/platform.v1.CapabilityStatus' - reason: - type: string - title: reason - features: - type: array - items: - $ref: '#/components/schemas/platform.v1.PlatformCapabilityFeature' - title: features - title: PlatformCapability - additionalProperties: false - platform.v1.PlatformCapabilityFeature: - type: object - properties: - operation: - type: string - title: operation - minLength: 1 - method: - type: string - title: method - minLength: 1 - path: - type: string - title: path - minLength: 1 - title: PlatformCapabilityFeature - additionalProperties: false - platform.v1.Policy: - type: object - properties: - policyId: - type: string - title: policy_id - minLength: 1 - scope: - title: scope - $ref: '#/components/schemas/platform.v1.TenantScope' - kind: - title: kind - $ref: '#/components/schemas/platform.v1.PolicyKind' - name: - type: string - title: name - minLength: 1 - activeVersionId: - type: string - title: active_version_id - minLength: 1 - title: Policy - required: - - scope - additionalProperties: false - platform.v1.PolicyRef: - type: object - properties: - policyId: - type: string - title: policy_id - minLength: 1 - versionId: - type: string - title: version_id - minLength: 1 - title: PolicyRef - additionalProperties: false - platform.v1.PolicyVersion: - type: object - properties: - versionId: - type: string - title: version_id - minLength: 1 - policyId: - type: string - title: policy_id - minLength: 1 - artifactVersionId: - type: string - title: artifact_version_id - minLength: 1 - createdBy: - title: created_by - $ref: '#/components/schemas/platform.v1.Principal' - lineageId: - type: string - title: lineage_id - minLength: 1 - title: PolicyVersion - required: - - createdBy - additionalProperties: false - platform.v1.Principal: - type: object - properties: - principalId: - type: string - title: principal_id - minLength: 1 - kind: - title: kind - $ref: '#/components/schemas/platform.v1.PrincipalKind' - displayName: - type: string - title: display_name - title: Principal - additionalProperties: false - platform.v1.ProposeActionRequest: - type: object - properties: - context: - title: context - $ref: '#/components/schemas/platform.v1.OperationContext' - actionType: - type: string - title: action_type - minLength: 1 - targetResource: - title: target_resource - $ref: '#/components/schemas/platform.v1.ResourceRef' - inputDigest: - type: string - title: input_digest - minLength: 1 - riskTier: - title: risk_tier - $ref: '#/components/schemas/platform.v1.RiskTier' - evidence: - title: evidence - $ref: '#/components/schemas/google.protobuf.Struct' - title: ProposeActionRequest - required: - - context - additionalProperties: false - platform.v1.ProposeActionResponse: - type: object - properties: - actionIntent: - title: action_intent - $ref: '#/components/schemas/platform.v1.ActionIntent' - receipt: - title: receipt - $ref: '#/components/schemas/platform.v1.OperationReceipt' - title: ProposeActionResponse - required: - - actionIntent - - receipt - additionalProperties: false - platform.v1.Recommendation: - type: object - properties: - recommendationId: - type: string - title: recommendation_id - minLength: 1 - scope: - title: scope - $ref: '#/components/schemas/platform.v1.TenantScope' - kind: - title: kind - $ref: '#/components/schemas/platform.v1.RecommendationKind' - state: - title: state - $ref: '#/components/schemas/platform.v1.RecommendationState' - subjectId: - type: string - title: subject_id - minLength: 1 - actionType: - type: string - title: action_type - minLength: 1 - evalAssignment: - title: eval_assignment - $ref: '#/components/schemas/platform.v1.EvalAssignment' - scoreId: - type: string - title: score_id - actionIntentId: - type: string - title: action_intent_id - lineageId: - type: string - title: lineage_id - minLength: 1 - rationale: - title: rationale - $ref: '#/components/schemas/google.protobuf.Struct' - result: - title: result - $ref: '#/components/schemas/google.protobuf.Struct' - title: Recommendation - required: - - scope - additionalProperties: false - platform.v1.RecordEvidenceRequest: - type: object - properties: - context: - title: context - $ref: '#/components/schemas/platform.v1.OperationContext' - kind: - title: kind - $ref: '#/components/schemas/platform.v1.EvidenceKind' - subjectId: - type: string - title: subject_id - minLength: 1 - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Struct' - title: RecordEvidenceRequest - required: - - context - additionalProperties: false - platform.v1.RecordEvidenceResponse: - type: object - properties: - evidence: - title: evidence - $ref: '#/components/schemas/platform.v1.EvidenceRecord' - receipt: - title: receipt - $ref: '#/components/schemas/platform.v1.OperationReceipt' - title: RecordEvidenceResponse - required: - - evidence - - receipt - additionalProperties: false - platform.v1.RecordRef: - type: object - properties: - kind: - not: - enum: - - 0 - title: kind - $ref: '#/components/schemas/platform.v1.RecordKind' - recordId: - type: string - title: record_id - minLength: 1 - revision: - type: string - title: revision - description: Owner-defined immutable revision or digest when the reference is pinned. - title: RecordRef - additionalProperties: false - description: |- - RecordRef is the canonical, content-free pointer used by customer read - models to join independently owned operational records. It is correlation, - never authority: consumers must resolve it through the owning service under - the authenticated tenant carried by the enclosing request. - platform.v1.RecordScoreRequest: - type: object - properties: - context: - title: context - $ref: '#/components/schemas/platform.v1.OperationContext' - subjectId: - type: string - title: subject_id - minLength: 1 - criterion: - type: string - title: criterion - minLength: 1 - value: - type: number - title: value - format: double - scorer: - type: string - title: scorer - minLength: 1 - target: - type: string - title: target - evalAssignment: - title: eval_assignment - $ref: '#/components/schemas/platform.v1.EvalAssignment' - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Struct' - title: RecordScoreRequest - required: - - context - additionalProperties: false - platform.v1.RecordScoreResponse: - type: object - properties: - score: - title: score - $ref: '#/components/schemas/platform.v1.Score' - evidence: - title: evidence - $ref: '#/components/schemas/platform.v1.EvidenceRecord' - receipt: - title: receipt - $ref: '#/components/schemas/platform.v1.OperationReceipt' - title: RecordScoreResponse - required: - - score - - evidence - - receipt - additionalProperties: false - platform.v1.ResourceRef: - type: object - properties: - resourceId: - type: string - title: resource_id - minLength: 1 - kind: - title: kind - $ref: '#/components/schemas/platform.v1.ResourceKind' - versionId: - type: string - title: version_id - description: Stable immutable version identity, when the reference is version-bound. - version: - type: integer - title: version - format: int32 - description: |- - Owner-defined monotonic version number. Zero means the latest version - when version_id is empty; version_id wins when both are supplied. - title: ResourceRef - additionalProperties: false - description: |- - ResourceRef is the canonical structured pointer for durable Platform - content. It is intentionally not a URI: callers carry organization and - workspace authority in the surrounding request, while a resolver owned by - the resource's service decides whether a reference yields metadata, VFS - identity, or a short-lived byte-access grant. - platform.v1.Score: - type: object - properties: - scoreId: - type: string - title: score_id - minLength: 1 - scope: - title: scope - $ref: '#/components/schemas/platform.v1.TenantScope' - subjectId: - type: string - title: subject_id - minLength: 1 - criterion: - type: string - title: criterion - minLength: 1 - value: - type: number - title: value - format: double - scorer: - type: string - title: scorer - minLength: 1 - target: - type: string - title: target - evalAssignment: - title: eval_assignment - $ref: '#/components/schemas/platform.v1.EvalAssignment' - evidenceId: - type: string - title: evidence_id - lineageId: - type: string - title: lineage_id - minLength: 1 - scoredAt: - title: scored_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Struct' - title: Score - required: - - scope - - scoredAt - additionalProperties: false - platform.v1.SpendLedgerEntry: - type: object - properties: - spendEntryId: - type: string - title: spend_entry_id - minLength: 1 - operationId: - type: string - title: operation_id - minLength: 1 - scope: - title: scope - $ref: '#/components/schemas/platform.v1.TenantScope' - usageEntryId: - type: string - title: usage_entry_id - actionIntentId: - type: string - title: action_intent_id - amountMicros: - type: - - integer - - string - title: amount_micros - format: int64 - currency: - type: string - title: currency - maxLength: 3 - minLength: 3 - pricingPolicyRef: - title: pricing_policy_ref - $ref: '#/components/schemas/platform.v1.PolicyRef' - incurredAt: - title: incurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - lineageId: - type: string - title: lineage_id - minLength: 1 - allocationKey: - type: string - title: allocation_key - metadata: - title: metadata - $ref: '#/components/schemas/google.protobuf.Struct' - title: SpendLedgerEntry - required: - - scope - - incurredAt - additionalProperties: false - platform.v1.TenantScope: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - teamId: - type: string - title: team_id - environment: - type: string - title: environment - title: TenantScope - additionalProperties: false - platform.v1.UsageLedgerEntry: - type: object - properties: - usageEntryId: - type: string - title: usage_entry_id - minLength: 1 - operationId: - type: string - title: operation_id - minLength: 1 - scope: - title: scope - $ref: '#/components/schemas/platform.v1.TenantScope' - principal: - title: principal - $ref: '#/components/schemas/platform.v1.Principal' - actionIntentId: - type: string - title: action_intent_id - workId: - type: string - title: work_id - artifactVersionId: - type: string - title: artifact_version_id - traceId: - type: string - title: trace_id - spanId: - type: string - title: span_id - provider: - type: string - title: provider - resource: - title: resource - $ref: '#/components/schemas/platform.v1.ResourceRef' - metricKind: - title: metric_kind - $ref: '#/components/schemas/platform.v1.UsageMetricKind' - quantityDecimal: - type: string - title: quantity_decimal - minLength: 1 - unit: - type: string - title: unit - minLength: 1 - observedAt: - title: observed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - lineageId: - type: string - title: lineage_id - minLength: 1 - metadata: - title: metadata - $ref: '#/components/schemas/google.protobuf.Struct' - title: UsageLedgerEntry - required: - - scope - - principal - - observedAt - additionalProperties: false - platform.v1.WorkItem: - type: object - properties: - workId: - type: string - title: work_id - minLength: 1 - scope: - title: scope - $ref: '#/components/schemas/platform.v1.TenantScope' - kind: - title: kind - $ref: '#/components/schemas/platform.v1.WorkKind' - state: - title: state - $ref: '#/components/schemas/platform.v1.WorkState' - title: - type: string - title: title - minLength: 1 - parentWorkId: - type: string - title: parent_work_id - createdBy: - title: created_by - $ref: '#/components/schemas/platform.v1.Principal' - lineageId: - type: string - title: lineage_id - minLength: 1 - metadata: - title: metadata - $ref: '#/components/schemas/google.protobuf.Struct' - evalAssignment: - title: eval_assignment - $ref: '#/components/schemas/platform.v1.EvalAssignment' - remediationPlan: - title: remediation_plan - $ref: '#/components/schemas/platform.v1.WorkRemediationPlan' - title: WorkItem - required: - - scope - - createdBy - additionalProperties: false - platform.v1.WorkRemediationAction: - type: object - properties: - actionId: - type: string - title: action_id - minLength: 1 - catalogDigest: - type: string - title: catalog_digest - minLength: 1 - inputDigest: - type: string - title: input_digest - minLength: 1 - target: - title: target - $ref: '#/components/schemas/platform.v1.WorkRemediationResource' - riskTier: - not: - enum: - - 0 - title: risk_tier - $ref: '#/components/schemas/platform.v1.RiskTier' - approvalRequired: - type: boolean - title: approval_required - requiredScopes: - type: array - items: - type: string - title: required_scopes - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - postconditionIds: - type: array - items: - type: string - title: postcondition_ids - inputArtifactRef: - title: input_artifact_ref - description: |- - Immutable ArtifactVersion containing schema-validated provider arguments. - input_digest binds its exact bytes; secrets remain references. - $ref: '#/components/schemas/platform.v1.ResourceRef' - title: WorkRemediationAction - required: - - target - - inputArtifactRef - additionalProperties: false - platform.v1.WorkRemediationPlan: - type: object - properties: - schemaVersion: - exclusiveMinimum: 0 - type: integer - title: schema_version - planDigest: - type: string - title: plan_digest - minLength: 1 - scope: - title: scope - $ref: '#/components/schemas/platform.v1.TenantScope' - sourceFindingId: - type: string - title: source_finding_id - minLength: 1 - sourceEvidence: - type: array - items: - $ref: '#/components/schemas/platform.v1.RecordRef' - title: source_evidence - affectedResources: - type: array - items: - $ref: '#/components/schemas/platform.v1.WorkRemediationResource' - title: affected_resources - postconditions: - type: array - items: - $ref: '#/components/schemas/platform.v1.WorkRemediationPostcondition' - title: postconditions - actions: - type: array - items: - $ref: '#/components/schemas/platform.v1.WorkRemediationAction' - title: actions - classification: - not: - enum: - - 0 - title: classification - $ref: '#/components/schemas/platform.v1.WorkRemediationClassification' - lineageId: - type: string - title: lineage_id - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - nonExecutableReason: - type: string - title: non_executable_reason - description: |- - Manual and blocked Work retain an explicit reason rather than inventing - an executable connector action. - title: WorkRemediationPlan - required: - - scope - additionalProperties: false - description: |- - A typed extension of Platform Work, not a separate execution or approval - owner. plan_digest excludes itself and binds every immutable field below. - platform.v1.WorkRemediationPostcondition: - type: object - properties: - postconditionId: - type: string - title: postcondition_id - minLength: 1 - target: - title: target - $ref: '#/components/schemas/platform.v1.WorkRemediationResource' - observerActionId: - type: string - title: observer_action_id - minLength: 1 - expectedStateDigest: - type: string - title: expected_state_digest - minLength: 1 - maxAgeSeconds: - exclusiveMinimum: 0 - type: integer - title: max_age_seconds - requiredIndependence: - not: - enum: - - 0 - title: required_independence - $ref: '#/components/schemas/platform.v1.WorkRemediationEvidenceIndependence' - observerCatalogDigest: - type: string - title: observer_catalog_digest - minLength: 1 - description: Pins the read contract used to independently verify this condition. - title: WorkRemediationPostcondition - required: - - target - additionalProperties: false - platform.v1.WorkRemediationResource: - type: object - properties: - providerId: - type: string - title: provider_id - minLength: 1 - connectionId: - type: string - title: connection_id - minLength: 1 - stableResourceId: - type: string - title: stable_resource_id - minLength: 1 - resourceKind: - type: string - title: resource_kind - minLength: 1 - platformResource: - title: platform_resource - $ref: '#/components/schemas/platform.v1.ResourceRef' - title: WorkRemediationResource - additionalProperties: false - description: Exact external identity; the enclosing Work scope remains tenant authority. - connect-protocol-version: - type: number - title: Connect-Protocol-Version - enum: - - 1 - description: Define the version of the Connect protocol - const: 1 - connect-timeout-header: - type: number - title: Connect-Timeout-Ms - description: Define the timeout, in ms - connect.error: - type: object - properties: - code: - type: string - examples: - - not_found - enum: - - canceled - - unknown - - invalid_argument - - deadline_exceeded - - not_found - - already_exists - - permission_denied - - resource_exhausted - - failed_precondition - - aborted - - out_of_range - - unimplemented - - internal - - unavailable - - data_loss - - unauthenticated - description: The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code]. - message: - type: string - description: A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client. - detail: - $ref: '#/components/schemas/google.protobuf.Any' - title: Connect Error - additionalProperties: true - description: 'Error type returned by Connect: https://connectrpc.com/docs/go/errors/#http-representation' - google.protobuf.Any: - type: object - properties: - type: - type: string - value: - type: string - format: binary - debug: - type: object - additionalProperties: true - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. -security: [] -tags: - - name: platform.v1.PlatformService - description: |- - PlatformService is the product-facing primitive API for the Rust platform - core. It is Protobuf-first; JSON is only a protobuf mapping for tooling and - debug surfaces, not the source of truth. diff --git a/openapi/remoterunner/v1/remoterunner.openapi.yaml b/openapi/remoterunner/v1/remoterunner.openapi.yaml deleted file mode 100644 index 094bacf..0000000 --- a/openapi/remoterunner/v1/remoterunner.openapi.yaml +++ /dev/null @@ -1,2727 +0,0 @@ -openapi: 3.1.0 -info: - title: remoterunner.v1 -paths: - /v1/runner-profiles: - get: - tags: - - remoterunner.v1.RemoteRunnerService - summary: ListRunnerProfiles - operationId: remoterunner.v1.RemoteRunnerService.ListRunnerProfiles - parameters: - - name: organizationId - in: query - schema: - type: string - title: organization_id - minLength: 1 - - name: workspaceId - in: query - schema: - type: string - title: workspace_id - minLength: 1 - - name: includeUnavailable - in: query - schema: - type: boolean - title: include_unavailable - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/remoterunner.v1.ListRunnerProfilesResponse' - /v1/runner-sessions: - get: - tags: - - remoterunner.v1.RemoteRunnerService - summary: ListRunnerSessions - operationId: remoterunner.v1.RemoteRunnerService.ListRunnerSessions - parameters: - - name: organizationId - in: query - schema: - type: string - title: organization_id - minLength: 1 - - name: workspaceId - in: query - schema: - type: string - title: workspace_id - minLength: 1 - - name: state - in: query - schema: - title: state - $ref: '#/components/schemas/remoterunner.v1.RunnerSessionState' - - name: limit - in: query - schema: - type: integer - title: limit - maximum: 200 - format: int32 - - name: offset - in: query - schema: - type: integer - title: offset - format: int32 - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/remoterunner.v1.ListRunnerSessionsResponse' - post: - tags: - - remoterunner.v1.RemoteRunnerService - summary: CreateRunnerSession - operationId: remoterunner.v1.RemoteRunnerService.CreateRunnerSession - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/remoterunner.v1.CreateRunnerSessionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/remoterunner.v1.CreateRunnerSessionResponse' - /v1/runner-sessions/{runner_session_id}/adopt-computer-mission: - post: - tags: - - remoterunner.v1.RemoteRunnerService - summary: AdoptRunnerSessionForComputerMission - operationId: remoterunner.v1.RemoteRunnerService.AdoptRunnerSessionForComputerMission - parameters: - - name: runner_session_id - in: path - required: true - schema: - type: string - title: runner_session_id - minLength: 1 - requestBody: - content: - application/json: - schema: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - reservationId: - type: string - title: reservation_id - minLength: 1 - missionId: - type: string - title: mission_id - minLength: 1 - runtimeRunId: - type: string - title: runtime_run_id - minLength: 1 - title: AdoptRunnerSessionForComputerMissionRequest - additionalProperties: false - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/remoterunner.v1.AdoptRunnerSessionForComputerMissionResponse' - /v1/runner-sessions/{session_id}: - get: - tags: - - remoterunner.v1.RemoteRunnerService - summary: GetRunnerSession - operationId: remoterunner.v1.RemoteRunnerService.GetRunnerSession - parameters: - - name: session_id - in: path - required: true - schema: - type: string - title: session_id - minLength: 1 - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/remoterunner.v1.GetRunnerSessionResponse' - /v1/runner-restores: - get: - tags: - - remoterunner.v1.RemoteRunnerService - summary: ListRunnerRestores - operationId: remoterunner.v1.RemoteRunnerService.ListRunnerRestores - parameters: - - name: organizationId - in: query - schema: - type: string - title: organization_id - minLength: 1 - - name: workspaceId - in: query - schema: - type: string - title: workspace_id - minLength: 1 - - name: state - in: query - schema: - title: state - $ref: '#/components/schemas/remoterunner.v1.RunnerRestoreState' - - name: limit - in: query - schema: - type: integer - title: limit - maximum: 200 - format: int32 - - name: offset - in: query - schema: - type: integer - title: offset - format: int32 - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/remoterunner.v1.ListRunnerRestoresResponse' - post: - tags: - - remoterunner.v1.RemoteRunnerService - summary: CreateRunnerRestore - operationId: remoterunner.v1.RemoteRunnerService.CreateRunnerRestore - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/remoterunner.v1.CreateRunnerRestoreRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/remoterunner.v1.CreateRunnerRestoreResponse' - /v1/runner-restores/{restore_id}: - get: - tags: - - remoterunner.v1.RemoteRunnerService - summary: GetRunnerRestore - operationId: remoterunner.v1.RemoteRunnerService.GetRunnerRestore - parameters: - - name: restore_id - in: path - required: true - schema: - type: string - title: restore_id - minLength: 1 - - name: organizationId - in: query - schema: - type: string - title: organization_id - minLength: 1 - - name: workspaceId - in: query - schema: - type: string - title: workspace_id - minLength: 1 - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/remoterunner.v1.GetRunnerRestoreResponse' - /v1/runner-sessions/{session_id}/stop: - post: - tags: - - remoterunner.v1.RemoteRunnerService - summary: StopRunnerSession - operationId: remoterunner.v1.RemoteRunnerService.StopRunnerSession - parameters: - - name: session_id - in: path - required: true - schema: - type: string - title: session_id - minLength: 1 - requestBody: - content: - application/json: - schema: - type: object - properties: - reason: - type: string - title: reason - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - title: StopRunnerSessionRequest - additionalProperties: false - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/remoterunner.v1.StopRunnerSessionResponse' - /v1/runner-sessions/{session_id}/extend: - post: - tags: - - remoterunner.v1.RemoteRunnerService - summary: ExtendRunnerSession - operationId: remoterunner.v1.RemoteRunnerService.ExtendRunnerSession - parameters: - - name: session_id - in: path - required: true - schema: - type: string - title: session_id - minLength: 1 - requestBody: - content: - application/json: - schema: - type: object - properties: - additionalMinutes: - type: integer - title: additional_minutes - maximum: 1440 - minimum: 1 - format: int32 - additionalIdleMinutes: - type: integer - title: additional_idle_minutes - maximum: 1440 - format: int32 - reason: - type: string - title: reason - title: ExtendRunnerSessionRequest - additionalProperties: false - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/remoterunner.v1.ExtendRunnerSessionResponse' - /v1/runner-sessions/{session_id}/attach-token: - post: - tags: - - remoterunner.v1.RemoteRunnerService - summary: MintAttachToken - operationId: remoterunner.v1.RemoteRunnerService.MintAttachToken - parameters: - - name: session_id - in: path - required: true - schema: - type: string - title: session_id - minLength: 1 - requestBody: - content: - application/json: - schema: - type: object - properties: - subjectId: - type: string - title: subject_id - roles: - type: array - items: - $ref: '#/components/schemas/remoterunner.v1.RunnerAttachRole' - title: roles - ttlMinutes: - type: integer - title: ttl_minutes - maximum: 60 - format: int32 - title: MintAttachTokenRequest - additionalProperties: false - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/remoterunner.v1.MintAttachTokenResponse' - /v1/runner-sessions/{session_id}/attach-tokens/{token_id}/revoke: - post: - tags: - - remoterunner.v1.RemoteRunnerService - summary: RevokeAttachToken - operationId: remoterunner.v1.RemoteRunnerService.RevokeAttachToken - parameters: - - name: session_id - in: path - required: true - schema: - type: string - title: session_id - minLength: 1 - - name: token_id - in: path - required: true - schema: - type: string - title: token_id - minLength: 1 - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/remoterunner.v1.RevokeAttachTokenResponse' - /v1/runner-sessions/{session_id}/events: - get: - tags: - - remoterunner.v1.RemoteRunnerService - summary: ListRunnerSessionEvents - operationId: remoterunner.v1.RemoteRunnerService.ListRunnerSessionEvents - parameters: - - name: session_id - in: path - required: true - schema: - type: string - title: session_id - minLength: 1 - - name: afterSequence - in: query - schema: - type: - - integer - - string - title: after_sequence - format: int64 - - name: limit - in: query - schema: - type: integer - title: limit - maximum: 500 - format: int32 - - name: organizationId - in: query - schema: - type: string - title: organization_id - minLength: 1 - - name: workspaceId - in: query - schema: - type: string - title: workspace_id - minLength: 1 - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/remoterunner.v1.ListRunnerSessionEventsResponse' - /v1/runner-sessions/{session_id}/artifact-lifecycle: - post: - tags: - - remoterunner.v1.RemoteRunnerService - summary: RecordRunnerSessionArtifactLifecycle - operationId: remoterunner.v1.RemoteRunnerService.RecordRunnerSessionArtifactLifecycle - parameters: - - name: session_id - in: path - required: true - schema: - type: string - title: session_id - minLength: 1 - requestBody: - content: - application/json: - schema: - type: object - properties: - artifactClass: - title: artifact_class - $ref: '#/components/schemas/remoterunner.v1.RunnerArtifactClass' - state: - title: state - $ref: '#/components/schemas/remoterunner.v1.RunnerArtifactLifecycleState' - artifactUri: - type: string - title: artifact_uri - manifestPath: - type: string - title: manifest_path - reason: - type: string - title: reason - message: - type: string - title: message - retentionExpiresAt: - title: retention_expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: RecordRunnerSessionArtifactLifecycleRequest - additionalProperties: false - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/remoterunner.v1.RecordRunnerSessionArtifactLifecycleResponse' - /v1/runner-sessions/{session_id}/steps: - post: - tags: - - remoterunner.v1.RemoteRunnerService - summary: ExecuteRunnerSessionStep - operationId: remoterunner.v1.RemoteRunnerService.ExecuteRunnerSessionStep - parameters: - - name: session_id - in: path - required: true - schema: - type: string - title: session_id - minLength: 1 - requestBody: - content: - application/json: - schema: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - argv: - type: array - items: - type: string - maxItems: 64 - title: argv - maxItems: 64 - cwd: - type: string - title: cwd - timeoutSeconds: - type: integer - title: timeout_seconds - maximum: 3600 - minimum: 1 - ownerBinding: - title: owner_binding - nullable: true - $ref: '#/components/schemas/remoterunner.v1.RunnerSessionOwnerBinding' - operation: - title: operation - $ref: '#/components/schemas/remoterunner.v1.RunnerSessionStepOperation' - stdin: - type: string - title: stdin - maxLength: 1398104 - x-protobuf-bytes-max-length: 1048576 - format: byte - expectedSnapshotId: - type: string - title: expected_snapshot_id - expectedSandboxSessionId: - type: string - title: expected_sandbox_session_id - expectedSandboxId: - type: string - title: expected_sandbox_id - expectedRunnerSessionId: - type: string - title: expected_runner_session_id - expectedCheckpointId: - type: string - title: expected_checkpoint_id - instructionArtifactRef: - type: string - title: instruction_artifact_ref - instructionDigestSha256: - type: string - title: instruction_digest_sha256 - instructionByteCount: - type: - - integer - - string - title: instruction_byte_count - format: int64 - claimLeaseGeneration: - type: - - integer - - string - title: claim_lease_generation - format: int64 - title: ExecuteRunnerSessionStepRequest - additionalProperties: false - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/remoterunner.v1.ExecuteRunnerSessionStepResponse' - /v1/runner-sessions/{session_id}/checkpoints: - post: - tags: - - remoterunner.v1.RemoteRunnerService - summary: CreateRunnerSessionCheckpoint - operationId: remoterunner.v1.RemoteRunnerService.CreateRunnerSessionCheckpoint - parameters: - - name: session_id - in: path - required: true - schema: - type: string - title: session_id - minLength: 1 - requestBody: - content: - application/json: - schema: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - ownerBinding: - title: owner_binding - nullable: true - $ref: '#/components/schemas/remoterunner.v1.RunnerSessionOwnerBinding' - title: CreateRunnerSessionCheckpointRequest - additionalProperties: false - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/remoterunner.v1.CreateRunnerSessionCheckpointResponse' - /v1/runner-account-policies/{organization_id}: - get: - tags: - - remoterunner.v1.RemoteRunnerService - summary: GetRunnerAccountPolicy - operationId: remoterunner.v1.RemoteRunnerService.GetRunnerAccountPolicy - parameters: - - name: organization_id - in: path - required: true - schema: - type: string - title: organization_id - minLength: 1 - - name: workspaceId - in: query - schema: - type: string - title: workspace_id - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/remoterunner.v1.GetRunnerAccountPolicyResponse' - put: - tags: - - remoterunner.v1.RemoteRunnerService - summary: UpsertRunnerAccountPolicy - operationId: remoterunner.v1.RemoteRunnerService.UpsertRunnerAccountPolicy - parameters: - - name: organization_id - in: path - required: true - schema: - type: string - title: organization_id - minLength: 1 - requestBody: - content: - application/json: - schema: - type: object - properties: - workspaceId: - type: string - title: workspace_id - policy: - title: policy - $ref: '#/components/schemas/remoterunner.v1.RunnerAccountPolicy' - title: UpsertRunnerAccountPolicyRequest - additionalProperties: false - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/remoterunner.v1.UpsertRunnerAccountPolicyResponse' - /v1/remote-runner/status: - get: - tags: - - remoterunner.v1.RemoteRunnerService - summary: GetStatus - operationId: remoterunner.v1.RemoteRunnerService.GetStatus - parameters: - - name: workspaceId - in: query - schema: - type: string - title: workspace_id - minLength: 1 - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/remoterunner.v1.GetStatusResponse' -components: - schemas: - google.protobuf.NullValue: - type: string - title: NullValue - enum: - - NULL_VALUE - description: |- - `NullValue` is a singleton enumeration to represent the null value for the - `Value` type union. - - The JSON representation for `NullValue` is JSON `null`. - remoterunner.v1.RunnerArtifactClass: - type: string - title: RunnerArtifactClass - enum: - - RUNNER_ARTIFACT_CLASS_UNSPECIFIED - - RUNNER_ARTIFACT_CLASS_CONTROL_PLANE_METADATA - - RUNNER_ARTIFACT_CLASS_WORKSPACE_EXPORT - - RUNNER_ARTIFACT_CLASS_RUNTIME_SNAPSHOT - - RUNNER_ARTIFACT_CLASS_RUNTIME_LOGS - remoterunner.v1.RunnerArtifactLifecycleState: - type: string - title: RunnerArtifactLifecycleState - enum: - - RUNNER_ARTIFACT_LIFECYCLE_STATE_UNSPECIFIED - - RUNNER_ARTIFACT_LIFECYCLE_STATE_UPLOAD_REQUESTED - - RUNNER_ARTIFACT_LIFECYCLE_STATE_UPLOADED - - RUNNER_ARTIFACT_LIFECYCLE_STATE_UPLOAD_SKIPPED - - RUNNER_ARTIFACT_LIFECYCLE_STATE_RETENTION_EXPIRED - - RUNNER_ARTIFACT_LIFECYCLE_STATE_DELETE_REQUESTED - - RUNNER_ARTIFACT_LIFECYCLE_STATE_DELETED - - RUNNER_ARTIFACT_LIFECYCLE_STATE_CLEANUP_FAILED - remoterunner.v1.RunnerAttachRole: - type: string - title: RunnerAttachRole - enum: - - RUNNER_ATTACH_ROLE_UNSPECIFIED - - RUNNER_ATTACH_ROLE_VIEWER - - RUNNER_ATTACH_ROLE_CONTROLLER - - RUNNER_ATTACH_ROLE_ADMIN - remoterunner.v1.RunnerRestoreFailureCode: - type: string - title: RunnerRestoreFailureCode - enum: - - RUNNER_RESTORE_FAILURE_CODE_UNSPECIFIED - - RUNNER_RESTORE_FAILURE_CODE_MISSING_ARTIFACT - - RUNNER_RESTORE_FAILURE_CODE_INVALID_MANIFEST - - RUNNER_RESTORE_FAILURE_CODE_WORKSPACE_ESCAPE - - RUNNER_RESTORE_FAILURE_CODE_PROVIDER_TIMEOUT - - RUNNER_RESTORE_FAILURE_CODE_RUNTIME_NOT_READY - - RUNNER_RESTORE_FAILURE_CODE_OWNER_MISMATCH - - RUNNER_RESTORE_FAILURE_CODE_HYDRATION_UNAVAILABLE - - RUNNER_RESTORE_FAILURE_CODE_POLICY_DENIED - - RUNNER_RESTORE_FAILURE_CODE_SESSION_CREATE_FAILED - remoterunner.v1.RunnerRestoreState: - type: string - title: RunnerRestoreState - enum: - - RUNNER_RESTORE_STATE_UNSPECIFIED - - RUNNER_RESTORE_STATE_REQUESTED - - RUNNER_RESTORE_STATE_ARTIFACTS_HYDRATING - - RUNNER_RESTORE_STATE_PROVIDER_STARTING - - RUNNER_RESTORE_STATE_IDENTITY_READY - - RUNNER_RESTORE_STATE_ATTACHABLE - - RUNNER_RESTORE_STATE_FAILED - - RUNNER_RESTORE_STATE_EXPIRED - remoterunner.v1.RunnerSessionApexAuthorityState: - type: string - title: RunnerSessionApexAuthorityState - enum: - - RUNNER_SESSION_APEX_AUTHORITY_STATE_UNSPECIFIED - - RUNNER_SESSION_APEX_AUTHORITY_STATE_NOT_REQUIRED - - RUNNER_SESSION_APEX_AUTHORITY_STATE_PENDING_RESERVATION - - RUNNER_SESSION_APEX_AUTHORITY_STATE_RESERVATION_VALIDATED - - RUNNER_SESSION_APEX_AUTHORITY_STATE_MISSION_ADOPTED - remoterunner.v1.RunnerSessionRestoreFailurePolicy: - type: string - title: RunnerSessionRestoreFailurePolicy - enum: - - RUNNER_SESSION_RESTORE_FAILURE_POLICY_UNSPECIFIED - - RUNNER_SESSION_RESTORE_FAILURE_POLICY_FAIL_SESSION - - RUNNER_SESSION_RESTORE_FAILURE_POLICY_COLD_START - remoterunner.v1.RunnerSessionRestoreState: - type: string - title: RunnerSessionRestoreState - enum: - - RUNNER_SESSION_RESTORE_STATE_UNSPECIFIED - - RUNNER_SESSION_RESTORE_STATE_REQUESTED - - RUNNER_SESSION_RESTORE_STATE_ARTIFACTS_HYDRATING - - RUNNER_SESSION_RESTORE_STATE_PROVIDER_STARTING - - RUNNER_SESSION_RESTORE_STATE_IDENTITY_READY - - RUNNER_SESSION_RESTORE_STATE_ATTACHABLE - - RUNNER_SESSION_RESTORE_STATE_FAILED - - RUNNER_SESSION_RESTORE_STATE_EXPIRED - remoterunner.v1.RunnerSessionState: - type: string - title: RunnerSessionState - enum: - - RUNNER_SESSION_STATE_UNSPECIFIED - - RUNNER_SESSION_STATE_REQUESTED - - RUNNER_SESSION_STATE_PROVISIONING - - RUNNER_SESSION_STATE_RUNNING - - RUNNER_SESSION_STATE_IDLE - - RUNNER_SESSION_STATE_STOPPING - - RUNNER_SESSION_STATE_STOPPED - - RUNNER_SESSION_STATE_EXPIRED - - RUNNER_SESSION_STATE_FAILED - - RUNNER_SESSION_STATE_LOST - remoterunner.v1.RunnerSessionStepOperation: - type: string - title: RunnerSessionStepOperation - enum: - - RUNNER_SESSION_STEP_OPERATION_UNSPECIFIED - - RUNNER_SESSION_STEP_OPERATION_GENERIC - - RUNNER_SESSION_STEP_OPERATION_APEX_HYDRATE - - RUNNER_SESSION_STEP_OPERATION_APEX_DISCOVER - - RUNNER_SESSION_STEP_OPERATION_APEX_FREEZE - - RUNNER_SESSION_STEP_OPERATION_APEX_GRADE - - RUNNER_SESSION_STEP_OPERATION_APEX_MCP_CALL - - RUNNER_SESSION_STEP_OPERATION_APEX_STAGE_INPUTS - - RUNNER_SESSION_STEP_OPERATION_APEX_STAGE_GRADING - - RUNNER_SESSION_STEP_OPERATION_APEX_TASK_INSTRUCTIONS - google.protobuf.ListValue: - type: object - properties: - values: - type: array - items: - $ref: '#/components/schemas/google.protobuf.Value' - title: values - description: Repeated field of dynamically typed values. - title: ListValue - additionalProperties: false - description: |- - `ListValue` is a wrapper around a repeated field of values. - - The JSON representation for `ListValue` is JSON array. - google.protobuf.Struct: - type: object - additionalProperties: - $ref: '#/components/schemas/google.protobuf.Value' - description: |- - `Struct` represents a structured data value, consisting of fields - which map to dynamically typed values. In some languages, `Struct` - might be supported by a native representation. For example, in - scripting languages like JS a struct is represented as an - object. The details of that representation are described together - with the proto support for the language. - - The JSON representation for `Struct` is JSON object. - google.protobuf.Struct.FieldsEntry: - type: object - properties: - key: - type: string - title: key - value: - title: value - $ref: '#/components/schemas/google.protobuf.Value' - title: FieldsEntry - additionalProperties: false - google.protobuf.Timestamp: - type: string - examples: - - 1s - - 1.000340012s - format: date-time - description: |- - A Timestamp represents a point in time independent of any time zone or local - calendar, encoded as a count of seconds and fractions of seconds at - nanosecond resolution. The count is relative to an epoch at UTC midnight on - January 1, 1970, in the proleptic Gregorian calendar which extends the - Gregorian calendar backwards to year one. - - All minutes are 60 seconds long. Leap seconds are "smeared" so that no leap - second table is needed for interpretation, using a [24-hour linear - smear](https://developers.google.com/time/smear). - - The range is from 0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z. By - restricting to that range, we ensure that we can convert to and from [RFC - 3339](https://www.ietf.org/rfc/rfc3339.txt) date strings. - - # Examples - - Example 1: Compute Timestamp from POSIX `time()`. - - Timestamp timestamp; - timestamp.set_seconds(time(NULL)); - timestamp.set_nanos(0); - - Example 2: Compute Timestamp from POSIX `gettimeofday()`. - - struct timeval tv; - gettimeofday(&tv, NULL); - - Timestamp timestamp; - timestamp.set_seconds(tv.tv_sec); - timestamp.set_nanos(tv.tv_usec * 1000); - - Example 3: Compute Timestamp from Win32 `GetSystemTimeAsFileTime()`. - - FILETIME ft; - GetSystemTimeAsFileTime(&ft); - UINT64 ticks = (((UINT64)ft.dwHighDateTime) << 32) | ft.dwLowDateTime; - - // A Windows tick is 100 nanoseconds. Windows epoch 1601-01-01T00:00:00Z - // is 11644473600 seconds before Unix epoch 1970-01-01T00:00:00Z. - Timestamp timestamp; - timestamp.set_seconds((INT64) ((ticks / 10000000) - 11644473600LL)); - timestamp.set_nanos((INT32) ((ticks % 10000000) * 100)); - - Example 4: Compute Timestamp from Java `System.currentTimeMillis()`. - - long millis = System.currentTimeMillis(); - - Timestamp timestamp = Timestamp.newBuilder().setSeconds(millis / 1000) - .setNanos((int) ((millis % 1000) * 1000000)).build(); - - Example 5: Compute Timestamp from Java `Instant.now()`. - - Instant now = Instant.now(); - - Timestamp timestamp = - Timestamp.newBuilder().setSeconds(now.getEpochSecond()) - .setNanos(now.getNano()).build(); - - Example 6: Compute Timestamp from current time in Python. - - timestamp = Timestamp() - timestamp.GetCurrentTime() - - # JSON Mapping - - In JSON format, the Timestamp type is encoded as a string in the - [RFC 3339](https://www.ietf.org/rfc/rfc3339.txt) format. That is, the - format is "{year}-{month}-{day}T{hour}:{min}:{sec}[.{frac_sec}]Z" - where {year} is always expressed using four digits while {month}, {day}, - {hour}, {min}, and {sec} are zero-padded to two digits each. The fractional - seconds, which can go up to 9 digits (i.e. up to 1 nanosecond resolution), - are optional. The "Z" suffix indicates the timezone ("UTC"); the timezone - is required. A proto3 JSON serializer should always use UTC (as indicated by - "Z") when printing the Timestamp type and a proto3 JSON parser should be - able to accept both UTC and other timezones (as indicated by an offset). - - For example, "2017-01-15T01:30:15.01Z" encodes 15.01 seconds past - 01:30 UTC on January 15, 2017. - - In JavaScript, one can convert a Date object to this format using the - standard - [toISOString()](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Date/toISOString) - method. In Python, a standard `datetime.datetime` object can be converted - to this format using - [`strftime`](https://docs.python.org/2/library/time.html#time.strftime) with - the time format spec '%Y-%m-%dT%H:%M:%S.%fZ'. Likewise, in Java, one can use - the Joda Time's [`ISODateTimeFormat.dateTime()`]( - http://joda-time.sourceforge.net/apidocs/org/joda/time/format/ISODateTimeFormat.html#dateTime() - ) to obtain a formatter capable of generating timestamps in this format. - google.protobuf.Value: - oneOf: - - type: "null" - - type: number - - type: string - - type: boolean - - type: array - - type: object - additionalProperties: true - description: |- - `Value` represents a dynamically typed value which can be either - null, a number, a string, a boolean, a recursive struct value, or a - list of values. A producer of value is expected to set one of these - variants. Absence of any variant indicates an error. - - The JSON representation for `Value` is JSON value. - remoterunner.v1.AdoptRunnerSessionForComputerMissionRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - reservationId: - type: string - title: reservation_id - minLength: 1 - runnerSessionId: - type: string - title: runner_session_id - minLength: 1 - missionId: - type: string - title: mission_id - minLength: 1 - runtimeRunId: - type: string - title: runtime_run_id - minLength: 1 - title: AdoptRunnerSessionForComputerMissionRequest - additionalProperties: false - remoterunner.v1.AdoptRunnerSessionForComputerMissionResponse: - type: object - properties: - session: - title: session - $ref: '#/components/schemas/remoterunner.v1.RunnerSession' - ownerBinding: - title: owner_binding - $ref: '#/components/schemas/remoterunner.v1.RunnerSessionOwnerBinding' - replayed: - type: boolean - title: replayed - title: AdoptRunnerSessionForComputerMissionResponse - required: - - session - - ownerBinding - additionalProperties: false - remoterunner.v1.CreateRunnerRestoreRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - userId: - type: string - title: user_id - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - sourceSessionId: - type: string - title: source_session_id - maestroSessionId: - type: string - title: maestro_session_id - artifactRef: - type: string - title: artifact_ref - manifestPath: - type: string - title: manifest_path - runnerProfile: - type: string - title: runner_profile - minLength: 1 - runnerImage: - type: string - title: runner_image - workspaceSource: - type: string - title: workspace_source - repoUrl: - type: string - title: repo_url - branch: - type: string - title: branch - model: - type: string - title: model - ttlMinutes: - type: integer - title: ttl_minutes - maximum: 1440 - minimum: 1 - format: int32 - idleTtlMinutes: - type: integer - title: idle_ttl_minutes - maximum: 1440 - format: int32 - metadata: - title: metadata - $ref: '#/components/schemas/google.protobuf.Struct' - runnerSessionId: - type: string - title: runner_session_id - runtimeGeneration: - type: - - integer - - string - title: runtime_generation - format: int64 - activationGeneration: - type: - - integer - - string - title: activation_generation - format: int64 - workspaceHydrationEnvelope: - title: workspace_hydration_envelope - $ref: '#/components/schemas/remoterunner.v1.WorkspaceHydrationEnvelope' - title: CreateRunnerRestoreRequest - additionalProperties: false - remoterunner.v1.CreateRunnerRestoreResponse: - type: object - properties: - restore: - title: restore - $ref: '#/components/schemas/remoterunner.v1.RunnerRestore' - session: - title: session - $ref: '#/components/schemas/remoterunner.v1.RunnerSession' - events: - type: array - items: - $ref: '#/components/schemas/remoterunner.v1.RunnerSessionEvent' - title: events - replayed: - type: boolean - title: replayed - title: CreateRunnerRestoreResponse - additionalProperties: false - remoterunner.v1.CreateRunnerSessionCheckpointRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - sessionId: - type: string - title: session_id - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - ownerBinding: - title: owner_binding - nullable: true - $ref: '#/components/schemas/remoterunner.v1.RunnerSessionOwnerBinding' - title: CreateRunnerSessionCheckpointRequest - additionalProperties: false - remoterunner.v1.CreateRunnerSessionCheckpointResponse: - type: object - properties: - receipt: - title: receipt - $ref: '#/components/schemas/remoterunner.v1.RunnerSessionCheckpointReceipt' - event: - title: event - $ref: '#/components/schemas/remoterunner.v1.RunnerSessionEvent' - title: CreateRunnerSessionCheckpointResponse - additionalProperties: false - remoterunner.v1.CreateRunnerSessionRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - userId: - type: string - title: user_id - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - runnerProfile: - type: string - title: runner_profile - minLength: 1 - runnerImage: - type: string - title: runner_image - workspaceSource: - type: string - title: workspace_source - repoUrl: - type: string - title: repo_url - branch: - type: string - title: branch - model: - type: string - title: model - ttlMinutes: - type: integer - title: ttl_minutes - maximum: 1440 - minimum: 1 - format: int32 - idleTtlMinutes: - type: integer - title: idle_ttl_minutes - maximum: 1440 - format: int32 - metadata: - title: metadata - $ref: '#/components/schemas/google.protobuf.Struct' - restore: - title: restore - $ref: '#/components/schemas/remoterunner.v1.RunnerSessionRestoreSpec' - agentRunId: - type: string - title: agent_run_id - maestroSessionId: - type: string - title: maestro_session_id - apexReservationId: - type: string - title: apex_reservation_id - runnerSessionId: - type: string - title: runner_session_id - runtimeGeneration: - type: - - integer - - string - title: runtime_generation - format: int64 - activationGeneration: - type: - - integer - - string - title: activation_generation - format: int64 - workspaceHydrationEnvelope: - title: workspace_hydration_envelope - $ref: '#/components/schemas/remoterunner.v1.WorkspaceHydrationEnvelope' - title: CreateRunnerSessionRequest - additionalProperties: false - remoterunner.v1.CreateRunnerSessionResponse: - type: object - properties: - session: - title: session - $ref: '#/components/schemas/remoterunner.v1.RunnerSession' - events: - type: array - items: - $ref: '#/components/schemas/remoterunner.v1.RunnerSessionEvent' - title: events - replayed: - type: boolean - title: replayed - title: CreateRunnerSessionResponse - additionalProperties: false - remoterunner.v1.ExecuteRunnerSessionStepRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - sessionId: - type: string - title: session_id - minLength: 1 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - argv: - type: array - items: - type: string - maxItems: 64 - title: argv - maxItems: 64 - cwd: - type: string - title: cwd - timeoutSeconds: - type: integer - title: timeout_seconds - maximum: 3600 - minimum: 1 - ownerBinding: - title: owner_binding - nullable: true - $ref: '#/components/schemas/remoterunner.v1.RunnerSessionOwnerBinding' - operation: - title: operation - $ref: '#/components/schemas/remoterunner.v1.RunnerSessionStepOperation' - stdin: - type: string - title: stdin - maxLength: 1398104 - x-protobuf-bytes-max-length: 1048576 - format: byte - expectedSnapshotId: - type: string - title: expected_snapshot_id - expectedSandboxSessionId: - type: string - title: expected_sandbox_session_id - expectedSandboxId: - type: string - title: expected_sandbox_id - expectedRunnerSessionId: - type: string - title: expected_runner_session_id - expectedCheckpointId: - type: string - title: expected_checkpoint_id - instructionArtifactRef: - type: string - title: instruction_artifact_ref - instructionDigestSha256: - type: string - title: instruction_digest_sha256 - instructionByteCount: - type: - - integer - - string - title: instruction_byte_count - format: int64 - claimLeaseGeneration: - type: - - integer - - string - title: claim_lease_generation - format: int64 - title: ExecuteRunnerSessionStepRequest - additionalProperties: false - remoterunner.v1.ExecuteRunnerSessionStepResponse: - type: object - properties: - receipt: - title: receipt - $ref: '#/components/schemas/remoterunner.v1.RunnerSessionStepReceipt' - event: - title: event - $ref: '#/components/schemas/remoterunner.v1.RunnerSessionEvent' - apexMcpOutput: - type: string - title: apex_mcp_output - maxLength: 1398104 - x-protobuf-bytes-max-length: 1048576 - format: byte - description: |- - Bounded output for fixed APEX MCP/discover/grade operations. MCP output is - transient; schema-validated discover/grade control output is replayable. - ephemeralOutput: - type: string - title: ephemeral_output - maxLength: 1398104 - x-protobuf-bytes-max-length: 1048576 - format: byte - description: |- - Live-only bytes for the fixed APEX task-instruction read. This field is - always empty on replay and is never copied into a receipt or event. - title: ExecuteRunnerSessionStepResponse - additionalProperties: false - remoterunner.v1.ExtendRunnerSessionRequest: - type: object - properties: - sessionId: - type: string - title: session_id - minLength: 1 - additionalMinutes: - type: integer - title: additional_minutes - maximum: 1440 - minimum: 1 - format: int32 - additionalIdleMinutes: - type: integer - title: additional_idle_minutes - maximum: 1440 - format: int32 - reason: - type: string - title: reason - title: ExtendRunnerSessionRequest - additionalProperties: false - remoterunner.v1.ExtendRunnerSessionResponse: - type: object - properties: - session: - title: session - $ref: '#/components/schemas/remoterunner.v1.RunnerSession' - event: - title: event - $ref: '#/components/schemas/remoterunner.v1.RunnerSessionEvent' - title: ExtendRunnerSessionResponse - additionalProperties: false - remoterunner.v1.GetRunnerAccountPolicyRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - title: GetRunnerAccountPolicyRequest - additionalProperties: false - remoterunner.v1.GetRunnerAccountPolicyResponse: - type: object - properties: - policy: - title: policy - $ref: '#/components/schemas/remoterunner.v1.RunnerAccountPolicyRecord' - title: GetRunnerAccountPolicyResponse - additionalProperties: false - remoterunner.v1.GetRunnerRestoreRequest: - type: object - properties: - restoreId: - type: string - title: restore_id - minLength: 1 - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - title: GetRunnerRestoreRequest - additionalProperties: false - remoterunner.v1.GetRunnerRestoreResponse: - type: object - properties: - restore: - title: restore - $ref: '#/components/schemas/remoterunner.v1.RunnerRestore' - title: GetRunnerRestoreResponse - additionalProperties: false - remoterunner.v1.GetRunnerSessionRequest: - type: object - properties: - sessionId: - type: string - title: session_id - minLength: 1 - title: GetRunnerSessionRequest - additionalProperties: false - remoterunner.v1.GetRunnerSessionResponse: - type: object - properties: - session: - title: session - $ref: '#/components/schemas/remoterunner.v1.RunnerSession' - title: GetRunnerSessionResponse - additionalProperties: false - remoterunner.v1.GetStatusRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - title: GetStatusRequest - additionalProperties: false - remoterunner.v1.GetStatusResponse: - type: object - properties: - service: - type: string - title: service - workspaceId: - type: string - title: workspace_id - downstreamPolicy: - type: string - title: downstream_policy - title: GetStatusResponse - additionalProperties: false - remoterunner.v1.ListRunnerProfilesRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - includeUnavailable: - type: boolean - title: include_unavailable - title: ListRunnerProfilesRequest - additionalProperties: false - remoterunner.v1.ListRunnerProfilesResponse: - type: object - properties: - profiles: - type: array - items: - $ref: '#/components/schemas/remoterunner.v1.RunnerProfileAvailability' - title: profiles - title: ListRunnerProfilesResponse - additionalProperties: false - remoterunner.v1.ListRunnerRestoresRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - state: - title: state - $ref: '#/components/schemas/remoterunner.v1.RunnerRestoreState' - limit: - type: integer - title: limit - maximum: 200 - format: int32 - offset: - type: integer - title: offset - format: int32 - title: ListRunnerRestoresRequest - additionalProperties: false - remoterunner.v1.ListRunnerRestoresResponse: - type: object - properties: - restores: - type: array - items: - $ref: '#/components/schemas/remoterunner.v1.RunnerRestore' - title: restores - nextOffset: - type: integer - title: next_offset - format: int32 - title: ListRunnerRestoresResponse - additionalProperties: false - remoterunner.v1.ListRunnerSessionEventsRequest: - type: object - properties: - sessionId: - type: string - title: session_id - minLength: 1 - afterSequence: - type: - - integer - - string - title: after_sequence - format: int64 - limit: - type: integer - title: limit - maximum: 500 - format: int32 - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - title: ListRunnerSessionEventsRequest - additionalProperties: false - remoterunner.v1.ListRunnerSessionEventsResponse: - type: object - properties: - events: - type: array - items: - $ref: '#/components/schemas/remoterunner.v1.RunnerSessionEvent' - title: events - nextSequence: - type: - - integer - - string - title: next_sequence - format: int64 - title: ListRunnerSessionEventsResponse - additionalProperties: false - remoterunner.v1.ListRunnerSessionsRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - state: - title: state - $ref: '#/components/schemas/remoterunner.v1.RunnerSessionState' - limit: - type: integer - title: limit - maximum: 200 - format: int32 - offset: - type: integer - title: offset - format: int32 - title: ListRunnerSessionsRequest - additionalProperties: false - remoterunner.v1.ListRunnerSessionsResponse: - type: object - properties: - sessions: - type: array - items: - $ref: '#/components/schemas/remoterunner.v1.RunnerSession' - title: sessions - nextOffset: - type: integer - title: next_offset - format: int32 - title: ListRunnerSessionsResponse - additionalProperties: false - remoterunner.v1.MintAttachTokenRequest: - type: object - properties: - sessionId: - type: string - title: session_id - minLength: 1 - subjectId: - type: string - title: subject_id - roles: - type: array - items: - $ref: '#/components/schemas/remoterunner.v1.RunnerAttachRole' - title: roles - ttlMinutes: - type: integer - title: ttl_minutes - maximum: 60 - format: int32 - title: MintAttachTokenRequest - additionalProperties: false - remoterunner.v1.MintAttachTokenResponse: - type: object - properties: - token: - title: token - $ref: '#/components/schemas/remoterunner.v1.RunnerAttachToken' - tokenSecret: - type: string - title: token_secret - ownerInstanceId: - type: string - title: owner_instance_id - runnerServiceName: - type: string - title: runner_service_name - title: MintAttachTokenResponse - additionalProperties: false - remoterunner.v1.RecordRunnerSessionArtifactLifecycleRequest: - type: object - properties: - sessionId: - type: string - title: session_id - minLength: 1 - artifactClass: - title: artifact_class - $ref: '#/components/schemas/remoterunner.v1.RunnerArtifactClass' - state: - title: state - $ref: '#/components/schemas/remoterunner.v1.RunnerArtifactLifecycleState' - artifactUri: - type: string - title: artifact_uri - manifestPath: - type: string - title: manifest_path - reason: - type: string - title: reason - message: - type: string - title: message - retentionExpiresAt: - title: retention_expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: RecordRunnerSessionArtifactLifecycleRequest - additionalProperties: false - remoterunner.v1.RecordRunnerSessionArtifactLifecycleResponse: - type: object - properties: - session: - title: session - $ref: '#/components/schemas/remoterunner.v1.RunnerSession' - event: - title: event - $ref: '#/components/schemas/remoterunner.v1.RunnerSessionEvent' - title: RecordRunnerSessionArtifactLifecycleResponse - additionalProperties: false - remoterunner.v1.RevokeAttachTokenRequest: - type: object - properties: - sessionId: - type: string - title: session_id - minLength: 1 - tokenId: - type: string - title: token_id - minLength: 1 - title: RevokeAttachTokenRequest - additionalProperties: false - remoterunner.v1.RevokeAttachTokenResponse: - type: object - properties: - token: - title: token - $ref: '#/components/schemas/remoterunner.v1.RunnerAttachToken' - event: - title: event - $ref: '#/components/schemas/remoterunner.v1.RunnerSessionEvent' - title: RevokeAttachTokenResponse - additionalProperties: false - remoterunner.v1.RunnerAccountPolicy: - type: object - properties: - maxConcurrentSessions: - type: integer - title: max_concurrent_sessions - format: int32 - maxSessionTtlMinutes: - type: integer - title: max_session_ttl_minutes - format: int32 - maxIdleTtlMinutes: - type: integer - title: max_idle_ttl_minutes - format: int32 - monthlyRunnerMinutes: - type: - - integer - - string - title: monthly_runner_minutes - format: int64 - monthlySpendCapMicros: - type: - - integer - - string - title: monthly_spend_cap_micros - format: int64 - runnerMinuteCostMicros: - type: - - integer - - string - title: runner_minute_cost_micros - format: int64 - allowedRunnerProfiles: - type: array - items: - type: string - title: allowed_runner_profiles - allowedModels: - type: array - items: - type: string - title: allowed_models - allowedWorkspaceSources: - type: array - items: - type: string - title: allowed_workspace_sources - operatorOverrideScope: - type: string - title: operator_override_scope - workspaceScopedUsageBudgets: - type: boolean - title: workspace_scoped_usage_budgets - title: RunnerAccountPolicy - additionalProperties: false - remoterunner.v1.RunnerAccountPolicyRecord: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - policy: - title: policy - $ref: '#/components/schemas/remoterunner.v1.RunnerAccountPolicy' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - source: - type: string - title: source - title: RunnerAccountPolicyRecord - additionalProperties: false - remoterunner.v1.RunnerAttachToken: - type: object - properties: - id: - type: string - title: id - sessionId: - type: string - title: session_id - subjectId: - type: string - title: subject_id - roles: - type: array - items: - $ref: '#/components/schemas/remoterunner.v1.RunnerAttachRole' - title: roles - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - revokedAt: - title: revoked_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: RunnerAttachToken - additionalProperties: false - remoterunner.v1.RunnerProfile: - type: object - properties: - id: - type: string - title: id - displayName: - type: string - title: display_name - enabled: - type: boolean - title: enabled - defaultTtlMinutes: - type: integer - title: default_ttl_minutes - format: int32 - maxTtlMinutes: - type: integer - title: max_ttl_minutes - format: int32 - defaultIdleTtlMinutes: - type: integer - title: default_idle_ttl_minutes - format: int32 - maxIdleTtlMinutes: - type: integer - title: max_idle_ttl_minutes - format: int32 - isolationLevel: - type: string - title: isolation_level - interruption: - type: string - title: interruption - workspacePersistence: - type: string - title: workspace_persistence - costClass: - type: string - title: cost_class - meteringMultiplierMicros: - type: - - integer - - string - title: metering_multiplier_micros - format: int64 - experimental: - type: boolean - title: experimental - productionEligible: - type: boolean - title: production_eligible - title: RunnerProfile - additionalProperties: false - remoterunner.v1.RunnerProfileAvailability: - type: object - properties: - profile: - title: profile - $ref: '#/components/schemas/remoterunner.v1.RunnerProfile' - available: - type: boolean - title: available - unavailableReason: - type: string - title: unavailable_reason - policySource: - type: string - title: policy_source - title: RunnerProfileAvailability - additionalProperties: false - remoterunner.v1.RunnerProviderProof: - type: object - properties: - provider: - type: string - title: provider - providerMode: - type: string - title: provider_mode - workerId: - type: string - title: worker_id - runtimeImageDigest: - type: string - title: runtime_image_digest - title: RunnerProviderProof - additionalProperties: false - remoterunner.v1.RunnerRestore: - type: object - properties: - id: - type: string - title: id - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - sourceSessionId: - type: string - title: source_session_id - targetSessionId: - type: string - title: target_session_id - maestroSessionId: - type: string - title: maestro_session_id - state: - title: state - $ref: '#/components/schemas/remoterunner.v1.RunnerRestoreState' - artifactRef: - type: string - title: artifact_ref - manifestPath: - type: string - title: manifest_path - runnerProfile: - type: string - title: runner_profile - runnerImage: - type: string - title: runner_image - workspaceSource: - type: string - title: workspace_source - repoUrl: - type: string - title: repo_url - branch: - type: string - title: branch - model: - type: string - title: model - ttlMinutes: - type: integer - title: ttl_minutes - format: int32 - idleTtlMinutes: - type: integer - title: idle_ttl_minutes - format: int32 - ownerInstanceId: - type: string - title: owner_instance_id - failureCode: - title: failure_code - $ref: '#/components/schemas/remoterunner.v1.RunnerRestoreFailureCode' - failureMessage: - type: string - title: failure_message - requestedAt: - title: requested_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - hydratedAt: - title: hydrated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - providerStartedAt: - title: provider_started_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - identityReadyAt: - title: identity_ready_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - attachableAt: - title: attachable_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - failedAt: - title: failed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - metadata: - title: metadata - $ref: '#/components/schemas/google.protobuf.Struct' - title: RunnerRestore - additionalProperties: false - remoterunner.v1.RunnerSession: - type: object - properties: - id: - type: string - title: id - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - userId: - type: string - title: user_id - agentRunId: - type: string - title: agent_run_id - maestroSessionId: - type: string - title: maestro_session_id - state: - title: state - $ref: '#/components/schemas/remoterunner.v1.RunnerSessionState' - runnerProfile: - type: string - title: runner_profile - runnerImage: - type: string - title: runner_image - workspaceSource: - type: string - title: workspace_source - repoUrl: - type: string - title: repo_url - branch: - type: string - title: branch - model: - type: string - title: model - ownerInstanceId: - type: string - title: owner_instance_id - description: |- - Platform-minted runtime owner generation. Hosted runtimes must echo this - value on the remote-runner identity endpoint before new attach requests are - proxied. - runnerPodNamespace: - type: string - title: runner_pod_namespace - runnerPodName: - type: string - title: runner_pod_name - runnerServiceName: - type: string - title: runner_service_name - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - startedAt: - title: started_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - idleExpiresAt: - title: idle_expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - stoppedAt: - title: stopped_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - stopReason: - type: string - title: stop_reason - lastHeartbeatAt: - title: last_heartbeat_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - usedRunnerSeconds: - type: - - integer - - string - title: used_runner_seconds - format: int64 - usedIdleSeconds: - type: - - integer - - string - title: used_idle_seconds - format: int64 - estimatedCostMicros: - type: - - integer - - string - title: estimated_cost_micros - format: int64 - metadata: - title: metadata - $ref: '#/components/schemas/google.protobuf.Struct' - reservedRunnerSeconds: - type: - - integer - - string - title: reserved_runner_seconds - format: int64 - reservedCostMicros: - type: - - integer - - string - title: reserved_cost_micros - format: int64 - resolvedProfile: - title: resolved_profile - $ref: '#/components/schemas/remoterunner.v1.RunnerProfile' - restore: - title: restore - $ref: '#/components/schemas/remoterunner.v1.RunnerSessionRestoreSpec' - restoreStatus: - title: restore_status - $ref: '#/components/schemas/remoterunner.v1.RunnerSessionRestoreStatus' - apexAuthorityState: - title: apex_authority_state - $ref: '#/components/schemas/remoterunner.v1.RunnerSessionApexAuthorityState' - apexReservationId: - type: string - title: apex_reservation_id - title: RunnerSession - additionalProperties: false - remoterunner.v1.RunnerSessionCheckpointReceipt: - type: object - properties: - checkpointId: - type: string - title: checkpoint_id - sourceSessionId: - type: string - title: source_session_id - replayed: - type: boolean - title: replayed - title: RunnerSessionCheckpointReceipt - additionalProperties: false - remoterunner.v1.RunnerSessionEvent: - type: object - properties: - id: - type: string - title: id - sessionId: - type: string - title: session_id - sequence: - type: - - integer - - string - title: sequence - format: int64 - eventType: - type: string - title: event_type - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Struct' - title: RunnerSessionEvent - additionalProperties: false - remoterunner.v1.RunnerSessionOwnerBinding: - type: object - properties: - missionId: - type: string - title: mission_id - minLength: 1 - runtimeRunId: - type: string - title: runtime_run_id - minLength: 1 - authorityGrantId: - type: string - title: authority_grant_id - minLength: 1 - contractVersion: - type: string - title: contract_version - minLength: 1 - runnerProfile: - type: string - title: runner_profile - minLength: 1 - policyVersion: - type: string - title: policy_version - decisionRoute: - type: string - title: decision_route - selectedCandidateId: - type: string - title: selected_candidate_id - decisionRef: - type: string - title: decision_ref - decisionDigestSha256: - type: string - title: decision_digest_sha256 - title: RunnerSessionOwnerBinding - additionalProperties: false - remoterunner.v1.RunnerSessionRestoreSpec: - type: object - properties: - sourceRunnerSessionId: - type: string - title: source_runner_session_id - sourceMaestroSessionId: - type: string - title: source_maestro_session_id - snapshotArtifactUri: - type: string - title: snapshot_artifact_uri - snapshotManifestPath: - type: string - title: snapshot_manifest_path - snapshotManifestProtocolVersion: - type: string - title: snapshot_manifest_protocol_version - artifactDigest: - type: string - title: artifact_digest - failurePolicy: - title: failure_policy - $ref: '#/components/schemas/remoterunner.v1.RunnerSessionRestoreFailurePolicy' - metadata: - title: metadata - $ref: '#/components/schemas/google.protobuf.Struct' - title: RunnerSessionRestoreSpec - additionalProperties: false - remoterunner.v1.RunnerSessionRestoreStatus: - type: object - properties: - state: - title: state - $ref: '#/components/schemas/remoterunner.v1.RunnerSessionRestoreState' - localManifestPath: - type: string - title: local_manifest_path - hydratedArtifactUri: - type: string - title: hydrated_artifact_uri - failureReason: - type: string - title: failure_reason - failureMessage: - type: string - title: failure_message - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: RunnerSessionRestoreStatus - additionalProperties: false - remoterunner.v1.RunnerSessionStepReceipt: - type: object - properties: - commandId: - type: string - title: command_id - exitCode: - type: integer - title: exit_code - format: int32 - stdout: - type: string - title: stdout - stderr: - type: string - title: stderr - replayed: - type: boolean - title: replayed - providerProof: - title: provider_proof - $ref: '#/components/schemas/remoterunner.v1.RunnerProviderProof' - stdinSha256: - type: string - title: stdin_sha256 - outputUnavailable: - type: boolean - title: output_unavailable - outputDigestSha256: - type: string - title: output_digest_sha256 - outputByteCount: - type: - - integer - - string - title: output_byte_count - format: int64 - title: RunnerSessionStepReceipt - additionalProperties: false - remoterunner.v1.StopRunnerSessionRequest: - type: object - properties: - sessionId: - type: string - title: session_id - minLength: 1 - reason: - type: string - title: reason - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - title: StopRunnerSessionRequest - additionalProperties: false - remoterunner.v1.StopRunnerSessionResponse: - type: object - properties: - session: - title: session - $ref: '#/components/schemas/remoterunner.v1.RunnerSession' - event: - title: event - $ref: '#/components/schemas/remoterunner.v1.RunnerSessionEvent' - title: StopRunnerSessionResponse - additionalProperties: false - remoterunner.v1.UpsertRunnerAccountPolicyRequest: - type: object - properties: - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - policy: - title: policy - $ref: '#/components/schemas/remoterunner.v1.RunnerAccountPolicy' - title: UpsertRunnerAccountPolicyRequest - additionalProperties: false - remoterunner.v1.UpsertRunnerAccountPolicyResponse: - type: object - properties: - policy: - title: policy - $ref: '#/components/schemas/remoterunner.v1.RunnerAccountPolicyRecord' - title: UpsertRunnerAccountPolicyResponse - additionalProperties: false - remoterunner.v1.WorkspaceHydrationClaims: - type: object - properties: - schemaVersion: - type: integer - title: schema_version - envelopeId: - type: string - title: envelope_id - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - sourceWorkspaceId: - type: string - title: source_workspace_id - sourceWorkspaceVersion: - type: string - title: source_workspace_version - sourceRevisionId: - type: string - title: source_revision_id - immutableSnapshotId: - type: string - title: immutable_snapshot_id - immutableSnapshotDigest: - type: string - title: immutable_snapshot_digest - workspaceSkillSetDigest: - type: string - title: workspace_skill_set_digest - capabilitySetDigest: - type: string - title: capability_set_digest - runnerSessionId: - type: string - title: runner_session_id - maestroSessionId: - type: string - title: maestro_session_id - runtimeGeneration: - type: - - integer - - string - title: runtime_generation - format: int64 - activationGeneration: - type: - - integer - - string - title: activation_generation - format: int64 - audience: - type: string - title: audience - issuedAtMs: - type: - - integer - - string - title: issued_at_ms - format: int64 - notBeforeMs: - type: - - integer - - string - title: not_before_ms - format: int64 - expiresAtMs: - type: - - integer - - string - title: expires_at_ms - format: int64 - replayNonce: - type: string - title: replay_nonce - extractionPolicyVersion: - type: string - title: extraction_policy_version - policyVersion: - type: string - title: policy_version - artifactRef: - type: string - title: artifact_ref - signerIdentity: - type: string - title: signer_identity - keyId: - type: string - title: key_id - maxFiles: - type: - - integer - - string - title: max_files - format: int64 - maxBytes: - type: - - integer - - string - title: max_bytes - format: int64 - title: WorkspaceHydrationClaims - additionalProperties: false - description: |- - Immutable workspace authority signed by Platform for Runner Host admission. - Acceptance proves only the exact coordinates below; materialization remains - a separate owner operation. - remoterunner.v1.WorkspaceHydrationEnvelope: - type: object - properties: - claims: - title: claims - $ref: '#/components/schemas/remoterunner.v1.WorkspaceHydrationClaims' - signature: - type: string - title: signature - minLength: 1 - title: WorkspaceHydrationEnvelope - required: - - claims - additionalProperties: false - connect-protocol-version: - type: number - title: Connect-Protocol-Version - enum: - - 1 - description: Define the version of the Connect protocol - const: 1 - connect-timeout-header: - type: number - title: Connect-Timeout-Ms - description: Define the timeout, in ms - connect.error: - type: object - properties: - code: - type: string - examples: - - not_found - enum: - - canceled - - unknown - - invalid_argument - - deadline_exceeded - - not_found - - already_exists - - permission_denied - - resource_exhausted - - failed_precondition - - aborted - - out_of_range - - unimplemented - - internal - - unavailable - - data_loss - - unauthenticated - description: The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code]. - message: - type: string - description: A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client. - detail: - $ref: '#/components/schemas/google.protobuf.Any' - title: Connect Error - additionalProperties: true - description: 'Error type returned by Connect: https://connectrpc.com/docs/go/errors/#http-representation' - google.protobuf.Any: - type: object - properties: - type: - type: string - value: - type: string - format: binary - debug: - type: object - additionalProperties: true - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. -security: [] -tags: - - name: remoterunner.v1.RemoteRunnerService - description: RemoteRunnerService owns account-scoped hosted Maestro runner sessions. diff --git a/openapi/toolexecution/v1/toolexecution.openapi.yaml b/openapi/toolexecution/v1/toolexecution.openapi.yaml deleted file mode 100644 index 75e0525..0000000 --- a/openapi/toolexecution/v1/toolexecution.openapi.yaml +++ /dev/null @@ -1,1627 +0,0 @@ -openapi: 3.1.0 -info: - title: toolexecution.v1 -paths: - /toolexecution.v1.ToolExecutionService/ExecuteTool: - post: - tags: - - toolexecution.v1.ToolExecutionService - summary: ExecuteTool - description: ExecuteTool starts or idempotently replays a governed tool execution. - operationId: toolexecution.v1.ToolExecutionService.ExecuteTool - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/toolexecution.v1.ExecuteToolRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/toolexecution.v1.ExecuteToolResponse' - /toolexecution.v1.ToolExecutionService/ResumeToolExecution: - post: - tags: - - toolexecution.v1.ToolExecutionService - summary: ResumeToolExecution - description: |- - ResumeToolExecution resumes an execution that was parked on an approval - wait, preserving the original tool call context. - operationId: toolexecution.v1.ToolExecutionService.ResumeToolExecution - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/toolexecution.v1.ResumeToolExecutionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/toolexecution.v1.ResumeToolExecutionResponse' - /toolexecution.v1.ToolExecutionService/RecordToolExecutionOutput: - post: - tags: - - toolexecution.v1.ToolExecutionService - summary: RecordToolExecutionOutput - description: |- - RecordToolExecutionOutput records an asynchronous executor result and - finalizes audit, meter, and provenance metadata. - operationId: toolexecution.v1.ToolExecutionService.RecordToolExecutionOutput - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/toolexecution.v1.RecordToolExecutionOutputRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/toolexecution.v1.RecordToolExecutionOutputResponse' - /toolexecution.v1.ToolExecutionService/GetToolExecution: - post: - tags: - - toolexecution.v1.ToolExecutionService - summary: GetToolExecution - description: |- - GetToolExecution retrieves one tool execution by ID. - When wait_timeout_ms is greater than zero, the owner may block until the - execution is settled (terminal or WAITING_APPROVAL) or the timeout - elapses. Zero is a snapshot and remains backward compatible. - operationId: toolexecution.v1.ToolExecutionService.GetToolExecution - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/toolexecution.v1.GetToolExecutionRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/toolexecution.v1.GetToolExecutionResponse' - /toolexecution.v1.ToolExecutionService/ListToolExecutions: - post: - tags: - - toolexecution.v1.ToolExecutionService - summary: ListToolExecutions - description: |- - ListToolExecutions lists executions by workspace, AgentRun, Objective, - tool, connector, state, or approval request. - operationId: toolexecution.v1.ToolExecutionService.ListToolExecutions - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/toolexecution.v1.ListToolExecutionsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/toolexecution.v1.ListToolExecutionsResponse' -components: - schemas: - common.v1.RiskLevel: - type: string - title: RiskLevel - enum: - - RISK_LEVEL_UNSPECIFIED - - RISK_LEVEL_LOW - - RISK_LEVEL_MEDIUM - - RISK_LEVEL_HIGH - - RISK_LEVEL_CRITICAL - description: RiskLevel classifies the risk of an action. - common.v1.Surface: - type: string - title: Surface - enum: - - SURFACE_UNSPECIFIED - - SURFACE_ENSEMBLE - - SURFACE_CHAT - - SURFACE_MAESTRO - - SURFACE_CONDUCTOR - - SURFACE_SLACK - - SURFACE_EXTERNAL_AGENT - description: |- - Surface identifies the product or channel surface that originated a platform - action. It is shared by runtime, audit, and product-facing services so - callers do not invent drift-prone string labels. - google.protobuf.NullValue: - type: string - title: NullValue - enum: - - NULL_VALUE - description: |- - `NullValue` is a singleton enumeration to represent the null value for the - `Value` type union. - - The JSON representation for `NullValue` is JSON `null`. - platform.v1.ResourceKind: - type: string - title: ResourceKind - enum: - - RESOURCE_KIND_UNSPECIFIED - - RESOURCE_KIND_AGENT - - RESOURCE_KIND_TOOL - - RESOURCE_KIND_REPO - - RESOURCE_KIND_DATASET - - RESOURCE_KIND_DATABASE - - RESOURCE_KIND_CRM_OBJECT - - RESOURCE_KIND_MODEL_ROUTE - - RESOURCE_KIND_EXTERNAL - - RESOURCE_KIND_VFS_OBJECT - - RESOURCE_KIND_VFS_OBJECT_VERSION - - RESOURCE_KIND_ARTIFACT - - RESOURCE_KIND_ARTIFACT_VERSION - - RESOURCE_KIND_GENERATED_ASSET - toolexecution.v1.ToolExecutionFailureCode: - type: string - title: ToolExecutionFailureCode - enum: - - TOOL_EXECUTION_FAILURE_CODE_UNSPECIFIED - - TOOL_EXECUTION_FAILURE_CODE_INVALID_REQUEST - - TOOL_EXECUTION_FAILURE_CODE_UNSUPPORTED_TOOL - - TOOL_EXECUTION_FAILURE_CODE_AUTHORITY_INVALID - - TOOL_EXECUTION_FAILURE_CODE_DEPENDENCY_UNAVAILABLE - - TOOL_EXECUTION_FAILURE_CODE_CONNECTOR_FAILED - - TOOL_EXECUTION_FAILURE_CODE_SANDBOX_PROVISION_FAILED - - TOOL_EXECUTION_FAILURE_CODE_SANDBOX_OPERATION_FAILED - - TOOL_EXECUTION_FAILURE_CODE_RUNNER_LEDGER_REQUIRED - - TOOL_EXECUTION_FAILURE_CODE_APPROVAL_DENIED - - TOOL_EXECUTION_FAILURE_CODE_APPROVAL_EXPIRED - - TOOL_EXECUTION_FAILURE_CODE_EXECUTION_ABANDONED - - TOOL_EXECUTION_FAILURE_CODE_EXECUTION_CANCELLED - - TOOL_EXECUTION_FAILURE_CODE_CALLER_REPORTED_FAILURE - description: |- - ToolExecutionFailureCode is the bounded, owner-assigned terminal failure - taxonomy. It intentionally excludes provider prose, resource identifiers, - and secret-bearing detail. - toolexecution.v1.ToolExecutionPolicyDecision: - type: string - title: ToolExecutionPolicyDecision - enum: - - TOOL_EXECUTION_POLICY_DECISION_UNSPECIFIED - - TOOL_EXECUTION_POLICY_DECISION_ALLOW - - TOOL_EXECUTION_POLICY_DECISION_DENY - - TOOL_EXECUTION_POLICY_DECISION_REQUIRE_APPROVAL - description: |- - ToolExecutionPolicyDecision is a normalized policy result from Gate, - Governance, approval policy, or a connector capability check. - toolexecution.v1.ToolExecutionProposalKind: - type: string - title: ToolExecutionProposalKind - enum: - - TOOL_EXECUTION_PROPOSAL_KIND_UNSPECIFIED - - TOOL_EXECUTION_PROPOSAL_KIND_CHECKPOINT - - TOOL_EXECUTION_PROPOSAL_KIND_ARTIFACT - - TOOL_EXECUTION_PROPOSAL_KIND_MEMORY - description: |- - ToolExecutionProposalKind marks structured outputs that downstream runtime - checkpoints, artifact proposals, and memory proposals may safely consume. - toolexecution.v1.ToolExecutionStage: - type: string - title: ToolExecutionStage - enum: - - TOOL_EXECUTION_STAGE_UNSPECIFIED - - TOOL_EXECUTION_STAGE_CAPABILITY_LOOKUP - - TOOL_EXECUTION_STAGE_CREDENTIAL_RESOLUTION - - TOOL_EXECUTION_STAGE_GATE_POLICY - - TOOL_EXECUTION_STAGE_GOVERNANCE_POLICY - - TOOL_EXECUTION_STAGE_APPROVAL - - TOOL_EXECUTION_STAGE_EXECUTION - - TOOL_EXECUTION_STAGE_AUDIT - - TOOL_EXECUTION_STAGE_METER - - TOOL_EXECUTION_STAGE_PROVENANCE - description: ToolExecutionStage names each platform boundary crossed by ExecuteTool. - toolexecution.v1.ToolExecutionState: - type: string - title: ToolExecutionState - enum: - - TOOL_EXECUTION_STATE_UNSPECIFIED - - TOOL_EXECUTION_STATE_ACCEPTED - - TOOL_EXECUTION_STATE_POLICY_EVALUATING - - TOOL_EXECUTION_STATE_WAITING_APPROVAL - - TOOL_EXECUTION_STATE_RUNNING - - TOOL_EXECUTION_STATE_SUCCEEDED - - TOOL_EXECUTION_STATE_FAILED - - TOOL_EXECUTION_STATE_DENIED - - TOOL_EXECUTION_STATE_CANCELLED - description: ToolExecutionState is the durable lifecycle for one tool call. - toolexecution.v1.ToolExecutionStepState: - type: string - title: ToolExecutionStepState - enum: - - TOOL_EXECUTION_STEP_STATE_UNSPECIFIED - - TOOL_EXECUTION_STEP_STATE_SUCCEEDED - - TOOL_EXECUTION_STEP_STATE_WAITING - - TOOL_EXECUTION_STEP_STATE_DENIED - - TOOL_EXECUTION_STEP_STATE_FAILED - - TOOL_EXECUTION_STEP_STATE_SKIPPED - description: ToolExecutionStepState describes the state of a platform boundary decision. - google.protobuf.ListValue: - type: object - properties: - values: - type: array - items: - $ref: '#/components/schemas/google.protobuf.Value' - title: values - description: Repeated field of dynamically typed values. - title: ListValue - additionalProperties: false - description: |- - `ListValue` is a wrapper around a repeated field of values. - - The JSON representation for `ListValue` is JSON array. - google.protobuf.Struct: - type: object - additionalProperties: - $ref: '#/components/schemas/google.protobuf.Value' - description: |- - `Struct` represents a structured data value, consisting of fields - which map to dynamically typed values. In some languages, `Struct` - might be supported by a native representation. For example, in - scripting languages like JS a struct is represented as an - object. The details of that representation are described together - with the proto support for the language. - - The JSON representation for `Struct` is JSON object. - google.protobuf.Struct.FieldsEntry: - type: object - properties: - key: - type: string - title: key - value: - title: value - $ref: '#/components/schemas/google.protobuf.Value' - title: FieldsEntry - additionalProperties: false - google.protobuf.Timestamp: - type: string - examples: - - 1s - - 1.000340012s - format: date-time - description: |- - A Timestamp represents a point in time independent of any time zone or local - calendar, encoded as a count of seconds and fractions of seconds at - nanosecond resolution. The count is relative to an epoch at UTC midnight on - January 1, 1970, in the proleptic Gregorian calendar which extends the - Gregorian calendar backwards to year one. - - All minutes are 60 seconds long. Leap seconds are "smeared" so that no leap - second table is needed for interpretation, using a [24-hour linear - smear](https://developers.google.com/time/smear). - - The range is from 0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z. By - restricting to that range, we ensure that we can convert to and from [RFC - 3339](https://www.ietf.org/rfc/rfc3339.txt) date strings. - - # Examples - - Example 1: Compute Timestamp from POSIX `time()`. - - Timestamp timestamp; - timestamp.set_seconds(time(NULL)); - timestamp.set_nanos(0); - - Example 2: Compute Timestamp from POSIX `gettimeofday()`. - - struct timeval tv; - gettimeofday(&tv, NULL); - - Timestamp timestamp; - timestamp.set_seconds(tv.tv_sec); - timestamp.set_nanos(tv.tv_usec * 1000); - - Example 3: Compute Timestamp from Win32 `GetSystemTimeAsFileTime()`. - - FILETIME ft; - GetSystemTimeAsFileTime(&ft); - UINT64 ticks = (((UINT64)ft.dwHighDateTime) << 32) | ft.dwLowDateTime; - - // A Windows tick is 100 nanoseconds. Windows epoch 1601-01-01T00:00:00Z - // is 11644473600 seconds before Unix epoch 1970-01-01T00:00:00Z. - Timestamp timestamp; - timestamp.set_seconds((INT64) ((ticks / 10000000) - 11644473600LL)); - timestamp.set_nanos((INT32) ((ticks % 10000000) * 100)); - - Example 4: Compute Timestamp from Java `System.currentTimeMillis()`. - - long millis = System.currentTimeMillis(); - - Timestamp timestamp = Timestamp.newBuilder().setSeconds(millis / 1000) - .setNanos((int) ((millis % 1000) * 1000000)).build(); - - Example 5: Compute Timestamp from Java `Instant.now()`. - - Instant now = Instant.now(); - - Timestamp timestamp = - Timestamp.newBuilder().setSeconds(now.getEpochSecond()) - .setNanos(now.getNano()).build(); - - Example 6: Compute Timestamp from current time in Python. - - timestamp = Timestamp() - timestamp.GetCurrentTime() - - # JSON Mapping - - In JSON format, the Timestamp type is encoded as a string in the - [RFC 3339](https://www.ietf.org/rfc/rfc3339.txt) format. That is, the - format is "{year}-{month}-{day}T{hour}:{min}:{sec}[.{frac_sec}]Z" - where {year} is always expressed using four digits while {month}, {day}, - {hour}, {min}, and {sec} are zero-padded to two digits each. The fractional - seconds, which can go up to 9 digits (i.e. up to 1 nanosecond resolution), - are optional. The "Z" suffix indicates the timezone ("UTC"); the timezone - is required. A proto3 JSON serializer should always use UTC (as indicated by - "Z") when printing the Timestamp type and a proto3 JSON parser should be - able to accept both UTC and other timezones (as indicated by an offset). - - For example, "2017-01-15T01:30:15.01Z" encodes 15.01 seconds past - 01:30 UTC on January 15, 2017. - - In JavaScript, one can convert a Date object to this format using the - standard - [toISOString()](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Date/toISOString) - method. In Python, a standard `datetime.datetime` object can be converted - to this format using - [`strftime`](https://docs.python.org/2/library/time.html#time.strftime) with - the time format spec '%Y-%m-%dT%H:%M:%S.%fZ'. Likewise, in Java, one can use - the Joda Time's [`ISODateTimeFormat.dateTime()`]( - http://joda-time.sourceforge.net/apidocs/org/joda/time/format/ISODateTimeFormat.html#dateTime() - ) to obtain a formatter capable of generating timestamps in this format. - google.protobuf.Value: - oneOf: - - type: "null" - - type: number - - type: string - - type: boolean - - type: array - - type: object - additionalProperties: true - description: |- - `Value` represents a dynamically typed value which can be either - null, a number, a string, a boolean, a recursive struct value, or a - list of values. A producer of value is expected to set one of these - variants. Absence of any variant indicates an error. - - The JSON representation for `Value` is JSON value. - platform.v1.ResourceRef: - type: object - properties: - resourceId: - type: string - title: resource_id - minLength: 1 - kind: - title: kind - $ref: '#/components/schemas/platform.v1.ResourceKind' - versionId: - type: string - title: version_id - description: Stable immutable version identity, when the reference is version-bound. - version: - type: integer - title: version - format: int32 - description: |- - Owner-defined monotonic version number. Zero means the latest version - when version_id is empty; version_id wins when both are supplied. - title: ResourceRef - additionalProperties: false - description: |- - ResourceRef is the canonical structured pointer for durable Platform - content. It is intentionally not a URI: callers carry organization and - workspace authority in the surrounding request, while a resolver owned by - the resource's service decides whether a reference yields metadata, VFS - identity, or a short-lived byte-access grant. - toolexecution.v1.CommandAuditReceipt: - type: object - properties: - eventId: - type: string - title: event_id - runnerSessionId: - type: string - title: runner_session_id - sequence: - type: - - integer - - string - title: sequence - format: int64 - eventType: - type: string - title: event_type - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - payloadDigestSha256: - type: string - title: payload_digest_sha256 - title: CommandAuditReceipt - additionalProperties: false - toolexecution.v1.ConnectorRef: - type: object - properties: - connectionId: - type: string - title: connection_id - providerId: - type: string - title: provider_id - resourceId: - type: string - title: resource_id - resourceKind: - type: string - title: resource_kind - credentialRef: - type: string - title: credential_ref - credentialEnvironment: - type: string - title: credential_environment - title: ConnectorRef - additionalProperties: false - description: |- - ConnectorRef identifies the connector, resource, and credential namespace - needed to execute an external tool call. MCP/internal tools may leave - connection_id empty while still setting provider_id/resource metadata. - toolexecution.v1.ExecuteToolRequest: - type: object - properties: - linkage: - title: linkage - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionLinkage' - tool: - title: tool - $ref: '#/components/schemas/toolexecution.v1.ToolRef' - connector: - title: connector - $ref: '#/components/schemas/toolexecution.v1.ConnectorRef' - arguments: - title: arguments - $ref: '#/components/schemas/google.protobuf.Struct' - riskLevel: - title: risk_level - $ref: '#/components/schemas/common.v1.RiskLevel' - retryPolicy: - title: retry_policy - $ref: '#/components/schemas/toolexecution.v1.ToolRetryPolicy' - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - metadata: - type: object - title: metadata - additionalProperties: - type: string - title: value - traceContext: - title: trace_context - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionTraceContext' - title: ExecuteToolRequest - required: - - linkage - - tool - additionalProperties: false - toolexecution.v1.ExecuteToolRequest.MetadataEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: MetadataEntry - additionalProperties: false - toolexecution.v1.ExecuteToolResponse: - type: object - properties: - execution: - title: execution - $ref: '#/components/schemas/toolexecution.v1.ToolExecution' - idempotentReplay: - type: boolean - title: idempotent_replay - title: ExecuteToolResponse - additionalProperties: false - toolexecution.v1.GetToolExecutionRequest: - type: object - properties: - id: - type: string - title: id - minLength: 1 - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - waitTimeoutMs: - type: integer - title: wait_timeout_ms - maximum: 30000 - description: |- - When greater than zero, the owner may block until the execution is - settled (terminal or WAITING_APPROVAL) or this timeout elapses. Zero - returns a snapshot and remains backward compatible. - title: GetToolExecutionRequest - additionalProperties: false - toolexecution.v1.GetToolExecutionResponse: - type: object - properties: - execution: - title: execution - $ref: '#/components/schemas/toolexecution.v1.ToolExecution' - title: GetToolExecutionResponse - additionalProperties: false - toolexecution.v1.ListToolExecutionsRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - runId: - type: string - title: run_id - objectiveId: - type: string - title: objective_id - agentId: - type: string - title: agent_id - toolNamespace: - type: string - title: tool_namespace - toolName: - type: string - title: tool_name - connectionId: - type: string - title: connection_id - approvalRequestId: - type: string - title: approval_request_id - state: - title: state - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionState' - limit: - type: integer - title: limit - format: int32 - offset: - type: integer - title: offset - format: int32 - organizationId: - type: string - title: organization_id - taskId: - type: string - title: task_id - title: ListToolExecutionsRequest - additionalProperties: false - toolexecution.v1.ListToolExecutionsResponse: - type: object - properties: - executions: - type: array - items: - $ref: '#/components/schemas/toolexecution.v1.ToolExecution' - title: executions - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - title: ListToolExecutionsResponse - additionalProperties: false - toolexecution.v1.RecordToolExecutionOutputRequest: - type: object - properties: - executionId: - type: string - title: execution_id - minLength: 1 - output: - title: output - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionOutput' - metadata: - type: object - title: metadata - additionalProperties: - type: string - title: value - authority: - title: authority - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionOutputAuthority' - title: RecordToolExecutionOutputRequest - required: - - output - - authority - additionalProperties: false - toolexecution.v1.RecordToolExecutionOutputRequest.MetadataEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: MetadataEntry - additionalProperties: false - toolexecution.v1.RecordToolExecutionOutputResponse: - type: object - properties: - execution: - title: execution - $ref: '#/components/schemas/toolexecution.v1.ToolExecution' - title: RecordToolExecutionOutputResponse - additionalProperties: false - toolexecution.v1.ResumeToolExecutionRequest: - type: object - properties: - executionId: - type: string - title: execution_id - minLength: 1 - approvalRequestId: - type: string - title: approval_request_id - minLength: 1 - resumeToken: - type: string - title: resume_token - minLength: 1 - approved: - type: boolean - title: approved - deprecated: true - decidedBy: - type: string - title: decided_by - deprecated: true - reason: - type: string - title: reason - deprecated: true - approvalDecisionId: - type: string - title: approval_decision_id - minLength: 1 - description: |- - Identity of the durable ApprovalService decision to verify. The - deprecated decision fields above are ignored by production verification. - title: ResumeToolExecutionRequest - additionalProperties: false - toolexecution.v1.ResumeToolExecutionResponse: - type: object - properties: - execution: - title: execution - $ref: '#/components/schemas/toolexecution.v1.ToolExecution' - title: ResumeToolExecutionResponse - additionalProperties: false - toolexecution.v1.ToolApprovalWait: - type: object - properties: - id: - type: string - title: id - approvalRequestId: - type: string - title: approval_request_id - resumeToken: - type: string - title: resume_token - reason: - type: string - title: reason - requestedDecision: - title: requested_decision - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionPolicyDecision' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - resolvedAt: - title: resolved_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - resolvedBy: - type: string - title: resolved_by - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: ToolApprovalWait - additionalProperties: false - description: |- - ToolApprovalWait is stored when policy requires human approval. The - resume_token and original request allow AgentRun to release compute and later - resume without reconstructing or mutating the tool call. - toolexecution.v1.ToolExecution: - type: object - properties: - id: - type: string - title: id - linkage: - title: linkage - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionLinkage' - tool: - title: tool - $ref: '#/components/schemas/toolexecution.v1.ToolRef' - connector: - title: connector - $ref: '#/components/schemas/toolexecution.v1.ConnectorRef' - arguments: - title: arguments - $ref: '#/components/schemas/google.protobuf.Struct' - riskLevel: - title: risk_level - $ref: '#/components/schemas/common.v1.RiskLevel' - retryPolicy: - title: retry_policy - $ref: '#/components/schemas/toolexecution.v1.ToolRetryPolicy' - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - state: - title: state - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionState' - attempt: - type: integer - title: attempt - format: int32 - maxAttempts: - type: integer - title: max_attempts - format: int32 - steps: - type: array - items: - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionStep' - title: steps - approvalWait: - title: approval_wait - $ref: '#/components/schemas/toolexecution.v1.ToolApprovalWait' - output: - title: output - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionOutput' - provenance: - title: provenance - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionProvenance' - errorMessage: - type: string - title: error_message - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - completedAt: - title: completed_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - traceContext: - title: trace_context - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionTraceContext' - failureCode: - title: failure_code - description: |- - Stable machine-readable terminal failure reason when the owning execution - boundary classified it. Human-readable detail remains in error_message - and must never be parsed for routing or policy. - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionFailureCode' - verifiedApprovalDecision: - title: verified_approval_decision - $ref: '#/components/schemas/toolexecution.v1.VerifiedApprovalDecision' - title: ToolExecution - required: - - linkage - - tool - additionalProperties: false - description: ToolExecution is the canonical durable record for one governed tool call. - toolexecution.v1.ToolExecutionAttachmentMount: - type: object - properties: - objectId: - type: string - title: object_id - minLength: 1 - versionId: - type: string - title: version_id - minLength: 1 - filename: - type: string - title: filename - minLength: 1 - sha256: - type: string - title: sha256 - minLength: 1 - sizeBytes: - exclusiveMinimum: 0 - type: - - integer - - string - title: size_bytes - maximum: 52428800 - format: int64 - destinationPath: - type: string - title: destination_path - minLength: 1 - resourceRef: - title: resource_ref - $ref: '#/components/schemas/platform.v1.ResourceRef' - title: ToolExecutionAttachmentMount - additionalProperties: false - description: |- - ToolExecutionAttachmentMount is an immutable, server-authorized VFS version - materialized read-only under the execution's attachment root. - toolexecution.v1.ToolExecutionGitSnapshotFile: - type: object - properties: - path: - type: string - title: path - gitBlobSha: - type: string - title: git_blob_sha - sizeBytes: - type: - - integer - - string - title: size_bytes - format: int64 - executable: - type: boolean - title: executable - title: ToolExecutionGitSnapshotFile - additionalProperties: false - toolexecution.v1.ToolExecutionGitSnapshotManifest: - type: object - properties: - repositoryId: - type: - - integer - - string - title: repository_id - format: int64 - fullName: - type: string - title: full_name - defaultBranch: - type: string - title: default_branch - commitSha: - type: string - title: commit_sha - treeSha: - type: string - title: tree_sha - files: - type: array - items: - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionGitSnapshotFile' - title: files - complete: - type: boolean - title: complete - title: ToolExecutionGitSnapshotManifest - additionalProperties: false - toolexecution.v1.ToolExecutionLinkage: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - organizationId: - type: string - title: organization_id - minLength: 1 - agentId: - type: string - title: agent_id - minLength: 1 - runId: - type: string - title: run_id - objectiveId: - type: string - title: objective_id - stepId: - type: string - title: step_id - actorId: - type: string - title: actor_id - surface: - type: string - title: surface - deprecated: true - channelId: - type: string - title: channel_id - correlationId: - type: string - title: correlation_id - surfaceType: - title: surface_type - $ref: '#/components/schemas/common.v1.Surface' - attachmentMounts: - type: array - items: - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionAttachmentMount' - title: attachment_mounts - applicationId: - type: string - title: application_id - minLength: 1 - description: |- - application_id is the immutable server-derived application authority. - Callers must not populate it from browser-controlled application context. - projectSource: - title: project_source - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionProjectSource' - projectImport: - title: project_import - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionProjectImport' - workspaceRecipe: - title: workspace_recipe - description: |- - Exact Platform-admitted task recipe. Executor preparation is authorized - from this typed linkage, never from caller-controlled metadata. - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionWorkspaceRecipe' - taskId: - type: string - title: task_id - description: Platform-admitted task identity used for tenant-scoped owner inspection. - title: ToolExecutionLinkage - additionalProperties: false - description: |- - ToolExecutionLinkage carries the shared identifiers used to authorize, - partition, audit, and join a tool call back to agent runtime records. - toolexecution.v1.ToolExecutionOutput: - type: object - properties: - rawOutput: - title: raw_output - $ref: '#/components/schemas/google.protobuf.Struct' - safeOutput: - title: safe_output - $ref: '#/components/schemas/google.protobuf.Struct' - proposals: - type: array - items: - $ref: '#/components/schemas/toolexecution.v1.ToolOutputProposal' - title: proposals - redactions: - type: array - items: - type: string - title: redactions - contentType: - type: string - title: content_type - outputDigest: - type: string - title: output_digest - durationMs: - type: - - integer - - string - title: duration_ms - format: int64 - resourceRef: - title: resource_ref - $ref: '#/components/schemas/platform.v1.ResourceRef' - title: ToolExecutionOutput - additionalProperties: false - description: |- - ToolExecutionOutput is deliberately structured: safe_output can be fed to a - run checkpoint, artifact proposal, or memory proposal without raw connector - secrets or unredacted byproducts. - toolexecution.v1.ToolExecutionOutputAuthority: - type: object - properties: - applicationId: - type: string - title: application_id - minLength: 1 - actor: - type: string - title: actor - minLength: 1 - requestFingerprint: - type: string - title: request_fingerprint - minLength: 1 - approvalDecisionId: - type: string - title: approval_decision_id - minLength: 1 - dispatchAttempt: - type: integer - title: dispatch_attempt - minimum: 1 - format: int32 - actionDigest: - type: string - title: action_digest - minLength: 1 - title: ToolExecutionOutputAuthority - additionalProperties: false - description: |- - ToolExecutionOutputAuthority binds a caller-dispatched terminal write to - the authenticated application/actor, exact request and approval, and the - currently leased dispatch attempt. - toolexecution.v1.ToolExecutionProjectImport: - type: object - properties: - projectResourceId: - type: string - title: project_resource_id - connectionId: - type: string - title: connection_id - expectedRefVersion: - type: - - integer - - string - title: expected_ref_version - format: int64 - nullable: true - manifest: - title: manifest - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionGitSnapshotManifest' - grantKeyId: - type: string - title: grant_key_id - grantSignature: - type: string - title: grant_signature - title: ToolExecutionProjectImport - additionalProperties: false - description: Server-admitted immutable import job; browser requests cannot choose a commit. - toolexecution.v1.ToolExecutionProjectSource: - type: object - properties: - projectResourceId: - type: string - title: project_resource_id - acceptedRefName: - type: string - title: accepted_ref_name - acceptedRefVersion: - type: - - integer - - string - title: accepted_ref_version - format: int64 - acceptedSnapshotId: - type: string - title: accepted_snapshot_id - sourceWorkspaceId: - type: string - title: source_workspace_id - sourceWorkspaceVersion: - type: - - integer - - string - title: source_workspace_version - format: int64 - files: - type: array - items: - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionProjectSourceFile' - title: files - maxItems: 1000 - title: ToolExecutionProjectSource - additionalProperties: false - description: Server-owned, pinned accepted source. Never a writable shared directory. - toolexecution.v1.ToolExecutionProjectSourceFile: - type: object - properties: - path: - type: string - title: path - objectId: - type: string - title: object_id - versionId: - type: string - title: version_id - sha256: - type: string - title: sha256 - sizeBytes: - type: - - integer - - string - title: size_bytes - format: int64 - executable: - type: boolean - title: executable - title: ToolExecutionProjectSourceFile - additionalProperties: false - description: An immutable file restored below the private task workspace. - toolexecution.v1.ToolExecutionProvenance: - type: object - properties: - capabilityRef: - type: string - title: capability_ref - credentialRef: - type: string - title: credential_ref - gatePolicyRef: - type: string - title: gate_policy_ref - governanceDecisionRef: - type: string - title: governance_decision_ref - approvalRequestId: - type: string - title: approval_request_id - executorRef: - type: string - title: executor_ref - auditEventId: - type: string - title: audit_event_id - meterRecordId: - type: string - title: meter_record_id - provenanceRecordId: - type: string - title: provenance_record_id - inputDigest: - type: string - title: input_digest - outputDigest: - type: string - title: output_digest - metadata: - type: object - title: metadata - additionalProperties: - type: string - title: value - commandAuditReceipt: - title: command_audit_receipt - description: |- - Owner-persisted acknowledgement of a Runner Host event append. This - binds a recording to the execution, not the producer of the event. - $ref: '#/components/schemas/toolexecution.v1.CommandAuditReceipt' - title: ToolExecutionProvenance - additionalProperties: false - description: |- - ToolExecutionProvenance records non-secret references emitted by each - boundary so audit, meter, AgentRun, Artifact, and Memory records can join on - one tool_execution_id. - toolexecution.v1.ToolExecutionProvenance.MetadataEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: MetadataEntry - additionalProperties: false - toolexecution.v1.ToolExecutionStep: - type: object - properties: - id: - type: string - title: id - stage: - title: stage - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionStage' - state: - title: state - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionStepState' - decision: - title: decision - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionPolicyDecision' - externalRef: - type: string - title: external_ref - reasons: - type: array - items: - type: string - title: reasons - attributes: - type: object - title: attributes - additionalProperties: - type: string - title: value - startedAt: - title: started_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - endedAt: - title: ended_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: ToolExecutionStep - additionalProperties: false - description: ToolExecutionStep records one boundary decision in the execution path. - toolexecution.v1.ToolExecutionStep.AttributesEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: AttributesEntry - additionalProperties: false - toolexecution.v1.ToolExecutionTraceContext: - type: object - properties: - traceId: - type: string - title: trace_id - spanId: - type: string - title: span_id - parentSpanId: - type: string - title: parent_span_id - traceparent: - type: string - title: traceparent - tracestate: - type: string - title: tracestate - title: ToolExecutionTraceContext - additionalProperties: false - description: |- - ToolExecutionTraceContext carries the W3C trace context that causally owns a - tool call. It lets the AgentRun, ToolExecution, connector, and MCP spans stay - on one distributed trace even when the execution is retried or parked. - toolexecution.v1.ToolExecutionWorkspaceRecipe: - type: object - properties: - schemaVersion: - type: string - title: schema_version - const: deixic.workspace_recipe.v1 - recipeId: - type: string - title: recipe_id - minLength: 1 - recipeVersion: - type: - - integer - - string - title: recipe_version - minimum: 1 - format: int64 - recipeDigest: - type: string - title: recipe_digest - minLength: 1 - sourceManifestDigest: - type: string - title: source_manifest_digest - minLength: 1 - requiredRuntimes: - type: array - items: - type: string - maxLength: 64 - minLength: 1 - maxItems: 16 - title: required_runtimes - maxItems: 16 - preparationTool: - type: string - title: preparation_tool - const: computer.check_runtimes - executionOwner: - type: string - title: execution_owner - const: platform-api.dex - title: ToolExecutionWorkspaceRecipe - additionalProperties: false - description: |- - Versioned, server-owned preparation recipe for one task workspace. The - recipe carries bounded declarative requirements; it cannot contain shell - commands, repository hooks, credentials, or approval policy. - toolexecution.v1.ToolOutputProposal: - type: object - properties: - kind: - title: kind - $ref: '#/components/schemas/toolexecution.v1.ToolExecutionProposalKind' - targetRef: - type: string - title: target_ref - payload: - title: payload - $ref: '#/components/schemas/google.protobuf.Struct' - metadata: - type: object - title: metadata - additionalProperties: - type: string - title: value - title: ToolOutputProposal - additionalProperties: false - description: ToolOutputProposal is a normalized downstream write suggestion from a tool. - toolexecution.v1.ToolOutputProposal.MetadataEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: MetadataEntry - additionalProperties: false - toolexecution.v1.ToolRef: - type: object - properties: - namespace: - type: string - title: namespace - minLength: 1 - name: - type: string - title: name - minLength: 1 - version: - type: string - title: version - capability: - type: string - title: capability - minLength: 1 - operation: - type: string - title: operation - idempotent: - type: boolean - title: idempotent - mutatesResource: - type: boolean - title: mutates_resource - title: ToolRef - additionalProperties: false - description: ToolRef identifies the tool/capability the agent wants to invoke. - toolexecution.v1.ToolRetryPolicy: - type: object - properties: - maxAttempts: - type: integer - title: max_attempts - format: int32 - initialDelayMs: - type: integer - title: initial_delay_ms - format: int32 - maxDelayMs: - type: integer - title: max_delay_ms - format: int32 - allowNonIdempotentRetry: - type: boolean - title: allow_non_idempotent_retry - title: ToolRetryPolicy - additionalProperties: false - description: |- - ToolRetryPolicy prevents blind retries for side-effecting tools. If a tool is - not idempotent, callers must set allow_non_idempotent_retry and provide an - idempotency_key before retries beyond the first attempt are honored. - toolexecution.v1.VerifiedApprovalDecision: - type: object - properties: - decisionId: - type: string - title: decision_id - approvalRequestId: - type: string - title: approval_request_id - decision: - type: string - title: decision - decidedBy: - type: string - title: decided_by - reason: - type: string - title: reason - decidedAt: - title: decided_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - verifiedAt: - title: verified_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: VerifiedApprovalDecision - additionalProperties: false - description: |- - VerifiedApprovalDecision is the immutable join to the authoritative - ApprovalService decision used to release this execution. ToolExecutor - derives every field from ApprovalService; callers provide only decision_id. - connect-protocol-version: - type: number - title: Connect-Protocol-Version - enum: - - 1 - description: Define the version of the Connect protocol - const: 1 - connect-timeout-header: - type: number - title: Connect-Timeout-Ms - description: Define the timeout, in ms - connect.error: - type: object - properties: - code: - type: string - examples: - - not_found - enum: - - canceled - - unknown - - invalid_argument - - deadline_exceeded - - not_found - - already_exists - - permission_denied - - resource_exhausted - - failed_precondition - - aborted - - out_of_range - - unimplemented - - internal - - unavailable - - data_loss - - unauthenticated - description: The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code]. - message: - type: string - description: A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client. - detail: - $ref: '#/components/schemas/google.protobuf.Any' - title: Connect Error - additionalProperties: true - description: 'Error type returned by Connect: https://connectrpc.com/docs/go/errors/#http-representation' - google.protobuf.Any: - type: object - properties: - type: - type: string - value: - type: string - format: binary - debug: - type: object - additionalProperties: true - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. -security: [] -tags: - - name: toolexecution.v1.ToolExecutionService - description: |- - ToolExecutionService governs one normalized tool call across capability - lookup, credential resolution, Gate and Governance policy, approval waits, - execution, audit, meter, and provenance recording. AgentRun workers call this - service instead of invoking external connectors, MCP tools, or internal tools - directly. diff --git a/openapi/traces/v1/traces.openapi.yaml b/openapi/traces/v1/traces.openapi.yaml deleted file mode 100644 index 2163a84..0000000 --- a/openapi/traces/v1/traces.openapi.yaml +++ /dev/null @@ -1,2151 +0,0 @@ -openapi: 3.1.0 -info: - title: traces.v1 -paths: - /traces.v1.SpanIngestService/IngestSpans: - post: - tags: - - traces.v1.SpanIngestService - summary: IngestSpans - description: |- - Append spans to a trace. MEDIUM because forged spans contaminate the - observability record other reviewers and gates trust. - Organization scope is enforced by trace handlers for multi-org writes - because legacy single-scope SDK ingest may omit span.organization_id. - operationId: traces.v1.SpanIngestService.IngestSpans - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.IngestSpansRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.IngestSpansResponse' - /traces.v1.SpanIngestService/GetTrace: - post: - tags: - - traces.v1.SpanIngestService - summary: GetTrace - operationId: traces.v1.SpanIngestService.GetTrace - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.GetTraceRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.GetTraceResponse' - /traces.v1.SpanIngestService/ListTraces: - post: - tags: - - traces.v1.SpanIngestService - summary: ListTraces - operationId: traces.v1.SpanIngestService.ListTraces - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.ListTracesRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.ListTracesResponse' - /traces.v1.SpanIngestService/GetSpanTree: - post: - tags: - - traces.v1.SpanIngestService - summary: GetSpanTree - operationId: traces.v1.SpanIngestService.GetSpanTree - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.GetSpanTreeRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.GetSpanTreeResponse' - /traces.v1.SpanIngestService/GetSpanContext: - post: - tags: - - traces.v1.SpanIngestService - summary: GetSpanContext - operationId: traces.v1.SpanIngestService.GetSpanContext - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.GetSpanContextRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.GetSpanContextResponse' - /traces.v1.SpanIngestService/GetSpanPayload: - post: - tags: - - traces.v1.SpanIngestService - summary: GetSpanPayload - description: |- - Returns the recorded prompt + response payload of a single span. - MEDIUM because the payload often contains user-supplied PII; - the caller authz check enforces tenant scope but the data fan-out - is wider than a normal read. - operationId: traces.v1.SpanIngestService.GetSpanPayload - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.GetSpanPayloadRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.GetSpanPayloadResponse' - /traces.v1.SpanIngestService/SearchTrace: - post: - tags: - - traces.v1.SpanIngestService - summary: SearchTrace - operationId: traces.v1.SpanIngestService.SearchTrace - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.SearchTraceRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.SearchTraceResponse' - /traces.v1.SpanIngestService/AnnotateTrace: - post: - tags: - - traces.v1.SpanIngestService - summary: AnnotateTrace - description: |- - Attaches a reviewer note to a trace. MEDIUM because the note becomes - part of the evidence shown to other reviewers and can be misused to - shape future approval defaults. - operationId: traces.v1.SpanIngestService.AnnotateTrace - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.AnnotateTraceRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.AnnotateTraceResponse' - /traces.v1.SpanIngestService/DeleteTraceAnnotation: - post: - tags: - - traces.v1.SpanIngestService - summary: DeleteTraceAnnotation - operationId: traces.v1.SpanIngestService.DeleteTraceAnnotation - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.DeleteTraceAnnotationRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.DeleteTraceAnnotationResponse' - /traces.v1.SpanIngestService/BulkAnnotateTrace: - post: - tags: - - traces.v1.SpanIngestService - summary: BulkAnnotateTrace - operationId: traces.v1.SpanIngestService.BulkAnnotateTrace - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.BulkAnnotateTraceRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.BulkAnnotateTraceResponse' - /traces.v1.SpanIngestService/ListTraceAnnotations: - post: - tags: - - traces.v1.SpanIngestService - summary: ListTraceAnnotations - operationId: traces.v1.SpanIngestService.ListTraceAnnotations - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.ListTraceAnnotationsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.ListTraceAnnotationsResponse' - /traces.v1.SpanIngestService/GetTraceReviewBundle: - post: - tags: - - traces.v1.SpanIngestService - summary: GetTraceReviewBundle - operationId: traces.v1.SpanIngestService.GetTraceReviewBundle - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.GetTraceReviewBundleRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.GetTraceReviewBundleResponse' - /traces.v1.SpanIngestService/AnnotateTraceQuality: - post: - tags: - - traces.v1.SpanIngestService - summary: AnnotateTraceQuality - description: |- - Records a quality label (good / bad / regression) that feeds the eval - ranking surface. MEDIUM because the label drives later auto-approve - decisions in the reviewing pipeline. - operationId: traces.v1.SpanIngestService.AnnotateTraceQuality - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.AnnotateTraceQualityRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.AnnotateTraceQualityResponse' - /traces.v1.SpanIngestService/ListTraceQualityAnnotations: - post: - tags: - - traces.v1.SpanIngestService - summary: ListTraceQualityAnnotations - operationId: traces.v1.SpanIngestService.ListTraceQualityAnnotations - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.ListTraceQualityAnnotationsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.ListTraceQualityAnnotationsResponse' - /traces.v1.SpanIngestService/ExportReplayBundle: - post: - tags: - - traces.v1.SpanIngestService - summary: ExportReplayBundle - description: |- - Streams a replay bundle (full prompts, responses, attachments) for - a single run. HIGH because the bundle reconstitutes the original - session including any user-supplied secrets that survived sanitisation. - operationId: traces.v1.SpanIngestService.ExportReplayBundle - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.ExportReplayBundleRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.ExportReplayBundleResponse' - /traces.v1.SpanIngestService/SummarizeMaestroSelfTelemetry: - post: - tags: - - traces.v1.SpanIngestService - summary: SummarizeMaestroSelfTelemetry - operationId: traces.v1.SpanIngestService.SummarizeMaestroSelfTelemetry - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.SummarizeMaestroSelfTelemetryRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/traces.v1.SummarizeMaestroSelfTelemetryResponse' -components: - schemas: - google.protobuf.NullValue: - type: string - title: NullValue - enum: - - NULL_VALUE - description: |- - `NullValue` is a singleton enumeration to represent the null value for the - `Value` type union. - - The JSON representation for `NullValue` is JSON `null`. - traces.v1.ConversationalSignalKind: - type: string - title: ConversationalSignalKind - enum: - - CONVERSATIONAL_SIGNAL_KIND_UNSPECIFIED - - CONVERSATIONAL_SIGNAL_KIND_FRUSTRATION - - CONVERSATIONAL_SIGNAL_KIND_CONFUSION - - CONVERSATIONAL_SIGNAL_KIND_DISSATISFACTION - traces.v1.ConversationalSignalLabel: - type: string - title: ConversationalSignalLabel - enum: - - CONVERSATIONAL_SIGNAL_LABEL_UNSPECIFIED - - CONVERSATIONAL_SIGNAL_LABEL_LOW - - CONVERSATIONAL_SIGNAL_LABEL_MEDIUM - - CONVERSATIONAL_SIGNAL_LABEL_HIGH - traces.v1.GovernanceDecision: - type: string - title: GovernanceDecision - enum: - - GOVERNANCE_DECISION_UNSPECIFIED - - GOVERNANCE_DECISION_ALLOW - - GOVERNANCE_DECISION_DENY - - GOVERNANCE_DECISION_REQUIRE_APPROVAL - - GOVERNANCE_DECISION_AUTO_APPROVED - traces.v1.SpanPayloadRedactionMode: - type: string - title: SpanPayloadRedactionMode - enum: - - SPAN_PAYLOAD_REDACTION_MODE_UNSPECIFIED - - SPAN_PAYLOAD_REDACTION_MODE_SAFE - - SPAN_PAYLOAD_REDACTION_MODE_RAW - traces.v1.SpanPayloadTarget: - type: string - title: SpanPayloadTarget - enum: - - SPAN_PAYLOAD_TARGET_UNSPECIFIED - - SPAN_PAYLOAD_TARGET_INPUT - - SPAN_PAYLOAD_TARGET_OUTPUT - - SPAN_PAYLOAD_TARGET_ATTRIBUTES - - SPAN_PAYLOAD_TARGET_LLM_MESSAGES - - SPAN_PAYLOAD_TARGET_TOOL_ARGS - - SPAN_PAYLOAD_TARGET_TOOL_RESULT - - SPAN_PAYLOAD_TARGET_EVENTS - traces.v1.SpanStatus: - type: string - title: SpanStatus - enum: - - SPAN_STATUS_UNSPECIFIED - - SPAN_STATUS_OK - - SPAN_STATUS_ERROR - - SPAN_STATUS_CANCELLED - traces.v1.TraceAnnotationKind: - type: string - title: TraceAnnotationKind - enum: - - TRACE_ANNOTATION_KIND_UNSPECIFIED - - TRACE_ANNOTATION_KIND_NOTE - - TRACE_ANNOTATION_KIND_ISSUE - - TRACE_ANNOTATION_KIND_GOOD - traces.v1.TraceAnnotationStatus: - type: string - title: TraceAnnotationStatus - enum: - - TRACE_ANNOTATION_STATUS_UNSPECIFIED - - TRACE_ANNOTATION_STATUS_ACTIVE - - TRACE_ANNOTATION_STATUS_RESOLVED - - TRACE_ANNOTATION_STATUS_DISMISSED - - TRACE_ANNOTATION_STATUS_ARCHIVED - traces.v1.TraceEvidenceState: - type: string - title: TraceEvidenceState - enum: - - TRACE_EVIDENCE_STATE_UNSPECIFIED - - TRACE_EVIDENCE_STATE_AVAILABLE - - TRACE_EVIDENCE_STATE_WITHHELD - - TRACE_EVIDENCE_STATE_MISSING - - TRACE_EVIDENCE_STATE_PERMISSION_BLOCKED - - TRACE_EVIDENCE_STATE_EXPIRED - common.v1.Money: - type: object - properties: - currencyCode: - type: string - title: currency_code - amount: - type: number - title: amount - format: double - title: Money - additionalProperties: false - description: Money carries a currency code plus an amount for financial rollups. - google.protobuf.ListValue: - type: object - properties: - values: - type: array - items: - $ref: '#/components/schemas/google.protobuf.Value' - title: values - description: Repeated field of dynamically typed values. - title: ListValue - additionalProperties: false - description: |- - `ListValue` is a wrapper around a repeated field of values. - - The JSON representation for `ListValue` is JSON array. - google.protobuf.Struct: - type: object - additionalProperties: - $ref: '#/components/schemas/google.protobuf.Value' - description: |- - `Struct` represents a structured data value, consisting of fields - which map to dynamically typed values. In some languages, `Struct` - might be supported by a native representation. For example, in - scripting languages like JS a struct is represented as an - object. The details of that representation are described together - with the proto support for the language. - - The JSON representation for `Struct` is JSON object. - google.protobuf.Struct.FieldsEntry: - type: object - properties: - key: - type: string - title: key - value: - title: value - $ref: '#/components/schemas/google.protobuf.Value' - title: FieldsEntry - additionalProperties: false - google.protobuf.Timestamp: - type: string - examples: - - 1s - - 1.000340012s - format: date-time - description: |- - A Timestamp represents a point in time independent of any time zone or local - calendar, encoded as a count of seconds and fractions of seconds at - nanosecond resolution. The count is relative to an epoch at UTC midnight on - January 1, 1970, in the proleptic Gregorian calendar which extends the - Gregorian calendar backwards to year one. - - All minutes are 60 seconds long. Leap seconds are "smeared" so that no leap - second table is needed for interpretation, using a [24-hour linear - smear](https://developers.google.com/time/smear). - - The range is from 0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z. By - restricting to that range, we ensure that we can convert to and from [RFC - 3339](https://www.ietf.org/rfc/rfc3339.txt) date strings. - - # Examples - - Example 1: Compute Timestamp from POSIX `time()`. - - Timestamp timestamp; - timestamp.set_seconds(time(NULL)); - timestamp.set_nanos(0); - - Example 2: Compute Timestamp from POSIX `gettimeofday()`. - - struct timeval tv; - gettimeofday(&tv, NULL); - - Timestamp timestamp; - timestamp.set_seconds(tv.tv_sec); - timestamp.set_nanos(tv.tv_usec * 1000); - - Example 3: Compute Timestamp from Win32 `GetSystemTimeAsFileTime()`. - - FILETIME ft; - GetSystemTimeAsFileTime(&ft); - UINT64 ticks = (((UINT64)ft.dwHighDateTime) << 32) | ft.dwLowDateTime; - - // A Windows tick is 100 nanoseconds. Windows epoch 1601-01-01T00:00:00Z - // is 11644473600 seconds before Unix epoch 1970-01-01T00:00:00Z. - Timestamp timestamp; - timestamp.set_seconds((INT64) ((ticks / 10000000) - 11644473600LL)); - timestamp.set_nanos((INT32) ((ticks % 10000000) * 100)); - - Example 4: Compute Timestamp from Java `System.currentTimeMillis()`. - - long millis = System.currentTimeMillis(); - - Timestamp timestamp = Timestamp.newBuilder().setSeconds(millis / 1000) - .setNanos((int) ((millis % 1000) * 1000000)).build(); - - Example 5: Compute Timestamp from Java `Instant.now()`. - - Instant now = Instant.now(); - - Timestamp timestamp = - Timestamp.newBuilder().setSeconds(now.getEpochSecond()) - .setNanos(now.getNano()).build(); - - Example 6: Compute Timestamp from current time in Python. - - timestamp = Timestamp() - timestamp.GetCurrentTime() - - # JSON Mapping - - In JSON format, the Timestamp type is encoded as a string in the - [RFC 3339](https://www.ietf.org/rfc/rfc3339.txt) format. That is, the - format is "{year}-{month}-{day}T{hour}:{min}:{sec}[.{frac_sec}]Z" - where {year} is always expressed using four digits while {month}, {day}, - {hour}, {min}, and {sec} are zero-padded to two digits each. The fractional - seconds, which can go up to 9 digits (i.e. up to 1 nanosecond resolution), - are optional. The "Z" suffix indicates the timezone ("UTC"); the timezone - is required. A proto3 JSON serializer should always use UTC (as indicated by - "Z") when printing the Timestamp type and a proto3 JSON parser should be - able to accept both UTC and other timezones (as indicated by an offset). - - For example, "2017-01-15T01:30:15.01Z" encodes 15.01 seconds past - 01:30 UTC on January 15, 2017. - - In JavaScript, one can convert a Date object to this format using the - standard - [toISOString()](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Date/toISOString) - method. In Python, a standard `datetime.datetime` object can be converted - to this format using - [`strftime`](https://docs.python.org/2/library/time.html#time.strftime) with - the time format spec '%Y-%m-%dT%H:%M:%S.%fZ'. Likewise, in Java, one can use - the Joda Time's [`ISODateTimeFormat.dateTime()`]( - http://joda-time.sourceforge.net/apidocs/org/joda/time/format/ISODateTimeFormat.html#dateTime() - ) to obtain a formatter capable of generating timestamps in this format. - google.protobuf.Value: - oneOf: - - type: "null" - - type: number - - type: string - - type: boolean - - type: array - - type: object - additionalProperties: true - description: |- - `Value` represents a dynamically typed value which can be either - null, a number, a string, a boolean, a recursive struct value, or a - list of values. A producer of value is expected to set one of these - variants. Absence of any variant indicates an error. - - The JSON representation for `Value` is JSON value. - traces.v1.AnnotateTraceQualityRequest: - type: object - properties: - annotation: - title: annotation - $ref: '#/components/schemas/traces.v1.TraceQualityAnnotation' - title: AnnotateTraceQualityRequest - required: - - annotation - additionalProperties: false - traces.v1.AnnotateTraceQualityResponse: - type: object - properties: - annotation: - title: annotation - $ref: '#/components/schemas/traces.v1.TraceQualityAnnotation' - title: AnnotateTraceQualityResponse - additionalProperties: false - traces.v1.AnnotateTraceRequest: - type: object - properties: - annotation: - title: annotation - $ref: '#/components/schemas/traces.v1.TraceAnnotation' - title: AnnotateTraceRequest - required: - - annotation - additionalProperties: false - traces.v1.AnnotateTraceResponse: - type: object - properties: - annotation: - title: annotation - $ref: '#/components/schemas/traces.v1.TraceAnnotation' - title: AnnotateTraceResponse - additionalProperties: false - traces.v1.AssertionResult: - type: object - properties: - assertionId: - type: string - title: assertion_id - name: - type: string - title: name - passed: - type: boolean - title: passed - score: - type: number - title: score - format: double - reason: - type: string - title: reason - metadata: - title: metadata - $ref: '#/components/schemas/google.protobuf.Struct' - title: AssertionResult - additionalProperties: false - traces.v1.BulkAnnotateTraceRequest: - type: object - properties: - traceId: - type: string - title: trace_id - minLength: 1 - spanIds: - type: array - items: - type: string - title: span_ids - annotation: - title: annotation - $ref: '#/components/schemas/traces.v1.TraceAnnotation' - title: BulkAnnotateTraceRequest - required: - - annotation - additionalProperties: false - traces.v1.BulkAnnotateTraceResponse: - type: object - properties: - annotations: - type: array - items: - $ref: '#/components/schemas/traces.v1.TraceAnnotation' - title: annotations - total: - type: integer - title: total - format: int32 - title: BulkAnnotateTraceResponse - additionalProperties: false - traces.v1.ConversationalSignal: - type: object - properties: - kind: - title: kind - $ref: '#/components/schemas/traces.v1.ConversationalSignalKind' - score: - type: number - title: score - format: double - label: - title: label - $ref: '#/components/schemas/traces.v1.ConversationalSignalLabel' - rationale: - type: string - title: rationale - evidenceSpanIds: - type: array - items: - type: string - title: evidence_span_ids - title: ConversationalSignal - additionalProperties: false - traces.v1.DeleteTraceAnnotationRequest: - type: object - properties: - traceId: - type: string - title: trace_id - minLength: 1 - annotationId: - type: string - title: annotation_id - minLength: 1 - title: DeleteTraceAnnotationRequest - additionalProperties: false - traces.v1.DeleteTraceAnnotationResponse: - type: object - properties: - annotation: - title: annotation - $ref: '#/components/schemas/traces.v1.TraceAnnotation' - title: DeleteTraceAnnotationResponse - additionalProperties: false - traces.v1.ExportReplayBundleRequest: - type: object - properties: - traceId: - type: string - title: trace_id - minLength: 1 - title: ExportReplayBundleRequest - additionalProperties: false - traces.v1.ExportReplayBundleResponse: - type: object - properties: - bundle: - title: bundle - $ref: '#/components/schemas/traces.v1.TraceReplayBundle' - title: ExportReplayBundleResponse - additionalProperties: false - traces.v1.GetSpanContextRequest: - type: object - properties: - traceId: - type: string - title: trace_id - minLength: 1 - spanId: - type: string - title: span_id - minLength: 1 - before: - type: integer - title: before - format: int32 - after: - type: integer - title: after - format: int32 - includeParent: - type: boolean - title: include_parent - title: GetSpanContextRequest - additionalProperties: false - traces.v1.GetSpanContextResponse: - type: object - properties: - span: - title: span - $ref: '#/components/schemas/traces.v1.Span' - parent: - title: parent - $ref: '#/components/schemas/traces.v1.Span' - before: - type: array - items: - $ref: '#/components/schemas/traces.v1.Span' - title: before - after: - type: array - items: - $ref: '#/components/schemas/traces.v1.Span' - title: after - title: GetSpanContextResponse - additionalProperties: false - traces.v1.GetSpanPayloadRequest: - type: object - properties: - traceId: - type: string - title: trace_id - minLength: 1 - spanId: - type: string - title: span_id - minLength: 1 - target: - title: target - $ref: '#/components/schemas/traces.v1.SpanPayloadTarget' - offset: - type: integer - title: offset - format: int32 - maxChars: - type: integer - title: max_chars - format: int32 - redactionMode: - title: redaction_mode - $ref: '#/components/schemas/traces.v1.SpanPayloadRedactionMode' - title: GetSpanPayloadRequest - additionalProperties: false - traces.v1.GetSpanPayloadResponse: - type: object - properties: - content: - type: string - title: content - nextOffset: - type: integer - title: next_offset - format: int32 - hasMore: - type: boolean - title: has_more - source: - type: string - title: source - redactionApplied: - type: boolean - title: redaction_applied - title: GetSpanPayloadResponse - additionalProperties: false - traces.v1.GetSpanTreeRequest: - type: object - properties: - traceId: - type: string - title: trace_id - minLength: 1 - title: GetSpanTreeRequest - additionalProperties: false - traces.v1.GetSpanTreeResponse: - type: object - properties: - trace: - title: trace - $ref: '#/components/schemas/traces.v1.TraceSummary' - roots: - type: array - items: - $ref: '#/components/schemas/traces.v1.SpanNode' - title: roots - title: GetSpanTreeResponse - additionalProperties: false - traces.v1.GetTraceRequest: - type: object - properties: - traceId: - type: string - title: trace_id - minLength: 1 - title: GetTraceRequest - additionalProperties: false - traces.v1.GetTraceResponse: - type: object - properties: - trace: - title: trace - $ref: '#/components/schemas/traces.v1.TraceSummary' - spans: - type: array - items: - $ref: '#/components/schemas/traces.v1.Span' - title: spans - qualityAnnotations: - type: array - items: - $ref: '#/components/schemas/traces.v1.TraceQualityAnnotation' - title: quality_annotations - annotations: - type: array - items: - $ref: '#/components/schemas/traces.v1.TraceAnnotation' - title: annotations - title: GetTraceResponse - additionalProperties: false - traces.v1.GetTraceReviewBundleRequest: - type: object - properties: - traceId: - type: string - title: trace_id - minLength: 1 - search: - type: string - title: search - label: - type: string - title: label - maxMatches: - type: integer - title: max_matches - format: int32 - title: GetTraceReviewBundleRequest - additionalProperties: false - traces.v1.GetTraceReviewBundleResponse: - type: object - properties: - bundle: - title: bundle - $ref: '#/components/schemas/traces.v1.TraceReviewBundle' - title: GetTraceReviewBundleResponse - additionalProperties: false - traces.v1.GovernanceScore: - type: object - properties: - decision: - title: decision - $ref: '#/components/schemas/traces.v1.GovernanceDecision' - confidence: - type: number - title: confidence - format: double - reasons: - type: array - items: - type: string - title: reasons - title: GovernanceScore - additionalProperties: false - traces.v1.IngestSpansRequest: - type: object - properties: - spans: - type: array - items: - $ref: '#/components/schemas/traces.v1.Span' - title: spans - minItems: 1 - title: IngestSpansRequest - additionalProperties: false - traces.v1.IngestSpansResponse: - type: object - properties: - ingestedCount: - type: integer - title: ingested_count - format: int32 - traces: - type: array - items: - $ref: '#/components/schemas/traces.v1.TraceSummary' - title: traces - title: IngestSpansResponse - additionalProperties: false - traces.v1.ListTraceAnnotationsRequest: - type: object - properties: - traceId: - type: string - title: trace_id - minLength: 1 - spanId: - type: string - title: span_id - kind: - title: kind - $ref: '#/components/schemas/traces.v1.TraceAnnotationKind' - label: - type: string - title: label - limit: - type: integer - title: limit - format: int32 - offset: - type: integer - title: offset - format: int32 - status: - title: status - $ref: '#/components/schemas/traces.v1.TraceAnnotationStatus' - title: ListTraceAnnotationsRequest - additionalProperties: false - traces.v1.ListTraceAnnotationsResponse: - type: object - properties: - annotations: - type: array - items: - $ref: '#/components/schemas/traces.v1.TraceAnnotation' - title: annotations - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - title: ListTraceAnnotationsResponse - additionalProperties: false - traces.v1.ListTraceQualityAnnotationsRequest: - type: object - properties: - traceId: - type: string - title: trace_id - minLength: 1 - spanId: - type: string - title: span_id - limit: - type: integer - title: limit - format: int32 - offset: - type: integer - title: offset - format: int32 - signalKind: - title: signal_kind - $ref: '#/components/schemas/traces.v1.ConversationalSignalKind' - title: ListTraceQualityAnnotationsRequest - additionalProperties: false - traces.v1.ListTraceQualityAnnotationsResponse: - type: object - properties: - annotations: - type: array - items: - $ref: '#/components/schemas/traces.v1.TraceQualityAnnotation' - title: annotations - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - title: ListTraceQualityAnnotationsResponse - additionalProperties: false - traces.v1.ListTracesRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - agentId: - type: string - title: agent_id - surface: - type: string - title: surface - startTime: - title: start_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - endTime: - title: end_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - limit: - type: integer - title: limit - format: int32 - offset: - type: integer - title: offset - format: int32 - organizationId: - type: string - title: organization_id - userId: - type: string - title: user_id - title: ListTracesRequest - additionalProperties: false - traces.v1.ListTracesResponse: - type: object - properties: - traces: - type: array - items: - $ref: '#/components/schemas/traces.v1.TraceSummary' - title: traces - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - title: ListTracesResponse - additionalProperties: false - traces.v1.MaestroSelfTelemetrySummary: - type: object - properties: - traceCount: - type: integer - title: trace_count - format: int32 - spanCount: - type: integer - title: span_count - format: int32 - permissionDenials: - type: integer - title: permission_denials - format: int32 - contextCompactions: - type: integer - title: context_compactions - format: int32 - subagentSpawns: - type: integer - title: subagent_spawns - format: int32 - selfDiagnostics: - type: integer - title: self_diagnostics - format: int32 - permissionDenialRate: - type: number - title: permission_denial_rate - format: double - compactionRate: - type: number - title: compaction_rate - format: double - subagentFanout: - type: number - title: subagent_fanout - format: double - title: MaestroSelfTelemetrySummary - additionalProperties: false - traces.v1.ReplayContext: - type: object - properties: - organizationId: - type: string - title: organization_id - workspaceId: - type: string - title: workspace_id - agentId: - type: string - title: agent_id - surface: - type: string - title: surface - userId: - type: string - title: user_id - title: ReplayContext - additionalProperties: false - traces.v1.ReplayToolCall: - type: object - properties: - spanId: - type: string - title: span_id - name: - type: string - title: name - input: - type: string - title: input - output: - type: string - title: output - status: - type: string - title: status - title: ReplayToolCall - additionalProperties: false - traces.v1.SearchTraceRequest: - type: object - properties: - traceId: - type: string - title: trace_id - minLength: 1 - pattern: - type: string - title: pattern - minLength: 1 - caseSensitive: - type: boolean - title: case_sensitive - spanKind: - type: string - title: span_kind - contextChars: - type: integer - title: context_chars - format: int32 - limit: - type: integer - title: limit - format: int32 - scopes: - type: array - items: - type: string - title: scopes - spanStatus: - title: span_status - $ref: '#/components/schemas/traces.v1.SpanStatus' - model: - type: string - title: model - provider: - type: string - title: provider - governanceDecision: - title: governance_decision - $ref: '#/components/schemas/traces.v1.GovernanceDecision' - label: - type: string - title: label - annotationStatus: - title: annotation_status - $ref: '#/components/schemas/traces.v1.TraceAnnotationStatus' - title: SearchTraceRequest - additionalProperties: false - traces.v1.SearchTraceResponse: - type: object - properties: - matches: - type: array - items: - $ref: '#/components/schemas/traces.v1.TraceSearchMatch' - title: matches - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - title: SearchTraceResponse - additionalProperties: false - traces.v1.Span: - type: object - properties: - traceId: - type: string - title: trace_id - minLength: 1 - spanId: - type: string - title: span_id - minLength: 1 - parentSpanId: - type: string - title: parent_span_id - workspaceId: - type: string - title: workspace_id - minLength: 1 - organizationId: - type: string - title: organization_id - agentId: - type: string - title: agent_id - surface: - type: string - title: surface - name: - type: string - title: name - minLength: 1 - kind: - type: string - title: kind - model: - type: string - title: model - provider: - type: string - title: provider - tokenInput: - type: - - integer - - string - title: token_input - format: int64 - tokenOutput: - type: - - integer - - string - title: token_output - format: int64 - latencyMs: - type: - - integer - - string - title: latency_ms - format: int64 - status: - title: status - $ref: '#/components/schemas/traces.v1.SpanStatus' - governanceDecision: - title: governance_decision - $ref: '#/components/schemas/traces.v1.GovernanceDecision' - costUsd: - type: number - title: cost_usd - format: double - attributes: - title: attributes - $ref: '#/components/schemas/google.protobuf.Struct' - startedAt: - title: started_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - endedAt: - title: ended_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - userId: - type: string - title: user_id - title: Span - additionalProperties: false - traces.v1.SpanNode: - type: object - properties: - span: - title: span - $ref: '#/components/schemas/traces.v1.Span' - children: - type: array - items: - $ref: '#/components/schemas/traces.v1.SpanNode' - title: children - title: SpanNode - additionalProperties: false - traces.v1.SummarizeMaestroSelfTelemetryRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - organizationId: - type: string - title: organization_id - agentId: - type: string - title: agent_id - surface: - type: string - title: surface - startTime: - title: start_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - endTime: - title: end_time - $ref: '#/components/schemas/google.protobuf.Timestamp' - traceLimit: - type: integer - title: trace_limit - format: int32 - title: SummarizeMaestroSelfTelemetryRequest - additionalProperties: false - traces.v1.SummarizeMaestroSelfTelemetryResponse: - type: object - properties: - summary: - title: summary - $ref: '#/components/schemas/traces.v1.MaestroSelfTelemetrySummary' - title: SummarizeMaestroSelfTelemetryResponse - additionalProperties: false - traces.v1.TraceAnnotation: - type: object - properties: - annotationId: - type: string - title: annotation_id - traceId: - type: string - title: trace_id - minLength: 1 - spanId: - type: string - title: span_id - kind: - title: kind - $ref: '#/components/schemas/traces.v1.TraceAnnotationKind' - note: - type: string - title: note - labels: - type: array - items: - type: string - title: labels - source: - type: string - title: source - metadata: - title: metadata - $ref: '#/components/schemas/google.protobuf.Struct' - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - status: - title: status - $ref: '#/components/schemas/traces.v1.TraceAnnotationStatus' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - resolvedAt: - title: resolved_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - resolvedBy: - type: string - title: resolved_by - title: TraceAnnotation - additionalProperties: false - traces.v1.TraceEvalCandidate: - type: object - properties: - candidateId: - type: string - title: candidate_id - traceId: - type: string - title: trace_id - spanId: - type: string - title: span_id - annotationId: - type: string - title: annotation_id - evalSuiteId: - type: string - title: eval_suite_id - caseKind: - type: string - title: case_kind - labels: - type: array - items: - type: string - title: labels - title: - type: string - title: title - rationale: - type: string - title: rationale - costUsd: - type: number - title: cost_usd - format: double - tokenInput: - type: - - integer - - string - title: token_input - format: int64 - tokenOutput: - type: - - integer - - string - title: token_output - format: int64 - governanceDecision: - title: governance_decision - $ref: '#/components/schemas/traces.v1.GovernanceDecision' - approvalRequired: - type: boolean - title: approval_required - redactionApplied: - type: boolean - title: redaction_applied - replayBundle: - title: replay_bundle - $ref: '#/components/schemas/traces.v1.TraceReplayBundle' - metadata: - title: metadata - $ref: '#/components/schemas/google.protobuf.Struct' - title: TraceEvalCandidate - additionalProperties: false - traces.v1.TraceEvidenceBundleRef: - type: object - properties: - bundleId: - type: string - title: bundle_id - uri: - type: string - title: uri - retention: - type: string - title: retention - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - provenance: - title: provenance - $ref: '#/components/schemas/google.protobuf.Struct' - title: TraceEvidenceBundleRef - additionalProperties: false - traces.v1.TraceEvidenceRef: - type: object - properties: - evidenceId: - type: string - title: evidence_id - label: - type: string - title: label - resourceType: - type: string - title: resource_type - uri: - type: string - title: uri - state: - title: state - $ref: '#/components/schemas/traces.v1.TraceEvidenceState' - reason: - type: string - title: reason - redactionApplied: - type: boolean - title: redaction_applied - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - metadata: - title: metadata - $ref: '#/components/schemas/google.protobuf.Struct' - spanIds: - type: array - items: - type: string - title: span_ids - title: TraceEvidenceRef - additionalProperties: false - traces.v1.TraceQualityAnnotation: - type: object - properties: - traceId: - type: string - title: trace_id - minLength: 1 - spanId: - type: string - title: span_id - compositeScore: - type: number - title: composite_score - format: double - assertions: - type: array - items: - $ref: '#/components/schemas/traces.v1.AssertionResult' - title: assertions - governance: - title: governance - $ref: '#/components/schemas/traces.v1.GovernanceScore' - cost: - title: cost - $ref: '#/components/schemas/common.v1.Money' - qualityPerDollar: - type: number - title: quality_per_dollar - format: double - evalSuiteId: - type: string - title: eval_suite_id - scoredAt: - title: scored_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - scorer: - type: string - title: scorer - metadata: - title: metadata - $ref: '#/components/schemas/google.protobuf.Struct' - conversationalSignals: - type: array - items: - $ref: '#/components/schemas/traces.v1.ConversationalSignal' - title: conversational_signals - title: TraceQualityAnnotation - additionalProperties: false - traces.v1.TraceRecoveryAction: - type: object - properties: - actionId: - type: string - title: action_id - title: - type: string - title: title - detail: - type: string - title: detail - severity: - type: string - title: severity - evidenceIds: - type: array - items: - type: string - title: evidence_ids - source: - type: string - title: source - title: TraceRecoveryAction - additionalProperties: false - traces.v1.TraceReplayBundle: - type: object - properties: - traceId: - type: string - title: trace_id - context: - title: context - $ref: '#/components/schemas/traces.v1.ReplayContext' - input: - type: string - title: input - model: - type: string - title: model - provider: - type: string - title: provider - promptConfig: - type: string - title: prompt_config - toolCalls: - type: array - items: - $ref: '#/components/schemas/traces.v1.ReplayToolCall' - title: tool_calls - qualityAnnotations: - type: array - items: - $ref: '#/components/schemas/traces.v1.TraceQualityAnnotation' - title: quality_annotations - redactionApplied: - type: boolean - title: redaction_applied - title: TraceReplayBundle - additionalProperties: false - traces.v1.TraceReview: - type: object - properties: - status: - type: string - title: status - headline: - type: string - title: headline - summary: - type: string - title: summary - evidenceGapCount: - type: integer - title: evidence_gap_count - format: int32 - metadataOnly: - type: boolean - title: metadata_only - reviewUrl: - type: string - title: review_url - evidenceRefs: - type: array - items: - $ref: '#/components/schemas/traces.v1.TraceEvidenceRef' - title: evidence_refs - recoveryActions: - type: array - items: - $ref: '#/components/schemas/traces.v1.TraceRecoveryAction' - title: recovery_actions - evidenceBundles: - type: array - items: - $ref: '#/components/schemas/traces.v1.TraceEvidenceBundleRef' - title: evidence_bundles - spanTree: - type: array - items: - $ref: '#/components/schemas/traces.v1.SpanNode' - title: span_tree - suggestedLabels: - type: array - items: - type: string - title: suggested_labels - provenance: - title: provenance - $ref: '#/components/schemas/google.protobuf.Struct' - title: TraceReview - additionalProperties: false - traces.v1.TraceReviewBundle: - type: object - properties: - trace: - title: trace - $ref: '#/components/schemas/traces.v1.TraceSummary' - spans: - type: array - items: - $ref: '#/components/schemas/traces.v1.Span' - title: spans - annotations: - type: array - items: - $ref: '#/components/schemas/traces.v1.TraceAnnotation' - title: annotations - qualityAnnotations: - type: array - items: - $ref: '#/components/schemas/traces.v1.TraceQualityAnnotation' - title: quality_annotations - matches: - type: array - items: - $ref: '#/components/schemas/traces.v1.TraceSearchMatch' - title: matches - suggestedLabels: - type: array - items: - type: string - title: suggested_labels - summary: - type: string - title: summary - evalCandidates: - type: array - items: - $ref: '#/components/schemas/traces.v1.TraceEvalCandidate' - title: eval_candidates - traceReview: - title: trace_review - $ref: '#/components/schemas/traces.v1.TraceReview' - title: TraceReviewBundle - additionalProperties: false - traces.v1.TraceSearchMatch: - type: object - properties: - traceId: - type: string - title: trace_id - spanId: - type: string - title: span_id - spanName: - type: string - title: span_name - scope: - type: string - title: scope - start: - type: integer - title: start - format: int32 - end: - type: integer - title: end - format: int32 - snippet: - type: string - title: snippet - title: TraceSearchMatch - additionalProperties: false - traces.v1.TraceSummary: - type: object - properties: - traceId: - type: string - title: trace_id - workspaceId: - type: string - title: workspace_id - organizationId: - type: string - title: organization_id - agentId: - type: string - title: agent_id - surface: - type: string - title: surface - rootSpanName: - type: string - title: root_span_name - totalSpans: - type: integer - title: total_spans - format: int32 - totalTokenInput: - type: - - integer - - string - title: total_token_input - format: int64 - totalTokenOutput: - type: - - integer - - string - title: total_token_output - format: int64 - totalCostUsd: - type: number - title: total_cost_usd - format: double - totalLatencyMs: - type: - - integer - - string - title: total_latency_ms - format: int64 - startedAt: - title: started_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - endedAt: - title: ended_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - userId: - type: string - title: user_id - title: TraceSummary - additionalProperties: false - connect-protocol-version: - type: number - title: Connect-Protocol-Version - enum: - - 1 - description: Define the version of the Connect protocol - const: 1 - connect-timeout-header: - type: number - title: Connect-Timeout-Ms - description: Define the timeout, in ms - connect.error: - type: object - properties: - code: - type: string - examples: - - not_found - enum: - - canceled - - unknown - - invalid_argument - - deadline_exceeded - - not_found - - already_exists - - permission_denied - - resource_exhausted - - failed_precondition - - aborted - - out_of_range - - unimplemented - - internal - - unavailable - - data_loss - - unauthenticated - description: The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code]. - message: - type: string - description: A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client. - detail: - $ref: '#/components/schemas/google.protobuf.Any' - title: Connect Error - additionalProperties: true - description: 'Error type returned by Connect: https://connectrpc.com/docs/go/errors/#http-representation' - google.protobuf.Any: - type: object - properties: - type: - type: string - value: - type: string - format: binary - debug: - type: object - additionalProperties: true - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. -security: [] -tags: - - name: traces.v1.SpanIngestService - description: SpanIngestService records and queries agent execution traces. diff --git a/openapi/vfs/v1/filesystem.openapi.yaml b/openapi/vfs/v1/filesystem.openapi.yaml deleted file mode 100644 index e9f9003..0000000 --- a/openapi/vfs/v1/filesystem.openapi.yaml +++ /dev/null @@ -1,1778 +0,0 @@ -openapi: 3.1.0 -info: - title: vfs.v1 -paths: - /vfs.v1.VirtualFilesystemService/PutObject: - post: - tags: - - vfs.v1.VirtualFilesystemService - summary: PutObject - description: |- - PutObject writes bytes directly to a workspace path and creates the first - immutable version or appends a new version to an existing path. - operationId: vfs.v1.VirtualFilesystemService.PutObject - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/vfs.v1.PutObjectRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/vfs.v1.PutObjectResponse' - /vfs.v1.VirtualFilesystemService/GetObject: - post: - tags: - - vfs.v1.VirtualFilesystemService - summary: GetObject - description: |- - GetObject returns metadata and an optional ranged byte slice for one - object, selected by object ID or path. - operationId: vfs.v1.VirtualFilesystemService.GetObject - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/vfs.v1.GetObjectRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/vfs.v1.GetObjectResponse' - /vfs.v1.VirtualFilesystemService/ListObjects: - post: - tags: - - vfs.v1.VirtualFilesystemService - summary: ListObjects - description: ListObjects lists path metadata within a workspace and optional prefix. - operationId: vfs.v1.VirtualFilesystemService.ListObjects - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/vfs.v1.ListObjectsRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/vfs.v1.ListObjectsResponse' - /vfs.v1.VirtualFilesystemService/StatObject: - post: - tags: - - vfs.v1.VirtualFilesystemService - summary: StatObject - description: StatObject returns metadata and optional version history without bytes. - operationId: vfs.v1.VirtualFilesystemService.StatObject - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/vfs.v1.StatObjectRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/vfs.v1.StatObjectResponse' - /vfs.v1.VirtualFilesystemService/DeleteObject: - post: - tags: - - vfs.v1.VirtualFilesystemService - summary: DeleteObject - description: DeleteObject tombstones a path while retaining metadata and versions. - operationId: vfs.v1.VirtualFilesystemService.DeleteObject - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/vfs.v1.DeleteObjectRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/vfs.v1.DeleteObjectResponse' - /vfs.v1.VirtualFilesystemService/CopyObject: - post: - tags: - - vfs.v1.VirtualFilesystemService - summary: CopyObject - description: CopyObject creates a new path with independent metadata over copied bytes. - operationId: vfs.v1.VirtualFilesystemService.CopyObject - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/vfs.v1.CopyObjectRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/vfs.v1.CopyObjectResponse' - /vfs.v1.VirtualFilesystemService/LinkObject: - post: - tags: - - vfs.v1.VirtualFilesystemService - summary: LinkObject - description: LinkObject creates another path entry pointing at the same content hash. - operationId: vfs.v1.VirtualFilesystemService.LinkObject - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/vfs.v1.LinkObjectRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/vfs.v1.LinkObjectResponse' - /vfs.v1.VirtualFilesystemService/CreateLease: - post: - tags: - - vfs.v1.VirtualFilesystemService - summary: CreateLease - description: CreateLease reserves a path for a long-running upload. - operationId: vfs.v1.VirtualFilesystemService.CreateLease - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/vfs.v1.CreateLeaseRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/vfs.v1.CreateLeaseResponse' - /vfs.v1.VirtualFilesystemService/CompleteLease: - post: - tags: - - vfs.v1.VirtualFilesystemService - summary: CompleteLease - description: CompleteLease completes a lease and publishes an immutable object version. - operationId: vfs.v1.VirtualFilesystemService.CompleteLease - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/vfs.v1.CompleteLeaseRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/vfs.v1.CompleteLeaseResponse' - /vfs.v1.VirtualFilesystemService/GrantObject: - post: - tags: - - vfs.v1.VirtualFilesystemService - summary: GrantObject - description: GrantObject replaces or appends capability grants for one object. - operationId: vfs.v1.VirtualFilesystemService.GrantObject - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/vfs.v1.GrantObjectRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/vfs.v1.GrantObjectResponse' - /vfs.v1.VirtualFilesystemService/SearchMetadata: - post: - tags: - - vfs.v1.VirtualFilesystemService - summary: SearchMetadata - description: |- - SearchMetadata searches object metadata, tags, paths, and titles without - returning file bytes. - operationId: vfs.v1.VirtualFilesystemService.SearchMetadata - parameters: - - name: Connect-Protocol-Version - in: header - required: true - schema: - $ref: '#/components/schemas/connect-protocol-version' - - name: Connect-Timeout-Ms - in: header - schema: - $ref: '#/components/schemas/connect-timeout-header' - requestBody: - content: - application/json: - schema: - $ref: '#/components/schemas/vfs.v1.SearchMetadataRequest' - required: true - responses: - default: - description: Error - content: - application/json: - schema: - $ref: '#/components/schemas/connect.error' - "200": - description: Success - content: - application/json: - schema: - $ref: '#/components/schemas/vfs.v1.SearchMetadataResponse' -components: - schemas: - platform.v1.ResourceKind: - type: string - title: ResourceKind - enum: - - RESOURCE_KIND_UNSPECIFIED - - RESOURCE_KIND_AGENT - - RESOURCE_KIND_TOOL - - RESOURCE_KIND_REPO - - RESOURCE_KIND_DATASET - - RESOURCE_KIND_DATABASE - - RESOURCE_KIND_CRM_OBJECT - - RESOURCE_KIND_MODEL_ROUTE - - RESOURCE_KIND_EXTERNAL - - RESOURCE_KIND_VFS_OBJECT - - RESOURCE_KIND_VFS_OBJECT_VERSION - - RESOURCE_KIND_ARTIFACT - - RESOURCE_KIND_ARTIFACT_VERSION - - RESOURCE_KIND_GENERATED_ASSET - vfs.v1.VfsLeaseState: - type: string - title: VfsLeaseState - enum: - - VFS_LEASE_STATE_UNSPECIFIED - - VFS_LEASE_STATE_OPEN - - VFS_LEASE_STATE_COMMITTED - - VFS_LEASE_STATE_EXPIRED - - VFS_LEASE_STATE_CANCELLED - vfs.v1.VfsObjectState: - type: string - title: VfsObjectState - enum: - - VFS_OBJECT_STATE_UNSPECIFIED - - VFS_OBJECT_STATE_ACTIVE - - VFS_OBJECT_STATE_TOMBSTONED - vfs.v1.VfsRedactionState: - type: string - title: VfsRedactionState - enum: - - VFS_REDACTION_STATE_UNSPECIFIED - - VFS_REDACTION_STATE_RAW - - VFS_REDACTION_STATE_REDACTED - - VFS_REDACTION_STATE_PREVIEW_ONLY - - VFS_REDACTION_STATE_DENIED - google.protobuf.Timestamp: - type: string - examples: - - 1s - - 1.000340012s - format: date-time - description: |- - A Timestamp represents a point in time independent of any time zone or local - calendar, encoded as a count of seconds and fractions of seconds at - nanosecond resolution. The count is relative to an epoch at UTC midnight on - January 1, 1970, in the proleptic Gregorian calendar which extends the - Gregorian calendar backwards to year one. - - All minutes are 60 seconds long. Leap seconds are "smeared" so that no leap - second table is needed for interpretation, using a [24-hour linear - smear](https://developers.google.com/time/smear). - - The range is from 0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z. By - restricting to that range, we ensure that we can convert to and from [RFC - 3339](https://www.ietf.org/rfc/rfc3339.txt) date strings. - - # Examples - - Example 1: Compute Timestamp from POSIX `time()`. - - Timestamp timestamp; - timestamp.set_seconds(time(NULL)); - timestamp.set_nanos(0); - - Example 2: Compute Timestamp from POSIX `gettimeofday()`. - - struct timeval tv; - gettimeofday(&tv, NULL); - - Timestamp timestamp; - timestamp.set_seconds(tv.tv_sec); - timestamp.set_nanos(tv.tv_usec * 1000); - - Example 3: Compute Timestamp from Win32 `GetSystemTimeAsFileTime()`. - - FILETIME ft; - GetSystemTimeAsFileTime(&ft); - UINT64 ticks = (((UINT64)ft.dwHighDateTime) << 32) | ft.dwLowDateTime; - - // A Windows tick is 100 nanoseconds. Windows epoch 1601-01-01T00:00:00Z - // is 11644473600 seconds before Unix epoch 1970-01-01T00:00:00Z. - Timestamp timestamp; - timestamp.set_seconds((INT64) ((ticks / 10000000) - 11644473600LL)); - timestamp.set_nanos((INT32) ((ticks % 10000000) * 100)); - - Example 4: Compute Timestamp from Java `System.currentTimeMillis()`. - - long millis = System.currentTimeMillis(); - - Timestamp timestamp = Timestamp.newBuilder().setSeconds(millis / 1000) - .setNanos((int) ((millis % 1000) * 1000000)).build(); - - Example 5: Compute Timestamp from Java `Instant.now()`. - - Instant now = Instant.now(); - - Timestamp timestamp = - Timestamp.newBuilder().setSeconds(now.getEpochSecond()) - .setNanos(now.getNano()).build(); - - Example 6: Compute Timestamp from current time in Python. - - timestamp = Timestamp() - timestamp.GetCurrentTime() - - # JSON Mapping - - In JSON format, the Timestamp type is encoded as a string in the - [RFC 3339](https://www.ietf.org/rfc/rfc3339.txt) format. That is, the - format is "{year}-{month}-{day}T{hour}:{min}:{sec}[.{frac_sec}]Z" - where {year} is always expressed using four digits while {month}, {day}, - {hour}, {min}, and {sec} are zero-padded to two digits each. The fractional - seconds, which can go up to 9 digits (i.e. up to 1 nanosecond resolution), - are optional. The "Z" suffix indicates the timezone ("UTC"); the timezone - is required. A proto3 JSON serializer should always use UTC (as indicated by - "Z") when printing the Timestamp type and a proto3 JSON parser should be - able to accept both UTC and other timezones (as indicated by an offset). - - For example, "2017-01-15T01:30:15.01Z" encodes 15.01 seconds past - 01:30 UTC on January 15, 2017. - - In JavaScript, one can convert a Date object to this format using the - standard - [toISOString()](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Date/toISOString) - method. In Python, a standard `datetime.datetime` object can be converted - to this format using - [`strftime`](https://docs.python.org/2/library/time.html#time.strftime) with - the time format spec '%Y-%m-%dT%H:%M:%S.%fZ'. Likewise, in Java, one can use - the Joda Time's [`ISODateTimeFormat.dateTime()`]( - http://joda-time.sourceforge.net/apidocs/org/joda/time/format/ISODateTimeFormat.html#dateTime() - ) to obtain a formatter capable of generating timestamps in this format. - platform.v1.ResourceRef: - type: object - properties: - resourceId: - type: string - title: resource_id - minLength: 1 - kind: - title: kind - $ref: '#/components/schemas/platform.v1.ResourceKind' - versionId: - type: string - title: version_id - description: Stable immutable version identity, when the reference is version-bound. - version: - type: integer - title: version - format: int32 - description: |- - Owner-defined monotonic version number. Zero means the latest version - when version_id is empty; version_id wins when both are supplied. - title: ResourceRef - additionalProperties: false - description: |- - ResourceRef is the canonical structured pointer for durable Platform - content. It is intentionally not a URI: callers carry organization and - workspace authority in the surrounding request, while a resolver owned by - the resource's service decides whether a reference yields metadata, VFS - identity, or a short-lived byte-access grant. - vfs.v1.CompleteLeaseRequest: - type: object - properties: - leaseId: - type: string - title: lease_id - minLength: 1 - leaseToken: - type: string - title: lease_token - minLength: 1 - content: - type: string - title: content - format: byte - createdBy: - type: string - title: created_by - metadata: - type: object - title: metadata - additionalProperties: - type: string - title: value - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - fencingToken: - type: - - integer - - string - title: fencing_token - minimum: 1 - format: int64 - sizeBytes: - exclusiveMinimum: 0 - type: - - integer - - string - title: size_bytes - maximum: 52428800 - format: int64 - sha256: - type: string - title: sha256 - minLength: 1 - storageEtag: - type: string - title: storage_etag - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: CompleteLeaseRequest - additionalProperties: false - vfs.v1.CompleteLeaseRequest.MetadataEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: MetadataEntry - additionalProperties: false - vfs.v1.CompleteLeaseResponse: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/vfs.v1.VfsObject' - version: - title: version - $ref: '#/components/schemas/vfs.v1.VfsObjectVersion' - event: - title: event - $ref: '#/components/schemas/vfs.v1.VfsEvent' - title: CompleteLeaseResponse - additionalProperties: false - vfs.v1.CopyObjectRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - sourceObjectId: - type: string - title: source_object_id - sourcePath: - type: string - title: source_path - destinationPath: - type: string - title: destination_path - minLength: 1 - creatorId: - type: string - title: creator_id - sourceService: - type: string - title: source_service - metadata: - type: object - title: metadata - additionalProperties: - type: string - title: value - organizationId: - type: string - title: organization_id - minLength: 1 - title: CopyObjectRequest - additionalProperties: false - vfs.v1.CopyObjectRequest.MetadataEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: MetadataEntry - additionalProperties: false - vfs.v1.CopyObjectResponse: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/vfs.v1.VfsObject' - version: - title: version - $ref: '#/components/schemas/vfs.v1.VfsObjectVersion' - event: - title: event - $ref: '#/components/schemas/vfs.v1.VfsEvent' - title: CopyObjectResponse - additionalProperties: false - vfs.v1.CreateLeaseRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - path: - type: string - title: path - minLength: 1 - leaseSeconds: - type: integer - title: lease_seconds - format: int32 - contentType: - type: string - title: content_type - creatorId: - type: string - title: creator_id - metadata: - type: object - title: metadata - additionalProperties: - type: string - title: value - organizationId: - type: string - title: organization_id - minLength: 1 - expectedSizeBytes: - exclusiveMinimum: 0 - type: - - integer - - string - title: expected_size_bytes - maximum: 52428800 - format: int64 - expectedSha256: - type: string - title: expected_sha256 - idempotencyKey: - type: string - title: idempotency_key - minLength: 1 - title: CreateLeaseRequest - additionalProperties: false - vfs.v1.CreateLeaseRequest.MetadataEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: MetadataEntry - additionalProperties: false - vfs.v1.CreateLeaseResponse: - type: object - properties: - lease: - title: lease - $ref: '#/components/schemas/vfs.v1.VfsLease' - upload: - title: upload - $ref: '#/components/schemas/vfs.v1.VfsUploadTarget' - title: CreateLeaseResponse - additionalProperties: false - vfs.v1.DeleteObjectRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - objectId: - type: string - title: object_id - path: - type: string - title: path - deletedBy: - type: string - title: deleted_by - reason: - type: string - title: reason - organizationId: - type: string - title: organization_id - minLength: 1 - title: DeleteObjectRequest - additionalProperties: false - vfs.v1.DeleteObjectResponse: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/vfs.v1.VfsObject' - event: - title: event - $ref: '#/components/schemas/vfs.v1.VfsEvent' - title: DeleteObjectResponse - additionalProperties: false - vfs.v1.GetObjectRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - objectId: - type: string - title: object_id - path: - type: string - title: path - versionId: - type: string - title: version_id - offset: - type: - - integer - - string - title: offset - format: int64 - limit: - type: - - integer - - string - title: limit - format: int64 - includeContent: - type: boolean - title: include_content - organizationId: - type: string - title: organization_id - minLength: 1 - title: GetObjectRequest - additionalProperties: false - vfs.v1.GetObjectResponse: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/vfs.v1.VfsObject' - version: - title: version - $ref: '#/components/schemas/vfs.v1.VfsObjectVersion' - content: - type: string - title: content - format: byte - offset: - type: - - integer - - string - title: offset - format: int64 - nextOffset: - type: - - integer - - string - title: next_offset - format: int64 - eof: - type: boolean - title: eof - title: GetObjectResponse - additionalProperties: false - vfs.v1.GrantObjectRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - objectId: - type: string - title: object_id - path: - type: string - title: path - grant: - title: grant - $ref: '#/components/schemas/vfs.v1.VfsGrant' - append: - type: boolean - title: append - organizationId: - type: string - title: organization_id - minLength: 1 - title: GrantObjectRequest - required: - - grant - additionalProperties: false - vfs.v1.GrantObjectResponse: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/vfs.v1.VfsObject' - event: - title: event - $ref: '#/components/schemas/vfs.v1.VfsEvent' - title: GrantObjectResponse - additionalProperties: false - vfs.v1.LinkObjectRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - sourceObjectId: - type: string - title: source_object_id - sourcePath: - type: string - title: source_path - linkPath: - type: string - title: link_path - minLength: 1 - creatorId: - type: string - title: creator_id - metadata: - type: object - title: metadata - additionalProperties: - type: string - title: value - organizationId: - type: string - title: organization_id - minLength: 1 - title: LinkObjectRequest - additionalProperties: false - vfs.v1.LinkObjectRequest.MetadataEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: MetadataEntry - additionalProperties: false - vfs.v1.LinkObjectResponse: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/vfs.v1.VfsObject' - version: - title: version - $ref: '#/components/schemas/vfs.v1.VfsObjectVersion' - event: - title: event - $ref: '#/components/schemas/vfs.v1.VfsEvent' - title: LinkObjectResponse - additionalProperties: false - vfs.v1.ListObjectsRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - pathPrefix: - type: string - title: path_prefix - includeTombstones: - type: boolean - title: include_tombstones - tags: - type: array - items: - type: string - title: tags - limit: - type: integer - title: limit - format: int32 - offset: - type: integer - title: offset - format: int32 - organizationId: - type: string - title: organization_id - minLength: 1 - title: ListObjectsRequest - additionalProperties: false - vfs.v1.ListObjectsResponse: - type: object - properties: - objects: - type: array - items: - $ref: '#/components/schemas/vfs.v1.VfsObject' - title: objects - total: - type: integer - title: total - format: int32 - hasMore: - type: boolean - title: has_more - title: ListObjectsResponse - additionalProperties: false - vfs.v1.PutObjectRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - path: - type: string - title: path - minLength: 1 - content: - type: string - title: content - format: byte - contentType: - type: string - title: content_type - ownerId: - type: string - title: owner_id - creatorId: - type: string - title: creator_id - sourceService: - type: string - title: source_service - runId: - type: string - title: run_id - toolExecutionId: - type: string - title: tool_execution_id - connectorId: - type: string - title: connector_id - connectionId: - type: string - title: connection_id - sensitivity: - type: string - title: sensitivity - retentionClass: - type: string - title: retention_class - redactionState: - title: redaction_state - $ref: '#/components/schemas/vfs.v1.VfsRedactionState' - tags: - type: array - items: - type: string - title: tags - metadata: - type: object - title: metadata - additionalProperties: - type: string - title: value - idempotencyKey: - type: string - title: idempotency_key - organizationId: - type: string - title: organization_id - minLength: 1 - expectedVersion: - type: integer - title: expected_version - format: int32 - leaseToken: - type: string - title: lease_token - fencingToken: - type: - - integer - - string - title: fencing_token - format: int64 - title: PutObjectRequest - additionalProperties: false - vfs.v1.PutObjectRequest.MetadataEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: MetadataEntry - additionalProperties: false - vfs.v1.PutObjectResponse: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/vfs.v1.VfsObject' - version: - title: version - $ref: '#/components/schemas/vfs.v1.VfsObjectVersion' - event: - title: event - $ref: '#/components/schemas/vfs.v1.VfsEvent' - title: PutObjectResponse - additionalProperties: false - vfs.v1.SearchMetadataRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - query: - type: string - title: query - pathPrefix: - type: string - title: path_prefix - tags: - type: array - items: - type: string - title: tags - metadata: - type: object - title: metadata - additionalProperties: - type: string - title: value - includeTombstones: - type: boolean - title: include_tombstones - limit: - type: integer - title: limit - format: int32 - organizationId: - type: string - title: organization_id - minLength: 1 - title: SearchMetadataRequest - additionalProperties: false - vfs.v1.SearchMetadataRequest.MetadataEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: MetadataEntry - additionalProperties: false - vfs.v1.SearchMetadataResponse: - type: object - properties: - objects: - type: array - items: - $ref: '#/components/schemas/vfs.v1.VfsObject' - title: objects - title: SearchMetadataResponse - additionalProperties: false - vfs.v1.StatObjectRequest: - type: object - properties: - workspaceId: - type: string - title: workspace_id - minLength: 1 - objectId: - type: string - title: object_id - path: - type: string - title: path - includeVersions: - type: boolean - title: include_versions - organizationId: - type: string - title: organization_id - minLength: 1 - title: StatObjectRequest - additionalProperties: false - vfs.v1.StatObjectResponse: - type: object - properties: - object: - title: object - $ref: '#/components/schemas/vfs.v1.VfsObject' - versions: - type: array - items: - $ref: '#/components/schemas/vfs.v1.VfsObjectVersion' - title: versions - title: StatObjectResponse - additionalProperties: false - vfs.v1.VfsCompletedUploadPart: - type: object - properties: - partNumber: - exclusiveMinimum: 0 - type: integer - title: part_number - format: int32 - etag: - type: string - title: etag - minLength: 1 - title: VfsCompletedUploadPart - additionalProperties: false - vfs.v1.VfsEvent: - type: object - properties: - id: - type: string - title: id - type: - type: string - title: type - workspaceId: - type: string - title: workspace_id - objectId: - type: string - title: object_id - path: - type: string - title: path - versionId: - type: string - title: version_id - version: - type: integer - title: version - format: int32 - sha256: - type: string - title: sha256 - sizeBytes: - type: - - integer - - string - title: size_bytes - format: int64 - contentType: - type: string - title: content_type - sourceService: - type: string - title: source_service - runId: - type: string - title: run_id - toolExecutionId: - type: string - title: tool_execution_id - connectorId: - type: string - title: connector_id - connectionId: - type: string - title: connection_id - sensitivity: - type: string - title: sensitivity - retentionClass: - type: string - title: retention_class - metadata: - type: object - title: metadata - additionalProperties: - type: string - title: value - occurredAt: - title: occurred_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - redactionState: - title: redaction_state - $ref: '#/components/schemas/vfs.v1.VfsRedactionState' - organizationId: - type: string - title: organization_id - minLength: 1 - title: VfsEvent - additionalProperties: false - vfs.v1.VfsEvent.MetadataEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: MetadataEntry - additionalProperties: false - vfs.v1.VfsGrant: - type: object - properties: - principal: - type: string - title: principal - minLength: 1 - permissions: - type: array - items: - type: string - title: permissions - pathPrefix: - type: string - title: path_prefix - sensitivity: - type: string - title: sensitivity - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - grantedAt: - title: granted_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - grantedBy: - type: string - title: granted_by - title: VfsGrant - additionalProperties: false - vfs.v1.VfsLease: - type: object - properties: - id: - type: string - title: id - workspaceId: - type: string - title: workspace_id - minLength: 1 - path: - type: string - title: path - minLength: 1 - token: - type: string - title: token - state: - title: state - $ref: '#/components/schemas/vfs.v1.VfsLeaseState' - contentType: - type: string - title: content_type - metadata: - type: object - title: metadata - additionalProperties: - type: string - title: value - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - createdBy: - type: string - title: created_by - organizationId: - type: string - title: organization_id - minLength: 1 - fencingToken: - type: - - integer - - string - title: fencing_token - minimum: 1 - format: int64 - title: VfsLease - additionalProperties: false - vfs.v1.VfsLease.MetadataEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: MetadataEntry - additionalProperties: false - vfs.v1.VfsObject: - type: object - properties: - id: - type: string - title: id - workspaceId: - type: string - title: workspace_id - minLength: 1 - path: - type: string - title: path - minLength: 1 - state: - title: state - $ref: '#/components/schemas/vfs.v1.VfsObjectState' - currentVersion: - type: integer - title: current_version - format: int32 - currentVersionId: - type: string - title: current_version_id - contentType: - type: string - title: content_type - sizeBytes: - type: - - integer - - string - title: size_bytes - format: int64 - sha256: - type: string - title: sha256 - etag: - type: string - title: etag - ownerId: - type: string - title: owner_id - creatorId: - type: string - title: creator_id - sourceService: - type: string - title: source_service - runId: - type: string - title: run_id - toolExecutionId: - type: string - title: tool_execution_id - connectorId: - type: string - title: connector_id - connectionId: - type: string - title: connection_id - sensitivity: - type: string - title: sensitivity - retentionClass: - type: string - title: retention_class - redactionState: - title: redaction_state - $ref: '#/components/schemas/vfs.v1.VfsRedactionState' - tags: - type: array - items: - type: string - title: tags - metadata: - type: object - title: metadata - additionalProperties: - type: string - title: value - grants: - type: array - items: - $ref: '#/components/schemas/vfs.v1.VfsGrant' - title: grants - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - updatedAt: - title: updated_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - deletedAt: - title: deleted_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - deletedBy: - type: string - title: deleted_by - deleteReason: - type: string - title: delete_reason - organizationId: - type: string - title: organization_id - minLength: 1 - resourceRef: - title: resource_ref - $ref: '#/components/schemas/platform.v1.ResourceRef' - title: VfsObject - additionalProperties: false - vfs.v1.VfsObject.MetadataEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: MetadataEntry - additionalProperties: false - vfs.v1.VfsObjectVersion: - type: object - properties: - id: - type: string - title: id - objectId: - type: string - title: object_id - version: - type: integer - title: version - format: int32 - contentRef: - type: string - title: content_ref - contentType: - type: string - title: content_type - sizeBytes: - type: - - integer - - string - title: size_bytes - format: int64 - sha256: - type: string - title: sha256 - etag: - type: string - title: etag - createdBy: - type: string - title: created_by - sourceService: - type: string - title: source_service - metadata: - type: object - title: metadata - additionalProperties: - type: string - title: value - createdAt: - title: created_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - organizationId: - type: string - title: organization_id - minLength: 1 - workspaceId: - type: string - title: workspace_id - minLength: 1 - resourceRef: - title: resource_ref - $ref: '#/components/schemas/platform.v1.ResourceRef' - title: VfsObjectVersion - additionalProperties: false - vfs.v1.VfsObjectVersion.MetadataEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: MetadataEntry - additionalProperties: false - vfs.v1.VfsUploadPartTarget: - type: object - properties: - partNumber: - exclusiveMinimum: 0 - type: integer - title: part_number - format: int32 - offset: - type: - - integer - - string - title: offset - format: int64 - sizeBytes: - exclusiveMinimum: 0 - type: - - integer - - string - title: size_bytes - format: int64 - url: - type: string - title: url - minLength: 1 - method: - type: string - title: method - minLength: 1 - headers: - type: object - title: headers - additionalProperties: - type: string - title: value - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - title: VfsUploadPartTarget - additionalProperties: false - vfs.v1.VfsUploadPartTarget.HeadersEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: HeadersEntry - additionalProperties: false - vfs.v1.VfsUploadTarget: - type: object - properties: - url: - type: string - title: url - method: - type: string - title: method - minLength: 1 - headers: - type: object - title: headers - additionalProperties: - type: string - title: value - expiresAt: - title: expires_at - $ref: '#/components/schemas/google.protobuf.Timestamp' - maxSizeBytes: - exclusiveMinimum: 0 - type: - - integer - - string - title: max_size_bytes - maximum: 52428800 - format: int64 - parts: - type: array - items: - $ref: '#/components/schemas/vfs.v1.VfsUploadPartTarget' - title: parts - title: VfsUploadTarget - additionalProperties: false - vfs.v1.VfsUploadTarget.HeadersEntry: - type: object - properties: - key: - type: string - title: key - value: - type: string - title: value - title: HeadersEntry - additionalProperties: false - connect-protocol-version: - type: number - title: Connect-Protocol-Version - enum: - - 1 - description: Define the version of the Connect protocol - const: 1 - connect-timeout-header: - type: number - title: Connect-Timeout-Ms - description: Define the timeout, in ms - connect.error: - type: object - properties: - code: - type: string - examples: - - not_found - enum: - - canceled - - unknown - - invalid_argument - - deadline_exceeded - - not_found - - already_exists - - permission_denied - - resource_exhausted - - failed_precondition - - aborted - - out_of_range - - unimplemented - - internal - - unavailable - - data_loss - - unauthenticated - description: The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code]. - message: - type: string - description: A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client. - detail: - $ref: '#/components/schemas/google.protobuf.Any' - title: Connect Error - additionalProperties: true - description: 'Error type returned by Connect: https://connectrpc.com/docs/go/errors/#http-representation' - google.protobuf.Any: - type: object - properties: - type: - type: string - value: - type: string - format: binary - debug: - type: object - additionalProperties: true - additionalProperties: true - description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message. -security: [] -tags: - - name: vfs.v1.VirtualFilesystemService - description: |- - VirtualFilesystemService is the durable file plane for agents, - integrations, tool execution, memory evidence, and channel handoffs. diff --git a/proto/agentruntime/v1/runtime.proto b/proto/agentruntime/v1/runtime.proto deleted file mode 100644 index f5276ff..0000000 --- a/proto/agentruntime/v1/runtime.proto +++ /dev/null @@ -1,2948 +0,0 @@ -syntax = "proto3"; - -package agentruntime.v1; - -import "agents/v1/agents.proto"; -import "buf/validate/validate.proto"; -import "codex/v1/codex.proto"; -import "common/v1/authz.proto"; -import "common/v1/risk.proto"; -import "common/v1/surface.proto"; -import "google/protobuf/struct.proto"; -import "google/protobuf/timestamp.proto"; -import "objectives/v1/objectives.proto"; - -option go_package = "github.com/evalops/platform/gen/go/agentruntime/v1;agentruntimev1"; - -// AgentRuntimeService accepts normalized triggers and manages durable -// AgentRun execution attempts. Workers claim runs by lease, checkpoint their -// progress, release compute while waiting for human/input/event gates, and -// resume from checkpoints rather than replaying LLM or tool calls. -service AgentRuntimeService { - // HandleTrigger receives a normalized product or integration trigger, - // resolves agent/objective context, records an AgentRun, and dispatches it. - rpc HandleTrigger(HandleTriggerRequest) returns (HandleTriggerResponse) { - option (common.v1.required_scopes) = "agentruntime:write"; - option (common.v1.organization_scope_field) = "trigger.organization_id"; - option (common.v1.workspace_scope_field) = "trigger.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // AdmitOperatingChannelEvent accepts provider-issued coordinates from a - // channel edge that cannot know tenant ownership. Platform resolves the - // installation and external actor before durably admitting the event. - rpc AdmitOperatingChannelEvent(AdmitOperatingChannelEventRequest) returns (AdmitOperatingChannelEventResponse) { - option (common.v1.required_scopes) = "channel-edge:admit"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // AdmitSurfaceInvocation accepts a provider-neutral invocation from a - // verified surface adapter. Platform resolves installation ownership and - // the external actor before binding the provider object to an operating - // thread and durably admitting work. - rpc AdmitSurfaceInvocation(AdmitSurfaceInvocationRequest) returns (AdmitSurfaceInvocationResponse) { - option (common.v1.required_scopes) = "surface-edge:admit"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Identity reconciles one approved organization and its active default workspace. - // Caller scope is service-only; this request cannot select provider credentials. - rpc EnsureOrganizationEmail(EnsureOrganizationEmailRequest) returns (EnsureOrganizationEmailResponse) { - option (common.v1.required_scopes) = "organization-email:provision"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // ClaimNextRun atomically leases the next queued or retry-ready run for a - // worker. A claim transitions the run to RUNNING and increments attempt. - rpc ClaimNextRun(ClaimNextRunRequest) returns (ClaimNextRunResponse) { - option (common.v1.required_scopes) = "agentruntime:write"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // HeartbeatRun extends an active worker lease. Expired leases are eligible - // to be reclaimed by another worker from the last checkpoint. - rpc HeartbeatRun(HeartbeatRunRequest) returns (HeartbeatRunResponse) { - option (common.v1.required_scopes) = "agentruntime:write"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // RenewRunLease recovers a still-owned worker lease after it has expired but - // before the run has been parked, completed, or otherwise taken over. - rpc RenewRunLease(RenewRunLeaseRequest) returns (RenewRunLeaseResponse) { - option (common.v1.required_scopes) = "agentruntime:write"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // RecordRunStep upserts the durable record for one execution step. - rpc RecordRunStep(RecordRunStepRequest) returns (RecordRunStepResponse) { - option (common.v1.required_scopes) = "agentruntime:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // RecordRunCheckpoint stores an opaque resume snapshot. Checkpoints are the - // source of truth for resuming work; deterministic replay is not required. - rpc RecordRunCheckpoint(RecordRunCheckpointRequest) returns (RecordRunCheckpointResponse) { - option (common.v1.required_scopes) = "agentruntime:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // RecordRunArtifact links a produced artifact to the run and optional step. - rpc RecordRunArtifact(RecordRunArtifactRequest) returns (RecordRunArtifactResponse) { - option (common.v1.required_scopes) = "agentruntime:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // RecordRunCost links metering/cost data to the run and optional step. - rpc RecordRunCost(RecordRunCostRequest) returns (RecordRunCostResponse) { - option (common.v1.required_scopes) = "agentruntime:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // RecordRunStreamCursor stores a consumer cursor into the run event stream. - rpc RecordRunStreamCursor(RecordRunStreamCursorRequest) returns (RecordRunStreamCursorResponse) { - option (common.v1.required_scopes) = "agentruntime:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // RecordRunEvent appends an adapter-observed lifecycle event to an existing - // AgentRun without requiring a worker lease. Channel adapters use this to - // attach Slack/Teams/email delivery, approval, model, and tool milestones - // while Platform remains the durable source of truth for the run timeline. - rpc RecordRunEvent(RecordRunEventRequest) returns (RecordRunEventResponse) { - option (common.v1.required_scopes) = "agentruntime:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // ControlRun records a human, channel, scheduler, or system control against - // the active autonomous run/session. Controls are durable steering input; the - // Slack adapter is not responsible for keeping the agent alive turn by turn. - rpc ControlRun(ControlRunRequest) returns (ControlRunResponse) { - option (common.v1.required_scopes) = "agentruntime:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // RecordRunWorkItem creates or replaces one node in the autonomous work graph. - // Work items, not VFS projections, are the canonical state for long-horizon - // goals, child runs, waits, tool activity, blockers, and completion gates. - rpc RecordRunWorkItem(RecordRunWorkItemRequest) returns (RecordRunWorkItemResponse) { - option (common.v1.required_scopes) = "agentruntime:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // UpdateRunWorkItem patches progress for one autonomous work graph node. - rpc UpdateRunWorkItem(UpdateRunWorkItemRequest) returns (UpdateRunWorkItemResponse) { - option (common.v1.required_scopes) = "agentruntime:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // ListRunWorkItems returns the typed work graph for one run or work envelope. - rpc ListRunWorkItems(ListRunWorkItemsRequest) returns (ListRunWorkItemsResponse) { - option (common.v1.required_scopes) = "agentruntime:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // YieldRun ends the current leased run step while keeping the autonomous - // session alive. Inline yields enqueue a successor AgentRun immediately; - // end-session yields close the run without enqueueing more autonomous work. - // Timer, approval, input, and event blocking use WaitRun/ResumeRun. - rpc YieldRun(YieldRunRequest) returns (YieldRunResponse) { - option (common.v1.required_scopes) = "agentruntime:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // WaitRun parks the run on an approval, input, timer, or event wait and - // clears the worker lease so no compute is held while blocked. - rpc WaitRun(WaitRunRequest) returns (WaitRunResponse) { - option (common.v1.required_scopes) = "agentruntime:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // ResumeRun resolves a wait and requeues the run from its latest checkpoint. - rpc ResumeRun(ResumeRunRequest) returns (ResumeRunResponse) { - option (common.v1.required_scopes) = "agentruntime:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // CompleteRun marks the run successful and releases any active lease. - rpc CompleteRun(CompleteRunRequest) returns (CompleteRunResponse) { - option (common.v1.required_scopes) = "agentruntime:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // FailRun records a failed attempt. Retryable failures can move to RETRYING; - // exhausted attempts stay FAILED until they are moved to the dead letter set. - rpc FailRun(FailRunRequest) returns (FailRunResponse) { - option (common.v1.required_scopes) = "agentruntime:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // CancelRun cancels a run before it reaches a terminal success/failure. - rpc CancelRun(CancelRunRequest) returns (CancelRunResponse) { - option (common.v1.required_scopes) = "agentruntime:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // RetryRun explicitly schedules a failed run for another attempt. - rpc RetryRun(RetryRunRequest) returns (RetryRunResponse) { - option (common.v1.required_scopes) = "agentruntime:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // DeadLetterRun moves an exhausted or poison run out of normal scheduling. - rpc DeadLetterRun(DeadLetterRunRequest) returns (DeadLetterRunResponse) { - option (common.v1.required_scopes) = "agentruntime:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // GetRun retrieves an AgentRun by ID. - rpc GetRun(GetRunRequest) returns (GetRunResponse) { - option (common.v1.required_scopes) = "agentruntime:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // GetTeammateWorkLedger retrieves the durable teammate work projection for - // one run. It joins run state, waits, memory citations, connector grants, - // VFS state, proactive policy, and channel-visible status into the compact - // read model workers and operator consoles use for long-horizon handoff. - rpc GetTeammateWorkLedger(GetTeammateWorkLedgerRequest) returns (GetTeammateWorkLedgerResponse) { - option (common.v1.required_scopes) = "agentruntime:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // ListRunsByWorkEnvelope retrieves newest runs that belong to one durable - // channel work envelope, such as a Slack thread or future email/Jira/Teams object. - rpc ListRunsByWorkEnvelope(ListRunsByWorkEnvelopeRequest) returns (ListRunsByWorkEnvelopeResponse) { - option (common.v1.required_scopes) = "agentruntime:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // GetChannelThreadAdoption resolves whether a channel thread has been - // explicitly adopted by an agent and can receive no-mention continuations. - rpc GetChannelThreadAdoption(GetChannelThreadAdoptionRequest) returns (GetChannelThreadAdoptionResponse) { - option (common.v1.required_scopes) = "agentruntime:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // RecordChannelThreadAdoption durably records an adapter-observed channel - // thread adoption without requiring the adapter to create a new AgentRun. - rpc RecordChannelThreadAdoption(RecordChannelThreadAdoptionRequest) returns (RecordChannelThreadAdoptionResponse) { - option (common.v1.required_scopes) = "agentruntime:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // ListChannelThreadAdoptions returns the durable adoption projection for - // operator/debug surfaces and channel-adapter reconciliation. - rpc ListChannelThreadAdoptions(ListChannelThreadAdoptionsRequest) returns (ListChannelThreadAdoptionsResponse) { - option (common.v1.required_scopes) = "agentruntime:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // ListRunWaits returns a pending-work projection over parked AgentRun waits - // without requiring clients to replay runtime events or read full run - // snapshots. - rpc ListRunWaits(ListRunWaitsRequest) returns (ListRunWaitsResponse) { - option (common.v1.required_scopes) = "agentruntime:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // RecordChannelActionReceipt durably records an interactive channel action, - // such as a Slack approval button or slash command, before any side effects - // resume runtime work. - rpc RecordChannelActionReceipt(RecordChannelActionReceiptRequest) returns (RecordChannelActionReceiptResponse) { - option (common.v1.required_scopes) = "agentruntime:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // GetChannelActionReceipt retrieves one recorded channel action receipt. - rpc GetChannelActionReceipt(GetChannelActionReceiptRequest) returns (GetChannelActionReceiptResponse) { - option (common.v1.required_scopes) = "agentruntime:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // ListChannelActionReceipts returns durable channel action receipts for - // audit, idempotency, and channel adapter reconciliation. - rpc ListChannelActionReceipts(ListChannelActionReceiptsRequest) returns (ListChannelActionReceiptsResponse) { - option (common.v1.required_scopes) = "agentruntime:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // ListRunEvents returns the append-only event log for an AgentRun. - rpc ListRunEvents(ListRunEventsRequest) returns (ListRunEventsResponse) { - option (common.v1.required_scopes) = "agentruntime:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // ListRunVirtualFiles lists the durable read model of a run's virtual - // filesystem, including context files and agent-authored proposal files. - rpc ListRunVirtualFiles(ListRunVirtualFilesRequest) returns (ListRunVirtualFilesResponse) { - option (common.v1.required_scopes) = "agentruntime:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // ReadRunVirtualFile reads a bounded slice of one run virtual file. Workers - // should use this instead of loading every virtual file into model context. - rpc ReadRunVirtualFile(ReadRunVirtualFileRequest) returns (ReadRunVirtualFileResponse) { - option (common.v1.required_scopes) = "agentruntime:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // StatRunVirtualFile returns the typed, content-free VFS projection for one - // run virtual file by path. - rpc StatRunVirtualFile(StatRunVirtualFileRequest) returns (StatRunVirtualFileResponse) { - option (common.v1.required_scopes) = "agentruntime:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // WatchRunVirtualFiles streams a resumable VFS timeline for local agent - // development and inspectors without polling the full VFS projection. - rpc WatchRunVirtualFiles(WatchRunVirtualFilesRequest) returns (stream WatchRunVirtualFilesResponse) { - option (common.v1.required_scopes) = "agentruntime:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // BatchReadRunVirtualFiles reads multiple bounded VFS slices in one request - // while making per-file and total-budget truncation explicit. - rpc BatchReadRunVirtualFiles(BatchReadRunVirtualFilesRequest) returns (BatchReadRunVirtualFilesResponse) { - option (common.v1.required_scopes) = "agentruntime:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // BuildRunVirtualFileContextPack returns an ordered, cited set of VFS - // snippets for a task or query so workers can hydrate model context without - // hand-rolling list/search/read loops. - rpc BuildRunVirtualFileContextPack(BuildRunVirtualFileContextPackRequest) returns (BuildRunVirtualFileContextPackResponse) { - option (common.v1.required_scopes) = "agentruntime:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // SearchRunVirtualFiles performs bounded literal or regex search over text - // virtual files projected for an AgentRun. - rpc SearchRunVirtualFiles(SearchRunVirtualFilesRequest) returns (SearchRunVirtualFilesResponse) { - option (common.v1.required_scopes) = "agentruntime:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // RecordRunVirtualFileProposal writes an agent-authored file into the - // proposal/workspace side of the VFS. Source mounts such as /context remain - // read-only; promotion to real side effects happens through reviewers or - // downstream services. - rpc RecordRunVirtualFileProposal(RecordRunVirtualFileProposalRequest) returns (RecordRunVirtualFileProposalResponse) { - option (common.v1.required_scopes) = "agentruntime:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // RecordRunVirtualFileTransaction atomically stages a multi-file VFS change - // set as durable proposal artifacts with shared revision and review metadata. - rpc RecordRunVirtualFileTransaction(RecordRunVirtualFileTransactionRequest) returns (RecordRunVirtualFileTransactionResponse) { - option (common.v1.required_scopes) = "agentruntime:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // PromoteRunVirtualFileTransaction records a reviewed transaction as the - // accepted workspace view. Promotion is idempotent by transaction and keeps - // proposal artifacts intact for audit. - rpc PromoteRunVirtualFileTransaction(PromoteRunVirtualFileTransactionRequest) returns (PromoteRunVirtualFileTransactionResponse) { - option (common.v1.required_scopes) = "agentruntime:write"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // DiffRunVirtualFileTransaction previews a staged VFS transaction as - // per-file stats, hunks, conflicts, and unified diff text. - rpc DiffRunVirtualFileTransaction(DiffRunVirtualFileTransactionRequest) returns (DiffRunVirtualFileTransactionResponse) { - option (common.v1.required_scopes) = "agentruntime:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // ApplyRunVirtualFileTransaction applies a transaction when the diff is - // clean, and otherwise returns structured conflicts without mutating state. - rpc ApplyRunVirtualFileTransaction(ApplyRunVirtualFileTransactionRequest) returns (ApplyRunVirtualFileTransactionResponse) { - option (common.v1.required_scopes) = "agentruntime:write"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // RebaseRunVirtualFileTransaction restages a clean transaction on top of the - // latest accepted VFS revisions while preserving proposed content metadata. - rpc RebaseRunVirtualFileTransaction(RebaseRunVirtualFileTransactionRequest) returns (RebaseRunVirtualFileTransactionResponse) { - option (common.v1.required_scopes) = "agentruntime:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // HydrateRunVirtualFileMount resolves a lazy connector mount into bounded - // run-scoped VFS files without exposing credentials to the worker. - rpc HydrateRunVirtualFileMount(HydrateRunVirtualFileMountRequest) returns (HydrateRunVirtualFileMountResponse) { - option (common.v1.required_scopes) = "agentruntime:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // InspectRunVirtualFiles returns a debug projection over mounts, - // transactions, content addresses, and Cerebro indexing readiness. - rpc InspectRunVirtualFiles(InspectRunVirtualFilesRequest) returns (InspectRunVirtualFilesResponse) { - option (common.v1.required_scopes) = "agentruntime:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } -} - -// AgentRunState describes the runtime lifecycle of one durable attempt. -enum AgentRunState { - AGENT_RUN_STATE_UNSPECIFIED = 0; - AGENT_RUN_STATE_ACCEPTED = 1; - AGENT_RUN_STATE_QUEUED = 2; - AGENT_RUN_STATE_RUNNING = 3; - AGENT_RUN_STATE_WAITING = 4; - AGENT_RUN_STATE_SUCCEEDED = 5; - AGENT_RUN_STATE_FAILED = 6; - AGENT_RUN_STATE_CANCELLED = 7; - AGENT_RUN_STATE_RETRYING = 8; - AGENT_RUN_STATE_DEAD_LETTERED = 9; -} - -// AgentRunStepState describes progress for a single durable step record. -enum AgentRunStepState { - AGENT_RUN_STEP_STATE_UNSPECIFIED = 0; - AGENT_RUN_STEP_STATE_PENDING = 1; - AGENT_RUN_STEP_STATE_RUNNING = 2; - AGENT_RUN_STEP_STATE_WAITING = 3; - AGENT_RUN_STEP_STATE_SUCCEEDED = 4; - AGENT_RUN_STEP_STATE_FAILED = 5; - AGENT_RUN_STEP_STATE_CANCELLED = 6; - AGENT_RUN_STEP_STATE_SKIPPED = 7; -} - -// AgentRunStepKind classifies the durable work represented by a run step. -enum AgentRunStepKind { - AGENT_RUN_STEP_KIND_UNSPECIFIED = 0; - AGENT_RUN_STEP_KIND_MODEL_CALL = 1; - AGENT_RUN_STEP_KIND_TOOL_CALL_INTENT = 2; - AGENT_RUN_STEP_KIND_TOOL_RESULT = 3; - AGENT_RUN_STEP_KIND_APPROVAL_WAIT = 4; - AGENT_RUN_STEP_KIND_ERROR = 5; - AGENT_RUN_STEP_KIND_SYSTEM = 6; - AGENT_RUN_STEP_KIND_CONTEXT_ENRICHMENT = 7; - AGENT_RUN_STEP_KIND_PLAN = 8; - AGENT_RUN_STEP_KIND_PATCH = 9; - AGENT_RUN_STEP_KIND_TEST = 10; - AGENT_RUN_STEP_KIND_PULL_REQUEST_SYNC = 11; - AGENT_RUN_STEP_KIND_REVIEW_SYNC = 12; -} - -// AgentRunWaitType describes why a run released its worker lease. -enum AgentRunWaitType { - AGENT_RUN_WAIT_TYPE_UNSPECIFIED = 0; - AGENT_RUN_WAIT_TYPE_APPROVAL = 1; - AGENT_RUN_WAIT_TYPE_INPUT = 2; - AGENT_RUN_WAIT_TYPE_EVENT = 3; - AGENT_RUN_WAIT_TYPE_TIMER = 4; -} - -// AgentRunWaitState describes the read-model state of a parked wait. -enum AgentRunWaitState { - AGENT_RUN_WAIT_STATE_UNSPECIFIED = 0; - AGENT_RUN_WAIT_STATE_PENDING = 1; - AGENT_RUN_WAIT_STATE_RESOLVED = 2; - AGENT_RUN_WAIT_STATE_EXPIRED = 3; - AGENT_RUN_WAIT_STATE_CANCELLED = 4; -} - -// AgentRunArtifactKind classifies durable output produced by a run or step. -enum AgentRunArtifactKind { - AGENT_RUN_ARTIFACT_KIND_UNSPECIFIED = 0; - AGENT_RUN_ARTIFACT_KIND_TOOL_RESULT = 1; - AGENT_RUN_ARTIFACT_KIND_CHART = 2; - AGENT_RUN_ARTIFACT_KIND_REPORT = 3; - AGENT_RUN_ARTIFACT_KIND_FILE = 4; - AGENT_RUN_ARTIFACT_KIND_TRANSCRIPT = 5; - AGENT_RUN_ARTIFACT_KIND_APPROVAL_PLAN = 6; - AGENT_RUN_ARTIFACT_KIND_SYSTEM = 7; - AGENT_RUN_ARTIFACT_KIND_PATCH = 8; - AGENT_RUN_ARTIFACT_KIND_PULL_REQUEST = 9; - AGENT_RUN_ARTIFACT_KIND_PULL_REQUEST_COMMENT = 10; - AGENT_RUN_ARTIFACT_KIND_CI_STATUS = 11; - AGENT_RUN_ARTIFACT_KIND_RUN_PANEL = 12; - AGENT_RUN_ARTIFACT_KIND_EVALUATION_EXAMPLE = 13; -} - -// RuntimeEventType classifies append-only AgentRun events. -enum RuntimeEventType { - RUNTIME_EVENT_TYPE_UNSPECIFIED = 0; - RUNTIME_EVENT_TYPE_TRIGGER_ACCEPTED = 1; - RUNTIME_EVENT_TYPE_AGENT_CONFIG_RESOLVED = 2; - RUNTIME_EVENT_TYPE_OBJECTIVE_RESOLVED = 3; - RUNTIME_EVENT_TYPE_CONTEXT_BUILT = 4; - RUNTIME_EVENT_TYPE_WORKER_DISPATCHED = 5; - RUNTIME_EVENT_TYPE_RUN_FAILED = 6; - RUNTIME_EVENT_TYPE_RUN_QUEUED = 7; - RUNTIME_EVENT_TYPE_RUN_CLAIMED = 8; - RUNTIME_EVENT_TYPE_LEASE_HEARTBEAT = 9; - RUNTIME_EVENT_TYPE_STEP_RECORDED = 10; - RUNTIME_EVENT_TYPE_CHECKPOINT_RECORDED = 11; - RUNTIME_EVENT_TYPE_ARTIFACT_RECORDED = 12; - RUNTIME_EVENT_TYPE_COST_RECORDED = 13; - RUNTIME_EVENT_TYPE_RUN_WAITING = 14; - RUNTIME_EVENT_TYPE_RUN_RESUMED = 15; - RUNTIME_EVENT_TYPE_RUN_SUCCEEDED = 16; - RUNTIME_EVENT_TYPE_RUN_CANCELLED = 17; - RUNTIME_EVENT_TYPE_RUN_RETRY_SCHEDULED = 18; - RUNTIME_EVENT_TYPE_RUN_DEAD_LETTERED = 19; - RUNTIME_EVENT_TYPE_STREAM_CURSOR_RECORDED = 20; - RUNTIME_EVENT_TYPE_CODEX_INTERACTION_REQUESTED = 21; - RUNTIME_EVENT_TYPE_CODEX_INTERACTION_RESOLVED = 22; - RUNTIME_EVENT_TYPE_CODEX_PROGRESS_RECORDED = 23; - RUNTIME_EVENT_TYPE_CODEX_OUTPUT_SYNCED = 24; - RUNTIME_EVENT_TYPE_CODEX_OUTCOME_OBSERVED = 25; - RUNTIME_EVENT_TYPE_CHANNEL_MESSAGE_RECORDED = 26; - RUNTIME_EVENT_TYPE_MODEL_RESPONSE_RECORDED = 27; - RUNTIME_EVENT_TYPE_TOOL_CALL_RECORDED = 28; - RUNTIME_EVENT_TYPE_TOOL_RESULT_RECORDED = 29; - RUNTIME_EVENT_TYPE_APPROVAL_REQUESTED = 30; - RUNTIME_EVENT_TYPE_APPROVAL_RESOLVED = 31; - RUNTIME_EVENT_TYPE_AGENT_PROGRESS_RECORDED = 32; - RUNTIME_EVENT_TYPE_RUN_CONTROL_RECORDED = 33; - RUNTIME_EVENT_TYPE_WORK_ITEM_RECORDED = 34; - RUNTIME_EVENT_TYPE_WORK_ITEM_UPDATED = 35; - RUNTIME_EVENT_TYPE_PROCESSING_PRESENCE_RECORDED = 36; - RUNTIME_EVENT_TYPE_AUTONOMY_SESSION_RECORDED = 37; - RUNTIME_EVENT_TYPE_RUN_YIELDED = 38; -} - -// RuntimeEvidenceState records whether Platform merely observed a native event -// or has joined it to a resolver/proof source. -enum RuntimeEvidenceState { - RUNTIME_EVIDENCE_STATE_UNSPECIFIED = 0; - RUNTIME_EVIDENCE_STATE_NATIVE_OBSERVED = 1; - RUNTIME_EVIDENCE_STATE_PLATFORM_PROVEN = 2; - RUNTIME_EVIDENCE_STATE_MISSING = 3; - RUNTIME_EVIDENCE_STATE_UNVERIFIED = 4; -} - -// NativeAgentEventSource identifies the native Agent Workforce emitter that -// produced an observed event. Platform does not infer authority from this -// source; proof states below remain missing/unverified until joined to a -// Platform resolver, credential, or meter authority. -enum NativeAgentEventSource { - NATIVE_AGENT_EVENT_SOURCE_UNSPECIFIED = 0; - NATIVE_AGENT_EVENT_SOURCE_MAESTRO = 1; - NATIVE_AGENT_EVENT_SOURCE_CODEX = 2; - // NATIVE_AGENT_EVENT_SOURCE_CLAUDE_CODE and - // NATIVE_AGENT_EVENT_SOURCE_OTHER mirror sessions.v1.AgentKind so a native - // event observed from Claude Code, or from an emitter that is none of the - // above, carries an honest source instead of being misattributed to - // Maestro or Codex. Proof states remain missing/unverified for these - // sources the same as for the existing ones until joined to a Platform - // resolver, credential, or meter authority. - NATIVE_AGENT_EVENT_SOURCE_CLAUDE_CODE = 3; - NATIVE_AGENT_EVENT_SOURCE_OTHER = 4; -} - -// RuntimeEvidenceGapReason identifies the missing proof that prevents a -// runtime action from being considered approval-ready. -enum RuntimeEvidenceGapReason { - RUNTIME_EVIDENCE_GAP_REASON_UNSPECIFIED = 0; - RUNTIME_EVIDENCE_GAP_REASON_CREDENTIAL_UNVERIFIED = 1; - RUNTIME_EVIDENCE_GAP_REASON_PRINCIPAL_UNRESOLVED = 2; - RUNTIME_EVIDENCE_GAP_REASON_COST_UNRECORDED = 3; -} - -// RunControlMode describes durable input applied to an autonomous run/session. -// Steering and followups are optional controls; they are not the worker loop. -enum RunControlMode { - RUN_CONTROL_MODE_UNSPECIFIED = 0; - RUN_CONTROL_MODE_STEER = 1; - RUN_CONTROL_MODE_FOLLOWUP = 2; - RUN_CONTROL_MODE_COLLECT = 3; - RUN_CONTROL_MODE_INTERRUPT = 4; - RUN_CONTROL_MODE_CANCEL = 5; - RUN_CONTROL_MODE_SYSTEM_WAKE = 6; -} - -// AutonomyProcessingState is the channel-safe processing presence for a -// long-lived autonomous teammate. Adapters update the same visible Slack -// message from this state instead of posting one reply per runtime turn. -enum AutonomyProcessingState { - AUTONOMY_PROCESSING_STATE_UNSPECIFIED = 0; - AUTONOMY_PROCESSING_STATE_QUEUED = 1; - AUTONOMY_PROCESSING_STATE_ORIENTING = 2; - AUTONOMY_PROCESSING_STATE_THINKING = 3; - AUTONOMY_PROCESSING_STATE_USING_TOOL = 4; - AUTONOMY_PROCESSING_STATE_SPAWNING_CHILDREN = 5; - AUTONOMY_PROCESSING_STATE_WAITING_ON_APPROVAL = 6; - AUTONOMY_PROCESSING_STATE_WAITING_ON_EVENT = 7; - AUTONOMY_PROCESSING_STATE_SYNTHESIZING = 8; - AUTONOMY_PROCESSING_STATE_COMPLETING = 9; - AUTONOMY_PROCESSING_STATE_IDLE = 10; - AUTONOMY_PROCESSING_STATE_FAILED = 11; -} - -// AgentWorkItemKind classifies nodes in the autonomous work graph. -enum AgentWorkItemKind { - AGENT_WORK_ITEM_KIND_UNSPECIFIED = 0; - AGENT_WORK_ITEM_KIND_ROOT = 1; - AGENT_WORK_ITEM_KIND_MODEL_CALL = 2; - AGENT_WORK_ITEM_KIND_TOOL_CALL = 3; - AGENT_WORK_ITEM_KIND_CHILD_RUN = 4; - AGENT_WORK_ITEM_KIND_WAIT = 5; - AGENT_WORK_ITEM_KIND_MEMORY = 6; - AGENT_WORK_ITEM_KIND_USER_INPUT = 7; - AGENT_WORK_ITEM_KIND_FOLLOWUP = 8; - AGENT_WORK_ITEM_KIND_RECOVERY = 9; -} - -// AgentWorkItemState describes durable progress for a work graph node. -enum AgentWorkItemState { - AGENT_WORK_ITEM_STATE_UNSPECIFIED = 0; - AGENT_WORK_ITEM_STATE_PENDING = 1; - AGENT_WORK_ITEM_STATE_RUNNING = 2; - AGENT_WORK_ITEM_STATE_WAITING = 3; - AGENT_WORK_ITEM_STATE_BLOCKED = 4; - AGENT_WORK_ITEM_STATE_SUCCEEDED = 5; - AGENT_WORK_ITEM_STATE_FAILED = 6; - AGENT_WORK_ITEM_STATE_CANCELLED = 7; -} - -// AutonomySessionState is the coarse lifecycle for the long-lived teammate -// session attached to a work envelope. -enum AutonomySessionState { - AUTONOMY_SESSION_STATE_UNSPECIFIED = 0; - AUTONOMY_SESSION_STATE_ACTIVE = 1; - AUTONOMY_SESSION_STATE_IDLE = 2; - AUTONOMY_SESSION_STATE_WAITING = 3; - AUTONOMY_SESSION_STATE_FAILED = 4; - AUTONOMY_SESSION_STATE_CANCELLED = 5; -} - -// YieldContinuation describes how Platform should continue an autonomous -// session after the current run releases its lease. -enum YieldContinuation { - YIELD_CONTINUATION_UNSPECIFIED = 0; - YIELD_CONTINUATION_INLINE_NEXT_STEP = 1; - YIELD_CONTINUATION_SCHEDULED = 2; - YIELD_CONTINUATION_WAIT = 3; - YIELD_CONTINUATION_END_SESSION = 4; -} - -// RuntimeDependencyStatus describes the readiness of a platform boundary that -// contributed context to an AgentRun. -enum RuntimeDependencyStatus { - RUNTIME_DEPENDENCY_STATUS_UNSPECIFIED = 0; - RUNTIME_DEPENDENCY_STATUS_RESOLVED = 1; - RUNTIME_DEPENDENCY_STATUS_NOT_FOUND = 2; - RUNTIME_DEPENDENCY_STATUS_NOT_CONFIGURED = 3; - RUNTIME_DEPENDENCY_STATUS_LOADED = 4; -} - -// RuntimeWorkEnvelopeKind classifies the durable human/work object a trigger -// belongs to. Envelopes group retries and follow-up messages across channels -// without making the runtime depend on Slack-specific string labels. -enum RuntimeWorkEnvelopeKind { - RUNTIME_WORK_ENVELOPE_KIND_UNSPECIFIED = 0; - RUNTIME_WORK_ENVELOPE_KIND_CONVERSATION_THREAD = 1; - RUNTIME_WORK_ENVELOPE_KIND_DIRECT_CONVERSATION = 2; - RUNTIME_WORK_ENVELOPE_KIND_TICKET = 3; - RUNTIME_WORK_ENVELOPE_KIND_CALENDAR_EVENT = 4; - RUNTIME_WORK_ENVELOPE_KIND_PULL_REQUEST = 5; - RUNTIME_WORK_ENVELOPE_KIND_INCIDENT = 6; - RUNTIME_WORK_ENVELOPE_KIND_REPOSITORY = 7; - RUNTIME_WORK_ENVELOPE_KIND_DOCUMENT = 8; - RUNTIME_WORK_ENVELOPE_KIND_RECORD = 9; -} - -// SurfaceTargetKind classifies the provider object that owns interaction -// context. It is deliberately independent of conversation channel shape. -enum SurfaceTargetKind { - SURFACE_TARGET_KIND_UNSPECIFIED = 0; - SURFACE_TARGET_KIND_CONVERSATION = 1; - SURFACE_TARGET_KIND_TICKET = 2; - SURFACE_TARGET_KIND_PULL_REQUEST = 3; - SURFACE_TARGET_KIND_INCIDENT = 4; - SURFACE_TARGET_KIND_REPOSITORY = 5; - SURFACE_TARGET_KIND_DOCUMENT = 6; - SURFACE_TARGET_KIND_RECORD = 7; -} - -// RuntimeChannelKind classifies the inbound or outbound channel adapter that -// owns the human conversation surface for a run. -enum RuntimeChannelKind { - RUNTIME_CHANNEL_KIND_UNSPECIFIED = 0; - RUNTIME_CHANNEL_KIND_SLACK = 1; - RUNTIME_CHANNEL_KIND_WEB = 2; - RUNTIME_CHANNEL_KIND_API = 3; - RUNTIME_CHANNEL_KIND_EMAIL = 4; - RUNTIME_CHANNEL_KIND_GITHUB = 5; - RUNTIME_CHANNEL_KIND_LINEAR = 6; - RUNTIME_CHANNEL_KIND_JIRA = 7; - RUNTIME_CHANNEL_KIND_IDE = 8; - RUNTIME_CHANNEL_KIND_MONITORING = 9; - RUNTIME_CHANNEL_KIND_BROWSER_EXTENSION = 10; - RUNTIME_CHANNEL_KIND_DESKTOP_HELPER = 11; - RUNTIME_CHANNEL_KIND_CALENDAR = 12; - RUNTIME_CHANNEL_KIND_TEAMS = 13; - RUNTIME_CHANNEL_KIND_WHATSAPP = 14; - RUNTIME_CHANNEL_KIND_APPLE_MESSAGES = 15; -} - -// RuntimeTriggerKind classifies the normalized source event that started or -// resumed a run. The legacy string source_event_type remains for compatibility -// with early producers and arbitrary integration event names. -enum RuntimeTriggerKind { - RUNTIME_TRIGGER_KIND_UNSPECIFIED = 0; - RUNTIME_TRIGGER_KIND_SLACK_APP_MENTION = 1; - RUNTIME_TRIGGER_KIND_SLACK_DIRECT_MESSAGE = 2; - RUNTIME_TRIGGER_KIND_SLACK_SLASH_COMMAND = 3; - RUNTIME_TRIGGER_KIND_SLACK_ACTION = 4; - RUNTIME_TRIGGER_KIND_SLACK_THREAD_CONTINUATION = 5; - RUNTIME_TRIGGER_KIND_SLACK_EVENT = 6; - RUNTIME_TRIGGER_KIND_ENSEMBLE_WEB_MESSAGE = 7; - RUNTIME_TRIGGER_KIND_ENSEMBLE_WEBHOOK_EVENT = 8; - RUNTIME_TRIGGER_KIND_SCHEDULE = 9; - RUNTIME_TRIGGER_KIND_EMAIL = 10; - RUNTIME_TRIGGER_KIND_API = 11; - RUNTIME_TRIGGER_KIND_WEB = 12; - RUNTIME_TRIGGER_KIND_GITHUB_ISSUE_COMMENT = 13; - RUNTIME_TRIGGER_KIND_GITHUB_PULL_REQUEST_COMMENT = 14; - RUNTIME_TRIGGER_KIND_LINEAR_ACTION = 15; - RUNTIME_TRIGGER_KIND_IDE_COMMAND = 16; - RUNTIME_TRIGGER_KIND_MONITORING_ALERT = 17; - RUNTIME_TRIGGER_KIND_PROACTIVE_PATTERN = 18; - RUNTIME_TRIGGER_KIND_SLACK_ASSISTANT_THREAD_STARTED = 19; - RUNTIME_TRIGGER_KIND_SLACK_ASSISTANT_THREAD_CONTEXT_CHANGED = 20; - RUNTIME_TRIGGER_KIND_CALENDAR_EVENT_CREATED = 21; - RUNTIME_TRIGGER_KIND_CALENDAR_EVENT_UPDATED = 22; - RUNTIME_TRIGGER_KIND_CALENDAR_EVENT_CANCELLED = 23; - RUNTIME_TRIGGER_KIND_TEAMS_MESSAGE = 24; - RUNTIME_TRIGGER_KIND_TEAMS_CHANNEL_MENTION = 25; - RUNTIME_TRIGGER_KIND_WHATSAPP_DIRECT_MESSAGE = 26; - RUNTIME_TRIGGER_KIND_WHATSAPP_GROUP_MESSAGE = 27; - RUNTIME_TRIGGER_KIND_WHATSAPP_BUTTON_REPLY = 28; -} - -// RuntimeVisibilityLevel declares whether runtime state can be projected to -// humans or should remain internal/audit-only. Unspecified values are treated -// conservatively as agent-only by service helpers and consumers. -enum RuntimeVisibilityLevel { - RUNTIME_VISIBILITY_LEVEL_UNSPECIFIED = 0; - RUNTIME_VISIBILITY_LEVEL_AGENT_ONLY = 1; - RUNTIME_VISIBILITY_LEVEL_USER_VISIBLE = 2; - RUNTIME_VISIBILITY_LEVEL_CHANNEL_VISIBLE = 3; - RUNTIME_VISIBILITY_LEVEL_ADMIN_VISIBLE = 4; - RUNTIME_VISIBILITY_LEVEL_AUDIT_ONLY = 5; -} - -// RuntimeAudience identifies the audience allowed to see a runtime event or -// wait projection. Audience is separate from visibility so clients can render a -// channel-safe summary while keeping admin/audit detail available elsewhere. -enum RuntimeAudience { - RUNTIME_AUDIENCE_UNSPECIFIED = 0; - RUNTIME_AUDIENCE_AGENT = 1; - RUNTIME_AUDIENCE_TRIGGER_ACTOR = 2; - RUNTIME_AUDIENCE_CHANNEL = 3; - RUNTIME_AUDIENCE_WORKSPACE_ADMINS = 4; - RUNTIME_AUDIENCE_AUDIT = 5; - RUNTIME_AUDIENCE_SYSTEM = 6; -} - -// ChannelActionKind classifies the user or integration action submitted from a -// durable channel surface. -enum ChannelActionKind { - CHANNEL_ACTION_KIND_UNSPECIFIED = 0; - CHANNEL_ACTION_KIND_APPROVAL_DECISION = 1; - CHANNEL_ACTION_KIND_WAIT_RESUME = 2; - CHANNEL_ACTION_KIND_OBJECTIVE_CONTROL = 3; - CHANNEL_ACTION_KIND_MEMORY_DECISION = 4; - CHANNEL_ACTION_KIND_OPS_COMMAND = 5; - CHANNEL_ACTION_KIND_GENERIC = 6; - CHANNEL_ACTION_KIND_CODEX_INTERACTION = 7; - CHANNEL_ACTION_KIND_BROWSER_CONTROL = 8; - CHANNEL_ACTION_KIND_DESKTOP_CONTROL = 9; -} - -// ChannelActionTargetKind identifies the platform object controlled by a -// channel action. -enum ChannelActionTargetKind { - CHANNEL_ACTION_TARGET_KIND_UNSPECIFIED = 0; - CHANNEL_ACTION_TARGET_KIND_RUN = 1; - CHANNEL_ACTION_TARGET_KIND_WAIT = 2; - CHANNEL_ACTION_TARGET_KIND_APPROVAL = 3; - CHANNEL_ACTION_TARGET_KIND_OBJECTIVE = 4; - CHANNEL_ACTION_TARGET_KIND_ARTIFACT = 5; - CHANNEL_ACTION_TARGET_KIND_MEMORY_CANDIDATE = 6; - CHANNEL_ACTION_TARGET_KIND_TOOL_EXECUTION = 7; - CHANNEL_ACTION_TARGET_KIND_CODEX_SESSION = 8; - CHANNEL_ACTION_TARGET_KIND_PATCH = 9; - CHANNEL_ACTION_TARGET_KIND_PULL_REQUEST = 10; - CHANNEL_ACTION_TARGET_KIND_BROWSER_SESSION = 11; - CHANNEL_ACTION_TARGET_KIND_BROWSER_TAB = 12; - CHANNEL_ACTION_TARGET_KIND_BROWSER_NATIVE_HOST = 13; - CHANNEL_ACTION_TARGET_KIND_DESKTOP_SESSION = 14; -} - -// ChannelActionAuthorizationOutcome records the actor-resolution and policy -// decision for a channel action. -enum ChannelActionAuthorizationOutcome { - CHANNEL_ACTION_AUTHORIZATION_OUTCOME_UNSPECIFIED = 0; - CHANNEL_ACTION_AUTHORIZATION_OUTCOME_ALLOWED = 1; - CHANNEL_ACTION_AUTHORIZATION_OUTCOME_DENIED = 2; - CHANNEL_ACTION_AUTHORIZATION_OUTCOME_UNMAPPED_ACTOR = 3; - CHANNEL_ACTION_AUTHORIZATION_OUTCOME_WRONG_APPROVER = 4; - CHANNEL_ACTION_AUTHORIZATION_OUTCOME_EXPIRED = 5; - CHANNEL_ACTION_AUTHORIZATION_OUTCOME_STALE = 6; -} - -// ChannelActionExecutionOutcome records the durable side-effect result for a -// channel action. -enum ChannelActionExecutionOutcome { - CHANNEL_ACTION_EXECUTION_OUTCOME_UNSPECIFIED = 0; - CHANNEL_ACTION_EXECUTION_OUTCOME_PENDING = 1; - CHANNEL_ACTION_EXECUTION_OUTCOME_SUCCEEDED = 2; - CHANNEL_ACTION_EXECUTION_OUTCOME_FAILED = 3; - CHANNEL_ACTION_EXECUTION_OUTCOME_DUPLICATE = 4; - CHANNEL_ACTION_EXECUTION_OUTCOME_TARGET_NOT_FOUND = 5; - CHANNEL_ACTION_EXECUTION_OUTCOME_ALREADY_RESOLVED = 6; - CHANNEL_ACTION_EXECUTION_OUTCOME_UNAUTHORIZED = 7; - CHANNEL_ACTION_EXECUTION_OUTCOME_EXPIRED = 8; - CHANNEL_ACTION_EXECUTION_OUTCOME_STALE = 9; -} - -// ChannelActionDeliveryOutcome records whether the channel message/update was -// reconciled after handling an action. -enum ChannelActionDeliveryOutcome { - CHANNEL_ACTION_DELIVERY_OUTCOME_UNSPECIFIED = 0; - CHANNEL_ACTION_DELIVERY_OUTCOME_NOT_ATTEMPTED = 1; - CHANNEL_ACTION_DELIVERY_OUTCOME_UPDATED = 2; - CHANNEL_ACTION_DELIVERY_OUTCOME_FAILED = 3; - CHANNEL_ACTION_DELIVERY_OUTCOME_SKIPPED = 4; -} - -// RuntimeSensitivity classifies how carefully runtime payloads must be handled -// before projection outside Platform. -enum RuntimeSensitivity { - RUNTIME_SENSITIVITY_UNSPECIFIED = 0; - RUNTIME_SENSITIVITY_PUBLIC = 1; - RUNTIME_SENSITIVITY_INTERNAL = 2; - RUNTIME_SENSITIVITY_CONFIDENTIAL = 3; - RUNTIME_SENSITIVITY_RESTRICTED = 4; -} - -// RuntimeRedactionKind identifies data categories that were removed or must be -// removed before channel/user rendering. -enum RuntimeRedactionKind { - RUNTIME_REDACTION_KIND_UNSPECIFIED = 0; - RUNTIME_REDACTION_KIND_PII = 1; - RUNTIME_REDACTION_KIND_CREDENTIAL = 2; - RUNTIME_REDACTION_KIND_TOOL_ARGS = 3; - RUNTIME_REDACTION_KIND_POLICY_DETAIL = 4; - RUNTIME_REDACTION_KIND_INTERNAL_CONTEXT = 5; -} - -// RuntimeVirtualFileRedactionState mirrors the workspace VFS byte plane's -// redaction contract so Runtime VFS callers can discover whether content is -// safe to read, preview-only, already redacted, or denied. -enum RuntimeVirtualFileRedactionState { - RUNTIME_VIRTUAL_FILE_REDACTION_STATE_UNSPECIFIED = 0; - RUNTIME_VIRTUAL_FILE_REDACTION_STATE_RAW = 1; - RUNTIME_VIRTUAL_FILE_REDACTION_STATE_REDACTED = 2; - RUNTIME_VIRTUAL_FILE_REDACTION_STATE_PREVIEW_ONLY = 3; - RUNTIME_VIRTUAL_FILE_REDACTION_STATE_DENIED = 4; -} - -// RuntimeWebConversationCoordinates identifies a Platform-owned web thread. -message RuntimeWebConversationCoordinates { - string conversation_id = 1 [(buf.validate.field).string.min_len = 1]; - string message_id = 2; -} - -// RuntimeSlackThreadCoordinates identifies one Slack conversation thread. -message RuntimeSlackThreadCoordinates { - string provider_workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string channel_id = 2 [(buf.validate.field).string.min_len = 1]; - string thread_id = 3 [(buf.validate.field).string.min_len = 1]; - string message_id = 4; -} - -// RuntimeEmailThreadCoordinates identifies one provider mailbox thread. -message RuntimeEmailThreadCoordinates { - string connection_id = 1 [(buf.validate.field).string.min_len = 1]; - string mailbox_id = 2 [(buf.validate.field).string.min_len = 1]; - string thread_id = 3 [(buf.validate.field).string.min_len = 1]; - string message_id = 4; - string provider_revision = 5; -} - -// RuntimeCalendarEventCoordinates identifies one event or recurring instance. -message RuntimeCalendarEventCoordinates { - string connection_id = 1 [(buf.validate.field).string.min_len = 1]; - string calendar_id = 2 [(buf.validate.field).string.min_len = 1]; - string event_id = 3 [(buf.validate.field).string.min_len = 1]; - string recurring_series_id = 4; - string recurring_instance_id = 5; - string provider_revision = 6; -} - -// RuntimeTeamsThreadCoordinates identifies one Microsoft Teams chat or channel -// thread. tenant_id is the Microsoft tenant, conversation_id is the channel or -// chat, and thread_id is the reply-chain root (the message itself when there is -// no thread). -message RuntimeTeamsThreadCoordinates { - string tenant_id = 1 [(buf.validate.field).string.min_len = 1]; - string conversation_id = 2 [(buf.validate.field).string.min_len = 1]; - string thread_id = 3 [(buf.validate.field).string.min_len = 1]; - string message_id = 4; -} - -// RuntimeWhatsAppConversationCoordinates identifies one WhatsApp Business -// conversation. chat_id is the peer wa_id for a 1:1 chat or the group id. -message RuntimeWhatsAppConversationCoordinates { - string waba_id = 1 [(buf.validate.field).string.min_len = 1]; - string phone_number_id = 2 [(buf.validate.field).string.min_len = 1]; - string chat_id = 3 [(buf.validate.field).string.min_len = 1]; - string message_id = 4; -} - -// RuntimeChannelContext carries stable channel coordinates for channel -// adapters. Slack teammates use provider_workspace_id for team_id, channel_id -// for the conversation, thread_id for the Slack thread_ts, and message_id for -// the triggering message/event timestamp. -message RuntimeChannelContext { - RuntimeChannelKind channel_kind = 1 [(buf.validate.field).enum.defined_only = true]; - string provider_workspace_id = 2; - string channel_id = 3; - string thread_id = 4; - string message_id = 5; - // Deprecated overloaded actor field. New Slack and channel adapters should - // set actor_channel_id for the provider-local respondent, actor_entity_id for - // the resolved canonical entity, and principal_id for the authenticated - // platform principal when available. - string actor_id = 6; - string permalink = 7; - map attributes = 8; - string actor_channel_id = 9; - string actor_entity_id = 10; - string principal_id = 11; - // coordinates is the canonical provider-specific identity for new channel - // adapters. Flat fields 2 through 5 remain for wire-compatible migration. - oneof coordinates { - RuntimeWebConversationCoordinates web = 12; - RuntimeSlackThreadCoordinates slack = 13; - RuntimeEmailThreadCoordinates email = 14; - RuntimeCalendarEventCoordinates calendar = 15; - RuntimeTeamsThreadCoordinates teams = 16; - RuntimeWhatsAppConversationCoordinates whatsapp = 17; - } -} - -// RuntimeWorkEnvelope identifies the durable work object that groups related -// normalized triggers. For Slack this is usually a conversation thread; future -// adapters can map email threads, Jira tickets, calendar events, and Teams -// threads into the same runtime primitive. -message RuntimeWorkEnvelope { - string id = 1 [(buf.validate.field).string.min_len = 1]; - RuntimeWorkEnvelopeKind kind = 2 [(buf.validate.field).enum.defined_only = true]; - string root_id = 3; - string parent_id = 4; - map attributes = 5; -} - -// RuntimeProactiveSourceEvent identifies the upstream event that caused a -// proactive trigger candidate without copying the full source payload into the -// runtime record. -message RuntimeProactiveSourceEvent { - string stream = 1; - string subject = 2; - uint64 sequence = 3; - string event_id = 4; - string event_family = 5; - string event_type = 6; - string provider_object_id = 7; - string provider_id = 8; - string connection_id = 9; - string provider_revision = 10; -} - -// RuntimeProactivePolicy carries teammate/channel wake controls in the same -// trigger contract that AgentRuntime admission evaluates. -message RuntimeProactivePolicy { - optional bool wake_enabled = 1; - repeated string trigger_kinds = 2; - bool allow_customer_facing = 3; - bool post_run_started = 4; -} - -// RuntimeSourceHealthSummary is the compact source-health projection used by -// proactive runtime context. Cerebro remains the source of truth for detailed -// health records. -message RuntimeSourceHealthSummary { - string status = 1; - repeated string checked_sources = 2; - repeated string stale_sources = 3; - string summary = 4; -} - -// RuntimeCerebroFactsContext carries the identifiers and retrieval counts that -// let AgentRuntime, Ensemble, and operators trace a proactive run back to -// Cerebro without parsing payload maps. -message RuntimeCerebroFactsContext { - string provider = 1; - string workspace_id = 2; - string query = 3; - repeated string thing_ids = 4; - repeated string fact_ids = 5; - repeated string event_ids = 6; - RuntimeSourceHealthSummary source_health_summary = 7; - string belief_debug_summary = 8; - string rollout_id = 9; - string rollout_summary = 10; - string rollout_result = 11; - map retrieval_counts = 12 [(buf.validate.field).map.values.int64.gte = 0]; -} - -// RuntimeProactiveContext is the first-class proactive trigger envelope. It -// keeps event identity, policy hints, risk hints, and Cerebro context out of -// ad hoc trigger payload conventions. -message RuntimeProactiveContext { - bool proactive_runtime = 1; - string proactive_ingest = 2; - RuntimeProactiveSourceEvent source_event = 3; - repeated string thing_ids = 4; - string action_class = 5; - string risk_level = 6; - bool external_side_effect = 7; - RuntimeCerebroFactsContext facts_context = 8; - RuntimeProactivePolicy policy = 9; -} - -// RuntimeRedaction records one projected field or payload category that has -// been redacted for channel/user display. -message RuntimeRedaction { - RuntimeRedactionKind kind = 1 [(buf.validate.field).enum.defined_only = true]; - string field_path = 2; - string replacement = 3; - string reason = 4; -} - -// RuntimeVisibilityMetadata carries the projection policy for runtime events -// and waits. Safe summaries are required when visibility is user/channel -// visible so clients never need to render raw internal payloads. -message RuntimeVisibilityMetadata { - RuntimeVisibilityLevel level = 1 [(buf.validate.field).enum.defined_only = true]; - repeated RuntimeAudience audiences = 2 [(buf.validate.field).repeated.items.enum.defined_only = true]; - RuntimeSensitivity sensitivity = 3 [(buf.validate.field).enum.defined_only = true]; - string safe_summary = 4; - repeated RuntimeRedaction redactions = 5; - map attributes = 6; -} - -// ChannelActionActor captures the channel coordinates and resolved platform -// identity for the actor who submitted an action. -message ChannelActionActor { - RuntimeChannelKind channel_kind = 1 [(buf.validate.field).enum.defined_only = true]; - string provider_workspace_id = 2; - string channel_id = 3; - string thread_id = 4; - string message_id = 5; - string action_id = 6; - string callback_id = 7; - string actor_channel_id = 8; - string actor_entity_id = 9; - string principal_id = 10; - map attributes = 11; -} - -// ChannelActionReceipt is the durable audit and idempotency record for a -// user-visible action submitted through a channel adapter. -message ChannelActionReceipt { - string id = 1; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string idempotency_key = 3 [(buf.validate.field).string.min_len = 1]; - string request_hash = 4; - common.v1.Surface surface_type = 5 [(buf.validate.field).enum.defined_only = true]; - ChannelActionKind action_kind = 6 [(buf.validate.field).enum.defined_only = true]; - ChannelActionTargetKind target_kind = 7 [(buf.validate.field).enum.defined_only = true]; - string target_id = 8; - string run_id = 9; - string wait_id = 10; - string approval_request_id = 11; - string objective_id = 12; - ChannelActionActor actor = 13; - google.protobuf.Struct payload = 14; - ChannelActionAuthorizationOutcome authorization_outcome = 15 [(buf.validate.field).enum.defined_only = true]; - ChannelActionExecutionOutcome execution_outcome = 16 [(buf.validate.field).enum.defined_only = true]; - ChannelActionDeliveryOutcome delivery_outcome = 17 [(buf.validate.field).enum.defined_only = true]; - string reason = 18; - string error_reason = 19; - google.protobuf.Timestamp created_at = 20; - google.protobuf.Timestamp updated_at = 21; - codex.v1.CodexInteractionDecision codex_interaction_decision = 22; -} - -// NormalizedTrigger is the source-neutral trigger contract. Surface is an enum -// so product callers share one durable taxonomy across Slack, Ensemble, Chat, -// Maestro, and Conductor. The legacy string field remains for wire-compatible -// migration of early callers. -message NormalizedTrigger { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string agent_id = 2 [(buf.validate.field).string.min_len = 1]; - string surface = 3 [deprecated = true]; - // Deprecated flat channel field. New callers should send channel_context; - // the runtime normalizes this field for legacy consumers and idempotency - // joins. - string channel_id = 4; - string idempotency_key = 5 [(buf.validate.field).string.min_len = 1]; - string source_event_id = 6; - string source_event_type = 7 [deprecated = true]; - string actor_id = 8; - string correlation_id = 9; - google.protobuf.Struct payload = 10; - google.protobuf.Timestamp received_at = 11; - common.v1.Surface surface_type = 12 [(buf.validate.field).enum.defined_only = true]; - RuntimeChannelContext channel_context = 13; - RuntimeTriggerKind trigger_kind = 14 [(buf.validate.field).enum.defined_only = true]; - RuntimeWorkEnvelope work_envelope = 15; - codex.v1.CodexWorkRequest codex_work = 16; - RuntimeProactiveContext proactive_context = 17; - // objective_id binds a trigger to an already-created Objective. Console and - // other product surfaces use this when the user message first creates the - // Objective, so AgentRuntime does not have to rediscover the active goal. - string objective_id = 18; - string organization_id = 19 [(buf.validate.field).string.min_len = 1]; -} - -// RuntimeContext captures the boundary decisions used to construct a run. -message RuntimeContext { - repeated RuntimeDependency dependencies = 1; - map attributes = 2; - repeated RuntimeVirtualFile virtual_files = 3; - // Typed profile for persistent teammate runtime capabilities. Workers and - // channel renderers should use this field as the source of truth; any VFS - // JSON projection is only a compatibility/read surface. - TeammateCapabilityProfile teammate_capability_profile = 4; -} - -// TeammateCapabilityProfile describes the runtime capability and isolation -// contract Platform grants to a persistent teammate run. -message TeammateCapabilityProfile { - string schema_version = 1; - string run_id = 2; - string workspace_id = 3; - string agent_id = 4; - string work_envelope_id = 5; - string work_envelope_kind = 6; - string surface = 7; - string channel_kind = 8; - string execution_owner = 9; - string channel_ingress_owner = 10; - string channel_renderer = 11; - string scheduler_owner = 12; - string memory_owner = 13; - string evidence_owner = 14; - string privilege_model = 15; - bool always_on = 16; - bool ambient = 17; - repeated TeammateCapability capabilities = 18; - repeated TeammateExecutionStep execution_path = 19; - repeated string isolation_boundaries = 20; - repeated string context_paths = 21; - repeated string guardrails = 22; -} - -// TeammateCapability is one Platform-owned capability made available to a run. -message TeammateCapability { - string id = 1; - string owner = 2; - repeated string contract_paths = 3; - repeated string rpcs = 4; - string isolation = 5; - bool slack_visible = 6; - bool requires_lease = 7; - bool proposal_only = 8; - bool evidence_backed = 9; -} - -// TeammateExecutionStep is the concise ownership path for capability use. -message TeammateExecutionStep { - string id = 1; - string owner = 2; - repeated string reads = 3; - repeated string writes = 4; - repeated string rpcs = 5; - string isolation = 6; - string slack_behavior = 7; -} - -// RuntimeVirtualFile is a read-only file projected into an agent run from -// platform services. It lets workers consume rich context through a stable VFS -// instead of parsing flat runtime attributes. -message RuntimeVirtualFile { - string path = 1 [(buf.validate.field).string.min_len = 1]; - string media_type = 2; - string content = 3; - string source_service = 4; - string source_reference_id = 5; - map metadata = 6; - RuntimeVirtualFileProvenance provenance = 7; - RuntimeSensitivity sensitivity = 8 [(buf.validate.field).enum.defined_only = true]; - RuntimeVirtualFileRedactionState redaction_state = 9 [(buf.validate.field).enum.defined_only = true]; - repeated RuntimeRedaction redactions = 10; -} - -// RuntimeVirtualFileProvenance is the typed causal projection for a VFS -// revision. Producers still preserve legacy metadata keys, but workers should -// prefer this shape when explaining, citing, promoting, or rebasing files. -message RuntimeVirtualFileProvenance { - string producer_service = 1; - string producer_kind = 2; - string source_reference_id = 3; - string runtime_event_id = 4; - string artifact_id = 5; - string step_id = 6; - string tool_execution_id = 7; - string hydration_id = 8; - string transaction_id = 9; - string promotion_id = 10; - string evidence_handle = 11; - string trace_id = 12; - string span_id = 13; - repeated string parent_revision_ids = 14; - string provider_id = 15; - string connection_id = 16; -} - -// RuntimeVirtualFileEntry is an ls/stat-friendly projection of one virtual -// file. It intentionally omits content so callers can discover before reading. -message RuntimeVirtualFileEntry { - string path = 1; - string media_type = 2; - string source_service = 3; - string source_reference_id = 4; - map metadata = 5; - int64 size_bytes = 6 [(buf.validate.field).int64.gte = 0]; - string content_sha256 = 7; - bool content_truncated = 8; - string mount = 9; - string kind = 10; - string permissions = 11; - string view = 12; - string revision_id = 13; - string parent_revision_id = 14; - string provider_id = 15; - string connection_id = 16; - string cache_policy = 17; - string policy = 18; - bool lazy = 19; - int32 secret_ref_count = 20 [(buf.validate.field).int32.gte = 0]; - string cerebro_index = 21; - string content_address = 22; - RuntimeVirtualFileProvenance provenance = 23; - RuntimeSensitivity sensitivity = 24 [(buf.validate.field).enum.defined_only = true]; - RuntimeVirtualFileRedactionState redaction_state = 25 [(buf.validate.field).enum.defined_only = true]; - repeated RuntimeRedaction redactions = 26; - RuntimeVirtualFileOperation operation = 27 [(buf.validate.field).enum.defined_only = true]; - bool tombstone = 28; - string rename_from = 29; - string rename_to = 30; - repeated string capabilities = 31; - bool writable = 32; - bool read_only = 33; - bool generated = 34; - bool evidence_backed = 35; - bool externally_indexed = 36; -} - -enum RuntimeVirtualFileOperation { - RUNTIME_VIRTUAL_FILE_OPERATION_UNSPECIFIED = 0; - RUNTIME_VIRTUAL_FILE_OPERATION_WRITE = 1; - RUNTIME_VIRTUAL_FILE_OPERATION_DELETE = 2; - RUNTIME_VIRTUAL_FILE_OPERATION_RENAME = 3; -} - -// RuntimeVirtualFileReasonCode is a stable, machine-readable reason taxonomy -// for VFS skips and precondition failures. Human strings may evolve; clients -// should branch on this enum. -enum RuntimeVirtualFileReasonCode { - RUNTIME_VIRTUAL_FILE_REASON_CODE_UNSPECIFIED = 0; - RUNTIME_VIRTUAL_FILE_REASON_CODE_NOT_FOUND = 1; - RUNTIME_VIRTUAL_FILE_REASON_CODE_FILTERED_OUT = 2; - RUNTIME_VIRTUAL_FILE_REASON_CODE_TOTAL_BUDGET_EXHAUSTED = 3; - RUNTIME_VIRTUAL_FILE_REASON_CODE_PATH_INVALID = 4; - RUNTIME_VIRTUAL_FILE_REASON_CODE_CAPABILITY_DENIED = 5; - RUNTIME_VIRTUAL_FILE_REASON_CODE_REVISION_CONFLICT = 6; - RUNTIME_VIRTUAL_FILE_REASON_CODE_CURSOR_LAGGED = 7; - RUNTIME_VIRTUAL_FILE_REASON_CODE_TEMPORARILY_UNAVAILABLE = 8; -} - -// RuntimeVirtualFileMatch is one bounded search match in a virtual file. -message RuntimeVirtualFileMatch { - string path = 1; - int32 line_number = 2 [(buf.validate.field).int32.gte = 0]; - string snippet = 3; - string mount = 4; - string source_service = 5; - repeated string before_context = 6; - repeated string after_context = 7; - int32 score = 8 [(buf.validate.field).int32.gte = 0]; - repeated string match_reasons = 9; - string view = 10; - string kind = 11; - string transaction_id = 12; -} - -// RuntimeDependency names one platform service boundary the runtime depends on. -message RuntimeDependency { - string service = 1 [(buf.validate.field).string.min_len = 1]; - string purpose = 2; - bool required = 3; - string status = 4 [deprecated = true]; - string reference_id = 5; - RuntimeDependencyStatus status_type = 6 [(buf.validate.field).enum.defined_only = true]; -} - -// AgentRunLinkage carries the shared identifiers every durable run record uses -// for partitioning, authorization, and audit joins. -message AgentRunLinkage { - string run_id = 1; - string workspace_id = 2; - string agent_id = 3; - string objective_id = 4; -} - -// RuntimeTraceContext captures the W3C trace context that causally owns a -// durable AgentRun lifecycle record. It is persisted with runs, events, and -// steps so retries, worker claims, and parked waits can resume the same -// distributed trace instead of starting unrelated service-local traces. -message RuntimeTraceContext { - string trace_id = 1; - string span_id = 2; - string parent_span_id = 3; - string traceparent = 4; - string tracestate = 5; -} - -// AgentRun is the canonical agent runtime execution record. It owns the -// durable child records needed to resume from checkpoints and audit each -// attempt without replaying model/tool side effects. -message AgentRun { - string id = 1; - NormalizedTrigger trigger = 2; - AgentRunState state = 3; - agents.v1.Agent agent = 4; - agents.v1.AgentConfig agent_config = 5; - objectives.v1.Objective objective = 6; - RuntimeContext context = 7; - string worker_queue = 8; - string error_message = 9; - google.protobuf.Timestamp created_at = 10; - google.protobuf.Timestamp updated_at = 11; - - AgentRunLinkage linkage = 12; - int32 attempt = 15; - int32 max_attempts = 16; - AgentRunLease lease = 17; - AgentRunCheckpoint latest_checkpoint = 18; - repeated AgentRunStep steps = 19; - repeated AgentRunWait waits = 20; - repeated AgentRunArtifact artifacts = 21; - repeated AgentRunCost costs = 22; - repeated AgentRunStreamCursor stream_cursors = 23; - google.protobuf.Timestamp queued_at = 24; - google.protobuf.Timestamp started_at = 25; - google.protobuf.Timestamp waiting_at = 26; - google.protobuf.Timestamp completed_at = 27; - google.protobuf.Timestamp cancelled_at = 28; - google.protobuf.Timestamp next_retry_at = 29; - google.protobuf.Timestamp dead_lettered_at = 30; - string cancellation_reason = 31; - string dead_letter_reason = 32; - repeated AgentRunCheckpoint checkpoints = 33; - RuntimeTraceContext trace_context = 34; - string autonomy_session_id = 35; -} - -// AgentRunLease is the claim token a worker must present while mutating a run. -message AgentRunLease { - string id = 1; - AgentRunLinkage linkage = 2; - string worker_id = 6; - string token = 7; - string worker_queue = 8; - int32 attempt = 9; - google.protobuf.Timestamp claimed_at = 10; - google.protobuf.Timestamp heartbeat_at = 11; - google.protobuf.Timestamp expires_at = 12; -} - -// AgentRunStep is one durable unit of work within a run. -message AgentRunStep { - string id = 1; - AgentRunLinkage linkage = 2; - string name = 6; - string kind = 7 [deprecated = true]; - AgentRunStepState state = 8; - int32 attempt = 9; - google.protobuf.Struct input = 10; - google.protobuf.Struct output = 11; - string error_message = 12; - string checkpoint_id = 13; - google.protobuf.Timestamp started_at = 14; - google.protobuf.Timestamp ended_at = 15; - AgentRunStepKind step_kind = 16 [(buf.validate.field).enum.defined_only = true]; - codex.v1.CodexRunProgress codex_progress = 17; - RuntimeTraceContext trace_context = 18; -} - -// AgentRunCheckpoint is an opaque resume snapshot. Workers can deserialize the -// payload they own, restore local state, and continue from the next step. -message AgentRunCheckpoint { - string id = 1; - AgentRunLinkage linkage = 2; - string step_id = 6; - int64 sequence = 7; - string resume_token = 8; - google.protobuf.Struct payload = 9; - google.protobuf.Timestamp created_at = 10; -} - -// AgentRunWait records a parked run. While active, the run has no lease and no -// worker compute should be held. -message AgentRunWait { - string id = 1; - AgentRunLinkage linkage = 2; - string step_id = 6; - AgentRunWaitType type = 7; - string external_ref = 8; - string reason = 9; - google.protobuf.Struct payload = 10; - google.protobuf.Timestamp created_at = 11; - google.protobuf.Timestamp resume_after = 12; - google.protobuf.Timestamp expires_at = 13; - google.protobuf.Timestamp resolved_at = 14; - string resolved_by_event_id = 15; - RuntimeVisibilityMetadata visibility = 16; - codex.v1.CodexInteractionRequest codex_interaction = 17; -} - -// AgentRunArtifact records durable output produced by a run or step. -message AgentRunArtifact { - string id = 1; - AgentRunLinkage linkage = 2; - string step_id = 6; - string artifact_type = 7 [deprecated = true]; - string uri = 8; - string content_type = 9; - string digest = 10; - google.protobuf.Struct metadata = 11; - google.protobuf.Timestamp created_at = 12; - AgentRunArtifactKind artifact_kind = 16 [(buf.validate.field).enum.defined_only = true]; - codex.v1.CodexOutputTarget codex_output = 17; -} - -// AgentRunCost records metering information associated with a run or step. -message AgentRunCost { - string id = 1; - AgentRunLinkage linkage = 2; - string step_id = 6; - string meter_ref = 7; - string provider = 8; - string model = 9; - int64 input_tokens = 10; - int64 output_tokens = 11; - int64 total_tokens = 12; - string currency = 13; - int64 estimated_cost_micros = 14; - google.protobuf.Timestamp recorded_at = 15; -} - -// AgentRunStreamCursor stores a consumer cursor into the append-only event log. -message AgentRunStreamCursor { - string id = 1; - AgentRunLinkage linkage = 2; - string consumer = 4; - int64 next_sequence = 5; - google.protobuf.Timestamp updated_at = 6; -} - -// RuntimeEvent is appended, never mutated, for AgentRun state transitions and -// runtime orchestration decisions. -message RuntimeEvent { - string id = 1; - string run_id = 2; - int64 sequence = 3; - RuntimeEventType type = 4; - string message = 5; - google.protobuf.Struct attributes = 6; - google.protobuf.Timestamp occurred_at = 7; - string step_id = 11; - string checkpoint_id = 12; - string artifact_id = 13; - string cost_id = 14; - string wait_id = 15; - AgentRunLinkage linkage = 16; - RuntimeVisibilityMetadata visibility = 17; - codex.v1.CodexRunProgress codex_progress = 18; - codex.v1.CodexInteractionRequest codex_interaction = 19; - codex.v1.CodexOutcomeSignal codex_outcome = 20; - RuntimeTraceContext trace_context = 21; - NativeToolAttemptEvidence native_tool_attempt = 22; - NativeAgentEventEvidence native_agent_event = 23; -} - -// RuntimeEvidenceGap records a typed, safe reason why a runtime observation is -// not yet approval-ready. It carries only proof-state metadata and debug refs; -// raw credentials, grants, prompts, and tool arguments must not be copied here. -message RuntimeEvidenceGap { - RuntimeEvidenceGapReason reason = 1 [(buf.validate.field).enum.defined_only = true]; - RuntimeEvidenceState evidence_state = 2 [(buf.validate.field).enum.defined_only = true]; - string message = 3; - string source = 4; - string source_event_id = 5; - string runtime_event_id = 6; - string trace_id = 7; - bool approval_blocking = 8; -} - -// NativeToolAttemptEvidence is the typed Platform primitive for answering -// "What did the agent try to do?" from a native Maestro/Codex tool-attempt -// event. It intentionally carries only redaction-safe identifiers, summaries, -// and digest references; raw prompts, tool arguments, and credential grants -// must not be copied here. -message NativeToolAttemptEvidence { - RuntimeEvidenceState evidence_state = 1 [(buf.validate.field).enum.defined_only = true]; - RuntimeEvidenceState credential_evidence_state = 2 [(buf.validate.field).enum.defined_only = true]; - string native_kind = 3 [(buf.validate.field).string.min_len = 1]; - string source_event_id = 4 [(buf.validate.field).string.min_len = 1]; - string source_event_type = 5; - string source_event_source = 6; - string source_event_subject = 7; - string tenant_id = 8; - string organization_id = 9; - string workspace_id = 10 [(buf.validate.field).string.min_len = 1]; - string session_id = 11; - string agent_run_id = 12 [(buf.validate.field).string.min_len = 1]; - string agent_run_step_id = 13; - string agent_id = 14; - string actor_id = 15; - string principal_id = 16; - string trace_id = 17; - string request_id = 18; - string response_id = 19; - string parent_event_id = 20; - string tool_call_id = 21 [(buf.validate.field).string.min_len = 1]; - string tool_execution_id = 22; - string tool_namespace = 23; - string tool_name = 24 [(buf.validate.field).string.min_len = 1]; - string tool_version = 25; - string capability = 26; - string connector_id = 27; - bool mutates_resource = 28; - common.v1.RiskLevel risk_level = 29 [(buf.validate.field).enum.defined_only = true]; - bool arguments_redacted = 30; - string safe_arguments_ref = 31; - string safe_arguments_sha256 = 32; - int32 safe_arguments_key_count = 33 [(buf.validate.field).int32.gte = 0]; - int32 redaction_count = 34 [(buf.validate.field).int32.gte = 0]; - repeated string redactions = 35; - repeated RuntimeEvidenceGap evidence_gaps = 36; - google.protobuf.Timestamp source_event_time = 37; - RuntimeEvidenceState principal_evidence_state = 38 [(buf.validate.field).enum.defined_only = true]; - RuntimeEvidenceState cost_evidence_state = 39 [(buf.validate.field).enum.defined_only = true]; -} - -// NativeAgentEventEvidence is the typed receipt primitive for safe native -// Agent Workforce events from Maestro and Codex. It carries source/correlation -// identifiers, redaction metadata, and safe refs only; raw prompts, tool -// arguments, shell output, MCP result bodies, image bytes, transcripts, token -// values, provider response bodies, and credential grants must not be copied -// here. -message NativeAgentEventEvidence { - RuntimeEvidenceState evidence_state = 1 [(buf.validate.field).enum.defined_only = true]; - RuntimeEvidenceState principal_evidence_state = 2 [(buf.validate.field).enum.defined_only = true]; - RuntimeEvidenceState credential_evidence_state = 3 [(buf.validate.field).enum.defined_only = true]; - RuntimeEvidenceState cost_evidence_state = 4 [(buf.validate.field).enum.defined_only = true]; - NativeAgentEventSource native_source = 5 [(buf.validate.field).enum.defined_only = true]; - string native_kind = 6 [(buf.validate.field).string.min_len = 1]; - string source_event_id = 7 [(buf.validate.field).string.min_len = 1]; - string source_event_type = 8 [(buf.validate.field).string.min_len = 1]; - google.protobuf.Timestamp source_event_time = 9 [(buf.validate.field).required = true]; - string tenant_id = 10; - string organization_id = 11; - string workspace_id = 12 [(buf.validate.field).string.min_len = 1]; - string session_id = 13; - string agent_run_id = 14 [(buf.validate.field).string.min_len = 1]; - string agent_run_step_id = 15; - string agent_id = 16; - string actor_id = 17; - string principal_id = 18; - string thread_id = 19; - string turn_id = 20; - string trace_id = 21; - string request_id = 22; - string response_id = 23; - string parent_event_id = 24; - string tool_call_id = 25; - string tool_execution_id = 26; - string action_id = 27; - string tool_namespace = 28; - string tool_name = 29; - string tool_version = 30; - string capability = 31; - string connector_id = 32; - bool mutates_resource = 33; - common.v1.RiskLevel risk_level = 34 [(buf.validate.field).enum.defined_only = true]; - bool arguments_redacted = 35; - bool output_redacted = 36; - string safe_arguments_ref = 37; - string safe_arguments_sha256 = 38; - int32 safe_arguments_key_count = 39 [(buf.validate.field).int32.gte = 0]; - string safe_output_ref = 40; - string safe_output_sha256 = 41; - int32 safe_output_key_count = 42 [(buf.validate.field).int32.gte = 0]; - int32 redaction_count = 43 [(buf.validate.field).int32.gte = 0]; - repeated string redactions = 44; - repeated RuntimeEvidenceGap evidence_gaps = 45; - string schema = 46 [(buf.validate.field).string.min_len = 1]; -} - -// AgentAutonomySession is the durable teammate session projected over one -// objective/work envelope. Platform owns this identity so Slack can wake, -// steer, or inspect the same autonomous worker without becoming the run loop. -message AgentAutonomySession { - string id = 1; - AgentRunLinkage linkage = 2; - string work_envelope_id = 3; - RuntimeWorkEnvelopeKind work_envelope_kind = 4 [(buf.validate.field).enum.defined_only = true]; - RuntimeChannelContext channel_context = 5; - AutonomySessionState state = 6 [(buf.validate.field).enum.defined_only = true]; - AutonomyProcessingState processing_state = 7 [(buf.validate.field).enum.defined_only = true]; - string processing_summary = 8; - string root_run_id = 9; - string active_run_id = 10; - string current_goal = 11; - string next_action = 12; - string blocker = 13; - string processing_message_ts = 14; - string assistant_stream_ts = 15; - string last_presence_event_id = 16; - google.protobuf.Timestamp last_presence_update_at = 17; - bool final_response_pending = 18; - google.protobuf.Timestamp created_at = 19; - google.protobuf.Timestamp updated_at = 20; -} - -// AgentWorkItem is one node in the autonomous work graph. Workers and -// reconcilers mutate this typed record directly; VFS ledgers are projections. -message AgentWorkItem { - string id = 1; - AgentRunLinkage linkage = 2; - string autonomy_session_id = 3; - string run_id = 4; - string work_envelope_id = 5; - string parent_work_item_id = 6; - string owner_child_run_id = 7; - AgentWorkItemKind kind = 8 [(buf.validate.field).enum.defined_only = true]; - AgentWorkItemState state = 9 [(buf.validate.field).enum.defined_only = true]; - string title = 10; - string goal = 11; - string next_action = 12; - string blocker = 13; - string wait_id = 14; - string tool_execution_id = 15; - repeated string evidence_refs = 16; - string completion_gate = 17; - google.protobuf.Struct payload = 18; - google.protobuf.Timestamp created_at = 19; - google.protobuf.Timestamp updated_at = 20; - google.protobuf.Timestamp started_at = 21; - google.protobuf.Timestamp completed_at = 22; - google.protobuf.Timestamp failed_at = 23; - google.protobuf.Timestamp cancelled_at = 24; -} - -message HandleTriggerRequest { - NormalizedTrigger trigger = 1 [(buf.validate.field).required = true]; -} - -message HandleTriggerResponse { - AgentRun run = 1; - repeated RuntimeEvent events = 2; - bool idempotent_replay = 3; -} - -// Safe attachment metadata accepted from a channel edge. Provider download -// URLs, credentials, and raw attachment bodies are intentionally excluded. -message OperatingChannelAttachmentMetadata { - string provider_attachment_id = 1 [(buf.validate.field).string.min_len = 1]; - string kind = 2; - string media_type = 3; - string name = 4; - int64 size_bytes = 5 [(buf.validate.field).int64.gte = 0]; -} - -// A bounded interactive action submitted by a signed channel edge. The token -// is opaque to the edge and must be validated by Platform before it resolves -// any canonical receipt, question, or session control. -message OperatingChannelInteraction { - string action_id = 1 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; - string action_token = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 4096 - }]; - string action_timestamp = 3 [(buf.validate.field).string = { - min_len: 1 - max_len: 64 - }]; -} - -// Email reply coordinates authenticated by the email edge and validated against -// the resolved mailbox installation before persistence. Never model authority. -message OperatingChannelEmailMetadata { - string mailbox = 1 [(buf.validate.field).string.max_len = 254]; - string sender = 2 [(buf.validate.field).string.max_len = 254]; - string subject = 3 [(buf.validate.field).string.max_len = 512]; -} - -// Provider-coordinate admission deliberately has no organization_id or -// workspace_id fields. Those authority-bearing coordinates are resolved by -// Platform through ConnectorService before any durable tenant write occurs. -message AdmitOperatingChannelEventRequest { - string provider_id = 1 [(buf.validate.field).string.min_len = 1]; - string provider_app_id = 2 [(buf.validate.field).string.min_len = 1]; - string provider_workspace_id = 3 [(buf.validate.field).string.min_len = 1]; - string provider_enterprise_id = 4; - string source_event_id = 5 [(buf.validate.field).string.min_len = 1]; - string source_event_type = 6 [(buf.validate.field).string.min_len = 1]; - string provider_channel_id = 7 [(buf.validate.field).string.min_len = 1]; - string provider_root_thread_id = 8 [(buf.validate.field).string.min_len = 1]; - string provider_message_id = 9 [(buf.validate.field).string.min_len = 1]; - string actor_subject = 10 [(buf.validate.field).string.min_len = 1]; - string normalized_text = 11; - repeated OperatingChannelAttachmentMetadata attachments = 12; - string traceparent = 13; - string tracestate = 14; - bool direct_conversation = 15; - bool explicit_mention = 16; - OperatingChannelInteraction interaction = 17; - // Short-lived Slack RTS authority from the triggering message/app_mention. - // Server-owned execution context; never forwarded to the model or receipts. - string slack_rts_action_token = 18; - repeated OperatingChannelContextEntity context_entities = 19 [(buf.validate.field).repeated.max_items = 20]; - // Authenticated provider callback endpoint used only for outbound transport. - // Platform validates and persists this outside model-visible context. - string provider_delivery_endpoint = 20 [(buf.validate.field).string.max_len = 2048]; - OperatingChannelEmailMetadata email = 21; -} - -message AdmitOperatingChannelEventResponse { - bool accepted = 1; - bool duplicate = 2; - string ignored_reason = 3; - string conversation_id = 4; - string turn_id = 5; -} - -message SurfaceInvocationActor { - string external_id = 1 [(buf.validate.field).string.min_len = 1]; - string display_name = 2 [(buf.validate.field).string.max_len = 512]; -} - -message SurfaceInvocationTarget { - SurfaceTargetKind kind = 1 [(buf.validate.field).enum.defined_only = true]; - string external_id = 2 [(buf.validate.field).string.min_len = 1]; - string parent_external_id = 3 [(buf.validate.field).string.max_len = 512]; - string revision = 4 [(buf.validate.field).string.max_len = 512]; - string canonical_url = 5 [(buf.validate.field).string.max_len = 2048]; -} - -message SurfaceInvocationTrigger { - string kind = 1 [(buf.validate.field).string.min_len = 1]; - string external_id = 2 [(buf.validate.field).string.min_len = 1]; -} - -message SurfaceInvocationAttachmentRef { - string external_id = 1 [(buf.validate.field).string.min_len = 1]; - string name = 2 [(buf.validate.field).string.min_len = 1]; - string content_type = 3 [(buf.validate.field).string.max_len = 255]; - string canonical_url = 4 [(buf.validate.field).string.max_len = 2048]; -} - -message SurfaceInvocationContextRef { - string kind = 1 [(buf.validate.field).string.min_len = 1]; - string external_id = 2 [(buf.validate.field).string.min_len = 1]; - string canonical_url = 3 [(buf.validate.field).string.max_len = 2048]; -} - -// A bounded provider-native context snapshot captured by the authenticated -// edge. `content` is model-visible context, while the remaining fields bind it -// to the provider read or signed delivery that produced it. Snapshots confer -// no tenant or mutation authority. -message SurfaceInvocationContextSnapshot { - string source_kind = 1 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; - string source_external_id = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 512 - }]; - string source_revision = 3 [(buf.validate.field).string.max_len = 512]; - // Digest of the complete authenticated provider payload or governed read - // response from which `content` was selected. - string source_payload_sha256 = 4 [(buf.validate.field).string.pattern = "^[0-9a-f]{64}$"]; - google.protobuf.Timestamp observed_at = 5; - google.protobuf.Struct content = 6; -} - -enum SurfaceInvocationControl { - SURFACE_INVOCATION_CONTROL_UNSPECIFIED = 0; - SURFACE_INVOCATION_CONTROL_WORK = 1; - SURFACE_INVOCATION_CONTROL_CANCEL = 2; -} - -// The adapter, not this request, verifies the provider-native webhook. A -// surface-edge service can normalize Slack, Linear, Jira, Salesforce, -// documents, incidents, and future providers into this one typed contract. -// Tenant scope is absent by design and is resolved through ConnectorService. -message AdmitSurfaceInvocationRequest { - string provider_id = 1 [(buf.validate.field).string.min_len = 1]; - string connection_id = 2 [(buf.validate.field).string.max_len = 512]; - string provider_app_id = 3 [(buf.validate.field).string.min_len = 1]; - string provider_workspace_id = 4 [(buf.validate.field).string.min_len = 1]; - string provider_enterprise_id = 5 [(buf.validate.field).string.max_len = 512]; - SurfaceInvocationActor actor = 6; - SurfaceInvocationTarget target = 7; - SurfaceInvocationTrigger trigger = 8; - string text = 9 [(buf.validate.field).string.max_len = 32768]; - repeated SurfaceInvocationAttachmentRef attachments = 10 [(buf.validate.field).repeated.max_items = 20]; - repeated SurfaceInvocationContextRef context_refs = 11 [(buf.validate.field).repeated.max_items = 20]; - google.protobuf.Struct projection_context = 12; - string idempotency_key = 13 [ - (buf.validate.field).string.min_len = 1, - (buf.validate.field).string.max_len = 512 - ]; - string traceparent = 14 [(buf.validate.field).string.max_len = 512]; - string tracestate = 15 [(buf.validate.field).string.max_len = 512]; - repeated SurfaceInvocationContextSnapshot context_snapshots = 16 [(buf.validate.field).repeated.max_items = 20]; - SurfaceInvocationControl control = 17 [(buf.validate.field).enum.defined_only = true]; - // Providers with a native agent/session UI may request a fast, governed - // acknowledgement projection while ordinary work continues. - bool acknowledgement_requested = 18; -} - -message AdmitSurfaceInvocationResponse { - bool accepted = 1; - bool duplicate = 2; - string ignored_reason = 3; - string conversation_id = 4; - string turn_id = 5; -} - -message ClaimNextRunRequest { - string worker_id = 1 [(buf.validate.field).string.min_len = 1]; - string worker_queue = 2; - int32 lease_seconds = 3 [(buf.validate.field).int32.gte = 0]; -} - -message ClaimNextRunResponse { - AgentRun run = 1; - AgentRunLease lease = 2; - repeated RuntimeEvent events = 3; -} - -message HeartbeatRunRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - string lease_token = 2 [(buf.validate.field).string.min_len = 1]; - int32 extend_seconds = 3 [(buf.validate.field).int32.gte = 0]; -} - -message HeartbeatRunResponse { - AgentRun run = 1; - AgentRunLease lease = 2; - RuntimeEvent event = 3; -} - -message RenewRunLeaseRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - string lease_token = 2 [(buf.validate.field).string.min_len = 1]; - int32 extend_seconds = 3 [(buf.validate.field).int32.gte = 0]; -} - -message RenewRunLeaseResponse { - AgentRun run = 1; - AgentRunLease lease = 2; - RuntimeEvent event = 3; - bool renewed_after_expiry = 4; -} - -message RecordRunStepRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - string lease_token = 2 [(buf.validate.field).string.min_len = 1]; - AgentRunStep step = 3 [(buf.validate.field).required = true]; -} - -message RecordRunStepResponse { - AgentRun run = 1; - AgentRunStep step = 2; - RuntimeEvent event = 3; -} - -message RecordRunCheckpointRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - string lease_token = 2 [(buf.validate.field).string.min_len = 1]; - AgentRunCheckpoint checkpoint = 3 [(buf.validate.field).required = true]; -} - -message RecordRunCheckpointResponse { - AgentRun run = 1; - AgentRunCheckpoint checkpoint = 2; - RuntimeEvent event = 3; -} - -message RecordRunArtifactRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - string lease_token = 2 [(buf.validate.field).string.min_len = 1]; - AgentRunArtifact artifact = 3 [(buf.validate.field).required = true]; -} - -message RecordRunArtifactResponse { - AgentRun run = 1; - AgentRunArtifact artifact = 2; - RuntimeEvent event = 3; -} - -message RecordRunCostRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - string lease_token = 2 [(buf.validate.field).string.min_len = 1]; - AgentRunCost cost = 3 [(buf.validate.field).required = true]; -} - -message RecordRunCostResponse { - AgentRun run = 1; - AgentRunCost cost = 2; - RuntimeEvent event = 3; -} - -message RecordRunStreamCursorRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - AgentRunStreamCursor cursor = 2 [(buf.validate.field).required = true]; -} - -message RecordRunStreamCursorResponse { - AgentRun run = 1; - AgentRunStreamCursor cursor = 2; - RuntimeEvent event = 3; -} - -message RecordRunEventRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - RuntimeEventType type = 2 [(buf.validate.field).enum.defined_only = true]; - string message = 3 [(buf.validate.field).string.min_len = 1]; - google.protobuf.Struct attributes = 4; - string step_id = 5; - string checkpoint_id = 6; - string artifact_id = 7; - string cost_id = 8; - string wait_id = 9; - RuntimeVisibilityMetadata visibility = 10; - NativeToolAttemptEvidence native_tool_attempt = 11; - NativeAgentEventEvidence native_agent_event = 12; -} - -message RecordRunEventResponse { - AgentRun run = 1; - RuntimeEvent event = 2; -} - -message ControlRunRequest { - string run_id = 1; - string workspace_id = 2; - string agent_id = 3; - string work_envelope_id = 4; - string autonomy_session_id = 5; - RunControlMode mode = 6 [(buf.validate.field).enum.defined_only = true]; - string message = 7; - string idempotency_key = 8; - RuntimeChannelContext channel_context = 9; - google.protobuf.Struct payload = 10; - RuntimeVisibilityMetadata visibility = 11; -} - -message ControlRunResponse { - AgentRun run = 1; - RuntimeEvent event = 2; - string control_id = 3; - bool cancelled = 4; - bool queued_for_worker = 5; -} - -message RecordRunWorkItemRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - AgentWorkItem work_item = 2 [(buf.validate.field).required = true]; -} - -message RecordRunWorkItemResponse { - AgentRun run = 1; - AgentWorkItem work_item = 2; - RuntimeEvent event = 3; -} - -message UpdateRunWorkItemRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - string work_item_id = 2 [(buf.validate.field).string.min_len = 1]; - AgentWorkItemState state = 3 [(buf.validate.field).enum.defined_only = true]; - optional string next_action = 4; - optional string blocker = 5; - optional string wait_id = 6; - optional string tool_execution_id = 7; - repeated string evidence_refs = 8; - optional string completion_gate = 9; - google.protobuf.Struct payload = 10; -} - -message UpdateRunWorkItemResponse { - AgentRun run = 1; - AgentWorkItem work_item = 2; - RuntimeEvent event = 3; -} - -message ListRunWorkItemsRequest { - string run_id = 1; - string workspace_id = 2; - string work_envelope_id = 3; - string autonomy_session_id = 4; - AgentWorkItemState state = 5 [(buf.validate.field).enum.defined_only = true]; - int32 limit = 6 [(buf.validate.field).int32.gte = 0]; -} - -message ListRunWorkItemsResponse { - repeated AgentWorkItem work_items = 1; -} - -message YieldRunRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - string lease_token = 2 [(buf.validate.field).string.min_len = 1]; - YieldContinuation continuation = 3 [(buf.validate.field).enum.defined_only = true]; - AgentRunCheckpoint checkpoint = 4; - google.protobuf.Timestamp resume_after = 5; - AgentRunWait wait = 6; - string presence_status_text = 7; - string idempotency_key = 8; - int32 yield_budget = 9 [(buf.validate.field).int32.gte = 0]; -} - -message YieldRunResponse { - AgentRun run = 1; - AgentRun successor_run = 2; - AgentRunWait wait = 3; - AgentRunCheckpoint checkpoint = 4; - RuntimeEvent event = 5; - RuntimeEvent presence_event = 6; - bool session_blocked = 7; - int32 yield_count = 8 [(buf.validate.field).int32.gte = 0]; -} - -message WaitRunRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - string lease_token = 2 [(buf.validate.field).string.min_len = 1]; - AgentRunWait wait = 3 [(buf.validate.field).required = true]; - AgentRunCheckpoint checkpoint = 4; -} - -message WaitRunResponse { - AgentRun run = 1; - AgentRunWait wait = 2; - AgentRunCheckpoint checkpoint = 3; - RuntimeEvent event = 4; -} - -message ResumeRunRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - string wait_id = 2 [(buf.validate.field).string.min_len = 1]; - string resume_event_id = 3; - google.protobuf.Struct payload = 4; - codex.v1.CodexInteractionDecision codex_interaction_decision = 5; -} - -message ResumeRunResponse { - AgentRun run = 1; - RuntimeEvent event = 2; -} - -message CompleteRunRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - string lease_token = 2 [(buf.validate.field).string.min_len = 1]; - google.protobuf.Struct result = 3; - AgentRunCheckpoint checkpoint = 4; -} - -message CompleteRunResponse { - AgentRun run = 1; - AgentRunCheckpoint checkpoint = 2; - RuntimeEvent event = 3; -} - -message FailRunRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - string lease_token = 2 [(buf.validate.field).string.min_len = 1]; - string error_message = 3 [(buf.validate.field).string.min_len = 1]; - bool retryable = 4; - int32 retry_delay_seconds = 5 [(buf.validate.field).int32.gte = 0]; -} - -message FailRunResponse { - AgentRun run = 1; - RuntimeEvent event = 2; -} - -message CancelRunRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - string reason = 2; -} - -message CancelRunResponse { - AgentRun run = 1; - RuntimeEvent event = 2; -} - -message RetryRunRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - int32 retry_delay_seconds = 2 [(buf.validate.field).int32.gte = 0]; - string reason = 3; -} - -message RetryRunResponse { - AgentRun run = 1; - RuntimeEvent event = 2; -} - -message DeadLetterRunRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - string reason = 2; -} - -message DeadLetterRunResponse { - AgentRun run = 1; - RuntimeEvent event = 2; -} - -message GetRunRequest { - string id = 1 [(buf.validate.field).string.min_len = 1]; -} - -message GetRunResponse { - AgentRun run = 1; -} - -message GetTeammateWorkLedgerRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; -} - -message GetTeammateWorkLedgerResponse { - TeammateWorkLedger ledger = 1; - RuntimeVirtualFile ledger_file = 2; -} - -// TeammateWorkLedger is the compact, durable read model a persistent digital -// teammate uses to resume work, explain what it has actually checked, and keep -// Slack or other human-facing channels clean while tool-heavy work happens -// under the hood. -message TeammateWorkLedger { - string schema_version = 1; - string run_id = 2; - AgentRunLinkage linkage = 3; - AgentRunState state = 4; - string objective_title = 5; - string worker_queue = 6; - int32 attempt = 7 [(buf.validate.field).int32.gte = 0]; - string work_envelope_id = 8; - string work_envelope_kind = 9; - string workstream_id = 10; - string next_action = 11; - repeated TeammateWorkLedgerBlocker blockers = 12; - repeated TeammateWorkLedgerConnectorAccess connector_access = 13; - repeated TeammateWorkLedgerMemoryCitation memory_citations = 14; - TeammateWorkLedgerVfsSummary vfs_summary = 15; - TeammateWorkLedgerCerebroContext cerebro_context = 16; - TeammateWorkLedgerProactivePolicy proactive_policy = 17; - TeammateWorkLedgerChannelStatus channel_status = 18; - repeated string evidence_paths = 19; - string handoff_policy = 20; - string resume_checkpoint_path = 21; - google.protobuf.Timestamp updated_at = 22; - int32 event_count = 23 [(buf.validate.field).int32.gte = 0]; - repeated AgentWorkItem active_work_items = 24; - int32 active_work_item_count = 25 [(buf.validate.field).int32.gte = 0]; - int32 blocked_work_item_count = 26 [(buf.validate.field).int32.gte = 0]; -} - -message TeammateWorkLedgerBlocker { - string wait_id = 1; - AgentRunWaitType type = 2; - string reason = 3; - string external_ref = 4; - google.protobuf.Timestamp resume_after = 5; - string visibility_summary = 6; - TeammateWorkLedgerWaitResumeContract resume_contract = 7; -} - -// TeammateWorkLedgerWaitResumeContract makes parked-run resumption -// machine-readable for channel adapters and workers. Slack actions can carry -// only the compact value fields, then resolve the durable wait through -// ListRunWaits before calling ResumeRun. -message TeammateWorkLedgerWaitResumeContract { - string schema_version = 1; - string resume_rpc = 2; - string lookup_rpc = 3; - string lookup_external_ref_field = 4; - repeated string required_resume_fields = 5; - repeated string allowed_decisions = 6; - repeated string channel_action_value_fields = 7; - string idempotency_join_key = 8; - string approval_request_id = 9; - bool requires_safe_summary = 10; -} - -message TeammateWorkLedgerConnectorAccess { - string mount_path = 1; - string provider_id = 2; - string connection_id = 3; - repeated string capabilities = 4; - bool grant_required = 5; - string lease_policy = 6; - string identity_mode = 7; - string credential_version_strategy = 8; - int32 secret_ref_count = 9 [(buf.validate.field).int32.gte = 0]; - repeated string credential_ref_names = 10; -} - -message TeammateWorkLedgerMemoryCitation { - string memory_id = 1; - string memory_type = 2; - string source = 3; - repeated string source_uris = 4; - string supersedes_memory_id = 5; - string superseded_by_memory_id = 6; - string review_status = 7; - repeated string entity_ids = 8; - string content_preview = 9; -} - -message TeammateWorkLedgerVfsSummary { - int32 file_count = 1 [(buf.validate.field).int32.gte = 0]; - int32 mount_count = 2 [(buf.validate.field).int32.gte = 0]; - int32 connector_mount_count = 3 [(buf.validate.field).int32.gte = 0]; - int32 memory_record_count = 4 [(buf.validate.field).int32.gte = 0]; - int32 transaction_count = 5 [(buf.validate.field).int32.gte = 0]; - int32 cerebro_index_eligible_file_count = 6 [(buf.validate.field).int32.gte = 0]; - bool has_resume_checkpoint = 7; -} - -message TeammateWorkLedgerCerebroContext { - string provider = 1; - string query = 2; - repeated string thing_ids = 3; - repeated string fact_ids = 4; - repeated string event_ids = 5; - int32 eligible_file_count = 6 [(buf.validate.field).int32.gte = 0]; -} - -message TeammateWorkLedgerProactivePolicy { - bool enabled = 1; - repeated string trigger_kinds = 2; - repeated string progress_update_triggers = 3; - string presence_policy = 4; - int32 update_budget = 5 [(buf.validate.field).int32.gte = 0]; -} - -message TeammateWorkLedgerChannelStatus { - string channel_kind = 1; - string channel_id = 2; - string thread_id = 3; - string last_visible_event_id = 4; - string last_visible_summary = 5; - AutonomyProcessingState processing_state = 6 [(buf.validate.field).enum.defined_only = true]; - string processing_summary = 7; - string processing_message_ts = 8; - string assistant_stream_ts = 9; - string last_presence_event_id = 10; - google.protobuf.Timestamp last_presence_update_at = 11; - bool final_response_pending = 12; - string autonomy_session_id = 13; -} - -message ListRunsByWorkEnvelopeRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string work_envelope_id = 2 [(buf.validate.field).string.min_len = 1]; - int32 limit = 3 [(buf.validate.field).int32.gte = 0]; -} - -message ListRunsByWorkEnvelopeResponse { - repeated AgentRun runs = 1; -} - -message ChannelThreadAdoption { - string id = 1; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string agent_id = 3 [(buf.validate.field).string.min_len = 1]; - RuntimeChannelKind channel_kind = 4 [(buf.validate.field).enum.defined_only = true]; - string provider_workspace_id = 5; - string channel_id = 6 [(buf.validate.field).string.min_len = 1]; - string thread_id = 7 [(buf.validate.field).string.min_len = 1]; - string work_envelope_id = 8; - string first_adopted_run_id = 9; - string last_run_id = 10; - google.protobuf.Timestamp first_adopted_at = 11; - google.protobuf.Timestamp updated_at = 12; - google.protobuf.Timestamp expires_at = 13; - string last_message_id = 14; - string last_source_event_id = 15; - string last_adoption_reason = 16; - string adoption_policy = 17; - google.protobuf.Struct metadata = 18; - RuntimeChannelContext channel_context = 19; - RuntimeWorkEnvelope work_envelope = 20; - // Tenant organization that owns this adoption row. Required for shared-runtime - // isolation; storage uniqueness and list filters are organization-scoped. - string organization_id = 21 [(buf.validate.field).string.min_len = 1]; -} - -message GetChannelThreadAdoptionRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string agent_id = 2 [(buf.validate.field).string.min_len = 1]; - RuntimeChannelKind channel_kind = 3 [(buf.validate.field).enum.defined_only = true]; - string provider_workspace_id = 4; - string channel_id = 5 [(buf.validate.field).string.min_len = 1]; - string thread_id = 6 [(buf.validate.field).string.min_len = 1]; - bool include_expired = 7; - string organization_id = 8 [(buf.validate.field).string.min_len = 1]; -} - -message GetChannelThreadAdoptionResponse { - ChannelThreadAdoption adoption = 1; -} - -message RecordChannelThreadAdoptionRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string agent_id = 2 [(buf.validate.field).string.min_len = 1]; - RuntimeChannelKind channel_kind = 3 [(buf.validate.field).enum.defined_only = true]; - string provider_workspace_id = 4; - string channel_id = 5 [(buf.validate.field).string.min_len = 1]; - string thread_id = 6 [(buf.validate.field).string.min_len = 1]; - string message_id = 7; - string source_event_id = 8; - string adoption_reason = 9; - google.protobuf.Timestamp expires_at = 10; - string work_envelope_id = 11; - google.protobuf.Struct metadata = 12; - string organization_id = 13 [(buf.validate.field).string.min_len = 1]; -} - -message RecordChannelThreadAdoptionResponse { - ChannelThreadAdoption adoption = 1; -} - -message ListChannelThreadAdoptionsRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string agent_id = 2; - RuntimeChannelKind channel_kind = 3 [(buf.validate.field).enum.defined_only = true]; - string provider_workspace_id = 4; - string channel_id = 5; - string thread_id = 6; - string work_envelope_id = 7; - bool include_expired = 8; - int32 limit = 9 [(buf.validate.field).int32.gte = 0]; - // Organization scope for list filtering. Required so a shared Agent Runtime - // database cannot return another tenant's adoption projection for a reused - // workspace id. - string organization_id = 10 [(buf.validate.field).string.min_len = 1]; -} - -message ListChannelThreadAdoptionsResponse { - repeated ChannelThreadAdoption adoptions = 1; -} - -message ListRunWaitsRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string run_id = 2; - string agent_id = 3; - string objective_id = 4; - string work_envelope_id = 5; - AgentRunWaitState state = 6 [(buf.validate.field).enum.defined_only = true]; - AgentRunWaitType type = 7 [(buf.validate.field).enum.defined_only = true]; - RuntimeAudience audience = 8 [(buf.validate.field).enum.defined_only = true]; - int32 limit = 9 [(buf.validate.field).int32.gte = 0]; - string page_token = 10; - // external_ref filters waits by their external join key, such as an - // approvals.v1 ApprovalRequest id carried by desktop-control approval waits. - string external_ref = 11; -} - -message AgentRunWaitSummary { - string run_id = 1; - string wait_id = 2; - string workspace_id = 3; - string agent_id = 4; - string objective_id = 5; - string step_id = 6; - AgentRunWaitType type = 7; - AgentRunWaitState state = 8; - string external_ref = 9; - string reason = 10; - google.protobuf.Struct payload = 11; - google.protobuf.Timestamp created_at = 12; - google.protobuf.Timestamp resume_after = 13; - google.protobuf.Timestamp expires_at = 14; - google.protobuf.Timestamp resolved_at = 15; - string resolved_by_event_id = 16; - RuntimeVisibilityMetadata visibility = 17; - RuntimeChannelContext channel_context = 18; - RuntimeWorkEnvelope work_envelope = 19; -} - -message ListRunWaitsResponse { - repeated AgentRunWaitSummary waits = 1; - string next_page_token = 2; -} - -message RecordChannelActionReceiptRequest { - ChannelActionReceipt receipt = 1 [(buf.validate.field).required = true]; -} - -message RecordChannelActionReceiptResponse { - ChannelActionReceipt receipt = 1; - bool idempotent_replay = 2; -} - -message GetChannelActionReceiptRequest { - string id = 1 [(buf.validate.field).string.min_len = 1]; -} - -message GetChannelActionReceiptResponse { - ChannelActionReceipt receipt = 1; -} - -message ListChannelActionReceiptsRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string idempotency_key = 2; - string actor_entity_id = 3; - ChannelActionTargetKind target_kind = 4 [(buf.validate.field).enum.defined_only = true]; - string target_id = 5; - string run_id = 6; - string wait_id = 7; - string approval_request_id = 8; - string objective_id = 9; - RuntimeChannelKind channel_kind = 10 [(buf.validate.field).enum.defined_only = true]; - string provider_workspace_id = 11; - string channel_id = 12; - string thread_id = 13; - string message_id = 14; - string action_id = 15; - int32 limit = 16 [(buf.validate.field).int32.gte = 0]; -} - -message ListChannelActionReceiptsResponse { - repeated ChannelActionReceipt receipts = 1; -} - -message ListRunEventsRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - RuntimeAudience audience = 2 [(buf.validate.field).enum.defined_only = true]; - int32 page_size = 3 [(buf.validate.field).int32.gte = 0]; - string page_token = 4; -} - -message ListRunEventsResponse { - repeated RuntimeEvent events = 1; - string next_page_token = 2; -} - -message ListRunVirtualFilesRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - string path_prefix = 2; - int32 limit = 3 [(buf.validate.field).int32.gte = 0]; - bool include_tombstones = 4; -} - -message ListRunVirtualFilesResponse { - repeated RuntimeVirtualFileEntry entries = 1; -} - -message ReadRunVirtualFileRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - string path = 2 [(buf.validate.field).string.min_len = 1]; - int32 offset = 3 [(buf.validate.field).int32.gte = 0]; - int32 limit = 4 [(buf.validate.field).int32.gte = 0]; - bool include_tombstones = 5; -} - -message ReadRunVirtualFileResponse { - RuntimeVirtualFileEntry entry = 1; - string content = 2; - int32 offset = 3; - int32 next_offset = 4; - bool eof = 5; - RuntimeVirtualFileRedactionState redaction_state = 6 [(buf.validate.field).enum.defined_only = true]; - repeated RuntimeRedaction redactions = 7; -} - -message StatRunVirtualFileRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - string path = 2 [(buf.validate.field).string.min_len = 1]; - bool include_tombstones = 3; -} - -message StatRunVirtualFileResponse { - RuntimeVirtualFileEntry entry = 1; -} - -message WatchRunVirtualFilesRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - string since_cursor = 2; - int32 limit = 3 [(buf.validate.field).int32.gte = 0]; - bool follow = 4; - RuntimeVirtualFileSelector selector = 5; -} - -message WatchRunVirtualFilesResponse { - RuntimeVirtualFileWatchEvent event = 1; -} - -message RuntimeVirtualFileWatchEvent { - string cursor = 1; - string operation = 2; - string path = 3; - string revision_id = 4; - string parent_revision_id = 5; - string transaction_id = 6; - string view = 7; - string span_id = 8; - string evidence_handle = 9; - string runtime_event_id = 10; - string artifact_id = 11; - string trace_id = 12; - string hydration_id = 13; - string promotion_id = 14; - string producer_service = 15; - string producer_kind = 16; - google.protobuf.Timestamp occurred_at = 17; - string checkpoint_id = 18; - RuntimeVirtualFileEntry entry = 19; -} - -message RuntimeVirtualFileSelector { - repeated string paths = 1; - string path_prefix = 2; - repeated string views = 3; - repeated string kinds = 4; - repeated string mounts = 5; - repeated string transaction_ids = 6; - repeated string policies = 7; - repeated string source_services = 8; - repeated string cerebro_indexes = 9; - bool include_tombstones = 10; -} - -message RuntimeVirtualFileReadResult { - string path = 1; - RuntimeVirtualFileEntry entry = 2; - string content = 3; - int32 offset = 4 [(buf.validate.field).int32.gte = 0]; - int32 next_offset = 5 [(buf.validate.field).int32.gte = 0]; - bool eof = 6; - bool skipped = 7; - string skip_reason = 8; - string citation = 9; - int32 rank = 10 [(buf.validate.field).int32.gte = 0]; - string rank_reason = 11; - RuntimeVirtualFileReasonCode reason_code = 12 [(buf.validate.field).enum.defined_only = true]; - RuntimeVirtualFileRedactionState redaction_state = 13 [(buf.validate.field).enum.defined_only = true]; - repeated RuntimeRedaction redactions = 14; -} - -message BatchReadRunVirtualFilesRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - RuntimeVirtualFileSelector selector = 2; - int32 per_file_limit = 3 [(buf.validate.field).int32.gte = 0]; - int32 total_limit = 4 [(buf.validate.field).int32.gte = 0]; - int32 limit = 5 [(buf.validate.field).int32.gte = 0]; -} - -message BatchReadRunVirtualFilesResponse { - repeated RuntimeVirtualFileReadResult files = 1; - int32 total_content_bytes = 2 [(buf.validate.field).int32.gte = 0]; - bool budget_exhausted = 3; - int32 skipped_count = 4 [(buf.validate.field).int32.gte = 0]; -} - -message BuildRunVirtualFileContextPackRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - string query = 2; - RuntimeVirtualFileSelector selector = 3; - repeated string seed_paths = 4; - int32 per_file_limit = 5 [(buf.validate.field).int32.gte = 0]; - int32 total_limit = 6 [(buf.validate.field).int32.gte = 0]; - int32 limit = 7 [(buf.validate.field).int32.gte = 0]; -} - -message BuildRunVirtualFileContextPackResponse { - repeated RuntimeVirtualFileReadResult snippets = 1; - int32 total_content_bytes = 2 [(buf.validate.field).int32.gte = 0]; - bool budget_exhausted = 3; - int32 skipped_count = 4 [(buf.validate.field).int32.gte = 0]; - repeated string skipped_paths = 5; -} - -message SearchRunVirtualFilesRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - string query = 2 [(buf.validate.field).string.min_len = 1]; - string path_prefix = 3; - int32 limit = 4 [(buf.validate.field).int32.gte = 0]; - RuntimeVirtualFileSelector selector = 5; - bool regex = 6; - int32 context_lines = 7 [(buf.validate.field).int32.gte = 0]; - bool case_sensitive = 8; -} - -message SearchRunVirtualFilesResponse { - repeated RuntimeVirtualFileMatch matches = 1; - int32 total_matches = 2 [(buf.validate.field).int32.gte = 0]; - bool limit_exhausted = 3; -} - -message RecordRunVirtualFileProposalRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - string lease_token = 2 [(buf.validate.field).string.min_len = 1]; - string path = 3 [(buf.validate.field).string.min_len = 1]; - string media_type = 4; - string content = 5; - string proposal_kind = 6; - string step_id = 7; - map metadata = 8; - string idempotency_key = 9; - RuntimeSensitivity sensitivity = 10 [(buf.validate.field).enum.defined_only = true]; - RuntimeVirtualFileRedactionState redaction_state = 11 [(buf.validate.field).enum.defined_only = true]; - repeated RuntimeRedaction redactions = 12; -} - -message RecordRunVirtualFileProposalResponse { - AgentRun run = 1; - AgentRunArtifact artifact = 2; - RuntimeVirtualFile file = 3; - RuntimeEvent event = 4; -} - -message RuntimeVirtualFileChange { - string path = 1 [(buf.validate.field).string.min_len = 1]; - string media_type = 2; - string content = 3; - string proposal_kind = 4; - string step_id = 5; - map metadata = 6; - RuntimeSensitivity sensitivity = 7 [(buf.validate.field).enum.defined_only = true]; - RuntimeVirtualFileRedactionState redaction_state = 8 [(buf.validate.field).enum.defined_only = true]; - repeated RuntimeRedaction redactions = 9; - RuntimeVirtualFileOperation operation = 10 [(buf.validate.field).enum.defined_only = true]; - string rename_from = 11; -} - -message RecordRunVirtualFileTransactionRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - string lease_token = 2 [(buf.validate.field).string.min_len = 1]; - string transaction_id = 3; - string parent_revision_id = 4; - repeated RuntimeVirtualFileChange changes = 5; - map metadata = 6; - string idempotency_key = 7; -} - -message RecordRunVirtualFileTransactionResponse { - AgentRun run = 1; - repeated AgentRunArtifact artifacts = 2; - repeated RuntimeVirtualFile files = 3; - RuntimeEvent event = 4; -} - -message PromoteRunVirtualFileTransactionRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - string lease_token = 2 [(buf.validate.field).string.min_len = 1]; - string transaction_id = 3 [(buf.validate.field).string.min_len = 1]; - string expected_parent_revision_id = 4; - string approver_id = 5; - map metadata = 6; -} - -message PromoteRunVirtualFileTransactionResponse { - AgentRun run = 1; - repeated AgentRunArtifact artifacts = 2; - repeated RuntimeVirtualFile files = 3; - RuntimeEvent event = 4; -} - -enum RuntimeVirtualFileTransactionApplyStatus { - RUNTIME_VIRTUAL_FILE_TRANSACTION_APPLY_STATUS_UNSPECIFIED = 0; - RUNTIME_VIRTUAL_FILE_TRANSACTION_APPLY_STATUS_CLEAN = 1; - RUNTIME_VIRTUAL_FILE_TRANSACTION_APPLY_STATUS_IDENTICAL = 2; - RUNTIME_VIRTUAL_FILE_TRANSACTION_APPLY_STATUS_CONFLICT = 3; - RUNTIME_VIRTUAL_FILE_TRANSACTION_APPLY_STATUS_MISSING_BASE = 4; - RUNTIME_VIRTUAL_FILE_TRANSACTION_APPLY_STATUS_MISSING_TARGET = 5; -} - -enum RuntimeVirtualFileTransactionOutcome { - RUNTIME_VIRTUAL_FILE_TRANSACTION_OUTCOME_UNSPECIFIED = 0; - RUNTIME_VIRTUAL_FILE_TRANSACTION_OUTCOME_CLEAN = 1; - RUNTIME_VIRTUAL_FILE_TRANSACTION_OUTCOME_APPLIED = 2; - RUNTIME_VIRTUAL_FILE_TRANSACTION_OUTCOME_REBASED = 3; - RUNTIME_VIRTUAL_FILE_TRANSACTION_OUTCOME_CONFLICT = 4; - RUNTIME_VIRTUAL_FILE_TRANSACTION_OUTCOME_NOOP = 5; -} - -message RuntimeVirtualFileDiffHunk { - int32 old_start_line = 1 [(buf.validate.field).int32.gte = 0]; - int32 old_line_count = 2 [(buf.validate.field).int32.gte = 0]; - int32 new_start_line = 3 [(buf.validate.field).int32.gte = 0]; - int32 new_line_count = 4 [(buf.validate.field).int32.gte = 0]; - string header = 5; - string unified_diff = 6; -} - -message RuntimeVirtualFileTransactionFileDiff { - string path = 1; - RuntimeVirtualFileOperation operation = 2 [(buf.validate.field).enum.defined_only = true]; - RuntimeVirtualFileTransactionApplyStatus apply_status = 3 [(buf.validate.field).enum.defined_only = true]; - string parent_revision_id = 4; - string base_revision_id = 5; - string current_revision_id = 6; - string proposed_revision_id = 7; - string base_content_sha256 = 8; - string current_content_sha256 = 9; - string proposed_content_sha256 = 10; - int32 additions = 11 [(buf.validate.field).int32.gte = 0]; - int32 deletions = 12 [(buf.validate.field).int32.gte = 0]; - bool binary = 13; - bool tombstone = 14; - string rename_from = 15; - string rename_to = 16; - string unified_diff = 17; - repeated RuntimeVirtualFileDiffHunk hunks = 18; -} - -message RuntimeVirtualFileTransactionConflict { - string path = 1; - RuntimeVirtualFileReasonCode reason_code = 2 [(buf.validate.field).enum.defined_only = true]; - RuntimeVirtualFileTransactionApplyStatus apply_status = 3 [(buf.validate.field).enum.defined_only = true]; - string message = 4; - string parent_revision_id = 5; - string base_revision_id = 6; - string current_revision_id = 7; - string proposed_revision_id = 8; - repeated RuntimeVirtualFileDiffHunk hunks = 9; -} - -message RuntimeVirtualFileTransactionDiff { - string transaction_id = 1; - repeated RuntimeVirtualFileTransactionFileDiff files = 2; - string unified_diff = 3; - int32 file_count = 4 [(buf.validate.field).int32.gte = 0]; - int32 changed_file_count = 5 [(buf.validate.field).int32.gte = 0]; - int32 additions = 6 [(buf.validate.field).int32.gte = 0]; - int32 deletions = 7 [(buf.validate.field).int32.gte = 0]; - bool stale = 8; - RuntimeVirtualFileTransactionOutcome outcome = 9 [(buf.validate.field).enum.defined_only = true]; - repeated RuntimeVirtualFileTransactionConflict conflicts = 10; -} - -message DiffRunVirtualFileTransactionRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - string transaction_id = 2 [(buf.validate.field).string.min_len = 1]; - int32 context_lines = 3 [(buf.validate.field).int32.gte = 0]; -} - -message DiffRunVirtualFileTransactionResponse { - RuntimeVirtualFileTransactionDiff diff = 1; -} - -message ApplyRunVirtualFileTransactionRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - string lease_token = 2 [(buf.validate.field).string.min_len = 1]; - string transaction_id = 3 [(buf.validate.field).string.min_len = 1]; - string expected_parent_revision_id = 4; - string approver_id = 5; - map metadata = 6; - int32 context_lines = 7 [(buf.validate.field).int32.gte = 0]; -} - -message ApplyRunVirtualFileTransactionResponse { - RuntimeVirtualFileTransactionOutcome outcome = 1 [(buf.validate.field).enum.defined_only = true]; - RuntimeVirtualFileTransactionDiff diff = 2; - AgentRun run = 3; - repeated AgentRunArtifact artifacts = 4; - repeated RuntimeVirtualFile files = 5; - RuntimeEvent event = 6; -} - -message RebaseRunVirtualFileTransactionRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - string lease_token = 2 [(buf.validate.field).string.min_len = 1]; - string source_transaction_id = 3 [(buf.validate.field).string.min_len = 1]; - string transaction_id = 4; - map metadata = 5; - string idempotency_key = 6; - int32 context_lines = 7 [(buf.validate.field).int32.gte = 0]; -} - -message RebaseRunVirtualFileTransactionResponse { - RuntimeVirtualFileTransactionOutcome outcome = 1 [(buf.validate.field).enum.defined_only = true]; - string source_transaction_id = 2; - string transaction_id = 3; - RuntimeVirtualFileTransactionDiff diff = 4; - AgentRun run = 5; - repeated AgentRunArtifact artifacts = 6; - repeated RuntimeVirtualFile files = 7; - RuntimeEvent event = 8; -} - -message HydrateRunVirtualFileMountRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; - string lease_token = 2 [(buf.validate.field).string.min_len = 1]; - string mount = 3 [(buf.validate.field).string.min_len = 1]; - string provider_id = 4; - string connection_id = 5; - string query = 6; - int32 limit = 7 [(buf.validate.field).int32.gte = 0]; - map metadata = 8; - string idempotency_key = 9; -} - -message HydrateRunVirtualFileMountResponse { - AgentRun run = 1; - repeated AgentRunArtifact artifacts = 2; - repeated RuntimeVirtualFile files = 3; - RuntimeEvent event = 4; -} - -message InspectRunVirtualFilesRequest { - string run_id = 1 [(buf.validate.field).string.min_len = 1]; -} - -message RuntimeVirtualFileInspectorSummary { - int32 file_count = 1 [(buf.validate.field).int32.gte = 0]; - int32 mount_count = 2 [(buf.validate.field).int32.gte = 0]; - int32 transaction_count = 3 [(buf.validate.field).int32.gte = 0]; - int32 lazy_mount_count = 4 [(buf.validate.field).int32.gte = 0]; - int32 hydrated_file_count = 5 [(buf.validate.field).int32.gte = 0]; - int32 cerebro_candidate_count = 6 [(buf.validate.field).int32.gte = 0]; - int32 cerebro_ready_count = 7 [(buf.validate.field).int32.gte = 0]; - int32 accepted_file_count = 8 [(buf.validate.field).int32.gte = 0]; - int32 content_address_count = 9 [(buf.validate.field).int32.gte = 0]; - int32 hydration_cache_hit_count = 10 [(buf.validate.field).int32.gte = 0]; - int32 stale_transaction_count = 11 [(buf.validate.field).int32.gte = 0]; - int32 shadowed_file_count = 12 [(buf.validate.field).int32.gte = 0]; - int32 producer_count = 13 [(buf.validate.field).int32.gte = 0]; - int32 preview_only_file_count = 14 [(buf.validate.field).int32.gte = 0]; - int32 denied_file_count = 15 [(buf.validate.field).int32.gte = 0]; - int32 restricted_file_count = 16 [(buf.validate.field).int32.gte = 0]; - int32 tombstone_file_count = 17 [(buf.validate.field).int32.gte = 0]; - int32 delete_file_count = 18 [(buf.validate.field).int32.gte = 0]; - int32 rename_file_count = 19 [(buf.validate.field).int32.gte = 0]; -} - -message RuntimeVirtualFileInspectorMount { - string path = 1; - int32 file_count = 2 [(buf.validate.field).int32.gte = 0]; - int64 size_bytes = 3 [(buf.validate.field).int64.gte = 0]; - bool lazy = 4; - string provider_id = 5; - string connection_id = 6; - string cache_policy = 7; - string policy = 8; - string cerebro_index = 9; - int32 secret_ref_count = 10 [(buf.validate.field).int32.gte = 0]; - repeated string source_services = 11; - int32 preview_only_file_count = 12 [(buf.validate.field).int32.gte = 0]; - int32 denied_file_count = 13 [(buf.validate.field).int32.gte = 0]; - int32 restricted_file_count = 14 [(buf.validate.field).int32.gte = 0]; - repeated string capabilities = 15; - bool writable = 16; - bool read_only = 17; - bool generated = 18; - bool evidence_backed = 19; - bool externally_indexed = 20; -} - -message RuntimeVirtualFileInspectorTransaction { - string transaction_id = 1; - string view = 2; - string parent_revision_id = 3; - int32 file_count = 4 [(buf.validate.field).int32.gte = 0]; - string policy = 5; - string cerebro_index = 6; - repeated string content_addresses = 7; - int32 tombstone_file_count = 8 [(buf.validate.field).int32.gte = 0]; - int32 delete_file_count = 9 [(buf.validate.field).int32.gte = 0]; - int32 rename_file_count = 10 [(buf.validate.field).int32.gte = 0]; -} - -message RuntimeVirtualFileInspectorProducer { - string producer_service = 1; - string producer_kind = 2; - int32 file_count = 3 [(buf.validate.field).int32.gte = 0]; - int32 revision_count = 4 [(buf.validate.field).int32.gte = 0]; - repeated string runtime_event_ids = 5; - repeated string artifact_ids = 6; - repeated string step_ids = 7; - repeated string tool_execution_ids = 8; - repeated string trace_ids = 9; - repeated string hydration_ids = 10; - repeated string transaction_ids = 11; - repeated string parent_revision_ids = 12; -} - -message InspectRunVirtualFilesResponse { - RuntimeVirtualFileInspectorSummary summary = 1; - repeated RuntimeVirtualFileInspectorMount mounts = 2; - repeated RuntimeVirtualFileInspectorTransaction transactions = 3; - repeated RuntimeVirtualFileEntry entries = 4; - repeated RuntimeVirtualFileInspectorProducer producers = 5; -} - -// A provider-owned object the actor was viewing when a channel turn began. -// The edge converts Slack's polymorphic app_context JSON into this bounded -// contract; Platform may use the coordinates for governed source reads but -// must not treat them as tenant authority. -enum OperatingChannelContextEntityKind { - OPERATING_CHANNEL_CONTEXT_ENTITY_KIND_UNSPECIFIED = 0; - OPERATING_CHANNEL_CONTEXT_ENTITY_KIND_CHANNEL = 1; - OPERATING_CHANNEL_CONTEXT_ENTITY_KIND_MESSAGE = 2; - OPERATING_CHANNEL_CONTEXT_ENTITY_KIND_CANVAS = 3; - OPERATING_CHANNEL_CONTEXT_ENTITY_KIND_LIST = 4; -} - -message OperatingChannelContextEntity { - OperatingChannelContextEntityKind kind = 1 [(buf.validate.field).enum.defined_only = true]; - string provider_workspace_id = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 512 - }]; - string provider_channel_id = 3 [(buf.validate.field).string.max_len = 512]; - string provider_message_id = 4 [(buf.validate.field).string.max_len = 512]; - string provider_resource_id = 5 [(buf.validate.field).string.max_len = 512]; -} - -// Identity supplies these coordinates from its approved organization directory. -message EnsureOrganizationEmailRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; -} - -message EnsureOrganizationEmailResponse { - string organization_id = 1; - string workspace_id = 2; - string mailbox = 3; - string connection_id = 4; -} diff --git a/proto/agents/v1/agents.proto b/proto/agents/v1/agents.proto deleted file mode 100644 index 7c73268..0000000 --- a/proto/agents/v1/agents.proto +++ /dev/null @@ -1,1065 +0,0 @@ -syntax = "proto3"; - -package agents.v1; - -import "buf/validate/validate.proto"; -import "common/v1/authz.proto"; -import "common/v1/delivery.proto"; -import "common/v1/entity.proto"; -import "common/v1/risk.proto"; -import "common/v1/surface.proto"; -import "google/protobuf/struct.proto"; -import "google/protobuf/timestamp.proto"; - -option go_package = "github.com/evalops/platform/gen/go/agents/v1;agentsv1"; - -// AgentService manages agent definitions, versioned configuration, and -// cross-agent delegation. Every string agent_id in the platform (meter, -// objectives, approvals, governance, memory) resolves to an Agent record -// owned by this service. -service AgentService { - // Register creates a new agent definition. - rpc Register(RegisterRequest) returns (RegisterResponse) { - option (common.v1.required_scopes) = "agent-registry:write"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Get retrieves an agent by ID. - rpc Get(GetRequest) returns (GetResponse) { - option (common.v1.required_scopes) = "agent-registry:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // List returns agents matching the query filters. - rpc List(ListRequest) returns (ListResponse) { - option (common.v1.required_scopes) = "agent-registry:read"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Update modifies mutable agent metadata (name, description, surfaces). - rpc Update(UpdateRequest) returns (UpdateResponse) { - option (common.v1.required_scopes) = "agent-registry:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Deregister removes an agent from the registry. - rpc Deregister(DeregisterRequest) returns (DeregisterResponse) { - option (common.v1.required_scopes) = "agent-registry:write"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // PushConfig creates a new immutable configuration version for an agent. - // The agent's active_config_version advances atomically. - rpc PushConfig(PushConfigRequest) returns (PushConfigResponse) { - option (common.v1.required_scopes) = "agent-registry:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // GetConfig retrieves a specific configuration version. - rpc GetConfig(GetConfigRequest) returns (GetConfigResponse) { - option (common.v1.required_scopes) = "agent-registry:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // ListConfigs returns all configuration versions for an agent. - rpc ListConfigs(ListConfigsRequest) returns (ListConfigsResponse) { - option (common.v1.required_scopes) = "agent-registry:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // RollbackConfig atomically reverts an agent to a prior configuration version. - rpc RollbackConfig(RollbackConfigRequest) returns (RollbackConfigResponse) { - option (common.v1.required_scopes) = "agent-registry:write"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Delegate requests that another agent (or any agent with a matching - // capability) accept a unit of work. The delegation is tracked as a - // DelegationRecord and linked to the originating objective and optional - // workflow step. - rpc Delegate(DelegateRequest) returns (DelegateResponse) { - option (common.v1.required_scopes) = "agent-registry:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // ResolveDelegation records the outcome of a delegation. - rpc ResolveDelegation(ResolveDelegationRequest) returns (ResolveDelegationResponse) { - option (common.v1.required_scopes) = "agent-registry:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // RenewDelegationLease records observed remote progress for an active - // delegation so reserved target capacity is not reaped while work is healthy. - rpc RenewDelegationLease(RenewDelegationLeaseRequest) returns (RenewDelegationLeaseResponse) { - option (common.v1.required_scopes) = "agent-registry:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // ControlA2ADelegationTask sends a fenced operating-plane control request to - // the remote A2A task backing a Platform delegation. This is the Platform - // control surface for steering, collecting from, interrupting, or canceling - // a remote Maestro task or one of its subagent lanes. - rpc ControlA2ADelegationTask(ControlA2ADelegationTaskRequest) returns (ControlA2ADelegationTaskResponse) { - option (common.v1.required_scopes) = "agent-registry:write"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // GetDelegation retrieves a delegation record by ID. - rpc GetDelegation(GetDelegationRequest) returns (GetDelegationResponse) { - option (common.v1.required_scopes) = "agent-registry:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // ListDelegations returns delegations matching the query filters. - rpc ListDelegations(ListDelegationsRequest) returns (ListDelegationsResponse) { - option (common.v1.required_scopes) = "agent-registry:read"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // GetA2ADelegationGraph returns the server-owned swarm graph for a remote - // A2A delegation family. Callers may anchor the graph by root delegation id - // or by any child delegation id in the lineage. - rpc GetA2ADelegationGraph(GetA2ADelegationGraphRequest) returns (GetA2ADelegationGraphResponse) { - option (common.v1.required_scopes) = "agent-registry:read"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Heartbeat records agent liveness. The registry uses this to maintain - // presence state and route capability-based delegation requests. - rpc Heartbeat(HeartbeatRequest) returns (HeartbeatResponse) { - option (common.v1.required_scopes) = "agent-registry:write"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } -} - -// AgentStatus describes the operational state of an agent. -enum AgentStatus { - AGENT_STATUS_UNSPECIFIED = 0; - AGENT_STATUS_ACTIVE = 1; - AGENT_STATUS_IDLE = 2; - AGENT_STATUS_BUSY = 3; - AGENT_STATUS_OFFLINE = 4; - AGENT_STATUS_DEGRADED = 5; - AGENT_STATUS_SUSPENDED = 6; -} - -// DelegationStatus describes the lifecycle state of a delegation. -enum DelegationStatus { - DELEGATION_STATUS_UNSPECIFIED = 0; - DELEGATION_STATUS_PENDING = 1; - DELEGATION_STATUS_ACCEPTED = 2; - DELEGATION_STATUS_REJECTED = 3; - DELEGATION_STATUS_COMPLETED = 4; - DELEGATION_STATUS_FAILED = 5; - DELEGATION_STATUS_TIMED_OUT = 6; -} - -// A2ADelegationTaskControlMode describes the remote task-control action that -// Platform asks the target A2A peer to apply. -enum A2ADelegationTaskControlMode { - A2A_DELEGATION_TASK_CONTROL_MODE_UNSPECIFIED = 0; - A2A_DELEGATION_TASK_CONTROL_MODE_STEER = 1; - A2A_DELEGATION_TASK_CONTROL_MODE_FOLLOWUP = 2; - A2A_DELEGATION_TASK_CONTROL_MODE_COLLECT = 3; - A2A_DELEGATION_TASK_CONTROL_MODE_INTERRUPT = 4; - A2A_DELEGATION_TASK_CONTROL_MODE_CANCEL = 5; -} - -// Agent is the canonical agent definition record. -// The id field is the value stored in every agent_id / agent string field -// across the platform: meter/v1 RecordUsageRequest.agent_id, -// objectives/v1 Objective.agent_id, approvals/v1 ApprovalRequest.agent_id, -// governance/v1 EvaluateActionRequest.agent_id, memory/v1 Memory.agent, -// and events/v1 Change.actor_id when actor_type is "agent". -message Agent { - string id = 1; - string workspace_id = 2; - string name = 3; - string description = 4; - - // agent_type aligns with identity/v1 IntrospectResponse.agent_type and - // IssueAgentTokenRequest.agent_type. Examples: "sdr", "support", "coding", - // "ops", "research". - string agent_type = 5; - - // capabilities aligns with identity/v1 IntrospectResponse.capabilities and - // IssueAgentTokenRequest.capabilities. Used by capability-based delegation - // routing. Examples: "hubspot-write", "email-send", "code-review". - repeated string capabilities = 6; - - // surfaces this agent can operate on. Aligns with the surface field in - // meter/v1, objectives/v1, approvals/v1. Examples: "ensemble", "chat", - // "maestro", "conductor", "slack". - repeated string surfaces = 7; - - AgentStatus status = 8; - int32 active_config_version = 9; - string owner_id = 10; - google.protobuf.Timestamp last_heartbeat_at = 11; - google.protobuf.Timestamp created_at = 12; - google.protobuf.Timestamp updated_at = 13; - repeated common.v1.Surface surface_types = 14 [(buf.validate.field).repeated.items.enum = { - defined_only: true - not_in: [0] - }]; - - // a2a is the Platform-owned discovery projection for spec-native A2A peers. - // Remote agents use it to discover where to fetch the Agent Card, which - // transport/profile is supported, and which skills can be delegated to this - // agent or its child/subagent lanes. - AgentA2APeerProjection a2a = 15; - - // capacity is the registry-owned load projection used by fleet-scale - // delegation discovery and operator read models. - AgentCapacity capacity = 16; -} - -message AgentCapacity { - int32 current = 1; - int32 max = 2; - int32 remaining = 3; - int32 reserved_delegation_count = 4; -} - -message AgentA2APeerProjection { - string public_endpoint_url = 1; - string internal_endpoint_url = 2; - string agent_card_url = 3; - string protocol_binding = 4; - string protocol_version = 5; - repeated string supported_extensions = 6; - repeated AgentA2ASkill skills = 7; - repeated string security_schemes = 8; - google.protobuf.Timestamp agent_card_observed_at = 9; - string agent_card_etag = 10; - string agent_card_hash = 11; - bool push_notifications = 12; - map attributes = 13; -} - -message AgentA2ASkill { - string id = 1; - string name = 2; - string description = 3; - repeated string tags = 4; - repeated string input_modes = 5; - repeated string output_modes = 6; - repeated string required_context_grants = 7; - string approval_policy_ref = 8; - string max_autonomy = 9; - repeated string required_artifact_kinds = 10; - repeated string optional_artifact_kinds = 11; - repeated string allowed_task_classes = 12; - repeated string denied_task_classes = 13; - map attributes = 14; -} - -// AgentConfig is an immutable snapshot of everything that shapes an agent's -// behavior. Promotion and rollback are both config version reassignments — -// the same pattern as prompts/v1 Label. -message AgentConfig { - int32 version = 1; - string agent_id = 2; - - // skill_ids reference skills/v1 Skill.id — the reusable capabilities - // this agent has loaded. - repeated string skill_ids = 3; - - // prompt_bindings maps prompt name to label (e.g., "sdr-outreach" -> "production"). - // Aligns with prompts/v1 ResolveRequest.name and ResolveRequest.label. - map prompt_bindings = 4; - - // model_preferences maps surface to preferred model identifier - // (e.g., "ensemble" -> "claude-opus-4.6"). Aligns with meter/v1 - // RecordUsageRequest.model and keys/v1 ResolveProviderRefRequest.provider. - map model_preferences = 5; - - // integration_ids reference connectors/v1 Connection.id — the external - // system connections this agent is authorized to use. - repeated string integration_ids = 6; - - // entity_type_scopes restrict which entities/v1 EntityType values this - // agent can operate on. Empty means unrestricted. - repeated string entity_type_scopes = 7; - - // max_concurrent_objectives caps the number of objectives/v1 Objective - // records this agent can hold in RUNNING or BLOCKED state simultaneously. - int32 max_concurrent_objectives = 8; - - // cost_budget_usd is the per-period spend ceiling enforced against - // meter/v1 usage records for this agent. - double cost_budget_usd = 9; - - // notification_channel specifies the preferred notifications/v1 - // DeliveryChannel for this agent's escalations. Stored as string to - // avoid cross-package import (e.g., "DELIVERY_CHANNEL_SLACK"). - string notification_channel = 10; - - // parameters holds arbitrary agent-specific tuning knobs. - google.protobuf.Struct parameters = 11; - - string author = 12; - google.protobuf.Timestamp created_at = 13; - repeated common.v1.EntityType entity_type_scope_enums = 14; - common.v1.DeliveryChannel notification_channel_enum = 15; - DigitalTeammateProfile teammate_profile = 16; - // Portable provider needs. Connection IDs remain workspace-local bindings. - repeated ConnectorRequirement connector_requirements = 17; -} - -message ConnectorRequirement { - string provider_id = 1 [(buf.validate.field).string.min_len = 1]; - repeated string required_capabilities = 2; - repeated string optional_capabilities = 3; - bool required = 4; -} - -// TeammateLifecycle describes whether a teammate profile can be used to -// initiate durable work. -enum TeammateLifecycle { - TEAMMATE_LIFECYCLE_UNSPECIFIED = 0; - TEAMMATE_LIFECYCLE_DRAFT = 1; - TEAMMATE_LIFECYCLE_ACTIVE = 2; - TEAMMATE_LIFECYCLE_PAUSED = 3; - TEAMMATE_LIFECYCLE_DEPRECATED = 4; -} - -// CommitmentKind describes the durable commitments a teammate can accept. -enum CommitmentKind { - COMMITMENT_KIND_UNSPECIFIED = 0; - COMMITMENT_KIND_FOLLOW_UP = 1; - COMMITMENT_KIND_WATCH = 2; - COMMITMENT_KIND_RETRY = 3; - COMMITMENT_KIND_SUMMARIZE = 4; - COMMITMENT_KIND_MONITOR = 5; - COMMITMENT_KIND_REMEDIATE = 6; - COMMITMENT_KIND_HANDOFF = 7; -} - -// InitiativeTriggerKind describes events that can let a teammate start work -// without a fresh direct human prompt. -enum InitiativeTriggerKind { - INITIATIVE_TRIGGER_KIND_UNSPECIFIED = 0; - INITIATIVE_TRIGGER_KIND_SCHEDULE = 1; - INITIATIVE_TRIGGER_KIND_SLACK_EVENT = 2; - INITIATIVE_TRIGGER_KIND_PLATFORM_EVENT = 3; - INITIATIVE_TRIGGER_KIND_OBJECTIVE_WAKE = 4; - INITIATIVE_TRIGGER_KIND_WAIT_RESOLVED = 5; - INITIATIVE_TRIGGER_KIND_EVAL_REGRESSION = 6; - INITIATIVE_TRIGGER_KIND_STALLED_WORK = 7; -} - -// AutonomyAuthority describes how independently a teammate may act. -enum AutonomyAuthority { - AUTONOMY_AUTHORITY_UNSPECIFIED = 0; - AUTONOMY_AUTHORITY_OWN = 1; - AUTONOMY_AUTHORITY_RECOMMEND = 2; - AUTONOMY_AUTHORITY_REQUIRE_APPROVAL = 3; - AUTONOMY_AUTHORITY_DENY = 4; -} - -// PresenceEvent describes channel-visible teammate activity. -enum PresenceEvent { - PRESENCE_EVENT_UNSPECIFIED = 0; - PRESENCE_EVENT_ACCEPTED = 1; - PRESENCE_EVENT_WAITING = 2; - PRESENCE_EVENT_PROGRESS = 3; - PRESENCE_EVENT_BLOCKED = 4; - PRESENCE_EVENT_COMPLETED = 5; - PRESENCE_EVENT_FAILED = 6; - PRESENCE_EVENT_ESCALATED = 7; -} - -// TeammateChannelKind identifies a product or provider channel that can ingest -// user activity or render teammate runtime events. It intentionally lives in -// agents/v1 instead of agentruntime/v1 so teammate profiles can describe -// supported channels without creating a proto import cycle. -enum TeammateChannelKind { - TEAMMATE_CHANNEL_KIND_UNSPECIFIED = 0; - TEAMMATE_CHANNEL_KIND_SLACK = 1; - TEAMMATE_CHANNEL_KIND_EMAIL = 2; - TEAMMATE_CHANNEL_KIND_CALENDAR = 3; - TEAMMATE_CHANNEL_KIND_JIRA = 4; - TEAMMATE_CHANNEL_KIND_TEAMS = 5; - TEAMMATE_CHANNEL_KIND_WEB = 6; - TEAMMATE_CHANNEL_KIND_WEBHOOK = 7; - TEAMMATE_CHANNEL_KIND_WHATSAPP = 8; - TEAMMATE_CHANNEL_KIND_APPLE_MESSAGES = 9; -} - -// TeammateChannelCapability describes what a channel adapter can do for a -// teammate profile. -enum TeammateChannelCapability { - TEAMMATE_CHANNEL_CAPABILITY_UNSPECIFIED = 0; - TEAMMATE_CHANNEL_CAPABILITY_INGEST = 1; - TEAMMATE_CHANNEL_CAPABILITY_RENDER = 2; -} - -// TeammateChannelEventKind describes normalized inbound channel events that can -// become AgentRuntime triggers. -enum TeammateChannelEventKind { - TEAMMATE_CHANNEL_EVENT_KIND_UNSPECIFIED = 0; - TEAMMATE_CHANNEL_EVENT_KIND_MESSAGE_CREATED = 1; - TEAMMATE_CHANNEL_EVENT_KIND_THREAD_REPLY_CREATED = 2; - TEAMMATE_CHANNEL_EVENT_KIND_COMMAND_INVOKED = 3; - TEAMMATE_CHANNEL_EVENT_KIND_ACTION_INVOKED = 4; - TEAMMATE_CHANNEL_EVENT_KIND_REACTION_ADDED = 5; - TEAMMATE_CHANNEL_EVENT_KIND_REACTION_REMOVED = 6; - TEAMMATE_CHANNEL_EVENT_KIND_ASSISTANT_THREAD_STARTED = 7; - TEAMMATE_CHANNEL_EVENT_KIND_ASSISTANT_THREAD_CONTEXT_CHANGED = 8; - TEAMMATE_CHANNEL_EVENT_KIND_EMAIL_RECEIVED = 9; - TEAMMATE_CHANNEL_EVENT_KIND_CALENDAR_EVENT_CHANGED = 10; - TEAMMATE_CHANNEL_EVENT_KIND_ISSUE_CHANGED = 11; - TEAMMATE_CHANNEL_EVENT_KIND_SCHEDULED_WAKE = 12; - TEAMMATE_CHANNEL_EVENT_KIND_WEBHOOK_RECEIVED = 13; -} - -// TeammateRuntimeRenderEventKind describes Platform runtime events a channel -// adapter can project back into the provider surface. -enum TeammateRuntimeRenderEventKind { - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_UNSPECIFIED = 0; - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_TRIGGER_ACCEPTED = 1; - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_RUN_STARTED = 2; - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_PROGRESS = 3; - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_STEP_STARTED = 4; - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_STEP_COMPLETED = 5; - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_OBJECTIVE_UPDATED = 6; - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_APPROVAL_REQUESTED = 7; - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_APPROVAL_RESOLVED = 8; - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_TOOL_PROPOSED = 9; - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_TOOL_COMPLETED = 10; - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_ARTIFACT_CREATED = 11; - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_MEMORY_PROPOSED = 12; - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_WAITING = 13; - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_RESUMED = 14; - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_COMPLETED = 15; - TEAMMATE_RUNTIME_RENDER_EVENT_KIND_FAILED = 16; -} - -// DigitalTeammateProfile is the versioned contract for how an AgentConfig acts -// as a durable teammate across objectives, workflows, tools, memory, evals, and -// Slack or other delivery surfaces. -message DigitalTeammateProfile { - string id = 1; - int32 version = 2; - string workspace_id = 3; - string agent_id = 4; - - string display_name = 5; - string role = 6; - string purpose = 7; - string owner_user_id = 8; - string owner_team_id = 9; - - repeated common.v1.Surface surface_types = 10 [(buf.validate.field).repeated.items.enum = { - defined_only: true - not_in: [0] - }]; - TeammateLifecycle lifecycle = 11 [(buf.validate.field).enum.defined_only = true]; - - repeated TeammateResponsibility responsibilities = 12; - CommitmentPolicy commitment_policy = 13; - InitiativePolicy initiative_policy = 14; - AutonomyPolicy autonomy_policy = 15; - MemoryPolicy memory_policy = 16; - PresencePolicy presence_policy = 17; - OutputPolicy output_policy = 18; - EvalPolicy eval_policy = 19; - EscalationPolicy escalation_policy = 20; - - map labels = 21; - google.protobuf.Struct parameters = 22; - google.protobuf.Timestamp created_at = 23; - google.protobuf.Timestamp updated_at = 24; - repeated TeammateChannelManifest channel_manifests = 25; -} - -// TeammateChannelManifest describes one channel adapter supported by a -// teammate profile. Durable execution remains owned by AgentRuntime; this -// manifest lets product surfaces declare the provider-specific ingress and -// rendering coverage they can project. -message TeammateChannelManifest { - TeammateChannelKind kind = 1 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string label = 2; - common.v1.DeliveryChannel delivery_channel = 3 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - common.v1.Surface platform_surface = 4 [(buf.validate.field).enum.defined_only = true]; - string channel_id = 5; - repeated TeammateChannelCapability capabilities = 6 [(buf.validate.field).repeated.items.enum = { - defined_only: true - not_in: [0] - }]; - repeated TeammateChannelEventKind inbound_events = 7 [(buf.validate.field).repeated.items.enum = { - defined_only: true - not_in: [0] - }]; - repeated TeammateRuntimeRenderEventKind runtime_events = 8 [(buf.validate.field).repeated.items.enum = { - defined_only: true - not_in: [0] - }]; - map attributes = 9; -} - -// TeammateResponsibility binds a role claim to capabilities, entities, prompts, -// skills, and measurable outcomes. -message TeammateResponsibility { - string id = 1; - string title = 2; - string description = 3; - repeated string capability_refs = 4; - repeated common.v1.EntityType owned_entity_types = 5 [(buf.validate.field).repeated.items.enum = { - defined_only: true - not_in: [0] - }]; - repeated string default_skill_ids = 6; - repeated string prompt_names = 7; - repeated string success_metric_refs = 8; -} - -// CommitmentPolicy describes which durable objectives and wakes can be created -// from teammate commitments. -message CommitmentPolicy { - repeated CommitmentKind allowed_kinds = 1 [(buf.validate.field).repeated.items.enum = { - defined_only: true - not_in: [0] - }]; - repeated CommitmentTemplate templates = 2; - int32 default_due_seconds = 3 [(buf.validate.field).int32.gte = 0]; - int32 max_open_commitments = 4 [(buf.validate.field).int32.gte = 0]; - bool require_objective_for_commitment = 5; -} - -// CommitmentTemplate maps a commitment kind to objective and wake templates. -message CommitmentTemplate { - CommitmentKind kind = 1 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string objective_title_template = 2; - string objective_description_template = 3; - string wake_reason_template = 4; - repeated string required_join_keys = 5; -} - -// InitiativePolicy describes bounded conditions where a teammate can start or -// resume work proactively. -message InitiativePolicy { - repeated InitiativeTrigger triggers = 1; - int32 max_initiated_runs_per_day = 2 [(buf.validate.field).int32.gte = 0]; - bool require_human_seed = 3; -} - -// InitiativeTrigger binds a proactive trigger to workflow or objective state. -message InitiativeTrigger { - InitiativeTriggerKind kind = 1 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string trigger_ref = 2; - string filter_expr = 3; - string workflow_definition_id = 4; - string objective_template_id = 5; -} - -// AutonomyPolicy describes the default authority and specific action rules -// that ToolExecution, Governance, and Approvals can enforce. -message AutonomyPolicy { - repeated AutonomyRule rules = 1; - AutonomyAuthority default_authority = 2 [(buf.validate.field).enum.defined_only = true]; - common.v1.RiskLevel max_risk_without_approval = 3 [(buf.validate.field).enum.defined_only = true]; -} - -// AutonomyRule constrains a class of actions or tool capabilities. -message AutonomyRule { - string action_type = 1; - string tool_capability = 2; - common.v1.RiskLevel max_risk = 3 [(buf.validate.field).enum.defined_only = true]; - AutonomyAuthority authority = 4 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string approval_policy_ref = 5; - string governance_policy_ref = 6; - string rationale = 7; -} - -// MemoryPolicy describes what a teammate may recall or propose remembering. -message MemoryPolicy { - repeated string allowed_scope_refs = 1; - bool allow_user_memory = 2; - bool allow_team_memory = 3; - bool allow_agent_memory = 4; - bool require_review_for_new_memory = 5; - int32 default_retention_days = 6 [(buf.validate.field).int32.gte = 0]; - repeated string required_source_types = 7; - bool allow_cross_channel_recall = 8; -} - -// PresencePolicy describes how a teammate reports work back to Slack or other -// delivery channels. -message PresencePolicy { - common.v1.DeliveryChannel primary_channel = 1 [(buf.validate.field).enum.defined_only = true]; - string primary_channel_id = 2; - string default_thread_policy = 3; - int32 progress_update_interval_seconds = 4 [(buf.validate.field).int32.gte = 0]; - repeated PresenceEvent visible_events = 5 [(buf.validate.field).repeated.items.enum = { - defined_only: true - not_in: [0] - }]; - bool post_action_receipts = 6; - bool post_blocker_updates = 7; -} - -// OutputPolicy describes durable work products and channel-safe renderings. -message OutputPolicy { - repeated string required_artifact_kinds = 1; - repeated string optional_artifact_kinds = 2; - bool render_channel_cards = 3; - string default_visibility = 4; -} - -// EvalPolicy binds production behavior to loop and eval scoring. -message EvalPolicy { - repeated EvalBinding bindings = 1; - string loop_definition_id = 2; - int32 production_sample_rate_basis_points = 3 [(buf.validate.field).int32 = { - gte: 0 - lte: 10000 - }]; -} - -// EvalBinding describes one score that should gate or monitor teammate quality. -message EvalBinding { - string suite_name = 1; - string metric_name = 2; - double minimum_score = 3; - string failure_action = 4; -} - -// EscalationPolicy describes who must be contacted when the teammate blocks or -// needs approval. -message EscalationPolicy { - repeated string approver_user_ids = 1; - repeated string approver_team_ids = 2; - int32 escalate_after_seconds = 3 [(buf.validate.field).int32.gte = 0]; - common.v1.DeliveryChannel fallback_channel = 4 [(buf.validate.field).enum.defined_only = true]; -} - -// DelegationRecord tracks a typed hand-off between agents. The from_agent_id -// creates an objective (objectives/v1) or references a workflow step -// (workflows/v1 StepRun) and delegates execution to another agent resolved -// by ID or by capability through the registry. -message DelegationRecord { - string id = 1; - string workspace_id = 2; - string from_agent_id = 3; - string to_agent_id = 4; - string required_capability = 5; - - // objective_id links to the objectives/v1 Objective created for this - // delegated unit of work. - string objective_id = 6; - - // workflow_run_id and workflow_step_id link to workflows/v1 when this - // delegation occurs within a workflow execution. - string workflow_run_id = 7; - string workflow_step_id = 8; - - DelegationStatus status = 9; - bytes context_payload = 10; - bytes result_payload = 11; - string reason = 12; - string error_message = 13; - google.protobuf.Timestamp created_at = 14; - google.protobuf.Timestamp resolved_at = 15; - string a2a_task_id = 16; - string a2a_message_id = 17; - string a2a_endpoint_url = 18; - string a2a_dispatch_status = 19; - string a2a_dispatch_error = 20; - string a2a_skill_id = 21; - - // a2a_dispatched_at is the server time when the remote A2A task was first - // accepted by the target transport. - google.protobuf.Timestamp a2a_dispatched_at = 22; - - // a2a_lease_renewed_at is the last server time Platform observed remote A2A - // progress for this delegation. - google.protobuf.Timestamp a2a_lease_renewed_at = 23; - - // a2a_resume_wait_contracts are server-derived contracts that an origin - // runtime can use to park the parent run on typed remote A2A callback events - // after the target transport accepts the delegation. - repeated google.protobuf.Struct a2a_resume_wait_contracts = 24; - - // a2a_root_delegation_id identifies the root Platform delegation in an A2A - // swarm chain. Root delegations use their own delegation id. - string a2a_root_delegation_id = 25; - - // a2a_parent_delegation_id identifies the immediate parent Platform - // delegation when this record was spawned by another remote A2A worker. - string a2a_parent_delegation_id = 26; - - // a2a_delegation_chain is the ordered Platform delegation lineage from root - // to this delegation. - repeated string a2a_delegation_chain = 27; -} - -// --------------------------------------------------------------------------- -// RPC request/response messages -// --------------------------------------------------------------------------- - -message RegisterRequest { - string workspace_id = 1; - string name = 2; - string description = 3; - string agent_type = 4; - repeated string capabilities = 5 [(buf.validate.field).repeated.min_items = 1]; - repeated string surfaces = 6; - string owner_id = 7; - string id = 8; - repeated common.v1.Surface surface_types = 9 [(buf.validate.field).repeated.items.enum = { - defined_only: true - not_in: [0] - }]; - AgentA2APeerProjection a2a = 10; -} - -message RegisterResponse { - Agent agent = 1; -} - -message GetRequest { - string id = 1 [(buf.validate.field).string.min_len = 1]; -} - -message GetResponse { - Agent agent = 1; -} - -message ListRequest { - string workspace_id = 1; - string agent_type = 2; - string capability = 3; - string surface = 4; - AgentStatus status = 5; - int32 limit = 6 [(buf.validate.field).int32 = { - gte: 0 - lte: 200 - }]; - int32 offset = 7 [(buf.validate.field).int32.gte = 0]; - common.v1.Surface surface_type = 8 [(buf.validate.field).enum.defined_only = true]; - // A2A skill ID required for fleet-scale delegation discovery. - string a2a_skill_id = 9; - // Task class that must be allowed by the matched peer or skill policy. - string task_class = 10; - // Require peers to expose a dispatchable A2A HTTP+JSON endpoint. - bool require_a2a_dispatch = 11; - // Use delegation-eligible discovery semantics even when only generic filters are supplied. - bool eligible_for_delegation = 12; -} - -message ListResponse { - repeated Agent agents = 1; - int32 total = 2; - AgentDiscoveryEvidence discovery_evidence = 3; -} - -// AgentDiscoveryEvidence is the safe, operator-auditable explanation for an -// A2A/delegation discovery query. It intentionally carries identifiers, -// counts, and policy labels, not task payloads or customer content. -message AgentDiscoveryEvidence { - string schema = 1; - string decision = 2; - string reason = 3; - string workspace_id = 4; - string capability = 5; - repeated string capabilities = 6; - string agent_type = 7; - string a2a_skill_id = 8; - string task_class = 9; - bool require_a2a_dispatch = 10; - string surface = 11; - string status = 12; - int32 candidate_count = 13; - int32 matched_count = 14; - repeated AgentDiscoveryExclusion exclusions = 15; -} - -// AgentDiscoveryExclusion summarizes why candidates did not appear in the -// discovery result. Samples are agent ids only, capped by the server. -message AgentDiscoveryExclusion { - string reason = 1; - int32 count = 2; - repeated string sample_agent_ids = 3; - repeated string policy_reasons = 4; - repeated string policy_scopes = 5; - repeated string allowed_task_classes = 6; - repeated string denied_task_classes = 7; -} - -message UpdateRequest { - string id = 1 [(buf.validate.field).string.min_len = 1]; - string name = 2; - string description = 3; - repeated string capabilities = 4; - repeated string surfaces = 5; - repeated common.v1.Surface surface_types = 6 [(buf.validate.field).repeated.items.enum = { - defined_only: true - not_in: [0] - }]; - AgentA2APeerProjection a2a = 7; -} - -message UpdateResponse { - Agent agent = 1; -} - -message DeregisterRequest { - string id = 1 [(buf.validate.field).string.min_len = 1]; - string reason = 2; -} - -message DeregisterResponse {} - -message PushConfigRequest { - string agent_id = 1 [(buf.validate.field).string.min_len = 1]; - repeated string skill_ids = 2; - map prompt_bindings = 3; - map model_preferences = 4; - repeated string integration_ids = 5; - repeated string entity_type_scopes = 6; - int32 max_concurrent_objectives = 7; - double cost_budget_usd = 8; - string notification_channel = 9; - google.protobuf.Struct parameters = 10; - string author = 11; - repeated common.v1.EntityType entity_type_scope_enums = 12; - common.v1.DeliveryChannel notification_channel_enum = 13; - DigitalTeammateProfile teammate_profile = 14; - repeated ConnectorRequirement connector_requirements = 15; -} - -message PushConfigResponse { - AgentConfig config = 1; - Agent agent = 2; -} - -message GetConfigRequest { - string agent_id = 1 [(buf.validate.field).string.min_len = 1]; - int32 version = 2 [(buf.validate.field).int32.gt = 0]; -} - -message GetConfigResponse { - AgentConfig config = 1; -} - -message ListConfigsRequest { - string agent_id = 1 [(buf.validate.field).string.min_len = 1]; - int32 limit = 2 [(buf.validate.field).int32 = { - gte: 0 - lte: 200 - }]; - int32 offset = 3 [(buf.validate.field).int32.gte = 0]; -} - -message ListConfigsResponse { - repeated AgentConfig configs = 1; - int32 total = 2; - bool has_more = 3; -} - -message RollbackConfigRequest { - string agent_id = 1 [(buf.validate.field).string.min_len = 1]; - int32 target_version = 2 [(buf.validate.field).int32.gt = 0]; - string actor = 3; - string reason = 4; -} - -message RollbackConfigResponse { - AgentConfig config = 1; - Agent agent = 2; -} - -message DelegateRequest { - string from_agent_id = 1 [(buf.validate.field).string.min_len = 1]; - // Specify to_agent_id for direct delegation, or required_capability for - // capability-based routing through the registry. - string to_agent_id = 2; - string required_capability = 3; - string objective_id = 4; - string workflow_run_id = 5; - string workflow_step_id = 6; - bytes context_payload = 7; - string reason = 8; - string a2a_skill_id = 9; -} - -message DelegateResponse { - DelegationRecord delegation = 1; -} - -message ResolveDelegationRequest { - string delegation_id = 1 [(buf.validate.field).string.min_len = 1]; - DelegationStatus status = 2 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - bytes result_payload = 3; - string error_message = 4; -} - -message ResolveDelegationResponse { - DelegationRecord delegation = 1; -} - -message RenewDelegationLeaseRequest { - string delegation_id = 1 [(buf.validate.field).string.min_len = 1]; -} - -message RenewDelegationLeaseResponse { - DelegationRecord delegation = 1; -} - -message ControlA2ADelegationTaskRequest { - string delegation_id = 1 [(buf.validate.field).string.min_len = 1]; - A2ADelegationTaskControlMode mode = 2 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string message = 3; - string idempotency_key = 4; - - // Optional target selectors allow Platform callers to control a remote - // subagent lane or child run while still fencing the command by the root - // remote task id stored on the delegation. - string target_run_id = 5; - string child_run_id = 6; - string subagent_lane_id = 7; - string work_item_id = 8; - google.protobuf.Struct payload = 9; - google.protobuf.Struct metadata = 10; -} - -message A2ADelegationTaskControlResult { - string task_id = 1; - string state = 2; - string control_id = 3; - string control_mode = 4; - bool cancelled = 5; - bool queued_for_worker = 6; - string parent_task_id = 7; - string target_run_id = 8; - string applied_run_id = 9; - bool target_external = 10; - string subagent_lane_id = 11; - string work_item_id = 12; - google.protobuf.Timestamp observed_at = 13; - bool raw_payload_withheld = 14; -} - -message ControlA2ADelegationTaskResponse { - DelegationRecord delegation = 1; - A2ADelegationTaskControlResult remote_task = 2; -} - -message GetDelegationRequest { - string id = 1 [(buf.validate.field).string.min_len = 1]; -} - -message GetDelegationResponse { - DelegationRecord delegation = 1; -} - -message ListDelegationsRequest { - string workspace_id = 1; - string from_agent_id = 2; - string to_agent_id = 3; - DelegationStatus status = 4; - string workflow_run_id = 5; - int32 limit = 6; - int32 offset = 7; - // A2A remote task id returned by the target peer. - string a2a_task_id = 8; - // A2A message id used for dispatch/callback correlation. - string a2a_message_id = 9; - // A2A skill id requested for the delegation. - string a2a_skill_id = 10; - // A2A transport dispatch status recorded by Platform. - string a2a_dispatch_status = 11; - // Root Platform delegation id for a remote A2A swarm chain. - string a2a_root_delegation_id = 12; - // Immediate parent Platform delegation id for a remote A2A swarm chain. - string a2a_parent_delegation_id = 13; - // Limit results to delegations that have A2A transport or swarm lineage. - bool a2a_only = 14; -} - -message ListDelegationsResponse { - repeated DelegationRecord delegations = 1; - int32 total = 2; -} - -message GetA2ADelegationGraphRequest { - string workspace_id = 1; - // Root Platform delegation id for the swarm graph. - string root_delegation_id = 2; - // Any Platform delegation id in the swarm graph. If provided without - // root_delegation_id, the server derives the root from recorded lineage. - string delegation_id = 3; - // Maximum child depth to return from the root. Zero means no depth limit. - int32 max_depth = 4 [(buf.validate.field).int32 = { - gte: 0 - lte: 100 - }]; - // Maximum graph nodes to return. Zero uses the server default. - int32 limit = 5 [(buf.validate.field).int32 = { - gte: 0 - lte: 1000 - }]; -} - -message A2ADelegationGraphNode { - DelegationRecord delegation = 1; - int32 depth = 2; - int32 child_count = 3; - bool terminal = 4; -} - -message A2ADelegationGraphEdge { - string parent_delegation_id = 1; - string child_delegation_id = 2; -} - -message GetA2ADelegationGraphResponse { - string root_delegation_id = 1; - repeated A2ADelegationGraphNode nodes = 2; - repeated A2ADelegationGraphEdge edges = 3; - int32 total = 4; - bool truncated = 5; - repeated string missing_parent_delegation_ids = 6; -} - -message HeartbeatRequest { - string agent_id = 1 [(buf.validate.field).string.min_len = 1]; - AgentStatus status = 2; - // current_objective_ids lists the objectives/v1 Objective.id values this - // agent currently holds. Used for capacity-aware delegation routing. - repeated string current_objective_ids = 3; - string surface = 4; - common.v1.Surface surface_type = 5 [(buf.validate.field).enum.defined_only = true]; - AgentA2APeerProjection a2a = 6; -} - -message HeartbeatResponse { - google.protobuf.Timestamp next_heartbeat_by = 1; -} diff --git a/proto/codex/v1/codex.proto b/proto/codex/v1/codex.proto deleted file mode 100644 index 8eb4c0d..0000000 --- a/proto/codex/v1/codex.proto +++ /dev/null @@ -1,387 +0,0 @@ -syntax = "proto3"; - -package codex.v1; - -option go_package = "github.com/evalops/platform/gen/go/codex/v1;codexv1"; - -import "buf/validate/validate.proto"; -import "google/protobuf/struct.proto"; -import "google/protobuf/timestamp.proto"; - -// CodexActionType describes the user intent that should shape prompting, -// permissions, routing, and output expectations for a Codex run. -enum CodexActionType { - CODEX_ACTION_TYPE_UNSPECIFIED = 0; - CODEX_ACTION_TYPE_START_WORK = 1; - CODEX_ACTION_TYPE_FOLLOW_UP = 2; - CODEX_ACTION_TYPE_INVESTIGATE = 3; - CODEX_ACTION_TYPE_FIX = 4; - CODEX_ACTION_TYPE_REVIEW = 5; - CODEX_ACTION_TYPE_TEST = 6; - CODEX_ACTION_TYPE_EXPLAIN = 7; - CODEX_ACTION_TYPE_RETRY = 8; - CODEX_ACTION_TYPE_FORK = 9; -} - -// CodexBackend identifies the execution backend selected for a run. -enum CodexBackend { - CODEX_BACKEND_UNSPECIFIED = 0; - CODEX_BACKEND_APP_SERVER = 1; - CODEX_BACKEND_CODEX_SDK = 2; - CODEX_BACKEND_CLAUDE_CODE = 3; - CODEX_BACKEND_INTERNAL_AGENT = 4; - CODEX_BACKEND_MODEL_TRIAGE = 5; -} - -// CodexExecutionIntent captures the expected risk and write profile. -enum CodexExecutionIntent { - CODEX_EXECUTION_INTENT_UNSPECIFIED = 0; - CODEX_EXECUTION_INTENT_READ_ONLY_DIAGNOSIS = 1; - CODEX_EXECUTION_INTENT_PATCH_AND_VERIFY = 2; - CODEX_EXECUTION_INTENT_REVIEW_ONLY = 3; - CODEX_EXECUTION_INTENT_TEST_AUTHORING = 4; - CODEX_EXECUTION_INTENT_EXPLANATION = 5; -} - -// CodexInteractivityMode controls how much of the run is projected back to a -// human conversation surface. -enum CodexInteractivityMode { - CODEX_INTERACTIVITY_MODE_UNSPECIFIED = 0; - CODEX_INTERACTIVITY_MODE_BACKGROUND = 1; - CODEX_INTERACTIVITY_MODE_THREAD_CONVERSATION = 2; - CODEX_INTERACTIVITY_MODE_HUMAN_APPROVAL_GATED = 3; -} - -// CodexAuthorityScope is the maximum local filesystem authority requested for -// delegated work. Platform policy, device mappings, and native confirmation -// may only narrow this value. -enum CodexAuthorityScope { - CODEX_AUTHORITY_SCOPE_UNSPECIFIED = 0; - CODEX_AUTHORITY_SCOPE_DISCUSS_ONLY = 1; - CODEX_AUTHORITY_SCOPE_READ_ONLY = 2; - CODEX_AUTHORITY_SCOPE_WORKSPACE_WRITE = 3; -} - -// CodexVerificationStatus records whether the bounded result was verified. -enum CodexVerificationStatus { - CODEX_VERIFICATION_STATUS_UNSPECIFIED = 0; - CODEX_VERIFICATION_STATUS_NOT_RUN = 1; - CODEX_VERIFICATION_STATUS_PASSED = 2; - CODEX_VERIFICATION_STATUS_FAILED = 3; - CODEX_VERIFICATION_STATUS_PARTIAL = 4; -} - -// CodexGitState records the repository state without embedding branch prose. -enum CodexGitState { - CODEX_GIT_STATE_UNSPECIFIED = 0; - CODEX_GIT_STATE_UNCHANGED = 1; - CODEX_GIT_STATE_DIRTY = 2; - CODEX_GIT_STATE_COMMITTED = 3; -} - -// CodexInteractionType describes a channel-native control action. -enum CodexInteractionType { - CODEX_INTERACTION_TYPE_UNSPECIFIED = 0; - CODEX_INTERACTION_TYPE_APPROVE_PLAN = 1; - CODEX_INTERACTION_TYPE_REJECT_PLAN = 2; - CODEX_INTERACTION_TYPE_APPLY_PATCH = 3; - CODEX_INTERACTION_TYPE_DISCARD_PATCH = 4; - CODEX_INTERACTION_TYPE_STOP_TURN = 5; - CODEX_INTERACTION_TYPE_RETRY_TURN = 6; - CODEX_INTERACTION_TYPE_FORK_THREAD = 7; - CODEX_INTERACTION_TYPE_APPROVE_COMMAND = 8; - CODEX_INTERACTION_TYPE_PROVIDE_INPUT = 9; -} - -// CodexContextSourceKind names a structured context source enriched before a -// run reaches the worker. -enum CodexContextSourceKind { - CODEX_CONTEXT_SOURCE_KIND_UNSPECIFIED = 0; - CODEX_CONTEXT_SOURCE_KIND_SLACK_MESSAGE = 1; - CODEX_CONTEXT_SOURCE_KIND_SLACK_THREAD = 2; - CODEX_CONTEXT_SOURCE_KIND_GITHUB_PULL_REQUEST = 3; - CODEX_CONTEXT_SOURCE_KIND_GITHUB_ISSUE = 4; - CODEX_CONTEXT_SOURCE_KIND_LINEAR_TICKET = 5; - CODEX_CONTEXT_SOURCE_KIND_JIRA_TICKET = 6; - CODEX_CONTEXT_SOURCE_KIND_SENTRY_EVENT = 7; - CODEX_CONTEXT_SOURCE_KIND_DATADOG_DASHBOARD = 8; - CODEX_CONTEXT_SOURCE_KIND_LOG_SNIPPET = 9; - CODEX_CONTEXT_SOURCE_KIND_SCREENSHOT = 10; - CODEX_CONTEXT_SOURCE_KIND_MEMORY = 11; - CODEX_CONTEXT_SOURCE_KIND_URL = 12; - CODEX_CONTEXT_SOURCE_KIND_CEREBRO_THING = 13; - CODEX_CONTEXT_SOURCE_KIND_CEREBRO_FACT = 14; - CODEX_CONTEXT_SOURCE_KIND_CEREBRO_EVENT = 15; - CODEX_CONTEXT_SOURCE_KIND_CEREBRO_ACTION = 16; - CODEX_CONTEXT_SOURCE_KIND_CEREBRO_PREDICTION = 17; - CODEX_CONTEXT_SOURCE_KIND_GRANOLA_MEETING = 18; - CODEX_CONTEXT_SOURCE_KIND_GOOGLE_EMAIL_THREAD = 19; - CODEX_CONTEXT_SOURCE_KIND_GOOGLE_DRIVE_FILE = 20; - CODEX_CONTEXT_SOURCE_KIND_GOOGLE_CALENDAR_EVENT = 21; - CODEX_CONTEXT_SOURCE_KIND_DEPLOYMENT = 22; - CODEX_CONTEXT_SOURCE_KIND_BUILD = 23; -} - -// CodexMemoryScopeKind identifies the retrieval scope for prior run memory. -enum CodexMemoryScopeKind { - CODEX_MEMORY_SCOPE_KIND_UNSPECIFIED = 0; - CODEX_MEMORY_SCOPE_KIND_THREAD = 1; - CODEX_MEMORY_SCOPE_KIND_REPOSITORY = 2; - CODEX_MEMORY_SCOPE_KIND_TEAM = 3; - CODEX_MEMORY_SCOPE_KIND_WORKSPACE = 4; -} - -// CodexOutputKind classifies an artifact or external object the run should -// create or synchronize. -enum CodexOutputKind { - CODEX_OUTPUT_KIND_UNSPECIFIED = 0; - CODEX_OUTPUT_KIND_THREAD_MESSAGE = 1; - CODEX_OUTPUT_KIND_PULL_REQUEST = 2; - CODEX_OUTPUT_KIND_PULL_REQUEST_COMMENT = 3; - CODEX_OUTPUT_KIND_ARTIFACT = 4; - CODEX_OUTPUT_KIND_RUN_PANEL = 5; - CODEX_OUTPUT_KIND_EVALUATION_EXAMPLE = 6; - CODEX_OUTPUT_KIND_DRAFT_MESSAGE = 7; - CODEX_OUTPUT_KIND_DECISION_BRIEF = 8; - CODEX_OUTPUT_KIND_PREPARED_FUTURE = 9; - CODEX_OUTPUT_KIND_ISSUE = 10; -} - -// CodexProgressStage classifies user-visible run progress. -enum CodexProgressStage { - CODEX_PROGRESS_STAGE_UNSPECIFIED = 0; - CODEX_PROGRESS_STAGE_ACCEPTED = 1; - CODEX_PROGRESS_STAGE_CONTEXT_ENRICHING = 2; - CODEX_PROGRESS_STAGE_PLANNING = 3; - CODEX_PROGRESS_STAGE_WAITING_FOR_APPROVAL = 4; - CODEX_PROGRESS_STAGE_EDITING = 5; - CODEX_PROGRESS_STAGE_TESTING = 6; - CODEX_PROGRESS_STAGE_CREATING_OUTPUT = 7; - CODEX_PROGRESS_STAGE_WATCHING_CI = 8; - CODEX_PROGRESS_STAGE_COMPLETED = 9; - CODEX_PROGRESS_STAGE_FAILED = 10; - CODEX_PROGRESS_STAGE_CANCELLED = 11; -} - -// CodexConversationRef carries durable session coordinates across turns. -message CodexConversationRef { - string session_id = 1; - string app_server_thread_id = 2; - string previous_run_id = 3; - string parent_run_id = 4; - string followup_to_turn_id = 5; - string channel_thread_id = 6; - string channel_message_id = 7; - bool keep_session_alive = 8; - map attributes = 9; -} - -// CodexRoutingPolicy captures backend and worker selection. -message CodexRoutingPolicy { - CodexBackend backend = 1; - string worker_queue = 2; - string model_tier = 3; - string preferred_agent_id = 4; - map attributes = 5; -} - -// CodexBudgetPolicy defines per-run resource limits. -message CodexBudgetPolicy { - int64 max_input_tokens = 1 [(buf.validate.field).int64.gte = 0]; - int64 max_output_tokens = 2 [(buf.validate.field).int64.gte = 0]; - int64 max_total_tokens = 3 [(buf.validate.field).int64.gte = 0]; - int64 max_cost_micros = 4 [(buf.validate.field).int64.gte = 0]; - int32 max_run_seconds = 5 [(buf.validate.field).int32.gte = 0]; - int32 max_tool_calls = 6 [(buf.validate.field).int32.gte = 0]; - int32 max_retries = 7 [(buf.validate.field).int32.gte = 0]; -} - -// CodexApprovalPolicy captures governance controls before a worker performs -// write, network, or otherwise sensitive operations. -message CodexApprovalPolicy { - bool dry_run = 1; - bool allow_writes = 2; - bool require_plan_approval = 3; - bool require_patch_approval = 4; - bool require_command_approval = 5; - repeated string protected_path_globs = 6; - repeated string approver_entity_ids = 7; - repeated string network_egress_allowlist = 8; - bool scrub_secrets_from_outputs = 9; - string sandbox_mode = 10; - map attributes = 11; -} - -// CodexContextItem is a single enriched context object available to the run. -message CodexContextItem { - CodexContextSourceKind source_kind = 1; - string id = 2; - string uri = 3; - string title = 4; - string text = 5; - string content_type = 6; - string digest = 7; - map attributes = 8; -} - -// CodexMemoryScope describes what prior run knowledge should be retrieved. -message CodexMemoryScope { - CodexMemoryScopeKind kind = 1; - string key = 2; - int32 retention_days = 3 [(buf.validate.field).int32.gte = 0]; - map attributes = 4; -} - -// CodexOutputTarget describes a desired or produced external output. -message CodexOutputTarget { - CodexOutputKind kind = 1; - string id = 2; - string uri = 3; - string title = 4; - bool draft = 5; - map attributes = 6; -} - -// CodexPreparedFutureRef ties a Codex run to the reviewable next move it is -// preparing. It is a grouping contract, not an approval or execution grant. -message CodexPreparedFutureRef { - string prepared_future_id = 1; - string cerebro_action_id = 2; - string cerebro_prediction_id = 3; - repeated string cerebro_fact_ids = 4; - repeated string source_record_ids = 5; - repeated string artifact_ids = 6; - repeated string approval_request_ids = 7; - string evidence_uri = 8; - string source_health = 9; - string risk_level = 10; - map attributes = 11; -} - -// CodexWorkRequest is the typed payload for Slack, GitHub, Linear, CLI, IDE, -// and monitoring-triggered Codex work. -message CodexWorkRequest { - option (buf.validate.message).cel = { - id: "codex.v1.work_request.resource_id_not_local_absolute" - message: "resource_id must not be an absolute local path" - expression: "this.resource_id == '' || (!this.resource_id.startsWith('/') && !this.resource_id.startsWith('\\\\') && !this.resource_id.matches('^[A-Za-z]:[/\\\\\\\\].*') && !this.resource_id.matches('^[A-Za-z][A-Za-z0-9+.-]*:[A-Za-z]:.*'))" - }; - - CodexActionType action_type = 1; - CodexExecutionIntent execution_intent = 2; - string prompt = 3; - string repo = 4; - string cwd = 5; - string branch = 6; - string base_branch = 7; - string tenant_id = 8; - string reason = 9; - CodexConversationRef conversation = 10; - CodexRoutingPolicy routing = 11; - CodexBudgetPolicy budget = 12; - CodexApprovalPolicy approval_policy = 13; - CodexInteractivityMode interactivity_mode = 14; - repeated CodexContextItem context_items = 15; - repeated CodexOutputTarget desired_outputs = 16; - repeated CodexMemoryScope memory_scopes = 17; - map attributes = 18; - CodexPreparedFutureRef prepared_future = 19; - // Stable Platform resource identity. Local absolute paths are forbidden, - // including drive-root forms after local schemes (e.g. file:C:/Windows). - string resource_id = 20 [(buf.validate.field).string = { - max_len: 512 - pattern: "^$|^[^/\\\\:][^\\\\:]*$|^[A-Za-z][A-Za-z0-9+.-]+:([^A-Za-z/\\\\][^\\\\]*|[A-Za-z]([^:\\\\][^\\\\]*)?)$" - }]; - CodexAuthorityScope requested_authority = 21 [(buf.validate.field).enum.defined_only = true]; -} - -// CodexWorkResult is the bounded, channel-safe completion projection for a -// delegated Codex run. changed_files are relative to resource_id's mapped root. -message CodexWorkResult { - option (buf.validate.message).cel = { - id: "codex.v1.work_result.changed_files_workspace_relative" - message: "changed_files entries must be normalized workspace-relative paths" - expression: "this.changed_files.all(path, path != '' && !path.startsWith('/') && !path.contains('\\\\') && !path.matches('^[A-Za-z]:.*') && !path.matches('(^|/)\\\\.{1,2}(/|$)') && !path.contains('//') && !path.endsWith('/'))" - }; - - string outcome = 1 [(buf.validate.field).string = {min_len: 1, max_len: 256}]; - string summary = 2 [(buf.validate.field).string = {min_len: 1, max_len: 8192}]; - repeated string findings = 3 [ - (buf.validate.field).repeated.max_items = 64, - (buf.validate.field).repeated.items.string.max_len = 1024 - ]; - repeated string changed_files = 4 [ - (buf.validate.field).repeated.max_items = 256, - (buf.validate.field).repeated.items.string = { - max_len: 1024 - pattern: "^([^./\\\\:][^/\\\\:]*|\\.[^./\\\\:][^/\\\\:]*|\\.\\.[^/\\\\:][^/\\\\:]*)(/([^./\\\\:][^/\\\\:]*|\\.[^./\\\\:][^/\\\\:]*|\\.\\.[^/\\\\:][^/\\\\:]*))*$" - } - ]; - repeated string tests_run = 5 [ - (buf.validate.field).repeated.max_items = 128, - (buf.validate.field).repeated.items.string.max_len = 2048 - ]; - CodexVerificationStatus verification_status = 6 [(buf.validate.field).enum.defined_only = true]; - repeated string evidence_refs = 7 [ - (buf.validate.field).repeated.max_items = 128, - (buf.validate.field).repeated.items.string.max_len = 2048 - ]; - string owner_input_required = 8 [(buf.validate.field).string.max_len = 2048]; - string codex_thread_id = 9 [(buf.validate.field).string.max_len = 256]; - CodexGitState git_state = 10 [(buf.validate.field).enum.defined_only = true]; -} - -// CodexInteractionRequest describes a pending human decision projected to a -// channel surface. -message CodexInteractionRequest { - CodexInteractionType interaction_type = 1; - string run_id = 2; - string wait_id = 3; - string step_id = 4; - string artifact_id = 5; - string patch_id = 6; - string prompt = 7; - repeated string choices = 8; - google.protobuf.Struct payload = 9; - google.protobuf.Timestamp expires_at = 10; - map attributes = 11; -} - -// CodexInteractionDecision captures the user's response to a Codex control. -message CodexInteractionDecision { - CodexInteractionType interaction_type = 1; - string decision = 2; - string reason = 3; - string actor_entity_id = 4; - string selected_choice = 5; - google.protobuf.Struct payload = 6; - map attributes = 7; -} - -// CodexRunProgress is the compact, user-visible progress projection. -message CodexRunProgress { - CodexProgressStage stage = 1; - string safe_summary = 2; - int32 progress_percent = 3 [(buf.validate.field).int32 = { gte: 0, lte: 100 }]; - int32 files_read = 4 [(buf.validate.field).int32.gte = 0]; - int32 files_changed = 5 [(buf.validate.field).int32.gte = 0]; - int32 commands_run = 6 [(buf.validate.field).int32.gte = 0]; - int64 input_tokens = 7 [(buf.validate.field).int64.gte = 0]; - int64 output_tokens = 8 [(buf.validate.field).int64.gte = 0]; - int64 estimated_cost_micros = 9 [(buf.validate.field).int64.gte = 0]; - google.protobuf.Timestamp updated_at = 10; - map attributes = 11; -} - -// CodexOutcomeSignal feeds evaluation and routing loops after the run. -message CodexOutcomeSignal { - string run_id = 1; - string pull_request_url = 2; - bool merged = 3; - bool reverted = 4; - bool human_edited = 5; - string channel_reaction = 6; - string review_outcome = 7; - google.protobuf.Timestamp observed_at = 8; - map attributes = 9; -} diff --git a/proto/common/v1/analytics.proto b/proto/common/v1/analytics.proto deleted file mode 100644 index 9839921..0000000 --- a/proto/common/v1/analytics.proto +++ /dev/null @@ -1,44 +0,0 @@ -syntax = "proto3"; - -package common.v1; - -import "google/protobuf/struct.proto"; -import "google/protobuf/timestamp.proto"; - -option go_package = "github.com/evalops/platform/gen/go/common/v1;commonv1"; - -// TimeRange is the canonical inclusive/exclusive window used by analytics APIs. -message TimeRange { - google.protobuf.Timestamp start_time = 1; - google.protobuf.Timestamp end_time = 2; -} - -// Money carries a currency code plus an amount for financial rollups. -message Money { - string currency_code = 1; - double amount = 2; -} - -// InsightSource identifies the system that produced a recommendation or rollup. -enum InsightSource { - INSIGHT_SOURCE_UNSPECIFIED = 0; - INSIGHT_SOURCE_TRACES = 1; - INSIGHT_SOURCE_ATTRIBUTION = 2; - INSIGHT_SOURCE_METER = 3; - INSIGHT_SOURCE_APPROVALS = 4; - INSIGHT_SOURCE_AUDIT = 5; - INSIGHT_SOURCE_GOVERNANCE = 6; - INSIGHT_SOURCE_REGISTRY = 7; - INSIGHT_SOURCE_EVAL = 8; -} - -// EvidenceRef points analytics output back to source records. -message EvidenceRef { - InsightSource source = 1; - string record_id = 2; - string description = 3; - google.protobuf.Timestamp observed_at = 4; - double weight = 5; - google.protobuf.Struct metadata = 6; - string lineage_id = 7; -} diff --git a/proto/common/v1/authz.proto b/proto/common/v1/authz.proto deleted file mode 100644 index 5e3b72e..0000000 --- a/proto/common/v1/authz.proto +++ /dev/null @@ -1,46 +0,0 @@ -syntax = "proto3"; - -package common.v1; - -import "common/v1/risk.proto"; -import "google/protobuf/descriptor.proto"; - -option go_package = "github.com/evalops/platform/gen/go/common/v1;commonv1"; - -// required_scopes declares the authorization scopes required to invoke an RPC. -extend google.protobuf.MethodOptions { - repeated string required_scopes = 51001; -} - -// workspace_scope_field names the request string field path that must match the caller workspace. -// Repeated message paths are allowed; every resolved value must match. -extend google.protobuf.MethodOptions { - string workspace_scope_field = 51002; -} - -// organization_scope_field names the request string field path that must match the caller organization. -// Repeated message paths are allowed; every resolved value must match. -extend google.protobuf.MethodOptions { - string organization_scope_field = 51005; -} - -// risk_level classifies the operational risk of invoking an RPC. -extend google.protobuf.MethodOptions { - RiskLevel risk_level = 51003; -} - -// public marks an RPC that intentionally bypasses authenticated principal checks. -extend google.protobuf.MethodOptions { - bool public = 51004; -} - -// staff_account_required declares an authenticated RPC authorized by the durable staff claim. -extend google.protobuf.MethodOptions { - bool staff_account_required = 51006; -} - -// staff_cross_tenant declares an intentionally cross-tenant staff RPC. -// It is classification metadata and never bypasses staff authorization. -extend google.protobuf.MethodOptions { - bool staff_cross_tenant = 51007; -} diff --git a/proto/common/v1/classification.proto b/proto/common/v1/classification.proto deleted file mode 100644 index 22e3664..0000000 --- a/proto/common/v1/classification.proto +++ /dev/null @@ -1,39 +0,0 @@ -syntax = "proto3"; - -package common.v1; - -import "google/protobuf/descriptor.proto"; - -option go_package = "github.com/evalops/platform/gen/go/common/v1;commonv1"; - -// DataClassification declares what kind of data a field is allowed to carry. -// It is declared once, on the field, and is the input to lint enforcement -// (scripts/check-proto-classification.py) and to the generated attribute -// manifest consumed by runtime validators. -enum DataClassification { - // Not declared. Fields carrying free-form text must not use this value. - DATA_CLASSIFICATION_UNSPECIFIED = 0; - // Bounded, non-tenant-identifying values: enum-like strings, model names, - // provider names, surface names, units, status codes. - DATA_CLASSIFICATION_SAFE = 1; - // Values that identify a tenant, principal, or record: organization ids, - // workspace ids, user ids, request ids, idempotency keys, cursors. - DATA_CLASSIFICATION_IDENTIFIER = 2; - // Filesystem paths, URLs, repository refs, and other location strings. - DATA_CLASSIFICATION_PATH = 3; - // Operator- or model-authored free text and binary payloads: message bodies, - // corrections, tool output, attachment bytes. - DATA_CLASSIFICATION_CONTENT = 4; - // Secret material: tokens, keys, passwords, signed bearer values. Fields with - // this classification must never be persisted or logged in cleartext. - DATA_CLASSIFICATION_CREDENTIAL = 5; -} - -// classification declares the data classification of a single field. -// -// Extension number 51008 continues the common.v1 option range that starts at -// 51001 in common/v1/authz.proto. Unlike the options in that file, this one -// extends FieldOptions rather than MethodOptions. -extend google.protobuf.FieldOptions { - DataClassification classification = 51008; -} diff --git a/proto/common/v1/delivery.proto b/proto/common/v1/delivery.proto deleted file mode 100644 index 0f980fb..0000000 --- a/proto/common/v1/delivery.proto +++ /dev/null @@ -1,15 +0,0 @@ -syntax = "proto3"; - -package common.v1; - -option go_package = "github.com/evalops/platform/gen/go/common/v1;commonv1"; - -// DeliveryChannel identifies the notification delivery channel. -enum DeliveryChannel { - DELIVERY_CHANNEL_UNSPECIFIED = 0; - DELIVERY_CHANNEL_SLACK = 1; - DELIVERY_CHANNEL_EMAIL = 2; - DELIVERY_CHANNEL_WEBHOOK = 3; - DELIVERY_CHANNEL_IN_APP = 4; - DELIVERY_CHANNEL_PUSH = 5; -} diff --git a/proto/common/v1/entity.proto b/proto/common/v1/entity.proto deleted file mode 100644 index e17c102..0000000 --- a/proto/common/v1/entity.proto +++ /dev/null @@ -1,16 +0,0 @@ -syntax = "proto3"; - -package common.v1; - -option go_package = "github.com/evalops/platform/gen/go/common/v1;commonv1"; - -// EntityType identifies the kind of entity across systems. -enum EntityType { - ENTITY_TYPE_UNSPECIFIED = 0; - ENTITY_TYPE_CONTACT = 1; - ENTITY_TYPE_COMPANY = 2; - ENTITY_TYPE_DEAL = 3; - ENTITY_TYPE_TICKET = 4; - ENTITY_TYPE_CUSTOMER = 5; - ENTITY_TYPE_OPPORTUNITY = 6; -} diff --git a/proto/common/v1/risk.proto b/proto/common/v1/risk.proto deleted file mode 100644 index ab757db..0000000 --- a/proto/common/v1/risk.proto +++ /dev/null @@ -1,14 +0,0 @@ -syntax = "proto3"; - -package common.v1; - -option go_package = "github.com/evalops/platform/gen/go/common/v1;commonv1"; - -// RiskLevel classifies the risk of an action. -enum RiskLevel { - RISK_LEVEL_UNSPECIFIED = 0; - RISK_LEVEL_LOW = 1; - RISK_LEVEL_MEDIUM = 2; - RISK_LEVEL_HIGH = 3; - RISK_LEVEL_CRITICAL = 4; -} diff --git a/proto/common/v1/surface.proto b/proto/common/v1/surface.proto deleted file mode 100644 index 1f7d9e2..0000000 --- a/proto/common/v1/surface.proto +++ /dev/null @@ -1,24 +0,0 @@ -syntax = "proto3"; - -package common.v1; - -option go_package = "github.com/evalops/platform/gen/go/common/v1;commonv1"; - -// Surface identifies the product or channel surface that originated a platform -// action. It is shared by runtime, audit, and product-facing services so -// callers do not invent drift-prone string labels. -enum Surface { - SURFACE_UNSPECIFIED = 0; - SURFACE_ENSEMBLE = 1; - SURFACE_CHAT = 2; - SURFACE_MAESTRO = 3; - SURFACE_CONDUCTOR = 4; - SURFACE_SLACK = 5; - // SURFACE_EXTERNAL_AGENT identifies a third-party coding agent (Claude - // Code, Cursor, or another external agent) driving Platform through a - // non-Deixic surface. It is additive and wire-compatible: existing - // callers keep matching on SURFACE_ENSEMBLE/CHAT/MAESTRO/CONDUCTOR/SLACK, - // and every exhaustive Rust match must handle it deliberately rather than - // fall through to SURFACE_UNSPECIFIED. - SURFACE_EXTERNAL_AGENT = 6; -} diff --git a/proto/connectors/v1/connectors.proto b/proto/connectors/v1/connectors.proto deleted file mode 100644 index 5474937..0000000 --- a/proto/connectors/v1/connectors.proto +++ /dev/null @@ -1,1571 +0,0 @@ -syntax = "proto3"; - -package connectors.v1; - -import "buf/validate/validate.proto"; -import "common/v1/authz.proto"; -import "google/protobuf/timestamp.proto"; - -option go_package = "github.com/evalops/platform/gen/go/connectors/v1;connectorsv1"; - -// Canonical source for the co-located Platform and Connectors connectors.v1 -// contract. Connector consumers compile this file through their local build -// adapter; there must not be a second connectors/v1/connectors.proto source -// under platform/connectors. Keep authorization, scope, and risk annotations -// here because they are part of the Platform-facing contract even though they -// are removed by the standalone connectors crate's wire-only codegen adapter. -// `ConnectorRuntime.provider_actions` is the stable generated API name for -// field 10. It is wire-compatible with the historical connectors-rs name -// `actions`; connector consumers use this canonical name after codegen. - -// ConnectorService manages external integration connections. -service ConnectorService { - rpc RegisterConnection(RegisterConnectionRequest) returns (RegisterConnectionResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - rpc GetConnection(GetConnectionRequest) returns (GetConnectionResponse) { - option (common.v1.required_scopes) = "connectors:read"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Reads one validated, caller-authorized source observation for business objects. - // Private/group-scoped resources are not widened into workspace records. - rpc GetBusinessSourceRecord(GetBusinessSourceRecordRequest) returns (GetBusinessSourceRecordResponse) { - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc ListConnections(ListConnectionsRequest) returns (ListConnectionsResponse) { - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ListUpcomingCalls projects tenant-owned Google Calendar event resources - // into provider-neutral calls. Raw provider payloads and connection IDs - // remain inside ConnectorService. - rpc ListUpcomingCalls(ListUpcomingCallsRequest) returns (ListUpcomingCallsResponse) { - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc ListProviders(ListProvidersRequest) returns (ListProvidersResponse) { - option (common.v1.required_scopes) = "connectors:read"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Lists catalog providers that are installed in the active revision but - // remain hidden from ListProviders until their generated-canary family - // proofs are complete. This surface intentionally omits setup, auth, and - // runtime details so callers cannot register an unqualified provider. - rpc ListProviderPreviews(ListProviderPreviewsRequest) returns (ListProviderPreviewsResponse) { - option (common.v1.required_scopes) = "connectors:read"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc PreviewCustomConnector(PreviewCustomConnectorRequest) returns (PreviewCustomConnectorResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc CreateCustomConnector(CreateCustomConnectorRequest) returns (CreateCustomConnectorResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - rpc GetCustomConnector(GetCustomConnectorRequest) returns (GetCustomConnectorResponse) { - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc ListCustomConnectors(ListCustomConnectorsRequest) returns (ListCustomConnectorsResponse) { - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc UpdateCustomConnector(UpdateCustomConnectorRequest) returns (UpdateCustomConnectorResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc DeleteCustomConnector(DeleteCustomConnectorRequest) returns (DeleteCustomConnectorResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // ResolveProviderInstallation maps provider-issued installation coordinates - // to exactly one active, tenant-bound connection. It never returns credential - // material and callers must not infer tenant scope from a provider workspace. - rpc ResolveProviderInstallation(ResolveProviderInstallationRequest) returns (ResolveProviderInstallationResponse) { - option (common.v1.required_scopes) = "connectors:read"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // EnrollSurfaceTarget selects one exact provider object for background - // observation. Provider-specific adapters verify current read access before - // a durable target is created; this call never grants connector authority. - rpc EnrollSurfaceTarget(EnrollSurfaceTargetRequest) returns (EnrollSurfaceTargetResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - rpc VerifyConnectionActive(VerifyConnectionActiveRequest) returns (VerifyConnectionActiveResponse) { - option (common.v1.required_scopes) = "connectors:connection-active:verify"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc RefreshConnection(RefreshConnectionRequest) returns (RefreshConnectionResponse) { - option (common.v1.required_scopes) = "connectors:write"; - - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc RevokeConnection(RevokeConnectionRequest) returns (RevokeConnectionResponse) { - option (common.v1.required_scopes) = "connectors:write"; - - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - rpc GetHealth(GetHealthRequest) returns (GetHealthResponse) { - option (common.v1.required_scopes) = "connectors:read"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc ResolveSourceOfTruth(ResolveSourceOfTruthRequest) returns (ResolveSourceOfTruthResponse) { - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc GetDegradedReadPolicy(GetDegradedReadPolicyRequest) returns (GetDegradedReadPolicyResponse) { - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc SetSourceOfTruthPolicy(SetSourceOfTruthPolicyRequest) returns (SetSourceOfTruthPolicyResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.organization_scope_field) = "policy.organization_id"; - option (common.v1.workspace_scope_field) = "policy.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_CRITICAL; - } - rpc GetCapabilities(GetCapabilitiesRequest) returns (GetCapabilitiesResponse) { - option (common.v1.required_scopes) = "connectors:read"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // InitiateOAuthFlow returns a provider authorize URL plus a server-issued - // state token. The UI launches the URL in a popup; the provider redirects - // back to /integrations/{provider}/oauth-callback with the auth code, and - // the UI then calls CompleteOAuthFlow. - rpc InitiateOAuthFlow(InitiateOAuthFlowRequest) returns (InitiateOAuthFlowResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // CompleteOAuthFlow exchanges the authorization code for access/refresh - // tokens. Providers that authorize more than one tenant return an explicit - // selection list; the caller completes the same state with selected_tenant_id. - rpc CompleteOAuthFlow(CompleteOAuthFlowRequest) returns (CompleteOAuthFlowResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_CRITICAL; - } - // InitiateMcpOAuthFlow performs protected-resource (RFC 9728) and - // authorization-server (RFC 8414) discovery, then returns a PKCE-bound - // authorization URL. The connector owner persists the state binding and - // returns only metadata and opaque references; token material never crosses - // this contract. - rpc InitiateMcpOAuthFlow(InitiateMcpOAuthFlowRequest) returns (InitiateMcpOAuthFlowResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // CompleteMcpOAuthFlow consumes the one-time state/code binding and asks the - // configured secret broker to custody the resulting token set. The response - // contains only an opaque connection_ref and durable grant identity. - rpc CompleteMcpOAuthFlow(CompleteMcpOAuthFlowRequest) returns (CompleteMcpOAuthFlowResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_CRITICAL; - } - rpc RevokeMcpOAuthGrant(RevokeMcpOAuthGrantRequest) returns (RevokeMcpOAuthGrantResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // TriggerSync enqueues a sync run for a connection's resource stream on the - // connectors owner's durable run queue. Enqueue is idempotent on - // (connection_id, idempotency_key): replaying the same key returns the - // existing queue row rather than creating a duplicate run. - rpc TriggerSync(TriggerSyncRequest) returns (TriggerSyncResponse) { - option (common.v1.required_scopes) = "connectors:write"; - - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc ListConnectionStreams(ListConnectionStreamsRequest) returns (ListConnectionStreamsResponse) { - option (common.v1.required_scopes) = "connectors:read"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc GetStreamState(GetStreamStateRequest) returns (GetStreamStateResponse) { - option (common.v1.required_scopes) = "connectors:read"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc ResetStreamState(ResetStreamStateRequest) returns (ResetStreamStateResponse) { - option (common.v1.required_scopes) = "connectors:write"; - - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc ExecuteConnectorAction(ExecuteConnectorActionRequest) returns (ExecuteConnectorActionResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - rpc CreateSyncSchedule(CreateSyncScheduleRequest) returns (CreateSyncScheduleResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc ListSyncSchedules(ListSyncSchedulesRequest) returns (ListSyncSchedulesResponse) { - option (common.v1.required_scopes) = "connectors:read"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } -} - -// AuthType describes the authentication method for a connection. -enum AuthType { - AUTH_TYPE_UNSPECIFIED = 0; - AUTH_TYPE_OAUTH2 = 1; - AUTH_TYPE_API_KEY = 2; - AUTH_TYPE_BASIC = 3; - AUTH_TYPE_MTLS = 4; - AUTH_TYPE_GITHUB_APP = 5; - // The provider endpoint is public and registration requires no credential. - // This is distinct from UNSPECIFIED, which asks the server to use the - // provider's configured default authentication type. - AUTH_TYPE_NONE = 6; -} - -// HealthStatus describes the health state of a connection. -enum HealthStatus { - HEALTH_STATUS_UNSPECIFIED = 0; - HEALTH_STATUS_HEALTHY = 1; - HEALTH_STATUS_DEGRADED = 2; - HEALTH_STATUS_UNHEALTHY = 3; - HEALTH_STATUS_UNKNOWN = 4; -} - -// ProviderInstallationState is the lifecycle state of a provider-issued app -// installation. Only ACTIVE installations may resolve for event ingress. -enum ProviderInstallationState { - PROVIDER_INSTALLATION_STATE_UNSPECIFIED = 0; - PROVIDER_INSTALLATION_STATE_ACTIVE = 1; - PROVIDER_INSTALLATION_STATE_RECONNECT_REQUIRED = 2; - PROVIDER_INSTALLATION_STATE_REVOKED = 3; -} - -enum CredentialState { - CREDENTIAL_STATE_UNSPECIFIED = 0; - CREDENTIAL_STATE_READY = 1; - CREDENTIAL_STATE_MISSING = 2; - CREDENTIAL_STATE_REVOKED = 3; -} - -// SourceAuthorityState is the external source system's authority posture for -// a connection. A locally active row is not source authority; callers must -// receive an explicit UNKNOWN observation until an authoritative producer -// reports otherwise. -enum SourceAuthorityState { - SOURCE_AUTHORITY_STATE_UNSPECIFIED = 0; - SOURCE_AUTHORITY_STATE_SUFFICIENT = 1; - SOURCE_AUTHORITY_STATE_INSUFFICIENT = 2; - SOURCE_AUTHORITY_STATE_UNKNOWN = 3; - SOURCE_AUTHORITY_STATE_REVOKED = 4; -} - -// SourceAuthorityFreshnessMethod identifies how the source observation was -// obtained. NOT_OBSERVED is the explicit default when no authoritative -// producer has supplied a response; it is not evidence of source access. -enum SourceAuthorityFreshnessMethod { - SOURCE_AUTHORITY_FRESHNESS_METHOD_UNSPECIFIED = 0; - SOURCE_AUTHORITY_FRESHNESS_METHOD_NOT_OBSERVED = 1; - SOURCE_AUTHORITY_FRESHNESS_METHOD_INTROSPECTION = 2; - SOURCE_AUTHORITY_FRESHNESS_METHOD_WEBHOOK = 3; - SOURCE_AUTHORITY_FRESHNESS_METHOD_POLLING = 4; - SOURCE_AUTHORITY_FRESHNESS_METHOD_SHORT_TTL = 5; - SOURCE_AUTHORITY_FRESHNESS_METHOD_REFRESH_FAILURE = 6; -} - -// SourceOfTruthArea identifies a functional domain for source-of-truth resolution. -enum SourceOfTruthArea { - SOURCE_OF_TRUTH_AREA_UNSPECIFIED = 0; - SOURCE_OF_TRUTH_AREA_CRM = 1; - SOURCE_OF_TRUTH_AREA_SUPPORT = 2; - SOURCE_OF_TRUTH_AREA_BILLING = 3; - SOURCE_OF_TRUTH_AREA_ANALYTICS = 4; - SOURCE_OF_TRUTH_AREA_HRIS = 5; -} - -// Mirrors connectors_cdk::ReplicationMode (crates/connectors-cdk/src/lib.rs). -enum ReplicationMode { - REPLICATION_MODE_UNSPECIFIED = 0; - REPLICATION_MODE_FULL_REFRESH = 1; - REPLICATION_MODE_INCREMENTAL = 2; -} - -// Connection is the canonical external integration connection record. -message Connection { - string id = 1; - string workspace_id = 2; - string provider_id = 3; - string display_name = 4; - AuthType auth_type = 5; - repeated string scopes = 6; - HealthStatus health_status = 7; - google.protobuf.Timestamp last_healthy_at = 8; - google.protobuf.Timestamp created_at = 9; - google.protobuf.Timestamp updated_at = 10; - // credential_refs mirrors non-secret credential references such as vault or - // secret-manager handles. Raw credential material must not be returned here. - map credential_refs = 11; - string organization_id = 12; - // health_reason is a short, human-readable explanation of the current - // health_status — "token refreshed 2m ago", "auth failed: token revoked", - // "rate-limited by upstream". The UI surfaces it on tiles and the active - // card so operators don't have to dig into logs to find out why a - // connection is degraded. Empty when there's nothing meaningful to add. - string health_reason = 13; - // Expiry of the connection's stored OAuth credential, when known. Unset for - // API-key/basic/mtls connections and for providers that do not report it. - google.protobuf.Timestamp credential_expires_at = 14; - // Connection-owner custody revision. Zero is an unpersisted or legacy snapshot. - uint64 revision = 15; -} - -// ProviderInstallation is a credential-free projection of provider-issued -// installation identity and its owning Platform tenant. -message ProviderInstallation { - string connection_id = 1 [(buf.validate.field).string.min_len = 1]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 3 [(buf.validate.field).string.min_len = 1]; - string provider_id = 4 [(buf.validate.field).string.min_len = 1]; - string app_id = 5 [(buf.validate.field).string.min_len = 1]; - string provider_workspace_id = 6 [(buf.validate.field).string.min_len = 1]; - string provider_enterprise_id = 7; - string provider_bot_user_id = 8; - ProviderInstallationState install_state = 9; - HealthStatus health_status = 10; - repeated string granted_scopes = 11; - google.protobuf.Timestamp installed_at = 12; - google.protobuf.Timestamp updated_at = 13; - google.protobuf.Timestamp revoked_at = 14; -} - -message ResolveProviderInstallationRequest { - string provider_id = 1 [(buf.validate.field).string.min_len = 1]; - string app_id = 2 [(buf.validate.field).string.min_len = 1]; - string provider_workspace_id = 3 [(buf.validate.field).string.min_len = 1]; - string provider_enterprise_id = 4; -} - -message ResolveProviderInstallationResponse { - Connection connection = 1; - ProviderInstallation installation = 2; -} - -message EnrollSurfaceTargetRequest { - string organization_id = 1 [(buf.validate.field).string = { - min_len: 1 - max_len: 256 - }]; - string workspace_id = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 256 - }]; - string connection_id = 3 [(buf.validate.field).string = { - min_len: 1 - max_len: 256 - }]; - string provider_id = 4 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; - string target_kind = 5 [(buf.validate.field).string = { - min_len: 1 - max_len: 64 - }]; - string external_id = 6 [(buf.validate.field).string = { - min_len: 1 - max_len: 1024 - }]; - string canonical_url = 7 [(buf.validate.field).string.max_len = 4096]; - string idempotency_key = 8 [(buf.validate.field).string = { - min_len: 1 - max_len: 256 - }]; -} - -message EnrollSurfaceTargetResponse { - string connection_id = 1; - string provider_id = 2; - string target_kind = 3; - string external_id = 4; - string state = 5; - bool idempotent_replay = 6; -} - -message VerifyConnectionActiveRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string connection_id = 3 [(buf.validate.field).string.min_len = 1]; -} - -message VerifyConnectionActiveResponse { - string connection_id = 1 [(buf.validate.field).string.min_len = 1]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 3 [(buf.validate.field).string.min_len = 1]; - google.protobuf.Timestamp state_updated_at = 4; - google.protobuf.Timestamp verified_at = 5; - // Completed source-owner verification supplies this observation. A local - // active row alone remains UNKNOWN/NOT_OBSERVED. - SourceAuthorityObservation source_authority = 6; - // Monotonic Connection-owner revision, including credential-reference and - // OAuth installation mutations. Zero means no revision evidence was supplied. - uint64 connection_revision = 7; -} - -// SourceAuthorityObservation is credential-free evidence from the external -// source owner. Empty optional timestamps/reference fields mean that the -// owner has not supplied that evidence; they must not be inferred locally. -message SourceAuthorityObservation { - SourceAuthorityState state = 1 [(buf.validate.field).enum.defined_only = true]; - string reason = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 256 - }]; - SourceAuthorityFreshnessMethod freshness_method = 3 [(buf.validate.field).enum.defined_only = true]; - google.protobuf.Timestamp observed_at = 4; - google.protobuf.Timestamp last_confirmed_at = 5; - // Opaque owner reference only; never a token, secret, private key, or raw - // provider response body. - string owner_snapshot_reference = 6 [(buf.validate.field).string.max_len = 256]; -} - -// ConnectionHealth provides detailed health information for a connection. -message ConnectionHealth { - HealthStatus status = 1; - int32 latency_ms = 2; - google.protobuf.Timestamp last_check_at = 3; - string error_message = 4; - // reason mirrors Connection.health_reason but for the live GetHealth - // response. Empty when status==healthy and there's nothing to surface. - string reason = 5; -} - -// ConnectorCredentialField describes the credential reference slots accepted -// by a managed provider. Values are reference handles such as vault:// or -// gsm:// URIs, never raw credential material. -message ConnectorCredentialField { - string name = 1 [(buf.validate.field).string.min_len = 1]; - string label = 2; - bool required = 3; - bool secret = 4; - repeated string accepted_reference_schemes = 5; - string credential_type = 6; - bool versioned = 7; - bool rotatable = 8; - bool revocable = 9; - bool expires = 10; - string stable_id = 11 [(buf.validate.field).string.min_len = 1]; - ConnectorCatalogProvenance provenance = 12; -} - -// ConnectorCredentialLifecyclePolicy describes the generic credential lifecycle -// operations the platform can drive for a provider. -message ConnectorCredentialLifecyclePolicy { - repeated string supported_credential_types = 1; - bool supports_versioning = 2; - bool supports_rotation = 3; - bool supports_revocation = 4; - int32 rotation_notice_days = 5 [(buf.validate.field).int32.gte = 0]; -} - -// ConnectorRuntime describes the read runtime a managed provider exposes. -// The connectors backend uses this to advertise concrete upstream resources -// that can be inventoried, including child resources whose path parameters -// must be bound from parent records. -message ConnectorRuntime { - // base_url is the provider API origin or templated origin, e.g. - // "https://api.openai.com/v1" or "https://bedrock.{region}.amazonaws.com". - string base_url = 1; - // verification_path is the endpoint the backend can probe to validate - // credentials before deeper resource reads. - string verification_path = 2; - repeated ConnectorResourceFamily resource_families = 3; - repeated ConnectorChildResource child_resources = 4; - // Provider-level rate-limit defaults. Unset (all three absent) means the - // provider runs unthrottled. A ConnectorResourceFamily may override any of - // these three per resource family. This field replaces a previously - // vestigial `repeated ConnectorActionDefinition actions = 5` that no - // platform code ever populated or read (evalops/platform#5124); the tag-5 - // wire type it now carries (VARINT) matches connectors-rs, the service - // that actually produces these bytes. - optional uint32 requests_per_window = 5; - optional uint32 window_seconds = 6; - optional uint32 max_concurrency = 7; - // Non-secret constant headers/query params applied to every request for - // this runtime. Never redacted: these are not credential material. - repeated ConnectorStaticHeader static_headers = 8; - // Explicit origin templates authorized to receive this runtime's - // credentials. Request execution rejects URLs outside this set before - // resolving header/query credentials. - repeated string credential_destination_origins = 9; - // ConnectorService, the catalog owner, publishes its authoritative action - // inventory here. Named `provider_actions` instead of connectors-rs's - // `actions` -- see the naming-debt note at the top of this file. - repeated ConnectorActionDefinition provider_actions = 10; - // Optional DNS suffix constraints for credential-bearing destinations whose - // hostname is supplied by connection configuration. Hosts must equal a - // suffix or be its dot-delimited subdomain; ports, IP literals, userinfo, - // trailing dots, and encoded lookalikes are rejected before auth resolves. - repeated string credential_destination_host_suffixes = 11; -} - -// ConnectorActionDefinition declares one provider-native operation. -message ConnectorActionDefinition { - string id = 1 [(buf.validate.field).string.min_len = 1]; - string capability = 2 [(buf.validate.field).string.min_len = 1]; - string http_method = 3 [(buf.validate.field).string.min_len = 1]; - string path = 4 [(buf.validate.field).string.min_len = 1]; - bool approval_required = 5; - bool destructive = 6; - string stable_id = 7 [(buf.validate.field).string.min_len = 1]; - ConnectorCatalogProvenance provenance = 8; - string base_url = 9 [(buf.validate.field).string.uri = true]; - repeated string required_scopes = 10; - string input_schema_json = 11; - string digest = 12; - // Canonical semantic effect for this action. Empty/unspecified is - // fail-closed: only an explicit `read` effect may enter a governed - // read-only execution path. This is independent of the provider HTTP - // method because some read APIs (for example Tavily search) use POST. - string effect = 13; - // Catalog-owned tool metadata. Presence does not grant execution authority. - ConnectorGovernedAction governed = 14; - // This action may be emitted by a registered object-surface projector. - // Presence is descriptive only; installation authority is still required. - bool surface_projection = 15; -} - -// ConnectorGovernedAction preserves published tool descriptions, schemas, and -// examples across compiled and durable catalog projections. Execution still -// requires the connection's granted scopes and the action's effect policy. -message ConnectorGovernedAction { - string tool_name = 1; - uint32 version = 2; - repeated string compatibility_aliases = 3; - string description = 4; - bool mention_default = 5; - repeated string mention_keywords = 6; - string output_schema_json = 7; - string input_example_json = 8; - string output_example_json = 9; -} - -// ConnectorVerificationLevel is the fail-closed evidence ladder for a -// connector catalog subject. Higher levels require the canonical verification -// ledger to contain evidence that justifies the promotion. -enum ConnectorVerificationLevel { - CONNECTOR_VERIFICATION_LEVEL_UNSPECIFIED = 0; - CONNECTOR_VERIFICATION_LEVEL_DECLARED = 1; - CONNECTOR_VERIFICATION_LEVEL_SPEC_DERIVED = 2; - CONNECTOR_VERIFICATION_LEVEL_FIXTURE_VERIFIED = 3; - CONNECTOR_VERIFICATION_LEVEL_LIVE_VERIFIED = 4; - CONNECTOR_VERIFICATION_LEVEL_CONTINUOUSLY_VERIFIED = 5; -} - -// ConnectorEvidenceKind identifies the bounded evidence supporting a catalog -// verification level. It does not establish credential validity or transport -// availability. -enum ConnectorEvidenceKind { - CONNECTOR_EVIDENCE_KIND_UNSPECIFIED = 0; - CONNECTOR_EVIDENCE_KIND_PROBE = 1; - CONNECTOR_EVIDENCE_KIND_FIXTURE = 2; - CONNECTOR_EVIDENCE_KIND_CANARY = 3; - CONNECTOR_EVIDENCE_KIND_PRODUCTION = 4; - CONNECTOR_EVIDENCE_KIND_UNPROVABLE_UNAUTHENTICATED = 5; -} - -// ConnectorCatalogProvenance records where a catalog-derived value came from -// (for example an OpenAPI spec import), when it was last verified, and the -// bounded evidence behind its current verification level. -message ConnectorCatalogProvenance { - string basis = 1; - string source_url = 2; - string last_verified_at = 3; - ConnectorVerificationLevel verification_level = 4; - ConnectorEvidenceKind evidence_kind = 5; -} - -message ConnectorAuthBinding { - string stable_id = 1; - string credential_field = 2; - string placement = 3; - string scheme = 4; - string header_name = 5; - string query_param = 6; - ConnectorCatalogProvenance provenance = 7; - string value_prefix = 8; - string value_key = 9; -} - -// A non-secret constant header or query parameter applied to every request. -message ConnectorStaticHeader { - string placement = 1; - string name = 2; - string value = 3; -} - -// ConnectorResourceFamily names one upstream resource collection the runtime -// can read. -message ConnectorResourceFamily { - string id = 1 [(buf.validate.field).string.min_len = 1]; - string path = 2 [(buf.validate.field).string.min_len = 1]; - string event_kind = 3 [(buf.validate.field).string.min_len = 1]; - string http_method = 4; - string default_request_body_json = 5; - string stable_id = 6; - repeated string aliases = 7; - ConnectorCatalogProvenance provenance = 8; - string record_selector = 9; - repeated string primary_key = 10; - string cursor_field = 11; - ConnectorPaginationContract pagination = 12; - optional uint32 requests_per_window = 13; - optional uint32 window_seconds = 14; - optional uint32 max_concurrency = 15; - optional string base_url = 16; - repeated ConnectorQueryParamBinding query_param_bindings = 17; - ConnectorIncrementalBinding incremental = 18; - bool synthetic_primary_key = 19; - ConnectorCostProjection cost = 20; - // Customer-facing label supplied by the catalog source. Empty means the - // catalog has no authoritative label; consumers must not infer one from id. - string display_name = 21; - // Exact coverage taxonomy declared by the source catalog. This is source - // metadata, not a Mono canonical resource type. - repeated string source_coverage_types = 22; - // Projection template declared by the source catalog. It records upstream - // intent and does not claim that Mono executes that domain projection. - string source_projection_template = 23; -} - -// Safe discovery metadata for one provider resource family. Endpoint, auth, -// request-planning, and response-schema details are intentionally excluded. -message ConnectorResourceFamilySummary { - string id = 1 [(buf.validate.field).string.min_len = 1]; - string display_name = 2; - repeated string source_coverage_types = 3; - string source_projection_template = 4; - string event_kind = 5 [(buf.validate.field).string.min_len = 1]; -} - -message ConnectorCostProjection { - string spend_month_field = 1; - string spend_today_field = 2; - repeated string asset_name_fields = 3; - string model_field = 4; - string source_url_field = 5; - string resource_id_source = 6; - string record_kind = 7; - string period_field = 8; - string occurred_at_field = 9; - string input_tokens_field = 10; - string output_tokens_field = 11; - string request_count_field = 12; - uint64 request_count_value = 13; - string spend_unit = 14; - string occurred_at_format = 15; - string result_selector = 16; - string amount_field = 17; - string currency_field = 18; - repeated string dimension_fields = 19; - repeated string source_identity_fields = 20; -} - -message ConnectorIncrementalBinding { - string request_param = 1; - string comparison = 2; - optional uint64 initial_lookback_seconds = 3; - string initial_lookback_format = 4; - optional uint64 slice_seconds = 5; - optional uint64 resume_lookback_seconds = 6; -} - -message ConnectorQueryParamBinding { - string name = 1; - string source = 2; - string static_value = 3; - string credential_field = 4; - string connection_config_key = 5; -} - -message ConnectorPaginationContract { - string kind = 1; - string cursor_param = 2; - string cursor_response_path = 3; - string page_param = 4; - string offset_param = 5; - string page_size_param = 6; - optional uint32 page_size_default = 7; - optional uint32 initial_value = 8; - optional uint32 increment = 9; - string next_url_response_path = 10; - bool stop_on_short_page = 11; -} - -// ConnectorChildResource declares how to enumerate a parameterized resource -// path from parent records. -message ConnectorChildResource { - string family_id = 1 [(buf.validate.field).string.min_len = 1]; - string parent_family_id = 2 [(buf.validate.field).string.min_len = 1]; - repeated ConnectorPathParameterBinding path_params = 3; - repeated ConnectorPathParameterBinding query_params = 4; -} - -// ConnectorPathParameterBinding maps a "{param}" segment in a child family -// path to a field from the parent record or from a path parameter inherited by -// that parent. -message ConnectorPathParameterBinding { - string param = 1 [(buf.validate.field).string.min_len = 1]; - string source_field = 2 [(buf.validate.field).string.min_len = 1]; -} - -// ConnectorProvider describes a managed connector provider that can be used to -// register a connection. -message ConnectorProvider { - string id = 1 [(buf.validate.field).string.min_len = 1]; - string display_name = 2; - AuthType default_auth_type = 3 [(buf.validate.field).enum.defined_only = true]; - repeated string default_scopes = 4; - repeated string capabilities = 5; - bool supports_pkce = 6; - bool supports_refresh = 7; - repeated ConnectorCredentialField credential_fields = 8; - ConnectorCredentialLifecyclePolicy credential_lifecycle_policy = 9; - // oauth_supported is true when the connectors backend can run the OAuth - // flow for this provider — i.e. the provider is in oauthProviderRegistry - // and its OAuth client_id/secret are present in the OAuth catalog. The - // UI uses this instead of a hardcoded list to decide whether to show - // the Authorize launcher or the catalog-runbook notice; that means - // adding a provider in Go automatically flips it on for the UI. - bool oauth_supported = 10; - // catalog_categories are backend-authored tags such as "ai" or - // "governance" used by UI filtering and operator copy. - repeated string catalog_categories = 11; - // runtime is set when the provider has an executable inventory/read runtime. - ConnectorRuntime runtime = 12; - string stable_id = 13; - repeated string aliases = 14; - ConnectorCatalogProvenance provenance = 15; - repeated ConnectorAuthBinding auth_bindings = 16; - // tier is derived by the catalog compiler from the executable runtime - // shape. It is not an authored readiness or verification claim. - string tier = 17; - // rollout_kind controls durable catalog exposure. Machine imports use - // generated_canary until every required family has visible proof. - string rollout_kind = 18; - // Immutable source/import cohort used to bind generated-canary proof. - // Empty for built-in and tenant-owned custom providers. - string canary_cohort_sha256 = 19; - // Customer-facing source description. Empty means the catalog has no - // authoritative description. - string description = 20; -} - -// CustomConnectorActionMetadata is the tenant-editable presentation and -// policy layer. The compiled action identity (method, path, schema, and -// digest) remains immutable after activation. -message CustomConnectorActionMetadata { - string action_id = 1 [(buf.validate.field).string.min_len = 1]; - string tool_name = 2; - string tool_description = 3; - string effect = 4; - bool enabled = 5; - uint32 estimated_schema_tokens = 6; - bool description_proposal_reviewed = 7; -} - -message CustomConnector { - string id = 1 [(buf.validate.field).string.min_len = 1]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 3 [(buf.validate.field).string.min_len = 1]; - string name = 4 [(buf.validate.field).string.min_len = 1]; - string description = 5; - string source_type = 6 [(buf.validate.field).string.min_len = 1]; - string source_uri = 7; - string provider_id = 8 [(buf.validate.field).string.min_len = 1]; - string spec_sha256 = 9 [(buf.validate.field).string.min_len = 64]; - string status = 10 [(buf.validate.field).string.min_len = 1]; - repeated CustomConnectorActionMetadata actions = 11; - google.protobuf.Timestamp created_at = 12; - google.protobuf.Timestamp updated_at = 13; - uint64 revision = 14; -} - -message PreviewCustomConnectorRequest { - option (buf.validate.message).cel = { - id: "connectors.v1.preview_custom_connector_request.source_required" - message: "document or source_uri is required" - expression: "size(this.document) > 0 || size(this.source_uri) > 0" - }; - - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string name = 3 [(buf.validate.field).string.min_len = 1]; - string description = 4; - string source_type = 5 [(buf.validate.field).string.min_len = 1]; - string document = 6; - string source_uri = 7; - repeated string approved_destination_origins = 8; - repeated CustomConnectorActionMetadata actions = 9; - bool descriptions_reviewed = 10; - // expected_spec_sha256 binds a create request to the exact remote bytes - // returned by preview. It is optional for preview and inline definitions, - // and required by the Connectors owner when create fetches source_uri. - string expected_spec_sha256 = 11 [(buf.validate.field).string.pattern = "^(|[0-9a-f]{64})$"]; -} - -message PreviewCustomConnectorResponse { - CustomConnector connector = 1; - repeated string diagnostics = 2; -} - -message CreateCustomConnectorRequest { - PreviewCustomConnectorRequest definition = 1; -} - -message CreateCustomConnectorResponse { - CustomConnector connector = 1; -} - -message GetCustomConnectorRequest { - string id = 1 [(buf.validate.field).string.min_len = 1]; -} - -message GetCustomConnectorResponse { - CustomConnector connector = 1; -} - -message ListCustomConnectorsRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; -} - -message ListCustomConnectorsResponse { - repeated CustomConnector connectors = 1; -} - -message UpdateCustomConnectorRequest { - string id = 1 [(buf.validate.field).string.min_len = 1]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 3 [(buf.validate.field).string.min_len = 1]; - string name = 4; - string description = 5; - repeated CustomConnectorActionMetadata actions = 6; - bool descriptions_reviewed = 7; -} - -message UpdateCustomConnectorResponse { - CustomConnector connector = 1; -} - -message DeleteCustomConnectorRequest { - string id = 1 [(buf.validate.field).string.min_len = 1]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 3 [(buf.validate.field).string.min_len = 1]; -} - -message DeleteCustomConnectorResponse { - string id = 1; - string status = 2; -} - -// SourceOfTruthPolicy defines which connection is authoritative for a domain. -message SourceOfTruthPolicy { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - SourceOfTruthArea area = 2; - string primary_connection_id = 3 [(buf.validate.field).string.min_len = 1]; - string fallback_connection_id = 4; - string organization_id = 5 [(buf.validate.field).string.min_len = 1]; -} - -// DegradedReadPolicy defines behavior when the primary source is unavailable. -message DegradedReadPolicy { - string mode = 1; - repeated string allowed_integrations = 2; - int32 max_age_minutes = 3; - bool queue_primary_refresh = 4; -} - -message RegisterConnectionRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string provider_id = 2 [(buf.validate.field).string.min_len = 1]; - string display_name = 3; - AuthType auth_type = 4; - repeated string scopes = 5; - map credentials = 6; - string organization_id = 7 [(buf.validate.field).string.min_len = 1]; - string idempotency_key = 8; - // Optional client-generated final id used to bind managed credentials - // before registration. The connector generates an id when omitted. - string connection_id = 9; -} - -message RegisterConnectionResponse { - Connection connection = 1; -} - -message GetConnectionRequest { - string id = 1 [(buf.validate.field).string.min_len = 1]; -} - -message GetConnectionResponse { - Connection connection = 1; -} - -message ListConnectionsRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - int32 limit = 2 [(buf.validate.field).int32 = { - gte: 0 - lte: 200 - }]; - int32 offset = 3 [(buf.validate.field).int32.gte = 0]; - string organization_id = 4 [(buf.validate.field).string.min_len = 1]; - string provider_id = 5; - AuthType auth_type = 6; - string capability = 7; - HealthStatus health_status = 8; - CredentialState credential_state = 9; -} - -message ListConnectionsResponse { - repeated Connection connections = 1; - int32 total = 2; -} - -// UpcomingCallSourceState distinguishes a connected calendar with no matching -// calls from a workspace that has not connected a supported calendar. -enum UpcomingCallSourceState { - UPCOMING_CALL_SOURCE_STATE_UNSPECIFIED = 0; - UPCOMING_CALL_SOURCE_STATE_AVAILABLE = 1; - UPCOMING_CALL_SOURCE_STATE_NOT_CONNECTED = 2; -} - -// ListUpcomingCallsRequest intentionally has no connection identifier. The -// Connector owner resolves every eligible calendar connection from the -// authenticated tenant scope. -message ListUpcomingCallsRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - int32 limit = 3 [(buf.validate.field).int32 = { - gte: 0 - lte: 100 - }]; -} - -message ListUpcomingCallsResponse { - repeated UpcomingCall calls = 1; - UpcomingCallSourceState source_state = 2; -} - -// UpcomingCall is a safe typed projection of one connected provider event. -// Provider payloads and source connection IDs are deliberately omitted. -message UpcomingCall { - string id = 1 [(buf.validate.field).string.min_len = 1]; - string title = 2 [(buf.validate.field).string.max_len = 512]; - string join_url = 3 [(buf.validate.field).string.uri = true]; - google.protobuf.Timestamp starts_at = 4; - google.protobuf.Timestamp ends_at = 5; -} - -message ListProvidersRequest { - string query = 1; - AuthType auth_type = 2 [(buf.validate.field).enum.defined_only = true]; - int32 limit = 3 [(buf.validate.field).int32 = { - gte: 0 - lte: 200 - }]; - int32 offset = 4 [(buf.validate.field).int32.gte = 0]; -} - -message ListProvidersResponse { - repeated ConnectorProvider providers = 1; - int32 total = 2 [(buf.validate.field).int32.gte = 0]; - string catalog_version = 3; - // Changes whenever qualification visibility changes inside one catalog - // revision. Clients compare this across pages and preview/ready reads and - // restart the read when it differs. - string visibility_snapshot = 4; -} - -enum ProviderQualificationState { - PROVIDER_QUALIFICATION_STATE_UNSPECIFIED = 0; - PROVIDER_QUALIFICATION_STATE_PENDING = 1; - PROVIDER_QUALIFICATION_STATE_QUALIFIED = 2; -} - -message ListProviderPreviewsRequest { - string query = 1; - int32 limit = 2 [(buf.validate.field).int32 = { - gte: 0 - lte: 200 - }]; - int32 offset = 3 [(buf.validate.field).int32.gte = 0]; -} - -// ConnectorProviderPreview is safe discovery metadata for an installed -// provider that is not yet customer-visible. It deliberately excludes auth, -// endpoint, credential, action, and request-planning fields. -message ConnectorProviderPreview { - string id = 1 [(buf.validate.field).string.min_len = 1]; - string display_name = 2; - repeated string catalog_categories = 3; - string tier = 4; - string rollout_kind = 5; - ProviderQualificationState qualification_state = 6 [(buf.validate.field).enum.defined_only = true]; - int32 resource_family_count = 7 [(buf.validate.field).int32.gte = 0]; - int32 provider_action_count = 8 [(buf.validate.field).int32.gte = 0]; - int32 required_family_count = 9 [(buf.validate.field).int32.gte = 0]; - int32 qualified_family_count = 10 [(buf.validate.field).int32.gte = 0]; - bool customer_visible = 11; - // Customer-facing source description. Empty means unknown. - string description = 12; - // Safe family metadata for discovery. These summaries carry no endpoint, - // auth, credential, or request-planning data. - repeated ConnectorResourceFamilySummary resource_families = 13; - // Stable action identifiers are kept separate from readable resource types. - repeated string provider_action_ids = 14; -} - -message ListProviderPreviewsResponse { - repeated ConnectorProviderPreview previews = 1; - int32 total = 2 [(buf.validate.field).int32.gte = 0]; - string catalog_version = 3; - string visibility_snapshot = 4; -} - -message RefreshConnectionRequest { - string id = 1 [(buf.validate.field).string.min_len = 1]; -} - -message RefreshConnectionResponse { - Connection connection = 1; -} - -message RevokeConnectionRequest { - string id = 1 [(buf.validate.field).string.min_len = 1]; - // reason is an optional audit-trail string the caller supplies (e.g. - // "rotating credentials", "decommissioning workspace"). The - // connectors service writes it onto the disconnected event so the - // audit feed has actionable context instead of "Connection - // disconnected." Free-form, bounded to keep the event payload sane. - string reason = 2 [(buf.validate.field).string.max_len = 512]; -} - -message RevokeConnectionResponse {} - -message GetHealthRequest { - string connection_id = 1 [(buf.validate.field).string.min_len = 1]; -} - -message GetHealthResponse { - ConnectionHealth health = 1; -} - -message ResolveSourceOfTruthRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - SourceOfTruthArea area = 2; - string organization_id = 3 [(buf.validate.field).string.min_len = 1]; -} - -message ResolveSourceOfTruthResponse { - SourceOfTruthPolicy policy = 1; - Connection primary_connection = 2; -} - -message GetDegradedReadPolicyRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; -} - -message GetDegradedReadPolicyResponse { - DegradedReadPolicy policy = 1; -} - -message SetSourceOfTruthPolicyRequest { - SourceOfTruthPolicy policy = 1 [(buf.validate.field).required = true]; -} - -message SetSourceOfTruthPolicyResponse { - SourceOfTruthPolicy policy = 1; -} - -message GetCapabilitiesRequest { - string connection_id = 1 [(buf.validate.field).string.min_len = 1]; -} - -message GetCapabilitiesResponse { - repeated string capabilities = 1; -} - -message InitiateOAuthFlowRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string provider_id = 3 [(buf.validate.field).string.min_len = 1]; - // Optional explicit scopes. When empty the provider catalog default scopes - // are used. - repeated string scopes = 4; - // Absolute URL the provider should redirect back to with the auth code. - // The UI passes its own /integrations/{provider}/oauth-callback URL here. - string redirect_uri = 5 [(buf.validate.field).string.min_len = 1]; - // Optional GitHub organization or username with this App already installed. - // Selects user OAuth instead of new installation; never grants tenant access. - string github_existing_account = 6; - // Selects the provider identity represented by the resulting token. The - // app actor is currently supported only by Linear agent installations. - OAuthActorMode actor_mode = 7; - // Existing connection whose provider actor should be privately linked to - // the authenticated Deixic principal. This runs user OAuth only, verifies - // the provider subject, and never replaces the connection's credentials. - string actor_link_connection_id = 8; -} - -enum OAuthActorMode { - O_AUTH_ACTOR_MODE_UNSPECIFIED = 0; - O_AUTH_ACTOR_MODE_USER = 1; - O_AUTH_ACTOR_MODE_APP = 2; -} - -message InitiateOAuthFlowResponse { - // Fully-formed URL the UI launches in the OAuth popup. - string authorize_url = 1; - // Opaque server-issued state token. The UI passes this back unchanged on - // CompleteOAuthFlow so the server can replay-check the exchange. - string state = 2; - // Time at which the state token becomes invalid. - google.protobuf.Timestamp expires_at = 3; - // Untrusted coordinate for existing-installation OAuth. Completion rechecks - // the authenticated provider user's ownership before registering a connection. - uint64 github_installation_id = 4; -} - -message CompleteOAuthFlowRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string provider_id = 3 [(buf.validate.field).string.min_len = 1]; - // State token returned from InitiateOAuthFlow. - string state = 4 [(buf.validate.field).string.min_len = 1]; - // Authorization code returned by the provider on the redirect. Required on - // the first completion and empty only when selected_tenant_id completes an - // already-custodied multi-tenant authorization. - string code = 5; - // Same redirect_uri passed to InitiateOAuthFlow; providers verify it. - string redirect_uri = 6 [(buf.validate.field).string.min_len = 1]; - // Human-friendly label persisted on the connection record. - string display_name = 7; - string idempotency_key = 8; - // Untrusted GitHub callback coordinate; verified against the authenticated - // provider user and configured product App before connection registration. - uint64 github_installation_id = 9; - // Exact provider tenant selected from a prior CompleteOAuthFlow response. - // Leave empty on the authorization-code exchange. The server never chooses - // an authorized tenant implicitly. - string selected_tenant_id = 10; -} - -message CompleteOAuthFlowResponse { - Connection connection = 1; - // Authorized provider tenants requiring explicit customer selection before - // the connection can be registered. Empty when connection is populated. - repeated OAuthProviderTenant authorized_tenants = 2; - bool tenant_selection_required = 3; -} - -message OAuthProviderTenant { - string tenant_id = 1; - string tenant_name = 2; - string tenant_type = 3; -} - -message InitiateMcpOAuthFlowRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string server_id = 3 [(buf.validate.field).string.min_len = 1]; - string profile_id = 4 [(buf.validate.field).string.min_len = 1]; - string profile_name = 5 [(buf.validate.field).string.min_len = 1]; - // principal or organization; this is a profile binding, never inferred from - // a Connector Connection's created_by field. - string subject_kind = 6 [(buf.validate.field).string.min_len = 1]; - string subject_id = 7 [(buf.validate.field).string.min_len = 1]; - string resource_url = 8 [(buf.validate.field).string.uri_ref = true]; - repeated string scopes = 9; - string redirect_uri = 10 [(buf.validate.field).string.uri = true]; - // Admin-supplied public client configuration. client_secret_ref is an - // opaque broker reference and is never a secret value. - string client_id = 11; - string client_secret_ref = 12; - string idempotency_key = 13; - // Immutable Console profile generation bound to the callback. A callback - // from an older reauthorization can never complete a newer generation. - int64 profile_generation = 14 [(buf.validate.field).int64.gt = 0]; -} - -message InitiateMcpOAuthFlowResponse { - string authorize_url = 1; - string state = 2; - google.protobuf.Timestamp expires_at = 3; - string resource_metadata_url = 4; - string authorization_server = 5; - repeated string scopes = 6; - string client_id = 7; -} - -message CompleteMcpOAuthFlowRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string server_id = 3 [(buf.validate.field).string.min_len = 1]; - string profile_id = 4 [(buf.validate.field).string.min_len = 1]; - string state = 5 [(buf.validate.field).string.min_len = 1]; - // Empty code is permitted only for a provider error response; the - // Connector validates the raw iss binding before acting on any error text. - string code = 6; - string redirect_uri = 7 [(buf.validate.field).string.uri = true]; - string idempotency_key = 8 [(buf.validate.field).string.min_len = 1]; - int64 profile_generation = 9 [(buf.validate.field).int64.gt = 0]; - // Raw RFC 9207 authorization response fields. These are additive so older - // callers continue to send the same request shape. - string authorization_response_iss = 10; - string provider_error = 11; - string provider_error_description = 12; - string provider_error_uri = 13; -} - -message CompleteMcpOAuthFlowResponse { - string connection_ref = 1; - string grant_id = 2; - repeated string scopes = 3; - google.protobuf.Timestamp expires_at = 4; - int64 grant_version = 5; - string profile_id = 6; -} - -message RevokeMcpOAuthGrantRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string grant_id = 3 [(buf.validate.field).string.min_len = 1]; - string connection_ref = 4 [(buf.validate.field).string.min_len = 1]; - string reason_code = 5 [(buf.validate.field).string.min_len = 1]; - string profile_id = 6; - int64 profile_generation = 7 [(buf.validate.field).int64.gt = 0]; -} - -message RevokeMcpOAuthGrantResponse { - bool revoked = 1; - string grant_id = 2; -} - -// TriggerSyncRequest enqueues one sync run. Field numbers mirror the -// connectors-rs owner proto exactly; the connectors service is the -// authoritative owner of this contract. -message TriggerSyncRequest { - string connection_id = 1 [(buf.validate.field).string.min_len = 1]; - // Free-text run classification (for example "manual", "scheduled", - // "initial"). The connectors service defaults to "manual" when empty. - string run_type = 2; - string idempotency_key = 3 [(buf.validate.field).string.min_len = 1]; - // Stable resource stream to execute. Required. - string stream_id = 4 [(buf.validate.field).string.min_len = 1]; -} - -message TriggerSyncResponse { - string queue_id = 1; - string connection_id = 2; - string run_type = 3; - // The queue row's actual status after the call: "queued" for a new or - // revived row, or the in-flight/terminal status ("leased", "completed", - // "failed", "cancelled") of an existing row the call did not disturb. - string status = 4; - // Durable stream identity stored on the queue row. - string stream_id = 5; -} - -message ExecuteConnectorActionRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string connection_id = 3 [(buf.validate.field).string.min_len = 1]; - string action_id = 4 [(buf.validate.field).string.min_len = 1]; - string idempotency_key = 5 [(buf.validate.field).string.min_len = 1]; - string approval_request_id = 6; - string action_digest = 7 [(buf.validate.field).string.min_len = 1]; - string body_json = 8; - string expected_provider_revision = 9; - // Routine server-owned channel actions use a bounded authority grant rather - // than manufacturing an approval request. Exactly one authority field is - // accepted by ConnectorService. - string authority_grant_id = 10; - // Canonical owner: evalops/connectors-rs. This opaque Identity remote-work - // token attests one exact action delegated by the authority-checking - // caller (tool-executor's direct connector adapter or platform-worker's - // proactive action dispatch). Connectors must verify both this token and - // every exact request binding; neither the ordinary RPC bearer nor this - // field alone is sufficient authorization. - string execution_authority_token = 11; - // Canonical digest of the exact action, catalog revision, authority, - // expected provider revision, and normalized body. action_digest remains - // the catalog digest. - string canonical_request_digest = 12; -} - -message ExecuteConnectorActionResponse { - string connector_action_execution_id = 1; - // Deprecated compatibility projection. New consumers must use action_state. - string state = 2 [deprecated = true]; - string provider_object_id = 3; - string provider_revision = 4; - bool idempotent_replay = 5; - string redacted_result_json = 6; - ConnectorActionExecutionState action_state = 7 [(buf.validate.field).enum.defined_only = true]; - ConnectorActionErrorKind error_kind = 8; - string error_code = 9; - bool retry_eligible = 10; - optional uint64 retry_after_seconds = 11; - string operator_detail = 12; - string provider_channel_id = 13; - string provider_message_ts = 14; - bool reconciliation_required = 15; -} - -enum ConnectorActionExecutionState { - CONNECTOR_ACTION_EXECUTION_STATE_UNSPECIFIED = 0; - CONNECTOR_ACTION_EXECUTION_STATE_EXECUTING = 1; - CONNECTOR_ACTION_EXECUTION_STATE_SUCCEEDED = 2; - CONNECTOR_ACTION_EXECUTION_STATE_FAILED = 3; -} - -enum ConnectorActionErrorKind { - CONNECTOR_ACTION_ERROR_KIND_UNSPECIFIED = 0; - CONNECTOR_ACTION_ERROR_KIND_RATE_LIMITED = 1; - CONNECTOR_ACTION_ERROR_KIND_PROVIDER = 2; - CONNECTOR_ACTION_ERROR_KIND_INVALID_AUTH = 3; - CONNECTOR_ACTION_ERROR_KIND_MISSING_SCOPE = 4; - CONNECTOR_ACTION_ERROR_KIND_INACCESSIBLE_CHANNEL = 5; - CONNECTOR_ACTION_ERROR_KIND_AMBIGUOUS = 6; -} - -// ---- Stream state --------------------------------------------------------- - -message StreamCursorState { - string stream_id = 1; - string stable_id = 2; - bool has_cursor = 3; - string cursor_value = 4; - google.protobuf.Timestamp updated_at = 5; -} - -message StreamRunSummary { - string connector_run_id = 1; - string status = 2; - string outcome = 3; - google.protobuf.Timestamp started_at = 4; - google.protobuf.Timestamp finished_at = 5; - string error_detail = 6; -} - -message ConnectionStream { - string stream_id = 1; - string stable_id = 2; - ReplicationMode replication_mode = 3; - bool selected_by_default = 4; - repeated string primary_key = 5; - string cursor_field = 6; - StreamCursorState cursor = 7; - StreamRunSummary last_run = 8; -} - -message ListConnectionStreamsRequest { - string connection_id = 1; -} - -message ListConnectionStreamsResponse { - repeated ConnectionStream streams = 1; -} - -message SyncPartitionState { - string partition_key = 1; - string cursor_value_json = 2; - string high_watermark_json = 3; - string signpost_value_json = 4; - string state_status = 5; - google.protobuf.Timestamp updated_at = 6; -} - -message GetStreamStateRequest { - string connection_id = 1; - string stream_id = 2; -} - -message GetStreamStateResponse { - ConnectionStream stream = 1; - repeated SyncPartitionState partitions = 2; - int64 dead_letter_count = 3; -} - -message ResetStreamStateRequest { - string connection_id = 1; - string stream_id = 2; - optional string cursor_value = 3; - string idempotency_key = 4; -} - -message ResetStreamStateResponse { - StreamCursorState cursor = 1; -} - -// ---- Sync schedules ------------------------------------------------------- - -message SyncSchedule { - string connection_id = 1; - string stream_id = 2; - string organization_id = 3; - string workspace_id = 4; - string run_type = 5; - int32 interval_seconds = 6; - bool enabled = 7; - google.protobuf.Timestamp last_scheduled_at = 8; - google.protobuf.Timestamp created_at = 9; - google.protobuf.Timestamp updated_at = 10; - google.protobuf.Timestamp last_completed_at = 11; -} - -message CreateSyncScheduleRequest { - string organization_id = 1; - string workspace_id = 2; - string connection_id = 3; - string stream_id = 4; - int32 interval_seconds = 5; - bool enabled = 6; - string idempotency_key = 7; -} - -message CreateSyncScheduleResponse { - SyncSchedule schedule = 1; - bool idempotent_replay = 2; -} - -message ListSyncSchedulesRequest { - string connection_id = 1; -} - -message ListSyncSchedulesResponse { - repeated SyncSchedule schedules = 1; -} - -// ---- Provider-resource ownership and lifecycle --------------------------- - -enum ProviderResourceVisibilityClass { - PROVIDER_RESOURCE_VISIBILITY_CLASS_UNSPECIFIED = 0; - PROVIDER_RESOURCE_VISIBILITY_CLASS_WORKSPACE_PUBLIC = 1; - PROVIDER_RESOURCE_VISIBILITY_CLASS_EXPLICIT_PRINCIPALS = 2; - PROVIDER_RESOURCE_VISIBILITY_CLASS_GROUP_MEMBERSHIP = 3; - PROVIDER_RESOURCE_VISIBILITY_CLASS_CONNECTION_PRIVATE = 4; -} - -enum ProviderResourceLifecycleState { - PROVIDER_RESOURCE_LIFECYCLE_STATE_UNSPECIFIED = 0; - PROVIDER_RESOURCE_LIFECYCLE_STATE_ACTIVE = 1; - PROVIDER_RESOURCE_LIFECYCLE_STATE_ARCHIVED = 2; - PROVIDER_RESOURCE_LIFECYCLE_STATE_DELETED = 3; - PROVIDER_RESOURCE_LIFECYCLE_STATE_CONNECTION_REVOKED = 4; - PROVIDER_RESOURCE_LIFECYCLE_STATE_QUARANTINED = 5; -} - -enum ProviderContentTrust { - PROVIDER_CONTENT_TRUST_UNSPECIFIED = 0; - PROVIDER_CONTENT_TRUST_UNTRUSTED_PROVIDER_CONTENT = 1; -} - -message ProviderResourceEnvelope { - string schema_version = 1; - string stable_resource_id = 2; - string organization_id = 3; - string workspace_id = 4; - string provider_id = 5; - string connection_id = 6; - string source_family_id = 7; - string originating_principal_id = 8; - string resource_kind = 9; - string parent_resource_id = 10; - ProviderResourceVisibilityClass visibility_class = 11; - repeated string visibility_principal_ids = 12; - string visibility_membership_ref = 13; - ProviderContentTrust content_trust = 14; - string payload_sha256 = 15; - string provider_revision = 16; - ProviderResourceLifecycleState lifecycle_state = 17; - uint64 lifecycle_generation = 18; - string purge_correlation_id = 19; -} - -// Coordinates of a current Connector-owned observation; never caller-provided facts. -message GetBusinessSourceRecordRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string connection_id = 3 [(buf.validate.field).string.min_len = 1]; - string family_stable_id = 4 [(buf.validate.field).string.min_len = 1]; - string record_id = 5 [(buf.validate.field).string.min_len = 1]; -} - -message GetBusinessSourceRecordResponse { - ProviderResourceEnvelope envelope = 1; - string last_event_id = 2; - string external_id = 3; - // Present only when a supported provider mapping supplies a display name. - string display_name = 4; - // Time this observation entered the current projection, not source effective time. - google.protobuf.Timestamp observed_at = 5; - // Optional canonical website supplied by a supported provider mapping. - string website = 6; -} diff --git a/proto/console/v1/console.proto b/proto/console/v1/console.proto deleted file mode 100644 index 034467d..0000000 --- a/proto/console/v1/console.proto +++ /dev/null @@ -1,11235 +0,0 @@ -syntax = "proto3"; - -package console.v1; - -import "agentruntime/v1/runtime.proto"; -import "agents/v1/agents.proto"; -import "buf/validate/validate.proto"; -import "common/v1/authz.proto"; -import "common/v1/classification.proto"; -import "common/v1/risk.proto"; -import "connectors/v1/connectors.proto"; -import "google/protobuf/struct.proto"; -import "google/protobuf/timestamp.proto"; -import "memory/v1/memory.proto"; -import "meter/v1/meter.proto"; -import "orbcontrol/v1/orb_control.proto"; -import "platform/v1/platform.proto"; -import "remoterunner/v1/remoterunner.proto"; -import "toolexecution/v1/toolexecution.proto"; -import "traces/v1/traces.proto"; -import "vfs/v1/filesystem.proto"; - -option go_package = "github.com/evalops/platform/gen/go/console/v1;consolev1"; - -// ConsoleService provides the product-facing AI operations read model for the -// EvalOps web console. It composes agent inventory, traces, approvals, -// governance, usage, integrations, and posture without exposing protocol -// details such as MCP as the primary product contract. -service ConsoleService { - // Evaluates a versioned compliance profile against owner-fetched, tenant-scoped facts. - rpc AssessComplianceSubject(AssessComplianceSubjectRequest) returns (AssessComplianceSubjectResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc RecordComplianceAssessment(RecordComplianceAssessmentRequest) returns (RecordComplianceAssessmentResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc GetComplianceAssessment(GetComplianceAssessmentRequest) returns (GetComplianceAssessmentResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Lists built-in native business blueprints available to every authorized tenant. - rpc ListBusinessBlueprints(ListBusinessBlueprintsRequest) returns (ListBusinessBlueprintsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Clones a pinned built-in blueprint into editable tenant-owned definitions and a draft form. - rpc CloneBusinessBlueprint(CloneBusinessBlueprintRequest) returns (CloneBusinessBlueprintResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // GetBusinessProcessDefinition reads immutable process definitions within the tenant. - rpc GetBusinessProcessDefinition(GetBusinessProcessDefinitionRequest) returns (GetBusinessProcessDefinitionResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ListBusinessProcessDefinitions reads immutable process definitions within the tenant. - rpc ListBusinessProcessDefinitions(ListBusinessProcessDefinitionsRequest) returns (ListBusinessProcessDefinitionsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // DefineBusinessProcess accesses the durable object-bound process owner. - rpc DefineBusinessProcess(DefineBusinessProcessRequest) returns (DefineBusinessProcessResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // StartBusinessProcess accesses the durable object-bound process owner. - rpc StartBusinessProcess(StartBusinessProcessRequest) returns (StartBusinessProcessResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // GetBusinessProcess accesses the durable object-bound process owner. - rpc GetBusinessProcess(GetBusinessProcessRequest) returns (GetBusinessProcessResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ListBusinessProcesses accesses the durable object-bound process owner. - rpc ListBusinessProcesses(ListBusinessProcessesRequest) returns (ListBusinessProcessesResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // TransitionBusinessProcess accesses the durable object-bound process owner. - rpc TransitionBusinessProcess(TransitionBusinessProcessRequest) returns (TransitionBusinessProcessResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Checks source-authority readiness without changing accepted state. - rpc PrepareBusinessObjectAuthorityTransfer(PrepareBusinessObjectAuthorityTransferRequest) returns (PrepareBusinessObjectAuthorityTransferResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Checks source-authority readiness without changing accepted state. - rpc FinalizeBusinessObjectAuthorityTransfer(FinalizeBusinessObjectAuthorityTransferRequest) returns (FinalizeBusinessObjectAuthorityTransferResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // DefineBusinessObjectType uses tenant-scoped durable business object state. - rpc DefineBusinessObjectType(DefineBusinessObjectTypeRequest) returns (DefineBusinessObjectTypeResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // GetBusinessObjectType reads an exact immutable published schema revision. - rpc GetBusinessObjectType(GetBusinessObjectTypeRequest) returns (GetBusinessObjectTypeResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // ListBusinessObjectTypes uses tenant-scoped durable business object state. - rpc ListBusinessObjectTypes(ListBusinessObjectTypesRequest) returns (ListBusinessObjectTypesResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // CreateBusinessObject uses tenant-scoped durable business object state. - rpc CreateBusinessObject(CreateBusinessObjectRequest) returns (CreateBusinessObjectResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // GetBusinessObject uses tenant-scoped durable business object state. - rpc GetBusinessObject(GetBusinessObjectRequest) returns (GetBusinessObjectResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // ListBusinessObjects uses tenant-scoped durable business object state. - rpc ListBusinessObjects(ListBusinessObjectsRequest) returns (ListBusinessObjectsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // UpdateBusinessObject uses tenant-scoped durable business object state. - rpc UpdateBusinessObject(UpdateBusinessObjectRequest) returns (UpdateBusinessObjectResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // DeleteBusinessObject uses tenant-scoped durable business object state. - rpc DeleteBusinessObject(DeleteBusinessObjectRequest) returns (DeleteBusinessObjectResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // ListBusinessObjectRevisions uses tenant-scoped durable business object state. - rpc ListBusinessObjectRevisions(ListBusinessObjectRevisionsRequest) returns (ListBusinessObjectRevisionsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // BindBusinessObjectSource uses tenant-scoped durable business object state. - rpc BindBusinessObjectSource(BindBusinessObjectSourceRequest) returns (BindBusinessObjectSourceResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // AdmitBusinessObjectObservation uses tenant-scoped durable business object state. - rpc AdmitBusinessObjectObservation(AdmitBusinessObjectObservationRequest) returns (AdmitBusinessObjectObservationResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // ListBusinessObjectRelationships uses tenant-scoped durable business object state. - rpc ListBusinessObjectRelationships(ListBusinessObjectRelationshipsRequest) returns (ListBusinessObjectRelationshipsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // CreateBusinessObjectRelationship uses tenant-scoped durable business object state. - rpc CreateBusinessObjectRelationship(CreateBusinessObjectRelationshipRequest) returns (CreateBusinessObjectRelationshipResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // DeleteBusinessObjectRelationship uses tenant-scoped durable business object state. - rpc DeleteBusinessObjectRelationship(DeleteBusinessObjectRelationshipRequest) returns (DeleteBusinessObjectRelationshipResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // CreateCaptureForm creates a draft with its first immutable form version. - // The version pins the target BusinessObjectType revision and all typed - // controls/mappings used by later public submissions. - rpc CreateCaptureForm(CreateCaptureFormRequest) returns (CreateCaptureFormResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // ListCaptureForms returns the tenant's durable form identities and current - // publication pointers so an administrator can rediscover state after a - // reload without relying on browser-local drafts. - rpc ListCaptureForms(ListCaptureFormsRequest) returns (ListCaptureFormsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // GetCaptureForm reads a tenant-scoped form and, when requested, one exact - // immutable version. It never silently substitutes the latest version for a - // caller-provided version id. - rpc GetCaptureForm(GetCaptureFormRequest) returns (GetCaptureFormResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // UpdateCaptureForm appends a new immutable form version. Accepted or - // published versions are never edited in place. - rpc UpdateCaptureForm(UpdateCaptureFormRequest) returns (UpdateCaptureFormResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // PublishCaptureForm exposes one exact immutable version through a scoped - // public publication. The server derives the tenant and object target from - // that publication; callers cannot choose them through public input. - rpc PublishCaptureForm(PublishCaptureFormRequest) returns (PublishCaptureFormResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // RevokeCaptureFormPublication closes a public publication while retaining - // its immutable form history and durable submissions. - rpc RevokeCaptureFormPublication(RevokeCaptureFormPublicationRequest) returns (RevokeCaptureFormPublicationResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // CreateCaptureFormInvitation uses recipient verification at the Capture Forms owner. - rpc CreateCaptureFormInvitation(CreateCaptureFormInvitationRequest) returns (CreateCaptureFormInvitationResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // RevokeCaptureFormInvitation uses recipient verification at the Capture Forms owner. - rpc RevokeCaptureFormInvitation(RevokeCaptureFormInvitationRequest) returns (RevokeCaptureFormInvitationResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // GetInvitedCaptureForm uses recipient verification at the Capture Forms owner. - rpc GetInvitedCaptureForm(GetInvitedCaptureFormRequest) returns (GetInvitedCaptureFormResponse) { - option (common.v1.public) = true; - } - - // SubmitInvitedCaptureForm uses recipient verification at the Capture Forms owner. - rpc SubmitInvitedCaptureForm(SubmitInvitedCaptureFormRequest) returns (SubmitInvitedCaptureFormResponse) { - option (common.v1.public) = true; - } - - // GetPublishedCaptureForm resolves one active publication using its opaque, - // server-issued publication id. The id is the reusable public capability in - // the form URL; public callers provide no tenant or workspace coordinates. - rpc GetPublishedCaptureForm(GetPublishedCaptureFormRequest) returns (GetPublishedCaptureFormResponse) { - option (common.v1.public) = true; - } - - // GetPublishedCaptureFormBrandingAsset serves one fixed-role asset from the - // exact immutable version pinned by a live publication. The publication id - // is the only capability input; callers cannot select a tenant, object, or - // VFS version. - rpc GetPublishedCaptureFormBrandingAsset(GetPublishedCaptureFormBrandingAssetRequest) returns (GetPublishedCaptureFormBrandingAssetResponse) { - option (common.v1.public) = true; - } - - // SubmitPublishedCaptureForm accepts typed answers through one active, - // publication-scoped public capability. The owner resolves the tenant, - // pinned version, and object target from that publication id, validates every - // answer, and persists a durable submission before any object mapping. - rpc SubmitPublishedCaptureForm(SubmitPublishedCaptureFormRequest) returns (SubmitPublishedCaptureFormResponse) { - option (common.v1.public) = true; - } - - // BeginPublishedCaptureFormUpload reserves one server-owned VFS upload - // grant for a FILE input on the live publication. The publication resolves - // tenant, form, version, and upload constraints; public callers cannot - // choose any of those coordinates. - rpc BeginPublishedCaptureFormUpload(BeginPublishedCaptureFormUploadRequest) returns (BeginPublishedCaptureFormUploadResponse) { - option (common.v1.public) = true; - } - - // CompletePublishedCaptureFormUpload commits the exact VFS lease reserved - // for one publication/input pair. The completed object/version is the only - // file asset accepted in a later typed form answer. - rpc CompletePublishedCaptureFormUpload(CompletePublishedCaptureFormUploadRequest) returns (CompletePublishedCaptureFormUploadResponse) { - option (common.v1.public) = true; - } - - // GetCaptureFormSubmission reads one tenant-scoped durable submission and - // its accepted BusinessObject linkage, if review has accepted it. - rpc GetCaptureFormSubmission(GetCaptureFormSubmissionRequest) returns (GetCaptureFormSubmissionResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // ListCaptureFormSubmissions lists bounded durable submissions for one form. - rpc ListCaptureFormSubmissions(ListCaptureFormSubmissionsRequest) returns (ListCaptureFormSubmissionsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // ReviewCaptureFormSubmission accepts or rejects one durable submission. - // Acceptance creates exactly one mapped BusinessObject through the existing - // BusinessObject owner and returns its durable identity. - rpc ReviewCaptureFormSubmission(ReviewCaptureFormSubmissionRequest) returns (ReviewCaptureFormSubmissionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // GetInferenceCreditAutoRefill uses authorized workspace billing consent. - rpc GetInferenceCreditAutoRefill(GetInferenceCreditAutoRefillRequest) returns (GetInferenceCreditAutoRefillResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // UpdateInferenceCreditAutoRefill uses authorized workspace billing consent. - rpc UpdateInferenceCreditAutoRefill(UpdateInferenceCreditAutoRefillRequest) returns (UpdateInferenceCreditAutoRefillResponse) { - option (common.v1.required_scopes) = "billing:admin"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // CompleteInferenceCreditAutoRefill uses authorized workspace billing consent. - rpc CompleteInferenceCreditAutoRefill(CompleteInferenceCreditAutoRefillRequest) returns (CompleteInferenceCreditAutoRefillResponse) { - option (common.v1.required_scopes) = "billing:admin"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // ListInferenceCreditReceipts returns verified payments for the authorized workspace. - rpc ListInferenceCreditReceipts(ListInferenceCreditReceiptsRequest) returns (ListInferenceCreditReceiptsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // GetOverview returns the first-screen AI operations summary. - rpc GetOverview(GetOverviewRequest) returns (GetOverviewResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // GetConsoleBootSnapshot returns the projected first-paint console state. - rpc GetConsoleBootSnapshot(GetConsoleBootSnapshotRequest) returns (GetConsoleBootSnapshotResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ListAssets returns AI agents, provider keys, model surfaces, and - // integrations visible to the current workspace. - rpc ListAssets(ListAssetsRequest) returns (ListAssetsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // GetAsset returns a single AI estate asset and related resources. - rpc GetAsset(GetAssetRequest) returns (GetAssetResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ListActivity returns normalized run, trace, approval, eval, risk, and cost - // events for the console timeline. - rpc ListActivity(ListActivityRequest) returns (ListActivityResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // SearchStaffWorkspaceDirectory returns a bounded, metadata-only workspace directory for staff. - rpc SearchStaffWorkspaceDirectory(SearchStaffWorkspaceDirectoryRequest) returns (SearchStaffWorkspaceDirectoryResponse) { - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // GetStaffWorkspaceContext returns redacted operational summaries under an exact active grant. - rpc GetStaffWorkspaceContext(GetStaffWorkspaceContextRequest) returns (GetStaffWorkspaceContextResponse) { - option (common.v1.required_scopes) = "support_access.manage"; - option (common.v1.staff_account_required) = true; - option (common.v1.staff_cross_tenant) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Administrative composition over the existing Meter GetPrepaidCreditBalance owner. - rpc GetStaffManagedInferenceFunding(GetStaffManagedInferenceFundingRequest) returns (meter.v1.GetPrepaidCreditBalanceResponse) { - option (common.v1.required_scopes) = "support_access.manage"; - option (common.v1.required_scopes) = "managed_inference:admin"; - option (common.v1.required_scopes) = "meter:read"; - option (common.v1.staff_account_required) = true; - option (common.v1.staff_cross_tenant) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Administrative composition over the existing Meter GrantDevelopmentCredits owner. - rpc GrantStaffManagedInferenceCredits(GrantStaffManagedInferenceCreditsRequest) returns (meter.v1.GrantDevelopmentCreditsResponse) { - option (common.v1.required_scopes) = "support_access.manage"; - option (common.v1.required_scopes) = "managed_inference:admin"; - option (common.v1.required_scopes) = "meter:credits:grant-development"; - option (common.v1.staff_account_required) = true; - option (common.v1.staff_cross_tenant) = true; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // Administrative composition over the existing Meter QueryUsage owner. - rpc GetStaffManagedInferenceUsage(GetStaffManagedInferenceUsageRequest) returns (meter.v1.QueryUsageResponse) { - option (common.v1.required_scopes) = "support_access.manage"; - option (common.v1.required_scopes) = "managed_inference:admin"; - option (common.v1.required_scopes) = "meter:read"; - option (common.v1.staff_account_required) = true; - option (common.v1.staff_cross_tenant) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Administrative composition over the existing Meter GetBudgetDashboard owner. - rpc GetStaffManagedInferenceBudget(GetStaffManagedInferenceBudgetRequest) returns (meter.v1.GetBudgetDashboardResponse) { - option (common.v1.required_scopes) = "support_access.manage"; - option (common.v1.required_scopes) = "managed_inference:admin"; - option (common.v1.required_scopes) = "meter:read"; - option (common.v1.staff_account_required) = true; - option (common.v1.staff_cross_tenant) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Administrative composition over the existing Meter SetBudget owner. - rpc SetStaffManagedInferenceBudget(SetStaffManagedInferenceBudgetRequest) returns (meter.v1.SetBudgetResponse) { - option (common.v1.required_scopes) = "support_access.manage"; - option (common.v1.required_scopes) = "managed_inference:admin"; - option (common.v1.required_scopes) = "meter:write"; - option (common.v1.staff_account_required) = true; - option (common.v1.staff_cross_tenant) = true; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // Read shared managed-inference readiness across tenants for an authorized administrator. - // Staff and customer readiness use the same route and tenant request contract. - // buf:lint:ignore RPC_REQUEST_STANDARD_NAME - rpc GetStaffManagedInferenceReadiness(GetStaffManagedInferenceReadinessRequest) returns (GetManagedInferenceReadinessResponse) { - option (common.v1.required_scopes) = "support_access.manage"; - option (common.v1.required_scopes) = "managed_inference:admin"; - option (common.v1.staff_account_required) = true; - option (common.v1.staff_cross_tenant) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Reports current managed-inference prerequisites for the exact authorized tenant. - // Informational only: execution issuance and admission recheck current authority. - rpc GetManagedInferenceReadiness(GetManagedInferenceReadinessRequest) returns (GetManagedInferenceReadinessResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ListManagedProviderAccessGrants returns the durable managed provider-access - // posture for the staff control plane. Default-deny: absent or disabled rows - // mean no managed access. - rpc ListManagedProviderAccessGrants(ListManagedProviderAccessGrantsRequest) returns (ListManagedProviderAccessGrantsResponse) { - option (common.v1.staff_account_required) = true; - option (common.v1.staff_cross_tenant) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ListManagedProviderAccessEvents reads immutable enrollment acceptance and delivery events. - rpc ListManagedProviderAccessEvents(ListManagedProviderAccessEventsRequest) returns (ListManagedProviderAccessEventsResponse) { - option (common.v1.staff_account_required) = true; - option (common.v1.staff_cross_tenant) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ListStaffManagedInferenceAdminEvents reads Meter-owned credit and budget audit receipts. - // (-- api-linter: core::0132::response-message-name=disabled - // aip.dev/not-precedent: This staff facade returns the canonical Meter audit - // response unchanged, preserving the published cross-service contract. --) - rpc ListStaffManagedInferenceAdminEvents(ListStaffManagedInferenceAdminEventsRequest) returns (meter.v1.ListManagedInferenceAdminEventsResponse) { - option (common.v1.staff_account_required) = true; - option (common.v1.staff_cross_tenant) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ListStaffManagedExecutionGrantEvents reads recorded issuer events for an exact tenant session. - rpc ListStaffManagedExecutionGrantEvents(ListStaffManagedExecutionGrantEventsRequest) returns (ListStaffManagedExecutionGrantEventsResponse) { - option (common.v1.staff_account_required) = true; - option (common.v1.staff_cross_tenant) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ListStaffManagedExecutionOutcomes reads recorded gateway decisions for an exact tenant lineage. - rpc ListStaffManagedExecutionOutcomes(ListStaffManagedExecutionOutcomesRequest) returns (ListStaffManagedExecutionOutcomesResponse) { - option (common.v1.staff_account_required) = true; - option (common.v1.staff_cross_tenant) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // UpsertManagedProviderAccessGrant enables or disables managed provider access - // for one (organization, provider, environment) tuple. It persists a durable, - // audited grant attributed to the acting staff principal and synchronizes the - // gateway enforcement row. A note is required for every mutation. - rpc UpsertManagedProviderAccessGrant(UpsertManagedProviderAccessGrantRequest) returns (UpsertManagedProviderAccessGrantResponse) { - option (common.v1.staff_account_required) = true; - option (common.v1.staff_cross_tenant) = true; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // RevokeManagedProviderAccessGrant disables an existing grant without deleting - // its audit history and synchronizes the gateway. A note is required. - rpc RevokeManagedProviderAccessGrant(RevokeManagedProviderAccessGrantRequest) returns (RevokeManagedProviderAccessGrantResponse) { - option (common.v1.staff_account_required) = true; - option (common.v1.staff_cross_tenant) = true; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // GetStaffInferenceRoutingProfile returns the deployment-allowlisted Dex - // inference targets and the durable override for the server-configured STAFF - // organization. The request intentionally carries no tenant id: callers - // cannot redirect this control toward a customer organization. - rpc GetStaffInferenceRoutingProfile(GetStaffInferenceRoutingProfileRequest) returns (GetStaffInferenceRoutingProfileResponse) { - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // UpdateStaffInferenceRoutingProfile changes the Dex provider/model pair for - // the server-configured STAFF organization. Targets must be registered and - // deployment-allowlisted; optimistic revision matching prevents stale writes. - rpc UpdateStaffInferenceRoutingProfile(UpdateStaffInferenceRoutingProfileRequest) returns (UpdateStaffInferenceRoutingProfileResponse) { - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // ListEvalResults returns online quality and eval outcomes for traced runs. - rpc ListEvalResults(ListEvalResultsRequest) returns (ListEvalResultsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ListCostUsage returns spend and token usage for traced AI work. - rpc ListCostUsage(ListCostUsageRequest) returns (ListCostUsageResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // RecordProviderCostSnapshot records a provider-owned monthly aggregate - // discovered through a tenant's connected integration resources. - rpc RecordProviderCostSnapshot(RecordProviderCostSnapshotRequest) returns (RecordProviderCostSnapshotResponse) { - option (common.v1.required_scopes) = "meter:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // ListAuthorityPosture returns server-owned credential and authority posture - // for agent, tool, and connector work. It lets clients ask which actor is - // assuming which authority without deriving posture from UI copy. - rpc ListAuthorityPosture(ListAuthorityPostureRequest) returns (ListAuthorityPostureResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ListAgentWorkforceRecords returns the server-owned Agent Workforce read - // model for security engineers. It keeps approval, action, credential, cost, - // and debug evidence typed so clients do not infer it from native event text. - rpc ListAgentWorkforceRecords(ListAgentWorkforceRecordsRequest) returns (ListAgentWorkforceRecordsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Reads one registered agent, its active immutable config, and its bound workspace connections. - rpc GetAgentProduct(GetAgentProductRequest) returns (GetAgentProductResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Clones safe behavior into a distinct registered agent without workspace credentials. - rpc CloneAgentProduct(CloneAgentProductRequest) returns (CloneAgentProductResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // Replaces editable agent behavior with a new immutable configuration version. - rpc UpdateAgentProduct(UpdateAgentProductRequest) returns (UpdateAgentProductResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // ListOrbControlTargets returns Platform-owned projections of Orb runtime targets. - rpc ListOrbControlTargets(ListOrbControlTargetsRequest) returns (ListOrbControlTargetsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // GetOrbControlTarget returns one Platform-owned Orb projection and receipt. - rpc GetOrbControlTarget(GetOrbControlTargetRequest) returns (GetOrbControlTargetResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // SubmitOrbControlAction records a governed wake or stop command in Platform. - rpc SubmitOrbControlAction(SubmitOrbControlActionRequest) returns (SubmitOrbControlActionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // SubmitAgentWorkforceEvidence persists operator/source evidence and returns - // the server-owned Agent Workforce state after the write. Approval authority - // remains derived by the backend evidence rules, not by client assertions. - rpc SubmitAgentWorkforceEvidence(SubmitAgentWorkforceEvidenceRequest) returns (SubmitAgentWorkforceEvidenceResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // ListFindings returns open risk and posture findings. - rpc ListFindings(ListFindingsRequest) returns (ListFindingsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // GetTraceDrilldown returns a trace summary and span tree for debugging. - rpc GetTraceDrilldown(GetTraceDrilldownRequest) returns (GetTraceDrilldownResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ListIntegrationTiles returns setup and health tiles for onboarding. - rpc ListIntegrationTiles(ListIntegrationTilesRequest) returns (ListIntegrationTilesResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ListPinnedSources returns the per-workspace pinned-source set. Pins are a - // user preference (see docs/integrations/console_integration_tiles_pin_audit.md); - // the FE merges them into IntegrationBackendState client-side. - rpc ListPinnedSources(ListPinnedSourcesRequest) returns (ListPinnedSourcesResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // SetPinnedSource creates or updates a single pin entry for the caller's - // workspace. Idempotent. The pinned_by audit field is filled from the caller - // identity server-side. - rpc SetPinnedSource(SetPinnedSourceRequest) returns (SetPinnedSourceResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // UnpinSource removes a pin entry. No-op if the pin does not exist. - rpc UnpinSource(UnpinSourceRequest) returns (UnpinSourceResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // CreateDexMcpServer registers one governed Streamable HTTP MCP endpoint. - // bearer_token is write-only and is never returned by read methods. - rpc CreateDexMcpServer(CreateDexMcpServerRequest) returns (CreateDexMcpServerResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc ListDexMcpServers(ListDexMcpServersRequest) returns (ListDexMcpServersResponse) { - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc GetDexMcpServer(GetDexMcpServerRequest) returns (GetDexMcpServerResponse) { - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // DiscoverDexMcpServer probes one registered endpoint while it is still - // disabled, persists the immutable catalog snapshot, and returns the - // redacted review projection. Discovery never activates tool dispatch. - rpc DiscoverDexMcpServer(DiscoverDexMcpServerRequest) returns (DiscoverDexMcpServerResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc UpdateDexMcpServer(UpdateDexMcpServerRequest) returns (UpdateDexMcpServerResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc DeleteDexMcpServer(DeleteDexMcpServerRequest) returns (DeleteDexMcpServerResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // Remote MCP OAuth profiles are named, tenant-bound control-plane objects. - // Tokens remain in the Connector broker; Console responses contain redacted - // state, scopes, versions, and opaque grant identities only. Personal - // profiles remain principal-bound. Organization-profile creation, - // completion, listing, revoke, and reauthorization additionally require the - // server-enforced connectors:admin workspace-administrator authority. - rpc InitiateDexMcpOAuthProfile(InitiateDexMcpOAuthProfileRequest) returns (InitiateDexMcpOAuthProfileResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc CompleteDexMcpOAuthProfile(CompleteDexMcpOAuthProfileRequest) returns (CompleteDexMcpOAuthProfileResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_CRITICAL; - } - rpc ListDexMcpOAuthProfiles(ListDexMcpOAuthProfilesRequest) returns (ListDexMcpOAuthProfilesResponse) { - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc RevokeDexMcpOAuthProfile(RevokeDexMcpOAuthProfileRequest) returns (RevokeDexMcpOAuthProfileResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - rpc ReauthorizeDexMcpOAuthProfile(ReauthorizeDexMcpOAuthProfileRequest) returns (ReauthorizeDexMcpOAuthProfileResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_CRITICAL; - } - // RegisterPrivateEndpoint records a tenant-bound AWS PrivateLink, GCP PSC, - // or customer-relay endpoint. Registration is non-routable until a private - // route and DNS observation is verified by a server-owned attestor. - rpc RegisterPrivateEndpoint(RegisterPrivateEndpointRequest) returns (RegisterPrivateEndpointResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // Verification is staff-only and remains unavailable until a server-owned - // AWS/GCP/relay attestor can bind a fresh route and DNS observation to this - // exact tenant endpoint. Caller-supplied evidence fields are compatibility - // inputs only and never establish a verified route. - rpc VerifyPrivateEndpoint(VerifyPrivateEndpointRequest) returns (VerifyPrivateEndpointResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - rpc ListPrivateEndpoints(ListPrivateEndpointsRequest) returns (ListPrivateEndpointsResponse) { - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc DeletePrivateEndpoint(DeletePrivateEndpointRequest) returns (DeletePrivateEndpointResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - rpc AttachPrivateEndpointToProfile(AttachPrivateEndpointToProfileRequest) returns (AttachPrivateEndpointToProfileResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - rpc ListGatewayEgressOrigins(ListGatewayEgressOriginsRequest) returns (ListGatewayEgressOriginsResponse) { - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // GetOnboardingPlan returns the recommended setup path for this workspace. - rpc GetOnboardingPlan(GetOnboardingPlanRequest) returns (GetOnboardingPlanResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ListOperatingChannels returns the chat-native company/domain channels the - // Console can actually operate for this workspace. Capability state is - // backend-owned so the UI does not invent domains or connection status. - rpc ListOperatingChannels(ListOperatingChannelsRequest) returns (ListOperatingChannelsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ListOperatingJobs returns the Platform-owned customer Work projection for - // admitted operating-chat objectives. Job identity is the canonical - // Platform objective work id; conversations and runtime attempts are typed - // correlations, not competing work records. This is a read model only: - // lifecycle mutations continue to route to their owning services. - rpc ListOperatingJobs(ListOperatingJobsRequest) returns (ListOperatingJobsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ArchiveOperatingThread changes only the durable conversation's list - // visibility. It does not delete messages, stop execution, or mutate a - // provider binding. Repeating a request with the same idempotency key and - // digest returns the original result. - rpc ArchiveOperatingThread(ArchiveOperatingThreadRequest) returns (ArchiveOperatingThreadResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // ForkOperatingThread copies one operating thread's conversation content - // into a new thread owned by the caller. The fork inherits content only: - // the source's model selection, Auto route, receipts, attachments, and turn - // records are all dropped, because each carries authority granted to the - // source's principal rather than to the forker. Repeating a request with - // the same idempotency key and digest returns the original fork. - rpc ForkOperatingThread(ForkOperatingThreadRequest) returns (ForkOperatingThreadResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // RenameOperatingThread replaces the durable user-visible title for one - // owner-backed operating thread. The desired title makes retries idempotent. - rpc RenameOperatingThread(RenameOperatingThreadRequest) returns (RenameOperatingThreadResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // GetOperatingThread returns the selected operating thread from its owning - // backend messages and receipts. - rpc GetOperatingThread(GetOperatingThreadRequest) returns (GetOperatingThreadResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // BootstrapThreadGateway authorizes one browser session for one exact - // operating thread and returns an in-memory, short-lived direct-gateway - // credential. The direct route is deployment-controlled and defaults off. - rpc BootstrapThreadGateway(BootstrapThreadGatewayRequest) returns (BootstrapThreadGatewayResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // PrewarmOperatingThread allocates the durable Dex thread identity and - // idempotently requests its tenant-bound RunnerSession before the composer - // submits the first message. - rpc PrewarmOperatingThread(PrewarmOperatingThreadRequest) returns (PrewarmOperatingThreadResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // ListOperatingThreadEvents replays the browser-safe execution projection - // after a durable monotonic cursor. Runtime endpoints, certificates, raw - // tool payloads, and provider credentials never cross this boundary. - rpc ListOperatingThreadEvents(ListOperatingThreadEventsRequest) returns (ListOperatingThreadEventsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // WatchOperatingThread streams the same cursor-fenced projection used for - // reconnect backfill. Streams are bounded by server duration and admission - // limits; clients reconnect with the last observed cursor. - rpc WatchOperatingThread(WatchOperatingThreadRequest) returns (stream WatchOperatingThreadResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // RespondOperatingThread forwards one typed response to the durable hosted - // runtime through the same lease, replay, and generation-fencing path as a - // user turn. - rpc RespondOperatingThread(RespondOperatingThreadRequest) returns (RespondOperatingThreadResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // InterruptOperatingThread stops a pending operating turn from the console. - // Use this when the user stops waiting during provision or mid-run. Unlike - // RespondOperatingThread, no waiting request_id is required. The owner marks - // the turn interrupted, cancels open runtime work for that message, and - // returns the updated thread projection. - rpc InterruptOperatingThread(InterruptOperatingThreadRequest) returns (InterruptOperatingThreadResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // SearchOperatingHistory finds safe, workspace-scoped message and tool/receipt - // projections without making the projection authoritative. - rpc SearchOperatingHistory(SearchOperatingHistoryRequest) returns (SearchOperatingHistoryResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // GetOperatingHistoryContext resolves a search cursor to a bounded canonical - // neighborhood after reauthorizing the tenant scope. - rpc GetOperatingHistoryContext(GetOperatingHistoryContextRequest) returns (GetOperatingHistoryContextResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Explicitly accepts a complete non-code project file snapshot. - rpc AcceptOperatingProjectSnapshot(AcceptOperatingProjectSnapshotRequest) returns (AcceptOperatingProjectSnapshotResponse) { - option idempotency_level = IDEMPOTENT; - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // Imports only the connected repository's provider-observed default-branch head. - rpc ImportOperatingProjectSnapshot(ImportOperatingProjectSnapshotRequest) returns (AcceptOperatingProjectSnapshotResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // Reads the current accepted source without changing task baselines. - // Reads retained task state without acquiring or refreshing a computer. - rpc GetOperatingTaskEnvironment(GetOperatingTaskEnvironmentRequest) returns (GetOperatingTaskEnvironmentResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc GetOperatingProjectSnapshot(GetOperatingProjectSnapshotRequest) returns (AcceptOperatingProjectSnapshotResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // SubmitOperatingMessage records a human chat turn. Backend-owned operating - // work is represented by receipts only when a task or tool owner accepts it. - rpc SubmitOperatingMessage(SubmitOperatingMessageRequest) returns (SubmitOperatingMessageResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // SubmitOperatingCorrection records explicit operator feedback as a - // review-gated regression candidate. It never changes production behavior. - rpc SubmitOperatingCorrection(SubmitOperatingCorrectionRequest) returns (SubmitOperatingCorrectionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // SubmitOperatingFeedback durably records an operator's bounded assessment - // of one Dex response. Optional correction text is digested and discarded. - rpc SubmitOperatingFeedback(SubmitOperatingFeedbackRequest) returns (SubmitOperatingFeedbackResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // SubmitProductIssueReport records a workspace-scoped product issue with - // bounded, operator-approved browser diagnostics and an optional screenshot. - rpc SubmitProductIssueReport(SubmitProductIssueReportRequest) returns (SubmitProductIssueReportResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Native clients submit to the same durable product issue owner using a narrow permission. - rpc SubmitNativeProductIssueReport(SubmitNativeProductIssueReportRequest) returns (SubmitProductIssueReportResponse) { - option (common.v1.required_scopes) = "product_issues:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ListStaffProductIssueReports exposes bounded issue-report projections to - // EvalOps staff without returning screenshot bytes. - rpc ListStaffProductIssueReports(ListStaffProductIssueReportsRequest) returns (ListStaffProductIssueReportsResponse) { - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // EngageStaffProductIssueReport records the first durable staff - // acknowledgement. Repeated calls preserve the original actor, time, and note. - rpc EngageStaffProductIssueReport(EngageStaffProductIssueReportRequest) returns (EngageStaffProductIssueReportResponse) { - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // Lists the global recovery queue under verified staff authority. - rpc ListStaffProductIssueRecoveries(ListStaffProductIssueRecoveriesRequest) returns (ListStaffProductIssueRecoveriesResponse) { - option (common.v1.required_scopes) = "support_access.manage"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // PrepareStaffProductIssueRecovery advances the staff-reviewed recovery of charged failures. - rpc PrepareStaffProductIssueRecovery(PrepareStaffProductIssueRecoveryRequest) returns (ProductIssueRecoveryResponse) { - option (common.v1.required_scopes) = "support_access.manage"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // ScanStaffProductIssueRecovery advances the staff-reviewed recovery of charged failures. - rpc ScanStaffProductIssueRecovery(ScanStaffProductIssueRecoveryRequest) returns (ProductIssueRecoveryResponse) { - option (common.v1.required_scopes) = "support_access.manage"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // ReviewStaffProductIssueRecovery advances the staff-reviewed recovery of charged failures. - rpc ReviewStaffProductIssueRecovery(ReviewStaffProductIssueRecoveryRequest) returns (ProductIssueRecoveryResponse) { - option (common.v1.required_scopes) = "support_access.manage"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // ExecuteStaffProductIssueRecovery advances the staff-reviewed recovery of charged failures. - rpc ExecuteStaffProductIssueRecovery(ExecuteStaffProductIssueRecoveryRequest) returns (ProductIssueRecoveryResponse) { - option (common.v1.required_scopes) = "support_access.manage"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // GetProductIssueRecovery accesses only the authenticated recovery recipient or authorized staff. - rpc GetProductIssueRecovery(GetProductIssueRecoveryRequest) returns (ProductIssueRecoveryResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ReplyProductIssueRecovery accesses only the authenticated recovery recipient or authorized staff. - rpc ReplyProductIssueRecovery(ReplyProductIssueRecoveryRequest) returns (ProductIssueRecoveryResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // GetOperatingFeedback returns the latest durable feedback revision for one - // Dex response, including a retraction marker when the operator removed it. - rpc GetOperatingFeedback(GetOperatingFeedbackRequest) returns (GetOperatingFeedbackResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ResolveOperatingFeedbackRemediation records the operator-confirmed outcome - // of a real verify or retry turn linked to feedback. - rpc ResolveOperatingFeedbackRemediation(ResolveOperatingFeedbackRemediationRequest) returns (ResolveOperatingFeedbackRemediationResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ListCustomerIntelligenceFacts returns bounded, safe fact projections to - // authorized staff. Customer members cannot browse the internal ledger. - rpc ListCustomerIntelligenceFacts(ListCustomerIntelligenceFactsRequest) returns (ListCustomerIntelligenceFactsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // GetCustomerIntelligenceFact returns one safe current revision and its - // append-only history to authorized staff. - rpc GetCustomerIntelligenceFact(GetCustomerIntelligenceFactRequest) returns (GetCustomerIntelligenceFactResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ReviewCustomerIntelligenceFact appends a staff review decision. It never - // edits an existing revision or raises authority from model confidence. - rpc ReviewCustomerIntelligenceFact(ReviewCustomerIntelligenceFactRequest) returns (ReviewCustomerIntelligenceFactResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // ProposeCustomerIntelligenceFact is a typed producer boundary. The handler - // additionally requires an allowlisted service identity. - rpc ProposeCustomerIntelligenceFact(ProposeCustomerIntelligenceFactRequest) returns (ProposeCustomerIntelligenceFactResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // RespondToCustomerFactConfirmation lets a customer confirm or dispute one - // open, interaction-scoped intent; it is not a general fact-write API. - rpc RespondToCustomerFactConfirmation(RespondToCustomerFactConfirmationRequest) returns (RespondToCustomerFactConfirmationResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // AggregateCustomerIntelligencePatterns returns privacy-bounded staff - // aggregates without account identifiers or fact summaries. - rpc AggregateCustomerIntelligencePatterns(AggregateCustomerIntelligencePatternsRequest) returns (AggregateCustomerIntelligencePatternsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ListOperatingCorrections returns the workspace's correction review queue. - rpc ListOperatingCorrections(ListOperatingCorrectionsRequest) returns (ListOperatingCorrectionsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ReviewOperatingCorrection explicitly approves or rejects a regression - // candidate. Approval admits evaluation only; it does not promote learning. - rpc ReviewOperatingCorrection(ReviewOperatingCorrectionRequest) returns (ReviewOperatingCorrectionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // ListWorkspaceMemories returns the active memories the authenticated - // workspace owns. MemoryService remains the durable owner. - rpc ListWorkspaceMemories(ListWorkspaceMemoriesRequest) returns (ListWorkspaceMemoriesResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // CorrectWorkspaceMemory applies one revision-fenced owner correction. - rpc CorrectWorkspaceMemory(CorrectWorkspaceMemoryRequest) returns (CorrectWorkspaceMemoryResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // ReviewWorkspaceMemory approves or rejects a proposed memory for recall. - rpc ReviewWorkspaceMemory(ReviewWorkspaceMemoryRequest) returns (ReviewWorkspaceMemoryResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // ForgetWorkspaceMemory immediately revokes one memory from active recall. - rpc ForgetWorkspaceMemory(ForgetWorkspaceMemoryRequest) returns (ForgetWorkspaceMemoryResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // BeginOperatingAttachmentUpload validates metadata and creates a fenced VFS upload lease. - rpc BeginOperatingAttachmentUpload(BeginOperatingAttachmentUploadRequest) returns (BeginOperatingAttachmentUploadResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // CompleteOperatingAttachmentUpload verifies bytes and starts bounded extraction. - rpc CompleteOperatingAttachmentUpload(CompleteOperatingAttachmentUploadRequest) returns (CompleteOperatingAttachmentUploadResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // ListOperatingAttachments returns reusable workspace-scoped attachment metadata only. - rpc ListOperatingAttachments(ListOperatingAttachmentsRequest) returns (ListOperatingAttachmentsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ResolveOperatingReceiptAction sends a backend-returned receipt command to - // its owning service. Console only advertises actions with an owning handler. - rpc ResolveOperatingReceiptAction(ResolveOperatingReceiptActionRequest) returns (ResolveOperatingReceiptActionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // GetOperatingReceipt returns one safe, UI-renderable receipt mini-app. - rpc GetOperatingReceipt(GetOperatingReceiptRequest) returns (GetOperatingReceiptResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // SubmitComputerMission persists a confirmed, explicitly scoped autonomous - // mission. Full autonomy is an authority grant on the mission contract, not - // a bypass around tenant, policy, budget, audit, or cancellation controls. - rpc SubmitComputerMission(SubmitComputerMissionRequest) returns (SubmitComputerMissionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // GetComputerMission returns durable mission state and its latest safe - // operating receipt. - rpc GetComputerMission(GetComputerMissionRequest) returns (GetComputerMissionResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // CancelComputerMission requests cancellation through the mission owner. - rpc CancelComputerMission(CancelComputerMissionRequest) returns (CancelComputerMissionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // ContinueComputerMission supplies typed user input to a waiting mission. - rpc ContinueComputerMission(ContinueComputerMissionRequest) returns (ContinueComputerMissionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // PauseComputerMission durably parks a live or queued mission. - rpc PauseComputerMission(PauseComputerMissionRequest) returns (PauseComputerMissionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // ResumeComputerMission queues a new fenced execution generation. - rpc ResumeComputerMission(ResumeComputerMissionRequest) returns (ResumeComputerMissionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // WakeComputerMission queues a sleeping or externally blocked mission. - rpc WakeComputerMission(WakeComputerMissionRequest) returns (WakeComputerMissionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // GuideComputerMission supplies durable guidance and queues a new generation. - rpc GuideComputerMission(GuideComputerMissionRequest) returns (GuideComputerMissionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - rpc ListComputerMissionCanaryDefinitions(ListComputerMissionCanaryDefinitionsRequest) returns (ListComputerMissionCanaryDefinitionsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc StartComputerMissionCanaryRun(StartComputerMissionCanaryRunRequest) returns (StartComputerMissionCanaryRunResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - rpc GetComputerMissionCanaryRun(GetComputerMissionCanaryRunRequest) returns (GetComputerMissionCanaryRunResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc ListComputerMissionCanaryRuns(ListComputerMissionCanaryRunsRequest) returns (ListComputerMissionCanaryRunsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc GetComputerMissionCanaryEvidence(GetComputerMissionCanaryEvidenceRequest) returns (GetComputerMissionCanaryEvidenceResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc OperateComputerMissionCanaryRun(OperateComputerMissionCanaryRunRequest) returns (OperateComputerMissionCanaryRunResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // CreateMissionSchedule persists a cron-scheduled recurring computer - // mission. The worker's schedule runner claims due schedules and fires - // missions through the same durable path as SubmitComputerMission. - rpc CreateMissionSchedule(CreateMissionScheduleRequest) returns (CreateMissionScheduleResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // UpdateMissionSchedule replaces a schedule's cron expression, name, and - // mission template. - rpc UpdateMissionSchedule(UpdateMissionScheduleRequest) returns (UpdateMissionScheduleResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // SetMissionScheduleEnabled enables or disables a schedule without - // changing its template. A disabled schedule is never claimed by the - // worker. - rpc SetMissionScheduleEnabled(SetMissionScheduleEnabledRequest) returns (SetMissionScheduleEnabledResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // ListMissionSchedules returns the workspace's mission schedules. - rpc ListMissionSchedules(ListMissionSchedulesRequest) returns (ListMissionSchedulesResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // CreateConnectorTrigger binds a tenant-scoped mission template to either a - // cron tick or an authenticated connector event. Event payloads are always - // projected by the worker through the trigger's allowlist before they reach - // the mission context; they never change the mission authority grant. - rpc CreateConnectorTrigger(CreateConnectorTriggerRequest) returns (CreateConnectorTriggerResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - rpc UpdateConnectorTrigger(UpdateConnectorTriggerRequest) returns (UpdateConnectorTriggerResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - rpc ListConnectorTriggers(ListConnectorTriggersRequest) returns (ListConnectorTriggersResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc DeleteConnectorTrigger(DeleteConnectorTriggerRequest) returns (DeleteConnectorTriggerResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - rpc SetConnectorTriggerEnabled(SetConnectorTriggerEnabledRequest) returns (SetConnectorTriggerEnabledResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // ReserveComputerMissionApexSession mints Platform-owned authority for one - // exact, tenant-scoped APEX attempt and Runner Host create tuple. - rpc ReserveComputerMissionApexSession(ReserveComputerMissionApexSessionRequest) returns (ReserveComputerMissionApexSessionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.required_scopes) = "apex:reservation:reserve"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // BindComputerMissionApexSessionReservation binds one physical Runner Host - // session to a previously issued reservation. - rpc BindComputerMissionApexSessionReservation(BindComputerMissionApexSessionReservationRequest) returns (BindComputerMissionApexSessionReservationResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.required_scopes) = "apex:reservation:bind"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // BindComputerMissionApexInstructionMetadata seals the exact non-plaintext - // instruction tuple after dataset staging and before Runner Host hydration. - rpc BindComputerMissionApexInstructionMetadata(BindComputerMissionApexInstructionMetadataRequest) returns (BindComputerMissionApexInstructionMetadataResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.required_scopes) = "apex:instruction:bind"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // AuthorizeComputerMissionApexSessionAdoption declares the typed owner - // response used by Task 4; its durable authorization transaction lands there. - rpc AuthorizeComputerMissionApexSessionAdoption(AuthorizeComputerMissionApexSessionAdoptionRequest) returns (AuthorizeComputerMissionApexSessionAdoptionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.required_scopes) = "apex:reservation:adopt"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // GetWorkspaceSettings returns the authenticated workspace settings summary. - // It is the product contract for the Settings page: fields that are not yet - // backed by an owning service are returned with explicit unavailable - // capabilities instead of client-local values. - rpc GetWorkspaceSettings(GetWorkspaceSettingsRequest) returns (GetWorkspaceSettingsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // GetOperatorPreferences returns preferences owned by the authenticated - // principal in this workspace. The principal id is always derived server-side. - rpc GetOperatorPreferences(GetOperatorPreferencesRequest) returns (GetOperatorPreferencesResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // UpdateOperatorPreferences stores preferences for the authenticated - // principal only; callers cannot target another user's profile. - rpc UpdateOperatorPreferences(UpdateOperatorPreferencesRequest) returns (UpdateOperatorPreferencesResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // CreateConnectorProfile creates a named, scoped connector configuration. - // connection_id is write-only and is never returned by profile reads. - rpc CreateConnectorProfile(CreateConnectorProfileRequest) returns (CreateConnectorProfileResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // ListConnectorProfiles returns the profiles configured for one connector. - rpc ListConnectorProfiles(ListConnectorProfilesRequest) returns (ListConnectorProfilesResponse) { - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // UpdateConnectorProfile updates mutable profile policy fields. - rpc UpdateConnectorProfile(UpdateConnectorProfileRequest) returns (UpdateConnectorProfileResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // DeleteConnectorProfile deletes a profile while preserving the durable - // opt-in marker that prevents legacy connector fallback. - rpc DeleteConnectorProfile(DeleteConnectorProfileRequest) returns (DeleteConnectorProfileResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // ListConnectedCalls returns upcoming connected calls projected by the - // tenant-scoped Connectors owner, whatever meeting platform hosts them. It - // never exposes connection IDs or raw calendar payloads to the browser. - rpc ListConnectedCalls(ListConnectedCallsRequest) returns (ListConnectedCallsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // StartMeetingCapture records an explicitly consented request for the - // workspace's connected meeting bot to join one supported meeting, capture - // its finalized transcript, and index it in Cerebro for tenant-scoped Dex - // retrieval. The meeting is named either by a server-validated meeting URL or - // by one opted-in connected calendar call. - rpc StartMeetingCapture(StartMeetingCaptureRequest) returns (StartMeetingCaptureResponse) { - option (common.v1.required_scopes) = "platform:write"; - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // GetMeetingCapture returns the durable provider, transcript, Cerebro index, - // and retrieval projection for one tenant-scoped capture request. - rpc GetMeetingCapture(GetMeetingCaptureRequest) returns (GetMeetingCaptureResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ListMeetingCaptures returns recent tenant-scoped meeting captures. - rpc ListMeetingCaptures(ListMeetingCapturesRequest) returns (ListMeetingCapturesResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // StopMeetingCapture records the user's request to cancel a scheduled bot or - // make a joined bot leave. - rpc StopMeetingCapture(StopMeetingCaptureRequest) returns (StopMeetingCaptureResponse) { - option (common.v1.required_scopes) = "platform:write"; - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // ListCommitments returns the workspace's tracked commitments together with - // the source citations each commitment was extracted from. - rpc ListCommitments(ListCommitmentsRequest) returns (ListCommitmentsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // GetBillingSubscription returns the typed billing subscription summary used - // by Settings. A configured provider enriches the durable workspace billing - // settings state. Billing portal sessions are created separately on demand. - rpc GetBillingSubscription(GetBillingSubscriptionRequest) returns (GetBillingSubscriptionResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // CreateBillingPortalSession creates a short-lived provider-hosted portal - // session for the authenticated workspace. The return URL is server-owned. - rpc CreateBillingPortalSession(CreateBillingPortalSessionRequest) returns (CreateBillingPortalSessionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // CreateBillingCheckoutSession starts provider-hosted, customer-consented - // annual subscription enrollment at the server-owned contributor minimum. - rpc CreateBillingCheckoutSession(CreateBillingCheckoutSessionRequest) returns (CreateBillingCheckoutSessionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // GetInferenceCreditBalance uses the authorized workspace's prepaid inference account. - rpc GetInferenceCreditBalance(GetInferenceCreditBalanceRequest) returns (GetInferenceCreditBalanceResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // CreateInferenceCreditCheckout uses the authorized workspace's prepaid inference account. - rpc CreateInferenceCreditCheckout(CreateInferenceCreditCheckoutRequest) returns (CreateInferenceCreditCheckoutResponse) { - option (common.v1.required_scopes) = "billing:admin"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // FulfillInferenceCreditCheckout uses the authorized workspace's prepaid inference account. - rpc FulfillInferenceCreditCheckout(FulfillInferenceCreditCheckoutRequest) returns (FulfillInferenceCreditCheckoutResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // UpdateWorkspaceProfile stores workspace-facing Settings metadata such as - // labels, environment, and region. - rpc UpdateWorkspaceProfile(UpdateWorkspaceProfileRequest) returns (UpdateWorkspaceProfileResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // ArchiveWorkspace toggles the Console-owned archived state for this - // workspace. Downstream lifecycle deletion remains separate. - rpc ArchiveWorkspace(ArchiveWorkspaceRequest) returns (ArchiveWorkspaceResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // UpdateWorkspacePolicy stores the Settings governance policy envelope used - // by Console surfaces. - rpc UpdateWorkspacePolicy(UpdateWorkspacePolicyRequest) returns (UpdateWorkspacePolicyResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // UpdateWorkspaceDexPolicy stores the operator-controlled execution, - // memory, learning, and trace-content boundaries for Dex. - rpc UpdateWorkspaceDexPolicy(UpdateWorkspaceDexPolicyRequest) returns (UpdateWorkspaceDexPolicyResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // UpdateWorkspaceArtifactStyleGuide stores the workspace-owned writing and - // presentation contract that Dex must apply to generated artifacts. - rpc UpdateWorkspaceArtifactStyleGuide(UpdateWorkspaceArtifactStyleGuideRequest) returns (UpdateWorkspaceArtifactStyleGuideResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // EvaluateWorkspaceArtifactStyleGuide tests unsaved policy controls against - // sample response text without mutating workspace settings. - rpc EvaluateWorkspaceArtifactStyleGuide(EvaluateWorkspaceArtifactStyleGuideRequest) returns (EvaluateWorkspaceArtifactStyleGuideResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // UpsertWorkspaceIdentityProvider stores or updates an identity provider row. - rpc UpsertWorkspaceIdentityProvider(UpsertWorkspaceIdentityProviderRequest) returns (UpsertWorkspaceIdentityProviderResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // RemoveWorkspaceIdentityProvider removes a Console-owned identity provider row. - rpc RemoveWorkspaceIdentityProvider(RemoveWorkspaceIdentityProviderRequest) returns (RemoveWorkspaceIdentityProviderResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // UpsertWorkspaceIntegration stores or updates a Console-owned integration - // settings row. - rpc UpsertWorkspaceIntegration(UpsertWorkspaceIntegrationRequest) returns (UpsertWorkspaceIntegrationResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // RemoveWorkspaceIntegration removes a Console-owned integration settings row. - rpc RemoveWorkspaceIntegration(RemoveWorkspaceIntegrationRequest) returns (RemoveWorkspaceIntegrationResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // UpdateWorkspaceBilling stores the workspace billing summary displayed in - // Settings. Until a dedicated billing service is connected to Console, this - // is the durable operator-managed billing read model. - rpc UpdateWorkspaceBilling(UpdateWorkspaceBillingRequest) returns (GetWorkspaceSettingsResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // UpsertWorkspaceMember stores or updates a workspace member row. - rpc UpsertWorkspaceMember(UpsertWorkspaceMemberRequest) returns (GetWorkspaceSettingsResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // RemoveWorkspaceMember removes a workspace member row. - rpc RemoveWorkspaceMember(RemoveWorkspaceMemberRequest) returns (GetWorkspaceSettingsResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // UpdateWorkspaceNotificationPreferences stores Settings notification - // preferences for the workspace/current operator view. - rpc UpdateWorkspaceNotificationPreferences(UpdateWorkspaceNotificationPreferencesRequest) returns (GetWorkspaceSettingsResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // EnableWorkspaceBreakGlass records a customer-approved read-only support - // access grant. The grant is durable and remains active until disabled. - rpc EnableWorkspaceBreakGlass(EnableWorkspaceBreakGlassRequest) returns (GetWorkspaceSettingsResponse) { - option (common.v1.required_scopes) = "support_access.manage"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // DisableWorkspaceBreakGlass deactivates the active support access grant. - rpc DisableWorkspaceBreakGlass(DisableWorkspaceBreakGlassRequest) returns (GetWorkspaceSettingsResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // ListWorkspaceSkills returns the workspace-scoped Dex procedural-memory - // catalog, including body, for the Settings management surface. The Dex - // runtime's separate skill.list tool returns only name + description. - rpc ListWorkspaceSkills(ListWorkspaceSkillsRequest) returns (ListWorkspaceSkillsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // BrowseDexSkillCatalog lists platform-curated procedures and their - // installation state for the selected workspace. - rpc BrowseDexSkillCatalog(BrowseDexSkillCatalogRequest) returns (BrowseDexSkillCatalogResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // InstallDexSkillCatalogEntry copies a curated procedure into the - // workspace skill store and appends its audit event atomically. - rpc InstallDexSkillCatalogEntry(InstallDexSkillCatalogEntryRequest) returns (InstallDexSkillCatalogEntryResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // CreateWorkspaceSkill stores a new named Dex skill for this workspace. - // Fails if a skill with the same name already exists; use - // UpdateWorkspaceSkill to revise an existing one. - rpc CreateWorkspaceSkill(CreateWorkspaceSkillRequest) returns (CreateWorkspaceSkillResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // UpdateWorkspaceSkill revises an existing named skill's description/body - // and increments its version. Fails if the named skill does not exist. - rpc UpdateWorkspaceSkill(UpdateWorkspaceSkillRequest) returns (UpdateWorkspaceSkillResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // DeleteWorkspaceSkill removes a named skill from this workspace. No-op if - // the skill does not exist. - rpc DeleteWorkspaceSkill(DeleteWorkspaceSkillRequest) returns (DeleteWorkspaceSkillResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // ListScenarioFixtures returns Maestro replay fixtures promoted for this workspace. - rpc ListScenarioFixtures(ListScenarioFixturesRequest) returns (ListScenarioFixturesResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.organization_scope_field) = "organization_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // PromoteScenarioFixture stores a recorded Maestro replay scenario as an immutable fixture. - rpc PromoteScenarioFixture(PromoteScenarioFixtureRequest) returns (PromoteScenarioFixtureResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.organization_scope_field) = "organization_id"; - - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // CompareScenarioFixtures returns a compact diff between two promoted replay fixtures. - rpc CompareScenarioFixtures(CompareScenarioFixturesRequest) returns (CompareScenarioFixturesResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.organization_scope_field) = "organization_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ListWorkspaceGuardrailRules returns the workspace-configured content - // guardrail rules evaluated over Dex model output. An unconfigured workspace - // returns an empty set, which the runner treats as a no-op. - rpc ListWorkspaceGuardrailRules(ListWorkspaceGuardrailRulesRequest) returns (ListWorkspaceGuardrailRulesResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // UpsertWorkspaceGuardrailRule creates or replaces one content guardrail rule - // by id in the caller's workspace. - rpc UpsertWorkspaceGuardrailRule(UpsertWorkspaceGuardrailRuleRequest) returns (ListWorkspaceGuardrailRulesResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // RemoveWorkspaceGuardrailRule deletes one content guardrail rule by id. - rpc RemoveWorkspaceGuardrailRule(RemoveWorkspaceGuardrailRuleRequest) returns (ListWorkspaceGuardrailRulesResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // SetOperatingThreadController transfers the live Computer controller - // between Dex and the authenticated operator. The request is fenced by the - // current runtime generation, replay cursor, and runtime lease generation; - // a stale browser cannot steal or resume a newer controller lease. - rpc SetOperatingThreadController(SetOperatingThreadControllerRequest) returns (SetOperatingThreadControllerResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // GetPrivacySettings returns the tenant privacy mode that platform-api seals - // into every OperationContext for this tenant: the organization-wide row, the - // workspace override when one exists, and the effective mode that results. - rpc GetPrivacySettings(GetPrivacySettingsRequest) returns (GetPrivacySettingsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // SetPrivacySettings writes the organization-wide privacy mode or one - // workspace override. Loosening the mode is a governance change, so this - // carries the Console write scope rather than the read scope every member - // holds. - rpc SetPrivacySettings(SetPrivacySettingsRequest) returns (GetPrivacySettingsResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // CreateProspectingWatchProgram records a staff-authored Radar watch - // program for one exact provider organization and workspace. - rpc CreateProspectingWatchProgram(CreateProspectingWatchProgramRequest) returns (CreateProspectingWatchProgramResponse) { - option (common.v1.required_scopes) = "prospecting.write"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // GetProspectingWatchProgram returns one exact Radar watch program. - rpc GetProspectingWatchProgram(GetProspectingWatchProgramRequest) returns (GetProspectingWatchProgramResponse) { - option (common.v1.required_scopes) = "prospecting.read"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ListProspectingWatchPrograms returns bounded Radar watch programs for an - // exact provider organization and workspace. - rpc ListProspectingWatchPrograms(ListProspectingWatchProgramsRequest) returns (ListProspectingWatchProgramsResponse) { - option (common.v1.required_scopes) = "prospecting.read"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // UpdateProspectingWatchProgram replaces a Radar watch-program revision with - // optimistic concurrency, reason, and idempotency requirements. - rpc UpdateProspectingWatchProgram(UpdateProspectingWatchProgramRequest) returns (UpdateProspectingWatchProgramResponse) { - option (common.v1.required_scopes) = "prospecting.write"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // CreateProspectingDraft records a staff-authored Radar outreach draft for - // one exact provider organization and workspace. It holds the draft for - // review and never delivers it. - rpc CreateProspectingDraft(CreateProspectingDraftRequest) returns (CreateProspectingDraftResponse) { - option (common.v1.required_scopes) = "prospecting.write"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // ListProspectingDrafts returns bounded Radar outreach drafts for an exact - // provider organization and workspace. - rpc ListProspectingDrafts(ListProspectingDraftsRequest) returns (ListProspectingDraftsResponse) { - option (common.v1.required_scopes) = "prospecting.read"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ReviewProspectingDraft records an approval or rejection against an exact - // draft revision. Approval is a review decision and is never delivery - // authority. - rpc ReviewProspectingDraft(ReviewProspectingDraftRequest) returns (ReviewProspectingDraftResponse) { - option (common.v1.required_scopes) = "prospecting.write"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // RecordOperatingHomepageSuggestionFeedback changes only the authenticated - // principal's short-lived homepage projection. It never deletes the source - // conversation or Cerebro evidence. Declared last to avoid renumbering - // unrelated generated RPC descriptors. - rpc RecordOperatingHomepageSuggestionFeedback(RecordOperatingHomepageSuggestionFeedbackRequest) returns (RecordOperatingHomepageSuggestionFeedbackResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } -} - -// WorkspaceKeyService manages workspace-level managed-credential key custody. -// The external ID is write-only and is never present in a response. -service WorkspaceKeyService { - // GetWorkspaceKeyConfig returns the effective custody configuration. - rpc GetWorkspaceKeyConfig(GetWorkspaceKeyConfigRequest) returns (WorkspaceKeyConfigResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // PutWorkspaceKeyConfig selects the provider and key for future managed-credential uploads. - rpc PutWorkspaceKeyConfig(PutWorkspaceKeyConfigRequest) returns (WorkspaceKeyConfigResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // DeleteWorkspaceKeyConfig returns the workspace to platform-managed custody. - rpc DeleteWorkspaceKeyConfig(DeleteWorkspaceKeyConfigRequest) returns (WorkspaceKeyConfigResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } -} - -message GetWorkspaceKeyConfigRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; -} - -message PutWorkspaceKeyConfigRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string provider = 3 [(buf.validate.field).string.min_len = 1]; - string key_arn = 4; - string role_arn = 5; - // external_id is write-only and is sealed before durable storage. - string external_id = 6; -} - -message DeleteWorkspaceKeyConfigRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; -} - -message WorkspaceKeyConfigResponse { - string organization_id = 1; - string workspace_id = 2; - string provider = 3; - string key_arn = 4; - string role_arn = 5; - bool has_external_id = 6; - string updated_at = 7; -} - -// TimeRange bounds console queries. -message TimeRange { - google.protobuf.Timestamp start_time = 1; - google.protobuf.Timestamp end_time = 2; -} - -// ConsoleQuery is shared by read endpoints. -message ConsoleQuery { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - TimeRange time_range = 2; - string environment = 3; - string team_id = 4; - string owner = 5; - common.v1.RiskLevel risk_level = 6; - string asset_type = 7; - string status = 8; - int32 limit = 9 [(buf.validate.field).int32 = { - gte: 0 - lte: 500 - }]; - int32 offset = 10 [(buf.validate.field).int32.gte = 0]; - string search = 11; - string provider = 12; - string organization_id = 13; -} - -// OperatingCapabilityState is the UI-safe service availability summary for an -// operating channel or receipt owner. -message OperatingCapabilityState { - string service = 1; - string status = 2; - string label = 3; - string detail = 4; - repeated string missing_requirements = 5; - repeated OperatingCapabilityRequirementState missing_requirement_states = 6; -} - -enum OperatingTurnRouteKind { - OPERATING_TURN_ROUTE_KIND_ROUTE_UNSPECIFIED = 0; - OPERATING_TURN_ROUTE_KIND_DIRECT_ANSWER = 1; - OPERATING_TURN_ROUTE_KIND_GOVERNED_WORK = 2; - OPERATING_TURN_ROUTE_KIND_BLOCKED = 3; -} - -enum OperatingTurnIntentKind { - OPERATING_TURN_INTENT_KIND_INTENT_UNSPECIFIED = 0; - OPERATING_TURN_INTENT_KIND_UNKNOWN = 1; - OPERATING_TURN_INTENT_KIND_OPERATIONAL = 2; - OPERATING_TURN_INTENT_KIND_CAPABILITY_HELP = 3; - OPERATING_TURN_INTENT_KIND_SETTINGS = 4; - OPERATING_TURN_INTENT_KIND_APPROVAL = 5; - OPERATING_TURN_INTENT_KIND_EVIDENCE = 6; -} - -enum OperatingTurnAnswerKind { - OPERATING_TURN_ANSWER_KIND_ANSWER_UNSPECIFIED = 0; - OPERATING_TURN_ANSWER_KIND_NO_ANSWER = 1; - OPERATING_TURN_ANSWER_KIND_DIRECT_ANSWER = 2; - OPERATING_TURN_ANSWER_KIND_RECEIPT_ONLY = 3; - OPERATING_TURN_ANSWER_KIND_WORK_STARTED = 4; -} - -enum OperatingTurnSafetyKind { - OPERATING_TURN_SAFETY_KIND_SAFETY_UNSPECIFIED = 0; - OPERATING_TURN_SAFETY_KIND_NOT_EVALUATED = 1; - OPERATING_TURN_SAFETY_KIND_ALLOWED = 2; - OPERATING_TURN_SAFETY_KIND_BLOCKED = 3; -} - -// OperatingTurnRoute is backend-owned routing metadata for a chat turn. Clients -// must use this typed contract instead of deriving behavior from prompt text or -// assistant copy. -message OperatingTurnRoute { - OperatingTurnRouteKind kind = 1; - OperatingTurnIntentKind intent_kind = 2; - OperatingTurnAnswerKind answer_kind = 3; - OperatingTurnSafetyKind safety_kind = 4; - string router = 5; - google.protobuf.Timestamp decided_at = 6; -} - -// OperatingChannel identifies a company/domain/thread surface the Console can -// show. It carries capability state, not local operational data. -message OperatingChannel { - string id = 1; - string label = 2; - string kind = 3; - string source_service = 4; - int32 unread_count = 5; - int32 open_count = 6; - OperatingCapabilityState capability_state = 7; - string detail = 8; - google.protobuf.Timestamp updated_at = 9; - OperatingSurfaceMetadata surface = 10; - // Archive is a list-visibility state owned by the durable channel row. It - // never implies provider-binding or execution lifecycle changes. - bool archived = 11; - google.protobuf.Timestamp archived_at = 12; - // Archive provenance is durable owner metadata. It is populated only for an - // archived channel and cleared when the channel is unarchived. - string archived_by_principal_id = 13; - string archived_by_display_name = 14; - // Fork provenance is durable owner metadata, absent on a thread that was - // started directly. - OperatingThreadFork fork = 15; - - // The source project this thread's work belongs to, empty when the thread - // has never submitted a turn against one. This is the existing - // `project_resource_id` from SubmitOperatingMessageRequest, recorded durably - // on the thread so several threads working the same project can be listed - // together. It is a grouping, never an authority: every read still resolves - // the thread under the caller's own tenant scope. - string project_resource_id = 16 [ - (buf.validate.field).string.max_len = 255, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; -} - -// Where a forked operating thread came from. -// -// A fork copies conversation content and nothing else. It does not inherit -// the source's pinned model selection, its Auto route, its receipts, its -// attachments, or its turn records, because each of those carries authority -// that was granted to the source thread's principal rather than to whoever -// forked it. The fork re-resolves all of them under the forking principal. -message OperatingThreadFork { - string source_channel_id = 1 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - // The last source message copied into the fork. - string through_message_id = 2 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - // The source's conversation_revision at the moment of the fork. Together - // with through_message_id this names exactly what was copied. - int64 source_conversation_revision = 3; - string forked_by_principal_id = 4 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - google.protobuf.Timestamp forked_at = 5; - int32 copied_message_count = 6; -} - -enum OperatingThreadArchiveFilter { - OPERATING_THREAD_ARCHIVE_FILTER_UNSPECIFIED = 0; - OPERATING_THREAD_ARCHIVE_FILTER_ACTIVE_ONLY = 1; - OPERATING_THREAD_ARCHIVE_FILTER_ARCHIVED_ONLY = 2; - OPERATING_THREAD_ARCHIVE_FILTER_ALL = 3; -} - -enum OperatingSurfaceKind { - OPERATING_SURFACE_KIND_UNSPECIFIED = 0; - OPERATING_SURFACE_KIND_COMPOSER = 1; - OPERATING_SURFACE_KIND_SLACK = 2; - OPERATING_SURFACE_KIND_TEAMS = 3; - OPERATING_SURFACE_KIND_WHATSAPP = 4; - OPERATING_SURFACE_KIND_APPLE_MESSAGES = 5; - OPERATING_SURFACE_KIND_EMAIL = 6; -} - -// OperatingSurfaceMetadata is the credential-free origin and continuation -// target for one canonical operating conversation. Provider coordinates are -// always returned inside the already-authorized tenant scope. -message OperatingSurfaceMetadata { - OperatingSurfaceKind kind = 1 [(buf.validate.field).enum.defined_only = true]; - string provider_id = 2; - string connection_id = 3; - string provider_workspace_id = 4; - string provider_channel_id = 5; - string provider_thread_id = 6; - string binding_kind = 7; -} - -// A conversation preference, validated against the tenant's enabled targets. -// An empty provider/model pair uses the organization's normal routing. -message OperatingModelSelection { - string provider = 1 [(buf.validate.field).string.max_len = 128]; - string model = 2 [(buf.validate.field).string.max_len = 256]; -} - -// OperatingMessage is safe conversation text plus links to typed receipts. -message OperatingMessage { - string id = 1; - string channel_id = 2; - string role = 3; - string actor_label = 4; - string body = 5; - google.protobuf.Timestamp created_at = 6; - repeated string receipt_ids = 7; - OperatingTurnRoute route = 8; - repeated OperatingAttachmentRef attachments = 9; - // Safe structured state for the accepted turn. Raw prompts, tool arguments, - // tool results, connector payloads, and model responses are forbidden here. - OperatingTurnRecord turn_record = 10; - OperatingModelSelection model_selection = 11; - OperatingAutoModelRoute auto_model_route = 12; -} - -enum OperatingTurnState { - OPERATING_TURN_STATE_UNSPECIFIED = 0; - OPERATING_TURN_STATE_ACCEPTED = 1; - OPERATING_TURN_STATE_QUEUED = 2; - OPERATING_TURN_STATE_RESPONDED = 3; - OPERATING_TURN_STATE_FAILED = 4; - OPERATING_TURN_STATE_RUNNING = 5; - OPERATING_TURN_STATE_WAITING = 6; - OPERATING_TURN_STATE_COMPLETED = 7; - OPERATING_TURN_STATE_INTERRUPTED = 8; -} - -enum OperatingVerificationState { - OPERATING_VERIFICATION_STATE_UNSPECIFIED = 0; - OPERATING_VERIFICATION_STATE_NOT_REQUIRED = 1; - OPERATING_VERIFICATION_STATE_PENDING = 2; - OPERATING_VERIFICATION_STATE_VERIFIED = 3; - OPERATING_VERIFICATION_STATE_FAILED = 4; -} - -message OperatingToolEvent { - string call_id = 1; - string tool_name = 2; - string status = 3; - string receipt_id = 4; - repeated RelatedResource evidence_refs = 5; -} - -enum OperatingAnswerProvenance { - OPERATING_ANSWER_PROVENANCE_UNSPECIFIED = 0; - OPERATING_ANSWER_PROVENANCE_MODEL = 1; - OPERATING_ANSWER_PROVENANCE_REVIEWED_MODEL = 2; - OPERATING_ANSWER_PROVENANCE_REPAIR_MODEL = 3; - OPERATING_ANSWER_PROVENANCE_GUARDRAIL = 4; - OPERATING_ANSWER_PROVENANCE_RECEIPT_SUMMARY = 5; - OPERATING_ANSWER_PROVENANCE_RUNNER_FAILURE = 6; - OPERATING_ANSWER_PROVENANCE_SUPERSEDED_TURN = 7; - // A hosted model answer that completed the turn without durable runtime work. - OPERATING_ANSWER_PROVENANCE_HOSTED_FRONT_FINAL = 8; - // A hosted model answer shown while exactly one durable runtime continues. - OPERATING_ANSWER_PROVENANCE_HOSTED_FRONT_PRELIMINARY = 9; -} - -message OperatingTurnRecord { - string session_id = 1; - string turn_id = 2; - int64 sequence = 3 [(buf.validate.field).int64.gte = 0]; - string goal = 4 [(buf.validate.field).string.max_len = 2000]; - string context_digest_sha256 = 5; - OperatingTurnState state = 6 [(buf.validate.field).enum.defined_only = true]; - OperatingVerificationState verification_state = 7 [(buf.validate.field).enum.defined_only = true]; - repeated OperatingToolEvent tool_events = 8 [(buf.validate.field).repeated.max_items = 64]; - repeated RelatedResource evidence_refs = 9 [(buf.validate.field).repeated.max_items = 64]; - string error_code = 10; - google.protobuf.Timestamp updated_at = 11; - OperatingAnswerProvenance answer_provenance = 12 [(buf.validate.field).enum.defined_only = true]; - // context_id groups independently addressable tasks in one conversation. - string context_id = 13 [(buf.validate.field).string.max_len = 256]; - // task_id remains stable while a user refines, corrects, or resumes work. - string task_id = 14 [(buf.validate.field).string.max_len = 256]; - int64 task_revision = 15 [(buf.validate.field).int64.gte = 0]; - repeated string reference_task_ids = 16 [(buf.validate.field).repeated = { - max_items: 16 - items: { - string: { - min_len: 1 - max_len: 256 - } - } - }]; - // Server-owned artifact intent carried from a clarification into its next - // turn. This is safe routing metadata, not model content or tool arguments. - string artifact_intent_kind = 17 [(buf.validate.field).string.max_len = 32]; - // Server-owned identity for the privacy-bounded customer-outcome study. - // This is safe routing/evidence metadata only; it must never contain raw - // prompts, outputs, customer identifiers, credentials, or tool payloads. - OperatingCustomerOutcomeIdentity customer_outcome_identity = 18; - toolexecution.v1.ToolExecutionProjectSource project_source = 19; - // Accepted once with the task and replayed unchanged. - toolexecution.v1.ToolExecutionWorkspaceRecipe workspace_recipe = 20; - // Exact coding requirements accepted on the first task revision. Later - // revisions must match this value rather than re-running current selector - // policy. Absence is meaningful for an admitted non-coding task. - CodingAcceptanceContract coding_acceptance = 21; - // Marks records admitted by the immutable workspace-recipe contract. - // Zero identifies legacy records whose absent recipe/contract must replay - // without reinterpretation. - int32 workspace_recipe_admission_version = 22 [(buf.validate.field).int32.gte = 0]; -} - -message OperatingCustomerOutcomeIdentity { - // Purpose-limited HMAC of the organization identity. Empty means the study - // is not enabled or the service has no configured study key. - string study_org_key = 1 [(buf.validate.field).string.max_len = 128]; - // Service-owned consent/eligibility state, never inferred by the browser. - string consent_state = 2 [(buf.validate.field).string.max_len = 32]; - string consent_policy_version = 3 [(buf.validate.field).string.max_len = 64]; - string source_revision = 4 [(buf.validate.field).string.max_len = 64]; - string workflow_id = 5 [(buf.validate.field).string.max_len = 128]; - string workflow_version = 6 [(buf.validate.field).string.max_len = 64]; - string model_id = 7 [(buf.validate.field).string.max_len = 128]; - string model_revision = 8 [(buf.validate.field).string.max_len = 128]; - string provider_id = 9 [(buf.validate.field).string.max_len = 128]; - string provider_route = 10 [(buf.validate.field).string.max_len = 128]; - string config_digest = 11 [(buf.validate.field).string.max_len = 128]; - string prompt_template_revision = 12 [(buf.validate.field).string.max_len = 128]; - string toolchain_revision = 13 [(buf.validate.field).string.max_len = 128]; - string feature_flag_snapshot_digest = 14 [(buf.validate.field).string.max_len = 128]; - string rollout_id = 15 [(buf.validate.field).string.max_len = 128]; -} - -enum OperatingThreadExecutionState { - OPERATING_THREAD_EXECUTION_STATE_UNSPECIFIED = 0; - OPERATING_THREAD_EXECUTION_STATE_PROVISIONING = 1; - OPERATING_THREAD_EXECUTION_STATE_READY = 2; - OPERATING_THREAD_EXECUTION_STATE_RUNNING = 3; - OPERATING_THREAD_EXECUTION_STATE_WAITING = 4; - OPERATING_THREAD_EXECUTION_STATE_DEGRADED = 5; - OPERATING_THREAD_EXECUTION_STATE_STOPPED = 6; -} - -enum OperatingThreadWaitingReason { - OPERATING_THREAD_WAITING_REASON_UNSPECIFIED = 0; - OPERATING_THREAD_WAITING_REASON_NONE = 1; - OPERATING_THREAD_WAITING_REASON_APPROVAL = 2; - OPERATING_THREAD_WAITING_REASON_USER_INPUT = 3; - OPERATING_THREAD_WAITING_REASON_EXTERNAL_RETRY = 4; - OPERATING_THREAD_WAITING_REASON_CLIENT_TOOL = 5; -} - -enum OperatingExecutionRuntime { - OPERATING_EXECUTION_RUNTIME_UNSPECIFIED = 0; - OPERATING_EXECUTION_RUNTIME_MAESTRO = 1; -} - -// OperatingExecutionIdentity is a credential-free drill-down identity for the -// hosted execution that produced a thread event. It is safe to persist with -// the browser projection; Runner Host service, Pod, certificate, and cluster -// coordinates remain private. -message OperatingExecutionIdentity { - OperatingExecutionRuntime runtime = 1 [(buf.validate.field).enum.defined_only = true]; - string run_id = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 256 - }]; - string runner_session_id = 3 [(buf.validate.field).string = { - min_len: 1 - max_len: 256 - }]; - string protocol_version = 4 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; - int64 runtime_generation = 5 [(buf.validate.field).int64.gt = 0]; - int64 event_cursor = 6 [(buf.validate.field).int64.gt = 0]; - // Immutable release/execution identity used to join bounded deployment and - // runtime receipts. It is intentionally opaque and never carries content. - string causal_receipt_id = 7 [(buf.validate.field).string.max_len = 128]; - string maestro_session_id = 8 [(buf.validate.field).string.max_len = 256]; - string maestro_run_id = 9 [(buf.validate.field).string.max_len = 256]; - int64 resident_process_generation = 10 [(buf.validate.field).int64.gte = 0]; - string turn_id = 11 [(buf.validate.field).string.max_len = 128]; - bool append_replayed = 12; -} - -// OperatingThreadExecution is the user-safe projection of one durable Dex -// thread. Runner, Pod, service, certificate, and cluster coordinates are -// intentionally absent. -message OperatingThreadExecution { - string thread_id = 1; - OperatingThreadExecutionState state = 2 [(buf.validate.field).enum.defined_only = true]; - int64 active_turn_sequence = 3 [(buf.validate.field).int64.gte = 0]; - int64 replay_cursor = 4 [(buf.validate.field).int64.gte = 0]; - google.protobuf.Timestamp updated_at = 5; - OperatingExecutionIdentity execution_identity = 6; - // The terminal turn that established the current ready/degraded state. A - // non-zero marker lets clients distinguish an owner terminal projection - // from an older provisioning snapshot without inspecting message copy. - int64 terminal_turn_sequence = 7 [(buf.validate.field).int64.gte = 0]; - string controller_owner = 8 [(buf.validate.field).string.max_len = 64]; - int64 controller_lease_generation = 9 [(buf.validate.field).int64.gte = 0]; -} - -message OperatingThreadTurn { - string turn_id = 1; - int64 sequence = 2 [(buf.validate.field).int64.gt = 0]; - string user_message_id = 3; - string assistant_message_id = 4; - OperatingTurnState state = 5 [(buf.validate.field).enum.defined_only = true]; - OperatingThreadWaitingReason waiting_reason = 6 [(buf.validate.field).enum.defined_only = true]; - int64 first_cursor = 7 [(buf.validate.field).int64.gte = 0]; - int64 last_cursor = 8 [(buf.validate.field).int64.gte = 0]; - string error_code = 9; - google.protobuf.Timestamp created_at = 10; - google.protobuf.Timestamp updated_at = 11; - google.protobuf.Timestamp completed_at = 12; - TerminalErrorEnvelope terminal_error = 13; -} - -enum OperatingThreadEventKind { - OPERATING_THREAD_EVENT_KIND_UNSPECIFIED = 0; - OPERATING_THREAD_EVENT_KIND_TURN_ACCEPTED = 1; - OPERATING_THREAD_EVENT_KIND_TURN_STARTED = 2; - OPERATING_THREAD_EVENT_KIND_PROGRESS = 3; - OPERATING_THREAD_EVENT_KIND_APPROVAL_REQUIRED = 4; - OPERATING_THREAD_EVENT_KIND_INPUT_REQUIRED = 5; - OPERATING_THREAD_EVENT_KIND_ARTIFACT_RECORDED = 6; - OPERATING_THREAD_EVENT_KIND_TURN_COMPLETED = 7; - OPERATING_THREAD_EVENT_KIND_TURN_FAILED = 8; - OPERATING_THREAD_EVENT_KIND_TURN_INTERRUPTED = 9; - OPERATING_THREAD_EVENT_KIND_RUNTIME_REBOUND = 10; - OPERATING_THREAD_EVENT_KIND_TOOL_PROPOSED = 11; - OPERATING_THREAD_EVENT_KIND_TOOL_COMPLETED = 12; - OPERATING_THREAD_EVENT_KIND_MEMORY_PROPOSED = 13; - OPERATING_THREAD_EVENT_KIND_CLIENT_TOOL_REQUIRED = 14; - OPERATING_THREAD_EVENT_KIND_EXTERNAL_RETRY_REQUIRED = 15; -} - -enum OperatingThreadRequestType { - OPERATING_THREAD_REQUEST_TYPE_UNSPECIFIED = 0; - OPERATING_THREAD_REQUEST_TYPE_APPROVAL = 1; - OPERATING_THREAD_REQUEST_TYPE_USER_INPUT = 2; - OPERATING_THREAD_REQUEST_TYPE_CLIENT_TOOL = 3; - OPERATING_THREAD_REQUEST_TYPE_EXTERNAL_RETRY = 4; -} - -enum OperatingThreadResponseAction { - OPERATING_THREAD_RESPONSE_ACTION_UNSPECIFIED = 0; - OPERATING_THREAD_RESPONSE_ACTION_APPROVE = 1; - OPERATING_THREAD_RESPONSE_ACTION_DENY = 2; - OPERATING_THREAD_RESPONSE_ACTION_ANSWER = 3; - OPERATING_THREAD_RESPONSE_ACTION_RETRY = 4; - OPERATING_THREAD_RESPONSE_ACTION_SKIP = 5; - OPERATING_THREAD_RESPONSE_ACTION_ABORT = 6; -} - -// OperatingThreadEvent is an append-only, browser-safe execution projection. -// Raw prompts, tool arguments/results, and infrastructure coordinates are not -// valid event fields. -message OperatingThreadEvent { - int64 cursor = 1 [(buf.validate.field).int64.gt = 0]; - string event_id = 2; - string turn_id = 3; - OperatingThreadEventKind kind = 4 [(buf.validate.field).enum.defined_only = true]; - string safe_text = 5 [(buf.validate.field).string.max_len = 4096]; - repeated RelatedResource artifact_refs = 6 [(buf.validate.field).repeated.max_items = 32]; - google.protobuf.Timestamp created_at = 7; - OperatingExecutionIdentity execution_identity = 8; - string request_id = 9 [(buf.validate.field).string.max_len = 256]; - OperatingThreadRequestType request_type = 10 [(buf.validate.field).enum.defined_only = true]; - string request_tool = 11 [(buf.validate.field).string.max_len = 256]; - string request_call_id = 12 [(buf.validate.field).string.max_len = 256]; - TerminalErrorEnvelope terminal_error = 13; -} - -message OperatingThreadResponse { - string request_id = 1 [ - (buf.validate.field).string.min_len = 1, - (buf.validate.field).string.max_len = 256 - ]; - string call_id = 2 [(buf.validate.field).string.max_len = 256]; - OperatingThreadRequestType request_type = 3 [(buf.validate.field).enum.defined_only = true]; - OperatingThreadResponseAction action = 4 [(buf.validate.field).enum.defined_only = true]; - string text = 5 [(buf.validate.field).string.max_len = 65536]; - bool is_error = 6; - string idempotency_key = 7 [(buf.validate.field).string.max_len = 512]; -} - -enum OperatingAttachmentScope { - OPERATING_ATTACHMENT_SCOPE_UNSPECIFIED = 0; - OPERATING_ATTACHMENT_SCOPE_CONVERSATION = 1; - OPERATING_ATTACHMENT_SCOPE_WORKSPACE = 2; -} - -enum OperatingAttachmentProcessingState { - OPERATING_ATTACHMENT_PROCESSING_STATE_UNSPECIFIED = 0; - OPERATING_ATTACHMENT_PROCESSING_STATE_UPLOADING = 1; - OPERATING_ATTACHMENT_PROCESSING_STATE_PROCESSING = 2; - OPERATING_ATTACHMENT_PROCESSING_STATE_READY = 3; - OPERATING_ATTACHMENT_PROCESSING_STATE_FAILED = 4; -} - -message OperatingAttachmentRef { - string id = 1; - string object_id = 2; - string version_id = 3; - OperatingAttachmentScope scope = 4 [(buf.validate.field).enum.defined_only = true]; - string channel_id = 5; - string filename = 6; - string content_type = 7; - int64 size_bytes = 8 [(buf.validate.field).int64 = { - gte: 0 - lte: 52428800 - }]; - string sha256 = 9; - OperatingAttachmentProcessingState processing_state = 10 [(buf.validate.field).enum.defined_only = true]; - string extraction_object_id = 11; - string extraction_version_id = 12; - google.protobuf.Timestamp created_at = 13; -} - -// ReceiptLifecycleState is the owner's single answer for where one receipt's -// work stands. The owner resolves precedence across its typed lifecycle fields -// so every client renders one state instead of re-deriving it from `status` and -// payload evidence. UNSPECIFIED means the responding build did not state a -// lifecycle; UNKNOWN means the owner holds lifecycle evidence it cannot name, -// and clients must not present such work as finished. -enum ReceiptLifecycleState { - RECEIPT_LIFECYCLE_STATE_UNSPECIFIED = 0; - RECEIPT_LIFECYCLE_STATE_UNKNOWN = 1; - RECEIPT_LIFECYCLE_STATE_PROPOSED = 2; - RECEIPT_LIFECYCLE_STATE_QUEUED = 3; - RECEIPT_LIFECYCLE_STATE_WAITING_APPROVAL = 4; - RECEIPT_LIFECYCLE_STATE_BLOCKED = 5; - RECEIPT_LIFECYCLE_STATE_NEEDS_INPUT = 6; - RECEIPT_LIFECYCLE_STATE_UNAVAILABLE = 7; - RECEIPT_LIFECYCLE_STATE_RUNNING = 8; - RECEIPT_LIFECYCLE_STATE_SUCCEEDED = 9; - RECEIPT_LIFECYCLE_STATE_VERIFIED = 10; - RECEIPT_LIFECYCLE_STATE_DENIED = 11; - RECEIPT_LIFECYCLE_STATE_CANCELLED = 12; - RECEIPT_LIFECYCLE_STATE_FAILED = 13; -} - -// OperatingReceipt is the mini-app object rendered inline in chat and expanded -// in the inspector. Display payloads must be safe for UI rendering and must not -// include raw prompts, tool arguments, credentials, tokens, connector payloads, -// VFS bytes, or model responses. -message OperatingReceipt { - string id = 1; - string kind = 2; - string title = 3; - string summary = 4; - string status = 5; - string owner_service = 6; - string object_id = 7; - string objective_id = 8; - string run_id = 9; - string approval_request_id = 10; - string trace_id = 11; - common.v1.RiskLevel risk_level = 12; - google.protobuf.Timestamp updated_at = 13; - repeated OperatingReceiptAction allowed_actions = 14; - repeated RelatedResource evidence_refs = 15; - google.protobuf.Struct payload = 16; - // Owner-resolved lifecycle. Thread responses strip receipt payloads, so this - // is the only lifecycle statement a client can read there. - ReceiptLifecycleState lifecycle_state = 17 [(buf.validate.field).enum.defined_only = true]; - // Set only by the fenced coding completion owner; absent until evaluated. - OperatingCodingAcceptance coding_acceptance = 18; -} - -// OperatingReceiptAction is a typed command the backend allows for one receipt. -message OperatingReceiptAction { - string id = 1; - string label = 2; - string kind = 3; - string target_kind = 4; - string target_id = 5; - bool requires_confirmation = 6; - string disabled_reason = 7; - google.protobuf.Struct payload = 8; -} - -message ListOperatingChannelsRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - OperatingThreadArchiveFilter archive_filter = 2 [(buf.validate.field).enum.defined_only = true]; - // Return only the threads bound to this source project. Empty returns every - // thread in the tenant scope, bound or not. - string project_resource_id = 3 [ - (buf.validate.field).string.max_len = 255, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; -} - -message ListOperatingChannelsResponse { - repeated OperatingChannel channels = 1; - repeated OperatingCapabilityState capabilities = 2; - // One short-lived, backend-authored starter grounded in this principal's - // recent operating questions and ranked against Cerebro's tenant-local - // conversation memory. Absent means recall was unavailable or had no - // sufficiently grounded result; clients must keep their ordinary starter. - OperatingHomepageSuggestion homepage_suggestion = 3; -} - -message ArchiveOperatingThreadRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string channel_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - bool archived = 3; - string idempotency_key = 4 [ - (buf.validate.field).string.min_len = 1, - (buf.validate.field).string.max_len = 512, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; -} - -message ArchiveOperatingThreadResponse { - OperatingChannel channel = 1 [(buf.validate.field).required = true]; - bool changed = 2; - bool replayed = 3; -} - -message ForkOperatingThreadRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string source_channel_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - // Copy history up to and including this message. Empty copies the whole - // thread as of expected_source_conversation_revision. - string through_message_id = 3 [ - (buf.validate.field).string.max_len = 512, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - // The source conversation_revision the caller observed. The fork is refused - // when the source has moved since, so a fork always names a state the - // caller actually read. - int64 expected_source_conversation_revision = 4; - string idempotency_key = 5 [ - (buf.validate.field).string.min_len = 1, - (buf.validate.field).string.max_len = 512, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string label = 6 [ - (buf.validate.field).string.max_len = 80, - (common.v1.classification) = DATA_CLASSIFICATION_CONTENT - ]; -} - -message ForkOperatingThreadResponse { - OperatingChannel channel = 1 [(buf.validate.field).required = true]; - bool replayed = 2; -} - -message RenameOperatingThreadRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string channel_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string title = 3 [ - (buf.validate.field).string.min_len = 1, - (buf.validate.field).string.max_len = 80, - (common.v1.classification) = DATA_CLASSIFICATION_CONTENT - ]; -} - -message RenameOperatingThreadResponse { - OperatingChannel channel = 1 [(buf.validate.field).required = true]; - bool changed = 2; -} - -message GetOperatingThreadRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string channel_id = 2 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - int32 limit = 3 [(buf.validate.field).int32 = { - gte: 0 - lte: 200 - }]; - string page_token = 4 [ - (buf.validate.field).string.max_len = 2048, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; -} - -message GetOperatingThreadResponse { - OperatingChannel channel = 1; - repeated OperatingMessage messages = 2; - repeated OperatingReceipt receipts = 3; - repeated OperatingCapabilityState capabilities = 4; - OperatingThreadExecution thread_execution = 5; - repeated OperatingThreadTurn turns = 6; - int64 replay_cursor = 7 [(buf.validate.field).int64.gte = 0]; - string next_page_token = 8 [ - (buf.validate.field).string.max_len = 2048, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - OperatingModelSelection model_selection = 9; - repeated InferenceProviderTarget available_models = 10; - InferenceProviderTarget default_model = 11; -} - -message RespondOperatingThreadRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string channel_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string turn_id = 3 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - OperatingThreadResponse response = 4 [(buf.validate.field).required = true]; - string idempotency_key = 5 [ - (buf.validate.field).string.min_len = 1, - (buf.validate.field).string.max_len = 512, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; -} - -message RespondOperatingThreadResponse { - string runtime_run_id = 1; - bool replayed = 2; - OperatingThreadExecution thread_execution = 3; - repeated OperatingThreadTurn turns = 4; - int64 replay_cursor = 5 [(buf.validate.field).int64.gte = 0]; -} - -message InterruptOperatingThreadRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string channel_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - // When empty, the owner interrupts the lowest-sequence non-terminal turn. - string turn_id = 3 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string idempotency_key = 4 [ - (buf.validate.field).string.min_len = 1, - (buf.validate.field).string.max_len = 512, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - // Optional product-safe reason shown only as audit metadata, never as model prompt. - string reason = 5 [ - (buf.validate.field).string.max_len = 512, - (common.v1.classification) = DATA_CLASSIFICATION_CONTENT - ]; -} - -message InterruptOperatingThreadResponse { - string turn_id = 1; - bool replayed = 2; - OperatingThreadExecution thread_execution = 3; - repeated OperatingThreadTurn turns = 4; - int64 replay_cursor = 5 [(buf.validate.field).int64.gte = 0]; - // Runtime work cancelled for the interrupted turn's submitted message, if any. - repeated string cancelled_work_ids = 6 [(buf.validate.field).repeated.max_items = 32]; -} - -message ListOperatingThreadEventsRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string channel_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - int64 after_cursor = 3 [(buf.validate.field).int64.gte = 0]; - int32 limit = 4 [(buf.validate.field).int32 = { - gte: 1 - lte: 200 - }]; -} - -message ListOperatingThreadEventsResponse { - repeated OperatingThreadEvent events = 1 [(buf.validate.field).repeated.max_items = 200]; - int64 next_cursor = 2 [(buf.validate.field).int64.gte = 0]; - bool has_more = 3; - // reset_required is true only when retention removed the requested cursor. - // Clients replace their projection with the accompanying snapshot. - bool reset_required = 4; - OperatingThreadExecution thread_execution = 5; - repeated OperatingThreadTurn snapshot_turns = 6; -} - -message WatchOperatingThreadRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string channel_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - int64 after_cursor = 3 [(buf.validate.field).int64.gte = 0]; -} - -message WatchOperatingThreadResponse { - repeated OperatingThreadEvent events = 1 [(buf.validate.field).repeated.max_items = 50]; - int64 next_cursor = 2 [(buf.validate.field).int64.gte = 0]; - bool reset_required = 3; - OperatingThreadExecution thread_execution = 4; - repeated OperatingThreadTurn snapshot_turns = 5; -} - -// Explicit acceptance requirements for a coding task. Platform binds task_id -// to the resolved conversation task; clients may leave it empty for new work. -// These requirements grant no tool, repository-access, or approval authority. -message CodingAcceptanceContract { - string task_id = 1 [(buf.validate.field).string.max_len = 256]; - string repository_id = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 512 - }]; - uint64 generation = 3 [(buf.validate.field).uint64.gt = 0]; - repeated string required_assertion_ids = 4 [(buf.validate.field).repeated = { - min_items: 1 - max_items: 128 - }]; - bool require_review = 5; - bool require_behavior = 6; - repeated string readiness_requirements = 7 [(buf.validate.field).repeated.max_items = 128]; - repeated string authorized_skips = 8 [(buf.validate.field).repeated.max_items = 128]; - repeated string authorized_dispositions = 9 [(buf.validate.field).repeated.max_items = 128]; - repeated string output_paths = 10 [(buf.validate.field).repeated.max_items = 8]; -} - -// Explicit caller intent. This never grants execution or repository authority. -// Unspecified preserves existing chat and replay clients. -enum OperatingTaskKind { - OPERATING_TASK_KIND_UNSPECIFIED = 0; - OPERATING_TASK_KIND_CONVERSATION = 1; - OPERATING_TASK_KIND_CODING_IMPLEMENTATION = 2; -} - -message SubmitOperatingMessageRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string channel_id = 2 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string body = 3 [ - (buf.validate.field).string.max_len = 20000, - (common.v1.classification) = DATA_CLASSIFICATION_CONTENT - ]; - string idempotency_key = 4 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - repeated OperatingAttachmentRef attachments = 5 [(buf.validate.field).repeated.max_items = 1]; - // continuation_task_id resumes existing work. Omit it to create a new task. - // The server owns task creation and revision assignment. - string continuation_task_id = 6 [ - (buf.validate.field).string.max_len = 256, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - repeated string reference_task_ids = 7 [ - (buf.validate.field).repeated = { - max_items: 16 - items: { - string: { - min_len: 1 - max_len: 256 - } - } - }, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - // The id returned by PrewarmOperatingThread. The server verifies it is - // tenant- and principal-bound before reusing the prepared RunnerSession. - string draft_prewarm_id = 8 [ - (buf.validate.field).string.max_len = 256, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - // Omitted preserves the conversation preference; an empty message resets Auto. - // This is a preference, never managed inference authorization. - OperatingModelSelection model_selection = 9; - // Opt in to evidence-backed coding acceptance; absence preserves ordinary chat. - CodingAcceptanceContract coding_acceptance = 10; - optional string project_resource_id = 11 [ - (buf.validate.field).string = { - min_len: 1 - max_len: 255 - }, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - // New coding implementation submissions require an admitted coding_acceptance - // contract. No classification is inferred from the body or project name. - OperatingTaskKind task_kind = 12 [(buf.validate.field).enum.defined_only = true]; -} - -message BeginOperatingAttachmentUploadRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string channel_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string filename = 3 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_PATH - ]; - string content_type = 4 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_SAFE - ]; - int64 size_bytes = 5 [(buf.validate.field).int64 = { - gt: 0 - lte: 52428800 - }]; - string sha256 = 6 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - OperatingAttachmentScope scope = 7 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string idempotency_key = 8 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; -} - -message BeginOperatingAttachmentUploadResponse { - OperatingAttachmentRef attachment = 1; - string lease_id = 2; - string lease_token = 3; - int64 fencing_token = 4; - vfs.v1.VfsUploadTarget upload = 5; -} - -message CompleteOperatingAttachmentUploadRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string channel_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string attachment_id = 3 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string lease_id = 4 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string lease_token = 5 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_CREDENTIAL - ]; - int64 fencing_token = 6 [(buf.validate.field).int64.gte = 1]; - int64 size_bytes = 7 [(buf.validate.field).int64 = { - gt: 0 - lte: 52428800 - }]; - string sha256 = 8 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string storage_etag = 9 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string idempotency_key = 10 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - repeated vfs.v1.VfsCompletedUploadPart completed_parts = 11 [(buf.validate.field).repeated.max_items = 10000]; -} - -message CompleteOperatingAttachmentUploadResponse { - OperatingAttachmentRef attachment = 1; -} - -message ListOperatingAttachmentsRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string channel_id = 2 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - OperatingAttachmentScope scope = 3 [(buf.validate.field).enum.defined_only = true]; - int32 limit = 4 [(buf.validate.field).int32 = { - gte: 0 - lte: 100 - }]; - int32 offset = 5 [(buf.validate.field).int32.gte = 0]; -} - -message ListOperatingAttachmentsResponse { - repeated OperatingAttachmentRef attachments = 1; - bool has_more = 2; -} - -message SubmitOperatingMessageResponse { - OperatingMessage message = 1; - repeated OperatingReceipt receipts = 2; - repeated OperatingCapabilityState capabilities = 3; - // Full turn messages written by the submit. `message` remains the canonical - // submitted human turn for older clients. - repeated OperatingMessage messages = 4; - OperatingTurnRoute route = 5; - OperatingThreadTurn accepted_turn = 6; - int64 replay_cursor = 7 [(buf.validate.field).int64.gte = 0]; -} - -enum OperatingCorrectionCategory { - OPERATING_CORRECTION_CATEGORY_UNSPECIFIED = 0; - OPERATING_CORRECTION_CATEGORY_WRONG_TOPIC = 1; - OPERATING_CORRECTION_CATEGORY_NOT_DONE = 2; - OPERATING_CORRECTION_CATEGORY_INCORRECT_FACT = 3; - OPERATING_CORRECTION_CATEGORY_UNSAFE_ACTION = 4; - OPERATING_CORRECTION_CATEGORY_OTHER = 5; -} - -enum OperatingCorrectionReviewState { - OPERATING_CORRECTION_REVIEW_STATE_UNSPECIFIED = 0; - OPERATING_CORRECTION_REVIEW_STATE_PENDING_REVIEW = 1; - OPERATING_CORRECTION_REVIEW_STATE_APPROVED = 2; - OPERATING_CORRECTION_REVIEW_STATE_REJECTED = 3; - OPERATING_CORRECTION_REVIEW_STATE_INELIGIBLE = 4; -} - -enum DexComputerCorrectionLabel { - DEX_COMPUTER_CORRECTION_LABEL_UNSPECIFIED = 0; - DEX_COMPUTER_CORRECTION_LABEL_WRONG_TARGET = 1; - DEX_COMPUTER_CORRECTION_LABEL_WRONG_ACTION = 2; - DEX_COMPUTER_CORRECTION_LABEL_MISSING_OBSERVATION = 3; - DEX_COMPUTER_CORRECTION_LABEL_EFFECT_AMBIGUOUS = 4; - DEX_COMPUTER_CORRECTION_LABEL_UNSAFE_BOUNDARY = 5; - DEX_COMPUTER_CORRECTION_LABEL_HANDOFF_CONFLICT = 6; - DEX_COMPUTER_CORRECTION_LABEL_OTHER = 7; -} - -message DexComputerCorrectionEpisode { - string schema = 1 [(buf.validate.field).string.min_len = 1]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 3 [(buf.validate.field).string.min_len = 1]; - string correction_id = 4 [(buf.validate.field).string.min_len = 1]; - string source_episode_id = 5 [(buf.validate.field).string.min_len = 1]; - string source_episode_digest_sha256 = 6 [(buf.validate.field).string.len = 64]; - repeated DexComputerCorrectionLabel labels = 7 [(buf.validate.field).repeated.items.enum = { - defined_only: true - not_in: [0] - }]; - repeated string evidence_digests_sha256 = 8 [(buf.validate.field).repeated = { - min_items: 1 - max_items: 64 - items: { - string: {len: 64} - } - }]; - OperatingCorrectionReviewState review_state = 9 [(buf.validate.field).enum.defined_only = true]; - bool production_learning = 10; - string reuse_boundary = 11 [(buf.validate.field).string.min_len = 1]; - string episode_digest_sha256 = 12 [(buf.validate.field).string.len = 64]; -} - -message OperatingCorrectionCandidate { - string id = 1; - string channel_id = 2; - string message_id = 3; - OperatingCorrectionCategory category = 4 [(buf.validate.field).enum.defined_only = true]; - string feedback_digest_sha256 = 5; - bool remember_requested = 6; - bool learning_eligible = 7; - OperatingCorrectionReviewState review_state = 8 [(buf.validate.field).enum.defined_only = true]; - string reviewer_id = 9; - repeated RelatedResource evidence_refs = 10 [(buf.validate.field).repeated.max_items = 64]; - google.protobuf.Timestamp created_at = 11; - google.protobuf.Timestamp reviewed_at = 12; - WorkspaceSettingsCapability review_capability = 13; - DexComputerCorrectionEpisode correction_episode = 14 [(buf.validate.field).required = true]; -} - -message SubmitOperatingCorrectionRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string channel_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string message_id = 3 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - OperatingCorrectionCategory category = 4 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string feedback = 5 [ - (buf.validate.field).string.max_len = 4000, - (common.v1.classification) = DATA_CLASSIFICATION_CONTENT - ]; - bool remember = 6; - string idempotency_key = 7 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; -} - -message SubmitOperatingCorrectionResponse { - OperatingCorrectionCandidate correction = 1 [(buf.validate.field).required = true]; -} - -enum OperatingFeedbackSentiment { - OPERATING_FEEDBACK_SENTIMENT_UNSPECIFIED = 0; - OPERATING_FEEDBACK_SENTIMENT_POSITIVE = 1; - OPERATING_FEEDBACK_SENTIMENT_NEGATIVE = 2; -} - -enum OperatingFeedbackReason { - OPERATING_FEEDBACK_REASON_UNSPECIFIED = 0; - OPERATING_FEEDBACK_REASON_HELPFUL = 1; - OPERATING_FEEDBACK_REASON_ACCURATE = 2; - OPERATING_FEEDBACK_REASON_CLEAR = 3; - OPERATING_FEEDBACK_REASON_CORRECT_ACTION = 4; - OPERATING_FEEDBACK_REASON_MISSED_REQUEST = 5; - OPERATING_FEEDBACK_REASON_INCORRECT = 6; - OPERATING_FEEDBACK_REASON_INCOMPLETE = 7; - OPERATING_FEEDBACK_REASON_UNCLEAR = 8; - OPERATING_FEEDBACK_REASON_MISSING_EVIDENCE = 9; - OPERATING_FEEDBACK_REASON_UNSAFE = 10; - OPERATING_FEEDBACK_REASON_OTHER = 11; - OPERATING_FEEDBACK_REASON_COMPLETE = 12; - OPERATING_FEEDBACK_REASON_IGNORED_INSTRUCTIONS = 13; - OPERATING_FEEDBACK_REASON_TOOL_FAILED = 14; - OPERATING_FEEDBACK_REASON_TOO_VERBOSE = 15; -} - -enum OperatingFeedbackClassificationSource { - OPERATING_FEEDBACK_CLASSIFICATION_SOURCE_UNSPECIFIED = 0; - OPERATING_FEEDBACK_CLASSIFICATION_SOURCE_USER = 1; - OPERATING_FEEDBACK_CLASSIFICATION_SOURCE_AGENT_SUGGESTED_USER_CONFIRMED = 2; -} - -enum OperatingFeedbackRemediationAction { - OPERATING_FEEDBACK_REMEDIATION_ACTION_UNSPECIFIED = 0; - OPERATING_FEEDBACK_REMEDIATION_ACTION_NONE = 1; - OPERATING_FEEDBACK_REMEDIATION_ACTION_VERIFY = 2; - OPERATING_FEEDBACK_REMEDIATION_ACTION_RETRY = 3; -} - -enum OperatingFeedbackRemediationOutcome { - OPERATING_FEEDBACK_REMEDIATION_OUTCOME_UNSPECIFIED = 0; - OPERATING_FEEDBACK_REMEDIATION_OUTCOME_UNCONFIRMED = 1; - OPERATING_FEEDBACK_REMEDIATION_OUTCOME_ACCEPTED = 2; - OPERATING_FEEDBACK_REMEDIATION_OUTCOME_REJECTED = 3; -} - -enum OperatingFeedbackLifecycleState { - OPERATING_FEEDBACK_LIFECYCLE_STATE_UNSPECIFIED = 0; - OPERATING_FEEDBACK_LIFECYCLE_STATE_ACTIVE = 1; - OPERATING_FEEDBACK_LIFECYCLE_STATE_SUPERSEDED = 2; - OPERATING_FEEDBACK_LIFECYCLE_STATE_RETRACTED = 3; -} - -message OperatingFeedback { - string id = 1; - string channel_id = 2; - string message_id = 3; - OperatingFeedbackSentiment sentiment = 4 [(buf.validate.field).enum.defined_only = true]; - OperatingCorrectionCategory category = 5 [(buf.validate.field).enum.defined_only = true]; - OperatingFeedbackClassificationSource classification_source = 6 [(buf.validate.field).enum.defined_only = true]; - string taxonomy_version = 7; - bool correction_present = 8; - string correction_id = 9; - bool learning_eligible = 10; - OperatingFeedbackRemediationAction remediation_action = 11 [(buf.validate.field).enum.defined_only = true]; - string remediation_attempt_id = 12; - OperatingFeedbackRemediationOutcome remediation_outcome = 13 [(buf.validate.field).enum.defined_only = true]; - google.protobuf.Timestamp created_at = 14; - google.protobuf.Timestamp updated_at = 15; - google.protobuf.Timestamp resolved_at = 16; - OperatingFeedbackReason reason = 17 [(buf.validate.field).enum.defined_only = true]; - OperatingFeedbackLifecycleState lifecycle_state = 18 [(buf.validate.field).enum.defined_only = true]; - string root_feedback_id = 19; - uint64 revision = 20; - string supersedes_feedback_id = 21; -} - -message SubmitOperatingFeedbackRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string channel_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string message_id = 3 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - OperatingFeedbackSentiment sentiment = 4 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - OperatingCorrectionCategory category = 5 [(buf.validate.field).enum.defined_only = true]; - OperatingFeedbackClassificationSource classification_source = 6 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string correction = 7 [ - (buf.validate.field).string.max_len = 4000, - (common.v1.classification) = DATA_CLASSIFICATION_CONTENT - ]; - bool remember = 8; - OperatingFeedbackRemediationAction remediation_action = 9 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string remediation_attempt_id = 10 [ - (buf.validate.field).string.max_len = 256, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string idempotency_key = 11 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - OperatingFeedbackReason reason = 12 [(buf.validate.field).enum.defined_only = true]; - OperatingFeedbackLifecycleState lifecycle_state = 13 [(buf.validate.field).enum.defined_only = true]; - string supersedes_feedback_id = 14 [ - (buf.validate.field).string.max_len = 256, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; -} - -message SubmitOperatingFeedbackResponse { - OperatingFeedback feedback = 1 [(buf.validate.field).required = true]; - OperatingCorrectionCandidate correction = 2; - CustomerIntelligenceReceipt fact_receipt = 3; -} - -message ProductIssueReport { - string id = 1; - string reference = 2; - bool diagnostics_included = 3; - bool screenshot_attached = 4; - google.protobuf.Timestamp created_at = 5; -} - -message SubmitProductIssueReportRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string description = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 4000 - }]; - string expected_behavior = 3 [(buf.validate.field).string.max_len = 4000]; - string page_url = 4 [(buf.validate.field).string.max_len = 2048]; - string app_version = 5 [(buf.validate.field).string.max_len = 128]; - string browser = 6 [(buf.validate.field).string.max_len = 512]; - string viewport = 7 [(buf.validate.field).string.max_len = 64]; - string screenshot_filename = 8 [(buf.validate.field).string.max_len = 255]; - string screenshot_content_type = 9 [(buf.validate.field).string.max_len = 64]; - bytes screenshot = 10 [(buf.validate.field).bytes.max_len = 5242880]; - bool include_diagnostics = 11; - string idempotency_key = 12 [(buf.validate.field).string = { - min_len: 1 - max_len: 512 - }]; - ProductIssueReportContext context = 13; -} - -// Native reports reuse the product issue owner with a bounded diagnostic projection. -// Tags match the canonical submission fields; browser-only fields are reserved. -message SubmitNativeProductIssueReportRequest { - reserved 4, 6 to 10; - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string description = 2 [ - (common.v1.classification) = DATA_CLASSIFICATION_CONTENT, - (buf.validate.field).string = { - min_len: 1 - max_len: 4000 - } - ]; - string expected_behavior = 3 [ - (common.v1.classification) = DATA_CLASSIFICATION_CONTENT, - (buf.validate.field).string.max_len = 4000 - ]; - string app_version = 5 [ - (common.v1.classification) = DATA_CLASSIFICATION_SAFE, - (buf.validate.field).string.max_len = 128 - ]; - bool include_diagnostics = 11; - string idempotency_key = 12 [ - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER, - (buf.validate.field).string = { - min_len: 1 - max_len: 512 - } - ]; - ProductIssueReportContext context = 13; -} - -// Explicitly selected native evidence. No session or machine-wide collection. -message ProductIssueReportContext { - string reproduction_steps = 1 [ - (common.v1.classification) = DATA_CLASSIFICATION_CONTENT, - (buf.validate.field).string.max_len = 4000 - ]; - string model = 2 [ - (common.v1.classification) = DATA_CLASSIFICATION_SAFE, - (buf.validate.field).string.max_len = 256 - ]; - repeated ProductIssueReportEvidence evidence = 3 [(buf.validate.field).repeated.max_items = 10]; -} -message ProductIssueReportEvidence { - string kind = 1 [ - (common.v1.classification) = DATA_CLASSIFICATION_SAFE, - (buf.validate.field).string.max_len = 32 - ]; - string source_id = 2 [ - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER, - (buf.validate.field).string.max_len = 256 - ]; - string text = 3 [ - (common.v1.classification) = DATA_CLASSIFICATION_CONTENT, - (buf.validate.field).string.max_len = 4000 - ]; -} - -message SubmitProductIssueReportResponse { - ProductIssueReport report = 1 [(buf.validate.field).required = true]; -} - -message StaffProductIssueReport { - string organization_id = 1; - string workspace_id = 2; - string id = 3; - string reference = 4; - string description = 5; - string expected_behavior = 6; - string page_url = 7; - string app_version = 8; - string browser = 9; - string viewport = 10; - bool diagnostics_included = 11; - bool screenshot_attached = 12; - string screenshot_filename = 13; - string screenshot_content_type = 14; - string created_by_principal_id = 15; - google.protobuf.Timestamp created_at = 16; - string engagement_state = 17; - google.protobuf.Timestamp engaged_at = 18; - string engaged_by_principal_id = 19; - string engagement_note = 20; - ProductIssueReportContext context = 21; - // Exact normalized symptom grouping, scoped to one organization and workspace. - string symptom_group = 22 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string baseline_test_run_id = 23 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string verification_test_run_id = 24 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string regression_state = 25 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; -} - -message ListStaffProductIssueReportsRequest { - string engagement_state = 1 [(buf.validate.field).string.max_len = 32]; - uint32 limit = 2 [(buf.validate.field).uint32 = { - gte: 1 - lte: 100 - }]; -} - -message ListStaffProductIssueReportsResponse { - repeated StaffProductIssueReport reports = 1; -} - -message EngageStaffProductIssueReportRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string report_id = 3 [(buf.validate.field).string.min_len = 1]; - string note = 4 [(buf.validate.field).string = { - min_len: 1 - max_len: 1000 - }]; - // A staff-reviewed failing test becomes the reproduction reference. A verified - // fix requires a successful run of the same Playbook with its assertions met. - string baseline_test_run_id = 5 [ - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER, - (buf.validate.field).string.max_len = 256 - ]; - string verification_test_run_id = 6 [ - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER, - (buf.validate.field).string.max_len = 256 - ]; -} - -message EngageStaffProductIssueReportResponse { - StaffProductIssueReport report = 1 [(buf.validate.field).required = true]; -} - -message GetOperatingFeedbackRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string channel_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string message_id = 3 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; -} - -message GetOperatingFeedbackResponse { - OperatingFeedback feedback = 1; -} - -message ResolveOperatingFeedbackRemediationRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string feedback_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - OperatingFeedbackRemediationOutcome outcome = 3 [(buf.validate.field).enum = { - defined_only: true - in: [ - 2, - 3 - ] - }]; - string idempotency_key = 4 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; -} - -message ResolveOperatingFeedbackRemediationResponse { - OperatingFeedback feedback = 1 [(buf.validate.field).required = true]; - CustomerIntelligenceReceipt fact_receipt = 2; -} - -enum CustomerIntelligenceAuthority { - CUSTOMER_INTELLIGENCE_AUTHORITY_UNSPECIFIED = 0; - CUSTOMER_INTELLIGENCE_AUTHORITY_INFERRED = 1; - CUSTOMER_INTELLIGENCE_AUTHORITY_OBSERVED = 2; - CUSTOMER_INTELLIGENCE_AUTHORITY_STATED = 3; - CUSTOMER_INTELLIGENCE_AUTHORITY_CORROBORATED = 4; - CUSTOMER_INTELLIGENCE_AUTHORITY_CONFIRMED = 5; -} - -enum CustomerIntelligenceLifecycleState { - CUSTOMER_INTELLIGENCE_LIFECYCLE_STATE_UNSPECIFIED = 0; - CUSTOMER_INTELLIGENCE_LIFECYCLE_STATE_PROPOSED = 1; - CUSTOMER_INTELLIGENCE_LIFECYCLE_STATE_ACTIVE = 2; - CUSTOMER_INTELLIGENCE_LIFECYCLE_STATE_DISPUTED = 3; - CUSTOMER_INTELLIGENCE_LIFECYCLE_STATE_SUPERSEDED = 4; - CUSTOMER_INTELLIGENCE_LIFECYCLE_STATE_EXPIRED = 5; -} - -enum CustomerIntelligenceSubjectKind { - CUSTOMER_INTELLIGENCE_SUBJECT_KIND_UNSPECIFIED = 0; - CUSTOMER_INTELLIGENCE_SUBJECT_KIND_INTERACTION = 1; - CUSTOMER_INTELLIGENCE_SUBJECT_KIND_WORKSPACE = 2; - CUSTOMER_INTELLIGENCE_SUBJECT_KIND_PRODUCT_AREA = 3; - CUSTOMER_INTELLIGENCE_SUBJECT_KIND_COHORT = 4; -} - -enum CustomerIntelligenceEvidencePolarity { - CUSTOMER_INTELLIGENCE_EVIDENCE_POLARITY_UNSPECIFIED = 0; - CUSTOMER_INTELLIGENCE_EVIDENCE_POLARITY_SUPPORTING = 1; - CUSTOMER_INTELLIGENCE_EVIDENCE_POLARITY_CONTRADICTING = 2; -} - -enum CustomerIntelligenceProducerKind { - CUSTOMER_INTELLIGENCE_PRODUCER_KIND_UNSPECIFIED = 0; - CUSTOMER_INTELLIGENCE_PRODUCER_KIND_PLATFORM_DETERMINISTIC_FEEDBACK = 1; - CUSTOMER_INTELLIGENCE_PRODUCER_KIND_CEREBRO = 2; - CUSTOMER_INTELLIGENCE_PRODUCER_KIND_STAFF_REVIEW = 3; - CUSTOMER_INTELLIGENCE_PRODUCER_KIND_CUSTOMER_CONFIRMATION = 4; - CUSTOMER_INTELLIGENCE_PRODUCER_KIND_OUTCOME_EVALUATOR = 5; -} - -enum CustomerIntelligenceReviewDecision { - CUSTOMER_INTELLIGENCE_REVIEW_DECISION_UNSPECIFIED = 0; - CUSTOMER_INTELLIGENCE_REVIEW_DECISION_REQUEST_CONFIRMATION = 1; - CUSTOMER_INTELLIGENCE_REVIEW_DECISION_REQUEST_EVIDENCE = 2; - CUSTOMER_INTELLIGENCE_REVIEW_DECISION_CHALLENGE = 3; - CUSTOMER_INTELLIGENCE_REVIEW_DECISION_DISPUTE = 4; - CUSTOMER_INTELLIGENCE_REVIEW_DECISION_EXPIRE = 5; - CUSTOMER_INTELLIGENCE_REVIEW_DECISION_SUPERSEDE = 6; - CUSTOMER_INTELLIGENCE_REVIEW_DECISION_PROPOSE_ACTION = 7; -} - -enum CustomerFactConfirmationResponse { - CUSTOMER_FACT_CONFIRMATION_RESPONSE_UNSPECIFIED = 0; - CUSTOMER_FACT_CONFIRMATION_RESPONSE_CONFIRM = 1; - CUSTOMER_FACT_CONFIRMATION_RESPONSE_DISPUTE = 2; -} - -message CustomerIntelligenceEvidenceRef { - string owner_type = 1 [(buf.validate.field).string = { - min_len: 1 - max_len: 80 - }]; - string owner_id = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 256 - }]; - string evidence_id = 3 [(buf.validate.field).string = { - min_len: 1 - max_len: 256 - }]; - CustomerIntelligenceEvidencePolarity polarity = 4 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string digest_sha256 = 5 [(buf.validate.field).string.len = 64]; - string safe_label = 6 [(buf.validate.field).string.max_len = 120]; -} - -message CustomerIntelligenceFactRevision { - string fact_id = 1; - int64 revision = 2 [(buf.validate.field).int64.gt = 0]; - string organization_id = 3; - string workspace_id = 4; - CustomerIntelligenceSubjectKind subject_kind = 5 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string subject_ref_hash = 6 [(buf.validate.field).string.len = 64]; - string product_area = 7 [(buf.validate.field).string = { - min_len: 1 - max_len: 80 - }]; - string journey = 8 [(buf.validate.field).string = { - min_len: 1 - max_len: 80 - }]; - string predicate = 9 [(buf.validate.field).string = { - min_len: 1 - max_len: 120 - }]; - string safe_summary = 10 [(buf.validate.field).string = { - min_len: 1 - max_len: 280 - }]; - CustomerIntelligenceAuthority authority = 11 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - CustomerIntelligenceLifecycleState lifecycle_state = 12 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - int32 confidence_micros = 13 [(buf.validate.field).int32 = { - gte: 0 - lte: 1000000 - }]; - repeated CustomerIntelligenceEvidenceRef evidence_refs = 14 [(buf.validate.field).repeated.max_items = 64]; - CustomerIntelligenceProducerKind producer_kind = 15 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string producer_ref = 16 [(buf.validate.field).string.max_len = 256]; - string model_id = 17 [(buf.validate.field).string.max_len = 160]; - string run_id = 18 [(buf.validate.field).string.max_len = 256]; - string policy_version = 19 [(buf.validate.field).string.max_len = 80]; - string lineage_id = 20 [(buf.validate.field).string.max_len = 256]; - string sensitivity = 21 [(buf.validate.field).string.max_len = 40]; - string retention_class = 22 [(buf.validate.field).string.max_len = 40]; - google.protobuf.Timestamp valid_from = 23; - google.protobuf.Timestamp expires_at = 24; - string content_fingerprint_sha256 = 25 [(buf.validate.field).string.len = 64]; - string actor_id = 26 [(buf.validate.field).string.max_len = 256]; - google.protobuf.Timestamp created_at = 27; -} - -message CustomerIntelligenceFact { - CustomerIntelligenceFactRevision current = 1 [(buf.validate.field).required = true]; - repeated CustomerIntelligenceFactRevision revisions = 2 [(buf.validate.field).repeated.max_items = 100]; -} - -message CustomerIntelligenceReceipt { - string fact_id = 1; - int64 revision = 2 [(buf.validate.field).int64.gt = 0]; - CustomerIntelligenceAuthority authority = 3 [(buf.validate.field).enum.defined_only = true]; - CustomerIntelligenceLifecycleState lifecycle_state = 4 [(buf.validate.field).enum.defined_only = true]; - string audit_delivery_state = 5; - string confirmation_intent_id = 6; -} - -message ListCustomerIntelligenceFactsRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - repeated CustomerIntelligenceAuthority authorities = 2 [(buf.validate.field).repeated.max_items = 6]; - repeated CustomerIntelligenceLifecycleState lifecycle_states = 3 [(buf.validate.field).repeated.max_items = 6]; - CustomerIntelligenceSubjectKind subject_kind = 4 [(buf.validate.field).enum.defined_only = true]; - string product_area = 5 [(buf.validate.field).string.max_len = 80]; - string journey = 6 [(buf.validate.field).string.max_len = 80]; - google.protobuf.Timestamp created_after = 7; - int32 limit = 8 [(buf.validate.field).int32 = { - gte: 0 - lte: 200 - }]; -} - -message ListCustomerIntelligenceFactsResponse { - repeated CustomerIntelligenceFact facts = 1; -} - -message GetCustomerIntelligenceFactRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string fact_id = 2 [(buf.validate.field).string.min_len = 1]; - bool include_history = 3; -} - -message GetCustomerIntelligenceFactResponse { - CustomerIntelligenceFact fact = 1 [(buf.validate.field).required = true]; -} - -message ReviewCustomerIntelligenceFactRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string fact_id = 2 [(buf.validate.field).string.min_len = 1]; - int64 expected_revision = 3 [(buf.validate.field).int64.gt = 0]; - CustomerIntelligenceReviewDecision decision = 4 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - repeated CustomerIntelligenceEvidenceRef evidence_refs = 5 [(buf.validate.field).repeated.max_items = 64]; - string replacement_safe_summary = 6 [(buf.validate.field).string.max_len = 280]; - string idempotency_key = 7 [(buf.validate.field).string.min_len = 1]; -} - -message ReviewCustomerIntelligenceFactResponse { - CustomerIntelligenceFact fact = 1 [(buf.validate.field).required = true]; - CustomerIntelligenceReceipt receipt = 2 [(buf.validate.field).required = true]; -} - -message ProposeCustomerIntelligenceFactRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string external_fact_id = 2 [(buf.validate.field).string.max_len = 256]; - CustomerIntelligenceSubjectKind subject_kind = 3 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string subject_ref = 4 [(buf.validate.field).string = { - min_len: 1 - max_len: 256 - }]; - string product_area = 5 [(buf.validate.field).string = { - min_len: 1 - max_len: 80 - }]; - string journey = 6 [(buf.validate.field).string = { - min_len: 1 - max_len: 80 - }]; - string predicate = 7 [(buf.validate.field).string = { - min_len: 1 - max_len: 120 - }]; - string safe_summary = 8 [(buf.validate.field).string = { - min_len: 1 - max_len: 280 - }]; - CustomerIntelligenceAuthority authority = 9 [(buf.validate.field).enum = { - defined_only: true - in: [ - 1, - 4 - ] - }]; - int32 confidence_micros = 10 [(buf.validate.field).int32 = { - gte: 0 - lte: 1000000 - }]; - repeated CustomerIntelligenceEvidenceRef evidence_refs = 11 [(buf.validate.field).repeated = { - min_items: 1 - max_items: 64 - }]; - CustomerIntelligenceProducerKind producer_kind = 12 [(buf.validate.field).enum = { - defined_only: true - in: [ - 1, - 2 - ] - }]; - string producer_ref = 13 [(buf.validate.field).string.min_len = 1]; - string model_id = 14 [(buf.validate.field).string.max_len = 160]; - string run_id = 15 [(buf.validate.field).string.max_len = 256]; - string policy_version = 16 [(buf.validate.field).string.min_len = 1]; - string lineage_id = 17 [(buf.validate.field).string.min_len = 1]; - string retention_class = 18 [(buf.validate.field).string.min_len = 1]; - google.protobuf.Timestamp expires_at = 19; - string idempotency_key = 20 [(buf.validate.field).string.min_len = 1]; -} - -message ProposeCustomerIntelligenceFactResponse { - CustomerIntelligenceFact fact = 1 [(buf.validate.field).required = true]; - CustomerIntelligenceReceipt receipt = 2 [(buf.validate.field).required = true]; -} - -message RespondToCustomerFactConfirmationRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string confirmation_intent_id = 2 [(buf.validate.field).string.min_len = 1]; - CustomerFactConfirmationResponse response = 3 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string idempotency_key = 4 [(buf.validate.field).string.min_len = 1]; -} - -message RespondToCustomerFactConfirmationResponse { - CustomerIntelligenceReceipt receipt = 1 [(buf.validate.field).required = true]; -} - -message AggregateCustomerIntelligencePatternsRequest { - string product_area = 1 [(buf.validate.field).string.max_len = 80]; - string journey = 2 [(buf.validate.field).string.max_len = 80]; - repeated CustomerIntelligenceAuthority authorities = 3 [(buf.validate.field).repeated.max_items = 6]; - repeated CustomerIntelligenceLifecycleState lifecycle_states = 4 [(buf.validate.field).repeated.max_items = 6]; - google.protobuf.Timestamp created_after = 5; - int32 minimum_organization_count = 6 [(buf.validate.field).int32.gte = 5]; -} - -message CustomerIntelligencePattern { - string product_area = 1; - string journey = 2; - string predicate = 3; - int64 organization_count = 4 [(buf.validate.field).int64.gte = 5]; - int64 fact_count = 5 [(buf.validate.field).int64.gte = 5]; - int32 average_confidence_micros = 6 [(buf.validate.field).int32 = { - gte: 0 - lte: 1000000 - }]; -} - -message AggregateCustomerIntelligencePatternsResponse { - repeated CustomerIntelligencePattern patterns = 1; -} - -message ListOperatingCorrectionsRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - OperatingCorrectionReviewState review_state = 2 [(buf.validate.field).enum.defined_only = true]; - int32 limit = 3 [(buf.validate.field).int32 = { - gte: 0 - lte: 200 - }]; -} - -message ListOperatingCorrectionsResponse { - repeated OperatingCorrectionCandidate corrections = 1; -} - -message ReviewOperatingCorrectionRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string correction_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - OperatingCorrectionReviewState decision = 3 [(buf.validate.field).enum = { - defined_only: true - in: [ - 2, - 3 - ] - }]; - repeated RelatedResource evidence_refs = 4 [(buf.validate.field).repeated = { - min_items: 1 - max_items: 64 - }]; - string idempotency_key = 5 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; -} - -message ReviewOperatingCorrectionResponse { - OperatingCorrectionCandidate correction = 1 [(buf.validate.field).required = true]; -} - -message ListWorkspaceMemoriesRequest { - // Unspecified preserves the approved-memory listing. - memory.v1.MemoryReviewStatus review_status = 4; - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - int32 limit = 2 [(buf.validate.field).int32 = { - gte: 0 - lte: 100 - }]; - int32 offset = 3 [(buf.validate.field).int32.gte = 0]; -} - -message ListWorkspaceMemoriesResponse { - repeated WorkspaceMemory memories = 1; - int32 total = 2 [(buf.validate.field).int32.gte = 0]; - bool has_more = 3; -} - -// WorkspaceMemory is the customer-safe projection of an owner record. It -// deliberately excludes embeddings, internal actor ids, and provenance refs. -message WorkspaceMemory { - memory.v1.MemoryReviewStatus review_status = 9; - string id = 1 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - memory.v1.Scope scope = 2; - string content = 3 [(common.v1.classification) = DATA_CLASSIFICATION_CONTENT]; - string type = 4; - repeated string tags = 5 [ - (buf.validate.field).repeated.max_items = 64, - (common.v1.classification) = DATA_CLASSIFICATION_CONTENT - ]; - int64 revision = 6 [(buf.validate.field).int64.gte = 1]; - google.protobuf.Timestamp created_at = 7; - google.protobuf.Timestamp updated_at = 8; -} - -message CorrectWorkspaceMemoryRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string memory_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - int64 expected_revision = 3 [(buf.validate.field).int64.gte = 1]; - string content = 4 [ - (buf.validate.field).string = { - min_len: 1 - max_len: 20000 - }, - (common.v1.classification) = DATA_CLASSIFICATION_CONTENT - ]; - repeated string tags = 5 [ - (buf.validate.field).repeated.max_items = 64, - (common.v1.classification) = DATA_CLASSIFICATION_CONTENT - ]; - string idempotency_key = 6 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; -} - -message CorrectWorkspaceMemoryResponse { - WorkspaceMemory memory = 1 [(buf.validate.field).required = true]; -} - -// Review changes only proposal status; the memory owner preserves content. -message ReviewWorkspaceMemoryRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string memory_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - int64 expected_revision = 3 [(buf.validate.field).int64.gte = 1]; - string idempotency_key = 4 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - // Only APPROVED and REJECTED are valid review decisions. - memory.v1.MemoryReviewStatus review_status = 5 [(buf.validate.field).enum = { - in: [ - 1, - 3 - ] - }]; -} - -message ReviewWorkspaceMemoryResponse { - WorkspaceMemory memory = 1 [(buf.validate.field).required = true]; -} - -message ForgetWorkspaceMemoryRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string memory_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - int64 expected_revision = 3 [(buf.validate.field).int64.gte = 1]; - string idempotency_key = 4 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; -} - -message ForgetWorkspaceMemoryResponse { - string memory_id = 1 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; -} - -message OperatingHistorySearchFilter { - repeated string record_kinds = 1; - repeated string roles = 2; - repeated string tool_names = 3; - repeated string statuses = 4; - google.protobuf.Timestamp occurred_after = 5; - google.protobuf.Timestamp occurred_before = 6; - repeated string channel_ids = 7; -} - -message SearchOperatingHistoryRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string search_query = 2 [ - (buf.validate.field).string = { - min_len: 1 - max_len: 1000 - }, - (common.v1.classification) = DATA_CLASSIFICATION_CONTENT - ]; - OperatingHistorySearchFilter filter = 3; - int32 page_size = 4 [(buf.validate.field).int32 = { - gte: 0 - lte: 25 - }]; - string page_token = 5 [ - (buf.validate.field).string.max_len = 4096, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; -} - -message OperatingHistorySearchResult { - string channel_id = 1; - string channel_title = 2; - string source_kind = 3; - string source_id = 4; - string role = 5; - string tool_name = 6; - string status = 7; - google.protobuf.Timestamp occurred_at = 8; - string excerpt = 9; - double score = 10; - string context_cursor = 11; - RelatedResource source_ref = 12; -} - -message SearchOperatingHistoryResponse { - repeated OperatingHistorySearchResult results = 1; - string next_page_token = 2; -} - -message GetOperatingHistoryContextRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string context_cursor = 2 [ - (buf.validate.field).string = { - min_len: 1 - max_len: 4096 - }, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - int32 before_count = 3 [(buf.validate.field).int32 = { - gte: 0 - lte: 20 - }]; - int32 after_count = 4 [(buf.validate.field).int32 = { - gte: 0 - lte: 20 - }]; -} - -message OperatingHistoryContextRecord { - string channel_id = 1; - string source_kind = 2; - string source_id = 3; - string role = 4; - string tool_name = 5; - string status = 6; - string body = 7; - google.protobuf.Timestamp occurred_at = 8; - RelatedResource source_ref = 9; -} - -message GetOperatingHistoryContextResponse { - string channel_id = 1; - string channel_title = 2; - repeated OperatingHistoryContextRecord records = 3; -} - -// OperatingCapabilityContract is the bounded, provider-neutral capability -// envelope attached to a durable Platform worker dispatch. It describes -// ownership and safe capability names; it never carries prompts, tool -// arguments, model output, credentials, or live Maestro session state. -message OperatingCapabilityContract { - string schema_version = 1; - repeated string capability_ids = 2; - repeated string skill_ids = 3; - repeated string memory_operations = 4; - string execution_owner = 5; - string memory_owner = 6; - string channel_renderer = 7; - bool proposal_only = 8; - bool evidence_backed = 9; - // Server-derived, action-specific Identity authorization. Consumers must - // reject governed effects when this evidence is absent, expired, denied, or - // does not match the independent tenant/application/subject boundaries. - IdentityToolAuthorizationEvidence identity_authorization = 10; -} - -message IdentityToolAuthorizationEvidence { - string schema_version = 1 [(buf.validate.field).string.min_len = 1]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 3 [(buf.validate.field).string.min_len = 1]; - string application_id = 4 [(buf.validate.field).string.min_len = 1]; - string subject_id = 5 [(buf.validate.field).string.min_len = 1]; - string actor_chain_digest = 6 [(buf.validate.field).string.min_len = 1]; - string decision_id = 7 [(buf.validate.field).string.min_len = 1]; - string authorization_lineage_id = 8 [(buf.validate.field).string.min_len = 1]; - string policy_id = 9 [(buf.validate.field).string.min_len = 1]; - string policy_version = 10 [(buf.validate.field).string.min_len = 1]; - string policy_digest = 11 [(buf.validate.field).string.min_len = 1]; - string authorization_fingerprint = 12 [(buf.validate.field).string.min_len = 1]; - string capability_digest = 13 [(buf.validate.field).string.min_len = 1]; - string action_digest = 14 [(buf.validate.field).string.min_len = 1]; - string audience = 15 [(buf.validate.field).string.min_len = 1]; - int64 issued_at_ms = 16 [(buf.validate.field).int64.gt = 0]; - int64 expires_at_ms = 17 [(buf.validate.field).int64.gt = 0]; -} - -// OperatingExecutionProfile is selected exclusively by Platform. It is not a -// SubmitOperatingMessage input. Platform validates any conversation preference -// before selecting the model, provider, credential lane, and action authority. -// The worker receives only safe routing -// attribution; credential names and secrets never cross this handoff. -enum OperatingExecutionProfileKind { - OPERATING_EXECUTION_PROFILE_KIND_UNSPECIFIED = 0; - OPERATING_EXECUTION_PROFILE_KIND_DEEP_AGENT = 1; - OPERATING_EXECUTION_PROFILE_KIND_HOSTED_FRONT_THEN_DEEP = 2; -} - -message OperatingExecutionProfile { - OperatingExecutionProfileKind kind = 1 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string profile_id = 2 [(buf.validate.field).string.min_len = 1]; - string front_model = 3 [(buf.validate.field).string.max_len = 256]; - string front_provider = 4 [(buf.validate.field).string.max_len = 128]; -} - -// OperatingHostedFrontDecision is the server-owned semantic boundary between -// an immediate hosted answer and durable private-computer continuation. The -// model returns this through a declared function schema; application code must -// not infer it from user or assistant prose. -enum OperatingHostedFrontDecisionKind { - OPERATING_HOSTED_FRONT_DECISION_KIND_UNSPECIFIED = 0; - OPERATING_HOSTED_FRONT_DECISION_KIND_ANSWER_NOW = 1; - OPERATING_HOSTED_FRONT_DECISION_KIND_ANSWER_AND_CONTINUE = 2; - OPERATING_HOSTED_FRONT_DECISION_KIND_COMPUTER_REQUIRED = 3; - OPERATING_HOSTED_FRONT_DECISION_KIND_CONTINUE_ONLY = 4; -} - -message OperatingHostedFrontDecision { - OperatingHostedFrontDecisionKind kind = 1 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string assistant_body = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 4096 - }]; -} - -// OperatingInitialActionResult is the safe, typed join between the hosted -// front action and the deep agent. The referenced ToolExecution is already -// durable before this message may be attached to a dispatch. Raw arguments, -// raw output, credentials, and provider responses are forbidden here. -message OperatingInitialActionResult { - string execution_id = 1 [(buf.validate.field).string.min_len = 1]; - string call_id = 2 [(buf.validate.field).string.min_len = 1]; - string tool_name = 3 [(buf.validate.field).string.min_len = 1]; - bool read_only = 4; - toolexecution.v1.ToolExecutionState state = 5 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string receipt_id = 6 [(buf.validate.field).string.min_len = 1]; - string safe_summary = 7 [(buf.validate.field).string.max_len = 4096]; - google.protobuf.Struct safe_output = 8; - repeated RelatedResource evidence_refs = 9 [(buf.validate.field).repeated.max_items = 32]; - string thread_id = 10 [(buf.validate.field).string.min_len = 1]; - string turn_id = 11 [(buf.validate.field).string.min_len = 1]; - int64 authority_revision = 12 [(buf.validate.field).int64.gt = 0]; - google.protobuf.Timestamp accepted_at = 13 [(buf.validate.field).required = true]; - // The first user-visible delta is deterministic receipt-grounded text. It - // is persisted in the same dispatch as the admitted action so the deep - // runtime cannot race ahead with ungrounded prose. - string assistant_delta = 14 [(buf.validate.field).string = { - min_len: 1 - max_len: 4096 - }]; -} - -// Exact server-selected provider candidate authorized for one managed -// inference turn. Credential names are non-secret references; secret material -// remains in the managed provider owner. -message OperatingManagedInferenceProviderCandidate { - string provider = 1 [(buf.validate.field).string.min_len = 1]; - string environment = 2 [(buf.validate.field).string.min_len = 1]; - string credential_name = 3 [(buf.validate.field).string.max_len = 512]; - string team_id = 4 [(buf.validate.field).string.max_len = 512]; - string model = 5 [(buf.validate.field).string.min_len = 1]; -} - -enum OperatingManagedInferenceRouting { - OPERATING_MANAGED_INFERENCE_ROUTING_UNSPECIFIED = 0; - OPERATING_MANAGED_INFERENCE_ROUTING_ORDERED = 1; -} - -enum OperatingManagedInferenceBudgetOrigin { - OPERATING_MANAGED_INFERENCE_BUDGET_ORIGIN_UNSPECIFIED = 0; - OPERATING_MANAGED_INFERENCE_BUDGET_ORIGIN_EXPLICIT = 1; - OPERATING_MANAGED_INFERENCE_BUDGET_ORIGIN_ROUTE_POLICY = 2; - OPERATING_MANAGED_INFERENCE_BUDGET_ORIGIN_PROVIDER_DEFAULT = 3; -} - -message OperatingManagedInferenceOutputTokenBudget { - optional uint64 value = 1; - OperatingManagedInferenceBudgetOrigin origin = 2 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string origin_reference = 3 [(buf.validate.field).string.max_len = 512]; -} - -// Durable, content-free authority for Runner Host to sign a per-turn managed -// inference authorization. Platform selects this before work creation and the -// worker replays it verbatim; clients never choose or widen these fields. -message OperatingManagedInferenceScope { - string endpoint = 1 [(buf.validate.field).string.const = "responses"]; - string model = 2 [(buf.validate.field).string.min_len = 1]; - repeated OperatingManagedInferenceProviderCandidate provider_candidates = 3 [(buf.validate.field).repeated = { - min_items: 1 - max_items: 16 - }]; - OperatingManagedInferenceRouting routing = 4 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - OperatingManagedInferenceOutputTokenBudget output_token_budget = 5 [(buf.validate.field).required = true]; -} - -// OperatingRunDispatch is the durable worker handoff for one submitted -// operating turn. It carries stable row identities so workers can reload the -// canonical Console message from Postgres. Authorized attachment mounts are -// materialized here as stable VFS identities so the queued worker can hydrate -// the same versions without copying attachment contents into work metadata. -message OperatingRunDispatch { - string runtime_run_id = 1 [(buf.validate.field).string.min_len = 1]; - string work_id = 2 [(buf.validate.field).string.min_len = 1]; - string operation_id = 3 [(buf.validate.field).string.min_len = 1]; - string organization_id = 4 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 5 [(buf.validate.field).string.min_len = 1]; - string channel_id = 6 [(buf.validate.field).string.min_len = 1]; - string submitted_message_id = 7 [(buf.validate.field).string.min_len = 1]; - string idempotency_key = 8 [(buf.validate.field).string.min_len = 1]; - string traceparent = 9; - google.protobuf.Timestamp enqueued_at = 10 [(buf.validate.field).required = true]; - repeated toolexecution.v1.ToolExecutionAttachmentMount attachment_mounts = 11; - // Optional additive metadata for Platform-owned dispatch consumers. - OperatingCapabilityContract capability_contract = 12; - OperatingThreadResponse response = 13; - OperatingExecutionProfile execution_profile = 14; - OperatingInitialActionResult initial_action = 15; - // Present when the hosted model produced a replay-stable preliminary answer - // before this durable deep-runtime dispatch was created. - OperatingHostedFrontDecision hosted_front_decision = 16; - // Immutable release/execution identity propagated across the durable queue - // and hosted runtime. It is deployment-owned, not client-provided. - string causal_receipt_id = 17 [(buf.validate.field).string.max_len = 128]; - // Exact server-selected Platform tool that must settle before the deep - // runtime may consume initial_action. Empty preserves the read-only hosted - // front contract. Mutating results are valid only when this value and the - // persisted turn authority match initial_action exactly. - string required_initial_tool = 18 [(buf.validate.field).string.max_len = 256]; - int64 required_initial_tool_authority_revision = 19 [(buf.validate.field).int64.gte = 0]; - // Optional durable task-plan authority. Both fields are set together; an - // absent approved plan is represented by zero plus an empty hash. - int64 approved_plan_version = 20 [(buf.validate.field).int64.gte = 0]; - string approved_plan_content_hash = 21 [(buf.validate.field).string.max_len = 128]; - // Canonical, non-secret required call persisted before Platform invokes the - // remote ToolExecution owner. Short-lived staff grants are minted only by - // the claiming worker and never enter this dispatch. - OperatingRequiredInitialToolIntent required_initial_tool_intent = 22; - // Platform-accepted visibility for internal installed skill content. This - // is persisted for exact replay and grants no staff, tool, or approval - // authority. - bool internal_skill_access_allowed = 23; - // Exact Platform-selected managed LLM authority. Hosted Maestro dispatches - // fail closed when this is absent or malformed; Runner Host adds the - // ephemeral per-turn signature using its existing signing boundary. - OperatingManagedInferenceScope managed_inference = 24; - // The canonical customer Job identity. Operating chat admits WorkKind - // OBJECTIVE rows, so this equals work_id and survives every runtime attempt. - // Empty only on legacy dispatches created before this additive field. - // Field 25 leaves field 24 reserved for managed inference authority. - string objective_id = 25 [(buf.validate.field).string.max_len = 256]; - // Exact Platform-admitted coding requirements, carried unchanged on replay. - CodingAcceptanceContract coding_acceptance = 26; - // Server-derived task coordinates, independent of whether a computer is allocated. - OperatingTaskEnvironmentBinding task_environment = 27; - // Authenticated actor whose tenant-scoped task binding admitted this dispatch. - string actor_id = 28 [(buf.validate.field).string.min_len = 1]; - // Provider-neutral object identity retained from the admitted surface. It - // groups retries and follow-ups by durable provider object without granting - // any tool or connector authority. - agentruntime.v1.RuntimeWorkEnvelope work_envelope = 29; - // Bounded, edge-authenticated provider context retained with the dispatch - // and sent to Maestro on every replay. It contains provenance-bearing - // surface snapshots, never provider credentials. - google.protobuf.Struct surface_context = 30; -} - -// Immutable task identity admitted from authenticated actor and tenant/channel scope. -message OperatingTaskEnvironmentBinding { - string actor_id = 1 [(buf.validate.field).string.min_len = 1]; - string task_id = 2 [(buf.validate.field).string.min_len = 1]; - string home_key = 3 [(buf.validate.field).string.min_len = 1]; - string workspace_dir = 4 [(buf.validate.field).string.min_len = 1]; - // Workspace/project policy accepted once for this turn. - int32 retention_days = 5 [(buf.validate.field).int32 = { - in: [ - 0, - 7, - 30 - ] - }]; - uint64 policy_revision = 6 [(buf.validate.field).uint64.gte = 1]; - toolexecution.v1.ToolExecutionProjectSource project_source = 7; - // Authenticated operating channel that admitted this task binding. - string channel_id = 8 [(buf.validate.field).string.min_len = 1]; - int32 retention_hours = 9 [(buf.validate.field).int32 = { - in: [ - 0, - 8, - 168, - 720 - ] - }]; - toolexecution.v1.ToolExecutionWorkspaceRecipe workspace_recipe = 10; -} - -message OperatingRequiredInitialToolIntent { - string call_id = 1 [ - (buf.validate.field).string.min_len = 1, - (buf.validate.field).string.max_len = 256 - ]; - string tool_name = 2 [(buf.validate.field).string.const = "computer.write_file"]; - google.protobuf.Struct arguments = 3 [(buf.validate.field).required = true]; - string actor_id = 4 [ - (buf.validate.field).string.min_len = 1, - (buf.validate.field).string.max_len = 256 - ]; - string tool_idempotency_key = 5 [ - (buf.validate.field).string.min_len = 1, - (buf.validate.field).string.max_len = 512 - ]; - string sandbox_session_id = 6 [ - (buf.validate.field).string.min_len = 1, - (buf.validate.field).string.max_len = 256 - ]; - string computer_home_key = 7 [(buf.validate.field).string.max_len = 256]; - string computer_workspace_dir = 8 [(buf.validate.field).string.max_len = 512]; - string capability = 9 [ - (buf.validate.field).string.min_len = 1, - (buf.validate.field).string.max_len = 256 - ]; - string operation = 10 [ - (buf.validate.field).string.min_len = 1, - (buf.validate.field).string.max_len = 256 - ]; - common.v1.RiskLevel risk_level = 11 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - // Canonical non-secret ToolExecution metadata. Raw grant claims, - // signatures, and server-owned verified authority are never persisted. - map metadata = 12; -} - -message ResolveOperatingReceiptActionRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string receipt_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - OperatingReceiptAction action = 3 [(buf.validate.field).required = true]; - string idempotency_key = 4 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; -} - -message ResolveOperatingReceiptActionResponse { - OperatingReceipt receipt = 1; - repeated OperatingCapabilityState capabilities = 2; -} - -message GetOperatingReceiptRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string receipt_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string channel_id = 3 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - bool include_coding_output_content = 4; -} - -// Read-only projection of the decision committed by Platform's fenced coding -// acceptance owner. Absence is not acceptance. Artifact bytes remain separately -// owned by VFS and must be read and verified by consumers. -message OperatingCodingAcceptance { - string organization_id = 1; - string workspace_id = 2; - string actor_id = 3; - string work_id = 4; - string runtime_run_id = 5; - CodingAcceptanceContract contract = 6; - bool accepted = 7; - string contract_digest = 8; - string submission_digest = 9; - repeated string reasons = 10; - string revision = 11; - repeated OperatingCodingOutput outputs = 12; -} - -message OperatingCodingOutput { - string path = 1; - string object_id = 2; - string version_id = 3; - string sha256 = 4; - uint64 size_bytes = 5; - // Read from VFS only for an explicit originating-actor receipt read. Never persisted here. - bytes content = 6; -} - -message GetOperatingReceiptResponse { - OperatingReceipt receipt = 1; -} - -enum ComputerMissionAuthorityMode { - COMPUTER_MISSION_AUTHORITY_MODE_UNSPECIFIED = 0; - COMPUTER_MISSION_AUTHORITY_MODE_SUPERVISED = 1; - COMPUTER_MISSION_AUTHORITY_MODE_BOUNDED_AUTONOMY = 2; - COMPUTER_MISSION_AUTHORITY_MODE_FULL_AUTONOMY = 3; -} - -enum ComputerMissionState { - COMPUTER_MISSION_STATE_UNSPECIFIED = 0; - COMPUTER_MISSION_STATE_QUEUED = 1; - COMPUTER_MISSION_STATE_RUNNING = 2; - COMPUTER_MISSION_STATE_WAITING_FOR_USER = 3; - COMPUTER_MISSION_STATE_CANCELLATION_REQUESTED = 4; - COMPUTER_MISSION_STATE_SUCCEEDED = 5; - COMPUTER_MISSION_STATE_FAILED = 6; - COMPUTER_MISSION_STATE_BUDGET_EXHAUSTED = 7; - COMPUTER_MISSION_STATE_CANCELLED = 8; - COMPUTER_MISSION_STATE_CLEANUP_UNCERTAIN = 9; - COMPUTER_MISSION_STATE_NOT_ROUTED = 10; - COMPUTER_MISSION_STATE_PLANNING = 11; - COMPUTER_MISSION_STATE_VERIFYING = 12; - COMPUTER_MISSION_STATE_SLEEPING = 13; - COMPUTER_MISSION_STATE_WAITING_FOR_APPROVAL = 14; - COMPUTER_MISSION_STATE_WAITING_FOR_EXTERNAL_EVENT = 15; - COMPUTER_MISSION_STATE_PAUSED = 16; -} - -enum ComputerMissionCanaryScenarioKind { - COMPUTER_MISSION_CANARY_SCENARIO_KIND_UNSPECIFIED = 0; - COMPUTER_MISSION_CANARY_SCENARIO_KIND_CI_REPAIR = 1; - COMPUTER_MISSION_CANARY_SCENARIO_KIND_REVIEW_OPERATIONS = 2; - COMPUTER_MISSION_CANARY_SCENARIO_KIND_RUNNER_RECOVERY = 3; - COMPUTER_MISSION_CANARY_SCENARIO_KIND_APPROVAL_CONTINUATION = 4; - COMPUTER_MISSION_CANARY_SCENARIO_KIND_AMBIGUOUS_TOOL_RESPONSE = 5; - COMPUTER_MISSION_CANARY_SCENARIO_KIND_BUDGET_STOP = 6; -} - -enum ComputerMissionEffectState { - COMPUTER_MISSION_EFFECT_STATE_UNSPECIFIED = 0; - COMPUTER_MISSION_EFFECT_STATE_INTENT_RECORDED = 1; - COMPUTER_MISSION_EFFECT_STATE_FORWARD_ACCEPTED = 2; - COMPUTER_MISSION_EFFECT_STATE_FORWARD_VERIFIED = 3; - COMPUTER_MISSION_EFFECT_STATE_ROLLBACK_RUNNING = 4; - COMPUTER_MISSION_EFFECT_STATE_ROLLED_BACK = 5; - COMPUTER_MISSION_EFFECT_STATE_CLEANUP_VERIFIED = 6; - COMPUTER_MISSION_EFFECT_STATE_CLEANUP_UNCERTAIN = 7; -} - -enum ComputerMissionCanaryRunState { - COMPUTER_MISSION_CANARY_RUN_STATE_UNSPECIFIED = 0; - COMPUTER_MISSION_CANARY_RUN_STATE_QUEUED = 1; - COMPUTER_MISSION_CANARY_RUN_STATE_RUNNING = 2; - COMPUTER_MISSION_CANARY_RUN_STATE_WAITING_FOR_USER = 3; - COMPUTER_MISSION_CANARY_RUN_STATE_CLEANUP_RUNNING = 4; - COMPUTER_MISSION_CANARY_RUN_STATE_EVALUATION_PENDING = 5; - COMPUTER_MISSION_CANARY_RUN_STATE_PASSED = 6; - COMPUTER_MISSION_CANARY_RUN_STATE_FAILED = 7; - COMPUTER_MISSION_CANARY_RUN_STATE_UNSAFE = 8; - COMPUTER_MISSION_CANARY_RUN_STATE_CLEANUP_UNCERTAIN = 9; - COMPUTER_MISSION_CANARY_RUN_STATE_CANCELLED = 10; -} - -enum ComputerMissionCanaryScoreDimension { - COMPUTER_MISSION_CANARY_SCORE_DIMENSION_UNSPECIFIED = 0; - COMPUTER_MISSION_CANARY_SCORE_DIMENSION_OUTCOME_CORRECTNESS = 1; - COMPUTER_MISSION_CANARY_SCORE_DIMENSION_HUMAN_INTERVENTION_EFFICIENCY = 2; - COMPUTER_MISSION_CANARY_SCORE_DIMENSION_SCOPE_ADHERENCE = 3; - COMPUTER_MISSION_CANARY_SCORE_DIMENSION_DUPLICATE_EFFECT_AVOIDANCE = 4; - COMPUTER_MISSION_CANARY_SCORE_DIMENSION_RECOVERY_SUCCESS = 5; - COMPUTER_MISSION_CANARY_SCORE_DIMENSION_BUDGET_EFFICIENCY = 6; - COMPUTER_MISSION_CANARY_SCORE_DIMENSION_EVIDENCE_COMPLETENESS = 7; - COMPUTER_MISSION_CANARY_SCORE_DIMENSION_TIME_TO_VERIFIED_COMPLETION = 8; -} - -enum ComputerMissionCanaryRecommendation { - COMPUTER_MISSION_CANARY_RECOMMENDATION_UNSPECIFIED = 0; - COMPUTER_MISSION_CANARY_RECOMMENDATION_HOLD = 1; - COMPUTER_MISSION_CANARY_RECOMMENDATION_PROMOTE = 2; - COMPUTER_MISSION_CANARY_RECOMMENDATION_ROLL_BACK = 3; -} - -enum ComputerMissionCanaryOperatorActionKind { - COMPUTER_MISSION_CANARY_OPERATOR_ACTION_KIND_UNSPECIFIED = 0; - COMPUTER_MISSION_CANARY_OPERATOR_ACTION_KIND_PAUSE = 1; - COMPUTER_MISSION_CANARY_OPERATOR_ACTION_KIND_CANCEL = 2; - COMPUTER_MISSION_CANARY_OPERATOR_ACTION_KIND_NARROW_SCOPE = 3; - COMPUTER_MISSION_CANARY_OPERATOR_ACTION_KIND_EXTEND_GRANT = 4; -} - -message ComputerMissionEvidenceGate { - string gate_id = 1 [(buf.validate.field).string.min_len = 1]; - string predicate = 2 [(buf.validate.field).string.min_len = 1]; - bool hard_safety_gate = 3; -} - -enum ComputerMissionRollbackArgumentSource { - COMPUTER_MISSION_ROLLBACK_ARGUMENT_SOURCE_UNSPECIFIED = 0; - COMPUTER_MISSION_ROLLBACK_ARGUMENT_SOURCE_PRE_ACTION_STATE = 1; - COMPUTER_MISSION_ROLLBACK_ARGUMENT_SOURCE_FORWARD_RECEIPT = 2; -} - -message ComputerMissionRollbackArgumentBinding { - string argument = 1 [(buf.validate.field).string.min_len = 1]; - ComputerMissionRollbackArgumentSource source = 2 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string source_path = 3 [(buf.validate.field).string.min_len = 1]; -} - -message ComputerMissionCompensatingAction { - string forward_capability = 1 [(buf.validate.field).string.min_len = 1]; - string forward_resource_id = 2 [(buf.validate.field).string.min_len = 1]; - string forward_arguments_digest = 3 [(buf.validate.field).string.min_len = 1]; - repeated string forward_preconditions = 4; - string rollback_capability = 5 [(buf.validate.field).string.min_len = 1]; - google.protobuf.Struct rollback_arguments = 6 [(buf.validate.field).required = true]; - string rollback_verification_predicate = 7 [(buf.validate.field).string.min_len = 1]; - bool rollback_safe_to_retry = 8; - uint32 max_rollback_attempts = 9 [(buf.validate.field).uint32.gt = 0]; - uint64 rollback_deadline_seconds = 10 [(buf.validate.field).uint64.gt = 0]; - string forward_evidence_predicate = 11 [(buf.validate.field).string.min_len = 1]; - string cleanup_evidence_predicate = 12 [(buf.validate.field).string.min_len = 1]; - string rollback_resource_id = 13 [(buf.validate.field).string.min_len = 1]; - repeated ComputerMissionRollbackArgumentBinding rollback_argument_bindings = 14 [(buf.validate.field).repeated.min_items = 1]; - bool explicit_retry_denial = 15; -} - -message ComputerMissionCanaryThreshold { - ComputerMissionCanaryScoreDimension dimension = 1 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - double minimum_score = 2 [(buf.validate.field).double = { - gte: 0 - lte: 100 - }]; -} - -message ComputerMissionCanaryDefinition { - string definition_id = 1 [(buf.validate.field).string.min_len = 1]; - uint32 version = 2 [(buf.validate.field).uint32.gt = 0]; - ComputerMissionCanaryScenarioKind scenario_kind = 3 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string objective = 4 [(buf.validate.field).string.min_len = 1]; - repeated string enabled_environments = 5 [(buf.validate.field).repeated.min_items = 1]; - repeated string fixture_resource_ids = 6 [(buf.validate.field).repeated.min_items = 1]; - repeated string required_canary_tags = 7 [(buf.validate.field).repeated.min_items = 1]; - repeated string required_capabilities = 8 [(buf.validate.field).repeated.min_items = 1]; - string runner_profile = 9 [(buf.validate.field).string.min_len = 1]; - ComputerMissionAuthorityMode authority_mode = 10 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - uint64 maximum_grant_duration_seconds = 11 [(buf.validate.field).uint64.gt = 0]; - ComputerMissionBudget budget = 12 [(buf.validate.field).required = true]; - repeated ComputerMissionEvidenceGate required_evidence_gates = 13 [(buf.validate.field).repeated.min_items = 1]; - repeated string expected_forward_effects = 14 [(buf.validate.field).repeated.min_items = 1]; - repeated ComputerMissionCompensatingAction required_compensating_effects = 15 [(buf.validate.field).repeated.min_items = 1]; - repeated ComputerMissionCanaryThreshold thresholds = 16 [(buf.validate.field).repeated.min_items = 1]; - repeated ComputerMissionEvidenceGate hard_safety_gates = 17 [(buf.validate.field).repeated.min_items = 1]; - string planner_version = 18 [(buf.validate.field).string.min_len = 1]; - string runtime_version = 19 [(buf.validate.field).string.min_len = 1]; - string tool_contract_version = 20 [(buf.validate.field).string.min_len = 1]; -} - -message ComputerMissionCanaryOperatorAction { - string action_id = 1 [(buf.validate.field).string.min_len = 1]; - ComputerMissionCanaryOperatorActionKind kind = 2 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string actor_id = 3 [(buf.validate.field).string.min_len = 1]; - string reason = 4 [(buf.validate.field).string.min_len = 1]; - google.protobuf.Timestamp occurred_at = 5 [(buf.validate.field).required = true]; - ComputerMissionScope scope_before = 6; - ComputerMissionScope scope_after = 7; - ComputerMissionBudget budget_before = 8; - ComputerMissionBudget budget_after = 9; - google.protobuf.Timestamp grant_expires_at_before = 10; - google.protobuf.Timestamp grant_expires_at_after = 11; - repeated RelatedResource evidence_refs = 12; -} - -message ComputerMissionBudget { - uint32 max_steps = 1 [(buf.validate.field).uint32.gt = 0]; - uint64 wall_clock_budget_seconds = 2 [(buf.validate.field).uint64.gt = 0]; - uint64 token_budget = 3 [(buf.validate.field).uint64.gt = 0]; - uint32 max_tool_calls = 4 [(buf.validate.field).uint32.gt = 0]; - uint64 max_cost_micros = 5 [(buf.validate.field).uint64.gt = 0]; -} - -message ComputerMissionCapability { - string name = 1 [(buf.validate.field).string.pattern = "^apex\\.[a-z0-9_.-]+$"]; - google.protobuf.Struct input_schema = 2 [(buf.validate.field).required = true]; - string observer_name = 3 [(buf.validate.field).string.pattern = "^apex\\.[a-z0-9_.-]+$"]; - string schema_digest_sha256 = 4 [(buf.validate.field).string.pattern = "^[0-9a-f]{64}$"]; - // Exact raw FastMCP catalog name. Platform authority remains namespaced by - // name; dispatch_name is never planner-selectable or derived by stripping. - string dispatch_name = 5 [(buf.validate.field).string.pattern = "^[a-z0-9_.-]+$"]; -} - -message ComputerMissionApexRunnerBinding { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string runner_session_id = 3 [(buf.validate.field).string.min_len = 1]; - string sandbox_id = 4 [(buf.validate.field).string.min_len = 1]; - string initial_checkpoint_id = 5 [(buf.validate.field).string.min_len = 1]; - string initial_snapshot_id = 6 [(buf.validate.field).string.min_len = 1]; - string workload_digest = 7 [(buf.validate.field).string.pattern = "^sha256:[0-9a-f]{64}$"]; - string provider = 8 [(buf.validate.field).string.min_len = 1]; - string provider_mode = 9 [(buf.validate.field).string.const = "apply"]; - string reservation_id = 10 [(buf.validate.field).string.min_len = 1]; - string instruction_artifact_ref = 11 [(buf.validate.field).string.min_len = 1]; - string instruction_digest_sha256 = 12 [(buf.validate.field).string.pattern = "^[0-9a-f]{64}$"]; - uint64 instruction_byte_count = 13 [(buf.validate.field).uint64 = { - gte: 1 - lte: 1048576 - }]; -} - -message ComputerMissionScope { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - repeated string resource_ids = 3 [(buf.validate.field).repeated.min_items = 1]; - repeated string capabilities = 4 [(buf.validate.field).repeated.min_items = 1]; - repeated ComputerMissionCapability capability_manifests = 5; - ComputerMissionApexRunnerBinding apex_runner_binding = 6; -} - -message ComputerMissionAuthorityGrant { - ComputerMissionAuthorityMode mode = 1 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string granted_by = 2 [(buf.validate.field).string.min_len = 1]; - google.protobuf.Timestamp granted_at = 3 [(buf.validate.field).required = true]; - string confirmation_version = 4 [(buf.validate.field).string.const = "dex.mission_authority_confirmation.v1"]; -} - -enum ComputerMissionDecisionRoute { - COMPUTER_MISSION_DECISION_ROUTE_UNSPECIFIED = 0; - COMPUTER_MISSION_DECISION_ROUTE_NO_ROUTE = 1; - COMPUTER_MISSION_DECISION_ROUTE_SINGLE_AGENT = 2; - COMPUTER_MISSION_DECISION_ROUTE_TOURNAMENT = 3; -} - -// ComputerMissionDecision binds mission creation to the governed routing -// decision that selected an execution candidate or deliberately selected no -// route. decision_digest_sha256 is the digest of the owner-produced decision -// record referenced by decision_ref. -message ComputerMissionDecision { - string policy_version = 1 [(buf.validate.field).string.min_len = 1]; - ComputerMissionDecisionRoute route = 2 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string selected_candidate_id = 3; - string decision_ref = 4 [(buf.validate.field).string.min_len = 1]; - string decision_digest_sha256 = 5 [(buf.validate.field).string.pattern = "^[0-9a-f]{64}$"]; -} - -message ComputerMissionContract { - option (buf.validate.message).cel = { - id: "console.v1.computer_mission.required_evidence" - message: "required_evidence must be non-empty unless an APEX runner binding is present" - expression: "size(this.required_evidence) > 0 || has(this.scope.apex_runner_binding)" - }; - - string goal = 1 [(buf.validate.field).string.min_len = 1]; - ComputerMissionScope scope = 2 [(buf.validate.field).required = true]; - ComputerMissionAuthorityGrant authority = 3 [(buf.validate.field).required = true]; - ComputerMissionBudget budget = 4 [(buf.validate.field).required = true]; - repeated string required_evidence = 5; - string runner_profile = 6 [(buf.validate.field).string.min_len = 1]; - // resume_of_mission_id links a new mission and fresh budget to a failed or - // budget-exhausted predecessor in the same tenant scope. - string resume_of_mission_id = 7; - ComputerMissionDecision decision = 8 [(buf.validate.field).required = true]; -} - -message ComputerMission { - string mission_id = 1 [(buf.validate.field).string.min_len = 1]; - string work_id = 2 [(buf.validate.field).string.min_len = 1]; - ComputerMissionContract contract = 3 [(buf.validate.field).required = true]; - ComputerMissionState state = 4 [(buf.validate.field).enum.defined_only = true]; - uint32 completed_steps = 5; - uint32 completed_tool_calls = 6; - uint64 consumed_tokens = 7; - uint64 consumed_cost_micros = 8; - repeated RelatedResource evidence_refs = 9; - string blocker = 10; - string next_action = 11; - google.protobuf.Timestamp created_at = 12 [(buf.validate.field).required = true]; - google.protobuf.Timestamp updated_at = 13 [(buf.validate.field).required = true]; - string tenant_scope_id = 14 [(buf.validate.field).string.min_len = 1]; - string authority_grant_id = 15 [(buf.validate.field).string.min_len = 1]; - string contract_version = 16 [(buf.validate.field).string.min_len = 1]; - string contract_digest_sha256 = 17 [(buf.validate.field).string.pattern = "^[0-9a-f]{64}$"]; - // Empty until Platform Worker has created the authoritative runtime row. - string runtime_run_id = 18; - // Monotonically increases whenever the mission is queued for new execution. - int64 active_generation = 19; - ComputerMissionLongHorizonBudgetState long_horizon_budget = 20; -} - -message ComputerMissionLongHorizonBudgetState { - google.protobuf.Timestamp deadline_at = 1 [(buf.validate.field).required = true]; - google.protobuf.Timestamp authority_expires_at = 2; - uint64 max_active_runner_seconds = 3; - uint64 consumed_active_runner_seconds = 4; - uint32 max_recoveries = 5; - uint32 consumed_recoveries = 6; - uint32 max_consecutive_failures = 7; - uint32 consecutive_failures = 8; -} - -message SubmitComputerMissionRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string channel_id = 3 [(buf.validate.field).string.min_len = 1]; - ComputerMissionContract contract = 4 [(buf.validate.field).required = true]; - string idempotency_key = 5 [(buf.validate.field).string.min_len = 1]; -} - -message SubmitComputerMissionResponse { - ComputerMission mission = 1 [(buf.validate.field).required = true]; - OperatingReceipt receipt = 2 [(buf.validate.field).required = true]; -} - -message GetComputerMissionRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string mission_id = 3 [(buf.validate.field).string.min_len = 1]; -} - -message GetComputerMissionResponse { - ComputerMission mission = 1 [(buf.validate.field).required = true]; - OperatingReceipt receipt = 2 [(buf.validate.field).required = true]; -} - -message CancelComputerMissionRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string mission_id = 3 [(buf.validate.field).string.min_len = 1]; - string reason = 4 [(buf.validate.field).string.min_len = 1]; - string idempotency_key = 5 [(buf.validate.field).string.min_len = 1]; -} - -message CancelComputerMissionResponse { - ComputerMission mission = 1 [(buf.validate.field).required = true]; - OperatingReceipt receipt = 2 [(buf.validate.field).required = true]; -} - -message ContinueComputerMissionRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string mission_id = 3 [(buf.validate.field).string.min_len = 1]; - string answer = 4 [(buf.validate.field).string.min_len = 1]; - string idempotency_key = 5 [(buf.validate.field).string.min_len = 1]; -} - -message ContinueComputerMissionResponse { - ComputerMission mission = 1 [(buf.validate.field).required = true]; - OperatingReceipt receipt = 2 [(buf.validate.field).required = true]; -} - -message PauseComputerMissionRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string mission_id = 3 [(buf.validate.field).string.min_len = 1]; - int64 expected_generation = 4 [(buf.validate.field).int64.gte = 0]; - string reason = 5 [(buf.validate.field).string.min_len = 1]; - string idempotency_key = 6 [(buf.validate.field).string.min_len = 1]; - google.protobuf.Struct condition = 7; - google.protobuf.Timestamp wake_at = 8; -} - -message PauseComputerMissionResponse { - ComputerMission mission = 1 [(buf.validate.field).required = true]; - OperatingReceipt receipt = 2 [(buf.validate.field).required = true]; - string wake_id = 3 [(buf.validate.field).string.min_len = 1]; -} - -message ResumeComputerMissionRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string mission_id = 3 [(buf.validate.field).string.min_len = 1]; - int64 expected_generation = 4 [(buf.validate.field).int64.gte = 0]; - string reason = 5 [(buf.validate.field).string.min_len = 1]; - string idempotency_key = 6 [(buf.validate.field).string.min_len = 1]; - google.protobuf.Struct condition = 7; - google.protobuf.Timestamp wake_at = 8; -} - -message ResumeComputerMissionResponse { - ComputerMission mission = 1 [(buf.validate.field).required = true]; - OperatingReceipt receipt = 2 [(buf.validate.field).required = true]; - string wake_id = 3 [(buf.validate.field).string.min_len = 1]; -} - -message WakeComputerMissionRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string mission_id = 3 [(buf.validate.field).string.min_len = 1]; - int64 expected_generation = 4 [(buf.validate.field).int64.gte = 0]; - string reason = 5 [(buf.validate.field).string.min_len = 1]; - google.protobuf.Struct condition = 6; - string idempotency_key = 7 [(buf.validate.field).string.min_len = 1]; - google.protobuf.Timestamp wake_at = 8; -} - -message WakeComputerMissionResponse { - ComputerMission mission = 1 [(buf.validate.field).required = true]; - OperatingReceipt receipt = 2 [(buf.validate.field).required = true]; - string wake_id = 3 [(buf.validate.field).string.min_len = 1]; -} - -message GuideComputerMissionRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string mission_id = 3 [(buf.validate.field).string.min_len = 1]; - int64 expected_generation = 4 [(buf.validate.field).int64.gte = 0]; - string guidance = 5 [(buf.validate.field).string.min_len = 1]; - google.protobuf.Struct condition = 6; - string idempotency_key = 7 [(buf.validate.field).string.min_len = 1]; - google.protobuf.Timestamp wake_at = 8; -} - -message GuideComputerMissionResponse { - ComputerMission mission = 1 [(buf.validate.field).required = true]; - OperatingReceipt receipt = 2 [(buf.validate.field).required = true]; - string wake_id = 3 [(buf.validate.field).string.min_len = 1]; -} - -message ComputerMissionCanaryRun { - string canary_run_id = 1 [(buf.validate.field).string.min_len = 1]; - string canary_definition_id = 2 [(buf.validate.field).string.min_len = 1]; - string mission_id = 3 [(buf.validate.field).string.min_len = 1]; - ComputerMissionCanaryRunState state = 4 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - ComputerMissionScope scope = 5 [(buf.validate.field).required = true]; - ComputerMissionBudget budget = 6 [(buf.validate.field).required = true]; - google.protobuf.Timestamp grant_expires_at = 7 [(buf.validate.field).required = true]; - ComputerMissionCanaryRecommendation recommendation = 8 [(buf.validate.field).enum.defined_only = true]; -} - -message ComputerMissionCanaryEffect { - string effect_id = 1 [(buf.validate.field).string.min_len = 1]; - ComputerMissionEffectState state = 2 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string capability = 3 [(buf.validate.field).string.min_len = 1]; - string resource_id = 4 [(buf.validate.field).string.min_len = 1]; - repeated RelatedResource evidence_refs = 5; - string forward_execution_id = 6; - string forward_idempotency_key = 7; - string rollback_execution_id = 8; - string rollback_idempotency_key = 9; - string recovery_action = 10; - google.protobuf.Timestamp recorded_at = 11; -} - -message ComputerMissionCanaryDimensionResult { - ComputerMissionCanaryScoreDimension dimension = 1 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - double score = 2 [(buf.validate.field).double = { - gte: 0 - lte: 100 - }]; - uint32 weight = 3; -} - -message ComputerMissionCanaryHardGateResult { - string gate_id = 1 [(buf.validate.field).string.min_len = 1]; - bool passed = 2; -} - -message ComputerMissionCanaryEvaluation { - string evaluation_id = 1 [(buf.validate.field).string.min_len = 1]; - string evaluator_version = 2 [(buf.validate.field).string.min_len = 1]; - ComputerMissionCanaryRecommendation recommendation = 3 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - double aggregate_score = 4 [(buf.validate.field).double = { - gte: 0 - lte: 100 - }]; - repeated RelatedResource evidence_refs = 5; - repeated ComputerMissionCanaryDimensionResult dimensions = 6; - repeated ComputerMissionCanaryHardGateResult hard_gates = 7; - string policy_version = 8; - string planner_version = 9; - string runtime_version = 10; - string tool_contract_version = 11; - string definition_id = 12; - uint32 definition_version = 13; -} - -message ListComputerMissionCanaryDefinitionsRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; -} -message ListComputerMissionCanaryDefinitionsResponse { - repeated ComputerMissionCanaryDefinition definitions = 1; -} -message StartComputerMissionCanaryRunRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string channel_id = 3 [(buf.validate.field).string.min_len = 1]; - string canary_definition_id = 4 [(buf.validate.field).string.min_len = 1]; - string environment = 5 [(buf.validate.field).string.min_len = 1]; - string idempotency_key = 6 [(buf.validate.field).string.min_len = 1]; -} -message StartComputerMissionCanaryRunResponse { - ComputerMissionCanaryRun run = 1 [(buf.validate.field).required = true]; - ComputerMission mission = 2 [(buf.validate.field).required = true]; - OperatingReceipt receipt = 3 [(buf.validate.field).required = true]; -} -message GetComputerMissionCanaryRunRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string canary_run_id = 3 [(buf.validate.field).string.min_len = 1]; -} -message GetComputerMissionCanaryRunResponse { - ComputerMissionCanaryRun run = 1 [(buf.validate.field).required = true]; -} -message ListComputerMissionCanaryRunsRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; -} -message ListComputerMissionCanaryRunsResponse { - repeated ComputerMissionCanaryRun runs = 1; -} -message GetComputerMissionCanaryEvidenceRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string canary_run_id = 3 [(buf.validate.field).string.min_len = 1]; -} -message GetComputerMissionCanaryEvidenceResponse { - repeated ComputerMissionCanaryEffect effects = 1; - ComputerMissionCanaryEvaluation evaluation = 2; - repeated ComputerMissionCanaryOperatorAction operator_actions = 3; - ComputerMissionCanaryDefinition definition = 4; -} -message OperateComputerMissionCanaryRunRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string canary_run_id = 3 [(buf.validate.field).string.min_len = 1]; - ComputerMissionCanaryOperatorActionKind kind = 4 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - ComputerMissionScope narrowed_scope = 5; - ComputerMissionBudget extended_budget = 6; - google.protobuf.Timestamp extended_grant_expires_at = 7; - string reason = 8 [(buf.validate.field).string.min_len = 1]; - string idempotency_key = 9 [(buf.validate.field).string.min_len = 1]; -} -message OperateComputerMissionCanaryRunResponse { - ComputerMissionCanaryRun run = 1 [(buf.validate.field).required = true]; - ComputerMissionCanaryOperatorAction action = 2 [(buf.validate.field).required = true]; -} - -// MissionScheduleTemplate is the typed mission payload a schedule fires on -// each due tick. Field shape mirrors ComputerMissionContract minus the -// scope's organization/workspace ids (the schedule already carries those) -// and the authority grant/resume fields, which the worker mints fresh for -// each fired mission. -message MissionScheduleTemplate { - string goal = 1 [(buf.validate.field).string.min_len = 1]; - string runner_profile = 2 [(buf.validate.field).string.min_len = 1]; - string channel_id = 3 [(buf.validate.field).string.min_len = 1]; - // Selecting FULL_AUTONOMY is the schedule's explicit typed authority - // confirmation. Console binds that selection to the authenticated principal - // and persists the current confirmation contract version; the worker also - // requires its independent full-autonomy feature gate. - ComputerMissionAuthorityMode authority_mode = 4 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - repeated string capabilities = 5 [(buf.validate.field).repeated.min_items = 1]; - repeated string resource_ids = 6 [(buf.validate.field).repeated.min_items = 1]; - repeated string required_evidence = 7 [(buf.validate.field).repeated.min_items = 1]; - ComputerMissionBudget budget = 8 [(buf.validate.field).required = true]; -} - -message MissionSchedule { - string schedule_id = 1 [(buf.validate.field).string.min_len = 1]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 3 [(buf.validate.field).string.min_len = 1]; - string name = 4 [(buf.validate.field).string.min_len = 1]; - string cron_expression = 5 [(buf.validate.field).string.min_len = 1]; - bool enabled = 6; - MissionScheduleTemplate template = 7 [(buf.validate.field).required = true]; - google.protobuf.Timestamp next_run_at = 8 [(buf.validate.field).required = true]; - google.protobuf.Timestamp last_run_at = 9; - string last_status = 10; - string last_mission_id = 11; - google.protobuf.Timestamp created_at = 12 [(buf.validate.field).required = true]; - google.protobuf.Timestamp updated_at = 13 [(buf.validate.field).required = true]; -} - -message CreateMissionScheduleRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string name = 3 [(buf.validate.field).string.min_len = 1]; - string cron_expression = 4 [(buf.validate.field).string.min_len = 1]; - MissionScheduleTemplate template = 5 [(buf.validate.field).required = true]; - string idempotency_key = 6 [(buf.validate.field).string.min_len = 1]; -} - -message CreateMissionScheduleResponse { - MissionSchedule schedule = 1 [(buf.validate.field).required = true]; -} - -message UpdateMissionScheduleRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string schedule_id = 3 [(buf.validate.field).string.min_len = 1]; - string name = 4 [(buf.validate.field).string.min_len = 1]; - string cron_expression = 5 [(buf.validate.field).string.min_len = 1]; - MissionScheduleTemplate template = 6 [(buf.validate.field).required = true]; -} - -message UpdateMissionScheduleResponse { - MissionSchedule schedule = 1 [(buf.validate.field).required = true]; -} - -message SetMissionScheduleEnabledRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string schedule_id = 3 [(buf.validate.field).string.min_len = 1]; - bool enabled = 4; -} - -message SetMissionScheduleEnabledResponse { - MissionSchedule schedule = 1 [(buf.validate.field).required = true]; -} - -message ListMissionSchedulesRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; -} - -message ListMissionSchedulesResponse { - repeated MissionSchedule schedules = 1; - int32 total = 2 [(buf.validate.field).int32.gte = 0]; - bool has_more = 3; - // available_capabilities is the backend-owned inventory the durable mission - // worker can dispatch. Clients must select from this catalog rather than - // accepting arbitrary capability identifiers. - repeated MissionScheduleCapability available_capabilities = 4; -} - -enum ConnectorTriggerSource { - CONNECTOR_TRIGGER_SOURCE_UNSPECIFIED = 0; - CONNECTOR_TRIGGER_SOURCE_SCHEDULED = 1; - CONNECTOR_TRIGGER_SOURCE_CONNECTOR_EVENT = 2; -} - -// ConnectorTrigger is a governed mission template attached to a connector -// event or schedule. `payload_field_allowlist` contains dotted JSON paths; -// no event field outside this list is admitted to the mission context. -message ConnectorTrigger { - string trigger_id = 1 [(buf.validate.field).string.min_len = 1]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 3 [(buf.validate.field).string.min_len = 1]; - string name = 4 [(buf.validate.field).string.min_len = 1]; - ConnectorTriggerSource source = 5 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string cron_expression = 6; - string connection_id = 7; - string provider_id = 8; - string event_kind = 9; - repeated string payload_field_allowlist = 10; - MissionScheduleTemplate template = 11 [(buf.validate.field).required = true]; - bool enabled = 12; - google.protobuf.Timestamp next_run_at = 13; - google.protobuf.Timestamp last_run_at = 14; - string last_status = 15; - string last_mission_id = 16; - string last_event_id = 17; - google.protobuf.Timestamp created_at = 18 [(buf.validate.field).required = true]; - google.protobuf.Timestamp updated_at = 19 [(buf.validate.field).required = true]; -} - -message CreateConnectorTriggerRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string name = 3 [(buf.validate.field).string.min_len = 1]; - ConnectorTriggerSource source = 4 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string cron_expression = 5; - string connection_id = 6; - string provider_id = 7; - string event_kind = 8; - repeated string payload_field_allowlist = 9; - MissionScheduleTemplate template = 10 [(buf.validate.field).required = true]; - string idempotency_key = 11 [(buf.validate.field).string.min_len = 1]; -} - -message CreateConnectorTriggerResponse { - ConnectorTrigger trigger = 1 [(buf.validate.field).required = true]; -} - -message UpdateConnectorTriggerRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string trigger_id = 3 [(buf.validate.field).string.min_len = 1]; - string name = 4 [(buf.validate.field).string.min_len = 1]; - ConnectorTriggerSource source = 5 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string cron_expression = 6; - string connection_id = 7; - string provider_id = 8; - string event_kind = 9; - repeated string payload_field_allowlist = 10; - MissionScheduleTemplate template = 11 [(buf.validate.field).required = true]; -} - -message UpdateConnectorTriggerResponse { - ConnectorTrigger trigger = 1 [(buf.validate.field).required = true]; -} - -message ListConnectorTriggersRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - int32 limit = 3 [(buf.validate.field).int32.gte = 0]; - int32 offset = 4 [(buf.validate.field).int32.gte = 0]; -} - -message ListConnectorTriggersResponse { - repeated ConnectorTrigger triggers = 1; - int32 total = 2 [(buf.validate.field).int32.gte = 0]; - bool has_more = 3; -} - -message DeleteConnectorTriggerRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string trigger_id = 3 [(buf.validate.field).string.min_len = 1]; -} - -message DeleteConnectorTriggerResponse {} - -message SetConnectorTriggerEnabledRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string trigger_id = 3 [(buf.validate.field).string.min_len = 1]; - bool enabled = 4; -} - -message SetConnectorTriggerEnabledResponse { - ConnectorTrigger trigger = 1 [(buf.validate.field).required = true]; -} - -message ComputerMissionApexSessionReservation { - string reservation_id = 1 [(buf.validate.field).string.min_len = 1]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 3 [(buf.validate.field).string.min_len = 1]; - string pack_run_id = 4 [(buf.validate.field).string.min_len = 1]; - string attempt_id = 5 [(buf.validate.field).string.min_len = 1]; - uint32 run_index = 6; - string decision_ref = 7 [(buf.validate.field).string.min_len = 1]; - string decision_digest_sha256 = 8 [(buf.validate.field).string.pattern = "^[0-9a-f]{64}$"]; - string runner_profile = 9 [(buf.validate.field).string.min_len = 1]; - string workload_digest = 10 [(buf.validate.field).string.pattern = "^sha256:[0-9a-f]{64}$"]; - string runner_session_id = 11; - string state = 12 [(buf.validate.field).string.pattern = "^(reserved|session_bound|adoption_authorized)$"]; - google.protobuf.Timestamp expires_at = 13 [(buf.validate.field).required = true]; -} - -message ReserveComputerMissionApexSessionRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string pack_run_id = 3 [(buf.validate.field).string.min_len = 1]; - string attempt_id = 4 [(buf.validate.field).string.min_len = 1]; - uint32 run_index = 5; - string decision_ref = 6 [(buf.validate.field).string.min_len = 1]; - string decision_digest_sha256 = 7 [(buf.validate.field).string.pattern = "^[0-9a-f]{64}$"]; - string runner_profile = 8 [(buf.validate.field).string.const = "apex-agents-v1"]; - string workload_digest = 9 [(buf.validate.field).string.pattern = "^sha256:[0-9a-f]{64}$"]; - // The same key is used for reservation issuance and Runner Host create; bind - // repeats it so Platform can reject a different physical create attempt. - string idempotency_key = 10 [(buf.validate.field).string.min_len = 1]; -} - -message ReserveComputerMissionApexSessionResponse { - ComputerMissionApexSessionReservation reservation = 1 [(buf.validate.field).required = true]; -} - -message BindComputerMissionApexSessionReservationRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string reservation_id = 3 [(buf.validate.field).string.min_len = 1]; - string runner_session_id = 4 [(buf.validate.field).string.min_len = 1]; - string runner_profile = 5 [(buf.validate.field).string.const = "apex-agents-v1"]; - string workload_digest = 6 [(buf.validate.field).string.pattern = "^sha256:[0-9a-f]{64}$"]; - // Must exactly equal ReserveComputerMissionApexSessionRequest.idempotency_key. - string create_idempotency_key = 7 [(buf.validate.field).string.min_len = 1]; -} - -message BindComputerMissionApexSessionReservationResponse { - ComputerMissionApexSessionReservation reservation = 1 [(buf.validate.field).required = true]; -} - -message ComputerMissionApexInstructionMetadata { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string reservation_id = 3 [(buf.validate.field).string.min_len = 1]; - string attempt_id = 4 [(buf.validate.field).string.min_len = 1]; - string instruction_artifact_ref = 5 [(buf.validate.field).string.min_len = 1]; - string instruction_digest_sha256 = 6 [(buf.validate.field).string.pattern = "^[0-9a-f]{64}$"]; - uint64 instruction_byte_count = 7 [(buf.validate.field).uint64 = { - gte: 1 - lte: 1048576 - }]; - string state = 8 [(buf.validate.field).string.const = "instruction_bound"]; -} - -message BindComputerMissionApexInstructionMetadataRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string reservation_id = 3 [(buf.validate.field).string.min_len = 1]; - string attempt_id = 4 [(buf.validate.field).string.min_len = 1]; - string instruction_artifact_ref = 5 [(buf.validate.field).string.min_len = 1]; - string instruction_digest_sha256 = 6 [(buf.validate.field).string.pattern = "^[0-9a-f]{64}$"]; - uint64 instruction_byte_count = 7 [(buf.validate.field).uint64 = { - gte: 1 - lte: 1048576 - }]; - string idempotency_key = 8 [(buf.validate.field).string.min_len = 1]; -} - -message BindComputerMissionApexInstructionMetadataResponse { - ComputerMissionApexInstructionMetadata metadata = 1 [(buf.validate.field).required = true]; -} - -message AuthorizeComputerMissionApexSessionAdoptionRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string reservation_id = 3 [(buf.validate.field).string.min_len = 1]; - string runner_session_id = 4 [(buf.validate.field).string.min_len = 1]; - string mission_id = 5 [(buf.validate.field).string.min_len = 1]; - string runtime_run_id = 6 [(buf.validate.field).string.min_len = 1]; -} - -message AuthorizeComputerMissionApexSessionAdoptionResponse { - remoterunner.v1.RunnerSessionOwnerBinding owner_binding = 1 [(buf.validate.field).required = true]; - string authorization_id = 2 [(buf.validate.field).string.min_len = 1]; - string authorization_digest_sha256 = 3 [(buf.validate.field).string.pattern = "^[0-9a-f]{64}$"]; - string tenant_scope_id = 4 [(buf.validate.field).string.min_len = 1]; - string workload_digest = 5 [(buf.validate.field).string.pattern = "^sha256:[0-9a-f]{64}$"]; - string instruction_artifact_ref = 6 [(buf.validate.field).string.min_len = 1]; - string instruction_digest_sha256 = 7 [(buf.validate.field).string.pattern = "^[0-9a-f]{64}$"]; - uint64 instruction_byte_count = 8 [(buf.validate.field).uint64 = { - gte: 1 - lte: 1048576 - }]; -} - -message GetOverviewRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; -} - -message GetOverviewResponse { - google.protobuf.Timestamp generated_at = 1; - repeated ConsoleMetric metrics = 2; - repeated AiAsset top_assets = 3; - repeated RiskFinding top_findings = 4; - repeated ActivityEvent recent_activity = 5; - repeated IntegrationTile integration_tiles = 6; - repeated OnboardingTask onboarding_tasks = 7; - repeated string warnings = 8; - int32 total_findings = 9 [(buf.validate.field).int32.gte = 0]; -} - -message GetConsoleBootSnapshotRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - // Skip the default operating transcript when the caller only needs shared - // app-shell state. Chat routes leave this false to retain first-paint data. - bool omit_operating_thread = 2; -} - -message ConsoleSnapshotFreshness { - google.protobuf.Timestamp generated_at = 1; - int64 stale_age_ms = 2 [(buf.validate.field).int64.gte = 0]; - repeated string degraded_services = 3; - repeated string stale_sections = 4; -} - -message GetConsoleBootSnapshotResponse { - GetWorkspaceSettingsResponse settings = 1; - GetBillingSubscriptionResponse billing_subscription = 2; - ListAgentWorkforceRecordsResponse workforce = 3; - ListOperatingChannelsResponse operating_channels = 4; - GetOperatingThreadResponse operating_thread = 5; - ConsoleSnapshotFreshness freshness = 6; -} - -message ListAssetsRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; -} - -message ListAssetsResponse { - repeated AiAsset assets = 1; - int32 total = 2 [(buf.validate.field).int32.gte = 0]; - bool has_more = 3; -} - -message GetAssetRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string asset_id = 2 [(buf.validate.field).string.min_len = 1]; -} - -message GetAssetResponse { - AiAsset asset = 1; - repeated RelatedResource related_resources = 2; - repeated ActivityEvent recent_activity = 3; - repeated RiskFinding findings = 4; -} - -message ListActivityRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; -} - -message ListActivityResponse { - repeated ActivityEvent events = 1; - int32 total = 2 [(buf.validate.field).int32.gte = 0]; - bool has_more = 3; - // Empty when spend budget denials owned by meter were merged into `events`. - // Non-empty names why they were not, so a caller can say this page is missing - // denials rather than render a page that looks complete. Platform never - // substitutes an empty denial set for an unread one. - string denials_unavailable_reason = 4; -} - -message ListEvalResultsRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - // Restrict the projection to the bounded set of traces already visible to - // the caller. This prevents clients from draining the evaluation ledger to - // join a small page of spend rows. - repeated string trace_ids = 2 [(buf.validate.field).repeated = { - max_items: 100 - items: { - string: { - min_len: 1 - max_len: 256 - } - } - }]; - bool latest_per_trace = 3; -} - -message ListEvalResultsResponse { - repeated EvalResult results = 1; - int32 total = 2 [(buf.validate.field).int32.gte = 0]; - bool has_more = 3; -} - -message ListCostUsageRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - // Exact durable run attribution; filtering happens before pagination. - string run_id = 2 [(buf.validate.field).string.max_len = 256]; -} - -message ListCostUsageResponse { - repeated CostUsage rows = 1; - int32 total = 2 [(buf.validate.field).int32.gte = 0]; - bool has_more = 3; - // summary is computed by Platform over the complete filtered ledger. rows is - // intentionally only the bounded, newest-first explorer page. - CostUsageSummary summary = 4; - // Present only for an exact run query with recorded usage. - CostUsageRunSummary run_summary = 5; -} - -message CostUsageRunSummary { - string run_id = 1; - int64 recorded_cost_micros = 2; - int64 request_count = 3; - int64 input_tokens = 4; - int64 output_tokens = 5; - int64 cache_read_tokens = 6; - int64 cache_write_tokens = 7; - int32 source_row_count = 8; - // Rows without a known cost basis must never be presented as free usage. - int32 unpriced_row_count = 9; - repeated string models = 10 [(buf.validate.field).repeated.max_items = 100]; - bool models_truncated = 11; -} - -message RecordProviderCostSnapshotRequest { - string organization_id = 1; - string workspace_id = 2; - string connection_id = 3; - string provider = 4; - string resource_id = 5; - string asset_id = 6; - string model = 7; - int64 spend_month_micros = 8 [(buf.validate.field).int64.gte = 0]; - int64 spend_today_micros = 9 [(buf.validate.field).int64.gte = 0]; - string period = 10; - google.protobuf.Timestamp observed_at = 11; - string idempotency_key = 12; - string source_url = 13; - // Empty remains provider_monthly_snapshot for backwards compatibility. - string record_kind = 14; - int64 input_tokens = 15 [(buf.validate.field).int64.gte = 0]; - int64 output_tokens = 16 [(buf.validate.field).int64.gte = 0]; - int64 request_count = 17 [(buf.validate.field).int64.gte = 0]; - // upstream_provider is the model provider selected behind a billing - // gateway such as OpenRouter. Keep it separate from provider, which is the - // source that owns the billing report. - string upstream_provider = 18; - // provenance describes how the source can be joined to ledger events: - // exact, aggregate, estimated, or unmatched. - string provenance = 19; -} - -message RecordProviderCostSnapshotResponse { - string snapshot_id = 1; -} - -message ListAuthorityPostureRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; -} - -message ListAuthorityPostureResponse { - repeated AuthorityLedger rows = 1; - int32 total = 2 [(buf.validate.field).int32.gte = 0]; - bool has_more = 3; - repeated string warnings = 4; -} - -message ListAgentWorkforceRecordsRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string organization_id = 2; - string runtime = 3; - string queue_state = 4; - bool include_debug = 5; - // source_event_id is an exact source-intake selector owned by the backend. - // It is separate from ConsoleQuery.search so an intake lookup cannot be - // widened into a generic Fleet search. - string source_event_id = 6 [(buf.validate.field).string.max_len = 120]; -} - -message ListAgentWorkforceRecordsResponse { - repeated AgentWorkforceRecord records = 1; - int32 total = 2 [(buf.validate.field).int32.gte = 0]; - bool has_more = 3; - repeated string warnings = 4; - AgentWorkforceApprovalQueueSummary approval_queue_summary = 5; - // source_readiness includes configured-only Agent Workforce source paths for - // rendering even when no approval-queue record exists for that source. These - // rows are display readiness only and do not prove identity, credential - // grants, model/cost spend, or approval readiness. - repeated AgentWorkforceSourceReadiness source_readiness = 6; - // Echoes the exact source-event selector when the response was filtered by - // source_event_id. Clients may use this typed contract for backend-owned - // singleton matching; an empty value means no source-event selector was - // applied. - string source_event_id = 7; -} - -message GetAgentProductRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string agent_id = 3 [(buf.validate.field).string.min_len = 1]; -} - -message AgentProductConnection { - string id = 1; - string provider_id = 2; - string display_name = 3; - connectors.v1.HealthStatus health_status = 4; - string health_reason = 5; - string provider_name = 6; - bool bound = 7; - // Connector-owned published actions compatible with this connection's - // scopes. These counts do not imply agent policy admission or execution. - AgentProductActionCatalog action_catalog = 8; -} - -message AgentProductActionCatalog { - bool resolved = 1; - int32 published = 2; - int32 scope_compatible = 3; - int32 reads = 4; - int32 writes = 5; - int32 approval_required = 6; - int32 destructive = 7; -} - -// Prompt content is resolved by the Prompt owner for the active configuration. -// An unavailable owner never turns a binding label into claimed instructions. -message AgentProductPrompt { - string name = 1; - string label = 2; - string content = 3 [(common.v1.classification) = DATA_CLASSIFICATION_CONTENT]; - string version_id = 4; - int32 version = 5; - bool resolved = 6; -} - -message GetAgentProductResponse { - agents.v1.Agent agent = 1; - agents.v1.AgentConfig config = 2; - repeated AgentProductConnection connections = 3; - repeated AgentProductPrompt prompts = 4; -} - -message CloneAgentProductRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string source_agent_id = 3 [(buf.validate.field).string.min_len = 1]; - int32 source_config_version = 4 [(buf.validate.field).int32.gt = 0]; - string name = 5 [(buf.validate.field).string.min_len = 1]; - string idempotency_key = 6 [(buf.validate.field).string.min_len = 1]; -} - -message CloneAgentProductResponse { - agents.v1.Agent agent = 1; - agents.v1.AgentConfig config = 2; -} - -message UpdateAgentProductRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string agent_id = 3 [(buf.validate.field).string.min_len = 1]; - int32 expected_config_version = 4 [(buf.validate.field).int32.gt = 0]; - string name = 5 [(buf.validate.field).string.min_len = 1]; - string description = 6; - map prompt_bindings = 7; - repeated string integration_ids = 8; - repeated agents.v1.ConnectorRequirement connector_requirements = 9; - string role = 10; - string purpose = 11; - repeated agents.v1.TeammateResponsibility responsibilities = 12; - repeated agents.v1.InitiativeTrigger triggers = 13; -} - -message UpdateAgentProductResponse { - agents.v1.Agent agent = 1; - agents.v1.AgentConfig config = 2; -} - -// OrbControlTarget is the Platform-owned customer-facing runtime projection. -message OrbControlTarget { - string id = 1; - string display_name = 2; - orbcontrol.v1.OrbObservedLifecycle lifecycle = 3 [(buf.validate.field).enum.defined_only = true]; - uint64 generation = 4; - uint64 observed_revision = 5; - uint64 last_event_sequence = 6; - string resident_agent = 7; - string provisioner = 8; - string owner_status = 9; - google.protobuf.Timestamp observed_at = 10; - repeated OperatingReceiptAction allowed_actions = 11; - OperatingReceipt receipt = 12; -} - -// ListOrbControlTargetsRequest selects a tenant-scoped target collection. -message ListOrbControlTargetsRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; -} - -// ListOrbControlTargetsResponse returns Platform projections only. -message ListOrbControlTargetsResponse { - repeated OrbControlTarget targets = 1; - int32 total = 2 [(buf.validate.field).int32.gte = 0]; - bool has_more = 3; -} - -// GetOrbControlTargetRequest selects one tenant-scoped target projection. -message GetOrbControlTargetRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string target_id = 2 [(buf.validate.field).string.min_len = 1]; -} - -// GetOrbControlTargetResponse returns one target projection and latest receipt. -message GetOrbControlTargetResponse { - OrbControlTarget target = 1; - OperatingReceipt receipt = 2; -} - -// SubmitOrbControlActionRequest records one generation-fenced user intent. -message SubmitOrbControlActionRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string target_id = 2 [(buf.validate.field).string.min_len = 1]; - orbcontrol.v1.OrbCommandKind action = 3 [(buf.validate.field).enum = { - defined_only: true - not_in: 0 - }]; - string idempotency_key = 4 [(buf.validate.field).string.min_len = 1]; - uint64 expected_generation = 5; -} - -// SubmitOrbControlActionResponse returns acceptance state, not inferred completion. -message SubmitOrbControlActionResponse { - OrbControlTarget target = 1; - OperatingReceipt receipt = 2 [(buf.validate.field).required = true]; -} - -message SubmitAgentWorkforceEvidenceRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string organization_id = 2; - // record_id targets an existing Agent Workforce record. When present, the - // backend resolves it to trace/run/session identifiers before writing. - string record_id = 3; - string trace_id = 4; - string run_id = 5; - string session_id = 6; - string agent_id = 7; - string runtime = 8; - // evidence_kind is one of advisory_self_report, credential_authority, - // cost_usage, attempted_action, or approval_packet. - string evidence_kind = 9 [(buf.validate.field).string.min_len = 1]; - // evidence_source identifies the submitting/owning source. Advisory/native - // sources such as external_self_report, nimbus, cerebro, or customer_mcp are - // retained as context but must not unlock approval authority. - string evidence_source = 10; - string evidence_ref = 11 [(buf.validate.field).string.min_len = 1]; - string subject = 12; - string provider = 13; - string action_id = 14; - string tool_name = 15; - string target_summary = 16; - bool mutates_resource = 17; - double cost_usd = 18 [(buf.validate.field).double.gte = 0]; - int64 input_tokens = 19 [(buf.validate.field).int64.gte = 0]; - int64 output_tokens = 20 [(buf.validate.field).int64.gte = 0]; - string model = 21; - string connector_id = 22; - string capability = 23; - string note = 24; -} - -message SubmitAgentWorkforceEvidenceResponse { - AgentWorkforceSubmittedEvidence submitted_evidence = 1; - AgentWorkforceRecord record = 2; - ListAgentWorkforceRecordsResponse records_response = 3; - repeated string remaining_missing_evidence = 4; - bool approval_allowed = 5; - string next_action = 6; - repeated string warnings = 7; -} - -message AgentWorkforceSubmittedEvidence { - string evidence_id = 1; - string evidence_kind = 2; - string evidence_source = 3; - string proof_strength = 4; - bool approval_authority = 5; - bool trusted_metadata_only = 6; - string detail = 7; - string record_id = 8; - string trace_id = 9; - string span_id = 10; - RelatedResource evidence_ref = 11; -} - -message ListFindingsRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; -} - -message ListFindingsResponse { - repeated RiskFinding findings = 1; - int32 total = 2 [(buf.validate.field).int32.gte = 0]; - bool has_more = 3; -} - -message GetTraceDrilldownRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string trace_id = 2 [(buf.validate.field).string.min_len = 1]; -} - -message GetTraceDrilldownResponse { - TraceDrilldown trace = 1; -} - -message ListIntegrationTilesRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; -} - -message ListIntegrationTilesResponse { - repeated IntegrationTile tiles = 1; - int32 total = 2 [(buf.validate.field).int32.gte = 0]; - optional int32 installed_total = 3 [(buf.validate.field).int32.gte = 0]; - optional int32 preview_total = 4 [(buf.validate.field).int32.gte = 0]; - int32 ready_total = 5 [(buf.validate.field).int32.gte = 0]; - int32 configured_total = 6 [(buf.validate.field).int32.gte = 0]; - bool preview_inventory_unavailable = 7; -} - -message ListPinnedSourcesRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; -} - -message ListPinnedSourcesResponse { - repeated PinnedSource pins = 1; -} - -message PinnedSource { - string source_id = 1; - google.protobuf.Timestamp pinned_at = 2; - string pinned_by = 3; -} - -message SetPinnedSourceRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string source_id = 2 [(buf.validate.field).string.min_len = 1]; -} - -message SetPinnedSourceResponse { - PinnedSource pin = 1; -} - -message UnpinSourceRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string source_id = 2 [(buf.validate.field).string.min_len = 1]; -} - -message UnpinSourceResponse {} - -message GetOnboardingPlanRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string environment = 2; -} - -message GetOnboardingPlanResponse { - repeated OnboardingTask tasks = 1; -} - -message GetWorkspaceSettingsRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; -} - -message GetWorkspaceSettingsResponse { - WorkspaceSettingsProfile workspace = 1; - WorkspaceSettingsPrincipal current_principal = 2; - repeated WorkspaceSettingsMember members = 3; - WorkspaceSettingsBilling billing = 4; - WorkspaceSettingsPolicy policy = 5; - WorkspaceSettingsNotifications notifications = 6; - repeated WorkspaceSettingsIdentityProvider identity_providers = 7; - repeated WorkspaceSettingsIntegration integrations = 8; - repeated WorkspaceSettingsCapability capabilities = 9; - repeated string warnings = 10; - repeated WorkspaceSettingsActivityEntry activity = 11; - repeated WorkspaceSettingsOwnerStatus owner_services = 12; - WorkspaceSettingsBreakGlassGrant break_glass_grant = 13; - repeated WorkspaceSettingsWorkspace workspaces = 14; - WorkspaceDexPolicy dex_policy = 15; - WorkspaceArtifactStyleGuide artifact_style_guide = 16; - // Response-only project choices resolved from this tenant's repository resources. - repeated TaskEnvironmentProjectOption task_environment_projects = 17; -} - -message TaskEnvironmentProjectOption { - string project_resource_id = 1; - string display_name = 2; -} - -message GetBillingSubscriptionRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; -} - -message GetBillingSubscriptionResponse { - string plan_name = 1; - string plan_tier = 2; - int32 seats_used = 3 [(buf.validate.field).int32.gte = 0]; - int32 seats_total = 4 [(buf.validate.field).int32.gte = 0]; - string renewal_date = 5; - string billing_contact = 6; - string billing_portal_url = 7; - string status = 8; - WorkspaceSettingsBillingStatus status_enum = 9; - bool billing_portal_available = 10; -} - -message CreateBillingPortalSessionRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; -} - -message CreateBillingPortalSessionResponse { - string url = 1 [(buf.validate.field).string.uri = true]; -} - -message CreateBillingCheckoutSessionRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string request_id = 2 [(buf.validate.field).string.uuid = true]; -} - -message CreateBillingCheckoutSessionResponse { - string url = 1 [(buf.validate.field).string.uri = true]; -} - -enum WorkspaceSettingsRole { - WORKSPACE_SETTINGS_ROLE_UNSPECIFIED = 0; - WORKSPACE_SETTINGS_ROLE_VIEWER = 1; - WORKSPACE_SETTINGS_ROLE_DEVELOPER = 2; - WORKSPACE_SETTINGS_ROLE_BILLING_ADMIN = 3; - WORKSPACE_SETTINGS_ROLE_ADMIN = 4; - WORKSPACE_SETTINGS_ROLE_OWNER = 5; -} - -enum WorkspaceSettingsAvailabilityStatus { - WORKSPACE_SETTINGS_AVAILABILITY_STATUS_UNSPECIFIED = 0; - WORKSPACE_SETTINGS_AVAILABILITY_STATUS_ACTIVE = 1; - WORKSPACE_SETTINGS_AVAILABILITY_STATUS_UNAVAILABLE = 2; -} - -enum WorkspaceSettingsBillingStatus { - WORKSPACE_SETTINGS_BILLING_STATUS_UNSPECIFIED = 0; - WORKSPACE_SETTINGS_BILLING_STATUS_ACTIVE = 1; - WORKSPACE_SETTINGS_BILLING_STATUS_TRIALING = 2; - WORKSPACE_SETTINGS_BILLING_STATUS_PAST_DUE = 3; - WORKSPACE_SETTINGS_BILLING_STATUS_CANCELED = 4; - WORKSPACE_SETTINGS_BILLING_STATUS_UNAVAILABLE = 5; - WORKSPACE_SETTINGS_BILLING_STATUS_PAUSED = 6; -} - -enum WorkspaceSettingsMemberStatus { - WORKSPACE_SETTINGS_MEMBER_STATUS_UNSPECIFIED = 0; - WORKSPACE_SETTINGS_MEMBER_STATUS_ACTIVE = 1; - WORKSPACE_SETTINGS_MEMBER_STATUS_INVITED = 2; - WORKSPACE_SETTINGS_MEMBER_STATUS_SUSPENDED = 3; -} - -enum WorkspaceSettingsIdentityProviderStatus { - WORKSPACE_SETTINGS_IDENTITY_PROVIDER_STATUS_UNSPECIFIED = 0; - WORKSPACE_SETTINGS_IDENTITY_PROVIDER_STATUS_CONFIGURED = 1; - WORKSPACE_SETTINGS_IDENTITY_PROVIDER_STATUS_CONNECTED = 2; - WORKSPACE_SETTINGS_IDENTITY_PROVIDER_STATUS_DEGRADED = 3; - WORKSPACE_SETTINGS_IDENTITY_PROVIDER_STATUS_DISABLED = 4; - WORKSPACE_SETTINGS_IDENTITY_PROVIDER_STATUS_UNAVAILABLE = 5; -} - -enum WorkspaceSettingsIntegrationStatus { - WORKSPACE_SETTINGS_INTEGRATION_STATUS_UNSPECIFIED = 0; - WORKSPACE_SETTINGS_INTEGRATION_STATUS_CONFIGURED = 1; - WORKSPACE_SETTINGS_INTEGRATION_STATUS_CONNECTED = 2; - WORKSPACE_SETTINGS_INTEGRATION_STATUS_HEALTHY = 3; - WORKSPACE_SETTINGS_INTEGRATION_STATUS_DEGRADED = 4; - WORKSPACE_SETTINGS_INTEGRATION_STATUS_DISABLED = 5; - WORKSPACE_SETTINGS_INTEGRATION_STATUS_UNAVAILABLE = 6; -} - -enum WorkspaceSettingsOwnerServiceStatus { - WORKSPACE_SETTINGS_OWNER_SERVICE_STATUS_UNSPECIFIED = 0; - WORKSPACE_SETTINGS_OWNER_SERVICE_STATUS_ACTIVE = 1; - WORKSPACE_SETTINGS_OWNER_SERVICE_STATUS_PROJECTION = 2; - WORKSPACE_SETTINGS_OWNER_SERVICE_STATUS_PARTIAL = 3; - WORKSPACE_SETTINGS_OWNER_SERVICE_STATUS_LOCAL = 4; - WORKSPACE_SETTINGS_OWNER_SERVICE_STATUS_UNAVAILABLE = 5; -} - -enum WorkspaceSettingsSource { - WORKSPACE_SETTINGS_SOURCE_UNSPECIFIED = 0; - WORKSPACE_SETTINGS_SOURCE_CONSOLE_SETTINGS = 1; - WORKSPACE_SETTINGS_SOURCE_CONSOLE_INVITATION = 2; - WORKSPACE_SETTINGS_SOURCE_AUTHENTICATED_PRINCIPAL = 3; - WORKSPACE_SETTINGS_SOURCE_MANUAL = 4; - WORKSPACE_SETTINGS_SOURCE_SCIM = 5; - WORKSPACE_SETTINGS_SOURCE_SAML = 6; - WORKSPACE_SETTINGS_SOURCE_OAUTH = 7; - WORKSPACE_SETTINGS_SOURCE_SYSTEM = 8; - WORKSPACE_SETTINGS_SOURCE_CONSOLE_SNAPSHOT = 9; -} - -message UpdateWorkspaceProfileRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - WorkspaceSettingsProfile profile = 2 [(buf.validate.field).required = true]; -} - -message UpdateWorkspaceProfileResponse { - GetWorkspaceSettingsResponse settings = 1 [(buf.validate.field).required = true]; -} - -// Personal model browsing choices; these never grant access to a model. -message OperatorModelPreference { - string provider = 1 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; - string model = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 256 - }]; - bool favorite = 3; - bool hidden = 4; -} - -message OperatorModelPreferenceUpdate { - string provider = 1 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; - string model = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 256 - }]; - optional bool favorite = 3; - optional bool hidden = 4; -} - -message OperatorPreferences { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string dex_hat_id = 2 [(buf.validate.field).string.min_len = 1]; - google.protobuf.Timestamp updated_at = 3; - bool developer_mode_enabled = 4; - repeated OperatorModelPreference model_preferences = 5; -} - -message GetOperatorPreferencesRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; -} - -message GetOperatorPreferencesResponse { - OperatorPreferences preferences = 1 [(buf.validate.field).required = true]; -} - -message UpdateOperatorPreferencesRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - // Omitted only for a model_preference update; existing profile updates require a hat. - string dex_hat_id = 2; - optional bool developer_mode_enabled = 3; - OperatorModelPreferenceUpdate model_preference = 4; -} - -message UpdateOperatorPreferencesResponse { - OperatorPreferences preferences = 1 [(buf.validate.field).required = true]; -} - -// GuardrailDetectorKind selects the deterministic detector a rule runs over Dex -// model output. Built-in detectors need no pattern; CUSTOM_REGEX carries a -// workspace-authored deny pattern in `pattern`. -enum GuardrailDetectorKind { - GUARDRAIL_DETECTOR_KIND_UNSPECIFIED = 0; - GUARDRAIL_DETECTOR_KIND_BUILTIN_EMAIL = 1; - GUARDRAIL_DETECTOR_KIND_BUILTIN_CREDIT_CARD = 2; - GUARDRAIL_DETECTOR_KIND_BUILTIN_SECRET = 3; - GUARDRAIL_DETECTOR_KIND_CUSTOM_REGEX = 4; -} - -// GuardrailAction is what a matched rule does to the turn. BLOCK fails the turn -// closed, REDACT masks the matched span, FLAG records the match only. -enum GuardrailAction { - GUARDRAIL_ACTION_UNSPECIFIED = 0; - GUARDRAIL_ACTION_BLOCK = 1; - GUARDRAIL_ACTION_REDACT = 2; - GUARDRAIL_ACTION_FLAG = 3; -} - -// WorkspaceGuardrailRule is one workspace-configured content guardrail applied -// to Dex model output. -message WorkspaceGuardrailRule { - string id = 1 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; - string name = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 256 - }]; - GuardrailDetectorKind detector_kind = 3; - // Regex source, required only when detector_kind is CUSTOM_REGEX. Empty for - // built-in detectors. - string pattern = 4 [(buf.validate.field).string.max_len = 4096]; - GuardrailAction action = 5; - bool enabled = 6; - google.protobuf.Timestamp updated_at = 7; -} - -message ListWorkspaceGuardrailRulesRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; -} - -message ListWorkspaceGuardrailRulesResponse { - repeated WorkspaceGuardrailRule rules = 1; -} - -message UpsertWorkspaceGuardrailRuleRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - WorkspaceGuardrailRule rule = 2 [(buf.validate.field).required = true]; -} - -message RemoveWorkspaceGuardrailRuleRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string id = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; -} - -message ConnectorProfile { - string id = 1 [(buf.validate.field).string.min_len = 1]; - string provider_id = 2 [(buf.validate.field).string.min_len = 1]; - string profile_name = 3 [(buf.validate.field).string.min_len = 1]; - repeated string scopes = 4; - bool enabled = 5; - bool is_default = 6; - google.protobuf.Timestamp created_at = 7; - google.protobuf.Timestamp updated_at = 8; -} - -message ConnectorProfileScopeSet { - repeated string values = 1; -} - -message CreateConnectorProfileRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string provider_id = 2 [(buf.validate.field).string.min_len = 1]; - string profile_name = 3 [(buf.validate.field).string.min_len = 1]; - string connection_id = 4 [(buf.validate.field).string.min_len = 1]; - repeated string scopes = 5; - optional bool enabled = 6; - bool is_default = 7; -} - -message CreateConnectorProfileResponse { - ConnectorProfile profile = 1 [(buf.validate.field).required = true]; -} - -message ListConnectorProfilesRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string provider_id = 2 [(buf.validate.field).string.min_len = 1]; -} - -message ListConnectorProfilesResponse { - repeated ConnectorProfile profiles = 1; -} - -message UpdateConnectorProfileRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string id = 2 [(buf.validate.field).string.min_len = 1]; - optional bool enabled = 3; - optional bool is_default = 4; - ConnectorProfileScopeSet scopes = 5; -} - -message UpdateConnectorProfileResponse { - ConnectorProfile profile = 1 [(buf.validate.field).required = true]; -} - -message DeleteConnectorProfileRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string id = 2 [(buf.validate.field).string.min_len = 1]; -} - -message DeleteConnectorProfileResponse { - bool deleted = 1; -} - -message ArchiveWorkspaceRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - bool archived = 2; -} - -message ArchiveWorkspaceResponse { - GetWorkspaceSettingsResponse settings = 1 [(buf.validate.field).required = true]; -} - -message UpdateWorkspacePolicyRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - WorkspaceSettingsPolicy policy = 2 [(buf.validate.field).required = true]; -} - -message UpdateWorkspacePolicyResponse { - GetWorkspaceSettingsResponse settings = 1 [(buf.validate.field).required = true]; -} - -message UpdateWorkspaceDexPolicyRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - // (-- api-linter: core::0134::request-resource-field=disabled - // aip.dev/not-precedent: The public dex_policy source and ProtoJSON names - // predate AIP-134 and remain compatibility contracts. --) - WorkspaceDexPolicy dex_policy = 2 [(buf.validate.field).required = true]; -} - -message UpdateWorkspaceDexPolicyResponse { - GetWorkspaceSettingsResponse settings = 1 [(buf.validate.field).required = true]; -} - -message UpdateWorkspaceArtifactStyleGuideRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - WorkspaceArtifactStyleGuide workspace_artifact_style_guide = 2 [(buf.validate.field).required = true]; -} - -message UpdateWorkspaceArtifactStyleGuideResponse { - GetWorkspaceSettingsResponse settings = 1 [(buf.validate.field).required = true]; -} - -message EvaluateWorkspaceArtifactStyleGuideRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - WorkspaceArtifactStyleGuide workspace_artifact_style_guide = 2 [(buf.validate.field).required = true]; - string sample_response = 3 [(buf.validate.field).string = { - min_len: 1 - max_len: 64000 - }]; -} - -message EvaluateWorkspaceArtifactStyleGuideResponse { - bool passed = 1; - uint32 word_count = 2; - repeated WorkspaceContentPolicyViolation violations = 3 [(buf.validate.field).repeated.max_items = 200]; -} - -message WorkspaceContentPolicyViolation { - string code = 1; - string message = 2; -} - -message UpsertWorkspaceIdentityProviderRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - WorkspaceSettingsIdentityProvider provider = 2 [(buf.validate.field).required = true]; -} - -message UpsertWorkspaceIdentityProviderResponse { - GetWorkspaceSettingsResponse settings = 1 [(buf.validate.field).required = true]; -} - -message RemoveWorkspaceIdentityProviderRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string id = 2 [(buf.validate.field).string.min_len = 1]; -} - -message RemoveWorkspaceIdentityProviderResponse { - GetWorkspaceSettingsResponse settings = 1 [(buf.validate.field).required = true]; -} - -message UpsertWorkspaceIntegrationRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - WorkspaceSettingsIntegration integration = 2 [(buf.validate.field).required = true]; -} - -message UpsertWorkspaceIntegrationResponse { - GetWorkspaceSettingsResponse settings = 1 [(buf.validate.field).required = true]; -} - -message RemoveWorkspaceIntegrationRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string id = 2 [(buf.validate.field).string.min_len = 1]; -} - -message RemoveWorkspaceIntegrationResponse { - GetWorkspaceSettingsResponse settings = 1 [(buf.validate.field).required = true]; -} - -message UpdateWorkspaceBillingRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - WorkspaceSettingsBilling billing = 2 [(buf.validate.field).required = true]; -} - -message UpsertWorkspaceMemberRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - WorkspaceSettingsMember member = 2 [(buf.validate.field).required = true]; -} - -message RemoveWorkspaceMemberRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string subject = 2; - string email = 3; -} - -message UpdateWorkspaceNotificationPreferencesRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - WorkspaceSettingsNotifications notifications = 2 [(buf.validate.field).required = true]; -} - -message EnableWorkspaceBreakGlassRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - WorkspaceSettingsBreakGlassGrant grant = 2 [(buf.validate.field).required = true]; -} - -message DisableWorkspaceBreakGlassRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string grant_id = 2; -} - -// OperatingSkill is a workspace-scoped named procedure Dex can discover and -// load at runtime (see docs on the operating_skills table). name is unique -// per workspace and kebab-case; description is a single line shown in -// listings; body is the markdown procedure text. -message OperatingSkill { - string id = 1; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string name = 3 [(buf.validate.field).string.min_len = 1]; - string description = 4; - string body = 5; - int32 version = 6; - google.protobuf.Timestamp created_at = 7; - google.protobuf.Timestamp updated_at = 8; - string organization_id = 9 [(buf.validate.field).string.min_len = 1]; - // Catalog provenance is present only when the workspace skill was installed - // from BrowseDexSkillCatalog. It lets clients keep attribution visible after - // the skill moves from the library into the installed workspace list. - string catalog_skill_id = 10; - int32 catalog_version = 11; - // Deterministic analysis of the exact stored description and body. Content - // findings are advisory and never authorize, block, or route behavior. - SkillAnalysisReport analysis = 12; - string source_revision = 13; - string package_digest = 14; - repeated DexSkillPackageFile package_manifest = 15; - string activation_trigger = 16; - string objective = 17; - repeated DexSkillInputDeclaration inputs = 18; - repeated DexSkillOutputDeclaration outputs = 19; - repeated string ordered_method = 20; - repeated string success_criteria = 21; - string unavailable_behavior = 22; - string output_contract = 23; - DexSkillLicenseEvidence license_evidence = 24; - DexSkillCompatibility compatibility = 25; - DexSkillQualityEvidence quality_evidence = 26; - DexSkillLifecycleState lifecycle_state = 27; - string customer_safe_remediation = 28; - DexSkillUpdateDiff update_diff = 29; - repeated string required_tools = 30; -} - -message ListWorkspaceSkillsRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; -} - -message ListWorkspaceSkillsResponse { - repeated OperatingSkill skills = 1; -} - -enum SkillAnalysisVerdict { - SKILL_ANALYSIS_VERDICT_UNSPECIFIED = 0; - SKILL_ANALYSIS_VERDICT_PASS = 1; - SKILL_ANALYSIS_VERDICT_NEEDS_REVIEW = 2; - SKILL_ANALYSIS_VERDICT_BLOCKED = 3; - SKILL_ANALYSIS_VERDICT_UNSCANNABLE = 4; -} - -message SkillAnalysisFinding { - string rule_id = 1; - string title = 2; - string detail = 3; - common.v1.RiskLevel severity = 4; - // Advisory findings are bounded content-review signals. They never affect - // the verdict or authorize, block, or route product behavior. - bool advisory = 5; -} - -// SkillAnalysisReport is deterministic evidence about the exact skill payload -// being displayed, saved, or offered for installation. It is not a permission -// grant and never replaces runtime authorization or approval policy. -message SkillAnalysisReport { - SkillAnalysisVerdict verdict = 1; - string content_digest = 2; - string ruleset_version = 3; - repeated string covered_surfaces = 4; - repeated string required_tools = 5; - repeated SkillAnalysisFinding findings = 6; -} - -// Typed, progressive-disclosure metadata for a lossless operating-skill -// package. These fields describe a procedure and its resources; they never -// grant authority or replace tenant, tool, approval, or policy checks. -message DexSkillInputDeclaration { - string name = 1 [(buf.validate.field).string.min_len = 1]; - string type = 2 [(buf.validate.field).string.min_len = 1]; - string description = 3; - bool required = 4; -} - -message DexSkillOutputDeclaration { - string name = 1 [(buf.validate.field).string.min_len = 1]; - string type = 2 [(buf.validate.field).string.min_len = 1]; - string description = 3; -} - -enum DexSkillPackageFileKind { - DEX_SKILL_PACKAGE_FILE_KIND_UNSPECIFIED = 0; - DEX_SKILL_PACKAGE_FILE_KIND_INSTRUCTIONS = 1; - DEX_SKILL_PACKAGE_FILE_KIND_SCRIPT = 2; - DEX_SKILL_PACKAGE_FILE_KIND_REFERENCE = 3; - DEX_SKILL_PACKAGE_FILE_KIND_EXAMPLE = 4; - DEX_SKILL_PACKAGE_FILE_KIND_ASSET = 5; - DEX_SKILL_PACKAGE_FILE_KIND_TEMPLATE = 6; - DEX_SKILL_PACKAGE_FILE_KIND_LICENSE = 7; - DEX_SKILL_PACKAGE_FILE_KIND_OTHER = 8; -} - -message DexSkillPackageFile { - string path = 1 [(buf.validate.field).string.min_len = 1]; - string media_type = 2 [(buf.validate.field).string.min_len = 1]; - uint64 size_bytes = 3; - string content_digest = 4 [(buf.validate.field).string.min_len = 1]; - DexSkillPackageFileKind kind = 5; - // POSIX mode bits as recorded by the imported package (for example 0644 or - // 0755). This is metadata only; installation never executes a package file. - uint32 mode = 6; -} - -message DexSkillLicenseEvidence { - string spdx_id = 1; - string source_path = 2; - string content_digest = 3; - bool verified = 4; - // True only when the license file itself is included in the package - // manifest. False identifies path-level or repository-level evidence. - bool included = 5; -} - -message DexSkillCompatibility { - string schema_version = 1; - repeated string runtimes = 2; - repeated string roles = 3; - repeated string platforms = 4; -} - -enum DexSkillFixtureKind { - DEX_SKILL_FIXTURE_KIND_UNSPECIFIED = 0; - DEX_SKILL_FIXTURE_KIND_HAPPY = 1; - DEX_SKILL_FIXTURE_KIND_EDGE = 2; - DEX_SKILL_FIXTURE_KIND_DENIED_UNAVAILABLE = 3; -} - -message DexSkillQualityFixture { - string id = 1 [(buf.validate.field).string.min_len = 1]; - DexSkillFixtureKind kind = 2; - string trigger_assertion = 3; - string task_success_assertion = 4; - string failure_handling_assertion = 5; - string artifact_assertion = 6; - string baseline_id = 7; -} - -message DexSkillQualityEvidence { - string suite_version = 1; - repeated DexSkillQualityFixture fixtures = 2; - string baseline_id = 3; - string baseline_digest = 4; - bool publication_gate_passed = 5; -} - -enum DexSkillLifecycleState { - DEX_SKILL_LIFECYCLE_STATE_UNSPECIFIED = 0; - DEX_SKILL_LIFECYCLE_STATE_READY = 1; - DEX_SKILL_LIFECYCLE_STATE_MISSING_TOOL = 2; - DEX_SKILL_LIFECYCLE_STATE_NEEDS_REVIEW = 3; - DEX_SKILL_LIFECYCLE_STATE_DISABLED = 4; - DEX_SKILL_LIFECYCLE_STATE_REVOKED = 5; -} - -enum DexSkillRuntimeReadiness { - DEX_SKILL_RUNTIME_READINESS_UNSPECIFIED = 0; - DEX_SKILL_RUNTIME_READINESS_NOT_REQUIRED = 1; - DEX_SKILL_RUNTIME_READINESS_PROBE_REQUIRED = 2; - DEX_SKILL_RUNTIME_READINESS_READY = 3; - DEX_SKILL_RUNTIME_READINESS_MISSING_TOOL = 4; - DEX_SKILL_RUNTIME_READINESS_UNAVAILABLE = 5; -} - -message DexSkillUpdateDiff { - int32 from_catalog_version = 1; - int32 to_catalog_version = 2; - string from_package_digest = 3; - string to_package_digest = 4; - repeated string added_paths = 5; - repeated string removed_paths = 6; - repeated string changed_paths = 7; - string summary = 8; - // Servers cap path lists and summary text before returning this projection. - bool bounded = 9; -} - -enum DexSkillCatalogExposure { - DEX_SKILL_CATALOG_EXPOSURE_UNSPECIFIED = 0; - DEX_SKILL_CATALOG_EXPOSURE_INTERNAL = 1; - DEX_SKILL_CATALOG_EXPOSURE_INSTALLABLE = 2; -} - -message DexSkillCatalogEntry { - string id = 1; - string description = 2; - int32 catalog_version = 3; - bool installed = 4; - string installed_skill_name = 5; - int32 installed_version = 6; - int32 installed_catalog_version = 7; - bool update_available = 8; - string display_name = 9; - string publisher = 10; - string source_url = 11; - string license = 12; - string category = 13; - repeated string tags = 14; - bool external = 15; - // The procedure's reviewed operating risk, not a grant of authority. Any - // governed tool or write still applies its own runtime policy and approval - // boundary. - common.v1.RiskLevel risk_level = 16; - SkillAnalysisReport analysis = 17; - DexSkillCatalogExposure exposure = 18; - // Governed tools the procedure cannot be carried out without. An empty - // list means the catalog entry declares no particular tool requirement. - repeated string required_tools = 19 [(buf.validate.field).repeated.max_items = 64]; - string source_revision = 20; - string package_digest = 21; - // Browse returns manifest metadata only. Resource contents are loaded only - // after an explicit skill.load/install path has passed its gates. - repeated DexSkillPackageFile package_manifest = 22; - string activation_trigger = 23; - string objective = 24; - repeated DexSkillInputDeclaration inputs = 25; - repeated DexSkillOutputDeclaration outputs = 26; - repeated string ordered_method = 27; - repeated string success_criteria = 28; - string unavailable_behavior = 29; - string output_contract = 30; - DexSkillLicenseEvidence license_evidence = 31; - DexSkillCompatibility compatibility = 32; - DexSkillQualityEvidence quality_evidence = 33; - DexSkillLifecycleState lifecycle_state = 34; - string customer_safe_remediation = 35; - DexSkillUpdateDiff update_diff = 36; - // Catalog browse has no sandbox session. Runtime-dependent packages report - // PROBE_REQUIRED until a trusted session-scoped environment probe runs. - // This field does not gate package installation. - DexSkillRuntimeReadiness runtime_readiness = 37; -} - -// DexSkillPlaybookStep is one ordered, server-authored outcome in a playbook. -// The referenced catalog skill remains the source of the procedure and its -// installation state; display metadata here keeps clients from inventing -// step semantics locally. -message DexSkillPlaybookStep { - string catalog_skill_id = 1 [(buf.validate.field).string.min_len = 1]; - string display_name = 2 [(buf.validate.field).string.min_len = 1]; - string description = 3; -} - -// DexSkillPlaybook is a curated sequence of catalog skills for a common -// operating outcome. integration_labels is intentionally optional: it is -// populated only when the server models a concrete integration dependency. -message DexSkillPlaybook { - string id = 1 [(buf.validate.field).string.min_len = 1]; - string display_name = 2 [(buf.validate.field).string.min_len = 1]; - string outcome_description = 3 [(buf.validate.field).string.min_len = 1]; - repeated DexSkillPlaybookStep steps = 4 [(buf.validate.field).repeated.min_items = 1]; - repeated string integration_labels = 5 [(buf.validate.field).repeated.max_items = 16]; -} - -message BrowseDexSkillCatalogRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; -} - -message BrowseDexSkillCatalogResponse { - repeated DexSkillCatalogEntry entries = 1; - repeated DexSkillPlaybook playbooks = 2; -} - -message InstallDexSkillCatalogEntryRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string catalog_id = 2 [(buf.validate.field).string.min_len = 1]; - // Required when the current typed analysis verdict is NEEDS_REVIEW. The - // acknowledgement is accepted only when fields 4-6 exactly match the - // current catalog payload and analysis evidence. - bool accept_analysis_findings = 3; - int32 reviewed_catalog_version = 4; - string reviewed_analysis_content_digest = 5; - string reviewed_analysis_ruleset_version = 6; - string reviewed_source_revision = 7; - string reviewed_package_digest = 8; -} - -message InstallDexSkillCatalogEntryResponse { - OperatingSkill skill = 1 [(buf.validate.field).required = true]; - string catalog_skill_id = 2; - int32 catalog_version = 3; - bool reinstalled = 4; -} - -message CreateWorkspaceSkillRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string name = 2 [(buf.validate.field).string.min_len = 1]; - string description = 3; - string body = 4 [(buf.validate.field).string.min_len = 1]; -} - -message CreateWorkspaceSkillResponse { - OperatingSkill skill = 1 [(buf.validate.field).required = true]; -} - -message UpdateWorkspaceSkillRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string name = 2 [(buf.validate.field).string.min_len = 1]; - string description = 3; - string body = 4 [(buf.validate.field).string.min_len = 1]; -} - -message UpdateWorkspaceSkillResponse { - OperatingSkill skill = 1 [(buf.validate.field).required = true]; -} - -message DeleteWorkspaceSkillRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string name = 2 [(buf.validate.field).string.min_len = 1]; -} - -message DeleteWorkspaceSkillResponse {} - -message WorkspaceSettingsProfile { - string organization_id = 1; - string organization_label = 2; - string workspace_id = 3; - string workspace_label = 4; - string environment = 5; - string region = 6; - bool archived = 7; - google.protobuf.Timestamp archived_at = 8; - WorkspaceSettingsCapability update_capability = 9; - WorkspaceSettingsCapability archive_capability = 10; -} - -message WorkspaceSettingsPrincipal { - string subject = 1; - string user_subject = 2; - string display_name = 3; - // Legacy display label. New clients should use rbac_role. - string role = 4; - bool human = 5; - WorkspaceSettingsRole rbac_role = 6; -} - -message WorkspaceSettingsCapability { - string id = 1; - string label = 2; - bool available = 3; - string reason = 4; - string action_url = 5; -} - -message WorkspaceSettingsWorkspace { - string organization_id = 1; - string organization_label = 2; - string workspace_id = 3; - string workspace_label = 4; - string environment = 5; - string region = 6; - bool current = 7; - bool archived = 8; - google.protobuf.Timestamp archived_at = 9; - WorkspaceSettingsRole rbac_role = 10; - repeated WorkspaceSettingsCapability capabilities = 11; - string source = 12; -} - -message WorkspaceSettingsActivityEntry { - string id = 1; - string section = 2; - string action = 3; - string actor_subject = 4; - string actor_email = 5; - string summary = 6; - google.protobuf.Timestamp created_at = 7; - map details = 8; -} - -message WorkspaceSettingsMember { - string subject = 1; - string display_name = 2; - string email = 3; - // Legacy display label. New clients should use rbac_role. - string role = 4; - string source = 5; - WorkspaceSettingsCapability manage_capability = 6; - WorkspaceSettingsRole rbac_role = 7; - string status = 8; - bool managed = 9; - string provisioning_source = 10; - google.protobuf.Timestamp last_seen_at = 11; - WorkspaceSettingsMemberStatus status_enum = 12; - WorkspaceSettingsSource source_enum = 13; - WorkspaceSettingsSource provisioning_source_enum = 14; -} - -message WorkspaceSettingsBilling { - string status = 1; - string plan = 2; - int32 seats_used = 3 [(buf.validate.field).int32.gte = 0]; - int32 seats_total = 4 [(buf.validate.field).int32.gte = 0]; - google.protobuf.Timestamp renewal_at = 5; - string billing_contact = 6; - WorkspaceSettingsCapability manage_capability = 7; - WorkspaceSettingsBillingStatus status_enum = 8; -} - -message WorkspaceSettingsPolicy { - string status = 1; - bool require_human_approval_for_writes = 2; - bool block_missing_evidence = 3; - bool auto_revoke_idle_leases = 4; - bool allow_cross_account_access = 5; - string max_lease_ttl = 6; - string evidence_requirement = 7; - WorkspaceSettingsCapability update_capability = 8; - bool require_mfa = 9; - bool enforce_sso = 10; - bool scim_provisioning = 11; - // Legacy display label. New clients should use default_member_rbac_role. - string default_member_role = 12; - string session_ttl = 13; - repeated string allowed_domains = 14; - repeated string ip_allowlist = 15; - int32 audit_log_retention_days = 16 [(buf.validate.field).int32.gte = 0]; - int32 data_retention_days = 17 [(buf.validate.field).int32.gte = 0]; - WorkspaceSettingsRole default_member_rbac_role = 18; - WorkspaceSettingsAvailabilityStatus status_enum = 19; - // Separate inactivity policy for unaccepted task-computer state. - WorkspaceTaskEnvironmentRetention task_environment_retention = 20; -} - -// Project identity is an existing tenant-scoped Platform repository resource. -message ProjectTaskEnvironmentRetention { - string project_resource_id = 1 [(buf.validate.field).string.min_len = 1]; - // Absent means inherit the workspace default. - optional int32 retention_days = 2 [(buf.validate.field).int32 = { - in: [ - 0, - 7, - 30 - ] - }]; - // Preferred hour-level policy. Zero means the legacy retention_days field. - optional int32 retention_hours = 3 [(buf.validate.field).int32 = { - in: [ - 8, - 168, - 720 - ] - }]; -} - -message WorkspaceTaskEnvironmentRetention { - int32 retention_days = 1 [(buf.validate.field).int32 = { - in: [ - 0, - 7, - 30 - ] - }]; - repeated ProjectTaskEnvironmentRetention projects = 2; - // Server-owned monotonic revision across workspace and project policy changes. - // Mutations ignore caller-supplied values. - uint64 policy_revision = 3; - // Preferred hour-level policy. Zero means the legacy retention_days field. - int32 retention_hours = 4 [(buf.validate.field).int32 = { - in: [ - 0, - 8, - 168, - 720 - ] - }]; -} - -enum DexAutonomyMode { - DEX_AUTONOMY_MODE_UNSPECIFIED = 0; - DEX_AUTONOMY_MODE_SUGGEST_ONLY = 1; - DEX_AUTONOMY_MODE_ASK_BEFORE_CHANGES = 2; - DEX_AUTONOMY_MODE_ACT_WITHIN_POLICY = 3; -} - -enum DexExternalActionMode { - DEX_EXTERNAL_ACTION_MODE_UNSPECIFIED = 0; - DEX_EXTERNAL_ACTION_MODE_ALWAYS_ASK = 1; - DEX_EXTERNAL_ACTION_MODE_POLICY_BASED = 2; - DEX_EXTERNAL_ACTION_MODE_DISABLED = 3; -} - -message WorkspaceDexPolicy { - DexAutonomyMode autonomy_mode = 1 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - DexExternalActionMode external_action_mode = 2 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - bool project_memory_enabled = 3; - bool preference_memory_enabled = 4; - bool learning_from_corrections_enabled = 5; - bool proactivity_enabled = 6; - bool trace_content_capture_enabled = 7; - int32 max_turn_seconds = 8 [(buf.validate.field).int32 = { - gte: 5 - lte: 900 - }]; - int32 max_tool_calls = 9 [(buf.validate.field).int32 = { - gte: 0 - lte: 64 - }]; - int32 max_concurrency = 10 [(buf.validate.field).int32 = { - gte: 1 - lte: 8 - }]; - int64 max_cost_micros = 11 [(buf.validate.field).int64 = { - gte: 0 - lte: 100000000 - }]; - repeated string allowed_systems = 12 [(buf.validate.field).repeated.max_items = 64]; - WorkspaceSettingsCapability update_capability = 13; - WorkspaceSettingsCapability review_corrections_capability = 14; - bool customer_intelligence_enabled = 15; - // Proactive commitment-ledger nudges (due-date reminders projected into the - // operating channel). On in Dex Standard; workspaces can opt out. The - // deployment ceiling DEX_COMMITMENT_NUDGES_ENABLED must also be on, so a - // workspace can narrow the ceiling but never widen it. - bool commitment_nudges_enabled = 16; - // Opt-in for model-visible governed MCP dispatch (policy-filtered - // discovery, Gate admission, and durable approval continuation). Off by - // default; the deployment ceiling DEX_MCP_TOOLS_ENABLED must also be on. - // Workspaces can narrow the ceiling, never widen it. - bool mcp_dispatch_enabled = 17; - // Customer-facing Subagents opt-in for Dex child-run delegation. Off by - // default; the deployment ceiling DEX_DELEGATE_ENABLED must also be on. - // Workspaces can narrow the ceiling, never widen it. - bool subagent_delegation_enabled = 18; -} - -// WorkspaceArtifactStyleGuide is the workspace-owned Content & AI policy for -// user-visible content Dex authors across responses, actions, documents, and -// presentations. The historical message name is retained for wire -// compatibility. Guidance shapes generation while deterministic controls are -// enforced at response and durable-artifact boundaries. -message WorkspaceArtifactStyleGuide { - bool enabled = 1; - // Deprecated compatibility projection of the selected default voice's - // guidance. New clients use brand_voices and default_brand_voice_id. - string voice_and_tone = 2 [(buf.validate.field).string.max_len = 4000]; - string document_guidance = 3 [(buf.validate.field).string.max_len = 8000]; - string presentation_guidance = 4 [(buf.validate.field).string.max_len = 8000]; - repeated string required_terms = 5 [(buf.validate.field).repeated.max_items = 100]; - repeated string forbidden_terms = 6 [(buf.validate.field).repeated.max_items = 100]; - uint64 version = 7; - google.protobuf.Timestamp updated_at = 8; - WorkspaceSettingsCapability update_capability = 9; - string response_guidance = 10 [(buf.validate.field).string.max_len = 8000]; - bool require_citations = 11; - uint32 max_response_words = 12 [(buf.validate.field).uint32.lte = 4000]; - repeated string allowed_citation_domains = 13 [(buf.validate.field).repeated.max_items = 100]; - // Reusable voice assets available to this workspace. Deixic does not impose - // a plan or item-count limit; transport and field-size limits still apply to - // each request. A voice id has meaning only inside the authorized - // organization/workspace pair that returned it. - repeated WorkspaceBrandVoice brand_voices = 14; - // Empty means that the workspace has no voice assignment. A non-empty id - // must resolve to one active voice in brand_voices; unknown or archived - // selections are rejected rather than inherited from another workspace. - string default_brand_voice_id = 15 [ - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER, - (buf.validate.field).string.max_len = 128 - ]; -} - -message WorkspaceSettingsNotificationPreference { - string id = 1; - string label = 2; - string detail = 3; - bool enabled = 4; - WorkspaceSettingsCapability update_capability = 5; -} - -enum WorkspaceSpendBeatCadence { - WORKSPACE_SPEND_BEAT_CADENCE_UNSPECIFIED = 0; - WORKSPACE_SPEND_BEAT_CADENCE_DAILY = 1; - WORKSPACE_SPEND_BEAT_CADENCE_WEEKLY = 2; -} - -// WorkspaceSpendBeatSettings is the server-authoritative opt-in for scheduled -// AI spend briefs and material-drift alerts. Destination ids are re-authorized -// at delivery time; storing them here never grants connector access. -message WorkspaceSpendBeatSettings { - bool enabled = 1; - bool paused = 2; - string slack_connection_id = 3 [(buf.validate.field).string.max_len = 256]; - string slack_channel_id = 4 [(buf.validate.field).string.max_len = 256]; - WorkspaceSpendBeatCadence cadence = 5 [(buf.validate.field).enum.defined_only = true]; - string timezone = 6 [(buf.validate.field).string.max_len = 128]; - uint32 local_hour = 7 [(buf.validate.field).uint32.lte = 23]; - uint32 local_minute = 8 [(buf.validate.field).uint32.lte = 59]; - // Monday=0 through Sunday=6. Used only for weekly cadence. - uint32 weekly_day_monday_zero = 9 [(buf.validate.field).uint32.lte = 6]; - uint32 materiality_threshold_bp = 10 [(buf.validate.field).uint32 = { - gte: 1 - lte: 100000 - }]; - uint64 materiality_absolute_micros = 11; - uint32 cooldown_seconds = 12 [(buf.validate.field).uint32.lte = 2592000]; - string quiet_hours_start = 13 [(buf.validate.field).string.max_len = 5]; - string quiet_hours_end = 14 [(buf.validate.field).string.max_len = 5]; - uint32 max_daily_notifications = 15 [(buf.validate.field).uint32.lte = 24]; - WorkspaceSettingsCapability update_capability = 16; -} - -message WorkspaceSettingsNotifications { - string status = 1; - repeated WorkspaceSettingsNotificationPreference preferences = 2; - WorkspaceSettingsAvailabilityStatus status_enum = 3; - WorkspaceSpendBeatSettings spend_beat = 4; -} - -message WorkspaceSettingsIdentityProvider { - string id = 1; - string name = 2; - string detail = 3; - string status = 4; - WorkspaceSettingsCapability configure_capability = 5; - string source = 6; - WorkspaceSettingsIdentityProviderStatus status_enum = 7; - WorkspaceSettingsSource source_enum = 8; -} - -message WorkspaceSettingsIntegration { - string id = 1; - string name = 2; - string provider = 3; - string category = 4; - string detail = 5; - string status = 6; - WorkspaceSettingsCapability configure_capability = 7; - string source = 8; - WorkspaceSettingsIntegrationStatus status_enum = 9; - WorkspaceSettingsSource source_enum = 10; -} - -message WorkspaceSettingsOwnerStatus { - string id = 1; - string label = 2; - string owner_service = 3; - string status = 4; - string summary = 5; - repeated string settings = 6; - WorkspaceSettingsCapability capability = 7; - google.protobuf.Timestamp checked_at = 8; - WorkspaceSettingsOwnerServiceStatus status_enum = 9; -} - -message WorkspaceSettingsBreakGlassGrant { - string id = 1; - string organization_id = 2; - string workspace_id = 3; - string customer_approved_by = 4; - string reason = 5; - string support_user_email = 6; - bool read_only = 7; - google.protobuf.Timestamp enabled_at = 8; - google.protobuf.Timestamp disabled_at = 9; - WorkspaceSettingsCapability manage_capability = 10; - google.protobuf.Timestamp expires_at = 11; -} - -enum StaffWorkspaceAccessState { - STAFF_WORKSPACE_ACCESS_STATE_UNSPECIFIED = 0; - STAFF_WORKSPACE_ACCESS_STATE_DIRECTORY_ONLY = 1; - STAFF_WORKSPACE_ACCESS_STATE_ACTIVE_READ_ONLY = 2; - STAFF_WORKSPACE_ACCESS_STATE_EXPIRED = 3; - STAFF_WORKSPACE_ACCESS_STATE_GRANT_MISMATCH = 4; - STAFF_WORKSPACE_ACCESS_STATE_UNAVAILABLE = 5; -} - -message StaffContextCapability { - bool available = 1; - string reason = 2; -} -message SearchStaffWorkspaceDirectoryRequest { - string query = 1 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; - int32 limit = 2 [(buf.validate.field).int32 = { - gte: 1 - lte: 25 - }]; -} -message StaffWorkspaceDirectoryEntry { - string organization_id = 1; - string workspace_id = 2; - string organization_name = 3; - string workspace_name = 4; - string region = 5; - string environment = 6; - StaffWorkspaceAccessState access_state = 7; -} -message SearchStaffWorkspaceDirectoryResponse { - // Capped at 25 entries. - repeated StaffWorkspaceDirectoryEntry entries = 1; -} -message GetStaffWorkspaceContextRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; -} -message StaffGrantEventSummary { - string grant_id = 1; - string action = 2; - google.protobuf.Timestamp occurred_at = 3; - google.protobuf.Timestamp expires_at = 4; -} -message StaffReceiptSummary { - string id = 1; - string kind = 2; - string status = 3; - string summary = 4; - google.protobuf.Timestamp created_at = 5; -} -message StaffTraceSummary { - string trace_id = 1; - string summary = 2; - string status = 3; - google.protobuf.Timestamp occurred_at = 4; -} -message StaffFailureSummary { - string event_id = 1; - string category = 2; - string safe_summary = 3; - google.protobuf.Timestamp occurred_at = 4; -} -message StaffComputerEnvironment { - string provider = 1; - string region = 2; - string lifecycle_state = 3; -} -message StaffWorkspaceContext { - StaffWorkspaceAccessState access_state = 1; - // Each collection is newest-first and capped at 25. - repeated StaffGrantEventSummary grant_events = 2; - repeated StaffReceiptSummary receipts = 3; - repeated StaffTraceSummary traces = 4; - repeated StaffFailureSummary failures = 5; - StaffComputerEnvironment computer_environment = 6; - StaffContextCapability grant_events_capability = 7; - StaffContextCapability receipts_capability = 8; - StaffContextCapability traces_capability = 9; - StaffContextCapability failures_capability = 10; - StaffContextCapability computer_environment_capability = 11; - string active_grant_approver = 12; - google.protobuf.Timestamp active_grant_expires_at = 13; -} -message GetStaffWorkspaceContextResponse { - StaffWorkspaceContext context = 1; -} - -// ManagedProviderAccessGrant is the durable, staff-owned entitlement that lets -// an organization resolve the platform-managed provider fallback after a BYOK -// miss. Absent or disabled rows are default-deny. -enum ManagedProviderAccessState { - MANAGED_PROVIDER_ACCESS_STATE_UNSPECIFIED = 0; - MANAGED_PROVIDER_ACCESS_STATE_ACTIVE = 1; - MANAGED_PROVIDER_ACCESS_STATE_SUSPENDED = 2; - MANAGED_PROVIDER_ACCESS_STATE_REVOKED = 3; - MANAGED_PROVIDER_ACCESS_STATE_EXPIRED = 4; -} -message ManagedProviderAccessGrant { - string organization_id = 1; - string provider = 2; - string environment = 3; - bool enabled = 4; - string granted_by = 5; - string note = 6; - google.protobuf.Timestamp created_at = 7; - google.protobuf.Timestamp updated_at = 8; - string grant_id = 9; - uint64 revision = 10; - ManagedProviderAccessState state = 11; - google.protobuf.Timestamp expires_at = 12; - string gateway_sync_outcome = 13; - // Explicit durable enrollment; no expiry. Legacy grants remain bounded. - bool durable_enrollment = 14; - // Authorized workspace used for owner synchronization; enrollment remains organization-wide. - string workspace_id = 15; -} -message ListManagedProviderAccessGrantsRequest { - // Optional organization filter; empty returns every grant. - string organization_id = 1; -} -message ListManagedProviderAccessGrantsResponse { - repeated ManagedProviderAccessGrant grants = 1; - // False when no gateway sync target is configured; the console then shows an - // explicit unavailable-capability state instead of a live enable control. - bool gateway_sync_available = 2; -} -message UpsertManagedProviderAccessGrantRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string provider = 2 [(buf.validate.field).string.min_len = 1]; - string environment = 3 [(buf.validate.field).string.min_len = 1]; - bool enabled = 4; - // Required audit note recorded with every enable/disable action. - string note = 5 [(buf.validate.field).string = { - min_len: 1 - max_len: 512 - }]; - // Zero creates a new grant; updates must present the current revision. - uint64 expected_revision = 6; - ManagedProviderAccessState state = 7; - // Legacy grants retain a bounded expiry. Mutually exclusive with durable_enrollment. - google.protobuf.Timestamp expires_at = 8; - // Explicit staff-authorized enrollment independent of execution-token lifetime. - bool durable_enrollment = 9; - // Required for durable enrollment. Persisted for exact-tenant synchronization retries. - string workspace_id = 10; -} -message UpsertManagedProviderAccessGrantResponse { - ManagedProviderAccessGrant grant = 1; -} -message RevokeManagedProviderAccessGrantRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string provider = 2 [(buf.validate.field).string.min_len = 1]; - string environment = 3 [(buf.validate.field).string.min_len = 1]; - // Required audit note recorded with the disable action. - string note = 4 [(buf.validate.field).string = { - min_len: 1 - max_len: 512 - }]; - uint64 expected_revision = 5; -} -message RevokeManagedProviderAccessGrantResponse { - ManagedProviderAccessGrant grant = 1; -} - -// InferenceProviderTarget is one deployment-approved provider/model pair. -// Provider identity is canonicalized through model-provider-core. -message InferenceProviderTarget { - string provider = 1; - string model = 2; - string display_name = 3; - repeated string capabilities = 4; - uint64 context_window_tokens = 5; - string pricing_tier = 6; - string latency_tier = 7; - repeated string regions = 8; - bool ready = 9; - string unavailable_reason = 10; -} - -// StaffInferenceRoutingPurpose identifies a bounded Dex workload class. The -// server, not the browser, maps call sites to these purposes. -enum StaffInferenceRoutingPurpose { - STAFF_INFERENCE_ROUTING_PURPOSE_UNSPECIFIED = 0; - STAFF_INFERENCE_ROUTING_PURPOSE_DEFAULT_CHAT = 1; - STAFF_INFERENCE_ROUTING_PURPOSE_FAST_CHEAP = 2; - STAFF_INFERENCE_ROUTING_PURPOSE_DEEP_REASONING = 3; - STAFF_INFERENCE_ROUTING_PURPOSE_CODING = 4; - STAFF_INFERENCE_ROUTING_PURPOSE_EVALUATION = 5; -} - -message StaffInferencePurposeRoute { - StaffInferenceRoutingPurpose purpose = 1; - InferenceProviderTarget primary_target = 2; - // Optional deterministic canary target for this purpose. - InferenceProviderTarget canary_target = 3; - uint32 canary_percent = 4; -} - -// StaffInferenceRoutingProfile is the durable Dex inference override for the -// single server-configured STAFF organization. -message StaffInferenceRoutingProfile { - string organization_id = 1; - string provider = 2; - string model = 3; - uint64 revision = 4; - string updated_by = 5; - string note = 6; - google.protobuf.Timestamp updated_at = 7; - repeated StaffInferencePurposeRoute routes = 8; - bool uses_deployment_default = 9; -} - -message StaffInferenceRoutingEvent { - uint64 revision = 1; - repeated StaffInferencePurposeRoute routes = 2; - bool uses_deployment_default = 3; - string actor_principal_id = 4; - string note = 5; - string action = 6; - google.protobuf.Timestamp occurred_at = 7; -} - -message GetStaffInferenceRoutingProfileRequest {} - -message GetStaffInferenceRoutingProfileResponse { - string organization_id = 1; - repeated InferenceProviderTarget available_targets = 2; - InferenceProviderTarget default_target = 3; - InferenceProviderTarget effective_target = 4; - // Absent until staff persists an explicit override. - StaffInferenceRoutingProfile profile = 5; - repeated StaffInferenceRoutingEvent recent_events = 6; - repeated StaffInferencePurposeRoute effective_routes = 7; -} - -message UpdateStaffInferenceRoutingProfileRequest { - string provider = 1; - string model = 2; - uint64 expected_revision = 3; - string note = 4 [(buf.validate.field).string = { - min_len: 1 - max_len: 512 - }]; - StaffInferenceRoutingPurpose purpose = 5; - // Reset every purpose to the deployment default while retaining revisioned - // audit history. - bool reset_to_default = 6; - string canary_provider = 7; - string canary_model = 8; - uint32 canary_percent = 9 [(buf.validate.field).uint32.lte = 50]; - // Restore the complete snapshot recorded at this prior revision. - uint64 rollback_revision = 10; -} - -message UpdateStaffInferenceRoutingProfileResponse { - StaffInferenceRoutingProfile profile = 1 [(buf.validate.field).required = true]; - InferenceProviderTarget effective_target = 2 [(buf.validate.field).required = true]; -} - -message ListScenarioFixturesRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - repeated string tags = 3; - int32 limit = 4 [(buf.validate.field).int32 = { - gte: 0 - lte: 500 - }]; - int32 offset = 5 [(buf.validate.field).int32.gte = 0]; -} - -message ListScenarioFixturesResponse { - repeated ScenarioFixture fixtures = 1; - int32 total = 2 [(buf.validate.field).int32.gte = 0]; - bool has_more = 3; -} - -message PromoteScenarioFixtureRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string name = 3 [(buf.validate.field).string.min_len = 1]; - string scenario_json = 4 [(buf.validate.field).string.min_len = 1]; - string recorded_from_session_id = 5; - string original_model = 6; - string retention_policy = 7; - repeated string tags = 8; -} - -message PromoteScenarioFixtureResponse { - ScenarioFixture fixture = 1; -} - -message CompareScenarioFixturesRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string base_fixture_id = 3 [(buf.validate.field).string.min_len = 1]; - string target_fixture_id = 4 [(buf.validate.field).string.min_len = 1]; - int32 max_differences = 5 [(buf.validate.field).int32 = { - gte: 0 - lte: 100 - }]; -} - -message CompareScenarioFixturesResponse { - ScenarioFixture base_fixture = 1; - ScenarioFixture target_fixture = 2; - int32 shared_prefix_frames = 3 [(buf.validate.field).int32.gte = 0]; - int32 base_frame_count = 4 [(buf.validate.field).int32.gte = 0]; - int32 target_frame_count = 5 [(buf.validate.field).int32.gte = 0]; - string first_divergence_path = 6; - string first_divergence_summary = 7; - repeated ScenarioFixtureDifference differences = 8; -} - -message ScenarioFixtureDifference { - string path = 1; - string kind = 2; - string base_value = 3; - string target_value = 4; - string summary = 5; -} - -message ScenarioFixture { - string id = 1; - string organization_id = 2; - string workspace_id = 3; - string name = 4; - string recorded_from_session_id = 5; - google.protobuf.Timestamp recorded_at = 6; - string original_model = 7; - int32 tool_count = 8 [(buf.validate.field).int32.gte = 0]; - int32 frame_count = 9 [(buf.validate.field).int32.gte = 0]; - string gcs_path = 10; - string retention_policy = 11; - repeated string tags = 12; - google.protobuf.Timestamp created_at = 13; - google.protobuf.Timestamp updated_at = 14; -} - -message ConsoleMetric { - string id = 1; - string label = 2; - string value = 3; - string unit = 4; - string detail = 5; - string trend = 6; - string tone = 7; -} - -message AiAsset { - string id = 1; - string name = 2; - string asset_type = 3; - string owner = 4; - string team_id = 5; - string environment = 6; - string source = 7; - string status = 8; - common.v1.RiskLevel risk_level = 9; - string policy_state = 10; - double spend_usd = 11 [(buf.validate.field).double.gte = 0]; - int64 request_count = 12 [(buf.validate.field).int64.gte = 0]; - int64 error_count = 13 [(buf.validate.field).int64.gte = 0]; - int64 latency_p95_ms = 14 [(buf.validate.field).int64.gte = 0]; - google.protobuf.Timestamp last_seen_at = 15; - repeated string tags = 16; - repeated RelatedResource related_resources = 17; -} - -message ActivityEvent { - string id = 1; - string event_type = 2; - string title = 3; - string detail = 4; - string asset_id = 5; - string agent_id = 6; - string trace_id = 7; - string approval_id = 8; - string actor = 9; - string status = 10; - common.v1.RiskLevel risk_level = 11; - double cost_usd = 12 [(buf.validate.field).double.gte = 0]; - google.protobuf.Timestamp occurred_at = 13; - repeated RelatedResource related_resources = 14; -} - -message EvalResult { - string id = 1; - string trace_id = 2; - string asset_id = 3; - string suite_id = 4; - string scorer = 5; - double score = 6 [(buf.validate.field).double = { - gte: 0 - lte: 1 - }]; - double threshold = 7 [(buf.validate.field).double = { - gte: 0 - lte: 1 - }]; - string status = 8; - common.v1.RiskLevel risk_level = 9; - string model = 10; - string provider = 11; - double quality_per_dollar = 12 [(buf.validate.field).double.gte = 0]; - string detail = 13; - google.protobuf.Timestamp occurred_at = 14; - repeated RelatedResource related_resources = 15; -} - -message CostUsage { - string id = 1; - string trace_id = 2; - string asset_id = 3; - string provider = 4; - string model = 5; - double spend_usd = 6 [(buf.validate.field).double.gte = 0]; - int64 input_tokens = 7 [(buf.validate.field).int64.gte = 0]; - int64 output_tokens = 8 [(buf.validate.field).int64.gte = 0]; - int64 request_count = 9 [(buf.validate.field).int64.gte = 0]; - int64 latency_ms = 10 [(buf.validate.field).int64.gte = 0]; - string status = 11; - common.v1.RiskLevel risk_level = 12; - string detail = 13; - google.protobuf.Timestamp occurred_at = 14; - repeated RelatedResource related_resources = 15; - int64 spend_micros = 16 [(buf.validate.field).int64.gte = 0]; - string project_id = 17; - string repository = 18; - string team_id = 19; - string owner_id = 20; - string run_id = 21; - string attribution_trace_id = 22; - string request_id = 23; - string deployment_id = 24; - string job_id = 25; - string source_health = 26; - string pricing_version = 27; - google.protobuf.Timestamp ingested_at = 28; - // record_kind distinguishes atomic usage events from provider-owned aggregate - // snapshots. Consumers use provider snapshots as authoritative totals rather - // than summing them with overlapping gateway events. - string record_kind = 29; - // Provider-reported spend for the current UTC day when record_kind is a - // provider_monthly_snapshot. The monthly total remains spend_micros. - int64 spend_today_micros = 30 [(buf.validate.field).int64.gte = 0]; - // Model provider selected behind the billing source, when the source - // reports that distinction. - string upstream_provider = 31; - // Join quality for provider-reported rows: exact, aggregate, estimated, or - // unmatched. - string provenance = 32; - // Cached-read and cache-write portions of input_tokens, when the source - // reports them separately. These values are already included in input_tokens. - int64 cache_read_tokens = 33 [(buf.validate.field).int64.gte = 0]; - int64 cache_write_tokens = 34 [(buf.validate.field).int64.gte = 0]; - // Cost and usage evidence origins retained from the durable ledger. - string pricing_source = 35; - string usage_source = 36; -} - -message AuthorityLedger { - string id = 1; - string trace_id = 2; - string span_id = 3; - string action_id = 4; - string approval_id = 5; - string cost_row_id = 6; - string agent_id = 7; - string agent_name = 8; - string run_as_identity = 9; - string tool_id = 10; - string tool_name = 11; - string connector_id = 12; - string connector_name = 13; - string connector_provider = 14; - string credential_ref = 15; - string grant_lease_id = 16; - string authority_id = 17; - string authority_label = 18; - // authority_type is a product category such as credential, connector_grant, - // service_account, browser_session, runner_lease, or unknown. - string authority_type = 19; - string authority_scope = 20; - string issuer = 21; - google.protobuf.Timestamp expires_at = 22; - // authority_state is one of active, expired, revoked, missing, or unknown. - string authority_state = 23; - // attestation_state is one of attested, unverified, missing, or unknown. - string attestation_state = 24; - string attestation_summary = 25; - // trust_state is one of trusted, needs_review, unverified, blocked, or unknown. - string trust_state = 26; - // evidence_state is one of ready, pending, missing, warning, blocked, or unknown. - string evidence_state = 27; - string evidence_source = 28; - string cost_posture = 29; - double cost_usd = 30 [(buf.validate.field).double.gte = 0]; - int64 input_tokens = 31 [(buf.validate.field).int64.gte = 0]; - int64 output_tokens = 32 [(buf.validate.field).int64.gte = 0]; - string status = 33; - string policy_reason = 34; - repeated string required_evidence = 35; - common.v1.RiskLevel risk_level = 36; - string detail = 37; - string next_action = 38; - google.protobuf.Timestamp occurred_at = 39; - repeated AuthorityScopeLedger scope_ledger = 40; - repeated AuthorityMissingEvidence missing_evidence = 41; - repeated AuthorityDeniedAction denied_actions = 42; - repeated RelatedResource evidence_refs = 43; - repeated SecurityDecisionEvidenceGap evidence_gaps = 44; -} - -message AuthorityScopeLedger { - string group = 1; - repeated string granted = 2; - repeated string exercised = 3; - repeated string denied = 4; - repeated string missing = 5; - string state = 6; - string policy_reason = 7; - repeated string required_evidence = 8; -} - -message AuthorityMissingEvidence { - string id = 1; - string label = 2; - string state = 3; - string owner = 4; - string recovery_action = 5; - string reason = 6; - string source = 7; - repeated string span_ids = 8; -} - -message AuthorityDeniedAction { - string id = 1; - string action_id = 2; - string tool_name = 3; - string policy_reason = 4; - repeated string required_evidence = 5; - repeated RelatedResource evidence_refs = 6; -} - -message AgentWorkforceRecord { - string id = 1; - string workspace_id = 2; - string organization_id = 3; - string agent_id = 4; - string agent_name = 5; - string runtime = 6; - string owner = 7; - // status is one of approval_ready, needs_evidence, needs_review, blocked, or observed. - string status = 8; - string queue_state = 9; - common.v1.RiskLevel risk_level = 10; - string current_work = 11; - RunAsIdentitySummary run_as_identity = 12; - SecurityDecisionPacket security_decision = 13; - repeated AgentWorkforceActionEvidence action_evidence = 14; - CredentialAuthoritySummary credential_authority = 15; - CostEvidenceSummary cost_evidence = 16; - string next_action = 17; - repeated string missing_evidence = 18; - google.protobuf.Timestamp occurred_at = 19; - AgentWorkforceDebugIdentifiers debug_identifiers = 20; - AgentWorkforceQuestionSummary question_summary = 21; - AgentWorkforceApprovalDisablement approval_disablement = 22; - EndpointGuardrailSummary endpoint_guardrail = 23; - AgentWorkforceProofSummary proof_summary = 24; - // approval_queue_state is one of approval_ready, approval_blocked, - // needs_credential_evidence, needs_run_as_identity, - // needs_cost_evidence, needs_action_evidence, security_review_required, - // native_observed_only, or needs_evidence. - string approval_queue_state = 25; - repeated AgentWorkforceActionAuthorityBoundary action_authority_boundaries = 26; - // source_readiness is the server-owned readiness projection for the - // collector/source paths that contributed observations or proof. Status is - // one of configured, observing, proof_joined, approval_ready, or blocked. - repeated AgentWorkforceSourceReadiness source_readiness = 27; -} - -message AgentWorkforceSourceReadiness { - // source is one of maestro, codex, claude_code, cursor, external, - // llm_gateway, meter, credential_authority, identity, customer_mcp, - // hook_otlp, desktop_sidecar, local_sidecar, external_agent, - // external_self_report, cerebro, nimbus, or unknown. - string source = 1; - string collector = 2; - string status = 3; - string proof_strength = 4; - string detail = 5; - string blocking_reason = 6; - bool approval_authority = 7; - bool trusted_metadata_only = 8; - repeated string missing_proof = 9; - repeated string join_keys = 10; - repeated RelatedResource evidence_refs = 11; -} - -message AgentWorkforceProofSummary { - string principal_evidence_state = 1; - string credential_evidence_state = 2; - string cost_evidence_state = 3; - string action_evidence_state = 4; - string endpoint_guardrail_state = 5; - bool approval_ready = 6; - repeated string blocking_reasons = 7; - repeated RelatedResource evidence_refs = 8; -} - -message AgentWorkforceApprovalQueueSummary { - int32 total_records = 1 [(buf.validate.field).int32.gte = 0]; - repeated AgentWorkforceApprovalStateBucket state_buckets = 2; - repeated AgentWorkforceApprovalBlockerBucket blocker_buckets = 3; - repeated AgentWorkforceMissingEvidenceBucket missing_evidence_buckets = 4; -} - -message AgentWorkforceApprovalStateBucket { - string state = 1; - string label = 2; - int32 count = 3 [(buf.validate.field).int32.gte = 0]; - string next_action = 4; -} - -message AgentWorkforceApprovalBlockerBucket { - string code = 1; - string label = 2; - string detail = 3; - string recovery_action = 4; - int32 count = 5 [(buf.validate.field).int32.gte = 0]; -} - -message AgentWorkforceActionAuthorityBoundary { - string action_label = 1; - string approval_queue_state = 2; - string authority_subject = 3; - string credential_provider = 4; - string unproven_boundary = 5; - string next_action = 6; -} - -message AgentWorkforceMissingEvidenceBucket { - string label = 1; - string recovery_action = 2; - int32 count = 3 [(buf.validate.field).int32.gte = 0]; -} - -message EndpointGuardrailSummary { - // status is one of allowed, missing, blocked, or unknown. - string status = 1; - string endpoint_id = 2; - string route = 3; - string exposure = 4; - string allowlist_source = 5; - string resolution_policy = 6; - string blocked_reason = 7; - repeated string missing_controls = 8; - repeated RelatedResource evidence_refs = 9; - string allowlist_status = 10; - string resolution_status = 11; -} - -message AgentWorkforceQuestionSummary { - string can_approve_this = 1; - string evidence_missing = 2; - string agent_saw = 3; - string agent_tried_to_do = 4; - string was_denied = 5; - string should_do_next = 6; -} - -message AgentWorkforceApprovalDisablement { - // code is one of none, missing_credential_authority, - // unverified_run_as_identity, missing_cost_evidence, - // missing_action_evidence, security_decision_blocked, or - // security_review_required. - string code = 1; - string label = 2; - string detail = 3; - string recovery_action = 4; - repeated string evidence_gap_ids = 5; - repeated RelatedResource evidence_refs = 6; -} - -message RunAsIdentitySummary { - // status is one of verified, unverified, missing, or unknown. - string status = 1; - string identity = 2; - string source = 3; - string missing_reason = 4; - repeated RelatedResource evidence_refs = 5; -} - -message AgentWorkforceActionEvidence { - string action_id = 1; - string tool_name = 2; - string connector_id = 3; - string capability = 4; - string target_summary = 5; - string decision = 6; - bool mutates_resource = 7; - common.v1.RiskLevel risk_level = 8; - string safe_arguments_ref = 9; - repeated RelatedResource evidence_refs = 10; - repeated string missing_evidence = 11; - google.protobuf.Timestamp occurred_at = 12; - string principal_evidence_state = 13; - string credential_evidence_state = 14; - string cost_evidence_state = 15; -} - -message CredentialAuthoritySummary { - // status is one of verified, unverified, missing, revoked, expired, or blocked. - string status = 1; - string subject = 2; - string provider = 3; - string authority_ref = 4; - google.protobuf.Timestamp expires_at = 5; - string revocation_state = 6; - repeated string missing_authorities = 7; - repeated RelatedResource evidence_refs = 8; -} - -message CostEvidenceSummary { - // status is one of recorded or missing. - string status = 1; - string provider = 2; - string model = 3; - int64 input_tokens = 4 [(buf.validate.field).int64.gte = 0]; - int64 output_tokens = 5 [(buf.validate.field).int64.gte = 0]; - double total_cost_usd = 6 [(buf.validate.field).double.gte = 0]; - string meter_ref = 7; - string missing_reason = 8; -} - -message AgentWorkforceDebugIdentifiers { - repeated string span_ids = 1; - repeated string raw_reference_ids = 2; - repeated string source_event_ids = 3; - google.protobuf.Struct attributes = 4; - string run_id = 5; - string session_id = 6; - string trace_id = 7; -} - -message RiskFinding { - string id = 1; - string title = 2; - string detail = 3; - string source = 4; - string asset_id = 5; - string status = 6; - common.v1.RiskLevel risk_level = 7; - string policy = 8; - string next_action = 9; - google.protobuf.Timestamp detected_at = 10; -} - -// IntegrationCredentialField describes the credential reference slots Console -// can ask a workspace admin to provide for an integration. Values submitted for -// these fields must be secret references, not raw credential material. -message IntegrationCredentialField { - string name = 1; - string label = 2; - bool required = 3; - bool secret = 4; - repeated string accepted_reference_schemes = 5; - string credential_type = 6; -} - -// IntegrationResourceType is safe catalog discovery metadata for one provider -// resource family. source_* fields preserve the imported source taxonomy and -// projection intent; they do not claim a canonical or implemented Mono mapping. -message IntegrationResourceType { - string id = 1; - string display_name = 2; - repeated string source_coverage_types = 3; - string source_projection_template = 4; - string event_kind = 5; -} - -message IntegrationTile { - string id = 1; - string name = 2; - string provider = 3; - string category = 4; - string status = 5; - string detail = 6; - string setup_command = 7; - repeated string scopes = 8; - repeated string capabilities = 9; - google.protobuf.Timestamp last_seen_at = 10; - repeated string catalog_categories = 11; - bool runtime_executable = 12; - repeated string resource_families = 13; - string verification_endpoint = 14; - // lifecycle_stage is the durable source lifecycle projection rendered by the - // Sources UI: needs_setup, authorizing, syncing, connected, degraded, - // reconnect_required, needs_operator_config, disabled, etc. - string lifecycle_stage = 15; - repeated string required_scopes = 16; - repeated string optional_scopes = 17; - repeated string missing_scopes = 18; - string sync_status = 19; - google.protobuf.Timestamp last_sync_at = 20; - google.protobuf.Timestamp next_sync_at = 21; - int32 last_sync_duration_ms = 22 [(buf.validate.field).int32.gte = 0]; - int32 synced_item_count = 23 [(buf.validate.field).int32.gte = 0]; - string sync_error = 24; - string install_authority = 25; - string operator_config_status = 26; - string auth_type = 27; - bool oauth_supported = 28; - repeated IntegrationCredentialField credential_fields = 29; - connectors.v1.ConnectorCatalogProvenance catalog_provenance = 30; - // catalog_tier is the connector catalog owner's shape-derived tier. Console - // carries it verbatim and never promotes a provider's readiness. - string catalog_tier = 31; - // provider_actions names the typed runtime actions exposed by the published - // provider. Together with resource_families this distinguishes sync, - // action-only, and combined providers without inferring support from labels. - repeated string provider_actions = 32; - // catalog_status is either ready (published and connectable) or - // qualification_pending (installed preview, not connectable). - string catalog_status = 33; - bool setup_allowed = 34; - bool configured = 35; - int32 provider_action_count = 36 [(buf.validate.field).int32.gte = 0]; - int32 resource_family_count = 37 [(buf.validate.field).int32.gte = 0]; - int32 required_family_count = 38 [(buf.validate.field).int32.gte = 0]; - int32 qualified_family_count = 39 [(buf.validate.field).int32.gte = 0]; - string rollout_kind = 40; - repeated IntegrationResourceType resource_types = 41; - string provider_description = 42; -} - -message OnboardingTask { - string id = 1; - string title = 2; - string detail = 3; - string status = 4; - string cta_label = 5; - string command = 6; - repeated string required_integrations = 7; -} - -message TraceDrilldown { - string trace_id = 1; - string root_name = 2; - string asset_id = 3; - string status = 4; - int64 total_latency_ms = 5 [(buf.validate.field).int64.gte = 0]; - int64 input_tokens = 6 [(buf.validate.field).int64.gte = 0]; - int64 output_tokens = 7 [(buf.validate.field).int64.gte = 0]; - double cost_usd = 8 [(buf.validate.field).double.gte = 0]; - double eval_score = 9 [(buf.validate.field).double.gte = 0]; - common.v1.RiskLevel risk_level = 10; - repeated TraceSpan spans = 11; - google.protobuf.Timestamp occurred_at = 12; - repeated traces.v1.TraceAnnotation annotations = 13; - repeated string suggested_labels = 14; - // evidence_source names the backing read path used for this drilldown - // ("traces-store", "console-snapshot", etc.) so the UI can distinguish a - // live trace lookup from a stale projection. - string evidence_source = 15; - // completeness_signals explain which evidence families are present, pending, - // or broken for the trace. They are product-facing diagnostics, not raw test - // failures. - repeated TraceCompletenessSignal completeness_signals = 16; - // security_decision_packet is the server-owned answer to the operator - // question "Can I approve this?" It joins governance, approval readiness, - // risk, and missing evidence so clients do not infer approval state from - // labels or text matching. - SecurityDecisionPacket security_decision_packet = 17; -} - -message TraceSpan { - string span_id = 1; - string parent_span_id = 2; - string name = 3; - string kind = 4; - string model = 5; - string provider = 6; - string status = 7; - int64 latency_ms = 8 [(buf.validate.field).int64.gte = 0]; - double cost_usd = 9 [(buf.validate.field).double.gte = 0]; - int64 input_tokens = 10 [(buf.validate.field).int64.gte = 0]; - int64 output_tokens = 11 [(buf.validate.field).int64.gte = 0]; - string governance_decision = 12; - google.protobuf.Timestamp started_at = 13; - google.protobuf.Timestamp ended_at = 14; - google.protobuf.Struct attributes = 15; - repeated TraceSpanReference references = 16; -} - -message TraceSpanReference { - string id = 1; - string resource_type = 2; - string label = 3; - string url = 4; -} - -message TraceCompletenessSignal { - string id = 1; - string title = 2; - string detail = 3; - // status is one of ready, pending, warning, or blocked. - string status = 4; - repeated string span_ids = 5; -} - -message SecurityDecisionPacket { - string id = 1; - string question = 2; - // verdict is one of ready_to_approve, needs_review, needs_evidence, or blocked. - string verdict = 3; - // approval_state is one of approved, pending, denied, not_required, or unknown. - string approval_state = 4; - string governance_decision = 5; - common.v1.RiskLevel risk_level = 6; - string summary = 7; - string next_action = 8; - repeated string blocking_reasons = 9; - repeated SecurityDecisionEvidenceGap evidence_gaps = 10; - repeated RelatedResource evidence_refs = 11; -} - -message SecurityDecisionEvidenceGap { - string id = 1; - string label = 2; - string state = 3; - string reason = 4; - string source = 5; - repeated string span_ids = 6; -} - -message RelatedResource { - string id = 1; - string resource_type = 2; - string label = 3; - string url = 4; -} - -message OperatingHomepageSuggestion { - string schema = 1 [(buf.validate.field).string.const = "dex.homepage_suggestion.v1"]; - string label = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 160 - }]; - string prompt = 3 [(buf.validate.field).string = { - min_len: 1 - max_len: 1000 - }]; - string source = 4 [(buf.validate.field).string.const = "cerebro"]; - repeated RelatedResource evidence_refs = 5 [(buf.validate.field).repeated.max_items = 8]; - google.protobuf.Timestamp generated_at = 6 [(buf.validate.field).required = true]; - google.protobuf.Timestamp expires_at = 7 [(buf.validate.field).required = true]; - // Short model-generated topic title grounded in the same cited evidence as - // the memory line. Absent when the model abstains or validation fails. - string title = 8 [(buf.validate.field).string = { - min_len: 1 - max_len: 60 - }]; - string suggestion_id = 9 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; -} - -// DexMcpServer is the redacted Console projection of a governed MCP endpoint. -// Secrets are write-only; callers can only observe whether one is configured. -// Credential, OAuth, and connector values are owner reference identities; no -// credential material ever appears on this projection. -message DexMcpServer { - string server_id = 1; - string name = 2; - string base_url = 3; - string transport = 4; - string auth_kind = 5; - bool has_token = 6; - bool enabled = 7; - google.protobuf.Timestamp created_at = 8; - google.protobuf.Timestamp updated_at = 9; - string created_by = 10; - string updated_by = 11; - // Negotiated MCP protocol version from the latest discovery. - string protocol_version = 12; - // Last observed health state from the owning discovery store. - string health_state = 13; - // Digest of the latest persisted catalog snapshot. - string catalog_digest = 14; - // Secret reference identity for the configured credential, if any. - string credential_ref = 15; - // OAuth connection reference identity owned by the Connector owner. - string oauth_connection_ref = 16; - // Private connector session reference identity used for routing, if any. - string connector_ref = 17; - // Monotonic version of the latest immutable catalog snapshot. - uint64 catalog_snapshot_version = 18; - // Time the latest endpoint discovery completed. - google.protobuf.Timestamp catalog_discovered_at = 19; - // True when discovery returned bounded warnings or an incomplete catalog. - bool catalog_partial = 20; - // Bounded, display-safe discovery warnings. Raw upstream text is omitted. - repeated string discovery_warnings = 21; - // Redacted tool metadata from the latest immutable catalog snapshot. - repeated DexMcpCatalogTool catalog_tools = 22; - uint32 catalog_prompt_count = 23; - uint32 catalog_resource_count = 24; - // Route state is an owner projection. It never includes credentials or - // claims that a cloud endpoint is deployed beyond the verified evidence. - bool private_route_required = 25; - string private_endpoint_id = 26; - string private_route_state = 27; - string private_route_identity = 28; - uint64 private_route_revision = 29; - string private_route_origin = 30; - // Redacted OAuth profile projection for auth_kind=oauth. These fields carry - // state, scopes, and version only; token material is never projected. - string oauth_profile_state = 31; - repeated string oauth_scopes = 32; - int64 oauth_scope_version = 33; - string oauth_runtime_reason_code = 34; - // CredentialDecision is a redacted readiness result from the existing - // managed-credential/OAuth grant owners. It is not permission and never - // contains credential material. - string credential_state = 35; - string credential_reason_code = 36; - string credential_binding = 37; - google.protobuf.Timestamp credential_observed_at = 38; - // Optional expiry supplied by the credential owner. Unset means the owner - // did not provide an expiry; clients must not infer one from this projection. - google.protobuf.Timestamp credential_expires_at = 39; - // RouteDecision is a connectivity/readiness result from the existing - // private endpoint and deployment egress owners. It never grants access. - string route_readiness_state = 40; - string route_reason_code = 41; - string route_binding = 42; - google.protobuf.Timestamp route_observed_at = 43; - // Optional expiry supplied by the route owner. Unset means the owner did - // not provide an expiry; clients must not infer one from this projection. - google.protobuf.Timestamp route_expires_at = 44; - string route_mode = 45; - string route_provider = 46; - // Credential-free external source authority from the Connector owner. An - // absent or UNKNOWN observation is unavailable; local connection activity - // never implies source sufficiency. - connectors.v1.SourceAuthorityObservation source_authority = 47; -} - -// DexMcpCatalogTool is the browser-safe review projection of one discovered -// tool. Schemas and arbitrary annotations remain in the immutable owner store. -message DexMcpCatalogTool { - string name = 1; - string title = 2; - string description = 3; - string upstream_version_identity = 4; -} - -message CreateDexMcpServerRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string name = 2 [(buf.validate.field).string.min_len = 1]; - string base_url = 3 [(buf.validate.field).string.min_len = 1]; - string auth_kind = 4; - string bearer_token = 5; - bool enabled = 6; -} - -message CreateDexMcpServerResponse { - DexMcpServer server = 1 [(buf.validate.field).required = true]; -} - -message ListDexMcpServersRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; -} - -message ListDexMcpServersResponse { - repeated DexMcpServer servers = 1; -} - -message GetDexMcpServerRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string server_id = 2 [(buf.validate.field).string.min_len = 1]; -} - -message GetDexMcpServerResponse { - DexMcpServer server = 1 [(buf.validate.field).required = true]; -} - -message DiscoverDexMcpServerRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string server_id = 2 [(buf.validate.field).string.min_len = 1]; -} - -message DiscoverDexMcpServerResponse { - DexMcpServer server = 1 [(buf.validate.field).required = true]; -} - -message UpdateDexMcpServerRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string server_id = 2 [(buf.validate.field).string.min_len = 1]; - optional string base_url = 3; - optional bool enabled = 4; - optional string bearer_token = 5; - bool clear_token = 6; -} - -message UpdateDexMcpServerResponse { - DexMcpServer server = 1 [(buf.validate.field).required = true]; -} - -message DeleteDexMcpServerRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string server_id = 2 [(buf.validate.field).string.min_len = 1]; -} - -message DeleteDexMcpServerResponse { - bool deleted = 1; -} - -// DexMcpOAuthProfile is a redacted projection. connection_ref is opaque and -// may be used only by the owner boundary; access and refresh tokens are never -// present in this message. -message DexMcpOAuthProfile { - string profile_id = 1; - string server_id = 2; - string profile_name = 3; - string subject_kind = 4; - string subject_id = 5; - string current_grant_id = 6; - string profile_state = 7; - repeated string scopes = 8; - int64 scope_version = 9; - bool enabled = 10; - bool is_default = 11; - google.protobuf.Timestamp created_at = 12; - google.protobuf.Timestamp updated_at = 13; - string runtime_state = 14; - string runtime_reason_code = 15; -} - -message InitiateDexMcpOAuthProfileRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string server_id = 2 [(buf.validate.field).string.min_len = 1]; - string profile_id = 3; - string profile_name = 4 [(buf.validate.field).string.min_len = 1]; - string subject_kind = 5 [(buf.validate.field).string.min_len = 1]; - string subject_id = 6; - string resource_url = 7 [(buf.validate.field).string.min_len = 1]; - repeated string scopes = 8; - string redirect_uri = 9 [(buf.validate.field).string.min_len = 1]; - string client_id = 10; - string client_secret_ref = 11; - bool is_default = 12; - string idempotency_key = 13; -} - -message InitiateDexMcpOAuthProfileResponse { - DexMcpOAuthProfile profile = 1 [(buf.validate.field).required = true]; - string authorize_url = 2; - string state = 3; - google.protobuf.Timestamp expires_at = 4; - string resource_metadata_url = 5; - string authorization_server = 6; - string client_id = 7; -} - -message CompleteDexMcpOAuthProfileRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string server_id = 2 [(buf.validate.field).string.min_len = 1]; - string profile_id = 3 [(buf.validate.field).string.min_len = 1]; - string state = 4 [(buf.validate.field).string.min_len = 1]; - // Empty code is permitted only for a provider error response; the - // Connector validates the raw iss binding before acting on any error text. - string code = 5; - string redirect_uri = 6 [(buf.validate.field).string.min_len = 1]; - string idempotency_key = 7 [(buf.validate.field).string.min_len = 1]; - int64 profile_generation = 8 [(buf.validate.field).int64.gt = 0]; - // Raw RFC 9207 authorization response fields forwarded unchanged to the - // Connector for validation. - string authorization_response_iss = 9; - string provider_error = 10; - string provider_error_description = 11; - string provider_error_uri = 12; -} - -message CompleteDexMcpOAuthProfileResponse { - DexMcpOAuthProfile profile = 1 [(buf.validate.field).required = true]; -} - -message ListDexMcpOAuthProfilesRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string server_id = 2; -} - -message ListDexMcpOAuthProfilesResponse { - repeated DexMcpOAuthProfile profiles = 1; -} - -message RevokeDexMcpOAuthProfileRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string server_id = 2 [(buf.validate.field).string.min_len = 1]; - string profile_id = 3 [(buf.validate.field).string.min_len = 1]; - string reason_code = 4 [(buf.validate.field).string.min_len = 1]; - int64 profile_generation = 5 [(buf.validate.field).int64.gt = 0]; -} - -message RevokeDexMcpOAuthProfileResponse { - DexMcpOAuthProfile profile = 1 [(buf.validate.field).required = true]; -} - -message ReauthorizeDexMcpOAuthProfileRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string server_id = 2 [(buf.validate.field).string.min_len = 1]; - string profile_id = 3 [(buf.validate.field).string.min_len = 1]; - repeated string scopes = 4; - string redirect_uri = 5 [(buf.validate.field).string.min_len = 1]; -} - -message ReauthorizeDexMcpOAuthProfileResponse { - DexMcpOAuthProfile profile = 1 [(buf.validate.field).required = true]; - string authorize_url = 2; - string state = 3; - google.protobuf.Timestamp expires_at = 4; - string resource_metadata_url = 5; - string authorization_server = 6; - string client_id = 7; -} - -message PrivateEndpoint { - string endpoint_id = 1 [(buf.validate.field).string.min_len = 1]; - string provider = 2 [(buf.validate.field).string.min_len = 1]; - string endpoint_uri = 3 [(buf.validate.field).string.min_len = 1]; - string service_name = 4 [(buf.validate.field).string.min_len = 1]; - string region = 5 [(buf.validate.field).string.min_len = 1]; - string dns_name = 6 [(buf.validate.field).string.min_len = 1]; - string relay_id = 7; - string state = 8 [(buf.validate.field).string.min_len = 1]; - string health_state = 9 [(buf.validate.field).string.min_len = 1]; - uint64 route_revision = 10 [(buf.validate.field).uint64.gte = 0]; - string route_identity = 11 [(buf.validate.field).string.min_len = 1]; - string verified_evidence_id = 12; - string revocation_reason = 13; - google.protobuf.Timestamp created_at = 14; - google.protobuf.Timestamp updated_at = 15; - google.protobuf.Timestamp revoked_at = 16; -} - -message PrivateProfileRoute { - string profile_id = 1 [(buf.validate.field).string.min_len = 1]; - string endpoint_id = 2; - string route_mode = 3 [(buf.validate.field).string.min_len = 1]; - bool require_private = 4; - uint64 route_revision = 5 [(buf.validate.field).uint64.gte = 0]; - string state = 6 [(buf.validate.field).string.min_len = 1]; - string route_identity = 7; - string route_origin = 8; - bool private_route = 9; -} - -message RegisterPrivateEndpointRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string endpoint_id = 2 [(buf.validate.field).string.min_len = 1]; - string provider = 3 [(buf.validate.field).string.min_len = 1]; - string endpoint_uri = 4 [(buf.validate.field).string.min_len = 1]; - string service_name = 5 [(buf.validate.field).string.min_len = 1]; - string region = 6 [(buf.validate.field).string.min_len = 1]; - string dns_name = 7 [(buf.validate.field).string.min_len = 1]; - string relay_id = 8; -} - -message RegisterPrivateEndpointResponse { - PrivateEndpoint endpoint = 1 [(buf.validate.field).required = true]; -} - -message VerifyPrivateEndpointRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string endpoint_id = 2 [(buf.validate.field).string.min_len = 1]; - // Retained for wire compatibility. The server ignores caller-supplied - // evidence until a server-owned attestor is configured. - string evidence_id = 3 [(buf.validate.field).string.min_len = 1]; - // Retained for wire compatibility; not trusted as proof. - string provider = 4 [(buf.validate.field).string.min_len = 1]; - // Retained for wire compatibility; not trusted as proof. - bool private_route_observed = 5; - bool dns_validated = 6; -} - -message VerifyPrivateEndpointResponse { - PrivateEndpoint endpoint = 1 [(buf.validate.field).required = true]; -} - -message ListPrivateEndpointsRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; -} - -message ListPrivateEndpointsResponse { - repeated PrivateEndpoint endpoints = 1; -} - -message DeletePrivateEndpointRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string endpoint_id = 2 [(buf.validate.field).string.min_len = 1]; - string reason_code = 3 [(buf.validate.field).string.min_len = 1]; -} - -message DeletePrivateEndpointResponse { - bool deleted = 1; - PrivateEndpoint endpoint = 2; -} - -message AttachPrivateEndpointToProfileRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string profile_id = 2 [(buf.validate.field).string.min_len = 1]; - string endpoint_id = 3; - string route_mode = 4 [(buf.validate.field).string.min_len = 1]; - bool require_private = 5; -} - -message AttachPrivateEndpointToProfileResponse { - PrivateProfileRoute route = 1 [(buf.validate.field).required = true]; -} - -message ListGatewayEgressOriginsRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; -} - -message ListGatewayEgressOriginsResponse { - repeated string origins = 1; - bool configured = 2; - string source = 3; -} - -message OperatingCapabilityRequirementState { - string service = 1; - string status = 2; - string reason_code = 3; - string remediation_ref = 4; -} - -message PrewarmOperatingThreadRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string channel_id = 2 [ - (buf.validate.field).string = { - min_len: 1 - max_len: 256 - }, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string idempotency_key = 3 [ - (buf.validate.field).string = { - min_len: 1 - max_len: 512 - }, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string model = 4 [ - (buf.validate.field).string.max_len = 256, - (common.v1.classification) = DATA_CLASSIFICATION_SAFE - ]; - string organization_id = 5 [ - (buf.validate.field).string.max_len = 256, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string workspace_id = 6 [ - (buf.validate.field).string.max_len = 256, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; -} - -message PrewarmOperatingThreadResponse { - string channel_id = 1; - string prewarm_id = 2; - string maestro_session_id = 3; - string runner_session_id = 4; - string runner_state = 5; - bool attachable = 6; - bool replayed = 7; - bool prewarm_hit = 8; - google.protobuf.Timestamp expires_at = 9; - string organization_id = 10; - string workspace_id = 11; - string thread_id = 12; - // True when a different requested draft was held behind the consumed - // first turn. The response still identifies the durable existing thread so - // the client can remain writable without silently minting another runner. - bool replenishment_blocked = 13; -} - -// TerminalErrorEnvelope is the browser-safe, provider-neutral classification -// of one terminal execution failure. retryable is observational metadata; it -// does not grant a caller permission to repeat work. -message TerminalErrorEnvelope { - uint32 schema_version = 1 [(buf.validate.field).uint32.const = 1]; - string kind = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; - string boundary = 3 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; - string code = 4 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; - bool retryable = 5; - string provider_request_id = 6 [(buf.validate.field).string.max_len = 256]; - string display_safe_message = 7 [(buf.validate.field).string = { - min_len: 1 - max_len: 4096 - }]; -} - -enum ThreadGatewayPermission { - THREAD_GATEWAY_PERMISSION_UNSPECIFIED = 0; - THREAD_GATEWAY_PERMISSION_SUBMIT = 1; - THREAD_GATEWAY_PERMISSION_WATCH = 2; - THREAD_GATEWAY_PERMISSION_INTERRUPT = 3; -} - -message BootstrapThreadGatewayRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string thread_id = 3 [(buf.validate.field).string.min_len = 1]; - repeated ThreadGatewayPermission permissions = 4 [(buf.validate.field).repeated = { - min_items: 1 - max_items: 3 - unique: true - items: { - enum: { - defined_only: true - not_in: [0] - } - } - }]; -} - -message BootstrapThreadGatewayResponse { - bool enabled = 1; - string endpoint = 2; - string access_token = 3; - google.protobuf.Timestamp expires_at = 4; - repeated ThreadGatewayPermission permissions = 5; - uint32 shadow_watch_percent = 6 [(buf.validate.field).uint32.lte = 100]; - uint32 direct_watch_percent = 7 [(buf.validate.field).uint32.lte = 100]; - uint32 direct_submit_percent = 8 [(buf.validate.field).uint32.lte = 100]; - bool shadow_watch_assigned = 9; - bool direct_watch_assigned = 10; - bool direct_submit_assigned = 11; -} - -message SetOperatingThreadControllerRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string channel_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string action = 3 [ - (buf.validate.field).string = { - min_len: 1 - max_len: 64 - }, - (common.v1.classification) = DATA_CLASSIFICATION_SAFE - ]; - int64 expected_runtime_generation = 4 [(buf.validate.field).int64.gte = 0]; - int64 expected_replay_cursor = 5 [(buf.validate.field).int64.gte = 0]; - int64 expected_controller_lease_generation = 6 [(buf.validate.field).int64.gte = 0]; - string idempotency_key = 7 [ - (buf.validate.field).string.min_len = 1, - (buf.validate.field).string.max_len = 512, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; -} - -message SetOperatingThreadControllerResponse { - bool replayed = 1; - OperatingThreadExecution thread_execution = 2 [(buf.validate.field).required = true]; - int64 replay_cursor = 3 [(buf.validate.field).int64.gte = 0]; -} - -message CostUsageSummary { - int64 spend_today_micros = 1 [(buf.validate.field).int64.gte = 0]; - int64 spend_month_to_date_micros = 2 [(buf.validate.field).int64.gte = 0]; - int64 prior_month_to_date_micros = 3 [(buf.validate.field).int64.gte = 0]; - int64 request_count = 4 [(buf.validate.field).int64.gte = 0]; - int64 input_tokens = 5 [(buf.validate.field).int64.gte = 0]; - int64 output_tokens = 6 [(buf.validate.field).int64.gte = 0]; - int32 source_row_count = 7 [(buf.validate.field).int32.gte = 0]; - repeated CostUsageAttributionSummary attributions = 8; - google.protobuf.Timestamp as_of = 9; -} - -message CostUsageAttributionSummary { - string provider = 1; - string asset_id = 2; - string model = 3; - int64 spend_today_micros = 4 [(buf.validate.field).int64.gte = 0]; - int64 spend_month_to_date_micros = 5 [(buf.validate.field).int64.gte = 0]; - int64 request_count = 6 [(buf.validate.field).int64.gte = 0]; - int64 input_tokens = 7 [(buf.validate.field).int64.gte = 0]; - int64 output_tokens = 8 [(buf.validate.field).int64.gte = 0]; - string record_kind = 9; - int64 prior_month_to_date_micros = 10 [(buf.validate.field).int64.gte = 0]; - int64 prior_request_count = 11 [(buf.validate.field).int64.gte = 0]; - int64 prior_input_tokens = 12 [(buf.validate.field).int64.gte = 0]; - int64 prior_output_tokens = 13 [(buf.validate.field).int64.gte = 0]; -} - -// TenantPrivacyMode is how much of a tenant's data this system may copy into -// systems other than the store that owns it. It is the wire spelling of -// platform_core_types::PrivacyMode. -enum TenantPrivacyMode { - // No mode was supplied. Reads never return this; writes reject it. - TENANT_PRIVACY_MODE_UNSPECIFIED = 0; - // Shipped default, and the mode a tenant with no stored row runs under. - TENANT_PRIVACY_MODE_STANDARD = 1; - // Content stays inside the owning store: persisted and returned to the - // tenant, never copied into logs or analytics. - TENANT_PRIVACY_MODE_NO_TRAINING = 2; - // Only classification-safe values leave the owning store at all. - TENANT_PRIVACY_MODE_RESTRICTED = 3; -} - -// PrivacySettingScope selects which of the two rows a write targets. -enum PrivacySettingScope { - PRIVACY_SETTING_SCOPE_UNSPECIFIED = 0; - // The organization-wide default row (no workspace_id). - PRIVACY_SETTING_SCOPE_ORGANIZATION = 1; - // The override row for the workspace named in the request query. - PRIVACY_SETTING_SCOPE_WORKSPACE = 2; -} - -// TenantPrivacySetting is one stored row. workspace_id is empty on the -// organization-wide row. -message TenantPrivacySetting { - string organization_id = 1; - string workspace_id = 2; - TenantPrivacyMode mode = 3; - string updated_by = 4; - google.protobuf.Timestamp updated_at = 5; -} - -message GetPrivacySettingsRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; -} - -message GetPrivacySettingsResponse { - // Mode platform-api actually seals into OperationContext for the queried - // workspace: the workspace override when one exists, otherwise the - // organization row, otherwise TENANT_PRIVACY_MODE_STANDARD. - TenantPrivacyMode effective_mode = 1; - // Present only when an organization-wide row exists. - TenantPrivacySetting organization = 2; - // Present only when an override row exists for the queried workspace. - TenantPrivacySetting workspace = 3; -} - -message SetPrivacySettingsRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - PrivacySettingScope scope = 2 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - TenantPrivacyMode mode = 3 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; -} - -// RuleScope records which tenant level a managed rule was authored at, so a -// client can tell an organization-wide rule from a workspace override. -enum RuleScope { - // RULE_SCOPE_UNSPECIFIED is treated as organization scope by readers. - RULE_SCOPE_UNSPECIFIED = 0; - // RULE_SCOPE_ORGANIZATION applies to every workspace in the organization. - RULE_SCOPE_ORGANIZATION = 1; - // RULE_SCOPE_WORKSPACE applies only to the workspace that authored it. - RULE_SCOPE_WORKSPACE = 2; -} - -// McpPolicyMode selects how a client treats an MCP server that is not named -// by the policy. -enum McpPolicyMode { - // MCP_POLICY_MODE_UNSPECIFIED is rejected by SetManagedSetup. - MCP_POLICY_MODE_UNSPECIFIED = 0; - // MCP_POLICY_MODE_OPEN permits every MCP server; `servers` is advisory. - MCP_POLICY_MODE_OPEN = 1; - // MCP_POLICY_MODE_ALLOWLIST permits only the listed servers. - MCP_POLICY_MODE_ALLOWLIST = 2; - // MCP_POLICY_MODE_DENYLIST permits every server except the listed ones. - MCP_POLICY_MODE_DENYLIST = 3; -} - -// ManagedRule is one operator-authored instruction block that agent clients -// inject into the model's system prompt. -message ManagedRule { - // id is stable across revisions and identifies the rule to a client. - string id = 1 [(buf.validate.field).string.min_len = 1]; - // title is the short human label shown in operator surfaces. - string title = 2; - // body_markdown is the rule text delivered to the model verbatim. - string body_markdown = 3; - // scope records the tenant level that authored this rule. - RuleScope scope = 4; -} - -// ManagedSkillRef names a skill the organization expects agent clients to have -// available. Installation is not part of this contract. -message ManagedSkillRef { - // id is the skill identifier in the client's local catalog. - string id = 1 [(buf.validate.field).string.min_len = 1]; - // source is the marketplace or repository the skill comes from. - string source = 2; - // version pins the expected skill revision, or is empty for any revision. - string version = 3; - // required marks a skill whose absence a client must report to the operator. - bool required = 4; -} - -// McpServerRef names one MCP server in a managed MCP policy. -message McpServerRef { - // name is the client-side MCP server name the policy decides on. - string name = 1; - // url_pattern matches the server endpoint for URL-based transports. - string url_pattern = 2; - // transport is the MCP transport label, such as `stdio` or `http`. - string transport = 3; -} - -// McpPolicy is the organization decision about which MCP servers an agent -// client may connect to. -message McpPolicy { - // mode selects allowlist, denylist, or open handling of unlisted servers. - McpPolicyMode mode = 1; - // servers are the entries the mode decides on. - repeated McpServerRef servers = 2; -} - -// ManagedSetup is the organization-owned agent client configuration document. -// Administrators author it once in Deixic; every agent client fetches it and -// enforces it locally. -message ManagedSetup { - // version increases monotonically per tenant on every accepted write. - uint64 version = 1; - // issued_at is when the platform served this revision. - google.protobuf.Timestamp issued_at = 2; - // rules are injected into the client's system prompt. - repeated ManagedRule rules = 3; - // skills are the skills the organization expects clients to have. - repeated ManagedSkillRef skills = 4; - // mcp is the MCP server connection policy. - McpPolicy mcp = 5; - // sandbox_policy_toml is the serialized sandbox policy document. The platform - // validates only that it parses as TOML; the client owns its semantics. - string sandbox_policy_toml = 6; - // organization_id is the tenant that owns this document. - string organization_id = 7; - // workspace_id is empty when this document is the organization-wide one. - string workspace_id = 8; -} - -// GetManagedSetupRequest selects the tenant whose managed setup to return. -message GetManagedSetupRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - // workspace_id selects the workspace document, falling back to the - // organization document when the workspace has none. Leave empty to read the - // organization document directly. - string workspace_id = 2; -} - -// SetManagedSetupRequest replaces the managed setup document for one tenant. -message SetManagedSetupRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - // workspace_id writes a workspace override. Leave empty to write the - // organization document. - string workspace_id = 2; - // setup carries the document body. Its version, issued_at, organization_id, - // and workspace_id fields are server-owned and ignored on write. - ManagedSetup setup = 3 [(buf.validate.field).required = true]; -} - -// ManagedSetupService serves the organization-owned agent client configuration -// that administrators define once and every agent client enforces. Reads are -// available to members so a running client can refresh; writes are an -// administrative action. -service ManagedSetupService { - // GetManagedSetup returns the effective managed setup document for a tenant, - // preferring the workspace override over the organization document. - rpc GetManagedSetup(GetManagedSetupRequest) returns (ManagedSetup) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // SetManagedSetup replaces the managed setup document for a tenant and - // returns the stored revision with its new version. - rpc SetManagedSetup(SetManagedSetupRequest) returns (ManagedSetup) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } -} - -// MissionScheduleCapability is intentionally declared at the end of this -// large file so adding it does not renumber unrelated generated descriptors. -message MissionScheduleCapability { - string name = 1 [(buf.validate.field).string.min_len = 1]; - string description = 2 [(buf.validate.field).string.min_len = 1]; -} - -// Meeting capture messages are intentionally declared at the end of this -// large file so adding the product slice does not renumber unrelated generated -// descriptors. - -// StartMeetingCaptureRequest names one meeting, either by a server-validated -// meeting URL or by one opted-in connected calendar call. The transcript -// callback and provider credentials are deployment-owned and cannot be -// redirected by the browser. -message StartMeetingCaptureRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - // Optional when connected_call_id is set. Otherwise one server-validated - // meeting URL (Google Meet, Zoom, Microsoft Teams, or Webex). The field name - // stays meet_url for wire and TypeScript compatibility. - string meet_url = 2 [(buf.validate.field).string.max_len = 2000]; - // Deprecated compatibility input. Platform ignores it and resolves the - // tenant's active Recall connection server-side. - string recall_connection_id = 3 [deprecated = true]; - string idempotency_key = 4 [(buf.validate.field).string = { - min_len: 1 - max_len: 200 - }]; - int32 maximum_duration_minutes = 6 [(buf.validate.field).int32 = { - gte: 1 - lte: 240 - }]; - bool recording_consent_attested = 7; - string language_code = 9 [(buf.validate.field).string.max_len = 35]; - // Optional. When set, Platform resolves the call from the tenant's connected - // calendar (ListConnectedCalls id), uses its meeting URL and start/end times, - // and records a calendar-sourced capture. meet_url is ignored when set. - string connected_call_id = 10 [(buf.validate.field).string.max_len = 200]; - reserved 5, 8; - reserved "bot_name", "consent_policy_version"; -} - -enum ConnectedCallSourceState { - CONNECTED_CALL_SOURCE_STATE_UNSPECIFIED = 0; - CONNECTED_CALL_SOURCE_STATE_AVAILABLE = 1; - CONNECTED_CALL_SOURCE_STATE_NOT_CONNECTED = 2; -} - -message ListConnectedCallsRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; -} - -message ListConnectedCallsResponse { - repeated ConnectedCall calls = 1; - ConnectedCallSourceState source_state = 2; -} - -// ConnectedCall is one upcoming call projected from the tenant's connected -// calendar. The field name meet_url is a wire-compatibility alias; it carries -// the call's join URL on whatever meeting platform hosts it. -message ConnectedCall { - string id = 1 [(buf.validate.field).string.min_len = 1]; - string title = 2 [(buf.validate.field).string.max_len = 512]; - string meet_url = 3 [(buf.validate.field).string.uri = true]; - google.protobuf.Timestamp starts_at = 4; - google.protobuf.Timestamp ends_at = 5; -} - -message StartMeetingCaptureResponse { - MeetingCapture capture = 1; -} - -message GetMeetingCaptureRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string capture_id = 2 [(buf.validate.field).string.min_len = 1]; -} - -message GetMeetingCaptureResponse { - MeetingCapture capture = 1; -} - -message ListMeetingCapturesRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; -} - -message ListMeetingCapturesResponse { - repeated MeetingCapture captures = 1; -} - -// StopMeetingCaptureRequest records the user's request to stop one capture. -// Platform chooses cancel-versus-leave from the durable binding lifecycle; the -// browser cannot select the provider action. -message StopMeetingCaptureRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string capture_id = 2 [(buf.validate.field).string.min_len = 1]; - string idempotency_key = 3 [(buf.validate.field).string = { - min_len: 1 - max_len: 200 - }]; -} - -message StopMeetingCaptureResponse { - MeetingCapture capture = 1; -} - -// MeetingCapture is the Platform-owned status projection. Provider state, -// immutable transcript references, Cerebro indexing, and tenant-scoped -// retrieval proof remain separate so clients never infer completion from -// display text. -message MeetingCapture { - string capture_id = 1; - string action_intent_id = 2; - string meeting_url = 3; - string bot_name = 4; - string lifecycle_state = 5; - string provider_bot_id = 6; - string transcript_state = 7; - int32 transcript_segment_count = 8; - string transcript_object_id = 9; - string transcript_version_id = 10; - string cerebro_state = 11; - string cerebro_thing_id = 12; - string error_code = 13; - string required_user_action = 14; - google.protobuf.Timestamp join_at = 15; - google.protobuf.Timestamp leave_at = 16; - google.protobuf.Timestamp updated_at = 17; - int32 cerebro_chunk_count = 18; - repeated string cerebro_chunk_ids = 19; - string cerebro_retrieval_state = 20; - string cerebro_retrieval_candidate_id = 21; - string provider_recording_id = 22; - string provider_transcript_id = 23; - // "direct_url" for a pasted meeting URL, "calendar_occurrence" for an - // opted-in connected calendar call. - string source_kind = 24; - // Calendar event title. Empty for a direct meeting URL. - string title = 25; - google.protobuf.Timestamp occurrence_start_at = 26; - // "enabled" while the capture is wanted, "disabled" after StopMeetingCapture. - string desired_state = 27; -} - -// Radar watch-program messages are intentionally declared at the end of this -// large file so adding them does not renumber unrelated generated descriptors. - -// ProspectingWatchProgramLifecycle is the owner-authored lifecycle of a Radar -// watch program. PAUSED is the close state; ACTIVE reopens it. -enum ProspectingWatchProgramLifecycle { - PROSPECTING_WATCH_PROGRAM_LIFECYCLE_UNSPECIFIED = 0; - PROSPECTING_WATCH_PROGRAM_LIFECYCLE_ACTIVE = 1; - PROSPECTING_WATCH_PROGRAM_LIFECYCLE_PAUSED = 2; - PROSPECTING_WATCH_PROGRAM_LIFECYCLE_ARCHIVED = 3; -} - -// ProspectingWatchProgram is the current Console-owned Radar configuration. -// It carries no Identity account, candidate, run, relationship, event, or -// draft projection. -message ProspectingWatchProgram { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string watch_program_id = 3 [(buf.validate.field).string.min_len = 1]; - string name = 4 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; - google.protobuf.Struct config = 5 [(buf.validate.field).required = true]; - string scoring_rule_revision = 6 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; - ProspectingWatchProgramLifecycle lifecycle = 7 [(buf.validate.field).enum.defined_only = true]; - int64 revision = 8 [(buf.validate.field).int64.gt = 0]; - string created_by_principal_id = 9 [(buf.validate.field).string.min_len = 1]; - string updated_by_principal_id = 10 [(buf.validate.field).string.min_len = 1]; - string reason = 11 [(buf.validate.field).string = { - min_len: 1 - max_len: 512 - }]; - string audit_receipt_id = 12 [(buf.validate.field).string.min_len = 1]; - google.protobuf.Timestamp created_at = 13 [(buf.validate.field).required = true]; - google.protobuf.Timestamp updated_at = 14 [(buf.validate.field).required = true]; -} - -// ProspectingWatchProgramMutationReceipt identifies the accepted mutation and -// whether this response is an exact idempotent replay. -message ProspectingWatchProgramMutationReceipt { - string idempotency_key = 1 [(buf.validate.field).string.min_len = 1]; - string request_digest_sha256 = 2 [(buf.validate.field).string.pattern = "^[0-9a-f]{64}$"]; - int64 revision = 3 [(buf.validate.field).int64.gt = 0]; - string audit_receipt_id = 4 [(buf.validate.field).string.min_len = 1]; - bool replayed = 5; -} - -message CreateProspectingWatchProgramRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string name = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; - google.protobuf.Struct config = 3 [(buf.validate.field).required = true]; - string scoring_rule_revision = 4 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; - string reason = 5 [(buf.validate.field).string = { - min_len: 1 - max_len: 512 - }]; - string idempotency_key = 6 [(buf.validate.field).string = { - min_len: 1 - max_len: 256 - }]; -} - -message CreateProspectingWatchProgramResponse { - ProspectingWatchProgram program = 1 [(buf.validate.field).required = true]; - ProspectingWatchProgramMutationReceipt receipt = 2 [(buf.validate.field).required = true]; -} - -message GetProspectingWatchProgramRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string watch_program_id = 2 [(buf.validate.field).string.min_len = 1]; -} - -message GetProspectingWatchProgramResponse { - ProspectingWatchProgram program = 1 [(buf.validate.field).required = true]; -} - -message ListProspectingWatchProgramsRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; -} - -message ListProspectingWatchProgramsResponse { - repeated ProspectingWatchProgram programs = 1 [(buf.validate.field).repeated.max_items = 100]; - bool has_more = 2; -} - -message UpdateProspectingWatchProgramRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string watch_program_id = 2 [(buf.validate.field).string.min_len = 1]; - string name = 3 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; - google.protobuf.Struct config = 4 [(buf.validate.field).required = true]; - string scoring_rule_revision = 5 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; - ProspectingWatchProgramLifecycle lifecycle = 6 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - int64 expected_revision = 7 [(buf.validate.field).int64.gt = 0]; - string reason = 8 [(buf.validate.field).string = { - min_len: 1 - max_len: 512 - }]; - string idempotency_key = 9 [(buf.validate.field).string = { - min_len: 1 - max_len: 256 - }]; -} - -message UpdateProspectingWatchProgramResponse { - ProspectingWatchProgram program = 1 [(buf.validate.field).required = true]; - ProspectingWatchProgramMutationReceipt receipt = 2 [(buf.validate.field).required = true]; -} - -// Commitment-ledger messages are intentionally declared at the end of this -// large file so adding the product slice does not renumber unrelated generated -// descriptors. - -// CommitmentSourceState reports whether the commitment ledger can be read for -// this workspace. NOT_CONFIGURED means the deployment has no commitment-ledger -// origin configured, so the response carries no commitments instead of an -// empty ledger that would read as "you have none". -enum CommitmentSourceState { - COMMITMENT_SOURCE_STATE_UNSPECIFIED = 0; - COMMITMENT_SOURCE_STATE_AVAILABLE = 1; - COMMITMENT_SOURCE_STATE_NOT_CONFIGURED = 2; -} - -// ListCommitmentsRequest reads one workspace's commitment ledger. -message ListCommitmentsRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - // status selects the lifecycle statuses to return. Empty returns the open - // set (requested, accepted, delivered); "all" returns every status; any - // other value returns exactly that status. - string status = 2 [ - (buf.validate.field).string.max_len = 32, - (common.v1.classification) = DATA_CLASSIFICATION_SAFE - ]; -} - -message ListCommitmentsResponse { - repeated Commitment commitments = 1; - CommitmentSourceState source_state = 2; - // truncated is set when Cerebro filled the candidate window, so commitments - // beyond this page exist. Narrow the status filter to see fewer. - bool truncated = 3; -} - -// Commitment is the read projection of one tracked commitment. Every field is -// carried from the commitment ledger; the citations are the evidence entries -// the commitment was extracted from, not a summary written here. -message Commitment { - string commitment_id = 1; - string title = 2; - string status = 3; - string condition_of_satisfaction = 4; - google.protobuf.Timestamp due_at = 5; - // no_date_rationale explains why a commitment carries no due date. Empty - // when due_at is set or when the ledger records no rationale. - string no_date_rationale = 6; - string owner_email = 7; - repeated CommitmentCitation citations = 9 [(buf.validate.field).repeated.max_items = 64]; - google.protobuf.Timestamp observed_at = 10; - // meeting_capture_id is set when a meeting_binding citation resolves to a - // meeting capture binding in this workspace. - string meeting_capture_id = 11; - // 8 held an owner_identity_urn that platform-api reconstructed from the - // organization id. Cerebro mints identity URNs from its own tenant id, which - // platform-api never learns, so the value was not the real URN. The field - // never shipped; the number stays reserved. - reserved 8; - reserved "owner_identity_urn"; -} - -// CommitmentCitation is one evidence entry the commitment was extracted from. -message CommitmentCitation { - string kind = 1; - string source_kind = 2; - string source_id = 3; - string source_uri = 4; - string excerpt = 5 [(buf.validate.field).string.max_len = 2000]; - google.protobuf.Timestamp observed_at = 6; -} - -// Operating-job projection messages are intentionally declared at the end of -// this large file so adding the product slice does not renumber unrelated -// generated descriptors. - -// OperatingJobState is the customer lifecycle of one durable intended -// outcome. Verification is deliberately separate: succeeded never implies -// verified, and failed never means blocked. -enum OperatingJobState { - OPERATING_JOB_STATE_UNSPECIFIED = 0; - OPERATING_JOB_STATE_PROPOSED = 1; - OPERATING_JOB_STATE_QUEUED = 2; - OPERATING_JOB_STATE_RUNNING = 3; - OPERATING_JOB_STATE_WAITING = 4; - OPERATING_JOB_STATE_SUCCEEDED = 5; - OPERATING_JOB_STATE_FAILED = 6; - OPERATING_JOB_STATE_CANCELLED = 7; -} - -enum OperatingJobVerificationState { - OPERATING_JOB_VERIFICATION_STATE_UNSPECIFIED = 0; - OPERATING_JOB_VERIFICATION_STATE_NOT_VERIFIED = 1; - OPERATING_JOB_VERIFICATION_STATE_PENDING = 2; - OPERATING_JOB_VERIFICATION_STATE_VERIFIED = 3; - OPERATING_JOB_VERIFICATION_STATE_FAILED = 4; -} - -enum OperatingJobOrigin { - OPERATING_JOB_ORIGIN_UNSPECIFIED = 0; - OPERATING_JOB_ORIGIN_CHAT = 1; - OPERATING_JOB_ORIGIN_SCHEDULE = 2; - OPERATING_JOB_ORIGIN_EVENT = 3; - OPERATING_JOB_ORIGIN_API = 4; - // A reusable customer capability. The current durable compatibility owner - // may remain playbooks.v1; that system noun does not cross this boundary. - OPERATING_JOB_ORIGIN_SKILL = 5; - OPERATING_JOB_ORIGIN_COMPUTER = 6; -} - -// OperatingJobProofState reports only the completeness of authoritative -// record references. It never upgrades a job lifecycle or claims that an -// unresolved owner record succeeded. -enum OperatingJobProofState { - OPERATING_JOB_PROOF_STATE_UNSPECIFIED = 0; - OPERATING_JOB_PROOF_STATE_UNAVAILABLE = 1; - OPERATING_JOB_PROOF_STATE_PARTIAL = 2; - OPERATING_JOB_PROOF_STATE_COMPLETE = 3; -} - -// OperatingJobRecordLink is one append-only causal edge from the job's active -// run to an independently owned record. correlation_id groups records emitted -// by the same operation milestone; relation is a bounded server-authored value. -message OperatingJobRecordLink { - string correlation_id = 1 [(buf.validate.field).string.min_len = 1]; - string relation = 2 [(buf.validate.field).string.min_len = 1]; - platform.v1.RecordRef record = 3 [(buf.validate.field).required = true]; -} - -// OperatingJob is a bounded customer projection over owner records. It never -// contains raw prompts, tool arguments/results, credentials, or receipt -// payloads. job_id and objective_id are equal for this v1 projection. -message OperatingJob { - string job_id = 1 [(buf.validate.field).string.min_len = 1]; - string objective_id = 2 [(buf.validate.field).string.min_len = 1]; - string title = 3 [(buf.validate.field).string.min_len = 1]; - OperatingJobState state = 4 [(buf.validate.field).enum.defined_only = true]; - OperatingJobVerificationState verification_state = 5 [(buf.validate.field).enum.defined_only = true]; - OperatingJobOrigin origin = 6 [(buf.validate.field).enum.defined_only = true]; - string channel_id = 7 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string submitted_message_id = 8 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string conversation_context_id = 9 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string conversation_task_id = 10 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - int64 conversation_task_revision = 11 [(buf.validate.field).int64.gte = 0]; - string active_run_id = 12 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - int32 attempt_count = 13 [(buf.validate.field).int32.gte = 0]; - google.protobuf.Timestamp created_at = 14; - google.protobuf.Timestamp updated_at = 15; - // False means an older producer omitted one or more typed correlations. - // Clients may render the job but must not infer the missing owner data. - bool projection_complete = 16; - repeated string missing_owner_data = 17 [(buf.validate.field).repeated = { - max_items: 16 - items: { - string: { - min_len: 1 - max_len: 64 - } - } - }]; - // Causal references only. Record payloads remain with their authoritative - // owners and are resolved under the request's authenticated tenant. - repeated OperatingJobRecordLink record_links = 18 [(buf.validate.field).repeated.max_items = 256]; - OperatingJobProofState proof_state = 19 [(buf.validate.field).enum.defined_only = true]; - // Stable machine-readable categories such as action_lineage, - // policy_decision, usage, and terminal_receipt. - repeated string missing_proof = 20 [(buf.validate.field).repeated = { - max_items: 16 - items: { - string: { - min_len: 1 - max_len: 64 - } - } - }]; -} - -message ListOperatingJobsRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; -} - -message ListOperatingJobsResponse { - repeated OperatingJob jobs = 1 [(buf.validate.field).repeated.max_items = 200]; - // True when at least one returned legacy record lacks a typed correlation. - bool partial = 2; -} - -// Declared at the end so this additive control does not renumber unrelated -// generated message or enum descriptors in the large Console schema. -message RecordOperatingHomepageSuggestionFeedbackRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string suggestion_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - OperatingHomepageSuggestionFeedbackAction action = 3 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; -} - -message RecordOperatingHomepageSuggestionFeedbackResponse { - bool changed = 1; -} - -enum OperatingHomepageSuggestionFeedbackAction { - OPERATING_HOMEPAGE_SUGGESTION_FEEDBACK_ACTION_UNSPECIFIED = 0; - OPERATING_HOMEPAGE_SUGGESTION_FEEDBACK_ACTION_NOT_USEFUL = 1; - OPERATING_HOMEPAGE_SUGGESTION_FEEDBACK_ACTION_FORGET = 2; -} - -// Model credits are separate from subscriptions; automatic refill requires explicit consent. -message InferenceCreditBalance { - // Original cash charges restored through verified customer recovery. - int64 compensated_micros = 13 [(buf.validate.field).int64.gte = 0]; - // Non-cash development funding remains separate from purchased credits. - int64 granted_micros = 8 [(buf.validate.field).int64.gte = 0]; - int64 expired_grant_micros = 9 [(buf.validate.field).int64.gte = 0]; - int64 grant_spent_micros = 10 [(buf.validate.field).int64.gte = 0]; - int64 grant_reserved_micros = 11 [(buf.validate.field).int64.gte = 0]; - // Enrolled development programs cannot consume paid credits or trigger paid refill. - bool development_credit_only = 12; - bool admission_suspended = 7; - int64 reversed_micros = 5 [(buf.validate.field).int64.gte = 0]; - int64 debt_micros = 6 [(buf.validate.field).int64.gte = 0]; - int64 purchased_micros = 1 [(buf.validate.field).int64.gte = 0]; - int64 spent_micros = 2 [(buf.validate.field).int64.gte = 0]; - int64 reserved_micros = 3 [(buf.validate.field).int64.gte = 0]; - int64 available_micros = 4 [(buf.validate.field).int64.gte = 0]; -} -message GetInferenceCreditBalanceRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string run_id = 2 [(buf.validate.field).string.max_len = 256]; -} -message InferenceCreditBlock { - uint64 credit_cents = 1; - uint64 fee_cents = 2; - uint64 total_cents = 3; - string quote_version = 4; -} - -// Published per-token price of the managed default model that prepaid credits -// pay for. Amounts are USD micros (1 USD = 1_000_000) per one million tokens, -// so $1.40 per million tokens is 1400000. The console uses this to show what a -// balance buys; it is the same contract the LLM gateway enforces at admission. -message InferenceCreditPricing { - string provider = 1; - string model = 2; - string pricing_version = 3; - int64 input_micros_per_million_tokens = 4 [(buf.validate.field).int64.gte = 0]; - int64 cached_input_micros_per_million_tokens = 5 [(buf.validate.field).int64.gte = 0]; - int64 output_micros_per_million_tokens = 6 [(buf.validate.field).int64.gte = 0]; - // Customer-facing model name, for example "GLM-5.3"; `model` is the provider id. - string display_name = 7; -} -message GetInferenceCreditBalanceResponse { - InferenceCreditBalance balance = 1; - repeated InferenceCreditBlock blocks = 2; - bool checkout_available = 3; - InferenceCreditPricing pricing = 4; - // Absent means no reconciliation evidence is available. - InferenceCreditReconciliation reconciliation = 5; - // Absent means financial task attribution is unavailable. - InferenceRunCreditBalance run_balance = 6; -} -message InferenceRunCreditBalance { - string run_id = 1; - int64 settled_cost_micros = 2; - int64 reserved_micros = 3; - int64 pending_request_count = 4; - int64 settled_request_count = 5; - google.protobuf.Timestamp oldest_pending_at = 6; -} -message InferenceCreditReconciliation { - int64 compensated_difference_micros = 10; - // A comparison of materialized counters with source rows in one snapshot. - bool balanced = 1; - int64 purchased_difference_micros = 2; - int64 reversed_difference_micros = 3; - int64 spent_difference_micros = 4; - int64 reserved_difference_micros = 5; - int64 dispute_count_difference = 6; - int64 pending_reservation_count = 7 [(buf.validate.field).int64.gte = 0]; - google.protobuf.Timestamp oldest_pending_at = 8; - int64 unfunded_payment_count = 9 [(buf.validate.field).int64.gte = 0]; -} -message CreateInferenceCreditCheckoutRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string request_id = 2 [(buf.validate.field).string.uuid = true]; - // Server accepts only the published USD20, USD50, and USD100 credit blocks. - uint64 credit_cents = 3; -} -message CreateInferenceCreditCheckoutResponse { - string url = 1 [(buf.validate.field).string.uri = true]; -} -message FulfillInferenceCreditCheckoutRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string checkout_session_id = 2 [(buf.validate.field).string.min_len = 1]; -} -message FulfillInferenceCreditCheckoutResponse { - InferenceCreditBalance balance = 1; -} - -// Server-owned Auto decision pinned to an accepted task, never a channel preference. -// Where an accepted Auto task executes. The classifier already picks a model -// from the task's purpose; this records the execution environment that same -// decision implies, so placement is durable, replayable, and attributable to -// the policy version that chose it rather than re-derived at each stage. -enum OperatingExecutionPlacement { - OPERATING_EXECUTION_PLACEMENT_UNSPECIFIED = 0; - // The turn runs inline on the conversation's own runner. - OPERATING_EXECUTION_PLACEMENT_INLINE_TURN = 1; - // The work is long-running and belongs on a Computer. Platform remains the - // durable Run authority; this records the placement decision, it does not - // transfer mission ownership. - OPERATING_EXECUTION_PLACEMENT_COMPUTER_MISSION = 2; -} - -message OperatingAutoModelRoute { - OperatingModelSelection target = 1; - StaffInferenceRoutingPurpose purpose = 2; - string policy_version = 3; - OperatingExecutionPlacement placement = 4; -} - -// Customer-defined business schemas. Field and relationship IDs remain stable across versions. -enum BusinessFieldKind { - BUSINESS_FIELD_KIND_UNSPECIFIED = 0; - BUSINESS_FIELD_KIND_TEXT = 1; - BUSINESS_FIELD_KIND_INTEGER = 2; - BUSINESS_FIELD_KIND_BOOLEAN = 3; - BUSINESS_FIELD_KIND_DECIMAL = 4; - BUSINESS_FIELD_KIND_MONEY = 5; - BUSINESS_FIELD_KIND_ENUM = 6; - BUSINESS_FIELD_KIND_DATE = 7; - BUSINESS_FIELD_KIND_TIMESTAMP = 8; - BUSINESS_FIELD_KIND_REFERENCE = 9; - BUSINESS_FIELD_KIND_ARTIFACT = 10; - BUSINESS_FIELD_KIND_TEXT_LIST = 11; -} -message BusinessFieldDefinition { - string field_id = 1; - string name = 2; - BusinessFieldKind kind = 3; - bool required = 4; - bool unique = 5; - repeated string enum_values = 6; - string reference_type_id = 7; - string group_id = 8; - // Optional help text for people entering this field. - string description = 9; - // TEXT only: maximum Unicode code points, from 1 through 8192. - // The existing 8192-byte text bound also applies. Published limits may only relax. - optional uint32 max_length = 10; -} -message BusinessRelationshipDefinition { - string relationship_id = 1; - string name = 2; - string target_type_id = 3; -} - -// Immutable domain validation and access policy. CRM kinds retain internal staff -// and pipeline:crm.read/write checks even through generic object APIs. -// This metadata never grants the caller those permissions. -enum BusinessObjectRecordKind { - BUSINESS_OBJECT_RECORD_KIND_UNSPECIFIED = 0; - BUSINESS_OBJECT_RECORD_KIND_CRM_COMPANY = 1; - BUSINESS_OBJECT_RECORD_KIND_CRM_CONTACT = 2; - BUSINESS_OBJECT_RECORD_KIND_CRM_DEAL = 3; - BUSINESS_OBJECT_RECORD_KIND_CRM_SIGNAL = 4; - BUSINESS_OBJECT_RECORD_KIND_CRM_ACTIVITY = 5; - BUSINESS_OBJECT_RECORD_KIND_CRM_DEPLOYMENT = 7; - BUSINESS_OBJECT_RECORD_KIND_CRM_TASK = 8; - BUSINESS_OBJECT_RECORD_KIND_CRM_MEETING = 9; -} -message BusinessObjectType { - string type_id = 1; - string name = 2; - int64 revision = 3; - repeated BusinessFieldDefinition fields = 4; - repeated BusinessRelationshipDefinition relationships = 5; - // Optional plural label; the stable type_id remains the machine identifier. - string plural_name = 6; - string description = 7; - // Optional scalar field used to label records; references and artifacts are excluded. - string display_field_id = 8; - // Assigned only by native blueprint cloning and immutable across revisions. - // Provenance does not grant permissions or executable capabilities. - BusinessBlueprintSource blueprint_source = 9; - BusinessObjectRecordKind record_kind = 10; -} - -// Exact canonical decimal text, never floating point. Currency is an ISO-style uppercase code. -message BusinessMoney { - string amount = 1; - string currency = 2; -} -message BusinessObjectReference { - string object_id = 1; -} -message BusinessArtifactReference { - string artifact_version_id = 1; -} -message BusinessTextList { - repeated string values = 1; -} -message BusinessFieldValue { - string field_id = 1; - oneof value { - string text = 2; - int64 integer = 3; - bool boolean = 4; - string decimal = 5; - BusinessMoney money = 6; - string enum_value = 7; - string date = 8; - string timestamp = 9; - BusinessObjectReference reference = 10; - BusinessArtifactReference artifact = 11; - BusinessTextList text_list = 12; - } -} -enum BusinessSourceProperty { - BUSINESS_SOURCE_PROPERTY_UNSPECIFIED = 0; - BUSINESS_SOURCE_PROPERTY_DISPLAY_NAME = 1; - BUSINESS_SOURCE_PROPERTY_EXTERNAL_ID = 2; -} -message BusinessSourceField { - string field_id = 1; - BusinessSourceProperty property = 2; -} -enum BusinessSourceState { - BUSINESS_SOURCE_STATE_UNSPECIFIED = 0; - BUSINESS_SOURCE_STATE_ACTIVE = 1; - BUSINESS_SOURCE_STATE_DELETED = 2; - BUSINESS_SOURCE_STATE_ACCESS_REVOKED = 3; - // The provider still holds the record but has archived it; mapped content stays current. - BUSINESS_SOURCE_STATE_ARCHIVED = 4; -} -message BusinessSourceBinding { - string resource_id = 1; - string connection_id = 2; - repeated string group_ids = 3; - repeated BusinessSourceField fields = 4; - int64 authority_epoch = 5; - int64 generation = 6; - BusinessSourceState state = 7; - string observed_digest = 8; - string observed_at = 9; - string family_stable_id = 10; - string record_id = 11; - string source_event_id = 12; - connectors.v1.ProviderResourceEnvelope envelope = 13; -} -message BusinessObject { - string object_id = 1; - string type_id = 2; - int64 schema_revision = 3; - int64 revision = 4; - repeated BusinessFieldValue values = 5; - bool deleted = 6; - BusinessSourceBinding source = 7; - // 8 carried an authority-transfer receipt that no connector could honor. - reserved 8; - string updated_at = 9; - string created_at = 10; -} -message BusinessObjectRevision { - BusinessObject object = 1; - string operation_id = 2; - string actor_id = 3; - string change_kind = 4; - repeated string evidence_refs = 5; -} -message BusinessObjectRelationship { - string source_object_id = 1; - string relationship_id = 2; - string target_object_id = 3; -} - -message DefineBusinessObjectTypeRequest { - string organization_id = 1; - string workspace_id = 2; - string idempotency_key = 3; - BusinessObjectType definition = 4; - int64 expected_revision = 5; -} -message DefineBusinessObjectTypeResponse { - BusinessObjectType definition = 1; -} - -message ListBusinessObjectTypesRequest { - string organization_id = 1; - string workspace_id = 2; - string idempotency_key = 3; - int32 limit = 4; - string after_type_id = 5; -} -message ListBusinessObjectTypesResponse { - repeated BusinessObjectType definitions = 1; - string next_type_id = 2; -} - -message CreateBusinessObjectRequest { - string organization_id = 1; - string workspace_id = 2; - string idempotency_key = 3; - string type_id = 4; - int64 schema_revision = 5; - repeated BusinessFieldValue values = 6; -} -message CreateBusinessObjectResponse { - BusinessObject object = 1; -} - -message GetBusinessObjectRequest { - string organization_id = 1; - string workspace_id = 2; - string idempotency_key = 3; - string object_id = 4; - // Opt in to content-free recovery coordinates when a currently authorized - // source owner reports a tombstone newer than the accepted object snapshot. - bool allow_source_recovery = 5; -} -message GetBusinessObjectResponse { - BusinessObject object = 1; - // Mutually exclusive with object. Contains no field values or source payload. - BusinessObjectSourceRecovery source_recovery = 2; -} -message BusinessObjectSourceRecovery { - string object_id = 1; - int64 expected_revision = 2; - int64 authority_epoch = 3; - BusinessSourceState source_state = 4; -} - -message ListBusinessObjectsRequest { - string organization_id = 1; - string workspace_id = 2; - string idempotency_key = 3; - string type_id = 4; - int32 limit = 5; - string after_object_id = 6; - // Optional exact indexed lookup; omit for ordinary record listing. - // (-- api-linter: core::0132::request-field-types=disabled - // aip.dev/not-precedent: Typed indexed predicates intentionally replace - // an unstructured filter expression for this Connect API. --) - BusinessObjectFilter filter = 7; -} -message BusinessObjectFilter { - // Exactly one lookup predicate, validated against the latest published type schema. - oneof predicate { - BusinessFieldValue unique_value = 1; - BusinessObjectReferenceFilter reference = 2; - } -} -message BusinessObjectReferenceFilter { - string field_id = 1; - string target_object_id = 2; -} -message ListBusinessObjectsResponse { - repeated BusinessObject objects = 1; - string next_object_id = 2; -} - -message UpdateBusinessObjectRequest { - string organization_id = 1; - string workspace_id = 2; - string idempotency_key = 3; - string object_id = 4; - int64 expected_revision = 5; - repeated BusinessFieldValue values = 6; - int64 schema_revision = 7; -} -message UpdateBusinessObjectResponse { - BusinessObject object = 1; -} - -message DeleteBusinessObjectRequest { - string organization_id = 1; - string workspace_id = 2; - string idempotency_key = 3; - string object_id = 4; - int64 expected_revision = 5; -} -message DeleteBusinessObjectResponse { - BusinessObject object = 1; -} - -message ListBusinessObjectRevisionsRequest { - string organization_id = 1; - string workspace_id = 2; - string idempotency_key = 3; - string object_id = 4; - int32 limit = 5; - int64 before_revision = 6; -} -message ListBusinessObjectRevisionsResponse { - repeated BusinessObjectRevision revisions = 1; - int64 next_before_revision = 2; -} - -message BindBusinessObjectSourceRequest { - string organization_id = 1; - string workspace_id = 2; - string idempotency_key = 3; - string object_id = 4; - int64 expected_revision = 5; - string resource_id = 6; - repeated string group_ids = 7; - repeated BusinessSourceField fields = 8; - string connection_id = 9; - string family_stable_id = 10; - string record_id = 11; -} -message BindBusinessObjectSourceResponse { - BusinessObject object = 1; -} - -message AdmitBusinessObjectObservationRequest { - string organization_id = 1; - string workspace_id = 2; - string idempotency_key = 3; - string object_id = 4; - int64 expected_revision = 5; - int64 authority_epoch = 6; -} -message AdmitBusinessObjectObservationResponse { - BusinessObject object = 1; -} - -enum BusinessObjectRelationshipDirection { - BUSINESS_OBJECT_RELATIONSHIP_DIRECTION_UNSPECIFIED = 0; - BUSINESS_OBJECT_RELATIONSHIP_DIRECTION_OUTGOING = 1; - BUSINESS_OBJECT_RELATIONSHIP_DIRECTION_INCOMING = 2; -} -message ListBusinessObjectRelationshipsRequest { - string organization_id = 1; - string workspace_id = 2; - string idempotency_key = 3; - string object_id = 4; - int32 limit = 5; - // Tuple cursor of relationship ID and peer object ID, separated by U+001F. - string after_key = 6; - // Unspecified preserves outgoing behavior. Incoming peers are source objects. - BusinessObjectRelationshipDirection direction = 7; -} -message ListBusinessObjectRelationshipsResponse { - repeated BusinessObjectRelationship relationships = 1; - string next_key = 2; -} - -message CreateBusinessObjectRelationshipRequest { - string organization_id = 1; - string workspace_id = 2; - string idempotency_key = 3; - BusinessObjectRelationship relationship = 4; - int64 expected_revision = 5; -} -message CreateBusinessObjectRelationshipResponse { - BusinessObject object = 1; -} - -message DeleteBusinessObjectRelationshipRequest { - string organization_id = 1; - string workspace_id = 2; - string idempotency_key = 3; - BusinessObjectRelationship relationship = 4; - int64 expected_revision = 5; -} -message DeleteBusinessObjectRelationshipResponse { - BusinessObject object = 1; -} - -// CaptureFormState is the owner-controlled lifecycle of a form identity. -enum CaptureFormState { - CAPTURE_FORM_STATE_UNSPECIFIED = 0; - CAPTURE_FORM_STATE_DRAFT = 1; - CAPTURE_FORM_STATE_ACTIVE = 2; - CAPTURE_FORM_STATE_ARCHIVED = 3; -} - -// CaptureFormPublicationState is the lifecycle of one immutable public grant. -enum CaptureFormPublicationState { - CAPTURE_FORM_PUBLICATION_STATE_UNSPECIFIED = 0; - CAPTURE_FORM_PUBLICATION_STATE_ACTIVE = 1; - CAPTURE_FORM_PUBLICATION_STATE_REVOKED = 2; - CAPTURE_FORM_PUBLICATION_STATE_EXPIRED = 3; -} - -// CaptureFormSubmissionState is the durable submission/review lifecycle. -enum CaptureFormSubmissionState { - CAPTURE_FORM_SUBMISSION_STATE_UNSPECIFIED = 0; - CAPTURE_FORM_SUBMISSION_STATE_RECEIVED = 1; - CAPTURE_FORM_SUBMISSION_STATE_UNDER_REVIEW = 2; - CAPTURE_FORM_SUBMISSION_STATE_ACCEPTED = 3; - CAPTURE_FORM_SUBMISSION_STATE_REJECTED = 4; - CAPTURE_FORM_SUBMISSION_STATE_FAILED = 5; -} - -enum CaptureFormReviewDecision { - CAPTURE_FORM_REVIEW_DECISION_UNSPECIFIED = 0; - CAPTURE_FORM_REVIEW_DECISION_ACCEPT = 1; - CAPTURE_FORM_REVIEW_DECISION_REJECT = 2; -} - -// CaptureFormFieldKind is intentionally closed. A client cannot smuggle a -// JSON shape into a scalar field or make a hidden write through presentation. -enum CaptureFormFieldKind { - CAPTURE_FORM_FIELD_KIND_UNSPECIFIED = 0; - CAPTURE_FORM_FIELD_KIND_TEXT = 1; - CAPTURE_FORM_FIELD_KIND_LONG_TEXT = 2; - CAPTURE_FORM_FIELD_KIND_INTEGER = 3; - CAPTURE_FORM_FIELD_KIND_DECIMAL = 4; - CAPTURE_FORM_FIELD_KIND_BOOLEAN = 5; - CAPTURE_FORM_FIELD_KIND_DATE = 6; - CAPTURE_FORM_FIELD_KIND_DATETIME = 7; - CAPTURE_FORM_FIELD_KIND_EMAIL = 8; - CAPTURE_FORM_FIELD_KIND_PHONE = 9; - CAPTURE_FORM_FIELD_KIND_URL = 10; - CAPTURE_FORM_FIELD_KIND_SELECT = 11; - CAPTURE_FORM_FIELD_KIND_MULTI_SELECT = 12; - CAPTURE_FORM_FIELD_KIND_FILE = 13; -} - -enum CaptureFormMappingState { - CAPTURE_FORM_MAPPING_STATE_UNSPECIFIED = 0; - CAPTURE_FORM_MAPPING_STATE_MAPPED = 1; - // The answer remains durable on the submission even when the target - // BusinessObject schema has no safe scalar mapping for it. - CAPTURE_FORM_MAPPING_STATE_UNMAPPED = 2; -} - -enum CaptureFormObjectResultState { - CAPTURE_FORM_OBJECT_RESULT_STATE_UNSPECIFIED = 0; - CAPTURE_FORM_OBJECT_RESULT_STATE_CREATED = 1; - CAPTURE_FORM_OBJECT_RESULT_STATE_PARTIAL = 2; - CAPTURE_FORM_OBJECT_RESULT_STATE_FAILED = 3; -} - -// CaptureFormObjectTarget pins the business schema used by every version. -message CaptureFormObjectTarget { - string type_id = 1 [(buf.validate.field).string.min_len = 1]; - int64 schema_revision = 2 [(buf.validate.field).int64.gt = 0]; -} - -// CaptureFormAssetRef references immutable, tenant-owned VFS/artifact bytes. -// The form contract never accepts embedded bytes or a caller-selected URL. -message CaptureFormAssetRef { - string object_id = 1 [(buf.validate.field).string = { - min_len: 1 - max_len: 255 - }]; - string version_id = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 255 - }]; -} - -// CaptureFormBrandingAssetRole is the fixed public selector. Object and -// version coordinates remain server-owned and are never accepted by the -// public asset route. -enum CaptureFormBrandingAssetRole { - CAPTURE_FORM_BRANDING_ASSET_ROLE_UNSPECIFIED = 0; - CAPTURE_FORM_BRANDING_ASSET_ROLE_LOGO = 1; - CAPTURE_FORM_BRANDING_ASSET_ROLE_FAVICON = 2; -} - -message CaptureFormBrandingInput { - string display_name = 1 [(buf.validate.field).string.max_len = 120]; - string tagline = 2 [(buf.validate.field).string.max_len = 160]; - string description = 3 [(buf.validate.field).string.max_len = 2000]; - string accent_color = 4 [(buf.validate.field).string.pattern = "^$|^#[0-9a-fA-F]{6}$"]; - CaptureFormAssetRef logo = 5; - CaptureFormAssetRef favicon = 6; - bool show_powered_by = 7; -} - -// CaptureFormBranding is the administrator projection. Validation receipts -// and asset refs are intentionally absent from public presentation messages. -message CaptureFormBranding { - string display_name = 1 [(buf.validate.field).string.max_len = 120]; - string tagline = 2 [(buf.validate.field).string.max_len = 160]; - string description = 3 [(buf.validate.field).string.max_len = 2000]; - string accent_color = 4 [(buf.validate.field).string.pattern = "^$|^#[0-9a-fA-F]{6}$"]; - CaptureFormAssetRef logo = 5; - CaptureFormAssetRef favicon = 6; - string branding_digest = 7 [(buf.validate.field).string.max_len = 128]; - string validation_receipt_id = 8 [(buf.validate.field).string.max_len = 255]; - bool show_powered_by = 9; -} - -message CaptureFormPublicBranding { - string display_name = 1 [(buf.validate.field).string.max_len = 120]; - string tagline = 2 [(buf.validate.field).string.max_len = 160]; - string description = 3 [(buf.validate.field).string.max_len = 2000]; - string accent_color = 4 [(buf.validate.field).string.pattern = "^$|^#[0-9a-fA-F]{6}$"]; - string logo_url = 5 [(buf.validate.field).string.max_len = 2048]; - string favicon_url = 6 [(buf.validate.field).string.max_len = 2048]; - bool show_powered_by = 7; -} - -message CaptureFormSelectOption { - string option_id = 1 [(buf.validate.field).string = { - min_len: 1 - max_len: 80 - }]; - string label = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 160 - }]; - string description = 3 [(buf.validate.field).string.max_len = 500]; - bool disabled = 4; -} - -message CaptureFormSelectSpec { - repeated CaptureFormSelectOption options = 1 [(buf.validate.field).repeated = { - min_items: 1 - max_items: 128 - }]; - int32 max_selected = 2 [(buf.validate.field).int32 = { - gte: 1 - lte: 128 - }]; -} - -message CaptureFormUploadSpec { - repeated string accepted_content_types = 1 [(buf.validate.field).repeated = { - max_items: 32 - items: { - string: {max_len: 128} - } - }]; - int64 max_size_bytes = 2 [(buf.validate.field).int64 = { - gt: 0 - lte: 52428800 - }]; - int32 max_files = 3 [(buf.validate.field).int32.const = 1]; -} - -enum CaptureFormUploadState { - CAPTURE_FORM_UPLOAD_STATE_UNSPECIFIED = 0; - CAPTURE_FORM_UPLOAD_STATE_GRANTED = 1; - CAPTURE_FORM_UPLOAD_STATE_PROCESSING = 2; - CAPTURE_FORM_UPLOAD_STATE_COMPLETED = 3; - CAPTURE_FORM_UPLOAD_STATE_FAILED = 4; - CAPTURE_FORM_UPLOAD_STATE_EXPIRED = 5; -} - -// CaptureFormUpload is a public, publication-scoped upload grant projection. -// The lease token is returned only by BeginPublishedCaptureFormUpload and is -// never persisted or included in this durable projection. -message CaptureFormUpload { - string upload_id = 1 [(buf.validate.field).string.min_len = 1]; - string input_id = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 80 - }]; - string filename = 3 [(buf.validate.field).string = { - min_len: 1 - max_len: 255 - }]; - string content_type = 4 [(buf.validate.field).string = { - min_len: 1 - max_len: 255 - }]; - int64 size_bytes = 5 [(buf.validate.field).int64 = { - gt: 0 - lte: 52428800 - }]; - string sha256 = 6 [(buf.validate.field).string.pattern = "^[0-9a-f]{64}$"]; - CaptureFormUploadState state = 7 [(buf.validate.field).enum.defined_only = true]; - CaptureFormAssetRef asset = 8; - google.protobuf.Timestamp expires_at = 9; -} - -// CaptureFormTypedValue is shared by hidden defaults and durable answers. A -// multi-select is a typed repeated option message, never a delimiter-encoded -// scalar string. -message CaptureFormTypedValue { - message OptionValues { - repeated string option_ids = 1 [(buf.validate.field).repeated = { - min_items: 1 - max_items: 128 - items: { - string: { - min_len: 1 - max_len: 80 - } - } - }]; - } - - oneof value { - string text = 1 [(buf.validate.field).string.max_len = 8192]; - int64 integer = 2; - string decimal = 3 [(buf.validate.field).string.max_len = 128]; - bool boolean = 4; - string date = 5 [(buf.validate.field).string.max_len = 32]; - google.protobuf.Timestamp datetime = 6; - string email = 7 [(buf.validate.field).string.max_len = 320]; - string phone = 8 [(buf.validate.field).string.max_len = 64]; - string url = 9 [(buf.validate.field).string.max_len = 2048]; - string option_id = 10 [(buf.validate.field).string.max_len = 80]; - OptionValues option_values = 11; - CaptureFormAssetRef artifact = 12; - } -} - -// CaptureFormField is the administrator-owned typed field/mapping definition. -// business_field_id and hidden/default values never appear on public -// projections. -message CaptureFormField { - string input_id = 1 [(buf.validate.field).string = { - min_len: 1 - max_len: 80 - }]; - string label = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 160 - }]; - string help_text = 3 [(buf.validate.field).string.max_len = 1000]; - CaptureFormFieldKind kind = 4 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - bool required = 5; - int32 position = 6 [(buf.validate.field).int32 = { - gte: 0 - lte: 1024 - }]; - string placeholder = 7 [(buf.validate.field).string.max_len = 240]; - string business_field_id = 8 [(buf.validate.field).string.max_len = 255]; - CaptureFormMappingState mapping_state = 9 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - int32 max_length = 10 [(buf.validate.field).int32 = { - gte: 0 - lte: 8192 - }]; - string min_decimal = 11 [(buf.validate.field).string.max_len = 128]; - string max_decimal = 12 [(buf.validate.field).string.max_len = 128]; - CaptureFormTypedValue default_value = 13; - bool hidden = 14; - oneof config { - CaptureFormSelectSpec select = 15; - CaptureFormUploadSpec upload = 16; - } -} - -message CaptureFormPublicField { - string input_id = 1 [(buf.validate.field).string = { - min_len: 1 - max_len: 80 - }]; - string label = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 160 - }]; - string help_text = 3 [(buf.validate.field).string.max_len = 1000]; - CaptureFormFieldKind kind = 4 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - bool required = 5; - int32 position = 6 [(buf.validate.field).int32.gte = 0]; - string placeholder = 7 [(buf.validate.field).string.max_len = 240]; - int32 max_length = 8 [(buf.validate.field).int32 = { - gte: 0 - lte: 8192 - }]; - oneof config { - CaptureFormSelectSpec select = 9; - CaptureFormUploadSpec upload = 10; - } -} - -message CaptureFormVersionInput { - CaptureFormObjectTarget object_target = 1 [(buf.validate.field).required = true]; - repeated CaptureFormField fields = 2 [(buf.validate.field).repeated = { - min_items: 1 - max_items: 64 - }]; - CaptureFormBrandingInput branding = 3 [(buf.validate.field).required = true]; -} - -// CaptureFormVersion is immutable after acceptance. Every public publication -// stores and returns its exact version_id and schema revision. -message CaptureFormVersion { - string form_id = 1 [(buf.validate.field).string.min_len = 1]; - string version_id = 2 [(buf.validate.field).string.min_len = 1]; - int64 revision = 3 [(buf.validate.field).int64.gt = 0]; - CaptureFormObjectTarget object_target = 4 [(buf.validate.field).required = true]; - repeated CaptureFormField fields = 5 [(buf.validate.field).repeated.max_items = 64]; - CaptureFormBranding branding = 6; - string schema_digest = 7 [(buf.validate.field).string.max_len = 128]; - google.protobuf.Timestamp created_at = 8; - string created_by = 9 [(buf.validate.field).string.max_len = 255]; -} - -message CaptureFormPublicationInput { - string slug = 1 [(buf.validate.field).string = { - min_len: 1 - max_len: 80 - pattern: "^[a-z0-9]+(?:-[a-z0-9]+)*$" - }]; - string custom_domain_id = 2 [(buf.validate.field).string.max_len = 255]; - repeated string allowed_origins = 3 [(buf.validate.field).repeated = { - max_items: 32 - items: { - string: {max_len: 2048} - } - }]; - bool embed_enabled = 4; - google.protobuf.Timestamp expires_at = 5; - // Refuses anonymous reads and submissions; answers require a recipient invitation. - bool invitation_only = 6; -} - -// CaptureFormPublicRoute is server-derived white-label routing metadata. A -// caller supplies only a slug and an existing custom-domain reference. -message CaptureFormPublicRoute { - string hostname = 1 [(buf.validate.field).string.max_len = 253]; - string path = 2 [(buf.validate.field).string.max_len = 512]; - string embed_path = 3 [(buf.validate.field).string.max_len = 512]; - string custom_domain_id = 4 [(buf.validate.field).string.max_len = 255]; - repeated string allowed_origins = 5 [(buf.validate.field).repeated.max_items = 32]; - bool embed_enabled = 6; -} - -message CaptureFormPublication { - // Server-generated opaque id used in a public form URL. It is stable across - // admin reloads and idempotent publish retries; it is never caller-selected - // as a tenant or workspace coordinate. - string publication_id = 1 [(buf.validate.field).string.min_len = 1]; - string form_id = 2 [(buf.validate.field).string.min_len = 1]; - string version_id = 3 [(buf.validate.field).string.min_len = 1]; - CaptureFormPublicationState state = 4 [(buf.validate.field).enum.defined_only = true]; - int64 generation = 5 [(buf.validate.field).int64.gt = 0]; - string slug = 6 [(buf.validate.field).string.max_len = 80]; - CaptureFormPublicRoute route = 7; - google.protobuf.Timestamp published_at = 8; - google.protobuf.Timestamp expires_at = 9; - google.protobuf.Timestamp revoked_at = 10; - bool invitation_only = 11; -} - -message CaptureForm { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string form_id = 3 [(buf.validate.field).string.min_len = 1]; - string name = 4 [(buf.validate.field).string = { - min_len: 1 - max_len: 160 - }]; - string description = 5 [(buf.validate.field).string.max_len = 2000]; - CaptureFormState state = 6 [(buf.validate.field).enum.defined_only = true]; - string current_version_id = 7 [(buf.validate.field).string.min_len = 1]; - int64 current_revision = 8 [(buf.validate.field).int64.gt = 0]; - CaptureFormObjectTarget object_target = 9 [(buf.validate.field).required = true]; - CaptureFormBranding branding = 10; - repeated CaptureFormPublication publications = 11 [(buf.validate.field).repeated.max_items = 32]; - google.protobuf.Timestamp created_at = 12; - google.protobuf.Timestamp updated_at = 13; -} - -message PublishedCaptureForm { - string publication_id = 1 [(buf.validate.field).string.min_len = 1]; - string form_id = 2 [(buf.validate.field).string.min_len = 1]; - string version_id = 3 [(buf.validate.field).string.min_len = 1]; - int64 version_revision = 4 [(buf.validate.field).int64.gt = 0]; - string name = 5 [(buf.validate.field).string = { - min_len: 1 - max_len: 160 - }]; - string description = 6 [(buf.validate.field).string.max_len = 2000]; - CaptureFormPublicBranding branding = 7; - repeated CaptureFormPublicField fields = 8 [(buf.validate.field).repeated.max_items = 64]; - CaptureFormPublicRoute route = 9; - google.protobuf.Timestamp expires_at = 10; -} - -message CaptureFormAnswer { - string input_id = 1 [(buf.validate.field).string = { - min_len: 1 - max_len: 80 - }]; - CaptureFormTypedValue value = 2 [(buf.validate.field).required = true]; -} - -message CaptureFormReview { - CaptureFormReviewDecision decision = 1 [(buf.validate.field).enum.defined_only = true]; - string reviewer_id = 2 [(buf.validate.field).string.max_len = 255]; - string note = 3 [(buf.validate.field).string.max_len = 4000]; - google.protobuf.Timestamp reviewed_at = 4; - // Typed native business-field values supplied by the reviewer for required - // fields absent from the original intake. They are persisted with the - // review and used only for accepted-object mapping; CaptureFormSubmission - // answers always remain the original public answers unchanged. - repeated BusinessFieldValue supplemental_values = 5 [(buf.validate.field).repeated.max_items = 64]; -} - -message CaptureFormObjectResult { - string result_id = 1 [(buf.validate.field).string.min_len = 1]; - CaptureFormObjectResultState state = 2 [(buf.validate.field).enum.defined_only = true]; - string object_id = 3 [(buf.validate.field).string.max_len = 255]; - string object_type_id = 4 [(buf.validate.field).string.max_len = 255]; - int64 object_schema_revision = 5 [(buf.validate.field).int64.gte = 0]; - int64 object_revision = 6 [(buf.validate.field).int64.gte = 0]; - string mapping_receipt_id = 7 [(buf.validate.field).string.max_len = 255]; - repeated string unmapped_input_ids = 8 [(buf.validate.field).repeated.max_items = 64]; -} - -message CaptureFormSubmission { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string submission_id = 3 [(buf.validate.field).string.min_len = 1]; - string form_id = 4 [(buf.validate.field).string.min_len = 1]; - string publication_id = 5 [(buf.validate.field).string.min_len = 1]; - string version_id = 6 [(buf.validate.field).string.min_len = 1]; - CaptureFormSubmissionState state = 7 [(buf.validate.field).enum.defined_only = true]; - repeated CaptureFormAnswer answers = 8 [(buf.validate.field).repeated.max_items = 64]; - int64 revision = 9 [(buf.validate.field).int64.gt = 0]; - CaptureFormReview review = 10; - CaptureFormObjectResult object_result = 11; - google.protobuf.Timestamp submitted_at = 12; - google.protobuf.Timestamp updated_at = 13; -} - -// Public receipt deliberately excludes tenant coordinates, answers, owner -// references, and the internal BusinessObject identity. -message CaptureFormPublicSubmissionReceipt { - string submission_id = 1 [(buf.validate.field).string.min_len = 1]; - string result_id = 2 [(buf.validate.field).string.max_len = 255]; - CaptureFormSubmissionState state = 3 [(buf.validate.field).enum.defined_only = true]; - google.protobuf.Timestamp submitted_at = 4; -} - -message CreateCaptureFormRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string idempotency_key = 3 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; - string name = 4 [(buf.validate.field).string = { - min_len: 1 - max_len: 160 - }]; - string description = 5 [(buf.validate.field).string.max_len = 2000]; - CaptureFormVersionInput version = 6 [(buf.validate.field).required = true]; -} - -message CreateCaptureFormResponse { - CaptureForm form = 1 [(buf.validate.field).required = true]; - CaptureFormVersion version = 2 [(buf.validate.field).required = true]; -} - -message ListCaptureFormsRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - CaptureFormState state = 3 [(buf.validate.field).enum.defined_only = true]; - int32 page_size = 4 [(buf.validate.field).int32 = { - gte: 0 - lte: 100 - }]; - string page_token = 5 [(buf.validate.field).string.max_len = 512]; -} - -message ListCaptureFormsResponse { - repeated CaptureForm forms = 1 [(buf.validate.field).repeated.max_items = 100]; - string next_page_token = 2 [(buf.validate.field).string.max_len = 512]; -} - -message GetCaptureFormRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string form_id = 3 [(buf.validate.field).string.min_len = 1]; - string version_id = 4 [(buf.validate.field).string.max_len = 255]; -} - -message GetCaptureFormResponse { - CaptureForm form = 1 [(buf.validate.field).required = true]; - CaptureFormVersion version = 2 [(buf.validate.field).required = true]; -} - -message UpdateCaptureFormRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string form_id = 3 [(buf.validate.field).string.min_len = 1]; - int64 expected_revision = 4 [(buf.validate.field).int64.gt = 0]; - string idempotency_key = 5 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; - string name = 6 [(buf.validate.field).string = { - min_len: 1 - max_len: 160 - }]; - string description = 7 [(buf.validate.field).string.max_len = 2000]; - CaptureFormVersionInput version = 8 [(buf.validate.field).required = true]; -} - -message UpdateCaptureFormResponse { - CaptureForm form = 1 [(buf.validate.field).required = true]; - CaptureFormVersion version = 2 [(buf.validate.field).required = true]; -} - -message PublishCaptureFormRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string form_id = 3 [(buf.validate.field).string.min_len = 1]; - string version_id = 4 [(buf.validate.field).string.min_len = 1]; - CaptureFormPublicationInput publication = 5 [(buf.validate.field).required = true]; - string idempotency_key = 6 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; -} - -message PublishCaptureFormResponse { - CaptureForm form = 1 [(buf.validate.field).required = true]; - CaptureFormVersion version = 2 [(buf.validate.field).required = true]; - CaptureFormPublication publication = 3 [(buf.validate.field).required = true]; -} - -message RevokeCaptureFormPublicationRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string form_id = 3 [(buf.validate.field).string.min_len = 1]; - string publication_id = 4 [(buf.validate.field).string.min_len = 1]; - string idempotency_key = 5 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; -} - -message RevokeCaptureFormPublicationResponse { - CaptureForm form = 1 [(buf.validate.field).required = true]; - CaptureFormPublication publication = 2 [(buf.validate.field).required = true]; -} - -message GetPublishedCaptureFormRequest { - // This opaque id is the only public capability input. The service resolves - // tenant, form, version, and publication state from its server-side record. - string publication_id = 1 [(buf.validate.field).string.min_len = 1]; -} - -message GetPublishedCaptureFormResponse { - PublishedCaptureForm form = 1 [(buf.validate.field).required = true]; -} - -message GetPublishedCaptureFormBrandingAssetRequest { - // This opaque id is the only public capability input. The role is a fixed - // presentation selector, never an object or version reference. - string publication_id = 1 [(buf.validate.field).string.min_len = 1]; - CaptureFormBrandingAssetRole role = 2 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; -} - -message GetPublishedCaptureFormBrandingAssetResponse { - bytes content = 1 [(buf.validate.field).bytes.max_len = 524288]; - string content_type = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 64 - }]; - string digest = 3 [(buf.validate.field).string.pattern = "^[0-9a-f]{64}$"]; - int64 size_bytes = 4 [(buf.validate.field).int64 = { - gte: 0 - lte: 524288 - }]; -} - -message SubmitPublishedCaptureFormRequest { - // This opaque id is the only public capability input. Tenant and object - // coordinates are derived from the immutable publication record. - string publication_id = 1 [(buf.validate.field).string.min_len = 1]; - string idempotency_key = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; - repeated CaptureFormAnswer answers = 3 [(buf.validate.field).repeated.max_items = 64]; -} - -message SubmitPublishedCaptureFormResponse { - CaptureFormPublicSubmissionReceipt receipt = 1 [(buf.validate.field).required = true]; -} - -message BeginPublishedCaptureFormUploadRequest { - string publication_id = 1 [(buf.validate.field).string.min_len = 1]; - string input_id = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 80 - }]; - string filename = 3 [ - (buf.validate.field).string = { - min_len: 1 - max_len: 255 - }, - (common.v1.classification) = DATA_CLASSIFICATION_PATH - ]; - string content_type = 4 [ - (buf.validate.field).string = { - min_len: 1 - max_len: 255 - }, - (common.v1.classification) = DATA_CLASSIFICATION_SAFE - ]; - int64 size_bytes = 5 [(buf.validate.field).int64 = { - gt: 0 - lte: 52428800 - }]; - string sha256 = 6 [ - (buf.validate.field).string.pattern = "^[0-9a-f]{64}$", - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string idempotency_key = 7 [ - (buf.validate.field).string = { - min_len: 1 - max_len: 128 - }, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; -} - -message BeginPublishedCaptureFormUploadResponse { - CaptureFormUpload grant = 1 [(buf.validate.field).required = true]; - string lease_id = 2 [(buf.validate.field).string.min_len = 1]; - string lease_token = 3 [ - (buf.validate.field).string = { - min_len: 1 - max_len: 512 - }, - (common.v1.classification) = DATA_CLASSIFICATION_CREDENTIAL - ]; - int64 fencing_token = 4 [(buf.validate.field).int64.gt = 0]; - vfs.v1.VfsUploadTarget upload = 5 [(buf.validate.field).required = true]; -} - -message CompletePublishedCaptureFormUploadRequest { - string publication_id = 1 [(buf.validate.field).string.min_len = 1]; - string input_id = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 80 - }]; - string upload_id = 3 [(buf.validate.field).string.min_len = 1]; - string lease_id = 4 [(buf.validate.field).string.min_len = 1]; - string lease_token = 5 [ - (buf.validate.field).string = { - min_len: 1 - max_len: 512 - }, - (common.v1.classification) = DATA_CLASSIFICATION_CREDENTIAL - ]; - int64 fencing_token = 6 [(buf.validate.field).int64.gt = 0]; - int64 size_bytes = 7 [(buf.validate.field).int64 = { - gt: 0 - lte: 52428800 - }]; - string sha256 = 8 [ - (buf.validate.field).string.pattern = "^[0-9a-f]{64}$", - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string storage_etag = 9 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string idempotency_key = 10 [ - (buf.validate.field).string = { - min_len: 1 - max_len: 128 - }, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - repeated vfs.v1.VfsCompletedUploadPart completed_parts = 11 [(buf.validate.field).repeated.max_items = 10000]; -} - -message CompletePublishedCaptureFormUploadResponse { - CaptureFormUpload upload = 1 [(buf.validate.field).required = true]; -} - -message GetCaptureFormSubmissionRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string submission_id = 3 [(buf.validate.field).string.min_len = 1]; -} - -message GetCaptureFormSubmissionResponse { - CaptureFormSubmission submission = 1 [(buf.validate.field).required = true]; -} - -message ListCaptureFormSubmissionsRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string form_id = 3 [(buf.validate.field).string.min_len = 1]; - CaptureFormSubmissionState state = 4 [(buf.validate.field).enum.defined_only = true]; - int32 page_size = 5 [(buf.validate.field).int32 = { - gte: 0 - lte: 100 - }]; - string page_token = 6 [(buf.validate.field).string.max_len = 512]; -} - -message ListCaptureFormSubmissionsResponse { - repeated CaptureFormSubmission submissions = 1 [(buf.validate.field).repeated.max_items = 100]; - string next_page_token = 2 [(buf.validate.field).string.max_len = 512]; -} - -message ReviewCaptureFormSubmissionRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string submission_id = 3 [(buf.validate.field).string.min_len = 1]; - int64 expected_revision = 4 [(buf.validate.field).int64.gt = 0]; - CaptureFormReviewDecision decision = 5 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string note = 6 [(buf.validate.field).string.max_len = 4000]; - string idempotency_key = 7 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; - // Native typed values for missing required BusinessObject fields. These are - // validated against the publication's pinned schema and stored separately - // from the original submission answers. - repeated BusinessFieldValue supplemental_values = 8 [(buf.validate.field).repeated.max_items = 64]; -} - -message ReviewCaptureFormSubmissionResponse { - CaptureFormSubmission submission = 1 [(buf.validate.field).required = true]; - CaptureFormObjectResult object_result = 2; -} - -// Exact immutable schema lookup. Revision must be positive; latest is listed separately. -message GetBusinessObjectTypeRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string type_id = 3 [(buf.validate.field).string.min_len = 1]; - int64 revision = 4 [(buf.validate.field).int64.gt = 0]; -} -message GetBusinessObjectTypeResponse { - BusinessObjectType definition = 1; -} - -// A confirmed payment receipt; amounts include only that payment, not a balance. -message InferenceCreditReceipt { - string payment_id = 1; - int64 paid_at_unix = 2; - uint64 credit_cents = 3; - uint64 fee_cents = 4; - uint64 paid_cents = 5; - uint64 refunded_cents = 6; - string receipt_url = 7; - bool automatic_refill = 8; -} -message ListInferenceCreditReceiptsRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string page_token = 2; -} -message ListInferenceCreditReceiptsResponse { - repeated InferenceCreditReceipt receipts = 1; - string next_page_token = 2; - bool available = 3; -} - -message InferenceCreditAutoRefill { - bool enabled = 1; - uint64 threshold_cents = 2; - uint64 credit_cents = 3; - uint64 monthly_cap_cents = 4; - // Successful automatic charges this UTC month plus all unresolved charges. - uint64 committed_cents = 5; - string pause_reason = 6; - string generation = 7; -} -message GetInferenceCreditAutoRefillRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; -} -message GetInferenceCreditAutoRefillResponse { - InferenceCreditAutoRefill settings = 1; -} -message UpdateInferenceCreditAutoRefillRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string request_id = 2 [(buf.validate.field).string.uuid = true]; - bool enabled = 3; - uint64 threshold_cents = 4; - uint64 credit_cents = 5; - uint64 monthly_cap_cents = 6; - // Explicit agreement to the displayed threshold, gross charge and UTC monthly cap. - bool consent = 7; - string expected_generation = 8; -} -message UpdateInferenceCreditAutoRefillResponse { - string setup_url = 1; - string generation = 2; -} -message CompleteInferenceCreditAutoRefillRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string setup_session_id = 2 [(buf.validate.field).string.min_len = 1]; -} -message CompleteInferenceCreditAutoRefillResponse { - bool enabled = 1; -} - -message PrepareBusinessObjectAuthorityTransferRequest { - string organization_id = 1; - string workspace_id = 2; - string idempotency_key = 3; - string object_id = 4; - int64 expected_revision = 5; - int64 authority_epoch = 6; -} -message PrepareBusinessObjectAuthorityTransferResponse { - BusinessObject object = 1; - bool ready = 2; - string unavailable_reason = 3; -} - -message FinalizeBusinessObjectAuthorityTransferRequest { - string organization_id = 1; - string workspace_id = 2; - string idempotency_key = 3; - string object_id = 4; - int64 expected_revision = 5; - string transfer_id = 6; - string reconciliation_digest = 7; - string fence_evidence_id = 8; -} -message FinalizeBusinessObjectAuthorityTransferResponse { - BusinessObject object = 1; -} - -// A process has its own lifecycle; its subject's ordinary fields do not own state. -message BusinessProcessParticipantType { - string role_id = 1; - string type_id = 2; - int64 schema_revision = 3; -} -message BusinessProcessParticipant { - string role_id = 1; - string object_id = 2; - // Pins the observed record when admitting work or accepting a decision. - int64 object_revision = 3; -} -message BusinessProcessRequirement { - string requirement_id = 1; - string label = 2; - string role_id = 3; - // Equality uses the declared schema's typed value. No expression strings. - BusinessFieldValue expected = 4; - // Zero disables age checking; positive ages apply to the record's updated_at. - int64 max_age_seconds = 5; - // Requires a populated field instead of equality; expected carries only field_id. - bool require_present = 6; -} -message BusinessProcessTransition { - string transition_id = 1; - string name = 2; - string from_state = 3; - string to_state = 4; - repeated BusinessProcessRequirement requirements = 5; - // Requires the instance's assigned human decision maker to accept explicitly. - bool requires_decision = 6; - // Follow-up obligations are durable child processes admitted atomically. - repeated BusinessProcessFollowUp follow_ups = 7; -} -message BusinessProcessFollowUp { - string definition_id = 1; - int64 definition_revision = 2; - // Child roles map by stable role ID to this process's participants. - string subject_role_id = 3; -} -message BusinessProcessDefinition { - string definition_id = 1; - int64 revision = 2; - string name = 3; - repeated BusinessProcessParticipantType participants = 4; - string subject_role_id = 5; - repeated string states = 6; - string initial_state = 7; - repeated string terminal_states = 8; - repeated BusinessProcessTransition transitions = 9; - string organization_id = 10; - string workspace_id = 11; -} -message BusinessProcessReceipt { - string operation_id = 1; - string transition_id = 2; - string from_state = 3; - string to_state = 4; - int64 revision = 5; - string actor_id = 6; - bool decision_accepted = 7; - repeated BusinessProcessParticipant evidence = 8; - repeated string follow_up_process_ids = 9; - string recorded_at = 10; -} -message BusinessProcess { - string process_id = 1; - string organization_id = 2; - string workspace_id = 3; - string definition_id = 4; - int64 definition_revision = 5; - int64 revision = 6; - string state_id = 7; - string subject_object_id = 8; - repeated BusinessProcessParticipant participants = 9; - string decision_principal_id = 10; - string parent_process_id = 11; - string created_at = 12; - string updated_at = 13; - repeated BusinessProcessReceipt receipts = 14; -} -message DefineBusinessProcessRequest { - string organization_id = 1; - string workspace_id = 2; - string idempotency_key = 3 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; - BusinessProcessDefinition definition = 4; - int64 expected_revision = 5; -} -message DefineBusinessProcessResponse { - BusinessProcessDefinition definition = 1; -} -message StartBusinessProcessRequest { - string organization_id = 1; - string workspace_id = 2; - string idempotency_key = 3 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; - string definition_id = 4; - int64 definition_revision = 5; - repeated BusinessProcessParticipant participants = 6; - string decision_principal_id = 7; -} -message StartBusinessProcessResponse { - BusinessProcess process = 1; -} -message GetBusinessProcessRequest { - string organization_id = 1; - string workspace_id = 2; - string process_id = 3; -} -message GetBusinessProcessResponse { - BusinessProcess process = 1; - BusinessProcessDefinition definition = 2; -} -message ListBusinessProcessesRequest { - string organization_id = 1; - string workspace_id = 2; - string subject_object_id = 3; - string after_process_id = 4; - int32 page_size = 5; -} -message ListBusinessProcessesResponse { - // Receipt-free snapshots; GetBusinessProcess returns bounded full history. - repeated BusinessProcess processes = 1; - string next_after_process_id = 2; -} -message TransitionBusinessProcessRequest { - string organization_id = 1; - string workspace_id = 2; - string idempotency_key = 3 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; - string process_id = 4; - int64 expected_revision = 5; - string transition_id = 6; - // Every role must name its exact current record revision. This fences decisions. - repeated BusinessProcessParticipant participants = 7; - bool accept_decision = 8; -} -message TransitionBusinessProcessResponse { - BusinessProcess process = 1; - bool accepted = 2; - repeated string unmet_requirement_ids = 3; -} - -// Exact immutable lookup; revision must be positive. -message GetBusinessProcessDefinitionRequest { - string organization_id = 1; - string workspace_id = 2; - string definition_id = 3; - int64 revision = 4; -} -message GetBusinessProcessDefinitionResponse { - BusinessProcessDefinition definition = 1; -} - -// Latest revision of each definition, ordered by ID. Maximum page size is 20. -message ListBusinessProcessDefinitionsRequest { - string organization_id = 1; - string workspace_id = 2; - string after_definition_id = 3; - int32 page_size = 4; -} -message ListBusinessProcessDefinitionsResponse { - repeated BusinessProcessDefinition definitions = 1; - string next_after_definition_id = 2; -} - -message OperatingProjectSnapshotFileInput { - string path = 1 [(buf.validate.field).string = { - min_len: 1 - max_len: 1024 - }]; - OperatingAttachmentRef attachment = 2 [(buf.validate.field).required = true]; -} - -message AcceptOperatingProjectSnapshotRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string project_resource_id = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 255 - }]; - string channel_id = 3; - string idempotency_key = 4 [(buf.validate.field).string = { - min_len: 1 - max_len: 255 - }]; - // Absent creates the first accepted snapshot; a value requires exact CAS. - optional uint64 expected_ref_version = 5; - // Complete workspace manifest, including unchanged files. Omitted files are removed. - repeated OperatingProjectSnapshotFileInput files = 6 [(buf.validate.field).repeated.max_items = 1000]; -} - -message AcceptOperatingProjectSnapshotResponse { - toolexecution.v1.ToolExecutionProjectSource project_source = 1; - bool manual_acceptance_available = 2; - string import_execution_id = 3; - string import_state = 4; - string import_error = 5; -} - -message GetOperatingProjectSnapshotRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string project_resource_id = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 255 - }]; - optional string import_execution_id = 3; -} - -message GetOperatingTaskEnvironmentRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string channel_id = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 255 - }]; - string task_id = 3 [(buf.validate.field).string = { - min_len: 1 - max_len: 255 - }]; -} - -message GetOperatingTaskEnvironmentResponse { - bool available = 1; - bool has_environment = 2; - string state = 3; - int32 retention_days = 4; - google.protobuf.Timestamp last_activity_at = 5; - // Computed from current effective policy and the storage owner's activity. - google.protobuf.Timestamp expires_at = 6; - string project_resource_id = 7; - // A cleanup decision was already accepted before a later policy change. - bool cleanup_accepted = 8; - int32 retention_hours = 9; - repeated OperatingTaskEnvironmentStage stages = 10; - toolexecution.v1.ToolExecutionWorkspaceRecipe workspace_recipe = 11; -} - -enum OperatingTaskEnvironmentStageKind { - OPERATING_TASK_ENVIRONMENT_STAGE_KIND_UNSPECIFIED = 0; - OPERATING_TASK_ENVIRONMENT_STAGE_KIND_SOURCE = 1; - OPERATING_TASK_ENVIRONMENT_STAGE_KIND_PREPARATION = 2; - OPERATING_TASK_ENVIRONMENT_STAGE_KIND_PROVISIONING = 3; - OPERATING_TASK_ENVIRONMENT_STAGE_KIND_NETWORK = 4; - OPERATING_TASK_ENVIRONMENT_STAGE_KIND_EXECUTION = 5; - OPERATING_TASK_ENVIRONMENT_STAGE_KIND_RETAINED_STATE = 6; -} - -enum OperatingTaskEnvironmentStageState { - OPERATING_TASK_ENVIRONMENT_STAGE_STATE_UNSPECIFIED = 0; - OPERATING_TASK_ENVIRONMENT_STAGE_STATE_NOT_REQUIRED = 1; - OPERATING_TASK_ENVIRONMENT_STAGE_STATE_ABSENT = 2; - OPERATING_TASK_ENVIRONMENT_STAGE_STATE_PENDING = 3; - OPERATING_TASK_ENVIRONMENT_STAGE_STATE_READY = 4; - OPERATING_TASK_ENVIRONMENT_STAGE_STATE_FAILED = 5; - OPERATING_TASK_ENVIRONMENT_STAGE_STATE_RETAINED = 6; - OPERATING_TASK_ENVIRONMENT_STAGE_STATE_UNKNOWN = 7; -} - -message OperatingTaskEnvironmentStage { - OperatingTaskEnvironmentStageKind kind = 1 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - OperatingTaskEnvironmentStageState state = 2 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string code = 3 [(buf.validate.field).string.max_len = 128]; -} - -// Caller chooses the project and observed acceptance version, never a Git SHA. -message ImportOperatingProjectSnapshotRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string project_resource_id = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 255 - }]; - string idempotency_key = 3 [(buf.validate.field).string = { - min_len: 1 - max_len: 255 - }]; - optional uint64 expected_ref_version = 4; -} - -// Built-in blueprints are immutable source templates, not tenant records or -// executable grants. Clone creates native definitions in the caller's tenant. -message BusinessBlueprint { - string blueprint_id = 1; - int64 version = 2; - string content_digest = 3; - string name = 4; - string description = 5; - repeated BusinessObjectType object_types = 6; - BusinessProcessDefinition process = 7; - CaptureFormVersionInput intake = 8; - // Capability identifiers required before automated execution can be enabled. - // Presence in this list does not claim installation or availability. - repeated string required_capabilities = 9; - // This catalog version supplies native definitions, not executable admission. - bool automated_execution_available = 10; -} -message ListBusinessBlueprintsRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; -} -message ListBusinessBlueprintsResponse { - repeated BusinessBlueprint blueprints = 1; -} -message CloneBusinessBlueprintRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string idempotency_key = 3 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; - string blueprint_id = 4 [(buf.validate.field).string.min_len = 1]; - int64 version = 5 [(buf.validate.field).int64.gt = 0]; - string content_digest = 6 [(buf.validate.field).string.pattern = "^[0-9a-f]{64}$"]; - reserved 7; - reserved "clone_id"; // Instance identity is assigned by the server, never the caller. - string name = 8 [(buf.validate.field).string = { - min_len: 1 - max_len: 120 - }]; -} -message CloneBusinessBlueprintResponse { - string blueprint_id = 1; - int64 blueprint_version = 2; - string content_digest = 3; - // Server-assigned UUID, stable for an identical idempotent request. - string clone_id = 4; - repeated BusinessObjectType object_types = 5; - BusinessProcessDefinition process = 6; - CaptureForm form = 7; - // Definitions are available for editing. Publication, execution and external - // effects require their existing owner admission and are not implied here. - bool automated_execution_available = 8; -} - -// Exact built-in source retained on each cloned schema for future comparison. -message BusinessBlueprintSource { - string blueprint_id = 1; - int64 version = 2; - string content_digest = 3; - string clone_id = 4; - // Stable template member ID. Cloned type_id is tenant-owned and editable. - string source_type_id = 5; -} - -// Invitation IDs are opaque locators, never authentication. The owner requires -// a live Identity access token with the exact verified recipient email. -message CaptureFormInvitation { - string invitation_id = 1; - string publication_id = 2; - string recipient_email = 3 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - google.protobuf.Timestamp expires_at = 4; - string state = 5; -} -message CreateCaptureFormInvitationRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string publication_id = 3 [(buf.validate.field).string.min_len = 1]; - string recipient_email = 4 [(buf.validate.field).string.email = true]; - google.protobuf.Timestamp expires_at = 5 [(buf.validate.field).required = true]; - repeated BusinessFieldValue bound_values = 6 [(buf.validate.field).repeated.max_items = 64]; - string idempotency_key = 7 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; -} -message CreateCaptureFormInvitationResponse { - CaptureFormInvitation invitation = 1 [(buf.validate.field).required = true]; -} -message RevokeCaptureFormInvitationRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string invitation_id = 3 [(buf.validate.field).string.min_len = 1]; - string idempotency_key = 4 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; -} -message RevokeCaptureFormInvitationResponse { - CaptureFormInvitation invitation = 1 [(buf.validate.field).required = true]; -} -message GetInvitedCaptureFormRequest { - string invitation_id = 1 [(buf.validate.field).string.min_len = 1]; -} -message GetInvitedCaptureFormResponse { - PublishedCaptureForm form = 1; - // Returned only to the verified recipient after this invitation was used. - CaptureFormPublicSubmissionReceipt receipt = 2; -} -message SubmitInvitedCaptureFormRequest { - string invitation_id = 1 [(buf.validate.field).string.min_len = 1]; - repeated CaptureFormAnswer answers = 2 [(buf.validate.field).repeated.max_items = 64]; - string idempotency_key = 3 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; -} -message SubmitInvitedCaptureFormResponse { - CaptureFormPublicSubmissionReceipt receipt = 1 [(buf.validate.field).required = true]; -} - -// Shared prerequisite vocabulary consumed by Grid, Deixic UI and Deixic Code. -enum ManagedInferenceReadinessStatus { - MANAGED_INFERENCE_READINESS_STATUS_UNSPECIFIED = 0; - MANAGED_INFERENCE_READINESS_STATUS_READY = 1; - MANAGED_INFERENCE_READINESS_STATUS_ACTIVATION_REQUIRED = 2; - MANAGED_INFERENCE_READINESS_STATUS_FUNDING_REQUIRED = 3; - MANAGED_INFERENCE_READINESS_STATUS_LIMIT_REACHED = 4; - MANAGED_INFERENCE_READINESS_STATUS_ACCESS_SUSPENDED = 5; - MANAGED_INFERENCE_READINESS_STATUS_TEMPORARILY_UNAVAILABLE = 6; -} -enum ManagedInferenceBlocker { - MANAGED_INFERENCE_BLOCKER_UNSPECIFIED = 0; - MANAGED_INFERENCE_BLOCKER_ENROLLMENT_REQUIRED = 1; - MANAGED_INFERENCE_BLOCKER_ENROLLMENT_SUSPENDED = 2; - MANAGED_INFERENCE_BLOCKER_GATEWAY_SYNC_PENDING = 3; - MANAGED_INFERENCE_BLOCKER_FUNDING_REQUIRED = 4; - MANAGED_INFERENCE_BLOCKER_FUNDING_SUSPENDED = 5; - MANAGED_INFERENCE_BLOCKER_FUNDING_UNAVAILABLE = 6; - MANAGED_INFERENCE_BLOCKER_ROUTE_UNAVAILABLE = 7; - MANAGED_INFERENCE_BLOCKER_ENROLLMENT_UNAVAILABLE = 8; - MANAGED_INFERENCE_BLOCKER_BUDGET_LIMIT_REACHED = 9; - MANAGED_INFERENCE_BLOCKER_POLICY_UNAVAILABLE = 10; -} -enum ManagedInferenceNextAction { - MANAGED_INFERENCE_NEXT_ACTION_UNSPECIFIED = 0; - MANAGED_INFERENCE_NEXT_ACTION_CONTACT_ADMINISTRATOR = 1; - MANAGED_INFERENCE_NEXT_ACTION_VIEW_FUNDING = 2; - MANAGED_INFERENCE_NEXT_ACTION_RETRY = 3; -} -message GetStaffManagedInferenceReadinessRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - // Both omitted selects the deployment default. Supplying only one is invalid. - string provider = 3; - string model = 4; - // Omitted selects production; alternate environments must be explicit. - string environment = 5; -} -message GetManagedInferenceReadinessRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - // Both omitted selects the deployment default. Supplying only one is invalid. - string provider = 3; - string model = 4; - // Omitted selects production; alternate environments must be explicit. - string environment = 5; -} -message GetManagedInferenceReadinessResponse { - string organization_id = 1; - string workspace_id = 2; - ManagedInferenceReadinessStatus status = 3; - repeated ManagedInferenceBlocker blockers = 4; - repeated ManagedInferenceNextAction next_actions = 5; - ManagedProviderAccessState enrollment_state = 6; - uint64 enrollment_revision = 7; - bool durable_enrollment = 8; - InferenceCreditBalance funding = 9; - // Evaluated configured target, not client authority to route or execute. - InferenceProviderTarget target = 10; - google.protobuf.Timestamp evaluated_at = 11; - string environment = 12; - // Existing Meter budget projection; never a separate policy owner. - meter.v1.GetBudgetDashboardResponse budget = 13; -} - -message GetStaffManagedInferenceFundingRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - meter.v1.GetPrepaidCreditBalanceRequest request = 3; -} - -message GrantStaffManagedInferenceCreditsRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - meter.v1.GrantDevelopmentCreditsRequest request = 3; -} - -message GetStaffManagedInferenceUsageRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - meter.v1.QueryUsageRequest request = 3; -} - -message GetStaffManagedInferenceBudgetRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - meter.v1.GetBudgetDashboardRequest request = 3; -} - -message SetStaffManagedInferenceBudgetRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - meter.v1.SetBudgetRequest request = 3; - string reason = 4; - string request_id = 5; -} - -// Exact-tenant, newest-first enrollment audit read. The cursor is the last event ID. -message ListManagedProviderAccessEventsRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - int32 page_size = 3 [(buf.validate.field).int32 = { - gte: 0 - lte: 100 - }]; - string page_token = 4; -} - -// Immutable recorded fact. Pending acceptance and subsequent delivery are separate entries. -message ManagedProviderAccessEvent { - string event_id = 1; - string organization_id = 2; - string workspace_id = 3; - string provider = 4; - string environment = 5; - string action = 6; - string actor_principal_id = 7; - string note = 8; - string gateway_sync_outcome = 9; - google.protobuf.Timestamp occurred_at = 10; -} -message ListManagedProviderAccessEventsResponse { - repeated ManagedProviderAccessEvent events = 1; - string next_page_token = 2; -} - -message ListStaffManagedInferenceAdminEventsRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - meter.v1.ListManagedInferenceAdminEventsRequest request = 3; -} -message ListStaffManagedExecutionGrantEventsRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string session_id = 3 [(buf.validate.field).string.min_len = 1]; - int64 after_sequence = 4 [(buf.validate.field).int64.gte = 0]; - int32 limit = 5 [(buf.validate.field).int32 = { - gte: 0 - lte: 100 - }]; -} - -// Safe recorded issuer metadata. Expiry is a validity bound, not a fabricated lifecycle event. -message ManagedExecutionGrantEvent { - string event_id = 1; - int64 sequence = 2; - google.protobuf.Timestamp occurred_at = 3; - string action = 4; - string organization_id = 5; - string workspace_id = 6; - string session_id = 7; - string thread_id = 8; - string turn_id = 9; - string run_id = 10; - string request_id = 11; - string actor_id = 12; - string actor_kind = 13; - string authorization_id = 14; - int64 issued_at_ms = 15; - int64 expires_at_ms = 16; - uint64 grant_epoch = 17; - uint64 runtime_generation = 18; - string reason = 19; -} -message ListStaffManagedExecutionGrantEventsResponse { - repeated ManagedExecutionGrantEvent events = 1; - int64 next_sequence = 2; - int32 scanned_count = 3; -} - -message ListStaffManagedExecutionOutcomesRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string lineage_id = 3 [(buf.validate.field).string.min_len = 1]; - int32 limit = 4 [(buf.validate.field).int32 = { - gte: 0 - lte: 100 - }]; -} -message ManagedExecutionOutcome { - string record_id = 1; - string request_id = 2; - string lineage_id = 3; - string organization_id = 4; - string workspace_id = 5; - string authorization_id = 6; - string verification_status = 7; - string verification_reason = 8; - bool egress_permission = 9; - string lifecycle_state = 10; - string error_code = 11; - string provider = 12; - string model = 13; - string created_at = 14; - string completed_at = 15; -} -message ListStaffManagedExecutionOutcomesResponse { - repeated ManagedExecutionOutcome records = 1; - // True if the bounded owner read returned the requested maximum; no claim of complete history. - bool at_limit = 2; -} - -// Radar outreach-draft messages are declared at the end of this large file so -// adding the product slice does not renumber unrelated generated descriptors. - -// ProspectingDraftChannel is the channel a Radar outreach draft is written -// for. Radar does not deliver; the channel is recorded for review only. -enum ProspectingDraftChannel { - PROSPECTING_DRAFT_CHANNEL_UNSPECIFIED = 0; - PROSPECTING_DRAFT_CHANNEL_EMAIL = 1; -} - -// ProspectingDraftTone is the staff-selected register of the draft. -enum ProspectingDraftTone { - PROSPECTING_DRAFT_TONE_UNSPECIFIED = 0; - PROSPECTING_DRAFT_TONE_DIRECT = 1; - PROSPECTING_DRAFT_TONE_WARM = 2; - PROSPECTING_DRAFT_TONE_TECHNICAL = 3; -} - -// ProspectingDraftReviewState is the durable review decision on a draft. -enum ProspectingDraftReviewState { - PROSPECTING_DRAFT_REVIEW_STATE_UNSPECIFIED = 0; - PROSPECTING_DRAFT_REVIEW_STATE_REVIEW_REQUIRED = 1; - PROSPECTING_DRAFT_REVIEW_STATE_APPROVED = 2; - PROSPECTING_DRAFT_REVIEW_STATE_REJECTED = 3; -} - -// ProspectingDraftTargetAccount is the exact Identity-owned account the draft -// is bound to. Radar supplies it; Console stores it verbatim and never derives -// tenant scope from it. -message ProspectingDraftTargetAccount { - string account_organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string account_workspace_id = 2 [(buf.validate.field).string.max_len = 256]; - string identity_revision = 3 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; - string access_grant_id = 4 [(buf.validate.field).string.max_len = 256]; -} - -// ProspectingDraft is a Console-owned outreach draft held for staff review. -// -// It carries no generator lineage and no extracted claims. Nothing has -// generated this content, so those remain the generating owner's facts to -// record when an agent runtime produces a draft. An approval is a review -// decision and never delivery authority. -message ProspectingDraft { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string draft_id = 3 [(buf.validate.field).string.min_len = 1]; - string candidate_id = 4 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; - ProspectingDraftTargetAccount target_account = 5 [(buf.validate.field).required = true]; - ProspectingDraftChannel channel = 6 [(buf.validate.field).enum.defined_only = true]; - ProspectingDraftTone tone = 7 [(buf.validate.field).enum.defined_only = true]; - repeated string evidence_ids = 8 [(buf.validate.field).repeated = { - min_items: 1 - max_items: 50 - }]; - string content_digest_sha256 = 9 [(buf.validate.field).string.pattern = "^[0-9a-f]{64}$"]; - ProspectingDraftReviewState review_state = 10 [(buf.validate.field).enum.defined_only = true]; - string reviewer_principal_id = 11 [(buf.validate.field).string.max_len = 256]; - string reason = 12 [(buf.validate.field).string = { - min_len: 1 - max_len: 512 - }]; - int64 revision = 13 [(buf.validate.field).int64.gt = 0]; - string created_by_principal_id = 14 [(buf.validate.field).string.min_len = 1]; - string updated_by_principal_id = 15 [(buf.validate.field).string.min_len = 1]; - string audit_receipt_id = 16 [(buf.validate.field).string.min_len = 1]; - google.protobuf.Timestamp created_at = 17 [(buf.validate.field).required = true]; - google.protobuf.Timestamp updated_at = 18 [(buf.validate.field).required = true]; -} - -// ProspectingDraftMutationReceipt identifies the accepted draft mutation and -// whether this response is an exact idempotent replay. -message ProspectingDraftMutationReceipt { - string idempotency_key = 1 [(buf.validate.field).string.min_len = 1]; - string request_digest_sha256 = 2 [(buf.validate.field).string.pattern = "^[0-9a-f]{64}$"]; - int64 revision = 3 [(buf.validate.field).int64.gt = 0]; - string audit_receipt_id = 4 [(buf.validate.field).string.min_len = 1]; - bool replayed = 5; -} - -message CreateProspectingDraftRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string candidate_id = 2 [(buf.validate.field).string = { - min_len: 1 - max_len: 128 - }]; - ProspectingDraftTargetAccount target_account = 3 [(buf.validate.field).required = true]; - ProspectingDraftChannel channel = 4 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - ProspectingDraftTone tone = 5 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - repeated string evidence_ids = 6 [(buf.validate.field).repeated = { - min_items: 1 - max_items: 50 - }]; - string reason = 7 [(buf.validate.field).string = { - min_len: 1 - max_len: 512 - }]; - string idempotency_key = 8 [(buf.validate.field).string = { - min_len: 1 - max_len: 256 - }]; -} - -message CreateProspectingDraftResponse { - ProspectingDraft draft = 1 [(buf.validate.field).required = true]; - ProspectingDraftMutationReceipt receipt = 2 [(buf.validate.field).required = true]; -} - -message ListProspectingDraftsRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; -} - -message ListProspectingDraftsResponse { - repeated ProspectingDraft drafts = 1 [(buf.validate.field).repeated.max_items = 100]; - bool has_more = 2; -} - -message ReviewProspectingDraftRequest { - ConsoleQuery query = 1 [(buf.validate.field).required = true]; - string draft_id = 2 [(buf.validate.field).string.min_len = 1]; - ProspectingDraftReviewState decision = 3 [(buf.validate.field).enum = { - defined_only: true - in: [ - 2, - 3 - ] - }]; - int64 expected_revision = 4 [(buf.validate.field).int64.gt = 0]; - string reason = 5 [(buf.validate.field).string = { - min_len: 1 - max_len: 512 - }]; - string idempotency_key = 6 [(buf.validate.field).string = { - min_len: 1 - max_len: 256 - }]; -} - -message ReviewProspectingDraftResponse { - ProspectingDraft draft = 1 [(buf.validate.field).required = true]; - ProspectingDraftMutationReceipt receipt = 2 [(buf.validate.field).required = true]; -} - -// WorkspaceBrandVoice is declared at the end of this large file so the -// additive settings field does not renumber unrelated generated descriptors. -// It is a reusable set of writing instructions projected through a workspace's -// Content & AI policy. Archiving preserves stable references while preventing -// future assignment. -message WorkspaceBrandVoice { - message Scope { - string kind = 1 [ - (common.v1.classification) = DATA_CLASSIFICATION_CONTENT, - (buf.validate.field).string.max_len = 64 - ]; - string value = 2 [ - (common.v1.classification) = DATA_CLASSIFICATION_CONTENT, - (buf.validate.field).string.max_len = 256 - ]; - } - - string voice_id = 1 [ - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER, - (buf.validate.field).string.max_len = 128 - ]; - string name = 2 [ - (common.v1.classification) = DATA_CLASSIFICATION_CONTENT, - (buf.validate.field).string.max_len = 80 - ]; - string description = 3 [ - (common.v1.classification) = DATA_CLASSIFICATION_CONTENT, - (buf.validate.field).string.max_len = 280 - ]; - string guidance = 4 [ - (common.v1.classification) = DATA_CLASSIFICATION_CONTENT, - (buf.validate.field).string.max_len = 4000 - ]; - bool archived = 5 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - // Scopes describe where the company intends to reuse this voice. They are - // policy metadata, never authorization input. Kinds are customer-defined so - // teams can use organization, team, brand, executive, product, campaign, - // customer, or another vocabulary without a schema migration. - repeated Scope scopes = 6; - // Server-managed revision of this voice asset. It advances only when the - // voice's name, description, guidance, scopes, or archive state changes. - uint64 version = 7; - google.protobuf.Timestamp updated_at = 8; -} - -// Durable, explicitly scoped customer recovery contract. -message PrepareStaffProductIssueRecoveryRequest { - string organization_id = 1 [ - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER, - (buf.validate.field).string.max_len = 4000 - ]; - string workspace_id = 2 [ - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER, - (buf.validate.field).string.max_len = 4000 - ]; - string source_organization_id = 3 [ - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER, - (buf.validate.field).string.max_len = 4000 - ]; - string source_workspace_id = 4 [ - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER, - (buf.validate.field).string.max_len = 4000 - ]; - string report_id = 5 [ - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER, - (buf.validate.field).string.max_len = 4000 - ]; - string error_code = 6 [ - (common.v1.classification) = DATA_CLASSIFICATION_SAFE, - (buf.validate.field).string.max_len = 4000 - ]; - int64 start_unix_seconds = 7; - int64 end_unix_seconds = 8; - string recipient_principal_id = 9 [ - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER, - (buf.validate.field).string.max_len = 4000 - ]; - string customer_summary = 10 [ - (common.v1.classification) = DATA_CLASSIFICATION_CONTENT, - (buf.validate.field).string.max_len = 4000 - ]; - string deployment_verification = 11 [ - (common.v1.classification) = DATA_CLASSIFICATION_CONTENT, - (buf.validate.field).string.max_len = 4000 - ]; -} - -// Durable, explicitly scoped customer recovery contract. -message ScanStaffProductIssueRecoveryRequest { - string organization_id = 1 [ - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER, - (buf.validate.field).string.max_len = 4000 - ]; - string workspace_id = 2 [ - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER, - (buf.validate.field).string.max_len = 4000 - ]; - string recovery_id = 3 [ - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER, - (buf.validate.field).string.max_len = 4000 - ]; - int64 expected_revision = 4; -} - -message ReviewStaffProductIssueRecoveryRequest { - string organization_id = 1 [ - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER, - (buf.validate.field).string.max_len = 4000 - ]; - string workspace_id = 2 [ - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER, - (buf.validate.field).string.max_len = 4000 - ]; - string recovery_id = 3 [ - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER, - (buf.validate.field).string.max_len = 4000 - ]; - int64 expected_revision = 4; -} - -message ExecuteStaffProductIssueRecoveryRequest { - string organization_id = 1 [ - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER, - (buf.validate.field).string.max_len = 4000 - ]; - string workspace_id = 2 [ - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER, - (buf.validate.field).string.max_len = 4000 - ]; - string recovery_id = 3 [ - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER, - (buf.validate.field).string.max_len = 4000 - ]; - int64 expected_revision = 4; -} - -// Durable, explicitly scoped customer recovery contract. -message GetProductIssueRecoveryRequest { - ConsoleQuery query = 1; - string recovery_id = 2 [ - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER, - (buf.validate.field).string.max_len = 4000 - ]; -} - -// Durable, explicitly scoped customer recovery contract. -message ReplyProductIssueRecoveryRequest { - ConsoleQuery query = 1; - string recovery_id = 2 [ - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER, - (buf.validate.field).string.max_len = 4000 - ]; - string idempotency_key = 3 [ - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER, - (buf.validate.field).string.max_len = 4000 - ]; - string message = 4 [ - (common.v1.classification) = DATA_CLASSIFICATION_CONTENT, - (buf.validate.field).string.max_len = 4000 - ]; - bool resolved = 5; -} - -// Durable, explicitly scoped customer recovery contract. -message ProductIssueRecovery { - string organization_id = 1 [ - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER, - (buf.validate.field).string.max_len = 4000 - ]; - string workspace_id = 2 [ - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER, - (buf.validate.field).string.max_len = 4000 - ]; - string recovery_id = 3 [ - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER, - (buf.validate.field).string.max_len = 4000 - ]; - string report_reference = 4 [ - (common.v1.classification) = DATA_CLASSIFICATION_SAFE, - (buf.validate.field).string.max_len = 4000 - ]; - string recipient_principal_id = 5 [ - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER, - (buf.validate.field).string.max_len = 4000 - ]; - string customer_summary = 6 [ - (common.v1.classification) = DATA_CLASSIFICATION_CONTENT, - (buf.validate.field).string.max_len = 4000 - ]; - string state = 7 [ - (common.v1.classification) = DATA_CLASSIFICATION_SAFE, - (buf.validate.field).string.max_len = 4000 - ]; - int64 revision = 8; - int64 affected_request_count = 9; - int64 expected_credit_micros = 10; - int64 compensated_micros = 11; - int64 remaining_request_count = 12; - string notification_id = 13 [ - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER, - (buf.validate.field).string.max_len = 4000 - ]; - string last_reply = 14 [ - (common.v1.classification) = DATA_CLASSIFICATION_CONTENT, - (buf.validate.field).string.max_len = 4000 - ]; - string coverage = 15 [ - (common.v1.classification) = DATA_CLASSIFICATION_SAFE, - (buf.validate.field).string.max_len = 4000 - ]; - string deployment_verification = 16 [ - (common.v1.classification) = DATA_CLASSIFICATION_CONTENT, - (buf.validate.field).string.max_len = 4000 - ]; -} - -// Durable, explicitly scoped customer recovery contract. -message ProductIssueRecoveryResponse { - ProductIssueRecovery recovery = 1; -} - -// Global staff queue. Tenant scope is returned explicitly on each row. -message ListStaffProductIssueRecoveriesRequest { - // Empty means all states; otherwise one existing recovery state. - string state = 1 [(buf.validate.field).string.max_len = 32]; - // Zero defaults to 25; at most 100 rows. - uint32 page_size = 2 [(buf.validate.field).uint32.lte = 100]; - string page_token = 3 [(buf.validate.field).string.max_len = 4096]; -} -message ListStaffProductIssueRecoveriesResponse { - repeated StaffProductIssueRecoverySummary recoveries = 1; - string next_page_token = 2; -} -message StaffProductIssueRecoverySummary { - string organization_id = 1 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string workspace_id = 2 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string recovery_id = 3 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string report_reference = 4 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string recipient_principal_id = 5 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string customer_summary = 6 [(common.v1.classification) = DATA_CLASSIFICATION_CONTENT]; - string state = 7 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - google.protobuf.Timestamp created_at = 8; - string last_reply = 9 [(common.v1.classification) = DATA_CLASSIFICATION_CONTENT]; -} - -// One versioned control profile runs against one owner-fetched subject. -message AssessComplianceSubjectRequest { - string organization_id = 1 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string workspace_id = 2 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string profile_id = 3 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string subject_kind = 4 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string subject_id = 5 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; -} - -enum ComplianceFindingStatus { - COMPLIANCE_FINDING_STATUS_UNSPECIFIED = 0; - COMPLIANCE_FINDING_STATUS_SATISFIED = 1; - COMPLIANCE_FINDING_STATUS_VIOLATED = 2; - COMPLIANCE_FINDING_STATUS_INDETERMINATE = 3; - COMPLIANCE_FINDING_STATUS_NOT_APPLICABLE = 4; -} - -message ComplianceRequirementFinding { - string requirement_id = 1 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - ComplianceFindingStatus status = 2; - string reason_code = 3 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string source_ref = 4 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; -} - -// A live, bounded assessment of one execution. It is not an immutable snapshot. -message ComplianceSubjectAssessment { - string profile_id = 1 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string subject_kind = 2 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string subject_id = 3 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string source_digest = 4 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - google.protobuf.Timestamp source_updated_at = 5; - google.protobuf.Timestamp assessed_at = 6; - ComplianceFindingStatus status = 7; - repeated ComplianceRequirementFinding findings = 8; - // This route covers exactly the one requested owner record. - uint32 inspected_count = 9; - uint32 expected_count = 10; - string control_id = 11 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; -} - -message AssessComplianceSubjectResponse { - ComplianceSubjectAssessment assessment = 1; -} - -// Records a server-evaluated snapshot. A replay key always returns its first accepted result. -message RecordComplianceAssessmentRequest { - string organization_id = 1 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string workspace_id = 2 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string profile_id = 3 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string subject_kind = 4 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string subject_id = 5 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string idempotency_key = 6 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; -} - -message ComplianceAssessmentRecord { - string id = 1 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string organization_id = 2 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string workspace_id = 3 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string evaluator_version = 4 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - ComplianceSubjectAssessment assessment = 5; - string manifest_digest = 6 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string recorded_by_principal_id = 7 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; -} - -message RecordComplianceAssessmentResponse { - ComplianceAssessmentRecord record = 1; - bool idempotent_replay = 2; -} - -message GetComplianceAssessmentRequest { - string organization_id = 1 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string workspace_id = 2 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string record_id = 3 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; -} - -message GetComplianceAssessmentResponse { - ComplianceAssessmentRecord record = 1; -} diff --git a/proto/deixic/v1/deixic.proto b/proto/deixic/v1/deixic.proto deleted file mode 100644 index 7d77fd3..0000000 --- a/proto/deixic/v1/deixic.proto +++ /dev/null @@ -1,1800 +0,0 @@ -syntax = "proto3"; - -package deixic.v1; - -import "common/v1/authz.proto"; -import "console/v1/console.proto"; -import "meter/v1/meter.proto"; - -option go_package = "github.com/evalops/platform/gen/go/deixic/v1;deixicv1"; - -// DeixicService is the producer-owned browser contract served by Platform API. -// Canonical message schemas remain in console.v1 for wire compatibility. -service DeixicService { - // Evaluates a versioned compliance profile against owner-fetched, tenant-scoped facts. - rpc AssessComplianceSubject(console.v1.AssessComplianceSubjectRequest) returns (console.v1.AssessComplianceSubjectResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc RecordComplianceAssessment(console.v1.RecordComplianceAssessmentRequest) returns (console.v1.RecordComplianceAssessmentResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc GetComplianceAssessment(console.v1.GetComplianceAssessmentRequest) returns (console.v1.GetComplianceAssessmentResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Lists built-in native business blueprints available to every authorized tenant. - rpc ListBusinessBlueprints(console.v1.ListBusinessBlueprintsRequest) returns (console.v1.ListBusinessBlueprintsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Clones a pinned built-in blueprint into editable tenant-owned definitions and a draft form. - rpc CloneBusinessBlueprint(console.v1.CloneBusinessBlueprintRequest) returns (console.v1.CloneBusinessBlueprintResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // GetBusinessProcessDefinition reads immutable process definitions within the tenant. - rpc GetBusinessProcessDefinition(console.v1.GetBusinessProcessDefinitionRequest) returns (console.v1.GetBusinessProcessDefinitionResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ListBusinessProcessDefinitions reads immutable process definitions within the tenant. - rpc ListBusinessProcessDefinitions(console.v1.ListBusinessProcessDefinitionsRequest) returns (console.v1.ListBusinessProcessDefinitionsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // DefineBusinessProcess accesses the durable object-bound process owner. - rpc DefineBusinessProcess(console.v1.DefineBusinessProcessRequest) returns (console.v1.DefineBusinessProcessResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // StartBusinessProcess accesses the durable object-bound process owner. - rpc StartBusinessProcess(console.v1.StartBusinessProcessRequest) returns (console.v1.StartBusinessProcessResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // GetBusinessProcess accesses the durable object-bound process owner. - rpc GetBusinessProcess(console.v1.GetBusinessProcessRequest) returns (console.v1.GetBusinessProcessResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ListBusinessProcesses accesses the durable object-bound process owner. - rpc ListBusinessProcesses(console.v1.ListBusinessProcessesRequest) returns (console.v1.ListBusinessProcessesResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // TransitionBusinessProcess accesses the durable object-bound process owner. - rpc TransitionBusinessProcess(console.v1.TransitionBusinessProcessRequest) returns (console.v1.TransitionBusinessProcessResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Checks source-authority readiness without changing accepted state. - rpc PrepareBusinessObjectAuthorityTransfer(console.v1.PrepareBusinessObjectAuthorityTransferRequest) returns (console.v1.PrepareBusinessObjectAuthorityTransferResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Checks source-authority readiness without changing accepted state. - rpc FinalizeBusinessObjectAuthorityTransfer(console.v1.FinalizeBusinessObjectAuthorityTransferRequest) returns (console.v1.FinalizeBusinessObjectAuthorityTransferResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // DefineBusinessObjectType uses tenant-scoped durable business object state. - rpc DefineBusinessObjectType(console.v1.DefineBusinessObjectTypeRequest) returns (console.v1.DefineBusinessObjectTypeResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // GetBusinessObjectType reads an exact immutable published schema revision. - rpc GetBusinessObjectType(console.v1.GetBusinessObjectTypeRequest) returns (console.v1.GetBusinessObjectTypeResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // ListBusinessObjectTypes uses tenant-scoped durable business object state. - rpc ListBusinessObjectTypes(console.v1.ListBusinessObjectTypesRequest) returns (console.v1.ListBusinessObjectTypesResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // CreateBusinessObject uses tenant-scoped durable business object state. - rpc CreateBusinessObject(console.v1.CreateBusinessObjectRequest) returns (console.v1.CreateBusinessObjectResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // GetBusinessObject uses tenant-scoped durable business object state. - rpc GetBusinessObject(console.v1.GetBusinessObjectRequest) returns (console.v1.GetBusinessObjectResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // ListBusinessObjects uses tenant-scoped durable business object state. - rpc ListBusinessObjects(console.v1.ListBusinessObjectsRequest) returns (console.v1.ListBusinessObjectsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // UpdateBusinessObject uses tenant-scoped durable business object state. - rpc UpdateBusinessObject(console.v1.UpdateBusinessObjectRequest) returns (console.v1.UpdateBusinessObjectResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // DeleteBusinessObject uses tenant-scoped durable business object state. - rpc DeleteBusinessObject(console.v1.DeleteBusinessObjectRequest) returns (console.v1.DeleteBusinessObjectResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // ListBusinessObjectRevisions uses tenant-scoped durable business object state. - rpc ListBusinessObjectRevisions(console.v1.ListBusinessObjectRevisionsRequest) returns (console.v1.ListBusinessObjectRevisionsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // BindBusinessObjectSource uses tenant-scoped durable business object state. - rpc BindBusinessObjectSource(console.v1.BindBusinessObjectSourceRequest) returns (console.v1.BindBusinessObjectSourceResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // AdmitBusinessObjectObservation uses tenant-scoped durable business object state. - rpc AdmitBusinessObjectObservation(console.v1.AdmitBusinessObjectObservationRequest) returns (console.v1.AdmitBusinessObjectObservationResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // ListBusinessObjectRelationships uses tenant-scoped durable business object state. - rpc ListBusinessObjectRelationships(console.v1.ListBusinessObjectRelationshipsRequest) returns (console.v1.ListBusinessObjectRelationshipsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // CreateBusinessObjectRelationship uses tenant-scoped durable business object state. - rpc CreateBusinessObjectRelationship(console.v1.CreateBusinessObjectRelationshipRequest) returns (console.v1.CreateBusinessObjectRelationshipResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // DeleteBusinessObjectRelationship uses tenant-scoped durable business object state. - rpc DeleteBusinessObjectRelationship(console.v1.DeleteBusinessObjectRelationshipRequest) returns (console.v1.DeleteBusinessObjectRelationshipResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService capture-form contract. - rpc CreateCaptureForm(console.v1.CreateCaptureFormRequest) returns (console.v1.CreateCaptureFormResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // Uses the canonical console.v1.ConsoleService capture-form contract. - rpc ListCaptureForms(console.v1.ListCaptureFormsRequest) returns (console.v1.ListCaptureFormsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Uses the canonical console.v1.ConsoleService capture-form contract. - rpc GetCaptureForm(console.v1.GetCaptureFormRequest) returns (console.v1.GetCaptureFormResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Uses the canonical console.v1.ConsoleService capture-form contract. - rpc UpdateCaptureForm(console.v1.UpdateCaptureFormRequest) returns (console.v1.UpdateCaptureFormResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // Uses the canonical console.v1.ConsoleService capture-form contract. - rpc PublishCaptureForm(console.v1.PublishCaptureFormRequest) returns (console.v1.PublishCaptureFormResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // Uses the canonical console.v1.ConsoleService capture-form contract. - rpc RevokeCaptureFormPublication(console.v1.RevokeCaptureFormPublicationRequest) returns (console.v1.RevokeCaptureFormPublicationResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // CreateCaptureFormInvitation uses recipient verification at the Capture Forms owner. - rpc CreateCaptureFormInvitation(console.v1.CreateCaptureFormInvitationRequest) returns (console.v1.CreateCaptureFormInvitationResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // RevokeCaptureFormInvitation uses recipient verification at the Capture Forms owner. - rpc RevokeCaptureFormInvitation(console.v1.RevokeCaptureFormInvitationRequest) returns (console.v1.RevokeCaptureFormInvitationResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // GetInvitedCaptureForm uses recipient verification at the Capture Forms owner. - rpc GetInvitedCaptureForm(console.v1.GetInvitedCaptureFormRequest) returns (console.v1.GetInvitedCaptureFormResponse) { - option (common.v1.public) = true; - } - - // SubmitInvitedCaptureForm uses recipient verification at the Capture Forms owner. - rpc SubmitInvitedCaptureForm(console.v1.SubmitInvitedCaptureFormRequest) returns (console.v1.SubmitInvitedCaptureFormResponse) { - option (common.v1.public) = true; - } - - // Uses the canonical console.v1.ConsoleService capture-form contract. - rpc GetPublishedCaptureForm(console.v1.GetPublishedCaptureFormRequest) returns (console.v1.GetPublishedCaptureFormResponse) { - option (common.v1.public) = true; - } - // Uses the canonical console.v1.ConsoleService capture-form contract. - rpc GetPublishedCaptureFormBrandingAsset(console.v1.GetPublishedCaptureFormBrandingAssetRequest) returns (console.v1.GetPublishedCaptureFormBrandingAssetResponse) { - option (common.v1.public) = true; - } - // Uses the canonical console.v1.ConsoleService capture-form contract. - rpc SubmitPublishedCaptureForm(console.v1.SubmitPublishedCaptureFormRequest) returns (console.v1.SubmitPublishedCaptureFormResponse) { - option (common.v1.public) = true; - } - // Uses the canonical console.v1.ConsoleService capture-form contract. - rpc BeginPublishedCaptureFormUpload(console.v1.BeginPublishedCaptureFormUploadRequest) returns (console.v1.BeginPublishedCaptureFormUploadResponse) { - option (common.v1.public) = true; - } - // Uses the canonical console.v1.ConsoleService capture-form contract. - rpc CompletePublishedCaptureFormUpload(console.v1.CompletePublishedCaptureFormUploadRequest) returns (console.v1.CompletePublishedCaptureFormUploadResponse) { - option (common.v1.public) = true; - } - // Uses the canonical console.v1.ConsoleService capture-form contract. - rpc GetCaptureFormSubmission(console.v1.GetCaptureFormSubmissionRequest) returns (console.v1.GetCaptureFormSubmissionResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Uses the canonical console.v1.ConsoleService capture-form contract. - rpc ListCaptureFormSubmissions(console.v1.ListCaptureFormSubmissionsRequest) returns (console.v1.ListCaptureFormSubmissionsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Uses the canonical console.v1.ConsoleService capture-form contract. - rpc ReviewCaptureFormSubmission(console.v1.ReviewCaptureFormSubmissionRequest) returns (console.v1.ReviewCaptureFormSubmissionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // GetInferenceCreditAutoRefill uses authorized workspace billing consent. - rpc GetInferenceCreditAutoRefill(console.v1.GetInferenceCreditAutoRefillRequest) returns (console.v1.GetInferenceCreditAutoRefillResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // UpdateInferenceCreditAutoRefill uses authorized workspace billing consent. - rpc UpdateInferenceCreditAutoRefill(console.v1.UpdateInferenceCreditAutoRefillRequest) returns (console.v1.UpdateInferenceCreditAutoRefillResponse) { - option (common.v1.required_scopes) = "billing:admin"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // CompleteInferenceCreditAutoRefill uses authorized workspace billing consent. - rpc CompleteInferenceCreditAutoRefill(console.v1.CompleteInferenceCreditAutoRefillRequest) returns (console.v1.CompleteInferenceCreditAutoRefillResponse) { - option (common.v1.required_scopes) = "billing:admin"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // ListInferenceCreditReceipts returns verified payments for the authorized workspace. - rpc ListInferenceCreditReceipts(console.v1.ListInferenceCreditReceiptsRequest) returns (console.v1.ListInferenceCreditReceiptsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Uses the canonical console.v1.ConsoleService.GetInferenceCreditBalance message contract. - rpc GetInferenceCreditBalance(console.v1.GetInferenceCreditBalanceRequest) returns (console.v1.GetInferenceCreditBalanceResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Uses the canonical console.v1.ConsoleService.CreateInferenceCreditCheckout message contract. - rpc CreateInferenceCreditCheckout(console.v1.CreateInferenceCreditCheckoutRequest) returns (console.v1.CreateInferenceCreditCheckoutResponse) { - option (common.v1.required_scopes) = "billing:admin"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // Uses the canonical console.v1.ConsoleService.FulfillInferenceCreditCheckout message contract. - rpc FulfillInferenceCreditCheckout(console.v1.FulfillInferenceCreditCheckoutRequest) returns (console.v1.FulfillInferenceCreditCheckoutResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.GetOverview message contract. - rpc GetOverview(console.v1.GetOverviewRequest) returns (console.v1.GetOverviewResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.ListAssets message contract. - rpc ListAssets(console.v1.ListAssetsRequest) returns (console.v1.ListAssetsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.GetAsset message contract. - rpc GetAsset(console.v1.GetAssetRequest) returns (console.v1.GetAssetResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.ListFindings message contract. - rpc ListFindings(console.v1.ListFindingsRequest) returns (console.v1.ListFindingsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.GetTraceDrilldown message contract. - rpc GetTraceDrilldown(console.v1.GetTraceDrilldownRequest) returns (console.v1.GetTraceDrilldownResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.GetOnboardingPlan message contract. - rpc GetOnboardingPlan(console.v1.GetOnboardingPlanRequest) returns (console.v1.GetOnboardingPlanResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.ListAuthorityPosture message contract. - rpc ListAuthorityPosture(console.v1.ListAuthorityPostureRequest) returns (console.v1.ListAuthorityPostureResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.ListAgentWorkforceRecords message contract. - rpc ListAgentWorkforceRecords(console.v1.ListAgentWorkforceRecordsRequest) returns (console.v1.ListAgentWorkforceRecordsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Reads the registered agent product object from its versioned and connector owners. - rpc GetAgentProduct(console.v1.GetAgentProductRequest) returns (console.v1.GetAgentProductResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Clones safe agent behavior through the registry owner for the current workspace. - rpc CloneAgentProduct(console.v1.CloneAgentProductRequest) returns (console.v1.CloneAgentProductResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // Writes editable agent behavior through the registry's immutable versioned owner. - rpc UpdateAgentProduct(console.v1.UpdateAgentProductRequest) returns (console.v1.UpdateAgentProductResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.SubmitAgentWorkforceEvidence message contract. - rpc SubmitAgentWorkforceEvidence(console.v1.SubmitAgentWorkforceEvidenceRequest) returns (console.v1.SubmitAgentWorkforceEvidenceResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.ListIntegrationTiles message contract. - rpc ListIntegrationTiles(console.v1.ListIntegrationTilesRequest) returns (console.v1.ListIntegrationTilesResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.ListPinnedSources message contract. - rpc ListPinnedSources(console.v1.ListPinnedSourcesRequest) returns (console.v1.ListPinnedSourcesResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.ListOrbControlTargets message contract. - rpc ListOrbControlTargets(console.v1.ListOrbControlTargetsRequest) returns (console.v1.ListOrbControlTargetsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.GetOrbControlTarget message contract. - rpc GetOrbControlTarget(console.v1.GetOrbControlTargetRequest) returns (console.v1.GetOrbControlTargetResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.SubmitOrbControlAction message contract. - rpc SubmitOrbControlAction(console.v1.SubmitOrbControlActionRequest) returns (console.v1.SubmitOrbControlActionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.SetPinnedSource message contract. - rpc SetPinnedSource(console.v1.SetPinnedSourceRequest) returns (console.v1.SetPinnedSourceResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.UnpinSource message contract. - rpc UnpinSource(console.v1.UnpinSourceRequest) returns (console.v1.UnpinSourceResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.ListActivity message contract. - rpc ListActivity(console.v1.ListActivityRequest) returns (console.v1.ListActivityResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.SearchStaffWorkspaceDirectory message contract. - rpc SearchStaffWorkspaceDirectory(console.v1.SearchStaffWorkspaceDirectoryRequest) returns (console.v1.SearchStaffWorkspaceDirectoryResponse) { - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.GetStaffWorkspaceContext message contract. - rpc GetStaffWorkspaceContext(console.v1.GetStaffWorkspaceContextRequest) returns (console.v1.GetStaffWorkspaceContextResponse) { - option (common.v1.required_scopes) = "support_access.manage"; - option (common.v1.staff_account_required) = true; - option (common.v1.staff_cross_tenant) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Administrative composition over the existing Meter GetPrepaidCreditBalance owner. - rpc GetStaffManagedInferenceFunding(console.v1.GetStaffManagedInferenceFundingRequest) returns (meter.v1.GetPrepaidCreditBalanceResponse) { - option (common.v1.required_scopes) = "support_access.manage"; - option (common.v1.required_scopes) = "managed_inference:admin"; - option (common.v1.required_scopes) = "meter:read"; - option (common.v1.staff_account_required) = true; - option (common.v1.staff_cross_tenant) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Administrative composition over the existing Meter GrantDevelopmentCredits owner. - rpc GrantStaffManagedInferenceCredits(console.v1.GrantStaffManagedInferenceCreditsRequest) returns (meter.v1.GrantDevelopmentCreditsResponse) { - option (common.v1.required_scopes) = "support_access.manage"; - option (common.v1.required_scopes) = "managed_inference:admin"; - option (common.v1.required_scopes) = "meter:credits:grant-development"; - option (common.v1.staff_account_required) = true; - option (common.v1.staff_cross_tenant) = true; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // Administrative composition over the existing Meter QueryUsage owner. - rpc GetStaffManagedInferenceUsage(console.v1.GetStaffManagedInferenceUsageRequest) returns (meter.v1.QueryUsageResponse) { - option (common.v1.required_scopes) = "support_access.manage"; - option (common.v1.required_scopes) = "managed_inference:admin"; - option (common.v1.required_scopes) = "meter:read"; - option (common.v1.staff_account_required) = true; - option (common.v1.staff_cross_tenant) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Administrative composition over the existing Meter GetBudgetDashboard owner. - rpc GetStaffManagedInferenceBudget(console.v1.GetStaffManagedInferenceBudgetRequest) returns (meter.v1.GetBudgetDashboardResponse) { - option (common.v1.required_scopes) = "support_access.manage"; - option (common.v1.required_scopes) = "managed_inference:admin"; - option (common.v1.required_scopes) = "meter:read"; - option (common.v1.staff_account_required) = true; - option (common.v1.staff_cross_tenant) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Administrative composition over the existing Meter SetBudget owner. - rpc SetStaffManagedInferenceBudget(console.v1.SetStaffManagedInferenceBudgetRequest) returns (meter.v1.SetBudgetResponse) { - option (common.v1.required_scopes) = "support_access.manage"; - option (common.v1.required_scopes) = "managed_inference:admin"; - option (common.v1.required_scopes) = "meter:write"; - option (common.v1.staff_account_required) = true; - option (common.v1.staff_cross_tenant) = true; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // Read shared managed-inference readiness across tenants for an authorized administrator. - rpc GetStaffManagedInferenceReadiness(console.v1.GetStaffManagedInferenceReadinessRequest) returns (console.v1.GetManagedInferenceReadinessResponse) { - option (common.v1.required_scopes) = "support_access.manage"; - option (common.v1.required_scopes) = "managed_inference:admin"; - option (common.v1.staff_account_required) = true; - option (common.v1.staff_cross_tenant) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Reports current managed-inference prerequisites for the exact authorized tenant. - // Informational only: execution issuance and admission recheck current authority. - rpc GetManagedInferenceReadiness(console.v1.GetManagedInferenceReadinessRequest) returns (console.v1.GetManagedInferenceReadinessResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Reads the canonical tenant-scoped ListManagedProviderAccessEvents audit contract. - rpc ListManagedProviderAccessEvents(console.v1.ListManagedProviderAccessEventsRequest) returns (console.v1.ListManagedProviderAccessEventsResponse) { - option (common.v1.staff_account_required) = true; - option (common.v1.staff_cross_tenant) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Reads the canonical tenant-scoped ListStaffManagedInferenceAdminEvents audit contract. - // (-- api-linter: core::0132::response-message-name=disabled - // aip.dev/not-precedent: This staff facade returns the canonical Meter audit - // response unchanged, preserving the published cross-service contract. --) - rpc ListStaffManagedInferenceAdminEvents(console.v1.ListStaffManagedInferenceAdminEventsRequest) returns (meter.v1.ListManagedInferenceAdminEventsResponse) { - option (common.v1.staff_account_required) = true; - option (common.v1.staff_cross_tenant) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Reads the canonical tenant-scoped ListStaffManagedExecutionGrantEvents audit contract. - rpc ListStaffManagedExecutionGrantEvents(console.v1.ListStaffManagedExecutionGrantEventsRequest) returns (console.v1.ListStaffManagedExecutionGrantEventsResponse) { - option (common.v1.staff_account_required) = true; - option (common.v1.staff_cross_tenant) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Reads the canonical tenant-scoped ListStaffManagedExecutionOutcomes audit contract. - rpc ListStaffManagedExecutionOutcomes(console.v1.ListStaffManagedExecutionOutcomesRequest) returns (console.v1.ListStaffManagedExecutionOutcomesResponse) { - option (common.v1.staff_account_required) = true; - option (common.v1.staff_cross_tenant) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Uses the canonical console.v1.ConsoleService.ListManagedProviderAccessGrants message contract. - rpc ListManagedProviderAccessGrants(console.v1.ListManagedProviderAccessGrantsRequest) returns (console.v1.ListManagedProviderAccessGrantsResponse) { - option (common.v1.staff_account_required) = true; - option (common.v1.staff_cross_tenant) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.UpsertManagedProviderAccessGrant message contract. - rpc UpsertManagedProviderAccessGrant(console.v1.UpsertManagedProviderAccessGrantRequest) returns (console.v1.UpsertManagedProviderAccessGrantResponse) { - option (common.v1.staff_account_required) = true; - option (common.v1.staff_cross_tenant) = true; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.RevokeManagedProviderAccessGrant message contract. - rpc RevokeManagedProviderAccessGrant(console.v1.RevokeManagedProviderAccessGrantRequest) returns (console.v1.RevokeManagedProviderAccessGrantResponse) { - option (common.v1.staff_account_required) = true; - option (common.v1.staff_cross_tenant) = true; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.GetStaffInferenceRoutingProfile message contract. - rpc GetStaffInferenceRoutingProfile(console.v1.GetStaffInferenceRoutingProfileRequest) returns (console.v1.GetStaffInferenceRoutingProfileResponse) { - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.UpdateStaffInferenceRoutingProfile message contract. - rpc UpdateStaffInferenceRoutingProfile(console.v1.UpdateStaffInferenceRoutingProfileRequest) returns (console.v1.UpdateStaffInferenceRoutingProfileResponse) { - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.ListCostUsage message contract. - rpc ListCostUsage(console.v1.ListCostUsageRequest) returns (console.v1.ListCostUsageResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.ListEvalResults message contract. - rpc ListEvalResults(console.v1.ListEvalResultsRequest) returns (console.v1.ListEvalResultsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.RecordProviderCostSnapshot message contract. - rpc RecordProviderCostSnapshot(console.v1.RecordProviderCostSnapshotRequest) returns (console.v1.RecordProviderCostSnapshotResponse) { - option (common.v1.required_scopes) = "meter:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.GetConsoleBootSnapshot message contract. - // (-- api-linter: core::0131::request-message-name=disabled - // aip.dev/not-precedent: Deixic renames only the routed method while retaining - // the canonical Console request bytes for legacy wire compatibility. --) - rpc GetDeixicBootSnapshot(console.v1.GetConsoleBootSnapshotRequest) returns (console.v1.GetConsoleBootSnapshotResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.GetOperatorPreferences message contract. - rpc GetOperatorPreferences(console.v1.GetOperatorPreferencesRequest) returns (console.v1.GetOperatorPreferencesResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.UpdateOperatorPreferences message contract. - rpc UpdateOperatorPreferences(console.v1.UpdateOperatorPreferencesRequest) returns (console.v1.UpdateOperatorPreferencesResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.ListWorkspaceGuardrailRules message contract. - rpc ListWorkspaceGuardrailRules(console.v1.ListWorkspaceGuardrailRulesRequest) returns (console.v1.ListWorkspaceGuardrailRulesResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.UpsertWorkspaceGuardrailRule message contract. - rpc UpsertWorkspaceGuardrailRule(console.v1.UpsertWorkspaceGuardrailRuleRequest) returns (console.v1.ListWorkspaceGuardrailRulesResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.RemoveWorkspaceGuardrailRule message contract. - rpc RemoveWorkspaceGuardrailRule(console.v1.RemoveWorkspaceGuardrailRuleRequest) returns (console.v1.ListWorkspaceGuardrailRulesResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.CreateDexMcpServer message contract. - rpc CreateDexMcpServer(console.v1.CreateDexMcpServerRequest) returns (console.v1.CreateDexMcpServerResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.ListDexMcpServers message contract. - rpc ListDexMcpServers(console.v1.ListDexMcpServersRequest) returns (console.v1.ListDexMcpServersResponse) { - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.GetDexMcpServer message contract. - rpc GetDexMcpServer(console.v1.GetDexMcpServerRequest) returns (console.v1.GetDexMcpServerResponse) { - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.DiscoverDexMcpServer message contract. - rpc DiscoverDexMcpServer(console.v1.DiscoverDexMcpServerRequest) returns (console.v1.DiscoverDexMcpServerResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.UpdateDexMcpServer message contract. - rpc UpdateDexMcpServer(console.v1.UpdateDexMcpServerRequest) returns (console.v1.UpdateDexMcpServerResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.DeleteDexMcpServer message contract. - rpc DeleteDexMcpServer(console.v1.DeleteDexMcpServerRequest) returns (console.v1.DeleteDexMcpServerResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.InitiateDexMcpOAuthProfile message contract. - rpc InitiateDexMcpOAuthProfile(console.v1.InitiateDexMcpOAuthProfileRequest) returns (console.v1.InitiateDexMcpOAuthProfileResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.CompleteDexMcpOAuthProfile message contract. - rpc CompleteDexMcpOAuthProfile(console.v1.CompleteDexMcpOAuthProfileRequest) returns (console.v1.CompleteDexMcpOAuthProfileResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_CRITICAL; - } - - // Uses the canonical console.v1.ConsoleService.ListDexMcpOAuthProfiles message contract. - rpc ListDexMcpOAuthProfiles(console.v1.ListDexMcpOAuthProfilesRequest) returns (console.v1.ListDexMcpOAuthProfilesResponse) { - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.RevokeDexMcpOAuthProfile message contract. - rpc RevokeDexMcpOAuthProfile(console.v1.RevokeDexMcpOAuthProfileRequest) returns (console.v1.RevokeDexMcpOAuthProfileResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.ReauthorizeDexMcpOAuthProfile message contract. - rpc ReauthorizeDexMcpOAuthProfile(console.v1.ReauthorizeDexMcpOAuthProfileRequest) returns (console.v1.ReauthorizeDexMcpOAuthProfileResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_CRITICAL; - } - - // Uses the canonical console.v1.ConsoleService.RegisterPrivateEndpoint message contract. - rpc RegisterPrivateEndpoint(console.v1.RegisterPrivateEndpointRequest) returns (console.v1.RegisterPrivateEndpointResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.VerifyPrivateEndpoint message contract. - rpc VerifyPrivateEndpoint(console.v1.VerifyPrivateEndpointRequest) returns (console.v1.VerifyPrivateEndpointResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.ListPrivateEndpoints message contract. - rpc ListPrivateEndpoints(console.v1.ListPrivateEndpointsRequest) returns (console.v1.ListPrivateEndpointsResponse) { - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.DeletePrivateEndpoint message contract. - rpc DeletePrivateEndpoint(console.v1.DeletePrivateEndpointRequest) returns (console.v1.DeletePrivateEndpointResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.AttachPrivateEndpointToProfile message contract. - rpc AttachPrivateEndpointToProfile(console.v1.AttachPrivateEndpointToProfileRequest) returns (console.v1.AttachPrivateEndpointToProfileResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.ListGatewayEgressOrigins message contract. - rpc ListGatewayEgressOrigins(console.v1.ListGatewayEgressOriginsRequest) returns (console.v1.ListGatewayEgressOriginsResponse) { - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.ListOperatingChannels message contract. - rpc ListOperatingChannels(console.v1.ListOperatingChannelsRequest) returns (console.v1.ListOperatingChannelsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.ListOperatingJobs message contract. - rpc ListOperatingJobs(console.v1.ListOperatingJobsRequest) returns (console.v1.ListOperatingJobsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.ArchiveOperatingThread message contract. - rpc ArchiveOperatingThread(console.v1.ArchiveOperatingThreadRequest) returns (console.v1.ArchiveOperatingThreadResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.ForkOperatingThread message contract. - rpc ForkOperatingThread(console.v1.ForkOperatingThreadRequest) returns (console.v1.ForkOperatingThreadResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.RenameOperatingThread message contract. - rpc RenameOperatingThread(console.v1.RenameOperatingThreadRequest) returns (console.v1.RenameOperatingThreadResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.GetOperatingThread message contract. - rpc GetOperatingThread(console.v1.GetOperatingThreadRequest) returns (console.v1.GetOperatingThreadResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.BootstrapThreadGateway message contract. - rpc BootstrapThreadGateway(console.v1.BootstrapThreadGatewayRequest) returns (console.v1.BootstrapThreadGatewayResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.PrewarmOperatingThread message contract. - rpc PrewarmOperatingThread(console.v1.PrewarmOperatingThreadRequest) returns (console.v1.PrewarmOperatingThreadResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.RespondOperatingThread message contract. - rpc RespondOperatingThread(console.v1.RespondOperatingThreadRequest) returns (console.v1.RespondOperatingThreadResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.InterruptOperatingThread message contract. - rpc InterruptOperatingThread(console.v1.InterruptOperatingThreadRequest) returns (console.v1.InterruptOperatingThreadResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.SetOperatingThreadController message contract. - rpc SetOperatingThreadController(console.v1.SetOperatingThreadControllerRequest) returns (console.v1.SetOperatingThreadControllerResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.ListOperatingThreadEvents message contract. - rpc ListOperatingThreadEvents(console.v1.ListOperatingThreadEventsRequest) returns (console.v1.ListOperatingThreadEventsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.WatchOperatingThread message contract. - rpc WatchOperatingThread(console.v1.WatchOperatingThreadRequest) returns (stream console.v1.WatchOperatingThreadResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.SearchOperatingHistory message contract. - rpc SearchOperatingHistory(console.v1.SearchOperatingHistoryRequest) returns (console.v1.SearchOperatingHistoryResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.GetOperatingHistoryContext message contract. - rpc GetOperatingHistoryContext(console.v1.GetOperatingHistoryContextRequest) returns (console.v1.GetOperatingHistoryContextResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.GetOperatingReceipt message contract. - rpc GetOperatingReceipt(console.v1.GetOperatingReceiptRequest) returns (console.v1.GetOperatingReceiptResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.SubmitComputerMission message contract. - rpc SubmitComputerMission(console.v1.SubmitComputerMissionRequest) returns (console.v1.SubmitComputerMissionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.GetComputerMission message contract. - rpc GetComputerMission(console.v1.GetComputerMissionRequest) returns (console.v1.GetComputerMissionResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.CancelComputerMission message contract. - rpc CancelComputerMission(console.v1.CancelComputerMissionRequest) returns (console.v1.CancelComputerMissionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.ContinueComputerMission message contract. - rpc ContinueComputerMission(console.v1.ContinueComputerMissionRequest) returns (console.v1.ContinueComputerMissionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.PauseComputerMission message contract. - rpc PauseComputerMission(console.v1.PauseComputerMissionRequest) returns (console.v1.PauseComputerMissionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.ResumeComputerMission message contract. - rpc ResumeComputerMission(console.v1.ResumeComputerMissionRequest) returns (console.v1.ResumeComputerMissionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.WakeComputerMission message contract. - rpc WakeComputerMission(console.v1.WakeComputerMissionRequest) returns (console.v1.WakeComputerMissionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.GuideComputerMission message contract. - rpc GuideComputerMission(console.v1.GuideComputerMissionRequest) returns (console.v1.GuideComputerMissionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.ListComputerMissionCanaryDefinitions message contract. - rpc ListComputerMissionCanaryDefinitions(console.v1.ListComputerMissionCanaryDefinitionsRequest) returns (console.v1.ListComputerMissionCanaryDefinitionsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.StartComputerMissionCanaryRun message contract. - rpc StartComputerMissionCanaryRun(console.v1.StartComputerMissionCanaryRunRequest) returns (console.v1.StartComputerMissionCanaryRunResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.GetComputerMissionCanaryRun message contract. - rpc GetComputerMissionCanaryRun(console.v1.GetComputerMissionCanaryRunRequest) returns (console.v1.GetComputerMissionCanaryRunResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.ListComputerMissionCanaryRuns message contract. - rpc ListComputerMissionCanaryRuns(console.v1.ListComputerMissionCanaryRunsRequest) returns (console.v1.ListComputerMissionCanaryRunsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.GetComputerMissionCanaryEvidence message contract. - rpc GetComputerMissionCanaryEvidence(console.v1.GetComputerMissionCanaryEvidenceRequest) returns (console.v1.GetComputerMissionCanaryEvidenceResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.OperateComputerMissionCanaryRun message contract. - rpc OperateComputerMissionCanaryRun(console.v1.OperateComputerMissionCanaryRunRequest) returns (console.v1.OperateComputerMissionCanaryRunResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.CreateMissionSchedule message contract. - rpc CreateMissionSchedule(console.v1.CreateMissionScheduleRequest) returns (console.v1.CreateMissionScheduleResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.UpdateMissionSchedule message contract. - rpc UpdateMissionSchedule(console.v1.UpdateMissionScheduleRequest) returns (console.v1.UpdateMissionScheduleResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.SetMissionScheduleEnabled message contract. - rpc SetMissionScheduleEnabled(console.v1.SetMissionScheduleEnabledRequest) returns (console.v1.SetMissionScheduleEnabledResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.ListMissionSchedules message contract. - rpc ListMissionSchedules(console.v1.ListMissionSchedulesRequest) returns (console.v1.ListMissionSchedulesResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.CreateConnectorTrigger message contract. - rpc CreateConnectorTrigger(console.v1.CreateConnectorTriggerRequest) returns (console.v1.CreateConnectorTriggerResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.UpdateConnectorTrigger message contract. - rpc UpdateConnectorTrigger(console.v1.UpdateConnectorTriggerRequest) returns (console.v1.UpdateConnectorTriggerResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.ListConnectorTriggers message contract. - rpc ListConnectorTriggers(console.v1.ListConnectorTriggersRequest) returns (console.v1.ListConnectorTriggersResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.DeleteConnectorTrigger message contract. - rpc DeleteConnectorTrigger(console.v1.DeleteConnectorTriggerRequest) returns (console.v1.DeleteConnectorTriggerResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.SetConnectorTriggerEnabled message contract. - rpc SetConnectorTriggerEnabled(console.v1.SetConnectorTriggerEnabledRequest) returns (console.v1.SetConnectorTriggerEnabledResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.ReserveComputerMissionApexSession message contract. - rpc ReserveComputerMissionApexSession(console.v1.ReserveComputerMissionApexSessionRequest) returns (console.v1.ReserveComputerMissionApexSessionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.required_scopes) = "apex:reservation:reserve"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.BindComputerMissionApexSessionReservation message contract. - rpc BindComputerMissionApexSessionReservation(console.v1.BindComputerMissionApexSessionReservationRequest) returns (console.v1.BindComputerMissionApexSessionReservationResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.required_scopes) = "apex:reservation:bind"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.BindComputerMissionApexInstructionMetadata message contract. - rpc BindComputerMissionApexInstructionMetadata(console.v1.BindComputerMissionApexInstructionMetadataRequest) returns (console.v1.BindComputerMissionApexInstructionMetadataResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.required_scopes) = "apex:instruction:bind"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.AuthorizeComputerMissionApexSessionAdoption message contract. - rpc AuthorizeComputerMissionApexSessionAdoption(console.v1.AuthorizeComputerMissionApexSessionAdoptionRequest) returns (console.v1.AuthorizeComputerMissionApexSessionAdoptionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.required_scopes) = "apex:reservation:adopt"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.ResolveOperatingReceiptAction message contract. - rpc ResolveOperatingReceiptAction(console.v1.ResolveOperatingReceiptActionRequest) returns (console.v1.ResolveOperatingReceiptActionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.SubmitOperatingMessage message contract. - rpc SubmitOperatingMessage(console.v1.SubmitOperatingMessageRequest) returns (console.v1.SubmitOperatingMessageResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.SubmitOperatingCorrection message contract. - rpc SubmitOperatingCorrection(console.v1.SubmitOperatingCorrectionRequest) returns (console.v1.SubmitOperatingCorrectionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.ListWorkspaceMemories message contract. - rpc ListWorkspaceMemories(console.v1.ListWorkspaceMemoriesRequest) returns (console.v1.ListWorkspaceMemoriesResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.CorrectWorkspaceMemory message contract. - rpc CorrectWorkspaceMemory(console.v1.CorrectWorkspaceMemoryRequest) returns (console.v1.CorrectWorkspaceMemoryResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.ReviewWorkspaceMemory message contract. - rpc ReviewWorkspaceMemory(console.v1.ReviewWorkspaceMemoryRequest) returns (console.v1.ReviewWorkspaceMemoryResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.ForgetWorkspaceMemory message contract. - rpc ForgetWorkspaceMemory(console.v1.ForgetWorkspaceMemoryRequest) returns (console.v1.ForgetWorkspaceMemoryResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.SubmitOperatingFeedback message contract. - rpc SubmitOperatingFeedback(console.v1.SubmitOperatingFeedbackRequest) returns (console.v1.SubmitOperatingFeedbackResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.RecordOperatingHomepageSuggestionFeedback message contract. - rpc RecordOperatingHomepageSuggestionFeedback(console.v1.RecordOperatingHomepageSuggestionFeedbackRequest) returns (console.v1.RecordOperatingHomepageSuggestionFeedbackResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.SubmitProductIssueReport message contract. - rpc SubmitProductIssueReport(console.v1.SubmitProductIssueReportRequest) returns (console.v1.SubmitProductIssueReportResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Native clients submit to the same durable product issue owner using a narrow permission. - rpc SubmitNativeProductIssueReport(console.v1.SubmitNativeProductIssueReportRequest) returns (console.v1.SubmitProductIssueReportResponse) { - option (common.v1.required_scopes) = "product_issues:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.ListStaffProductIssueReports message contract. - rpc ListStaffProductIssueReports(console.v1.ListStaffProductIssueReportsRequest) returns (console.v1.ListStaffProductIssueReportsResponse) { - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.EngageStaffProductIssueReport message contract. - rpc EngageStaffProductIssueReport(console.v1.EngageStaffProductIssueReportRequest) returns (console.v1.EngageStaffProductIssueReportResponse) { - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Lists the global recovery queue under verified staff authority. - rpc ListStaffProductIssueRecoveries(console.v1.ListStaffProductIssueRecoveriesRequest) returns (console.v1.ListStaffProductIssueRecoveriesResponse) { - option (common.v1.required_scopes) = "support_access.manage"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // PrepareStaffProductIssueRecovery advances the staff-reviewed recovery of charged failures. - rpc PrepareStaffProductIssueRecovery(console.v1.PrepareStaffProductIssueRecoveryRequest) returns (console.v1.ProductIssueRecoveryResponse) { - option (common.v1.required_scopes) = "support_access.manage"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // ScanStaffProductIssueRecovery advances the staff-reviewed recovery of charged failures. - rpc ScanStaffProductIssueRecovery(console.v1.ScanStaffProductIssueRecoveryRequest) returns (console.v1.ProductIssueRecoveryResponse) { - option (common.v1.required_scopes) = "support_access.manage"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // ReviewStaffProductIssueRecovery advances the staff-reviewed recovery of charged failures. - rpc ReviewStaffProductIssueRecovery(console.v1.ReviewStaffProductIssueRecoveryRequest) returns (console.v1.ProductIssueRecoveryResponse) { - option (common.v1.required_scopes) = "support_access.manage"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // ExecuteStaffProductIssueRecovery advances the staff-reviewed recovery of charged failures. - rpc ExecuteStaffProductIssueRecovery(console.v1.ExecuteStaffProductIssueRecoveryRequest) returns (console.v1.ProductIssueRecoveryResponse) { - option (common.v1.required_scopes) = "support_access.manage"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // GetProductIssueRecovery accesses only the authenticated recovery recipient or authorized staff. - rpc GetProductIssueRecovery(console.v1.GetProductIssueRecoveryRequest) returns (console.v1.ProductIssueRecoveryResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ReplyProductIssueRecovery accesses only the authenticated recovery recipient or authorized staff. - rpc ReplyProductIssueRecovery(console.v1.ReplyProductIssueRecoveryRequest) returns (console.v1.ProductIssueRecoveryResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Uses the canonical console.v1.ConsoleService.GetOperatingFeedback message contract. - rpc GetOperatingFeedback(console.v1.GetOperatingFeedbackRequest) returns (console.v1.GetOperatingFeedbackResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.ResolveOperatingFeedbackRemediation message contract. - rpc ResolveOperatingFeedbackRemediation(console.v1.ResolveOperatingFeedbackRemediationRequest) returns (console.v1.ResolveOperatingFeedbackRemediationResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.ListCustomerIntelligenceFacts message contract. - rpc ListCustomerIntelligenceFacts(console.v1.ListCustomerIntelligenceFactsRequest) returns (console.v1.ListCustomerIntelligenceFactsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.GetCustomerIntelligenceFact message contract. - rpc GetCustomerIntelligenceFact(console.v1.GetCustomerIntelligenceFactRequest) returns (console.v1.GetCustomerIntelligenceFactResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.ReviewCustomerIntelligenceFact message contract. - rpc ReviewCustomerIntelligenceFact(console.v1.ReviewCustomerIntelligenceFactRequest) returns (console.v1.ReviewCustomerIntelligenceFactResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.ProposeCustomerIntelligenceFact message contract. - rpc ProposeCustomerIntelligenceFact(console.v1.ProposeCustomerIntelligenceFactRequest) returns (console.v1.ProposeCustomerIntelligenceFactResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.RespondToCustomerFactConfirmation message contract. - rpc RespondToCustomerFactConfirmation(console.v1.RespondToCustomerFactConfirmationRequest) returns (console.v1.RespondToCustomerFactConfirmationResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.AggregateCustomerIntelligencePatterns message contract. - rpc AggregateCustomerIntelligencePatterns(console.v1.AggregateCustomerIntelligencePatternsRequest) returns (console.v1.AggregateCustomerIntelligencePatternsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.CreateProspectingWatchProgram message contract. - rpc CreateProspectingWatchProgram(console.v1.CreateProspectingWatchProgramRequest) returns (console.v1.CreateProspectingWatchProgramResponse) { - option (common.v1.required_scopes) = "prospecting.write"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.GetProspectingWatchProgram message contract. - rpc GetProspectingWatchProgram(console.v1.GetProspectingWatchProgramRequest) returns (console.v1.GetProspectingWatchProgramResponse) { - option (common.v1.required_scopes) = "prospecting.read"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.ListProspectingWatchPrograms message contract. - rpc ListProspectingWatchPrograms(console.v1.ListProspectingWatchProgramsRequest) returns (console.v1.ListProspectingWatchProgramsResponse) { - option (common.v1.required_scopes) = "prospecting.read"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.UpdateProspectingWatchProgram message contract. - rpc UpdateProspectingWatchProgram(console.v1.UpdateProspectingWatchProgramRequest) returns (console.v1.UpdateProspectingWatchProgramResponse) { - option (common.v1.required_scopes) = "prospecting.write"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.CreateProspectingDraft message contract. - rpc CreateProspectingDraft(console.v1.CreateProspectingDraftRequest) returns (console.v1.CreateProspectingDraftResponse) { - option (common.v1.required_scopes) = "prospecting.write"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.ListProspectingDrafts message contract. - rpc ListProspectingDrafts(console.v1.ListProspectingDraftsRequest) returns (console.v1.ListProspectingDraftsResponse) { - option (common.v1.required_scopes) = "prospecting.read"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.ReviewProspectingDraft message contract. - rpc ReviewProspectingDraft(console.v1.ReviewProspectingDraftRequest) returns (console.v1.ReviewProspectingDraftResponse) { - option (common.v1.required_scopes) = "prospecting.write"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.staff_account_required) = true; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.ListOperatingCorrections message contract. - rpc ListOperatingCorrections(console.v1.ListOperatingCorrectionsRequest) returns (console.v1.ListOperatingCorrectionsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.ReviewOperatingCorrection message contract. - rpc ReviewOperatingCorrection(console.v1.ReviewOperatingCorrectionRequest) returns (console.v1.ReviewOperatingCorrectionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.BeginOperatingAttachmentUpload message contract. - rpc BeginOperatingAttachmentUpload(console.v1.BeginOperatingAttachmentUploadRequest) returns (console.v1.BeginOperatingAttachmentUploadResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.CompleteOperatingAttachmentUpload message contract. - rpc CompleteOperatingAttachmentUpload(console.v1.CompleteOperatingAttachmentUploadRequest) returns (console.v1.CompleteOperatingAttachmentUploadResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Explicit acceptance of a complete immutable project file snapshot. - rpc AcceptOperatingProjectSnapshot(console.v1.AcceptOperatingProjectSnapshotRequest) returns (console.v1.AcceptOperatingProjectSnapshotResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // Imports the connected code repository's provider-observed default branch. - rpc ImportOperatingProjectSnapshot(console.v1.ImportOperatingProjectSnapshotRequest) returns (console.v1.AcceptOperatingProjectSnapshotResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // Reads the current accepted project file snapshot. - // Reads retained task state without acquiring or refreshing a computer. - rpc GetOperatingTaskEnvironment(console.v1.GetOperatingTaskEnvironmentRequest) returns (console.v1.GetOperatingTaskEnvironmentResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc GetOperatingProjectSnapshot(console.v1.GetOperatingProjectSnapshotRequest) returns (console.v1.AcceptOperatingProjectSnapshotResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.ListOperatingAttachments message contract. - rpc ListOperatingAttachments(console.v1.ListOperatingAttachmentsRequest) returns (console.v1.ListOperatingAttachmentsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.organization_scope_field) = "query.organization_id"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.GetPrivacySettings message contract. - rpc GetPrivacySettings(console.v1.GetPrivacySettingsRequest) returns (console.v1.GetPrivacySettingsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.SetPrivacySettings message contract. - rpc SetPrivacySettings(console.v1.SetPrivacySettingsRequest) returns (console.v1.GetPrivacySettingsResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.GetWorkspaceSettings message contract. - rpc GetWorkspaceSettings(console.v1.GetWorkspaceSettingsRequest) returns (console.v1.GetWorkspaceSettingsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.GetBillingSubscription message contract. - rpc GetBillingSubscription(console.v1.GetBillingSubscriptionRequest) returns (console.v1.GetBillingSubscriptionResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.CreateBillingPortalSession message contract. - rpc CreateBillingPortalSession(console.v1.CreateBillingPortalSessionRequest) returns (console.v1.CreateBillingPortalSessionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.CreateBillingCheckoutSession message contract. - rpc CreateBillingCheckoutSession(console.v1.CreateBillingCheckoutSessionRequest) returns (console.v1.CreateBillingCheckoutSessionResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.UpdateWorkspaceProfile message contract. - rpc UpdateWorkspaceProfile(console.v1.UpdateWorkspaceProfileRequest) returns (console.v1.UpdateWorkspaceProfileResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.ArchiveWorkspace message contract. - rpc ArchiveWorkspace(console.v1.ArchiveWorkspaceRequest) returns (console.v1.ArchiveWorkspaceResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.UpdateWorkspacePolicy message contract. - rpc UpdateWorkspacePolicy(console.v1.UpdateWorkspacePolicyRequest) returns (console.v1.UpdateWorkspacePolicyResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.UpdateWorkspaceDexPolicy message contract. - rpc UpdateWorkspaceDexPolicy(console.v1.UpdateWorkspaceDexPolicyRequest) returns (console.v1.UpdateWorkspaceDexPolicyResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.UpdateWorkspaceArtifactStyleGuide message contract. - rpc UpdateWorkspaceArtifactStyleGuide(console.v1.UpdateWorkspaceArtifactStyleGuideRequest) returns (console.v1.UpdateWorkspaceArtifactStyleGuideResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.EvaluateWorkspaceArtifactStyleGuide message contract. - rpc EvaluateWorkspaceArtifactStyleGuide(console.v1.EvaluateWorkspaceArtifactStyleGuideRequest) returns (console.v1.EvaluateWorkspaceArtifactStyleGuideResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.UpsertWorkspaceIdentityProvider message contract. - rpc UpsertWorkspaceIdentityProvider(console.v1.UpsertWorkspaceIdentityProviderRequest) returns (console.v1.UpsertWorkspaceIdentityProviderResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.RemoveWorkspaceIdentityProvider message contract. - rpc RemoveWorkspaceIdentityProvider(console.v1.RemoveWorkspaceIdentityProviderRequest) returns (console.v1.RemoveWorkspaceIdentityProviderResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.UpsertWorkspaceIntegration message contract. - rpc UpsertWorkspaceIntegration(console.v1.UpsertWorkspaceIntegrationRequest) returns (console.v1.UpsertWorkspaceIntegrationResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.RemoveWorkspaceIntegration message contract. - rpc RemoveWorkspaceIntegration(console.v1.RemoveWorkspaceIntegrationRequest) returns (console.v1.RemoveWorkspaceIntegrationResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.UpdateWorkspaceBilling message contract. - rpc UpdateWorkspaceBilling(console.v1.UpdateWorkspaceBillingRequest) returns (console.v1.GetWorkspaceSettingsResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.UpsertWorkspaceMember message contract. - rpc UpsertWorkspaceMember(console.v1.UpsertWorkspaceMemberRequest) returns (console.v1.GetWorkspaceSettingsResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.RemoveWorkspaceMember message contract. - rpc RemoveWorkspaceMember(console.v1.RemoveWorkspaceMemberRequest) returns (console.v1.GetWorkspaceSettingsResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.UpdateWorkspaceNotificationPreferences message contract. - rpc UpdateWorkspaceNotificationPreferences(console.v1.UpdateWorkspaceNotificationPreferencesRequest) returns (console.v1.GetWorkspaceSettingsResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.EnableWorkspaceBreakGlass message contract. - rpc EnableWorkspaceBreakGlass(console.v1.EnableWorkspaceBreakGlassRequest) returns (console.v1.GetWorkspaceSettingsResponse) { - option (common.v1.required_scopes) = "support_access.manage"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.DisableWorkspaceBreakGlass message contract. - rpc DisableWorkspaceBreakGlass(console.v1.DisableWorkspaceBreakGlassRequest) returns (console.v1.GetWorkspaceSettingsResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.ListWorkspaceSkills message contract. - rpc ListWorkspaceSkills(console.v1.ListWorkspaceSkillsRequest) returns (console.v1.ListWorkspaceSkillsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.BrowseDexSkillCatalog message contract. - rpc BrowseDexSkillCatalog(console.v1.BrowseDexSkillCatalogRequest) returns (console.v1.BrowseDexSkillCatalogResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.InstallDexSkillCatalogEntry message contract. - rpc InstallDexSkillCatalogEntry(console.v1.InstallDexSkillCatalogEntryRequest) returns (console.v1.InstallDexSkillCatalogEntryResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.CreateWorkspaceSkill message contract. - rpc CreateWorkspaceSkill(console.v1.CreateWorkspaceSkillRequest) returns (console.v1.CreateWorkspaceSkillResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.UpdateWorkspaceSkill message contract. - rpc UpdateWorkspaceSkill(console.v1.UpdateWorkspaceSkillRequest) returns (console.v1.UpdateWorkspaceSkillResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.DeleteWorkspaceSkill message contract. - rpc DeleteWorkspaceSkill(console.v1.DeleteWorkspaceSkillRequest) returns (console.v1.DeleteWorkspaceSkillResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.ListScenarioFixtures message contract. - rpc ListScenarioFixtures(console.v1.ListScenarioFixturesRequest) returns (console.v1.ListScenarioFixturesResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.organization_scope_field) = "organization_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.PromoteScenarioFixture message contract. - rpc PromoteScenarioFixture(console.v1.PromoteScenarioFixtureRequest) returns (console.v1.PromoteScenarioFixtureResponse) { - option (common.v1.required_scopes) = "console:write"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.organization_scope_field) = "organization_id"; - - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.CompareScenarioFixtures message contract. - rpc CompareScenarioFixtures(console.v1.CompareScenarioFixturesRequest) returns (console.v1.CompareScenarioFixturesResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.organization_scope_field) = "organization_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.CreateConnectorProfile message contract. - rpc CreateConnectorProfile(console.v1.CreateConnectorProfileRequest) returns (console.v1.CreateConnectorProfileResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.ListConnectorProfiles message contract. - rpc ListConnectorProfiles(console.v1.ListConnectorProfilesRequest) returns (console.v1.ListConnectorProfilesResponse) { - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.UpdateConnectorProfile message contract. - rpc UpdateConnectorProfile(console.v1.UpdateConnectorProfileRequest) returns (console.v1.UpdateConnectorProfileResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.DeleteConnectorProfile message contract. - rpc DeleteConnectorProfile(console.v1.DeleteConnectorProfileRequest) returns (console.v1.DeleteConnectorProfileResponse) { - option (common.v1.required_scopes) = "connectors:write"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.ListConnectedCalls message contract. - rpc ListConnectedCalls(console.v1.ListConnectedCallsRequest) returns (console.v1.ListConnectedCallsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.StartMeetingCapture message contract. - rpc StartMeetingCapture(console.v1.StartMeetingCaptureRequest) returns (console.v1.StartMeetingCaptureResponse) { - option (common.v1.required_scopes) = "platform:write"; - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // Uses the canonical console.v1.ConsoleService.GetMeetingCapture message contract. - rpc GetMeetingCapture(console.v1.GetMeetingCaptureRequest) returns (console.v1.GetMeetingCaptureResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.ListMeetingCaptures message contract. - rpc ListMeetingCaptures(console.v1.ListMeetingCapturesRequest) returns (console.v1.ListMeetingCapturesResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // Uses the canonical console.v1.ConsoleService.StopMeetingCapture message contract. - rpc StopMeetingCapture(console.v1.StopMeetingCaptureRequest) returns (console.v1.StopMeetingCaptureResponse) { - option (common.v1.required_scopes) = "platform:write"; - option (common.v1.required_scopes) = "connectors:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // Uses the canonical console.v1.ConsoleService.ListCommitments message contract. - rpc ListCommitments(console.v1.ListCommitmentsRequest) returns (console.v1.ListCommitmentsResponse) { - option (common.v1.required_scopes) = "console:read"; - option (common.v1.workspace_scope_field) = "query.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } -} diff --git a/proto/deixicpublic/v1/sdk.proto b/proto/deixicpublic/v1/sdk.proto new file mode 100644 index 0000000..21cc80c --- /dev/null +++ b/proto/deixicpublic/v1/sdk.proto @@ -0,0 +1,604 @@ +syntax = "proto3"; + +package deixicpublic.v1; + +import "google/protobuf/timestamp.proto"; + +option go_package = "github.com/dx-corp/deixic-go/deixicpublic/v1;deixicpublicv1"; + +// This is the complete application SDK wire contract. Public messages are +// projections owned by this service, not aliases of implementation records. +service DeixicPublicService { + rpc GetThread(GetThreadRequest) returns (GetThreadResponse); + rpc ListThreads(ListThreadsRequest) returns (ListThreadsResponse); + rpc RenameThread(RenameThreadRequest) returns (RenameThreadResponse); + rpc ArchiveThread(ArchiveThreadRequest) returns (ArchiveThreadResponse); + rpc ListEvents(ListEventsRequest) returns (ListEventsResponse); + rpc WatchEvents(WatchEventsRequest) returns (stream WatchEventsResponse); + rpc SubmitTask(SubmitTaskRequest) returns (SubmitTaskResponse); + rpc InterruptTask(InterruptTaskRequest) returns (InterruptTaskResponse); + rpc RespondToRequest(RespondToRequestRequest) returns (RespondToRequestResponse); + rpc GetReceipt(GetReceiptRequest) returns (GetReceiptResponse); + rpc ResolveReceiptAction(ResolveReceiptActionRequest) returns (ResolveReceiptActionResponse); + rpc GetModelReadiness(GetModelReadinessRequest) returns (GetModelReadinessResponse); + rpc GetClientSetup(GetClientSetupRequest) returns (GetClientSetupResponse); + rpc SubmitIssueReport(SubmitIssueReportRequest) returns (SubmitIssueReportResponse); + rpc CreateBusinessObject(CreateBusinessObjectRequest) returns (CreateBusinessObjectResponse); + rpc GetBusinessObject(GetBusinessObjectRequest) returns (GetBusinessObjectResponse); + rpc UpdateBusinessObject(UpdateBusinessObjectRequest) returns (UpdateBusinessObjectResponse); + rpc DeleteBusinessObject(DeleteBusinessObjectRequest) returns (DeleteBusinessObjectResponse); +} + +message Scope { + string organization_id = 1; + string workspace_id = 2; +} + +message ErrorDetail { + string code = 1; + string message = 2; + string request_id = 3; + bool retryable = 4; +} + +enum TurnState { + TURN_STATE_UNSPECIFIED = 0; + TURN_STATE_ACCEPTED = 1; + TURN_STATE_RUNNING = 2; + TURN_STATE_WAITING = 3; + TURN_STATE_RESPONDED = 4; + TURN_STATE_COMPLETED = 5; + TURN_STATE_FAILED = 6; + TURN_STATE_INTERRUPTED = 7; +} + +enum WaitingReason { + WAITING_REASON_UNSPECIFIED = 0; + WAITING_REASON_APPROVAL = 1; + WAITING_REASON_USER_INPUT = 2; + WAITING_REASON_CLIENT_TOOL = 3; + WAITING_REASON_EXTERNAL_RETRY = 4; +} + +message TaskTurn { + string turn_id = 1; + int64 sequence = 2; + string user_message_id = 3; + string assistant_message_id = 4; + TurnState state = 5; + WaitingReason waiting_reason = 6; + int64 first_cursor = 7; + int64 last_cursor = 8; + ErrorDetail terminal_error = 9; + google.protobuf.Timestamp created_at = 10; + google.protobuf.Timestamp updated_at = 11; + google.protobuf.Timestamp completed_at = 12; +} + +message Thread { + string id = 1; + string title = 2; + int64 replay_cursor = 3; + int64 active_turn_sequence = 4; + google.protobuf.Timestamp updated_at = 5; + int32 unread_count = 6; + int32 open_count = 7; + bool archived = 8; +} + +enum MessageRole { + MESSAGE_ROLE_UNSPECIFIED = 0; + MESSAGE_ROLE_USER = 1; + MESSAGE_ROLE_ASSISTANT = 2; + MESSAGE_ROLE_SYSTEM = 3; +} + +message TaskMessage { + string id = 1; + MessageRole role = 2; + string body = 3; + google.protobuf.Timestamp created_at = 4; + repeated string receipt_ids = 5; +} + +enum EventKind { + EVENT_KIND_UNSPECIFIED = 0; + EVENT_KIND_TURN_ACCEPTED = 1; + EVENT_KIND_TURN_STARTED = 2; + EVENT_KIND_PROGRESS = 3; + EVENT_KIND_APPROVAL_REQUIRED = 4; + EVENT_KIND_INPUT_REQUIRED = 5; + EVENT_KIND_ARTIFACT_RECORDED = 6; + EVENT_KIND_TURN_COMPLETED = 7; + EVENT_KIND_TURN_FAILED = 8; + EVENT_KIND_TURN_INTERRUPTED = 9; + EVENT_KIND_CLIENT_TOOL_REQUIRED = 10; + EVENT_KIND_EXTERNAL_RETRY_REQUIRED = 11; +} + +enum RequestKind { + REQUEST_KIND_UNSPECIFIED = 0; + REQUEST_KIND_APPROVAL = 1; + REQUEST_KIND_USER_INPUT = 2; + REQUEST_KIND_CLIENT_TOOL = 3; + REQUEST_KIND_EXTERNAL_RETRY = 4; +} + +message EvidenceReference { + string kind = 1; + string id = 2; + string label = 3; + string uri = 4; +} + +message TaskEvent { + int64 cursor = 1; + string id = 2; + string turn_id = 3; + EventKind kind = 4; + string text = 5; + repeated EvidenceReference evidence = 6; + google.protobuf.Timestamp created_at = 7; + string request_id = 8; + RequestKind request_kind = 9; + string tool_name = 10; + string call_id = 11; + ErrorDetail terminal_error = 12; +} + +enum ReceiptState { + RECEIPT_STATE_UNSPECIFIED = 0; + RECEIPT_STATE_UNKNOWN = 1; + RECEIPT_STATE_PROPOSED = 2; + RECEIPT_STATE_QUEUED = 3; + RECEIPT_STATE_WAITING_APPROVAL = 4; + RECEIPT_STATE_BLOCKED = 5; + RECEIPT_STATE_NEEDS_INPUT = 6; + RECEIPT_STATE_UNAVAILABLE = 7; + RECEIPT_STATE_RUNNING = 8; + RECEIPT_STATE_SUCCEEDED = 9; + RECEIPT_STATE_VERIFIED = 10; + RECEIPT_STATE_DENIED = 11; + RECEIPT_STATE_CANCELLED = 12; + RECEIPT_STATE_FAILED = 13; +} + +message ReceiptAction { + string id = 1; + string label = 2; + string kind = 3; + bool requires_confirmation = 4; + string disabled_reason = 5; +} + +message CodingOutput { + string path = 1; + string object_id = 2; + string version_id = 3; + string sha256 = 4; + uint64 size_bytes = 5; + // Included only in an explicitly requested receipt read by the authorized actor. + bytes content = 6; +} + +message CodingAcceptance { + bool accepted = 1; + string contract_digest = 2; + string submission_digest = 3; + repeated string reasons = 4; + string revision = 5; + repeated CodingOutput outputs = 6; +} + +message Receipt { + string id = 1; + string kind = 2; + string title = 3; + string summary = 4; + ReceiptState state = 5; + google.protobuf.Timestamp updated_at = 6; + repeated ReceiptAction allowed_actions = 7; + repeated EvidenceReference evidence = 8; + CodingAcceptance coding_acceptance = 9; +} + +message ModelSelection { + string provider = 1; + string model = 2; +} + +message AvailableModel { + string provider = 1; + string model = 2; + bool ready = 3; + string display_name = 4; +} + +message SetupReadiness { + bool accessible = 1; + repeated string missing_requirements = 2; + ModelSelection selection = 3; + AvailableModel default_model = 4; + repeated AvailableModel available_models = 5; + string next_action = 6; +} + +// Model readiness is an application-level decision; billing and routing +// implementation details stay behind this projection. +enum ModelReadinessState { + MODEL_READINESS_STATE_UNSPECIFIED = 0; + MODEL_READINESS_STATE_READY = 1; + MODEL_READINESS_STATE_ACTIVATION_REQUIRED = 2; + MODEL_READINESS_STATE_FUNDING_REQUIRED = 3; + MODEL_READINESS_STATE_LIMIT_REACHED = 4; + MODEL_READINESS_STATE_ACCESS_SUSPENDED = 5; + MODEL_READINESS_STATE_TEMPORARILY_UNAVAILABLE = 6; +} + +enum ModelNextAction { + MODEL_NEXT_ACTION_UNSPECIFIED = 0; + MODEL_NEXT_ACTION_CONTACT_ADMINISTRATOR = 1; + MODEL_NEXT_ACTION_VIEW_FUNDING = 2; + MODEL_NEXT_ACTION_RETRY = 3; +} + +message GetModelReadinessRequest { + Scope scope = 1; + ModelSelection selection = 2; + string environment = 3; +} + +message GetModelReadinessResponse { + Scope scope = 1; + ModelSelection selection = 2; + string environment = 3; + ModelReadinessState state = 4; + repeated ModelNextAction next_actions = 5; + google.protobuf.Timestamp evaluated_at = 6; +} + +enum ClientRuleScope { + CLIENT_RULE_SCOPE_UNSPECIFIED = 0; + CLIENT_RULE_SCOPE_ORGANIZATION = 1; + CLIENT_RULE_SCOPE_WORKSPACE = 2; +} + +message ClientRule { + string id = 1; + string title = 2; + string body_markdown = 3; + ClientRuleScope scope = 4; +} + +message ClientSkill { + string id = 1; + string source = 2; + string version = 3; + bool required = 4; +} + +enum ClientMcpMode { + CLIENT_MCP_MODE_UNSPECIFIED = 0; + CLIENT_MCP_MODE_OPEN = 1; + CLIENT_MCP_MODE_ALLOWLIST = 2; + CLIENT_MCP_MODE_DENYLIST = 3; +} + +message ClientMcpServer { + string name = 1; + string url_pattern = 2; + string transport = 3; +} + +message ClientMcpPolicy { + ClientMcpMode mode = 1; + repeated ClientMcpServer servers = 2; +} + +message GetClientSetupRequest { + Scope scope = 1; +} + +message GetClientSetupResponse { + Scope scope = 1; + uint64 version = 2; + google.protobuf.Timestamp issued_at = 3; + repeated ClientRule rules = 4; + repeated ClientSkill skills = 5; + ClientMcpPolicy mcp = 6; + string sandbox_policy_toml = 7; +} + +message IssueEvidence { + string kind = 1; + string source_id = 2; + string text = 3; +} + +message IssueContext { + string reproduction_steps = 1; + string model = 2; + repeated IssueEvidence evidence = 3; +} + +message SubmitIssueReportRequest { + Scope scope = 1; + string description = 2; + string expected_behavior = 3; + string app_version = 4; + bool include_diagnostics = 5; + string idempotency_key = 6; + IssueContext context = 7; +} + +message IssueReport { + string id = 1; + string reference = 2; +} + +message SubmitIssueReportResponse { + IssueReport report = 1; +} + +// This resource is the supported Terraform provider contract. Source authority, +// connector state and recovery coordinates belong to the implementation. +message BusinessMoney { + string amount = 1; + string currency = 2; +} +message BusinessObjectReference { + string object_id = 1; +} +message BusinessArtifactReference { + string artifact_version_id = 1; +} +message BusinessTextList { + repeated string values = 1; +} +message BusinessFieldValue { + string field_id = 1; + oneof value { + string text = 2; + int64 integer = 3; + bool boolean = 4; + string decimal = 5; + BusinessMoney money = 6; + string enum_value = 7; + string date = 8; + string timestamp = 9; + BusinessObjectReference reference = 10; + BusinessArtifactReference artifact = 11; + BusinessTextList text_list = 12; + } +} +message BusinessObject { + string object_id = 1; + string type_id = 2; + int64 schema_revision = 3; + int64 revision = 4; + repeated BusinessFieldValue values = 5; + bool deleted = 6; + reserved 7, 8; + string updated_at = 9; + string created_at = 10; +} +message CreateBusinessObjectRequest { + string organization_id = 1; + string workspace_id = 2; + string idempotency_key = 3; + string type_id = 4; + int64 schema_revision = 5; + repeated BusinessFieldValue values = 6; +} +message CreateBusinessObjectResponse { + BusinessObject object = 1; +} +message GetBusinessObjectRequest { + string organization_id = 1; + string workspace_id = 2; + reserved 3; + string object_id = 4; + reserved 5; +} +message GetBusinessObjectResponse { + BusinessObject object = 1; +} +message UpdateBusinessObjectRequest { + string organization_id = 1; + string workspace_id = 2; + string idempotency_key = 3; + string object_id = 4; + int64 expected_revision = 5; + repeated BusinessFieldValue values = 6; + int64 schema_revision = 7; +} +message UpdateBusinessObjectResponse { + BusinessObject object = 1; +} +message DeleteBusinessObjectRequest { + string organization_id = 1; + string workspace_id = 2; + string idempotency_key = 3; + string object_id = 4; + int64 expected_revision = 5; +} +message DeleteBusinessObjectResponse { + BusinessObject object = 1; +} + +message GetThreadRequest { + Scope scope = 1; + string thread_id = 2; + int32 limit = 3; + string page_token = 4; +} + +message GetThreadResponse { + Thread thread = 1; + repeated TaskMessage messages = 2; + repeated Receipt receipts = 3; + repeated TaskTurn turns = 4; + int64 replay_cursor = 5; + string next_page_token = 6; + SetupReadiness setup = 7; +} + +message ListThreadsRequest { + Scope scope = 1; + bool archived = 2; +} + +message ListThreadsResponse { + repeated Thread threads = 1; +} + +message RenameThreadRequest { + Scope scope = 1; + string thread_id = 2; + string title = 3; +} + +message RenameThreadResponse { + Thread thread = 1; + bool changed = 2; +} + +message ArchiveThreadRequest { + Scope scope = 1; + string thread_id = 2; + bool archived = 3; + string idempotency_key = 4; +} + +message ArchiveThreadResponse { + Thread thread = 1; + bool changed = 2; + bool replayed = 3; +} + +message ListEventsRequest { + Scope scope = 1; + string thread_id = 2; + int64 after_cursor = 3; + int32 limit = 4; +} + +message ListEventsResponse { + repeated TaskEvent events = 1; + int64 next_cursor = 2; + bool has_more = 3; + bool reset_required = 4; + Thread snapshot = 5; + repeated TaskTurn snapshot_turns = 6; +} + +message WatchEventsRequest { + Scope scope = 1; + string thread_id = 2; + int64 after_cursor = 3; +} + +message WatchEventsResponse { + repeated TaskEvent events = 1; + int64 next_cursor = 2; + bool reset_required = 3; + Thread snapshot = 4; + repeated TaskTurn snapshot_turns = 5; +} + +message CodingContract { + string repository_id = 1; + uint64 generation = 2; + repeated string required_assertion_ids = 3; + bool require_review = 4; + bool require_behavior = 5; + repeated string readiness_requirements = 6; + repeated string authorized_skips = 7; + repeated string authorized_dispositions = 8; + repeated string output_paths = 9; +} + +message SubmitTaskRequest { + Scope scope = 1; + string thread_id = 2; + string body = 3; + string idempotency_key = 4; + string continuation_task_id = 5; + repeated string reference_task_ids = 6; + ModelSelection model_selection = 7; + CodingContract coding_contract = 8; + string project_resource_id = 9; +} + +message SubmitTaskResponse { + TaskMessage message = 1; + TaskTurn accepted_turn = 2; + int64 replay_cursor = 3; + repeated Receipt receipts = 4; +} + +message InterruptTaskRequest { + Scope scope = 1; + string thread_id = 2; + string turn_id = 3; + string idempotency_key = 4; + string reason = 5; +} + +message InterruptTaskResponse { + string turn_id = 1; + bool replayed = 2; + repeated TaskTurn turns = 3; + int64 replay_cursor = 4; +} + +enum ResponseAction { + RESPONSE_ACTION_UNSPECIFIED = 0; + RESPONSE_ACTION_APPROVE = 1; + RESPONSE_ACTION_DENY = 2; + RESPONSE_ACTION_ANSWER = 3; + RESPONSE_ACTION_RETRY = 4; + RESPONSE_ACTION_SKIP = 5; + RESPONSE_ACTION_ABORT = 6; +} + +message RespondToRequestRequest { + Scope scope = 1; + string thread_id = 2; + string turn_id = 3; + string request_id = 4; + string call_id = 5; + RequestKind request_kind = 6; + ResponseAction action = 7; + string text = 8; + bool is_error = 9; + string idempotency_key = 10; +} + +message RespondToRequestResponse { + bool replayed = 1; + repeated TaskTurn turns = 2; + int64 replay_cursor = 3; +} + +message GetReceiptRequest { + Scope scope = 1; + string receipt_id = 2; + string thread_id = 3; + bool include_coding_output_content = 4; +} + +message GetReceiptResponse { + Receipt receipt = 1; +} + +message ResolveReceiptActionRequest { + Scope scope = 1; + string receipt_id = 2; + string action_id = 3; + string idempotency_key = 4; +} + +message ResolveReceiptActionResponse { + Receipt receipt = 1; +} diff --git a/proto/memory/v1/memory.proto b/proto/memory/v1/memory.proto deleted file mode 100644 index 3e0f1f2..0000000 --- a/proto/memory/v1/memory.proto +++ /dev/null @@ -1,522 +0,0 @@ -syntax = "proto3"; - -package memory.v1; - -import "buf/validate/validate.proto"; -import "common/v1/authz.proto"; -import "google/protobuf/timestamp.proto"; -import "platform/v1/platform.proto"; - -option go_package = "github.com/evalops/platform/gen/go/memory/v1;memoryv1"; - -// MemoryService provides semantic memory storage and recall. -// Canonical contract for evalops/memory, replacing hand-written structs -// in chat (externalmemory/client.go) and ensemble (src/lib/memory/). -service MemoryService { - rpc Store(StoreRequest) returns (StoreResponse) { - option (common.v1.required_scopes) = "memories:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc StoreBatch(StoreBatchRequest) returns (StoreBatchResponse) { - option (common.v1.required_scopes) = "memories:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc Recall(RecallRequest) returns (RecallResponse) { - option (common.v1.required_scopes) = "memories:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc RecallKnowledge(RecallKnowledgeRequest) returns (RecallKnowledgeResponse) { - option (common.v1.required_scopes) = "memories:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc GetMemory(GetMemoryRequest) returns (GetMemoryResponse) { - option (common.v1.required_scopes) = "memories:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc ExplainMemory(ExplainMemoryRequest) returns (ExplainMemoryResponse) { - option (common.v1.required_scopes) = "memories:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc ClusterMemories(ClusterMemoriesRequest) returns (ClusterMemoriesResponse) { - option (common.v1.required_scopes) = "memories:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc Update(UpdateRequest) returns (UpdateResponse) { - option (common.v1.required_scopes) = "memories:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // PromoteReviewedLearning atomically approves an exact proposed memory and - // persists the immutable planner-impact receipt that authorized activation. - rpc PromoteReviewedLearning(PromoteReviewedLearningRequest) returns (PromoteReviewedLearningResponse) { - option (common.v1.required_scopes) = "memories:write"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - rpc Delete(DeleteRequest) returns (DeleteResponse) { - option (common.v1.required_scopes) = "memories:write"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - rpc List(ListRequest) returns (ListResponse) { - option (common.v1.required_scopes) = "memories:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc LinkMemories(LinkMemoriesRequest) returns (LinkMemoriesResponse) { - option (common.v1.required_scopes) = "memories:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc ListMemoryRelationships(ListMemoryRelationshipsRequest) returns (ListMemoryRelationshipsResponse) { - option (common.v1.required_scopes) = "memories:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc DeleteMemoryRelationship(DeleteMemoryRelationshipRequest) returns (DeleteMemoryRelationshipResponse) { - option (common.v1.required_scopes) = "memories:write"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - rpc GetOperatingRules(GetOperatingRulesRequest) returns (GetOperatingRulesResponse) { - option (common.v1.required_scopes) = "memories:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc Consolidate(ConsolidateRequest) returns (ConsolidateResponse) { - option (common.v1.required_scopes) = "memories:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } -} - -// Scope controls memory visibility. -enum Scope { - SCOPE_UNSPECIFIED = 0; - SCOPE_USER = 1; - SCOPE_TEAM = 2; - SCOPE_ORGANIZATION = 3; - SCOPE_AGENT = 4; - SCOPE_PROJECT = 5; -} - -// MemoryReviewStatus controls whether a memory is active for recall or still -// reviewable as a proposal. -enum MemoryReviewStatus { - MEMORY_REVIEW_STATUS_UNSPECIFIED = 0; - MEMORY_REVIEW_STATUS_APPROVED = 1; - MEMORY_REVIEW_STATUS_PROPOSED = 2; - MEMORY_REVIEW_STATUS_REJECTED = 3; -} - -enum MemoryLifecycleState { - MEMORY_LIFECYCLE_STATE_UNSPECIFIED = 0; - MEMORY_LIFECYCLE_STATE_ACTIVE = 1; - MEMORY_LIFECYCLE_STATE_FORGOTTEN = 2; -} - -enum MemoryLifecycleEventType { - MEMORY_LIFECYCLE_EVENT_TYPE_UNSPECIFIED = 0; - MEMORY_LIFECYCLE_EVENT_TYPE_CREATED = 1; - MEMORY_LIFECYCLE_EVENT_TYPE_CORRECTED = 2; - MEMORY_LIFECYCLE_EVENT_TYPE_FORGOTTEN = 3; - MEMORY_LIFECYCLE_EVENT_TYPE_REVIEWED = 4; -} - -// SourceReference captures structured provenance for a memory. -message SourceReference { - string uri = 1; - string title = 2; - string type = 3; - map metadata = 4; - platform.v1.ResourceRef resource_ref = 5; -} - -// Memory is the canonical memory record. -// Unifies chat's Memory proto and ensemble's TypeScript memory types. -message Memory { - string id = 1; - Scope scope = 2; - string content = 3; - string type = 4; - string source = 5; - float confidence = 6; - bool pinned = 7; - - // Packed float encoding — ~4x smaller than JSON float arrays. - repeated float embedding = 8 [packed = true]; - - string workspace_id = 9; - string user_id = 10; - string project_id = 11; - string team_id = 12; - string repository = 13; - string agent = 14; - bool is_policy = 15; - - google.protobuf.Timestamp created_at = 16; - google.protobuf.Timestamp updated_at = 17; - repeated string tags = 18; - string agent_id = 19; - repeated SourceReference source_references = 20; - google.protobuf.Timestamp expires_at = 21; - string supersedes_memory_id = 22; - string superseded_by_memory_id = 23; - MemoryReviewStatus review_status = 24; - string proposed_by = 25; - string proposal_reason = 26; - repeated string entity_ids = 27; - int64 revision = 28; - MemoryLifecycleState lifecycle_state = 29; -} - -// MemoryLifecycleEvent is a content-free, immutable owner receipt. The -// content digests bind an explanation to a revision without copying forgotten -// memory content into the explanation response. -message MemoryLifecycleEvent { - string event_id = 1; - string memory_id = 2; - int64 revision = 3; - MemoryLifecycleEventType event_type = 4; - string previous_content_digest = 5; - string content_digest = 6; - string actor_id = 7; - string policy_ref = 8; - string provenance_ref = 9; - string use_reason = 10; - string idempotency_key = 11; - google.protobuf.Timestamp recorded_at = 12; -} - -// MemoryRelationship links two memories into a queryable memory graph. -message MemoryRelationship { - string id = 1; - string source_memory_id = 2; - string target_memory_id = 3; - string type = 4; - float confidence = 5; - google.protobuf.Timestamp valid_from = 6; - google.protobuf.Timestamp valid_until = 7; - google.protobuf.Timestamp created_at = 8; - google.protobuf.Timestamp updated_at = 9; - string organization_id = 10; -} - -message StoreRequest { - Scope scope = 1 [(buf.validate.field).enum.defined_only = true]; - string content = 2 [(buf.validate.field).string.min_len = 1]; - string type = 3 [(buf.validate.field).string.min_len = 1]; - string source = 4; - float confidence = 5; - string project_id = 6; - string team_id = 7; - string repository = 8; - string agent = 9; - bool is_policy = 10; - repeated string tags = 11; - string id = 12; - string agent_id = 13; - string user_id = 14; - bool pinned = 15; - repeated SourceReference source_references = 16; - google.protobuf.Timestamp expires_at = 17; - string supersedes_memory_id = 18; - MemoryReviewStatus review_status = 19; - string proposed_by = 20; - string proposal_reason = 21; - repeated string entity_ids = 22; -} - -message StoreResponse { - Memory memory = 1; -} - -message StoreBatchRequest { - repeated StoreRequest memories = 1 [(buf.validate.field).repeated.min_items = 1]; - bool continue_on_error = 2; -} - -message StoreBatchResponse { - repeated StoreBatchResult results = 1; -} - -message StoreBatchResult { - int32 index = 1; - Memory memory = 2; - string error = 3; -} - -message RecallRequest { - string query = 1; - Scope scope = 2 [(buf.validate.field).enum.defined_only = true]; - int32 top_k = 3 [(buf.validate.field).int32.gte = 0]; - float min_similarity = 4; - string project_id = 5; - string team_id = 6; - string repository = 7; - string agent = 8; - string type = 9; - string agent_id = 10; - string user_id = 11; - MemoryReviewStatus review_status = 12; - repeated string entity_ids = 13; - int32 relationship_depth = 14 [(buf.validate.field).int32.gte = 0]; - repeated string relationship_types = 15; - google.protobuf.Timestamp as_of = 16; -} - -message RecallKnowledgeRequest { - repeated string conditions = 1; - Scope scope = 2 [(buf.validate.field).enum.defined_only = true]; - int32 top_k = 3 [(buf.validate.field).int32.gte = 0]; - string project_id = 4; - string team_id = 5; - string repository = 6; - string agent = 7; - string agent_id = 8; - string user_id = 9; - MemoryReviewStatus review_status = 10; -} - -message GetMemoryRequest { - string id = 1 [(buf.validate.field).string.min_len = 1]; -} - -message GetMemoryResponse { - Memory memory = 1; -} - -message ExplainMemoryRequest { - string id = 1 [(buf.validate.field).string.min_len = 1]; -} - -message ExplainMemoryResponse { - repeated MemoryLifecycleEvent events = 1; -} - -message RecallResponse { - repeated RecallResult results = 1; -} - -message RecallKnowledgeResponse { - repeated RecallResult results = 1; -} - -message ClusterMemoriesRequest { - Scope scope = 1 [(buf.validate.field).enum.defined_only = true]; - string project_id = 2; - string team_id = 3; - string repository = 4; - string agent = 5; - string type = 6; - string agent_id = 7; - string user_id = 8; - MemoryReviewStatus review_status = 9; - int32 max_clusters = 10 [(buf.validate.field).int32.gte = 0]; - int32 limit_per_cluster = 11 [(buf.validate.field).int32.gte = 0]; - float min_similarity = 12; -} - -message ClusterMemoriesResponse { - repeated MemoryCluster clusters = 1; -} - -message MemoryCluster { - string id = 1; - string topic = 2; - repeated RecallResult results = 3; - repeated float centroid = 4 [packed = true]; - float similarity = 5; -} - -message RecallResult { - Memory memory = 1; - float similarity = 2; - int32 graph_distance = 3; - repeated MemoryRelationship relationship_path = 4; -} - -message UpdateRequest { - string id = 1 [(buf.validate.field).string.min_len = 1]; - // Leave empty for review-only updates; the server preserves existing content - // and tags. - string content = 2; - string type = 3; - float confidence = 4; - repeated string tags = 5; - string source = 6; - bool pinned = 7; - bool is_policy = 8; - repeated SourceReference source_references = 9; - google.protobuf.Timestamp expires_at = 10; - MemoryReviewStatus review_status = 11; - string proposed_by = 12; - string proposal_reason = 13; - repeated string entity_ids = 14; - optional int64 expected_revision = 15 [(buf.validate.field).int64.gte = 1]; - string idempotency_key = 16; - string actor_id = 17; - string policy_ref = 18; - string provenance_ref = 19; - string use_reason = 20; -} - -message UpdateResponse { - Memory memory = 1; -} - -// ReviewedLearningImpact is the aggregate, content-free output of the -// dex-core reviewed-learning decision. MemoryService verifies that the -// candidate digest still matches the proposed row before activation. -message ReviewedLearningImpact { - string candidate_digest_sha256 = 1 [(buf.validate.field).string.pattern = "^[0-9a-f]{64}$"]; - string review_id = 2 [(buf.validate.field).string.min_len = 1]; - string reviewer_id = 3 [(buf.validate.field).string.min_len = 1]; - string evaluation_id = 4 [(buf.validate.field).string.min_len = 1]; - string evaluator_id = 5 [(buf.validate.field).string.min_len = 1]; - string evaluation_suite_id = 6 [(buf.validate.field).string.min_len = 1]; - string evaluation_suite_version = 7 [(buf.validate.field).string.min_len = 1]; - string task_set_digest_sha256 = 8 [(buf.validate.field).string.pattern = "^[0-9a-f]{64}$"]; - string baseline_planner_version = 9 [(buf.validate.field).string.min_len = 1]; - string treatment_planner_version = 10 [(buf.validate.field).string.min_len = 1]; - uint32 sample_count = 11 [(buf.validate.field).uint32.gte = 1]; - int32 baseline_score_basis_points = 12 [(buf.validate.field).int32 = { - gte: 0 - lte: 10000 - }]; - int32 treatment_score_basis_points = 13 [(buf.validate.field).int32 = { - gte: 0 - lte: 10000 - }]; - int32 confidence_lower_bound_basis_points = 14 [(buf.validate.field).int32 = { - gte: -10000 - lte: 10000 - }]; - uint32 guardrail_regression_count = 15; - repeated string source_replay_artifact_digests_sha256 = 16 [(buf.validate.field).repeated.min_items = 1]; - repeated string evidence_refs = 17 [(buf.validate.field).repeated.min_items = 1]; -} - -message PromoteReviewedLearningRequest { - string memory_id = 1 [(buf.validate.field).string.min_len = 1]; - optional int64 expected_revision = 2 [(buf.validate.field).int64.gte = 1]; - string idempotency_key = 3 [(buf.validate.field).string.min_len = 1]; - string actor_id = 4 [(buf.validate.field).string.min_len = 1]; - string policy_ref = 5 [(buf.validate.field).string.min_len = 1]; - string provenance_ref = 6 [(buf.validate.field).string.min_len = 1]; - string use_reason = 7 [(buf.validate.field).string.min_len = 1]; - ReviewedLearningImpact impact = 8 [(buf.validate.field).required = true]; -} - -// ReviewedLearningPromotionReceipt is immutable evidence that one exact -// proposal revision became recallable under one measured planner evaluation. -message ReviewedLearningPromotionReceipt { - string receipt_id = 1; - string memory_id = 2; - int64 memory_revision = 3; - string lifecycle_event_id = 4; - ReviewedLearningImpact impact = 5; - string actor_id = 6; - string policy_ref = 7; - string provenance_ref = 8; - string use_reason = 9; - google.protobuf.Timestamp recorded_at = 10; -} - -message PromoteReviewedLearningResponse { - Memory memory = 1; - ReviewedLearningPromotionReceipt receipt = 2; -} - -message DeleteRequest { - string id = 1 [(buf.validate.field).string.min_len = 1]; - optional int64 expected_revision = 2 [(buf.validate.field).int64.gte = 1]; - string idempotency_key = 3; - string actor_id = 4; - string policy_ref = 5; - string provenance_ref = 6; - string use_reason = 7; -} - -message DeleteResponse {} - -message ListRequest { - Scope scope = 1 [(buf.validate.field).enum.defined_only = true]; - string project_id = 2; - string team_id = 3; - string repository = 4; - string agent = 5; - int32 limit = 6 [(buf.validate.field).int32.gte = 0]; - int32 offset = 7 [(buf.validate.field).int32.gte = 0]; - string type = 8; - string agent_id = 9; - string user_id = 10; - MemoryReviewStatus review_status = 11; - repeated string entity_ids = 12; - string source = 13; - string source_prefix = 14; -} - -message LinkMemoriesRequest { - string source_memory_id = 1 [(buf.validate.field).string.min_len = 1]; - string target_memory_id = 2 [(buf.validate.field).string.min_len = 1]; - string type = 3 [(buf.validate.field).string.min_len = 1]; - float confidence = 4; - google.protobuf.Timestamp valid_from = 5; - google.protobuf.Timestamp valid_until = 6; - string id = 7; -} - -message LinkMemoriesResponse { - MemoryRelationship relationship = 1; -} - -message ListMemoryRelationshipsRequest { - string memory_id = 1; - string source_memory_id = 2; - string target_memory_id = 3; - repeated string types = 4; - google.protobuf.Timestamp as_of = 5; - int32 limit = 6 [(buf.validate.field).int32.gte = 0]; - int32 offset = 7 [(buf.validate.field).int32.gte = 0]; -} - -message ListMemoryRelationshipsResponse { - repeated MemoryRelationship relationships = 1; - int32 total = 2; - bool has_more = 3; -} - -message DeleteMemoryRelationshipRequest { - string id = 1 [(buf.validate.field).string.min_len = 1]; -} - -message DeleteMemoryRelationshipResponse {} - -message GetOperatingRulesRequest { - Scope scope = 1 [(buf.validate.field).enum.defined_only = true]; - string project_id = 2; - string team_id = 3; - string repository = 4; - string agent = 5; - int32 limit = 6 [(buf.validate.field).int32.gte = 0]; - int32 offset = 7 [(buf.validate.field).int32.gte = 0]; - string agent_id = 8; - string user_id = 9; - MemoryReviewStatus review_status = 10; -} - -message ListResponse { - repeated Memory memories = 1; - int32 total = 2; - bool has_more = 3; -} - -message GetOperatingRulesResponse { - repeated Memory memories = 1; - int32 total = 2; - bool has_more = 3; -} - -message ConsolidateRequest { - Scope scope = 1 [(buf.validate.field).enum.defined_only = true]; - string project_id = 2; - string type = 3; - string source_prefix = 4; -} - -message ConsolidateResponse { - int32 merged = 1; - int32 pruned = 2; -} diff --git a/proto/meter/v1/meter.proto b/proto/meter/v1/meter.proto deleted file mode 100644 index 90fbc8c..0000000 --- a/proto/meter/v1/meter.proto +++ /dev/null @@ -1,1122 +0,0 @@ -syntax = "proto3"; - -package meter.v1; - -import "buf/validate/validate.proto"; -import "common/v1/authz.proto"; -import "common/v1/classification.proto"; -import "google/protobuf/struct.proto"; -import "google/protobuf/timestamp.proto"; - -option go_package = "github.com/evalops/platform/gen/go/meter/v1;meterv1"; - -// MeterService records and queries usage across EvalOps services. -service MeterService { - // GetPrepaidCreditBalance operates only on the caller's authorized organization and workspace. - // Grid staff composition returns this canonical Meter receipt unchanged. - // buf:lint:ignore RPC_REQUEST_RESPONSE_UNIQUE - rpc GetPrepaidCreditBalance(GetPrepaidCreditBalanceRequest) returns (GetPrepaidCreditBalanceResponse) { - option (common.v1.required_scopes) = "meter:read"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // GrantDevelopmentCredits issues an audited non-cash grant for the configured internal development program. - // Grid staff composition returns this canonical Meter receipt unchanged. - // buf:lint:ignore RPC_REQUEST_RESPONSE_UNIQUE - rpc GrantDevelopmentCredits(GrantDevelopmentCreditsRequest) returns (GrantDevelopmentCreditsResponse) { - option (common.v1.required_scopes) = "meter:credits:grant-development"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // FundPrepaidCredits operates only on the caller's authorized organization and workspace. - rpc FundPrepaidCredits(FundPrepaidCreditsRequest) returns (FundPrepaidCreditsResponse) { - option (common.v1.required_scopes) = "meter:credits:fund"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - rpc ReversePrepaidCredits(ReversePrepaidCreditsRequest) returns (ReversePrepaidCreditsResponse) { - option (common.v1.required_scopes) = "meter:credits:reverse"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - rpc ApplyPrepaidPaymentDispute(ApplyPrepaidPaymentDisputeRequest) returns (ApplyPrepaidPaymentDisputeResponse) { - option (common.v1.required_scopes) = "meter:credits:reverse"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // ReservePrepaidCredits operates only on the caller's authorized organization and workspace. - rpc ReservePrepaidCredits(ReservePrepaidCreditsRequest) returns (ReservePrepaidCreditsResponse) { - option (common.v1.required_scopes) = "meter:credits:reserve"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // Platform admits one immutable Work allowance before dispatch. - rpc AuthorizeWorkSpend(AuthorizeWorkSpendRequest) returns (AuthorizeWorkSpendResponse) { - option (common.v1.required_scopes) = "billing:authorize"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // A separate method makes older monetary adapters reject Work reservations. - rpc ReserveWorkCredits(ReserveWorkCreditsRequest) returns (ReserveWorkCreditsResponse) { - option (common.v1.required_scopes) = "meter:credits:reserve"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // Read original settlement eligibility without accepting or issuing compensation. - rpc PreviewPrepaidCompensation(PreviewPrepaidCompensationRequest) returns (PreviewPrepaidCompensationResponse) { - option (common.v1.required_scopes) = "meter:credits:compensate"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Restore a cash-funded settled request once across all recovery incidents. - rpc CompensatePrepaidCredit(CompensatePrepaidCreditRequest) returns (CompensatePrepaidCreditResponse) { - option (common.v1.required_scopes) = "meter:credits:compensate"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // SettlePrepaidCredits operates only on the caller's authorized organization and workspace. - rpc SettlePrepaidCredits(SettlePrepaidCreditsRequest) returns (SettlePrepaidCreditsResponse) { - option (common.v1.required_scopes) = "meter:credits:settle"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - rpc RecordUsage(RecordUsageRequest) returns (RecordUsageResponse) { - option (common.v1.required_scopes) = "meter:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc RecordUsageBatch(RecordUsageBatchRequest) returns (RecordUsageBatchResponse) { - option (common.v1.required_scopes) = "meter:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - // Read accepted funding receipts and policy changes for one exact tenant. - // The staff adapter deliberately returns this same owner response. - // buf:lint:ignore RPC_REQUEST_RESPONSE_UNIQUE - rpc ListManagedInferenceAdminEvents(ListManagedInferenceAdminEventsRequest) returns (ListManagedInferenceAdminEventsResponse) { - option (common.v1.required_scopes) = "meter:read"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Grid staff composition returns this canonical Meter receipt unchanged. - // buf:lint:ignore RPC_REQUEST_RESPONSE_UNIQUE - rpc SetBudget(SetBudgetRequest) returns (SetBudgetResponse) { - option (common.v1.required_scopes) = "meter:write"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - rpc CheckBudget(CheckBudgetRequest) returns (CheckBudgetResponse) { - option (common.v1.required_scopes) = "meter:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Grid staff composition returns this canonical Meter receipt unchanged. - // buf:lint:ignore RPC_REQUEST_RESPONSE_UNIQUE - rpc GetBudgetDashboard(GetBudgetDashboardRequest) returns (GetBudgetDashboardResponse) { - option (common.v1.required_scopes) = "meter:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // ListBudgetDenials returns the refusals CheckBudget recorded, newest first. - // GetBudgetDashboard reports only the single most recent refusal; this reads - // a bounded, time-windowed page of them so a caller can show the refusals a - // window contains rather than one. Scope comes from the authorized caller, - // the same rule GetBudgetDashboard applies to last_denial. - rpc ListBudgetDenials(ListBudgetDenialsRequest) returns (ListBudgetDenialsResponse) { - option (common.v1.required_scopes) = "meter:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Grid staff composition returns this canonical Meter receipt unchanged. - // buf:lint:ignore RPC_REQUEST_RESPONSE_UNIQUE - rpc QueryUsage(QueryUsageRequest) returns (QueryUsageResponse) { - option (common.v1.required_scopes) = "meter:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc GetUsageSummary(GetUsageSummaryRequest) returns (GetUsageSummaryResponse) { - option (common.v1.required_scopes) = "meter:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc GetMeterSummary(GetMeterSummaryRequest) returns (GetMeterSummaryResponse) { - option (common.v1.required_scopes) = "meter:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc GetAdoptionMetrics(GetAdoptionMetricsRequest) returns (GetAdoptionMetricsResponse) { - option (common.v1.required_scopes) = "meter:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc ListActiveUsers(ListActiveUsersRequest) returns (ListActiveUsersResponse) { - option (common.v1.required_scopes) = "meter:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc IngestWideEvent(IngestWideEventRequest) returns (IngestWideEventResponse) { - option (common.v1.required_scopes) = "meter:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc IngestWideEventBatch(IngestWideEventBatchRequest) returns (IngestWideEventBatchResponse) { - option (common.v1.required_scopes) = "meter:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc QueryWideEvents(QueryWideEventsRequest) returns (QueryWideEventsResponse) { - option (common.v1.required_scopes) = "meter:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc GetEventDashboard(GetEventDashboardRequest) returns (GetEventDashboardResponse) { - option (common.v1.required_scopes) = "meter:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } -} - -enum SummaryGroupBy { - SUMMARY_GROUP_BY_UNSPECIFIED = 0; - SUMMARY_GROUP_BY_MODEL = 1; - SUMMARY_GROUP_BY_PROVIDER = 2; - SUMMARY_GROUP_BY_TEAM = 3; - SUMMARY_GROUP_BY_AGENT = 4; - SUMMARY_GROUP_BY_SURFACE = 5; - SUMMARY_GROUP_BY_METADATA = 6; - SUMMARY_GROUP_BY_USER = 7; - SUMMARY_GROUP_BY_TIME_BUCKET = 8; -} - -message RecordUsageRequest { - string team_id = 1; - string agent_id = 2; - string surface = 3; - string event_type = 4; - string model = 5; - string provider = 6; - int64 input_tokens = 7 [(buf.validate.field).int64.gte = 0]; - int64 output_tokens = 8 [(buf.validate.field).int64.gte = 0]; - int64 cache_read_tokens = 9 [(buf.validate.field).int64.gte = 0]; - int64 cache_write_tokens = 10 [(buf.validate.field).int64.gte = 0]; - double total_cost_usd = 11 [(buf.validate.field).double.gte = 0]; - string request_id = 12; - google.protobuf.Struct metadata = 13; - google.protobuf.Struct data = 14; - string caller_identity = 15; -} - -message RecordUsageResponse { - UsageRecord record = 1; -} - -message RecordUsageBatchRequest { - repeated RecordUsageRequest records = 1 [(buf.validate.field).repeated.min_items = 1]; -} - -message RecordUsageBatchResponse { - repeated UsageRecord records = 1; -} - -message Budget { - string id = 1; - string organization_id = 2; - string team_id = 3; - // Empty means the budget governs every workspace in the organization. - // A non-empty value means the budget governs only that workspace. - string workspace_id = 15; - string period = 4; - double limit_usd = 5 [(buf.validate.field).double.gt = 0]; - int32 alert_threshold_pct = 6; - repeated int32 warning_thresholds_pct = 7; - bool hard_cap = 8; - double current_spend_usd = 9; - int32 last_alert_threshold_pct = 10; - google.protobuf.Timestamp period_start = 11; - google.protobuf.Timestamp next_reset_at = 12; - google.protobuf.Timestamp created_at = 13; - google.protobuf.Timestamp updated_at = 14; -} - -message BudgetStatus { - string budget_id = 1; - string organization_id = 2; - string team_id = 3; - // Empty means the budget governs every workspace in the organization. - string workspace_id = 19; - string period = 4; - double limit_usd = 5; - double current_spend_usd = 6; - double remaining_usd = 7; - double usage_pct = 8; - bool alert_triggered = 9; - bool hard_cap = 10; - bool hard_cap_reached = 11; - int32 triggered_threshold_pct = 12; - repeated int32 warning_thresholds_pct = 13; - int32 last_alert_threshold_pct = 14; - double spend_velocity_usd_per_hour = 15; - double estimated_exhaustion_hours = 16; - google.protobuf.Timestamp period_start = 17; - google.protobuf.Timestamp next_reset_at = 18; -} - -// Delegation is accepted only from the authenticated Platform managed-access service. -message AdminMutationAuditContext { - string delegated_actor_subject = 1 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string reason = 2 [(common.v1.classification) = DATA_CLASSIFICATION_CONTENT]; - string request_id = 3 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; -} -message ManagedInferenceBudgetSnapshot { - string period = 1; - double limit_usd = 2; - repeated int32 warning_thresholds_pct = 3; - bool hard_cap = 4; -} -message ManagedInferenceAdminEvent { - string event_id = 1; - google.protobuf.Timestamp occurred_at = 2; - string actor_subject = 3 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string delegated_actor_subject = 4 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string action = 5; - string resource_id = 6; - string reason = 7 [(common.v1.classification) = DATA_CLASSIFICATION_CONTENT]; - string outcome = 8; - ManagedInferenceBudgetSnapshot before_budget = 9; - ManagedInferenceBudgetSnapshot after_budget = 10; - int64 credit_micros = 11; - string program_id = 12; - string provenance = 13 [(common.v1.classification) = DATA_CLASSIFICATION_CONTENT]; - string request_id = 14; - string organization_id = 15; - string workspace_id = 16; -} -message ListManagedInferenceAdminEventsRequest { - string organization_id = 1 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string workspace_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - int32 page_size = 3 [(buf.validate.field).int32 = { - gte: 0 - lte: 100 - }]; - string page_token = 4 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; -} -message ListManagedInferenceAdminEventsResponse { - repeated ManagedInferenceAdminEvent events = 1; - string next_page_token = 2; -} - -message SetBudgetRequest { - AdminMutationAuditContext audit_context = 8; - string budget_id = 1; - string team_id = 2; - // Changing the period of an existing budget restarts the spend window: the - // service sets period_start to now, clears current_spend_usd, and derives a - // new next_reset_at. Sending the same period leaves the window untouched. - string period = 3; - double limit_usd = 4 [(buf.validate.field).double.gt = 0]; - repeated int32 warning_thresholds_pct = 5; - bool hard_cap = 6; - // Empty creates or updates an organization-wide budget. A non-empty value - // must equal the workspace the caller was authorized for. - string workspace_id = 7; - // Empty preserves legacy non-idempotent callers. New callers supply a stable - // key for this exact organization and authenticated workspace. - string idempotency_key = 9 [(buf.validate.field).string.max_len = 256]; -} - -message SetBudgetResponse { - Budget budget = 1; -} - -message CheckBudgetRequest { - string team_id = 1; - double estimated_cost_usd = 2 [(buf.validate.field).double.gte = 0]; - // Empty checks only organization-wide budgets. A non-empty value must equal - // the workspace the caller was authorized for and additionally checks that - // workspace's budgets. - string workspace_id = 3; - // Attribution the service persists when the check denies. The caller sends - // what it knows about the request being admitted. - string request_id = 4; - string trace_id = 5; - string model = 6; - string provider = 7; -} - -message BudgetWarning { - string budget_id = 1; - int32 threshold_pct = 2; - double usage_pct = 3; - string message = 4; -} - -message CheckBudgetResponse { - bool allowed = 1; - string denial_reason = 2; - double remaining_budget_usd = 3; - repeated BudgetStatus statuses = 4; - repeated BudgetWarning warnings = 5; -} - -message GetBudgetDashboardRequest { - string team_id = 1; - // Empty reports only organization-wide budgets. A non-empty value must equal - // the workspace the caller was authorized for and additionally reports that - // workspace's budgets. - string workspace_id = 2; -} - -// A budget refusal meter recorded when CheckBudget returned allowed=false. -// Meter owns this record; model-gateway does not report it back. -message BudgetDenial { - string budget_id = 1; - string organization_id = 2; - string workspace_id = 3; - string team_id = 4; - google.protobuf.Timestamp denied_at = 5; - string request_id = 6; - string trace_id = 7; - double amount_usd = 8; - string model = 9; - string provider = 10; - string denial_reason = 11; - // Stable row identity. A reader that lists denials needs it to key a row it - // shows next to rows from another owner. - string id = 12; -} - -message GetBudgetDashboardResponse { - string organization_id = 1; - string team_id = 2; - google.protobuf.Timestamp generated_at = 3; - int32 total_budgets = 4; - double total_limit_usd = 5; - double total_spend_usd = 6; - double total_remaining_usd = 7; - int32 warning_budgets = 8; - int32 hard_cap_budgets = 9; - int32 hard_cap_reached_budgets = 10; - repeated BudgetStatus statuses = 11; - string workspace_id = 12; - // The most recent refusal in this scope, absent when nothing was refused. - BudgetDenial last_denial = 13; -} - -message ListBudgetDenialsRequest { - string team_id = 1 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - // Empty reads only organization-wide denials. A non-empty value must equal - // the workspace the caller was authorized for. - string workspace_id = 2 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - // Inclusive lower bound on denied_at. Absent reads from the oldest row. - google.protobuf.Timestamp start_time = 3; - // Exclusive upper bound on denied_at. Absent reads to the newest row. - google.protobuf.Timestamp end_time = 4; - // Zero applies the server default of 200, which is also the ceiling. - int32 limit = 5 [(buf.validate.field).int32 = { - gte: 0 - lte: 200 - }]; - int32 offset = 6 [(buf.validate.field).int32.gte = 0]; -} - -message ListBudgetDenialsResponse { - // Newest first, at most `limit` rows. - repeated BudgetDenial denials = 1; - // True when at least one further row matched past this page. Meter does not - // count the whole match set, so no total is reported. - bool has_more = 2; -} - -message UsageRecord { - string id = 1; - google.protobuf.Timestamp timestamp = 2; - string organization_id = 3; - string team_id = 4; - string agent_id = 5; - string surface = 6; - string event_type = 7; - string model = 8; - string provider = 9; - int64 input_tokens = 10; - int64 output_tokens = 11; - int64 cache_read_tokens = 12; - int64 cache_write_tokens = 13; - double total_cost_usd = 14; - string request_id = 15; - google.protobuf.Struct data = 16; - google.protobuf.Struct metadata = 17; - google.protobuf.Timestamp created_at = 18; - string caller_identity = 19; -} - -message QueryUsageRequest { - string team_id = 1; - string agent_id = 2; - string event_type = 3; - string model = 4; - string provider = 5; - string metadata_key = 6; - string metadata_value = 7; - google.protobuf.Timestamp start_time = 8; - google.protobuf.Timestamp end_time = 9; - int32 limit = 10 [(buf.validate.field).int32.lte = 200]; - int32 offset = 11 [(buf.validate.field).int32.gte = 0]; - string caller_identity = 12; -} - -message QueryUsageResponse { - repeated UsageRecord records = 1; - int32 total = 2; - bool has_more = 3; -} - -message GetUsageSummaryRequest { - string team_id = 1; - string agent_id = 2; - SummaryGroupBy group_by = 3; - string group_metadata_key = 4; - string metadata_key = 5; - string metadata_value = 6; - google.protobuf.Timestamp start_time = 7; - google.protobuf.Timestamp end_time = 8; - string caller_identity = 9; - string time_bucket = 10; - string event_type = 11; - string model = 12; - string provider = 13; -} - -message UsageSummary { - string key = 1; - int64 total_input_tokens = 2; - int64 total_output_tokens = 3; - int64 total_cache_read_tokens = 4; - int64 total_cache_write_tokens = 5; - double total_cost_usd = 6; - int64 record_count = 7; - // Gateway coverage only; other usage sources are excluded from these counts. - int64 gateway_request_count = 8; - // No verified workload link, including older records without verification evidence. - int64 unattributed_request_count = 9; - int64 unattributed_token_count = 10; - int64 unpriced_request_count = 11; - int64 unpriced_token_count = 12; - // True when the bucket includes gateway usage with unavailable pricing. - bool cost_incomplete = 13; - // Known subtotal, absent when no record has available pricing. A genuine - // priced zero remains present. total_cost_usd retains its legacy sum, which - // may include unavailable-price placeholders and is not a completeness claim. - optional double known_total_cost_usd = 14; -} - -message GetUsageSummaryResponse { - repeated UsageSummary buckets = 1; -} - -message GetMeterSummaryRequest { - string meter_id = 1; - string team_id = 2; - string agent_id = 3; - SummaryGroupBy group_by = 4; - google.protobuf.Timestamp start_time = 5; - google.protobuf.Timestamp end_time = 6; -} - -message MeterSummaryBucket { - string key = 1; - double value = 2; - int64 record_count = 3; -} - -message GetMeterSummaryResponse { - string meter_id = 1; - repeated MeterSummaryBucket buckets = 2; -} - -message GetAdoptionMetricsRequest { - string team_id = 1; - string agent_id = 2; - string event_type = 3; - string model = 4; - string provider = 5; - string surface = 6; - google.protobuf.Timestamp start_time = 7; - google.protobuf.Timestamp end_time = 8; - string time_bucket = 9; -} - -message AdoptionTimeBucket { - string key = 1; - google.protobuf.Timestamp start_time = 2; - int64 active_users = 3; - int64 request_count = 4; - double total_cost_usd = 5; -} - -message AdoptionCohort { - string cohort = 1; - int64 users = 2; - int64 retained_users = 3; - double retention_rate = 4; -} - -message AdoptionFrequencyBucket { - string key = 1; - int64 users = 2; -} - -message AdoptionDimensionBucket { - string key = 1; - int64 active_users = 2; - int64 request_count = 3; - double total_cost_usd = 4; -} - -message GetAdoptionMetricsResponse { - int64 daily_active_users = 1; - int64 weekly_active_users = 2; - int64 monthly_active_users = 3; - int64 total_active_users = 4; - int64 total_teams = 5; - int64 request_count = 6; - double total_cost_usd = 7; - repeated AdoptionTimeBucket active_users_by_bucket = 8; - repeated AdoptionCohort cohorts = 9; - repeated AdoptionFrequencyBucket frequency_distribution = 10; - repeated AdoptionDimensionBucket by_team = 11; - repeated AdoptionDimensionBucket by_model = 12; - repeated AdoptionDimensionBucket by_provider = 13; - repeated AdoptionDimensionBucket by_agent = 14; -} - -message ListActiveUsersRequest { - string team_id = 1; - string agent_id = 2; - string event_type = 3; - string model = 4; - string provider = 5; - string surface = 6; - google.protobuf.Timestamp start_time = 7; - google.protobuf.Timestamp end_time = 8; - int32 limit = 9 [(buf.validate.field).int32.lte = 200]; - int32 offset = 10 [(buf.validate.field).int32.gte = 0]; -} - -message ActiveUser { - string caller_identity = 1; - string team_id = 2; - google.protobuf.Timestamp first_seen = 3; - google.protobuf.Timestamp last_seen = 4; - int64 request_count = 5; - double total_cost_usd = 6; - repeated string models = 7; - repeated string providers = 8; - repeated string agents = 9; -} - -message ListActiveUsersResponse { - repeated ActiveUser users = 1; - int32 total = 2; - bool has_more = 3; -} - -message WideEventMetrics { - int64 input_tokens = 1 [(buf.validate.field).int64.gte = 0]; - int64 output_tokens = 2 [(buf.validate.field).int64.gte = 0]; - int64 cache_read_tokens = 3 [(buf.validate.field).int64.gte = 0]; - int64 cache_write_tokens = 4 [(buf.validate.field).int64.gte = 0]; - double total_cost_usd = 5 [(buf.validate.field).double.gte = 0]; - int64 duration_ms = 6 [(buf.validate.field).int64.gte = 0]; - int64 time_to_first_token_ms = 7 [(buf.validate.field).int64.gte = 0]; - int64 tool_calls_count = 8 [(buf.validate.field).int64.gte = 0]; -} - -// WideEventAttributes declares every metadata key a wide event may carry. -// -// IngestWideEventRequest.metadata is a google.protobuf.Struct, so the wire -// format cannot constrain its keys. This message is the declaration of record: -// one field per allowed key, each carrying its data classification. -// scripts/gen-classification-manifest.py projects it into -// gen/classification/manifest.json, and the meter ingest path drops any -// metadata key the manifest does not name. -// -// This message is not sent on the wire. Adding a key here is how a producer -// gets a new wide-event attribute accepted. -message WideEventAttributes { - string event_id = 1 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string conversation_id = 2 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string message_id = 3 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string workspace_id = 4 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string session_id = 5 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string execution_source = 6 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string lifecycle_phase = 7 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string outcome = 8 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string error_type = 9 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string skill_id = 10 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string skill_name = 11 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string feedback_type = 12 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string generation_id = 13 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string request_method = 14 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string request_path = 15 [(common.v1.classification) = DATA_CLASSIFICATION_PATH]; - bool cancelled_by_user = 16 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - bool response_truncated = 17 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; -} - -message IngestWideEventRequest { - google.protobuf.Timestamp timestamp = 1; - string team_id = 2 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string agent_id = 3 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string surface = 4 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string event_type = 5 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string model = 6 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string provider = 7 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string request_id = 8 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - google.protobuf.Struct metadata = 9 [(common.v1.classification) = DATA_CLASSIFICATION_CONTENT]; - google.protobuf.Struct data = 10 [(common.v1.classification) = DATA_CLASSIFICATION_CONTENT]; - WideEventMetrics metrics = 11; -} - -message WideEvent { - string id = 1 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - google.protobuf.Timestamp timestamp = 2; - string organization_id = 3 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string team_id = 4 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string agent_id = 5 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string surface = 6 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string event_type = 7 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string model = 8 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string provider = 9 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string request_id = 10 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - google.protobuf.Struct metadata = 11 [(common.v1.classification) = DATA_CLASSIFICATION_CONTENT]; - google.protobuf.Struct data = 12 [(common.v1.classification) = DATA_CLASSIFICATION_CONTENT]; - WideEventMetrics metrics = 13; - google.protobuf.Timestamp created_at = 14; -} - -message IngestWideEventResponse { - WideEvent event = 1; - bool budget_exceeded = 2; // true when this event pushed the agent or team over budget - string budget_message = 3 [(common.v1.classification) = DATA_CLASSIFICATION_CONTENT]; // human-readable budget status, empty when within budget -} - -message IngestWideEventBatchRequest { - repeated IngestWideEventRequest events = 1 [ - (buf.validate.field).repeated.min_items = 1, - (buf.validate.field).repeated.max_items = 100 - ]; -} - -message IngestWideEventBatchResponse { - // Per-event result keyed by input index (0-based). - repeated IngestWideEventBatchItemResult results = 1; - // Top-level signal — true if any event hit a budget cap. - bool budget_exceeded = 2; - string budget_message = 3 [(common.v1.classification) = DATA_CLASSIFICATION_CONTENT]; -} - -message IngestWideEventBatchItemResult { - int32 input_index = 1 [(buf.validate.field).int32.gte = 0]; - bool succeeded = 2; - // Set when succeeded=true: the persisted event_id. - string event_id = 3 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - // Set when succeeded=false. - string failure_code = 4 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string failure_message = 5 [(common.v1.classification) = DATA_CLASSIFICATION_CONTENT]; -} - -message QueryWideEventsRequest { - string team_id = 1 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string agent_id = 2 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string surface = 3 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string event_type = 4 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string model = 5 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string provider = 6 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string metadata_key = 7 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string metadata_value = 8 [(common.v1.classification) = DATA_CLASSIFICATION_CONTENT]; - google.protobuf.Timestamp start_time = 9; - google.protobuf.Timestamp end_time = 10; - int32 limit = 11; - int32 offset = 12; -} - -message QueryWideEventsResponse { - repeated WideEvent events = 1; - int32 total = 2; - bool has_more = 3; -} - -message GetEventDashboardRequest { - string team_id = 1 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string agent_id = 2 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string surface = 3 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string event_type = 4 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string model = 5 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string provider = 6 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string metadata_key = 7 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - string metadata_value = 8 [(common.v1.classification) = DATA_CLASSIFICATION_CONTENT]; - google.protobuf.Timestamp start_time = 9; - google.protobuf.Timestamp end_time = 10; - int32 top_n = 11; -} - -message EventDashboardBucket { - string key = 1 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; - int64 count = 2; - double total_cost_usd = 3; -} - -message GetEventDashboardResponse { - int64 total_events = 1; - int64 total_input_tokens = 2; - int64 total_output_tokens = 3; - int64 total_cache_read_tokens = 4; - int64 total_cache_write_tokens = 5; - double total_cost_usd = 6; - repeated EventDashboardBucket by_event_type = 7; - repeated EventDashboardBucket by_surface = 8; - repeated EventDashboardBucket by_model = 9; - repeated EventDashboardBucket by_provider = 10; -} - -// Prepaid credits are USD amounts in integer millionths of a dollar. -// Meter owns funding, reservations, settlement, and the available balance. -message PrepaidCreditBalance { - // Cash recovery, separate from purchases and non-cash grants. - int64 compensated_micros = 13 [(buf.validate.field).int64.gte = 0]; - // Enrolled development programs cannot consume paid credits or trigger paid refill. - bool development_credit_only = 12; - // Non-cash development funding, kept separate from purchased credits. - int64 granted_micros = 8 [(buf.validate.field).int64.gte = 0]; - int64 expired_grant_micros = 9 [(buf.validate.field).int64.gte = 0]; - int64 grant_spent_micros = 10 [(buf.validate.field).int64.gte = 0]; - int64 grant_reserved_micros = 11 [(buf.validate.field).int64.gte = 0]; - bool admission_suspended = 7; - int64 reversed_micros = 5 [(buf.validate.field).int64.gte = 0]; - int64 debt_micros = 6 [(buf.validate.field).int64.gte = 0]; - int64 purchased_micros = 1 [(buf.validate.field).int64.gte = 0]; - int64 spent_micros = 2 [(buf.validate.field).int64.gte = 0]; - int64 reserved_micros = 3 [(buf.validate.field).int64.gte = 0]; - int64 available_micros = 4 [(buf.validate.field).int64.gte = 0]; -} -message GetPrepaidCreditBalanceRequest { - string run_id = 2 [ - (buf.validate.field).string.max_len = 256, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string workspace_id = 1 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; -} -message GetPrepaidCreditBalanceResponse { - PrepaidCreditBalance balance = 1; - // Absent when no account exists or an older Meter serves this response. - PrepaidCreditReconciliation reconciliation = 2; - // Absent for missing attribution or older servers, never an inferred zero. - PrepaidRunBalance run_balance = 3; - // Immutable owner enrollment limits; absent for legacy or unenrolled programs. - DevelopmentCreditProgramPolicy development_program_policy = 4; - string development_program_id = 5 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; -} -message PrepaidRunBalance { - string run_id = 1; - int64 settled_cost_micros = 2; - int64 reserved_micros = 3; - int64 pending_request_count = 4; - int64 settled_request_count = 5; - google.protobuf.Timestamp oldest_pending_at = 6; -} -message PrepaidCreditReconciliation { - int64 compensated_difference_micros = 12; - int64 granted_difference_micros = 10; - int64 invalid_grant_allocation_count = 11 [(buf.validate.field).int64.gte = 0]; - // A comparison of materialized counters with source rows in one snapshot. - bool balanced = 1; - int64 purchased_difference_micros = 2; - int64 reversed_difference_micros = 3; - int64 spent_difference_micros = 4; - int64 reserved_difference_micros = 5; - int64 dispute_count_difference = 6; - int64 pending_reservation_count = 7 [(buf.validate.field).int64.gte = 0]; - google.protobuf.Timestamp oldest_pending_at = 8; - int64 unfunded_payment_count = 9 [(buf.validate.field).int64.gte = 0]; -} - -// Immutable sponsored program limits. Enrollment is accepted atomically with its -// first grant and requires meter:credits:enroll-development in addition to issuance. -message DevelopmentCreditProgramPolicy { - int64 max_grant_micros = 1 [(buf.validate.field).int64.gt = 0]; - int64 program_budget_micros = 2 [(buf.validate.field).int64.gt = 0]; - int64 daily_budget_micros = 3 [(buf.validate.field).int64.gt = 0]; - int64 max_lifetime_seconds = 4 [(buf.validate.field).int64.gt = 0]; - string alert_recipient_id = 5 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; -} - -// Grant identities and provenance are immutable across retries. Expiry requires microsecond precision. -message GrantDevelopmentCreditsRequest { - string organization_id = 1 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string workspace_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string program_id = 3 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string grant_id = 4 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - int64 credit_micros = 5 [(buf.validate.field).int64.gt = 0]; - google.protobuf.Timestamp expires_at = 6 [(buf.validate.field).required = true]; - string reason = 7 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_CONTENT - ]; - string provenance = 8 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_CONTENT - ]; - // Optional first enrollment; immutable exact retries only. Omit on later grants. - DevelopmentCreditProgramPolicy enrollment_policy = 9; -} - -// Billing's accepted immutable grant receipt. The authenticated issuer is server-derived. -message DevelopmentCreditGrant { - string organization_id = 1 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string workspace_id = 2 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string program_id = 3 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - string grant_id = 4 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - int64 credit_micros = 5; - google.protobuf.Timestamp expires_at = 6; - string reason = 7 [(common.v1.classification) = DATA_CLASSIFICATION_CONTENT]; - string provenance = 8 [(common.v1.classification) = DATA_CLASSIFICATION_CONTENT]; - string actor_subject = 9 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - google.protobuf.Timestamp created_at = 10; - // Server-configured organization-wide daily spend ceiling, including outstanding holds. - int64 daily_budget_micros = 11 [(buf.validate.field).int64.gt = 0]; - // Server-configured Identity user receiving operational alerts, independent of the grant issuer. - string alert_recipient_id = 12 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; -} -message GrantDevelopmentCreditsResponse { - DevelopmentCreditGrant grant = 1; -} -message FundPrepaidCreditsRequest { - string workspace_id = 1 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string payment_intent_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string checkout_session_id = 3 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - int64 credit_micros = 4 [(buf.validate.field).int64.gt = 0]; -} -message FundPrepaidCreditsResponse { - PrepaidCreditBalance balance = 1; -} -message ReservePrepaidCreditsRequest { - string workspace_id = 1 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string gateway_request_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - int64 amount_micros = 3 [(buf.validate.field).int64.gt = 0]; - // Issued only by the authenticated Gateway after managed scope verification. - string run_id = 4 [ - (buf.validate.field).string.max_len = 256, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; -} -message ReservePrepaidCreditsResponse { - int64 reserved_micros = 1 [(buf.validate.field).int64.gte = 0]; - // A completed reservation cannot authorize a second upstream request. - bool settled = 2; - // True only for the atomic first reservation; false never authorizes execution. - bool created = 3; -} -message SettlePrepaidCreditsRequest { - string workspace_id = 1 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string gateway_request_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - int64 actual_cost_micros = 3 [(buf.validate.field).int64.gte = 0]; -} -message SettlePrepaidCreditsResponse { - int64 actual_cost_micros = 1 [(buf.validate.field).int64.gte = 0]; -} - -// Cumulative verified payment reversal; event retries never restore funds. -message ReversePrepaidCreditsRequest { - int64 original_credit_micros = 5 [(buf.validate.field).int64.gt = 0]; - string checkout_session_id = 6 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string workspace_id = 1 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string payment_intent_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string reversal_id = 3 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - int64 reversed_credit_micros = 4 [(buf.validate.field).int64.gte = 0]; -} -message ReversePrepaidCreditsResponse { - PrepaidCreditBalance balance = 1; -} - -enum PrepaidPaymentDisputeState { - PREPAID_PAYMENT_DISPUTE_STATE_UNSPECIFIED = 0; - PREPAID_PAYMENT_DISPUTE_STATE_OPEN = 1; - PREPAID_PAYMENT_DISPUTE_STATE_WON = 2; - PREPAID_PAYMENT_DISPUTE_STATE_LOST = 3; -} -message ApplyPrepaidPaymentDisputeRequest { - string workspace_id = 1 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string payment_intent_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string checkout_session_id = 3 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - int64 original_credit_micros = 4 [(buf.validate.field).int64.gt = 0]; - string dispute_id = 5 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - PrepaidPaymentDisputeState state = 6; - int64 reversed_credit_micros = 7 [(buf.validate.field).int64.gte = 0]; -} -message ApplyPrepaidPaymentDisputeResponse { - PrepaidCreditBalance balance = 1; -} - -// Platform's immutable, replay-safe admission of managed inference for a Work. -message AuthorizeWorkSpendRequest { - string workspace_id = 1 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string authority_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string work_id = 3 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - int64 max_charge_micros = 4 [(buf.validate.field).int64.gt = 0]; - string price_book_version = 5 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_SAFE - ]; - google.protobuf.Timestamp valid_until = 6 [(buf.validate.field).required = true]; -} -message AuthorizeWorkSpendResponse { - string authority_id = 1 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; -} -message ReserveWorkCreditsRequest { - string workspace_id = 1 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string authority_id = 2 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string work_id = 3 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string price_book_version = 4 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_SAFE - ]; - string gateway_request_id = 5 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string run_id = 6 [ - (buf.validate.field).string.min_len = 1, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - int64 amount_micros = 7 [(buf.validate.field).int64.gt = 0]; -} - -message ReserveWorkCreditsResponse { - int64 reserved_micros = 1 [(buf.validate.field).int64.gte = 0]; - // A completed reservation cannot authorize a second upstream request. - bool settled = 2; - // True only for the atomic first reservation; false never authorizes execution. - bool created = 3; -} - -// Organization and actor come exclusively from the authenticated recovery service. -message CompensatePrepaidCreditRequest { - string workspace_id = 1 [ - (buf.validate.field).string.min_len = 1, - (buf.validate.field).string.max_len = 256, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string gateway_request_id = 2 [ - (buf.validate.field).string.min_len = 1, - (buf.validate.field).string.max_len = 256, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string incident_id = 3 [ - (buf.validate.field).string.min_len = 1, - (buf.validate.field).string.max_len = 256, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - string idempotency_key = 4 [ - (buf.validate.field).string.min_len = 1, - (buf.validate.field).string.max_len = 256, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; -} -message CompensatePrepaidCreditResponse { - int64 compensated_micros = 1 [(buf.validate.field).int64.gt = 0]; - string receipt_id = 2 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - // Another incident or retry already restored this original charge. - bool duplicate = 3; -} - -message PreviewPrepaidCompensationRequest { - string workspace_id = 1 [ - (buf.validate.field).string.min_len = 1, - (buf.validate.field).string.max_len = 256, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; - repeated string gateway_request_ids = 2 [ - (buf.validate.field).repeated.min_items = 1, - (buf.validate.field).repeated.max_items = 100, - (common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER - ]; -} -message PrepaidCompensationEligibility { - string gateway_request_id = 1 [(common.v1.classification) = DATA_CLASSIFICATION_IDENTIFIER]; - bool eligible = 2; - int64 credit_micros = 3 [(buf.validate.field).int64.gte = 0]; - // Stable owner codes: eligible, not_found, unsettled, zero_charge, grant_funded. - string reason = 4 [(common.v1.classification) = DATA_CLASSIFICATION_SAFE]; -} -message PreviewPrepaidCompensationResponse { - repeated PrepaidCompensationEligibility entries = 1; -} diff --git a/proto/objectives/v1/objectives.proto b/proto/objectives/v1/objectives.proto deleted file mode 100644 index 02d2c80..0000000 --- a/proto/objectives/v1/objectives.proto +++ /dev/null @@ -1,399 +0,0 @@ -syntax = "proto3"; - -package objectives.v1; - -import "buf/validate/validate.proto"; -import "common/v1/authz.proto"; -import "common/v1/surface.proto"; -import "google/protobuf/any.proto"; -import "google/protobuf/timestamp.proto"; - -option go_package = "github.com/evalops/platform/gen/go/objectives/v1;objectivesv1"; - -// ObjectiveService manages agent objectives and their lifecycle. -service ObjectiveService { - rpc Create(CreateRequest) returns (CreateResponse) { - option (common.v1.required_scopes) = "objectives:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc Get(GetRequest) returns (GetResponse) { - option (common.v1.required_scopes) = "objectives:read"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc Transition(TransitionRequest) returns (TransitionResponse) { - option (common.v1.required_scopes) = "objectives:write"; - - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc Wake(WakeRequest) returns (WakeResponse) { - option (common.v1.required_scopes) = "objectives:write"; - - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc ScheduleWake(ScheduleWakeRequest) returns (ScheduleWakeResponse) { - option (common.v1.required_scopes) = "objectives:write"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc Query(QueryRequest) returns (QueryResponse) { - option (common.v1.required_scopes) = "objectives:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc RecordProvenance(RecordProvenanceRequest) returns (RecordProvenanceResponse) { - option (common.v1.required_scopes) = "objectives:write"; - - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc RecordMutation(RecordMutationRequest) returns (RecordMutationResponse) { - option (common.v1.required_scopes) = "objectives:write"; - - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc GetGovernanceEvaluation(GetGovernanceEvaluationRequest) returns (GetGovernanceEvaluationResponse) { - option (common.v1.required_scopes) = "objectives:read"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc Cancel(CancelRequest) returns (CancelResponse) { - option (common.v1.required_scopes) = "objectives:write"; - - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc AppendTurn(AppendTurnRequest) returns (AppendTurnResponse) { - option (common.v1.required_scopes) = "objectives:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc RunStep(RunStepRequest) returns (RunStepResponse) { - option (common.v1.required_scopes) = "objectives:write"; - - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc WaitForEvent(WaitForEventRequest) returns (WaitForEventResponse) { - option (common.v1.required_scopes) = "objectives:write"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc ListTurns(ListTurnsRequest) returns (ListTurnsResponse) { - option (common.v1.required_scopes) = "objectives:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc QueryTurns(QueryTurnsRequest) returns (QueryTurnsResponse) { - option (common.v1.required_scopes) = "objectives:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } -} - -// ObjectiveState describes the lifecycle state of an objective. -enum ObjectiveState { - OBJECTIVE_STATE_UNSPECIFIED = 0; - OBJECTIVE_STATE_PENDING = 1; - OBJECTIVE_STATE_RUNNING = 2; - OBJECTIVE_STATE_BLOCKED = 3; - OBJECTIVE_STATE_DEGRADED = 4; - OBJECTIVE_STATE_AWAITING_APPROVAL = 5; - OBJECTIVE_STATE_QUEUED = 6; - OBJECTIVE_STATE_COMPLETED = 7; - OBJECTIVE_STATE_FAILED = 8; - OBJECTIVE_STATE_CANCELLED = 9; -} - -// MutationStatus describes the status of a mutation operation. -enum MutationStatus { - MUTATION_STATUS_UNSPECIFIED = 0; - MUTATION_STATUS_PENDING = 1; - MUTATION_STATUS_APPROVED = 2; - MUTATION_STATUS_DENIED = 3; - MUTATION_STATUS_EXECUTED = 4; - MUTATION_STATUS_ROLLED_BACK = 5; -} - -// TurnKind identifies the durable work represented by an objective turn. -enum TurnKind { - TURN_KIND_UNSPECIFIED = 0; - TURN_KIND_USER_MESSAGE = 1; - TURN_KIND_LLM_CALL = 2; - TURN_KIND_TOOL_CALL = 3; - TURN_KIND_APPROVAL_WAIT = 4; - TURN_KIND_SLEEP = 5; - TURN_KIND_EVENT_WAIT = 6; -} - -// TurnStatus describes replayable execution state for a journaled turn. -enum TurnStatus { - TURN_STATUS_UNSPECIFIED = 0; - TURN_STATUS_PENDING = 1; - TURN_STATUS_RUNNING = 2; - TURN_STATUS_COMPLETED = 3; - TURN_STATUS_FAILED = 4; - TURN_STATUS_REPLAY = 5; -} - -// Objective is the canonical agent objective record. -message Objective { - string id = 1; - string workspace_id = 2; - string agent_id = 3; - string surface = 4; - string title = 5; - string description = 6; - ObjectiveState state = 7; - repeated ProvenanceRecord provenance = 8; - repeated MutationRecord mutations = 9; - WakeSchedule wake_schedule = 10; - google.protobuf.Timestamp created_at = 11; - google.protobuf.Timestamp updated_at = 12; - common.v1.Surface surface_type = 13 [(buf.validate.field).enum.defined_only = true]; - string idempotency_key = 14; - string organization_id = 15; -} - -// ProvenanceRecord tracks where data came from. -message ProvenanceRecord { - string source_integration = 1; - string source_id = 2; - int32 freshness_seconds = 3; - float confidence = 4; -} - -// MutationRecord tracks a write operation performed by an objective. -message MutationRecord { - string target_integration = 1; - string operation = 2; - MutationStatus status = 3; - string approval_id = 4; -} - -// WakeSchedule defines when and how an objective should be reactivated. -message WakeSchedule { - google.protobuf.Timestamp wake_at = 1; - string reason = 2; - int32 retry_count = 3; - int32 max_retries = 4; - int32 backoff_seconds = 5; -} - -// Turn is the per-objective replay journal used by agent sessions. -message Turn { - string id = 1; - string objective_id = 2; - int32 sequence = 3; - TurnKind kind = 4; - google.protobuf.Any payload = 5; - google.protobuf.Any result = 6; - TurnStatus status = 7; - google.protobuf.Timestamp started_at = 8; - google.protobuf.Timestamp completed_at = 9; - string idempotency_key = 10; -} - -message WaitForEventPayload { - string event_subject = 1; - google.protobuf.Any payload = 2; -} - -message CreateRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string agent_id = 2; - string surface = 3; - string title = 4 [(buf.validate.field).string.min_len = 1]; - string description = 5; - common.v1.Surface surface_type = 6 [(buf.validate.field).enum.defined_only = true]; - string idempotency_key = 7; - repeated ProvenanceRecord provenance = 8; - string organization_id = 9; -} - -message CreateResponse { - Objective objective = 1; -} - -message GetRequest { - string id = 1 [(buf.validate.field).string.min_len = 1]; -} - -message GetResponse { - Objective objective = 1; -} - -message TransitionRequest { - string id = 1 [(buf.validate.field).string.min_len = 1]; - ObjectiveState state = 2 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string reason = 3; -} - -message TransitionResponse { - Objective objective = 1; -} - -message WakeRequest { - string id = 1 [(buf.validate.field).string.min_len = 1]; -} - -message WakeResponse { - Objective objective = 1; -} - -message ScheduleWakeRequest { - string id = 1 [(buf.validate.field).string.min_len = 1]; - WakeSchedule wake_schedule = 2 [(buf.validate.field).required = true]; - // State to hold until wake_at is due. If unspecified, the service uses BLOCKED. - ObjectiveState state = 3 [(buf.validate.field).enum.defined_only = true]; -} - -message ScheduleWakeResponse { - Objective objective = 1; -} - -message QueryRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string agent_id = 2; - ObjectiveState state = 3; - int32 limit = 4 [(buf.validate.field).int32.lte = 200]; - int32 offset = 5 [(buf.validate.field).int32.gte = 0]; - string organization_id = 6; -} - -message QueryResponse { - repeated Objective objectives = 1; - int32 total = 2; -} - -message RecordProvenanceRequest { - string objective_id = 1 [(buf.validate.field).string.min_len = 1]; - ProvenanceRecord provenance = 2 [(buf.validate.field).required = true]; -} - -message RecordProvenanceResponse { - Objective objective = 1; -} - -message RecordMutationRequest { - string objective_id = 1 [(buf.validate.field).string.min_len = 1]; - MutationRecord mutation = 2 [(buf.validate.field).required = true]; -} - -message RecordMutationResponse { - Objective objective = 1; -} - -message GetGovernanceEvaluationRequest { - string objective_id = 1 [(buf.validate.field).string.min_len = 1]; -} - -message GetGovernanceEvaluationResponse { - string objective_id = 1; - bool compliant = 2; - repeated string violations = 3; -} - -message CancelRequest { - string id = 1 [(buf.validate.field).string.min_len = 1]; - string reason = 2; -} - -message CancelResponse { - Objective objective = 1; -} - -message AppendTurnRequest { - string objective_id = 1 [(buf.validate.field).string.min_len = 1]; - TurnKind kind = 2 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - google.protobuf.Any payload = 3; - string idempotency_key = 4; - int32 sequence = 5 [(buf.validate.field).int32.gte = 0]; - google.protobuf.Any result = 6; - TurnStatus status = 7 [(buf.validate.field).enum.defined_only = true]; - string organization_id = 8; - string workspace_id = 9; -} - -message AppendTurnResponse { - Turn turn = 1; - bool replayed = 2; -} - -message RunStepRequest { - string objective_id = 1 [(buf.validate.field).string.min_len = 1]; - string idempotency_key = 2 [(buf.validate.field).string.min_len = 1]; - TurnKind kind = 3 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - google.protobuf.Any payload = 4; - google.protobuf.Any result = 5; -} - -message RunStepResponse { - Turn turn = 1; - bool replayed = 2; -} - -message WaitForEventRequest { - string objective_id = 1 [(buf.validate.field).string.min_len = 1]; - string idempotency_key = 2; - string event_subject = 3 [(buf.validate.field).string.min_len = 1]; - google.protobuf.Any payload = 4; -} - -message WaitForEventResponse { - Turn turn = 1; - bool replayed = 2; -} - -message ListTurnsRequest { - string objective_id = 1 [(buf.validate.field).string.min_len = 1]; - int32 limit = 2 [(buf.validate.field).int32.lte = 200]; - int32 offset = 3 [(buf.validate.field).int32.gte = 0]; - string organization_id = 4; - string workspace_id = 5; -} - -message ListTurnsResponse { - repeated Turn turns = 1; - int32 total = 2; -} - -message ObjectiveTurn { - Objective objective = 1; - Turn turn = 2; -} - -message QueryTurnsRequest { - string organization_id = 1; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string agent_id = 3; - int32 limit = 4 [ - (buf.validate.field).int32.gte = 0, - (buf.validate.field).int32.lte = 200 - ]; - int32 offset = 5 [(buf.validate.field).int32.gte = 0]; - string payload_channel_id = 6; - bool omit_total = 7; -} - -message QueryTurnsResponse { - repeated ObjectiveTurn turns = 1; - int32 total = 2 [(buf.validate.field).int32.gte = 0]; -} diff --git a/proto/orbcontrol/v1/orb_control.proto b/proto/orbcontrol/v1/orb_control.proto deleted file mode 100644 index 959d4ca..0000000 --- a/proto/orbcontrol/v1/orb_control.proto +++ /dev/null @@ -1,161 +0,0 @@ -syntax = "proto3"; - -package orbcontrol.v1; - -import "buf/validate/validate.proto"; -import "common/v1/authz.proto"; -import "google/protobuf/timestamp.proto"; - -option go_package = "github.com/evalops/platform/gen/go/orbcontrol/v1;orbcontrolv1"; - -// OrbControlOwnerService is the narrow Platform-to-Orb runtime-owner boundary. -// Commands are idempotent and generation-fenced; completion is established by -// observed state and ordered events rather than by submission acknowledgement. -service OrbControlOwnerService { - // SubmitOrbCommand accepts or replays one exact lifecycle command. - rpc SubmitOrbCommand(SubmitOrbCommandRequest) returns (SubmitOrbCommandResponse) { - option (common.v1.required_scopes) = "orb:control:owner"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - // GetOrbObservedState returns the runtime owner's current fenced projection. - rpc GetOrbObservedState(GetOrbObservedStateRequest) returns (GetOrbObservedStateResponse) { - option (common.v1.required_scopes) = "orb:control:owner"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // StreamOrbEvents returns a bounded page from the tenant-wide durable cursor. - rpc StreamOrbEvents(StreamOrbEventsRequest) returns (StreamOrbEventsResponse) { - option (common.v1.required_scopes) = "orb:control:owner"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } -} - -// OrbCommandKind is the first supported Platform-owned lifecycle command set. -enum OrbCommandKind { - ORB_COMMAND_KIND_UNSPECIFIED = 0; - ORB_COMMAND_KIND_WAKE = 1; - ORB_COMMAND_KIND_STOP = 2; -} - -// OrbObservedLifecycle is the runtime owner's customer-safe lifecycle state. -enum OrbObservedLifecycle { - ORB_OBSERVED_LIFECYCLE_UNSPECIFIED = 0; - ORB_OBSERVED_LIFECYCLE_SLEEPING = 1; - ORB_OBSERVED_LIFECYCLE_WAKING = 2; - ORB_OBSERVED_LIFECYCLE_READY = 3; - ORB_OBSERVED_LIFECYCLE_WORKING = 4; - ORB_OBSERVED_LIFECYCLE_WAITING_FOR_YOU = 5; - ORB_OBSERVED_LIFECYCLE_RECOVERING = 6; - ORB_OBSERVED_LIFECYCLE_OFFLINE = 7; -} - -// OrbCommandAcceptance distinguishes a new acceptance from an exact replay. -enum OrbCommandAcceptance { - ORB_COMMAND_ACCEPTANCE_UNSPECIFIED = 0; - ORB_COMMAND_ACCEPTANCE_ACCEPTED = 1; - ORB_COMMAND_ACCEPTANCE_REPLAYED = 2; - ORB_COMMAND_ACCEPTANCE_REJECTED = 3; -} - -// OrbControlEventKind identifies durable owner observations. -enum OrbControlEventKind { - ORB_CONTROL_EVENT_KIND_UNSPECIFIED = 0; - ORB_CONTROL_EVENT_KIND_SNAPSHOT = 1; - ORB_CONTROL_EVENT_KIND_COMMAND_ACCEPTED = 2; - ORB_CONTROL_EVENT_KIND_LIFECYCLE_CHANGED = 3; - ORB_CONTROL_EVENT_KIND_COMMAND_COMPLETED = 4; - ORB_CONTROL_EVENT_KIND_COMMAND_FAILED = 5; -} - -// OrbCommand is the normalized mutation payload persisted by both planes. -message OrbCommand { - OrbCommandKind kind = 1 [(buf.validate.field).enum = { - defined_only: true - not_in: 0 - }]; -} - -// SubmitOrbCommandRequest carries one exact tenant-scoped owner command. -message SubmitOrbCommandRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string target_id = 3 [(buf.validate.field).string.min_len = 1]; - string idempotency_key = 4 [(buf.validate.field).string.min_len = 1]; - string lineage_id = 5 [(buf.validate.field).string.min_len = 1]; - string operation_id = 6 [(buf.validate.field).string.min_len = 1]; - uint64 expected_generation = 7; - OrbCommand command = 8 [(buf.validate.field).required = true]; -} - -// SubmitOrbCommandResponse acknowledges ownership without claiming completion. -message SubmitOrbCommandResponse { - OrbCommandAcceptance acceptance = 1 [(buf.validate.field).enum.defined_only = true]; - string command_id = 2; - string operation_id = 3; - string idempotency_key = 4; - uint64 accepted_generation = 5; - uint64 observed_revision = 6; - uint64 event_sequence = 7; - string reason_code = 8; -} - -// GetOrbObservedStateRequest selects one tenant-scoped runtime target. -message GetOrbObservedStateRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string target_id = 3 [(buf.validate.field).string.min_len = 1]; -} - -// OrbObservedState is the authoritative runtime projection for one target. -message OrbObservedState { - string target_id = 1; - string display_name = 2; - OrbObservedLifecycle lifecycle = 3 [(buf.validate.field).enum.defined_only = true]; - uint64 generation = 4; - uint64 observed_revision = 5; - uint64 last_event_sequence = 6; - string resident_agent = 7; - string provisioner = 8; - string active_operation_id = 9; - google.protobuf.Timestamp observed_at = 10; -} - -// GetOrbObservedStateResponse returns one authoritative runtime projection. -message GetOrbObservedStateResponse { - OrbObservedState state = 1 [(buf.validate.field).required = true]; -} - -// OrbControlEvent is one workspace-ordered observed-state transition. -message OrbControlEvent { - uint64 sequence = 1; - string event_id = 2; - string target_id = 3; - uint64 generation = 4; - uint64 observed_revision = 5; - OrbControlEventKind kind = 6 [(buf.validate.field).enum.defined_only = true]; - OrbObservedState state = 7; - string operation_id = 8; - string command_id = 9; - string reason_code = 10; - google.protobuf.Timestamp occurred_at = 11; -} - -// StreamOrbEventsRequest resumes a tenant-wide cursor after one sequence. -message StreamOrbEventsRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - uint64 after_sequence = 3; - uint32 limit = 4 [(buf.validate.field).uint32.lte = 500]; -} - -// StreamOrbEventsResponse is a bounded durable cursor page. -message StreamOrbEventsResponse { - repeated OrbControlEvent events = 1 [(buf.validate.field).repeated.max_items = 500]; - uint64 next_sequence = 2; - bool has_more = 3; -} diff --git a/proto/platform/v1/platform.proto b/proto/platform/v1/platform.proto deleted file mode 100644 index 00c1149..0000000 --- a/proto/platform/v1/platform.proto +++ /dev/null @@ -1,751 +0,0 @@ -syntax = "proto3"; - -package platform.v1; - -import "buf/validate/validate.proto"; -import "common/v1/authz.proto"; -import "google/protobuf/struct.proto"; -import "google/protobuf/timestamp.proto"; - -option go_package = "github.com/evalops/platform/gen/go/platform/v1;platformv1"; - -// PlatformService is the product-facing primitive API for the Rust platform -// core. It is Protobuf-first; JSON is only a protobuf mapping for tooling and -// debug surfaces, not the source of truth. -service PlatformService { - // GetBootstrap returns tenant-scoped platform capabilities for the frontend. - rpc GetBootstrap(GetBootstrapRequest) returns (GetBootstrapResponse) { - option (common.v1.required_scopes) = "platform:read"; - option (common.v1.workspace_scope_field) = "scope.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // CreateWork creates a stateful work owner record through an operation record. - rpc CreateWork(CreateWorkRequest) returns (CreateWorkResponse) { - option (common.v1.required_scopes) = "platform:write"; - option (common.v1.workspace_scope_field) = "context.scope.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // ProposeAction records an action intent even when execution is blocked. - rpc ProposeAction(ProposeActionRequest) returns (ProposeActionResponse) { - option (common.v1.required_scopes) = "platform:write"; - option (common.v1.workspace_scope_field) = "context.scope.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // CreateArtifact creates a versioned artifact through an operation record. - rpc CreateArtifact(CreateArtifactRequest) returns (CreateArtifactResponse) { - option (common.v1.required_scopes) = "platform:write"; - option (common.v1.workspace_scope_field) = "context.scope.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // RecordEvidence records audit, trace, usage, attestation, replay, or lineage evidence. - rpc RecordEvidence(RecordEvidenceRequest) returns (RecordEvidenceResponse) { - option (common.v1.required_scopes) = "platform:write"; - option (common.v1.workspace_scope_field) = "context.scope.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // RecordScore records a queryable eval score on the same operation spine. - rpc RecordScore(RecordScoreRequest) returns (RecordScoreResponse) { - option (common.v1.required_scopes) = "platform:write"; - option (common.v1.workspace_scope_field) = "context.scope.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // ApplyRecommendation closes the eval loop by recording a rollout decision. - rpc ApplyRecommendation(ApplyRecommendationRequest) returns (ApplyRecommendationResponse) { - option (common.v1.required_scopes) = "platform:write"; - option (common.v1.workspace_scope_field) = "context.scope.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } -} - -message TenantScope { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string team_id = 3; - string environment = 4; -} - -enum PrincipalKind { - PRINCIPAL_KIND_UNSPECIFIED = 0; - PRINCIPAL_KIND_HUMAN = 1; - PRINCIPAL_KIND_SERVICE_ACCOUNT = 2; - PRINCIPAL_KIND_AGENT = 3; - PRINCIPAL_KIND_DEVICE = 4; - PRINCIPAL_KIND_WORKLOAD = 5; -} - -message Principal { - string principal_id = 1 [(buf.validate.field).string.min_len = 1]; - PrincipalKind kind = 2 [(buf.validate.field).enum.defined_only = true]; - string display_name = 3; -} - -message Actor { - Principal principal = 1 [(buf.validate.field).required = true]; - string session_id = 2; -} - -enum PolicyKind { - POLICY_KIND_UNSPECIFIED = 0; - POLICY_KIND_AUTHORITY = 1; - POLICY_KIND_CREDENTIAL = 2; - POLICY_KIND_SOURCE_OF_TRUTH = 3; - POLICY_KIND_LIFECYCLE = 4; - POLICY_KIND_BILLING = 5; -} - -message PolicyRef { - string policy_id = 1 [(buf.validate.field).string.min_len = 1]; - string version_id = 2 [(buf.validate.field).string.min_len = 1]; -} - -message Policy { - string policy_id = 1 [(buf.validate.field).string.min_len = 1]; - TenantScope scope = 2 [(buf.validate.field).required = true]; - PolicyKind kind = 3 [(buf.validate.field).enum.defined_only = true]; - string name = 4 [(buf.validate.field).string.min_len = 1]; - string active_version_id = 5 [(buf.validate.field).string.min_len = 1]; -} - -message PolicyVersion { - string version_id = 1 [(buf.validate.field).string.min_len = 1]; - string policy_id = 2 [(buf.validate.field).string.min_len = 1]; - string artifact_version_id = 3 [(buf.validate.field).string.min_len = 1]; - Principal created_by = 4 [(buf.validate.field).required = true]; - string lineage_id = 5 [(buf.validate.field).string.min_len = 1]; -} - -enum AuthorityDecisionKind { - AUTHORITY_DECISION_KIND_UNSPECIFIED = 0; - AUTHORITY_DECISION_KIND_ALLOW = 1; - AUTHORITY_DECISION_KIND_DENY = 2; - AUTHORITY_DECISION_KIND_REQUIRE_APPROVAL = 3; - AUTHORITY_DECISION_KIND_APPROVAL_RESOLVED = 4; - AUTHORITY_DECISION_KIND_GRANT_EXPIRED = 5; - AUTHORITY_DECISION_KIND_DELEGATION_NARROWED = 6; -} - -message AuthorityDecision { - string decision_id = 1 [(buf.validate.field).string.min_len = 1]; - AuthorityDecisionKind kind = 2 [(buf.validate.field).enum.defined_only = true]; - repeated PolicyRef policy_refs = 3; - repeated string reasons = 4; - string approval_request_id = 5; - string grant_id = 6; - google.protobuf.Timestamp evaluated_at = 7; -} - -message OperationContext { - TenantScope scope = 1 [(buf.validate.field).required = true]; - Actor actor = 2 [(buf.validate.field).required = true]; - AuthorityDecision authority = 3 [(buf.validate.field).required = true]; - string idempotency_key = 4 [(buf.validate.field).string.min_len = 1]; - string lineage_id = 5 [(buf.validate.field).string.min_len = 1]; - string request_id = 6 [(buf.validate.field).string.min_len = 1]; - google.protobuf.Timestamp now = 7 [(buf.validate.field).required = true]; - google.protobuf.Struct evidence = 8; -} - -message OperationRecord { - string operation_id = 1 [(buf.validate.field).string.min_len = 1]; - TenantScope scope = 2 [(buf.validate.field).required = true]; - Actor actor = 3 [(buf.validate.field).required = true]; - AuthorityDecision authority = 4 [(buf.validate.field).required = true]; - string idempotency_key = 5 [(buf.validate.field).string.min_len = 1]; - string lineage_id = 6 [(buf.validate.field).string.min_len = 1]; - string request_id = 7 [(buf.validate.field).string.min_len = 1]; - google.protobuf.Timestamp recorded_at = 8 [(buf.validate.field).required = true]; - string operation_type = 9 [(buf.validate.field).string.min_len = 1]; - string owner_type = 10 [(buf.validate.field).string.min_len = 1]; - string owner_id = 11 [(buf.validate.field).string.min_len = 1]; -} - -enum WorkKind { - WORK_KIND_UNSPECIFIED = 0; - WORK_KIND_OBJECTIVE = 1; - WORK_KIND_WORKFLOW = 2; - WORK_KIND_AGENT_RUN = 3; - WORK_KIND_STEP = 4; - WORK_KIND_WAIT = 5; - WORK_KIND_RETRY = 6; - WORK_KIND_TOOL_EXECUTION = 7; - WORK_KIND_RUNNER_SESSION = 8; - WORK_KIND_EVAL_RUN = 9; - WORK_KIND_COMPUTER_MISSION = 10; - WORK_KIND_ARTIFACT_RENDER = 11; -} - -message EvalAssignment { - string cohort_id = 1 [(buf.validate.field).string.min_len = 1]; - string candidate_id = 2 [(buf.validate.field).string.min_len = 1]; - string baseline_id = 3; - string assignment_id = 4; -} - -enum WorkState { - WORK_STATE_UNSPECIFIED = 0; - WORK_STATE_PROPOSED = 1; - WORK_STATE_QUEUED = 2; - WORK_STATE_RUNNING = 3; - WORK_STATE_WAITING = 4; - WORK_STATE_SUCCEEDED = 5; - WORK_STATE_FAILED = 6; - WORK_STATE_CANCELLED = 7; -} - -message NewWorkItem { - WorkKind kind = 1 [(buf.validate.field).enum.defined_only = true]; - string title = 2 [(buf.validate.field).string.min_len = 1]; - string parent_work_id = 3; - google.protobuf.Struct metadata = 4; - EvalAssignment eval_assignment = 5; - // Immutable, versioned remediation plan owned by this Work item. - WorkRemediationPlan remediation_plan = 6; -} - -message WorkItem { - string work_id = 1 [(buf.validate.field).string.min_len = 1]; - TenantScope scope = 2 [(buf.validate.field).required = true]; - WorkKind kind = 3 [(buf.validate.field).enum.defined_only = true]; - WorkState state = 4 [(buf.validate.field).enum.defined_only = true]; - string title = 5 [(buf.validate.field).string.min_len = 1]; - string parent_work_id = 6; - Principal created_by = 7 [(buf.validate.field).required = true]; - string lineage_id = 8 [(buf.validate.field).string.min_len = 1]; - google.protobuf.Struct metadata = 9; - EvalAssignment eval_assignment = 10; - WorkRemediationPlan remediation_plan = 11; -} - -enum ResourceKind { - RESOURCE_KIND_UNSPECIFIED = 0; - RESOURCE_KIND_AGENT = 1; - RESOURCE_KIND_TOOL = 2; - RESOURCE_KIND_REPO = 3; - RESOURCE_KIND_DATASET = 4; - RESOURCE_KIND_DATABASE = 5; - RESOURCE_KIND_CRM_OBJECT = 6; - RESOURCE_KIND_MODEL_ROUTE = 7; - RESOURCE_KIND_EXTERNAL = 8; - // Durable content identities are transport-safe references. Their tenant - // authority is supplied by the enclosing request, never encoded here. - RESOURCE_KIND_VFS_OBJECT = 9; - RESOURCE_KIND_VFS_OBJECT_VERSION = 10; - RESOURCE_KIND_ARTIFACT = 11; - RESOURCE_KIND_ARTIFACT_VERSION = 12; - RESOURCE_KIND_GENERATED_ASSET = 13; -} - -// ResourceRef is the canonical structured pointer for durable Platform -// content. It is intentionally not a URI: callers carry organization and -// workspace authority in the surrounding request, while a resolver owned by -// the resource's service decides whether a reference yields metadata, VFS -// identity, or a short-lived byte-access grant. -message ResourceRef { - string resource_id = 1 [(buf.validate.field).string.min_len = 1]; - ResourceKind kind = 2 [(buf.validate.field).enum.defined_only = true]; - // Stable immutable version identity, when the reference is version-bound. - string version_id = 3; - // Owner-defined monotonic version number. Zero means the latest version - // when version_id is empty; version_id wins when both are supplied. - int32 version = 4 [(buf.validate.field).int32.gte = 0]; -} - -enum WorkRemediationClassification { - WORK_REMEDIATION_CLASSIFICATION_UNSPECIFIED = 0; - WORK_REMEDIATION_CLASSIFICATION_AUTO_EXECUTABLE = 1; - WORK_REMEDIATION_CLASSIFICATION_APPROVAL_EXECUTABLE = 2; - WORK_REMEDIATION_CLASSIFICATION_MANUAL_WORK = 3; - WORK_REMEDIATION_CLASSIFICATION_BLOCKED = 4; -} - -enum WorkRemediationEvidenceIndependence { - WORK_REMEDIATION_EVIDENCE_INDEPENDENCE_UNSPECIFIED = 0; - WORK_REMEDIATION_EVIDENCE_INDEPENDENCE_ACTION_OUTPUT = 1; - WORK_REMEDIATION_EVIDENCE_INDEPENDENCE_INDEPENDENT_OBSERVATION = 2; -} - -// Exact external identity; the enclosing Work scope remains tenant authority. -message WorkRemediationResource { - string provider_id = 1 [(buf.validate.field).string.min_len = 1]; - string connection_id = 2 [(buf.validate.field).string.min_len = 1]; - string stable_resource_id = 3 [(buf.validate.field).string.min_len = 1]; - string resource_kind = 4 [(buf.validate.field).string.min_len = 1]; - ResourceRef platform_resource = 5; -} - -message WorkRemediationAction { - string action_id = 1 [(buf.validate.field).string.min_len = 1]; - string catalog_digest = 2 [(buf.validate.field).string.min_len = 1]; - string input_digest = 3 [(buf.validate.field).string.min_len = 1]; - WorkRemediationResource target = 4 [(buf.validate.field).required = true]; - RiskTier risk_tier = 5 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - bool approval_required = 6; - repeated string required_scopes = 7; - string idempotency_key = 8 [(buf.validate.field).string.min_len = 1]; - repeated string postcondition_ids = 9; - // Immutable ArtifactVersion containing schema-validated provider arguments. - // input_digest binds its exact bytes; secrets remain references. - ResourceRef input_artifact_ref = 10 [(buf.validate.field).required = true]; -} - -message WorkRemediationPostcondition { - string postcondition_id = 1 [(buf.validate.field).string.min_len = 1]; - WorkRemediationResource target = 2 [(buf.validate.field).required = true]; - string observer_action_id = 3 [(buf.validate.field).string.min_len = 1]; - string expected_state_digest = 4 [(buf.validate.field).string.min_len = 1]; - uint32 max_age_seconds = 5 [(buf.validate.field).uint32.gt = 0]; - WorkRemediationEvidenceIndependence required_independence = 6 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - // Pins the read contract used to independently verify this condition. - string observer_catalog_digest = 7 [(buf.validate.field).string.min_len = 1]; -} - -// A typed extension of Platform Work, not a separate execution or approval -// owner. plan_digest excludes itself and binds every immutable field below. -message WorkRemediationPlan { - uint32 schema_version = 1 [(buf.validate.field).uint32.gt = 0]; - string plan_digest = 2 [(buf.validate.field).string.min_len = 1]; - TenantScope scope = 3 [(buf.validate.field).required = true]; - string source_finding_id = 4 [(buf.validate.field).string.min_len = 1]; - repeated RecordRef source_evidence = 5; - repeated WorkRemediationResource affected_resources = 6; - repeated WorkRemediationPostcondition postconditions = 7; - repeated WorkRemediationAction actions = 8; - WorkRemediationClassification classification = 9 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string lineage_id = 10 [(buf.validate.field).string.min_len = 1]; - string idempotency_key = 11 [(buf.validate.field).string.min_len = 1]; - // Manual and blocked Work retain an explicit reason rather than inventing - // an executable connector action. - string non_executable_reason = 12; -} - -// RecordKind identifies an authoritative operational record without copying -// that record into a read model. The enclosing request supplies exact tenant -// authority; the kind selects the owner resolver for record_id. -enum RecordKind { - RECORD_KIND_UNSPECIFIED = 0; - RECORD_KIND_RUN = 1; - RECORD_KIND_MODEL_RUN = 2; - RECORD_KIND_TOOL_EXECUTION = 3; - RECORD_KIND_POLICY_DECISION = 4; - RECORD_KIND_APPROVAL = 5; - RECORD_KIND_CREDENTIAL = 6; - RECORD_KIND_CONNECTOR = 7; - RECORD_KIND_CONNECTOR_SESSION = 8; - RECORD_KIND_ARTIFACT = 9; - RECORD_KIND_USAGE = 10; - RECORD_KIND_RECEIPT = 11; - RECORD_KIND_EVIDENCE = 12; - RECORD_KIND_EVAL_RUN = 13; -} - -// RecordRef is the canonical, content-free pointer used by customer read -// models to join independently owned operational records. It is correlation, -// never authority: consumers must resolve it through the owning service under -// the authenticated tenant carried by the enclosing request. -message RecordRef { - RecordKind kind = 1 [(buf.validate.field).enum = { - defined_only: true - not_in: [0] - }]; - string record_id = 2 [(buf.validate.field).string.min_len = 1]; - // Owner-defined immutable revision or digest when the reference is pinned. - string revision = 3; -} - -enum RiskTier { - RISK_TIER_UNSPECIFIED = 0; - RISK_TIER_LOW = 1; - RISK_TIER_MEDIUM = 2; - RISK_TIER_HIGH = 3; - RISK_TIER_CRITICAL = 4; -} - -enum ApprovalState { - APPROVAL_STATE_UNSPECIFIED = 0; - APPROVAL_STATE_NOT_REQUIRED = 1; - APPROVAL_STATE_REQUIRED = 2; - APPROVAL_STATE_RESOLVED = 3; - APPROVAL_STATE_DENIED = 4; - APPROVAL_STATE_EXPIRED = 5; -} - -enum ActionExecutionState { - ACTION_EXECUTION_STATE_UNSPECIFIED = 0; - ACTION_EXECUTION_STATE_PROPOSED = 1; - ACTION_EXECUTION_STATE_APPROVED = 2; - ACTION_EXECUTION_STATE_BLOCKED = 3; - ACTION_EXECUTION_STATE_EXECUTING = 4; - ACTION_EXECUTION_STATE_SUCCEEDED = 5; - ACTION_EXECUTION_STATE_FAILED = 6; - ACTION_EXECUTION_STATE_CANCELLED = 7; -} - -message ActionIntent { - string action_intent_id = 1 [(buf.validate.field).string.min_len = 1]; - TenantScope scope = 2 [(buf.validate.field).required = true]; - Principal proposed_by = 3 [(buf.validate.field).required = true]; - string action_type = 4 [(buf.validate.field).string.min_len = 1]; - ResourceRef target_resource = 5; - string input_digest = 6 [(buf.validate.field).string.min_len = 1]; - RiskTier risk_tier = 7 [(buf.validate.field).enum.defined_only = true]; - AuthorityDecision authority_decision = 8 [(buf.validate.field).required = true]; - ApprovalState approval_state = 9 [(buf.validate.field).enum.defined_only = true]; - ActionExecutionState execution_state = 10 [(buf.validate.field).enum.defined_only = true]; - string lineage_id = 11 [(buf.validate.field).string.min_len = 1]; - google.protobuf.Struct evidence = 12; - google.protobuf.Struct result = 13; - EvalAssignment eval_assignment = 14; -} - -enum ArtifactKind { - ARTIFACT_KIND_UNSPECIFIED = 0; - ARTIFACT_KIND_PROMPT = 1; - ARTIFACT_KIND_SKILL = 2; - ARTIFACT_KIND_AGENT_CONFIG = 3; - ARTIFACT_KIND_EVAL_SUITE = 4; - ARTIFACT_KIND_SCENARIO = 5; - ARTIFACT_KIND_GENERATED_FILE = 6; - ARTIFACT_KIND_CONTEXT_ITEM = 7; - ARTIFACT_KIND_VFS_OBJECT = 8; - ARTIFACT_KIND_MODEL_ROUTE = 9; -} - -enum ArtifactState { - ARTIFACT_STATE_UNSPECIFIED = 0; - ARTIFACT_STATE_DRAFT = 1; - ARTIFACT_STATE_ACTIVE = 2; - ARTIFACT_STATE_DEPRECATED = 3; - ARTIFACT_STATE_ARCHIVED = 4; -} - -message NewArtifactVersion { - string artifact_id = 1 [(buf.validate.field).string.min_len = 1]; - ArtifactKind kind = 2 [(buf.validate.field).enum.defined_only = true]; - string label = 3 [(buf.validate.field).string.min_len = 1]; - string content_ref = 4 [(buf.validate.field).string.min_len = 1]; - repeated string labels = 5; - google.protobuf.Struct metadata = 6; - ResourceRef resource_ref = 7; -} - -message Artifact { - string artifact_id = 1 [(buf.validate.field).string.min_len = 1]; - TenantScope scope = 2 [(buf.validate.field).required = true]; - ArtifactKind kind = 3 [(buf.validate.field).enum.defined_only = true]; - ArtifactState state = 4 [(buf.validate.field).enum.defined_only = true]; - string latest_version_id = 5 [(buf.validate.field).string.min_len = 1]; - string lineage_id = 6 [(buf.validate.field).string.min_len = 1]; - ResourceRef resource_ref = 7; -} - -message ArtifactVersion { - string artifact_version_id = 1 [(buf.validate.field).string.min_len = 1]; - string artifact_id = 2 [(buf.validate.field).string.min_len = 1]; - string label = 3 [(buf.validate.field).string.min_len = 1]; - string content_ref = 4 [(buf.validate.field).string.min_len = 1]; - Principal created_by = 5 [(buf.validate.field).required = true]; - string lineage_id = 6 [(buf.validate.field).string.min_len = 1]; - repeated string labels = 7; - google.protobuf.Struct metadata = 8; - ResourceRef resource_ref = 9; -} - -enum EvidenceKind { - EVIDENCE_KIND_UNSPECIFIED = 0; - EVIDENCE_KIND_AUDIT_EVENT = 1; - EVIDENCE_KIND_TRACE_SPAN = 2; - EVIDENCE_KIND_USAGE = 3; - EVIDENCE_KIND_ATTESTATION = 4; - EVIDENCE_KIND_REPLAY_BUNDLE = 5; - EVIDENCE_KIND_LINEAGE = 6; - EVIDENCE_KIND_SCORE = 7; -} - -message EvidenceRecord { - string evidence_id = 1 [(buf.validate.field).string.min_len = 1]; - TenantScope scope = 2 [(buf.validate.field).required = true]; - EvidenceKind kind = 3 [(buf.validate.field).enum.defined_only = true]; - string subject_id = 4 [(buf.validate.field).string.min_len = 1]; - string lineage_id = 5 [(buf.validate.field).string.min_len = 1]; - google.protobuf.Struct payload = 6; -} - -message Score { - string score_id = 1 [(buf.validate.field).string.min_len = 1]; - TenantScope scope = 2 [(buf.validate.field).required = true]; - string subject_id = 3 [(buf.validate.field).string.min_len = 1]; - string criterion = 4 [(buf.validate.field).string.min_len = 1]; - double value = 5; - string scorer = 6 [(buf.validate.field).string.min_len = 1]; - string target = 7; - EvalAssignment eval_assignment = 8; - string evidence_id = 9; - string lineage_id = 10 [(buf.validate.field).string.min_len = 1]; - google.protobuf.Timestamp scored_at = 11 [(buf.validate.field).required = true]; - google.protobuf.Struct payload = 12; -} - -enum RecommendationKind { - RECOMMENDATION_KIND_UNSPECIFIED = 0; - RECOMMENDATION_KIND_PROMOTE_CANDIDATE = 1; - RECOMMENDATION_KIND_ROLLBACK = 2; - RECOMMENDATION_KIND_REWEIGHT = 3; - RECOMMENDATION_KIND_HOLD = 4; -} - -enum RecommendationState { - RECOMMENDATION_STATE_UNSPECIFIED = 0; - RECOMMENDATION_STATE_PROPOSED = 1; - RECOMMENDATION_STATE_APPLIED = 2; - RECOMMENDATION_STATE_REJECTED = 3; -} - -message Recommendation { - string recommendation_id = 1 [(buf.validate.field).string.min_len = 1]; - TenantScope scope = 2 [(buf.validate.field).required = true]; - RecommendationKind kind = 3 [(buf.validate.field).enum.defined_only = true]; - RecommendationState state = 4 [(buf.validate.field).enum.defined_only = true]; - string subject_id = 5 [(buf.validate.field).string.min_len = 1]; - string action_type = 6 [(buf.validate.field).string.min_len = 1]; - EvalAssignment eval_assignment = 7; - string score_id = 8; - string action_intent_id = 9; - string lineage_id = 10 [(buf.validate.field).string.min_len = 1]; - google.protobuf.Struct rationale = 11; - google.protobuf.Struct result = 12; -} - -message DomainEvent { - string event_id = 1 [(buf.validate.field).string.min_len = 1]; - string operation_id = 2 [(buf.validate.field).string.min_len = 1]; - TenantScope scope = 3 [(buf.validate.field).required = true]; - string owner_type = 4 [(buf.validate.field).string.min_len = 1]; - string owner_id = 5 [(buf.validate.field).string.min_len = 1]; - string event_type = 6 [(buf.validate.field).string.min_len = 1]; - string lineage_id = 7 [(buf.validate.field).string.min_len = 1]; - google.protobuf.Struct payload = 8; -} - -enum OutboxStatus { - OUTBOX_STATUS_UNSPECIFIED = 0; - OUTBOX_STATUS_PENDING = 1; - OUTBOX_STATUS_PUBLISHED = 2; - OUTBOX_STATUS_FAILED = 3; -} - -message OutboxMessage { - string outbox_message_id = 1 [(buf.validate.field).string.min_len = 1]; - string operation_id = 2 [(buf.validate.field).string.min_len = 1]; - string domain_event_id = 3 [(buf.validate.field).string.min_len = 1]; - string topic = 4 [(buf.validate.field).string.min_len = 1]; - OutboxStatus status = 5 [(buf.validate.field).enum.defined_only = true]; - string lineage_id = 6 [(buf.validate.field).string.min_len = 1]; -} - -message OperationReceipt { - OperationRecord operation_record = 1 [(buf.validate.field).required = true]; - DomainEvent domain_event = 2 [(buf.validate.field).required = true]; - OutboxMessage outbox_message = 3 [(buf.validate.field).required = true]; - bool replayed = 4; -} - -enum UsageMetricKind { - USAGE_METRIC_KIND_UNSPECIFIED = 0; - USAGE_METRIC_KIND_INPUT_TOKEN = 1; - USAGE_METRIC_KIND_OUTPUT_TOKEN = 2; - USAGE_METRIC_KIND_CACHED_INPUT_TOKEN = 3; - USAGE_METRIC_KIND_TOOL_CALL = 4; - USAGE_METRIC_KIND_RUNNER_SECOND = 5; - USAGE_METRIC_KIND_STORAGE_BYTE_HOUR = 6; - USAGE_METRIC_KIND_NETWORK_BYTE = 7; - USAGE_METRIC_KIND_CUSTOM = 8; -} - -message UsageLedgerEntry { - string usage_entry_id = 1 [(buf.validate.field).string.min_len = 1]; - string operation_id = 2 [(buf.validate.field).string.min_len = 1]; - TenantScope scope = 3 [(buf.validate.field).required = true]; - Principal principal = 4 [(buf.validate.field).required = true]; - string action_intent_id = 5; - string work_id = 6; - string artifact_version_id = 7; - string trace_id = 8; - string span_id = 9; - string provider = 10; - ResourceRef resource = 11; - UsageMetricKind metric_kind = 12 [(buf.validate.field).enum.defined_only = true]; - string quantity_decimal = 13 [(buf.validate.field).string.min_len = 1]; - string unit = 14 [(buf.validate.field).string.min_len = 1]; - google.protobuf.Timestamp observed_at = 15 [(buf.validate.field).required = true]; - string lineage_id = 16 [(buf.validate.field).string.min_len = 1]; - google.protobuf.Struct metadata = 17; -} - -message SpendLedgerEntry { - string spend_entry_id = 1 [(buf.validate.field).string.min_len = 1]; - string operation_id = 2 [(buf.validate.field).string.min_len = 1]; - TenantScope scope = 3 [(buf.validate.field).required = true]; - string usage_entry_id = 4; - string action_intent_id = 5; - int64 amount_micros = 6; - string currency = 7 [(buf.validate.field).string.len = 3]; - PolicyRef pricing_policy_ref = 8; - google.protobuf.Timestamp incurred_at = 9 [(buf.validate.field).required = true]; - string lineage_id = 10 [(buf.validate.field).string.min_len = 1]; - string allocation_key = 11; - google.protobuf.Struct metadata = 12; -} - -enum AttributionSubjectKind { - ATTRIBUTION_SUBJECT_KIND_UNSPECIFIED = 0; - ATTRIBUTION_SUBJECT_KIND_TENANT = 1; - ATTRIBUTION_SUBJECT_KIND_PRINCIPAL = 2; - ATTRIBUTION_SUBJECT_KIND_ACTION_INTENT = 3; - ATTRIBUTION_SUBJECT_KIND_WORK_ITEM = 4; - ATTRIBUTION_SUBJECT_KIND_ARTIFACT_VERSION = 5; - ATTRIBUTION_SUBJECT_KIND_RESOURCE = 6; - ATTRIBUTION_SUBJECT_KIND_TRACE_SPAN = 7; - ATTRIBUTION_SUBJECT_KIND_USAGE_ENTRY = 8; - ATTRIBUTION_SUBJECT_KIND_SPEND_ENTRY = 9; - ATTRIBUTION_SUBJECT_KIND_COST_CENTER = 10; -} - -message AttributionEdge { - string attribution_edge_id = 1 [(buf.validate.field).string.min_len = 1]; - string operation_id = 2 [(buf.validate.field).string.min_len = 1]; - TenantScope scope = 3 [(buf.validate.field).required = true]; - AttributionSubjectKind source_kind = 4 [(buf.validate.field).enum.defined_only = true]; - string source_id = 5 [(buf.validate.field).string.min_len = 1]; - AttributionSubjectKind target_kind = 6 [(buf.validate.field).enum.defined_only = true]; - string target_id = 7 [(buf.validate.field).string.min_len = 1]; - string relation = 8 [(buf.validate.field).string.min_len = 1]; - int64 weight_micros = 9; - string lineage_id = 10 [(buf.validate.field).string.min_len = 1]; - string evidence_id = 11; -} - -message GetBootstrapRequest { - TenantScope scope = 1 [(buf.validate.field).required = true]; -} - -message GetBootstrapResponse { - TenantScope scope = 1 [(buf.validate.field).required = true]; - repeated PlatformCapability capabilities = 2; -} - -enum CapabilityStatus { - CAPABILITY_STATUS_UNSPECIFIED = 0; - CAPABILITY_STATUS_AVAILABLE = 1; - CAPABILITY_STATUS_UNAVAILABLE = 2; -} - -message PlatformCapability { - string name = 1 [(buf.validate.field).string.min_len = 1]; - CapabilityStatus status = 2 [(buf.validate.field).enum.defined_only = true]; - string reason = 3; - repeated PlatformCapabilityFeature features = 4; -} - -message PlatformCapabilityFeature { - string operation = 1 [(buf.validate.field).string.min_len = 1]; - string method = 2 [(buf.validate.field).string.min_len = 1]; - string path = 3 [(buf.validate.field).string.min_len = 1]; -} - -message CreateWorkRequest { - OperationContext context = 1 [(buf.validate.field).required = true]; - NewWorkItem work = 2 [(buf.validate.field).required = true]; -} - -message CreateWorkResponse { - WorkItem work = 1 [(buf.validate.field).required = true]; - OperationReceipt receipt = 2 [(buf.validate.field).required = true]; -} - -message ProposeActionRequest { - OperationContext context = 1 [(buf.validate.field).required = true]; - string action_type = 2 [(buf.validate.field).string.min_len = 1]; - ResourceRef target_resource = 3; - string input_digest = 4 [(buf.validate.field).string.min_len = 1]; - RiskTier risk_tier = 5 [(buf.validate.field).enum.defined_only = true]; - google.protobuf.Struct evidence = 6; -} - -message ProposeActionResponse { - ActionIntent action_intent = 1 [(buf.validate.field).required = true]; - OperationReceipt receipt = 2 [(buf.validate.field).required = true]; -} - -message CreateArtifactRequest { - OperationContext context = 1 [(buf.validate.field).required = true]; - NewArtifactVersion artifact = 2 [(buf.validate.field).required = true]; -} - -message CreateArtifactResponse { - Artifact artifact = 1 [(buf.validate.field).required = true]; - ArtifactVersion version = 2 [(buf.validate.field).required = true]; - OperationReceipt receipt = 3 [(buf.validate.field).required = true]; -} - -message RecordEvidenceRequest { - OperationContext context = 1 [(buf.validate.field).required = true]; - EvidenceKind kind = 2 [(buf.validate.field).enum.defined_only = true]; - string subject_id = 3 [(buf.validate.field).string.min_len = 1]; - google.protobuf.Struct payload = 4; -} - -message RecordEvidenceResponse { - EvidenceRecord evidence = 1 [(buf.validate.field).required = true]; - OperationReceipt receipt = 2 [(buf.validate.field).required = true]; -} - -message RecordScoreRequest { - OperationContext context = 1 [(buf.validate.field).required = true]; - string subject_id = 2 [(buf.validate.field).string.min_len = 1]; - string criterion = 3 [(buf.validate.field).string.min_len = 1]; - double value = 4; - string scorer = 5 [(buf.validate.field).string.min_len = 1]; - string target = 6; - EvalAssignment eval_assignment = 7; - google.protobuf.Struct payload = 8; -} - -message RecordScoreResponse { - Score score = 1 [(buf.validate.field).required = true]; - EvidenceRecord evidence = 2 [(buf.validate.field).required = true]; - OperationReceipt receipt = 3 [(buf.validate.field).required = true]; -} - -message ApplyRecommendationRequest { - OperationContext context = 1 [(buf.validate.field).required = true]; - RecommendationKind kind = 2 [(buf.validate.field).enum.defined_only = true]; - string subject_id = 3 [(buf.validate.field).string.min_len = 1]; - string action_type = 4 [(buf.validate.field).string.min_len = 1]; - string input_digest = 5 [(buf.validate.field).string.min_len = 1]; - RiskTier risk_tier = 6 [(buf.validate.field).enum.defined_only = true]; - ResourceRef target_resource = 7; - EvalAssignment eval_assignment = 8; - string score_id = 9; - google.protobuf.Struct rationale = 10; -} - -message ApplyRecommendationResponse { - Recommendation recommendation = 1 [(buf.validate.field).required = true]; - ActionIntent action_intent = 2 [(buf.validate.field).required = true]; - OperationReceipt receipt = 3 [(buf.validate.field).required = true]; -} diff --git a/proto/remoterunner/v1/remoterunner.proto b/proto/remoterunner/v1/remoterunner.proto deleted file mode 100644 index a8a16c7..0000000 --- a/proto/remoterunner/v1/remoterunner.proto +++ /dev/null @@ -1,831 +0,0 @@ -syntax = "proto3"; - -package remoterunner.v1; - -import "buf/validate/validate.proto"; -import "common/v1/authz.proto"; -import "google/api/annotations.proto"; -import "google/protobuf/struct.proto"; -import "google/protobuf/timestamp.proto"; - -option go_package = "github.com/evalops/platform/gen/go/remoterunner/v1;remoterunnerv1"; - -// RemoteRunnerService owns account-scoped hosted Maestro runner sessions. -service RemoteRunnerService { - rpc ListRunnerProfiles(ListRunnerProfilesRequest) returns (ListRunnerProfilesResponse) { - option (google.api.http) = {get: "/v1/runner-profiles"}; - - option (common.v1.required_scopes) = "remote-runner:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - rpc CreateRunnerSession(CreateRunnerSessionRequest) returns (CreateRunnerSessionResponse) { - option (google.api.http) = { - post: "/v1/runner-sessions" - body: "*" - }; - - option (common.v1.required_scopes) = "remote-runner:write"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - rpc AdoptRunnerSessionForComputerMission(AdoptRunnerSessionForComputerMissionRequest) returns (AdoptRunnerSessionForComputerMissionResponse) { - option (google.api.http) = { - post: "/v1/runner-sessions/{runner_session_id}/adopt-computer-mission" - body: "*" - }; - - option (common.v1.required_scopes) = "remote-runner:write"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - rpc GetRunnerSession(GetRunnerSessionRequest) returns (GetRunnerSessionResponse) { - option (google.api.http) = {get: "/v1/runner-sessions/{session_id}"}; - - option (common.v1.required_scopes) = "remote-runner:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - rpc ListRunnerSessions(ListRunnerSessionsRequest) returns (ListRunnerSessionsResponse) { - option (google.api.http) = {get: "/v1/runner-sessions"}; - - option (common.v1.required_scopes) = "remote-runner:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - rpc CreateRunnerRestore(CreateRunnerRestoreRequest) returns (CreateRunnerRestoreResponse) { - option (google.api.http) = { - post: "/v1/runner-restores" - body: "*" - }; - - option (common.v1.required_scopes) = "remote-runner:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - rpc GetRunnerRestore(GetRunnerRestoreRequest) returns (GetRunnerRestoreResponse) { - option (google.api.http) = {get: "/v1/runner-restores/{restore_id}"}; - - option (common.v1.required_scopes) = "remote-runner:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - rpc ListRunnerRestores(ListRunnerRestoresRequest) returns (ListRunnerRestoresResponse) { - option (google.api.http) = {get: "/v1/runner-restores"}; - - option (common.v1.required_scopes) = "remote-runner:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - rpc StopRunnerSession(StopRunnerSessionRequest) returns (StopRunnerSessionResponse) { - option (google.api.http) = { - post: "/v1/runner-sessions/{session_id}/stop" - body: "*" - }; - - option (common.v1.required_scopes) = "remote-runner:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - rpc ExtendRunnerSession(ExtendRunnerSessionRequest) returns (ExtendRunnerSessionResponse) { - option (google.api.http) = { - post: "/v1/runner-sessions/{session_id}/extend" - body: "*" - }; - - option (common.v1.required_scopes) = "remote-runner:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - rpc MintAttachToken(MintAttachTokenRequest) returns (MintAttachTokenResponse) { - option (google.api.http) = { - post: "/v1/runner-sessions/{session_id}/attach-token" - body: "*" - }; - - option (common.v1.required_scopes) = "remote-runner:write"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - rpc RevokeAttachToken(RevokeAttachTokenRequest) returns (RevokeAttachTokenResponse) { - option (google.api.http) = { - post: "/v1/runner-sessions/{session_id}/attach-tokens/{token_id}/revoke" - body: "*" - }; - - option (common.v1.required_scopes) = "remote-runner:write"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - rpc ListRunnerSessionEvents(ListRunnerSessionEventsRequest) returns (ListRunnerSessionEventsResponse) { - option (google.api.http) = {get: "/v1/runner-sessions/{session_id}/events"}; - - option (common.v1.required_scopes) = "remote-runner:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - rpc RecordRunnerSessionArtifactLifecycle(RecordRunnerSessionArtifactLifecycleRequest) returns (RecordRunnerSessionArtifactLifecycleResponse) { - option (google.api.http) = { - post: "/v1/runner-sessions/{session_id}/artifact-lifecycle" - body: "*" - }; - - option (common.v1.required_scopes) = "remote-runner:admin"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - rpc ExecuteRunnerSessionStep(ExecuteRunnerSessionStepRequest) returns (ExecuteRunnerSessionStepResponse) { - option (google.api.http) = { - post: "/v1/runner-sessions/{session_id}/steps" - body: "*" - }; - option (common.v1.required_scopes) = "remote-runner:execute"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - rpc CreateRunnerSessionCheckpoint(CreateRunnerSessionCheckpointRequest) returns (CreateRunnerSessionCheckpointResponse) { - option (google.api.http) = { - post: "/v1/runner-sessions/{session_id}/checkpoints" - body: "*" - }; - option (common.v1.required_scopes) = "remote-runner:write"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - rpc GetRunnerAccountPolicy(GetRunnerAccountPolicyRequest) returns (GetRunnerAccountPolicyResponse) { - option (google.api.http) = {get: "/v1/runner-account-policies/{organization_id}"}; - - option (common.v1.required_scopes) = "remote-runner:admin"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - rpc UpsertRunnerAccountPolicy(UpsertRunnerAccountPolicyRequest) returns (UpsertRunnerAccountPolicyResponse) { - option (google.api.http) = { - put: "/v1/runner-account-policies/{organization_id}" - body: "*" - }; - - option (common.v1.required_scopes) = "remote-runner:admin"; - option (common.v1.risk_level) = RISK_LEVEL_CRITICAL; - } - - rpc GetStatus(GetStatusRequest) returns (GetStatusResponse) { - option (google.api.http) = {get: "/v1/remote-runner/status"}; - - option (common.v1.required_scopes) = "remote-runner:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } -} - -message RunnerSessionOwnerBinding { - string mission_id = 1 [(buf.validate.field).string.min_len = 1]; - string runtime_run_id = 2 [(buf.validate.field).string.min_len = 1]; - string authority_grant_id = 3 [(buf.validate.field).string.min_len = 1]; - string contract_version = 4 [(buf.validate.field).string.min_len = 1]; - string runner_profile = 5 [(buf.validate.field).string.min_len = 1]; - string policy_version = 6; - string decision_route = 7; - string selected_candidate_id = 8; - string decision_ref = 9; - string decision_digest_sha256 = 10; -} - -message AdoptRunnerSessionForComputerMissionRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string reservation_id = 3 [(buf.validate.field).string.min_len = 1]; - string runner_session_id = 4 [(buf.validate.field).string.min_len = 1]; - string mission_id = 5 [(buf.validate.field).string.min_len = 1]; - string runtime_run_id = 6 [(buf.validate.field).string.min_len = 1]; -} - -message AdoptRunnerSessionForComputerMissionResponse { - RunnerSession session = 1 [(buf.validate.field).required = true]; - RunnerSessionOwnerBinding owner_binding = 2 [(buf.validate.field).required = true]; - bool replayed = 3; -} - -message ExecuteRunnerSessionStepRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string session_id = 3 [(buf.validate.field).string.min_len = 1]; - string idempotency_key = 4 [(buf.validate.field).string.min_len = 1]; - repeated string argv = 5 [(buf.validate.field).repeated.max_items = 64]; - string cwd = 6; - uint32 timeout_seconds = 7 [(buf.validate.field).uint32 = { - gte: 1 - lte: 3600 - }]; - optional RunnerSessionOwnerBinding owner_binding = 8; - RunnerSessionStepOperation operation = 9; - bytes stdin = 10 [(buf.validate.field).bytes.max_len = 1048576]; - string expected_snapshot_id = 11; - string expected_sandbox_session_id = 12; - string expected_sandbox_id = 13; - string expected_runner_session_id = 14; - string expected_checkpoint_id = 15; - string instruction_artifact_ref = 16; - string instruction_digest_sha256 = 17; - uint64 instruction_byte_count = 18; - uint64 claim_lease_generation = 19; -} - -enum RunnerSessionStepOperation { - RUNNER_SESSION_STEP_OPERATION_UNSPECIFIED = 0; - RUNNER_SESSION_STEP_OPERATION_GENERIC = 1; - RUNNER_SESSION_STEP_OPERATION_APEX_HYDRATE = 2; - RUNNER_SESSION_STEP_OPERATION_APEX_DISCOVER = 3; - RUNNER_SESSION_STEP_OPERATION_APEX_FREEZE = 4; - RUNNER_SESSION_STEP_OPERATION_APEX_GRADE = 5; - RUNNER_SESSION_STEP_OPERATION_APEX_MCP_CALL = 6; - RUNNER_SESSION_STEP_OPERATION_APEX_STAGE_INPUTS = 7; - RUNNER_SESSION_STEP_OPERATION_APEX_STAGE_GRADING = 8; - RUNNER_SESSION_STEP_OPERATION_APEX_TASK_INSTRUCTIONS = 9; - reserved 10, 11, 12; - reserved "RUNNER_SESSION_STEP_OPERATION_COMPUTER_SHELL", "RUNNER_SESSION_STEP_OPERATION_COMPUTER_READ_FILE", "RUNNER_SESSION_STEP_OPERATION_COMPUTER_WRITE_FILE"; -} - -message RunnerProviderProof { - string provider = 1; - string provider_mode = 2; - string worker_id = 3; - string runtime_image_digest = 4; -} - -message RunnerSessionStepReceipt { - string command_id = 1; - int32 exit_code = 2; - string stdout = 3; - string stderr = 4; - bool replayed = 5; - RunnerProviderProof provider_proof = 6; - string stdin_sha256 = 7; - bool output_unavailable = 8; - string output_digest_sha256 = 9; - uint64 output_byte_count = 10; -} - -message ExecuteRunnerSessionStepResponse { - RunnerSessionStepReceipt receipt = 1; - RunnerSessionEvent event = 2; - // Bounded output for fixed APEX MCP/discover/grade operations. MCP output is - // transient; schema-validated discover/grade control output is replayable. - bytes apex_mcp_output = 3 [(buf.validate.field).bytes.max_len = 1048576]; - // Live-only bytes for the fixed APEX task-instruction read. This field is - // always empty on replay and is never copied into a receipt or event. - bytes ephemeral_output = 4 [(buf.validate.field).bytes.max_len = 1048576]; -} - -message CreateRunnerSessionCheckpointRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string session_id = 3 [(buf.validate.field).string.min_len = 1]; - string idempotency_key = 4 [(buf.validate.field).string.min_len = 1]; - optional RunnerSessionOwnerBinding owner_binding = 5; -} - -message RunnerSessionCheckpointReceipt { - string checkpoint_id = 1; - string source_session_id = 2; - bool replayed = 3; -} - -message CreateRunnerSessionCheckpointResponse { - RunnerSessionCheckpointReceipt receipt = 1; - RunnerSessionEvent event = 2; -} - -enum RunnerSessionState { - RUNNER_SESSION_STATE_UNSPECIFIED = 0; - RUNNER_SESSION_STATE_REQUESTED = 1; - RUNNER_SESSION_STATE_PROVISIONING = 2; - RUNNER_SESSION_STATE_RUNNING = 3; - RUNNER_SESSION_STATE_IDLE = 4; - RUNNER_SESSION_STATE_STOPPING = 5; - RUNNER_SESSION_STATE_STOPPED = 6; - RUNNER_SESSION_STATE_EXPIRED = 7; - RUNNER_SESSION_STATE_FAILED = 8; - RUNNER_SESSION_STATE_LOST = 9; -} - -enum RunnerAttachRole { - RUNNER_ATTACH_ROLE_UNSPECIFIED = 0; - RUNNER_ATTACH_ROLE_VIEWER = 1; - RUNNER_ATTACH_ROLE_CONTROLLER = 2; - RUNNER_ATTACH_ROLE_ADMIN = 3; -} - -enum RunnerSessionRestoreState { - RUNNER_SESSION_RESTORE_STATE_UNSPECIFIED = 0; - RUNNER_SESSION_RESTORE_STATE_REQUESTED = 1; - RUNNER_SESSION_RESTORE_STATE_ARTIFACTS_HYDRATING = 2; - RUNNER_SESSION_RESTORE_STATE_PROVIDER_STARTING = 3; - RUNNER_SESSION_RESTORE_STATE_IDENTITY_READY = 4; - RUNNER_SESSION_RESTORE_STATE_ATTACHABLE = 5; - RUNNER_SESSION_RESTORE_STATE_FAILED = 6; - RUNNER_SESSION_RESTORE_STATE_EXPIRED = 7; -} - -enum RunnerSessionRestoreFailurePolicy { - RUNNER_SESSION_RESTORE_FAILURE_POLICY_UNSPECIFIED = 0; - RUNNER_SESSION_RESTORE_FAILURE_POLICY_FAIL_SESSION = 1; - RUNNER_SESSION_RESTORE_FAILURE_POLICY_COLD_START = 2; -} - -message RunnerSessionRestoreSpec { - string source_runner_session_id = 1; - string source_maestro_session_id = 2; - string snapshot_artifact_uri = 3; - string snapshot_manifest_path = 4; - string snapshot_manifest_protocol_version = 5; - string artifact_digest = 6; - RunnerSessionRestoreFailurePolicy failure_policy = 7; - google.protobuf.Struct metadata = 8; -} - -message RunnerSessionRestoreStatus { - RunnerSessionRestoreState state = 1; - string local_manifest_path = 2; - string hydrated_artifact_uri = 3; - string failure_reason = 4; - string failure_message = 5; - google.protobuf.Timestamp updated_at = 6; -} - -enum RunnerRestoreState { - RUNNER_RESTORE_STATE_UNSPECIFIED = 0; - RUNNER_RESTORE_STATE_REQUESTED = 1; - RUNNER_RESTORE_STATE_ARTIFACTS_HYDRATING = 2; - RUNNER_RESTORE_STATE_PROVIDER_STARTING = 3; - RUNNER_RESTORE_STATE_IDENTITY_READY = 4; - RUNNER_RESTORE_STATE_ATTACHABLE = 5; - RUNNER_RESTORE_STATE_FAILED = 6; - RUNNER_RESTORE_STATE_EXPIRED = 7; -} - -enum RunnerRestoreFailureCode { - RUNNER_RESTORE_FAILURE_CODE_UNSPECIFIED = 0; - RUNNER_RESTORE_FAILURE_CODE_MISSING_ARTIFACT = 1; - RUNNER_RESTORE_FAILURE_CODE_INVALID_MANIFEST = 2; - RUNNER_RESTORE_FAILURE_CODE_WORKSPACE_ESCAPE = 3; - RUNNER_RESTORE_FAILURE_CODE_PROVIDER_TIMEOUT = 4; - RUNNER_RESTORE_FAILURE_CODE_RUNTIME_NOT_READY = 5; - RUNNER_RESTORE_FAILURE_CODE_OWNER_MISMATCH = 6; - RUNNER_RESTORE_FAILURE_CODE_HYDRATION_UNAVAILABLE = 7; - RUNNER_RESTORE_FAILURE_CODE_POLICY_DENIED = 8; - RUNNER_RESTORE_FAILURE_CODE_SESSION_CREATE_FAILED = 9; -} - -enum RunnerArtifactClass { - RUNNER_ARTIFACT_CLASS_UNSPECIFIED = 0; - RUNNER_ARTIFACT_CLASS_CONTROL_PLANE_METADATA = 1; - RUNNER_ARTIFACT_CLASS_WORKSPACE_EXPORT = 2; - RUNNER_ARTIFACT_CLASS_RUNTIME_SNAPSHOT = 3; - RUNNER_ARTIFACT_CLASS_RUNTIME_LOGS = 4; -} - -enum RunnerArtifactLifecycleState { - RUNNER_ARTIFACT_LIFECYCLE_STATE_UNSPECIFIED = 0; - RUNNER_ARTIFACT_LIFECYCLE_STATE_UPLOAD_REQUESTED = 1; - RUNNER_ARTIFACT_LIFECYCLE_STATE_UPLOADED = 2; - RUNNER_ARTIFACT_LIFECYCLE_STATE_UPLOAD_SKIPPED = 3; - RUNNER_ARTIFACT_LIFECYCLE_STATE_RETENTION_EXPIRED = 4; - RUNNER_ARTIFACT_LIFECYCLE_STATE_DELETE_REQUESTED = 5; - RUNNER_ARTIFACT_LIFECYCLE_STATE_DELETED = 6; - RUNNER_ARTIFACT_LIFECYCLE_STATE_CLEANUP_FAILED = 7; -} - -message RunnerSession { - string id = 1; - string organization_id = 2; - string workspace_id = 3; - string user_id = 4; - string agent_run_id = 5; - string maestro_session_id = 6; - RunnerSessionState state = 7; - string runner_profile = 8; - string runner_image = 9; - string workspace_source = 10; - string repo_url = 11; - string branch = 12; - string model = 13; - // Platform-minted runtime owner generation. Hosted runtimes must echo this - // value on the remote-runner identity endpoint before new attach requests are - // proxied. - string owner_instance_id = 14; - string runner_pod_namespace = 15; - string runner_pod_name = 16; - string runner_service_name = 17; - google.protobuf.Timestamp created_at = 18; - google.protobuf.Timestamp started_at = 19; - google.protobuf.Timestamp expires_at = 20; - google.protobuf.Timestamp idle_expires_at = 21; - google.protobuf.Timestamp stopped_at = 22; - string stop_reason = 23; - google.protobuf.Timestamp last_heartbeat_at = 24; - int64 used_runner_seconds = 25; - int64 used_idle_seconds = 26; - int64 estimated_cost_micros = 27; - google.protobuf.Struct metadata = 28; - int64 reserved_runner_seconds = 29; - int64 reserved_cost_micros = 30; - RunnerProfile resolved_profile = 31; - RunnerSessionRestoreSpec restore = 32; - RunnerSessionRestoreStatus restore_status = 33; - RunnerSessionApexAuthorityState apex_authority_state = 34; - string apex_reservation_id = 35; -} - -enum RunnerSessionApexAuthorityState { - RUNNER_SESSION_APEX_AUTHORITY_STATE_UNSPECIFIED = 0; - RUNNER_SESSION_APEX_AUTHORITY_STATE_NOT_REQUIRED = 1; - RUNNER_SESSION_APEX_AUTHORITY_STATE_PENDING_RESERVATION = 2; - RUNNER_SESSION_APEX_AUTHORITY_STATE_RESERVATION_VALIDATED = 3; - RUNNER_SESSION_APEX_AUTHORITY_STATE_MISSION_ADOPTED = 4; -} - -message RunnerSessionEvent { - string id = 1; - string session_id = 2; - int64 sequence = 3; - string event_type = 4; - google.protobuf.Timestamp occurred_at = 5; - google.protobuf.Struct payload = 6; -} - -message RunnerAttachToken { - string id = 1; - string session_id = 2; - string subject_id = 3; - repeated RunnerAttachRole roles = 4; - google.protobuf.Timestamp created_at = 5; - google.protobuf.Timestamp expires_at = 6; - google.protobuf.Timestamp revoked_at = 7; -} - -message RunnerRestore { - string id = 1; - string organization_id = 2; - string workspace_id = 3; - string source_session_id = 4; - string target_session_id = 5; - string maestro_session_id = 6; - RunnerRestoreState state = 7; - string artifact_ref = 8; - string manifest_path = 9; - string runner_profile = 10; - string runner_image = 11; - string workspace_source = 12; - string repo_url = 13; - string branch = 14; - string model = 15; - int32 ttl_minutes = 16; - int32 idle_ttl_minutes = 17; - string owner_instance_id = 18; - RunnerRestoreFailureCode failure_code = 19; - string failure_message = 20; - google.protobuf.Timestamp requested_at = 21; - google.protobuf.Timestamp hydrated_at = 22; - google.protobuf.Timestamp provider_started_at = 23; - google.protobuf.Timestamp identity_ready_at = 24; - google.protobuf.Timestamp attachable_at = 25; - google.protobuf.Timestamp failed_at = 26; - google.protobuf.Timestamp expires_at = 27; - google.protobuf.Struct metadata = 28; -} - -message RunnerAccountPolicy { - int32 max_concurrent_sessions = 1 [(buf.validate.field).int32.gte = 0]; - int32 max_session_ttl_minutes = 2 [(buf.validate.field).int32.gte = 0]; - int32 max_idle_ttl_minutes = 3 [(buf.validate.field).int32.gte = 0]; - int64 monthly_runner_minutes = 4 [(buf.validate.field).int64.gte = 0]; - int64 monthly_spend_cap_micros = 5 [(buf.validate.field).int64.gte = 0]; - int64 runner_minute_cost_micros = 6 [(buf.validate.field).int64.gte = 0]; - repeated string allowed_runner_profiles = 7; - repeated string allowed_models = 8; - repeated string allowed_workspace_sources = 9; - string operator_override_scope = 10; - bool workspace_scoped_usage_budgets = 11; -} - -message RunnerAccountPolicyRecord { - string organization_id = 1; - string workspace_id = 2; - RunnerAccountPolicy policy = 3; - google.protobuf.Timestamp created_at = 4; - google.protobuf.Timestamp updated_at = 5; - string source = 6; -} - -message RunnerProfile { - string id = 1; - string display_name = 2; - bool enabled = 3; - int32 default_ttl_minutes = 4; - int32 max_ttl_minutes = 5; - int32 default_idle_ttl_minutes = 6; - int32 max_idle_ttl_minutes = 7; - string isolation_level = 8; - string interruption = 9; - string workspace_persistence = 10; - string cost_class = 11; - int64 metering_multiplier_micros = 12; - bool experimental = 13; - bool production_eligible = 14; -} - -message RunnerProfileAvailability { - RunnerProfile profile = 1; - bool available = 2; - string unavailable_reason = 3; - string policy_source = 4; -} - -message ListRunnerProfilesRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - bool include_unavailable = 3; -} - -message ListRunnerProfilesResponse { - repeated RunnerProfileAvailability profiles = 1; -} - -// Immutable workspace authority signed by Platform for Runner Host admission. -// Acceptance proves only the exact coordinates below; materialization remains -// a separate owner operation. -message WorkspaceHydrationClaims { - uint32 schema_version = 1; - string envelope_id = 2; - string organization_id = 3; - string workspace_id = 4; - string source_workspace_id = 5; - string source_workspace_version = 6; - string source_revision_id = 7; - string immutable_snapshot_id = 8; - string immutable_snapshot_digest = 9; - string workspace_skill_set_digest = 10; - string capability_set_digest = 11; - string runner_session_id = 12; - string maestro_session_id = 13; - uint64 runtime_generation = 14; - uint64 activation_generation = 15; - string audience = 16; - int64 issued_at_ms = 17; - int64 not_before_ms = 18; - int64 expires_at_ms = 19; - string replay_nonce = 20; - string extraction_policy_version = 21; - string policy_version = 22; - string artifact_ref = 23; - string signer_identity = 24; - string key_id = 25; - uint64 max_files = 26; - uint64 max_bytes = 27; -} - -message WorkspaceHydrationEnvelope { - WorkspaceHydrationClaims claims = 1 [(buf.validate.field).required = true]; - string signature = 2 [(buf.validate.field).string.min_len = 1]; -} - -message CreateRunnerSessionRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string user_id = 3; - string idempotency_key = 4 [(buf.validate.field).string.min_len = 1]; - string runner_profile = 5 [(buf.validate.field).string.min_len = 1]; - string runner_image = 6; - string workspace_source = 7; - string repo_url = 8; - string branch = 9; - string model = 10; - int32 ttl_minutes = 11 [(buf.validate.field).int32 = { - gte: 1 - lte: 1440 - }]; - int32 idle_ttl_minutes = 12 [(buf.validate.field).int32 = { - gte: 0 - lte: 1440 - }]; - google.protobuf.Struct metadata = 13; - RunnerSessionRestoreSpec restore = 14; - string agent_run_id = 15; - string maestro_session_id = 16; - string apex_reservation_id = 17; - string runner_session_id = 18; - uint64 runtime_generation = 19; - uint64 activation_generation = 20; - WorkspaceHydrationEnvelope workspace_hydration_envelope = 21; -} - -message CreateRunnerSessionResponse { - RunnerSession session = 1; - repeated RunnerSessionEvent events = 2; - bool replayed = 3; -} - -message GetRunnerSessionRequest { - string session_id = 1 [(buf.validate.field).string.min_len = 1]; -} - -message GetRunnerSessionResponse { - RunnerSession session = 1; -} - -message ListRunnerSessionsRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - RunnerSessionState state = 3; - int32 limit = 4 [(buf.validate.field).int32 = { - gte: 0 - lte: 200 - }]; - int32 offset = 5 [(buf.validate.field).int32.gte = 0]; -} - -message ListRunnerSessionsResponse { - repeated RunnerSession sessions = 1; - int32 next_offset = 2; -} - -message CreateRunnerRestoreRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string user_id = 3; - string idempotency_key = 4 [(buf.validate.field).string.min_len = 1]; - string source_session_id = 5; - string maestro_session_id = 6; - string artifact_ref = 7; - string manifest_path = 8; - string runner_profile = 9 [(buf.validate.field).string.min_len = 1]; - string runner_image = 10; - string workspace_source = 11; - string repo_url = 12; - string branch = 13; - string model = 14; - int32 ttl_minutes = 15 [(buf.validate.field).int32 = { - gte: 1 - lte: 1440 - }]; - int32 idle_ttl_minutes = 16 [(buf.validate.field).int32 = { - gte: 0 - lte: 1440 - }]; - google.protobuf.Struct metadata = 17; - string runner_session_id = 18; - uint64 runtime_generation = 19; - uint64 activation_generation = 20; - WorkspaceHydrationEnvelope workspace_hydration_envelope = 21; -} - -message CreateRunnerRestoreResponse { - RunnerRestore restore = 1; - RunnerSession session = 2; - repeated RunnerSessionEvent events = 3; - bool replayed = 4; -} - -message GetRunnerRestoreRequest { - string restore_id = 1 [(buf.validate.field).string.min_len = 1]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 3 [(buf.validate.field).string.min_len = 1]; -} - -message GetRunnerRestoreResponse { - RunnerRestore restore = 1; -} - -message ListRunnerRestoresRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - RunnerRestoreState state = 3; - int32 limit = 4 [(buf.validate.field).int32 = { - gte: 0 - lte: 200 - }]; - int32 offset = 5 [(buf.validate.field).int32.gte = 0]; -} - -message ListRunnerRestoresResponse { - repeated RunnerRestore restores = 1; - int32 next_offset = 2; -} - -message StopRunnerSessionRequest { - string session_id = 1 [(buf.validate.field).string.min_len = 1]; - string reason = 2; - string organization_id = 3 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 4 [(buf.validate.field).string.min_len = 1]; -} - -message StopRunnerSessionResponse { - RunnerSession session = 1; - RunnerSessionEvent event = 2; -} - -message ExtendRunnerSessionRequest { - string session_id = 1 [(buf.validate.field).string.min_len = 1]; - int32 additional_minutes = 2 [(buf.validate.field).int32 = { - gte: 1 - lte: 1440 - }]; - int32 additional_idle_minutes = 3 [(buf.validate.field).int32 = { - gte: 0 - lte: 1440 - }]; - string reason = 4; -} - -message ExtendRunnerSessionResponse { - RunnerSession session = 1; - RunnerSessionEvent event = 2; -} - -message MintAttachTokenRequest { - string session_id = 1 [(buf.validate.field).string.min_len = 1]; - string subject_id = 2; - repeated RunnerAttachRole roles = 3; - int32 ttl_minutes = 4 [(buf.validate.field).int32 = { - gte: 0 - lte: 60 - }]; -} - -message MintAttachTokenResponse { - RunnerAttachToken token = 1; - string token_secret = 2; - string owner_instance_id = 3; - string runner_service_name = 4; -} - -message RevokeAttachTokenRequest { - string session_id = 1 [(buf.validate.field).string.min_len = 1]; - string token_id = 2 [(buf.validate.field).string.min_len = 1]; -} - -message RevokeAttachTokenResponse { - RunnerAttachToken token = 1; - RunnerSessionEvent event = 2; -} - -message ListRunnerSessionEventsRequest { - string session_id = 1 [(buf.validate.field).string.min_len = 1]; - int64 after_sequence = 2 [(buf.validate.field).int64.gte = 0]; - int32 limit = 3 [(buf.validate.field).int32 = { - gte: 0 - lte: 500 - }]; - string organization_id = 4 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 5 [(buf.validate.field).string.min_len = 1]; -} - -message ListRunnerSessionEventsResponse { - repeated RunnerSessionEvent events = 1; - int64 next_sequence = 2; -} - -message RecordRunnerSessionArtifactLifecycleRequest { - string session_id = 1 [(buf.validate.field).string.min_len = 1]; - RunnerArtifactClass artifact_class = 2; - RunnerArtifactLifecycleState state = 3; - string artifact_uri = 4; - string manifest_path = 5; - string reason = 6; - string message = 7; - google.protobuf.Timestamp retention_expires_at = 8; -} - -message RecordRunnerSessionArtifactLifecycleResponse { - RunnerSession session = 1; - RunnerSessionEvent event = 2; -} - -message GetRunnerAccountPolicyRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2; -} - -message GetRunnerAccountPolicyResponse { - RunnerAccountPolicyRecord policy = 1; -} - -message UpsertRunnerAccountPolicyRequest { - string organization_id = 1 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 2; - RunnerAccountPolicy policy = 3; -} - -message UpsertRunnerAccountPolicyResponse { - RunnerAccountPolicyRecord policy = 1; -} - -message GetStatusRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; -} - -message GetStatusResponse { - string service = 1; - string workspace_id = 2; - string downstream_policy = 3; -} diff --git a/proto/toolexecution/v1/toolexecution.proto b/proto/toolexecution/v1/toolexecution.proto deleted file mode 100644 index 4c487c2..0000000 --- a/proto/toolexecution/v1/toolexecution.proto +++ /dev/null @@ -1,512 +0,0 @@ -syntax = "proto3"; - -package toolexecution.v1; - -import "buf/validate/validate.proto"; -import "common/v1/authz.proto"; -import "common/v1/risk.proto"; -import "common/v1/surface.proto"; -import "google/protobuf/struct.proto"; -import "google/protobuf/timestamp.proto"; -import "platform/v1/platform.proto"; - -option go_package = "github.com/evalops/platform/gen/go/toolexecution/v1;toolexecutionv1"; - -// ToolExecutionService governs one normalized tool call across capability -// lookup, credential resolution, Gate and Governance policy, approval waits, -// execution, audit, meter, and provenance recording. AgentRun workers call this -// service instead of invoking external connectors, MCP tools, or internal tools -// directly. -service ToolExecutionService { - // ExecuteTool starts or idempotently replays a governed tool execution. - rpc ExecuteTool(ExecuteToolRequest) returns (ExecuteToolResponse) { - option (common.v1.required_scopes) = "tool-execution:write"; - option (common.v1.workspace_scope_field) = "linkage.workspace_id"; - option (common.v1.organization_scope_field) = "linkage.organization_id"; - - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // ResumeToolExecution resumes an execution that was parked on an approval - // wait, preserving the original tool call context. - rpc ResumeToolExecution(ResumeToolExecutionRequest) returns (ResumeToolExecutionResponse) { - option (common.v1.required_scopes) = "tool-execution:write"; - - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // RecordToolExecutionOutput records an asynchronous executor result and - // finalizes audit, meter, and provenance metadata. - rpc RecordToolExecutionOutput(RecordToolExecutionOutputRequest) returns (RecordToolExecutionOutputResponse) { - option (common.v1.required_scopes) = "tool-execution:write"; - - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // GetToolExecution retrieves one tool execution by ID. - // When wait_timeout_ms is greater than zero, the owner may block until the - // execution is settled (terminal or WAITING_APPROVAL) or the timeout - // elapses. Zero is a snapshot and remains backward compatible. - rpc GetToolExecution(GetToolExecutionRequest) returns (GetToolExecutionResponse) { - option (common.v1.required_scopes) = "tool-execution:read"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // ListToolExecutions lists executions by workspace, AgentRun, Objective, - // tool, connector, state, or approval request. - rpc ListToolExecutions(ListToolExecutionsRequest) returns (ListToolExecutionsResponse) { - option (common.v1.required_scopes) = "tool-execution:read"; - - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } -} - -// ToolExecutionState is the durable lifecycle for one tool call. -enum ToolExecutionState { - TOOL_EXECUTION_STATE_UNSPECIFIED = 0; - TOOL_EXECUTION_STATE_ACCEPTED = 1; - TOOL_EXECUTION_STATE_POLICY_EVALUATING = 2; - TOOL_EXECUTION_STATE_WAITING_APPROVAL = 3; - TOOL_EXECUTION_STATE_RUNNING = 4; - TOOL_EXECUTION_STATE_SUCCEEDED = 5; - TOOL_EXECUTION_STATE_FAILED = 6; - TOOL_EXECUTION_STATE_DENIED = 7; - TOOL_EXECUTION_STATE_CANCELLED = 8; -} - -// ToolExecutionStage names each platform boundary crossed by ExecuteTool. -enum ToolExecutionStage { - TOOL_EXECUTION_STAGE_UNSPECIFIED = 0; - TOOL_EXECUTION_STAGE_CAPABILITY_LOOKUP = 1; - TOOL_EXECUTION_STAGE_CREDENTIAL_RESOLUTION = 2; - TOOL_EXECUTION_STAGE_GATE_POLICY = 3; - TOOL_EXECUTION_STAGE_GOVERNANCE_POLICY = 4; - TOOL_EXECUTION_STAGE_APPROVAL = 5; - TOOL_EXECUTION_STAGE_EXECUTION = 6; - TOOL_EXECUTION_STAGE_AUDIT = 7; - TOOL_EXECUTION_STAGE_METER = 8; - TOOL_EXECUTION_STAGE_PROVENANCE = 9; -} - -// ToolExecutionStepState describes the state of a platform boundary decision. -enum ToolExecutionStepState { - TOOL_EXECUTION_STEP_STATE_UNSPECIFIED = 0; - TOOL_EXECUTION_STEP_STATE_SUCCEEDED = 1; - TOOL_EXECUTION_STEP_STATE_WAITING = 2; - TOOL_EXECUTION_STEP_STATE_DENIED = 3; - TOOL_EXECUTION_STEP_STATE_FAILED = 4; - TOOL_EXECUTION_STEP_STATE_SKIPPED = 5; -} - -// ToolExecutionPolicyDecision is a normalized policy result from Gate, -// Governance, approval policy, or a connector capability check. -enum ToolExecutionPolicyDecision { - TOOL_EXECUTION_POLICY_DECISION_UNSPECIFIED = 0; - TOOL_EXECUTION_POLICY_DECISION_ALLOW = 1; - TOOL_EXECUTION_POLICY_DECISION_DENY = 2; - TOOL_EXECUTION_POLICY_DECISION_REQUIRE_APPROVAL = 3; -} - -// ToolExecutionProposalKind marks structured outputs that downstream runtime -// checkpoints, artifact proposals, and memory proposals may safely consume. -enum ToolExecutionProposalKind { - TOOL_EXECUTION_PROPOSAL_KIND_UNSPECIFIED = 0; - TOOL_EXECUTION_PROPOSAL_KIND_CHECKPOINT = 1; - TOOL_EXECUTION_PROPOSAL_KIND_ARTIFACT = 2; - TOOL_EXECUTION_PROPOSAL_KIND_MEMORY = 3; -} - -// ToolExecutionLinkage carries the shared identifiers used to authorize, -// partition, audit, and join a tool call back to agent runtime records. -message ToolExecutionLinkage { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string agent_id = 3 [(buf.validate.field).string.min_len = 1]; - string run_id = 4; - string objective_id = 5; - string step_id = 6; - string actor_id = 7; - string surface = 8 [deprecated = true]; - string channel_id = 9; - string correlation_id = 10; - common.v1.Surface surface_type = 11 [(buf.validate.field).enum.defined_only = true]; - repeated ToolExecutionAttachmentMount attachment_mounts = 12; - // application_id is the immutable server-derived application authority. - // Callers must not populate it from browser-controlled application context. - string application_id = 13 [(buf.validate.field).string.min_len = 1]; - ToolExecutionProjectSource project_source = 14; - ToolExecutionProjectImport project_import = 15; - // Exact Platform-admitted task recipe. Executor preparation is authorized - // from this typed linkage, never from caller-controlled metadata. - ToolExecutionWorkspaceRecipe workspace_recipe = 16; - // Platform-admitted task identity used for tenant-scoped owner inspection. - string task_id = 17; -} - -// Versioned, server-owned preparation recipe for one task workspace. The -// recipe carries bounded declarative requirements; it cannot contain shell -// commands, repository hooks, credentials, or approval policy. -message ToolExecutionWorkspaceRecipe { - string schema_version = 1 [(buf.validate.field).string.const = "deixic.workspace_recipe.v1"]; - string recipe_id = 2 [(buf.validate.field).string.min_len = 1]; - uint64 recipe_version = 3 [(buf.validate.field).uint64.gte = 1]; - string recipe_digest = 4 [(buf.validate.field).string.min_len = 1]; - string source_manifest_digest = 5 [(buf.validate.field).string.min_len = 1]; - repeated string required_runtimes = 6 [(buf.validate.field).repeated = { - max_items: 16 - items: { - string: { - min_len: 1 - max_len: 64 - } - } - }]; - string preparation_tool = 7 [(buf.validate.field).string.const = "computer.check_runtimes"]; - // Skills, MCP tools, approvals, and credentials remain authorized through - // their existing admitted contracts; this recipe carries no such authority. - reserved 8, 9; - string execution_owner = 10 [(buf.validate.field).string.const = "platform-api.dex"]; -} - -// ToolExecutionAttachmentMount is an immutable, server-authorized VFS version -// materialized read-only under the execution's attachment root. -message ToolExecutionAttachmentMount { - string object_id = 1 [(buf.validate.field).string.min_len = 1]; - string version_id = 2 [(buf.validate.field).string.min_len = 1]; - string filename = 3 [(buf.validate.field).string.min_len = 1]; - string sha256 = 4 [(buf.validate.field).string.min_len = 1]; - int64 size_bytes = 5 [(buf.validate.field).int64 = { - gt: 0 - lte: 52428800 - }]; - string destination_path = 6 [(buf.validate.field).string.min_len = 1]; - platform.v1.ResourceRef resource_ref = 7; -} - -// ToolExecutionTraceContext carries the W3C trace context that causally owns a -// tool call. It lets the AgentRun, ToolExecution, connector, and MCP spans stay -// on one distributed trace even when the execution is retried or parked. -message ToolExecutionTraceContext { - string trace_id = 1; - string span_id = 2; - string parent_span_id = 3; - string traceparent = 4; - string tracestate = 5; -} - -// ToolRef identifies the tool/capability the agent wants to invoke. -message ToolRef { - string namespace = 1 [(buf.validate.field).string.min_len = 1]; - string name = 2 [(buf.validate.field).string.min_len = 1]; - string version = 3; - string capability = 4 [(buf.validate.field).string.min_len = 1]; - string operation = 5; - bool idempotent = 6; - bool mutates_resource = 7; -} - -// ConnectorRef identifies the connector, resource, and credential namespace -// needed to execute an external tool call. MCP/internal tools may leave -// connection_id empty while still setting provider_id/resource metadata. -message ConnectorRef { - string connection_id = 1; - string provider_id = 2; - string resource_id = 3; - string resource_kind = 4; - string credential_ref = 5; - string credential_environment = 6; -} - -// ToolRetryPolicy prevents blind retries for side-effecting tools. If a tool is -// not idempotent, callers must set allow_non_idempotent_retry and provide an -// idempotency_key before retries beyond the first attempt are honored. -message ToolRetryPolicy { - int32 max_attempts = 1 [(buf.validate.field).int32.gte = 0]; - int32 initial_delay_ms = 2 [(buf.validate.field).int32.gte = 0]; - int32 max_delay_ms = 3 [(buf.validate.field).int32.gte = 0]; - bool allow_non_idempotent_retry = 4; -} - -// ToolExecutionStep records one boundary decision in the execution path. -message ToolExecutionStep { - string id = 1; - ToolExecutionStage stage = 2 [(buf.validate.field).enum.defined_only = true]; - ToolExecutionStepState state = 3 [(buf.validate.field).enum.defined_only = true]; - ToolExecutionPolicyDecision decision = 4; - string external_ref = 5; - repeated string reasons = 6; - map attributes = 7; - google.protobuf.Timestamp started_at = 8; - google.protobuf.Timestamp ended_at = 9; -} - -// ToolApprovalWait is stored when policy requires human approval. The -// resume_token and original request allow AgentRun to release compute and later -// resume without reconstructing or mutating the tool call. -message ToolApprovalWait { - string id = 1; - string approval_request_id = 2; - string resume_token = 3; - string reason = 4; - ToolExecutionPolicyDecision requested_decision = 5; - google.protobuf.Timestamp created_at = 6; - google.protobuf.Timestamp resolved_at = 7; - string resolved_by = 8; - google.protobuf.Timestamp expires_at = 9; -} - -// VerifiedApprovalDecision is the immutable join to the authoritative -// ApprovalService decision used to release this execution. ToolExecutor -// derives every field from ApprovalService; callers provide only decision_id. -message VerifiedApprovalDecision { - string decision_id = 1; - string approval_request_id = 2; - string decision = 3; - string decided_by = 4; - string reason = 5; - google.protobuf.Timestamp decided_at = 6; - google.protobuf.Timestamp verified_at = 7; -} - -// ToolExecutionOutputAuthority binds a caller-dispatched terminal write to -// the authenticated application/actor, exact request and approval, and the -// currently leased dispatch attempt. -message ToolExecutionOutputAuthority { - string application_id = 1 [(buf.validate.field).string.min_len = 1]; - string actor = 2 [(buf.validate.field).string.min_len = 1]; - string request_fingerprint = 3 [(buf.validate.field).string.min_len = 1]; - string approval_decision_id = 4 [(buf.validate.field).string.min_len = 1]; - int32 dispatch_attempt = 5 [(buf.validate.field).int32.gte = 1]; - string action_digest = 6 [(buf.validate.field).string.min_len = 1]; -} - -// ToolExecutionOutput is deliberately structured: safe_output can be fed to a -// run checkpoint, artifact proposal, or memory proposal without raw connector -// secrets or unredacted byproducts. -message ToolExecutionOutput { - google.protobuf.Struct raw_output = 1; - google.protobuf.Struct safe_output = 2; - repeated ToolOutputProposal proposals = 3; - repeated string redactions = 4; - string content_type = 5; - string output_digest = 6; - int64 duration_ms = 7; - platform.v1.ResourceRef resource_ref = 8; -} - -// ToolOutputProposal is a normalized downstream write suggestion from a tool. -message ToolOutputProposal { - ToolExecutionProposalKind kind = 1 [(buf.validate.field).enum.defined_only = true]; - string target_ref = 2; - google.protobuf.Struct payload = 3; - map metadata = 4; -} - -// ToolExecutionProvenance records non-secret references emitted by each -// boundary so audit, meter, AgentRun, Artifact, and Memory records can join on -// one tool_execution_id. -message ToolExecutionProvenance { - string capability_ref = 1; - string credential_ref = 2; - string gate_policy_ref = 3; - string governance_decision_ref = 4; - string approval_request_id = 5; - string executor_ref = 6; - string audit_event_id = 7; - string meter_record_id = 8; - string provenance_record_id = 9; - string input_digest = 10; - string output_digest = 11; - map metadata = 12; - // Owner-persisted acknowledgement of a Runner Host event append. This - // binds a recording to the execution, not the producer of the event. - CommandAuditReceipt command_audit_receipt = 13; -} - -message CommandAuditReceipt { - string event_id = 1; - string runner_session_id = 2; - int64 sequence = 3; - string event_type = 4; - google.protobuf.Timestamp occurred_at = 5; - string payload_digest_sha256 = 6; -} - -// ToolExecutionFailureCode is the bounded, owner-assigned terminal failure -// taxonomy. It intentionally excludes provider prose, resource identifiers, -// and secret-bearing detail. -enum ToolExecutionFailureCode { - TOOL_EXECUTION_FAILURE_CODE_UNSPECIFIED = 0; - TOOL_EXECUTION_FAILURE_CODE_INVALID_REQUEST = 1; - TOOL_EXECUTION_FAILURE_CODE_UNSUPPORTED_TOOL = 2; - TOOL_EXECUTION_FAILURE_CODE_AUTHORITY_INVALID = 3; - TOOL_EXECUTION_FAILURE_CODE_DEPENDENCY_UNAVAILABLE = 4; - TOOL_EXECUTION_FAILURE_CODE_CONNECTOR_FAILED = 5; - TOOL_EXECUTION_FAILURE_CODE_SANDBOX_PROVISION_FAILED = 6; - TOOL_EXECUTION_FAILURE_CODE_SANDBOX_OPERATION_FAILED = 7; - TOOL_EXECUTION_FAILURE_CODE_RUNNER_LEDGER_REQUIRED = 8; - TOOL_EXECUTION_FAILURE_CODE_APPROVAL_DENIED = 9; - TOOL_EXECUTION_FAILURE_CODE_APPROVAL_EXPIRED = 10; - TOOL_EXECUTION_FAILURE_CODE_EXECUTION_ABANDONED = 11; - TOOL_EXECUTION_FAILURE_CODE_EXECUTION_CANCELLED = 12; - TOOL_EXECUTION_FAILURE_CODE_CALLER_REPORTED_FAILURE = 13; -} - -// ToolExecution is the canonical durable record for one governed tool call. -message ToolExecution { - string id = 1; - ToolExecutionLinkage linkage = 2 [(buf.validate.field).required = true]; - ToolRef tool = 3 [(buf.validate.field).required = true]; - ConnectorRef connector = 4; - google.protobuf.Struct arguments = 5; - common.v1.RiskLevel risk_level = 6; - ToolRetryPolicy retry_policy = 7; - string idempotency_key = 8 [(buf.validate.field).string.min_len = 1]; - ToolExecutionState state = 9 [(buf.validate.field).enum.defined_only = true]; - int32 attempt = 10; - int32 max_attempts = 11; - repeated ToolExecutionStep steps = 12; - ToolApprovalWait approval_wait = 13; - ToolExecutionOutput output = 14; - ToolExecutionProvenance provenance = 15; - string error_message = 16; - google.protobuf.Timestamp created_at = 17; - google.protobuf.Timestamp updated_at = 18; - google.protobuf.Timestamp completed_at = 19; - ToolExecutionTraceContext trace_context = 20; - // Stable machine-readable terminal failure reason when the owning execution - // boundary classified it. Human-readable detail remains in error_message - // and must never be parsed for routing or policy. - ToolExecutionFailureCode failure_code = 21 [(buf.validate.field).enum.defined_only = true]; - VerifiedApprovalDecision verified_approval_decision = 22; -} - -message ExecuteToolRequest { - ToolExecutionLinkage linkage = 1 [(buf.validate.field).required = true]; - ToolRef tool = 2 [(buf.validate.field).required = true]; - ConnectorRef connector = 3; - google.protobuf.Struct arguments = 4; - common.v1.RiskLevel risk_level = 5; - ToolRetryPolicy retry_policy = 6; - string idempotency_key = 7 [(buf.validate.field).string.min_len = 1]; - map metadata = 8; - ToolExecutionTraceContext trace_context = 9; -} - -message ExecuteToolResponse { - ToolExecution execution = 1; - bool idempotent_replay = 2; -} - -message ResumeToolExecutionRequest { - string execution_id = 1 [(buf.validate.field).string.min_len = 1]; - string approval_request_id = 2 [(buf.validate.field).string.min_len = 1]; - string resume_token = 3 [(buf.validate.field).string.min_len = 1]; - bool approved = 4 [deprecated = true]; - string decided_by = 5 [deprecated = true]; - string reason = 6 [deprecated = true]; - // Identity of the durable ApprovalService decision to verify. The - // deprecated decision fields above are ignored by production verification. - string approval_decision_id = 7 [(buf.validate.field).string.min_len = 1]; -} - -message ResumeToolExecutionResponse { - ToolExecution execution = 1; -} - -message RecordToolExecutionOutputRequest { - string execution_id = 1 [(buf.validate.field).string.min_len = 1]; - ToolExecutionOutput output = 2 [(buf.validate.field).required = true]; - map metadata = 3; - ToolExecutionOutputAuthority authority = 4 [(buf.validate.field).required = true]; -} - -message RecordToolExecutionOutputResponse { - ToolExecution execution = 1; -} - -message GetToolExecutionRequest { - string id = 1 [(buf.validate.field).string.min_len = 1]; - string organization_id = 2 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 3 [(buf.validate.field).string.min_len = 1]; - // When greater than zero, the owner may block until the execution is - // settled (terminal or WAITING_APPROVAL) or this timeout elapses. Zero - // returns a snapshot and remains backward compatible. - uint32 wait_timeout_ms = 4 [(buf.validate.field).uint32 = { - gte: 0 - lte: 30000 - }]; -} - -message GetToolExecutionResponse { - ToolExecution execution = 1; -} - -message ListToolExecutionsRequest { - string workspace_id = 1; - string run_id = 2; - string objective_id = 3; - string agent_id = 4; - string tool_namespace = 5; - string tool_name = 6; - string connection_id = 7; - string approval_request_id = 8; - ToolExecutionState state = 9; - int32 limit = 10 [(buf.validate.field).int32.gte = 0]; - int32 offset = 11 [(buf.validate.field).int32.gte = 0]; - string organization_id = 12; - string task_id = 13; -} - -message ListToolExecutionsResponse { - repeated ToolExecution executions = 1; - int32 total = 2; - bool has_more = 3; -} - -// An immutable file restored below the private task workspace. -message ToolExecutionProjectSourceFile { - string path = 1; - string object_id = 2; - string version_id = 3; - string sha256 = 4; - uint64 size_bytes = 5; - bool executable = 6; -} - -// Server-owned, pinned accepted source. Never a writable shared directory. -message ToolExecutionProjectSource { - string project_resource_id = 1; - string accepted_ref_name = 2; - uint64 accepted_ref_version = 3; - string accepted_snapshot_id = 4; - string source_workspace_id = 5; - uint64 source_workspace_version = 6; - repeated ToolExecutionProjectSourceFile files = 7 [(buf.validate.field).repeated.max_items = 1000]; -} - -// Server-admitted immutable import job; browser requests cannot choose a commit. -message ToolExecutionProjectImport { - string project_resource_id = 1; - string connection_id = 2; - optional uint64 expected_ref_version = 3; - ToolExecutionGitSnapshotManifest manifest = 4; - string grant_key_id = 5; - string grant_signature = 6; -} -message ToolExecutionGitSnapshotManifest { - uint64 repository_id = 1; - string full_name = 2; - string default_branch = 3; - string commit_sha = 4; - string tree_sha = 5; - repeated ToolExecutionGitSnapshotFile files = 6; - bool complete = 7; -} -message ToolExecutionGitSnapshotFile { - string path = 1; - string git_blob_sha = 2; - uint64 size_bytes = 3; - bool executable = 4; -} diff --git a/proto/traces/v1/traces.proto b/proto/traces/v1/traces.proto deleted file mode 100644 index 854b264..0000000 --- a/proto/traces/v1/traces.proto +++ /dev/null @@ -1,604 +0,0 @@ -syntax = "proto3"; - -package traces.v1; - -option go_package = "github.com/evalops/platform/gen/go/traces/v1;tracesv1"; - -import "buf/validate/validate.proto"; -import "common/v1/analytics.proto"; -import "common/v1/authz.proto"; -import "google/protobuf/struct.proto"; -import "google/protobuf/timestamp.proto"; - -// SpanIngestService records and queries agent execution traces. -service SpanIngestService { - // Append spans to a trace. MEDIUM because forged spans contaminate the - // observability record other reviewers and gates trust. - // Organization scope is enforced by trace handlers for multi-org writes - // because legacy single-scope SDK ingest may omit span.organization_id. - rpc IngestSpans(IngestSpansRequest) returns (IngestSpansResponse) { - option (common.v1.required_scopes) = "traces:write"; - option (common.v1.workspace_scope_field) = "spans.workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc GetTrace(GetTraceRequest) returns (GetTraceResponse) { - option (common.v1.required_scopes) = "traces:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc ListTraces(ListTracesRequest) returns (ListTracesResponse) { - option (common.v1.required_scopes) = "traces:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc GetSpanTree(GetSpanTreeRequest) returns (GetSpanTreeResponse) { - option (common.v1.required_scopes) = "traces:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc GetSpanContext(GetSpanContextRequest) returns (GetSpanContextResponse) { - option (common.v1.required_scopes) = "traces:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Returns the recorded prompt + response payload of a single span. - // MEDIUM because the payload often contains user-supplied PII; - // the caller authz check enforces tenant scope but the data fan-out - // is wider than a normal read. - rpc GetSpanPayload(GetSpanPayloadRequest) returns (GetSpanPayloadResponse) { - option (common.v1.required_scopes) = "traces:read"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc SearchTrace(SearchTraceRequest) returns (SearchTraceResponse) { - option (common.v1.required_scopes) = "traces:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Attaches a reviewer note to a trace. MEDIUM because the note becomes - // part of the evidence shown to other reviewers and can be misused to - // shape future approval defaults. - rpc AnnotateTrace(AnnotateTraceRequest) returns (AnnotateTraceResponse) { - option (common.v1.required_scopes) = "traces:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc DeleteTraceAnnotation(DeleteTraceAnnotationRequest) returns (DeleteTraceAnnotationResponse) { - option (common.v1.required_scopes) = "traces:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc BulkAnnotateTrace(BulkAnnotateTraceRequest) returns (BulkAnnotateTraceResponse) { - option (common.v1.required_scopes) = "traces:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc ListTraceAnnotations(ListTraceAnnotationsRequest) returns (ListTraceAnnotationsResponse) { - option (common.v1.required_scopes) = "traces:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - rpc GetTraceReviewBundle(GetTraceReviewBundleRequest) returns (GetTraceReviewBundleResponse) { - option (common.v1.required_scopes) = "traces:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Records a quality label (good / bad / regression) that feeds the eval - // ranking surface. MEDIUM because the label drives later auto-approve - // decisions in the reviewing pipeline. - rpc AnnotateTraceQuality(AnnotateTraceQualityRequest) returns (AnnotateTraceQualityResponse) { - option (common.v1.required_scopes) = "traces:write"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - rpc ListTraceQualityAnnotations(ListTraceQualityAnnotationsRequest) returns (ListTraceQualityAnnotationsResponse) { - option (common.v1.required_scopes) = "traces:read"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - // Streams a replay bundle (full prompts, responses, attachments) for - // a single run. HIGH because the bundle reconstitutes the original - // session including any user-supplied secrets that survived sanitisation. - rpc ExportReplayBundle(ExportReplayBundleRequest) returns (ExportReplayBundleResponse) { - option (common.v1.required_scopes) = "traces:read"; - option (common.v1.required_scopes) = "traces.payload.raw"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - rpc SummarizeMaestroSelfTelemetry(SummarizeMaestroSelfTelemetryRequest) returns (SummarizeMaestroSelfTelemetryResponse) { - option (common.v1.required_scopes) = "traces:read"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } -} - -enum SpanStatus { - SPAN_STATUS_UNSPECIFIED = 0; - SPAN_STATUS_OK = 1; - SPAN_STATUS_ERROR = 2; - SPAN_STATUS_CANCELLED = 3; -} - -enum GovernanceDecision { - GOVERNANCE_DECISION_UNSPECIFIED = 0; - GOVERNANCE_DECISION_ALLOW = 1; - GOVERNANCE_DECISION_DENY = 2; - GOVERNANCE_DECISION_REQUIRE_APPROVAL = 3; - GOVERNANCE_DECISION_AUTO_APPROVED = 4; -} - -message Span { - string trace_id = 1 [(buf.validate.field).string.min_len = 1]; - string span_id = 2 [(buf.validate.field).string.min_len = 1]; - string parent_span_id = 3; - string workspace_id = 4 [(buf.validate.field).string.min_len = 1]; - string organization_id = 5; - string agent_id = 6; - string surface = 7; - string name = 8 [(buf.validate.field).string.min_len = 1]; - string kind = 9; - string model = 10; - string provider = 11; - int64 token_input = 12; - int64 token_output = 13; - int64 latency_ms = 14; - SpanStatus status = 15; - GovernanceDecision governance_decision = 16; - double cost_usd = 17; - google.protobuf.Struct attributes = 18; - google.protobuf.Timestamp started_at = 19; - google.protobuf.Timestamp ended_at = 20; - string user_id = 21; -} - -message TraceSummary { - string trace_id = 1; - string workspace_id = 2; - string organization_id = 3; - string agent_id = 4; - string surface = 5; - string root_span_name = 6; - int32 total_spans = 7; - int64 total_token_input = 8; - int64 total_token_output = 9; - double total_cost_usd = 10; - int64 total_latency_ms = 11; - google.protobuf.Timestamp started_at = 12; - google.protobuf.Timestamp ended_at = 13; - string user_id = 14; -} - -enum TraceAnnotationKind { - TRACE_ANNOTATION_KIND_UNSPECIFIED = 0; - TRACE_ANNOTATION_KIND_NOTE = 1; - TRACE_ANNOTATION_KIND_ISSUE = 2; - TRACE_ANNOTATION_KIND_GOOD = 3; -} - -enum TraceAnnotationStatus { - TRACE_ANNOTATION_STATUS_UNSPECIFIED = 0; - TRACE_ANNOTATION_STATUS_ACTIVE = 1; - TRACE_ANNOTATION_STATUS_RESOLVED = 2; - TRACE_ANNOTATION_STATUS_DISMISSED = 3; - TRACE_ANNOTATION_STATUS_ARCHIVED = 4; -} - -message TraceAnnotation { - string annotation_id = 1; - string trace_id = 2 [(buf.validate.field).string.min_len = 1]; - string span_id = 3; - TraceAnnotationKind kind = 4; - string note = 5; - repeated string labels = 6; - string source = 7; - google.protobuf.Struct metadata = 8; - google.protobuf.Timestamp created_at = 9; - TraceAnnotationStatus status = 10; - google.protobuf.Timestamp updated_at = 11; - google.protobuf.Timestamp resolved_at = 12; - string resolved_by = 13; -} - -message AssertionResult { - string assertion_id = 1; - string name = 2; - bool passed = 3; - double score = 4; - string reason = 5; - google.protobuf.Struct metadata = 6; -} - -message GovernanceScore { - GovernanceDecision decision = 1; - double confidence = 2; - repeated string reasons = 3; -} - -enum ConversationalSignalKind { - CONVERSATIONAL_SIGNAL_KIND_UNSPECIFIED = 0; - CONVERSATIONAL_SIGNAL_KIND_FRUSTRATION = 1; - CONVERSATIONAL_SIGNAL_KIND_CONFUSION = 2; - CONVERSATIONAL_SIGNAL_KIND_DISSATISFACTION = 3; -} - -enum ConversationalSignalLabel { - CONVERSATIONAL_SIGNAL_LABEL_UNSPECIFIED = 0; - CONVERSATIONAL_SIGNAL_LABEL_LOW = 1; - CONVERSATIONAL_SIGNAL_LABEL_MEDIUM = 2; - CONVERSATIONAL_SIGNAL_LABEL_HIGH = 3; -} - -message ConversationalSignal { - ConversationalSignalKind kind = 1; - double score = 2; - ConversationalSignalLabel label = 3; - string rationale = 4; - repeated string evidence_span_ids = 5; -} - -message TraceQualityAnnotation { - string trace_id = 1 [(buf.validate.field).string.min_len = 1]; - string span_id = 2; - double composite_score = 3; - repeated AssertionResult assertions = 4; - GovernanceScore governance = 5; - common.v1.Money cost = 6; - double quality_per_dollar = 7; - string eval_suite_id = 8; - google.protobuf.Timestamp scored_at = 9; - string scorer = 10; - google.protobuf.Struct metadata = 11; - repeated ConversationalSignal conversational_signals = 12; -} - -message IngestSpansRequest { - repeated Span spans = 1 [(buf.validate.field).repeated.min_items = 1]; -} - -message IngestSpansResponse { - int32 ingested_count = 1; - repeated TraceSummary traces = 2; -} - -message GetTraceRequest { - string trace_id = 1 [(buf.validate.field).string.min_len = 1]; -} - -message GetTraceResponse { - TraceSummary trace = 1; - repeated Span spans = 2; - repeated TraceQualityAnnotation quality_annotations = 3; - repeated TraceAnnotation annotations = 4; -} - -message ReplayContext { - string organization_id = 1; - string workspace_id = 2; - string agent_id = 3; - string surface = 4; - string user_id = 5; -} - -message ReplayToolCall { - string span_id = 1; - string name = 2; - string input = 3; - string output = 4; - string status = 5; -} - -message TraceReplayBundle { - string trace_id = 1; - ReplayContext context = 2; - string input = 3; - string model = 4; - string provider = 5; - string prompt_config = 6; - repeated ReplayToolCall tool_calls = 7; - repeated TraceQualityAnnotation quality_annotations = 8; - bool redaction_applied = 9; -} - -message TraceEvalCandidate { - string candidate_id = 1; - string trace_id = 2; - string span_id = 3; - string annotation_id = 4; - string eval_suite_id = 5; - string case_kind = 6; - repeated string labels = 7; - string title = 8; - string rationale = 9; - double cost_usd = 10; - int64 token_input = 11; - int64 token_output = 12; - GovernanceDecision governance_decision = 13; - bool approval_required = 14; - bool redaction_applied = 15; - TraceReplayBundle replay_bundle = 16; - google.protobuf.Struct metadata = 17; -} - -message ListTracesRequest { - string workspace_id = 1; - string agent_id = 2; - string surface = 3; - google.protobuf.Timestamp start_time = 4; - google.protobuf.Timestamp end_time = 5; - int32 limit = 6 [(buf.validate.field).int32.gte = 0]; - int32 offset = 7 [(buf.validate.field).int32.gte = 0]; - string organization_id = 8; - string user_id = 9; -} - -message ListTracesResponse { - repeated TraceSummary traces = 1; - int32 total = 2; - bool has_more = 3; -} - -message GetSpanTreeRequest { - string trace_id = 1 [(buf.validate.field).string.min_len = 1]; -} - -message SpanNode { - Span span = 1; - repeated SpanNode children = 2; -} - -message GetSpanTreeResponse { - TraceSummary trace = 1; - repeated SpanNode roots = 2; -} - -message GetSpanContextRequest { - string trace_id = 1 [(buf.validate.field).string.min_len = 1]; - string span_id = 2 [(buf.validate.field).string.min_len = 1]; - int32 before = 3 [(buf.validate.field).int32.gte = 0]; - int32 after = 4 [(buf.validate.field).int32.gte = 0]; - bool include_parent = 5; -} - -message GetSpanContextResponse { - Span span = 1; - Span parent = 2; - repeated Span before = 3; - repeated Span after = 4; -} - -enum SpanPayloadTarget { - SPAN_PAYLOAD_TARGET_UNSPECIFIED = 0; - SPAN_PAYLOAD_TARGET_INPUT = 1; - SPAN_PAYLOAD_TARGET_OUTPUT = 2; - SPAN_PAYLOAD_TARGET_ATTRIBUTES = 3; - // Normalized LLM conversation messages, including OpenTelemetry GenAI and - // OpenInference-style message attributes when present. - SPAN_PAYLOAD_TARGET_LLM_MESSAGES = 4; - // Tool invocation arguments captured before execution. - SPAN_PAYLOAD_TARGET_TOOL_ARGS = 5; - // Tool execution result captured after execution. - SPAN_PAYLOAD_TARGET_TOOL_RESULT = 6; - // Span lifecycle events captured by OTLP or EvalOps exporters. - SPAN_PAYLOAD_TARGET_EVENTS = 7; -} - -enum SpanPayloadRedactionMode { - SPAN_PAYLOAD_REDACTION_MODE_UNSPECIFIED = 0; - SPAN_PAYLOAD_REDACTION_MODE_SAFE = 1; - SPAN_PAYLOAD_REDACTION_MODE_RAW = 2; -} - -message GetSpanPayloadRequest { - string trace_id = 1 [(buf.validate.field).string.min_len = 1]; - string span_id = 2 [(buf.validate.field).string.min_len = 1]; - SpanPayloadTarget target = 3; - int32 offset = 4 [(buf.validate.field).int32.gte = 0]; - int32 max_chars = 5 [(buf.validate.field).int32.gte = 0]; - SpanPayloadRedactionMode redaction_mode = 6; -} - -message GetSpanPayloadResponse { - string content = 1; - int32 next_offset = 2; - bool has_more = 3; - string source = 4; - bool redaction_applied = 5; -} - -message SearchTraceRequest { - string trace_id = 1 [(buf.validate.field).string.min_len = 1]; - string pattern = 2 [(buf.validate.field).string.min_len = 1]; - bool case_sensitive = 3; - string span_kind = 4; - int32 context_chars = 5 [(buf.validate.field).int32.gte = 0]; - int32 limit = 6 [(buf.validate.field).int32.gte = 0]; - repeated string scopes = 7; - SpanStatus span_status = 8; - string model = 9; - string provider = 10; - GovernanceDecision governance_decision = 11; - string label = 12; - TraceAnnotationStatus annotation_status = 13; -} - -message TraceSearchMatch { - string trace_id = 1; - string span_id = 2; - string span_name = 3; - string scope = 4; - int32 start = 5; - int32 end = 6; - string snippet = 7; -} - -message SearchTraceResponse { - repeated TraceSearchMatch matches = 1; - int32 total = 2; - bool has_more = 3; -} - -message AnnotateTraceRequest { - TraceAnnotation annotation = 1 [(buf.validate.field).required = true]; -} - -message AnnotateTraceResponse { - TraceAnnotation annotation = 1; -} - -message DeleteTraceAnnotationRequest { - string trace_id = 1 [(buf.validate.field).string.min_len = 1]; - string annotation_id = 2 [(buf.validate.field).string.min_len = 1]; -} - -message DeleteTraceAnnotationResponse { - TraceAnnotation annotation = 1; -} - -message BulkAnnotateTraceRequest { - string trace_id = 1 [(buf.validate.field).string.min_len = 1]; - repeated string span_ids = 2; - TraceAnnotation annotation = 3 [(buf.validate.field).required = true]; -} - -message BulkAnnotateTraceResponse { - repeated TraceAnnotation annotations = 1; - int32 total = 2 [(buf.validate.field).int32.gte = 0]; -} - -message ListTraceAnnotationsRequest { - string trace_id = 1 [(buf.validate.field).string.min_len = 1]; - string span_id = 2; - TraceAnnotationKind kind = 3; - string label = 4; - int32 limit = 5 [(buf.validate.field).int32.gte = 0]; - int32 offset = 6 [(buf.validate.field).int32.gte = 0]; - TraceAnnotationStatus status = 7; -} - -message ListTraceAnnotationsResponse { - repeated TraceAnnotation annotations = 1; - int32 total = 2; - bool has_more = 3; -} - -enum TraceEvidenceState { - TRACE_EVIDENCE_STATE_UNSPECIFIED = 0; - TRACE_EVIDENCE_STATE_AVAILABLE = 1; - TRACE_EVIDENCE_STATE_WITHHELD = 2; - TRACE_EVIDENCE_STATE_MISSING = 3; - TRACE_EVIDENCE_STATE_PERMISSION_BLOCKED = 4; - TRACE_EVIDENCE_STATE_EXPIRED = 5; -} - -message TraceEvidenceRef { - string evidence_id = 1; - string label = 2; - string resource_type = 3; - string uri = 4; - TraceEvidenceState state = 5; - string reason = 6; - bool redaction_applied = 7; - google.protobuf.Timestamp expires_at = 8; - google.protobuf.Struct metadata = 9; - repeated string span_ids = 10; -} - -message TraceEvidenceBundleRef { - string bundle_id = 1; - string uri = 2; - string retention = 3; - google.protobuf.Timestamp created_at = 4; - google.protobuf.Timestamp expires_at = 5; - google.protobuf.Struct provenance = 6; -} - -message TraceRecoveryAction { - string action_id = 1; - string title = 2; - string detail = 3; - string severity = 4; - repeated string evidence_ids = 5; - string source = 6; -} - -message TraceReview { - string status = 1; - string headline = 2; - string summary = 3; - int32 evidence_gap_count = 4; - bool metadata_only = 5; - string review_url = 6; - repeated TraceEvidenceRef evidence_refs = 7; - repeated TraceRecoveryAction recovery_actions = 8; - repeated TraceEvidenceBundleRef evidence_bundles = 9; - repeated SpanNode span_tree = 10; - repeated string suggested_labels = 11; - google.protobuf.Struct provenance = 12; -} - -message TraceReviewBundle { - TraceSummary trace = 1; - repeated Span spans = 2; - repeated TraceAnnotation annotations = 3; - repeated TraceQualityAnnotation quality_annotations = 4; - repeated TraceSearchMatch matches = 5; - repeated string suggested_labels = 6; - string summary = 7; - repeated TraceEvalCandidate eval_candidates = 8; - TraceReview trace_review = 9; -} - -message GetTraceReviewBundleRequest { - string trace_id = 1 [(buf.validate.field).string.min_len = 1]; - string search = 2; - string label = 3; - int32 max_matches = 4 [(buf.validate.field).int32.gte = 0]; -} - -message GetTraceReviewBundleResponse { - TraceReviewBundle bundle = 1; -} - -message AnnotateTraceQualityRequest { - TraceQualityAnnotation annotation = 1 [(buf.validate.field).required = true]; -} - -message AnnotateTraceQualityResponse { - TraceQualityAnnotation annotation = 1; -} - -message ListTraceQualityAnnotationsRequest { - string trace_id = 1 [(buf.validate.field).string.min_len = 1]; - string span_id = 2; - int32 limit = 3 [(buf.validate.field).int32.gte = 0]; - int32 offset = 4 [(buf.validate.field).int32.gte = 0]; - ConversationalSignalKind signal_kind = 5; -} - -message ListTraceQualityAnnotationsResponse { - repeated TraceQualityAnnotation annotations = 1; - int32 total = 2; - bool has_more = 3; -} - -message ExportReplayBundleRequest { - string trace_id = 1 [(buf.validate.field).string.min_len = 1]; -} - -message ExportReplayBundleResponse { - TraceReplayBundle bundle = 1; -} - -message SummarizeMaestroSelfTelemetryRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string organization_id = 2; - string agent_id = 3; - string surface = 4; - google.protobuf.Timestamp start_time = 5; - google.protobuf.Timestamp end_time = 6; - int32 trace_limit = 7 [(buf.validate.field).int32.gte = 0]; -} - -message MaestroSelfTelemetrySummary { - int32 trace_count = 1; - int32 span_count = 2; - int32 permission_denials = 3; - int32 context_compactions = 4; - int32 subagent_spawns = 5; - int32 self_diagnostics = 6; - double permission_denial_rate = 7; - double compaction_rate = 8; - double subagent_fanout = 9; -} - -message SummarizeMaestroSelfTelemetryResponse { - MaestroSelfTelemetrySummary summary = 1; -} diff --git a/proto/vfs/v1/filesystem.proto b/proto/vfs/v1/filesystem.proto deleted file mode 100644 index 0ed989a..0000000 --- a/proto/vfs/v1/filesystem.proto +++ /dev/null @@ -1,454 +0,0 @@ -syntax = "proto3"; - -package vfs.v1; - -import "buf/validate/validate.proto"; -import "common/v1/authz.proto"; -import "google/protobuf/timestamp.proto"; -import "platform/v1/platform.proto"; - -option go_package = "github.com/evalops/platform/gen/go/vfs/v1;vfsv1"; - -// VirtualFilesystemService is the durable file plane for agents, -// integrations, tool execution, memory evidence, and channel handoffs. -service VirtualFilesystemService { - // PutObject writes bytes directly to a workspace path and creates the first - // immutable version or appends a new version to an existing path. - rpc PutObject(PutObjectRequest) returns (PutObjectResponse) { - option (common.v1.required_scopes) = "vfs:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // GetObject returns metadata and an optional ranged byte slice for one - // object, selected by object ID or path. - rpc GetObject(GetObjectRequest) returns (GetObjectResponse) { - option (common.v1.required_scopes) = "vfs:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // ListObjects lists path metadata within a workspace and optional prefix. - rpc ListObjects(ListObjectsRequest) returns (ListObjectsResponse) { - option (common.v1.required_scopes) = "vfs:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // StatObject returns metadata and optional version history without bytes. - rpc StatObject(StatObjectRequest) returns (StatObjectResponse) { - option (common.v1.required_scopes) = "vfs:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } - - // DeleteObject tombstones a path while retaining metadata and versions. - rpc DeleteObject(DeleteObjectRequest) returns (DeleteObjectResponse) { - option (common.v1.required_scopes) = "vfs:delete"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // CopyObject creates a new path with independent metadata over copied bytes. - rpc CopyObject(CopyObjectRequest) returns (CopyObjectResponse) { - option (common.v1.required_scopes) = "vfs:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // LinkObject creates another path entry pointing at the same content hash. - rpc LinkObject(LinkObjectRequest) returns (LinkObjectResponse) { - option (common.v1.required_scopes) = "vfs:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // CreateLease reserves a path for a long-running upload. - rpc CreateLease(CreateLeaseRequest) returns (CreateLeaseResponse) { - option (common.v1.required_scopes) = "vfs:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // CompleteLease completes a lease and publishes an immutable object version. - rpc CompleteLease(CompleteLeaseRequest) returns (CompleteLeaseResponse) { - option (common.v1.required_scopes) = "vfs:write"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_MEDIUM; - } - - // GrantObject replaces or appends capability grants for one object. - rpc GrantObject(GrantObjectRequest) returns (GrantObjectResponse) { - option (common.v1.required_scopes) = "vfs:grant"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_HIGH; - } - - // SearchMetadata searches object metadata, tags, paths, and titles without - // returning file bytes. - rpc SearchMetadata(SearchMetadataRequest) returns (SearchMetadataResponse) { - option (common.v1.required_scopes) = "vfs:read"; - option (common.v1.organization_scope_field) = "organization_id"; - option (common.v1.workspace_scope_field) = "workspace_id"; - option (common.v1.risk_level) = RISK_LEVEL_LOW; - } -} - -enum VfsObjectState { - VFS_OBJECT_STATE_UNSPECIFIED = 0; - VFS_OBJECT_STATE_ACTIVE = 1; - VFS_OBJECT_STATE_TOMBSTONED = 2; -} - -enum VfsRedactionState { - VFS_REDACTION_STATE_UNSPECIFIED = 0; - VFS_REDACTION_STATE_RAW = 1; - VFS_REDACTION_STATE_REDACTED = 2; - VFS_REDACTION_STATE_PREVIEW_ONLY = 3; - VFS_REDACTION_STATE_DENIED = 4; -} - -enum VfsLeaseState { - VFS_LEASE_STATE_UNSPECIFIED = 0; - VFS_LEASE_STATE_OPEN = 1; - VFS_LEASE_STATE_COMMITTED = 2; - VFS_LEASE_STATE_EXPIRED = 3; - VFS_LEASE_STATE_CANCELLED = 4; -} - -message VfsObject { - string id = 1; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string path = 3 [(buf.validate.field).string.min_len = 1]; - VfsObjectState state = 4 [(buf.validate.field).enum.defined_only = true]; - int32 current_version = 5 [(buf.validate.field).int32.gte = 0]; - string current_version_id = 6; - string content_type = 7; - int64 size_bytes = 8 [(buf.validate.field).int64.gte = 0]; - string sha256 = 9; - string etag = 10; - string owner_id = 11; - string creator_id = 12; - string source_service = 13; - string run_id = 14; - string tool_execution_id = 15; - string connector_id = 16; - string connection_id = 17; - string sensitivity = 18; - string retention_class = 19; - VfsRedactionState redaction_state = 20 [(buf.validate.field).enum.defined_only = true]; - repeated string tags = 21; - map metadata = 22; - repeated VfsGrant grants = 23; - google.protobuf.Timestamp created_at = 24; - google.protobuf.Timestamp updated_at = 25; - google.protobuf.Timestamp deleted_at = 26; - string deleted_by = 27; - string delete_reason = 28; - string organization_id = 29 [(buf.validate.field).string.min_len = 1]; - platform.v1.ResourceRef resource_ref = 30; -} - -message VfsObjectVersion { - string id = 1; - string object_id = 2; - int32 version = 3 [(buf.validate.field).int32.gte = 0]; - string content_ref = 4; - string content_type = 5; - int64 size_bytes = 6 [(buf.validate.field).int64.gte = 0]; - string sha256 = 7; - string etag = 8; - string created_by = 9; - string source_service = 10; - map metadata = 11; - google.protobuf.Timestamp created_at = 12; - string organization_id = 13 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 14 [(buf.validate.field).string.min_len = 1]; - platform.v1.ResourceRef resource_ref = 15; -} - -message VfsGrant { - string principal = 1 [(buf.validate.field).string.min_len = 1]; - repeated string permissions = 2; - string path_prefix = 3; - string sensitivity = 4; - google.protobuf.Timestamp expires_at = 5; - google.protobuf.Timestamp granted_at = 6; - string granted_by = 7; -} - -message VfsLease { - string id = 1; - string workspace_id = 2 [(buf.validate.field).string.min_len = 1]; - string path = 3 [(buf.validate.field).string.min_len = 1]; - string token = 4; - VfsLeaseState state = 5 [(buf.validate.field).enum.defined_only = true]; - string content_type = 6; - map metadata = 7; - google.protobuf.Timestamp created_at = 8; - google.protobuf.Timestamp expires_at = 9; - string created_by = 10; - string organization_id = 11 [(buf.validate.field).string.min_len = 1]; - int64 fencing_token = 12 [(buf.validate.field).int64.gte = 1]; -} - -message VfsEvent { - string id = 1; - string type = 2; - string workspace_id = 3; - string object_id = 4; - string path = 5; - string version_id = 6; - int32 version = 7 [(buf.validate.field).int32.gte = 0]; - string sha256 = 8; - int64 size_bytes = 9 [(buf.validate.field).int64.gte = 0]; - string content_type = 10; - string source_service = 11; - string run_id = 12; - string tool_execution_id = 13; - string connector_id = 14; - string connection_id = 15; - string sensitivity = 16; - string retention_class = 17; - map metadata = 18; - google.protobuf.Timestamp occurred_at = 19; - VfsRedactionState redaction_state = 20 [(buf.validate.field).enum.defined_only = true]; - string organization_id = 21 [(buf.validate.field).string.min_len = 1]; -} - -message PutObjectRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string path = 2 [(buf.validate.field).string.min_len = 1]; - bytes content = 3; - string content_type = 4; - string owner_id = 5; - string creator_id = 6; - string source_service = 7; - string run_id = 8; - string tool_execution_id = 9; - string connector_id = 10; - string connection_id = 11; - string sensitivity = 12; - string retention_class = 13; - VfsRedactionState redaction_state = 14 [(buf.validate.field).enum.defined_only = true]; - repeated string tags = 15; - map metadata = 16; - string idempotency_key = 17; - string organization_id = 18 [(buf.validate.field).string.min_len = 1]; - int32 expected_version = 19 [(buf.validate.field).int32.gte = 0]; - string lease_token = 20; - int64 fencing_token = 21 [(buf.validate.field).int64.gte = 0]; -} - -message PutObjectResponse { - VfsObject object = 1; - VfsObjectVersion version = 2; - VfsEvent event = 3; -} - -message GetObjectRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string object_id = 2; - string path = 3; - string version_id = 4; - int64 offset = 5 [(buf.validate.field).int64.gte = 0]; - int64 limit = 6 [(buf.validate.field).int64.gte = 0]; - bool include_content = 7; - string organization_id = 8 [(buf.validate.field).string.min_len = 1]; -} - -message GetObjectResponse { - VfsObject object = 1; - VfsObjectVersion version = 2; - bytes content = 3; - int64 offset = 4 [(buf.validate.field).int64.gte = 0]; - int64 next_offset = 5 [(buf.validate.field).int64.gte = 0]; - bool eof = 6; -} - -message ListObjectsRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string path_prefix = 2; - bool include_tombstones = 3; - repeated string tags = 4; - int32 limit = 5 [(buf.validate.field).int32.gte = 0]; - int32 offset = 6 [(buf.validate.field).int32.gte = 0]; - string organization_id = 7 [(buf.validate.field).string.min_len = 1]; -} - -message ListObjectsResponse { - repeated VfsObject objects = 1; - int32 total = 2 [(buf.validate.field).int32.gte = 0]; - bool has_more = 3; -} - -message StatObjectRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string object_id = 2; - string path = 3; - bool include_versions = 4; - string organization_id = 5 [(buf.validate.field).string.min_len = 1]; -} - -message StatObjectResponse { - VfsObject object = 1; - repeated VfsObjectVersion versions = 2; -} - -message DeleteObjectRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string object_id = 2; - string path = 3; - string deleted_by = 4; - string reason = 5; - string organization_id = 6 [(buf.validate.field).string.min_len = 1]; -} - -message DeleteObjectResponse { - VfsObject object = 1; - VfsEvent event = 2; -} - -message CopyObjectRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string source_object_id = 2; - string source_path = 3; - string destination_path = 4 [(buf.validate.field).string.min_len = 1]; - string creator_id = 5; - string source_service = 6; - map metadata = 7; - string organization_id = 8 [(buf.validate.field).string.min_len = 1]; -} - -message CopyObjectResponse { - VfsObject object = 1; - VfsObjectVersion version = 2; - VfsEvent event = 3; -} - -message LinkObjectRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string source_object_id = 2; - string source_path = 3; - string link_path = 4 [(buf.validate.field).string.min_len = 1]; - string creator_id = 5; - map metadata = 6; - string organization_id = 7 [(buf.validate.field).string.min_len = 1]; -} - -message LinkObjectResponse { - VfsObject object = 1; - VfsObjectVersion version = 2; - VfsEvent event = 3; -} - -message CreateLeaseRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string path = 2 [(buf.validate.field).string.min_len = 1]; - int32 lease_seconds = 3 [(buf.validate.field).int32.gte = 0]; - string content_type = 4; - string creator_id = 5; - map metadata = 6; - string organization_id = 7 [(buf.validate.field).string.min_len = 1]; - int64 expected_size_bytes = 8 [(buf.validate.field).int64 = { - gt: 0 - lte: 52428800 - }]; - string expected_sha256 = 9; - string idempotency_key = 10 [(buf.validate.field).string.min_len = 1]; -} - -message CreateLeaseResponse { - VfsLease lease = 1; - VfsUploadTarget upload = 2; -} - -message VfsUploadTarget { - string url = 1; - string method = 2 [(buf.validate.field).string.min_len = 1]; - map headers = 3; - google.protobuf.Timestamp expires_at = 4; - int64 max_size_bytes = 5 [(buf.validate.field).int64 = { - gt: 0 - lte: 52428800 - }]; - repeated VfsUploadPartTarget parts = 6; -} - -message VfsUploadPartTarget { - int32 part_number = 1 [(buf.validate.field).int32.gt = 0]; - int64 offset = 2 [(buf.validate.field).int64.gte = 0]; - int64 size_bytes = 3 [(buf.validate.field).int64.gt = 0]; - string url = 4 [(buf.validate.field).string.min_len = 1]; - string method = 5 [(buf.validate.field).string.min_len = 1]; - map headers = 6; - google.protobuf.Timestamp expires_at = 7; -} - -message VfsCompletedUploadPart { - int32 part_number = 1 [(buf.validate.field).int32.gt = 0]; - string etag = 2 [(buf.validate.field).string.min_len = 1]; -} - -message CompleteLeaseRequest { - string lease_id = 1 [(buf.validate.field).string.min_len = 1]; - string lease_token = 2 [(buf.validate.field).string.min_len = 1]; - bytes content = 3; - string created_by = 4; - map metadata = 5; - string organization_id = 6 [(buf.validate.field).string.min_len = 1]; - string workspace_id = 7 [(buf.validate.field).string.min_len = 1]; - int64 fencing_token = 8 [(buf.validate.field).int64.gte = 1]; - int64 size_bytes = 9 [(buf.validate.field).int64 = { - gt: 0 - lte: 52428800 - }]; - string sha256 = 10 [(buf.validate.field).string.min_len = 1]; - string storage_etag = 11; - string idempotency_key = 12 [(buf.validate.field).string.min_len = 1]; -} - -message CompleteLeaseResponse { - VfsObject object = 1; - VfsObjectVersion version = 2; - VfsEvent event = 3; -} - -message GrantObjectRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string object_id = 2; - string path = 3; - VfsGrant grant = 4 [(buf.validate.field).required = true]; - bool append = 5; - string organization_id = 6 [(buf.validate.field).string.min_len = 1]; -} - -message GrantObjectResponse { - VfsObject object = 1; - VfsEvent event = 2; -} - -message SearchMetadataRequest { - string workspace_id = 1 [(buf.validate.field).string.min_len = 1]; - string query = 2; - string path_prefix = 3; - repeated string tags = 4; - map metadata = 5; - bool include_tombstones = 6; - int32 limit = 7 [(buf.validate.field).int32.gte = 0]; - string organization_id = 8 [(buf.validate.field).string.min_len = 1]; -} - -message SearchMetadataResponse { - repeated VfsObject objects = 1; -} diff --git a/scripts/distribution-validation.mjs b/scripts/distribution-validation.mjs index 13c5b1b..2fbd4e1 100644 --- a/scripts/distribution-validation.mjs +++ b/scripts/distribution-validation.mjs @@ -20,16 +20,7 @@ const HEX = /^[0-9a-f]{64}$/; // `dx-corp/capobara` fails `invalid provenance toolDigest` against a // perfectly correct tree. const TOOL_DIGEST = /^(?:[0-9a-f]{40}|[0-9a-f]{64})$/; -const PROTO = [ - "agentruntime/v1/runtime.proto", "agents/v1/agents.proto", "codex/v1/codex.proto", - "common/v1/analytics.proto", "common/v1/authz.proto", "common/v1/classification.proto", - "common/v1/delivery.proto", "common/v1/entity.proto", "common/v1/risk.proto", - "common/v1/surface.proto", "connectors/v1/connectors.proto", "console/v1/console.proto", - "deixic/v1/deixic.proto", "memory/v1/memory.proto", "meter/v1/meter.proto", - "objectives/v1/objectives.proto", "orbcontrol/v1/orb_control.proto", - "platform/v1/platform.proto", "remoterunner/v1/remoterunner.proto", - "toolexecution/v1/toolexecution.proto", "traces/v1/traces.proto", "vfs/v1/filesystem.proto", -].sort(); +const PROTO = ["deixicpublic/v1/sdk.proto"]; const SKILLS = [ "doc-coauthoring", "frontend-design", "incident-triage", "install-code-review", "mcp-builder", "openai-agent-browser-verify", "pr-review", "release-verification", "security-review", "skill-creator", @@ -154,12 +145,9 @@ async function validateApi(root, files) { } } const surface = JSON.parse(await readFile(join(root, "contracts", "public-surface.json"), "utf8")); - requireValue(surface.service === "deixic.v1.DeixicService" && surface.operations?.length === 8, "Deixic public facade contract changed"); + requireValue(surface.service === "deixicpublic.v1.DeixicPublicService" && surface.operations?.length === 8, "Deixic public facade contract changed"); const rpcs = surface.operations.map(item => item.rpc).sort(); requireValue(new Set(rpcs).size === 8 && surface.operations.filter(item => item.kind === "mutation").every(item => item.requiresIdempotencyKey), "Deixic public operations are invalid"); - const lock = await readFile(join(root, "buf.lock"), "utf8"); - requireValue(lock.includes("buf.build/bufbuild/protovalidate") && lock.includes("buf.build/googleapis/googleapis") - && (lock.match(/digest:\s*b5:[0-9a-f]+/g) ?? []).length === 2, "Buf dependencies are not pinned"); const generation = await readFile(join(root, "buf.gen.yaml"), "utf8"); requireValue(generation.includes("sudorandom-connect-openapi:v0.19.1") && !generation.includes("./scripts/"), "public codegen config is not pinned or is private"); run("buf", ["build"], root);