On this page

List loaded agents

GET/agents

Operation listAgentsAuthBearer token

Responses

StatusDescriptionBody
200Loaded agentsAgentList · array<AgentSummary>
idrequiredstring
filePathrequiredstring | null
namerequiredstring
handlestring
autostartrequiredboolean
Errors 401 · 403
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin

Error bodies use the error format.

Example

Request
curl "http://127.0.0.1:7385/agents" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"

Load an agent from an .adf file

POST/agents/load

Operation loadAgentAuthBearer token

Loading an already-loaded file returns its existing reference. Direct loads bypass the review gate unless requireReview is true.

Request bodyapplication/json · LoadAgentBody · required

FieldTypeDescription
filePathrequiredstring

Absolute path of the .adf file

requireReviewboolean

Enforce the review gate for this load (direct loads bypass it by default)

Responses

StatusDescriptionBody
200The loaded agentAgentRef
idrequiredstring
filePathrequiredstring | null
configrequiredobject

The agent's ADF v0.2 config (adf_config). Only the most used fields are listed; the full shape is the ADF spec's AgentConfig. Secret values never appear here.

25 fields of config · AgentConfig
adf_versionrequiredstring

Value 0.2

idrequiredstring

Agent id (stable, the daemon addresses the agent by it)

namerequiredstring
descriptionrequiredstring
handlestring
iconstring
staterequiredstring

Display (fleet-map) state of an agent

One of active, idle, hibernate, suspended, off

autonomousrequiredboolean
autostartboolean
modelrequiredobject
9 fields of model · ModelConfig
providerrequiredstring

Provider id (app provider or one of the agent's own providers)

model_idrequiredstring
temperaturenumber | null
max_tokensinteger | null
top_pnumber | null
reasoningobject

Provider-agnostic reasoning ("thinking") config

multimodalobject
3 fields of multimodal
imageboolean
audioboolean
videoboolean
paramsarray<object>
2 fields of params
keyrequiredstring
valuerequiredstring
provider_paramsobject
instructionsrequiredstring
contextrequiredobject

compact_threshold, audit, dynamic_instructions

toolsrequiredarray<object>

Tool declarations

5 fields of tools
namerequiredstring
enabledrequiredboolean
visibleboolean
restrictedboolean
lockedboolean
triggersrequiredmap<string, TriggerConfig>

on_startup, on_inbox, on_outbox, on_file_change, on_chat, on_timer, on_tool_call, on_task_create, on_task_complete, on_logs, on_llm_call

3 fields of triggers
enabledrequiredboolean
targetsrequiredarray<TriggerTarget>
11 fields of targets
scoperequiredstring

One of agent, system

lambdastring

System scope: path/file.ts:functionName

commandstring

System scope: shell command (alternative to lambda)

warmboolean
filterobject
debounce_msinteger
interval_msinteger
batch_msinteger
batch_countinteger
lockedboolean
loopstring

Cognition loop this target wakes; absent = main

lockedboolean
securityrequiredobject
limitsrequiredobject
messagingrequiredobject

mode (proactive | respond_only | listen_only), receive, network, …

mcpobject
2 fields of mcp
serversrequiredarray<McpServerConfig>
20 fields of servers
namerequiredstring
transportrequiredstring

One of stdio, http

commandstring
argsarray<string>
urlstring
oauthboolean
headersmap<string, string>
header_envarray<object>
bearer_token_env_varstring
envmap<string, string>
env_keysarray<string>
env_schemaarray<object>
npm_packagestring
pypi_packagestring
sourcestring
available_toolsarray<object>
tool_call_timeout_msinteger
restrictedboolean
run_locationstring

One of host, shared

credential_filesarray<object>
3 fields of credential_files
pathrequiredstring
requiredboolean
write_backboolean
new_tools_restrictedboolean
adaptersmap<string, AdapterInstanceConfig>

Channel adapters by type

4 fields of adapters
enabledrequiredboolean
configobject

Adapter-specific settings (no secrets: tokens are credentials)

policyobject
limitsobject
1 field of limits
max_attachment_sizeinteger

Bytes

providersarray<AgentProviderConfig>
8 fields of providers
idrequiredstring

anthropic, openai, … or custom:<id>

typerequiredstring

One of anthropic, openai, openai-compatible, openrouter

namerequiredstring
baseUrlrequiredstring
presetstring
defaultModelstring
paramsarray<object>
2 fields of params
keyrequiredstring
valuerequiredstring
requestDelayMsinteger
loopsarray<LoopConfig>

Inner (side) loops; main is implicit

8 fields of loops
namerequiredstring

pattern: ^[a-z0-9][a-z0-9_-]{0,31}$

goalrequiredstring

Becomes the loop's instructions

enabledrequiredboolean
autostartboolean
autonomousboolean
modelobject

Fields as in ModelConfig above.

compact_thresholdinteger | null
toolsarray<string>

Absolute allow-list, intersected with the host's enabled tools

ws_connectionsarray<object>
servingobject
locked_fieldsarray<string>
metadatarequiredobject

created_at, updated_at, author, tags, version

Errors 400 · 401 · 403 · 500
400Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY
401Missing or wrong bearer token (unauthorized)
403The .adf must be reviewed on this machine before it loads (AGENT_REVIEW_REQUIRED), or the request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)ReviewRequiredResponse | ErrorResponse
Option 1object

The .adf has not been reviewed on this machine; review it (GET /agents/review) and accept (POST /agents/review/accept) first.

4 fields of Option 1 · ReviewRequiredResponse
errorrequiredstring
coderequiredstring

Value AGENT_REVIEW_REQUIRED

agentIdrequiredstring
filePathrequiredstring
Option 2object

Every error body. Some routes add fields (e.g. identity, coveredBy, agentId).

2 fields of Option 2 · ErrorResponse
errorrequiredstring

Human-readable message

codestring

Stable machine-readable code. Every error body has one: route-specific where listed, else the status default (400 bad_request, 403 forbidden, 404 not_found, 405 not_supported, 409 conflict, 500 internal_error, 502 upstream_error, 503 unavailable)

500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X POST "http://127.0.0.1:7385/agents/load" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"filePath":"/home/me/agents/agent-1.adf"}'

Create an agent from a template, then load it

POST/agents/create

Operation createAgentAuthBearer token

Studio's "new agent", headless: template instance → sealed identity with owner/runtime stamps and attestations → marked reviewed → directory tracked → loaded (and started with start: true). Needs a ready owner identity; 409 identity_not_ready carries identity so a client can offer create / restore / unlock. load_failed (422) means the file was created, reviewed and tracked but could not load (e.g. no provider configured): fix it, then POST /agents/load.

Request bodyapplication/json · CreateAgentBody · optional

FieldTypeDescription
namestring

File name (<= 64 chars). Omitted: a generated adjective-plant name.

directorystring

Absolute, existing directory. Default: settings.agentsFolder, else ~/Documents/adf-agents.

templatestring

Template id (GET /templates). Default: settings.defaultTemplateId, else standard.

providerstring

App provider id (must exist in settings.providers)

modelstring
startboolean

default: false

Responses

StatusDescriptionBody
201Created (and loaded; started when start)CreateAgentResponse
agentIdrequiredstring
namerequiredstring
filePathrequiredstring
didrequiredstring
startedrequiredboolean
Errors 400 · 401 · 403 · 409 · 422 · 500 · 503
400Invalid field (bad_request)AgentCreateErrorResponse
errorrequiredstring
coderequiredstring

One of bad_request, identity_not_ready, name_taken, template_missing, template_unreviewed, template_invalid, password_required, wrong_password, load_failed

identityobject
7 fields of identity · IdentityStatus
statusrequiredstring

One of none, locked, restore-needed, ready

ownerDidrequiredstring | null
runtimeDidrequiredstring | null

This daemon's own runtime DID (never Studio's)

storagerequiredstring

One of keychain, file

backupConfirmedrequiredboolean
passphraseRequiredrequiredboolean

File storage not unlocked: create/restore/unlock take a passphrase

messagerequiredstring

What to do next

401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
409Owner identity not ready (identity_not_ready) or the name is taken in that directory (name_taken)identity_not_readyname_takenAgentCreateErrorResponse
422The template was refused (template_missing, template_unreviewed, template_invalid) or the new file could not load (load_failed)AgentCreateErrorResponse
500Unexpected runtime failure
503The subsystem is not configured on this daemon

Error bodies use the error format.

Example

Request
curl -X POST "http://127.0.0.1:7385/agents/create" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"name":"agent-1","template":"standard","start":true}'
Response 201
{
  "agentId": "Xk3v9QpLm2",
  "name": "agent-1",
  "filePath": "/home/me/Documents/adf-agents/agent-1.adf",
  "did": "did:key:z6Mk…",
  "started": true
}

Scan folders and autostart their reviewed agents

POST/agents/autostart

Operation autostartAgentsAuthBearer token

Same rules as daemon boot: autostart agents that are reviewed and not password-protected; others are reported in skipped.

Request bodyapplication/json · AutostartBody · required

FieldTypeDescription
trackedDirsrequiredarray<string>
maxDepthinteger

Responses

StatusDescriptionBody
200What was started, skipped and failedAutostartReport
scannedrequiredinteger

.adf files found

startedrequiredarray<object>
4 fields of started
agentIdrequiredstring
filePathrequiredstring
namerequiredstring
startupTriggeredrequiredboolean
skippedrequiredarray<object>
4 fields of skipped
filePathrequiredstring
namerequiredstring
reasonrequiredstring

One of already_loaded, not_autostart, password_protected, unreviewed

agentIdstring
failedrequiredarray<object>
3 fields of failed
filePathrequiredstring
namerequiredstring
errorrequiredstring
Errors 400 · 401 · 403 · 500
400Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X POST "http://127.0.0.1:7385/agents/autostart" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"trackedDirs":["/home/me/agents"],"maxDepth":5}'
Response 200
{
  "scanned": 2,
  "started": [
    {
      "agentId": "Xk3v9QpLm2",
      "filePath": "/home/me/agents/agent-1.adf",
      "name": "agent-1",
      "startupTriggered": true
    }
  ],
  "skipped": [
    {
      "filePath": "/home/me/agents/agent-2.adf",
      "name": "agent-2",
      "reason": "unreviewed"
    }
  ],
  "failed": []
}

Review information for an .adf file

GET/agents/review

Operation getAgentReviewAuthBearer token

Query parameters

NameTypeDescription
filePathrequiredstring

Absolute path of the .adf file

example: /home/me/agents/agent-2.adf

Responses

StatusDescriptionBody
200Review summaryReviewInfo
agentIdrequiredstring
filePathrequiredstring
reviewedrequiredboolean
summaryrequiredobject

What the agent can do, as the review dialog shows it (Studio's AgentConfigSummary).

13 fields of summary · ReviewSummary
namerequiredstring
descriptionrequiredstring
iconstring
identityrequiredobject

agentDid, fileOwnerDid, ownerIsYou, scenario (mine | recognized | foreign | unclaimed), needsClaim, …

computeTierrequiredstring

One of shared, isolated, host

autostartrequiredboolean
toolsrequiredarray<object>
3 fields of tools
namerequiredstring
enabledrequiredboolean
notablerequiredboolean
mcpServersrequiredarray<object>
triggersrequiredarray<object>
3 fields of triggers
typerequiredstring
enabledrequiredboolean
targetCountrequiredinteger
codeExecutionrequiredboolean
messagingrequiredobject
1 field of messaging
moderequiredstring
networkrequiredobject
securityrequiredobject
Errors 400 · 401 · 403 · 500
400Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl "http://127.0.0.1:7385/agents/review?filePath=/home/me/agents/agent-2.adf" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"

Mark an .adf file's agent as reviewed

POST/agents/review/accept

Operation acceptAgentReviewAuthBearer token

Request bodyapplication/json · ReviewAcceptBody · required

FieldTypeDescription
filePathrequiredstring

Responses

StatusDescriptionBody
200ReviewedReviewInfo

Fields as in ReviewInfo above.

Errors 400 · 401 · 403 · 500
400Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X POST "http://127.0.0.1:7385/agents/review/accept" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"filePath":"/home/me/agents/agent-2.adf"}'

A loaded agent's reference (id, file, config)

GET/agents/{id}

Operation getAgentAuthBearer token

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Responses

StatusDescriptionBody
200Agent referenceAgentRef

Fields as in AgentRef above.

Errors 401 · 403 · 404
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)

Error bodies use the error format.

Example

Request
curl "http://127.0.0.1:7385/agents/agent-1" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"

Agent runtime status

GET/agents/{id}/status

Operation getAgentStatusAuthBearer token

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Responses

StatusDescriptionBody
200StatusAgentStatus
idrequiredstring
filePathrequiredstring | null
namerequiredstring
handlestring
autostartrequiredboolean
runtimeStaterequiredstring

Executor state: idle, thinking, tool_use, awaiting_approval, awaiting_ask, suspended, error, stopped: or a display state (active, hibernate, off)

targetStaterequiredstring | null
loopCountrequiredinteger

Persisted entries in main's loop stream

degradedstring

Set when the agent loaded but cannot fully function (CREDENTIALS_LOCKED: its credentials envelope is locked); cleared once the owner identity unlocks it

Errors 401 · 403 · 404
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)

Error bodies use the error format.

Example

Request
curl "http://127.0.0.1:7385/agents/agent-1/status" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"
Response 200
{
  "id": "Xk3v9QpLm2",
  "filePath": "/home/me/agents/agent-1.adf",
  "name": "agent-1",
  "handle": "agent-1",
  "autostart": true,
  "runtimeState": "idle",
  "targetState": null,
  "loopCount": 1
}

Start an agent, loading it from a tracked folder when needed

POST/agents/{id}/start

Operation startAgentAuthBearer token

id may also name an agent that is not loaded: an .adf path, or an id / handle / name found in the tracked folders. The daemon loads it (review gate applies: 403) and starts it; loaded says whether it did. startupTriggered is true when the agent's start state fired its startup event. An identifier that matches several files answers 409 ambiguous_agent with the candidates: start one by its file path. No body.

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Responses

StatusDescriptionBody
200StartedStartAgentResponse
successrequiredboolean

Value true

loadedrequiredboolean

The agent was loaded from a tracked folder first

startupTriggeredrequiredboolean
agentobject

Fields as in AgentStatus above.

Errors 401 · 403 · 404 · 409 · 500
401Missing or wrong bearer token (unauthorized)
403The .adf must be reviewed on this machine before it loads (AGENT_REVIEW_REQUIRED), or the request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)ReviewRequiredResponse | ErrorResponse
Option 1object

The .adf has not been reviewed on this machine; review it (GET /agents/review) and accept (POST /agents/review/accept) first.

4 fields of Option 1 · ReviewRequiredResponse
errorrequiredstring
coderequiredstring

Value AGENT_REVIEW_REQUIRED

agentIdrequiredstring
filePathrequiredstring
Option 2object

Every error body. Some routes add fields (e.g. identity, coveredBy, agentId).

2 fields of Option 2 · ErrorResponse
errorrequiredstring

Human-readable message

codestring

Stable machine-readable code. Every error body has one: route-specific where listed, else the status default (400 bad_request, 403 forbidden, 404 not_found, 405 not_supported, 409 conflict, 500 internal_error, 502 upstream_error, 503 unavailable)

404Unknown agent (or the named resource: loop, task, file, …)
409The identifier matches several agent files (ambiguous_agent)AmbiguousAgentResponse
errorrequiredstring

Human-readable message

codestring

Stable machine-readable code. Every error body has one: route-specific where listed, else the status default (400 bad_request, 403 forbidden, 404 not_found, 405 not_supported, 409 conflict, 500 internal_error, 502 upstream_error, 503 unavailable)

candidatesrequiredarray<object>
3 fields of candidates
namerequiredstring
handlerequiredstring | null
filePathrequiredstring
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X POST "http://127.0.0.1:7385/agents/agent-1/start" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"
Response 200
{
  "success": true,
  "loaded": false,
  "startupTriggered": true,
  "agent": {
    "id": "Xk3v9QpLm2",
    "filePath": "/home/me/agents/agent-1.adf",
    "name": "agent-1",
    "autostart": true,
    "runtimeState": "idle",
    "targetState": null,
    "loopCount": 1
  }
}

Stop and unload an agent

POST/agents/{id}/stop

Operation stopAgentAuthBearer token

Graceful: a running turn gets a 5 s grace period, then the agent is unloaded (its file stays on disk). No body.

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Responses

StatusDescriptionBody
200Stopped and unloadedSuccessResponse
successrequiredboolean
Errors 401 · 403 · 404 · 500
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X POST "http://127.0.0.1:7385/agents/agent-1/stop" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"
Response 200
{
  "success": true
}

Unload an agent (alias of stop)

POST/agents/{id}/unload

Operation unloadAgentAuthBearer token

No body.

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Responses

StatusDescriptionBody
200UnloadedSuccessResponse
successrequiredboolean
Errors 401 · 403 · 404 · 500
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X POST "http://127.0.0.1:7385/agents/agent-1/unload" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"
Response 200
{
  "success": true
}

Abort the current turn without unloading

POST/agents/{id}/abort

Operation abortAgentAuthBearer token

A hard stop: the executor of main (or the named inner loop) is left stopped and runs no further turns, triggers or timers until the agent is reloaded. To end a turn and keep working, use /interrupt. Chats still queued behind the turn are discarded, never silently: a chat.discarded event names their turnIds and a System notice lands in the loop. Unknown loop 404; a loop with no running executor 409.

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Query parameters

NameTypeDescription
loopstring

Cognition loop to address. Absent = main. Unknown loops answer 404.

Request bodyapplication/json · LoopBody · optional

Optional; ?loop= wins.

FieldTypeDescription
loopstring

Cognition loop; absent = main. The loop query parameter wins.

Responses

StatusDescriptionBody
200AbortedAbortResponse
successrequiredboolean

Value true

loopstring

Echoed when a loop was named

Errors 401 · 403 · 404 · 409 · 500
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)
409The resource is in a state that does not allow this now
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X POST "http://127.0.0.1:7385/agents/agent-1/abort" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{}'

Interrupt the running turn and leave the loop idle

POST/agents/{id}/interrupt

Operation interruptAgentAuthBearer token

Ends main's (or the named loop's) running turn and sets that executor idle; it keeps accepting chats, triggers and timers. Unlike /abort it never stops the executor, and chats queued behind the turn are kept and run next. interrupted is false when nothing was running; 409 when the loop is stopped or errored.

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Query parameters

NameTypeDescription
loopstring

Cognition loop to address. Absent = main. Unknown loops answer 404.

Request bodyapplication/json · LoopBody · optional

Optional; ?loop= wins.

FieldTypeDescription
loopstring

Cognition loop; absent = main. The loop query parameter wins.

Responses

StatusDescriptionBody
200Interrupted (or nothing to interrupt)InterruptResponse
successrequiredboolean

Value true

interruptedrequiredboolean

False when nothing was running

looprequiredstring
Errors 401 · 403 · 404 · 409 · 500
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)
409The resource is in a state that does not allow this now
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X POST "http://127.0.0.1:7385/agents/agent-1/interrupt" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{}'
Response 200
{
  "success": true,
  "interrupted": true,
  "loop": "main"
}

Move the running agent's display state

POST/agents/{id}/state

Operation setAgentDisplayStateAuthBearer token

Fleet-map semantics, not persisted to the .adf: a config.state change via PUT …/config does not move the running agent; this does.

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Request bodyapplication/json · DisplayStateBody · required

FieldTypeDescription
staterequiredstring

Display (fleet-map) state of an agent

One of active, idle, hibernate, suspended, off

Responses

StatusDescriptionBody
200State setDisplayStateResponse
agentIdrequiredstring

Agent id

successrequiredboolean

Value true

staterequiredstring

Display (fleet-map) state of an agent

One of active, idle, hibernate, suspended, off

Errors 400 · 401 · 403 · 404 · 500
400Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X POST "http://127.0.0.1:7385/agents/agent-1/state" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"state":"idle"}'

Read the agent config

GET/agents/{id}/config

Operation getAgentConfigAuthBearer token

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Responses

StatusDescriptionBody
200ConfigAgentConfigResponse
agentIdrequiredstring

Agent id

configrequiredobject

The agent's ADF v0.2 config (adf_config). Only the most used fields are listed; the full shape is the ADF spec's AgentConfig. Secret values never appear here.

Fields as in AgentConfig above.

Errors 401 · 403 · 404
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)

Error bodies use the error format.

Example

Request
curl "http://127.0.0.1:7385/agents/agent-1/config" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"

Replace the agent config

PUT/agents/{id}/config

Operation setAgentConfigAuthBearer token

Validated against the ADF config schema, persisted and applied to the running executor, trigger evaluator and loops. A changed state does not move the running agent (it is the persisted start state); use POST …/state. Owner locks (locked, locked_fields) bind the agent's own sys_update_config, not this route.

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Request bodyapplication/json · AgentConfig · required

The agent's ADF v0.2 config (adf_config). Only the most used fields are listed; the full shape is the ADF spec's AgentConfig. Secret values never appear here.

Fields as in AgentConfig above.

Responses

StatusDescriptionBody
200SavedAgentConfigUpdateResponse
agentIdrequiredstring

Agent id

successrequiredboolean

Value true

configrequiredobject

The agent's ADF v0.2 config (adf_config). Only the most used fields are listed; the full shape is the ADF spec's AgentConfig. Secret values never appear here.

Fields as in AgentConfig above.

Errors 400 · 401 · 403 · 404 · 500
400Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X PUT "http://127.0.0.1:7385/agents/agent-1/config" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
  "adf_version": "0.2",
  "id": "string",
  "name": "string",
  "description": "string",
  "state": "active",
  "autonomous": true,
  "model": {
    "provider": "anthropic",
    "model_id": "claude-sonnet-4-5"
  },
  "instructions": "string",
  "context": {},
  "tools": [],
  "triggers": {},
  "security": {},
  "limits": {},
  "messaging": {},
  "metadata": {}
}'

The agent's tool catalog

GET/agents/{id}/tools

Operation getAgentToolsAuthBearer token

Every built-in tool the main registry holds, every MCP tool its servers advertise and every declared tool, sorted by name, with declared state and description (what sys_get_config gives the agent). Read-only: change tools with PUT …/config.

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Responses

StatusDescriptionBody
200ToolsAgentToolsResponse
agentIdrequiredstring

Agent id

toolsrequiredarray<ToolEntry>
9 fields of tools
namerequiredstring
enabledrequiredboolean
visiblerequiredboolean

Exposed in the LLM's active tool list (when enabled)

restrictedrequiredboolean

Authorized code only; an LLM call needs owner approval

lockedrequiredboolean

Owner lock: the agent cannot change this entry

sourcerequiredstring

builtin or mcp:<server>

descriptionrequiredstring
schemarequiredobject

The tool's JSON input schema

restrictionsrequiredobject
2 fields of restrictions
restrictedrequiredboolean
lockedrequiredboolean
Errors 401 · 403 · 404 · 500
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl "http://127.0.0.1:7385/agents/agent-1/tools" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"

List metadata entries (adf_meta)

GET/agents/{id}/meta

Operation getAgentMetaAuthBearer token

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Responses

StatusDescriptionBody
200EntriesMetaResponse
agentIdrequiredstring

Agent id

entriesrequiredarray<MetaEntry>
3 fields of entries
keyrequiredstring
valuerequiredstring
protectionrequiredstring

One of none, readonly, increment

Errors 401 · 403 · 404
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)

Error bodies use the error format.

Example

Request
curl "http://127.0.0.1:7385/agents/agent-1/meta" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"

Set a metadata value

PUT/agents/{id}/meta/{key}

Operation setAgentMetaAuthBearer token

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

keyrequiredstring

Metadata key

Request bodyapplication/json · MetaSetBody · required

FieldTypeDescription
valuerequiredstring
protectionstring

One of none, readonly, increment

Responses

StatusDescriptionBody
200SavedAgentSuccess
agentIdrequiredstring

Agent id

successrequiredboolean
Errors 400 · 401 · 403 · 404 · 500
400Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X PUT "http://127.0.0.1:7385/agents/agent-1/meta/KEY" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"value":"42"}'
Response 200
{
  "agentId": "Xk3v9QpLm2",
  "success": true
}

Delete a metadata value

DELETE/agents/{id}/meta/{key}

Operation deleteAgentMetaAuthBearer token

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

keyrequiredstring

Metadata key

Responses

StatusDescriptionBody
200success is false when nothing was deletedAgentSuccess
agentIdrequiredstring

Agent id

successrequiredboolean
Errors 401 · 403 · 404 · 500
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X DELETE "http://127.0.0.1:7385/agents/agent-1/meta/KEY" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"
Response 200
{
  "agentId": "Xk3v9QpLm2",
  "success": true
}

Set a metadata key's protection

PATCH/agents/{id}/meta/{key}/protection

Operation setAgentMetaProtectionAuthBearer token

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

keyrequiredstring

Metadata key

Request bodyapplication/json · MetaProtectionBody · required

FieldTypeDescription
protectionrequiredstring

One of none, readonly, increment

Responses

StatusDescriptionBody
200SavedAgentSuccess
agentIdrequiredstring

Agent id

successrequiredboolean
Errors 400 · 401 · 403 · 404 · 500
400Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X PATCH "http://127.0.0.1:7385/agents/agent-1/meta/KEY/protection" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"protection":"none"}'
Response 200
{
  "agentId": "Xk3v9QpLm2",
  "success": true
}

List the agent's local tables

GET/agents/{id}/tables

Operation listAgentLocalTablesAuthBearer token

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Responses

StatusDescriptionBody
200TablesTablesResponse
agentIdrequiredstring

Agent id

tablesrequiredarray<object>
2 fields of tables
namerequiredstring
row_countrequiredinteger
Errors 401 · 403 · 404
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)

Error bodies use the error format.

Example

Request
curl "http://127.0.0.1:7385/agents/agent-1/tables" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"

Read rows of a local table

GET/agents/{id}/tables/{table}

Operation queryAgentLocalTableAuthBearer token

Only local_* tables and adf_audit are readable (anything else: 400 "Invalid table name"); read the inbox and outbox through their own routes. limit default 100 (1–1000), offset default 0.

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

tablerequiredstring

Local table name (local_*)

Query parameters

NameTypeDescription
limitinteger

Maximum rows to return

offsetinteger

Rows to skip

range: ≥ 0

Responses

StatusDescriptionBody
200RowsTableQueryResponse
agentIdrequiredstring

Agent id

columnsrequiredarray<string>
rowsrequiredarray<object>
Errors 400 · 401 · 403 · 404 · 500
400Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl "http://127.0.0.1:7385/agents/agent-1/tables/TABLE" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"

Drop a local table

DELETE/agents/{id}/tables/{table}

Operation dropAgentLocalTableAuthBearer token

Only local_* tables can be dropped.

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

tablerequiredstring

Local table name (local_*)

Responses

StatusDescriptionBody
200DroppedAgentSuccess
agentIdrequiredstring

Agent id

successrequiredboolean
Errors 401 · 403 · 404 · 500
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X DELETE "http://127.0.0.1:7385/agents/agent-1/tables/TABLE" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"
Response 200
{
  "agentId": "Xk3v9QpLm2",
  "success": true
}

Recent agent logs (adf_logs)

GET/agents/{id}/logs

Operation getAgentLogsAuthBearer token

limit default 50 (clamped 1–500).

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Query parameters

NameTypeDescription
limitinteger

Maximum rows to return

originstring

Only this origin (e.g. lambda, websocket)

eventstring

Only this event name

Responses

StatusDescriptionBody
200Log rows, newest lastAgentLogsResponse
agentIdrequiredstring

Agent id

logsrequiredarray<LogEntry>
8 fields of logs
idrequiredinteger
levelrequiredstring

One of debug, info, warn, error

originrequiredstring | null
eventrequiredstring | null
targetrequiredstring | null
messagerequiredstring
datarequiredstring | null

JSON text

created_atrequiredinteger

Epoch ms

Errors 400 · 401 · 403 · 404
400Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)

Error bodies use the error format.

Example

Request
curl "http://127.0.0.1:7385/agents/agent-1/logs" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"

Clear the agent's logs

DELETE/agents/{id}/logs

Operation clearAgentLogsAuthBearer token

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Responses

StatusDescriptionBody
200ClearedAgentSuccess
agentIdrequiredstring

Agent id

successrequiredboolean
Errors 401 · 403 · 404 · 500
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)
500Unexpected runtime failure

Error bodies use the error format.

Example

Request
curl -X DELETE "http://127.0.0.1:7385/agents/agent-1/logs" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"
Response 200
{
  "agentId": "Xk3v9QpLm2",
  "success": true
}

Log rows after an id (tail)

GET/agents/{id}/logs/after

Operation getAgentLogsAfterAuthBearer token

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Query parameters

NameTypeDescription
afterIdrequiredinteger

Return rows with id greater than this

Responses

StatusDescriptionBody
200Newer rowsAgentLogsResponse

Fields as in AgentLogsResponse above.

Errors 400 · 401 · 403 · 404
400Invalid request: missing or malformed field, query parameter or body. A body Fastify cannot parse gets Fastify's own shape (statusCode, code, error, message).bad_requestFST_ERR_CTP_EMPTY_JSON_BODY
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)

Error bodies use the error format.

Example

Request
curl "http://127.0.0.1:7385/agents/agent-1/logs/after?afterId=AFTER_ID" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"

Token usage from the agent's persisted loop rows

GET/agents/{id}/usage

Operation getAgentUsageAuthBearer token

A rollup of adf_loop.tokens (compaction summary rows included). It excludes model_invoke and any provider call that created no loop row; the per-call usage/cost channel is the llm.completed umbilical event. input already includes cacheRead and cacheWrite; total = input + output.

Path parameters

NameTypeDescription
idrequiredstring

Loaded agent: its id, handle or name.

example: agent-1

Responses

StatusDescriptionBody
200UsageAgentUsageResponse
agentIdrequiredstring

Agent id

sourcerequiredstring

Value adf_loop

noterequiredstring
loopRowsrequiredinteger
usageRowsrequiredinteger
totalsrequiredobject
5 fields of totals · UsageTotals
inputrequiredinteger
outputrequiredinteger
cacheReadrequiredinteger
cacheWriterequiredinteger
totalrequiredinteger
byModelrequiredarray<object>
7 fields of byModel
inputrequiredinteger
outputrequiredinteger
cacheReadrequiredinteger
cacheWriterequiredinteger
totalrequiredinteger
modelrequiredstring
rowsrequiredinteger
Errors 401 · 403 · 404
401Missing or wrong bearer token (unauthorized)
403The request guard refused it: Host header not allowed (host_not_allowed, DNS-rebinding protection) or a browser cross-site request (cross_origin)host_not_allowedcross_origin
404Unknown agent (or the named resource: loop, task, file, …)

Error bodies use the error format.

Example

Request
curl "http://127.0.0.1:7385/agents/agent-1/usage" \
  -H "Authorization: Bearer $ADF_DAEMON_TOKEN"